# How to unzip compressed logs and ship through forwarder?

**URL:** <https://discuss.elastic.co/t/how-to-unzip-compressed-logs-and-ship-through-forwarder/685>\
**Category:** Logstash\
**Created:** [May 14, 2015, 12:07pm UTC](https://discuss.elastic.co/t/how-to-unzip-compressed-logs-and-ship-through-forwarder/685 "2015-05-14T12:07:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [May 14, 2015, 12:07pm UTC](https://discuss.elastic.co/t/how-to-unzip-compressed-logs-and-ship-through-forwarder/685/1 "2015-05-14T12:07:38Z")

</div>

Hello friends,  
I am using forwarder to ship log to logstash 1.4.2 where those are filtered.  
I have one system which compressed log files in a zip file. there are more than one zip files created at static location once in a day.  
Expected:

1. Forwarder is expected to extract those zip files as soon as those are created
2. read log files inside
3. ship logs to logstash.

is there any way to extract zip files in logstash?  
Please suggest. Also guide me if there is any watcher kind of thing which will make forwarder to wake-up as soon as zip is created.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 14, 2015, 2:42pm UTC](https://discuss.elastic.co/t/how-to-unzip-compressed-logs-and-ship-through-forwarder/685/2 "2015-05-14T14:42:25Z")

</div>

logstash-forwarder doesn't read files inside zip archives so you'd have to write a script for the unpacking. The script could check for new archives and unpack them in a directory that you configure logstash-forwarder to read files from. If the filenames aren't unique you can create a directory for each archive and make sure the wildcard you configure logstash-forwarder with covers all such directories.

It's hard to know when logstash-forwarder has processed a file so the easiest is probably to just have a cronjob that deletes all files older than a certain threshold after which you can be reasonable certain that the files have been processed.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [May 15, 2015, 5:58am UTC](https://discuss.elastic.co/t/how-to-unzip-compressed-logs-and-ship-through-forwarder/685/3 "2015-05-15T05:58:32Z")

</div>

Thanks Manguns.  
At least this is clear that there is now way logstash unzip files.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/how-to-unzip-compressed-logs-and-ship-through-forwarder/685/4 "2017-07-06T05:39:49Z")

</div>


