# Logstash service will not run (Ubuntu server 14.04)

**URL:** <https://discuss.elastic.co/t/logstash-service-will-not-run-ubuntu-server-14-04/44719>\
**Category:** Logstash\
**Created:** [March 17, 2016, 2:39pm UTC](https://discuss.elastic.co/t/logstash-service-will-not-run-ubuntu-server-14-04/44719 "2016-03-17T14:39:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Post date:** [March 17, 2016, 2:39pm UTC](https://discuss.elastic.co/t/logstash-service-will-not-run-ubuntu-server-14-04/44719/1 "2016-03-17T14:39:51Z")

</div>

Hi,

I'm trying out the ELK stack on an environment of 1 ELK server, two client servers and one laptop to access Kabina.

I have followed [https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-04](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-04) throughout and got to the point where I am configuring my client servers.

I came across a problem. I set up filebeat and configured it by following the guide, everything worked out well but when I try to restart the filebeat service to save the changes I get the following message:

- Restarting Sends log files to Logstash or directly to Elasticsearch. filebeat 2016/03/17 14:25:12.419905 transport.go:125: ERR SSL client failed to connect with: dial tcp [XXX.XXX.XXX.XXX:5044](http://XXX.XXX.XXX.XXX:5044): getsockopt: connection refused.

I tried to troubleshoot this myself and thought that something was wrong with either the SSL cert I made or the port. But I'm pretty sure my configs are correct.

After some time I noticed that my logstash service was not running so i went ahead and started it, but and it started up but after 5 seconds it just goes back to not running.

Can someone help me out?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 18, 2016, 4:52am UTC](https://discuss.elastic.co/t/logstash-service-will-not-run-ubuntu-server-14-04/44719/2 "2016-03-18T04:52:51Z")

</div>

Check your LS logs, if there is nothing run LS directly using the same command as the service to see what is happening.

---

<div class="post-metadata">

**Author:** ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Post date:** [March 18, 2016, 10:53am UTC](https://discuss.elastic.co/t/logstash-service-will-not-run-ubuntu-server-14-04/44719/3 "2016-03-18T10:53:59Z")

</div>

> [@Configuring filebeat to send specified logs to E.L.K server's logstash HELP!](https://discuss.elastic.co/t/configuring-filebeat-to-send-specified-logs-to-e-l-k-servers-logstash-help/44830):
>
> Hi there, About two days ago I started looking into ELK and decided to try it out on a few machines. My set-up is the following: 1 E.L.K server, 2 Client servers and 1 Laptop to access Kibana. I have followed the official guide of installation on Ubuntu 14.04 and reached the part where I start configuring my client servers to send out the logs to the logstash. I have created the following filebeat.yml stored in /etc/filebeat/ filebeat: prospectors: - paths: - /var/log/au…

Created a new topic with much more info, this one can be closed

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/logstash-service-will-not-run-ubuntu-server-14-04/44719/4 "2017-07-06T05:06:28Z")

</div>


