# Close\_older not working as expected

**URL:** <https://discuss.elastic.co/t/close-older-not-working-as-expected/113993>\
**Category:** Logstash\
**Created:** [January 4, 2018, 12:20am UTC](https://discuss.elastic.co/t/close-older-not-working-as-expected/113993 "2018-01-04T00:20:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pgervais](https://avatars.discourse-cdn.com/v4/letter/p/65b543/32.png) [@pgervais](https://discuss.elastic.co/u/pgervais)\
**Post date:** [January 4, 2018, 12:20am UTC](https://discuss.elastic.co/t/close-older-not-working-as-expected/113993/1 "2018-01-04T00:20:58Z")

</div>

I'm running logstash from a bash script. I have the following input section :  
input {  
file {  
path =\> "/home/pxg110/logstash/mach/test.csv"  
start\_position =\> "end"  
sincedb\_path =\> "/dev/null"  
close\_older =\> 1  
}  
}  
I want logstash to time out after 1 second according to the online docs shown below.  
What do I need to do to get this to time out properly.

**The file input closes any files that were last read the specified timespan in seconds ago.** This has different implications depending on if a file is being tailed or read. If tailing, and there is a large time gap in incoming data the file can be closed (allowing other files to be opened) but will be queued for reopening when new data is detected. **If reading, the file will be closed after closed\_older seconds from when the last bytes were read. The default is 1 hour**

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 4, 2018, 6:40am UTC](https://discuss.elastic.co/t/close-older-not-working-as-expected/113993/2 "2018-01-04T06:40:18Z")

</div>

> [@pgervais](#):
>
> sincedb\_path =\> "/dev/null"

Why are you disabling the sincedb functionality? I am not sure what you are looking to achieve with this configuration - could you please elaborate a bit more?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 4, 2018, 8:59am UTC](https://discuss.elastic.co/t/close-older-not-working-as-expected/113993/3 "2018-01-04T08:59:33Z")

</div>

> I want logstash to time out after 1 second according to the online docs shown below.

What do you mean by time out? Shut down if the file hasn't seen any activity for more than one second? That's not what `close_older` does.

---

<div class="post-metadata">

**Author:** ![pgervais](https://avatars.discourse-cdn.com/v4/letter/p/65b543/32.png) [@pgervais](https://discuss.elastic.co/u/pgervais)\
**Post date:** [January 4, 2018, 1:59pm UTC](https://discuss.elastic.co/t/close-older-not-working-as-expected/113993/4 "2018-01-04T13:59:21Z")

</div>

The behaviour that I need is for logstash to exit once it has processed all bytes reading from the beginning to the end the file as specified by the file . As logstash is invoked from a bash script it cannot wait until more data comes in.

From the documentation I read and copied in my submission, when you set it to read from the beginning of the file, it will exit after the number of seconds specified has elapsed.

If this not possible, I would need to have logstash monitor a folder for changing content and have it process the file once it its submitted.

If you have examples, that would be great.  
PS: the /dev/null was used in an example to disable the creation of a sincdb file that keeps track where logstash is while processing a file. This si used in case of failure so it knows where to restart.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 4, 2018, 2:04pm UTC](https://discuss.elastic.co/t/close-older-not-working-as-expected/113993/5 "2018-01-04T14:04:27Z")

</div>

You could make Logstash stop once the file has been processed if you pipe it into a stdin input plugin rather than using the file input plugin.

---

<div class="post-metadata">

**Author:** ![pgervais](https://avatars.discourse-cdn.com/v4/letter/p/65b543/32.png) [@pgervais](https://discuss.elastic.co/u/pgervais)\
**Post date:** [January 4, 2018, 2:22pm UTC](https://discuss.elastic.co/t/close-older-not-working-as-expected/113993/6 "2018-01-04T14:22:37Z")

</div>

Christian  
I searched and found a post by Marcus suggesting the use of the stdin plugin and piping data into logstash. Just tried it and it works like I need it to work.

Thanks all for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2018, 2:22pm UTC](https://discuss.elastic.co/t/close-older-not-working-as-expected/113993/7 "2018-02-01T14:22:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
