# Logstash not showing any output

**URL:** <https://discuss.elastic.co/t/logstash-not-showing-any-output/120850>\
**Category:** Logstash\
**Created:** [February 21, 2018, 1:32pm UTC](https://discuss.elastic.co/t/logstash-not-showing-any-output/120850 "2018-02-21T13:32:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![student](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@student](https://discuss.elastic.co/u/student)\
**Post date:** [February 21, 2018, 1:32pm UTC](https://discuss.elastic.co/t/logstash-not-showing-any-output/120850/1 "2018-02-21T13:32:32Z")

</div>

Hi  
I am a student working on a project and decided to use ELK Stack as a logging tool to present its value.  
I am using SUSE Linux Enterprise Server 12 SP3 (x86\_64) as OS and running it on a virtual machine.

I need a bit of help understanding how logstash works. Right now I have set it up so it should take my apache2 logs and send it to elasticsearch. But nothing gets through, I have tested with your examples with the bank and everything worked as it should, I was able to find the bank data through kibana and create an index for it. But when I moved on to another example, setting up for apache data nothing happens. I've checked the logs but nothing seems to be wrong.

Here is the simple.config I am using for logstash:

```
input {
  file {
    path => "/var/log/apache2/access_log"
    start_position => "beginning"
  }
}
filter {

    grok {
        match => { "message" => "%{COMBINEDAPACHELOG}"}
    }
    date {
        match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
  }
}

output {
  elasticsearch {
  hosts => ["localhost:9200"]
  }
 }

```

and the logstash logs looks as following:

> [2018-02-21T13:10:46,658][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.2.0"}  
> [2018-02-21T13:10:47,118][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
> [2018-02-21T13:10:48,068][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
> [2018-02-21T13:10:48,324][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
> [2018-02-21T13:10:48,326][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
> [2018-02-21T13:10:48,403][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
> [2018-02-21T13:10:48,445][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>nil}  
> [2018-02-21T13:10:48,445][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
> [2018-02-21T13:10:48,448][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
> [2018-02-21T13:10:48,450][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
> [2018-02-21T13:10:48,457][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::Elasticsearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
> [2018-02-21T13:10:48,732][INFO][logstash.pipeline] Pipeline started succesfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x13f51a3@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:246 sleep\>"}  
> [2018-02-21T13:10:48,749][INFO][logstash.agent] Pipelines running {:count=\>1, :pipelines=\>["main"]}

Otherwise most of everything is kept at default, Logstash, Kibana and Elasticsearch is all installed on the same machine.  
Anyone has any idea why I cant find the apach2 logs in Kibana?

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [February 21, 2018, 4:59pm UTC](https://discuss.elastic.co/t/logstash-not-showing-any-output/120850/2 "2018-02-21T16:59:21Z")

</div>

A common issue with not seeing events from a file input is that Logstash has already read that file. Logstash keeps a track of all files it has processed and the latest offset for each file which stores it in a [since\_db](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-sincedb_path) file.

So if you try and reprocess an already processed file, Logstash actually knows it has already read it and skips it. Check if such a file exists in the default path and delete it if so, see if that resolves the issue.

---

<div class="post-metadata">

**Author:** ![student](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@student](https://discuss.elastic.co/u/student)\
**Post date:** [February 23, 2018, 8:28am UTC](https://discuss.elastic.co/t/logstash-not-showing-any-output/120850/3 "2018-02-23T08:28:07Z")

</div>

I couldn't find since\_db file anywhere, I checked the defaul path which is Usr/share/logstash but no results, I even tried the find /-name since\_db and it came up empty. Do you have any other suggestions?  
Edit1:  
I've just tried to create a new file in my home catalog called taccess\_log and copied in some example data. Changed the file path in the conf file and it worked, but now when i change the path to my actual apache2 logs which is in var/log/apache2 and it still dosen't work.

Also, after this change, I tried to find the since\_db file again with still no result.. Either its hidden somewere, or something is amiss

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [February 23, 2018, 9:28am UTC](https://discuss.elastic.co/t/logstash-not-showing-any-output/120850/4 "2018-02-23T09:28:51Z")

</div>

Documentation suggests that it's under `<path.data>/plugins/inputs/file`, but you can always provide your own path in the config and it should spawn a new file which you will be able to control better.

---

<div class="post-metadata">

**Author:** ![student](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@student](https://discuss.elastic.co/u/student)\
**Post date:** [February 23, 2018, 10:32am UTC](https://discuss.elastic.co/t/logstash-not-showing-any-output/120850/5 "2018-02-23T10:32:02Z")

</div>

Thank you for the assistans, we have solved the problem, we checked the chmod on the access\_log file, but not on the apache2 directory..

So it was a chmod problem afterall.

It now reads the correct file and inputs data as we wished.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2018, 10:32am UTC](https://discuss.elastic.co/t/logstash-not-showing-any-output/120850/6 "2018-03-23T10:32:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
