# Logstash pipe plugin exec not working

**URL:** <https://discuss.elastic.co/t/logstash-pipe-plugin-exec-not-working/72097>\
**Category:** Logstash\
**Created:** [January 18, 2017, 11:43pm UTC](https://discuss.elastic.co/t/logstash-pipe-plugin-exec-not-working/72097 "2017-01-18T23:43:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sharat\_Jagannath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharat_jagannath/32/24299_2.png) [@Sharat\_Jagannath](https://discuss.elastic.co/u/Sharat_Jagannath)\
**Post date:** [January 18, 2017, 11:43pm UTC](https://discuss.elastic.co/t/logstash-pipe-plugin-exec-not-working/72097/1 "2017-01-18T23:43:22Z")

</div>

I have a logstash conf file that gets data from kafka as input and then based on if the input contains a field it is supposed to pipe the input data to a script(unix of python)  
For example-

```
input{
kafka {
zk_connect => '112.16.40.126:2181'
     topic_id => 'READY_FOR_INDEX'
  } 
 kafka {
      zk_connect => '112.16.40.126:2181'
      topic_id => 'INDEX_CSV'
   }
 } 
  output {
if ([csvLocation]) {
        pipe{
          command => "/home/test.sh"
        }
}
stdout {codec => rubydebug}

 }

```

The script reads the input as arguments i suppose

```
#!/bin/bash  
 while read LINE; do
   echo ${LINE} # do something with it here
   done

 exit 0

```

But for some reason the script does not get any data. How do i get this working to get all the input data.  
I was referring to [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-pipe.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-pipe.html)

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 20, 2017, 6:38am UTC](https://discuss.elastic.co/t/logstash-pipe-plugin-exec-not-working/72097/2 "2017-01-20T06:38:23Z")

</div>

Please show an example event (i.e. output from your `stdout {codec => rubydebug}` output). Is Logstash forking a child process that runs /home/test.sh? Is there anything in Logstash's log? You might want to increase the log level to see everything that's interesting.

---

<div class="post-metadata">

**Author:** ![Sharat\_Jagannath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharat_jagannath/32/24299_2.png) [@Sharat\_Jagannath](https://discuss.elastic.co/u/Sharat_Jagannath)\
**Post date:** [January 20, 2017, 6:43pm UTC](https://discuss.elastic.co/t/logstash-pipe-plugin-exec-not-working/72097/3 "2017-01-20T18:43:36Z")

</div>

@magnusbaeck Here us a sample stdout event.

```
 {
              "index" => "xxx",
     "dimension_name" => "xxx",
             "source" => "xxx",
               "type" => "xxx",
"abc" => {
                        "test1" => {
          "display_name" => "xxx",
        "testid" => "5xxx"
    },
                            "test2" => {
          "display_name" => "xxx2",
        "testid" => "6xxx"
    }
},
         "PROJECT_ID" => "xxx",
          "tableName" => "xxx",
        "csvLocation" => "abc.csv",
           "@version" => "1",
         "@timestamp" => "2017-01-19T21:24:21.775Z"
}

```

this is what i get when i run logstash in debug mode

Opening pipe {:command=\>"/home/test.sh", :level=\>:info}  
Starting stale pipes cleanup cycle {:pipes=\>{"python /home/test.sh"=\>#\<PipeWrapper:0x7150cc3 @pipe=#\<IO:fd 454\>, @active=true\>}, :level=\>:info}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 22, 2017, 1:50pm UTC](https://discuss.elastic.co/t/logstash-pipe-plugin-exec-not-working/72097/4 "2017-01-22T13:50:14Z")

</div>

But that's not the only output, right? Off the top of my head I don't know what's up here.

---

<div class="post-metadata">

**Author:** ![Sharat\_Jagannath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharat_jagannath/32/24299_2.png) [@Sharat\_Jagannath](https://discuss.elastic.co/u/Sharat_Jagannath)\
**Post date:** [January 23, 2017, 8:33pm UTC](https://discuss.elastic.co/t/logstash-pipe-plugin-exec-not-working/72097/5 "2017-01-23T20:33:15Z")

</div>

Sorry I didn't get you. I didn't post the actual output for privacy reasons.but its mostly structured that way.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 23, 2017, 9:23pm UTC](https://discuss.elastic.co/t/logstash-pipe-plugin-exec-not-working/72097/6 "2017-01-23T21:23:51Z")

</div>

Well, seeing more of the logs could be helpful. You can obfuscate sensitive parts if you like

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2017, 9:23pm UTC](https://discuss.elastic.co/t/logstash-pipe-plugin-exec-not-working/72097/7 "2017-02-20T21:23:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
