# LOGSTASH, simple code unable to get output in elasticsearch and kibana

**URL:** <https://discuss.elastic.co/t/logstash-simple-code-unable-to-get-output-in-elasticsearch-and-kibana/206848>\
**Category:** Logstash\
**Created:** [November 6, 2019, 6:33pm UTC](https://discuss.elastic.co/t/logstash-simple-code-unable-to-get-output-in-elasticsearch-and-kibana/206848 "2019-11-06T18:33:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![santhosh\_l](https://avatars.discourse-cdn.com/v4/letter/s/f08c70/32.png) [@santhosh\_l](https://discuss.elastic.co/u/santhosh_l)\
**Post date:** [November 6, 2019, 6:33pm UTC](https://discuss.elastic.co/t/logstash-simple-code-unable-to-get-output-in-elasticsearch-and-kibana/206848/1 "2019-11-06T18:33:29Z")

</div>

Hello all,

I am a beginner in elk, i am trying to execute logstash ( through power shell). when ever i execute the fallowing command :-

C:\siem\> .\logstash-7.4.1\bin\logstash.bat -f .\myfirst.conf

the output on the powershell is this:-

Java HotSpot(TM) 64-Bit Server VM warning: Option UseConcMarkSweepGC was deprecated in version 9.0 and will likely be removed in a future release.  
WARNING: An illegal reflective access operation has occurred  
WARNING: Illegal reflective access by org.jruby.runtime.encoding.EncodingService (file:/C:/siem/logstash-7.4.1/logstash-core/lib/jars/jruby-complete-9.2.8.0.jar) to field java.io.Console.cs  
WARNING: Please consider reporting this to the maintainers of org.jruby.runtime.encoding.EncodingService  
WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations  
WARNING: All illegal access operations will be denied in a future release  
Thread.exclusive is deprecated, use Thread::Mutex  
Sending Logstash logs to C:/siem/logstash-7.4.1/logs which is now configured via log4j2.properties  
[2019-11-06T13:02:04,511][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-11-06T13:02:04,528][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.4.1"}  
[2019-11-06T13:02:07,219][INFO][org.reflections.Reflections] Reflections took 63 ms to scan 1 urls, producing 20 keys and 40 values  
[2019-11-06T13:02:08,703][INFO][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2019-11-06T13:02:08,999][WARN][logstash.outputs.elasticsearch][main] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2019-11-06T13:02:09,063][INFO][logstash.outputs.elasticsearch][main] ES Output version determined {:es\_version=\>7}  
[2019-11-06T13:02:09,067][WARN][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>7}  
[2019-11-06T13:02:09,103][INFO][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
[2019-11-06T13:02:09,203][INFO][logstash.outputs.elasticsearch][main] Using default mapping template  
[2019-11-06T13:02:09,263][WARN][org.logstash.instrument.metrics.gauge.LazyDelegatingGauge][main] A gauge metric of an unknown type (org.jruby.specialized.RubyArrayOneObject) has been create for key: cluster\_uuids. This may result in invalid serialization. It is recommended to log an issue to the responsible developer/development team.  
[2019-11-06T13:02:09,277][INFO][logstash.javapipeline][main] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50, "pipeline.max\_inflight"=\>500, :thread=\>"#\<Thread:0xbe34079 run\>"}  
[2019-11-06T13:02:09,325][INFO][logstash.outputs.elasticsearch][main] Attempting to install template {:manage\_template=\>{"index\_patterns"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s", "number\_of\_shards"=\>1}, "mappings"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}  
[2019-11-06T13:02:10,318][INFO][logstash.inputs.file][main] No sincedb\_path set, generating one based on the "path" setting {:sincedb\_path=\>"C:/siem/logstash-7.4.1/data/plugins/inputs/file/.sincedb\_f5fa93b0623f6608d9a7bf96966c81e5", :path=\>["C:\siem\logs\_for\_filebeat\logstash-tutorial-dataset.txt"]}  
[2019-11-06T13:02:10,354][INFO][logstash.javapipeline][main] Pipeline started {"pipeline.id"=\>"main"}  
[2019-11-06T13:02:10,510][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2019-11-06T13:02:10,526][INFO][filewatch.observingtail][main] START, creating Discoverer, Watch with file and sincedb collections  
[2019-11-06T13:02:11,540][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

Now if i go and check in **elasticsearch** ----\> index managament, I am unable to find the **"myfirst"** (index) and even in **kibana** as well, which i have mentioned in the configuration file. The logstash configuration file is like this:-- myfirst.conf

input {  
file {  
path =\> "C:\siem\logs\_for\_filebeat\logstash-tutorial-dataset.txt"  
start\_position =\> "beginning"  
}  
}  
output {  
elasticsearch { hosts =\> ["localhost:9200"]  
index =\> "myfirst"  
}  
stdout{ codec =\> rubydebug}

```
     }	

```

versions of all 3:-

elasticsearch-7.4.1  
kibana-7.4.1-windows-x86\_64  
logstash-7.4.1

I dont know where it is going wrong.

So, could you please help me to understand or educate more on this and down the line.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 6, 2019, 7:22pm UTC](https://discuss.elastic.co/t/logstash-simple-code-unable-to-get-output-in-elasticsearch-and-kibana/206848/2 "2019-11-06T19:22:25Z")

</div>

> [@santhosh\_l](#):
>
> path =\> "C:\siem\logs\_for\_filebeat\logstash-tutorial-dataset.txt"

Do not use backslash in the path option of a file input. Use forward slash.

