# (seems) Doesn't read default configuration, logstash.conf

**URL:** <https://discuss.elastic.co/t/seems-doesnt-read-default-configuration-logstash-conf/63169>\
**Category:** Logstash\
**Created:** [October 17, 2016, 9:08am UTC](https://discuss.elastic.co/t/seems-doesnt-read-default-configuration-logstash-conf/63169 "2016-10-17T09:08:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dstjahjono](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@dstjahjono](https://discuss.elastic.co/u/dstjahjono)\
**Post date:** [October 17, 2016, 9:08am UTC](https://discuss.elastic.co/t/seems-doesnt-read-default-configuration-logstash-conf/63169/1 "2016-10-17T09:08:16Z")

</div>

Hi,

Newbie here, just installed Logstash, have 2 questions.

1. I follow this step, [https://www.elastic.co/guide/en/logstash/5.0/config-examples.html](https://www.elastic.co/guide/en/logstash/5.0/config-examples.html), run in command line and working.

[/opt/logstash]$ bin/logstash -f /opt/logstash/logstash-access\_log.conf  
Settings: Default pipeline workers: 2  
Pipeline main started  
{  
"message" =\> "x.x.x.x - - [17/Oct/2016:16:45:01 +0800] "GET /KG HTTP/1.1" 302 -",  
"@version" =\> "1",  
"@timestamp" =\> "2016-10-17T09:02:42.609Z",  
"path" =\> "/myapp/logs/access\_log.2016-10-17.txt",  
"host" =\> "ip-y.y.y.y",  
"type" =\> "apache\_access"

I copied the logstash-access\_log.conf into /etc/logstash/conf.d/logstash.conf (just rename into another file).

$ diff /opt/logstash/logstash-access\_log.conf /etc/logstash/conf.d/logstash.conf | wc -l  
0

But when I start logstash as a service, service logstash st,art, it doesn't send any data at all and the logs only show below,

[/var/log/logstash]$ cat \*  
{:timestamp=\>"2016-10-17T11:53:29.162000+0800", :message=\>"Pipeline main started"}  
{:timestamp=\>"2016-10-17T14:57:02.191000+0800", :message=\>"SIGTERM received. Shutting down the agent.", :level=\>:warn}  
{:timestamp=\>"2016-10-17T14:57:02.193000+0800", :message=\>"stopping pipeline", :id=\>"main"}  
{:timestamp=\>"2016-10-17T14:57:02.705000+0800", :message=\>"Pipeline main has been shutdown"}  
{:timestamp=\>"2016-10-17T16:49:18.867000+0800", :message=\>"Pipeline main started"}  
{:timestamp=\>"2016-10-17T17:00:01.734000+0800", :message=\>"SIGTERM received. Shutting down the agent.", :level=\>:warn}  
{:timestamp=\>"2016-10-17T17:00:01.736000+0800", :message=\>"stopping pipeline", :id=\>"main"}  
{:timestamp=\>"2016-10-17T17:00:02.033000+0800", :message=\>"Pipeline main has been shutdown"}  
Sending logstash logs to /var/log/logstash/logstash.log.  
{:timestamp=\>"2016-10-17T16:49:18.867000+0800", :message=\>"Pipeline main started"}  
{:timestamp=\>"2016-10-17T17:00:01.736000+0800", :message=\>"stopping pipeline", :id=\>"main"}  
{:timestamp=\>"2016-10-17T17:00:02.033000+0800", :message=\>"Pipeline main has been shutdown"}

[/var/log/logstash]$ ls -ltr  
total 8  
-rw-r--r-- 1 root root 0 Oct 17 16:49 logstash.err  
-rw-r--r-- 1 root root 325 Oct 17 17:00 logstash.stdout  
-rw-r--r-- 1 logstash logstash 774 Oct 17 17:00 logstash.log

What's wrong?

1. The input log contains date which is rolling daily. How to make it auto update in configuration file? I tried to make like "/mylog/logs/access\_log.`date +"%Y-%m-%d"`.txt" is not working.

input {  
file {  
path =\> "/mylog/logs/access\_log.2016-10-17.txt"  
start\_position =\> "beginning"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 18, 2016, 6:11am UTC](https://discuss.elastic.co/t/seems-doesnt-read-default-configuration-logstash-conf/63169/2 "2016-10-18T06:11:34Z")

</div>

1. There are many possible reasons why this doesn't work, e.g. that the user that Logstash runs as when run as a service (most likely "logstash") doesn't have permissions to read the access log. If you increase the logging verbosity by adjusting LS\_OPTS in /etc/sysconfig/logstash or /etc/default/logstash (I believe that's how it works also in Logstash 5) you'll get additional details.
2. Just use a filename pattern that selects all log files, like /mylog/logs/access\_log.\*.txt.

---

<div class="post-metadata">

**Author:** ![dstjahjono](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@dstjahjono](https://discuss.elastic.co/u/dstjahjono)\
**Post date:** [October 18, 2016, 7:47am UTC](https://discuss.elastic.co/t/seems-doesnt-read-default-configuration-logstash-conf/63169/3 "2016-10-18T07:47:44Z")

</div>

Fantastic, solves all my 2 problems !!! 👏

Reason for no. 1, logstash is run under logstash user when I run as a service where logstash user doesn't have an READ access to my log file. I thought it's run under ec2-user or root.

Another question, how to make logstash auto reload configuration when runs as a service, instead of restarting? In command line I can use --auto-reload option.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 18, 2016, 7:54am UTC](https://discuss.elastic.co/t/seems-doesnt-read-default-configuration-logstash-conf/63169/4 "2016-10-18T07:54:08Z")

</div>

> Another question, how to make logstash auto reload configuration when runs as a service, instead of restarting? In command line I can use --auto-reload option.

Again, command line options are (AFAIK) controlled via LS\_OPTS in /etc/sysconfig/logstash or /etc/default/logstash.

---

<div class="post-metadata">

**Author:** ![dstjahjono](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@dstjahjono](https://discuss.elastic.co/u/dstjahjono)\
**Post date:** [October 18, 2016, 8:14am UTC](https://discuss.elastic.co/t/seems-doesnt-read-default-configuration-logstash-conf/63169/5 "2016-10-18T08:14:06Z")

</div>

Thanks, it works!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:33am UTC](https://discuss.elastic.co/t/seems-doesnt-read-default-configuration-logstash-conf/63169/6 "2017-07-06T04:33:46Z")

</div>


