# Rsync changing inode numbers causing multiple imports

**URL:** <https://discuss.elastic.co/t/rsync-changing-inode-numbers-causing-multiple-imports/26939>\
**Category:** Logstash\
**Created:** [August 6, 2015, 5:36am UTC](https://discuss.elastic.co/t/rsync-changing-inode-numbers-causing-multiple-imports/26939 "2015-08-06T05:36:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jason\_wilson](https://avatars.discourse-cdn.com/v4/letter/j/9de053/32.png) [@jason\_wilson](https://discuss.elastic.co/u/jason_wilson)\
**Post date:** [August 6, 2015, 5:36am UTC](https://discuss.elastic.co/t/rsync-changing-inode-numbers-causing-multiple-imports/26939/1 "2015-08-06T05:36:50Z")

</div>

Hi All,

Fairly new to the whole ELK stack and running into an issue.

To test things out I am rsync'ing a bunch of logs from various Windows IIS servers back to my host running the ELK software.

Things are working fine, but because rsync creates a new file and a new inode each time I am getting the same logs imported each time.

Googling found me this 'patch' that seems to address this exact issue:  
[https://github.com/michio-nikaido/ruby-filewatch/commit/a376432a64a821a569490d0b15eb4d0060b8f60f](https://github.com/michio-nikaido/ruby-filewatch/commit/a376432a64a821a569490d0b15eb4d0060b8f60f)

How do I go about getting this into by currently running logstash?

Running logstash 1.5.3 on a Fedora box (to do a proof of concept).

Not a ruby person, so not sure how I can update just this package to get this additional functionality.

Thanks,  
Jason

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 7, 2015, 8:03am UTC](https://discuss.elastic.co/t/rsync-changing-inode-numbers-causing-multiple-imports/26939/2 "2015-08-07T08:03:08Z")

</div>

This is, unfortunately, a short coming of the file watch library.

I've raised a [GH issue here](https://github.com/logstash-plugins/logstash-input-file/issues/63) for it 🙂

---

<div class="post-metadata">

**Author:** ![PhaedrusTheGreek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phaedrusthegreek/32/4884_2.png) [@PhaedrusTheGreek](https://discuss.elastic.co/u/PhaedrusTheGreek)\
**Post date:** [August 2, 2016, 8:44pm UTC](https://discuss.elastic.co/t/rsync-changing-inode-numbers-causing-multiple-imports/26939/3 "2016-08-02T20:44:21Z")

</div>

Rsync has an `--inplace` option that will overwrite the existing file instead of making a new copy and moving it. There is a warning in the manpage though:

> WARNING: The file's data will be in an inconsistent state during the transfer (and possibly afterward if the transfer gets interrupted), so you should not use this option to update files that are in use. Also note that rsync will be unable to update a file in-place that is not writable by the receiving user.

I think that so long as the file only changes in an append-only way, and a simple test shows this method as working

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:45am UTC](https://discuss.elastic.co/t/rsync-changing-inode-numbers-causing-multiple-imports/26939/4 "2017-07-06T04:45:12Z")

</div>