---

<div class="post-metadata">

**Author:** ![santhosh\_l](https://avatars.discourse-cdn.com/v4/letter/s/f08c70/32.png) [@santhosh\_l](https://discuss.elastic.co/u/santhosh_l)\
**Post date:** [November 6, 2019, 9:01pm UTC](https://discuss.elastic.co/t/logstash-simple-code-unable-to-get-output-in-elasticsearch-and-kibana/206848/3 "2019-11-06T21:01:31Z")

</div>

Hello Badger,

as per your specifications, i have changed the path to the fallowing:-

path =\> "C:/siem/logs\_for\_filebeat/logstash-tutorial-dataset.txt"

and i have ran the command in powershell windows

PS C:\siem\> .\logstash-7.4.1\bin\logstash.bat -f .\myfirst.conf

The logs on the powershell as fallows:-

Java HotSpot(TM) 64-Bit Server VM warning: Option UseConcMarkSweepGC was deprecated in version 9.0 and will likely be removed in a future release.  
WARNING: An illegal reflective access operation has occurred  
WARNING: Illegal reflective access by org.jruby.runtime.encoding.EncodingService (file:/C:/siem/logstash-7.4.1/logstash-core/lib/jars/jruby-complete-9.2.8.0.jar) to field java.io.Console.cs  
WARNING: Please consider reporting this to the maintainers of org.jruby.runtime.encoding.EncodingService  
WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations  
WARNING: All illegal access operations will be denied in a future release  
Thread.exclusive is deprecated, use Thread::Mutex  
Sending Logstash logs to C:/siem/logstash-7.4.1/logs which is now configured via log4j2.properties  
[2019-11-06T15:58:29,213][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-11-06T15:58:29,245][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.4.1"}  
[2019-11-06T15:58:32,252][INFO][org.reflections.Reflections] Reflections took 51 ms to scan 1 urls, producing 20 keys and 40 values  
[2019-11-06T15:58:34,197][INFO][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2019-11-06T15:58:34,500][WARN][logstash.outputs.elasticsearch][main] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2019-11-06T15:58:34,563][INFO][logstash.outputs.elasticsearch][main] ES Output version determined {:es\_version=\>7}  
[2019-11-06T15:58:34,572][WARN][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>7}  
[2019-11-06T15:58:34,618][INFO][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
[2019-11-06T15:58:34,793][INFO][logstash.outputs.elasticsearch][main] Using default mapping template  
[2019-11-06T15:58:34,822][WARN][org.logstash.instrument.metrics.gauge.LazyDelegatingGauge][main] A gauge metric of an unknown type (org.jruby.specialized.RubyArrayOneObject) has been create for key: cluster\_uuids. This may result in invalid serialization. It is recommended to log an issue to the responsible developer/development team.  
[2019-11-06T15:58:34,847][INFO][logstash.javapipeline][main] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50, "pipeline.max\_inflight"=\>500, :thread=\>"#\<Thread:0x154920b1 run\>"}  
[2019-11-06T15:58:34,906][INFO][logstash.outputs.elasticsearch][main] Attempting to install template {:manage\_template=\>{"index\_patterns"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s", "number\_of\_shards"=\>1}, "mappings"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}  
[2019-11-06T15:58:36,239][INFO][logstash.inputs.file][main] No sincedb\_path set, generating one based on the "path" setting {:sincedb\_path=\>"C:/siem/logstash-7.4.1/data/plugins/inputs/file/.sincedb\_5be0d94968a6f971cbb160730d8a33e2", :path=\>["C:/siem/logs\_for\_filebeat/logstash-tutorial-dataset.txt"]}  
[2019-11-06T15:58:36,314][INFO][logstash.javapipeline][main] Pipeline started {"pipeline.id"=\>"main"}  
[2019-11-06T15:58:36,418][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2019-11-06T15:58:36,506][INFO][filewatch.observingtail][main] START, creating Discoverer, Watch with file and sincedb collections  
[2019-11-06T15:58:38,036][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

When i checked in **elasticsearch** --\> index management , i could not see the **myfirst**  
index still.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 6, 2019, 9:25pm UTC](https://discuss.elastic.co/t/logstash-simple-code-unable-to-get-output-in-elasticsearch-and-kibana/206848/4 "2019-11-06T21:25:37Z")

</div>

Try enabling log.level trace, restarting, and then appending a line to your text file. The filewatch code should tell you when it outputs an event with trace logging enabled.

---

<div class="post-metadata">

**Author:** ![santhosh\_l](https://avatars.discourse-cdn.com/v4/letter/s/f08c70/32.png) [@santhosh\_l](https://discuss.elastic.co/u/santhosh_l)\
**Post date:** [November 6, 2019, 9:40pm UTC](https://discuss.elastic.co/t/logstash-simple-code-unable-to-get-output-in-elasticsearch-and-kibana/206848/5 "2019-11-06T21:40:59Z")

</div>

> [@Badger](#):
>
> Try enabling log.level trace, restarting, and then appending a line to your text file. The filewatch code should tell you when it outputs an event with trace logging enabled.

Hello Badger,

1. log.level trace (i dont know how, but i will search in the web and i will find out.)
2. restarting ( it can be done)  
3.appending a line to text file ( it can be done)
3. filewatch code ( i dont know how, but i will search in the web and i will find out.)
4. trace logging enabled ( i dont know how, but i will search in the web and i will find out.)

Sorry I am a beginner.

I wil get back to you soon

Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2019, 9:41pm UTC](https://discuss.elastic.co/t/logstash-simple-code-unable-to-get-output-in-elasticsearch-and-kibana/206848/6 "2019-12-04T21:41:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
