# Logstash fails to fetch Configuration

**URL:** <https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915>\
**Category:** Logstash\
**Created:** [October 5, 2022, 9:57pm UTC](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915 "2022-10-05T21:57:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 5, 2022, 9:57pm UTC](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915/1 "2022-10-05T21:57:42Z")

</div>

My logstash isn't starting. When I check the logs, I see these:

```auto
Could not fetch all the sources {:exception=>Errno::EACCES, :message=>"Permission denied - /etc/logstash/conf.d/log.conf", :backtrace=>["org/jruby/RubyIO.java:1237:in `sysopen'", "org/jruby/RubyIO.java:3774:in `read'", "/usr/share/logstash/logstash-core/lib/logstash/config/source/local.rb:87:in `block in read'", "org/jruby/RubyArray.java:1821:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/config/source/local.rb:77:in `read'", "/usr/share/logstash/logstash-core/lib/logstash/config/source/local.rb:110:in `read'", "/usr/share/logstash/logstash-core/lib/logstash/config/source/local.rb:206:in `local_pipeline_configs'", "/usr/share/logstash/logstash-core/lib/logstash/config/source/multi_local.rb:44:in `block in pipeline_configs'", "org/jruby/RubyArray.java:2589:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/config/source/multi_local.rb:39:in `pipeline_configs'", "/usr/share/logstash/logstash-core/lib/logstash/config/source_loader.rb:76:in `block in fetch'", "org/jruby/RubyArray.java:2584:in `collect'", "/usr/share/logstash/logstash-core/lib/logstash/config/source_loader.rb:75:in `fetch'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:185:in `converge_state_and_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:123:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:417:in `block in execute'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}
[2022-10-05T18:37:09,241][ERROR][logstash.agent] An exception happened when converging configuration {:exception=>RuntimeError, :message=>"Could not fetch the configuration, message: Permission denied - /etc/logstash/conf.d/log.conf"}
[2022-10-05T18:38:33,527][WARN][logstash.runner] SIGTERM received. Shutting down.

```

This is my log.conf file:

```auto
input {
  beats {
    port => 5044
  }
}
filter{
  grok {
    match => { "message" => ["\[%{TIMESTAMP_ISO8601:timestamp}\]%{DATA:class} %{SPACE}%{LOGLEVEL:level} -%{GREEDYDATA:message}", "%{GREEDYDATA:message}" ] }
    overwrite => ["message"]
  }
  if "ERROR" in [message] {
    mutate { add_tag => "error" }
  }
  date {
    match => ["timestamp", "MMM dd yyyy HH:mm:ss", "MMM d yyyy HH:mm:ss", "ISO8601"]
    target => "@timestamp"
    remove_field => ["timestamp"]
  }
}
output {
  elasticsearch {
    hosts => ["${ELKIP}:9200"]
    index =>"log-%{+YYYY.MM.dd}"
  }
}

```

These are permissions:  
``  
drwxr-xr-x 2 root root conf.d  
-rw-r--r-- 1 root root jvm.options  
-rw-r--r-- 1 root root log4j2.properties  
-rw-r--r-- 1 root root logstash-sample.conf  
-rw-r--r-- 1 root root logstash.yml  
-rw-r--r-- 1 root root pipelines.yml  
-rw------- 1 root root startup.options  
-rw------- 1 root root log.conf

```auto
I have added the line sudo` chown root:root logstash.yml,` to my script, but it doesn't change anything
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 5, 2022, 10:06pm UTC](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915/2 "2022-10-05T22:06:56Z")

</div>

> [@Chma](#):
>
> `Errno::EACCES, :message=>"Permission denied - /etc/logstash/conf.d/log.conf"`

What are the permissions on that file?

---

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 5, 2022, 10:16pm UTC](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915/3 "2022-10-05T22:16:31Z")

</div>

> [@Chma](#):
>
> `-rw------- 1 root root`

-rw------- 1 root root

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 5, 2022, 10:21pm UTC](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915/4 "2022-10-05T22:21:44Z")

</div>

OK, so that is only readable by root. If you are not running as root (and you definitely should not do so) then the error is expected. Try

```
chmod o+r log.conf

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 5, 2022, 11:57pm UTC](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915/6 "2022-10-05T23:57:48Z")

</div>

Best to ask a new question about that.

---

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 6, 2022, 12:02am UTC](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915/7 "2022-10-06T00:02:41Z")

</div>

Okay, thanks. Done that.

---

<div class="post-metadata">

**Author:** ![rapking67](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@rapking67](https://discuss.elastic.co/u/rapking67)\
**Post date:** [October 6, 2022, 1:32am UTC](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915/8 "2022-10-06T01:32:40Z")

</div>

Well start with the basics, since it can't reach it. Do traceroute etc.

Your elasticsearch url is just "elasticsearch"? And it resolves without fqdn?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2022, 1:33am UTC](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915/9 "2022-11-03T01:33:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
