# Running logstash as a deamon

**URL:** <https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754>\
**Category:** Logstash\
**Created:** [June 3, 2016, 3:14am UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754 "2016-06-03T03:14:53Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![mke](https://avatars.discourse-cdn.com/v4/letter/m/7cd45c/32.png) [@mke](https://discuss.elastic.co/u/mke)\
**Post date:** [June 3, 2016, 3:14am UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754/1 "2016-06-03T03:14:53Z")

</div>

I try to start logstash as a deamon but for some reason it does not seem to read my logstash.conf which I placed in /etc/logstash/conf.d/ What could be the reason?  
When I run it like `sudo bin/logstash -f ./logstash.conf` all works fine

sudo service logstash status  
● logstash.service - LSB: Starts Logstash as a daemon.  
Loaded: loaded (/etc/init.d/logstash; bad; vendor preset: enabled)  
Active: active (running) since Thu 2016-06-02 22:58:56 EDT; 9min ago  
Docs: man:systemd-sysv-generator(8)  
Process: 5198 ExecStart=/etc/init.d/logstash start (code=exited, status=0/SUCCESS)  
Tasks: 20  
Memory: 175.1M  
CPU: 18.598s  
CGroup: /system.slice/logstash.service  
└─5206 /usr/bin/java -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -Djava.awt.headless=true -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+HeapDumpOn

```
Jun 02 22:58:56 michal-ubuntu systemd[1]: Starting LSB: Starts Logstash as a daemon....
Jun 02 22:58:56 michal-ubuntu logstash[5198]: logstash started.
Jun 02 22:58:56 michal-ubuntu systemd[1]: Started LSB: Starts Logstash as a daemon..
Jun 02 23:08:07 michal-ubuntu systemd[1]: Started LSB: Starts Logstash as a daemon..
```

---

<div class="post-metadata">

**Author:** ![alibrelato](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@alibrelato](https://discuss.elastic.co/u/alibrelato)\
**Post date:** [June 3, 2016, 2:22pm UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754/2 "2016-06-03T14:22:30Z")

</div>

I got same problem with my new installation, my all conf files dint work when i start the logstash as deamon (/etc/init.d/logstash start), but if i run it like "bin/logstash -f /etc/logstash/conf.d/" all works fine...  
Its bug?  
Following the /etc/init.d/logstash file (START SESSION).

start() {

LS\_JAVA\_OPTS="${LS\_JAVA\_OPTS} -Djava.io.tmpdir=${LS\_HOME}"  
HOME=${LS\_HOME}  
export PATH HOME LS\_HEAP\_SIZE LS\_JAVA\_OPTS LS\_USE\_GC\_LOGGING LS\_GC\_LOG\_FILE

# chown doesn't grab the suplimental groups when setting the user:group - so we have to do it for it.

# Boy, I hope we're root here.

SGROUPS=$(id -Gn "$LS\_USER" | tr " " "," | sed 's/,$//'; echo '')

if [! -z $SGROUPS]  
then  
EXTRA\_GROUPS="--groups $SGROUPS"  
fi

# set ulimit as (root, presumably) first, before we drop privileges

ulimit -n ${LS\_OPEN\_FILES}

# Run the program!

nice -n ${LS\_NICE} chroot --userspec $LS\_USER:$LS\_GROUP $EXTRA\_GROUPS / sh -c "  
cd $LS\_HOME  
ulimit -n ${LS\_OPEN\_FILES}  
exec "$program" $args  
" \> "${LS\_LOG\_DIR}/$name.stdout" 2\> "${LS\_LOG\_DIR}/$name.err" &

# Generate the pidfile from here. If we instead made the forked process

# generate it there will be a race condition between the pidfile writing

# and a process possibly asking for status.

echo $! \> $pidfile

echo "$name started."  
return 0  
}

---

<div class="post-metadata">

**Author:** ![alibrelato](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@alibrelato](https://discuss.elastic.co/u/alibrelato)\
**Post date:** [June 6, 2016, 11:42am UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754/3 "2016-06-06T11:42:02Z")

</div>

Any news about this?

