# Logstash configuration returns different results

**URL:** <https://discuss.elastic.co/t/logstash-configuration-returns-different-results/190471>\
**Category:** Logstash\
**Created:** [July 15, 2019, 9:03am UTC](https://discuss.elastic.co/t/logstash-configuration-returns-different-results/190471 "2019-07-15T09:03:42Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 16, 2019, 2:49pm UTC](https://discuss.elastic.co/t/logstash-configuration-returns-different-results/190471/11 "2019-07-16T14:49:21Z")

</div>

Are you really just reading one file or are you reading a set of files that is changing over time. I am wondering if you are seeing inode re-use. That's where you read a file and delete it, then create a new file with a different name but the same inode. logstash will start reading the file at an offset equal to the length of the previous file.

If you enable '--log.level trace' then filewatch will log messages about each file that it discovers and the associated sincedb entry.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-configuration-returns-different-results/190471)._
