# Logstash is creating a directory literally called ${sys:ls.logs}

**URL:** <https://discuss.elastic.co/t/logstash-is-creating-a-directory-literally-called-sys-ls-logs/100126>\
**Category:** Logstash\
**Created:** [September 11, 2017, 8:03pm UTC](https://discuss.elastic.co/t/logstash-is-creating-a-directory-literally-called-sys-ls-logs/100126 "2017-09-11T20:03:01Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 11, 2017, 8:03pm UTC](https://discuss.elastic.co/t/logstash-is-creating-a-directory-literally-called-sys-ls-logs/100126/1 "2017-09-11T20:03:02Z")

</div>

When I run logstash 5.5.1 I am used to getting an error

> ERROR StatusLogger No log4j2 configuration file found. Using default configuration: logging only errors to the console.

Followed by the message

> Sending Logstash's logs to /opt/applications/logstash/logs/ls-part1 which is now configured via log4j2.properties

I believe this is fixed in today's 5.6 release. There is another issue I have. If I run /usr/share/logstash/bin/logstash from the directory that I pass it as --path.settings then instead of that first error I get

> ERROR Unable to locate appender "${sys:ls.log.format}\_rolling" for logger config "root"

and it creates this directory:

> drwxr-xr-x 2 root root 4096 Sep 11 16:00 ${sys:ls.logs}/

Is this also fixed?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 12, 2017, 1:33am UTC](https://discuss.elastic.co/t/logstash-is-creating-a-directory-literally-called-sys-ls-logs/100126/2 "2017-09-12T01:33:14Z")

</div>

> [@Badger](#):
>
> If I run /usr/share/logstash/bin/logstash from the directory that I pass it as --path.settings then instead of that first error I get

Please provide the full command you are running.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 12, 2017, 12:59pm UTC](https://discuss.elastic.co/t/logstash-is-creating-a-directory-literally-called-sys-ls-logs/100126/3 "2017-09-12T12:59:49Z")

</div>

> /usr/share/logstash/bin/logstash -f /etc/logstash/conf.HelioWebEvents/ --path.settings=/etc/logstash --path.data=/tmp/data.HelioWeb

The non-comment lines in logstash.yml are

> path.data: /opt/applications/logstash/logs/loads/data  
> path.config: /etc/logstash/conf.d  
> path.logs: /opt/applications/logstash/logs/loads

The log4j2.properties is unmodified and does reference

> appender.json\_rolling.fileName = ${sys:ls.logs}/logstash-${sys:ls.log.format}.log  
> and  
> rootLogger.appenderRef.rolling.ref = ${sys:ls.log.format}\_rolling

Run from /etc/logstash I get the second error, from anywhere else the first.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 20, 2017, 4:37pm UTC](https://discuss.elastic.co/t/logstash-is-creating-a-directory-literally-called-sys-ls-logs/100126/4 "2017-09-20T16:37:06Z")

</div>

The issue exists in 5.6 too.

---

<div class="post-metadata">

**Author:** ![ppuschmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppuschmann/32/146751_2.png) [@ppuschmann](https://discuss.elastic.co/u/ppuschmann)\
**Post date:** [October 6, 2017, 2:14pm UTC](https://discuss.elastic.co/t/logstash-is-creating-a-directory-literally-called-sys-ls-logs/100126/5 "2017-10-06T14:14:09Z")

</div>

With Logstash 5.6.2:

```
sudo -Hu logstash /usr/share/logstash/bin/logstash -f /etc/logstash/ -t --path.settings /etc/logstash

```

creates a longer stacktrace and:

```
2017-10-06 14:12:56,072 main ERROR Null object returned for RollingFile in Appenders.
2017-10-06 14:12:56,073 main ERROR Null object returned for RollingFile in Appenders.
2017-10-06 14:12:56,074 main ERROR Unable to locate appender "${sys:ls.log.format}_rolling" for logger config "root"
Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties

```

and creates the mentioned file in `/etc/logstash`

---

<div class="post-metadata">

**Author:** ![r72cccp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/r72cccp/32/22864_2.png) [@r72cccp](https://discuss.elastic.co/u/r72cccp)\
**Post date:** [October 8, 2017, 9:42am UTC](https://discuss.elastic.co/t/logstash-is-creating-a-directory-literally-called-sys-ls-logs/100126/6 "2017-10-08T09:42:29Z")

</div>

This is actually for me  
i'm on 5.6.2 version now.

---

<div class="post-metadata">

**Author:** ![AndrewMcQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewmcq/32/23131_2.png) [@AndrewMcQ](https://discuss.elastic.co/u/AndrewMcQ)\
**Post date:** [November 1, 2017, 7:26pm UTC](https://discuss.elastic.co/t/logstash-is-creating-a-directory-literally-called-sys-ls-logs/100126/7 "2017-11-01T19:26:15Z")

</div>

Wanted to chime in and state that we're seeing this issue as well. Haven't been able to nail it down to the exact cause, but it's creating quite a messy file system for us.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2017, 7:26pm UTC](https://discuss.elastic.co/t/logstash-is-creating-a-directory-literally-called-sys-ls-logs/100126/8 "2017-11-29T19:26:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
