# How is the state (last read file or position in a file) is maintained for multiple pods running logstash

**URL:** <https://discuss.elastic.co/t/how-is-the-state-last-read-file-or-position-in-a-file-is-maintained-for-multiple-pods-running-logstash/314502>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [September 15, 2022, 11:25am UTC](https://discuss.elastic.co/t/how-is-the-state-last-read-file-or-position-in-a-file-is-maintained-for-multiple-pods-running-logstash/314502 "2022-09-15T11:25:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jyoti\_Patel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jyoti_patel/32/110923_2.png) [@Jyoti\_Patel](https://discuss.elastic.co/u/Jyoti_Patel)\
**Post date:** [September 15, 2022, 11:25am UTC](https://discuss.elastic.co/t/how-is-the-state-last-read-file-or-position-in-a-file-is-maintained-for-multiple-pods-running-logstash/314502/1 "2022-09-15T11:25:29Z")

</div>

Hi Everyone,  
I just have a query regarding last read s3 file or the last read line in the s3 file.  
How or where is that data stored? and how is that shared among multiple pods running logstash?  
What if the pod is replaced? How does the new pod know the last read location in s3?

input plugin: s3  
output plugin Elasticsearch

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 15, 2022, 12:54pm UTC](https://discuss.elastic.co/t/how-is-the-state-last-read-file-or-position-in-a-file-is-maintained-for-multiple-pods-running-logstash/314502/2 "2022-09-15T12:54:00Z")

</div>

> [@Jyoti\_Patel](#):
>
> How or where is that data stored?

The plugin stores the time of the last read inside a file in the configured [sincedb\_path](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-s3.html#plugins-inputs-s3-sincedb_path).

> [@Jyoti\_Patel](#):
>
> and how is that shared among multiple pods running logstash?

It is not shared, the plugin was not build to have multiple inputs consuming from the same bucket, so to avoid duplication you can have only one input per bucket or prefix.

---

<div class="post-metadata">

**Author:** ![Jyoti\_Patel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jyoti_patel/32/110923_2.png) [@Jyoti\_Patel](https://discuss.elastic.co/u/Jyoti_Patel)\
**Post date:** [September 15, 2022, 1:29pm UTC](https://discuss.elastic.co/t/how-is-the-state-last-read-file-or-position-in-a-file-is-maintained-for-multiple-pods-running-logstash/314502/3 "2022-09-15T13:29:49Z")

</div>

Thanks for the reply @leandrojmp .  
A follow up question on that.  
If the logstash container restarts, the file might get deleted from the configured or default **sincedb\_path**. How is that handled in case of logstash running as a container?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 15, 2022, 1:45pm UTC](https://discuss.elastic.co/t/how-is-the-state-last-read-file-or-position-in-a-file-is-maintained-for-multiple-pods-running-logstash/314502/4 "2022-09-15T13:45:12Z")

</div>

Check the documentation for the [sincedb\_path](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-s3.html#plugins-inputs-s3-sincedb_path) setting.

You will need to configure this setting to a persistent volume that would be reused by a new container.

---

<div class="post-metadata">

**Author:** ![Jyoti\_Patel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jyoti_patel/32/110923_2.png) [@Jyoti\_Patel](https://discuss.elastic.co/u/Jyoti_Patel)\
**Post date:** [September 15, 2022, 2:12pm UTC](https://discuss.elastic.co/t/how-is-the-state-last-read-file-or-position-in-a-file-is-maintained-for-multiple-pods-running-logstash/314502/5 "2022-09-15T14:12:00Z")

</div>

Got it. Thanks @leandrojmp

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2022, 2:12pm UTC](https://discuss.elastic.co/t/how-is-the-state-last-read-file-or-position-in-a-file-is-maintained-for-multiple-pods-running-logstash/314502/6 "2022-10-13T14:12:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
