# File input not working - logstash 2.2.2

**URL:** <https://discuss.elastic.co/t/file-input-not-working-logstash-2-2-2/44335>\
**Category:** Logstash\
**Created:** [March 14, 2016, 2:59pm UTC](https://discuss.elastic.co/t/file-input-not-working-logstash-2-2-2/44335 "2016-03-14T14:59:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Giulio](https://avatars.discourse-cdn.com/v4/letter/g/45deac/32.png) [@Giulio](https://discuss.elastic.co/u/Giulio)\
**Post date:** [March 14, 2016, 2:59pm UTC](https://discuss.elastic.co/t/file-input-not-working-logstash-2-2-2/44335/1 "2016-03-14T14:59:08Z")

</div>

Hi

First of all, sorry for my poor english, I will try to explain my problem as better as I can.

I have just begun to use logstash + elasticsearch and I have a problem with file input.  
Each program is running in a virtual machine (CentOS7) and everything work except when i must load logs from a file!  
Data are perfectly processed by logstash and stored by elasticsearch when I insert them manually, or also when logstash is listening for TCP and UDP event.

This is the simple program that I'm using as test

input {  
file {  
path =\> "/tmp/tutorial.log"  
start\_position =\> beginning  
}  
}

filter {  
grok { match =\> { "message" =\> "%{COMBINEDAPACHELOG}"} }  
geoip { source =\> "clientip" }  
}

output {  
elasticsearch { hosts =\> "192.168.122.243:9200"}  
stdout { codec =\> rubydebug }  
}

The result is the follow:

Settings: Default pipeline workers: 1  
Logstash startup completed

Nothing else, I have alredy try to use the --debug option but nothing, all looks fine 😕

The file exist and is in the correct folder. As a test, I have write a similar code but using stdinput {} and I lunch the program using the follow command and it works, all the data are normalized and stored in the database!

cat /tmp/tutorial.log | bin/logstash -f test.conf

Thanks in advance for your help.

Giulio

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2016, 3:07pm UTC](https://discuss.elastic.co/t/file-input-not-working-logstash-2-2-2/44335/2 "2016-03-14T15:07:29Z")

</div>

Logstash is waiting for additional input to be written to /tmp/tutorial.log since it at some point has processed the file before (or you just added `start_position => beginning`). Please read the file input documentation's section on sincedb files.

If you want to reprocess /tmp/tutorial.log multiple times I suggest you also set `sincedb_path => "/dev/null"` so that Logstash doesn't save and remember its current position in the file.

This is the third time I see this question _today_ so you'll find several other answers in the archives.

---

<div class="post-metadata">

**Author:** ![Giulio](https://avatars.discourse-cdn.com/v4/letter/g/45deac/32.png) [@Giulio](https://discuss.elastic.co/u/Giulio)\
**Post date:** [March 14, 2016, 4:02pm UTC](https://discuss.elastic.co/t/file-input-not-working-logstash-2-2-2/44335/3 "2016-03-14T16:02:13Z")

</div>

Thanks for your reply.

Maybe I haven't explain my problem properly or simply logstash is driving me crazy (problably both options)  
I must not write the data on a file, I must read from file and write normalized them on DB (elasticsearch).  
As I write, all work perfectly using other forms of input (syslog, direct input, ecc) but when I load the data from file simply nothing happen.

I've alredy read the input option guide ([https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html)) but it doesn't help much.

I'm sorry to disturb you and the community but after a couple of days fighting against this (stupid) problem but I really don't have idea where else I can ask for help.

Thank you again

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2016, 6:34pm UTC](https://discuss.elastic.co/t/file-input-not-working-logstash-2-2-2/44335/4 "2016-03-14T18:34:03Z")

</div>

Did you attempt to delete the sincedb file or set `sincedb_path` to /dev/null?

Another cause for this could be that the file is older than 24 hours. By default such old files will be ignored. See the file input's [`ignore_older` option](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-ignore_older).

---

<div class="post-metadata">

**Author:** ![Giulio](https://avatars.discourse-cdn.com/v4/letter/g/45deac/32.png) [@Giulio](https://discuss.elastic.co/u/Giulio)\
**Post date:** [March 15, 2016, 8:27am UTC](https://discuss.elastic.co/t/file-input-not-working-logstash-2-2-2/44335/5 "2016-03-15T08:27:53Z")

</div>

I've already try both options and nothing... Anything works...  
At this point I simply surrender.  
I thank you again for your kind answer.

Have a nice day

Giulio

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/file-input-not-working-logstash-2-2-2/44335/6 "2017-07-06T05:06:59Z")

</div>


