# Logstash not recognising .log files

**URL:** <https://discuss.elastic.co/t/logstash-not-recognising-log-files/175744>\
**Category:** Logstash\
**Created:** [April 8, 2019, 12:57am UTC](https://discuss.elastic.co/t/logstash-not-recognising-log-files/175744 "2019-04-08T00:57:59Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rb6](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@rb6](https://discuss.elastic.co/u/rb6)\
**Post date:** [April 8, 2019, 12:57am UTC](https://discuss.elastic.co/t/logstash-not-recognising-log-files/175744/1 "2019-04-08T00:57:59Z")

</div>

Hi,

I'm attempting to parse authentication logs using an elk stack, it was all up and running one week. Logstash was able to process all of the logs placed within the directory, both .log and .log.1 files. Then after re-indexing the data it has appeared that logstash will not recognise any .log files only .log.1 etc.

I've uploaded part of the file config that deals with the input path.

> file {  
> path =\> "C:/LOGS/\*\*/_.log_"  
> type =\> "Authentication"  
> start\_position =\> beginning  
> close\_older =\> "1 hour"  
> sincedb\_path =\> "NUL"  
> codec =\> plain {  
> charset =\> "Windows-1252"  
> }  
> }

When setting the output to console using rubydebug. Usually logstash starts up then stops on this line, as it can't seem to find any of the .log files.

> [2019-04-04T11:11:46,873][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

I managed to get an error message eventually when it failed to process a .log file.

> [2019-04-04T11:15:35,047][WARN][filewatch.tailmode.processor] \>\>\> Rotation In Progress - inode change detected and original content is not fully read, file is closed and path points to new content {"watched\_file details"=\>"\<FileWatch::WatchedFile: @filename='AuthenticationService.log', @state='rotation\_in\_progress', @recent\_states='[:watched, :watched]', @bytes\_read='0', @bytes\_unread='0', current\_size='13950782', last\_stat\_size='13950782', file\_open?='false', @initial=false, @sincedb\_key='unknown 0 0'\>"}

Anyone know anything about this issue? as it would be greatly appreciated.

Edit:  
After trying to find more information on this matter, I enabled sincedb to see what its trying to process. and this is the result.

> unknown 0 0 0 1554687598.275 C:/LOGS/AuthenticationService.log

> 612407792-715744-983040 0 0 40960059 1554687592.116 C:/LOGS/AuthenticationService.log.1

Whilst one log file gets an inode identifier the .log doesn't.

--SOLVED--

Turns out theres a known bug with this issue.

> [@Logstash stopped working (sincedb is not updated) after upgrade from 6.2.4 –\> 6.4.0 (Update 6.5 doesn't work also)](https://discuss.elastic.co/t/logstash-stopped-working-sincedb-is-not-updated-after-upgrade-from-6-2-4-6-4-0-update-6-5-doesnt-work-also/161335/43):
>
> @RonGros Version 4.1.10 is released with fix for "unknown 0 0". Please verify fix works for you. [https://rubygems.org/gems/logstash-input-file/versions/4.1.10](https://rubygems.org/gems/logstash-input-file/versions/4.1.10)

This post here allowed me to fix the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2019, 12:58am UTC](https://discuss.elastic.co/t/logstash-not-recognising-log-files/175744/2 "2019-05-06T00:58:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
