# Logstash status: Failed to start logstash

**URL:** <https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065>\
**Category:** Logstash\
**Created:** [January 22, 2020, 1:15pm UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065 "2020-01-22T13:15:01Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ekta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ekta/32/55987_2.png) [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Post date:** [January 22, 2020, 1:15pm UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/1 "2020-01-22T13:15:01Z")

</div>

logstash failed to start.

I am using logstash7 .2.0  
Elasticsearch-7.2.0  
Java-11.0.6

When I check the status after starting it shows Active:Failed.

$: systemctl status logstash.service  
â logstash.service - logstash  
Loaded: loaded (/etc/systemd/system/logstash.service; enabled; vendor preset: enabled)  
Active: failed (Result: exit-code) since Wed 2020-01-22 08:04:59 EST; 37s ago  
Main PID: 12167 (code=exited, status=1/FAILURE)

systemd[1]: logstash.service: Service hold-off time over, scheduling restart.  
Jan 22 08:04:59 xxxxxxx systemd[1]: logstash.service: Scheduled restart job, restart counter is at 5.  
Jan 22 08:04:59 xxxxxxx systemd[1]: Stopped logstash.  
Jan 22 08:04:59 xxxxxxx systemd[1]: logstash.service: Start request repeated too quickly.  
Jan 22 08:04:59 xxxxxxx systemd[1]: logstash.service: Failed with result 'exit-code'.  
Jan 22 08:04:59 xxxxxxx systemd[1]: Failed to start logstash.

can any help why is it failed?

---

<div class="post-metadata">

**Author:** ![Ekta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ekta/32/55987_2.png) [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Post date:** [January 22, 2020, 1:43pm UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/2 "2020-01-22T13:43:50Z")

</div>

after stopping logstash service It also shows status failed instead of inactive.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [January 22, 2020, 11:30pm UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/3 "2020-01-22T23:30:28Z")

</div>

What do Logstash's logs say? The location of your logs depends on how you installed Logstash, but [this documentation](https://www.elastic.co/guide/en/logstash/current/dir-layout.html) should help you find them.

---

<div class="post-metadata">

**Author:** ![Ekta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ekta/32/55987_2.png) [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Post date:** [January 23, 2020, 12:33am UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/4 "2020-01-23T00:33:01Z")

</div>

Hi yaauie,

I compared with this as I am downloaded with .deb file.  
It is the same as a document  
so... now what to do

**The Debian package and the RPM package each place config files**

---

<div class="post-metadata">

**Author:** ![Ekta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ekta/32/55987_2.png) [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Post date:** [January 23, 2020, 12:54am UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/5 "2020-01-23T00:54:02Z")

</div>

I am trying this on also as below  
 cd /usr/share/logstash sudo bin/logstah -f /etc/logstash/conf.d/example.conf

but it shows below error:

:/usr/share/logstash# sudo /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/example.conf  
**could not find java; set JAVA\_HOME or ensure java is in PATH**

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [January 23, 2020, 1:12am UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/6 "2020-01-23T01:12:33Z")

</div>

As the error message states, you need to have a valid java on your `PATH`, or need to have an environment variable `JAVA_HOME` that points to a valid java.

---

<div class="post-metadata">

**Author:** ![Ekta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ekta/32/55987_2.png) [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Post date:** [January 23, 2020, 1:42am UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/7 "2020-01-23T01:42:39Z")

</div>

Hi yaauie,

already set this variable in bashrc file

JAVA\_HOME="/usr/lib/jvm/jdk-11.0.6/"  
export JAVA\_HOME  
export PATH=$PATH:$JAVA\_HOME/bin

and javac is working properly

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 23, 2020, 8:30am UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/8 "2020-01-23T08:30:41Z")

</div>

Did you set this as root user or normal user ? that's how things usually break with envars.

---

<div class="post-metadata">

**Author:** ![Ekta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ekta/32/55987_2.png) [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Post date:** [January 28, 2020, 12:06am UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/9 "2020-01-28T00:06:47Z")

</div>

Hi Grumo  
I am at root user

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 28, 2020, 3:37am UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/10 "2020-01-28T03:37:53Z")

</div>

Sooooo,

The paths might be all broken if you install dependencies and other stuff as root user without using "sudo" before each command you'll most likely end-up with think not working.

My advice is to re install java with sudo as normal user and then start logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 25, 2020, 3:38am UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065/11 "2020-02-25T03:38:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
