# Logstash own debugging logs location?

**URL:** <https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404>\
**Category:** Logstash\
**Created:** [March 15, 2016, 8:42am UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404 "2016-03-15T08:42:42Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [March 15, 2016, 8:42am UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404/1 "2016-03-15T08:42:42Z")

</div>

Hi,

I am trying to debug logstash; therefore, I need it's debug logs but couldn't find any. In fact, I moved the ELK stack from one Windows box to another. Obviously, version has also changed. Before I was using logstash-indexer.cfg but now I have noticed that there is by default another file called logstash.json. I did copy all the contents from old to new one and start the logstash service with logstash.json configuration file but it seems, it's not shipping logs to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2016, 9:06am UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404/2 "2016-03-15T09:06:06Z")

</div>

Logstash sends its logs to where you tell it to with the `-l`/`--log` option. Check how you invoke Logstash. Without that option Logstash will log to stdout (or is it stderr?).

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [March 15, 2016, 9:24am UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404/3 "2016-03-15T09:24:17Z")

</div>

I have a this line in my code:

stdout { codec =\> rubydebug}

Where to check the logs in this case?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2016, 9:33am UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404/4 "2016-03-15T09:33:31Z")

</div>

The answer is the same. Logstash's stdout output goes to the same location as its log.

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [March 15, 2016, 9:51am UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404/5 "2016-03-15T09:51:08Z")

</div>

Command line -l, --log FILE = Log to a given path. Default is to log to stdout

So, by default is there any location for stdout because it says by default it logs to stdout, what does it mean?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2016, 12:06pm UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404/6 "2016-03-15T12:06:17Z")

</div>

What "stdout" is and what it means is probably better explained elsewhere.

If a process's stdout stream isn't redirected anywhere it'll end up in the console/terminal where the process was started. If you're starting Logstash as a service on a Windows system you'll want to pass the `--log` option to have the logs written to a file.

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [March 15, 2016, 1:25pm UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404/7 "2016-03-15T13:25:15Z")

</div>

Thanks Magnus. Now, I can see the logs and as per log, I guess, logs are being shipped to Elasticsearch from Logstash but I can't see them in Kibana. I can only see the logs that are coming via Winlogbeats but not Logstash.

Is there any way to check it out if Elasticsearch is receiving the logs or not?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2016, 1:33pm UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404/8 "2016-03-15T13:33:31Z")

</div>

Perhaps the logs are there, it's just that you're looking for them in the wrong time interval.

You could capture and analyze the network traffic, measure the number of documents in the ES indexes before and after Logstash runs, widen your search to search in all indexes, etc.

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [March 16, 2016, 5:24am UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404/9 "2016-03-16T05:24:45Z")

</div>

Thanks a lot... I did create a new index for Logstash-, now I can see. You are a star!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/logstash-own-debugging-logs-location/44404/10 "2017-07-06T05:06:49Z")

</div>


