# Logstash file input not working

**URL:** <https://discuss.elastic.co/t/logstash-file-input-not-working/82843>\
**Category:** Logstash\
**Created:** [April 19, 2017, 8:57am UTC](https://discuss.elastic.co/t/logstash-file-input-not-working/82843 "2017-04-19T08:57:54Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 19, 2017, 8:57am UTC](https://discuss.elastic.co/t/logstash-file-input-not-working/82843/1 "2017-04-19T08:57:54Z")

</div>

Hello,

I have a question.

Before i used filebeat to send logs to logstash. I decided (to better performance) to delete filebeat.

Now i use file input in logstash :

```
 file {
   path => "/home/cra_elk/*"
   type => "cra"
   #start_position => "beginning"
   #sincedb_path => "/dev/null"
 }

```

If i not use **sincedb\_path =\> "/dev/null"** it doesn't work.

Files i try to upload are created yesterday (2017041818h). I don't understand.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 20, 2017, 5:19am UTC](https://discuss.elastic.co/t/logstash-file-input-not-working/82843/2 "2017-04-20T05:19:23Z")

</div>

Logstash thinks it has already processed the files so it's just waiting for more data to be appended to hem. Setting the `sincedb_path` option like that resets the saved state about the current position in the file, so that combined with `start_position => "beginning"` will make Logstash read the files from the top. Alternatively you can delete the current sincedb files to reset the state.

See the file input's documentation and countless previous threads on this topic.

---

<div class="post-metadata">

**Author:** ![pablosan](https://avatars.discourse-cdn.com/v4/letter/p/e19adc/32.png) [@pablosan](https://discuss.elastic.co/u/pablosan)\
**Post date:** [April 20, 2017, 7:52am UTC](https://discuss.elastic.co/t/logstash-file-input-not-working/82843/3 "2017-04-20T07:52:32Z")

</div>

Also check the ignore\_older setting in [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html)

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 20, 2017, 8:04am UTC](https://discuss.elastic.co/t/logstash-file-input-not-working/82843/4 "2017-04-20T08:04:14Z")

</div>

Ok it's work now i don't know why 🙂

I don't find sincedb file, i deleted it there is few days and i believe It has not been created since.

Thank you for your help

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 21, 2017, 8:44am UTC](https://discuss.elastic.co/t/logstash-file-input-not-working/82843/5 "2017-04-21T08:44:57Z")

</div>

Furthermore

Logstash prefer whats syntaxe ? :

`Method 1 :`

```
 file {
   path => "/data/serveur_*/elkf/DC7_*.txt"
   type => "cra"
 }

```

`Method 2 :`

```
file {
       path => ["/data/serveur_1/elkf/DC7_*.txt", "/data/serveur_2/elkf/DC7_*.txt", "/data/serveur_3/elkf/DC7_*.txt"]
       type => "cra"
     }

```

`Method 3`

```
 file {
   path => "/data/serveur_1/elkf/DC7_*.txt"
   type => "cra"
   path => "/data/serveur_2/elkf/DC7_*.txt"
   type => "cra"
   path => "/data/serveur_3/elkf/DC7_*.txt"
   type => "cra"
     }

```

?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 21, 2017, 8:46am UTC](https://discuss.elastic.co/t/logstash-file-input-not-working/82843/6 "2017-04-21T08:46:02Z")

</div>

The first two are fine. I'd avoid the last one even if it might work.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [April 21, 2017, 9:01am UTC](https://discuss.elastic.co/t/logstash-file-input-not-working/82843/7 "2017-04-21T09:01:44Z")

</div>

@Beuhlet_Reseau - the glob patterns are taken from the OS - [https://en.wikipedia.org/wiki/Glob\_(programming)](https://en.wikipedia.org/wiki/Glob_(programming))

`path => "/data/serveur_[1-3]/elkf/DC7_*.txt"` should work too if you want to prevent file discovery from `serveur_5` for example.

FWIW: as far as I can recall, with Method 2 you can control the order of discovered files better - if you wanted, say, to read `serveur_3` before `serveur_1`.

Other than that, follow Magnus' advice.

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 21, 2017, 10:17am UTC](https://discuss.elastic.co/t/logstash-file-input-not-working/82843/8 "2017-04-21T10:17:03Z")

</div>

Yes the controle is the key ! I think turn me to

`"/data/serveur_*/elkf/DC7_*.txt"` because i don't need order.

However I find the upload quite bizarre. I explain me :

Log file created at 12h06,  
Discover available about this file in kibana : 12h11,  
Timestamp display in Discover about this file : 12h07.

It's correct but i find bizarre the gap of 5 minutes for upload. (but the timestamp is correct 🙂 )

It is surely nothing but ... The main thing is that it works 😊

Thank you both @warkolm @guyboertje.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2017, 10:19am UTC](https://discuss.elastic.co/t/logstash-file-input-not-working/82843/9 "2017-05-19T10:19:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
