# Logstash output

**URL:** <https://discuss.elastic.co/t/logstash-output/113392>\
**Category:** Logstash\
**Created:** [December 28, 2017, 5:55am UTC](https://discuss.elastic.co/t/logstash-output/113392 "2017-12-28T05:55:41Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![anjali](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@anjali](https://discuss.elastic.co/u/anjali)\
**Post date:** [December 28, 2017, 5:55am UTC](https://discuss.elastic.co/t/logstash-output/113392/1 "2017-12-28T05:55:42Z")

</div>

Hello, I am new to the ELK stack. I have installed logstash stdout output plugin. Can someone tell me where I can see the output of logstash?  
(Because I am parsing the message in logstash but it is not showing in Kibana).  
Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 28, 2017, 6:25am UTC](https://discuss.elastic.co/t/logstash-output/113392/2 "2017-12-28T06:25:22Z")

</div>

FYI we’ve renamed ELK to the Elastic Stack, otherwise Beats and APM feel left out! 😉

`stdout` means to the console or logged to the default log file, depending on how you are running Logstash.

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [December 28, 2017, 7:11am UTC](https://discuss.elastic.co/t/logstash-output/113392/3 "2017-12-28T07:11:56Z")

</div>

hi @anjali can you share your configuration file. and can you tell me which Elastic Stack version you used ?

Thanks & Regards,  
Krunal Patel.

---

<div class="post-metadata">

**Author:** ![anjali](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@anjali](https://discuss.elastic.co/u/anjali)\
**Post date:** [December 28, 2017, 8:29am UTC](https://discuss.elastic.co/t/logstash-output/113392/4 "2017-12-28T08:29:28Z")

</div>

Thanks a lot. But i'm still unable to see the output in the log files present in the log folder. My version is 5.6.3. Any advice?

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [December 28, 2017, 2:25pm UTC](https://discuss.elastic.co/t/logstash-output/113392/5 "2017-12-28T14:25:13Z")

</div>

how are you running logstash? systemd?

---

<div class="post-metadata">

**Author:** ![anjali](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@anjali](https://discuss.elastic.co/u/anjali)\
**Post date:** [December 29, 2017, 5:30am UTC](https://discuss.elastic.co/t/logstash-output/113392/6 "2017-12-29T05:30:24Z")

</div>

no, I am running it on win10.  
the logstash input comes from filebeat, and output goes to elastic search (visualized on kibana)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 29, 2017, 5:36am UTC](https://discuss.elastic.co/t/logstash-output/113392/7 "2017-12-29T05:36:20Z")

</div>

Please post your config.

---

<div class="post-metadata">

**Author:** ![anjali](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@anjali](https://discuss.elastic.co/u/anjali)\
**Post date:** [December 29, 2017, 5:52am UTC](https://discuss.elastic.co/t/logstash-output/113392/8 "2017-12-29T05:52:22Z")

</div>

config is all commented.

