# Logstash will not start

**URL:** <https://discuss.elastic.co/t/logstash-will-not-start/101535>\
**Category:** Logstash\
**Created:** [September 22, 2017, 8:03pm UTC](https://discuss.elastic.co/t/logstash-will-not-start/101535 "2017-09-22T20:03:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajstark123](https://avatars.discourse-cdn.com/v4/letter/a/73ab20/32.png) [@ajstark123](https://discuss.elastic.co/u/ajstark123)\
**Post date:** [September 22, 2017, 8:03pm UTC](https://discuss.elastic.co/t/logstash-will-not-start/101535/1 "2017-09-22T20:03:01Z")

</div>

We install logstash v5.5.2 from the tar file. We are running logstash from our /opt/pki/logstash/bin directory.

Logstast is not start and getting the following error below. It appears that logstash is having an issue with the /opt/pki/logstash/config/jvm.options file in our /opt/pki/logstash/config.

/opt/pki/logstash/bin/logstash -t --path.data /opt/pki/logstash/data -f /opt/pki/logstash/config -l /opt/pki/logstash/logs \>/opt/pki/logstash/logs/logstash\_std\_outerr.txt 2\>&1

[2017-09-22T16:00:00,918][DEBUG][logstash.runner] Reading config file {:config\_file=\>"/opt/pki/logstash/config/jvm.options"}  
[2017-09-22T16:00:00,919][DEBUG][logstash.runner] Reading config file {:config\_file=\>"/opt/pki/logstash/config/log4j2.properties"}  
[2017-09-22T16:00:00,919][DEBUG][logstash.runner] Reading config file {:config\_file=\>"/opt/pki/logstash/config/logstash.yml"}  
[2017-09-22T16:00:00,920][DEBUG][logstash.runner] Reading config file {:config\_file=\>"/opt/pki/logstash/config/startup.options"}  
[2017-09-22T16:00:00,925][FATAL][logstash.runner] The given configuration is invalid. Reason: Expected one of #, input, filter, output at line 6, column 1 (byte 132) after ## JVM configuration

# Xms represents the initial size of total heap space

# Xmx represents the maximum size of total heap space

---

<div class="post-metadata">

**Author:** ![vl.zemtsov](https://avatars.discourse-cdn.com/v4/letter/v/eb9ed0/32.png) [@vl.zemtsov](https://discuss.elastic.co/u/vl.zemtsov)\
**Post date:** [September 22, 2017, 8:33pm UTC](https://discuss.elastic.co/t/logstash-will-not-start/101535/2 "2017-09-22T20:33:29Z")

</div>

> [@ajstark123](#):
>
> The given configuration is invalid. Reason: **Expected one of #, input, filter, output at line 6, column 1** (byte 132) after ## JVM configuration

First: Start logstash in \<Home\_logstash\_dirrectory\>:  
cd /opt/pki/logstash/  
bin/logstash -t --path.data /opt/pki/logstash/data -f /opt/pki/logstash/config ...

Second: Show u config file

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 24, 2017, 8:44pm UTC](https://discuss.elastic.co/t/logstash-will-not-start/101535/3 "2017-09-24T20:44:26Z")

</div>

Don't put anything but pipeline configuration files in the pipeline configuration file directory (the path you use together with the `-f` option). Logstash will read all files in that directory and expects all of them to be pipeline configuration files.

---

<div class="post-metadata">

**Author:** ![ajstark123](https://avatars.discourse-cdn.com/v4/letter/a/73ab20/32.png) [@ajstark123](https://discuss.elastic.co/u/ajstark123)\
**Post date:** [September 25, 2017, 2:41pm UTC](https://discuss.elastic.co/t/logstash-will-not-start/101535/4 "2017-09-25T14:41:11Z")

</div>

We are using the following command t o run logstash  
cd /opt/pki/logstash/  
./bin/logstash --path.data /opt/pki/logstash/data -f /opt/pki/logstash/config -l /opt/pki/logstash/logs

It crashes immediately.

We only have the logstash.yml in the /opt/pki/logstash/config directory.

logstash.yml contains the following. We have not changed the configuration.  
# Settings file in YAML

