# Logstash not reading the logs from file input

**URL:** <https://discuss.elastic.co/t/logstash-not-reading-the-logs-from-file-input/68524>\
**Category:** Logstash\
**Created:** [December 9, 2016, 7:43am UTC](https://discuss.elastic.co/t/logstash-not-reading-the-logs-from-file-input/68524 "2016-12-09T07:43:18Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![shashi0905](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shashi0905](https://discuss.elastic.co/u/shashi0905)\
**Post date:** [December 9, 2016, 7:43am UTC](https://discuss.elastic.co/t/logstash-not-reading-the-logs-from-file-input/68524/1 "2016-12-09T07:43:18Z")

</div>

I am trying to configure logstash to push data from log files to elasticsearch, but logstash is not reading the log files specified in the file input.

When run in debug mode, I see this message - "Plugin not defined in namespace, checking for plugin file".

Part of my configuration file :

```
input {
          beats {
            type => beats
           port => 5001
         }

         file{
           path => "/opt/application/proj/logs/prod-logs/proj.log.*"
           type => "proj-logs"
           start_position => "beginning"
        }
     } 

```

Although beats is not configured yet, I want to test first with log files.

I have confirmed the file exists at the specified path, and there are no permission issues as well. I also tried modifying the log files to update its last modify time (to avoid any possible issue because of sincedb property), but it didn't work either.

There are no indices created in the elasticsearch, as no data being read by logstash.  
What might be the possible issue, and what is the meaning of the message in the logs 'plugin not defined in namespace' ?

Some Lines from debug logs -

```
:message=>"Reading config file", :config_file=>"/images/ELKPKG/logstash-2.4.0/proj-funcANDapache-logstash.conf", :level=>:debug, :file=>"logstash/config/loader.rb", :line=>"69", :method=>"local_config"}
:message=>"Plugin not defined in namespace, checking for plugin file", :type=>"input", :name=>"beats", :path=>"logstash/inputs/beats", :level=>:debug, :file=>"logstash/plugin.rb", :line=>"86", :method=>"lookup"}
:message=>"Plugin not defined in namespace, checking for plugin file", :type=>"codec", :name=>"plain", :path=>"logstash/codecs/plain", :level=>:debug, :file=>"logstash/plugin.rb", :line=>"86", :method=>"lookup"}
:message=>"Plugin not defined in namespace, checking for plugin file", :type=>"input", :name=>"file", :path=>"logstash/inputs/file", :level=>:debug, :file=>"logstash/plugin.rb", :line=>"86", :method=>"lookup"}
:message=>"Plugin not defined in namespace, checking for plugin file", :type=>"input", :name=>"file", :path=>"logstash/inputs/file", :level=>:debug, :file=>"logstash/plugin.rb", :line=>"86", :method=>"lookup"}
:message=>"config LogStash::Codecs::Plain/@charset = \"UTF-8\"", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"config LogStash::Inputs::File/@path = [\"/opt/application/proj/logs/prod-logs/proj.log.*\"]", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"config LogStash::Inputs::File/@type = \"proj-logs\"", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"config LogStash::Inputs::File/@start_position = \"beginning\"", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}

```

Logstash Version : 2.4.0  
Elasticsearch Version : 2.4.0

Any help/support would be appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 9, 2016, 8:02am UTC](https://discuss.elastic.co/t/logstash-not-reading-the-logs-from-file-input/68524/2 "2016-12-09T08:02:30Z")

</div>

Look for log entries with "discover" in them. You could have a permission problem that results in Logstash not being able to find any files.

Perhaps Logstash thinks it has processed the files and is tailing them and waiting for more input. What's in the sincedb file?

---

<div class="post-metadata">

**Author:** ![shashi0905](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shashi0905](https://discuss.elastic.co/u/shashi0905)\
**Post date:** [December 9, 2016, 10:51am UTC](https://discuss.elastic.co/t/logstash-not-reading-the-logs-from-file-input/68524/3 "2016-12-09T10:51:43Z")

