# Logstash does not do anything with file input but starts successfully

**URL:** <https://discuss.elastic.co/t/logstash-does-not-do-anything-with-file-input-but-starts-successfully/171902>\
**Category:** Logstash\
**Created:** [March 12, 2019, 9:26am UTC](https://discuss.elastic.co/t/logstash-does-not-do-anything-with-file-input-but-starts-successfully/171902 "2019-03-12T09:26:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gegi\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gegi_k/32/38376_2.png) [@Gegi\_K](https://discuss.elastic.co/u/Gegi_K)\
**Post date:** [March 12, 2019, 9:26am UTC](https://discuss.elastic.co/t/logstash-does-not-do-anything-with-file-input-but-starts-successfully/171902/1 "2019-03-12T09:26:31Z")

</div>

Hello All,

I have an issue where I cannot find what is goint on. I have a plain logstash config file:

input {  
file {  
path =\> ["C:\Users\Administrator\Desktop\1.txt"]  
}  
}  
output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
file {  
path =\> "C:\Users\Administrator\Desktop\LogTest\test.log"  
}  
}

Here the contents of the 1.txt will not be read and put to elasticsearch nor into the file.  
I have a FIrewall where it can stream logs to TCP/UDP and if I set the input to the appropriate port then I see the logs from the firewall in the test.log file and in Kibana.

Any help Appreciated.

All modules are on version 6.5.0

Thanks in advance!  
Kind Regards,  
Gergö

---

<div class="post-metadata">

**Author:** ![samyo](https://avatars.discourse-cdn.com/v4/letter/s/e9c0ed/32.png) [@samyo](https://discuss.elastic.co/u/samyo)\
**Post date:** [March 12, 2019, 9:31am UTC](https://discuss.elastic.co/t/logstash-does-not-do-anything-with-file-input-but-starts-successfully/171902/2 "2019-03-12T09:31:55Z")

</div>

Of course it will not read your "1.txt" , cause in your Config file you do not have any filter , to match your "1.txt" log file.

---

<div class="post-metadata">

**Author:** ![Gegi\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gegi_k/32/38376_2.png) [@Gegi\_K](https://discuss.elastic.co/u/Gegi_K)\
**Post date:** [March 12, 2019, 9:34am UTC](https://discuss.elastic.co/t/logstash-does-not-do-anything-with-file-input-but-starts-successfully/171902/3 "2019-03-12T09:34:53Z")

</div>

dear samyo,

thanks for the input, what confuses me is that this:

input {  
tcp {  
port =\> 5002  
}  
udp {  
port =\> 5002  
}  
}  
output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
file {  
path =\> "C:\Users\Administrator\Desktop\LogTest\test.log"  
}  
}

works and the data stream arriving on that port will be added to the test.log file without any filter. but I'll make one and test it.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 12, 2019, 12:54pm UTC](https://discuss.elastic.co/t/logstash-does-not-do-anything-with-file-input-but-starts-successfully/171902/4 "2019-03-12T12:54:20Z")

</div>

Use forward slash, not backslash, in filenames.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [March 12, 2019, 12:56pm UTC](https://discuss.elastic.co/t/logstash-does-not-do-anything-with-file-input-but-starts-successfully/171902/5 "2019-03-12T12:56:49Z")

</div>

If the file `1.txt` exists when you start Logstash it will "tail" from the end (it assumes that the existing contents are old and of no interest). If you want the full file to be **read and then tailed** use `start_position => "beginning"` **BUT** if you want to simply read a "done" file then read up on **read mode** [here](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#_read_mode), [the setting](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-mode) and [this setting also](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-file_completed_action).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2019, 12:56pm UTC](https://discuss.elastic.co/t/logstash-does-not-do-anything-with-file-input-but-starts-successfully/171902/6 "2019-04-09T12:56:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
