# Logstash on docker: configure sincedb file to use the last indexed position whenever container restarts/new

**URL:** <https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [July 16, 2020, 7:33pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537 "2020-07-16T19:33:43Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [July 16, 2020, 7:33pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/1 "2020-07-16T19:33:44Z")

</div>

Hi Team

I mounted the logstash sincedb position to a persistent volume assuming logstash will remember the position of last indexed log. But every time I create/restart a container it's pushing all the logs again to elasticsearch.

What am I missing here.

Kubernetes file:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/0/b032ca3dc80fab6737bfb7c03dab0b6e7d405eb8.jpeg)

Logstash sincedb path:

`sincedb_path => "/usr/share/logstash/data/sincedb/.sincedb"`

Any suggestions would be helpful.

Thank you

Best  
Rahul

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 16, 2020, 8:02pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/2 "2020-07-16T20:02:28Z")

</div>

A file input [tracks](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#_tracking_of_current_position_in_watched_files) a file identity using a combination of name, inode, major and minor device numbers. Is it possible the device number changes when you create a new container?

If you enable trace level logging you should see this message when a sincedb entry is read

```auto
[2019-07-30T13:18:08,571][TRACE][filewatch.sincedbcollection] open: setting #<struct FileWatch::InodeStruct inode="8420933", maj=0, min=51713> to #<FileWatch::SincedbValue:0x3050973 @last_changed_at=1564492539.4538882, @path_in_sincedb="/tmp/test/test.log", @watched_file=nil, @position=4>

```

and this message when it first see a file

```auto
[2019-07-30T13:18:08,984][TRACE][filewatch.discoverer] discover_files handling: {"new discovery"=>true, "watched_file details"=>"<FileWatch::WatchedFile: @filename='test.log.1', @state='watched', @recent_states='[:watched]', @bytes_read='0', @bytes_unread='0', current_size='4', last_stat_size='4', file_open?='false', @initial=true, @sincedb_key='8420933 0 51713'>"}

```

Check if the sincedb\_key in the second message matches the values in the InodeStruct in the first.

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [July 16, 2020, 8:17pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/3 "2020-07-16T20:17:23Z")

</div>

Hi Badger

Not sure on how to check the device number ?

Will see the logs by setting loglevel trace.

Also, in my logstash.conf file have start\_position =\> "beginning". will this force the logstash to start from beginning irrespective of sincedb file ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 16, 2020, 9:57pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/4 "2020-07-16T21:57:24Z")

</div>

> [@rahulnama](#):
>
> Not sure on how to check the device number ?

Maybe "sar -d", maybe "lsblk", maybe "ls -l /dev". It really depends on the flavour of your OS.

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [July 17, 2020, 12:22am UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/5 "2020-07-17T00:22:49Z")

</div>

Hi @Badger Badger

Logstash is working fine even when restarted. I removed the start\_position from logstash.conf

Still, I have a question. What happens when the log file is cleared and updated with new logs. Because for every application restart log file will be cleared.

Will logstash be able to identify and ingest all the new logs from start. I believe that should be the behavior. please let me know

Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2020, 2:06am UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/6 "2020-07-17T02:06:57Z")

</div>

> [@rahulnama](#):
>
> Will logstash be able to identify and ingest all the new logs from start. I believe that should be the behavior

That is what everyone wants, but determining whether an updated file is an extension of a file that has already been mostly read, or a completely new file is ridiculously hard. Far harder than anyone would think until they have attempted to implement it.

If you re-read the entire file and verify that the parts already read are exactly the same then you can assume (sometimes incorrectly) that the file is the same.

Alternatively you can make some assumptions that work almost all the time, and make the process very cheap, but sometimes break down. That is what the file filter does.

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [July 17, 2020, 2:38am UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/7 "2020-07-17T02:38:58Z")

</div>

@Badger

Got it. Very interesting. Any insights on how logstash does it internally ? Excited to know. Also, is there any blog explaining about it. would be very helpful.

Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2020, 4:03pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/8 "2020-07-17T16:03:07Z")

</div>

I do not think it is documented anywhere.

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [July 17, 2020, 8:17pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/9 "2020-07-17T20:17:57Z")

</div>

Got it.

Also, I'm trying with few different scenarios to fully understand this.

So, I stopped logstash and restarted it after some time. I see no logs in kibana for the time logstash has been shutdown.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/e/1e3a006a3dac79ec78cb0c16aed4154a81aae61b.png)

I believe once logstash starts, it should either send all the logs or it should send the logs from previous indexed log. But why is it missing the logs ? Any suggestions ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2020, 8:42pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/10 "2020-07-17T20:42:28Z")

</div>

It depends on the configuration of the file input, but generally it should start reading from where it left off. So if you are using a date filter to set @timestamp I would expect that gap to have been filled in.

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [July 17, 2020, 8:47pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/11 "2020-07-17T20:47:49Z")

</div>

Got it.

This is my file input configuration

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/4/248ffe72883cdbe195bd17b7337a768849b273ab.png)

And yes, I'm using a date filter to set timestamp.

Is there anything I'm missing ?

-- Rahul

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2020, 9:22pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/12 "2020-07-17T21:22:57Z")

</div>

> [@rahulnama](#):
>
> Is there anything I'm missing ?

Not that I can see.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2020, 9:22pm UTC](https://discuss.elastic.co/t/logstash-on-docker-configure-sincedb-file-to-use-the-last-indexed-position-whenever-container-restarts-new/241537/13 "2020-08-14T21:22:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