# Settings file in YAML

# 

# Settings can be specified either in hierarchical form, e.g.:

# 

# pipeline:

# batch:

# size: 125

# delay: 5

# 

# Or as flat keys:

# 

# pipeline.batch.size: 125

# pipeline.batch.delay: 5

# 

# ------------ Node identity ------------

# 

# Use a descriptive name for the node:

# 

# [node.name](http://node.name): test

# 

# If omitted the node name will default to the machine's host name

# 

# ------------ Data path ------------------

# 

# Which directory should be used by logstash and its plugins

# for any persistent needs. Defaults to LOGSTASH\_HOME/data

# 

# path.data: C:\apps\logstash-5.6.3\logs

# 

# ------------ Pipeline Settings --------------

# 

# Set the number of workers that will, in parallel, execute the filters+outputs

# stage of the pipeline.

# 

# This defaults to the number of the host's CPU cores.

# 

# pipeline.workers: 2

# 

# How many workers should be used per output plugin instance

# 

# pipeline.output.workers: 1

# 

# How many events to retrieve from inputs before sending to filters+workers

# 

# pipeline.batch.size: 125

# 

# How long to wait before dispatching an undersized batch to filters+workers

# Value is in milliseconds.

# 

# pipeline.batch.delay: 5

# 

# Force Logstash to exit during shutdown even if there are still inflight

# events in memory. By default, logstash will refuse to quit until all

# received events have been pushed to the outputs.

# 

# WARNING: enabling this can lead to data loss during shutdown

# 

# pipeline.unsafe\_shutdown: false

# 

# ------------ Pipeline Configuration Settings --------------

# 

# Where to fetch the pipeline configuration for the main pipeline

# 

# path.config:

# 

# Pipeline configuration string for the main pipeline

# 

# config.string:

# 

# At startup, test if the configuration is valid and exit (dry run)

# 

# config.test\_and\_exit: false

# 

# Periodically check if the configuration has changed and reload the pipeline

# This can also be triggered manually through the SIGHUP signal

# 

# config.reload.automatic: false

# 

# How often to check if the pipeline configuration has changed (in seconds)

# 

# config.reload.interval: 3

# 

# Show fully compiled configuration as debug log message

# NOTE: --log.level must be 'debug'

# 

# config.debug: false

# 

# When enabled, process escaped characters such as \n and " in strings in the

# pipeline configuration files.

# 

# config.support\_escapes: false

# 

# ------------ Module Settings ---------------

# Define modules here. Modules definitions must be defined as an array.

# The simple way to see this is to prepend each `name` with a `-`, and keep

# all associated variables under the `name` they are associated with, and

# above the next, like this:

# 

# modules:

# - name: MODULE\_NAME

# var.PLUGINTYPE1.PLUGINNAME1.KEY1: VALUE

# var.PLUGINTYPE1.PLUGINNAME1.KEY2: VALUE

# var.PLUGINTYPE2.PLUGINNAME1.KEY1: VALUE

# var.PLUGINTYPE3.PLUGINNAME3.KEY1: VALUE

# 

# Module variable names must be in the format of

# 

# var.PLUGIN\_TYPE.PLUGIN\_NAME.KEY

# 

# modules:

# 

# ------------ Queuing Settings --------------

# 

# Internal queuing model, "memory" for legacy in-memory based queuing and

# "persisted" for disk-based acked queueing. Defaults is memory

# 

# queue.type: memory

# 

# If using queue.type: persisted, the directory path where the data files will be stored.

# Default is path.data/queue

# 

# path.queue:

# 

# If using queue.type: persisted, the page data files size. The queue data consists of

# append-only data files separated into pages. Default is 250mb

# 

# queue.page\_capacity: 250mb

# 

# If using queue.type: persisted, the maximum number of unread events in the queue.

# Default is 0 (unlimited)

# 

# queue.max\_events: 0

# 

# If using queue.type: persisted, the total capacity of the queue in number of bytes.

# If you would like more unacked events to be buffered in Logstash, you can increase the

# capacity using this setting. Please make sure your disk drive has capacity greater than

# the size specified here. If both max\_bytes and max\_events are specified, Logstash will pick

# whichever criteria is reached first

# Default is 1024mb or 1gb

# 

# queue.max\_bytes: 1024mb

# 

# If using queue.type: persisted, the maximum number of acked events before forcing a checkpoint

# Default is 1024, 0 for unlimited

# 

# queue.checkpoint.acks: 1024

# 

# If using queue.type: persisted, the maximum number of written events before forcing a checkpoint

# Default is 1024, 0 for unlimited

# 

# queue.checkpoint.writes: 1024

# 

# If using queue.type: persisted, the interval in milliseconds when a checkpoint is forced on the head page

# Default is 1000, 0 for no periodic checkpoint.

# 

# queue.checkpoint.interval: 1000

# 

# ------------ Dead-Letter Queue Settings --------------

# Flag to turn on dead-letter queue.

# 

# dead\_letter\_queue.enable: false

# If using dead\_letter\_queue.enable: true, the maximum size of each dead letter queue. Entries

# will be dropped if they would increase the size of the dead letter queue beyond this setting.

# Default is 1024mb

# dead\_letter\_queue.max\_bytes: 1024mb

# If using dead\_letter\_queue.enable: true, the directory path where the data files will be stored.

# Default is path.data/dead\_letter\_queue

# 

# path.dead\_letter\_queue:

# 

# ------------ Metrics Settings --------------

# 

# Bind address for the metrics REST endpoint

# 

# http.host: "127.0.0.1"

# 

# Bind port for the metrics REST endpoint, this option also accept a range

# (9600-9700) and logstash will pick up the first available ports.

# 

# http.port: 9600-9700

# 

# ------------ Debugging Settings --------------

# 

# Options for log.level:

# \* fatal

# \* error

# \* warn

# \* info (default)

# \* debug

# \* trace

# 

# log.level: info

# path.logs:

# 

# ------------ Other Settings --------------

# 

# Where to find custom plugins

# path.plugins: []

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 29, 2017, 6:07am UTC](https://discuss.elastic.co/t/logstash-output/113392/9 "2017-12-29T06:07:16Z")

</div>

I mean the config doing the processing 🙂

Also please use the code button - `</>` - to format things, otherwise it's very difficult to read.

---

<div class="post-metadata">

**Author:** ![anjali](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@anjali](https://discuss.elastic.co/u/anjali)\
**Post date:** [December 29, 2017, 6:29am UTC](https://discuss.elastic.co/t/logstash-output/113392/10 "2017-12-29T06:29:06Z")

</div>

input {  
beats {  
port =\> "5044"  
}  
}

filter {

```
    grok {
         
         match => ["message", "\[%{DATA:timestamp}]%{GREEDYDATA:message}"]
        # overwrite => ["message"]
        add_field => {
    time => "%{timestamp}"
    error => "%{message}"
  }
         
         }

    date{
                match => ["timestamp","HH:mm:ss:SSS", "dd/MM/YY HH:mm:ss:SSS", "M/d/YY HH:mm:ss:SSS", "MM/d/YY HH:mm:ss:SSS", "M/dd/YY HH:mm:ss:SSS", "MM/dd/YY H:mm:ss:SSS", "M/d/YY H:mm:ss:SSS", "MM/d/YY H:mm:ss:SSS",
    "M/dd/YY H:mm:ss:SSS"]
    
    }

```

}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}  
stdout{ codec =\> rubydebug}`Preformatted text`  
}

---

<div class="post-metadata">

**Author:** ![anjali](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@anjali](https://discuss.elastic.co/u/anjali)\
**Post date:** [December 29, 2017, 6:29am UTC](https://discuss.elastic.co/t/logstash-output/113392/11 "2017-12-29T06:29:32Z")

</div>

Ahhhh! I didn't know about this code button. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2018, 6:29am UTC](https://discuss.elastic.co/t/logstash-output/113392/12 "2018-01-26T06:29:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
