# Logstash elasticsearch output problem

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-output-problem/234577>\
**Category:** Logstash\
**Created:** [May 27, 2020, 3:49pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-problem/234577 "2020-05-27T15:49:22Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Rasoul\_Ahmadi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rasoul_ahmadi/32/68520_2.png) [@Rasoul\_Ahmadi](https://discuss.elastic.co/u/Rasoul_Ahmadi)\
**Post date:** [May 27, 2020, 8:33pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-problem/234577/5 "2020-05-27T20:33:47Z")

</div>

thanks aggain  
but it seems to me logstash is actually reading my config file correctly

```auto
[2020-05-28T00:54:28,670][DEBUG][logstash.config.source.local.configpathloader] Reading config file {:config_file=>"/etc/logstash/conf.d/30-filter-nginx.conf"}
[2020-05-28T00:54:28,728][DEBUG][logstash.agent] Converging pipelines state {:actions_count=>1}
[2020-05-28T00:54:28,746][DEBUG][logstash.agent] Executing action {:action=>LogStash::PipelineAction::Create/pipeline_id:main}
[2020-05-28T00:54:30,260][DEBUG][org.logstash.secret.store.SecretStoreFactory] Attempting to exists or secret store with implementation: org.logstash.secret.store.backend.JavaKeyStore
[2020-05-28T00:54:31,539][DEBUG][org.reflections.Reflections] going to scan these urls:
jar:file:/usr/share/logstash/logstash-core/lib/jars/logstash-core.jar!/
[2020-05-28T00:54:31,588][INFO][org.reflections.Reflections] Reflections took 45 ms to scan 1 urls, producing 21 keys and 41 values

```

and this is looped

```auto
[2020-05-28T01:05:21,091][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
[2020-05-28T01:05:25,687][DEBUG][org.logstash.execution.PeriodicFlush][main] Pushing flush onto pipeline.
[2020-05-28T01:05:25,807][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=>"ParNew"}
[2020-05-28T01:05:25,809][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=>"ConcurrentMarkSweep"}
[2020-05-28T01:05:30,687][DEBUG][org.logstash.execution.PeriodicFlush][main] Pushing flush onto pipeline.
[2020-05-28T01:05:30,821][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=>"ParNew"}
[2020-05-28T01:05:30,830][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=>"ConcurrentMarkSweep"}

```

and this didn't work  
I have tried both /dev/null and nul

> [@Logstash Issue: Glob did not work, collector name {:name=\>"ConcurrentMarkSweep"}](https://discuss.elastic.co/t/logstash-issue-glob-did-not-work-collector-name-name-concurrentmarksweep/133964/5):
>
> why did that happen without changing any configuration? Why did what happen? If it started working after you changed "null" to "nul" then you certainly changed the configuration. what's the importance of since\_db file. I don't think it's mandatory specifying in a configuration file? No, but setting it to "nul" or "/dev/null" (depending on your OS) will make Logstash oblivious to any old saved state about the current position in the file. The file input documentation has a few paragraphs…

---

_[View the full topic](https://discuss.elastic.co/t/logstash-elasticsearch-output-problem/234577)._
