- Logstash Reference: other versions:
- Logstash Introduction
- Getting Started with Logstash
- How Logstash Works
- Setting Up and Running Logstash
- Logstash Directory Layout
- Logstash Configuration Files
- logstash.yml
- Secrets keystore for secure settings
- Running Logstash from the Command Line
- Running Logstash as a Service on Debian or RPM
- Running Logstash on Docker
- Configuring Logstash for Docker
- Running Logstash on Kubernetes
- Running Logstash on Windows
- Logging
- Shutting Down Logstash
- Upgrading Logstash
- Creating a Logstash pipeline
- Secure your connection
- Advanced Logstash Configurations
- Logstash-to-Logstash communication
- Managing Logstash
- Using Logstash with Elastic Integrations
- Working with Logstash Modules
- Working with Filebeat Modules
- Working with Winlogbeat Modules
- Queues and data resiliency
- Transforming Data
- Deploying and Scaling Logstash
- Managing GeoIP Databases
- Performance tuning
- Monitoring Logstash with Elastic Agent
- Monitoring Logstash (legacy)
- Monitoring Logstash with APIs
- Working with plugins
- Integration plugins
- Input plugins
- azure_event_hubs
- beats
- cloudwatch
- couchdb_changes
- dead_letter_queue
- elastic_agent
- elastic_serverless_forwarder
- elasticsearch
- exec
- file
- ganglia
- gelf
- generator
- github
- google_cloud_storage
- google_pubsub
- graphite
- heartbeat
- http
- http_poller
- imap
- irc
- java_generator
- java_stdin
- jdbc
- jms
- jmx
- kafka
- kinesis
- logstash
- log4j
- lumberjack
- meetup
- pipe
- puppet_facter
- rabbitmq
- redis
- relp
- rss
- s3
- s3-sns-sqs
- salesforce
- snmp
- snmptrap
- sqlite
- sqs
- stdin
- stomp
- syslog
- tcp
- udp
- unix
- varnishlog
- websocket
- wmi
- xmpp
- Output plugins
- boundary
- circonus
- cloudwatch
- csv
- datadog
- datadog_metrics
- dynatrace
- elastic_app_search
- elastic_workplace_search
- elasticsearch
- exec
- file
- ganglia
- gelf
- google_bigquery
- google_cloud_storage
- google_pubsub
- graphite
- graphtastic
- http
- influxdb
- irc
- java_stdout
- juggernaut
- kafka
- librato
- logstash
- loggly
- lumberjack
- metriccatcher
- mongodb
- nagios
- nagios_nsca
- opentsdb
- pagerduty
- pipe
- rabbitmq
- redis
- redmine
- riak
- riemann
- s3
- sink
- sns
- solr_http
- sqs
- statsd
- stdout
- stomp
- syslog
- tcp
- timber
- udp
- webhdfs
- websocket
- xmpp
- zabbix
- Filter plugins
- age
- aggregate
- alter
- bytes
- cidr
- cipher
- clone
- csv
- date
- de_dot
- dissect
- dns
- drop
- elapsed
- elastic_integration
- elasticsearch
- environment
- extractnumbers
- fingerprint
- geoip
- grok
- http
- i18n
- java_uuid
- jdbc_static
- jdbc_streaming
- json
- json_encode
- kv
- memcached
- metricize
- metrics
- mutate
- prune
- range
- ruby
- sleep
- split
- syslog_pri
- threats_classifier
- throttle
- tld
- translate
- truncate
- urldecode
- useragent
- uuid
- wurfl_device_detection
- xml
- Codec plugins
- Tips and best practices
- Troubleshooting
- Contributing to Logstash
- How to write a Logstash input plugin
- How to write a Logstash codec plugin
- How to write a Logstash filter plugin
- How to write a Logstash output plugin
- Logstash Plugins Community Maintainer Guide
- Document your plugin
- Publish your plugin to RubyGems.org
- List your plugin
- Contributing a patch to a Logstash plugin
- Extending Logstash core
- Contributing a Java Plugin
- Breaking changes
- Release Notes
- Logstash 8.17.1 Release Notes
- Logstash 8.17.0 Release Notes
- Logstash 8.16.3 Release Notes
- Logstash 8.16.2 Release Notes
- Logstash 8.16.1 Release Notes
- Logstash 8.16.0 Release Notes
- Logstash 8.15.5 Release Notes
- Logstash 8.15.4 Release Notes
- Logstash 8.15.3 Release Notes
- Logstash 8.15.2 Release Notes
- Logstash 8.15.1 Release Notes
- Logstash 8.15.0 Release Notes
- Logstash 8.14.3 Release Notes
- Logstash 8.14.2 Release Notes
- Logstash 8.14.1 Release Notes
- Logstash 8.14.0 Release Notes
- Logstash 8.13.4 Release Notes
- Logstash 8.13.3 Release Notes
- Logstash 8.13.2 Release Notes
- Logstash 8.13.1 Release Notes
- Logstash 8.13.0 Release Notes
