# How can i make logstash to read file with same filename after processing

**URL:** <https://discuss.elastic.co/t/how-can-i-make-logstash-to-read-file-with-same-filename-after-processing/226187>\
**Category:** Logstash\
**Created:** [April 2, 2020, 9:23am UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-to-read-file-with-same-filename-after-processing/226187 "2020-04-02T09:23:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![yigene](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yigene/32/65553_2.png) [@yigene](https://discuss.elastic.co/u/yigene)\
**Post date:** [April 2, 2020, 9:23am UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-to-read-file-with-same-filename-after-processing/226187/1 "2020-04-02T09:23:30Z")

</div>

Hi,

I have tried many ways but still not able to get it work  
basically, i have logstash to watching one folder and load into ES with read model  
input {  
file {  
path =\> [  
"/tmp/\*csv"  
]  
type =\> "stp"  
tags =\> ["aa"]  
mode =\> "read"  
file\_completed\_action =\> "delete"  
sincedb\_clean\_after =\> "2 min"  
sincedb\_path =\> "/env/.csvstp"  
}  
}  
so first time when i load file aa.csv into the folder it get processed and file been deleted. this is expected

later i put different content into aa.csv and copy to /tm/ folder again, but logstash is not processing unless i restart and clear sincedb file.

I have tried to use sincedb to /dev/null, but it will only process file after restart logstash

is there anyway i can make it

1. automatically process the file from /tmp/\*csv
2. delete it after process
3. load the file again if the files with same filename copy to /tmp/ folder

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 2, 2020, 1:05pm UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-to-read-file-with-same-filename-after-processing/226187/2 "2020-04-02T13:05:37Z")

</div>

No, it is a known [issue](https://github.com/logstash-plugins/logstash-input-file/issues/213) that a file that is deleted should be removed from the sincedb, and another known issue that file content fingerprinting would work better than simple inode re-use detection.

---

<div class="post-metadata">

**Author:** ![yigene](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yigene/32/65553_2.png) [@yigene](https://discuss.elastic.co/u/yigene)\
**Post date:** [April 3, 2020, 5:51am UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-to-read-file-with-same-filename-after-processing/226187/3 "2020-04-03T05:51:56Z")

</div>

thanks..  
even i put the sincedb to /dev/null it not work.. so looks like it cache the position in memory and will not process the next file if it has the same name

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 3, 2020, 2:00pm UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-to-read-file-with-same-filename-after-processing/226187/4 "2020-04-03T14:00:49Z")

</div>

The file input always uses an in-memory sincedb. Setting sincedb\_path to /dev/null prevents the in-memory sincedb being persisted across restarts.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2020, 2:01pm UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-to-read-file-with-same-filename-after-processing/226187/5 "2020-05-01T14:01:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
