# Is there a faster way to test logstash configs with stdin?

**URL:** <https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113>\
**Category:** Logstash\
**Created:** [September 25, 2019, 10:11pm UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113 "2019-09-25T22:11:54Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [September 25, 2019, 10:11pm UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113/1 "2019-09-25T22:11:54Z")

</div>

I found [this post from Dec 2018](https://discuss.elastic.co/t/quick-way-to-test-logstash-config-file/159270), but the automatic reload doesn't work with stdin (at least up to 6.8, which is my limit at the moment)... Any tips on how to test a developing configuration faster? Or we really have to suffer with starting logstash back every time?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 25, 2019, 10:29pm UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113/2 "2019-09-25T22:29:29Z")

</div>

echo "2019-04-11 14:57:59.11" | /usr/share/logstash/bin/logstash -e 'input { stdin {} } filter { date { match =\> ["message", "yyyy-MM-dd HH:mm:ss.SS"] } }'

{  
"host" =\> "localhost",  
"@version" =\> "1",  
"@timestamp" =\> 2019-04-11T19:57:59.110Z,  
"message" =\> "2019-04-11 14:57:59.11"  
}

---

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [September 25, 2019, 10:50pm UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113/3 "2019-09-25T22:50:48Z")

</div>

I'm running with a config file (`Get-Content X | .\logstash -f ../config/logstash.conf`), but takes 62 seconds for `[2019-09-25T19:49:43,334][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified` to show up and logstash start doing it's thing.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 26, 2019, 4:45am UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113/4 "2019-09-26T04:45:00Z")

</div>

Why not read data from file as described in [this blog post](https://www.elastic.co/blog/a-practical-introduction-to-logstash)? That allows auto reload to work. With stdin I think there is no way to avoid restarting every time. Another option could be to switch to a TCP input or use a generator input.

---

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [September 26, 2019, 2:18pm UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113/5 "2019-09-26T14:18:40Z")

</div>

my scenario, at the moment, is to create a pipeline to ingest old IAS/RRAS logs, but I'm still struggling with the filters - so I need to test it over and over and over again... but each time I try, Logstash takes over a minute to start up...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 26, 2019, 2:47pm UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113/6 "2019-09-26T14:47:27Z")

</div>

The ways I suggested avoids that, assuming you are on a recent version.

---

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [September 26, 2019, 2:50pm UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113/7 "2019-09-26T14:50:42Z")

</div>

my limit version is 6.8

I've read the article you linked, but didn't understand where does it talk about a different way to ingest the content. File input won't be feasible while I'm still working on the filters, AFAIK it will read files once, and be done with them, and I need it to keep re-reading the same line to check for the desired output

---

<div class="post-metadata">

**Author:** ![simmel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simmel/32/48040_2.png) [@simmel](https://discuss.elastic.co/u/simmel)\
**Post date:** [September 27, 2019, 12:32pm UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113/8 "2019-09-27T12:32:51Z")

</div>

Using TCP input and when I've made a change to the configuration I send  
an HUP-signal to Logstash which reloads the config within seconds and  
then send the log via TCP again is how I do it (which I guess is sort of  
what Christian suggested).

I'm unsure how you'd HUP on Windows (which I assume you're using) but  
you can make Logstash poll for changes in the config, see  
[https://www.elastic.co/guide/en/logstash/6.8/reloading-config.html](https://www.elastic.co/guide/en/logstash/6.8/reloading-config.html).

BR,

- Simon

---

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [September 27, 2019, 4:34pm UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113/9 "2019-09-27T16:34:16Z")

</div>

I think I could manage to find something. But that'll have to wait for the next project (dunno when), since this one is, thankfully, over.

In case anyone want to check out, I needed to ingest some old IAS logs (not NPS format), and this is the end result =D

> <https://gist.github.com/joaociocca/f3a00b509766f5d4b2aa8aed6b6123a9>

So, for now, no more suffering waiting 62 seconds for Logstash to boot up =p

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2019, 4:34pm UTC](https://discuss.elastic.co/t/is-there-a-faster-way-to-test-logstash-configs-with-stdin/201113/10 "2019-10-25T16:34:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
