# Logstash is stuck?

**URL:** <https://discuss.elastic.co/t/logstash-is-stuck/141571>\
**Category:** Logstash\
**Created:** [July 25, 2018, 12:48pm UTC](https://discuss.elastic.co/t/logstash-is-stuck/141571 "2018-07-25T12:48:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![emanresu](https://avatars.discourse-cdn.com/v4/letter/e/9d8465/32.png) [@emanresu](https://discuss.elastic.co/u/emanresu)\
**Post date:** [July 25, 2018, 12:48pm UTC](https://discuss.elastic.co/t/logstash-is-stuck/141571/1 "2018-07-25T12:48:21Z")

</div>

I'd like to load a csv into Elastic using Logstash. This is the output of my run:

/ C:\Users...\Documents\logstash-6.3.1\logstash-6.3.1\bin\>logstash -f logstash\_rplim3.config  
Sending Logstash's logs to C:/Users/.../Documents/logstash-6.3.1/logstash-6.3.1/logs which is now configured via log4j2.properties  
[2018-07-25T08:28:02,832][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-07-25T08:28:03,382][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.3.1"}  
[2018-07-25T08:28:07,693][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pip  
[2018-07-25T08:28:08,135][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}  
[2018-07-25T08:28:08,146][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>ht  
[2018-07-25T08:28:08,383][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2018-07-25T08:28:08,457][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2018-07-25T08:28:08,462][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the doc  
[2018-07-25T08:28:08,483][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost](https://localhost)  
[2018-07-25T08:28:08,498][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2018-07-25T08:28:08,520][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>600  
5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text  
tch"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}],  
}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>  
loat"}}}}}}}}  
[2018-07-25T08:28:09,228][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x652ab12d run\>"}  
[2018-07-25T08:28:09,288][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>[]}  
[2018-07-25T08:28:09,605][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600} /

This is top 3 lines of my csv:

/ "entity\_name","timestamp\_utc","headline","source\_name","provider\_id"  
"JPMorgan Chase & Co.","2018-07-12 10:03:56","Analyst at Peel Hunt Maintains Premier Oil PLC (LON:PMO)Stock Rating as a 'Buy'","Bibey Post","MRVR"  
"Fifth Third Bancorp","2018-07-12 10:03:56","Analyst at Peel Hunt Maintains Premier Oil PLC (LON:PMO)Stock Rating as a 'Buy'","Bibey Post","MRVR" /

This is my config:

/input {  
file {  
path =\> "C:\Users...\Documents\rplim.csv"  
start\_position =\> "beginning"  
}  
}  
filter {  
csv {  
separator =\> ","  
#quote\_char =\> """  
columns =\> ["entity\_name", "timestamp\_utc", "headline", "source\_name","provider\_id"]  
}  
date {  
match =\> ["timestamp\_utc", "YYYY-MM-dd HH:mm:ss"]  
}  
}  
output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "rplim3"  
}  
} /  
What am I doing wrong? It looks like Logstash is stuck or waiting?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 25, 2018, 1:06pm UTC](https://discuss.elastic.co/t/logstash-is-stuck/141571/2 "2018-07-25T13:06:43Z")

</div>

A file input is like "tail -f". It waits forever for new lines to get appended to the file. This looks normal to me.

---

<div class="post-metadata">

**Author:** ![emanresu](https://avatars.discourse-cdn.com/v4/letter/e/9d8465/32.png) [@emanresu](https://discuss.elastic.co/u/emanresu)\
**Post date:** [July 25, 2018, 1:16pm UTC](https://discuss.elastic.co/t/logstash-is-stuck/141571/3 "2018-07-25T13:16:30Z")

</div>

Thank you Badger. I was about to say, do I need to use this flag then?

C:\Users...\Documents\logstash-6.3.1\logstash-6.3.1\bin\>logstash -f logstash\_rplim3.config --config.reload.automatic

---

<div class="post-metadata">

**Author:** ![emanresu](https://avatars.discourse-cdn.com/v4/letter/e/9d8465/32.png) [@emanresu](https://discuss.elastic.co/u/emanresu)\
**Post date:** [July 25, 2018, 1:19pm UTC](https://discuss.elastic.co/t/logstash-is-stuck/141571/4 "2018-07-25T13:19:14Z")

</div>

I don't understand "...NOTE: Use SIGHUP to manually reload the config. The default is false." said about the auto reload flag. Please explain how to manually reload the config?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 25, 2018, 2:41pm UTC](https://discuss.elastic.co/t/logstash-is-stuck/141571/5 "2018-07-25T14:41:26Z")

</div>

SIGHUP is UNIX specific, there is no Windows equivalent that I know of. On Windows either use -r to automatically reload when the config changes, or restart logstash every time you change the configuration (which is expensive).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2018, 2:41pm UTC](https://discuss.elastic.co/t/logstash-is-stuck/141571/6 "2018-08-22T14:41:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
