# Logstash doesn't parse logs if i don't define start\_position

**URL:** <https://discuss.elastic.co/t/logstash-doesnt-parse-logs-if-i-dont-define-start-position/265329>\
**Category:** Logstash\
**Created:** [February 24, 2021, 11:34am UTC](https://discuss.elastic.co/t/logstash-doesnt-parse-logs-if-i-dont-define-start-position/265329 "2021-02-24T11:34:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rknd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rknd/32/103882_2.png) [@rknd](https://discuss.elastic.co/u/rknd)\
**Post date:** [February 24, 2021, 11:34am UTC](https://discuss.elastic.co/t/logstash-doesnt-parse-logs-if-i-dont-define-start-position/265329/1 "2021-02-24T11:34:52Z")

</div>

Below is my code. When I try to run this pipeline. Pipeline is starting but not parsing the logs. I have deleted .sincedb files at (data/plugins/inputs/file).

```auto
input {
    file {
        path => ".../directory/*.log"
    }
}
filter {
    
}
output { 
    stdout{
        codec => rubydebug
    }
}

```

But if I put,

```auto
start_position => "beginning"

```

That works. But everytime it starts from beginning, not where it left. If i put the below code and delete .sincedb files. It still doesn't parse.

```auto
start_position => "end"

```

In the first case that i didn't define start\_position or define start\_position =\> "end". That waits at "Successfully started Logstash API endpoint {:port=\>9601}" But both cases I deleted .sincedb files. How can i make logstash continue where it left ? Thanks for answering

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [February 24, 2021, 11:53am UTC](https://discuss.elastic.co/t/logstash-doesnt-parse-logs-if-i-dont-define-start-position/265329/2 "2021-02-24T11:53:20Z")

</div>

Hi,

> [@rknd](#):
>
> Pipeline is starting but not parsing the logs

The default for `start_position` is `end` so it will only ingest entries that are written after LogStash found the file for the first time. Are you sure there were log entries written after that? Have you tried setting the `log.level`([logstash.yml | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/logstash-settings-file.html)) to debug or trace to find more information why the files are not read?

> [@rknd](#):
>
> But everytime it starts from beginning, not where it left

This should not happen - did you delete the sincedb file? The `start_position` is only used when detecting a new file. After that, the current position is stored in the sincedb file.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![rknd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rknd/32/103882_2.png) [@rknd](https://discuss.elastic.co/u/rknd)\
**Post date:** [February 24, 2021, 1:22pm UTC](https://discuss.elastic.co/t/logstash-doesnt-parse-logs-if-i-dont-define-start-position/265329/3 "2021-02-24T13:22:06Z")

</div>

I think thats the answer.I have checked the box. I didn't get same problem again after your answer. If something could be different I will comment it. Thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2021, 1:22pm UTC](https://discuss.elastic.co/t/logstash-doesnt-parse-logs-if-i-dont-define-start-position/265329/4 "2021-03-24T13:22:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
