# File watcher

**URL:** <https://discuss.elastic.co/t/file-watcher/208520>\
**Category:** Logstash\
**Created:** [November 19, 2019, 2:04pm UTC](https://discuss.elastic.co/t/file-watcher/208520 "2019-11-19T14:04:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krypton8](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@Krypton8](https://discuss.elastic.co/u/Krypton8)\
**Post date:** [November 19, 2019, 2:04pm UTC](https://discuss.elastic.co/t/file-watcher/208520/1 "2019-11-19T14:04:56Z")

</div>

Hello all,

I have a problem regarding file input to get data from several csv files.

The goal is pretty simple but i'm struggling.  
I need to retrieve data from a csv file, easy, I works nicely. The data are stored in ES.

But, I need more than that. In fact, let's say I have my csv file under:  
`/data/patch-management/my_file.csv`

Every now and then, a new version of this file is send to my folder /data/patch-management/ under the same name as the previsous csv file.

So it will be erase with new version of this file.  
That being said, I now have my new csv file under:  
`/data/patch-management/my_file.csv`

But contain different information from the first one.

What I need: To erase the file once its read by Logstash, and then read the new file. But I don't know when it will be "update", so my Logstash need to "watch" the folder, and if it sees that the new file is not read (thanks to sincedb\_path, I guess), reads it, and store the content in my ES index (the same as the first file).

Example: My first file as 4 lines, then, my ES index has 4 events.  
My second file as 6 lines, then my ES index should have 10 events.

I put a "file\_completed\_action" =\> "delete", which, once read, will delete the file "my\_file.csv". It is not the case. Logstash have access to this file so it is not a permission problem.

Here's my config:

```
input {	 
  file {
    path => "/data/patch-management/*.csv"
	sincedb_path => "/etc/logstash/conf.d/since_db_path/patch-management_csv.sdb"
	mode => "read"
	file_completed_action => "delete"
	type => "patch_management"
  }
}

```

The filter and output works great, no problem on this part.

I hope someone can explain how to achieve this.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2019, 2:05pm UTC](https://discuss.elastic.co/t/file-watcher/208520/2 "2019-12-17T14:05:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
