# Logstash as a service config not working

**URL:** <https://discuss.elastic.co/t/logstash-as-a-service-config-not-working/219836>\
**Category:** Logstash\
**Created:** [February 18, 2020, 4:38pm UTC](https://discuss.elastic.co/t/logstash-as-a-service-config-not-working/219836 "2020-02-18T16:38:36Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sdkeslar](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@sdkeslar](https://discuss.elastic.co/u/sdkeslar)\
**Post date:** [February 18, 2020, 4:38pm UTC](https://discuss.elastic.co/t/logstash-as-a-service-config-not-working/219836/1 "2020-02-18T16:38:36Z")

</div>

Trying to get a new install of LogStash running as a service on Ubuntu 18.04 LTS. I can start it ok as root, but it won't start using systemctl.

/etc/systemd/system/logstash.service:

[Unit]  
Description=logstash

[Service]  
Type=simple  
User=logstash  
Group=logstash

# Load env vars from /etc/default/ and /etc/sysconfig/ if they exist.

# Prefixing the path with '-' makes it try to load, but if the file doesn't

# exist, it continues onward.

EnvironmentFile=-/etc/default/logstash  
EnvironmentFile=-/etc/sysconfig/logstash  
ExecStart=/usr/share/logstash/bin/logstash "--path.setttings=/etc/logstash/"  
Restart=always  
WorkingDirectory=/  
Nice=19  
LimitNOFILE=16384

[Install]  
WantedBy=multi-user.target

trying to use systemctl creates no entries in /var/log/logstash/logstash-plain.log, and status shows:

root@uh-es-01://usr/share/logstash# systemctl status logstash  
● logstash.service - logstash  
Loaded: loaded (/etc/systemd/system/logstash.service; enabled; vendor preset: enabled)  
Active: failed (Result: exit-code) since Tue 2020-02-18 11:23:03 EST; 13min ago  
Main PID: 1636 (code=exited, status=1/FAILURE)

Feb 18 11:23:03 uh-es-01 systemd[1]: logstash.service: Service hold-off time over, scheduling restart.  
Feb 18 11:23:03 uh-es-01 systemd[1]: logstash.service: Scheduled restart job, restart counter is at 5.  
Feb 18 11:23:03 uh-es-01 systemd[1]: Stopped logstash.  
Feb 18 11:23:03 uh-es-01 systemd[1]: logstash.service: Start request repeated too quickly.  
Feb 18 11:23:03 uh-es-01 systemd[1]: logstash.service: Failed with result 'exit-code'.  
Feb 18 11:23:03 uh-es-01 systemd[1]: Failed to start logstash.

I'm sure this is a permissions issue, but I'm stuck as to where to look....

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 19, 2020, 2:50pm UTC](https://discuss.elastic.co/t/logstash-as-a-service-config-not-working/219836/2 "2020-02-19T14:50:05Z")

</div>

Hi @sdkeslar,

sharing your Logstash conf might help 🙂

My first suspects would be log files and lock files. These files are open by the Logstash process on one of my nodes

```
root @ logstash1.example.net ~ # lsof -p 2597 | grep REG | grep .log$
java 2597 logstash 56r REG 253,0 8604637 408740 /var/dead_letter_queue/main/2777.log
java 2597 logstash 89w REG 253,0 8604637 408740 /var/dead_letter_queue/main/2777.log
java 2597 logstash 342w REG 253,0 5944830 405891 /var/log/logstash/logstash-plain.log
root @ logstash1.example.net ~ # lsof -p 2597 | grep REG | grep lock
java 2597 logstash 50wW REG 253,0 0 394130 /var/lib/logstash/.lock
java 2597 logstash 51wW REG 253,0 0 405876 /var/dead_letter_queue/main/.lock

```

So, I would check ownership of those files or other files in those folders.

