# LogStash Docker just stops after start

**URL:** <https://discuss.elastic.co/t/logstash-docker-just-stops-after-start/207790>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [November 13, 2019, 11:07pm UTC](https://discuss.elastic.co/t/logstash-docker-just-stops-after-start/207790 "2019-11-13T23:07:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aravindpillai](https://avatars.discourse-cdn.com/v4/letter/a/48db29/32.png) [@aravindpillai](https://discuss.elastic.co/u/aravindpillai)\
**Post date:** [November 13, 2019, 11:07pm UTC](https://discuss.elastic.co/t/logstash-docker-just-stops-after-start/207790/1 "2019-11-13T23:07:56Z")

</div>

HI

Here is a simple Docker file and configuration file for Elastic Search and Log stash. The plugin wont start

```
version: '3.2'
services:
  elasticsearch:
    image: docker.elastic.co/elasticsearch/elasticsearch:7.4.0
    container_name: elasticsearch
    environment:
      - node.name=elasticsearch
      - cluster.initial_master_nodes=elasticsearch
      - cluster.name=docker-cluster
      - bootstrap.memory_lock=true
      - "ES_JAVA_OPTS=-Xms512m -Xmx512m"
      - xpack.security.enabled=false
    ulimits:
        memlock:
          soft: -1
          hard: -1
    volumes:
      - esdata01:/Users/Assets/ELK/data
    ports:
    - 9200:9200
    - 9300:9300
    networks:
      - esnet
  logstash:
      image: docker.elastic.co/logstash/logstash:7.4.0
      container_name: logstash
      environment:
        - xpack.monitoring.enabled=false
      links:
       - elasticsearch
      volumes:
        - /Users/Assets/ELK/pipeline/:/usr/share/logstash/pipeline/
      depends_on: 
        - elasticsearch
      networks:
          - esnet 
volumes:
  esdata01:
    driver: local

networks:
  esnet

```

And the configuration file is as below

```
input { stdin { } }
output {
  elasticsearch { hosts => ["elasticsearch:9200"] }
  stdout { codec => rubydebug }
}

```

And the container just exits on start. No error message and i am pretty new to the stack so any help is appreciated.

```
logstash | [2019-11-13T22:39:50,107][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
elasticsearch | {"type": "server", "timestamp": "2019-11-13T22:39:50,113Z", "level": "INFO", "component": "o.e.c.m.MetaDataIndexTemplateService", "cluster.name": "docker-cluster", "node.name": "elasticsearch", "message": "adding template [logstash] for index patterns [logstash-*]", "cluster.uuid": "85h4uyuJQPKbTqOoflh_WA", "node.id": "qt3cb4TBR9yHUsBk3tQ8cg" }
logstash | [2019-11-13T22:39:50,198][INFO][logstash.outputs.elasticsearch] Creating rollover alias <logstash-{now/d}-000001>
elasticsearch | {"type": "server", "timestamp": "2019-11-13T22:39:50,251Z", "level": "INFO", "component": "o.e.c.m.MetaDataCreateIndexService", "cluster.name": "docker-cluster", "node.name": "elasticsearch", "message": "[logstash-2019.11.13-000001] creating index, cause [api], templates [logstash], shards [1]/[1], mappings [_doc]", "cluster.uuid": "85h4uyuJQPKbTqOoflh_WA", "node.id": "qt3cb4TBR9yHUsBk3tQ8cg" }
logstash | [2019-11-13T22:39:50,612][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
logstash | [2019-11-13T22:39:50,750][INFO][logstash.outputs.elasticsearch] Installing ILM policy {"policy"=>{"phases"=>{"hot"=>{"actions"=>{"rollover"=>{"max_size"=>"50gb", "max_age"=>"30d"}}}}}} to _ilm/policy/logstash-policy
elasticsearch | {"type": "server", "timestamp": "2019-11-13T22:39:50,771Z", "level": "INFO", "component": "o.e.x.i.a.TransportPutLifecycleAction", "cluster.name": "docker-cluster", "node.name": "elasticsearch", "message": "adding index lifecycle policy [logstash-policy]", "cluster.uuid": "85h4uyuJQPKbTqOoflh_WA", "node.id": "qt3cb4TBR9yHUsBk3tQ8cg" }
logstash | [2019-11-13T22:39:52,258][INFO][logstash.runner] Logstash shut down.
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 13, 2019, 11:13pm UTC](https://discuss.elastic.co/t/logstash-docker-just-stops-after-start/207790/2 "2019-11-13T23:13:19Z")

</div>

If a stdin {} input reaches end-of-file then it will shut down logstash.

---

<div class="post-metadata">

**Author:** ![aravindpillai](https://avatars.discourse-cdn.com/v4/letter/a/48db29/32.png) [@aravindpillai](https://discuss.elastic.co/u/aravindpillai)\
**Post date:** [November 14, 2019, 12:54am UTC](https://discuss.elastic.co/t/logstash-docker-just-stops-after-start/207790/3 "2019-11-14T00:54:33Z")

</div>

Thanks for the quick reply.

Excuse me on ignorance, i thought Stdin{} will keep the stream open for any inputs we are providing correct?. Default docker image for log stash waits for stdin{} for unlimited times and prints to output console as well. So what am i missing in my conf file. Can you please explain a little more?.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 14, 2019, 3:01pm UTC](https://discuss.elastic.co/t/logstash-docker-just-stops-after-start/207790/4 "2019-11-14T15:01:05Z")

</div>

I don't know what stdin is connected to when you start logstash like that, I am just pointing out that if stdin reads EOF then it will shut down with exactly that message.

---

<div class="post-metadata">

**Author:** ![aravindpillai](https://avatars.discourse-cdn.com/v4/letter/a/48db29/32.png) [@aravindpillai](https://discuss.elastic.co/u/aravindpillai)\
**Post date:** [November 14, 2019, 3:29pm UTC](https://discuss.elastic.co/t/logstash-docker-just-stops-after-start/207790/5 "2019-11-14T15:29:08Z")

</div>

Yes that Makes sense however the stdin name suggests it should wait for an input. Want to know why it doesnt wait and just exits when started. Mainly if there is an issue with my conf file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2019, 3:29pm UTC](https://discuss.elastic.co/t/logstash-docker-just-stops-after-start/207790/6 "2019-12-12T15:29:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
