# Permission Denied - permission settings?

**URL:** <https://discuss.elastic.co/t/permission-denied-permission-settings/123359>\
**Category:** Logstash\
**Created:** [March 9, 2018, 11:17pm UTC](https://discuss.elastic.co/t/permission-denied-permission-settings/123359 "2018-03-09T23:17:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DevT](https://avatars.discourse-cdn.com/v4/letter/d/e495f1/32.png) [@DevT](https://discuss.elastic.co/u/DevT)\
**Post date:** [March 9, 2018, 11:17pm UTC](https://discuss.elastic.co/t/permission-denied-permission-settings/123359/1 "2018-03-09T23:17:24Z")

</div>

I get these errors when trying to start Logstash. I tried changing permissions. What do your permission settings look like on Ubuntu?

**logstash --path.settings /etc/logstash**  
`ERROR Unable to create file /var/log/logstash/logstash-plain.log java.io.IOException: Permission denied

ERROR Could not create plugin of type class org.apache.logging.log4j.core.appender.RollingFileAppender for element RollingFile: java.lang.IllegalStateException: ManagerFactory

ERROR Unable to invoke factory method in class org.apache.logging.log4j.core.appender.RollingFileAppender for element RollingFile: java.lang.IllegalStateException: No factory method found for class org.apache.logging.log4j.core.appender.RollingFileAppender java.lang.IllegalStateException: No factory method found for class org.apache.logging.log4j.core.appender.RollingFileAppender

ERROR Unable to create file /var/log/logstash/logstash-plain.log java.io.IOException: Permission denied

main ERROR Null object returned for RollingFile in Appenders.  
main ERROR Null object returned for RollingFile in Appenders.  
main ERROR Unable to locate appender "plain\_rolling" for logger config "root"  
`

**These are my permission settings:**  
drwxrwxr-x 10 logstash logstash 4096 Mar 9 17:33 /usr/share/logstash  
drwxrwxr-x 3 root root 4096 Mar 9 17:38 /etc/logstash  
drwxrwxr-x 2 logstash logstash 4096 Feb 16 15:54 logstash

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 10, 2018, 12:23am UTC](https://discuss.elastic.co/t/permission-denied-permission-settings/123359/2 "2018-03-10T00:23:25Z")

</div>

From the error, it is attempting to create the file `/var/log/logstash/logstash-plain.log`; what are your permissions for `/var/log/logstash/`, and what user is Logstash running as?

---

<div class="post-metadata">

**Author:** ![DevT](https://avatars.discourse-cdn.com/v4/letter/d/e495f1/32.png) [@DevT](https://discuss.elastic.co/u/DevT)\
**Post date:** [March 10, 2018, 11:51pm UTC](https://discuss.elastic.co/t/permission-denied-permission-settings/123359/3 "2018-03-10T23:51:54Z")

</div>

They are:  
drwxrwxr-x 2 root root 4096 Feb 16 15:54 logstash

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 11, 2018, 3:51am UTC](https://discuss.elastic.co/t/permission-denied-permission-settings/123359/4 "2018-03-11T03:51:25Z")

</div>

You don't have permission to write to that directory.

It is owned by `root` and assigned to group `root`; the permissions, with spaces and headers added for clarity, are:

```auto
type | user | group | other
d | rwx | rwx | r-x

```

- Since the owner is `root`, the fact that the owner has read, write, and execute doesn't help the `logstash` user
- since the assigned group is `root`, and the `logstash` user isn't in the `root` group, the group being assigned read, write, and execute doesn't help either.
- this means the `logstash` user fits into the "other" category, which only has read and execute permissions.

Most likely, you will want to change ownership of this directory to `logstash` with [`chown`](https://linux.die.net/man/1/chown):

```auto
chown --recursive logstash /var/log/logstash

```

The above command may require `sudo`, since your user is also not likely in the `root` group (and shouldn't be).

---

<div class="post-metadata">

**Author:** ![DevT](https://avatars.discourse-cdn.com/v4/letter/d/e495f1/32.png) [@DevT](https://discuss.elastic.co/u/DevT)\
**Post date:** [March 13, 2018, 1:27am UTC](https://discuss.elastic.co/t/permission-denied-permission-settings/123359/5 "2018-03-13T01:27:46Z")

</div>

O I C. Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2018, 1:28am UTC](https://discuss.elastic.co/t/permission-denied-permission-settings/123359/6 "2018-04-10T01:28:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