---

<div class="post-metadata">

**Author:** ![sdkeslar](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@sdkeslar](https://discuss.elastic.co/u/sdkeslar)\
**Post date:** [February 20, 2020, 2:33pm UTC](https://discuss.elastic.co/t/logstash-as-a-service-config-not-working/219836/3 "2020-02-20T14:33:56Z")

</div>

logstash.conf:

input {  
udp {  
port =\> 514 ## change me to whatever you set your ASA syslog port to  
type =\> "cisco-fw"  
}  
}

filter {  
####### Cisco FW ####  
if [type] == "cisco-fw" {  
grok {  
match =\> ["message", "%{CISCO\_TAGGED\_SYSLOG} %{GREEDYDATA:cisco\_message}"]  
}

# Parse the syslog severity and facility

syslog\_pri { }

# Extract fields from the each of the detailed message types

# The patterns provided below are included in core of LogStash 1.2.0.

grok {  
match =\> [  
"cisco\_message", "%{CISCOFW106001}",  
"cisco\_message", "%{CISCOFW106006\_106007\_106010}",  
"cisco\_message", "%{CISCOFW106014}",  
"cisco\_message", "%{CISCOFW106015}",  
"cisco\_message", "%{CISCOFW106021}",  
"cisco\_message", "%{CISCOFW106023}",  
"cisco\_message", "%{CISCOFW106100}",  
"cisco\_message", "%{CISCOFW110002}",  
"cisco\_message", "%{CISCOFW302010}",  
"cisco\_message", "%{CISCOFW302013\_302014\_302015\_302016}",  
"cisco\_message", "%{CISCOFW302020\_302021}",  
"cisco\_message", "%{CISCOFW305011}",  
"cisco\_message", "%{CISCOFW313001\_313004\_313008}",  
"cisco\_message", "%{CISCOFW313005}",  
"cisco\_message", "%{CISCOFW402117}",  
"cisco\_message", "%{CISCOFW402119}",  
"cisco\_message", "%{CISCOFW419001}",  
"cisco\_message", "%{CISCOFW419002}",  
"cisco\_message", "%{CISCOFW500004}",  
"cisco\_message", "%{CISCOFW602303\_602304}",  
"cisco\_message", "%{CISCOFW710001\_710002\_710003\_710005\_710006}",  
"cisco\_message", "%{CISCOFW713172}",  
"cisco\_message", "%{CISCOFW733100}",  
"message", "%IP"  
]  
}

geoip {  
source =\> "src\_ip"  
}

# Parse the date

date {  
match =\> ["timestamp",  
"MMM dd HH:mm:ss",  
"MMM d HH:mm:ss",  
"MMM dd yyyy HH:mm:ss",  
"MMM d yyyy HH:mm:ss"  
]  
}  
}

###### End of Cisco FW

}

output {

# stdout {

#codec =\> json  
#}

elasticsearch {  
ssl =\> true  
hosts =\> ["[https://10.101.100.93:9200](https://10.101.100.93:9200)"] # change me to the IP of your elasticsearch server  
user =\> elastic  
password =\> xxxxxxxxxxxxxxxxxxxxxxxx  
cacert =\> "/etc/elasticsearch/certs/ca.crt"  
}  
}

---

<div class="post-metadata">

**Author:** ![sdkeslar](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@sdkeslar](https://discuss.elastic.co/u/sdkeslar)\
**Post date:** [February 20, 2020, 2:37pm UTC](https://discuss.elastic.co/t/logstash-as-a-service-config-not-working/219836/4 "2020-02-20T14:37:23Z")

</div>

I don't have /var/dead\_letter\_queue, but /var/log/logstash and /var/lib/logstash are both owned by logstash, and that's the user and group in the unit file:

[Unit]  
Description=logstash

[Service]  
Type=simple  
User=logstash  
Group=logstash

# Load env vars from /etc/default/ and /etc/sysconfig/ if they exist.

# Prefixing the path with '-' makes it try to load, but if the file doesn't

# exist, it continues onward.

EnvironmentFile=-/etc/default/logstash  
EnvironmentFile=-/etc/sysconfig/logstash  
ExecStart=/usr/share/logstash/bin/logstash "--path.setttings=/etc/logstash/"  
Restart=always  
WorkingDirectory=/  
Nice=19  
LimitNOFILE=16384

[Install]  
WantedBy=multi-user.target

/etc/logstash and /usr/share/logstash are both owned by logstash as well....

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 20, 2020, 2:40pm UTC](https://discuss.elastic.co/t/logstash-as-a-service-config-not-working/219836/5 "2020-02-20T14:40:29Z")

</div>

Hi @sdkeslar,

could you please use _Preformated text_ for the config. It is `</>` from the text formatting menu.

