# No output - (no matches ?) with my config-file

**URL:** <https://discuss.elastic.co/t/no-output-no-matches-with-my-config-file/42127>\
**Category:** Logstash\
**Created:** [February 18, 2016, 10:40am UTC](https://discuss.elastic.co/t/no-output-no-matches-with-my-config-file/42127 "2016-02-18T10:40:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Justin\_V](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@Justin\_V](https://discuss.elastic.co/u/Justin_V)\
**Post date:** [February 18, 2016, 10:40am UTC](https://discuss.elastic.co/t/no-output-no-matches-with-my-config-file/42127/1 "2016-02-18T10:40:59Z")

</div>

Hi everyone.

## So, I'm a little bit new at the elk-stack, and I’m having an issue with further experiment with the tools. I'm using a linux machine. First of all, here's my config-file :

> input {  
> file {  
> type =\> "openerp"  
> path =\> "/home/jvc/Documents/log/openerp-cron.log.2014-11-20.txt"  
> start\_position =\> "beginning"  
> codec =\> multiline{  
> pattern =\> "^%{TIMESTAMP\_ISO8601} "  
> negate =\> true  
> what =\> previous  
> }  
> }  
> }  
> filter{  
> if [type]=="openerp"{  
> date{  
> match =\> ["timestamp","yyyy-MM-dd HH:mm:ss,SSS"]  
> }  
> grok{  
> patterns\_dir =\> "./patterns"  
> match =\> { "message" =\> "%{ODOOLOG}" }  
> }  
> }  
> }  
> output{  
> file{  
> path =\> "/home/jvc/Bureau/testretour.txt"  
> }  
> }

* * *

I have some patterns too :

> REQUESTTIMESTAMP %{MONTHDAY}/%{MONTH}/%{YEAR} %{TIME}  
> REQUEST %{IPORHOST:client} %{USER:ident} %{USER:auth} [%{REQUESTTIMESTAMP:request\_timestamp}] "%{WORD:request\_type} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response} -  
> ODOOMISC %{GREEDYDATA}  
> ODOOLOG %{TIMESTAMP\_ISO8601:timestamp} %{POSINT:pid} %{LOGLEVEL:level} (?:%{USERNAME:user}|?) %{PROG:module}: (?:%{REQUEST}|%{ODOOMISC:misc})

* * *

Some examples of the logs :

> 2014-11-21 08:00:16,715 17798 DEBUG noe openerp.addons.base.ir.ir\_cron: cron.object.execute('noe', 1, '\*', u'crossovered.budget.lines', u'\_compute\_blank')  
> 2014-11-21 08:00:17,172 17798 WARNING noe openerp.osv.orm.browse\_record.noe\_utils.synchro\_date: Field ' **conform**' does not exist in object 'browse\_record(noe\_utils.synchro\_date, 13)'  
> 2014-11-21 08:00:17,172 17798 ERROR noe openerp.sql\_db: Programming error: can't adapt type 'browse\_record', in query SELECT id  
> FROM crossovered\_budget\_lines  
> WHERE is\_blank='t'  
> AND general\_budget\_id in %s  
> AND date\_from \<= %s AND date\_to \>= %s  
> 2014-11-21 08:00:17,173 17798 ERROR noe openerp.addons.base.ir.ir\_cron: Call of self.pool.get('crossovered.budget.lines').\_compute\_blank(cr, uid, \*()) failed in Job 10

* * *

I'm having trouble with this config. For some reason that I can't find, this produces nothing.  
What I have tried - done :  
-First of all, I tested my grok, and multiline _pattern_ in some grok debugger I have find on the web. All of them matches my logs.  
-Before using the codec for multiline, i used the multiline filter. This one worked, but seems to be deprecated. So it's not a solution.  
-I know that logstash keep in mind what he had read or not with the "sincedb" files : I delete these before every test, but you know what happens.  
-I tried to run logstash with the -verbose, but nothing wrong is displayed.  
-I don't really know if I must write the ".txt" at the end of my paths. But anyway, none of them works.

Have I missed something ? Thank you in advance for helping hands.

---

<div class="post-metadata">

**Author:** ![Justin\_V](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@Justin\_V](https://discuss.elastic.co/u/Justin_V)\
**Post date:** [February 18, 2016, 12:27pm UTC](https://discuss.elastic.co/t/no-output-no-matches-with-my-config-file/42127/2 "2016-02-18T12:27:37Z")

</div>

So, with more test I succeeded. I copied the content of one of my logs file and pasted it in another file : It works.

But, there is now another question : if deleting the "sincedb" file doesn't work, how can i "empty" the cache of logstash ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 20, 2016, 7:43pm UTC](https://discuss.elastic.co/t/no-output-no-matches-with-my-config-file/42127/3 "2016-02-20T19:43:57Z")

</div>

Deleting the sincedb file(s) will work, but you have to shutdown Logstash before removing them. Logstash's verbose logs (i.e. start with `--verbose`) will tell you everything you need to know about which files are tracked, which sincedb files there are, the current position in the input files, and so on.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:10am UTC](https://discuss.elastic.co/t/no-output-no-matches-with-my-config-file/42127/4 "2017-07-06T05:10:27Z")

</div>


