# Logstash-forwarder missing lines after log rotate

**URL:** <https://discuss.elastic.co/t/logstash-forwarder-missing-lines-after-log-rotate/2111>\
**Category:** Logstash\
**Created:** [June 8, 2015, 3:45am UTC](https://discuss.elastic.co/t/logstash-forwarder-missing-lines-after-log-rotate/2111 "2015-06-08T03:45:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Laines](https://avatars.discourse-cdn.com/v4/letter/l/e495f1/32.png) [@Laines](https://discuss.elastic.co/u/Laines)\
**Post date:** [June 8, 2015, 3:45am UTC](https://discuss.elastic.co/t/logstash-forwarder-missing-lines-after-log-rotate/2111/1 "2015-06-08T03:45:05Z")

</div>

Hello,

We have problems with the logstash-forwarder after the log rotate of massages & secure we are missing the first couple of messages. At least the first one and then sometimes the next 2-5. After that there isn't a message lost anymore.

We use version 0.3.1 is this fixed in 0.4.0?

Any help appreciated!

Here the logstash-forwarder config:  
cat /etc/logstash-forwarder.conf  
{  
"network": {  
"servers": [  
"xxx:xxx",  
"xxx:xxx"  
],  
"timeout": 15,  
"ssl ca": "/etc/pki/tls/certs/logstash-forwarder.crt"  
},  
"files": [  
{  
"paths": [  
"/var/log/messages",  
"/var/log/secure"  
],  
"fields": {  
"type": "syslog"  
}  
},  
{  
"paths": [  
"/var/log/genericlog/\*"  
],  
"fields": {  
"type": "generic"  
}  
}  
]  
}

Cheers,  
Chris

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 8, 2015, 3:56am UTC](https://discuss.elastic.co/t/logstash-forwarder-missing-lines-after-log-rotate/2111/2 "2015-06-08T03:56:00Z")

</div>

Log writers might not realize immediately that the file they're writing to has been rotated. Does it work better if you let logstash-forwarder monitor the first-order rotated files, i.e. /var/log/messages.1 and /var/log/secure.1?

---

<div class="post-metadata">

**Author:** ![Laines](https://avatars.discourse-cdn.com/v4/letter/l/e495f1/32.png) [@Laines](https://discuss.elastic.co/u/Laines)\
**Post date:** [June 8, 2015, 3:59am UTC](https://discuss.elastic.co/t/logstash-forwarder-missing-lines-after-log-rotate/2111/3 "2015-06-08T03:59:56Z")

</div>

Hello,

tried it, does not change anything.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:38am UTC](https://discuss.elastic.co/t/logstash-forwarder-missing-lines-after-log-rotate/2111/4 "2017-07-06T05:38:14Z")

</div>


