# Problem with Logstash logs

**URL:** <https://discuss.elastic.co/t/problem-with-logstash-logs/80276>\
**Category:** Logstash\
**Created:** [March 28, 2017, 10:42am UTC](https://discuss.elastic.co/t/problem-with-logstash-logs/80276 "2017-03-28T10:42:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![emilio](https://avatars.discourse-cdn.com/v4/letter/e/f475e1/32.png) [@emilio](https://discuss.elastic.co/u/emilio)\
**Post date:** [March 28, 2017, 10:42am UTC](https://discuss.elastic.co/t/problem-with-logstash-logs/80276/1 "2017-03-28T10:42:03Z")

</div>

Dear all,

I I would like to get know where is logstash logs. My goal is to have logstash logs in /data01/logstah/logs

Please help

Here are my configs:

logstash.yml

'''

# Settings file in YAML

# 

# Settings can be specified either in hierarchical form, e.g.:

# 

pipeline:  
batch:  
size: 125  
delay: 5

# 

# Or as flat keys:

# 

pipeline.batch.size: 125  
pipeline.batch.delay: 5

# 

# ------------ Node identity ------------

# 

# Use a descriptive name for the node:

# 

[node.name](http://node.name): "logstash"

# 

# If omitted the node name will default to the machine's host name

# 

# ------------ Data path ------------------

# 

# Which directory should be used by logstash and its plugins

# for any persistent needs. Defaults to LOGSTASH\_HOME/data

# 

path.data: /data01/logstash/data

# 

# ------------ Pipeline Settings --------------

# 

# Set the number of workers that will, in parallel, execute the filters+outputs

# stage of the pipeline.

# 

# This defaults to the number of the host's CPU cores.

# 

pipeline.workers: 1

# 

# How many workers should be used per output plugin instance

# 

pipeline.output.workers: 1

# 

# How many events to retrieve from inputs before sending to filters+workers

# 

pipeline.batch.size: 125

# 

# How long to wait before dispatching an undersized batch to filters+workers

# Value is in milliseconds.

# 

pipeline.batch.delay: 5

# 

# Force Logstash to exit during shutdown even if there are still inflight

# events in memory. By default, logstash will refuse to quit until all

# received events have been pushed to the outputs.

# 

# WARNING: enabling this can lead to data loss during shutdown

# 

pipeline.unsafe\_shutdown: false

# 

# ------------ Pipeline Configuration Settings --------------

# 

# Where to fetch the pipeline configuration for the main pipeline

# 

path.config: /etc/logstash/conf.d

# 

# Pipeline configuration string for the main pipeline

# 

config.string: /etc/logstash/conf.d

# 

# At startup, test if the configuration is valid and exit (dry run)

# 

# config.test\_and\_exit: false

# 

# Periodically check if the configuration has changed and reload the pipeline

# This can also be triggered manually through the SIGHUP signal

# 

config.reload.automatic: true

# 

# How often to check if the pipeline configuration has changed (in seconds)

# 

config.reload.interval: 3600

# 

# Show fully compiled configuration as debug log message

# NOTE: --log.level must be 'debug'

# 

config.debug: false

# 

# ------------ Queuing Settings --------------

# 

# Internal queuing model, "memory" for legacy in-memory based queuing and

# "persisted" for disk-based acked queueing. Defaults is memory

# 

queue.type: memory

# 

# If using queue.type: persisted, the directory path where the data files will be stored.

# Default is path.data/queue

# 

# path.queue:

# 

# If using queue.type: persisted, the page data files size. The queue data consists of

# append-only data files separated into pages. Default is 250mb

# 

# queue.page\_capacity: 250mb

# 

# If using queue.type: persisted, the maximum number of unread events in the queue.

# Default is 0 (unlimited)

# 

# queue.max\_events: 0

# 

# If using queue.type: persisted, the total capacity of the queue in number of bytes.

# If you would like more unacked events to be buffered in Logstash, you can increase the

# capacity using this setting. Please make sure your disk drive has capacity greater than

# the size specified here. If both max\_bytes and max\_events are specified, Logstash will pick

# whichever criteria is reached first

# Default is 1024mb or 1gb

# 

# queue.max\_bytes: 1024mb

# 

# If using queue.type: persisted, the maximum number of acked events before forcing a checkpoint

# Default is 1024, 0 for unlimited

# 

# queue.checkpoint.acks: 1024

# 

# If using queue.type: persisted, the maximum number of written events before forcing a checkpoint

# Default is 1024, 0 for unlimited

# 

# queue.checkpoint.writes: 1024

# 

# If using queue.type: persisted, the interval in milliseconds when a checkpoint is forced on the head page

# Default is 1000, 0 for no periodic checkpoint.

# 

# queue.checkpoint.interval: 1000

# 

# ------------ Metrics Settings --------------

# 

# Bind address for the metrics REST endpoint

# 

http.host: "127.0.0.1"

# 

# Bind port for the metrics REST endpoint, this option also accept a range

# (9600-9700) and logstash will pick up the first available ports.

# 

http.port: 9600-9700

# 

# ------------ Debugging Settings --------------

# 

# Options for

log.level:

