# Rubydebug is not displayed

**URL:** <https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743>\
**Category:** Logstash\
**Created:** [September 25, 2017, 6:54pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743 "2017-09-25T18:54:55Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![sam281](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sam281](https://discuss.elastic.co/u/sam281)\
**Post date:** [September 25, 2017, 6:54pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/1 "2017-09-25T18:54:56Z")

</div>

Hello,

I am running logstash on a windows server and have enabled Rubydebug to see how the data is being processed, but I don't see anything being logged on to console or in the rubydebug file. I have tried both the options stdout and file as mentioned below without any luck.

Any thoughts are appreciated on fixing this. Thanks in Advance.

output {

# Uncomment out below file output if users wish to view

# event data in a debug file. Specify the path for the file.

stdout{  
codec =\> rubydebug  
}  
#file {

# codec =\> rubydebug

# path =\> "C:\logstash2.2.1\log\ruby-debug.log"

# }

}

- 

Sam

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 25, 2017, 7:07pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/2 "2017-09-25T19:07:07Z")

</div>

`rubydebug` only works on stdout. It does not work with the file output.

As for why you're not seeing it at the command-line, how is it being launched?

---

<div class="post-metadata">

**Author:** ![sam281](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sam281](https://discuss.elastic.co/u/sam281)\
**Post date:** [September 25, 2017, 7:14pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/3 "2017-09-25T19:14:30Z")

</div>

I am running the logstash from command prompt below is the command I am using.

logstash agent --verbose -f C:\logstash2.2.1\logstash\plugins\logstash\config\logstash-scala\_rubydebug.conf -l C:\logstash2.2.1\log\console.log

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 25, 2017, 7:40pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/4 "2017-09-25T19:40:17Z")

</div>

For `stdout` to work with the `rubydebug` codec, remove the `-l C:\logstash2.2.1\log\console.log` portion. It needs to log to the console.

---

<div class="post-metadata">

**Author:** ![sam281](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sam281](https://discuss.elastic.co/u/sam281)\
**Post date:** [September 25, 2017, 8:33pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/5 "2017-09-25T20:33:27Z")

</div>

Yes, I have tried that already, I see only the Regex patterns being logged in the console.

Below is an excerpt of the output on the conosole.

