# Issue on setting up Logstash

**URL:** <https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679>\
**Category:** Logstash\
**Created:** [September 24, 2018, 1:11pm UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679 "2018-09-24T13:11:12Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![pananth](https://avatars.discourse-cdn.com/v4/letter/p/9de053/32.png) [@pananth](https://discuss.elastic.co/u/pananth)\
**Post date:** [September 24, 2018, 1:11pm UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/1 "2018-09-24T13:11:12Z")

</div>

I am facing issue on configuring Logstash, have set java\_home with Jave 1.8.0\_171 (JDK)

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0de962485f971b54538d25b7da3713e2e4160e32.png)

While running logstash -f logstash-sample.conf - throwing error as Oracle "" was unexpected at this time.

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/2/12b8f1b0149e7dbe7aea5f6c5fbf89399272db5b.png)

On other side used NSSM and installed Logstash as service installed successfully but on starting the logstash service its automatically paused and throw a popup error as below

Windows could not resume the logstach service on local Computer.  
The service did not return an error. This could be internal windows error or an internal server error.  
If the problem persists, ocntact your system administrator.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d17ecbcaa8b4a7101d4b48baa76023c3b1cbb014.png)

Please help me on fixing this.

---

<div class="post-metadata">

**Author:** ![pananth](https://avatars.discourse-cdn.com/v4/letter/p/9de053/32.png) [@pananth](https://discuss.elastic.co/u/pananth)\
**Post date:** [September 24, 2018, 1:12pm UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/2 "2018-09-24T13:12:43Z")

</div>

Note that the Oracle java path (C:\ProgramData\Oracle\Java\javapath) also pointed to the JDK 1.8.0.171.

---

<div class="post-metadata">

**Author:** ![Prakti](https://avatars.discourse-cdn.com/v4/letter/p/96bed5/32.png) [@Prakti](https://discuss.elastic.co/u/Prakti)\
**Post date:** [September 24, 2018, 1:19pm UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/3 "2018-09-24T13:19:55Z")

</div>

SInce you are running this in cmd prompt i suppose you should use the following syntax:  
logstash\bin\logstash instead of bin\>logstash

also make sure to not mess up logstaCH and logstaSH.

---

<div class="post-metadata">

**Author:** ![pananth](https://avatars.discourse-cdn.com/v4/letter/p/9de053/32.png) [@pananth](https://discuss.elastic.co/u/pananth)\
**Post date:** [September 24, 2018, 1:27pm UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/4 "2018-09-24T13:27:41Z")

</div>

Hi

It typo error using Logstash.

Sorry I am running logstash in bin folder only. still facing this issue

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 24, 2018, 2:06pm UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/5 "2018-09-24T14:06:02Z")

</div>

What does your configuration look like?

---

<div class="post-metadata">

**Author:** ![pananth](https://avatars.discourse-cdn.com/v4/letter/p/9de053/32.png) [@pananth](https://discuss.elastic.co/u/pananth)\
**Post date:** [September 24, 2018, 2:12pm UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/6 "2018-09-24T14:12:47Z")

</div>

# Sample Logstash configuration for creating a simple

# Beats -\> Logstash -\> Elasticsearch pipeline.

input { stdin { } }

filter {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
#user =\> "elastic"  
#password =\> "changeme"  
}  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 24, 2018, 2:57pm UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/7 "2018-09-24T14:57:58Z")

</div>

Why are you using the stdin input plugin?

---

<div class="post-metadata">

**Author:** ![pananth](https://avatars.discourse-cdn.com/v4/letter/p/9de053/32.png) [@pananth](https://discuss.elastic.co/u/pananth)\
**Post date:** [September 24, 2018, 3:04pm UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/8 "2018-09-24T15:04:27Z")

</div>

as new to this just starting with the sample provided, does this config file cause the issue

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 24, 2018, 3:08pm UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/9 "2018-09-24T15:08:45Z")

</div>

That is primarily used for testing, and I am not if it works when running Logstash as a service. If you are starting out, have a look at [this introductory blog post](https://www.elastic.co/blog/a-practical-introduction-to-logstash).

