# No config files found in path

**URL:** <https://discuss.elastic.co/t/no-config-files-found-in-path/327879>\
**Category:** Logstash\
**Created:** [March 16, 2023, 8:06pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879 "2023-03-16T20:06:02Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mxnita](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@Mxnita](https://discuss.elastic.co/u/Mxnita)\
**Post date:** [March 16, 2023, 8:06pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/1 "2023-03-16T20:06:02Z")

</div>

Hello everyone  
I am new with Logstash and i trying to start Logstash 8.6.2 on a Windows Server 2019 Server to forward syslogs from a Firewall to Wazuh.  
When I try to run as administrator in PS the command C:\logstash-8.6.2\bin\logstash.bat -f C:\logstash-8.6.2\config\logstash.conf I get the following error message:

 ![error](https://us1.discourse-cdn.com/elastic/original/3X/c/a/ca8a1e5add2bafc0bfdd91e8adb2d21911f06631.png)

[ERROR] [logstash.config.sourceloader] No configuration found in the configured sources.

Before this, a line appears indicating the following:

[INFO] [logstash.config.source.local.configpathloader] No config files found in path {:path=\>"C:/logstash-8.6.2/config/logstash.conf"}

The strange thing is that this configuration file does exist, and the path is correct, but I don't understand why that error message appears. Please, could you help me to identify what is the problem that I am having?

Regards

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 17, 2023, 6:31am UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/2 "2023-03-17T06:31:28Z")

</div>

Try with additional path settings:  
`C:\logstash-8.6.2\bin\logstash.bat -f C:\logstash-8.6.2\config\logstash.conf --path.settings C:\logstash-8.6.2\config`

---

<div class="post-metadata">

**Author:** ![Mxnita](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@Mxnita](https://discuss.elastic.co/u/Mxnita)\
**Post date:** [March 17, 2023, 12:28pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/3 "2023-03-17T12:28:39Z")

</div>

Hi @Rios  
Thanks for your reply. When i try to run that, i get the command syntax is not correct.

Regards.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 17, 2023, 12:32pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/4 "2023-03-17T12:32:36Z")

</div>

What is the content of the file `C:\logstash-8.6.2\config\logstash.conf`? Can you share it?

---

<div class="post-metadata">

**Author:** ![Mxnita](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@Mxnita](https://discuss.elastic.co/u/Mxnita)\
**Post date:** [March 17, 2023, 12:40pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/5 "2023-03-17T12:40:37Z")

</div>

Hi @leandrojmp  
This is the content of the file:

```auto
input {
   syslog {
      port => 514
   }
}

output {
   file {
      path => "C:\logstash-8.6.2\logs\file_name.log"
      codec => "line"
   }
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 17, 2023, 1:01pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/6 "2023-03-17T13:01:04Z")

</div>

Try to pass the full path to the config between double quotes.

```auto
C:\logstash-8.6.2\bin\logstash.bat -f "C:\logstash-8.6.2\config\logstash.conf"

```

Or try to use backslashes

```auto
C:\logstash-8.6.2\bin\logstash.bat -f "C:/logstash-8.6.2/config/logstash.conf"

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 17, 2023, 1:12pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/7 "2023-03-17T13:12:21Z")

</div>

> [@Mxnita](#):
>
> ```auto
> file {
> path => "C:\logstash-8.6.2\logs\file_name.log"
> 
> ```

Also

```auto
file {
      path => "C:/logstash-8.6.2/logs/file_name.log"
      codec => "line"
   }

```

---

<div class="post-metadata">

**Author:** ![Mxnita](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@Mxnita](https://discuss.elastic.co/u/Mxnita)\
**Post date:** [March 17, 2023, 2:06pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/8 "2023-03-17T14:06:33Z")

</div>

I tried both ways, but it didn't work:

 ![4324](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3d754adb5cf41c515c75956ad74333cbfa58ef85.png)

 ![Capturaee](https://us1.discourse-cdn.com/elastic/original/3X/7/2/722b49f172eb6a542d79627bb1ebc692df405a81.png)

---

<div class="post-metadata">

**Author:** ![Mxnita](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@Mxnita](https://discuss.elastic.co/u/Mxnita)\
**Post date:** [March 17, 2023, 2:11pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/9 "2023-03-17T14:11:30Z")

</div>

I modified the logstash.conf file and it was as follows:

```auto
input {
   syslog {
      port => 514
   }
}

output {
   file {
      path => "C:/logstash-8.6.2/logs/file_name.log"
      codec => "line"
   }
}

```

and

```auto
input {
   syslog {
      port => 514
   }
}

output {
   file {
      path => "C:\logstash\logs\file_name.log"
      codec => "line"
   }
}

```

I save both versions and run the commands they recommended here and it didn't work.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 17, 2023, 4:17pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/10 "2023-03-17T16:17:08Z")

</div>

A little bit stupid question, does logstash.conf exist? It might be logstash.conf.txt where .txt is not visible. Can you list C:\logstash-8.6.2\config\ from command line or PShell?

