# Logstash pipeline not starting

**URL:** <https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937>\
**Category:** Logstash\
**Created:** [March 24, 2017, 6:27pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937 "2017-03-24T18:27:05Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![g.le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/g.le/32/22526_2.png) [@g.le](https://discuss.elastic.co/u/g.le)\
**Post date:** [March 24, 2017, 6:27pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/1 "2017-03-24T18:27:05Z")

</div>

Hello,  
I have created a rather complex Logstash config using various plugins.

I have noticed that Logstash normally produces the following entries in /var/log/logstash/logstash-plain.log:

**[2017-03-24T20:01:05,639][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>250}**  
**[2017-03-24T20:01:05,643][INFO][logstash.pipeline] Pipeline main started**  
[2017-03-24T20:01:05,713][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

Nevertheless, there are cases where Logstash seems not to be able to start a pipeline _and keeps retrying_ (i.e. logs are starting over).  
In those cases the first two entries mentioned above (in bold) are completely missing.

No errors are logged, therefore I cannot understand what the issue mught be.  
Any help?

Thank you!

---

<div class="post-metadata">

**Author:** ![suyograo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyograo/32/44898_2.png) [@suyograo](https://discuss.elastic.co/u/suyograo)\
**Post date:** [March 24, 2017, 6:40pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/2 "2017-03-24T18:40:35Z")

</div>

You can try running Logstash with --debug. Also, check if there is a stderr. What OS/platform and version is this?

---

<div class="post-metadata">

**Author:** ![raorashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raorashmi/32/16721_2.png) [@raorashmi](https://discuss.elastic.co/u/raorashmi)\
**Post date:** [March 25, 2017, 2:19pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/3 "2017-03-25T14:19:10Z")

</div>

Hi! I am using Ubuntu 14.04 version vm and have installed Elasticsearch 5.2.2 and Logstash 5.2.2.  
I used [https://www.elastic.co/guide/en/logstash/current/installing-logstash.html](https://www.elastic.co/guide/en/logstash/current/installing-logstash.html) to install logstash using apt-get.  
I have started elasticsearch and logstash as service but when I try to run ./logstash "Pipeline main started" isnt appearing in the console. When I check /var/logs/logstash/logstash.err I am not able to see any logs. My default Logstash directory is not /opt/logstash. It is /usr/share/logstash. Not able to find what am I doing wrong. Sorry but I am new to ELK and I might be missing something obvious. Please help.

---

<div class="post-metadata">

**Author:** ![laangarita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laangarita/32/14376_2.png) [@laangarita](https://discuss.elastic.co/u/laangarita)\
**Post date:** [March 25, 2017, 4:29pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/4 "2017-03-25T16:29:59Z")

</div>

Hey Rashmi,

You can verify your config as such:  
--config.debug  
Show the fully compiled configuration as a debug log message (you must also have --log.level=debug enabled). WARNING: The log message will include any password options passed to plugin configs as plaintext, and may result in plaintext passwords appearing in your logs!

Also, your bolded entry shows " **pipeline.max\_inflight" =\> 250**. I verified your settings at this link and that arguments doesn't seem to be an option. When you specify batch size, that sets the maximum for you : [https://www.elastic.co/guide/en/logstash/5.2/running-logstash-command-line.html](https://www.elastic.co/guide/en/logstash/5.2/running-logstash-command-line.html)

Try running:  
# \<logstash\_home\>/bin/logstash --debug -f \<logstash\_home\>/conf/ -w 2 -b 125 -u 5

... and see what it tells you. You can add -l \<log\_file\> to capture the output in a log file and just "tail -f" the log file.

Post your output if you continue to have issues or if you remove the pipeline.max\_inflight argument from your startup script and it resolves the issue, feel free to post as well 😉

---

<div class="post-metadata">

**Author:** ![raorashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raorashmi/32/16721_2.png) [@raorashmi](https://discuss.elastic.co/u/raorashmi)\
**Post date:** [March 26, 2017, 6:27am UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/5 "2017-03-26T06:27:04Z")

</div>

Hey Luis,  
That code in bold is not mine. My problem is "pipeline main started" isnt even appearing in console when I try to run the basic logstash pipeline given in [https://www.elastic.co/guide/en/logstash/current/first-event.html](https://www.elastic.co/guide/en/logstash/current/first-event.html)

---

<div class="post-metadata">

**Author:** ![g.le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/g.le/32/22526_2.png) [@g.le](https://discuss.elastic.co/u/g.le)\
**Post date:** [March 27, 2017, 8:03am UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/6 "2017-03-27T08:03:17Z")

</div>

@suyograo : I'm using Logstash 5.2.1 under CentOS 7. There is no \*.err log file generated though; all output is logged under /var/log/logstash/logstash-plain.log

@laangarita : I am worried about the pipeline.max\_inflight mentioned in the logs as well. Nevertheless, I am using the default logstash.yml and there is no explicit specification of this flag.

