# Logstash with rotating logs

**URL:** <https://discuss.elastic.co/t/logstash-with-rotating-logs/152031>\
**Category:** Logstash\
**Created:** [October 11, 2018, 10:46am UTC](https://discuss.elastic.co/t/logstash-with-rotating-logs/152031 "2018-10-11T10:46:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![serozhka](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@serozhka](https://discuss.elastic.co/u/serozhka)\
**Post date:** [October 11, 2018, 10:46am UTC](https://discuss.elastic.co/t/logstash-with-rotating-logs/152031/1 "2018-10-11T10:46:37Z")

</div>

Hi!  
We use logstash 6.2.4. which sends logs to Kafka nodes. We need to to track application logs which are rotated each 24h, it is not possible to control log file names and their format is like:  
mylogfile\_20181007\_000000.log  
mylogfile\_20181008\_000000.log  
mylogfile\_20181009\_000000.log

Easiest would be to issue:  
input {  
file {  
path =\> "/my/application/logs/mylogfile\_\_\*.log"

But in this case it captures all the logs all the time, consuming CPU. I tried to add  
ignore\_older =\> "300"  
max\_open\_files =\> "1"  
Unfortunately, it still wants to capture all logs but one by one because of "max\_open\_files"

Issue is that I want logstash to work only with one (current day) file. Is there any possibility to enter path only to work with current day file?  
E.g.  
path =\> "/my/application/logs/mylogfile\_\_"%{CURRENTDATE}"\_"%{[0-9.]+}".log

where  
CURRENTDATE is today's date in format YYYYMMDD  
[0-9.]+ is some regex for any number, because instead of "000000" there could be e.g. "000001"

---

<div class="post-metadata">

**Author:** ![OphyTe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ophyte/32/36444_2.png) [@OphyTe](https://discuss.elastic.co/u/OphyTe)\
**Post date:** [October 11, 2018, 3:55pm UTC](https://discuss.elastic.co/t/logstash-with-rotating-logs/152031/2 "2018-10-11T15:55:50Z")

</div>

Maybe with something like that :

```
input {
  exec {
    command => "tail -f mylogfile_`date +%Y%m%d`_000000.log
    schedule => "0 0 * * *"
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2018, 3:55pm UTC](https://discuss.elastic.co/t/logstash-with-rotating-logs/152031/3 "2018-11-08T15:55:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
