# Logstash manages to send data to elasticsearch only in debugging mode

**URL:** <https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196>\
**Category:** Logstash\
**Created:** [April 18, 2023, 8:19am UTC](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196 "2023-04-18T08:19:15Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [April 18, 2023, 10:08am UTC](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196/2 "2023-04-18T10:08:51Z")

</div>

When you run LS form the command line, it will run, in your case, as root user as a process. You can run as a background process with & at the end of command. Recommended mode is a service mode for continuous running.

Follow next steps:

1. Change in `elasticsearch.yml` and restart:  
`network.host: [_site_ , _local_]`  
Or just set to 0.0.0.0. Leandro explained [here](https://discuss.elastic.co/t/what-is-network-host/274426/3).  
Restart elasticsearch.
2. Edit apache.conf on Linux should be: _sincedb\_path =\> "/dev/null"_ - this means sincedb is runtime mode, keep log read tracking until restart process, not permanent on disk. The disk mode is used in the production mode, when you need to track logs read.
3. Check log permissions, root user might take ownership, so run: `chown -R logstash:logstash /var/log/logstash/`
4. Run as the service: `sudo systemctl start logstash.service`  
If is not enabled: `systemctl enable logstash.service` and most likely: systemctl daemon-reload

---

_[View the full topic](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196)._
