# Logstash 2.2.2 not working on windows 7

**URL:** <https://discuss.elastic.co/t/logstash-2-2-2-not-working-on-windows-7/43716>\
**Category:** Logstash\
**Created:** [March 7, 2016, 11:16pm UTC](https://discuss.elastic.co/t/logstash-2-2-2-not-working-on-windows-7/43716 "2016-03-07T23:16:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanaya](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@sanaya](https://discuss.elastic.co/u/sanaya)\
**Post date:** [March 7, 2016, 11:16pm UTC](https://discuss.elastic.co/t/logstash-2-2-2-not-working-on-windows-7/43716/1 "2016-03-07T23:16:30Z")

</div>

I've been trying to upgrade to the latest versions of ELK on a windows box to no avail.  
Testing my configurations one piece at a time starting with logstash.  
Current version of logstash that works with my configurations is 1.5.3

I downloaded logstash 2.2.2 zip for windows from the download page.  
I copied my configurations over from 1.5.3 logstash directory. I have a config directory with the configurations broken out into different files: 1 file for inputs, 1 file for each filter, and 1 file for outputs.

I setup the input to read a test file, and the output to write to a file so I can verify things look correct, but it appears that logstash isn't even reading the input file. After logstash starts up I see no activity in my output directory until I hit CNTRL-C to stop logstash then the since\_db file is created with no data in the file.

**Here is my input configuration:**  
input {  
file {  
path =\> "D:/temp/log\_stash/testfile.txt"  
type =\> "TG"  
start\_position =\> "beginning"  
sincedb\_path =\> "D:/temp/log\_stash/tg\_sincedb"  
}  
}

**Output configuration:**  
output {  
if [type] == "TG" {  
file {  
path =\> "D:/temp/log\_stash/tg\_results.txt"  
flush\_interval =\> 0  
}  
}  
}

**Filter for my custom log file:**  
filter {  
if [type] == "TG" {

```
  mutate {
     gsub => ["message", "\r", ""] 
  }

  grok {
     match => ["message", "\[%{TIMESTAMP_ISO8601:LogTimestamp}\] %{WORD:Status}-%{GREEDYDATA:RepId}, %{GREEDYDATA:Test}, Session:%{GREEDYDATA:Session}, package id: %{UUID:ClientPackageIdentifier}, %{TIMESTAMP_ISO8601:SentAt}, (?<ClientIdentifier>\S*)",
	   "message", "\[%{TIMESTAMP_ISO8601:LogTimestamp}\] %{WORD:Status}-%{GREEDYDATA:RepId}, Session:%{GREEDYDATA:Session}, package id: %{UUID:ClientPackageIdentifier}, %{TIMESTAMP_ISO8601:ReceivedAt}, Sequence:%{NUMBER:Sequence}, RequestRetries:%{NUMBER:RequestRetries}, ResponseRetries:%{NUMBER:ResponseRetries}, %{WORD:ResponseReason}, %{WORD:ErrorCode}, Occured at: %{TIMESTAMP_ISO8601:OccuredAt}, SSI:%{POSINT:SSI}, ClientId: %{GREEDYDATA:ClientIdentifier}, RadioType: %{GREEDYDATA:RadioType}",
	   "message", "\[%{TIMESTAMP_ISO8601:LogTimestamp}\] Response-%{DATA:Status}, Radio id:%{GREEDYDATA:RepId}, Package id:(?<ClientIdentifier>\S*)"
	 ]
	 
	 add_tag => ["%{ClientIdentifier}"]
	 add_tag => ["%{Status}"]
    }	
  
    date {
        match => ["LogTimestamp", "YYYY-MM-dd HH:mm:ss.SSS"]
    }

    #if "_grokparsefailure" in [tags] {
    # drop { }
    #}	
}

elapsed {
   start_tag => "Sending"
   end_tag => "Response"
   unique_id_field => "ClientPackageIdentifier"
   timeout => 61
   new_event_on_match => false
}

```

}

**Command line output:**  
D:\elk\logstash-2.2.2\bin\>logstash.bat agent -f ../configs  
io/console not supported; tty will not be manipulated  
Settings: Default pipeline workers: 8  
←[33mDefaulting pipeline worker threads to 1 because there are some filters that might not work with multiple worker th  
eads {:count\_was=\>8, :filters=\>["multiline", "multiline", "multiline", "multiline"], :level=\>:warn}←[0m  
Logstash startup completed  
^←[33mSIGINT received. Shutting down the pipeline. {:level=\>:warn}←[0mC  
Terminate batch job (Y/N)? Logstash shutdown completed  
y

**Sample log lines:**  
[2016-01-06 21:30:56.620] Sending-012372000003227, Class 1 Poll, Session:0, package id: c4916ca2-cbfb-446a-91d8-53b11eeb1b9e, 2016-01-06 21:30:56.600, WIN7X64-VM-LAB-TG-20160106-213038  
[2016-01-06 21:31:01.334] Response-012372000003227, Session:0, package id: c4916ca2-cbfb-446a-91d8-53b11eeb1b9e, 2016-01-06 21:31:01.325, Sequence:37, RequestRetries:0, ResponseRetries:0, NORMAL, NO\_ERROR, Occured at: 2016-01-06 21:30:59.155, SSI:94, ClientId: WIN7X64-VM-LAB-TG-20160106-213038, RadioType: cellular  
[2016-01-06 21:31:01.339] RTT-012372000003227, Session:0, 2016-01-06 21:31:01.325, 4.7244

Any help would be appreciated.

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 8, 2016, 6:58am UTC](https://discuss.elastic.co/t/logstash-2-2-2-not-working-on-windows-7/43716/2 "2016-03-08T06:58:36Z")

</div>

Perhaps the input file is old than one day? See the [`ignore_older` option](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-ignore_older).

---

<div class="post-metadata">

**Author:** ![sanaya](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@sanaya](https://discuss.elastic.co/u/sanaya)\
**Post date:** [March 8, 2016, 2:06pm UTC](https://discuss.elastic.co/t/logstash-2-2-2-not-working-on-windows-7/43716/3 "2016-03-08T14:06:23Z")

</div>

yep, that was it.  
Set that value to a year, and the file was processed as expected.

I was searching all over the change logs and breaking changes; completely missed that setting.

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:07am UTC](https://discuss.elastic.co/t/logstash-2-2-2-not-working-on-windows-7/43716/4 "2017-07-06T05:07:59Z")

</div>


