# Logstash7.6 - data loss when input file logrotation happens

**URL:** <https://discuss.elastic.co/t/logstash7-6-data-loss-when-input-file-logrotation-happens/239719>\
**Category:** Logstash\
**Created:** [July 3, 2020, 12:16am UTC](https://discuss.elastic.co/t/logstash7-6-data-loss-when-input-file-logrotation-happens/239719 "2020-07-03T00:16:03Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2020, 12:41am UTC](https://discuss.elastic.co/t/logstash7-6-data-loss-when-input-file-logrotation-happens/239719/2 "2020-07-03T00:41:22Z")

</div>

> [@manu1](#):
>
> We have observed data loss when input file's logrotation happens every day.

That could be an inode reuse issue. There are links to various issues in the META issue [211](https://github.com/logstash-plugins/logstash-input-file/issues/211). Especially see [251](https://github.com/logstash-plugins/logstash-input-file/issues/251).

Tracking which files have been read when those files can get rotated is an extremely hard problem. Way harder than most folks would initially think. A good option to get it right is to checksum the file contents (although this is not foolproof), and the file input does not do that, because it can get ridiculously expensive. Instead it implements a very cheap technique that almost always gets it right (but in a few cases it decides it has already read a file that it has not read).

There are other cases where it gets it wrong by [duplicating data](https://discuss.elastic.co/t/when-logstash-shutdown-renam-file-and-data-can-be-lost-or-duplicated/192669). As I said, it is a really hard problem.

---

_[View the full topic](https://discuss.elastic.co/t/logstash7-6-data-loss-when-input-file-logrotation-happens/239719)._
