# WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash

**URL:** <https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022>\
**Category:** Logstash\
**Created:** [May 8, 2018, 2:03pm UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022 "2018-05-08T14:03:32Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![sayed\_mohamed](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Post date:** [May 8, 2018, 2:03pm UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/1 "2018-05-08T14:03:32Z")

</div>

i have a problem that i run file as command : sudo bin/logstash --path.data sensor38 -f /home/sayed/logstash/sayed.conf  
and i have an warning that i set some configuration on it  
WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console  
so i need help and i did every thing that related this topic but no vain

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 8, 2018, 7:44pm UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/2 "2018-05-08T19:44:04Z")

</div>

Did you try using the `--path.settings` option to point to the directory where logstash.yml resides? If you run an RPM- or Debian-based distribution I recommend you use the packages instead of downloading the tarball (which seems to be what you've done).

---

<div class="post-metadata">

**Author:** ![sayed\_mohamed](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Post date:** [May 9, 2018, 7:50am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/3 "2018-05-09T07:50:17Z")

</div>

yes . i used it and i got this error ERROR: Unrecognised option '--path.settings.'

---

<div class="post-metadata">

**Author:** ![MrNerd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrnerd/32/30763_2.png) [@MrNerd](https://discuss.elastic.co/u/MrNerd)\
**Post date:** [May 9, 2018, 8:11am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/4 "2018-05-09T08:11:47Z")

</div>

can you please post the command you use and the error please when you use `-path.settings`?

---

<div class="post-metadata">

**Author:** ![sayed\_mohamed](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Post date:** [May 9, 2018, 8:14am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/5 "2018-05-09T08:14:28Z")

</div>

WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
ERROR: Unrecognised option '--path.settings.'

See: 'bin/logstash --help'  
[ERROR] 2018-05-09 09:48:58.104 [main] Logstash - java.lang.IllegalStateException: org.jruby.exceptions.RaiseException: (SystemExit) exit

---

<div class="post-metadata">

**Author:** ![MrNerd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrnerd/32/30763_2.png) [@MrNerd](https://discuss.elastic.co/u/MrNerd)\
**Post date:** [May 9, 2018, 8:16am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/6 "2018-05-09T08:16:40Z")

</div>

and the **COMMAND** you used?

---

<div class="post-metadata">

**Author:** ![sayed\_mohamed](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Post date:** [May 9, 2018, 8:17am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/7 "2018-05-09T08:17:20Z")

</div>

sudo bin/logstash --path.settings. /etc/logstash --path.data sensor39 -f /home/sayed/logstash/sayed.conf

---

<div class="post-metadata">

**Author:** ![MrNerd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrnerd/32/30763_2.png) [@MrNerd](https://discuss.elastic.co/u/MrNerd)\
**Post date:** [May 9, 2018, 8:17am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/8 "2018-05-09T08:17:56Z")

</div>

try with this

> sudo bin/logstash --path.settings /etc/logstash/ --path.data sensor39 -f /home/sayed/logstash/sayed.conf

---

<div class="post-metadata">

**Author:** ![sayed\_mohamed](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Post date:** [May 9, 2018, 8:19am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/9 "2018-05-09T08:19:57Z")

</div>

i get  
ERROR: Failed to parse YAML file "/etc/logstash/logstash.yml". Please confirm if the YAML structure is valid (e.g. look for incorrect usage of whitespace or indentation). Aborting... parser\_error=\>(): expected , but found BlockMappingStart while parsing a block mapping at line 41 column 2  
[ERROR] 2018-05-09 10:19:32.813 [main] Logstash - java.lang.IllegalStateException: org.jruby.exceptions.RaiseException: (SystemExit) exit

---

<div class="post-metadata">

**Author:** ![MrNerd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrnerd/32/30763_2.png) [@MrNerd](https://discuss.elastic.co/u/MrNerd)\
**Post date:** [May 9, 2018, 8:26am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/10 "2018-05-09T08:26:25Z")

</div>

Show me your **logstash.yml** configuration. I have to say that imnot an expert so i will do my best 😕

---

<div class="post-metadata">

**Author:** ![sayed\_mohamed](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Post date:** [May 9, 2018, 8:31am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/11 "2018-05-09T08:31:06Z")

