# Logstash running as service is not sending logs

**URL:** <https://discuss.elastic.co/t/logstash-running-as-service-is-not-sending-logs/208777>\
**Category:** Logstash\
**Created:** [November 20, 2019, 9:12pm UTC](https://discuss.elastic.co/t/logstash-running-as-service-is-not-sending-logs/208777 "2019-11-20T21:12:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![alesabat](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@alesabat](https://discuss.elastic.co/u/alesabat)\
**Post date:** [November 20, 2019, 9:12pm UTC](https://discuss.elastic.co/t/logstash-running-as-service-is-not-sending-logs/208777/1 "2019-11-20T21:12:31Z")

</div>

Hi there!

I have a rhel ppc64le with tomcat. Wanted to send logs to ELK cluster (filebeat discarted because has no ppc version, so I choose logstash).

If I run logstash from CLI, it works fine and I can discover logs in KIbana. But if I start logstash service, stop sending logs. Theese are commands issued:

/bin/logstash -f /etc/logstash/conf.d/myconf.conf -path.settings /etc/logstash (works fine).

systemctl stasrt logstash (service starts OK, no error logs, but not sending logs to ELK).

I checked /etc/logstash/logstash.yml, /etc/logstasg/pipelines.yml, etc... and everythings looks correctly.

I will very appreciatte any help.

Regards!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 20, 2019, 9:28pm UTC](https://discuss.elastic.co/t/logstash-running-as-service-is-not-sending-logs/208777/2 "2019-11-20T21:28:03Z")

</div>

Try

```
systemctl show logstash.service | grep ExecStart

```

Then run the command that that shows.

---

<div class="post-metadata">

**Author:** ![alesabat](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@alesabat](https://discuss.elastic.co/u/alesabat)\
**Post date:** [November 21, 2019, 1:25pm UTC](https://discuss.elastic.co/t/logstash-running-as-service-is-not-sending-logs/208777/3 "2019-11-21T13:25:24Z")

</div>

This is the output:

ExecStart={ path=/usr/share/logstash/bin/logstash ; argv=/usr/share/logstash/bin/logstash --path.settings /etc/logstash ; ignore\_errors=no ; start\_time=[Wed 2019-11-20 15:51:15 -03] ; stop\_time=[n/a] ; pid=21171 ; code=(null) ; status=0/0 }

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 21, 2019, 1:43pm UTC](https://discuss.elastic.co/t/logstash-running-as-service-is-not-sending-logs/208777/4 "2019-11-21T13:43:52Z")

</div>

> [@alesabat](#):
>
> /usr/share/logstash/bin/logstash --path.settings /etc/logstash

What is logged when you execute that? (You will need to stop the service before doing so.)

---

<div class="post-metadata">

**Author:** ![alesabat](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@alesabat](https://discuss.elastic.co/u/alesabat)\
**Post date:** [November 21, 2019, 2:09pm UTC](https://discuss.elastic.co/t/logstash-running-as-service-is-not-sending-logs/208777/5 "2019-11-21T14:09:48Z")

</div>

Okay, I did it (I did run with root user and logstash user, getting same behavior).

It's weird but is not logging anything (I'm checking /var/log/logstash/logstash-plain.log and /var/log/messages). No logs are sending to Kibana, but process is running.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [November 21, 2019, 3:30pm UTC](https://discuss.elastic.co/t/logstash-running-as-service-is-not-sending-logs/208777/6 "2019-11-21T15:30:03Z")

</div>

When you ran from the command line as root, files were probably created owned by root. When you run from systemctl, it will probably run with user logstash and won't have permission to the files it needs to run. The pid file is the most notorious.

So, check file ownership 🙂

---

<div class="post-metadata">

**Author:** ![alesabat](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@alesabat](https://discuss.elastic.co/u/alesabat)\
**Post date:** [November 22, 2019, 7:02pm UTC](https://discuss.elastic.co/t/logstash-running-as-service-is-not-sending-logs/208777/7 "2019-11-22T19:02:09Z")

</div>

Hi, thanks for your answer. I've checked this out, this is what I got:

I have this lines from /etc/logstash/startup.options:

```
\# pidfiles aren't used the same way for upstart and systemd; this is for sysv users.
LS_PIDFILE=/var/run/logstash.pid

```

/var/run is a symbolic link which points to /run.

ls /run/logstash.pid file doesn't exists (logstash service status is running). Shoul I create it?

Theese are /run permissions:

drwxr-xr-x. 32 root root 980 Nov 21 10:57 /run

I added write permissions to others, restarted logstash but problem is still there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2019, 7:02pm UTC](https://discuss.elastic.co/t/logstash-running-as-service-is-not-sending-logs/208777/8 "2019-12-20T19:02:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
