# Logstash 2.4 eventually (intermittent issue) read partial log lines

**URL:** https://discuss.elastic.co/t/logstash-2-4-eventually-intermittent-issue-read-partial-log-lines/65525
**Category:** Logstash
**Created:** [November 9, 2016, 4:05pm UTC](https://discuss.elastic.co/t/logstash-2-4-eventually-intermittent-issue-read-partial-log-lines/65525 "2016-11-09T16:05:33Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Andre\_Buzzo](https://avatars.discourse-cdn.com/v4/letter/a/46a35a/32.png) [@Andre\_Buzzo](https://discuss.elastic.co/u/Andre_Buzzo)
#### Post date: [November 9, 2016, 4:05pm UTC](https://discuss.elastic.co/t/logstash-2-4-eventually-intermittent-issue-read-partial-log-lines/65525/1 "2016-11-09T16:05:33Z")

</div>

I guess this is an issue but I can't find anything about it. Unfortunately I don't have steps to reproduce it, happens eventually across different prod servers in different log files a few times a day.

I can see that it is aways a partial read of a line, somewhere from the middle to the end. It is never from the beginning to somewhere in the middle. The line sometimes is the first line of a rotated log, sometimes in the middle of the log. Mostly common the line is read empty or with a few characters.

Did anyone had a problem like this? Can you point me any source of a know bug or fix?  
Bellow are all the details that I could collect from logstash. All sensitive data was removed.

- Version: Logstash 2.4
- Operating System: Red Hat 4.4.6-3
- Config File:

input {

file {  
type =\> "myservice"  
path =\> “/root/MyService.\*”  
start\_position =\> "beginning"  
codec =\> multiline {  
pattern =\> "^%{LOGLEVEL}"  
negate =\> true  
what =\> "previous"  
}  
sincedb\_path =\> “/root/application.db"  
}

….  
}

filter{

if [type] == "myservice" {  
grok {  
patterns\_dir =\> “/root/logstash\_patterns"  
match =\> ["message", "%{LOGLEVEL:severity}%{SPACE}%{LOG4JTIMESTAMP:logDate}%{SPACE}%{GREEDYDATA:category}%{SPACE}|%{GREEDYDATA:message}"]  
overwrite =\> ["message"]  
}

…

}  
output {  
server\_es {  
hosts =\> ["{{ host }}"]  
region =\> "{{ region }}"  
index =\> "{{ index }}"  
}  
}

- Log line  
...  
DEBUG 09 Nov 2016 09:20:44,276 com.service.ui.aop.MetricsInterceptor |Intercepting bean: action:com.service.metrics.RateMetricsFactory pjp:execution(RateMetrics com.service.metrics.RateMetricsFactory.newRateMetrics(String))  
...

- Logstash log in debug mode:

{:timestamp=\>"2016-11-09T09:20:53.109000+0000", :message=\>"\_discover\_file: /root/MyService.\*: new: /root/MyService.2016-11-09-09 (exclude is [])", :level=\>:debug, :file=\>"filewatch/watch.rb", :line=\>"141", :method=\>"\_discover\_file"}

{:timestamp=\>"2016-11-09T09:20:54.110000+0000", :message=\>"\_open\_file: /root/MyService.2016-11-09-09: opening", :level=\>:debug, :file=\>"filewatch/tail.rb", :line=\>"118", :method=\>"\_open\_file"}

{:timestamp=\>"2016-11-09T09:20:54.110000+0000", :message=\>"/root/MyService.2016-11-09-09: sincedb last value 3628, cur size 4068", :level=\>:debug, :file=\>"filewatch/tail.rb", :line=\>"145", :method=\>"\_open\_file"}

{:timestamp=\>"2016-11-09T09:20:54.110000+0000", :message=\>"/root/MyService.2016-11-09-09: sincedb: seeking to 3628", :level=\>:debug, :file=\>"filewatch/tail.rb", :line=\>"147", :method=\>"\_open\_file"}

{:timestamp=\>"2016-11-09T09:20:54.111000+0000", :message=\>"Received line", :path=\>"/root/MyService.2016-11-09-09", :text=\>"r |Intercepting bean: action:com.service.metrics.RateMetricsFactory pjp:execution(RateMetrics com.service.metrics.RateMetricsFactory.newRateMetrics(String))", :level=\>:debug, :file=\>"logstash/inputs/file.rb", :line=\>"207", :method=\>"log\_line\_received"}

{:timestamp=\>"2016-11-09T09:20:54.111000+0000", :message=\>"Multiline", :pattern=\>"^%{LOGLEVEL}", :text=\>"r |Intercepting bean: action:com.service.metrics.RateMetricsFactory pjp:execution(RateMetrics com.service.metrics.RateMetricsFactory.newRateMetrics(String))", :match=\>true, :negate=\>true, :level=\>:debug, :file=\>"logstash/codecs/multiline.rb", :line=\>"168", :method=\>"decode"}

{:timestamp=\>"2016-11-09T09:20:54.113000+0000", :message=\>"filter received", :event=\>{"@timestamp"=\>"2016-11-09T09:20:54.112Z", "message"=\>"r |Intercepting bean: action:com.service.metrics.RateMetricsFactory pjp:execution(RateMetrics com.service.metrics.RateMetricsFactory.newRateMetrics(String))", "@version"=\>"1", "host"=\>"[myhost.com](http://myhost.com)", "path"=\>"/root/MyService.2016-11-09-09", "type"=\>"myservice"}, :level=\>:debug, :file=\>"(eval)", :line=\>"129", :method=\>"filter\_func"}

{:timestamp=\>"2016-11-09T09:20:54.113000+0000", :message=\>"Running grok filter", :event=\>  
... (big line here) ... }

{:timestamp=\>"2016-11-09T09:20:54.115000+0000", :message=\>"output received", :event=\>{"@timestamp"=\>"2016-11-09T09:20:54.112Z", "message"=\>"r |Intercepting bean: action:com.service.metrics.RateMetricsFactory pjp:execution(RateMetrics com.service.metrics.RateMetricsFactory.newRateMetrics(String))", "@version"=\>"1", "host"=\>"[myhost.com](http://myhost.com)", "path"=\>"/root/MyService.2016-11-09-09", "type"=\>"myservice", "tags"=\>["\_grokparsefailure"]}, :level=\>:debug, :file=\>"(eval)", :line=\>"137", :method=\>"output\_func"}root/

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 7, 2016, 4:06pm UTC](https://discuss.elastic.co/t/logstash-2-4-eventually-intermittent-issue-read-partial-log-lines/65525/2 "2016-12-07T16:06:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