C:\logstash2.2.1\bin\>logstash agent --verbose -f C:\logstash2.2.1\logstash\plugins\logstash\config\logstash-scala\_rubydebug.conf  
io/console not supported; tty will not be manipulated  
Settings: Default pipeline workers: 1  
e[32mRegistering file input {:path=\>["C:\Windows\System32\winevt\Logs\ForwardedEvents.evtx"], :level=\>:info}e[0m  
e[32mNo sincedb\_path set, generating one based on the file path {:sincedb\_path=\>"C:\Users\itmuser/.sincedb\_d1c5aedc0be3c7fc50ce39bb2e81ca62", :path=\>["C:\Windows\System32\winevt\Logs\ForwardedEvents.evtx"], :level=\>:info}e[0m  
e[32mGrok patterns path {:patterns\_dir=\>["C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns", "C:/logstash2.2.1/patterns/_"], :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/aws", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/bacula", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/bro", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/exim", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/firewalls", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/grok-patterns", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/haproxy", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/java", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/junos", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/linux-syslog", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/mcollective", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/mcollective-patterns", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/mongodb", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/nagios", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/postgresql", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/rails", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/redis", :level=\>:info}e[0m  
e[32mGrok loading patterns from file {:path=\>"C:/logstash2.2.1/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns/ruby", :level=\>:info}e[0m  
e[32mMatch data {:match=\>{"TimeGenerated"=\>"%{DATA:TIMEGEN\_DATE} %{DATA:TIMEGEN\_TIME} %{ISO8601\_TIMEZONE:TZ}", "message"=\>[]}, :level=\>:info}e[0m  
e[32mGrok compile {:field=\>"TimeGenerated", :patterns=\>["%{DATA:TIMEGEN\_DATE} %{DATA:TIMEGEN\_TIME} %{ISO8601\_TIMEZONE:TZ}"], :level=\>:info}e[0m  
e[32mAdding pattern {"S3\_REQUEST\_LINE"=\>"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})", :level=\>:info}e[0m  
e[32mAdding pattern {"S3\_ACCESS\_LOG"=\>"%{WORD:owner} %{NOTSPACE:bucket} \[%{HTTPDATE:timestamp}\] %{IP:clientip} %{NOTSPACE:requester} %{NOTSPACE:request\_id} %{NOTSPACE:operation} %{NOTSPACE:key} (?:"%{S3\_REQUEST\_LINE}"|-) (?:%{INT:response:int}|-) (?:-|%{NOTSPACE:error\_code}) (?:%{INT:bytes:int}|-) (?:%{INT:object\_size:int}|-) (?:%{INT:request\_time\_ms:int}|-) (?:%{INT:turnaround\_time\_ms:int}|-) (?:%{QS:referrer}|-) (?:"?%{QS:agent}"?|-) (?:-|%{NOTSPACE:version\_id})", :level=\>:info}e[0m  
e[32mAdding pattern {"ELB\_URIPATHPARAM"=\>"%{URIPATH:path}(?:%{URIPARAM:params})?", :level=\>:info}e[0m  
e[32mAdding pattern {"ELB\_URI"=\>"%{URIPROTO:proto}://(?:%{USER}(?::[^@]_)?@)?(?:%{URIHOST:urihost})?(?:%{ELB\_URIPATHPARAM})?", :level=\>:info}e[0m  
e[32mAdding pattern {"ELB\_REQUEST\_LINE"=\>"(?:%{WORD:verb} %{ELB\_URI:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})", :level=\>:info}e[0m  
e[32mAdding pattern {"ELB\_ACCESS\_LOG"=\>"%{TIMESTAMP\_ISO8601:timestamp} %{NOTSPACE:elb} %{IP:clientip}:%{INT:clientport:int} (?:(%{IP:backendip}:?:%{INT:backendport:int})|-) %{NUMBER:request\_processing\_time:float} %{NUMBER:backend\_processing\_time:float} %{NUMBER:response\_processing\_time:float} %{INT:response:int} %{INT:backend\_response:int} %{INT:received\_bytes:int} %{INT:bytes:int} "%{ELB\_REQUEST\_LINE}"", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_TIMESTAMP"=\>"%{MONTHDAY}-%{MONTH} %{HOUR}:%{MINUTE}", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_HOST"=\>"[a-zA-Z0-9-]+", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_VOLUME"=\>"%{USER}", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_DEVICE"=\>"%{USER}", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_DEVICEPATH"=\>"%{UNIXPATH}", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_CAPACITY"=\>"%{INT}{1,3}(,%{INT}{3})\*", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_VERSION"=\>"%{USER}", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_JOB"=\>"%{USER}", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_LOG\_MAX\_CAPACITY"=\>"User defined maximum volume capacity %{BACULA\_CAPACITY} exceeded on device \"%{BACULA\_DEVICE:device}\" \(%{BACULA\_DEVICEPATH}\)", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_LOG\_END\_VOLUME"=\>"End of medium on Volume \"%{BACULA\_VOLUME:volume}\" Bytes=%{BACULA\_CAPACITY} Blocks=%{BACULA\_CAPACITY} at %{MONTHDAY}-%{MONTH}-%{YEAR} %{HOUR}:%{MINUTE}.", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_LOG\_NEW\_VOLUME"=\>"Created new Volume \"%{BACULA\_VOLUME:volume}\" in catalog.", :level=\>:info}e[0m  
e[32mAdding pattern {"BACULA\_LOG\_NEW\_LABEL"=\>"Labeled new Volume \"%{BACULA\_VOLUME:volume}\" on device \"%{BACULA\_DEVICE:device}\" \(%{BACULA\_DEVICEPATH}\).", :level=\>:info}e[0m

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 25, 2017, 8:35pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/6 "2017-09-25T20:35:32Z")

</div>

You shouldn't need to add `agent`, and remove `--verbose` for this test.

