# Logstash cannot Index Log Files into Elasticsearch

**URL:** https://discuss.elastic.co/t/logstash-cannot-index-log-files-into-elasticsearch/290408
**Category:** Logstash
**Created:** [November 29, 2021, 8:54am UTC](https://discuss.elastic.co/t/logstash-cannot-index-log-files-into-elasticsearch/290408 "2021-11-29T08:54:05Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Amol](https://avatars.discourse-cdn.com/v4/letter/a/a4c791/32.png) [@Amol](https://discuss.elastic.co/u/Amol)
#### Post date: [November 29, 2021, 8:54am UTC](https://discuss.elastic.co/t/logstash-cannot-index-log-files-into-elasticsearch/290408/1 "2021-11-29T08:54:05Z")

</div>

Could anyone please help, as i have a logstash config file which need to pick log file when it is updated with new logs. once logstash is started it is working fine, but next day the log file is updated but the data is not indexed to elk.

```auto
	file{
		type => "AAM"
		path => ["/usr/aam/R11.2.4/logs/marketing.log"]
		start_position => "beginning"
		sincedb_path => "/home/btuser/Elastic/logstash-7.13.3/data/amm_core"
		mode => "tail"
	}

```

Please help in this.  
Many thanks!

---

<div class="post-metadata">

### Author: ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)
#### Post date: [December 1, 2021, 7:31pm UTC](https://discuss.elastic.co/t/logstash-cannot-index-log-files-into-elasticsearch/290408/2 "2021-12-01T19:31:11Z")

</div>

Have you tried using filebeat instead?  
You may have more success using it instead and then sending the data to a beats input in logstash.

---

<div class="post-metadata">

### Author: ![Amol](https://avatars.discourse-cdn.com/v4/letter/a/a4c791/32.png) [@Amol](https://discuss.elastic.co/u/Amol)
#### Post date: [December 4, 2021, 4:00am UTC](https://discuss.elastic.co/t/logstash-cannot-index-log-files-into-elasticsearch/290408/3 "2021-12-04T04:00:14Z")

</div>

Thank you for your idea.

Yes, working on file beat.

Facing issue when providing multiple paths in filebeat.yml.

this is format:

- "user/folder1/\*.log "
- "user/folder2/\*.log "

is it correct on Linux server?

---

<div class="post-metadata">

### Author: ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)
#### Post date: [December 5, 2021, 12:20pm UTC](https://discuss.elastic.co/t/logstash-cannot-index-log-files-into-elasticsearch/290408/4 "2021-12-05T12:20:06Z")

</div>

Can you post the input of your config file?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 2, 2022, 12:20pm UTC](https://discuss.elastic.co/t/logstash-cannot-index-log-files-into-elasticsearch/290408/5 "2022-01-02T12:20:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
