# Netflow in Logstash does not find the logstash.yml file

**URL:** <https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115>\
**Category:** Logstash\
**Created:** [September 11, 2019, 5:38pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115 "2019-09-11T17:38:20Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 11, 2019, 5:38pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/1 "2019-09-11T17:38:20Z")

</div>

Hello everyone,  
I am trying to use Netflow on my cluster, so I configured the logstash.yml file as describe on the articules as follows, this directory is located on /etc/logstash:  
modules:  
-name: netflow  
var.input.udp.port: XXXX  
var.elasticsearch.host: ["ip1:9200","ip2:9200","ip3:9200"]  
var.kibana.host: "kibanaip:5600"

Then I moved to logstash installation directory to /usr/share/logstash and ran:  
bin/logstash --modules netflow --setup  
in order to start the netflow but, when I run this command I get a warning followed by a lot of errors. "Warning: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
"  
Any suggestions?

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [September 11, 2019, 8:37pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/2 "2019-09-11T20:37:27Z")

</div>

I think you might be missing

bin/logstash --modules netflow --setup --path.settings /path/to/logstash.yml

where "/path/to/logstash.yml" is the path to your logstash.yml

---

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 11, 2019, 10:19pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/3 "2019-09-11T22:19:45Z")

</div>

Hello @Andrew22, thank you for your response, unfortiunetlly it didn't work, I added the --path/settings /etc/logstash to the end and when run it I got the following error:  
Thread.exclusive is deprecated, use Thread::Mutex  
Sending Logstash logs to /var/log/logstash which is now configured via log4j2.properties  
[2019-09-11T15:18:20,352][FATAL][logstash.runner] An unexpected error occurred! {:error=\>#\<ArgumentError: Setting "var.input.udp.port" hasn't been registered\>, :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/settings.rb:36:in `get_setting'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:69:in`set\_value'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:88:in `block in merge'", "org/jruby/RubyHash.java:1419:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:88:in `merge'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:137:in`validate\_all'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:283:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/clamp-0.6.5/lib/clamp/command.rb:67:in`run'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:242:in `run'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/clamp-0.6.5/lib/clamp/command.rb:132:in`run'", "/usr/share/logstash/lib/bootstrap/environment.rb:73:in `'"]}  
[2019-09-11T15:18:20,368][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 11, 2019, 11:15pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/4 "2019-09-11T23:15:31Z")

</div>

I think that might be an indentation error in your logstash.yml file.

---

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 12, 2019, 5:19pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/5 "2019-09-12T17:19:34Z")

</div>

Thank you @Badger , I did resolve the indentation on the yml file, now I am getting this.

Thread.exclusive is deprecated, use Thread::Mutex  
Sending Logstash logs to /var/log/logstash which is now configured via log4j2.properties  
[2019-09-12T10:13:58,105][INFO][logstash.config.source.modules] Both command-line and logstash.yml modules configurations detected. Using command-line module configuration to override logstash.yml module configuration.  
[2019-09-12T10:13:58,121][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-09-12T10:13:58,133][FATAL][logstash.runner] Logstash could not be started because there is already another instance using the configured data directory. If you wish to run multiple instances, you must change the "path.data" setting.  
[2019-09-12T10:13:58,142][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [September 12, 2019, 5:28pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/6 "2019-09-12T17:28:13Z")

</div>

it looks like you are already running logstash. try stopping the service then running the command again

---

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 12, 2019, 5:29pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/7 "2019-09-12T17:29:02Z")

</div>

And the other pipelines that I have running will start again?

---

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 12, 2019, 5:48pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/8 "2019-09-12T17:48:13Z")

</div>

@Andrew22 Seems like now Im getting this error

Thread.exclusive is deprecated, use Thread::Mutex  
Sending Logstash logs to /usr/share/logstash/logs which is now configured via log4j2.properties  
[2019-09-12T10:46:38,341][FATAL][logstash.runner] An unexpected error occurred! {:error=\>#\<ArgumentError: Setting "" hasn't been registered\>, :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/settings.rb:36:in `get_setting'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:69:in`set\_value'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:88:in `block in merge'", "org/jruby/RubyHash.java:1419:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:88:in `merge'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:137:in`validate\_all'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:283:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/clamp-0.6.5/lib/clamp/command.rb:67:in`run'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:242:in `run'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/clamp-0.6.5/lib/clamp/command.rb:132:in`run'", "/usr/share/logstash/lib/bootstrap/environment.rb:73:in `'"]}  
[2019-09-12T10:46:38,356][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

---

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 23, 2019, 9:51pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/9 "2019-09-23T21:51:30Z")

</div>

@Andrew22 sorry for the late response I was Out of Town, question, yes indeed I have a pipeline already running, so I will have to stop logstash service, then run the above command (bin/logstash --modules netflow --setup --path.settings /path/to/logstash.yml), and this will automatically start the logstash service? I just want to be sure I understand.

