# Logstash cloudwatch\_logs input plugin has sincedb\_path issues

**URL:** <https://discuss.elastic.co/t/logstash-cloudwatch-logs-input-plugin-has-sincedb-path-issues/187679>\
**Category:** Logstash\
**Created:** [June 26, 2019, 9:05pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-logs-input-plugin-has-sincedb-path-issues/187679 "2019-06-26T21:05:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [June 26, 2019, 9:05pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-logs-input-plugin-has-sincedb-path-issues/187679/1 "2019-06-26T21:05:36Z")

</div>

According to lukewaite: [Cloudwatch\_logs input plugin](https://github.com/lukewaite/logstash-input-cloudwatch-logs) the default sincedb\_path for cloudwatch\_logs is `$HOME/.sincedb*"`. However, when I use this, I get some logs filtered, and I can see them being processed using the rubydebug, but then I get an error that keeps repeating, and no more logs are read from AWS Cloudwatch after.

**Error:**

```
[2019-06-26T20:47:03,411][ERROR][logstash.javapipeline] A plugin had an unrecoverable error. Will restart this plugin.
  Pipeline_id:main
  Plugin: <LogStash::Inputs::CloudWatch_Logs start_position=>"beginning", log_group=>["/aws/lambda/", "/code/", "/aws/batch/", "/aws-glue/crawlers"], interval=>5, id=>"e6c72228bd2ed838a1dfab46e284edf6defac1cbf394491197fac15921ab0b6a", region=>"us-west-2", type=>"Cloudwatch", sincedb_path=>"$HOME/.sincedb*", log_group_prefix=>true, enable_metric=>true, codec=><LogStash::Codecs::Plain id=>"plain_18a099a3-d8d3-4552-a429-f51f299088c1", enable_metric=>true, charset=>"UTF-8">, role_session_name=>"logstash">
  Error: No such file or directory - $HOME/.sincedb*
  Exception: Errno::ENOENT
  Stack: org/jruby/RubyIO.java:1236:in `sysopen'
org/jruby/RubyIO.java:3796:in `write'
/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-cloudwatch_logs-1.0.3/lib/logstash/inputs/cloudwatch_logs.rb:250:in `_sincedb_write'
/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-cloudwatch_logs-1.0.3/lib/logstash/inputs/cloudwatch_logs.rb:198:in `block in process_group'
org/jruby/RubyKernel.java:1425:in `loop'
/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-cloudwatch_logs-1.0.3/lib/logstash/inputs/cloudwatch_logs.rb:182:in `process_group'
/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-cloudwatch_logs-1.0.3/lib/logstash/inputs/cloudwatch_logs.rb:123:in `block in run'
org/jruby/RubyArray.java:1792:in `each'
/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-cloudwatch_logs-1.0.3/lib/logstash/inputs/cloudwatch_logs.rb:121:in `run'
/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:297:in `inputworker'
/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:290:in `block in start_input'

```

**Logstash configuration:**

```
input{
  cloudwatch_logs {
    log_group_prefix => true
    log_group => ["/aws/lambda/", "/code/", "/aws/batch/", "/aws-glue/crawlers"]
    region => "${AWS_REGION}"
    type => "Cloudwatch"
    interval => 5
    start_position => "beginning"
    sincedb_path => "$HOME/.sincedb*"
  }
}

filter{
  if [type] == "Cloudwatch" {
    if [event] != "" {
      mutate{
        add_field => {
          "[@metadata][tags]" => ["Cloudwatch"]
          "key" => "%{[Records][object][key]}"
        }
      }

      date {
        match => ["log-datestamp", "YYYY-MM-dd HH:mm:ss,SSS"]
        target => "@timestamp"
        timezone => "UTC"
      }       
      date {
        match => ["log-datestamp", "YY-MM-dd HH:mm:ss,SSS"]
        target => "@timestamp"
        timezone => "UTC"
      }    
      date {
        match => ["log-datestamp", "ISO8601"]
        target => "@timestamp"
        timezone => "UTC"
      }    
      date {
        match => ["log-epoch", "UNIX"]
        target => "@timestamp"
        timezone => "UTC"
      }    
      date {
        match => ["log-epoch", "UNIX_MS"]
        target => "@timestamp"
        timezone => "UTC"
      }
    }
  }
}

output{
  if [type] == "Cloudwatch" {
    elasticsearch{
      hosts => ["${ES_HOST}"]
      user => "${USERNAME}"
      password => "${PASSWORD}"
      index => "${CW_INDEX}"
      document_id => "_cloudwatch"
    }
  }

  stdout { 
    codec => rubydebug {
      metadata => true
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2019, 9:20pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-logs-input-plugin-has-sincedb-path-issues/187679/2 "2019-06-26T21:20:47Z")

</div>

> [@EZprogramming](#):
>
> sincedb\_path =\> "$HOME/.sincedb\*"

That will not work. If you want the default value then do not specify a value, the [code](https://github.com/lukewaite/logstash-input-cloudwatch-logs/blob/bde0fd896418c5861d56639c2d5ae47abc0cb725/lib/logstash/inputs/cloudwatch_logs.rb#L67) will then generate a filename and create it under path.data.

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [June 26, 2019, 9:22pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-logs-input-plugin-has-sincedb-path-issues/187679/3 "2019-06-26T21:22:30Z")

</div>

The default is dev/null. The problem is, next time I run my program again, it keeps reading the logs that have been read, so I end up with duplicates.

Also, just to clarify, I am not using his code, but lukewaite has similar input plugin as I do.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2019, 9:31pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-logs-input-plugin-has-sincedb-path-issues/187679/4 "2019-06-26T21:31:46Z")

</div>

> [@EZprogramming](#):
>
> The default is dev/null.

That's not true if you are running the code I linked to.

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [June 26, 2019, 9:34pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-logs-input-plugin-has-sincedb-path-issues/187679/5 "2019-06-26T21:34:00Z")

</div>

@Badger, all I have in my directory is this:

```
kourosh:~/Desktop/dashboard_project$ ls
  Dockerfile pipeline
kourosh:~/Desktop/dashboard_project$ ls pipeline/
  logstash.conf

```

I am not using lukewaite code at all. Do you think that is why it might be the problem?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2019, 9:34pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-logs-input-plugin-has-sincedb-path-issues/187679/6 "2019-07-24T21:34:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
