# File input doesn t read incoming Json file from web application

**URL:** <https://discuss.elastic.co/t/file-input-doesn-t-read-incoming-json-file-from-web-application/172499>\
**Category:** Logstash\
**Created:** [March 15, 2019, 9:42am UTC](https://discuss.elastic.co/t/file-input-doesn-t-read-incoming-json-file-from-web-application/172499 "2019-03-15T09:42:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![hilne](https://avatars.discourse-cdn.com/v4/letter/h/ea5d25/32.png) [@hilne](https://discuss.elastic.co/u/hilne)\
**Post date:** [March 15, 2019, 9:42am UTC](https://discuss.elastic.co/t/file-input-doesn-t-read-incoming-json-file-from-web-application/172499/1 "2019-03-15T09:42:14Z")

</div>

Hi everyone,

I'm trying to parse incoming json files from my web app stored in folder /tmp/test/\*.json.

The problem is that logstash doesnt read my files when there are created. I have to modify them so that logstash parses them.

I try to change parameters in my input file like ignore\_older to parse all logs but changed nothing

I did this filter.conf:

input {  
file {  
path =\> "/tmp/test/\*.json"  
codec =\> json  
start\_position =\> "beginning"  
ignore\_older =\> 0  
}  
}

filter {  
json {  
source =\> "message"  
}  
}

output {  
stdout {codec =\> json}  
elasticsearch {  
hosts =\> "127.0.0.1:9200"  
index =\> "test-%{+YYYY.MM}"  
codec =\> json  
}  
}

Below, this is my folder with files permissions

 ![folder_test](https://us1.discourse-cdn.com/elastic/original/3X/3/9/39dbf91c7c4ecf70f3cfe3c3d01dda9a8590578c.png)

I started logstash with --debug and -v but there is no error message. The .sincedbpath is not updated when the log is created.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 15, 2019, 12:51pm UTC](https://discuss.elastic.co/t/file-input-doesn-t-read-incoming-json-file-from-web-application/172499/2 "2019-03-15T12:51:20Z")

</div>

> [@hilne](#):
>
> ignore\_older =\> 0

This says to ignore all files older than 0 seconds. Which means it ignores all files.

---

<div class="post-metadata">

**Author:** ![hilne](https://avatars.discourse-cdn.com/v4/letter/h/ea5d25/32.png) [@hilne](https://discuss.elastic.co/u/hilne)\
**Post date:** [March 16, 2019, 11:13am UTC](https://discuss.elastic.co/t/file-input-doesn-t-read-incoming-json-file-from-web-application/172499/3 "2019-03-16T11:13:17Z")

</div>

Thanks for your reply !

I have removed the ignore\_older parameter from my config. Now logstash see my file and add an entry into .sincedbpath. However, The current byte offset within the file is 0 so I understand that logstash doesnt read the file ?

Sincedb information:  
262169 0 2049 500 1552734148.288747 -\> file parsed by logstash if I do a modification  
262195 0 2049 0 1552734148.2914188 -\> file incoming not parsed by logstash.

Still no error or info message on logs of logstash.  
If you need more information, ask me.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 16, 2019, 11:56am UTC](https://discuss.elastic.co/t/file-input-doesn-t-read-incoming-json-file-from-web-application/172499/4 "2019-03-16T11:56:43Z")

</div>

Run with '--log.level trace' to see what filewatch is doing.

---

<div class="post-metadata">

**Author:** ![hilne](https://avatars.discourse-cdn.com/v4/letter/h/ea5d25/32.png) [@hilne](https://discuss.elastic.co/u/hilne)\
**Post date:** [April 3, 2019, 6:18pm UTC](https://discuss.elastic.co/t/file-input-doesn-t-read-incoming-json-file-from-web-application/172499/5 "2019-04-03T18:18:33Z")

</div>

This is the log when I create a new file in the folder. The entry is added into sincedb but logstash detects a problem of delimiter if I understand well. My json file didnt end by \n so logstash never detects the end of the file. I edit the file, add \n and reloaded logstash and it worked well.  
Thanks for the --log.level trace. was helpfull

[2019-04-03T20:03:14,268][TRACE][filewatch.tailmode.processor] Active - no change {"watched\_file"=\>"\<FileWatch::WatchedFile: @filename='\*\*\*\_2019-03-07\_suivi.json', @state='active', @recent\_states='[:watched, :watched]', @bytes\_read='501', @bytes\_unread='0', current\_size='501', last\_stat\_size='501', file\_open?='true', @initial=false, @sincedb\_key='262195 0 2049'\>"}  
[2019-04-03T20:03:14,272][TRACE][filewatch.tailmode.processor] Active - file grew: \*\*\*\_2019-03-08\_suivi.json: new size is 501, bytes read 0  
[2019-04-03T20:03:14,273][TRACE][filewatch.tailmode.handlers.grow] handling: \*\*_\_2019-03-08\_suivi.json  
[2019-04-03T20:03:14,278][TRACE][filewatch.tailmode.handlers.grow] reading... {"iterations"=\>1, "amount"=\>501, "filename"=\>"**\_2019-03-08\_suivi.json"}  
[2019-04-03T20:03:14,279][DEBUG][filewatch.tailmode.handlers.grow] read\_to\_eof: get chunk  
[2019-04-03T20:03:14,288][TRACE][filewatch.tailmode.handlers.grow] buffer\_extract: a delimiter can't be found in current chunk, maybe there are no more delimiters or the delimiter is incorrect or the text before the delimiter, a 'line', is very large, if this message is logged often try increasing the `file_chunk_size` setting. {"delimiter"=\>"\n", "read\_position"=\>0, "bytes\_read\_count"=\>501, "last\_known\_file\_size"=\>501, "file\_path"=\>"**_/\_2019-03-08\_suivi.json"}

This topic can be closed. thanks a lot

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2019, 6:18pm UTC](https://discuss.elastic.co/t/file-input-doesn-t-read-incoming-json-file-from-web-application/172499/6 "2019-05-01T18:18:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
