# Logstash manages to send data to elasticsearch only in debugging mode

**URL:** <https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196>\
**Category:** Logstash\
**Created:** [April 18, 2023, 8:19am UTC](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196 "2023-04-18T08:19:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Skairik](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Post date:** [April 18, 2023, 8:19am UTC](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196/1 "2023-04-18T08:19:15Z")

</div>

Hello everyone,

I am currently trying a basic test setup with apache logs on logstash, but I have a problem, my data is received on kibana/elasticsearch only when I run the following command:

```auto
/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/apache.conf

```

And so the problem is that if I stop this command and logstash is running normally, I have no errors but no data appears, and another weird thing, when I'm in debugging mode, it seems to me from the tutorials I've seen that I'm supposed to see the data in real time, but that's not the case.

If anyone has an idea.. Btw I'm on version 8.7

Here is my logstash configuration:

```auto

root@srv-elk:/etc/logstash/conf.d# cat /etc/logstash/conf.d/apache.conf | grep ^[^#]
input {
        file {
                 path => "/var/log/apache2/access.log"
                 #start_position => "beginning"
                 #ignore_older => 0
                 #sincedb_path => "NUL"
                 #delimiter => "\r"
                 }
}
filter {
        grok {
                #patterns_dir => ["/etc/logstash/patterns.d"]
                match => ["message" , "%{COMBINEDAPACHELOG}"]
        }
        date {
                match => ["timestamp","dd/MMM/yyyy:HH:mm:ss Z"]
        }
}
output {
    elasticsearch {
         hosts => ["https://localhost"]
         user => "elastic"
         password => "ozPpuZ0=ypPMUHJLkobf"
         index => "apache-%{+YYYY.MM.dd}"
         ssl => true
         cacert => "/http_ca.crt"
    }
}

```

And for elasticsearch:

```auto
root@srv-elk:/etc/logstash/conf.d# cat /etc/elasticsearch/elasticsearch.yml | grep ^[^#]
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
discovery.type: single-node
network.host: "172.16.10.62"
http.port: 9200
discovery.seed_hosts: [""]
xpack.security.enabled: true
xpack.security.enrollment.enabled: true
xpack.security.http.ssl:
  enabled: true
  keystore.path: certs/http.p12
xpack.security.transport.ssl:
  enabled: true
  verification_mode: certificate
  keystore.path: certs/transport.p12
  truststore.path: certs/transport.p12
http.host: "localhost"

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [April 18, 2023, 10:08am UTC](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196/2 "2023-04-18T10:08:51Z")

</div>

When you run LS form the command line, it will run, in your case, as root user as a process. You can run as a background process with & at the end of command. Recommended mode is a service mode for continuous running.

Follow next steps:

1. Change in `elasticsearch.yml` and restart:  
`network.host: [_site_ , _local_]`  
Or just set to 0.0.0.0. Leandro explained [here](https://discuss.elastic.co/t/what-is-network-host/274426/3).  
Restart elasticsearch.
2. Edit apache.conf on Linux should be: _sincedb\_path =\> "/dev/null"_ - this means sincedb is runtime mode, keep log read tracking until restart process, not permanent on disk. The disk mode is used in the production mode, when you need to track logs read.
3. Check log permissions, root user might take ownership, so run: `chown -R logstash:logstash /var/log/logstash/`
4. Run as the service: `sudo systemctl start logstash.service`  
If is not enabled: `systemctl enable logstash.service` and most likely: systemctl daemon-reload

---

<div class="post-metadata">

**Author:** ![Skairik](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Post date:** [April 18, 2023, 11:29am UTC](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196/3 "2023-04-18T11:29:19Z")

</div>

Thank you for your answer, unfortunately it did not work, always the same problem. No errors anywhere, the only message I didn't mention is this one (last line) :

```auto
[INFO] 2023-04-18 11:21:49.216 [Agent thread] agent - Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
/usr/share/logstash/vendor/bundle/jruby/2.6.0/gems/manticore-0.9.1-java/lib/manticore/client.rb:536: warning: already initialized constant Manticore::Client::StringEntity

```

But it didn't seem very useful to me.

---

<div class="post-metadata">

**Author:** ![Skairik](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Post date:** [April 18, 2023, 11:53am UTC](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196/4 "2023-04-18T11:53:06Z")

</div>

Seeing you talk about permission made me think I wasn't sure if logstash had read rights to the apache log file, I gave it permissions:

```auto
sudo usermod -aG adm logstash

```

**And it works ! ^^'**

I had already made this command but I uninstalled logstash from my server in the meantime and suddenly it no longer had the rights!

Sorry it was a noob error x)  
I always find it weird that it didn't get any error about that...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2023, 11:53am UTC](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196/5 "2023-05-16T11:53:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
