# Why logstash does not start?

**URL:** <https://discuss.elastic.co/t/why-logstash-does-not-start/233453>\
**Category:** Logstash\
**Created:** [May 20, 2020, 4:41am UTC](https://discuss.elastic.co/t/why-logstash-does-not-start/233453 "2020-05-20T04:41:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![H\_EO](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/h_eo/32/46843_2.png) [@H\_EO](https://discuss.elastic.co/u/H_EO)\
**Post date:** [May 20, 2020, 4:41am UTC](https://discuss.elastic.co/t/why-logstash-does-not-start/233453/1 "2020-05-20T04:41:41Z")

</div>

\*error message :  
--path.settings. Continuing using the defaults  
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console  
[WARN] 2020-05-20 22:06:21.916 [LogStash::Runner] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[INFO] 2020-05-20 22:06:21.935 [LogStash::Runner] runner - Starting Logstash {"logstash.version"=\>"7.7.0"}  
[ERROR] 2020-05-20 22:06:24.665 [Converge PipelineAction::Create] agent - Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", "=\>" at line 8, column 8 (byte 118) after input {\n beats {\n port =\> 5044\n host =\> "192.168.200.167"\n sincedb\_path =\> "/dev/null"\n }\nfilter {\n grok ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:58:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:66:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:28:in `block in compile_sources'", "org/jruby/RubyArray.java:2577:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:27:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:181:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:67:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:43:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:342:in `block in converge\_state'"]}  
[INFO] 2020-05-20 22:06:25.279 [Api Webserver] agent - Successfully started Logstash API endpoint {:port=\>9600}  
[INFO] 2020-05-20 22:06:30.139 [LogStash::Runner] runner - Logstash shut down.

\*log example:  
2020-05-19T02:59:56.062564+09:00 127.0.0.1 [IPS-7514] [Attack\_Name=SQL Injection\_1], [Time=2020/05/19 02:59:49], [Hacker=0.0.0.0], [Victim=0.0.0.0], [Protocol=icmp/2048], [Risk=High], [Handling=Defence], [Information=], [SrcPort=0], [HackType=04100]

\*grok pattern:  
%{IP:host\_ip}\s+[%{DATA:host}]\s+[Attack\_Name=%{DATA:attack\_name}],\s+[Time=%{DATA:attack\_time}],\s+[Hacker=%{IP:src\_ip}],\s+[Victim=%{IP:dst\_ip}],\s+[Protocol=%{DATA:protocol}],\s+[Risk=%{WORD:risk}],\s+[Handling=%{DATA:handling}],\s+[Information=%{DATA:info}],\s+[SrcPort=%{INT:src\_port}],\s+[HackType=%{DATA:hack\_type}]

\*config file :  
input {  
beats {  
port =\> 5044  
host =\> "192.168.200.167"  
sincedb\_path =\> "/dev/null"  
}  
filter {  
grok {  
match =\> {"message" =\> "%{IP:host\_ip},\s+[%{DATA:host}],\s+[Attack\_Name=%{DATA:attack\_name}],\s+[Time=%{DATA:attack\_time}],\s+[Hacker=%{IP:src\_ip}],\s+[Victim=%{IP:dst\_ip}],\s+[Protocol=%{DATA:protocol}],\s+[Risk=%{WORD:risk}],\s+[Handling=%{DATA:handling}],\s+[Information=%{DATA:info}],\s+[SrcPort=%{INT:src\_port}],\s+[HackType=%{DATA:hack\_type}]"}  
}  
date{ match =\> ["attack\_time"= "YYYY/MM/DD HH:mm:SS"]  
target =\> "@timestamp"}  
}  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

OS = centos 7  
logstash version = 7.7  
es, kibana ver. = 7.7

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 20, 2020, 4:50am UTC](https://discuss.elastic.co/t/why-logstash-does-not-start/233453/2 "2020-05-20T04:50:12Z")

</div>

> [@H\_EO](#):
>
> input {  
> beats {  
> port =\> 5044  
> host =\> "192.168.200.167"  
> sincedb\_path =\> "/dev/null"  
> }

You need another closing bracket after that last one.

Also, please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2020, 4:50am UTC](https://discuss.elastic.co/t/why-logstash-does-not-start/233453/3 "2020-06-17T04:50:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
