# Logstash Keystore While Running As A Service

**URL:** <https://discuss.elastic.co/t/logstash-keystore-while-running-as-a-service/277262>\
**Category:** Logstash\
**Created:** [June 28, 2021, 6:22pm UTC](https://discuss.elastic.co/t/logstash-keystore-while-running-as-a-service/277262 "2021-06-28T18:22:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [June 28, 2021, 6:22pm UTC](https://discuss.elastic.co/t/logstash-keystore-while-running-as-a-service/277262/1 "2021-06-28T18:22:15Z")

</div>

Hello Team, I have created Logstash Keystore with command `sudo -E /usr/share/logstash/bin/logstash-keystore --path.settings /etc/logstash create` but while running `/usr/share/logstash/bin/logstash-keystore list` it is throwing `Can not find Logstash keystore at /usr/share/logstash/config/logstash.keystore. Please verify this file exists and is a valid Logstash keystore.` I am a bit confused by the documentation given and not sure what to do! any help would be highly appreciated

Questions :

1. Do I need to pass `--path.settings` flag every time interacting with keystore?

2. What are the recommendations to interact with keystore smoothly as possible?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 28, 2021, 7:08pm UTC](https://discuss.elastic.co/t/logstash-keystore-while-running-as-a-service/277262/2 "2021-06-28T19:08:47Z")

</div>

> [@ankitdevnalkar](#):
>
> Do I need to pass `--path.settings` flag every time interacting with keystore?

If you want a non-default value for path.settings then you need to set it every time, yes. That includes setting it on the command that the service manager uses to start logstash.

The default depends on the way logstash was installed. For RPM packages it is /etc/logstash, for Docker images it is /usr/share/logstash/config, etc.

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [June 29, 2021, 4:11pm UTC](https://discuss.elastic.co/t/logstash-keystore-while-running-as-a-service/277262/3 "2021-06-29T16:11:36Z")

</div>

I installed Logstsh via `apt-get` package.

> [@Badger](#):
>
> That includes setting it on the command that the service manager uses to start Logstash.

You mean, I will need to run with the following command?  
`service logstash start --path.settings /etc/logstash`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 29, 2021, 4:20pm UTC](https://discuss.elastic.co/t/logstash-keystore-while-running-as-a-service/277262/4 "2021-06-29T16:20:46Z")

</div>

> [@ankitdevnalkar](#):
>
> You mean, I will need to run with the following command?  
> `service logstash start --path.settings /etc/logstash`

No, I mean that the logstash init script (probably in /etc/init.d if you are running the sysvinit-utils service command) should include --path.settings when it invokes logstash.

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [June 30, 2021, 3:09pm UTC](https://discuss.elastic.co/t/logstash-keystore-while-running-as-a-service/277262/5 "2021-06-30T15:09:08Z")

</div>

I am running Logstash as `systemd` , I can see `path.settings` available in configuration file :

 ![Selection_200](https://us1.discourse-cdn.com/elastic/original/3X/5/c/5cfe210d1ffcae79e126e5c894fb0206f649b834.png)

However, when I run `/usr/share/logstash/bin/logstash-keystore list`, it is giving me following error :

```auto
OpenJDK 64-Bit Server VM warning: Option UseConcMarkSweepGC was deprecated in version 9.0 and will likely be removed in a future release.
2021-06-30 15:05:19,157 main ERROR Unable to locate appender "${sys:ls.log.format}_console" for logger config "root"
2021-06-30 15:05:19,158 main ERROR Unable to locate appender "${sys:ls.log.format}_rolling" for logger config "root"
2021-06-30 15:05:19,158 main ERROR Unable to locate appender "${sys:ls.log.format}_rolling_slowlog" for logger config "slowlog"
2021-06-30 15:05:19,159 main ERROR Unable to locate appender "${sys:ls.log.format}_console_slowlog" for logger config "slowlog"
WARNING: Could not find logstash.yml which is typically located in $LS_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 30, 2021, 4:15pm UTC](https://discuss.elastic.co/t/logstash-keystore-while-running-as-a-service/277262/6 "2021-06-30T16:15:16Z")

</div>

OK, so the service should be OK, but you will still need to set it on the command line when running other logstash tools.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2021, 4:15pm UTC](https://discuss.elastic.co/t/logstash-keystore-while-running-as-a-service/277262/7 "2021-07-28T16:15:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
