# Force logstash-forwarder to index newest events first

**URL:** <https://discuss.elastic.co/t/force-logstash-forwarder-to-index-newest-events-first/41381>\
**Category:** Logstash\
**Created:** [February 10, 2016, 1:19pm UTC](https://discuss.elastic.co/t/force-logstash-forwarder-to-index-newest-events-first/41381 "2016-02-10T13:19:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nkoleff](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@nkoleff](https://discuss.elastic.co/u/nkoleff)\
**Post date:** [February 10, 2016, 1:19pm UTC](https://discuss.elastic.co/t/force-logstash-forwarder-to-index-newest-events-first/41381/1 "2016-02-10T13:19:33Z")

</div>

Hello,

I'm shipping logs with logstash-forwarder and for one of my types I can see that its mainly indexing old data (mostly near the dead time), whcih results in not having events for the last four hours. Instead, it's entering old data first. I would like this to be configured somehow and to force it to index the newest data first, and then if theres nothing new - to index older data.

Here's my configuration block:

> ### GW LOGS BLOCK
> 
> ```
> {
> "paths": [
> "/srv/logserver/data/2016/*/*/srv-*-gw0*/*.GW0*.GATEWAY*"
> ],
> "dead time": "100h",
> "fields": { "type": "applog" }
> },
> 
> ```

What am i missing?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:12am UTC](https://discuss.elastic.co/t/force-logstash-forwarder-to-index-newest-events-first/41381/2 "2017-07-06T05:12:14Z")

</div>


