# Logstash throwing \_globbed\_files error while reading a file

**URL:** <https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470>\
**Category:** Logstash\
**Created:** [September 5, 2017, 6:31pm UTC](https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470 "2017-09-05T18:31:55Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajesh](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@rajesh](https://discuss.elastic.co/u/rajesh)\
**Post date:** [September 5, 2017, 6:31pm UTC](https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470/1 "2017-09-05T18:31:55Z")

</div>

Hi,

I am trying to parse file in a directory(Linux) under /opt/\*. I am giving the exact file name and it's throwing an error

`_globbed_files: /opt/my_file_2017-07-21_03-10-46_agg_19303.out: glob is: ["/opt/my_file_2017-07-21_03-10-46_agg_19303.out"] {:level=>:debug, :file=>"filewatch/watch.rb", :line=>"346", :method=>"_globbed_files"}`

/opt directory has read, write, execute permissions. Can someone please explain what the problem is?

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 6, 2017, 5:34am UTC](https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470/2 "2017-09-06T05:34:42Z")

</div>

This isn't an error message, it's a diagnostic message that you asked for by enabling debug-level logging.

---

<div class="post-metadata">

**Author:** ![rajesh](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@rajesh](https://discuss.elastic.co/u/rajesh)\
**Post date:** [September 6, 2017, 4:04pm UTC](https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470/3 "2017-09-06T16:04:00Z")

</div>

Hi Magnus,

But it didn't pick any of the files(deleted sincedb file). After some time without any change it parsed all the files. Can you please say why it's behaving that way? I am using Logstash 2.4.0 and Java 1.7 on redhat distribution.

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 6, 2017, 7:25pm UTC](https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470/4 "2017-09-06T19:25:26Z")

</div>

I don't know why it's behaving like that, but even with greater knowledge of the file input's behavior it would take more details and probably logs to explain it.

---

<div class="post-metadata">

**Author:** ![rajesh](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@rajesh](https://discuss.elastic.co/u/rajesh)\
**Post date:** [September 7, 2017, 6:57pm UTC](https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470/5 "2017-09-07T18:57:41Z")

</div>

Will capture the logs if it happens again. Can you please explain how sincedb works when there are lot of input files and a single sincedb file. I assume sincedb logs multiple entries for all the files.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 8, 2017, 6:06am UTC](https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470/6 "2017-09-08T06:06:59Z")

</div>

Yes, one entry per file and one file per file input (or is it filename pattern?).

---

<div class="post-metadata">

**Author:** ![rajesh](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@rajesh](https://discuss.elastic.co/u/rajesh)\
**Post date:** [September 9, 2017, 11:33pm UTC](https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470/7 "2017-09-09T23:33:47Z")

</div>

> [@magnusbaeck](#):
>
> (or is it filename pattern?).

I didn't get it

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 11, 2017, 6:02am UTC](https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470/8 "2017-09-11T06:02:43Z")

</div>

The file input supports multiple filename pattern (i.e. the `path` option can point to an array of patterns). I don't remember if it's one sincedb file per file input or one per pattern in the `path` option. It's probably one sincedb file per file input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2017, 6:02am UTC](https://discuss.elastic.co/t/logstash-throwing--globbed-files-error-while-reading-a-file/99470/9 "2017-10-09T06:02:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
