# We are getting logstash 5.4 error

**URL:** https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360
**Category:** Logstash
**Created:** [June 6, 2017, 6:44am UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360 "2017-06-06T06:44:34Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![bvnages](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@bvnages](https://discuss.elastic.co/u/bvnages)
#### Post date: [June 6, 2017, 6:44am UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/1 "2017-06-06T06:44:34Z")

</div>

[2017-06-06T06:43:36,425][FATAL][logstash.runner] Logstash could not be started because there is already another instance using the configured data directory. If you wish to run multiple instances, you must change the "path.data" setting.

above error i will found in 5.4 only

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 8, 2017, 7:34pm UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/2 "2017-06-08T19:34:05Z")

</div>

So... are you running multiple Logstash instances?

---

<div class="post-metadata">

### Author: ![bvnages](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@bvnages](https://discuss.elastic.co/u/bvnages)
#### Post date: [June 9, 2017, 5:21am UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/3 "2017-06-09T05:21:27Z")

</div>

Yes magnusbaeck

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 9, 2017, 5:23am UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/4 "2017-06-09T05:23:26Z")

</div>

Then pick a unique data directory for each instance. This can e.g. be set with the `--path.data` command line option.

---

<div class="post-metadata">

### Author: ![bvnages](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@bvnages](https://discuss.elastic.co/u/bvnages)
#### Post date: [June 9, 2017, 5:24am UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/5 "2017-06-09T05:24:57Z")

</div>

But earlier version we are not finding this error.

we are changing every time in logstash.yml file in path setting after instance is working.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 9, 2017, 7:42am UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/6 "2017-06-09T07:42:20Z")

</div>

> But earlier version we are not finding this error.

Well, it seems like that restriction was added in 5.4 then.

> we are changing every time in logstash.yml file in path setting after instance is working.

That's clearly not very sustainable (or convenient).

---

<div class="post-metadata">

### Author: ![medelastic](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@medelastic](https://discuss.elastic.co/u/medelastic)
#### Post date: [June 15, 2017, 9:36am UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/7 "2017-06-15T09:36:44Z")

</div>

"bin/logstash --path.settings /etc/logstash -f logstash-simple.conf"

logstash-simple.conf: Simple file in which I am taking input from keyboard and displaying it.

It was running fine earlier but sometimes it is giving following error:

"Logstash could not be started because there is already another instance using the configured data directory. If you wish to run multiple instances, you must change the "path.data" setting"

This is just a single instance then why this error is coming ?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 15, 2017, 1:01pm UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/8 "2017-06-15T13:01:01Z")

</div>

No other Logstash instances are running on the machine when you issue the command above?

---

<div class="post-metadata">

### Author: ![medelastic](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@medelastic](https://discuss.elastic.co/u/medelastic)
#### Post date: [June 15, 2017, 1:13pm UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/9 "2017-06-15T13:13:47Z")

</div>

No other instances are running

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 15, 2017, 1:45pm UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/10 "2017-06-15T13:45:27Z")

</div>

Do you have a .lock file in the directory pointed to by the path.data setting? Perhaps Logstash crashed for you so that the lockfile wasn't deleted.

---

<div class="post-metadata">

### Author: ![medelastic](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@medelastic](https://discuss.elastic.co/u/medelastic)
#### Post date: [June 16, 2017, 2:11am UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/11 "2017-06-16T02:11:09Z")

</div>

Yeah \*".lock file" \*is present there along withe _"queue"_ directory and  
_"uuid_" is there. What is the solution for this ?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 16, 2017, 5:13am UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/12 "2017-06-16T05:13:36Z")

</div>

If you have a .lock file but you've verified that no Logstash process is running you can delete the file. That should fix your problem.

---

<div class="post-metadata">

### Author: ![medelastic](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@medelastic](https://discuss.elastic.co/u/medelastic)
#### Post date: [June 16, 2017, 6:21am UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/13 "2017-06-16T06:21:28Z")

</div>

Yeah I am doing that .... But it is being create again then .... May be  
some other problem is there ... I will ask you if I am not being able to  
rectify it .... Thanx

---

<div class="post-metadata">

### Author: ![medelastic](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@medelastic](https://discuss.elastic.co/u/medelastic)
#### Post date: [June 16, 2017, 2:36pm UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/14 "2017-06-16T14:36:55Z")

</div>

input {

file {

```
path => "/tmp/access_log"

start_position => "beginning"

```

}

}

filter {

if [path] =~ "access" {

```
mutate { replace => { "type" => "apache_access" } }

grok {

  match => { "message" => "%{COMBINEDAPACHELOG}" }

}

```

}

date {

```
match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]

```

}

}

output {

elasticsearch { hosts =\> ["localhost:9200"]

user =\> elastic

password =\> changeme

index =\> "apache-access.log"

}

stdout { codec =\> rubydebug }

}

This is a demo script. This is working fine on visualising it in kibana  
following error is coming ... Any thoughts ?

- Index: apache-access.log Shard: 0 Reason:  
{"type":"illegal\_argument\_exception","reason":"Fielddata  
is disabled on text fields by default. Set fielddata=true on [timestamp] in  
order to load fielddata in memory by uninverting the inverted index. Note  
that this can however use significant memory. Alternatively use a keyword  
field instead."}

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 14, 2017, 2:37pm UTC](https://discuss.elastic.co/t/we-are-getting-logstash-5-4-error/88360/15 "2017-07-14T14:37:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
