# Index only created if sincedb\_path = /dev/null

**URL:** <https://discuss.elastic.co/t/index-only-created-if-sincedb-path-dev-null/164657>\
**Category:** Logstash\
**Created:** [January 17, 2019, 3:04pm UTC](https://discuss.elastic.co/t/index-only-created-if-sincedb-path-dev-null/164657 "2019-01-17T15:04:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wholzgruber](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wholzgruber/32/39267_2.png) [@wholzgruber](https://discuss.elastic.co/u/wholzgruber)\
**Post date:** [January 17, 2019, 3:04pm UTC](https://discuss.elastic.co/t/index-only-created-if-sincedb-path-dev-null/164657/1 "2019-01-17T15:04:10Z")

</div>

Dear Community,

I need your help regarding following issue.

I´m parsing a couple of log files from a honeywell system.  
Those 68 log files are quite small (about 600kb until 22mb) and have timestamps from 2014 until now.

I created a custom pattern and everything matched correctly but only the import in logstash has some troubles.

Thats my input config:

```
input {
  file {
type => "honeywell"
path => ["/LOGS/HONEYWELL/*.txt"]
codec => plain {charset => "CP1252" }
#start_position => "beginning"
#sincedb_path => "/dev/null"
     }   
   }
}

```

Now the problem:  
I tried a lot with enabled the start\_position and sincedb\_path to /dev/null because to get the logs into ELK just for testing and then delete them.

With this (start\_position and sincedb\_path to /dev/null) enabled the index has been created immediately and everything has been parsed fine.

Now I deleted all "test-indexes" and disabled those 2 input options because testing has been finished and it would be fine if logstash would know where it stops and also it is not necessary to start every time from the beginning.

Unfortunately with those disabled (or removed) options from the input section no index will be created and I have no clue why.

If I just add those both options again and restart logstash --\> Index were created.

Maybe you have a hint for me.

Regards  
Wilhelm

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 17, 2019, 3:16pm UTC](https://discuss.elastic.co/t/index-only-created-if-sincedb-path-dev-null/164657/2 "2019-01-17T15:16:27Z")

</div>

It sounds like this is working as designed. If you disable the sincedb (setting it to /dev/null) then logstash will read all the files that match the path from the beginning. However, if you have a sincedb and let logstash process the files, then if you restart logstash it will start tailing those files waiting for data to be appended to them. If nothing is appended to them then nothing will be written to the output, and no index will be created.

If these files are not getting data appended then to consume them you need to run logstash once with sincedb set to /dev/null.

---

<div class="post-metadata">

**Author:** ![wholzgruber](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wholzgruber/32/39267_2.png) [@wholzgruber](https://discuss.elastic.co/u/wholzgruber)\
**Post date:** [January 21, 2019, 2:24pm UTC](https://discuss.elastic.co/t/index-only-created-if-sincedb-path-dev-null/164657/3 "2019-01-21T14:24:44Z")

</div>

Thanks thats it!

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 18, 2019, 2:24pm UTC](https://discuss.elastic.co/t/index-only-created-if-sincedb-path-dev-null/164657/4 "2019-02-18T14:24:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
