# Logstash is only partially reading input files

**URL:** <https://discuss.elastic.co/t/logstash-is-only-partially-reading-input-files/91489>\
**Category:** Logstash\
**Created:** [June 30, 2017, 8:41pm UTC](https://discuss.elastic.co/t/logstash-is-only-partially-reading-input-files/91489 "2017-06-30T20:41:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cpast](https://avatars.discourse-cdn.com/v4/letter/c/e5b9ba/32.png) [@cpast](https://discuss.elastic.co/u/cpast)\
**Post date:** [June 30, 2017, 8:41pm UTC](https://discuss.elastic.co/t/logstash-is-only-partially-reading-input-files/91489/1 "2017-06-30T20:41:59Z")

</div>

I'm trying to parse some very large input files (\>10,000 lines) with Logstash, pass them through the CSV, ruby, and mutate filters, and send them out via HTTP. My config is something like this:

```
input {
  file {
    path => "/system1/logs/*"
    type => "sys1"
    sincedb_path => "/system1/sincedb"
    start_position => "beginning"
  }
  file {
    path => "/system2/logs/*"
    type => "sys2"
    sincedb_path => "/system2/sincedb"
    start_position => "beginning"
  }
}
output { http { /*output stuff*/ } }
filter { /* filters */ }

```

Logstash starts parsing the first files for both systems and pops out a few thousand events via HTTP. Then it stops. The `sincedb`s are not created, and Logstash doesn't move on (I've waited \>30m for it to move on, and it doesn't seem to pop out a single additional event; the first few thousand events take only a minute or two to handle). The log (at "trace" level) ends with a bunch of "output received" lines followed by "Pushing flush onto pipeline"; there seems to be no error message.

What's going on?

---

<div class="post-metadata">

**Author:** ![cpast](https://avatars.discourse-cdn.com/v4/letter/c/e5b9ba/32.png) [@cpast](https://discuss.elastic.co/u/cpast)\
**Post date:** [July 3, 2017, 5:22pm UTC](https://discuss.elastic.co/t/logstash-is-only-partially-reading-input-files/91489/2 "2017-07-03T17:22:12Z")

</div>

OK, a sample last entry:

```
[timestamp][DEBUG][logstash.pipeline] output received {"event"=>{...event details...}}
[time][DEBUG][logstash.inputs.file] Reveived line {:path=>"/system1/logs/log1", :text=>"...text..."}
[time][DEBUG][logstash.inputs.file] Reveived line {:path=>"/system2/logs/log1", :text=>"...text..."}
[time][DEBUG][logstash.pipeline] Pushing flush onto pipeline

```

This is with the pipeline size set to 1. If I try restarting it, I get warnings that the Mutate filter is hanging.

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [July 3, 2017, 5:53pm UTC](https://discuss.elastic.co/t/logstash-is-only-partially-reading-input-files/91489/3 "2017-07-03T17:53:43Z")

</div>

can you post a thread dump or the return of the [hot threads api](https://www.elastic.co/guide/en/logstash/current/hot-threads-api.html) when logstash is stalling?

---

<div class="post-metadata">

**Author:** ![cpast](https://avatars.discourse-cdn.com/v4/letter/c/e5b9ba/32.png) [@cpast](https://discuss.elastic.co/u/cpast)\
**Post date:** [July 7, 2017, 9:10pm UTC](https://discuss.elastic.co/t/logstash-is-only-partially-reading-input-files/91489/4 "2017-07-07T21:10:34Z")

</div>

I'll see if I can get the thread dump. In the meantime, I did a couple changes to test things. It now reads the files using a Filebeats instance on the same server, and dropped my filters except a match filter (to ignore comments in the log file), a CSV filter, and a date filter. Now, Logstash no longer says `pushing flush onto pipeline`; it just ends with an `output received` line. Filebeat is reporting I/O timeouts. The top threads are `Runner`, `worker0`, and `worker1`, with the latter two's call stacks ending at `http.rb:141`.

---

<div class="post-metadata">

**Author:** ![cpast](https://avatars.discourse-cdn.com/v4/letter/c/e5b9ba/32.png) [@cpast](https://discuss.elastic.co/u/cpast)\
**Post date:** [July 10, 2017, 8:15pm UTC](https://discuss.elastic.co/t/logstash-is-only-partially-reading-input-files/91489/5 "2017-07-10T20:15:43Z")

</div>

Update: Applying [this patch](https://github.com/logstash-plugins/logstash-output-http/pull/64) fixed the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2017, 8:16pm UTC](https://discuss.elastic.co/t/logstash-is-only-partially-reading-input-files/91489/6 "2017-08-07T20:16:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
