# Logstash not indexing logs when run as service

**URL:** <https://discuss.elastic.co/t/logstash-not-indexing-logs-when-run-as-service/155506>\
**Category:** Logstash\
**Created:** [November 6, 2018, 8:32am UTC](https://discuss.elastic.co/t/logstash-not-indexing-logs-when-run-as-service/155506 "2018-11-06T08:32:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Billz1026](https://avatars.discourse-cdn.com/v4/letter/b/67e7ee/32.png) [@Billz1026](https://discuss.elastic.co/u/Billz1026)\
**Post date:** [November 6, 2018, 8:32am UTC](https://discuss.elastic.co/t/logstash-not-indexing-logs-when-run-as-service/155506/1 "2018-11-06T08:32:35Z")

</div>

Hi,

I have configure ELK stack and ran logstash and when I checked the configuration using below command, it says "configuration OK". When I run the logstash using below command it is indexing logs to Elasticsearch and i could see the logs through Kibana.  
" ` /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/sample.conf`"

The problem is when I run logstash as a service, it is not sending logs to elasticsearch. I cannot see logs through Kibana. But logstash service is up and running. following is the logs present in the "logstash-plain.log" file.

> "[2018-11-06T13:42:09,430][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.4.2"}  
> [2018-11-06T13:42:11,937][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
> [2018-11-06T13:42:12,413][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://172.25.37.214:9200/](http://172.25.37.214:9200/)]}}  
> [2018-11-06T13:42:12,423][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://172.25.37.214:9200/](http://172.25.37.214:9200/), :path=\>"/"}  
> [2018-11-06T13:42:12,599][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://172.25.37.214:9200/](http://172.25.37.214:9200/)"}  
> [2018-11-06T13:42:12,653][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
> [2018-11-06T13:42:12,656][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
> [2018-11-06T13:42:12,677][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::Elasticsearch", :hosts=\>["[http://172.25.37.214:9200](http://172.25.37.214:9200)"]}  
> [2018-11-06T13:42:12,699][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
> [2018-11-06T13:42:12,723][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
> [2018-11-06T13:42:18,209][INFO][logstash.inputs.file] No sincedb\_path set, generating one based on the "path" setting {:sincedb\_path=\>"/var/lib/logstash/plugins/inputs/file/.sincedb\_fa3bc1f5b266ecfd40c72246b23bc8e6", :path=\>["/var/log/syslog/network2.log"]}  
> [2018-11-06T13:42:18,310][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x230619ba run\>"}  
> [2018-11-06T13:42:18,364][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
> [2018-11-06T13:42:18,367][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
> [2018-11-06T13:42:18,697][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
> "

