# Restarting logstash container sends events again to elastic, despite sincedb

**URL:** <https://discuss.elastic.co/t/restarting-logstash-container-sends-events-again-to-elastic-despite-sincedb/324675>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [February 3, 2023, 4:35pm UTC](https://discuss.elastic.co/t/restarting-logstash-container-sends-events-again-to-elastic-despite-sincedb/324675 "2023-02-03T16:35:01Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 6, 2023, 5:50pm UTC](https://discuss.elastic.co/t/restarting-logstash-container-sends-events-again-to-elastic-despite-sincedb/324675/6 "2023-02-06T17:50:10Z")

</div>

> [@paul\_chrlt](#):
>
> associate: matched but allocated to another

That appears to be hitting something similar to [this](https://discuss.elastic.co/t/when-logstash-shutdown-renam-file-and-data-can-be-lost-or-duplicated/192669/3) use case. Making the distinction between rotation and inode reuse without doing a checksum of the file each time it is read is probably impossible. The file input uses heuristics that almost always get it right for some use cases (like daily log files on a busy filesystem). This is not one of them.

---

_[View the full topic](https://discuss.elastic.co/t/restarting-logstash-container-sends-events-again-to-elastic-despite-sincedb/324675)._
