# Logstash not reading files changes

**URL:** <https://discuss.elastic.co/t/logstash-not-reading-files-changes/199305>\
**Category:** Logstash\
**Created:** [September 12, 2019, 6:07pm UTC](https://discuss.elastic.co/t/logstash-not-reading-files-changes/199305 "2019-09-12T18:07:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sergioc](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@Sergioc](https://discuss.elastic.co/u/Sergioc)\
**Post date:** [September 12, 2019, 6:07pm UTC](https://discuss.elastic.co/t/logstash-not-reading-files-changes/199305/1 "2019-09-12T18:07:41Z")

</div>

I have Logstash installed and im reading a file that is remote and also i have created a pipeline for a local file. I was thinking at the beginning that the issue was the remote file but the local one is not read at all either.  
I should be missing something.

my pipelines.yml config is like this

> ```
> - pipeline.id: frontdesk
> config.string: |
> input { file {
> path => "\\palace-dev\wwwroot\PalsoftWebApi\file.log"
> start_position => beginning 
>        
>     
> } }
> filter {
> # Weblog filter statements here...
> }
> output {
> stdout {}
> elasticsearch {
> hosts => ["http://sc-elk-01:9200"]            
> index => "frontdesklog-%{+YYYY.MM.dd}"
> }
> }
>     
>   
>   
> - pipeline.id: logstash
> config.string: |
> input { file {
> path => "D:\ElasticSearch\logstash\logs\logstash-plain.log"
> start_position => beginning 
>        
>     
> } }
> filter {
> # Weblog filter statements here...
> }
> output {
> stdout {}
> elasticsearch {
> hosts => ["http://sc-elk-01:9200"]            
> index => "logtashssss-%{+YYYY.MM.dd}"
> }
> }
> 
> ```

and the log in logtash at the end have this.  
\> [2019-09-12T13:59:18,492][INFO][logstash.javapipeline] Pipeline started {"pipeline.id"=\>"logstash"}

> ```
> [2019-09-12T13:59:18,498][INFO][logstash.javapipeline] Pipeline started {"pipeline.id"=>"frontdesk"}
> [2019-09-12T13:59:18,607][INFO][logstash.agent] Pipelines running {:count=>2, :running_pipelines=>[:frontdesk, :logstash], :non_running_pipelines=>[]}
> [2019-09-12T13:59:18,634][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections
> [2019-09-12T13:59:18,643][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections
> [2019-09-12T13:59:19,431][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
> 
> ```

so I'm assuming config is fine. but nothing is printed in the console and nothing is sent to elastic.

any help will be really appreciated.

Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 12, 2019, 6:10pm UTC](https://discuss.elastic.co/t/logstash-not-reading-files-changes/199305/2 "2019-09-12T18:10:48Z")

</div>

Do not use backslash in the path option of a file input, use forward slash.

---

<div class="post-metadata">

**Author:** ![Sergioc](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@Sergioc](https://discuss.elastic.co/u/Sergioc)\
**Post date:** [September 20, 2019, 6:34pm UTC](https://discuss.elastic.co/t/logstash-not-reading-files-changes/199305/3 "2019-09-20T18:34:16Z")

</div>

Thank you, yes it works with the forward slash. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2019, 6:34pm UTC](https://discuss.elastic.co/t/logstash-not-reading-files-changes/199305/4 "2019-10-18T18:34:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
