# Logstash doesn't store in elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-doesnt-store-in-elasticsearch/124317>\
**Category:** Logstash\
**Created:** [March 16, 2018, 2:53pm UTC](https://discuss.elastic.co/t/logstash-doesnt-store-in-elasticsearch/124317 "2018-03-16T14:53:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [March 16, 2018, 2:53pm UTC](https://discuss.elastic.co/t/logstash-doesnt-store-in-elasticsearch/124317/1 "2018-03-16T14:53:59Z")

</div>

I'm trying to do a script to load an apache file log.

The configuration files is correct because I started different time to load this file with the command logstash -f \<path\_conf\_file\> and I viewed the dot on the screen.

I interrupted different time by CTRL+C che process and killed it other time. Now at the restart of the server ELK with logstash too I don't see dot on the screen and the

[http://localhost:9200/scenario1-\*/\_count](http://localhost:9200/scenario1-*/_count)

is alway to 0.

I check the log of elasticsearch (/var/log/elasticsearch/elasticsearch.log) and logstash (/var/log/logstash/logstash-plain.log) too but I don't found nothing.

I check the cluster too with [http://localhost:9200/\_cluster/health?pretty=true](http://localhost:9200/_cluster/health?pretty=true) and I see empty sherd.

How could I solve this problem?

Thank you in advance  
Franco

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [March 16, 2018, 10:46pm UTC](https://discuss.elastic.co/t/logstash-doesnt-store-in-elasticsearch/124317/2 "2018-03-16T22:46:26Z")

</div>

I may have found the problem, it could be due to the sincedb which contains the information of the file already processed. where do I find the synchedb configuration on logstash 6.2.1?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 17, 2018, 4:02am UTC](https://discuss.elastic.co/t/logstash-doesnt-store-in-elasticsearch/124317/3 "2018-03-17T04:02:06Z")

</div>

[`sincedb_path`](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-sincedb_path) is configurable, but it's default depends on your Logstash settings for `path.data`; you can either find and delete it, or just specify a path where a new sincedb can be created.

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [March 17, 2018, 7:55am UTC](https://discuss.elastic.co/t/logstash-doesnt-store-in-elasticsearch/124317/4 "2018-03-17T07:55:43Z")

</div>

My path.data is  
path.data: /var/lib/logstash  
In this folder I don't found sincedb,  
I have this result  
franco@serverElk:/var/lib/logstash/plugins/inputs/file$ ls -li/var/lib/logstash/plugins/inputs/file$ ls -li  
total 0  
what is the name? Where is stored?  
My Os is debian server 9.0 and logstash 6.2.1.  
Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2018, 7:55am UTC](https://discuss.elastic.co/t/logstash-doesnt-store-in-elasticsearch/124317/5 "2018-04-14T07:55:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
