# Archive index to gzip - cant decompressed

**URL:** <https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108>\
**Category:** Logstash\
**Created:** [December 10, 2018, 7:22am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108 "2018-12-10T07:22:58Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![bmatoki](https://avatars.discourse-cdn.com/v4/letter/b/7ea924/32.png) [@bmatoki](https://discuss.elastic.co/u/bmatoki)\
**Post date:** [December 10, 2018, 7:22am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/1 "2018-12-10T07:22:59Z")

</div>

Hey all.  
im trying to archive logs every 1hour to gzip - its working and saving every 1 hour to gzip.  
while im trying to decompressed it via node js \ linux \ gunzip \ cygnwin - got an error  
" Gzip outputting invalid compressed data "  
"gzip: logs-2018.12.10.07.log.tar.gz: invalid compressed data--format violated"  
i tried to cd into the gzip via cygnwin (linux) - i saw to json at invalid format.  
my logstash config is  
input {  
tcp {  
port =\> 5556  
}  
udp {  
port =\> 5566  
}  
}  
filter {  
csv {  
separator =\> ","  
columns =\> [ "os","host\_name","client\_time","full\_server\_time","process\_id","process\_name","process\_path","application\_name","protocol",  
"status","source\_port","destination\_port","direction","file\_path","x\_cast","state",  
"source\_ip","destination\_ip","sequance\_number","sub\_sequance\_number","user\_name","mog\_counter"  
,"destination\_path","reason","image\_path","image\_name","parent\_path","parent\_name","chain\_array"  
]  
}  
mutate {convert =\> ["process\_id","integer"]}  
mutate {convert =\> ["source\_port","integer"]}  
mutate {convert =\> ["destination\_port","integer"]}  
mutate {convert =\> ["sequance\_number","integer"]}  
mutate {convert =\> ["mog\_counter","integer"]}

```
}
output {
  elasticsearch {
    hosts => "localhost:9200"
    index => "logs-%{+YYYY.MM.dd}"
    template => "C:\Cyber20\loginsert\application\logstash_config\index_template.json"
    template_overwrite => "true"
      }
  file {
    path => "c:/cyber20/logarchiver/logs-%{+YYYY.MM.dd.HH}.gz"
    gzip => true
  }
}

```

I tried to read the gzip with input file , and gzip lines codec - nothing happened it read the config but cant see the logs.  
logstash-6.4.2  
ES- 6.42  
kibana - 6.42

please help 🙂  
thanks.

---

<div class="post-metadata">

**Author:** ![bmatoki](https://avatars.discourse-cdn.com/v4/letter/b/7ea924/32.png) [@bmatoki](https://discuss.elastic.co/u/bmatoki)\
**Post date:** [December 11, 2018, 2:41pm UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/2 "2018-12-11T14:41:30Z")

</div>

Bump  
tried with version 6.5.x also - same issue  
tried to add to file path codec = \> json\_lines - same issue.

---

<div class="post-metadata">

**Author:** ![bmatoki](https://avatars.discourse-cdn.com/v4/letter/b/7ea924/32.png) [@bmatoki](https://discuss.elastic.co/u/bmatoki)\
**Post date:** [December 13, 2018, 9:49am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/3 "2018-12-13T09:49:09Z")

</div>

Bump

---

<div class="post-metadata">

**Author:** ![bmatoki](https://avatars.discourse-cdn.com/v4/letter/b/7ea924/32.png) [@bmatoki](https://discuss.elastic.co/u/bmatoki)\
**Post date:** [December 17, 2018, 5:57am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/4 "2018-12-17T05:57:50Z")

</div>

no one ? ☹

---

<div class="post-metadata">

**Author:** ![bmatoki](https://avatars.discourse-cdn.com/v4/letter/b/7ea924/32.png) [@bmatoki](https://discuss.elastic.co/u/bmatoki)\
**Post date:** [December 19, 2018, 7:24am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/5 "2018-12-19T07:24:52Z")

</div>

> [@bmatoki](#):
>
> Bump

Bump

---

<div class="post-metadata">

**Author:** ![bmatoki](https://avatars.discourse-cdn.com/v4/letter/b/7ea924/32.png) [@bmatoki](https://discuss.elastic.co/u/bmatoki)\
**Post date:** [December 26, 2018, 8:56am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/6 "2018-12-26T08:56:16Z")

</div>

bump

---

<div class="post-metadata">

**Author:** ![bmatoki](https://avatars.discourse-cdn.com/v4/letter/b/7ea924/32.png) [@bmatoki](https://discuss.elastic.co/u/bmatoki)\
**Post date:** [January 8, 2019, 11:28am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/7 "2019-01-08T11:28:16Z")

</div>

bump

---

<div class="post-metadata">

**Author:** ![bmatoki](https://avatars.discourse-cdn.com/v4/letter/b/7ea924/32.png) [@bmatoki](https://discuss.elastic.co/u/bmatoki)\
**Post date:** [January 15, 2019, 9:42am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/8 "2019-01-15T09:42:38Z")

</div>

bump

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [January 15, 2019, 12:29pm UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/9 "2019-01-15T12:29:03Z")

</div>

This is a known issue: [Gzip compression results to uncompressable package · Issue #61 · logstash-plugins/logstash-output-file · GitHub](https://github.com/logstash-plugins/logstash-output-file/issues/61)  
Try to get it fixed from there, I gave up a long time ago 🙂

EDIT:

> i tried to cd into the gzip via cygnwin (linux) - i saw to json at invalid format.

My data was very much intact, but it was missing gzip footer (or something like that). Are you sure the json is invalid, if you zcat it?

---

<div class="post-metadata">

**Author:** ![bmatoki](https://avatars.discourse-cdn.com/v4/letter/b/7ea924/32.png) [@bmatoki](https://discuss.elastic.co/u/bmatoki)\
**Post date:** [January 16, 2019, 8:27am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/10 "2019-01-16T08:27:24Z")

</div>

tried with zcat and zlib via node.js same issue.  
"outputting invalid compressed data "

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [January 16, 2019, 9:02am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/11 "2019-01-16T09:02:06Z")

</div>

Yes, but that still doesn't indicate that the JSON data inside the archive would be invalid. It just says that the compressed package is invalid, like in my case.  
Anyway, you have to take it to the developer or try to fix it yourself. There does not seem to be anything wrong with your config.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2019, 9:02am UTC](https://discuss.elastic.co/t/archive-index-to-gzip-cant-decompressed/160108/12 "2019-02-13T09:02:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
