# Stopping logstash

**URL:** <https://discuss.elastic.co/t/stopping-logstash/336586>\
**Category:** Logstash\
**Created:** [June 21, 2023, 1:17pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586 "2023-06-21T13:17:06Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [June 21, 2023, 1:17pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586/1 "2023-06-21T13:17:06Z")

</div>

Hello, i'm currently working on logstash and i have a question. To launch my logtash script, i use this command:

```auto
sudo /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/test.conf 

```

When I run it in my terminal, to stop logstash I have to press ctrl +C, which is quite annoying because I have to cronize my script so that it runs every day at a given time.

How can I do this?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 21, 2023, 1:19pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586/2 "2023-06-21T13:19:03Z")

</div>

What is your input?

The easiest way is to run Logstash as a [service](https://www.elastic.co/guide/en/logstash/current/running-logstash.html#running-logstash-systemd), so it will always be running or you can start and stop it using systemd.

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [June 26, 2023, 8:11am UTC](https://discuss.elastic.co/t/stopping-logstash/336586/3 "2023-06-26T08:11:18Z")

</div>

How can I do it?

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [June 26, 2023, 8:36am UTC](https://discuss.elastic.co/t/stopping-logstash/336586/4 "2023-06-26T08:36:29Z")

</div>

When I run this command :

```auto
sudo systemctl status logstash

```

I have this output :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0ab844e13ad847cc16a0834088a0394e4fceb4b3.png)

So it seems that logstash is already running as a service.

But when data are ingest in my repository logstash doesn't send them automatically into elasticsearch

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [June 26, 2023, 8:51am UTC](https://discuss.elastic.co/t/stopping-logstash/336586/5 "2023-06-26T08:51:00Z")

</div>

You have installed LS from the DEB or RPM installation which by default creates the service.

1. Show us test.conf
2. Add `log.level: debug` in logstash.yml
3. Show us the log: logstash-plain.log

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 26, 2023, 11:38am UTC](https://discuss.elastic.co/t/stopping-logstash/336586/6 "2023-06-26T11:38:30Z")

</div>

> [@Hanni](#):
>
> But when data are ingest in my repository logstash doesn't send them automatically into elasticsearch

You need to share your `test.conf` file to show what logstash is doing.

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [June 26, 2023, 1:04pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586/7 "2023-06-26T13:04:23Z")

</div>

Here it is

```auto
input {
  file {
    path => "/testELK/*.csv"
    start_position => "beginning"
    sincedb_path => "/dev/null"
  }
}

filter {
  csv {
    separator => ","
    skip_header => "true"
    skip_empty_rows => true
    columns => [
      "Plugin_ID",
      "CVE",
      "CVSS_v2.0_Base_Score",
      "Risk",
      "Host",
      "Protocol",
      "Port",
      "Name",
      "CVSS_v3.0_Base_Score",
      "CVSS_v2.0_Temporal_Score",
      "CVSS_v3.0_Temporal_Score",
      "Risk_Factor",
      "Metasploit"
    ]
  }
}

output {
  elasticsearch {
    hosts => " ******* :9200"
    index => "index"
    template_name => "template"
  }

  stdout {}
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 26, 2023, 1:06pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586/8 "2023-06-26T13:06:24Z")

</div>

> [@Hanni](#):
>
> `/testELK/`

Does the logstash user have permissions to read the files on this path?

When Logstash runs as a service it runs as the `logstash` user.

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [June 26, 2023, 1:07pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586/9 "2023-06-26T13:07:51Z")

</div>

I have one more question:

Every day I receive csvs in a directory. logstash ingests them into elasticsearch. How do I tell it that after integrating a csv into elasticsearch, it moves to another directory or simply that it doesn't ingest the same file that it already ingested the day before?

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [June 26, 2023, 1:09pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586/10 "2023-06-26T13:09:08Z")

</div>

yes because I applied chmod 777 to my file

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 26, 2023, 1:24pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586/11 "2023-06-26T13:24:47Z")

</div>

> [@Hanni](#):
>
> How do I tell it that after integrating a csv into elasticsearch, it moves to another directory

Logstash cannot move files, only delete, but it needs to use the `file` input with the `mode` set as `read`.

Per default it will use the `mode` as `tail`, which will constantly look for changes in the files, if the files in the directory are not being constantly updated, then you could change the mode to `read` and configure logstash to delete the files.

Check the [documentiaton](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html) for more information about it.

> [@Hanni](#):
>
> or simply that it doesn't ingest the same file that it already ingested the day before?

This is done by the `sincedb_path` configuration, since you set it to `/dev/null` you are telling logstash to reprocess everything. If you want it to not process files that it already read you need to point the `sincedb_path` to a custom file or just remove this setting and logstash will create a sincedb file per default.

> [@Hanni](#):
>
> yes because I applied chmod 777 to my file

Yeah, but this doesn't matter if the `logstash` user cannot access the path, the logstash user needs to have permissions on the path as well, does it?

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [June 27, 2023, 8:59am UTC](https://discuss.elastic.co/t/stopping-logstash/336586/12 "2023-06-27T08:59:01Z")

</div>

So, if I understand your point of view correctly, I should remove this parameter. : **sincedb\_path =\> "/dev/null"**

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [June 27, 2023, 10:53am UTC](https://discuss.elastic.co/t/stopping-logstash/336586/13 "2023-06-27T10:53:47Z")

</div>

sincedb\_path =\> "/dev/null" is used for in-memory tracking of file processing.

As Leandro said, you can remove/comment than will [LS used default settings](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-sincedb_path) and keep processed records in a file or set by your own path/file.

In short, if you want to keep the file tracking, just do not use null, remove the line.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 27, 2023, 1:06pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586/15 "2023-06-27T13:06:11Z")

</div>

> [@wicckkjoe](#):
>
> How do I tell it that after integrating a csv into elasticsearch, it moves to another directory or simply that it doesn't ingest the same file that it already ingested the day before?

Hello, this was alread answered in this topic, please check previous answers.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2023, 1:06pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586/16 "2023-07-25T13:06:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
