# Logstash does not start analysing directly

**URL:** <https://discuss.elastic.co/t/logstash-does-not-start-analysing-directly/98247>\
**Category:** Logstash\
**Created:** [August 24, 2017, 2:18pm UTC](https://discuss.elastic.co/t/logstash-does-not-start-analysing-directly/98247 "2017-08-24T14:18:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ThaPoox](https://avatars.discourse-cdn.com/v4/letter/t/9e8a1a/32.png) [@ThaPoox](https://discuss.elastic.co/u/ThaPoox)\
**Post date:** [August 24, 2017, 2:18pm UTC](https://discuss.elastic.co/t/logstash-does-not-start-analysing-directly/98247/1 "2017-08-24T14:18:45Z")

</div>

Hi,  
I have configured Logstash to run on a log file that I have. I have specified the path in the configuration, and I have added some other stuff in the file configuration:

> ```
> input {
> file {
> path => "C:\users\XXX\Downloads\Logstash\server.log.2017-08-01"
> start_position => "beginning"
> codec => multiline {
> pattern => "^(\d{4}-\d{2}-\d{2}\s*)?\d{2}:\d{2}:\d{2},\d{3}" # Time indicates a new line.
> negate => true
> what => previous
> charset => "ASCII"
> }
> }
> }
> 
> ```

The problem is that, when I start logstash and the log file is where it's supposed to be, nothing happens. I have to open the file, and like add a space or something (Just make a modification) and then save the file again to make logstash start analysing my logs.  
Why does this happen? What I want is to make Logstash start directly without me modifying the file.

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 24, 2017, 8:12pm UTC](https://discuss.elastic.co/t/logstash-does-not-start-analysing-directly/98247/2 "2017-08-24T20:12:07Z")

</div>

`start_position => "beginning"` only matters the first time Logstash sees a file. Even with this setting Logstash won't start from the beginning every time. Read about sincedb in the file input documentation.

---

<div class="post-metadata">

**Author:** ![ThaPoox](https://avatars.discourse-cdn.com/v4/letter/t/9e8a1a/32.png) [@ThaPoox](https://discuss.elastic.co/u/ThaPoox)\
**Post date:** [August 25, 2017, 10:17am UTC](https://discuss.elastic.co/t/logstash-does-not-start-analysing-directly/98247/3 "2017-08-25T10:17:39Z")

</div>

Thank you.  
But removing the line didn't solve the problem.  
I launched Logstash, I copied the file into the correct path and Logstash is still on hold.  
Same behavior occurs when I start Logstash with the file already in the correct path.

---

<div class="post-metadata">

**Author:** ![ThaPoox](https://avatars.discourse-cdn.com/v4/letter/t/9e8a1a/32.png) [@ThaPoox](https://discuss.elastic.co/u/ThaPoox)\
**Post date:** [August 25, 2017, 1:15pm UTC](https://discuss.elastic.co/t/logstash-does-not-start-analysing-directly/98247/4 "2017-08-25T13:15:04Z")

</div>

I found the solution. There's two options:  
1- I have added the `sincedb_path` into the configuration  
2- Launched _Logstash_ with a new log file (Renamed the old one)  
3- Before starting _Logstash_ again, I removed the _sincedb_ file that was generated in the path I specified in my previous configuration, and restarted _Logstash_ again. It started analyzing directly.  
So I just had to "reset" it's position.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2017, 1:28pm UTC](https://discuss.elastic.co/t/logstash-does-not-start-analysing-directly/98247/5 "2017-09-22T13:28:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
