# Logstash re-processes files, incorrectly updates sincedb

**URL:** <https://discuss.elastic.co/t/logstash-re-processes-files-incorrectly-updates-sincedb/358640>\
**Category:** Logstash\
**Created:** [May 2, 2024, 12:05pm UTC](https://discuss.elastic.co/t/logstash-re-processes-files-incorrectly-updates-sincedb/358640 "2024-05-02T12:05:20Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 2, 2024, 5:10pm UTC](https://discuss.elastic.co/t/logstash-re-processes-files-incorrectly-updates-sincedb/358640/2 "2024-05-02T17:10:09Z")

</div>

You state that inodes are being re-used. Detecting that in the file input is a ridiculously hard problem. Any approach that has a reasonable cost (i.e. not doing checksums on chunks of the file) will sometimes get the answer wrong. See [this](https://discuss.elastic.co/t/when-logstash-shutdown-renam-file-and-data-can-be-lost-or-duplicated/192669/3) thread for an example.

And yes, it having the wrong name for a file in the sincedb is indeed strange.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-re-processes-files-incorrectly-updates-sincedb/358640)._