---

<div class="post-metadata">

**Author:** ![sam281](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sam281](https://discuss.elastic.co/u/sam281)\
**Post date:** [September 25, 2017, 8:40pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/7 "2017-09-25T20:40:47Z")

</div>

I still don't see anything being logged on the console. Below is the ouput.

C:\logstash2.2.1\bin\>logstash -f C:\logstash2.2.1\logstash\plugins\logstash\config\logstash-scala\_rubydebug.conf  
io/console not supported; tty will not be manipulated  
Settings: Default pipeline workers: 1  
Logstash startup completed

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 25, 2017, 9:37pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/8 "2017-09-25T21:37:48Z")

</div>

> [@sam281](#):
>
> io/console not supported; tty will not be manipulated

I am AFK at the moment. There was something about how Windows launched java that did this, but I don't remember off hand. Is there a reason you're not using a more recent version? Like 5.6.1?

---

<div class="post-metadata">

**Author:** ![sam281](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sam281](https://discuss.elastic.co/u/sam281)\
**Post date:** [September 25, 2017, 10:35pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/9 "2017-09-25T22:35:55Z")

</div>

I am using logstash with an IBM log management product, so I had to use the custom output plugin which is developed for the product. I had to go with officially supported logstash which is 2.2.1 and not sure about support of the latest version of Logstash with the plugin.

Do you have any thoughts regarding using filebeats or winlogbeat with custom plugins to divert the output to a different tool?

---

<div class="post-metadata">

**Author:** ![sam281](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sam281](https://discuss.elastic.co/u/sam281)\
**Post date:** [September 27, 2017, 4:39pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/10 "2017-09-27T16:39:35Z")

</div>

Hi,

As you suggested I am trying to use logstash 5.6.2. now I see a different issue that its unable to locate jruby.

C:\logstash-5.6.2\bin\>logstash.bat --configtest -f C:\logstash2.2.1\logstash\plugins\logstash\config\logstash-scala\_rubydebug.conf  
"could not find jruby in C:\logstash-5.6.2\vendor\jruby"

Do we have to set any environment variables to point Jruby which is coming with Logstash? Any help is appreciated.

Thanks.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 27, 2017, 6:58pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/11 "2017-09-27T18:58:32Z")

</div>

Have you tried running `setup.bat` in the same directory? Is `JAVA_HOME` properly set?

---

<div class="post-metadata">

**Author:** ![sam281](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sam281](https://discuss.elastic.co/u/sam281)\
**Post date:** [September 27, 2017, 7:05pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/12 "2017-09-27T19:05:43Z")

</div>

Yes, I just tried setup.bat which is again complaining about jruby.

C:\logstash-5.6.2\bin\>setup.bat  
"could not find jruby in C:\logstash-5.6.2\vendor\jruby"

Below if the JAVA\_HOME path.

C:\logstash-5.6.2\bin\>echo %JAVA\_HOME%  
C:\logstash2.2.1\eclipseDevelopmentPackage\ibm\_sdk80

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 27, 2017, 7:23pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/13 "2017-09-27T19:23:30Z")

</div>

> [@sam281](#):
>
> C:\logstash2.2.1\eclipseDevelopmentPackage\ibm\_sdk80

That JVM is not a supported one. I'm sorry this is not straightforward. ☹ I'm not sure what to say at this point. It seems that a very custom installation was created to support the IBM JDK, and your specific plugin. Perhaps the people who created it know more?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2017, 7:23pm UTC](https://discuss.elastic.co/t/rubydebug-is-not-displayed/101743/14 "2017-10-25T19:23:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
