# Logstash input file not working

**URL:** <https://discuss.elastic.co/t/logstash-input-file-not-working/186713>\
**Category:** Logstash\
**Created:** [June 20, 2019, 2:38pm UTC](https://discuss.elastic.co/t/logstash-input-file-not-working/186713 "2019-06-20T14:38:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![paksoft18](https://avatars.discourse-cdn.com/v4/letter/p/73ab20/32.png) [@paksoft18](https://discuss.elastic.co/u/paksoft18)\
**Post date:** [June 20, 2019, 2:38pm UTC](https://discuss.elastic.co/t/logstash-input-file-not-working/186713/1 "2019-06-20T14:38:23Z")

</div>

Hello, Greetings, I'm new to ELK Stack and I'm trying to put some router logs to elasticsearch via Logstash but it's not working. it doesn't create the index on elasticsearch please help.  
My Config file is as below  
  
input {  
file {  
path =\> "/User/fazal/Desktop/logstach/data.txt"  
start\_position =\> "beginning"  
sincedb\_path =\> "/tmp/mysincedbfile"  
codec =\> multiline {  
pattern =\> "^type"  
negate =\> "true"  
what =\> "next"  
}  
}  
}  
filter {  
grok {  
match =\> { "message" =\> "%{WORD:type} %{WORD:channel} %{NUMBER:use} %{WORD:bitrate}" }  
}  
}  
output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "demo"

```
    }
    stdout { codec => rubydebug }
}</BBCode>

```

Data.txt  
  
type=frequency channel="2447/20/gn" use=7.6% bitrate=39.1kbps  
frequency-network-count=0 noise-floor=-107 frequency-station-count=4

type=frequency channel="2412/20/gn" use=8.4% bitrate=150.9kbps  
frequency-network-count=5 noise-floor=-110 frequency-station-count=13

type=frequency channel="2417/20/gn" use=9.2% bitrate=58.6kbps  
frequency-network-count=1 noise-floor=-112 frequency-station-count=3

Logstash Log  
  
[2019-06-20T19:03:51,705][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-06-20T19:03:51,724][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.0.1"}  
[2019-06-20T19:03:55,668][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2019-06-20T19:03:55,955][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2019-06-20T19:03:56,032][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>7}  
[2019-06-20T19:03:56,036][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>7}  
[2019-06-20T19:03:56,090][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[http://localhost:9200](http://localhost:9200)"]}  
[2019-06-20T19:03:56,090][INFO][logstash.outputs.elasticsearch] Using default mapping template  
[2019-06-20T19:03:56,132][INFO][logstash.javapipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50, "pipeline.max\_inflight"=\>500, :thread=\>"#\<Thread:0x327461fa run\>"}  
[2019-06-20T19:03:56,281][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"index\_patterns"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s", "number\_of\_shards"=\>1}, "mappings"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}  
[2019-06-20T19:04:01,785][INFO][logstash.javapipeline] Pipeline started {"pipeline.id"=\>"main"}  
[2019-06-20T19:04:01,865][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2019-06-20T19:04:01,870][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2019-06-20T19:04:02,202][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 20, 2019, 4:53pm UTC](https://discuss.elastic.co/t/logstash-input-file-not-working/186713/2 "2019-06-20T16:53:38Z")

</div>

Are you appending new entries to the log?

---

<div class="post-metadata">

**Author:** ![paksoft18](https://avatars.discourse-cdn.com/v4/letter/p/73ab20/32.png) [@paksoft18](https://discuss.elastic.co/u/paksoft18)\
**Post date:** [June 20, 2019, 5:59pm UTC](https://discuss.elastic.co/t/logstash-input-file-not-working/186713/3 "2019-06-20T17:59:11Z")

</div>

No, I need to add entries from the data.txt to elasticsearch

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 20, 2019, 6:07pm UTC](https://discuss.elastic.co/t/logstash-input-file-not-working/186713/4 "2019-06-20T18:07:15Z")

</div>

start\_position only has any effect when the file input sees a new file. It is possible that you ran logstash, the file input read the file and persisted the fact that it had done so in the sincedb, but for some reason it failed to write the data to elasticsearch. If you fixed the problem that caused it not to write the data and restarted logstash it would not re-read the file. Take a look at /tmp/mysincedbfile (it is a text file) and see if it has a line for /User/fazal/Desktop/logstach/data.txt. You may need to stop logstash, delete that line, then restart logstash, or perhaps (depending on your use case) you may want to surpress persistence of the sincedb using 'sincedb\_path =\> "/dev/null"'

---

<div class="post-metadata">

**Author:** ![paksoft18](https://avatars.discourse-cdn.com/v4/letter/p/73ab20/32.png) [@paksoft18](https://discuss.elastic.co/u/paksoft18)\
**Post date:** [June 21, 2019, 7:51am UTC](https://discuss.elastic.co/t/logstash-input-file-not-working/186713/5 "2019-06-21T07:51:17Z")

</div>

/tmp/mysincedbfile is empty and I have also tried to set sincedb\_path =\> "/dev/null" but the same results. I don't understand why it isn't writing data to elasticsearch. is there any way to see deeper debug logs? to understand what's actually going wrong

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 21, 2019, 1:36pm UTC](https://discuss.elastic.co/t/logstash-input-file-not-working/186713/6 "2019-06-21T13:36:39Z")

</div>

Could be there is not a line that triggers the multiline filter to push the accumulated lines into the pipeline.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2019, 1:36pm UTC](https://discuss.elastic.co/t/logstash-input-file-not-working/186713/7 "2019-07-19T13:36:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
