# Logstash 7.9.1 have issues in ARM

**URL:** <https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596>\
**Category:** Logstash\
**Created:** [September 23, 2020, 1:04am UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596 "2020-09-23T01:04:00Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![goutham968](https://avatars.discourse-cdn.com/v4/letter/g/f4b2a3/32.png) [@goutham968](https://discuss.elastic.co/u/goutham968)\
**Post date:** [September 23, 2020, 1:04am UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/1 "2020-09-23T01:04:00Z")

</div>

```auto
[2020-09-23T00:58:12,480][ERROR][logstash.javapipeline][main][167820c884ed4020909a7d2491232c40eac5b47a3f91495a85db21bdf02afeca] A plugin had an unrecoverable error. Will restart this plugin.

Pipeline_id:main

Plugin: <LogStash::Inputs::File start_position=>"end", path=>["/applications.logs/*"], codec=><LogStash::Codecs::Multiline pattern=>"^%{MONTHDAY} %{MONTH} %{YEAR} %{TIME}", what=>"previous", id=>"186ada5d-8731-4a2a-97c2-9fbd48d1b5e1", negate=>true, enable_metric=>true, charset=>"UTF-8", multiline_tag=>"multiline", max_lines=>500, max_bytes=>10485760>, exclude=>["*.gz"], id=>"167820c884ed4020909a7d2491232c40eac5b47a3f91495a85db21bdf02afeca", sincedb_path=>"tmp/mysincedbfile", enable_metric=>true, stat_interval=>1.0, discover_interval=>15, sincedb_write_interval=>15.0, delimiter=>"\n", close_older=>3600.0, mode=>"tail", file_completed_action=>"delete", sincedb_clean_after=>1209600.0, file_chunk_size=>32768, file_chunk_count=>140737488355327, file_sort_by=>"last_modified", file_sort_direction=>"asc", exit_after_read=>false, check_archive_validity=>false>

Error: Operation not permitted - No message available

Exception: Errno::EPERM

Stack: org/jruby/RubyFile.java:675:in `chown'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/helper.rb:41:in `write_atomically'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/sincedb_collection.rb:232:in `atomic_write'

org/jruby/RubyMethod.java:131:in `call'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/sincedb_collection.rb:216:in `sincedb_write'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/sincedb_collection.rb:190:in `flush_at_interval'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/sincedb_collection.rb:32:in `request_disk_flush'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/tail_mode/handlers/base.rb:76:in `controlled_read'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/tail_mode/handlers/grow.rb:10:in `block in handle_specifically'

org/jruby/RubyKernel.java:1442:in `loop'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/tail_mode/handlers/grow.rb:7:in `handle_specifically'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/tail_mode/handlers/base.rb:25:in `handle'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/tail_mode/processor.rb:43:in `grow'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/tail_mode/processor.rb:234:in `block in process_active'

org/jruby/RubyArray.java:1809:in `each'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/tail_mode/processor.rb:228:in `process_active'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/tail_mode/processor.rb:75:in `process_all_states'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/watch.rb:67:in `iterate_on_state'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/watch.rb:44:in `subscribe'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/observing_tail.rb:12:in `subscribe'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/logstash/inputs/file.rb:364:in `run'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/logstash-core/lib/logstash/java_pipeline.rb:378:in `inputworker'

/aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/logstash-core/lib/logstash/java_pipeline.rb:369:in `block in start_input'

[2020-09-23T00:58:13,509][INFO][filewatch.observingtail][main][167820c884ed4020909a7d2491232c40eac5b47a3f91495a85db21bdf02afeca] QUIT - closing all files and shutting down.

[2020-09-23T00:58:13,513][INFO][filewatch.observingtail][main][167820c884ed4020909a7d2491232c40eac5b47a3f91495a85db21bdf02afeca] START, creating Discoverer, Watch with file and sincedb collections

```

Can anyone help in resolving this error?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 23, 2020, 1:22pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/2 "2020-09-23T13:22:00Z")

</div>

> [@goutham968](#):
>
> `sincedb_path=>"tmp/mysincedbfile"`

Did you mean that to be /tmp?

```
sincedb_path=>"/tmp/mysincedbfile

```

---

<div class="post-metadata">

**Author:** ![goutham968](https://avatars.discourse-cdn.com/v4/letter/g/f4b2a3/32.png) [@goutham968](https://discuss.elastic.co/u/goutham968)\
**Post date:** [September 24, 2020, 4:02pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/3 "2020-09-24T16:02:07Z")

</div>

Getting this errors, without sincedb\_path

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 24, 2020, 4:05pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/4 "2020-09-24T16:05:26Z")

</div>

If you removed the sincedb\_path option then the file input will log an INFO message saying what sincedb\_path it is using. Verify that the user running logstash has write access to it.

