# Issue with unintentionally becoming non\_running in Logstash management

**URL:** <https://discuss.elastic.co/t/issue-with-unintentionally-becoming-non-running-in-logstash-management/361298>\
**Category:** Logstash\
**Tags:** jdbc\
**Created:** [June 12, 2024, 5:45am UTC](https://discuss.elastic.co/t/issue-with-unintentionally-becoming-non-running-in-logstash-management/361298 "2024-06-12T05:45:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![shibadog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shibadog/32/135165_2.png) [@shibadog](https://discuss.elastic.co/u/shibadog)\
**Post date:** [June 12, 2024, 5:45am UTC](https://discuss.elastic.co/t/issue-with-unintentionally-becoming-non-running-in-logstash-management/361298/1 "2024-06-12T05:45:26Z")

</div>

Using Logstash management, I was adding pipeline settings from Kibana. Although it was working fine before, after adding a pipeline, the newly added pipeline unintentionally became non-running.

The environment is as follows:

- Elasticsearch 7.15.2 on a cluster of 5 nodes
- Logstash 8.7.0 using JDBC plugin to ingest data from a database into Elasticsearch
- All running on RHEL7
- Licensed

I aligned the versions in my local environment and conducted the verification, but the issue could not be reproduced.

```auto
2024-06-07 12:30:31 [2024-06-07T03:30:31,106][INFO][logstash.agent] Pipelines running {:count=>29, :running_pipelines=>[:".monitoring-logstash", :test01, :test02, :test03, :test04, :test05, :test06, :test07, :test08, :test09, :test10, :test11, :test12, :test13, :test14, :test15, :test16, :test17, :test18, :test19, :test20, :test21, :test22, :test23, :test24, :test26, :test27, :test28, :test29], :non_running_pipelines=>[]}

```

(Here, additional pipelines are being added to "non\_running\_pipelines" other than the intended one, and it's causing a problem.)

Here are the steps I tried to address the issue, listed in bullet points:

- Copied the non\_running pipeline and registered it with a different ID.
  - Another pipeline moved to non\_running.

- Added a simple pipeline (which just retrieves the date and outputs it to standard output) with the ID `test`.
  - Similarly, another previously running pipeline moved to non\_running.

- Made a non-impacting edit to the pipeline that moved to non\_running and saved it.
  - It became running again, but another pipeline moved to non\_running.

Although I failed to reproduce the issue, I have created a minimal environment with the same versions as the target environment and uploaded it to GitHub. Here is the link:  
[shibadog/sample-logstash-management (github.com)](https://github.com/shibadog/sample-logstash-management)

Based on the testing so far, it seems likely that we are hitting some kind of limit related to resources or configurations.

Does anyone have insights on what might be causing this? We are looking for potential candidates for investigation.

Thank you for your assistance.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 12, 2024, 6:02am UTC](https://discuss.elastic.co/t/issue-with-unintentionally-becoming-non-running-in-logstash-management/361298/2 "2024-06-12T06:02:03Z")

</div>

Welcome!

Mixing major versions is probably the cause here.

Upgrade everything to 8.14 and you should be in a much better position.

---

<div class="post-metadata">

**Author:** ![shibadog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shibadog/32/135165_2.png) [@shibadog](https://discuss.elastic.co/u/shibadog)\
**Post date:** [June 12, 2024, 6:45am UTC](https://discuss.elastic.co/t/issue-with-unintentionally-becoming-non-running-in-logstash-management/361298/3 "2024-06-12T06:45:10Z")

</div>

Thank you for your response.

I see your point.

We are currently considering an upgrade, but we cannot do it immediately. Therefore, I thought about downgrading the version of Logstash for testing.

If we manage to reproduce the issue, I will consult with you again.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 12, 2024, 7:03am UTC](https://discuss.elastic.co/t/issue-with-unintentionally-becoming-non-running-in-logstash-management/361298/4 "2024-06-12T07:03:15Z")

</div>

While you are at it, upgrade to 7.17.latest. There are plenty of bug and security fixes...

---

<div class="post-metadata">

**Author:** ![shibadog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shibadog/32/135165_2.png) [@shibadog](https://discuss.elastic.co/u/shibadog)\
**Post date:** [June 12, 2024, 7:15am UTC](https://discuss.elastic.co/t/issue-with-unintentionally-becoming-non-running-in-logstash-management/361298/5 "2024-06-12T07:15:37Z")

</div>

I see... I'll do my best. :’(

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 12, 2024, 12:04pm UTC](https://discuss.elastic.co/t/issue-with-unintentionally-becoming-non-running-in-logstash-management/361298/6 "2024-06-12T12:04:43Z")

</div>

> [@shibadog](#):
>
> - Copied the non\_running pipeline and registered it with a different ID.
> - Another pipeline moved to non\_running.
> 
> - Added a simple pipeline (which just retrieves the date and outputs it to standard output) with the ID `test`.
> - Similarly, another previously running pipeline moved to non\_running.
> 
> - Made a non-impacting edit to the pipeline that moved to non\_running and saved it.
> - It became running again, but another pipeline moved to non\_running.

What do you have in Logstash logs when these things happens?

---

<div class="post-metadata">

**Author:** ![shibadog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shibadog/32/135165_2.png) [@shibadog](https://discuss.elastic.co/u/shibadog)\
**Post date:** [June 13, 2024, 9:48am UTC](https://discuss.elastic.co/t/issue-with-unintentionally-becoming-non-running-in-logstash-management/361298/7 "2024-06-13T09:48:25Z")

</div>

Thank you for your response.

In this case, no logs are being generated.

If I had to say, the following logs are being generated, and pipelines that were not added to non\_running\_pipelines are included.

> [@shibadog](#):
>
> `2024-06-07 12:30:31 [2024-06-07T03:30:31,106][INFO][logstash.agent] Pipelines running {:count=>29, :running_pipelines=>[:".monitoring-logstash", :test01, :test02, :test03, :test04, :test05, :test06, :test07, :test08, :test09, :test10, :test11, :test12, :test13, :test14, :test15, :test16, :test17, :test18, :test19, :test20, :test21, :test22, :test23, :test24, :test26, :test27, :test28, :test29], :non_running_pipelines=>[]}`

Additionally, I have also observed messages like the following.

```auto
Metric registration error: `input_throughput` could not be registered in namespace `[:stats, :pipelines, :{pipelines that were excluded}, :flow]`

```

All of them are INFO level logs, so I believe they indicate normal operation.

---

<div class="post-metadata">

**Author:** ![shibadog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shibadog/32/135165_2.png) [@shibadog](https://discuss.elastic.co/u/shibadog)\
**Post date:** [June 18, 2024, 7:29am UTC](https://discuss.elastic.co/t/issue-with-unintentionally-becoming-non-running-in-logstash-management/361298/8 "2024-06-18T07:29:10Z")

</div>

For troubleshooting purposes, I installed version `7.15.2`, which is the same version as Elasticsearch, and deployed the same pipelines.

As a result, the issue did not occur! 🙂

As you pointed out, it seems to be an issue caused by version differences outside of the supported range... I will check the support list and update to the appropriate upper limit version (in this case, `7.17.latest`) first.

[Support Matrix | Elastic](https://www.elastic.co/support/matrix/#matrix_compatibility)

However, I am curious about the underlying reasoning behind this issue...