Another option is to install Oracle JDK(not OpenJDK), that helped me once on Linux. AFAIK, normally LS should use JDK from subfolder, if I'm not wrong.

---

<div class="post-metadata">

**Author:** ![Mxnita](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@Mxnita](https://discuss.elastic.co/u/Mxnita)\
**Post date:** [March 17, 2023, 6:59pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/11 "2023-03-17T18:59:11Z")

</div>

> [@Rios](#):
>
> Oracle JDK

Yes, i check on the command line that the logstash file only had the .conf extension.

I download the Oracle JDK from here: [JDK 19 Releases](https://jdk.java.net/19/)  
But when I unzip the file, I can't find an executable or something similar to install it, so Oracle JDK is executed to do the test?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 18, 2023, 12:25am UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/12 "2023-03-18T00:25:32Z")

</div>

That is OpenJDK, use [this](https://www.oracle.com/cis/java/technologies/downloads/#jdk19-windows).

---

<div class="post-metadata">

**Author:** ![jba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jba/32/118482_2.png) [@jba](https://discuss.elastic.co/u/jba)\
**Post date:** [March 18, 2023, 5:00pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/13 "2023-03-18T17:00:35Z")

</div>

I think the clue is in the wording of the error message: "No config files found in path C:....."

Files, not file.

Logstash can load multiple files with the \*.conf extension from a configuration DIRECTORY. Try starting it with the path to the directory/folder with the configuration file(s). As long as the file ends with `.conf`, Logstash should see it and load it.

This feature also means that if you should ever want to disable a config file, you do not need to delete it. All you need to do is to rename it so it no longer ends in `.conf`. Add a `.disabled` is the standard I think.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 18, 2023, 5:11pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/14 "2023-03-18T17:11:22Z")

</div>

> [@jba](#):
>
> As long as the file ends with `.conf`, Logstash should see it and load it.

I do not believe it has to end in conf. If you point path.config at a directory then it will [try to read](https://discuss.elastic.co/t/message-file-too-big-for-single-read/238348/2) everything in the directory.

---

<div class="post-metadata">

**Author:** ![jba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jba/32/118482_2.png) [@jba](https://discuss.elastic.co/u/jba)\
**Post date:** [March 18, 2023, 5:44pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/15 "2023-03-18T17:44:46Z")

</div>

Okay. I stand corrected. But there is something about file extensions being relevant for Logstash modules? Or is that Filebeat modules? Something about the modules being shipped out-of-the-box with a `.disabled` extension, and enabling them (either with a little enable tool, or manually) just involves deleting or adding the `.disabled` extension?

I am surprised that a similar convention is not applied to conf/filter files.

---

<div class="post-metadata">

**Author:** ![jba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jba/32/118482_2.png) [@jba](https://discuss.elastic.co/u/jba)\
**Post date:** [March 18, 2023, 5:50pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/16 "2023-03-18T17:50:07Z")

</div>

Or maybe I do not stand corrected 🙂

- "You create pipeline configuration files when you define the stages of your Logstash processing pipeline. On deb and rpm, you place the pipeline configuration files in the /etc/logstash/conf.d directory. Logstash tries to load only files with .conf extension in the /etc/logstash/conf.d directory and ignores all other files."

[https://www.elastic.co/guide/en/logstash/current/config-setting-files.html](https://www.elastic.co/guide/en/logstash/current/config-setting-files.html)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 18, 2023, 6:56pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/17 "2023-03-18T18:56:27Z")

</div>

As I said, if you point path.config at a directory then it will read everything in the directory. If I point path.config to a /tmp/conf.d directory that contains two files, one a valid configuration and the other a few megabytes of /dev/random then logstash will complain

> [2023-03-18T14:47:23,218][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600, :ssl\_enabled=\>false}  
> [2023-03-18T14:47:23,610][ERROR][logstash.config.sourceloader] Could not fetch all the sources {:exception=\>LogStash::ConfigLoadingError, :message=\>"The following config files contains non-ascii characters but are not UTF-8 encoded ["/tmp/conf.d/zzz.disabled"]",  
> [2023-03-18T14:47:26,617][ERROR][logstash.config.sourceloader] No source loaders matched! This shouldn't happen  
> [2023-03-18T14:47:26,987][ERROR][logstash.agent] An exception happened when converging configuration {:exception=\>LogStash::InvalidSourceLoaderSettingError, :message=\>"Can't find an appropriate config loader with current settings"}

It is entirely plausible that when using the deb or rpm packages the default value for path.config is /etc/logstash/conf.d/\*.conf, in which case you would get something similar to

> [2023-03-18T14:54:24,069][DEBUG][logstash.config.source.local.configpathloader] Skipping the following files while reading config since they don't match the specified glob pattern {:files=\>["/tmp/conf.d/zzz.disabled"]}  
> [2023-03-18T14:54:24,071][DEBUG][logstash.config.source.local.configpathloader] Reading config file {:config\_file=\>"/tmp/conf.d/test.conf"}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 15, 2023, 6:56pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879/18 "2023-04-15T18:56:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
