# Logstash Keeps Restarting

**URL:** <https://discuss.elastic.co/t/logstash-keeps-restarting/111122>\
**Category:** Logstash\
**Created:** [December 11, 2017, 2:55pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122 "2017-12-11T14:55:09Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [December 11, 2017, 2:55pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/1 "2017-12-11T14:55:09Z")

</div>

The only setting I have changed in the Logstash .yml is: log.level: debug.

Logstash keeps restarting and there is absolutely nothing in the log file (/var/log/logstash/logstash-plaing.log)

The only info I can find is in journalctl -u logstash.service. I see the following over and over again:

> Started logstash.  
> Dec 11 14:10:59 SIEM-MLS-VM-elkt logstash[5464]: Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties  
> Dec 11 14:10:59 SIEM-MLS-VM-elkt logstash[5464]: [ERROR] 2017-12-11 14:10:59.683 [Ruby-0-Thread-1: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud-0.0.23/lib/stud/task.rb:22] sourceloader - No configuration found in the configured sources.  
> Dec 11 14:10:59 SIEM-MLS-VM-elkt systemd[1]: logstash.service: Main process exited, code=exited, status=1/FAILURE  
> Dec 11 14:10:59 SIEM-MLS-VM-elkt systemd[1]: logstash.service: Unit entered failed state.  
> Dec 11 14:10:59 SIEM-MLS-VM-elkt systemd[1]: logstash.service: Failed with result 'exit-code'.  
> Dec 11 14:10:59 SIEM-MLS-VM-elkt systemd[1]: logstash.service: Service hold-off time over, scheduling restart.  
> Dec 11 14:10:59 SIEM-MLS-VM-elkt systemd[1]: Stopped logstash.

Any ideas guys?

Cheers,

George

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 11, 2017, 3:09pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/2 "2017-12-11T15:09:20Z")

</div>

Do you have any configuration files in /etc/logstash/conf.d or wherever logstash.yml points to?

---

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [December 11, 2017, 3:12pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/3 "2017-12-11T15:12:02Z")

</div>

So I tried at first with no config in the /etc/logstash/conf.d folder. Then I added the file 02-NASA-IIS.conf with the following contents:

```
input {
  beats {
    port => 5044
  }
}

filter {
                grok {
                        match => { "message" => "^%{DATA:Host}\s%{DATA:FIELD1}\s%{DATA:FIELD2}\s\[%{DATA:OrigTime}\s%{DATA:TimeOffSet}]\s\"%{WORD:Method}\s%{DATA:Query}(\s%{DATA:HTTPVersion})?\"\s%{BASE10NUM:HTTPReply}\s%{NUMBER:Bytes:int}?" }
                }
                date {
                        match => ["OrigTime", "dd/MMM/yyyy:HH:mm:ss"]
                        target => "@timestamp"
                }
}

output {
  elasticsearch {
    hosts => "localhost:9200"
    manage_template => false
    index => "filebeat-%{+YYYY.MM.dd}"
  }
}

```

Cheers,

G

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 11, 2017, 3:27pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/4 "2017-12-11T15:27:27Z")

</div>

And that helped?

---

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [December 11, 2017, 3:28pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/5 "2017-12-11T15:28:48Z")

</div>

Sorry, it had no affect, still getting constant restarts.

G

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 11, 2017, 4:08pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/6 "2017-12-11T16:08:12Z")

</div>

With the same error message? Please show the non-comment lines in logstash.yml.

---

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [December 11, 2017, 4:11pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/7 "2017-12-11T16:11:25Z")

</div>

These are the only lines that are not commented out. I had set the logging level to 'trace' I have now commented out that line as Logstash wasn't logging at all, it still doesn't seem to be.

path.config: /etc/logstash/conf.d/\*.conf  
path.data: /var/lib/logstash  
path.logs: /var/log/logstash

G

---

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [December 11, 2017, 4:18pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/8 "2017-12-11T16:18:30Z")

</div>

Okay so the logging seems to be fixed since I commented out the logging level 'trace' (I have also tried 'debug' and that broke logging as well). So my logs keep showing me this over and over again:

> [2017-12-11T16:11:45,288][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"/usr/share/logstash/modules/fb\_apache/configuration"}  
> [2017-12-11T16:11:45,307][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"/usr/share/logstash/modules/netflow/configuration"}  
> [2017-12-11T16:11:46,728][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
> [2017-12-11T16:11:48,541][INFO][logstash.config.source.local.configpathloader] No config files found in path {:path=\>"/etc/logstash/conf.d/\*.conf"}

---

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [December 11, 2017, 4:30pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/9 "2017-12-11T16:30:45Z")

</div>

Okay so I ran chmod 755 on the /etc/logstash/conf.d folder and logstash has now been up for over 7mins and seems to be fine. I then stopped Logstash and installed Xpack onto it, started Logstash again and what do you know, more restarting! So I stopped Logstash and removed Xpack and the restarting hasn't stopped.

G

---

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [December 11, 2017, 5:07pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/10 "2017-12-11T17:07:01Z")

</div>

Okay so I think I have found the actual issue here. I was using the wrong version of Java, I ran this command:

```auto
sudo apt-get install openjdk-8-jre

```

and now everything is working fine. I will report back if I face any issues.

EDIT: So upon installing XPack again I now face the issue of constant restarts.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 5:07pm UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/111122/11 "2018-01-08T17:07:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
