# Run Logstash in the background on Ubuntu

**URL:** <https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422>\
**Category:** Logstash\
**Created:** [July 24, 2018, 3:50pm UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422 "2018-07-24T15:50:07Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![hHelen](https://avatars.discourse-cdn.com/v4/letter/h/7ea924/32.png) [@hHelen](https://discuss.elastic.co/u/hHelen)\
**Post date:** [July 24, 2018, 3:50pm UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/1 "2018-07-24T15:50:07Z")

</div>

I already have logstash running on the termial with this command:

`sudo -Hu logstash /usr/share/logstash/bin/logstash --path.settings=/etc/logstash -f logstash-simple.conf`

I can see files scrolling past on the terminal, so closing it will kill the service.  
So, my question is how do I run my command above so that my terminal is free - and I can continue working on it? Basically, I need a way to start this command in the background:

`sudo -Hu logstash /usr/share/logstash/bin/logstash --path.settings=/etc/logstash -f logstash-simple.conf`

Any help would be appreciated.  
Helen

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 24, 2018, 6:33pm UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/2 "2018-07-24T18:33:27Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/running-logstash.html](https://www.elastic.co/guide/en/logstash/current/running-logstash.html)

---

<div class="post-metadata">

**Author:** ![hHelen](https://avatars.discourse-cdn.com/v4/letter/h/7ea924/32.png) [@hHelen](https://discuss.elastic.co/u/hHelen)\
**Post date:** [July 24, 2018, 8:46pm UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/3 "2018-07-24T20:46:47Z")

</div>

Thanks, I saw that link, but no where does it explain how to point to a config file. It assumes that that one is using the default config - at least that's my understanding.

So, how does running this command below know where my config file is?

`sudo systemctl start logstash.service`

I'm sorry if I sound daft but it doesn't show how to run a specific config file.

Thanks again for your help.  
Helen

---

<div class="post-metadata">

**Author:** ![Jevgenij](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jevgenij/32/33543_2.png) [@Jevgenij](https://discuss.elastic.co/u/Jevgenij)\
**Post date:** [July 25, 2018, 10:09am UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/4 "2018-07-25T10:09:24Z")

</div>

Trying to solve the exact same question.

As far as I see, you can't pass parameters to service while using [systemctl](https://www.freedesktop.org/software/systemd/man/systemctl.html).

So the only way I found so far is using [logstash.yml](https://www.elastic.co/guide/en/logstash/current/logstash-settings-file.html).

I haven't tried it yet, though.

---

<div class="post-metadata">

**Author:** ![Jevgenij](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jevgenij/32/33543_2.png) [@Jevgenij](https://discuss.elastic.co/u/Jevgenij)\
**Post date:** [July 25, 2018, 11:20am UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/5 "2018-07-25T11:20:26Z")

</div>

Ok, I've created `logstash.yml` under my `LS_HOME/config` directory.

You can find yours by running in terminal:

```
sudo cat /etc/default/logstash

```

`logstash.yml` file content in my case is:

```
pipeline.workers: 1
path.config: "/home/me/logstash.conf"

```

And it works perfectly while running Logstash with no parameters set from command line:

```
sudo -Hu logstash /usr/share/logstash/bin/logstash

```

But no luck with `sudo systemctl start logstash.service`.

It says:

```
[2018-07-25T12:48:56,717][INFO][logstash.runner] Starting Logstash {"logstash.version"=>"6.3.2"}
[2018-07-25T12:48:56,837][INFO][logstash.config.source.local.configpathloader] No config files found in path {:path=>"/etc/logstash/conf.d/*.conf"}
[2018-07-25T12:48:56,847][ERROR][logstash.config.sourceloader] No configuration found in the configured sources.
[2018-07-25T12:48:57,103][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}

```

Next thing I've done - I've copied my `logstash.conf` to `/etc/logstash/conf.d/` and got Logstash service working. But its results were like the `pipeline.workers: 1` wasn't set.

So it looks like Logstash service completely ignores `logstash.yml` settings file.

Any ideas?

---

<div class="post-metadata">

**Author:** ![tgaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgaudin/32/32583_2.png) [@tgaudin](https://discuss.elastic.co/u/tgaudin)\
**Post date:** [July 25, 2018, 11:24am UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/6 "2018-07-25T11:24:23Z")

</div>

When you install Logstash with the deb or rpm package, its configuration is in `/etc/logstash/logstash.yml`, with the pipelines definition in `/etc/logstash/pipelines.yml`.  
It is then picked up automatically when you start Logstash with `systemctl start logstash.service`

---

<div class="post-metadata">

**Author:** ![Jevgenij](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jevgenij/32/33543_2.png) [@Jevgenij](https://discuss.elastic.co/u/Jevgenij)\
**Post date:** [July 25, 2018, 12:47pm UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/7 "2018-07-25T12:47:06Z")

</div>

@tgaudin, thanks for collaboration!

Just moved my `logstash.yml` to `/etc/logstash` and got logstash service running correctly.

The only issue now is that running Logstash from command line fails with warning:

> Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults

Have no idea why can't it find `logstash.yml` in `/etc/logstash`.

But anyway, I believe that topicstarters question was answered.

---

<div class="post-metadata">

**Author:** ![tgaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgaudin/32/32583_2.png) [@tgaudin](https://discuss.elastic.co/u/tgaudin)\
**Post date:** [July 25, 2018, 12:51pm UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/8 "2018-07-25T12:51:10Z")

</div>

You can run it with `--path.settings /etc/logstash` on the CLI then, that's what I use to check if my configuration is syntactically correct (`/usr/share/logstash/bin/logstash -t --path.settings /etc/logstash/ --config.debug --log.level debug`).

But I think I see this warning all the time, it still picks up the configuration and runs correctly afterwards.

---

<div class="post-metadata">

**Author:** ![hHelen](https://avatars.discourse-cdn.com/v4/letter/h/7ea924/32.png) [@hHelen](https://discuss.elastic.co/u/hHelen)\
**Post date:** [July 25, 2018, 2:45pm UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/9 "2018-07-25T14:45:23Z")

</div>

Thanks for your comment and sample code.  
I will try your suggestion and see if that helps. You would expect this to be very simple but instead people are just pointing you to links that doesn't actually address your issue.

Thanks again, will let you know if it works for me.

Helen

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 25, 2018, 7:10pm UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/10 "2018-07-25T19:10:49Z")

</div>

> Thanks, I saw that link, but no where does it explain how to point to a config file. It assumes that that one is using the default config - at least that's my understanding.

Well, if you start Logstash or any other Linux service via e.g. systemd it'll look in the predefined directories for configuration files. There's no way to pass an option to the service startup command to point Logstash elsewhere (however, if you change configuration files that systemd pays attention to you can make it run other files).

See also [Logstash Directory Layout | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/dir-layout.html#deb-layout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2018, 7:11pm UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422/11 "2018-08-22T19:11:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