---

<div class="post-metadata">

**Author:** ![sdkeslar](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@sdkeslar](https://discuss.elastic.co/u/sdkeslar)\
**Post date:** [February 20, 2020, 4:21pm UTC](https://discuss.elastic.co/t/logstash-as-a-service-config-not-working/219836/6 "2020-02-20T16:21:41Z")

</div>

sorry..

```
[Unit]
Description=logstash

[Service]
Type=simple
User=logstash
Group=logstash
# Load env vars from /etc/default/ and /etc/sysconfig/ if they exist.
# Prefixing the path with '-' makes it try to load, but if the file doesn't
# exist, it continues onward.
EnvironmentFile=-/etc/default/logstash
EnvironmentFile=-/etc/sysconfig/logstash
ExecStart=/usr/share/logstash/bin/logstash "--path.settings" "/etc/logstash"
Restart=always
WorkingDirectory=/
Nice=19
LimitNOFILE=16384

[Install]
WantedBy=multi-user.target

input {
 udp { 
 port => 514 ## change me to whatever you set your ASA syslog port to
 type => "cisco-fw"
 }
}

filter {
 ####### Cisco FW ####
 if [type] == "cisco-fw" {
 grok {
 match => ["message", "%{CISCO_TAGGED_SYSLOG} %{GREEDYDATA:cisco_message}"]
 }
 # Parse the syslog severity and facility
 syslog_pri { }

 # Extract fields from the each of the detailed message types
 # The patterns provided below are included in core of LogStash 1.2.0.
 grok {
 match => [
 "cisco_message", "%{CISCOFW106001}",
 "cisco_message", "%{CISCOFW106006_106007_106010}",
 "cisco_message", "%{CISCOFW106014}",
 "cisco_message", "%{CISCOFW106015}",
 "cisco_message", "%{CISCOFW106021}",
 "cisco_message", "%{CISCOFW106023}",
 "cisco_message", "%{CISCOFW106100}",
 "cisco_message", "%{CISCOFW110002}",
 "cisco_message", "%{CISCOFW302010}",
 "cisco_message", "%{CISCOFW302013_302014_302015_302016}",
 "cisco_message", "%{CISCOFW302020_302021}",
 "cisco_message", "%{CISCOFW305011}",
 "cisco_message", "%{CISCOFW313001_313004_313008}",
 "cisco_message", "%{CISCOFW313005}",
 "cisco_message", "%{CISCOFW402117}",
 "cisco_message", "%{CISCOFW402119}",
 "cisco_message", "%{CISCOFW419001}",
 "cisco_message", "%{CISCOFW419002}",
 "cisco_message", "%{CISCOFW500004}",
 "cisco_message", "%{CISCOFW602303_602304}",
 "cisco_message", "%{CISCOFW710001_710002_710003_710005_710006}",
 "cisco_message", "%{CISCOFW713172}",
 "cisco_message", "%{CISCOFW733100}",
 "message", "%IP"
 ]
 }

geoip {
source => "src_ip" 
}

 # Parse the date
 date {
 match => ["timestamp",
 "MMM dd HH:mm:ss",
 "MMM d HH:mm:ss",
 "MMM dd yyyy HH:mm:ss",
 "MMM d yyyy HH:mm:ss"
 ]
 }
 }
 ###### End of Cisco FW #######
}

output {
# stdout { 
#codec => json
#}

 elasticsearch {
 ssl => true
 hosts => ["https://10.101.100.93:9200"] # change me to the IP of your elasticsearch server
 user => elastic
 password => xxxxxxxxxxxxxxxxxxxxxxxxx
 cacert => "/etc/elasticsearch/certs/ca.crt" 
 }
}
```

---

<div class="post-metadata">

**Author:** ![sdkeslar](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@sdkeslar](https://discuss.elastic.co/u/sdkeslar)\
**Post date:** [February 20, 2020, 4:47pm UTC](https://discuss.elastic.co/t/logstash-as-a-service-config-not-working/219836/7 "2020-02-20T16:47:28Z")

</div>

AHA ! found it. Had to explicitly specify JAVA\_HOME in /etc/default/logstash. Now just need to get ufw to redirect the incoming from 514 to another high port since I'm not running LS as root.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2020, 4:47pm UTC](https://discuss.elastic.co/t/logstash-as-a-service-config-not-working/219836/8 "2020-03-19T16:47:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
