# Is there a solution available for issue mentioned in "153152"?

**URL:** <https://discuss.elastic.co/t/is-there-a-solution-available-for-issue-mentioned-in-153152/164098>\
**Category:** Logstash\
**Created:** [January 14, 2019, 7:33am UTC](https://discuss.elastic.co/t/is-there-a-solution-available-for-issue-mentioned-in-153152/164098 "2019-01-14T07:33:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![girishpaik](https://avatars.discourse-cdn.com/v4/letter/g/e480ec/32.png) [@girishpaik](https://discuss.elastic.co/u/girishpaik)\
**Post date:** [January 14, 2019, 7:33am UTC](https://discuss.elastic.co/t/is-there-a-solution-available-for-issue-mentioned-in-153152/164098/1 "2019-01-14T07:33:23Z")

</div>

Hi Team,

Issue mentioned in below discussion is solved? could you let me know version? I am still seeing this issue in latest GA'ed version, i.e., 6.5.4?

> [@One or more required cgroup files or directories not found](https://discuss.elastic.co/t/one-or-more-required-cgroup-files-or-directories-not-found/153152):
>
> ENV: CentOS release 6.8 (Final) (2.6.32-642.el6.x86\_64) Logstash 6.4.2 logstash : INPUT: from kafka 6.4.2 OUTPUT: to Elastashsearch 6.4.2 There is some output to ES when I start logstash using /usr/share/logstash/bin/logstash --path.settings /etc/logstash/ -f /etc/logstash/conf.d/test.conf,but no any output after few minitues. Change to DEBUG mode,logstash log always output: [2018-10-19T17:49:59,396][DEBUG][logstash.instrument.periodicpoller.cgroup] One or more required cgroup files or d…

Thanks in advance

GPK

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 14, 2019, 10:17am UTC](https://discuss.elastic.co/t/is-there-a-solution-available-for-issue-mentioned-in-153152/164098/2 "2019-01-14T10:17:26Z")

</div>

Are you running Logstash in docker?

---

<div class="post-metadata">

**Author:** ![girishpaik](https://avatars.discourse-cdn.com/v4/letter/g/e480ec/32.png) [@girishpaik](https://discuss.elastic.co/u/girishpaik)\
**Post date:** [January 14, 2019, 10:26am UTC](https://discuss.elastic.co/t/is-there-a-solution-available-for-issue-mentioned-in-153152/164098/3 "2019-01-14T10:26:05Z")

</div>

No, its a standalone setup on windows 10.

using CLI, i am running "logstash -conf \<logstash\_extract\_dir\>\config\MyFile.conf".  
I did NOT install anything as service [ELK Stack]. Download & extract GA version and start running using windows CLI.

Same setting is working with 5.6.14/6.2.4 but issue observed in 6.5.2/6.5.4. Might be specific to windows.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 14, 2019, 10:44am UTC](https://discuss.elastic.co/t/is-there-a-solution-available-for-issue-mentioned-in-153152/164098/4 "2019-01-14T10:44:44Z")

</div>

OK.

We included some metrics collectors for docker container stats. You are seeing a debug output log message that the collector emits when it can't find the files to read - in some containers the files are in odd places so we debug log if we can't find them.

Unfortunately, we have not added the ability to disable the cgroup collectors if you know that there is no cgroup info.

The workaround is probably a good thing to know in general, make your debug logging more targeted at the area or component of interest so that the metrics collectors are not logging at DEBUG level.

Logstash has the ability to set logging levels at a finer level of granularity, i.e. you can DEBUG log the grok filter while INFO logging all else. This means that the log files contain only the debug messages you need. In addition, this can be done dynamically through the REST API or permanently in the log4j config files.

This is what I've been pasting into various support channels

* * *

The [logging API](https://www.elastic.co/guide/en/logstash/6.5/logging.html#logging) allows for different levels of logging for different components in LS.

First do `curl -XGET 'localhost:9600/_node/logging?pretty'`  
You see something like this:

```auto
{
  "host" : "Elastics-MacBook-Pro.local",
  "version" : "6.4.0",
  "http_address" : "127.0.0.1:9600",
  "id" : "8789409b-7126-4034-9347-de47e6ce12a9",
  "name" : "Elastics-MacBook-Pro.local",
  "loggers" : {
    "filewatch.discoverer" : "DEBUG",
    "filewatch.observingtail" : "DEBUG",
    "filewatch.sincedbcollection" : "DEBUG",
    "filewatch.tailmode.handlers.createinitial" : "DEBUG",
    "filewatch.tailmode.processor" : "DEBUG",
    "logstash.agent" : "DEBUG",
    "logstash.api.service" : "DEBUG",
    "logstash.codecs.json" : "DEBUG",
    ...
    "logstash.filters.date" : "DEBUG",
    "logstash.inputs.file" : "DEBUG",
    ...
    "logstash.outputs.stdout" : "DEBUG",
    "logstash.pipeline" : "DEBUG",
    ...
    "slowlog.logstash.codecs.json" : "TRACE",
    "slowlog.logstash.codecs.rubydebug" : "TRACE",
    "slowlog.logstash.filters.date" : "TRACE",
    "slowlog.logstash.inputs.file" : "TRACE",
    "slowlog.logstash.outputs.stdout" : "TRACE"
  }
}

```

* * *

Using the API  
Turn trace on:

```auto
curl -XPUT 'localhost:9600/_node/logging?pretty' -H 'Content-Type: application/json' -d'
{
    "logger.filewatch.discoverer" : "TRACE"
}
'

```

Turn trace off:

```auto
curl -XPUT 'localhost:9600/_node/logging?pretty' -H 'Content-Type: application/json' -d'
{
    "logger.filewatch.discoverer" : "WARN"
}
'

```

Or

```auto
curl -XPUT 'localhost:9600/_node/logging/reset?pretty'

```

NOTE: it might be a good idea to start LS with logging set to WARN in the logstash.yml so other logging is less verbose.

* * *

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2019, 10:44am UTC](https://discuss.elastic.co/t/is-there-a-solution-available-for-issue-mentioned-in-153152/164098/5 "2019-02-11T10:44:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
