# Logstash start successfully but no result

**URL:** <https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611>\
**Category:** Logstash\
**Created:** [June 18, 2020, 9:54am UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611 "2020-06-18T09:54:34Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 18, 2020, 9:54am UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/1 "2020-06-18T09:54:34Z")

</div>

Hello,  
I really need help importing my log files.  
If I create a file right now, this will be imported successfully, but if I try to import a file that already exists since about 11 hours, logstash will not show any output!!  
i get this :

```auto
[INFO] 2020-06-18 09:45:24.043 [Converge PipelineAction::Create<main>] pipeline - Pipeline started successfully {:pipeline_id=>"main", :thread=>"#<Thread:0x698e3f67 run>"}
[INFO] 2020-06-18 09:45:24.097 [[main]<file] observingtail - START, creating Discoverer, Watch with file and sincedb collections
[INFO] 2020-06-18 09:45:24.114 [Agent thread] agent - Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[INFO] 2020-06-18 09:45:24.588 [Api Webserver] agent - Successfully started Logstash API endpoint {:port=>9600}

```

and my config file is :

```auto
input{
        file {
        path => ["/home/...../Gest/*"]
                start_position => beginning
                ignore_older => 86400
                codec => multiline {
                        charset => "BINARY"
                        pattern => "^%{YEAR}%{MONTHDAY}%{MONTHNUM2}"
                        negate => true
                        what => previous
                }
    }
}

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [June 18, 2020, 10:34am UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/2 "2020-06-18T10:34:47Z")

</div>

> **[File input plugin | Logstash Plugins](https://www.elastic.co/docs/reference/logstash/plugins/plugins-inputs-file)**
>
> Plugin version: v4.4.7 (Other versions), Released on: 2026-01-31, Changelog. For questions about the plugin, open a topic in the Discuss forums. For bugs...

Maybe the file was already read before and won't give any new results. Add the below to test that.

```auto
sincedb_path => "/dev/null"

```

Or you can just add a line entry in the file to see if it just reads that single one.

---

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 18, 2020, 10:50am UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/3 "2020-06-18T10:50:14Z")

</div>

I tried this but I get same result

```auto
input{
        file {
        path => ["/home/user_ftp/..../*.txt"]
                start_position => "beginning"
                ignore_older => 0
                sincedb_path => "/dev/null"
                codec => multiline {
                        charset => "BINARY"
                        pattern => "^%{YEAR}%{MONTHDAY}%{MONTHNUM2}"
                        negate => true
                        what => previous
                }
    }
}

```

---

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 18, 2020, 10:59am UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/4 "2020-06-18T10:59:03Z")

</div>

I just want to specify that this configuration works with the test files I create myself, and I didn't perform an import on the current folder .

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [June 18, 2020, 11:10am UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/5 "2020-06-18T11:10:25Z")

</div>

If you remove the multiline and test what happens?

---

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 18, 2020, 11:17am UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/6 "2020-06-18T11:17:01Z")

</div>

I've commented every line, but still no output

```auto
 #codec => multiline {
                # charset => "BINARY"
                # pattern => "^%{YEAR}%{MONTHDAY}%{MONTHNUM2}"
                #
                # negate => true
                # what => previous
                #}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 18, 2020, 3:09pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/7 "2020-06-18T15:09:14Z")

</div>

> [@Katia](#):
>
> `ignore_older => 0`

In filebeat, setting ignore\_older to zero tells filebeat not to filter files based on age.

In a logstash file input, setting ignore\_older to zero tells the input to ignore any files more than zero seconds old, which is every file.

---

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 18, 2020, 7:59pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/8 "2020-06-18T19:59:26Z")

</div>

I think it works now, but it was just a test (I left some commented lines) so I need to import it again. do I need to change sincedb\_path ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 18, 2020, 8:43pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/9 "2020-06-18T20:43:25Z")

</div>

If you want to re-read files you could stop logstash and remove entries from the sincedb, or point sincedb\_path to a new location to completely start over.

---

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 18, 2020, 9:03pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/10 "2020-06-18T21:03:00Z")

</div>

is there another way to stop logstash other than ctrl+c

---

<div class="post-metadata">

**Author:** ![Rahul\_Kumar4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_kumar4/32/67369_2.png) [@Rahul\_Kumar4](https://discuss.elastic.co/u/Rahul_Kumar4)\
**Post date:** [June 18, 2020, 9:12pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/11 "2020-06-18T21:12:16Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/shutdown.html](https://www.elastic.co/guide/en/logstash/current/shutdown.html)

---

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 18, 2020, 9:30pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/12 "2020-06-18T21:30:55Z")

</div>

After the last line, logstash still waiting so i can't execute systemctl stop logstash

```auto
{
      "@version" => "1",
          "path" => "/home/.../.txt",
           "seq" => 374167,
         "count" => "1",
     "timestamp" => "20201806\t00:07:09.993",
    "@timestamp" => 2020-06-18T00:07:09.993Z,
          "data" => "MPC CarteAbsente A:3,I:1,P:0,R:0,E:",
       "message" => "20201806\t00:07:09.993\tMPC CarteAbsente A:3,I:1,P:0,R:0,E:1\\n"
}
|

```

---

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 18, 2020, 9:35pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/13 "2020-06-18T21:35:52Z")

</div>

My problem is not really solved:  
I can retrieve yesterday's logs with ignore\_older =\> 86400, but with ignore\_older =\> 7200 no output !

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [June 19, 2020, 1:35am UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/14 "2020-06-19T01:35:10Z")

</div>

Have you removed the ignore\_older parameter and tried it? It doesn't sound like you even need it.

---

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 19, 2020, 8:04am UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/15 "2020-06-19T08:04:27Z")

</div>

I have a lot of files, and I only need the log that was generated today, that's why I'm using ignore\_older

---

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 19, 2020, 12:23pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/16 "2020-06-19T12:23:36Z")

</div>

Sometimes I success to import the file and other times not.  
Sometimes I change the path or ignore\_older.  
But I don't really understand this situation!!

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [June 19, 2020, 12:29pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/17 "2020-06-19T12:29:12Z")

</div>

Is it an option for you to create a folder where only the files you want imported go? Then just remove the ignore parameter? So every file currently in that folder and all new ones will get processed?

I don't understand what's going on either.

---

<div class="post-metadata">

**Author:** ![abrx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abrx/32/43881_2.png) [@abrx](https://discuss.elastic.co/u/abrx)\
**Post date:** [June 19, 2020, 12:37pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/18 "2020-06-19T12:37:18Z")

</div>

Hi,

You can reload logstash configuration using a SIGHUP signal, so as you specified to gather lines from the begining it shoud ingest it again.

To do so, you can just do a `kill -1` to logstash's pid, for instance:  
`ps -ef |grep [l]ogstash | awk -F' ' '{print $2}' | xargs -I {} kill -1 {}`

If it's not enough, you should delete the sincedb files used yo track the parser position in the file, using a `find -rm` .

---

<div class="post-metadata">

**Author:** ![Katia](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@Katia](https://discuss.elastic.co/u/Katia)\
**Post date:** [June 19, 2020, 12:55pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/19 "2020-06-19T12:55:18Z")

</div>

I didn't think about moving the already imported files to another directory, I thought I could do it with ignore\_older

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2020, 12:55pm UTC](https://discuss.elastic.co/t/logstash-start-successfully-but-no-result/237611/20 "2020-07-17T12:55:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