Anyway, I have enabled the debug parameter and logs are getting temporarily stuck at:

**[2017-03-27T10:55:29,822][DEBUG][logstash.filters.aggregate] Aggregate register call {:code=\>"map['EventMap'] = event.get('Event')"}**  
**[2017-03-27T10:55:29,824][DEBUG][logstash.filters.aggregate] Aggregate register call {:code=\>"event.set('Event', (map['EventMap'])"}**  
**[2017-03-27T10:55:29,830][DEBUG][logstash.agent] Starting puma**  
**[2017-03-27T10:55:29,831][DEBUG][logstash.agent] Trying to start WebServer {:port=\>9600}**  
**[2017-03-27T10:55:29,831][DEBUG][logstash.api.service] [api-service] start**  
**[2017-03-27T10:55:29,849][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}**

Then, the following error appears and entries are starting over:

**[2017-03-27T11:01:59,373][DEBUG][logstash.agent] Error in reactor loop escaped: Bad file descriptor - Bad file descriptor (Errno::EBADF)**  
_[2017-03-27T11:02:53,728][DEBUG][logstash.runner] -------- Logstash Settings ( means modified) ---------_\*  
**[2017-03-27T11:02:53,729][DEBUG][logstash.runner] [node.name](http://node.name): "[some.host.name](http://some.host.name)"**  
_**[2017-03-27T11:02:53,729][DEBUG][logstash.runner] \*path.config: "/etc/logstash/conf.d"**_  
_**[2017-03-27T11:02:53,730][DEBUG][logstash.runner] \*path.data: "/var/lib/logstash" (default: "/usr/share/logstash/data")**_

Finally, note how path.config and path.data are marked as modified during the "start-over".

Any ideas?

---

<div class="post-metadata">

**Author:** ![laangarita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laangarita/32/14376_2.png) [@laangarita](https://discuss.elastic.co/u/laangarita)\
**Post date:** [March 27, 2017, 5:24pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/7 "2017-03-27T17:24:22Z")

</div>

Hi @suyograo

All I can find for this is a bug reported and getting worked on:  
[https://github.com/elastic/logstash/issues/5822](https://github.com/elastic/logstash/issues/5822).

Anyone else have any information on this?

---

<div class="post-metadata">

**Author:** ![laangarita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laangarita/32/14376_2.png) [@laangarita](https://discuss.elastic.co/u/laangarita)\
**Post date:** [March 27, 2017, 5:27pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/8 "2017-03-27T17:27:58Z")

</div>

Hi @raorashmi,

This pipeline from the link assumes that you have data being sent to your logstash instance to get some sort of output. Have you tried adding the --debg flag to your command? If so, do you get anything?

---

<div class="post-metadata">

**Author:** ![g.le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/g.le/32/22526_2.png) [@g.le](https://discuss.elastic.co/u/g.le)\
**Post date:** [March 28, 2017, 6:38am UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/9 "2017-03-28T06:38:02Z")

</div>

Hi @laangarita

The issue was due to an extra parenthesis in the [code](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate-code) part of the Aggregate filter plugin.  
I am wondering why I never got a syntax error during startup.

I suggest @raorashmi to also perform a syntax check in any ruby code she might be using.

---

<div class="post-metadata">

**Author:** ![laangarita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laangarita/32/14376_2.png) [@laangarita](https://discuss.elastic.co/u/laangarita)\
**Post date:** [March 29, 2017, 7:46pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/10 "2017-03-29T19:46:32Z")

</div>

Thanks for the update @g.le. I'll keep this in mind for those who face similar issues in the future.

---

<div class="post-metadata">

**Author:** ![g.le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/g.le/32/22526_2.png) [@g.le](https://discuss.elastic.co/u/g.le)\
**Post date:** [March 29, 2017, 8:01pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/11 "2017-03-29T20:01:38Z")

</div>

In the meantime, anyone having access could file a report for investigating why the Aggregate filter plugin either does not perform Ruby syntax check or suppresses the error

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2017, 8:01pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937/12 "2017-04-26T20:01:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
