# Logstash behaviour is inconsistent

**URL:** <https://discuss.elastic.co/t/logstash-behaviour-is-inconsistent/34965>\
**Category:** Logstash\
**Created:** [November 18, 2015, 4:13pm UTC](https://discuss.elastic.co/t/logstash-behaviour-is-inconsistent/34965 "2015-11-18T16:13:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![vijay\_dhaks](https://avatars.discourse-cdn.com/v4/letter/v/258eb7/32.png) [@vijay\_dhaks](https://discuss.elastic.co/u/vijay_dhaks)\
**Post date:** [November 18, 2015, 4:13pm UTC](https://discuss.elastic.co/t/logstash-behaviour-is-inconsistent/34965/1 "2015-11-18T16:13:38Z")

</div>

Hi,

I have recently started learning logstash by following the tutorials. Currently I am facing a weird problem.  
I have my config as below,

```
input {
    file {
        path => "/home/test/project/logstash_sample_data/logstash-tutorial.log"
        start_position => beginning
    }
}
filter {
    grok {
        match => { "message" => "%{COMBINEDAPACHELOG}"}
    }
    geoip {
        source => "clientip"
    }
}
output {
    file {
        path => "/home/test/project/logstash_sample_data/output.txt"
    }
}

```

Commnd to run:  
`./logstash -f ../../logstash_conf/first-pipeline.conf`  
First time when I run with this config, I got the output in output.txt. But after clearing output.txt, once again if i try, I dont get any output. I could not exactly guess the pattern that when it works correctly or when its not. I have been struggling with this problem for the past 3 days.  
Do we need to clear any cache or any setting before processing the same input file again and again ? I have no clue at the moment. Could someone help me out to solve this issue ?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 18, 2015, 4:38pm UTC](https://discuss.elastic.co/t/logstash-behaviour-is-inconsistent/34965/2 "2015-11-18T16:38:28Z")

</div>

With the file input, you're likely hitting the sincedb, which remembers the last position in the file that was read.

Even with `start_position => beginning`, the sincedb will prevent re-reading the file from the beginning on the next run. It will try to resume where it left off.

If you plan on re-reading the same file, I suggest specifying the sincedb path manually and then deleting that file between runs.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 18, 2015, 8:17pm UTC](https://discuss.elastic.co/t/logstash-behaviour-is-inconsistent/34965/3 "2015-11-18T20:17:05Z")

</div>

Another alternative it to cat/type the file and pipe it into a stdin inout.

---

<div class="post-metadata">

**Author:** ![vijay\_dhaks](https://avatars.discourse-cdn.com/v4/letter/v/258eb7/32.png) [@vijay\_dhaks](https://discuss.elastic.co/u/vijay_dhaks)\
**Post date:** [November 30, 2015, 2:00pm UTC](https://discuss.elastic.co/t/logstash-behaviour-is-inconsistent/34965/4 "2015-11-30T14:00:45Z")

</div>

Thanks @theuntergeek. Your technique worked for me. Now I clear the since\_db file everytime and I see the output.

---

<div class="post-metadata">

**Author:** ![vijay\_dhaks](https://avatars.discourse-cdn.com/v4/letter/v/258eb7/32.png) [@vijay\_dhaks](https://discuss.elastic.co/u/vijay_dhaks)\
**Post date:** [November 30, 2015, 2:01pm UTC](https://discuss.elastic.co/t/logstash-behaviour-is-inconsistent/34965/5 "2015-11-30T14:01:32Z")

</div>

thanks @warkolm. Will try this method.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:20am UTC](https://discuss.elastic.co/t/logstash-behaviour-is-inconsistent/34965/6 "2017-07-06T05:20:48Z")

</div>


