# No logstash output on windows

**URL:** <https://discuss.elastic.co/t/no-logstash-output-on-windows/326077>\
**Category:** Logstash\
**Created:** [February 21, 2023, 2:24pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077 "2023-02-21T14:24:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeanette](https://avatars.discourse-cdn.com/v4/letter/j/c0e974/32.png) [@jeanette](https://discuss.elastic.co/u/jeanette)\
**Post date:** [February 21, 2023, 2:24pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077/1 "2023-02-21T14:24:08Z")

</div>

Hello, I have been troubleshooting my logstash for some time now. I was following the "Parsing Logs with Logstash" tutorial for Windows and have not been able to see any output with the basic pipeline. Below is my first-pipeline.conf file:

```auto
input { 
    beats { 
        port => "5044" 
    } 
} 

 

filter { 
    grok { 
        match => { "message" => "%{COMBINEDAPACHELOG}"} 
    } 
} 

 

output { 
    stdout { codec => rubydebug } 
}

```

Testing and running the configuration did not show any errors, but when I debug Logstash an error starts to repeat itself:

`[DEBUG][logstash.instrument.periodicpoller.cgroup] One or more required cgroup files or directories not found: /proc/self/cgroup, /sys/fs/cgroup/cpuacct, /sys/fs/cgroup/cpu`

Any help is appreciated!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2023, 5:11pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077/2 "2023-02-21T17:11:53Z")

</div>

> [@jeanette](#):
>
> [DEBUG][logstash.instrument.periodicpoller.cgroup] One or more required cgroup files or directories not found: /proc/self/cgroup, /sys/fs/cgroup/cpuacct, /sys/fs/cgroup/cpu

That is normal, you can ignore it. It is just a debug message.

It sounds like logstash is waiting to receive some data from a beat so that it can process it.

---

<div class="post-metadata">

**Author:** ![jeanette](https://avatars.discourse-cdn.com/v4/letter/j/c0e974/32.png) [@jeanette](https://discuss.elastic.co/u/jeanette)\
**Post date:** [February 21, 2023, 5:32pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077/3 "2023-02-21T17:32:25Z")

</div>

Thanks for the quick response -- Does that mean the problem is not with logstash but filebeats? Below are my changes to the filebeat.yml:

```auto
# ============================== Filebeat inputs ===============================

filebeat.inputs:

# filestream is an input for collecting log messages from files.
- type: log

  # Unique ID among all inputs, an ID is required.
  id: my-filestream-id

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - C:/Test/logstash-tutorial.log

# ------------------------------ Logstash Output -------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["localhost:5044"]

```

The elasticsearch output is commented out bc I saw that caused problems for other people.

---

<div class="post-metadata">

**Author:** ![ingri.mahecha](https://avatars.discourse-cdn.com/v4/letter/i/51bf81/32.png) [@ingri.mahecha](https://discuss.elastic.co/u/ingri.mahecha)\
**Post date:** [February 21, 2023, 7:34pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077/4 "2023-02-21T19:34:08Z")

</div>

Hello,  
If you are using **LOGSTASH**.

You want to check logs from your computer I suggest you:

1. **Install Visual Code**
2. Download the LogStash agent (.zip)
3. Open in Visual Code the decompress folder of logstash
4. Create the **pipeline.conf** file you want to perform
5. In Visual Code open the **TERMINAL** , and execute the following command that allows to display in console

```auto
 .\bin\logstash -f .\pipeline.conf --config.reload.automatic 

```

In the pipeline.conf file configure as follows:

```auto
input { 
    beats { 
        port => "5044" 
    } 
} 

 

filter { 
    grok { 
        match => { 
               "message" => "%{GREEDYDATA:message}"
              } 
    } 
} 

 
output { 
    stdout { } 
}

```

---

<div class="post-metadata">

**Author:** ![ingri.mahecha](https://avatars.discourse-cdn.com/v4/letter/i/51bf81/32.png) [@ingri.mahecha](https://discuss.elastic.co/u/ingri.mahecha)\
**Post date:** [February 21, 2023, 7:52pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077/5 "2023-02-21T19:52:17Z")

</div>

Hello,  
if you are using **FILEBEAT**.

If you want to check the logs on your computer, I suggest:

- Install visual code
- Download the FILEBEAT agent(.zip)
- Open in Visual Code the logstash unzip folder
- the **filebeat.yml** file that you want to make
- In Visual Code open the TERMINAL , and execute the following command that allows you to visualize in console

```auto
.\filebeat.exe -c .\filebeat.yml

```

You configure the filebeat.yml file as follows:

```auto
# ============================== Filebeat inputs ===============================

filebeat.inputs:
- type: beats  
  beats:
    port: 5044

```

If you have a specific path to bring the logs from, you enable it.

```auto
 paths:
 # - /var/log/*.log
     c:\programdata\elasticsearch\logs\*

```

for the output of information by console is:

```auto
# ================================== Outputs ===================================

# Configure what output to use when sending the data collected by the beat.
#output.stdout:
 # pretty: true
  
output.console:
  pretty: true

```

---

<div class="post-metadata">

**Author:** ![jeanette](https://avatars.discourse-cdn.com/v4/letter/j/c0e974/32.png) [@jeanette](https://discuss.elastic.co/u/jeanette)\
**Post date:** [February 21, 2023, 9:36pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077/6 "2023-02-21T21:36:56Z")

</div>

Thanks for your input Ingri. I will try that.

---

<div class="post-metadata">

**Author:** ![ingri.mahecha](https://avatars.discourse-cdn.com/v4/letter/i/51bf81/32.png) [@ingri.mahecha](https://discuss.elastic.co/u/ingri.mahecha)\
**Post date:** [February 21, 2023, 11:50pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077/7 "2023-02-21T23:50:09Z")

</div>

Ok, the important thing is that if you don't have a log storage path, just comment out the line and that's it.

```auto
#paths:
 # - /var/log/*.log
  # c:\programdata\elasticsearch\logs\*

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2023, 11:50pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077/8 "2023-03-21T23:50:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
