# Logstash Stdout empty

**URL:** <https://discuss.elastic.co/t/logstash-stdout-empty/342073>\
**Category:** Logstash\
**Created:** [August 31, 2023, 3:53pm UTC](https://discuss.elastic.co/t/logstash-stdout-empty/342073 "2023-08-31T15:53:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bountardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bountardos/32/129564_2.png) [@Bountardos](https://discuss.elastic.co/u/Bountardos)\
**Post date:** [August 31, 2023, 3:53pm UTC](https://discuss.elastic.co/t/logstash-stdout-empty/342073/1 "2023-08-31T15:53:39Z")

</div>

Hi there, i'm having issues with a recent configuration on my logstash and i can't understand why it's not working.  
I have multiple configuration files running, and working. This one was working also as of a week ago, but we changed the source IP that was sending the logs, that is all, so we updated the filter in our configuration file and nothing is showinf anymore.

```auto
# FIle
input {
  udp {
    port => 10000
  }
}

filter {
# empty for now
}

output {
  stdout { codec => rubydebug { metadata => true } }

  kafka {
    ...
  }
}

```

Pretty basic configuration, please ignore the "..." under kafka, that is working i just removed it here for clarity.

If i do a tcpdump on the port we receive the logs, the server is listeneing on the port on udp, but i never see anything via the stdout and i can't understand why. Any ideas please?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [August 31, 2023, 4:50pm UTC](https://discuss.elastic.co/t/logstash-stdout-empty/342073/2 "2023-08-31T16:50:26Z")

</div>

> but we changed the source IP that was sending the logs, that is all, so we updated the filter in our configuration file and nothing is showinf anymore.

Most likely a firewall issue. LS doesn't filter anything which arrive to the port 10000.

---

<div class="post-metadata">

**Author:** ![Bountardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bountardos/32/129564_2.png) [@Bountardos](https://discuss.elastic.co/u/Bountardos)\
**Post date:** [September 1, 2023, 6:51am UTC](https://discuss.elastic.co/t/logstash-stdout-empty/342073/3 "2023-09-01T06:51:17Z")

</div>

Hi, thank you for your reply. I don't understand how can this be firewall related, traffic is coming, we see it through tcpdump.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [September 1, 2023, 9:33am UTC](https://discuss.elastic.co/t/logstash-stdout-empty/342073/4 "2023-09-01T09:33:35Z")

</div>

Is tcpdump on the same host where is LS?  
Is the UDP port 10000 correct?  
Can you check did LS start listener on port 10000? by netstat and also should be visible in LS log.

You must have some trace, something is not OK.  
input is simple, filter is empty, output shows rubydebug ... simpliest cannot be.

The firewall can block the traffic, if you change source address and rules were set like that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2023, 9:33am UTC](https://discuss.elastic.co/t/logstash-stdout-empty/342073/5 "2023-09-29T09:33:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
