# Logstash skipping files while reading config

**URL:** <https://discuss.elastic.co/t/logstash-skipping-files-while-reading-config/205767>\
**Category:** Logstash\
**Created:** [October 29, 2019, 11:17pm UTC](https://discuss.elastic.co/t/logstash-skipping-files-while-reading-config/205767 "2019-10-29T23:17:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [October 29, 2019, 11:17pm UTC](https://discuss.elastic.co/t/logstash-skipping-files-while-reading-config/205767/1 "2019-10-29T23:17:33Z")

</div>

Logstash just starts and shuts down due to configpathloader error. Please explain what the issue is.

Below is the config file-

filebeat.inputs:

- type: log  
paths:
  - /var/log/system.log
  - /var/log/wifi.log

- type: log  
paths:
  - "/var/log/apache2/\*"  
fields:  
apache: true  
fields\_under\_root: true

output.elasticsearch:  
hosts: ["[https://localhost:9200](https://localhost:9200/)"]  
index: "filebeat-%{[agent.version]}-%{+yyyy.MM.dd}"  
ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]  
ssl.certificate: "/etc/pki/client/cert.pem"  
ssl.key: "/etc/pki/client/cert.key"

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 29, 2019, 11:50pm UTC](https://discuss.elastic.co/t/logstash-skipping-files-while-reading-config/205767/2 "2019-10-29T23:50:32Z")

</div>

Please do not post pictures of text, just post the text.

Can you post the text of your configuration?

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [October 29, 2019, 11:54pm UTC](https://discuss.elastic.co/t/logstash-skipping-files-while-reading-config/205767/3 "2019-10-29T23:54:00Z")

</div>

Sorry about that! Didnt realize pictures weren't allowed.

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [October 30, 2019, 12:02am UTC](https://discuss.elastic.co/t/logstash-skipping-files-while-reading-config/205767/4 "2019-10-30T00:02:46Z")

</div>

Also I am not sure where to input path of a log file so filebeat uses it and sends it to elasticsearch.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 30, 2019, 12:12am UTC](https://discuss.elastic.co/t/logstash-skipping-files-while-reading-config/205767/5 "2019-10-30T00:12:41Z")

</div>

If you are using filebeat with an elasticsearch output then you should ask a question in the filebeat forum. The forums are more specific than you might expect.

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [October 30, 2019, 12:23am UTC](https://discuss.elastic.co/t/logstash-skipping-files-while-reading-config/205767/6 "2019-10-30T00:23:44Z")

</div>

Thanks, just posted the error and config file under Beats/Filebeats forum!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2019, 12:23am UTC](https://discuss.elastic.co/t/logstash-skipping-files-while-reading-config/205767/7 "2019-11-27T00:23:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
