# Logstash not listening for second input

**URL:** <https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480>\
**Category:** Logstash\
**Created:** [June 20, 2023, 12:32pm UTC](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480 "2023-06-20T12:32:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 20, 2023, 12:32pm UTC](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480/1 "2023-06-20T12:32:53Z")

</div>

I have set up a working ELK stack with input from winlogbeat. Now I want to add a second input for ingesting syslog logs from a switch. I configured my logstash to do so, but it still only listens on port 5044 after restarting. I have the logging level on DEBUG and there are no errors displayed. I just see that the second listener is not started. The output config works with beats and I did not change it. 'ss -tlpn' and 'netstat -luptn' show, that there is no socket with the port 514 as I would expect.

Here is my input config:  
 ![logstash](https://us1.discourse-cdn.com/elastic/original/3X/a/d/adfa2cf43d3e28be4e348cdcc053da95c961edc1.png)

Why is the second listener not starting?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 20, 2023, 12:46pm UTC](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480/2 "2023-06-20T12:46:57Z")

</div>

How are you starting Lostash? Are you running it as a service?

Ports lower than 1024 are privileged ports and reserved for the `root` user, if you are running Logstash as a service it will run as the `logstash` user, which cannot bind to this port and this will thrown an error.

Also, it is not recommended to run Logstash as a root, if you want to use port `514` you will need to use an iptables/firewall rule to forward connections into this port to a different port in the syslog input, `5514` for example or use `setcap` to allow the java process to bind to port `514`, this [blog post](https://dev.to/bidhanahdib/binding-privileged-port-514-to-logstash-7-10-0-4og2) explains how to do it.

> [@Shabu](#):
>
> I have the logging level on DEBUG and there are no errors displayed.

If the input is not running you will have an log about it but DEBUG level is pretty noise and can make you miss this log, this kind of error you can get without DEBUG, change your log level to INFO and start logstash again to get new logs.

---

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 20, 2023, 1:01pm UTC](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480/3 "2023-06-20T13:01:21Z")

</div>

Thank you very much, I made it work using the Linux Capability for java as shown in the blog post you mentioned.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2023, 1:01pm UTC](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480/4 "2023-07-18T13:01:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
