# Logstash not stashing logs even after starting successfully

**URL:** <https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010>\
**Category:** Logstash\
**Created:** [July 13, 2018, 8:07pm UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010 "2018-07-13T20:07:37Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [July 13, 2018, 8:07pm UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/1 "2018-07-13T20:07:38Z")

</div>

Hi all,

I have an apache log file that I want to ingest into logstash and then send the stashed data to elasticsearch.

I run the logstash command like this:

> .\logstash -f logtstash.conf

After running the command this is the output I get

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/9/4/940443bc057c121ebec4d57fef43b4995d457840.PNG)

Successfully started Logstash API endpoint is the last line. Ideally I should be able to see all the logs being uploaded to Elasticsearch. But, it isn't happening.

Here is my logstash.conf

```
input {
  file {
    path => "E:\elk\logstash\apache_logs"
    type => "apache_access"
    start_position => "beginning"
  }
}

filter {
   if [type] in ["apache" , "apache_access" , "apache-access"] {
      grok {
         match => [
         "message" , "%{COMBINEDAPACHELOG}+%{GREEDYDATA:extra_fields}",
         "message" , "%{COMMONAPACHELOG}+%{GREEDYDATA:extra_fields}"
         ]
         overwrite => ["message"]
      }
      mutate {
         convert => ["response", "integer"]
         convert => ["bytes", "integer"]
         convert => ["responsetime", "float"]
      }
      geoip {
         source => "clientip"
         target => "geoip"
         add_tag => ["apache-geoip"]
      }
      date {
         match => ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]
         remove_field => ["timestamp"]
      }
      useragent {
         source => "agent"
      }
   }
   if [type] in ["apache_error","apache-error"] {
      grok {
         match => ["message", "\[%{WORD:dayname} %{WORD:month} %{DATA:day} %{DATA:hour}:%{DATA:minute}:%{DATA:second} %{YEAR:year}\] \[%{NOTSPACE:loglevel}\] (?:\[client %{IPORHOST:clientip}\] ){0,1}%{GREEDYDATA:message}"]
         overwrite => ["message"]
      }
      mutate
      {
         add_field =>
         {
            "time_stamp" => "%{day}/%{month}/%{year}:%{hour}:%{minute}:%{second}"
         }
      }
      date {
         match => ["time_stamp", "dd/MMM/YYYY:HH:mm:ss"]
         remove_field => ["time_stamp","day","dayname","month","hour","minute","second","year"]
      }
   }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "apache-%{+YYYY.MM.dd}"
    document_type => "system_logs"
  }
  stdout { codec => rubydebug }
} 

```

My elasticsearch indices look like this

 ![Capture1](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c1936a9bb8f530fa883c75ba41a603a0abdc8b54.PNG)

I have attempted several times to execute the above command, but the logs never get stashed. What wrong am I doing? Can someone please help me out?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 13, 2018, 8:13pm UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/2 "2018-07-13T20:13:23Z")

</div>

> [@APJ](#):
>
> path =\> "E:\elk\logstash\apache\_logs"

That will read a file called apache\_logs. Is that what you want, or do you want to read all the files in that directory?

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [July 13, 2018, 8:17pm UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/3 "2018-07-13T20:17:05Z")

</div>

I just want to read apache\_logs

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [July 13, 2018, 8:25pm UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/4 "2018-07-13T20:25:25Z")

</div>

Should I alter the config file?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 13, 2018, 9:10pm UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/5 "2018-07-13T21:10:42Z")

</div>

Are additional lines being appended to "E:\elk\logstash\apache\_logs"?

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [July 13, 2018, 9:31pm UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/6 "2018-07-13T21:31:45Z")

</div>

Sorry, what do you mean by additional lines?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 13, 2018, 11:00pm UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/7 "2018-07-13T23:00:56Z")

</div>

The file input tails the log file. If no new lines are added then it does not stash anything.

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [July 16, 2018, 6:22am UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/8 "2018-07-16T06:22:46Z")

</div>

This is the first time I am inserting all the lines. So, ideally all the lines need to get stashed.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 16, 2018, 10:18am UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/9 "2018-07-16T10:18:05Z")

</div>

> [@APJ](#):
>
> This is the first time

You said previously that you had run the command several times. Once you have run it once it will not stash anything unless there are additional lines appended to the file. So if the first time you ran the command the configuration had an issue, it is possible a sincedb got created and the size of the file got recorded.

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [July 16, 2018, 3:59pm UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/10 "2018-07-16T15:59:04Z")

</div>

Thanks! I understand what the problem may be

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2018, 3:59pm UTC](https://discuss.elastic.co/t/logstash-not-stashing-logs-even-after-starting-successfully/140010/11 "2018-08-13T15:59:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
