# Logstash Logging setting to output rubydebug info for running service

**URL:** <https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435>\
**Category:** Logstash\
**Created:** [November 4, 2021, 5:24pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435 "2021-11-04T17:24:04Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![teebu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teebu/32/10119_2.png) [@teebu](https://discuss.elastic.co/u/teebu)\
**Post date:** [November 4, 2021, 5:24pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/1 "2021-11-04T17:24:04Z")

</div>

I'm using the default settings. When I run LS as a service, the logging in the plain.log file doesn't have any of the rubydebug output.

When I run it with the -f flag, I see all the output normally.

What setting file do I need to modify to show all the logging output? I looked at log4j2 but couldn't determine what needed to be modified. I think 'info' is the default logging level?

Setting the 'debug' level in logstash.yml is too verbose compared to the regular output when I run -f. I just want the console output from rubydebug.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 4, 2021, 5:39pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/2 "2021-11-04T17:39:21Z")

</div>

rubydebug output does not go through log4j2. You could use a file output with a rubydebug codec.

---

<div class="post-metadata">

**Author:** ![teebu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teebu/32/10119_2.png) [@teebu](https://discuss.elastic.co/u/teebu)\
**Post date:** [November 4, 2021, 7:41pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/3 "2021-11-04T19:41:44Z")

</div>

But it outputs to console?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 4, 2021, 8:10pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/4 "2021-11-04T20:10:47Z")

</div>

If you use

```
output { stdout { codec => rubydebug } }

```

then it outputs to the console. But you can use

```
output { file { codec => rubydebug path => "/tmp/foo.txt" } }
```

---

<div class="post-metadata">

**Author:** ![teebu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teebu/32/10119_2.png) [@teebu](https://discuss.elastic.co/u/teebu)\
**Post date:** [November 4, 2021, 8:16pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/5 "2021-11-04T20:16:00Z")

</div>

I don't like that, because then I would have to modify the way it works when i do the -f param, where the logging is happening in a single terminal.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 4, 2021, 8:17pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/6 "2021-11-04T20:17:25Z")

</div>

If you want to capture stdout of a service then that is a question about whatever service manager you use, not about logstash.

If you are using systemd then [this](https://unix.stackexchange.com/questions/20399/view-stdout-stderr-of-systemd-service) might help.

---

<div class="post-metadata">

**Author:** ![teebu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teebu/32/10119_2.png) [@teebu](https://discuss.elastic.co/u/teebu)\
**Post date:** [November 4, 2021, 8:36pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/7 "2021-11-04T20:36:26Z")

</div>

I'm just running logstash as a service and using `tail -f /etc/logstash/logs/logstash-plain.log`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 4, 2021, 9:08pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/8 "2021-11-04T21:08:11Z")

</div>

Which service manager are you using?

---

<div class="post-metadata">

**Author:** ![teebu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teebu/32/10119_2.png) [@teebu](https://discuss.elastic.co/u/teebu)\
**Post date:** [November 4, 2021, 9:17pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/9 "2021-11-04T21:17:51Z")

</div>

I'm using ubuntu, so systemd i guess.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 4, 2021, 9:20pm UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/10 "2021-11-04T21:20:16Z")

</div>

OK, so read the post that I linked to.

---

<div class="post-metadata">

**Author:** ![teebu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teebu/32/10119_2.png) [@teebu](https://discuss.elastic.co/u/teebu)\
**Post date:** [November 5, 2021, 12:07am UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/11 "2021-11-05T00:07:13Z")

</div>

That was a lot of text to read through, but the gist is to do this:

```auto
sudo journalctl -f -u logstash

```

is there no way to make log4j2 capture console logs?

Last time I used logstash (1.5) I don't think this wasn't a problem.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 5, 2021, 2:23am UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/12 "2021-11-05T02:23:28Z")

</div>

> [@teebu](#):
>
> is there no way to make log4j2 capture console logs?

There is no way to route data from a stdout output to log4j2. It [writes](https://github.com/logstash-plugins/logstash-output-stdout/blob/0836253f9b7a495bee937ef172f0e8225365506c/lib/logstash/outputs/stdout.rb#L43) directly to stdout.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2021, 2:24am UTC](https://discuss.elastic.co/t/logstash-logging-setting-to-output-rubydebug-info-for-running-service/288435/13 "2021-12-03T02:24:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
