# Gz log files deleted by logstash when it crashed

**URL:** <https://discuss.elastic.co/t/gz-log-files-deleted-by-logstash-when-it-crashed/211985>\
**Category:** Logstash\
**Created:** [December 16, 2019, 11:01am UTC](https://discuss.elastic.co/t/gz-log-files-deleted-by-logstash-when-it-crashed/211985 "2019-12-16T11:01:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lzx5033](https://avatars.discourse-cdn.com/v4/letter/l/ea5d25/32.png) [@lzx5033](https://discuss.elastic.co/u/lzx5033)\
**Post date:** [December 16, 2019, 11:01am UTC](https://discuss.elastic.co/t/gz-log-files-deleted-by-logstash-when-it-crashed/211985/1 "2019-12-16T11:01:56Z")

</div>

logstash version: 6.4.1

I was sending gz logs to elasticsearch by logstash. The elasticsearch's disk was full but i leave it, so that the logstash reported many 403 errors.  
But some day after that, the logstash crashed, and some of my gz logs was diappeared. The crash did not generate any hprof files or any other dumps.  
I configed the gz logs path to the soft links of its parent folders.  
I think, no matter how logstash crashed, it should not delete my raw logs.

Logstash last line log:  
[logstash.outputs.elasticsearch] Retrying individual bulk actions that failed or were rejected by the previous bulk request. {:count=\>1000}

---

<div class="post-metadata">

**Author:** ![lzx5033](https://avatars.discourse-cdn.com/v4/letter/l/ea5d25/32.png) [@lzx5033](https://discuss.elastic.co/u/lzx5033)\
**Post date:** [December 16, 2019, 1:25pm UTC](https://discuss.elastic.co/t/gz-log-files-deleted-by-logstash-when-it-crashed/211985/2 "2019-12-16T13:25:26Z")

</div>

Finally, i found that file input plugin starting from v4.1.0 add a new config "file\_completed\_action" which default value is delete.  
[https://www.elastic.co/guide/en/logstash-versioned-plugins/current/v4.1.0-plugins-inputs-file.html#v4.1.0-plugins-inputs-file-file\_completed\_action](https://www.elastic.co/guide/en/logstash-versioned-plugins/current/v4.1.0-plugins-inputs-file.html#v4.1.0-plugins-inputs-file-file_completed_action)  
I think this **MURDER** my raw gz log data.  
The dev team, do you know the raw gz log data is always priceless?  
Do you know the delete operation always should be carefull?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 16, 2019, 3:30pm UTC](https://discuss.elastic.co/t/gz-log-files-deleted-by-logstash-when-it-crashed/211985/3 "2019-12-16T15:30:53Z")

</div>

There is an open [issue](https://github.com/logstash-plugins/logstash-input-file/issues/223) for that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2020, 3:30pm UTC](https://discuss.elastic.co/t/gz-log-files-deleted-by-logstash-when-it-crashed/211985/4 "2020-01-13T15:30:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
