# Logstash: Simplest pipeline in the history of mankind not working

**URL:** <https://discuss.elastic.co/t/logstash-simplest-pipeline-in-the-history-of-mankind-not-working/155235>\
**Category:** Logstash\
**Created:** [November 2, 2018, 8:01pm UTC](https://discuss.elastic.co/t/logstash-simplest-pipeline-in-the-history-of-mankind-not-working/155235 "2018-11-02T20:01:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pkaramol](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkaramol/32/22610_2.png) [@pkaramol](https://discuss.elastic.co/u/pkaramol)\
**Post date:** [November 2, 2018, 8:01pm UTC](https://discuss.elastic.co/t/logstash-simplest-pipeline-in-the-history-of-mankind-not-working/155235/1 "2018-11-02T20:01:39Z")

</div>

Using `logstash 2.4` (I have my reasons) on `Ubuntu 16.04`

```
root@logbox:/etc/logstash/conf.d# ls -al
total 16
drwxrwxr-x 2 root root 4096 Nov 2 19:53 .
drwxrwxr-x 3 root root 4096 Nov 2 15:46 ..
-rwxrwxrwx 1 root root 277 Nov 2 19:52 01_01_input.conf
-rwxrwxrwx 1 root root 604 Nov 2 19:48 03_02_output_pa_http.conf

root@logbox:/etc/logstash/conf.d# cat *.conf

input {

  stdin {}

  file {
    path => "/usr/share/logstash/files/production_input.txt"
    start_position => "beginning"
    # codec => plain { charset => "ISO-8859-1" }
    codec => json
    # add_field => ['redis_db', '10']
  }

  
}
output {

  stdout {}

}

root@logbox:/etc/logstash/conf.d# ls -al /usr/share/logstash/files/production_input.txt
-rwxrwxrwx 1 root root 11910 Nov 2 16:09 /usr/share/logstash/files/production_input.txt

```

However...

```
vagrant@logbox:/etc/logstash/conf.d$ sudo tail -f /var/log/logstash/logstash*

Sending logstash logs to /var/log/logstash/logstash.log.

==> /var/log/logstash/logstash.log <==
{:timestamp=>"2018-11-02T19:59:52.947000+0000", :message=>"Pipeline main started"}

==> /var/log/logstash/logstash.stdout <==
{:timestamp=>"2018-11-02T19:59:52.947000+0000", :message=>"Pipeline main started"}

```

The file is not printed in `stdout`...I have tried both codecs (`json` and `plain`)

**edit** : actually it might be the case the file has been read only **once** ; does this have to do with `sincedb`?  
how do I force logstash to read it again? isn't `start_position => beginning` enough?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 4, 2018, 12:10pm UTC](https://discuss.elastic.co/t/logstash-simplest-pipeline-in-the-history-of-mankind-not-working/155235/2 "2018-11-04T12:10:41Z")

</div>

> [@pkaramol](#):
>
> **edit** : actually it might be the case the file has been read only **once** ; does this have to do with `sincedb` ?

Probably. You need to stop Logstash and delete the .sincedb file to make it reread the file.

---

<div class="post-metadata">

**Author:** ![pkaramol](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkaramol/32/22610_2.png) [@pkaramol](https://discuss.elastic.co/u/pkaramol)\
**Post date:** [November 4, 2018, 4:32pm UTC](https://discuss.elastic.co/t/logstash-simplest-pipeline-in-the-history-of-mankind-not-working/155235/3 "2018-11-04T16:32:05Z")

</div>

Any suggestions where this `.sincedb` file is stored?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 5, 2018, 2:12pm UTC](https://discuss.elastic.co/t/logstash-simplest-pipeline-in-the-history-of-mankind-not-working/155235/4 "2018-11-05T14:12:01Z")

</div>

The [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#_tracking_of_current_position_in_watched_files) indicates it should be found in the data directory.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2018, 2:12pm UTC](https://discuss.elastic.co/t/logstash-simplest-pipeline-in-the-history-of-mankind-not-working/155235/5 "2018-12-03T14:12:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