</div>

# Settings file in YAML

# 

# Settings can be specified either in hierarchical form, e.g.:

# 

# pipeline:

# batch:

# size: 500

# delay: 5

# 

# Or as flat keys:

# 

# pipeline.batch.size: 500

# pipeline.batch.delay: 5

# 

# ------------ Node identity ------------

# 

# Use a descriptive name for the node:

# 

# node.name: test

# 

# If omitted the node name will default to the machine's host name

# 

# ------------ Data path ------------------

# 

# Which directory should be used by logstash and its plugins

# for any persistent needs. Defaults to LOGSTASH\_HOME/data

# 

path.data: /var/lib/logstash

# 

# ------------ Pipeline Settings --------------

# 

# The ID of the pipeline.

# 

# pipeline.id: main

# 

# Set the number of workers that will, in parallel, execute the filters+outputs

# stage of the pipeline.

# 

# This defaults to the number of the host's CPU cores.

# 

pipeline.workers: 10

# 

# How many events to retrieve from inputs before sending to filters+workers

# 

# pipeline.batch.size: 125

# 

# How long to wait in milliseconds while polling for the next event

# before dispatching an undersized batch to filters+outputs

# 

# pipeline.batch.delay: 50

# 

# Force Logstash to exit during shutdown even if there are still inflight

# events in memory. By default, logstash will refuse to quit until all

# received events have been pushed to the outputs.

# 

# WARNING: enabling this can lead to data loss during shutdown

# 

# pipeline.unsafe\_shutdown: false

# 

# ------------ Pipeline Configuration Settings --------------

# 

# Where to fetch the pipeline configuration for the main pipeline

# 

# path.config:

# 

# Pipeline configuration string for the main pipeline

# 

# config.string:

# 

# At startup, test if the configuration is valid and exit (dry run)

# 

# config.test\_and\_exit: false

# 

# Periodically check if the configuration has changed and reload the pipeline

# This can also be triggered manually through the SIGHUP signal

# 

# config.reload.automatic: false

# 

# How often to check if the pipeline configuration has changed (in seconds)

# 

# config.reload.interval: 3s

# 

# Show fully compiled configuration as debug log message

# NOTE: --log.level must be 'debug'

# 

# config.debug: false

# 

# When enabled, process escaped characters such as \n and " in strings in the

# pipeline configuration files.

# 

# config.support\_escapes: false

# 

# ------------ Module Settings ---------------

# Define modules here. Modules definitions must be defined as an array.

# The simple way to see this is to prepend each `name` with a `-`, and keep

# all associated variables under the `name` they are associated with, and

# above the next, like this:

# 

# modules:

# - name: MODULE\_NAME

# var.PLUGINTYPE1.PLUGINNAME1.KEY1: VALUE

# var.PLUGINTYPE1.PLUGINNAME1.KEY2: VALUE

# var.PLUGINTYPE2.PLUGINNAME1.KEY1: VALUE

# var.PLUGINTYPE3.PLUGINNAME3.KEY1: VALUE

# 

# Module variable names must be in the format of

# 

# var.PLUGIN\_TYPE.PLUGIN\_NAME.KEY

# 

# modules:

# 

# ------------ Cloud Settings ---------------

# Define Elastic Cloud settings here.

# Format of cloud.id is a base64 value e.g. dXMtZWFzdC0xLmF3cy5mb3VuZC5pbyRub3RhcmVhbCRpZGVudGlmaWVy

# and it may have an label prefix e.g. staging:dXMtZ...

# This will overwrite 'var.elasticsearch.hosts' and 'var.kibana.host'

# cloud.id:

# 

# Format of cloud.auth is: :

# This is optional

# If supplied this will overwrite 'var.elasticsearch.username' and 'var.elasticsearch.password'

# If supplied this will overwrite 'var.kibana.username' and 'var.kibana.password'

# cloud.auth: elastic:

# 

# ------------ Queuing Settings --------------

# 

# Internal queuing model, "memory" for legacy in-memory based queuing and

# "persisted" for disk-based acked queueing. Defaults is memory

# 

# queue.type: memory

# 

# If using queue.type: persisted, the directory path where the data files will be stored.

# Default is path.data/queue

# 

# path.queue:

# 

# If using queue.type: persisted, the page data files size. The queue data consists of

# append-only data files separated into pages. Default is 64mb

# 

# queue.page\_capacity: 2gb

# 

# If using queue.type: persisted, the maximum number of unread events in the queue.

# Default is 0 (unlimited)

# 

# queue.max\_events: 0

# 

# If using queue.type: persisted, the total capacity of the queue in number of bytes.

