# In RHEL how to run Configuration file along with logstash?

**URL:** <https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479>\
**Category:** Logstash\
**Created:** [February 26, 2018, 12:04pm UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479 "2018-02-26T12:04:01Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [February 26, 2018, 12:04pm UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/1 "2018-02-26T12:04:01Z")

</div>

Hi ELK team,  
i have successfully installed Logstash in RHEL. but what issue is we want to run Config file placed under config.d folder when we run "sudo initctl start logstash ". it is not reading those config files placed under config.d folder. OR how we need to run " logstash -f simple.conf " command in RHEl to start logstash and run config file at a time???

Thanks in advance. any reference on this will be great help!!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 26, 2018, 12:10pm UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/2 "2018-02-26T12:10:00Z")

</div>

What config.d directory are you talking about, /etc/logstash/conf.d? With what arguments are Logstash started (check with `ps aux | grep logstash`)? What's in logstash.yml?

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [February 27, 2018, 5:59am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/3 "2018-02-27T05:59:02Z")

</div>

Hi Magnusbaeck,

Yes im talking about /etc/logstash/conf.d directory , my logstash.yml looks like:

only following lines are active in LOGSTASH.yml file

path.data: /var/lib/logstash

path.config: /etc/logstash/conf.d/\*.conf

path.logs: /var/log/logstash

* * *

in RHEL im Starting logstash using command " sudo initctl start logstash "

this above command should also execute config files placed in /etc/logstash/conf.d directory right??

Thanks,  
Naveena K N

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 27, 2018, 6:52am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/4 "2018-02-27T06:52:23Z")

</div>

> this above command should also execute config files placed in /etc/logstash/conf.d directory right??

Yes. How do you know the files aren't read? If you bump of the log level Logstash will log information about all configuration that's loaded.

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [February 27, 2018, 6:58am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/5 "2018-02-27T06:58:32Z")

</div>

im placing simple.conf file inside /etc/logstash/conf.d as follows:  
input { stdin { } }  
output {  
stdout { codec =\> rubydebug } }

so after executing sudo initctl start logstash , it should ask for input from shell right??it is not taking any input!!!

Thanks,  
Naveena K N

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 27, 2018, 7:00am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/6 "2018-02-27T07:00:06Z")

</div>

No, it won't ask for input from the shell. When you start Logstash with initctl it'll run in the background and the stdin input won't be usable.

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [February 27, 2018, 7:01am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/7 "2018-02-27T07:01:16Z")

</div>

ok then will try with feeding data to ELK  
Thanks

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [February 27, 2018, 8:18am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/8 "2018-02-27T08:18:44Z")

</div>

this is the error im getting in /var/log/logstash/logstash-plain.log file:

[2018-02-26T12:43:06,967][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"/usr/share/logstash/modules/fb\_apache/configuration"}  
[2018-02-26T12:43:06,990][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"/usr/share/logstash/modules/netflow/configuration"}  
[2018-02-26T12:43:07,937][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-02-26T12:43:08,394][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.2.2"}  
[2018-02-26T12:43:08,622][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, { at line 3, column 5 (byte 14) after input {\n\nssl ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:50:in`compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:51:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:169:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in`execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:315:in `block in converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in`with\_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:312:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:299:in `converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:166:in`block in converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:164:in`converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:90:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:348:in`block in execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}  
[2018-02-26T12:43:08,619][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

why am i getting this error??any configuration missing??

Thanks in advance

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 27, 2018, 8:56am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/9 "2018-02-27T08:56:40Z")

</div>

There's a syntax problem in one of the configuration files. The error message indicates approximately where.

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [March 1, 2018, 7:37am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/10 "2018-03-01T07:37:11Z")

</div>

Hi @magnusbaeck  
i tried with placing config file under /etc/logstash/conf.d directory.  
and changed log mode to debug mode...  
logstash is working fine but it is not able to create index by taking server log as input.

following are the lines of Logstash log file:  
Pipeline started succesfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x3c05e288@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:246 sleep\>"}

\_globbed\_files: /home/nakn/logfile/server.log: glob is: []

Pipelines running {:count=\>1, :pipelines=\>["main"]}

collector name {:name=\>"ParNew"}  
collector name {:name=\>"ConcurrentMarkSweep"}  
Pushing flush onto pipeline {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x3c05e288@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:246 sleep\>"}

collector name {:name=\>"ParNew"}  
collector name {:name=\>"ConcurrentMarkSweep"}

....continues  
help me to resolve this issue of pushing data to ELK!

Thanks  
Naveena K N

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 1, 2018, 7:39am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/11 "2018-03-01T07:39:34Z")

</div>

> \_globbed\_files: /home/nakn/logfile/server.log: glob is:

This indicates a typo in the path or that Logstash doesn't have permissions to read the file or any of the directories leading up to it.

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [March 1, 2018, 7:54am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/12 "2018-03-01T07:54:47Z")

</div>

Thanks @magnusbaeck im able to resolve the issue now. Index is getting created now.

Naveena K N

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [March 14, 2018, 10:34am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/13 "2018-03-14T10:34:58Z")

</div>

Hi Elastic Experts!, Hi @magnusbaeck

we are trying send serverlog data from file system and error log data from database.so we placed config files in "/etc/logstash/conf.d/ " , for filesystem we are using file input plugin and for database we are using jdbc input plugin. so when we start logstash using command "sudo /usr/bin/systemctl start logstash" its working but data in indexes created are not correct. for config file which needs to read from database ,it is reading from file system path specified in other config files.

so why it is behaving like that, do we need to make any changes in logstash.yml or pipeline.yml for our Scenario to work proprly??

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2018, 10:54am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/14 "2018-03-14T10:54:48Z")

</div>

All configuration files in /etc/logstash/conf.d will be concatenated. If you want to have isolated event streams you need to use conditionals or switch to using multiple pipelines.

This is an extremely frequently asked question so please excuse my brevity.

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [March 14, 2018, 11:09am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/15 "2018-03-14T11:09:26Z")

</div>

thanks @magnusbaeck for your approach of using multiple pipelines, but how to configure that??

Thanks,  
Naveena K N

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2018, 11:23am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/16 "2018-03-14T11:23:16Z")

</div>

Have you read the documentation about that feature?

[https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html)

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [March 14, 2018, 11:28am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/17 "2018-03-14T11:28:03Z")

</div>

so according that documentation, we need to create different pipelines with unique id and in the path we need to specify which config file to select , right??

Thanks,  
Naveena K N

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [March 14, 2018, 11:30am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/18 "2018-03-14T11:30:57Z")

</div>

like for example :

- pipeline.id: my-pipeline\_1  
path.config: "/etc/path/to/mon.config"  
pipeline.workers: 2
- pipeline.id: my-pipeline\_2  
path.config: "/etc/different/path/sl1a.cfg"
  - pipeline.id: my-pipeline\_3  
path.config: "/etc/different/path/sl2a.cfg"

This is how u r suggesting??

what is that workers means??

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2018, 11:58am UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/19 "2018-03-14T11:58:10Z")

</div>

> so according that documentation, we need to create different pipelines with unique id and in the path we need to specify which config file to select , right??

Yes.

> what is that workers means??

Have you looked in the documentation?

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [March 14, 2018, 12:05pm UTC](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479/20 "2018-03-14T12:05:15Z")

</div>

thanks @magnusbaeck, i hope problem will resolve now.

workers come into picture if we consider cpu utilization i think according to documentation??!

[Next page](https://discuss.elastic.co/t/in-rhel-how-to-run-configuration-file-along-with-logstash/121479.md?page=2)
