# Logstash Gone Wrong After force shutdown

**URL:** <https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867>\
**Category:** Logstash\
**Created:** [January 26, 2024, 9:25am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867 "2024-01-26T09:25:14Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![akrog79](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Post date:** [January 26, 2024, 9:25am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/1 "2024-01-26T09:25:14Z")

</div>

I have logstash installed as a service on a machine with Logstash+Kibana+Elastic.

My logstash was updated, so its seems that doesn't shutdown properly and now show an error with a pipeline:

```auto
Jan 26 10:19:56 esearch logstash[29197]: [2024-01-26T10:19:56,748][INFO][logstash.outputs.elasticsearch][pipeline][dec4e13358daa92f56dcbdf7685e6d1c745c7be9f58d718cb6dda6176d841907] Aborting the batch due to shutdown request while waiting for connections to become live
Jan 26 10:19:56 esearch logstash[29197]: [2024-01-26T10:19:56,758][INFO][org.logstash.execution.WorkerLoop][pipeline] Received signal to abort processing current batch. Terminating pipeline worker [pipeline]>worker5

```

I only want that pipeline start and ingest data. How can I solve it?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 26, 2024, 12:17pm UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/2 "2024-01-26T12:17:25Z")

</div>

Hello,

There are no errors in the logs that you shared, both are INFO logs, it is not clear what is the issue.

Have you tried to restart your logstash service?

---

<div class="post-metadata">

**Author:** ![akrog79](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Post date:** [January 26, 2024, 12:44pm UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/3 "2024-01-26T12:44:02Z")

</div>

Yes, I tried to restart logstash service but doesn't solve the problem, returns the same log.

The log show that the pipeline is terminated, this is an error, no?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 26, 2024, 12:50pm UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/4 "2024-01-26T12:50:19Z")

</div>

> [@akrog79](#):
>
> The log show that the pipeline is terminated, this is an error, no?

No, errors are logged as ERROR, this is an INFO log.

This is a message saying that a shutdown for your logstash was requested.

What was the version you are using and what is the updated version? How you updated it?

Also, what else do you have in the logs?

Have you tried to stop the service and then start again, not just a restart command?

---

<div class="post-metadata">

**Author:** ![akrog79](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Post date:** [January 26, 2024, 1:43pm UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/5 "2024-01-26T13:43:30Z")

</div>

Yes, I tried to stop and start service, made a complete machine reboot...

I upgrade to 8.12 from 8.11 via zypper update.

How can I check more logs? logstash-plain.log show the same logs that I share with you.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 26, 2024, 7:19pm UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/6 "2024-01-26T19:19:38Z")

</div>

Check this [topic](https://discuss.elastic.co/t/logstash-starts-but-doesn-t-do-anything/291637), maaaaybe data has been locked.

I'm suggest to check ES, reason: _[logstash.outputs.elasticsearch][pipeline][dec4e13358daa92f56dcbdf7685e6d1c745c7be9f58d718cb6dda6176d841907] Aborting the batch due to shutdown request while waiting for connections to become live_

---

<div class="post-metadata">

**Author:** ![akrog79](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Post date:** [January 29, 2024, 8:53am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/7 "2024-01-29T08:53:52Z")

</div>

not work deleting .lock file 😭

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 29, 2024, 9:22am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/8 "2024-01-29T09:22:46Z")

</div>

Have you restarted LS the service?

Have you check ES, does it work from LS host?

---

<div class="post-metadata">

**Author:** ![akrog79](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Post date:** [January 29, 2024, 9:42am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/9 "2024-01-29T09:42:40Z")

</div>

No... Can you explain me how I should do it?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 29, 2024, 10:05am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/10 "2024-01-29T10:05:06Z")

</div>

LS: systemcl restart logstash

ES:

1. Test by curl:  
`curl -u user:pass -v https://eshost:9200/_cat/health?v=true`

2. Check ES log " /var/log/elasticsearch/"

---

<div class="post-metadata">

**Author:** ![Ritikapawar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ritikapawar/32/98580_2.png) [@Ritikapawar](https://discuss.elastic.co/u/Ritikapawar)\
**Post date:** [January 29, 2024, 10:29am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/11 "2024-01-29T10:29:57Z")

</div>

If systemctl restart logstash is not working you might need to kill the whole process follow the document [Shutting Down Logstash | Logstash Reference [8.12] | Elastic](https://www.elastic.co/guide/en/logstash/current/shutdown.html#:~:text=To%20enable%20Logstash%20to%20forcibly,flag%20when%20you%20start%20Logstash).  
and also check the status of elasticsearch

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 29, 2024, 11:43am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/12 "2024-01-29T11:43:12Z")

</div>

If he had restarted LS, should be normally terminated. However it's good to check what Ritikapawar suggested.  
systemctl stop logstash  
ps aux | grep logstash

---

<div class="post-metadata">

**Author:** ![akrog79](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Post date:** [January 31, 2024, 8:37am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/13 "2024-01-31T08:37:15Z")

</div>

I see a new type of error

`Failed to install template {:message=>"Failed to load template file '/etc/logstash/elastic-fortigate-template.json': Unrecognized token 'te': was expecting (JSON String, Number, Array, Object or token 'null', 'true' or 'false')\n at [Source: (byte[])\"te\": \"fortigate*\",\n \"settings\": {\n \"index.refresh_interval\": \"5s\",\n \"number_of_shards\" : 1,\n \"number_of_replicas\" : 0\n },\n \"mappings\": {\n \"fortigate\": {\n \"dynamic_templates\": [\n {\n \"notanalyzed\": {\n \"match\": \"*\",\n \"match_mapping_type\": \"string\",\n \"mapping\": {\n \"type\": \"string\",\n \"index\": \"not_analyzed\",\n \"doc_values\": \"true\"\n }\n }\n }\n],\n \"properties\": \"[truncated 7532 bytes]; line: 1, column: 4]", :exception=>LogStash::ConfigurationError, :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-output-elasticsearch-11.22.2-java/lib/logstash/outputs/elasticsearch/template_manager.rb:106:in`read\_template\_file'", "/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-output-elasticsearch-11.22.2-java/lib/logstash/outputs/elasticsearch/template\_manager.rb:23:in `install_template'", "/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-output-elasticsearch-11.22.2-java/lib/logstash/outputs/elasticsearch.rb:663:in `install\_template'", "/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-output-elasticsearch-11.22.2-java/lib/logstash/outputs/elasticsearch.rb:371:in `finish_register'", "/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-output-elasticsearch-11.22.2-java/lib/logstash/outputs/elasticsearch.rb:328:in `block in register'", "/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-output-elasticsearch-11.22.2-java/lib/logstash/plugin\_mixins/elasticsearch/common.rb:172:in `block in after\_successful\_connection'"]}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2024, 8:37am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867/14 "2024-02-28T08:37:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
