# Problem with input file logstash version 1.5.3

**URL:** <https://discuss.elastic.co/t/problem-with-input-file-logstash-version-1-5-3/62796>\
**Category:** Logstash\
**Created:** [October 12, 2016, 10:01am UTC](https://discuss.elastic.co/t/problem-with-input-file-logstash-version-1-5-3/62796 "2016-10-12T10:01:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 12, 2016, 10:01am UTC](https://discuss.elastic.co/t/problem-with-input-file-logstash-version-1-5-3/62796/1 "2016-10-12T10:01:25Z")

</div>

Hello, I'm trying to take the logs from a file and send them to an elasticsearh instance in another machine, but I don't know why everytime I try it logstash service keep running without finishing the service and no new index is created in ES machine.

this is my logstash configuration:

```
input {
  file {
    path => ["/etc/elk/logout/test"]
    type => "file"
    start_position => "beginning"
  }
}
filter {

 if [type]== "file"{
       mutate {
             rename => ["@host", "host"]
        }
        dns {
             reverse => ["host"]
             action => "replace"
             nameserver => "IP_DNS_SERVER"
        }

       grok {
             patterns_dir => "/etc/logstash/patterns"
             match => [
                     "message","%{MESSAGE_1}",
                     "message", "%{MESSAGE_2}",
                    "message", "%{MESSAGE_3}",
                    "message", "%{MESSAGE_4}",
                    "message", "%{MESSAGE_5}"
                     ]
            }

         date{
           match => ["dater", "YYYY/MM/dd HH:mm:ss.SSS"]
           target => "@timestamp"
               }
}
}

output {

elasticsearch
{
    protocol => "http"
    cluster => "logstash"
     host=>"IP_B"
     index => "logstash-syslog-%{+YYYY.MM.dd}-fromFile"
    }
}

```

This is the format of text file content (it has been taken from another ES instance:

```
{"message":"2016/10/05 15:09:30.146 ...","@version":"1","@timestamp":"2016-10-05T13:09:30.205Z","type":"udp"...."} 
{"message...} 
...
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 12, 2016, 10:52am UTC](https://discuss.elastic.co/t/problem-with-input-file-logstash-version-1-5-3/62796/2 "2016-10-12T10:52:44Z")

</div>

> everytime I try it logstash service keep running without finishing the service

Logstash doesn't shut down just because it reaches the end of the input file. It's designed to continuously monitor files and send data as it arrives.

> and no new index is created in ES machine.

This is an extremely common problem that people are having. Please see my response here: [Logstash not indexing the input data to elastic search](https://discuss.elastic.co/t/logstash-not-indexing-the-input-data-to-elastic-search/62659)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:34am UTC](https://discuss.elastic.co/t/problem-with-input-file-logstash-version-1-5-3/62796/3 "2017-07-06T04:34:35Z")

</div>


