# Changing file content during indexation

**URL:** <https://discuss.elastic.co/t/changing-file-content-during-indexation/63032>\
**Category:** Logstash\
**Created:** [October 14, 2016, 8:03am UTC](https://discuss.elastic.co/t/changing-file-content-during-indexation/63032 "2016-10-14T08:03:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![frederes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frederes/32/12476_2.png) [@frederes](https://discuss.elastic.co/u/frederes)\
**Post date:** [October 14, 2016, 8:03am UTC](https://discuss.elastic.co/t/changing-file-content-during-indexation/63032/1 "2016-10-14T08:03:15Z")

</div>

I have a logstah monitoring all files of type \*.csv in a directory.  
If i delete or change the content of one .csv (remove lines), will logstash be perturbated in its indexation task ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 19, 2016, 5:58am UTC](https://discuss.elastic.co/t/changing-file-content-during-indexation/63032/2 "2016-10-19T05:58:14Z")

</div>

Deleted files should be dropped the next time the filename patterns are scanned (every 15 seconds or whatever `discovery_interval` is set to). For updates it depends on how the files are updated. New file that's renamed into place or in-place update of existing file?

---

<div class="post-metadata">

**Author:** ![frederes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frederes/32/12476_2.png) [@frederes](https://discuss.elastic.co/u/frederes)\
**Post date:** [October 19, 2016, 7:47am UTC](https://discuss.elastic.co/t/changing-file-content-during-indexation/63032/3 "2016-10-19T07:47:37Z")

</div>

What would happen in these 2 cases :

- renaming the file
- updating in-place content of file (deleting lines or changing lines values)

..?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 19, 2016, 7:53am UTC](https://discuss.elastic.co/t/changing-file-content-during-indexation/63032/4 "2016-10-19T07:53:04Z")

</div>

> - renaming the file

Not entirely sure.

> - updating in-place content of file (deleting lines or changing lines values)

Logstash will continue reading from the current position. If the update takes place afterwards in the file (i.e. a higher file offset) then it won't affect Logstash, but if it takes place earlier you'll see weird things. You can't delete a line without truncating the file and rewriting at least the remainder of the file, which might trigger Logstash's rotation logic (i.e. it thinks the file has shrunken and therefore has been rotated).

Just don't make in-place edits of files that Logstash monitors.

---

<div class="post-metadata">

**Author:** ![frederes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frederes/32/12476_2.png) [@frederes](https://discuss.elastic.co/u/frederes)\
**Post date:** [October 19, 2016, 8:09am UTC](https://discuss.elastic.co/t/changing-file-content-during-indexation/63032/5 "2016-10-19T08:09:52Z")

</div>

Thank you very much for your response, this confirms what i thought.  
Logstash is not suitable in my study case.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:33am UTC](https://discuss.elastic.co/t/changing-file-content-during-indexation/63032/6 "2017-07-06T04:33:34Z")

</div>


