# Logstash 5.4.0 not writing logs or opening port

**URL:** <https://discuss.elastic.co/t/logstash-5-4-0-not-writing-logs-or-opening-port/85495>\
**Category:** Logstash\
**Created:** [May 12, 2017, 1:50am UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-writing-logs-or-opening-port/85495 "2017-05-12T01:50:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Geezer](https://avatars.discourse-cdn.com/v4/letter/g/49beb7/32.png) [@Geezer](https://discuss.elastic.co/u/Geezer)\
**Post date:** [May 12, 2017, 1:50am UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-writing-logs-or-opening-port/85495/1 "2017-05-12T01:50:55Z")

</div>

Hello,

I have a new install of Logstash 5.4.0 on CentOS 7 with a single beat input and output configured.

The service starts, and sytemctl says it is running, but it won't open the TCP port, connect to RabbitMQ or write any logs. The configs files are held in /etc/logstash/conf.d:

input {  
beats {  
port =\> 5044  
tags =\> ["winlogbeat"]  
}  
}

output {  
if "winlogbeat" in [tags] {  
rabbitmq {   
key =\> "winlogbeatkey"  
exchange =\> "winlogbeatex"  
exchange\_type =\> "direct"  
user =\> "logstashuser"  
password =\> "xxxxxx"  
host =\> "127.0.0.1"  
port =\> 5672  
durable =\> true  
persistent =\> true  
}  
}  
}

I have tried starting it with debug flags but get nothing.

Can anyone suggest what's wrong?

Thank you

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 12, 2017, 3:44am UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-writing-logs-or-opening-port/85495/2 "2017-05-12T03:44:47Z")

</div>

Does [https://github.com/elastic/logstash/issues/6117](https://github.com/elastic/logstash/issues/6117) help?

---

<div class="post-metadata">

**Author:** ![Geezer](https://avatars.discourse-cdn.com/v4/letter/g/49beb7/32.png) [@Geezer](https://discuss.elastic.co/u/Geezer)\
**Post date:** [May 12, 2017, 3:58am UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-writing-logs-or-opening-port/85495/3 "2017-05-12T03:58:03Z")

</div>

Thank you for the suggestion, I will look into that.

---

<div class="post-metadata">

**Author:** ![Geezer](https://avatars.discourse-cdn.com/v4/letter/g/49beb7/32.png) [@Geezer](https://discuss.elastic.co/u/Geezer)\
**Post date:** [May 12, 2017, 2:36pm UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-writing-logs-or-opening-port/85495/4 "2017-05-12T14:36:26Z")

</div>

Managed to start it in debug mode but had to specify the path to the yml. Without doing so, I get this error:

WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
ERROR StatusLogger No log4j2 configuration file found. Using default configuration: logging only errors to the console

The logstash.yml is in /etc/logstash, but until I specified that fact with --path.settings logstash couldn't find it. Once I did, logstash loaded.

It can;t find the log4j2 file either.

Why would it not be able to find these files in the default path?

Thanks

---

<div class="post-metadata">

**Author:** ![Geezer](https://avatars.discourse-cdn.com/v4/letter/g/49beb7/32.png) [@Geezer](https://discuss.elastic.co/u/Geezer)\
**Post date:** [May 12, 2017, 5:53pm UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-writing-logs-or-opening-port/85495/5 "2017-05-12T17:53:56Z")

</div>

Further:

The service file is here: /etc/systemd/system/logstash.service

It contains the following which is all default:

[Unit]  
Description=logstash

[Service]  
Type=simple  
User=logstash  
Group=logstash  
EnvironmentFile=-/etc/default/logstash  
EnvironmentFile=-/etc/sysconfig/logstash  
ExecStart=/usr/share/logstash/bin/logstash "--path.settings" "/etc/logstash"  
Restart=always  
WorkingDirectory=/  
Nice=19  
LimitNOFILE=16384

[Install]  
WantedBy=multi-user.target

It points to an EnvironmentFile here: /etc/default/logstash

...which contains the following:

JAVACMD="/usr/bin/java"  
LS\_HOME="/usr/share/logstash"  
LS\_SETTINGS\_DIR="/etc/logstash"  
LS\_PIDFILE="/var/run/logstash.pid"  
LS\_USER="logstash"  
LS\_GROUP="logstash"  
LS\_GC\_LOG\_FILE="/var/log/logstash/gc.log"  
LS\_OPEN\_FILES="16384"  
LS\_NICE="19"  
SERVICE\_NAME="logstash"  
SERVICE\_DESCRIPTION="logstash"

So it has all the correct paths, all default, but when I start Logstash as a service it doesn't find the settings file, and hence no logging and no config file.

Starting it like this from /usr/share/logstash works:

bin/logstash --debug --path.settings /etc/logstash/

When I start it manually and specify the settings file I am doing so as root rather than the logstash user, but the /etc/logstash directory is readable by everyone

drwxrwxr-x 2 root root 71 May 12 09:42 conf.d  
-rw-r--r-- 1 root root 1738 Apr 28 14:15 jvm.options  
-rw-r--r-- 1 root root 1334 Apr 28 14:15 log4j2.properties  
-rw-r--r-- 1 root root 223 May 11 22:40 logrotate.logstash.conf  
-rw-r--r-- 1 root root 4483 May 12 13:49 logstash.yml  
-rw-r--r-- 1 root root 1659 Apr 28 14:15 startup.options

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2017, 6:06pm UTC](https://discuss.elastic.co/t/logstash-5-4-0-not-writing-logs-or-opening-port/85495/6 "2017-06-09T18:06:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
