# Logstash Config Error-JAVA

**URL:** <https://discuss.elastic.co/t/logstash-config-error-java/125546>\
**Category:** Logstash\
**Created:** [March 26, 2018, 5:47am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546 "2018-03-26T05:47:41Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [March 26, 2018, 5:47am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/1 "2018-03-26T05:47:41Z")

</div>

i have performing basic setup of logstash getting JAVA error. not able to complete the config test.

Error:  
ERROR: Failed to load settings file from "path.settings". Aborting... path.setting=/etc/logstash/logstash.yml, exception=Java::JavaLang::RuntimeException, message=\>Unhandled IOException: java.io.IOException: unhandled errno: Not a directory  
[ERROR] 2018-03-26 01:42:49.137 [main] Logstash - java.lang.IllegalStateException: org.jruby.exceptions.RaiseException: (SystemExit) exit

This is my startup.config file for logstash

# Override Java location

#JAVACMD=/usr/lib/jvm/java

JAVA\_HOME="/usr/lib/jvm/jre-1.8.0"

# Set a home directory

LS\_HOME=/etc/logstash

# logstash settings directory, the path which contains logstash.yml

LS\_SETTINGS\_DIR=/etc/logstash

# Arguments to pass to logstash

LS\_OPTS="--path.settings ${LS\_SETTINGS\_DIR}"

# Arguments to pass to java

LS\_JAVA\_OPTS=""

# pidfiles aren't used the same way for upstart and systemd; this is for sysv users.

LS\_PIDFILE=/var/run/logstash.pid

# user and group id to be invoked as

LS\_USER=logstash  
LS\_GROUP=logstash

# Enable GC logging by uncommenting the appropriate lines in the GC logging

# section in jvm.options

LS\_GC\_LOG\_FILE=/var/log/logstash/gc.log

# Open file limit

LS\_OPEN\_FILES=16384

# Nice level

LS\_NICE=19  
"startup.options" 55L, 1696C

---

<div class="post-metadata">

**Author:** ![Faktu4noCaM](https://avatars.discourse-cdn.com/v4/letter/f/71c47a/32.png) [@Faktu4noCaM](https://discuss.elastic.co/u/Faktu4noCaM)\
**Post date:** [March 26, 2018, 6:27am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/2 "2018-03-26T06:27:11Z")

</div>

you set the wrong config file for parameter path.setting!

In that param you need to set input\output config for logstash

path.setting =/etc/logstash/conf.d/\*.conf

and create in folder /etc/logstash/conf.d/ file logstash.conf with input\output config!

logstash.yml sets for logstash in 2 ways:

1. as a parameter commandline  
[https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html#command-line-flags](https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html#command-line-flags)

2. as a variable in startup.options file

---

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [March 26, 2018, 6:42am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/3 "2018-03-26T06:42:10Z")

</div>

> [@Nagu\_R\_Pujari](#):
>
> Arguments to pass to logstash  
> LS\_OPTS="--path.settings ${LS\_SETTINGS\_DIR}"

do you mean .

i have to provide the logstash.config file path here

Arguments to pass to logstash

LS\_OPTS="--path.settings ${LS\_SETTINGS\_DIR}"

because i have already created the conf.d folder and the .conf file is available in the folder  
it works fine when i run the command /bin/logstash -f /etc/logstash/conf.d/logstash.conf

but logstash does not listen on port 5044 . so i looked at this error when i ran the command /usr/share/logstash/bin/logstash --path.settings /etc/logstash/logstash.yml -t

---

<div class="post-metadata">

**Author:** ![Faktu4noCaM](https://avatars.discourse-cdn.com/v4/letter/f/71c47a/32.png) [@Faktu4noCaM](https://discuss.elastic.co/u/Faktu4noCaM)\
**Post date:** [March 26, 2018, 6:52am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/4 "2018-03-26T06:52:32Z")

</div>

> [@Nagu\_R\_Pujari](#):
>
> /etc/logstash/conf.d/logstash.conf

check rights for this config file with command ls -lh . -rw-rw---- for user logstash from group logstash.  
(chown and chmod 660)  
In some cases logstash cant read this file and goes down with errors

---

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [March 26, 2018, 7:06am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/5 "2018-03-26T07:06:51Z")

</div>

yea this is done. but i am not able to see logstash listening at 5044 port number.  
any checks ???

---

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [March 26, 2018, 7:24am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/6 "2018-03-26T07:24:47Z")

</div>

i have tried alot making this logstash up . looking at basic structure to collect var log files from some 200 linux box machines

---

<div class="post-metadata">

**Author:** ![Faktu4noCaM](https://avatars.discourse-cdn.com/v4/letter/f/71c47a/32.png) [@Faktu4noCaM](https://discuss.elastic.co/u/Faktu4noCaM)\
**Post date:** [March 26, 2018, 10:01am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/7 "2018-03-26T10:01:40Z")

</div>

show your input and output logstash config, and show logstash log. If there any error on logstash start - it will be there.

for example i use winlogbeat and meticbeat for input, so i use:

> **logstash.conf**
>
> input {  
> beats {  
> port =\> 5044  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> ["xx.xx.xx.xx:9200"]  
> sniffing =\> true  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> }  
> }

so, after restart logstash service, if everything configured right, i use netstat -tulpn and see that  
tcp6 0 0 :::5044 :::\* LISTEN  
340/java

---

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [March 28, 2018, 8:54am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/8 "2018-03-28T08:54:52Z")

</div>

can i use filebeat instead of metric beat ?  
i want to basically capture the syslogs and auth.log files details from all 200 machines

---

<div class="post-metadata">

**Author:** ![Faktu4noCaM](https://avatars.discourse-cdn.com/v4/letter/f/71c47a/32.png) [@Faktu4noCaM](https://discuss.elastic.co/u/Faktu4noCaM)\
**Post date:** [March 29, 2018, 6:01am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/9 "2018-03-29T06:01:40Z")

</div>

metricbeat is gathering system info about CPU, RAM, HDD, LAN and etc usage, and processes on PC. It doesnt collect or send any logs.  
WInlogbeat collects and sends windows system logs (application, security, system, setup or others)  
So, if you want to collect Windows syslogs - better use Winlogbeat (because it has filters and thin configuration).  
If you need some other logs from different apps - use Filebeat - it was made for it.

---

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [April 9, 2018, 7:34am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/10 "2018-04-09T07:34:39Z")

</div>

thanks for the info . how do i connect to elastic search cloud setup using local logstash server

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2018, 7:34am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/11 "2018-05-07T07:34:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![insuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/insuk/32/29396_2.png) [@insuk](https://discuss.elastic.co/u/insuk)\
**Post date:** [August 3, 2021, 3:24am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546/12 "2021-08-03T03:24:15Z")

</div>

> [@Nagu\_R\_Pujari](#):
>
> setup using local logstash server

> **[Sending data to Elastic Cloud (hosted Elasticsearch Service) | Logstash...](https://www.elastic.co/guide/en/logstash/current/connecting-to-cloud.html)**