---

<div class="post-metadata">

**Author:** ![goutham968](https://avatars.discourse-cdn.com/v4/letter/g/f4b2a3/32.png) [@goutham968](https://discuss.elastic.co/u/goutham968)\
**Post date:** [September 24, 2020, 4:37pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/5 "2020-09-24T16:37:48Z")

</div>

> [@Badger](#):
>
> If you removed the sincedb\_path option then the file input will log an INFO message saying what sincedb\_path it is using. Verify that the user running logstash has write access to it.

How can change the logstash running user?

After removing sincedb\_path the below log is printed

```auto
[INFO][logstash.inputs.file][main] No sincedb_path set, generating one based on the "path" setting {:sincedb_path=>"/aarch64/logstash/data/plugins/inputs/file/.sincedb_22914414f9f7324c1744d3b8907f8420", 

```

Navigated to the above sincedb\_path and ran ls -ltrh command

> cd /aarch64/logstash/data/plugins/inputs/  
> ls -ltrh

```auto
drwxr-xr-x 2 user1 user1 4.0K Sep 24 16:36 file

```

where as logstash plain

```auto
-rw-rw-r-- 1 user1 qlrm 236K Sep 24 16:36 logstash-plain.log

```

---

<div class="post-metadata">

**Author:** ![goutham968](https://avatars.discourse-cdn.com/v4/letter/g/f4b2a3/32.png) [@goutham968](https://discuss.elastic.co/u/goutham968)\
**Post date:** [September 24, 2020, 4:45pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/6 "2020-09-24T16:45:00Z")

</div>

One more thing. 7.9.1 is working perfectly in \_x86 machines only in arm it's throwing exceptions

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 24, 2020, 5:04pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/7 "2020-09-24T17:04:19Z")

</div>

> [@goutham968](#):
>
> ```auto
> Stack: org/jruby/RubyFile.java:675:in `chown'
> 
> /aarch64/Logstash-agent/Logstash-agent-6624.0-0/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-file-4.2.1/lib/filewatch/helper.rb:41:in `write_atomically'
> 
> ```

This feels like a bug to me. Only privileged processes can change the ownership of a file. Calling chown makes no sense to me. I could understand trying to chgrp (and ignoring a failure) but not chown.

If you have some systems where it works and some where it does not then I would guess the ones where it works are [choosing](https://github.com/logstash-plugins/logstash-input-file/blob/be18de77292f0aafb667debbdef8fe7297065fe3/lib/filewatch/sincedb_collection.rb#L20) to use the non-atomic write function.

The non-atomic write is used on Windows, or if the sincedb\_path points to something that is neither a character nor a block device. Frankly I cannot think of a circumstance where that would occur, but you seem to have hit it.

---

<div class="post-metadata">

**Author:** ![goutham968](https://avatars.discourse-cdn.com/v4/letter/g/f4b2a3/32.png) [@goutham968](https://discuss.elastic.co/u/goutham968)\
**Post date:** [September 25, 2020, 3:39pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/8 "2020-09-25T15:39:55Z")

</div>

Is it possible to disable the sincedb functionality ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 25, 2020, 3:46pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/9 "2020-09-25T15:46:57Z")

</div>

> [@goutham968](#):
>
> Is it possible to disable the sincedb functionality ?

No. The in-memory sincedb is always maintained. You can set

```
sincedb_path => "/dev/null"

```

but it will still write the in-memory db to /dev/null, and it may still choose to use the atomic write for that. In that case it would chown /dev/null

If I were you I would try pointing sincedb\_path at every file system you have available, and see if one of them chooses the non-atomic write. Local disk, RAM disk, NFS mount, /dev/null...

I see you are on aarch64. A user had the [same problem](https://discuss.elastic.co/t/issue-with-logstash-on-aarch64/133008) a couple of years ago. No solution was found. I am wondering if .blockdev? is broken in the ruby implementation.

---

<div class="post-metadata">

**Author:** ![goutham968](https://avatars.discourse-cdn.com/v4/letter/g/f4b2a3/32.png) [@goutham968](https://discuss.elastic.co/u/goutham968)\
**Post date:** [September 25, 2020, 4:13pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/10 "2020-09-25T16:13:13Z")

</div>

Not seeing exceptions after setting `sincedb_path => "/dev/null"`  
Want to check, will it create any other issues if we set the `sincedb_path => "/dev/null"`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 25, 2020, 5:13pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/11 "2020-09-25T17:13:14Z")

</div>

> [@goutham968](#):
>
> will it create any other issues if we set the `sincedb_path => "/dev/null"`

The in-memory sincedb will not be persisted across restarts, so when logstash is restarted it may re-read the files. That may or may not be a problem, depending on your use case.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2020, 5:13pm UTC](https://discuss.elastic.co/t/logstash-7-9-1-have-issues-in-arm/249596/12 "2020-10-23T17:13:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
