# Logstash problem with Elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-problem-with-elasticsearch/111795>\
**Category:** Logstash\
**Created:** [December 14, 2017, 3:03pm UTC](https://discuss.elastic.co/t/logstash-problem-with-elasticsearch/111795 "2017-12-14T15:03:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Judin](https://avatars.discourse-cdn.com/v4/letter/j/4491bb/32.png) [@Judin](https://discuss.elastic.co/u/Judin)\
**Post date:** [December 14, 2017, 3:03pm UTC](https://discuss.elastic.co/t/logstash-problem-with-elasticsearch/111795/1 "2017-12-14T15:03:42Z")

</div>

Hi,

First I appologize for my english it's not my first langage.

I did not find a similar post about my issue that's why i'm creating a new one.

I have a test environnement composed by Elasticsearch, Logstash, Kibana and X-Pack version 6.0.0.  
All work fine except for my logstash configurations.

When I start logstash as a service or in command line, i have the following error : "ERROR: There are config files (1) in the '/etc/logstash/conf.d/winlogbeat.conf' folder. Elasticsearch is configured as the config store so configs cannot be sourced via the command line with -f or via logstash.yml with path.config".

I don't understand what "Elasticsearch is configured as the config store" means.

Could anyone help me please ?

Thank you,  
Judin

---

<div class="post-metadata">

**Author:** ![yishain11](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Post date:** [December 26, 2017, 8:35am UTC](https://discuss.elastic.co/t/logstash-problem-with-elasticsearch/111795/2 "2017-12-26T08:35:19Z")

</div>

I have the exact same issue. Can anyone give us any solution?

Here is the logstash log:

`[2017-12-26T10:35:28,062][ERROR][logstash.configmanagement.bootstrapcheck] There are config files (1) in the '/etc/logstash/conf.d/*.conf' folder. Elasticsearch is configured as the config store so configs cannot be sourced via the command line with -f or via logstash.yml with path.config`

---

<div class="post-metadata">

**Author:** ![iamhowardtheduck](https://avatars.discourse-cdn.com/v4/letter/i/ecb155/32.png) [@iamhowardtheduck](https://discuss.elastic.co/u/iamhowardtheduck)\
**Post date:** [December 26, 2017, 10:37pm UTC](https://discuss.elastic.co/t/logstash-problem-with-elasticsearch/111795/3 "2017-12-26T22:37:14Z")

</div>

Same issue here, I've found that if comment out the path.settings for the \*.conf file it boots up fine, but of course no data is ingested. I am trying to employ this with the ArcSight module and I am still unable to get it working as well. If include the path settings, Logstash throws the errors, logs are ingested, but no ArcSigt module. I am hoping to hear a response back as well.

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [December 27, 2017, 12:49am UTC](https://discuss.elastic.co/t/logstash-problem-with-elasticsearch/111795/4 "2017-12-27T00:49:15Z")

</div>

That's a weird error message. Is `/etc/logstash/conf.d/winlogbeat.conf` even a folder? It should be a file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2018, 12:49am UTC](https://discuss.elastic.co/t/logstash-problem-with-elasticsearch/111795/5 "2018-01-24T00:49:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![insuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/insuk/32/29396_2.png) [@insuk](https://discuss.elastic.co/u/insuk)\
**Post date:** [March 8, 2019, 4:03am UTC](https://discuss.elastic.co/t/logstash-problem-with-elasticsearch/111795/7 "2019-03-08T04:03:58Z")

</div>

> [@Judin](#):
>
> "ERROR: There are config files (1) in the '/etc/logstash/conf.d/winlogbeat.conf' folder. Elasticsearch is configured as the config store so configs cannot be sourced via the command line with -f or via logstash.yml with path.config"

It seems you've enabled [Centralized Pipeline Management](https://www.elastic.co/guide/en/logstash/6.6/configuring-centralized-pipelines.html#configuring-centralized-pipelines), so you can no longer specify local pipeline configurations.
