# Problem with reading logs

**URL:** <https://discuss.elastic.co/t/problem-with-reading-logs/126727>\
**Category:** Logstash\
**Created:** [April 4, 2018, 11:05am UTC](https://discuss.elastic.co/t/problem-with-reading-logs/126727 "2018-04-04T11:05:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![pablo\_gracia](https://avatars.discourse-cdn.com/v4/letter/p/a4c791/32.png) [@pablo\_gracia](https://discuss.elastic.co/u/pablo_gracia)\
**Post date:** [April 4, 2018, 11:05am UTC](https://discuss.elastic.co/t/problem-with-reading-logs/126727/1 "2018-04-04T11:05:23Z")

</div>

First of all sorry for my english I know it´s not the best one.

Well so, I installed logstash, elasicsearch and kibana on my debian 8 in Virtual box, and i Hvae a WatchWard where im receiving the logs from.

The problem is that i use the comand tcpdump port 5000 and im receiving pakets from my WatchWard, on my logstash file configuration it is configured to check te port 5000 and i dont know why it is not doing it, or maybe its my elasticsearch that its not doing its work i dunno, because if i configure my elastisearch to look up for local logs it shows me thoso so i dont know where is the problem.  
if someone could help me it will be Awesome!

Thanks

Pablo

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 4, 2018, 6:36pm UTC](https://discuss.elastic.co/t/problem-with-reading-logs/126727/2 "2018-04-04T18:36:22Z")

</div>

- can you share the `input` and `output` blocks from your pipeline configuration? If they include credentials, please make sure to redact them.
- the logs that Logstash emits can be helpful in determining many problems; where the logs end up dependent on how you've installed and are running Logstash, but these [docs](https://www.elastic.co/guide/en/logstash/current/logging.html) should help you find them.
- typically, I include an additional `output` to `stdout` using the `rubydebug` codec while I'm standing up a new pipeline, which helps me see what Logstash is doing:

```auto
output {
  stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![pablo\_gracia](https://avatars.discourse-cdn.com/v4/letter/p/a4c791/32.png) [@pablo\_gracia](https://discuss.elastic.co/u/pablo_gracia)\
**Post date:** [April 5, 2018, 8:02am UTC](https://discuss.elastic.co/t/problem-with-reading-logs/126727/3 "2018-04-05T08:02:39Z")

</div>

First of all thank you for answering me.

As u can see here i receive packets from my watchward at port 5000

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e0bd7995240b69b819fa85d23cf4d8e6f1f9462.png)

And now i will show you my configuration even the IPs my logstash and elasticsearch are "listening".

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a501644bc826f8a1548c02c94d4c3c312ed5b3d0.jpg)

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9f43d4016a5541d1cd7870212b3c2f8ad7bac138.jpg)

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/257b35d6a2b0d3ea6502b7b8618df7bc8bb0b117.jpg)

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/2/22049c09079c48f43768db0c4ae3b06af754f56e.jpg)

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/3/135e3ef8365edbd0a4d0f00f52be213af4e33319.png)

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 5, 2018, 7:48pm UTC](https://discuss.elastic.co/t/problem-with-reading-logs/126727/4 "2018-04-05T19:48:27Z")

</div>

The packets in your tcpdump are being sent to _UDP_ port 5000; Lumberjack listens on _TCP_ ports.

Worth noting though, `logstash_forwarder` has been deprecated; it is suggested to use [Filebeat](https://www.elastic.co/products/beats/filebeat) and the [Beats Input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html) instead.

---

<div class="post-metadata">

**Author:** ![pablo\_gracia](https://avatars.discourse-cdn.com/v4/letter/p/a4c791/32.png) [@pablo\_gracia](https://discuss.elastic.co/u/pablo_gracia)\
**Post date:** [April 6, 2018, 8:00am UTC](https://discuss.elastic.co/t/problem-with-reading-logs/126727/5 "2018-04-06T08:00:40Z")

</div>

Well i used rsyslog and apparently im receiving logs now I store them at /var/log/udp.log and i receive them from udp and tcp.

Thanks for answering me back @yaauie

Pablo

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2018, 8:01am UTC](https://discuss.elastic.co/t/problem-with-reading-logs/126727/6 "2018-05-04T08:01:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
