# Logstash 2.4 output won't execute until stop

**URL:** <https://discuss.elastic.co/t/logstash-2-4-output-wont-execute-until-stop/65769>\
**Category:** Logstash\
**Created:** [November 11, 2016, 8:24am UTC](https://discuss.elastic.co/t/logstash-2-4-output-wont-execute-until-stop/65769 "2016-11-11T08:24:59Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![yiju](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@yiju](https://discuss.elastic.co/u/yiju)\
**Post date:** [November 11, 2016, 8:24am UTC](https://discuss.elastic.co/t/logstash-2-4-output-wont-execute-until-stop/65769/1 "2016-11-11T08:24:59Z")

</div>

Hi,

I am running logstash 2.4 on ubuntu 14.0.4.

My config file is:  
input {  
file {  
path =\> "/home/spark/_.log"  
start\_position =\> beginning  
codec =\> multiline {  
pattern =\> "(^\d+._)"  
what =\> "previous"  
}  
}  
}  
filter {  
grok {  
match =\> ["path","%{GREEDYDATA}/%{GREEDYDATA:filename}.log"]  
}  
}  
output {  
file {  
path =\> "/home/spark/file"  
}  
azureblob {  
storage\_account\_name =\> "**"  
storage\_access\_key =\> "**"  
azure\_container =\> "test"  
}  
}

I run logstash from command line:  
/opt/logstash/bin/logstash -f /etc/logstash/conf.d/first-pipeline.conf -l /var/log/logstash/logstash.log --verbose  
In this way, I found the output will not actually execute until it receives SIGINT. What's the problem here?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 13, 2016, 7:57am UTC](https://discuss.elastic.co/t/logstash-2-4-output-wont-execute-until-stop/65769/2 "2016-11-13T07:57:14Z")

</div>

Given you are using multiline it's probably waiting for a CRLF so that it know's the pattern has ended.

---

<div class="post-metadata">

**Author:** ![yiju](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@yiju](https://discuss.elastic.co/u/yiju)\
**Post date:** [November 13, 2016, 12:56pm UTC](https://discuss.elastic.co/t/logstash-2-4-output-wont-execute-until-stop/65769/3 "2016-11-13T12:56:44Z")

</div>

I putted an enter character at the end of the file, it's still not work. BTW, I can see the position of the files are written in since\_db file. It means logstash already got the input, but for some reason it doesn't handle it in the output. I guess it has bugs in multiline codec or logstash?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 13, 2016, 10:03pm UTC](https://discuss.elastic.co/t/logstash-2-4-output-wont-execute-until-stop/65769/4 "2016-11-13T22:03:47Z")

</div>

Just because something doesn't work the way you expect doesn't mean there are bugs.

> [@yiju](#):
>
> BTW, I can see the position of the files are written in since\_db file. It means logstash already got the input, but for some reason it doesn't handle it in the output.

Have a read of [File input plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#_tracking_of_current_position_in_watched_files)

---

<div class="post-metadata">

**Author:** ![yiju](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@yiju](https://discuss.elastic.co/u/yiju)\
**Post date:** [November 14, 2016, 1:42am UTC](https://discuss.elastic.co/t/logstash-2-4-output-wont-execute-until-stop/65769/5 "2016-11-14T01:42:34Z")

</div>

I have read the file document, but I can't find the solution of my problem. I set the input start\_position to beginning, the last modify time of the file not exceed ignore\_older value and it has LF in the end. I believe multiline codec is able to pass the input to output, or it will be meaningless. How can I make it happen?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 14, 2016, 4:04am UTC](https://discuss.elastic.co/t/logstash-2-4-output-wont-execute-until-stop/65769/6 "2016-11-14T04:04:09Z")

</div>

Did you try removing the sincedb?

---

<div class="post-metadata">

**Author:** ![yiju](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@yiju](https://discuss.elastic.co/u/yiju)\
**Post date:** [November 15, 2016, 8:40am UTC](https://discuss.elastic.co/t/logstash-2-4-output-wont-execute-until-stop/65769/7 "2016-11-15T08:40:28Z")

</div>

I found a solution of this issue. Enable auto flush by set a small value to auto\_flush\_interval in multiline codec. It will push events to output periodically.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2016, 8:41am UTC](https://discuss.elastic.co/t/logstash-2-4-output-wont-execute-until-stop/65769/8 "2016-12-13T08:41:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
