# Logstash log4j input gets stuck after a while

**URL:** <https://discuss.elastic.co/t/logstash-log4j-input-gets-stuck-after-a-while/58803>\
**Category:** Logstash\
**Created:** [August 24, 2016, 10:38am UTC](https://discuss.elastic.co/t/logstash-log4j-input-gets-stuck-after-a-while/58803 "2016-08-24T10:38:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jonasdaugalas](https://avatars.discourse-cdn.com/v4/letter/j/ec9cab/32.png) [@jonasdaugalas](https://discuss.elastic.co/u/jonasdaugalas)\
**Post date:** [August 24, 2016, 10:38am UTC](https://discuss.elastic.co/t/logstash-log4j-input-gets-stuck-after-a-while/58803/1 "2016-08-24T10:38:41Z")

</div>

I think I have a problem with log4j input plugin.

OS: Scientific Linux CERN SLC release 6.6 (Carbon)  
Logstash: 2.3.4  
Config pipeline.conf:

> input {  
> log4j {  
> mode =\> "client"  
> host =\> log\_output\_host  
> port =\> 26021  
> }  
> }  
> output {  
> stdout {codec =\> rubydebug}  
> }

Then I do:

> ./bin/logstash -f pipeline.conf

It starts OK, I see nice output for around 10 minutes, then it stops. CPU usage for logstash drops from 2-7% to 0%. I know that log4j socket hub output (on log\_output\_host:26021) is fine because if I start another instance of logstash with the same config, it starts and outputs receiving events.  
When it is stuck and I hit Ctrl+C, I get:

> SIGINT received. Shutting down the agent. {:level=\>:warn}  
> stopping pipeline {:id=\>"main"}  
> Closing inputs {:level=\>:info}  
> Closed inputs {:level=\>:info}  
> Received shutdown signal, but pipeline is still waiting for in-flight events  
> to be processed. Sending another ^C will force quit Logstash, but this may cause  
> data loss. {:level=\>:warn}

Then after some time:

> {"inflight\_count"=\>0, "stalling\_thread\_info"=\>{"other"=\>[{"thread\_id"=\>17, "name"=\>"[main]\<log4j", "current\_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-input-log4j-2.0.7-java/lib/logstash/inputs/log4j.rb:105:in `read_object'"}, {"thread_id"=\>18, "name"=\>"[main]\>worker0", "current_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:309:in `synchronize'"}, {"thread\_id"=\>19, "name"=\>"[main]\>worker1", "current\_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:309:in `synchronize'"}, {"thread_id"=\>20, "name"=\>"[main]\>worker2", "current_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:218:in `synchronize'"}, {"thread\_id"=\>21, "name"=\>"[main]\>worker3", "current\_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:218:in `synchronize'"}, {"thread_id"=\>22, "name"=\>"[main]\>worker4", "current_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:218:in `synchronize'"}, {"thread\_id"=\>23, "name"=\>"[main]\>worker5", "current\_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:218:in `synchronize'"}, {"thread_id"=\>24, "name"=\>"[main]\>worker6", "current_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:309:in `synchronize'"}, {"thread\_id"=\>25, "name"=\>"[main]\>worker7", "current\_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:218:in `synchronize'"}, {"thread_id"=\>26, "name"=\>"[main]\>worker8", "current_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:218:in `synchronize'"}, {"thread\_id"=\>27, "name"=\>"[main]\>worker9", "current\_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:218:in `synchronize'"}, {"thread_id"=\>28, "name"=\>"[main]\>worker10", "current_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:309:in `synchronize'"}, {"thread\_id"=\>29, "name"=\>"[main]\>worker11", "current\_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:309:in `synchronize'"}]}} {:level=\>:warn}  
> The shutdown process appears to be stalled due to busy or blocked plugins. Check the logs for more information. {:level=\>:error}

Does anybody have any advice?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:41am UTC](https://discuss.elastic.co/t/logstash-log4j-input-gets-stuck-after-a-while/58803/2 "2017-07-06T04:41:53Z")

</div>