- fatal
- error
- warn
- info (default)

# \* debug

# \* trace

# 

log.format: plain

path.logs: /data01/logstash/logs

log.level: info,warn,error

#path.logs: /data01/logstash/logs

# 

# ------------ Other Settings --------------

# 

# Where to find custom plugins

# path.plugins: []

'''  
'''  
log4j2.properties

status = error  
name = LogstashPropertiesConfig

appender.rolling.type = RollingFile  
[appender.rolling.name](http://appender.rolling.name) = plain\_rolling  
appender.rolling.fileName = /data01/logstash/logs/logstash-%d{yyyy-MM-dd}.log  
appender.rolling.filePattern = /data01/logstash/logs/logstash-%d{yyyy-MM-dd}.log  
appender.rolling.policies.type = Policies  
appender.rolling.policies.time.type = TimeBasedTriggeringPolicy  
appender.rolling.policies.time.interval = 1  
appender.rolling.policies.time.modulate = true  
appender.rolling.layout.type = PatternLayout  
appender.rolling.layout.pattern = [%d{ISO8601}][%-5p][%-25c] %-.10000m%n

appender.json\_rolling.type = RollingFile  
appender.json\_rolling.name = json\_rolling  
appender.json\_rolling.fileName = /data01/logstash/logs/logstash-%d{yyyy-MM-dd}.log  
appender.json\_rolling.filePattern = /data01/logstash/logs/logstash-%d{yyyy-MM-dd}.log  
appender.json\_rolling.policies.type = Policies  
appender.json\_rolling.policies.time.type = TimeBasedTriggeringPolicy  
appender.json\_rolling.policies.time.interval = 1  
appender.json\_rolling.policies.time.modulate = true  
appender.json\_rolling.layout.type = JSONLayout  
appender.json\_rolling.layout.compact = true  
appender.json\_rolling.layout.eventEol = true

rootLogger.level = ${sys:ls.log.level}  
rootLogger.appenderRef.rolling.ref = ${sys:ls.log.format}\_rolling  
'''

30-elasticsearch-output.conf

input {  
redis {  
enabled =\> true  
hosts =\> ["10.3.2.10:5044"]  
type =\> "redis-input"  
# these settings should match the output of the agent  
datatype =\> "pattern\_channel"  
key =\> "logs\*"  
codec =\> json

```
  # We use json_event here since the sender is a logstash agent
  format => "json_event"

```

}  
}

output {

```
elasticsearch {
#type => "all"
#embedded => false
enabled = "True"
hosts => ["10.3.2.11:9200"]
port => "9200"
sniffing => true
manage_template => false
index => "logs-%{+YYYY.MM.dd}"
document_type => "%{[@metadata][type]}"
timeout => "30"
max_retries => "3"
codec => json

```

}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 28, 2017, 10:50am UTC](https://discuss.elastic.co/t/problem-with-logstash-logs/80276/2 "2017-03-28T10:50:02Z")

</div>

Never mind those configuration files. What inputs, outputs, and filters do you have?

---

<div class="post-metadata">

**Author:** ![emilio](https://avatars.discourse-cdn.com/v4/letter/e/f475e1/32.png) [@emilio](https://discuss.elastic.co/u/emilio)\
**Post date:** [March 28, 2017, 10:54am UTC](https://discuss.elastic.co/t/problem-with-logstash-logs/80276/3 "2017-03-28T10:54:36Z")

</div>

Corrected info provided and added input-output config

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 28, 2017, 10:55am UTC](https://discuss.elastic.co/t/problem-with-logstash-logs/80276/4 "2017-03-28T10:55:13Z")

</div>

Use a file output to store logs in the local file system.

---

<div class="post-metadata">

**Author:** ![emilio](https://avatars.discourse-cdn.com/v4/letter/e/f475e1/32.png) [@emilio](https://discuss.elastic.co/u/emilio)\
**Post date:** [March 28, 2017, 11:38am UTC](https://discuss.elastic.co/t/problem-with-logstash-logs/80276/5 "2017-03-28T11:38:20Z")

</div>

How can i do it correctly?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 28, 2017, 1:03pm UTC](https://discuss.elastic.co/t/problem-with-logstash-logs/80276/6 "2017-03-28T13:03:23Z")

</div>

For example

```nohighlight
output {
  file {
    path => "/path/to/desired/file"
  }
}

```

---

<div class="post-metadata">

**Author:** ![emilio](https://avatars.discourse-cdn.com/v4/letter/e/f475e1/32.png) [@emilio](https://discuss.elastic.co/u/emilio)\
**Post date:** [March 28, 2017, 1:38pm UTC](https://discuss.elastic.co/t/problem-with-logstash-logs/80276/7 "2017-03-28T13:38:44Z")

</div>

Thanks a lot, Magnus!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2017, 1:38pm UTC](https://discuss.elastic.co/t/problem-with-logstash-logs/80276/8 "2017-04-25T13:38:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
