# Getting error for sincedb\_path in window 7

**URL:** <https://discuss.elastic.co/t/getting-error-for-sincedb-path-in-window-7/168905>\
**Category:** Logstash\
**Created:** [February 18, 2019, 10:00pm UTC](https://discuss.elastic.co/t/getting-error-for-sincedb-path-in-window-7/168905 "2019-02-18T22:00:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![anujjai](https://avatars.discourse-cdn.com/v4/letter/a/f08c70/32.png) [@anujjai](https://discuss.elastic.co/u/anujjai)\
**Post date:** [February 18, 2019, 10:00pm UTC](https://discuss.elastic.co/t/getting-error-for-sincedb-path-in-window-7/168905/1 "2019-02-18T22:00:39Z")

</div>

HI ,  
My config is below  
input {  
file {  
path =\> "C:/Anuj/ElasticSearch/DMS\_GTX-Process\_Archive.log"  
start\_position =\> "beginning"  
sincedb\_path =\> "C:/dev/null/logdbpath.txt"  
sincedb\_write\_interval =\> 10  
}  
}  
filter {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP :timestamp} GMT %{NUMBER:num} %{USERNAME:Application} User [%{USERNAME :BWuser}] - %{USERNAME :job} [(?[a-zA-Z0-9./\s]+)]:%{GREEDYDATA:Log}" }  
}  
geoip {  
source =\> "clientip"

i am getting below error weather i use sincedb\_path =\> "C:/dev/null/logdbpath.txt" or remove the sincedb\_path in logstash 6.5.4 in window 7  
below is the error in console when i do not use sincedb\_path

Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<ArgumentError: The "sincedb\_path" argument must point to a file, received a directory: "/dev/null"\>, :backtrace=\>["C:/Anuj/ElasticSearch/logstash-6.5.4/vendor/bundle/jruby/2.3.0/gems/logstash-input-file-4.1.8/lib/logstash/inputs/file.rb:280:in `register'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:242:in`register\_plugin'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:253:in `block in register_plugins'", "org/jruby/RubyArray.java:1734:in`each'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:253:in `register_plugins'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:396:in`start\_inputs'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:294:in `start_workers'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:200:in`run'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:160:in `block in start'"], :thread=\>"#\<Thread:0x46a0759 run\>"}  
[2019-02-18T13:48:11,513][ERROR][logstash.agent] Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}  
[2019-02-18T13:48:12,433][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

when i use sincedb\_path i am getting below error:  
Error registering plugin {:pipeline\_id=\>"main", :plugin=\>"\<LogStash::Inputs::File start\_position=\>"beginning", path=\>["C:\\Anuj\\ElasticSearch\\apache-daily-access.log"], id=\>"9bcb27f7f5896ab49bb3f04a8e55bf2014c540b984adaa730cc5b1d4c818f56e", sincedb\_path=\>"/dev/null", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_4ab1ca26-a0af-4af3-938b-e2fcacdae12d", enable\_metric=\>true, charset=\>"UTF-8"\>, stat\_interval=\>1.0, discover\_interval=\>15, sincedb\_write\_interval=\>15.0, delimiter=\>"\n", close\_older=\>3600.0, mode=\>"tail", file\_completed\_action=\>"delete", sincedb\_clean\_after=\>1209600.0, file\_chunk\_size=\>32768, file\_chunk\_count=\>140737488355327, file\_sort\_by=\>"last\_modified", file\_sort\_direction=\>"asc"\>", :error=\>"The "sincedb\_path" argument must point to a file, received a directory: "/dev/null"", :thread=\>"#\<Thread:0x345380c7 run\>"}  
[2019-02-18T12:02:31,119][ERROR][logstash.pipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<ArgumentError: The "sincedb\_path" argument must point to a file, received a directory: "/dev/null"\>, :backtrace=\>["C:/Anuj/ElasticSearch/logstash-6.5.4/vendor/bundle/jruby/2.3.0/gems/logstash-input-file-4.1.8/lib/logstash/inputs/file.rb:280:in `register'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:242:in`register\_plugin'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:253:in `block in register_plugins'", "org/jruby/RubyArray.java:1734:in`each'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:253:in `register_plugins'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:396:in`start\_inputs'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:294:in `start_workers'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:200:in`run'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:160:in `block in start'"], :thread=\>"#\<Thread:0x345380c7 run\>"}  
[2019-02-18T12:02:31,152][ERROR][logstash.agent] Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 18, 2019, 10:05pm UTC](https://discuss.elastic.co/t/getting-error-for-sincedb-path-in-window-7/168905/2 "2019-02-18T22:05:07Z")

</div>

On Windows, if you do not want a persistent sincedb, set

```
sincedb_path => "NUL"

```

If you want a sincedb, I cannot think of a worse directory to place it in that C:/dev/null. It will confuse _everyone_. Just use the default location and remove the sincedb\_path option.

