# Service seem to hang

**URL:** https://discuss.elastic.co/t/service-seem-to-hang/134755
**Category:** Logstash
**Created:** [June 6, 2018, 8:06am UTC](https://discuss.elastic.co/t/service-seem-to-hang/134755 "2018-06-06T08:06:57Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![yks](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@yks](https://discuss.elastic.co/u/yks)
#### Post date: [June 6, 2018, 8:06am UTC](https://discuss.elastic.co/t/service-seem-to-hang/134755/1 "2018-06-06T08:06:57Z")

</div>

Hi,

I am using the guide here  
: [Parsing Logs with Logstash | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html),  
The service seem to hang at here after i executed the following command

> logstash -f first-pipeline.conf --config.reload.automatic  
> Sending Logstash's logs to /usr/local/Cellar/logstash/6.2.4/libexec/logs which is now configured via log4j2.properties  
> [2018-06-06T15:56:01,700][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"/usr/local/Cellar/logstash/6.2.4/libexec/modules/fb\_apache/configuration"}  
> [2018-06-06T15:56:01,726][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"/usr/local/Cellar/logstash/6.2.4/libexec/modules/netflow/configuration"}  
> [2018-06-06T15:56:02,049][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
> [2018-06-06T15:56:03,178][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.2.4"}  
> [2018-06-06T15:56:03,723][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
> [2018-06-06T15:56:08,820][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
> [2018-06-06T15:56:09,431][INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=\>"0.0.0.0:5044"}  
> [2018-06-06T15:56:09,547][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x2c108465 run\>"}  
> [2018-06-06T15:56:09,625][INFO][org.logstash.beats.Server] Starting server on port: 5044  
> [2018-06-06T15:56:09,687][INFO][logstash.agent] Pipelines running {:count=\>1, :pipelines=\>["main"]}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 6, 2018, 12:23pm UTC](https://discuss.elastic.co/t/service-seem-to-hang/134755/2 "2018-06-06T12:23:35Z")

</div>

Please show your Logstash configuration. If you're using Filebeat, please check the Filebeat log for clues about what it's doing.

---

<div class="post-metadata">

### Author: ![yks](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@yks](https://discuss.elastic.co/u/yks)
#### Post date: [June 7, 2018, 7:57am UTC](https://discuss.elastic.co/t/service-seem-to-hang/134755/3 "2018-06-07T07:57:31Z")

