# Logstash is processing old documents

**URL:** <https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678>\
**Category:** Logstash\
**Created:** [November 22, 2023, 2:19am UTC](https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678 "2023-11-22T02:19:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cruz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cruz/32/116126_2.png) [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Post date:** [November 22, 2023, 2:19am UTC](https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678/1 "2023-11-22T02:19:05Z")

</div>

When I restart the logstash service, the old documents are coming out.  
I tried to stopping the filebeat service where the logs are coming from and I deleted the old documents. But when I restart the logstash service the logs I deleted came back.

Has anyone encountered this?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 23, 2023, 4:26am UTC](https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678/2 "2023-11-23T04:26:24Z")

</div>

Are you using FB-\>LS? If do, logs read on FB side. There is the param [registry](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-general-options.html#_registry_path): `filebeat.registry.path: ${path.data}/registry` in filebeat.yml which keeps tracks about files which has been read.

If files were deleted from a disk, no chance to get back in LS.

---

<div class="post-metadata">

**Author:** ![Cruz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cruz/32/116126_2.png) [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Post date:** [November 23, 2023, 10:59pm UTC](https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678/3 "2023-11-23T22:59:31Z")

</div>

What does `filebeat.registry.path` do?  
Thank you for your time @Rios

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 24, 2023, 9:12am UTC](https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678/4 "2023-11-24T09:12:38Z")

</div>

It keeps track which files have been processed. If you testing often, and a file is processed, FB will not process again the same file.

Details about the fields inside the registry are [here](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271/2).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2023, 9:12am UTC](https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678/5 "2023-12-22T09:12:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