- Logstash 8.12.2 Release Notes
- Logstash 8.12.1 Release Notes
- Logstash 8.12.0 Release Notes
- Logstash 8.11.4 Release Notes
- Logstash 8.11.3 Release Notes
- Logstash 8.11.2 Release Notes
- Logstash 8.11.1 Release Notes
- Logstash 8.11.0 Release Notes
- Logstash 8.10.4 Release Notes
- Logstash 8.10.3 Release Notes
- Logstash 8.10.2 Release Notes
- Logstash 8.10.1 Release Notes
- Logstash 8.10.0 Release Notes
- Logstash 8.9.2 Release Notes
- Logstash 8.9.1 Release Notes
- Logstash 8.9.0 Release Notes
- Logstash 8.8.2 Release Notes
- Logstash 8.8.1 Release Notes
- Logstash 8.8.0 Release Notes
- Logstash 8.7.1 Release Notes
- Logstash 8.7.0 Release Notes
- Logstash 8.6.2 Release Notes
- Logstash 8.6.1 Release Notes
- Logstash 8.6.0 Release Notes
- Logstash 8.5.3 Release Notes
- Logstash 8.5.2 Release Notes
- Logstash 8.5.1 Release Notes
- Logstash 8.5.0 Release Notes
- Logstash 8.4.2 Release Notes
- Logstash 8.4.1 Release Notes
- Logstash 8.4.0 Release Notes
- Logstash 8.3.3 Release Notes
- Logstash 8.3.2 Release Notes
- Logstash 8.3.1 Release Notes
- Logstash 8.3.0 Release Notes
- Logstash 8.2.3 Release Notes
- Logstash 8.2.2 Release Notes
- Logstash 8.2.1 Release Notes
- Logstash 8.2.0 Release Notes
- Logstash 8.1.3 Release Notes
- Logstash 8.1.2 Release Notes
- Logstash 8.1.1 Release Notes
- Logstash 8.1.0 Release Notes
- Logstash 8.0.1 Release Notes
- Logstash 8.0.0 Release Notes
- Logstash 8.0.0-rc2 Release Notes
- Logstash 8.0.0-rc1 Release Notes
- Logstash 8.0.0-beta1 Release Notes
- Logstash 8.0.0-alpha2 Release Notes
- Logstash 8.0.0-alpha1 Release Notes
Running Logstash on Windows
editRunning Logstash on Windows
editBefore reading this section, see Installing Logstash to get started. You also need to be familiar with Running Logstash from the Command Line as command line options are used to test running Logstash on Windows.
Specifying command line options is useful when you are testing Logstash. However, in a production environment, we recommend that you use logstash.yml to control Logstash execution. Using the settings file makes it easier for you to specify multiple options, and it provides you with a single, versionable file that you can use to start up Logstash consistently for each run.
Logstash is not started automatically after installation. How to start and stop Logstash on Windows depends on whether you want to run it manually, as a service (with NSSM), or run it as a scheduled task. This guide provides an example of some of the ways Logstash can run on Windows.
It is recommended to validate your configuration works by running Logstash manually before running Logstash as a service or a scheduled task.
Validating JVM prerequisites on Windows
editAfter installing a supported JVM, open a PowerShell session and run the following commands to verify LS_JAVA_HOME
is set and the Java version:
Write-Host $env:LS_JAVA_HOME
edit-
The output should be pointed to where the JVM software is located, for example:
PS C:\> Write-Host $env:LS_JAVA_HOME C:\Program Files\Java\jdk-11.0.3
-
If
LS_JAVA_HOME
is not set, perform one of the following:-
Set using the GUI:
- Navigate to the Windows Environmental Variables window
-
In the Environmental Variables window, edit LS_JAVA_HOME to point to where the JDK software is located, for example:
C:\Program Files\Java\jdk-11.0.3
-
Set using PowerShell:
-
In an Administrative PowerShell session, execute the following SETX commands:
PS C:\Windows\system32> SETX /m LS_JAVA_HOME "C:\Program Files\Java\jdk-11.0.3" PS C:\Windows\system32> SETX /m PATH "$env:PATH;C:\Program Files\Java\jdk-11.0.3\bin;"
-
Exit PowerShell, then open a new PowerShell session and run
Write-Host $env:LS_JAVA_HOME
to verify
-
-
Java -version
edit-
This command produces output similar to the following:
PS C:\> Java -version java version "11.0.3" 2019-04-16 LTS Java(TM) SE Runtime Environment 18.9 (build 11.0.3+12-LTS) Java HotSpot(TM) 64-Bit Server VM 18.9 (build 11.0.3+12-LTS, mixed mode)
As of the publication of this document, please review this known issue that impacts Java 11 before proceeding.
