# Scheduling Logstash Failed

**URL:** <https://discuss.elastic.co/t/scheduling-logstash-failed/131558>\
**Category:** Logstash\
**Created:** [May 12, 2018, 6:54am UTC](https://discuss.elastic.co/t/scheduling-logstash-failed/131558 "2018-05-12T06:54:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Meghla\_Chakravorty](https://avatars.discourse-cdn.com/v4/letter/m/9de0a6/32.png) [@Meghla\_Chakravorty](https://discuss.elastic.co/u/Meghla_Chakravorty)\
**Post date:** [May 12, 2018, 6:54am UTC](https://discuss.elastic.co/t/scheduling-logstash-failed/131558/1 "2018-05-12T06:54:45Z")

</div>

I am running a logstash pipeline to read logs from all files in a directory. I want my logstash conf file to run every 30 minutes in a day. Is there any command which I have to write in the conf file. Below is the snippet from the logstash conf file. Am using schedule to test it every 2 seconds (later will change it to 30 mins) but it seems schedule is not working.

Any help..

`

input  
{  
file  
{  
path=\> "/home/cloudera/hive-metastore.log.2018-03-24"  
start\_position=\> beginning  
sincedb\_path =\> "/dev/null"  
codec =\> multiline {  
pattern =\> "^%{TIMESTAMP\_ISO8601} "  
negate =\> true  
what =\> previous  
}  
}  
schedule =\> '2 \* \* \* \*'

}

`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 13, 2018, 8:01pm UTC](https://discuss.elastic.co/t/scheduling-logstash-failed/131558/2 "2018-05-13T20:01:16Z")

</div>

Only some inputs have a `schedule` option and the file input is not one of them. Besides, you've placed the option outside the file input, i.e. in the input block itself.

I suggest you keep Logstash running and have it continuously monitor the files you're interested in.

---

<div class="post-metadata">

**Author:** ![Meghla\_Chakravorty](https://avatars.discourse-cdn.com/v4/letter/m/9de0a6/32.png) [@Meghla\_Chakravorty](https://discuss.elastic.co/u/Meghla_Chakravorty)\
**Post date:** [May 14, 2018, 7:32am UTC](https://discuss.elastic.co/t/scheduling-logstash-failed/131558/3 "2018-05-14T07:32:35Z")

</div>

## input { file { path=\> "/home/cloudera/yarnlogs/\*" start\_position=\> beginning sincedb\_path =\> "dev/null" ignore\_older =\> 0 stat\_interval =\> 5

Changing to this worked. I am now trying to use filebeat , but stuck at configuring the filter part of logstash config to filebeat

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 14, 2018, 8:08am UTC](https://discuss.elastic.co/t/scheduling-logstash-failed/131558/4 "2018-05-14T08:08:45Z")

</div>

> sincedb\_path =\> "dev/null"

/dev/null, not dev/null.

> I am now trying to use filebeat , but stuck at configuring the filter part of logstash config to filebeat

If you want help you need to be more specific.

---

<div class="post-metadata">

**Author:** ![Meghla\_Chakravorty](https://avatars.discourse-cdn.com/v4/letter/m/9de0a6/32.png) [@Meghla\_Chakravorty](https://discuss.elastic.co/u/Meghla_Chakravorty)\
**Post date:** [May 14, 2018, 6:19pm UTC](https://discuss.elastic.co/t/scheduling-logstash-failed/131558/5 "2018-05-14T18:19:43Z")

</div>

yes , thanks!

I am trying to input my log files through file beat to logstash and then run this logstash in every 30 mins(or any particular time interval) . Is there any particular config changes I need to do in either logstash / filebeat?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 14, 2018, 7:03pm UTC](https://discuss.elastic.co/t/scheduling-logstash-failed/131558/6 "2018-05-14T19:03:21Z")

</div>

What does your configuration look like now? What problem are you experiencing?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2018, 7:03pm UTC](https://discuss.elastic.co/t/scheduling-logstash-failed/131558/7 "2018-06-11T19:03:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
