# Logstash file input

**URL:** https://discuss.elastic.co/t/logstash-file-input/58076
**Category:** Logstash
**Created:** [August 16, 2016, 12:30am UTC](https://discuss.elastic.co/t/logstash-file-input/58076 "2016-08-16T00:30:26Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![datadude](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@datadude](https://discuss.elastic.co/u/datadude)
#### Post date: [August 16, 2016, 12:30am UTC](https://discuss.elastic.co/t/logstash-file-input/58076/1 "2016-08-16T00:30:26Z")

</div>

Trying to figure out an issue with file input

It just doesn't seem to be reading the file. It is a suricata eve.json file

- permissions look fine (world readable)
- verbose output says it registers the file
- no output to elasticsearch
- no output to standard out either

:timestamp=\>"2016-08-15T17:15:16.313000-0700", :message=\>"starting agent", :level=\>:info}  
{:timestamp=\>"2016-08-15T17:15:16.318000-0700", :message=\>"starting pipeline", :id=\>"main", :level=\>:info}  
**{:timestamp=\>"2016-08-15T17:15:16.663000-0700", :message=\>"Registering file input", :path=\>["/var/log/suricata/eve.json"], :level=\>:info}**  
{:timestamp=\>"2016-08-15T17:15:16.776000-0700", :message=\>"\*\* WARNING \*\* Detected UNSAFE options in elasticsearch output configuration!\n\*\* WARNING \*\* You have enabled encryption but DISABLED certificate verification.\n\*\* WARNING \*\* To make sure your data is secure change :ssl\_certificate\_verification to true", :level=\>:warn}  
{:timestamp=\>"2016-08-15T17:15:17.239000-0700", :message=\>"Using mapping template from", :path=\>nil, :level=\>:info}  
{:timestamp=\>"2016-08-15T17:15:17.453000-0700", :message=\>"Attempting to install template", :manage\_template=\>{"template"=\>"logstash-_", "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "omit\_norms"=\>true}, "dynamic\_templates"=\>[{"message\_field"=\>{"match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"string", "index"=\>"analyzed", "omit\_norms"=\>true, "fielddata"=\>{"format"=\>"disabled"}}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"string", "index"=\>"analyzed", "omit\_norms"=\>true, "fielddata"=\>{"format"=\>"disabled"}, "fields"=\>{"raw"=\>{"type"=\>"string", "index"=\>"not\_analyzed", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"string", "index"=\>"not\_analyzed"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"float"}, "longitude"=\>{"type"=\>"float"}}}}}}}, :level=\>:info}  
{:timestamp=\>"2016-08-15T17:15:17.832000-0700", :message=\>"New Elasticsearch output", :class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["10.136.255.160:9200"], :level=\>:info}  
{:timestamp=\>"2016-08-15T17:15:17.943000-0700", :message=\>"Starting pipeline", :id=\>"main", :pipeline\_workers=\>2, :batch\_size=\>125, :batch\_delay=\>5, :max\_inflight=\>250, :level=\>:info}  
{:timestamp=\>"2016-08-15T17:15:17.983000-0700", :message=\>"Pipeline main started"}

@elk-receiver ~]# ls -l /var/log/suricata/eve.json  
-rw-r--r--. 1 suricata suricata 498738317 Aug 15 17:18 /var/log/suricata/eve.json

# cat /etc/logstash/conf.d/10-ids-suricata-input.conf

input {  
file {  
path =\> ["/var/log/suricata/eve.json"]  
sincedb\_path =\> ["/var/lib/logstash/suricata.sincedb"]  
start\_position =\> "beginning"  
codec =\> "json"  
type =\> "Suricata"  
tags =\> ["Suricata","IDS"]  
}  
}

]# cat /etc/logstash/conf.d/50-ids-suricata-output.conf  
output {  
if [type] == "Suricata" {  
elasticsearch {  
hosts =\> ["10.10.10.12:9200"]  
ssl =\> true  
ssl\_certificate\_verification =\> false  
keystore =\> "/var/certs/elkstack.jks"  
keystore\_password =\> password  
user =\> "user"  
password =\> password  
index =\> "unv\_suricata-%{+YYYY.MM.dd}"  
}  
stdout {  
codec =\> rubydebug  
}  
}  
}

I have other TCP/UDP inputs and the elasticsearch output working but have it striped down to this at the moment trying to find the issue.

any ideas would be appreciated

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [August 16, 2016, 12:41am UTC](https://discuss.elastic.co/t/logstash-file-input/58076/2 "2016-08-16T00:41:37Z")

</div>

Have you tried deleting the sincedb file?

---

<div class="post-metadata">

### Author: ![datadude](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@datadude](https://discuss.elastic.co/u/datadude)
#### Post date: [August 16, 2016, 1:26am UTC](https://discuss.elastic.co/t/logstash-file-input/58076/3 "2016-08-16T01:26:35Z")

</div>

I fiddled with that a bit, that is a new path in the configuration file and  
I didn't specify the file, just directory.

There was an error in the log saying it needed a file specified. I did that  
and it never created a file so I touched it and the size changed but still  
never worked.

I can try deleting that file again and see what happens I guess

---

<div class="post-metadata">

### Author: ![datadude](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@datadude](https://discuss.elastic.co/u/datadude)
#### Post date: [August 16, 2016, 3:15pm UTC](https://discuss.elastic.co/t/logstash-file-input/58076/4 "2016-08-16T15:15:01Z")

</div>

deleted the file, restarted logstash

- regenerated traffic to update the eve.json file
- no change, no data loaded in to elasticsearch nor stdout
- the sincedb file wasn't created either
- running as the logstash user
- logstash user has permissions

root 22226 0.0 0.0 193436 2788 pts/0 S+ 08:00 0:00 sudo -u logstash /opt/logstash/bin/logstash agent -f /etc/logstash/conf.d --log /var/log/logstash/logstash.log --verbose

logstash 22227 32.6 5.4 3633364 219192 pts/0 Sl+ 08:00 0:21 /bin/java -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -Djava.awt.headless=true -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+HeapDumpOnOutOfMemoryError -Xmx1g -Xss2048k -Djffi.boot.library.path=/opt/logstash/vendor/jruby/lib/jni -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -Djava.awt.headless=true -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=/opt logstash/heapdump.hprof -Xbootclasspath/a:/opt/logstash/vendor/jruby/lib/jruby.jar -classpath : -Djruby.home=/opt/logstash/vendor/jruby -Djruby.lib=/opt/logstash/vendor/jruby/lib -Djruby.script=jruby -Djruby.shell=/bin/sh org.jruby.Main --1.9 /opt/logstash/lib/bootstrap/environment.rb logstash/runner.rb agent -f /etc/logstash/conf.d --log /var/log/logstash/logstash.log --verbose

[@elk-receiver ~]# ls -la /var/lib/logstash/  
total 4  
drwxrwxr-x. 2 logstash logstash 6 Aug 16 07:59 .

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:43am UTC](https://discuss.elastic.co/t/logstash-file-input/58076/5 "2017-07-06T04:43:16Z")

</div>