# If you would like more unacked events to be buffered in Logstash, you can increase the

# capacity using this setting. Please make sure your disk drive has capacity greater than

# the size specified here. If both max\_bytes and max\_events are specified, Logstash will pick

# whichever criteria is reached first

# Default is 1024mb or 1gb

# 

# queue.max\_bytes: 150gb

# 

# If using queue.type: persisted, the maximum number of acked events before forcing a checkpoint

# Default is 1024, 0 for unlimited

# 

# queue.checkpoint.acks: 1024

# 

# If using queue.type: persisted, the maximum number of written events before forcing a checkpoint

# Default is 1024, 0 for unlimited

# 

# queue.checkpoint.writes: 1024

# 

# If using queue.type: persisted, the interval in milliseconds when a checkpoint is forced on the head page

# Default is 1000, 0 for no periodic checkpoint.

# 

# queue.checkpoint.interval: 1000

# 

# ------------ Dead-Letter Queue Settings --------------

# Flag to turn on dead-letter queue.

# 

# dead\_letter\_queue.enable: false

# If using dead\_letter\_queue.enable: true, the maximum size of each dead letter queue. Entries

# will be dropped if they would increase the size of the dead letter queue beyond this setting.

# Default is 1024mb

# dead\_letter\_queue.max\_bytes: 1024mb

# If using dead\_letter\_queue.enable: true, the directory path where the data files will be stored.

# Default is path.data/dead\_letter\_queue

# 

# path.dead\_letter\_queue:

# 

# ------------ Metrics Settings --------------

# 

# Bind address for the metrics REST endpoint

# 

# http.host: "127.0.0.1"

# 

# Bind port for the metrics REST endpoint, this option also accept a range

# (9600-9700) and logstash will pick up the first available ports.

# 

# http.port: 9600-9700

# 

# ------------ Debugging Settings --------------

# 

# Options for log.level:

# \* fatal

# \* error

# \* warn

# \* info (default)

# \* debug

# \* trace

# 

# log.level: info

path.logs: /var/log/logstash

# 

# ------------ Other Settings --------------

# 

# Where to find custom plugins

# path.plugins: []

---

<div class="post-metadata">

**Author:** ![MrNerd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrnerd/32/30763_2.png) [@MrNerd](https://discuss.elastic.co/u/MrNerd)\
**Post date:** [May 9, 2018, 8:47am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/12 "2018-05-09T08:47:45Z")

</div>

Can you do this and then try to use the command again?

> **service logstash stop  
> service logstash start  
> service logstash status -l**

And this:

> **systemctl stop logstash.service  
> systemctl start logstash.service  
> systemctl status logstash.service -l**

`If it shows any error while you do the status command post it here` 😛

---

<div class="post-metadata">

**Author:** ![MrNerd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrnerd/32/30763_2.png) [@MrNerd](https://discuss.elastic.co/u/MrNerd)\
**Post date:** [May 9, 2018, 8:56am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/13 "2018-05-09T08:56:01Z")

</div>

Or you can just comment this part, and work with the defaults settings; is that ok?

> ------------ Pipeline Settings --------------  
> The ID of the pipeline.  
> pipeline.id: main  
> Set the number of workers that will, in parallel, execute the filters+outputs  
> stage of the pipeline.  
> This defaults to the number of the host's CPU cores.  
> `###pipeline.workers: 10###` \<-- **[THIS ONE]**  
> How many events to retrieve from inputs before sending to filters+workers  
> pipeline.batch.size: 125

---

<div class="post-metadata">

**Author:** ![sayed\_mohamed](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Post date:** [May 9, 2018, 8:58am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/14 "2018-05-09T08:58:14Z")

</div>

but commands that i have run before i got this

WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console

---

<div class="post-metadata">

**Author:** ![MrNerd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrnerd/32/30763_2.png) [@MrNerd](https://discuss.elastic.co/u/MrNerd)\
**Post date:** [May 9, 2018, 9:02am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/15 "2018-05-09T09:02:16Z")

</div>

the problem there is that when you used the coomand you left this: [/] and you have to delete the [.] of the path settings in your command.

