# Running the ELK stack on windows

**URL:** <https://discuss.elastic.co/t/running-the-elk-stack-on-windows/91202>\
**Category:** Logstash\
**Created:** [June 28, 2017, 10:29pm UTC](https://discuss.elastic.co/t/running-the-elk-stack-on-windows/91202 "2017-06-28T22:29:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [June 28, 2017, 10:29pm UTC](https://discuss.elastic.co/t/running-the-elk-stack-on-windows/91202/1 "2017-06-28T22:29:05Z")

</div>

Hello. I am currently running the ELK stack through the batch files on a Windows machine. I noticed when I close the batch files and then reopen the services the data remains in elasticsearch. I figured out that to delete this data I would need to go to the directory where elasticsearch held its data and delete the nodes directory. This removes the data from elasticsearch:

```
C:\ELK-Stack_windows\elasticsearch-5.4.2\data

```

What I can't seem to figure out is how to get logstash to read files that were in there from the previous run. When restarted logstash will only parse new files that are placed in where I read the files from.

For example, if I had a file called alarm.prn in the directory where it reads data from. I close/stop logstash and delete the elasticsearch node information so all of the parsed information is gone. When I restart elasticsearch there is no data present. When I restart logstash it doesn't read data from alarm.prn. If I place a new file, lets call it syslog.prn, it will read only that file. Can I have it read both files? I'm sure it stored a file somewhere saying which files it has read but can't seem to figure out where.

Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 28, 2017, 10:46pm UTC](https://discuss.elastic.co/t/running-the-elk-stack-on-windows/91202/2 "2017-06-28T22:46:01Z")

</div>

[quote="CDR, post:1, topic:91202"]I figured out that to delete this data I would need to go to the directory where elasticsearch held its data and delete the nodes directory  
[/quote]

Always use the APIs to remove data, don't do it on the filesystem.

> [@CDR](#):
>
> What I can't seem to figure out is how to get logstash to read files that were in there from the previous run.

Look at [File input plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-sincedb_path)

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [June 29, 2017, 12:06pm UTC](https://discuss.elastic.co/t/running-the-elk-stack-on-windows/91202/3 "2017-06-29T12:06:38Z")

</div>

Is there a way to use the APIs without downloading any new software? On a Windows machine I am unsure how to use the delete commands. I know that in a linux machine I could use the curl commands. But windows doesn't support that without downloading other software, at least to the best of my knowledge

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 29, 2017, 10:35pm UTC](https://discuss.elastic.co/t/running-the-elk-stack-on-windows/91202/4 "2017-06-29T22:35:02Z")

</div>

If you have Kibana then use Console, under dev tools.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2017, 10:43pm UTC](https://discuss.elastic.co/t/running-the-elk-stack-on-windows/91202/5 "2017-07-27T22:43:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