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [September 25, 2019, 2:21pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/10 "2019-09-25T14:21:24Z")

</div>

That will run logstash with the settings in logstash.yml. I dont have much experience with starting logstash this way but I was just aware of how to do it.

---

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 25, 2019, 4:17pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/11 "2019-09-25T16:17:45Z")

</div>

Thank you @Andrew22, actually it worked, and installed everything on Kibana, but for some reason I am not getting any data in. Not sure what is going on.

---

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 25, 2019, 6:09pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/12 "2019-09-25T18:09:14Z")

</div>

He @Badger by any chance do you know if after running the netflow Module do you have to manually create a pipeline in Logstash? I ran the command to setup the netflow module and all went through, I have the Index pattern and the visualizations in kibana but no data is getting recieved on the Kibana side. also, after stopping logstash service and running the command

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 25, 2019, 6:11pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/13 "2019-09-25T18:11:27Z")

</div>

I don't know.

---

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 25, 2019, 6:20pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/14 "2019-09-25T18:20:13Z")

</div>

@badger, do you know how to stop the netflow module?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 25, 2019, 6:22pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/15 "2019-09-25T18:22:47Z")

</div>

I do not.

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [September 25, 2019, 9:03pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/16 "2019-09-25T21:03:52Z")

</div>

Elastiflow is worth checking out. Netflow module is based on an earlier version of elastiflow

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 25, 2019, 9:12pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/17 "2019-09-25T21:12:40Z")

</div>

I have exactly same problem. all dashboard/visulization created, netflow-\* index pattern created but no index

I think there is no support for this thing

> [@Netflow setup giving me error](https://discuss.elastic.co/t/netflow-setup-giving-me-error/200761/10):
>
> I still can't see anything as index on elasticserch logstash starts up ok with this module Do I have to do anything else? [2019-09-25T15:11:40,712][INFO][logstash.javapipeline] Starting pipeline {:pipeline\_id=\>"module-netflow", "pipeline.workers"=\>16, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50, "pipeline.max\_inflight"=\>2000, :thread=\>"#\<Thread:0x51327c04 run\>"} [2019-09-25T15:11:40,787][INFO][logstash.javapipeline] Pipeline started {"pipeline.id"=\>"module-netflow"} [20…

---

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 25, 2019, 9:14pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/18 "2019-09-25T21:14:19Z")

</div>

@elasticforme is your logstash service running after you ran the Netflow command?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 25, 2019, 9:16pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/19 "2019-09-25T21:16:59Z")

</div>

yes.  
Actually this is my test cluster and I didn't have any pipleline configure. just netflow

as you can see from my last input on my thread. it seems running fine. I can run ps -ef |grep logstash and can see it is running. even logstash log says it is running  
netstat -a shows that port 2055 is open and listening on 0.0.0.0  
but no input on elasticsearch

---

<div class="post-metadata">

**Author:** ![eemtzc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eemtzc/32/54095_2.png) [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Post date:** [September 25, 2019, 9:21pm UTC](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115/21 "2019-09-25T21:21:27Z")

</div>

Oh thats good,  
the thing is that when I run the systemctl status logstash i get the following  
logstash.service - logstash  
Loaded: loaded (/etc/systemd/system/logstash.service; enabled; vendor preset: disabled)  
Active: active (running) since Wed 2019-09-25 14:17:39 PDT; 1min 0s ago  
Main PID: 24022 (java)  
CGroup: /system.slice/logstash.service  
└─24022 /bin/java -Xms16g -Xmx16g -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -Djava.awt.headless=true -Dfile.encoding=UTF-...

Sep 25 14:17:39 [XXXX.com](http://XXXXcom/) systemd[1]: Started logstash.  
Sep 25 14:17:39 [XXXX.com](http://XXXX.com/) systemd[1]: Starting logstash...  
Sep 25 14:18:27 [XXXX.com](http://XXXX.com/) logstash[24022]: Thread.exclusive is deprecated, use Thread::Mutex  
Sep 25 14:18:30 [XXXX.com](http://XXXX.com/) logstash[24022]: Sending Logstash logs to /var/log/logstash which is now configured via log4j2.properties

[Next page](https://discuss.elastic.co/t/netflow-in-logstash-does-not-find-the-logstash-yml-file/199115.md?page=2)