logstash config file

> input{  
> file {  
> path =\> "/var/log/syslog/network2.log"  
> start\_position =\> "beginning"  
> }  
> }
> 
> filter {  
> grok {  
> match =\> {  
> "message" =\> ["%{MONTH:Month}%{SPACE}%{NUMBER:Day} %{TIME:Time} %{IP:Host} %{NUMBER:SEQ\_NO}: %{DATA:Month\_From\_Device}%{SPACE}%{NUMBER:Day\_From\_Device} %{TIME:Time\_From\_Device}: %%{DATA:Facility}-%{DATA:Severity}-%{DATA:Event}: Login Success [user: %{NUMBER:Service\_Number}] [Source: %{IP:Log\_in\_Source}] %{GREEDYDATA:Information}", "%{MONTH:Month}%{SPACE}%{NUMBER:Day} %{TIME:Time} %{IP:Host} %{NUMBER:SEQ\_NO}: %{DATA:Month\_From\_Device}%{SPACE}%{NUMBER:Day\_From\_Device} %{TIME:Time\_From\_Device}: %%{DATA:Facility}-%{DATA:Severity}-%{DATA:Event}: Login failed [user: %{NUMBER:Service\_Number}] [Source: %{IP:Log\_in\_Source}] %{GREEDYDATA:Information}", "%{MONTH:Month}%{SPACE}%{NUMBER:Day} %{TIME:Time} %{IP:Host} %{NUMBER:SEQ\_NO}: %{DATA:Month\_From\_Device}%{SPACE}%{NUMBER:Day\_From\_Device} %{TIME:Time\_From\_Device}: %%{DATA:Facility}-%{DATA:Severity}-%{DATA:Event}: %{GREEDYDATA:Information}", "%{MONTH:Month}%{SPACE}%{NUMBER:Day} %{TIME:Time} %{IP:Host} %{NUMBER:SEQ\_NO}: %{GREEDYDATA:Information}", "%{MONTH:Month}%{SPACE}%{NUMBER:Day} %{TIME:Time} %{IP:Host} %{DATA:Time\_From\_device} level=%{DATA:Log\_Level} vd=%{DATA:VDOM\_Name} srcip=%{IP:VPN\_Source\_IP} %{DATA:Misc\_info} dstip=%{IP:Destination\_IP} dstport=%{NUMBER:Destination\_Port} %{DATA:Misc\_info2} %{DATA:Misc\_info3} proto=%{NUMBER:Protocol\_Number} action=%{DATA:Action} user=%{DATA:Username} group=%{DATA:Group} policyid=%{NUMBER:Policy\_ID} %{GREEDYDATA:Misc\_info4}", "%{MONTH:Month}%{SPACE}%{NUMBER:Day} %{TIME:Time} %{IP:Host} %{DATA:Time\_From\_device} level=%{DATA:Log\_Level} vd=%{DATA:VDOM\_Name} srcip=%{IP:VPN\_Source\_IP} %{DATA:Misc\_info} dstip=%{IP:Destination\_IP} dstport=%{NUMBER:Destination\_Port} %{DATA:Misc\_info2} %{DATA:Misc\_info3} proto=%{NUMBER:Protocol\_Number} action=%{DATA:Action} user=%{DATA:Username} policyid=%{NUMBER:Policy\_ID} %{GREEDYDATA:Misc\_info4}", "%{MONTH:Month}%{SPACE}%{NUMBER:Day} %{TIME:Time} %{IP:Host} %{DATA:Time\_From\_device} level=%{DATA:Log\_Level} vd=%{DATA:VDOM\_Name} srcip=%{IP:VPN\_Source\_IP} %{DATA:Misc\_info} dstip=%{IP:Destination\_IP} dstport=%{NUMBER:Destination\_Port} %{DATA:Misc\_info2} %{DATA:Misc\_info3} proto=%{NUMBER:Protocol\_Number} action=%{DATA:Action} policyid=%{NUMBER:Policy\_ID} %{GREEDYDATA:Misc\_info4}", "%{MONTH:Month}%{SPACE}%{NUMBER:Day} %{TIME:Time} %{IP:Host} %{DATA:Time\_From\_device} %{DATA:Misc\_Info1} subtype=%{DATA:Event\_Type} %{DATA:Misc\_Info2} vd=%{DATA:VDOM\_Name} logdesc=%{DATA:Log\_Description} action=%{DATA:Log\_Type} %{DATA:Misc\_Info2} remip=%{IP:Remote\_IP} tunnelip=%{IP:Tunel\_IP} user=%{DATA:User\_Name} group=%{DATA:Group\_Name} %{GREEDYDATA:Misc\_Info3}"]  
> }  
> }  
> }
> 
> output {
> 
> elasticsearch {
> 
> ```
> hosts => "http://[server IP]:9200"
> index => "logstash"
> }
> }
> 
> ```

file permissions of log file

> -rwxrwxrwx. 1 root root 274624283 Nov 6 14:01 network2.log

Please help me to sort this issue since i am heading nowhere to find the solution.

Thanks  
[Billz1026]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2018, 8:32am UTC](https://discuss.elastic.co/t/logstash-not-indexing-logs-when-run-as-service/155506/2 "2018-12-04T08:32:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
