# Grokparsefailure randomly

**URL:** <https://discuss.elastic.co/t/grokparsefailure-randomly/166203>\
**Category:** Logstash\
**Created:** [January 29, 2019, 3:47pm UTC](https://discuss.elastic.co/t/grokparsefailure-randomly/166203 "2019-01-29T15:47:49Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![fry2k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fry2k/32/40337_2.png) [@fry2k](https://discuss.elastic.co/u/fry2k)\
**Post date:** [February 4, 2019, 4:52pm UTC](https://discuss.elastic.co/t/grokparsefailure-randomly/166203/5 "2019-02-04T16:52:10Z")

</div>

Thanks a lot. I didn't know the mode "read" until now. That's exactly what I was looking for.

With this setup it works perfect now:

```auto
file {
    path => '/var/elk-logs/queue/*lfa_event_20*.log'
    mode => "read"
    sincedb_path => "/var/elk-logs/sincedb/sincedb"
    file_completed_action => "log_and_delete"
    file_completed_log_path => "/var/elk-logs/logs/complete.log"
    ignore_older => 50
    sincedb_clean_after => "60s"
    add_field => {
      "[@metadata][indexType]" => "lfaEvent"
    }
  }
```

Like you suggested I copy the new file with a temp file name and rename it after the copy process.

At my log I see still the same inode IDs but they didn't cause any problems.

---

_[View the full topic](https://discuss.elastic.co/t/grokparsefailure-randomly/166203)._
