# Logstash not working when started via systemctl

**URL:** <https://discuss.elastic.co/t/logstash-not-working-when-started-via-systemctl/157409>\
**Category:** Logstash\
**Created:** [November 19, 2018, 5:09pm UTC](https://discuss.elastic.co/t/logstash-not-working-when-started-via-systemctl/157409 "2018-11-19T17:09:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marlon\_Ruttmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marlon_ruttmann/32/37839_2.png) [@Marlon\_Ruttmann](https://discuss.elastic.co/u/Marlon_Ruttmann)\
**Post date:** [November 19, 2018, 5:09pm UTC](https://discuss.elastic.co/t/logstash-not-working-when-started-via-systemctl/157409/1 "2018-11-19T17:09:55Z")

</div>

Hello,

I have all my environment configured and tested using the command `bin/logstash -f myfile.conf --config.reload.automatic` and everything works fine. Elasticsearch generates indices, all the filters defined in my .conf file are working as expected.

When I try to start Logstash with `systemctl start logstash`, it is started and I can see the process running under the logstash username.

The point is that no log files are being generated under `/var/log/logstash` directory. I already changed the ownership and permissions for this directory and also verified the `path.logs` configuration in `logstash.yml` file.

I have noticed that when I run Logstash with the test command, the following errors are reported:

> WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
> Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console

Where should I verify if those path are correctly configured? Is this log4j2.properties error the reponsible for log files not being generated?

**My environment is SLES 12. Logstash and other stack members were installed with RPM packages.**

Thanks!

---

<div class="post-metadata">

**Author:** ![Marlon\_Ruttmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marlon_ruttmann/32/37839_2.png) [@Marlon\_Ruttmann](https://discuss.elastic.co/u/Marlon_Ruttmann)\
**Post date:** [November 20, 2018, 12:25pm UTC](https://discuss.elastic.co/t/logstash-not-working-when-started-via-systemctl/157409/2 "2018-11-20T12:25:32Z")

</div>

I could solve the issue by myself.

There were some syntax errors in logstash.yml file and also a directory lacking permissions.

After correcting these problems everything works as expected.

BR!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2018, 12:25pm UTC](https://discuss.elastic.co/t/logstash-not-working-when-started-via-systemctl/157409/3 "2018-12-18T12:25:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
