# Problem when i run logstash as a service

**URL:** <https://discuss.elastic.co/t/problem-when-i-run-logstash-as-a-service/227312>\
**Category:** Logstash\
**Created:** [April 9, 2020, 12:04pm UTC](https://discuss.elastic.co/t/problem-when-i-run-logstash-as-a-service/227312 "2020-04-09T12:04:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mimimike](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mimimike/32/60397_2.png) [@mimimike](https://discuss.elastic.co/u/mimimike)\
**Post date:** [April 9, 2020, 12:04pm UTC](https://discuss.elastic.co/t/problem-when-i-run-logstash-as-a-service/227312/1 "2020-04-09T12:04:52Z")

</div>

Hi everyone,

I don't know why cannot run logstash as a service. If i run logstash in command line works well but when i run as a service appears the next error in status service:

Apr 09 14:03:02 kafka02 logstash[60398]: 2012 down?: false  
Apr 09 14:03:02 kafka02 logstash[60398]: 2012 threads: 2  
Apr 09 14:03:02 kafka02 logstash[60398]: 2012 thread: #Thread:0x209fe7  
Apr 09 14:03:02 kafka02 logstash[60398]: 2012 thread\_key: rufus\_scheduler\_2010  
Apr 09 14:03:02 kafka02 logstash[60398]: 2012 work\_threads: 1  
Apr 09 14:03:02 kafka02 logstash[60398]: 2012 active: 1  
Apr 09 14:03:02 kafka02 logstash[60398]: 2012 vacant: 0  
Apr 09 14:03:02 kafka02 logstash[60398]: 2012 max\_work\_threads: 1  
Apr 09 14:03:02 kafka02 logstash[60398]: 2012 mutexes: {}  
Apr 09 14:03:02 kafka02 logstash[60398]: 2012 jobs: 1

Meanwhile in logs file:

[2020-04-09T14:02:25,448][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2020-04-09T14:02:25,540][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.1.1"}  
[2020-04-09T14:02:45,474][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://ip:9200/](http://ip:9200/)]}}  
[2020-04-09T14:02:46,294][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://ip:9200/](http://ip:9200/)"}  
[2020-04-09T14:02:46,532][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>7}  
[2020-04-09T14:02:46,547][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>7}  
[2020-04-09T14:02:46,711][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[http://ip:9200](http://ip:9200)"]}  
[2020-04-09T14:02:46,763][INFO][logstash.outputs.elasticsearch] Using default mapping template  
[2020-04-09T14:02:46,866][INFO][logstash.javapipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50, "pipeline.max\_inflight"=\>250, :thread=\>"#\<Thread:0x54e5324e run\>"}  
[2020-04-09T14:02:47,635][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"index\_patterns"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s", "number\_of\_shards"=\>1}, "mappings"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}  
[2020-04-09T14:02:48,340][INFO][logstash.javapipeline] Pipeline started {"pipeline.id"=\>"main"}  
[2020-04-09T14:02:49,483][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2020-04-09T14:02:52,620][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

I don't understand the error. Could someone help me?  
Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2020, 2:34pm UTC](https://discuss.elastic.co/t/problem-when-i-run-logstash-as-a-service/227312/2 "2020-04-09T14:34:28Z")

</div>

> [@mimimike](#):
>
> I don't understand the error. Could someone help me?

I do not see any error. That appears to be a normal startup.

---

<div class="post-metadata">

**Author:** ![mimimike](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mimimike/32/60397_2.png) [@mimimike](https://discuss.elastic.co/u/mimimike)\
**Post date:** [April 9, 2020, 5:13pm UTC](https://discuss.elastic.co/t/problem-when-i-run-logstash-as-a-service/227312/3 "2020-04-09T17:13:20Z")

</div>

So, if I run logstash in command line, some documents are recorded in a index. If I run as a service, no documents are recorded.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2020, 5:13pm UTC](https://discuss.elastic.co/t/problem-when-i-run-logstash-as-a-service/227312/4 "2020-05-07T17:13:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
