# No raw logs from logstash

**URL:** <https://discuss.elastic.co/t/no-raw-logs-from-logstash/246775>\
**Category:** Logstash\
**Created:** [August 28, 2020, 1:48pm UTC](https://discuss.elastic.co/t/no-raw-logs-from-logstash/246775 "2020-08-28T13:48:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jhayvee](https://avatars.discourse-cdn.com/v4/letter/j/f1d935/32.png) [@jhayvee](https://discuss.elastic.co/u/jhayvee)\
**Post date:** [August 28, 2020, 1:48pm UTC](https://discuss.elastic.co/t/no-raw-logs-from-logstash/246775/1 "2020-08-28T13:48:03Z")

</div>

I'm trying to do the import logs using IIS logs here's my config below.

input{  
file{  
path =\>"C:/Users/Administrator/Documents/New folder/u\_ex200419.log"  
type =\>"iis"  
start\_position =\> "beginning"  
}  
}  
output{  
elasticsearch{  
hosts =\> ["192.168.2.70:9200"]  
index =\> "iislog"  
}  
stdout {}  
}

i have no error in the logstash please below.

[2020-08-28T21:04:55,785][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.8.1", "jruby.version"=\>"jruby 9.2.11.1 (2.5.7) 2020-03-25 b1f55b1a40 Java HotSpot(TM) 64-Bit Server VM 14.0.2+12-46 on 14.0.2+12-46 +indy +jit [mswin32-x86\_64]"}  
[2020-08-28T21:04:57,254][INFO][org.reflections.Reflections] Reflections took 62 ms to scan 1 urls, producing 21 keys and 41 values  
[2020-08-28T21:04:58,834][INFO][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://192.168.2.70:9200/](http://192.168.2.70:9200/)]}}  
[2020-08-28T21:04:59,065][WARN][logstash.outputs.elasticsearch][main] Restored connection to ES instance {:url=\>"[http://192.168.2.70:9200/](http://192.168.2.70:9200/)"}  
[2020-08-28T21:04:59,120][INFO][logstash.outputs.elasticsearch][main] ES Output version determined {:es\_version=\>7}  
[2020-08-28T21:04:59,127][WARN][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>7}  
[2020-08-28T21:04:59,236][INFO][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//192.168.2.70:9200](https://192.168.2.70:9200)"]}  
[2020-08-28T21:04:59,332][INFO][logstash.javapipeline][main] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>8, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50, "pipeline.max\_inflight"=\>1000, "pipeline.sources"=\>["C:/logstash-7.8.1/logstash-7.8.1/bin/iislog.conf"], :thread=\>"#\<Thread:0x33bcc6dd run\>"}  
[2020-08-28T21:04:59,334][INFO][logstash.outputs.elasticsearch][main] Using default mapping template  
[2020-08-28T21:04:59,490][INFO][logstash.outputs.elasticsearch][main] Attempting to install template {:manage\_template=\>{"index\_patterns"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s", "number\_of\_shards"=\>1}, "mappings"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}  
[2020-08-28T21:05:00,980][INFO][logstash.inputs.file][main] No sincedb\_path set, generating one based on the "path" setting {:sincedb\_path=\>"C:/logstash-7.8.1/logstash-7.8.1/data/plugins/inputs/file/.sincedb\_d657e67e84771d791eb7c63834894e9a", :path=\>["C:/Users/Administrator/Documents/New folder/u\_ex200419.log"]}  
[2020-08-28T21:05:01,008][INFO][logstash.javapipeline][main] Pipeline started {"pipeline.id"=\>"main"}  
[2020-08-28T21:05:01,057][INFO][filewatch.observingtail][main][ee2da0d8570ecf88049a1c4757f8db2e41049921f1a7204d465574228623d142] START, creating Discoverer, Watch with file and sincedb collections  
[2020-08-28T21:05:01,084][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2020-08-28T21:05:01,486][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

I already create a index pattern and i choose the iislog.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/0/800b00e6d21a903a488abad1a273a02d62231ab2.png)

but no raw logs for IISlog.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/f/df4b24c7c8843f59151c5116c95e2083a9df1e7d.png)

please help me on this.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 28, 2020, 8:31pm UTC](https://discuss.elastic.co/t/no-raw-logs-from-logstash/246775/2 "2020-08-28T20:31:58Z")

</div>

Try adding

```
sincedb_path => "NUL"

```

to the file input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2020, 8:31pm UTC](https://discuss.elastic.co/t/no-raw-logs-from-logstash/246775/3 "2020-09-25T20:31:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
