# Logstash2.4 File Input doesn't work

**URL:** <https://discuss.elastic.co/t/logstash2-4-file-input-doesnt-work/66087>\
**Category:** Logstash\
**Created:** [November 15, 2016, 10:04am UTC](https://discuss.elastic.co/t/logstash2-4-file-input-doesnt-work/66087 "2016-11-15T10:04:53Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![yiju](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@yiju](https://discuss.elastic.co/u/yiju)\
**Post date:** [November 15, 2016, 10:04am UTC](https://discuss.elastic.co/t/logstash2-4-file-input-doesnt-work/66087/1 "2016-11-15T10:04:53Z")

</div>

Hi,

I'm running logstash 2.4 as a service in Ubuntu 14.04.

Here is my config:  
input {  
file {  
path =\> "/mnt/resource/hadoop/yarn/log/_/_/stderr"  
start\_position =\> beginning  
stat\_interval =\> 300  
discover\_interval =\> 0  
codec =\> multiline {  
pattern =\> "^%{TIMESTAMP\_ISO8601} "  
negate =\> true  
what =\> "previous"  
auto\_flush\_interval =\> 10  
max\_lines =\> 1000000  
max\_bytes =\> "1 GiB"  
}  
}  
}  
filter {  
grok {  
match =\> ["path","%{GREEDYDATA}/%{GREEDYDATA:filename}.log"]  
}  
}  
output {  
azureblob {  
storage\_account\_name =\> "oasparkintegratedata"  
storage\_access\_key =\> "j2ybUFO667hiHBB+lttAv18JWAluoCiuM2cvEWi5Sg7sDGNC+16+wRxRkXc1MmwxzG/x768RTUeffLqOm03aNw=="  
azure\_container =\> "test"  
}  
}

When the service starts, it shows the following information:  
{:timestamp=\>"2016-11-15T09:54:24.184000+0000", :message=\>"Starting pipeline", :id=\>"main", :pipeline\_workers=\>1, :batch\_size=\>125, :batch\_delay=\>5, :max\_inflight=\>125, :level=\>:info}  
{:timestamp=\>"2016-11-15T09:54:24.185000+0000", :message=\>"Pipeline main started"}

Then, it shows nothing new in both logstash.err and logstash.log files. I tried to remove .sincedb file and the monitored folder is keep writing new lines, but still no events found by logstash. What's the problem here?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 15, 2016, 10:13am UTC](https://discuss.elastic.co/t/logstash2-4-file-input-doesnt-work/66087/2 "2016-11-15T10:13:02Z")

</div>

I seriously doubt it's a good idea to have `discover_interval => 0`.

I suggest you bump the log level with `--verbose` or even `--debug` to get additional clues about what the file input is doing.

---

<div class="post-metadata">

**Author:** ![yiju](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@yiju](https://discuss.elastic.co/u/yiju)\
**Post date:** [November 22, 2016, 6:54am UTC](https://discuss.elastic.co/t/logstash2-4-file-input-doesnt-work/66087/3 "2016-11-22T06:54:13Z")

</div>

Sorry for late reply. I'm forced to set discover\_interval =\> 0 as for new file discover time is also related to stat\_interval. If I set large discover interval, it won't find new files for a long period.

I set log level to --verbose, the logs didn't show any useful error messages. The logs flooding when set level to --debug. I can't catch useful clues till now.

Indeed, the file input can actually find some files under the given path, but it also can't find some files. Once, I found some files were not caught by the input, I did nothing just run command "service logstash reload", then it worked for the unfound files. After sometime, it can't find part of files again. It's really strange and I have no idea how to resolve it.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 22, 2016, 6:59am UTC](https://discuss.elastic.co/t/logstash2-4-file-input-doesnt-work/66087/4 "2016-11-22T06:59:06Z")

</div>

Logstash logs which files it finds when it expands the filename patterns. Is that list correct? If you have a large file churn maybe your problem is inode number reuse.

---

<div class="post-metadata">

**Author:** ![yiju](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@yiju](https://discuss.elastic.co/u/yiju)\
**Post date:** [November 22, 2016, 7:25am UTC](https://discuss.elastic.co/t/logstash2-4-file-input-doesnt-work/66087/5 "2016-11-22T07:25:55Z")

</div>

Yes, it's able to find some of files under the filename patterns. I found the .sincedb file had record of a file's inode number, but indeed it didn't found in the output. Dose this phenomenon related to inode number reuse? Why won't file input continue to handle file with the inode number in the .sincedb file?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 22, 2016, 7:59am UTC](https://discuss.elastic.co/t/logstash2-4-file-input-doesnt-work/66087/6 "2016-11-22T07:59:23Z")

</div>

> Yes, it's able to find some of files under the filename patterns.

Some of the files? Or all files?

> I found the .sincedb file had record of a file's inode number, but indeed it didn't found in the output. Dose this phenomenon related to inode number reuse? Why won't file input continue to handle file with the inode number in the .sincedb file?

According to the sincedb file Logstash has already processed the file. Logstash's file input isn't able of deleting old entries from sincedb but I think Filebeat is.

---

<div class="post-metadata">

**Author:** ![yiju](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@yiju](https://discuss.elastic.co/u/yiju)\
**Post date:** [November 22, 2016, 10:41am UTC](https://discuss.elastic.co/t/logstash2-4-file-input-doesnt-work/66087/7 "2016-11-22T10:41:33Z")

</div>

> [@](#):
>
> Logstash logs which files it finds when it expands the filename patterns. Is that list correct? If you have a large file churn maybe your problem is inode number reuse.

It can only find some files.

I found a new issue that after running a period of time, file input can't find new file under the given pattern any more.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2016, 10:41am UTC](https://discuss.elastic.co/t/logstash2-4-file-input-doesnt-work/66087/8 "2016-12-20T10:41:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
