# Nothing Happens After Restart

**URL:** <https://discuss.elastic.co/t/nothing-happens-after-restart/62240>\
**Category:** Logstash\
**Created:** [October 5, 2016, 8:02am UTC](https://discuss.elastic.co/t/nothing-happens-after-restart/62240 "2016-10-05T08:02:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Romain\_PZK](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@Romain\_PZK](https://discuss.elastic.co/u/Romain_PZK)\
**Post date:** [October 5, 2016, 8:02am UTC](https://discuss.elastic.co/t/nothing-happens-after-restart/62240/1 "2016-10-05T08:02:45Z")

</div>

Hello,

I've tried some modifications on my logstash config file and when I restart logstash nothing happens after "Pipeline main started". If I do a roll back on the config file, it's the same problem.  
Logstash not starting correctly as a service. But if I run logstash in verbose mode with the user root, it's working.  
(My syslog-ng still running)  
Can you help me for this problem ?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 5, 2016, 8:17am UTC](https://discuss.elastic.co/t/nothing-happens-after-restart/62240/2 "2016-10-05T08:17:40Z")

</div>

What does your config look like then?

---

<div class="post-metadata">

**Author:** ![Romain\_PZK](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@Romain\_PZK](https://discuss.elastic.co/u/Romain_PZK)\
**Post date:** [October 5, 2016, 8:25am UTC](https://discuss.elastic.co/t/nothing-happens-after-restart/62240/3 "2016-10-05T08:25:40Z")

</div>

This is my working config file :  
input{  
file{  
path =\> "/home/logs/firewall/heimdall.log"  
type =\> "linux-syslog"  
}  
}  
filter {  
grok {  
match =\> {   
"message" =\> '%{SYSLOGTIMESTAMP} %{IPV4:iphost} %{GREEDYDATA:fgtlogmsg}'  
}  
}  
kv {  
source =\> "fgtlogmsg"  
}  
mutate {  
remove\_field =\> ["message" , "fgtlogmsg", "vd", "host", "logid"]  
}  
}  
output {  
elasticsearch {  
codec =\> "json"  
hosts =\> ["127.0.0.1:9200"]  
index =\> "heimdall"  
}  
# stdout { codec =\> rubydebug }  
}

If I restart the service, this never starting correctly with "service logstash restart"

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 5, 2016, 8:29am UTC](https://discuss.elastic.co/t/nothing-happens-after-restart/62240/4 "2016-10-05T08:29:39Z")

</div>

It's likely this then - [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#\_tracking\_of\_current\_position\_in\_watched\_files](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#_tracking_of_current_position_in_watched_files)

---

<div class="post-metadata">

**Author:** ![Romain\_PZK](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@Romain\_PZK](https://discuss.elastic.co/u/Romain_PZK)\
**Post date:** [October 5, 2016, 8:52am UTC](https://discuss.elastic.co/t/nothing-happens-after-restart/62240/5 "2016-10-05T08:52:43Z")

</div>

I have not specified any file but I have some file in /var/lib/logstash named .sincedb\_\*.  
So, normally it's ok ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:35am UTC](https://discuss.elastic.co/t/nothing-happens-after-restart/62240/6 "2017-07-06T04:35:43Z")

</div>