Once you have Setting Up and Running Logstash and validated JVM pre-requisites, you may proceed.
For the examples listed below, we are running Windows Server 2016, Java 11.0.3,
have extracted the Logstash ZIP
package to C:\logstash-8.17.1\
, and using the example
syslog.conf
file shown below (stored in
C:\logstash-8.17.1\config\
).
Running Logstash manually
editLogstash can be run manually using PowerShell. Open an Administrative PowerShell session, then run the following commands:
PS C:\Windows\system32> cd C:\logstash-8.17.1\ PS C:\logstash-8.17.1> .\bin\logstash.bat -f .\config\syslog.conf
In a production environment, we recommend that you use logstash.yml to control Logstash execution.
Wait for the following messages to appear, to confirm Logstash has started successfully:
[logstash.runner ] Starting Logstash {"logstash.version"=>"8.17.1"} [logstash.inputs.udp ] Starting UDP listener {:address=>"0.0.0.0:514"} [logstash.agent ] Successfully started Logstash API endpoint {:port=>9600}
Running Logstash as a service with NSSM
editIt is recommended to validate your configuration works by running Logstash manually before you proceed.
Download NSSM, then extract nssm.exe
from
nssm-<version.number>\win64\nssm.exe
to C:\logstash-8.17.1\bin\
.
Then open an Administrative
PowerShell session, then run the
following commands:
PS C:\Windows\system32> cd C:\logstash-8.17.1\ PS C:\logstash-8.17.1> .\bin\nssm.exe install logstash
Once the NSSM service installer
window appears, specify the following parameters in the Application
tab:
-
In the
Application
tab:-
Path: Path to
logstash.bat
:C:\logstash-8.17.1\bin\logstash.bat
-
Startup Directory: Path to the
bin
directory:C:\logstash-8.17.1\bin
-
Arguments: For this example to start Logstash:
-f C:\logstash-8.17.1\config\syslog.conf
In a production environment, we recommend that you use logstash.yml to control Logstash execution.
-
Path: Path to
-
Review and make any changes necessary in the
Details
tab:-
Ensure
Startup Type
is set appropriately -
Set the
Display name
andDescription
fields to something relevant
-
Ensure
-
Review any other required settings (for the example we aren’t making any other changes)
-
Be sure to determine if you need to set the
Log on
user
-
Be sure to determine if you need to set the
-
Validate the
Service name
is set appropriately-
For this example, we will set ours to
logstash-syslog
-
For this example, we will set ours to
-
Click
Install Service
-
Click OK when the
Service "logstash-syslog" installed successfully!
window appears
-
Click OK when the
Once the service has been installed with NSSM, validate and start the service following the PowerShell Managing Services documentation.
Running Logstash with Task Scheduler
editIt is recommended to validate your configuration works by running Logstash manually before you proceed.
Open the Windows Task Scheduler, then click Create Task
in the Actions window. Specify the following parameters in the Actions
tab:
-
In the
Actions
tab:-
Click
New
, then specify the following: -
Action:
Start a program
-
Program/script:
C:\logstash-8.17.1\bin\logstash.bat
-
Add arguments:
-f C:\logstash-8.17.1\config\syslog.conf
-
Start in:
C:\logstash-8.17.1\bin\
In a production environment, we recommend that you use logstash.yml to control Logstash execution.
-
Click
-
Review and make any changes necessary in the
General
,Triggers
,Conditions
, andSettings
tabs. -
Click
OK
to finish creating the scheduled task. -
Once the new task has been created, either wait for it to run on the schedule or select the service then click
Run
to start the task.
Logstash can be stopped by selecting the service, then clicking End
in the Task Scheduler window.
Example Logstash Configuration
editWe will configure Logstash to listen for syslog messages over port 514 with this configuration (file name is syslog.conf
):
# Sample Logstash configuration for receiving # UDP syslog messages over port 514 input { udp { port => 514 type => "syslog" } } output { elasticsearch { hosts => ["localhost:9200"] } stdout { codec => rubydebug } }
On this page