# Logstash 5.4.0 not sending logs

**URL:** <https://discuss.elastic.co/t/logstash-5-4-0-not-sending-logs/86093>\
**Category:** Logstash\
**Created:** [May 17, 2017, 11:48am UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-sending-logs/86093 "2017-05-17T11:48:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [May 17, 2017, 11:48am UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-sending-logs/86093/1 "2017-05-17T11:48:18Z")

</div>

I am using a fresh install of the ELK stack 5.4.0  
Elasticsearch, Logstash, kibana with X-pack  
Now when i fire a configuration given below

```
input
{
	file{
		path => "C:\somepath\path\file.csv"
		start_position => beginning
# sincedb_path => "NUL"
		sincedb_path => "F:\somepath\testsince"
	}
}
filter {
	csv {
	columns => ["IPID",
"EVENT_ID",
"AREA_ID",
"DATE_AND_TIME","EVENT_TEXT","DATE_AND_TIME_UTC","RTU_TIME","RTU_TIME_UTC",
"COLOR",
"CRITICALITY",
"TYPE",
"VALUE",
"COMMENT_NBR",
"INDEX_NBR",
"RTU",
"IPTYPE",
"DPADR",
"NBR",
"Area_code",
"RTU_ID",
"PIPESIZE",
"B4",
"B5",
"PIS",
"DIMENSION",
"STATE_ZERO",
"STATE_ONE",
"ARCHIVE_CLASS",
"GENTIME",
"UPPER_IPID",
"PART",
"PLANT",
"IT",
"TC_ADR_ASDU",
"TC_ADR_IO",
"PROFILE_TYPE",
"TEXT",
"CLIENT",
"AREA",
"AREA_CODE",
"PVNAME",
"Connection_type",
"PRJTXT2T","PRJTXT3T","PRJTXT4T","PRJTXT5T","PRJTXT6T","PRJTXT7T","PRJTXT8T","PRJTXT9T",
"LATITUDE","LONGITUDE",
"DEC_PLACES",
"ALARM_LIMIT_LOW","ALARM_LIMIT_HIGH","WARNING_LIMIT_LOW","WARNING_LIMIT_HIGH","MIN_VALUE","MAX_VALUE"]

separator => ","

	remove_field => ["PRJTXT2T","PRJTXT3T","PRJTXT4T","PRJTXT5T","PRJTXT6T","PRJTXT7T","PRJTXT8T","PRJTXT9T"]
	convert => {"DATE_AND_TIME" => "date_time"}
	convert => {"DATE_AND_TIME_UTC" => "date_time"}
	convert => {"RTU_TIME" => "date_time"}
	convert => {"RTU_TIME_UTC" => "date_time"}
	convert => {"ALARM_LIMIT_LOW" => "float"}
	convert => {"ALARM_LIMIT_HIGH" => "float"}
	convert => {"WARNING_LIMIT_LOW" => "float"}
	convert => {"WARNING_LIMIT_HIGH" => "float"}
	convert => {"MIN_VALUE" => "float"}
	convert => {"MAX_VALUE" => "float"}
	convert => {"LATITUDE" => "float"}
	convert => {"LONGITUDE" => "float"}

	add_field => ["location","%{LATITUDE},%{LONGITUDE}"]
	convert => {"location" => "float"}
	}
}
output{
	elasticsearch {
	hosts => ["127.0.0.1:9200"]
	action => "index"	
	index => "scada2"
	}
	stdout {}
}

```

I could see the events been processed by logstash on the command line,

 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/d/dd3d3b52dd970da7c5f42204f51a76704d60d3c7.PNG)  
however there are no documents found in the ES ![](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0fa8b8a588816872c0127a3e8443b67f465e3020.PNG)

May i know what is wrong with the configuration, may be X-pack? since this was working fine without it when using 5.3.0

---

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [May 18, 2017, 4:38am UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-sending-logs/86093/2 "2017-05-18T04:38:49Z")

</div>

Was able to get this correct, credentials required in logstash configuration (output) when using with XPACK

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2017, 4:39am UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-sending-logs/86093/3 "2017-06-15T04:39:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
