# Logstash- /var/log/logstash - has no files

**URL:** <https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780>\
**Category:** Logstash\
**Created:** [May 2, 2022, 9:45pm UTC](https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780 "2022-05-02T21:45:12Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![gurumu](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@gurumu](https://discuss.elastic.co/u/gurumu)\
**Post date:** [May 2, 2022, 9:45pm UTC](https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780/1 "2022-05-02T21:45:12Z")

</div>

Hello- I have installed Elasticsearch, Kibana and Logstash version 8.1.0 on my ubuntu VM. I am trying to ingest auth.log into ES by passing it through logstash. attached is the configuration file screenshots. I am not seeing the data being ingested and while troubleshooting that, I am not able to see the logstash-plain.log file at all. I am new to ELK stack and just following the documentation. Could you please advise where am I going wrong.

 ![confd_config](https://us1.discourse-cdn.com/elastic/original/3X/9/1/91ec153b7a483b2a3c9ccfd96e0e3e0da86c30e1.png)  
 ![logstash_Error](https://us1.discourse-cdn.com/elastic/original/3X/5/9/59f15b3e6a146977a1f9c228599989ae2c7bf3d0.png)  
 ![logstash_log_folder_permission](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a36b7754e9ab3b1b8c096d40761c903121a242d.png)

---

<div class="post-metadata">

**Author:** ![ibra\_013](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibra_013/32/104827_2.png) [@ibra\_013](https://discuss.elastic.co/u/ibra_013)\
**Post date:** [May 3, 2022, 4:43pm UTC](https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780/2 "2022-05-03T16:43:53Z")

</div>

Hi,

could you add [this line](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-stdout.html#_description_106) to your logstash config,

```auto
output {
  elasticsearch { hosts => ["localhost:9200"] }
  stdout { codec => rubydebug }
}

```

and please run this command on the cli and see what happens

```auto
bin/logstash -f /etc/logstash/conf.d/authlog.conf

```

---

<div class="post-metadata">

**Author:** ![gurumu](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@gurumu](https://discuss.elastic.co/u/gurumu)\
**Post date:** [May 3, 2022, 7:34pm UTC](https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780/4 "2022-05-03T19:34:31Z")

</div>

```auto
ng@ubuntu:/usr/share/logstash$ bin/logstash -f /etc/logstash/conf.d/authlog.conf

OpenJDK 64-Bit Server VM warning: Option UseConcMarkSweepGC was deprecated in version 9.0 and will likely be removed in a future release.
WARNING: An illegal reflective access operation has occurred
WARNING: Illegal reflective access by com.headius.backport9.modules.Modules (file:/usr/share/logstash/logstash-core/lib/jars/jruby-complete-9.2.8.0.jar) to field java.io.FileDescriptor.fd
WARNING: Please consider reporting this to the maintainers of com.headius.backport9.modules.Modules
WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations
WARNING: All illegal access operations will be denied in a future release
Thread.exclusive is deprecated, use Thread::Mutex
WARNING: Could not find logstash.yml which is typically located in $LS_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console
[FATAL] 2022-05-03 12:28:19.705 [main] runner - An unexpected error occurred! {:error=>#<ArgumentError: Path "/usr/share/logstash/data" must be a writable directory. It is not writable.>, :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/settings.rb:489:in `validate'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:271:in `validate_value'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:182:in `block in validate_all'", "org/jruby/RubyHash.java:1417:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:181:in `validate_all'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:283:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/clamp-0.6.5/lib/clamp/command.rb:67:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:242:in `run'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/clamp-0.6.5/lib/clamp/command.rb:132:in `run'", "/usr/share/logstash/lib/bootstrap/environment.rb:73:in `<main>'"]}
[ERROR] 2022-05-03 12:28:19.734 [main] Logstash - java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

```

---

<div class="post-metadata">

**Author:** ![ibra\_013](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibra_013/32/104827_2.png) [@ibra\_013](https://discuss.elastic.co/u/ibra_013)\
**Post date:** [May 3, 2022, 7:37pm UTC](https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780/5 "2022-05-03T19:37:47Z")

</div>

Hi,

sorry i did not precise where to run the command, it should be on /etc/logstash/

---

<div class="post-metadata">

**Author:** ![gurumu](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@gurumu](https://discuss.elastic.co/u/gurumu)\
**Post date:** [May 3, 2022, 7:39pm UTC](https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780/6 "2022-05-03T19:39:25Z")

</div>

ng@ubuntu:/etc/logstash$ bin/logstash -f /etc/logstash/conf.d/authlog.conf  
-bash: bin/logstash: No such file or directory  
ng@ubuntu:/etc/logstash$

---

<div class="post-metadata">

**Author:** ![gurumu](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@gurumu](https://discuss.elastic.co/u/gurumu)\
**Post date:** [May 3, 2022, 7:40pm UTC](https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780/7 "2022-05-03T19:40:47Z")

</div>

hi ibra - am I missing something here? when I run the command, it says no such file or directory

---

<div class="post-metadata">

**Author:** ![ibra\_013](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibra_013/32/104827_2.png) [@ibra\_013](https://discuss.elastic.co/u/ibra_013)\
**Post date:** [May 3, 2022, 8:04pm UTC](https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780/8 "2022-05-03T20:04:33Z")

</div>

Hi,

let do this again

```auto
ng@ubuntu:/etc/logstash# /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/authlog.conf 

```

---

<div class="post-metadata">

**Author:** ![gurumu](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@gurumu](https://discuss.elastic.co/u/gurumu)\
**Post date:** [May 3, 2022, 8:46pm UTC](https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780/9 "2022-05-03T20:46:35Z")

</div>

hi ibra - It worked after elevating the privileges to root.

root@ubuntu:/usr/share/logstash# cd /etc/logstash  
root@ubuntu:/etc/logstash# /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/authlog.conf

thank you so much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2022, 8:47pm UTC](https://discuss.elastic.co/t/logstash-var-log-logstash-has-no-files/303780/10 "2022-05-31T20:47:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
