# Logstash does not read Files

**URL:** <https://discuss.elastic.co/t/logstash-does-not-read-files/125141>\
**Category:** Logstash\
**Created:** [March 22, 2018, 8:49am UTC](https://discuss.elastic.co/t/logstash-does-not-read-files/125141 "2018-03-22T08:49:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![YannickWeber](https://avatars.discourse-cdn.com/v4/letter/y/c57346/32.png) [@YannickWeber](https://discuss.elastic.co/u/YannickWeber)\
**Post date:** [March 22, 2018, 8:49am UTC](https://discuss.elastic.co/t/logstash-does-not-read-files/125141/1 "2018-03-22T08:49:44Z")

</div>

Hello,

I am new to Logstash and I am trying to read my logfiles. While I can parse single logs using stdin logstash does not seem to scan the configured files.

my .config file looks like this:

input {  
file {  
path =\> ["D:\Logs\*.txt"]  
start\_position =\> "beginning"  
ignore\_older =\> 3600  
}  
}  
filter {  
grok {  
match =\> { "message" =\> "\A%{BIND9\_TIMESTAMP:dns\_timestamp} client \<%{BACULA\_HOST:IntOrExt}\_%{USER:User}\>#%{INT:Int}: query: %{HOSTNAME:hostname} %{CRON\_ACTION:Action}+"}  
}  
date {  
match =\> ["dns\_timestamp", "dd-MMM-yyyy HH:mm:ss.SSS"]  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "wabern"  
}  
stdout {  
}  
}

---

<div class="post-metadata">

**Author:** ![xmatt](https://avatars.discourse-cdn.com/v4/letter/x/5daacb/32.png) [@xmatt](https://discuss.elastic.co/u/xmatt)\
**Post date:** [March 22, 2018, 9:44am UTC](https://discuss.elastic.co/t/logstash-does-not-read-files/125141/2 "2018-03-22T09:44:35Z")

</div>

I'd suggest using Filebeat for this which will follow log files perfectly, including ones that are automatically rolled over.

Best of luck!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2018, 10:23am UTC](https://discuss.elastic.co/t/logstash-does-not-read-files/125141/3 "2018-03-22T10:23:54Z")

</div>

> path =\> ["D:\Logs\*.txt"]

I think you need to use forward slashes instead of backslashes.

---

<div class="post-metadata">

**Author:** ![YannickWeber](https://avatars.discourse-cdn.com/v4/letter/y/c57346/32.png) [@YannickWeber](https://discuss.elastic.co/u/YannickWeber)\
**Post date:** [March 23, 2018, 8:45am UTC](https://discuss.elastic.co/t/logstash-does-not-read-files/125141/4 "2018-03-23T08:45:08Z")

</div>

Thank you very much, this did the trick.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2018, 8:45am UTC](https://discuss.elastic.co/t/logstash-does-not-read-files/125141/5 "2018-04-20T08:45:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
