# File input: ignore\_older quick question

**URL:** <https://discuss.elastic.co/t/file-input-ignore-older-quick-question/54388>\
**Category:** Logstash\
**Created:** [June 30, 2016, 10:19am UTC](https://discuss.elastic.co/t/file-input-ignore-older-quick-question/54388 "2016-06-30T10:19:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alex\_6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_6/32/1330_2.png) [@Alex\_6](https://discuss.elastic.co/u/Alex_6)\
**Post date:** [June 30, 2016, 10:19am UTC](https://discuss.elastic.co/t/file-input-ignore-older-quick-question/54388/1 "2016-06-30T10:19:55Z")

</div>

I just want to check the behaviour of the ignore\_older parameter. Logstash 2.3.3.

Logstash has a file input and is set start\_position: beginning.  
ignore\_older set to default of 24h.

- Logstash has been down for 48h.
- More than 24h ago a new log was created but it has not been modified in the last 24h.
- Logstash comes back up. It ignores that log file and does not read from it.
- The log file has new lines appended.
- **Logstash only starts reading those new log lines and still ignores the older log lines.**

Is this all correct? Even though Logstash has start\_position: beginning it will only read the new log lines when the file is modified again?

---

<div class="post-metadata">

**Author:** ![noemie](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@noemie](https://discuss.elastic.co/u/noemie)\
**Post date:** [June 30, 2016, 10:33am UTC](https://discuss.elastic.co/t/file-input-ignore-older-quick-question/54388/2 "2016-06-30T10:33:28Z")

</div>

Hello,

Logstash will read the new log lines **and** the older ones.

You have 2 cases:  
**Case 1:**

1. You created the file while Logstas was down but it is older than 24 hours
2. Logstash comes back up. It ignores that log file and does not read from it
3. The log file is modified by adding new lines
4. Logstash will starts reading the file from the beginning, new lines and older ones will be read

**Case 2:**

1. You created the file while Logstas was up so it is older than 48 hours. Meaning that Logstash already read that file.
2. The file appended to be modified when Logstash was down but the modification appended at least 24 hours before restarting Logstash . Meaning that the last position known for this file in the sincedb file is not the last line of the file.
3. Logstash comes back up. It ignores that log file and does not read from it
4. The log file is modified by adding new lines
5. Logstash will starts reading the file from the last position known (old lines not read yet and new ones)

I don't know if I'm understandable...  
I hope this help though.

---

<div class="post-metadata">

**Author:** ![Alex\_6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_6/32/1330_2.png) [@Alex\_6](https://discuss.elastic.co/u/Alex_6)\
**Post date:** [June 30, 2016, 10:50am UTC](https://discuss.elastic.co/t/file-input-ignore-older-quick-question/54388/3 "2016-06-30T10:50:15Z")

</div>

Hi Noémie,

I understood perfectly 🙂

So in summary, all log lines will be processed as long as the file has been modified in the last 24h. All previously ignored lines will be picked up.

Thanks!

---

<div class="post-metadata">

**Author:** ![noemie](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@noemie](https://discuss.elastic.co/u/noemie)\
**Post date:** [June 30, 2016, 11:16am UTC](https://discuss.elastic.co/t/file-input-ignore-older-quick-question/54388/4 "2016-06-30T11:16:55Z")

</div>

Exactly!

The only lines that won't be read again are those already read before the crash 🙂  
If not read, when modifiying the file, Logstash will just resume from the last know position in the sincedb file for the file that was modified 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:50am UTC](https://discuss.elastic.co/t/file-input-ignore-older-quick-question/54388/5 "2017-07-06T04:50:10Z")

</div>