---

<div class="post-metadata">

**Author:** ![mke](https://avatars.discourse-cdn.com/v4/letter/m/7cd45c/32.png) [@mke](https://discuss.elastic.co/u/mke)\
**Post date:** [June 6, 2016, 12:53pm UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754/4 "2016-06-06T12:53:22Z")

</div>

I found this topic, but no specific response yet [Logstash don't read conf.d settings file when running as daemon](https://discuss.elastic.co/t/logstash-dont-read-conf-d-settings-file-when-running-as-daemon/50423)

It may be some permission/ownership problem

---

<div class="post-metadata">

**Author:** ![alibrelato](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@alibrelato](https://discuss.elastic.co/u/alibrelato)\
**Post date:** [June 7, 2016, 2:18pm UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754/5 "2016-06-07T14:18:59Z")

</div>

Daer mke

iIts running normal for me.  
what i change (2 choices)

1 - You have to create a username/group called logstash  
2 - Edit the file /etc/init.d/logstash and chance the options LS\_USER=root and LS\_GROUP=root

In my case, i made 2nd 😉

To start the application with your SO you have to do this:  
update-rc.d kibana defaults 95 10  
update-rc.d logstash defaults 95 10  
update-rc.d elasticsearch defaults 95 10

I guess Logstash team dev have to create the user/group when you install it by apt-get.

Rewards,  
Alex

---

<div class="post-metadata">

**Author:** ![mke](https://avatars.discourse-cdn.com/v4/letter/m/7cd45c/32.png) [@mke](https://discuss.elastic.co/u/mke)\
**Post date:** [June 7, 2016, 3:44pm UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754/6 "2016-06-07T15:44:36Z")

</div>

In my case all looks good out of the box but still does not seem to be reading confing files

Here is part of my logstash file you mentioned

name=logstash  
pidfile="/var/run/$name.pid"

LS\_USER=logstash  
LS\_GROUP=logstash  
LS\_HOME=/var/lib/logstash  
LS\_HEAP\_SIZE="1g"  
LS\_LOG\_DIR=/var/log/logstash  
LS\_LOG\_FILE="${LS\_LOG\_DIR}/$name.log"  
LS\_CONF\_DIR=/etc/logstash/conf.d  
#LS\_CONF\_DIR=/opt/logstash/bin  
LS\_OPEN\_FILES=16384  
LS\_NICE=19  
KILL\_ON\_STOP\_TIMEOUT=0  
LS\_OPTS=""

and just to make sure ownership is correct

ls -la /etc/logstash/conf.d/  
total 12  
drwxrwxr-x 2 root root 4096 Jun 6 10:47 .  
drwxrwxr-x 3 root root 4096 Jun 4 08:00 ..  
-rw-r--r-- 1 logstash logstash 2129 Jun 4 08:09 logstash.conf

---

<div class="post-metadata">

**Author:** ![alibrelato](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@alibrelato](https://discuss.elastic.co/u/alibrelato)\
**Post date:** [June 7, 2016, 5:38pm UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754/7 "2016-06-07T17:38:10Z")

</div>

> [@alibrelato](#):
>
> 2 - Edit the file /etc/init.d/logstash and chance the options LS\_USER=root and LS\_GROUP=root
> 
> In my case, i made 2nd

how i told you before.

if you edit the file /etc/init.d/logstash and chance:  
LS\_USER=logstash  
LS\_GROUP=logstash

to

LS\_USER=root  
LS\_GROUP=root

your conf files on /etc/logstash/conf.d will work if you run logstash as a deamon

---

<div class="post-metadata">

**Author:** ![Anton\_H](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anton_h/32/10200_2.png) [@Anton\_H](https://discuss.elastic.co/u/Anton_H)\
**Post date:** [June 8, 2016, 6:56am UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754/8 "2016-06-08T06:56:09Z")

</div>

With Ubuntu Logstash is started with the logstash user and group.  
Logstash would also fail to start as a daemon but would start when run as root.

The problem here was that java was not allowed to bind to ports below 1024.  
Have you checked that your input config is not listening to ports below 1024?  
If so you can use this command to allow java to do so.

setcap 'cap\_net\_bind\_service=+ep' /path/to/program

(the entire command in my case was: "sudo setcap 'cap\_net\_bind\_service=+ep' /usr/lib/jvm/java-8-oracle/jre/bin/java")

Hope this helps.

---

<div class="post-metadata">

**Author:** ![mke](https://avatars.discourse-cdn.com/v4/letter/m/7cd45c/32.png) [@mke](https://discuss.elastic.co/u/mke)\
**Post date:** [June 8, 2016, 1:48pm UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754/9 "2016-06-08T13:48:05Z")

</div>

Yup, that was what I needed, now it works not as a root but logstash. Yes indeed i was listening to port 514

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:54am UTC](https://discuss.elastic.co/t/running-logstash-as-a-deamon/51754/10 "2017-07-06T04:54:09Z")

</div>


