# Reading a log file into Logstash

**URL:** <https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514>\
**Category:** Logstash\
**Created:** [June 28, 2015, 11:13pm UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514 "2015-06-28T23:13:03Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![gruszeckim2](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gruszeckim2](https://discuss.elastic.co/u/gruszeckim2)\
**Post date:** [June 28, 2015, 11:13pm UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/1 "2015-06-28T23:13:03Z")

</div>

I'm new to logstash/elasticsearch and am trying to teach myself how to use them. I've written a config file to read a file into logstash and then forward it to elasticsearch and, for the life of me, logstash never seems to read the file. Here is the config:

input {  
file {  
path =\> "C:\Users\baneling\Desktop\logstash-1.5.1\bin\test.log"  
}  
}  
output {  
stdout { codec =\> rubydebug }  
#elasticsearch{ host =\> localhost }  
}

The contents of test.log are the following:

this is a test 1  
this is a test 2  
this is a test 3  
this is a test 4

I've tried configuring it with a variety of types (apache-access, apache, log4j). I've tried using grok patterns to look for stuff to take from the lines in the file. I've specified directly the sincedb path )the default is correct, though). I've even tried using the start position as "beginning" and have tried modifying the file after logstash is running since it is essentially tailing it. Nothing seems to work aside from the stdin plugin - any advice? I'm on a Windows 8 64bit OS, by the way. Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 28, 2015, 11:16pm UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/2 "2015-06-28T23:16:49Z")

</div>

It's a sincedb issue, check the file input docs for more info on it. But the short of it is that you need to delete the file that tracks Logstash's progress in processing it.

---

<div class="post-metadata">

**Author:** ![gruszeckim2](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gruszeckim2](https://discuss.elastic.co/u/gruszeckim2)\
**Post date:** [June 28, 2015, 11:45pm UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/3 "2015-06-28T23:45:26Z")

</div>

Hi Warkolm,

I've tried deleting the sincedb files and then starting logstash fresh - that didn't seem work work either. I'll do some more reading, but any other, more specific suggestions are welcome!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 28, 2015, 11:47pm UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/4 "2015-06-28T23:47:48Z")

</div>

Then it's probably [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-start\_position](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-start_position)

---

<div class="post-metadata">

**Author:** ![gruszeckim2](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gruszeckim2](https://discuss.elastic.co/u/gruszeckim2)\
**Post date:** [June 29, 2015, 12:17am UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/5 "2015-06-29T00:17:21Z")

</div>

Hi Warkolm,

I juststopped logstash, deleted my sincedb file, modified my config to the one below, and started logstash. Still not working. Any more suggestions?

input {  
file {  
path =\> "C:\Users\grusz\_000\Desktop\logstash-1.5.1\bin\ip.log"  
start\_position =\> "beginning"  
}  
}  
output {  
stdout { codec =\> rubydebug }  
#elasticsearch{ host =\> localhost }  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 29, 2015, 3:43am UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/6 "2015-06-29T03:43:47Z")

</div>

A permissions issue? Try starting Logstash with `--verbose` or even `--debug` and see what it says. If it doesn't scream about the permissions it'll tell you straight out what it thinks about sincedb and the current position in the file.

---

<div class="post-metadata">

**Author:** ![jrgns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jrgns/32/640_2.png) [@jrgns](https://discuss.elastic.co/u/jrgns)\
**Post date:** [June 29, 2015, 5:35am UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/7 "2015-06-29T05:35:11Z")

</div>

Hey

Just confirming the obvious, here. Are you not seeing output on stdout?

Did you try enabling the elasticsearch output and checking there as well?

J

---

<div class="post-metadata">

**Author:** ![gruszeckim2](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gruszeckim2](https://discuss.elastic.co/u/gruszeckim2)\
**Post date:** [June 30, 2015, 12:20am UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/8 "2015-06-30T00:20:43Z")

</div>

Hi Everyone,

It wasn't any kind of permission issue or anything. I fixed it by adding in the following:

sincedb\_path \> "/dev/null"

I don't quite know why this lets me read from a file. Can anyone explain?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 30, 2015, 3:28am UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/9 "2015-06-30T03:28:25Z")

</div>

I can't explain it either, but having a null `sincedb_path` is a very bad idea since Logstash won't be able to keep track of the current position in each file, so you may end up processing files more than once or miss data. I maintain that starting Logstash with `--verbose` or `--debug` will divulge something interesting (probably about the sincedb\_files since that's where its hang-up seems to be).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:36am UTC](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/10 "2017-07-06T05:36:07Z")

</div>


