# Logstach can't read input file

**URL:** <https://discuss.elastic.co/t/logstach-cant-read-input-file/62364>\
**Category:** Logstash\
**Created:** [October 6, 2016, 11:12am UTC](https://discuss.elastic.co/t/logstach-cant-read-input-file/62364 "2016-10-06T11:12:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AlexDM](https://avatars.discourse-cdn.com/v4/letter/a/edb3f5/32.png) [@AlexDM](https://discuss.elastic.co/u/AlexDM)\
**Post date:** [October 6, 2016, 11:12am UTC](https://discuss.elastic.co/t/logstach-cant-read-input-file/62364/1 "2016-10-06T11:12:39Z")

</div>

I'm so sorry, still start to learn and install ELK.  
input { stdin { } } is working and I can see resault in Kibana. When I try to use file in input path, logstach can't read log file.

Logstach 2.4.0

my simple conf from Logstach documentations:

input {  
file {  
path =\> "/var/log/http.log"  
sincedb\_path =\> "/dev/null"  
}  
}  
filter {  
grok {  
match =\> { "message" =\> "%{IP:client} %{WORD:method} %{URIPATHPARAM:request} %{NUMBER:bytes} %{NUMBER:duration}" }  
}  
}  
output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

Answer from Logstach:  
-- [slog@smt06hpsa004 logstash-2.4.0]$ bin/logstash -f ./conf/example0.conf  
-- Settings: Default pipeline workers: 4  
-- Pipeline main started

...nothing more

The same conf with "input { stdin { } }" correctly work.

1. File and path:  
[slog@smt06hpsa004 slog]$ cat /var/log/http.log  
55.3.244.1 GET /index.html 15824 0.043 [slog@smt06hpsa004 slog]$
2. Priveleg:  
-rwxrwxrwx. 1 root root 38 Oct 6 10:18 http.log

I tried to change conf without sincedb\_path =\> "/dev/null" but the same result  
Help me please.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 6, 2016, 11:57am UTC](https://discuss.elastic.co/t/logstach-cant-read-input-file/62364/2 "2016-10-06T11:57:15Z")

</div>

Reset the permissions of the file to whatever it was. It shouldn't be world-writable or executable for anyone. Check the permissions of /var/log. It needs to be readable and executable for the logstash user.

If the logfile is older than 24 hours you also need to adjust the file input's `ignore_older` option.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:35am UTC](https://discuss.elastic.co/t/logstach-cant-read-input-file/62364/3 "2017-07-06T04:35:25Z")

</div>


