# Logstash file wont run

**URL:** <https://discuss.elastic.co/t/logstash-file-wont-run/55927>\
**Category:** Logstash\
**Created:** [July 19, 2016, 9:01pm UTC](https://discuss.elastic.co/t/logstash-file-wont-run/55927 "2016-07-19T21:01:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [July 19, 2016, 9:01pm UTC](https://discuss.elastic.co/t/logstash-file-wont-run/55927/1 "2016-07-19T21:01:12Z")

</div>

I have the following logstash configuration file. When i try to run it..it won't show up on stdout...what it wrong with it? It worked before...what happened now? PLEASE HELP!

input {  
file {  
path =\> ["/opt/cast/report.log"]  
type =\> "dn\_reportlog"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}

filter {  
grok {  
match =\> ["message", "%{NOTSPACE} %{NOTSPACE:threadType} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE:requestType} %{NOTSPACE} %{NOTSPACE:requestStatus} %{NOTSPACE} %{GREEDYDATA:requestDetails}  
"]  
tag\_on\_failure =\> ["\_grokparsefailure\_match1"]  
}

grok {  
match =\> ["message", "%{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE:requestType} %{NOTSPACE} %{NOTSPACE:requestStatus} %{NOTSPACE} %{GREEDYDATA:requestDetails}"]  
tag\_on\_failure =\> ["\_grokparsefailure\_match2"]  
}

```
mutate {
    remove => ["message"]
}

```

}

output {  
stdout { codec =\> rubydebug }  
redis { host =\> "10.10.32.141" data\_type =\> "list" key =\> "num1" }  
}

---

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [July 19, 2016, 9:11pm UTC](https://discuss.elastic.co/t/logstash-file-wont-run/55927/2 "2016-07-19T21:11:38Z")

</div>

Please someone help! I am stuck on this for a very long time and I cannot figure out why ☹

---

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [July 19, 2016, 10:55pm UTC](https://discuss.elastic.co/t/logstash-file-wont-run/55927/3 "2016-07-19T22:55:01Z")

</div>

Can someone please point me in the right direction?  
I tried to run other logstash sample files..and they seem to work fine but this config file wont work!

---

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [July 19, 2016, 11:13pm UTC](https://discuss.elastic.co/t/logstash-file-wont-run/55927/4 "2016-07-19T23:13:30Z")

</div>

when I use the --debug option when starting logstash I get the following:

\_globbed\_files: /opt/Oracle/Middleware/weblogic12c/user\_projects/domains/ph2stg1/logs/dn\_report.log: glob is: ["/opt/cast/report.log"] {:level=\>:debug, :file=\>"filewatch/watch.rb", :line=\>"346", :method=\>"\_globbed\_files"}  
Pushing flush onto pipeline {:level=\>:debug, :file=\>"logstash/pipeline.rb", :line=\>"458", :method=\>"flush"}  
Pushing flush onto pipeline {:level=\>:debug, :file=\>"logstash/pipeline.rb", :line=\>"458", :method=\>"flush"}  
Pushing flush onto pipeline {:level=\>:debug, :file=\>"logstash/pipeline.rb", :line=\>"458", :method=\>"flush"}  
\_globbed\_files: /opt/Oracle/Middleware/weblogic12c/user\_projects/domains/ph2stg1/logs/dn\_report.log: glob is: ["/opt/cast/report.log"] {:level=\>:debug, :file=\>"filewatch/watch.rb", :line=\>"346", :method=\>"\_globbed\_files"}  
Pushing flush onto pipeline {:level=\>:debug, :file=\>"logstash/pipeline.rb", :line=\>"458", :method=\>"flush"}  
Pushing flush onto pipeline {:level=\>:debug, :file=\>"logstash/pipeline.rb", :line=\>"458", :method=\>"flush"}  
Pushing flush onto pipeline {:level=\>:debug, :file=\>"logstash/pipeline.rb", :line=\>"458", :method=\>"flush"}

What does it mean?

---

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [July 19, 2016, 11:27pm UTC](https://discuss.elastic.co/t/logstash-file-wont-run/55927/5 "2016-07-19T23:27:23Z")

</div>

I fixed this issue.  
I added the line ignore\_older = 0

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 21, 2016, 6:24pm UTC](https://discuss.elastic.co/t/logstash-file-wont-run/55927/6 "2016-07-21T18:24:06Z")

</div>

If the input file is older than 24 hours you need to adjust the file input's `ignore_older` option.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:46am UTC](https://discuss.elastic.co/t/logstash-file-wont-run/55927/7 "2017-07-06T04:46:58Z")

</div>


