# Logstash read mode not reading file with same name

**URL:** <https://discuss.elastic.co/t/logstash-read-mode-not-reading-file-with-same-name/234861>\
**Category:** Logstash\
**Created:** [May 29, 2020, 5:40am UTC](https://discuss.elastic.co/t/logstash-read-mode-not-reading-file-with-same-name/234861 "2020-05-29T05:40:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ghostd9](https://avatars.discourse-cdn.com/v4/letter/g/e9c0ed/32.png) [@ghostd9](https://discuss.elastic.co/u/ghostd9)\
**Post date:** [May 29, 2020, 5:40am UTC](https://discuss.elastic.co/t/logstash-read-mode-not-reading-file-with-same-name/234861/1 "2020-05-29T05:40:35Z")

</div>

Hi

I'm using the read mode in logstash (version-7.7.0) to read my log files and delete them once they've been parsed by logstash. The use case is such that I have a log file in which data will be coming in intervals which is not fixed (Can be minutes or hours) and the disk space on the server is low so we want to remove log files which have been consumed by logstash. Below is my logstash conf file

```auto
    input {
        file {
            path => "/path/to/log/file/*"
            file_completed_action => "delete"
            mode => "read"
            sincedb_path => "/dev/null"
      }
    }

    filter {
     grok { match => { "message" => "%{TIMESTAMP_ISO8601:createdtime} %{GREEDYDATA:logmessage}" }
     }
     mutate{
             remove_field => ["message"]
           }
     date{
             match => ["logtime", "YYYY-MM-dd HH:mm:ss.SSSSSS"]
             target => "logtime"
     }
    }

    output {
      kafka {
        bootstrap_servers => "kafka1:9092,kafka2:9092"
        topic_id => ["mytopic"]
        codec => "json"
        compression_type => "gzip"
      }
      stdout { codec => rubydebug }
    }

```

The issue that i'm facing is that logstash initially parses the file and deletes it after consumption but when the file with the same name is created again, logstash is not consuming it. When I change the name then logstash parses the file with the new name and deletes it as well. Please help me out here.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 29, 2020, 12:59pm UTC](https://discuss.elastic.co/t/logstash-read-mode-not-reading-file-with-same-name/234861/2 "2020-05-29T12:59:41Z")

</div>

This is most likely due to inode reuse. There are multiple [open issues](https://github.com/logstash-plugins/logstash-input-file/issues?q=is%3Aissue+is%3Aopen+inode+sincedb) related to it. Everyone knows how to fix it, but nobody is working on it.

---

<div class="post-metadata">

**Author:** ![ghostd9](https://avatars.discourse-cdn.com/v4/letter/g/e9c0ed/32.png) [@ghostd9](https://discuss.elastic.co/u/ghostd9)\
**Post date:** [June 1, 2020, 7:38am UTC](https://discuss.elastic.co/t/logstash-read-mode-not-reading-file-with-same-name/234861/3 "2020-06-01T07:38:05Z")

</div>

Thanks Badger.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2020, 7:38am UTC](https://discuss.elastic.co/t/logstash-read-mode-not-reading-file-with-same-name/234861/4 "2020-06-29T07:38:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
