# File updates in read mode

**URL:** <https://discuss.elastic.co/t/file-updates-in-read-mode/202730>\
**Category:** Logstash\
**Created:** [October 8, 2019, 9:02pm UTC](https://discuss.elastic.co/t/file-updates-in-read-mode/202730 "2019-10-08T21:02:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kurbar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kurbar/32/74880_2.png) [@kurbar](https://discuss.elastic.co/u/kurbar)\
**Post date:** [October 8, 2019, 9:02pm UTC](https://discuss.elastic.co/t/file-updates-in-read-mode/202730/1 "2019-10-08T21:02:37Z")

</div>

I have input file plugin configured in read mode where I read the entire file and use multiline to concat it into a single event.

```auto
input {
  file {
    path => "/absolute/path/to/xmls/**/*.xml"
    start_position => "beginning"
    max_open_files => 10000
    mode => "read"
    close_older => "1 minute"
    codec => multiline {
      charset => "ISO-8859-1"
      pattern => "\Z"
      what => "previous"
    }
  }
}

```

On initial run it worked perfectly. However I am confused as to what happens when an XML file, with the same filename gets added again with the last modified updated?

In theory, the file should be read again? Currently it doesn't seem to do so.

I tried by adding an XML file with a filename that got processed earlier. The XML files last modified has changed to a more recent time but with 10 minutes into waiting, the file has yet to be read by Logstash.

The reason why I want to re-use XML files with the same name is that these have content that occasionally get updated so I want to pull them in again and my elsticsearch output upserts the content if needed (based on document\_id and XML internal updated timestamp).

Could someone explain to me how the file updates should work? Could it be that I have to disable .sincedb file from being created (/dev/null)?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [October 8, 2019, 9:08pm UTC](https://discuss.elastic.co/t/file-updates-in-read-mode/202730/2 "2019-10-08T21:08:22Z")

</div>

it is going by inode. hence it is not reading it because logstash thinks it has already read file sitting on same inode.

check mode detail explanation that I put, as I had exact same problem

[https://discuss.elastic.co/t/elk-kibana-showing-data-that-was-already-deleted-wont-show-new-data/181631/2](https://discuss.elastic.co/t/elk-kibana-showing-data-that-was-already-deleted-wont-show-new-data/181631/2)

---

<div class="post-metadata">

**Author:** ![kurbar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kurbar/32/74880_2.png) [@kurbar](https://discuss.elastic.co/u/kurbar)\
**Post date:** [October 8, 2019, 9:19pm UTC](https://discuss.elastic.co/t/file-updates-in-read-mode/202730/3 "2019-10-08T21:19:29Z")

</div>

Thank-you for the info. Your post helped me steer to the right solution.

I did a simple test by doing a rename of the filename, which doesn't change the inode. However it seems that Logstash parsed the file even if the inode remained the same.

So it is possible that it might be enough to just have a different named file but since if I will be serving timestamped files to make Logstash do updates it wouldn't really matter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2019, 9:19pm UTC](https://discuss.elastic.co/t/file-updates-in-read-mode/202730/4 "2019-11-05T21:19:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