> sudo bin/logstash --path.settings. /etc/logstash --path.data sensor39 -f /home/sayed/logstash/sayed.conf

it's not like that.

it's like this:

> sudo bin/logstash --path.settings /etc/logstash/ --path.data sensor39 -f /home/sayed/logstash/sayed.conf

And please post the /etc/logstash/log4j2 configuration

---

<div class="post-metadata">

**Author:** ![sayed\_mohamed](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Post date:** [May 9, 2018, 9:03am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/16 "2018-05-09T09:03:36Z")

</div>

i have already run last command not first  
ok i'll post that

---

<div class="post-metadata">

**Author:** ![sayed\_mohamed](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Post date:** [May 9, 2018, 9:04am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/17 "2018-05-09T09:04:22Z")

</div>

status = error  
name = LogstashPropertiesConfig

appender.rolling.type = RollingFile  
appender.rolling.name = plain\_rolling  
appender.rolling.fileName = ${sys:ls.logs}/logstash-${sys:ls.log.format}.log  
appender.rolling.filePattern = ${sys:ls.logs}/logstash-${sys:ls.log.format}-%d{yyyy-MM-dd}.log  
appender.rolling.policies.type = Policies  
appender.rolling.policies.time.type = TimeBasedTriggeringPolicy  
appender.rolling.policies.time.interval = 1  
appender.rolling.policies.time.modulate = true  
appender.rolling.layout.type = PatternLayout  
appender.rolling.layout.pattern = [%d{ISO8601}][%-5p][%-25c] %-.10000m%n

appender.json\_rolling.type = RollingFile  
appender.json\_rolling.name = json\_rolling  
appender.json\_rolling.fileName = ${sys:ls.logs}/logstash-${sys:ls.log.format}.log  
appender.json\_rolling.filePattern = ${sys:ls.logs}/logstash-${sys:ls.log.format}-%d{yyyy-MM-dd}.log  
appender.json\_rolling.policies.type = Policies  
appender.json\_rolling.policies.time.type = TimeBasedTriggeringPolicy  
appender.json\_rolling.policies.time.interval = 1  
appender.json\_rolling.policies.time.modulate = true  
appender.json\_rolling.layout.type = JSONLayout  
appender.json\_rolling.layout.compact = true  
appender.json\_rolling.layout.eventEol = true

rootLogger.level = ${sys:ls.log.level}  
rootLogger.appenderRef.rolling.ref = ${sys:ls.log.format}\_rolling

---

<div class="post-metadata">

**Author:** ![sayed\_mohamed](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Post date:** [May 9, 2018, 9:06am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/18 "2018-05-09T09:06:22Z")

</div>

when i run this command : sudo bin/logstash --path.settings /etc/logstash/ --path.data sensor39 -f /home/sayed/logstash/sayed.conf

i still get this : ERROR: Failed to parse YAML file "/etc/logstash/logstash.yml". Please confirm if the YAML structure is valid (e.g. look for incorrect usage of whitespace or indentation). Aborting... parser\_error=\>(): expected , but found BlockMappingStart while parsing a block mapping at line 41 column 2  
[ERROR] 2018-05-09 11:05:17.264 [main] Logstash - java.lang.IllegalStateException: org.jruby.exceptions.RaiseException: (SystemExit) exit

---

<div class="post-metadata">

**Author:** ![MrNerd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrnerd/32/30763_2.png) [@MrNerd](https://discuss.elastic.co/u/MrNerd)\
**Post date:** [May 9, 2018, 9:18am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/19 "2018-05-09T09:18:50Z")

</div>

I don't know what happends there; maybe @magnusbaeck or @Christian_Dahlqvist help you I don't know much about that, sorry @sayed_mohamed

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 9, 2018, 11:00am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022/20 "2018-05-09T11:00:28Z")

</div>

> ERROR: Failed to parse YAML file "/etc/logstash/logstash.yml". Please confirm if the YAML structure is valid (e.g. look for incorrect usage of whitespace or indentation). Aborting... parser\_error=\>(): expected , but found BlockMappingStart while parsing a block mapping at line 41 column 2

Clearly there's a problem with your logstash.yml, probably in the vicinity of line 41. Post the file again **and format it as preformatted text using markdown syntax or the `</>` toolbar button**.

[Next page](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022.md?page=2)