---

<div class="post-metadata">

**Author:** ![pananth](https://avatars.discourse-cdn.com/v4/letter/p/9de053/32.png) [@pananth](https://discuss.elastic.co/u/pananth)\
**Post date:** [September 25, 2018, 8:35am UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/10 "2018-09-25T08:35:33Z")

</div>

Hi Christian,

As specified in the blog post Practical introduction, placed test.config 6 testdata.log using nssm configured the logstash service - installed successfully but there is no output generated

Also while running logstash -f test.conf - getting same Oracle "" unexpected at this time.

Please help me to fix this issue. note that I am in initial level trying to test the log that exists in testdata.log to be display in the output file

test.conf  
input {  
file {  
path =\> ["C:\elk\logstash\testdata.log"]  
sincedb\_path =\> "/dev/nul"  
start\_position =\> "beginning"  
}  
}

filter {  
}

output {  
stdout {  
path =\> \my\_output\_text\_file

```
codec => rubydebug

```

}  
}

testdata.log  
"Hello Logstash!”

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 25, 2018, 8:38am UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/11 "2018-09-25T08:38:41Z")

</div>

While you are working with the configuration it is often easier to start and stop Logstash manually rather than running it as a service. This makes it easier to spot errors in the configuration, and it looks like yours is not valid.

> [@pananth](#):
>
> path =\> \my\_output\_text\_file

I believe this should be removed.

---

<div class="post-metadata">

**Author:** ![pananth](https://avatars.discourse-cdn.com/v4/letter/p/9de053/32.png) [@pananth](https://discuss.elastic.co/u/pananth)\
**Post date:** [September 25, 2018, 8:44am UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/12 "2018-09-25T08:44:01Z")

</div>

Eventough removed output file path I am getting the Oracle ""unexpected at this time error.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 25, 2018, 8:48am UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/13 "2018-09-25T08:48:24Z")

</div>

Please show us your config as well as the exact full error you are getting. Make sure you copy and paste and format it correctly.

I am not a Windows user, but believe you should use forward slashes in your path and replace `/dev/nul` with just `nul`.

---

<div class="post-metadata">

**Author:** ![pananth](https://avatars.discourse-cdn.com/v4/letter/p/9de053/32.png) [@pananth](https://discuss.elastic.co/u/pananth)\
**Post date:** [September 25, 2018, 8:59am UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/14 "2018-09-25T08:59:38Z")

</div>

Testdata.log  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0a0d201e9d27bb97c52edb25fdd8dd58736d48c0.png)

Test.conf  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0c41cbd35f6f1ecd3a18dc8b3a3756c500dada59.png)

Running the logstash in command prompt as  
below - getting the same error

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fb4770d07deaf65778adc8f56e6c2779ff1ab548.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 25, 2018, 9:42am UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/15 "2018-09-25T09:42:31Z")

</div>

Seems to be some issue with your Java installation, but I have never seen this error before.

---

<div class="post-metadata">

**Author:** ![pananth](https://avatars.discourse-cdn.com/v4/letter/p/9de053/32.png) [@pananth](https://discuss.elastic.co/u/pananth)\
**Post date:** [September 25, 2018, 9:44am UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/16 "2018-09-25T09:44:42Z")

</div>

yes it seems to be java issue but java - version is fine as you see above screen shot

Also I have configured Elasticsearch and Kibana in the same machine its working fine.

Tried uninstalling JDK and reinstalled no luck.

Please let me know if you have any other idea to trouble shoot this

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 25, 2018, 9:47am UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/17 "2018-09-25T09:47:40Z")

</div>

Is there not a `logstash.bat` file you should use to start it on Windows?

---

<div class="post-metadata">

**Author:** ![pananth](https://avatars.discourse-cdn.com/v4/letter/p/9de053/32.png) [@pananth](https://discuss.elastic.co/u/pananth)\
**Post date:** [September 25, 2018, 10:02am UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/18 "2018-09-25T10:02:52Z")

</div>

No its exists, if I run nssm install logstash with test.conf - installation is success but while stating the service throwing error as  
Windows could not resume the logstash service on local Computer.  
The service did not return an error. This could be internal windows error or an internal server error.  
If the problem persists, contact your system administrator.

as in the screen shot in step-1

logstash\bin folder files has logstash.bat and logstash file

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/7/2760c0ce77dac0d00d940c57a1639b99866a37f7.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2018, 10:03am UTC](https://discuss.elastic.co/t/issue-on-setting-up-logstash/149679/19 "2018-10-23T10:03:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