---

<div class="post-metadata">

**Author:** ![anujjai](https://avatars.discourse-cdn.com/v4/letter/a/f08c70/32.png) [@anujjai](https://discuss.elastic.co/u/anujjai)\
**Post date:** [February 18, 2019, 10:29pm UTC](https://discuss.elastic.co/t/getting-error-for-sincedb-path-in-window-7/168905/3 "2019-02-18T22:29:35Z")

</div>

Hi ,  
After changing the configuration to sincedb\_path =\> "NUL"  
i am getting below error #\<ArgumentError: The "sincedb\_path" argument must point to a file, received a directory: "/dev/null"\>  
not able to see index getting created in elastic search.

Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2019-02-18T14:25:56,600][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
[2019-02-18T14:25:56,628][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2019-02-18T14:25:56,691][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2019-02-18T14:25:56,964][INFO][logstash.filters.geoip] Using geoip database {:path=\>"C:/Anuj/ElasticSearch/logstash-6.5.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-geoip-5.0.3-java/vendor/GeoLite2-City.mmdb"}  
[2019-02-18T14:25:57,535][ERROR][logstash.pipeline] **Error registering plugin {:pipeline\_id=\>"main", :plugin=\>"\<LogStash::Inputs::File start\_position=\>"beginning", path=\>["C:\\Anuj\\ElasticSearch\\apache-daily-access.log"],** id=\>"9bcb27f7f5896ab49bb3f04a8e55bf2014c540b984adaa730cc5b1d4c818f56e", sincedb\_path=\>"/dev/null", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_a42f75ea-7ef8-4e8c-9a5e-631802da8388", enable\_metric=\>true, charset=\>"UTF-8"\>, stat\_interval=\>1.0, discover\_interval=\>15, sincedb\_write\_interval=\>15.0, delimiter=\>"\n", close\_older=\>3600.0, mode=\>"tail", file\_completed\_action=\>"delete", sincedb\_clean\_after=\>1209600.0, file\_chunk\_size=\>32768, file\_chunk\_count=\>140737488355327, file\_sort\_by=\>"last\_modified", file\_sort\_direction=\>"asc"\>", :error=\>"The "sincedb\_path" argument must point to a file, received a directory: "/dev/null"", :thread=\>"#\<Thread:0x2ca871df run\>"}  
[2019-02-18T14:25:58,634][ERROR][logstash.pipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<ArgumentError: The "sincedb\_path" argument must point to a file, received a directory: "/dev/null"\>, :backtrace=\>["C:/Anuj/ElasticSearch/logstash-6.5.4/vendor/bundle/jruby/2.3.0/gems/logstash-input-file-4.1.8/lib/logstash/inputs/file.rb:280:in `register'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:242:in`register\_plugin'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:253:in `block in register_plugins'", "org/jruby/RubyArray.java:1734:in`each'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:253:in `register_plugins'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:396:in`start\_inputs'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:294:in `start_workers'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:200:in`run'", "C:/Anuj/ElasticSearch/logstash-6.5.4/logstash-core/lib/logstash/pipeline.rb:160:in `block in start'"], :thread=\>"#\<Thread:0x2ca871df run\>"}  
[2019-02-18T14:25:58,663][ERROR][logstash.agent] Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}  
[2019-02-18T14:25:59,429][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 18, 2019, 11:17pm UTC](https://discuss.elastic.co/t/getting-error-for-sincedb-path-in-window-7/168905/4 "2019-02-18T23:17:24Z")

</div>

Do you have a second configuation file in the directory that contains the configuration? If -f points to a directory logstash will concatenate all the files to create a configuration. So if you have test.conf and test.conf.backup it will read both.

---

<div class="post-metadata">

**Author:** ![anujjai](https://avatars.discourse-cdn.com/v4/letter/a/f08c70/32.png) [@anujjai](https://discuss.elastic.co/u/anujjai)\
**Post date:** [February 19, 2019, 12:27am UTC](https://discuss.elastic.co/t/getting-error-for-sincedb-path-in-window-7/168905/5 "2019-02-19T00:27:32Z")

</div>

Thanks It worked .i had another configuration file as well in same location.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2019, 12:27am UTC](https://discuss.elastic.co/t/getting-error-for-sincedb-path-in-window-7/168905/6 "2019-03-19T00:27:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