</div>

Hi Magnus,

Attached the logstash.yml.  
Yes I'm using filebeat, but can't find the related log.. I am using brew to install filebeat

```
# Settings file in YAML
#
# Settings can be specified either in hierarchical form, e.g.:
#
# pipeline:
# batch:
# size: 125
# delay: 5
#
# Or as flat keys:
#
# pipeline.batch.size: 125
# pipeline.batch.delay: 5
#
# ------------ Node identity ------------
#
# Use a descriptive name for the node:
#
# node.name: test
#
# If omitted the node name will default to the machine's host name
#
# ------------ Data path ------------------
#
# Which directory should be used by logstash and its plugins
# for any persistent needs. Defaults to LOGSTASH_HOME/data
#
 path.data: /usr/local/etc
#
# ------------ Pipeline Settings --------------
#
# The ID of the pipeline.
#
# pipeline.id: main
#
# Set the number of workers that will, in parallel, execute the filters+outputs
# stage of the pipeline.
#
# This defaults to the number of the host's CPU cores.
#
# pipeline.workers: 2
#
# How many events to retrieve from inputs before sending to filters+workers
#
# pipeline.batch.size: 125
#
# How long to wait in milliseconds while polling for the next event
# before dispatching an undersized batch to filters+outputs
#
# pipeline.batch.delay: 50
#
# Force Logstash to exit during shutdown even if there are still inflight
# events in memory. By default, logstash will refuse to quit until all
# received events have been pushed to the outputs.
#
# WARNING: enabling this can lead to data loss during shutdown
#
# pipeline.unsafe_shutdown: false
#
# ------------ Pipeline Configuration Settings --------------
#
# Where to fetch the pipeline configuration for the main pipeline
#
# path.config:
#
# Pipeline configuration string for the main pipeline
#
# config.string:
#
# At startup, test if the configuration is valid and exit (dry run)
#
# config.test_and_exit: false
#
# Periodically check if the configuration has changed and reload the pipeline
# This can also be triggered manually through the SIGHUP signal
#
# config.reload.automatic: false
#
# How often to check if the pipeline configuration has changed (in seconds)
#
# config.reload.interval: 3s
#
# Show fully compiled configuration as debug log message
# NOTE: --log.level must be 'debug'
#
# config.debug: false
#
# When enabled, process escaped characters such as \n and \" in strings in the
# pipeline configuration files.
#
# config.support_escapes: false
#
# ------------ Module Settings ---------------
# Define modules here. Modules definitions must be defined as an array.
# The simple way to see this is to prepend each `name` with a `-`, and keep
# all associated variables under the `name` they are associated with, and
# above the next, like this:
#
# modules:
# - name: MODULE_NAME
# var.PLUGINTYPE1.PLUGINNAME1.KEY1: VALUE
# var.PLUGINTYPE1.PLUGINNAME1.KEY2: VALUE
# var.PLUGINTYPE2.PLUGINNAME1.KEY1: VALUE
# var.PLUGINTYPE3.PLUGINNAME3.KEY1: VALUE
#
# Module variable names must be in the format of
#
# var.PLUGIN_TYPE.PLUGIN_NAME.KEY
#
# modules:
#
# ------------ Cloud Settings ---------------
# Define Elastic Cloud settings here.
# Format of cloud.id is a base64 value e.g. dXMtZWFzdC0xLmF3cy5mb3VuZC5pbyRub3RhcmVhbCRpZGVudGlmaWVy
# and it may have an label prefix e.g. staging:dXMtZ...
# This will overwrite 'var.elasticsearch.hosts' and 'var.kibana.host'
# cloud.id: <identifier>
#
# Format of cloud.auth is: <user>:<pass>
# This is optional
# If supplied this will overwrite 'var.elasticsearch.username' and 'var.elasticsearch.password'
# If supplied this will overwrite 'var.kibana.username' and 'var.kibana.password'
# cloud.auth: elastic:<password>
#
# ------------ Queuing Settings --------------
#
# Internal queuing model, "memory" for legacy in-memory based queuing and
# "persisted" for disk-based acked queueing. Defaults is memory
#
# queue.type: memory
#
# If using queue.type: persisted, the directory path where the data files will be stored.
# Default is path.data/queue
#
# path.queue:
#
# If using queue.type: persisted, the page data files size. The queue data consists of
# append-only data files separated into pages. Default is 64mb
#
 queue.page_capacity: 64mb
#
# If using queue.type: persisted, the maximum number of unread events in the queue.
# Default is 0 (unlimited)
# whichever criteria is reached first
# Default is 1024mb or 1gb
#
# queue.max_bytes: 1024mb
#
# If using queue.type: persisted, the maximum number of acked events before forcing a checkpoint
# Default is 1024, 0 for unlimited
#
# queue.checkpoint.acks: 1024
#
# If using queue.type: persisted, the maximum number of written events before forcing a checkpoint
# Default is 1024, 0 for unlimited
#
# queue.checkpoint.writes: 1024
#
# If using queue.type: persisted, the interval in milliseconds when a checkpoint is forced on the head page
# Default is 1000, 0 for no periodic checkpoint.
#
# queue.checkpoint.interval: 1000
#
# ------------ Dead-Letter Queue Settings --------------
# Flag to turn on dead-letter queue.
#
# dead_letter_queue.enable: false

# If using dead_letter_queue.enable: true, the maximum size of each dead letter queue. Entries
# will be dropped if they would increase the size of the dead letter queue beyond this setting.
# Default is 1024mb
# dead_letter_queue.max_bytes: 1024mb

# If using dead_letter_queue.enable: true, the directory path where the data files will be stored.
# Default is path.data/dead_letter_queue
#
# path.dead_letter_queue:
#
# ------------ Metrics Settings --------------
#
# Bind address for the metrics REST endpoint
#
# http.host: "127.0.0.1"
#
# Bind port for the metrics REST endpoint, this option also accept a range
# (9600-9700) and logstash will pick up the first available ports.
#
 http.port: 9600
#
# ------------ Debugging Settings --------------
#
# Options for log.level:
# * fatal
# * error
# * warn
# * info (default)
# * debug
# * trace
#
# log.level: info
 path.logs: /usr/local/etc/logstash
```

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 7, 2018, 9:36am UTC](https://discuss.elastic.co/t/service-seem-to-hang/134755/4 "2018-06-07T09:36:45Z")

</div>

I meant first-pipeline.conf.

You need to locate the Filebeat logs. I think the Filebeat documentation explains where they are, or at least how you can configure the location (including the default location).

---

<div class="post-metadata">

### Author: ![yks](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@yks](https://discuss.elastic.co/u/yks)
#### Post date: [June 8, 2018, 6:52am UTC](https://discuss.elastic.co/t/service-seem-to-hang/134755/5 "2018-06-08T06:52:46Z")

</div>

I updated the logging at path: /usr/local/var/log/filebeat in filetbeat.yml file.  
But no updates on filebeat log from what i see based on timestamp.  
Is there any thing I miss out here?

first-pipeline.conf

> ```
> input {
> beats {
> port => "5044"
> }
> }
> # The filter part of this file is commented out to indicate that it is
> # optional.
> # filter {
> #
> # }
> output {
> stdout { codec => rubydebug }
> }
> 
> ```

filebeat.yml -\> I added the logging at path: /usr/local/var/log/filebeat

#================================ Logging =====================================

# Sets log level. The default log level is info.

# Available log levels are: error, warning, info, debug

#logging.level: debug

# At debug level, you can selectively enable logging only for some components.

# To enable all selectors use ["\*"]. Examples of other selectors are "beat",

# "publish", "service".

#logging.selectors: ["\*"]  
logging.level: info  
logging.to\_files: true  
logging.files:  
path: /usr/local/var/log/filebeat  
name: filebeat  
keepfiles: 7  
permissions: 0644

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2018, 6:52am UTC](https://discuss.elastic.co/t/service-seem-to-hang/134755/6 "2018-07-06T06:52:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