# 

# Settings can be specified either in hierarchical form, e.g.:

# 

# pipeline:

# batch:

# size: 125

# delay: 5

# 

# Or as flat keys:

# 

# pipeline.batch.size: 125

# pipeline.batch.delay: 5

# 

# ------------ Node identity ------------

# 

# Use a descriptive name for the node:

# 

# [node.name](http://node.name): test

# 

# If omitted the node name will default to the machine's host name

# 

# ------------ Data path ------------------

# 

# Which directory should be used by logstash and its plugins

# for any persistent needs. Defaults to LOGSTASH\_HOME/data

# 

# path.data:

# 

# ------------ Pipeline Settings --------------

# 

# Set the number of workers that will, in parallel, execute the filters+outputs

# stage of the pipeline.

# 

# This defaults to the number of the host's CPU cores.

# 

# pipeline.workers: 2

# 

# How many workers should be used per output plugin instance

# 

# pipeline.output.workers: 1

# 

# How many events to retrieve from inputs before sending to filters+workers

# 

# pipeline.batch.size: 125

# 

# How long to wait before dispatching an undersized batch to filters+workers

# Value is in milliseconds.

# 

# pipeline.batch.delay: 5

# 

# Force Logstash to exit during shutdown even if there are still inflight

# events in memory. By default, logstash will refuse to quit until all

# received events have been pushed to the outputs.

# 

# WARNING: enabling this can lead to data loss during shutdown

# 

# pipeline.unsafe\_shutdown: false

# 

# ------------ Pipeline Configuration Settings --------------

# 

# Where to fetch the pipeline configuration for the main pipeline

# 

# path.config:

# 

# Pipeline configuration string for the main pipeline

# 

# config.string:

# 

# At startup, test if the configuration is valid and exit (dry run)

# 

# config.test\_and\_exit: false

# 

# Periodically check if the configuration has changed and reload the pipeline

# This can also be triggered manually through the SIGHUP signal

# 

# config.reload.automatic: false

# 

# How often to check if the pipeline configuration has changed (in seconds)

# 

# config.reload.interval: 3

# 

# Show fully compiled configuration as debug log message

# NOTE: --log.level must be 'debug'

# 

# config.debug: false

# 

# ------------ Module Settings ---------------

# Define modules here. Modules definitions must be defined as an array.

# The simple way to see this is to prepend each `name` with a `-`, and keep

# all associated variables under the `name` they are associated with, and

# above the next, like this:

# 

# modules:

# - name: MODULE\_NAME

# var.PLUGINTYPE1.PLUGINNAME1.KEY1: VALUE

# var.PLUGINTYPE1.PLUGINNAME1.KEY2: VALUE

# var.PLUGINTYPE2.PLUGINNAME1.KEY1: VALUE

# var.PLUGINTYPE3.PLUGINNAME3.KEY1: VALUE

# 

# Module variable names must be in the format of

# 

# var.PLUGIN\_TYPE.PLUGIN\_NAME.KEY

# 

# modules:

# 

# ------------ Queuing Settings --------------

# 

# Internal queuing model, "memory" for legacy in-memory based queuing and

# "persisted" for disk-based acked queueing. Defaults is memory

# 

# queue.type: memory

# 

# If using queue.type: persisted, the directory path where the data files will be stored.

# Default is path.data/queue

# 

# path.queue:

# 

# If using queue.type: persisted, the page data files size. The queue data consists of

# append-only data files separated into pages. Default is 250mb

# 

# queue.page\_capacity: 250mb

# 

# If using queue.type: persisted, the maximum number of unread events in the queue.

# Default is 0 (unlimited)

# 

# queue.max\_events: 0

# 

# If using queue.type: persisted, the total capacity of the queue in number of bytes.

# If you would like more unacked events to be buffered in Logstash, you can increase the

# capacity using this setting. Please make sure your disk drive has capacity greater than

# the size specified here. If both max\_bytes and max\_events are specified, Logstash will pick

# whichever criteria is reached first

# Default is 1024mb or 1gb

# 

# queue.max\_bytes: 1024mb

# 

# If using queue.type: persisted, the maximum number of acked events before forcing a checkpoint

# Default is 1024, 0 for unlimited

# 

# queue.checkpoint.acks: 1024

# 

# If using queue.type: persisted, the maximum number of written events before forcing a checkpoint

# Default is 1024, 0 for unlimited

# 

# queue.checkpoint.writes: 1024

# 

# If using queue.type: persisted, the interval in milliseconds when a checkpoint is forced on the head page

# Default is 1000, 0 for no periodic checkpoint.

# 

# queue.checkpoint.interval: 1000

# 

# ------------ Dead-Letter Queue Settings --------------

# Flag to turn on dead-letter queue.

# 

# dead\_letter\_queue.enable: false

# If using dead\_letter\_queue.enable: true, the maximum size of each dead letter queue. Entries

# will be dropped if they would increase the size of the dead letter queue beyond this setting.

# Deafault is 1024mb

# dead\_letter\_queue.max\_bytes: 1024mb

# If using dead\_letter\_queue.enable: true, the directory path where the data files will be stored.

# Default is path.data/dead\_letter\_queue

# 

# path.dead\_letter\_queue:

# 

# ------------ Metrics Settings --------------

# 

# Bind address for the metrics REST endpoint

# 

# http.host: "127.0.0.1"

# 

# Bind port for the metrics REST endpoint, this option also accept a range

# (9600-9700) and logstash will pick up the first available ports.

# 

# http.port: 9600-9700

# 

# ------------ Debugging Settings --------------

# 

# Options for log.level:

# \* fatal

# \* error

# \* warn

# \* info (default)

# \* debug

# \* trace

# 

# log.level: info

log.level: debug

# path.logs:

# 

# ------------ Other Settings --------------

# 

# Where to find custom plugins

# path.plugins: []

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 25, 2017, 2:49pm UTC](https://discuss.elastic.co/t/logstash-will-not-start/101535/5 "2017-09-25T14:49:53Z")

</div>

> We only have the logstash.yml in the /opt/pki/logstash/config directory.

Don't put anything but pipeline configuration files (those with input, output, and filter sections) in that directory. logstash.yml is not a pipeline configuration file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2017, 2:50pm UTC](https://discuss.elastic.co/t/logstash-will-not-start/101535/6 "2017-10-23T14:50:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