</div>

Thanks for your response.  
Following are the entries with 'discover' and 'sincedb' in the debug logs

```
:message=>"Reading config file", :config_file=>"/images/ELKPKG/logstash-2.4.0/proj-funcANDapache-logstash.conf", :level=>:debug, :file=>"logstash/config/loader.rb", :line=>"69", :method=>"local_config"}
:message=>"Plugin not defined in namespace, checking for plugin file", :type=>"input", :name=>"file", :path=>"logstash/inputs/file", :level=>:debug, :file=>"logstash/plugin.rb", :line=>"86", :method=>"lookup"}
:message=>"Plugin not defined in namespace, checking for plugin file", :type=>"codec", :name=>"plain", :path=>"logstash/codecs/plain", :level=>:debug, :file=>"logstash/plugin.rb", :line=>"86", :method=>"lookup"}
:message=>"config LogStash::Codecs::Plain/@charset = \"UTF-8\"", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"config LogStash::Inputs::File/@path = [\"/opt/application/proj/logs/prod-logs/proj.log.*\"]", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"config LogStash::Inputs::File/@type = \"proj-logs\"", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"config LogStash::Inputs::File/@ **sincedb** _write_interval = 15", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"config LogStash::Inputs::File/@delimiter = \"\\n\"", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"config LogStash::Inputs::File/@close_older = 3600", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"Plugin not defined in namespace, checking for plugin file", :type=>"filter", :name=>"grok", :path=>"logstash/filters/grok", :level=>:debug, :file=>"logstash/plugin.rb", :line=>"86", :method=>"lookup"}
.................
:message=>"Plugin not defined in namespace, checking for plugin file", :type=>"filter", :name=>"drop", :path=>"logstash/filters/drop", :level=>:debug, :file=>"logstash/plugin.rb", :line=>"86", :method=>"lookup"}
:message=>"config LogStash::Filters::Drop/@percentage = 100", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"starting agent", :level=>:info, :file=>"logstash/agent.rb", :line=>"213", :method=>"execute"}
:message=>"starting pipeline", :id=>"main", :level=>:info, :file=>"logstash/agent.rb", :line=>"487", :method=>"start_pipeline"}
:message=>"Registering file input", :path=>["/opt/application/proj/logs/prod-logs/proj.log.*"], :level=>:info, :file=>"logstash/inputs/file.rb", :line=>"171", :method=>"register"}
:message=>"No **sincedb** _path set, generating one based on the file path", : **sincedb** _path=>"/home/osadmin/. **sincedb** _fe955e0b1809dbb46277ebb71ea4a22a", :path=>["/opt/application/proj/logs/prod-logs/proj.log.*"], :level=>:info, :file=>"logstash/inputs/file.rb", :line=>"216", :method=>"register"}
:message=>"config LogStash::Codecs::Plain/@charset = \"UTF-8\"", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"_globbed_files: /opt/application/proj/logs/prod-logs/proj.log.*: glob is: [\"/opt/application/proj/logs/prod-logs/proj.log.2016-10-12\"]", :level=>:debug, :file=>"filewatch/watch.rb", :line=>"346", :method=>"_globbed_files"}
:message=>"config LogStash::Outputs::ElasticSearch/@hosts = [\"10.192.225.32:9200\"]", :level=>:debug, :file=>"logstash/config/mixin.rb", :line=>"154", :method=>"config_init"}
:message=>"_ **discover** _file: /opt/application/proj/logs/prod-logs/proj.log.*: new: /opt/application/proj/logs/prod-logs/proj.log.2016-10-12 (exclude is [])", :level=>:debug, :file=>"filewatch/watch.rb", :line=>"310", :method=>"_ **discover** _file"}
:message=>"_open_file: /opt/application/proj/logs/prod-logs/proj.log.2016-10-12: opening", :level=>:debug, :file=>"filewatch/tail_base.rb", :line=>"86", :method=>"_open_file"}
:message=>"/opt/application/proj/logs/prod-logs/proj.log.2016-10-12: **sincedb** last value 17451552, cur size 17451552", :level=>:debug, :file=>"filewatch/tail_base.rb", :line=>"123", :method=>"_add_to_ **sincedb**"}

```

I don't think there is any permissions issue, as per the log entry file seems accessible to logstash. I'm not sure about the sincedb entry though, and the message 'plugin not defined in namespace' ?  
Should I consider re-installing logstash instance?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 9, 2016, 10:56am UTC](https://discuss.elastic.co/t/logstash-not-reading-the-logs-from-file-input/68524/4 "2016-12-09T10:56:49Z")

</div>

> I'm not sure about the sincedb entry though,

Not sure how to check it, or what are you unsure about?

> and the message 'plugin not defined in namespace' ?

I don't think you should worry about that.

> Should I consider re-installing logstash instance?

That probably won't help.

---

<div class="post-metadata">

**Author:** ![shashi0905](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shashi0905](https://discuss.elastic.co/u/shashi0905)\
**Post date:** [December 9, 2016, 11:11am UTC](https://discuss.elastic.co/t/logstash-not-reading-the-logs-from-file-input/68524/5 "2016-12-09T11:11:30Z")

</div>

Should I try deleting the sincedb files?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 9, 2016, 11:55am UTC](https://discuss.elastic.co/t/logstash-not-reading-the-logs-from-file-input/68524/6 "2016-12-09T11:55:13Z")

</div>

Yes, that could help. Shut down Logstash first, though.

---

<div class="post-metadata">

**Author:** ![shashi0905](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shashi0905](https://discuss.elastic.co/u/shashi0905)\
**Post date:** [December 15, 2016, 11:15am UTC](https://discuss.elastic.co/t/logstash-not-reading-the-logs-from-file-input/68524/7 "2016-12-15T11:15:56Z")

</div>

Hi Magnus,

I was able to find the issue, which was due to difference in the log files on qualification and production server. One of the field was missing in the production logs.

While debugging, I assumed that both the logs are same. But after checking all the configuration of logstash and elasticsearch, I turned to the logstash parsing section.... using the grok debugger against the log file being used. This is when I found out the issue... and moreover, the missing field was being used as a filter in the logstash parsing, resulting in, all the entries getting dropped.

Anyways, thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2017, 11:16am UTC](https://discuss.elastic.co/t/logstash-not-reading-the-logs-from-file-input/68524/8 "2017-01-12T11:16:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
