# S3 output - Corrupted gzip file on abnormal shutdown

**URL:** <https://discuss.elastic.co/t/s3-output-corrupted-gzip-file-on-abnormal-shutdown/143120>\
**Category:** Logstash\
**Created:** [August 6, 2018, 8:19am UTC](https://discuss.elastic.co/t/s3-output-corrupted-gzip-file-on-abnormal-shutdown/143120 "2018-08-06T08:19:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![hpello](https://avatars.discourse-cdn.com/v4/letter/h/e36b37/32.png) [@hpello](https://discuss.elastic.co/u/hpello)\
**Post date:** [August 6, 2018, 8:19am UTC](https://discuss.elastic.co/t/s3-output-corrupted-gzip-file-on-abnormal-shutdown/143120/1 "2018-08-06T08:19:31Z")

</div>

Hi,

I posted an [issue on GitHub](https://github.com/logstash-plugins/logstash-output-s3/issues/189) but I thought I might as well ask for some help here:

- Description:

When logstash is shut down abnormally, the s3 files created in the temporary directory are saved, and automatically uploaded on next startup (when the `restore` option is set to `true`).

This is usually fine, but when the `encoding => "gzip"` option is set, the saved gzip file may become corrupted, and sent as such to the s3.

```auto
$ zcat ls.s3.18e199e7-6bf9-4a82-ad65-5fbc3d34ccce.2018-08-02T14.06.part3.txt.gz >/dev/null
zcat: ls.s3.18e199e7-6bf9-4a82-ad65-5fbc3d34ccce.2018-08-02T14.06.part3.txt.gz: unexpected end of file
zcat: ls.s3.18e199e7-6bf9-4a82-ad65-5fbc3d34ccce.2018-08-02T14.06.part3.txt.gz: uncompress failed

```

The files cannot be retrieved via the s3 input plugin, i.e. the following error is thrown:

```auto
Error: Unexpected end of ZLIB input stream

```

And all records from that file/batch are discarded.

This is problematic since it means we cannot rely on persistent queues to ensure no data is lost.

- Version: 4.1.4
- Operating System: Docker `docker.elastic.co/logstash/logstash:6.3.2`
- Options: `encoding => "gzip"`, `restore => "true"`
- Steps to Reproduce:
  - Launch a logstash instance with an input plugin that receives a flow of events.
  - Configure s3 output plugin with options `encoding => "gzip"` and `restore => "true"`
  - When a gzip file appears in `/tmp/logstash`, kill the logstash instance abruptly, e.g. with `docker exec -it logstash kill -KILL 1` if you are under docker.
  - Inspect the temporary file in `/tmp/logstash`, that will be sent via to the s3 on next startup. It will most likely be corrupted, i.e. :

```auto
$ zcat ls.s3.18e199e7-6bf9-4a82-ad65-5fbc3d34ccce.2018-08-02T14.06.part3.txt.gz >/dev/null
zcat: ls.s3.18e199e7-6bf9-4a82-ad65-5fbc3d34ccce.2018-08-02T14.06.part3.txt.gz: unexpected end of file
zcat: ls.s3.18e199e7-6bf9-4a82-ad65-5fbc3d34ccce.2018-08-02T14.06.part3.txt.gz: uncompress failed

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 3, 2018, 8:19am UTC](https://discuss.elastic.co/t/s3-output-corrupted-gzip-file-on-abnormal-shutdown/143120/2 "2018-09-03T08:19:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
