# Logstash stdout going to syslog

**URL:** <https://discuss.elastic.co/t/logstash-stdout-going-to-syslog/73585>\
**Category:** Logstash\
**Created:** [February 1, 2017, 8:55pm UTC](https://discuss.elastic.co/t/logstash-stdout-going-to-syslog/73585 "2017-02-01T20:55:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![astickler](https://avatars.discourse-cdn.com/v4/letter/a/53a042/32.png) [@astickler](https://discuss.elastic.co/u/astickler)\
**Post date:** [February 1, 2017, 8:55pm UTC](https://discuss.elastic.co/t/logstash-stdout-going-to-syslog/73585/1 "2017-02-01T20:55:15Z")

</div>

I have just installed logstash 5.2.0 on a clean Ubuntu 16.04, and my 'metric' filter is now writing its 1-minute document count and rates to syslog instead of logstash.stdout.

Is this a change in 5.2.0?

With 2.4, it used to be logstash.stdout in the /var/log/logstash folder, this seemed to change to a variant of logstash.stdout (IIRC it had other alphanumerics in the name) in /var/log, but now the output only appears in syslog.

FTR, the relevant part of my config is as follows:

> filter  
> {  
> metrics {  
> meter =\> "documents"  
> add\_tag =\> "metric"  
> flush\_interval =\> 60  
> }  
> }  
> output {  
> if "metric" in [tags] {  
> stdout {  
> codec =\> line {  
> format =\> "1m rate: %{[documents][rate\_1m]} ( %{[documents][count]} )"  
> }  
> }  
> }  
> }

Andrew.

---

<div class="post-metadata">

**Author:** ![astickler](https://avatars.discourse-cdn.com/v4/letter/a/53a042/32.png) [@astickler](https://discuss.elastic.co/u/astickler)\
**Post date:** [February 15, 2017, 1:16pm UTC](https://discuss.elastic.co/t/logstash-stdout-going-to-syslog/73585/2 "2017-02-15T13:16:48Z")

</div>

Can no-one explain this?  
Andrew

---

<div class="post-metadata">

**Author:** ![astickler](https://avatars.discourse-cdn.com/v4/letter/a/53a042/32.png) [@astickler](https://discuss.elastic.co/u/astickler)\
**Post date:** [February 21, 2017, 10:44am UTC](https://discuss.elastic.co/t/logstash-stdout-going-to-syslog/73585/3 "2017-02-21T10:44:30Z")

</div>

Odd - logstash 5.2.1 on Ubuntu 14.04 doesn't seem to write stdout anywhere when running as a service. Perhaps this is by design?

---

<div class="post-metadata">

**Author:** ![astickler](https://avatars.discourse-cdn.com/v4/letter/a/53a042/32.png) [@astickler](https://discuss.elastic.co/u/astickler)\
**Post date:** [February 21, 2017, 10:47am UTC](https://discuss.elastic.co/t/logstash-stdout-going-to-syslog/73585/4 "2017-02-21T10:47:26Z")

</div>

OK, I needed a bit of knowledge about upstart - I found that stdout is now written to /etc/upstart/logstash.log.  
Problem solved.

---

<div class="post-metadata">

**Author:** ![astickler](https://avatars.discourse-cdn.com/v4/letter/a/53a042/32.png) [@astickler](https://discuss.elastic.co/u/astickler)\
**Post date:** [March 9, 2017, 6:31pm UTC](https://discuss.elastic.co/t/logstash-stdout-going-to-syslog/73585/5 "2017-03-09T18:31:42Z")

</div>

Oops - that path should have been /var/log/upstart/logstash.log.

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [March 9, 2017, 6:31pm UTC](https://discuss.elastic.co/t/logstash-stdout-going-to-syslog/73585/6 "2017-03-09T18:31:49Z")

</div>

On CentOS, there is NO /var/log/upstart folder, and /var/log/logstashlogstash-plain.log does NOT show what used to be in /var/log/logstash/logstash.stdout.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2017, 6:31pm UTC](https://discuss.elastic.co/t/logstash-stdout-going-to-syslog/73585/7 "2017-04-06T18:31:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
