# Logstash file read basic question

**URL:** <https://discuss.elastic.co/t/logstash-file-read-basic-question/43074>\
**Category:** Logstash\
**Created:** [March 1, 2016, 5:46am UTC](https://discuss.elastic.co/t/logstash-file-read-basic-question/43074 "2016-03-01T05:46:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sudheer157](https://avatars.discourse-cdn.com/v4/letter/s/b5ac83/32.png) [@sudheer157](https://discuss.elastic.co/u/sudheer157)\
**Post date:** [March 1, 2016, 5:46am UTC](https://discuss.elastic.co/t/logstash-file-read-basic-question/43074/1 "2016-03-01T05:46:07Z")

</div>

please point me in the right direction. I just started with logstash. Thanks

My config file  
**cat test.conf**  
`input { file { path => "/localhome/user/test.txt" start_position => "beginning" } } filter { grok { match => { "message" => "%{NUMBER:age},%{WORD:name}" } } } output { file { path => "/localhome/user/outfile.txt" } }`  
started logstash as  
**logstash -f test.conf**  
Logstash startup completed

Now i created a test file as below  
cat test.txt  
25,Mark  
23,Sammy  
24,Luna

save the file, and i am expecting to see a new file output.txt with three records  
but this is what i got  
cat outfile.txt  
{"message":"25,Mark","@version":"1","@timestamp":"2016-03-01T05:40:41.172Z","path":"/localhome/user/test.txt","host":"hostname","age":"25","name":"Mark"}

why is it reading only the first record?

Now i edited the file test.txt and added one more record  
now this is what i see in output.txt

```
]cat outfile.txt
{"message":"25,Mark","@version":"1","@timestamp":"2016-03-01T05:40:41.172Z","path":"/localhome/user/test.txt","host":"hostname","age":"25","name":"Mark"}
{"message":"23,Sammy","@version":"1","@timestamp":"2016-03-01T05:40:41.176Z","path":"/localhome/user/test.txt","host":"hostname","age":"23","name":"Sammy"}
{"message":"24,Luna","@version":"1","@timestamp":"2016-03-01T05:40:41.178Z","path":"/localhome/user/test.txt","host":"hostname","age":"24","name":"Luna"}
{"message":"25,Mark","@version":"1","@timestamp":"2016-03-01T05:42:58.362Z","path":"/localhome/user/test.txt","host":"hostname","age":"25","name":"Mark"}

```

didn't quite understand this behavior, why is it not reading the whole file? why is it missing the last record and also repeating the first record?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 1, 2016, 6:09am UTC](https://discuss.elastic.co/t/logstash-file-read-basic-question/43074/2 "2016-03-01T06:09:51Z")

</div>

You need to set `sincedb_path` to something like `/dev/null`.

Take a read of [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-sincedb\_path](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-sincedb_path)

---

<div class="post-metadata">

**Author:** ![sudheer157](https://avatars.discourse-cdn.com/v4/letter/s/b5ac83/32.png) [@sudheer157](https://discuss.elastic.co/u/sudheer157)\
**Post date:** [March 1, 2016, 6:17am UTC](https://discuss.elastic.co/t/logstash-file-read-basic-question/43074/3 "2016-03-01T06:17:50Z")

</div>

yes, i cleared $HOME/.sincedb\* before starting logstash

with no .sincedb files, with no data file, i started logstash  
and then created a new data file. then i expect it to auto read the entire file form the beginning and write it to output file, but in output file i only see 1 line in first pass.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/logstash-file-read-basic-question/43074/4 "2017-07-06T05:09:11Z")

</div>


