# Sincedb and rsync - it's not a solution

**URL:** <https://discuss.elastic.co/t/sincedb-and-rsync-its-not-a-solution/365822>\
**Category:** Logstash\
**Created:** [August 30, 2024, 1:13pm UTC](https://discuss.elastic.co/t/sincedb-and-rsync-its-not-a-solution/365822 "2024-08-30T13:13:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [August 30, 2024, 1:13pm UTC](https://discuss.elastic.co/t/sincedb-and-rsync-its-not-a-solution/365822/1 "2024-08-30T13:13:10Z")

</div>

Hi  
Is there any chance to config some parameters for sincedb for read file only for name, I have updated folder with the second server over rsync and after synchronization data structure are overwrite like inode and etc but still I have the same one name of files. Do You have some solution for avoid reload the same file to elasticsearch?

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [August 30, 2024, 1:38pm UTC](https://discuss.elastic.co/t/sincedb-and-rsync-its-not-a-solution/365822/2 "2024-08-30T13:38:21Z")

</div>

I found that it should be add param --inplace but it doesn't work. Logstash with sincedb are duplicated still the same file.

```auto
&& rsync -va --append --inplace --times --progress --stats 

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 30, 2024, 3:19pm UTC](https://discuss.elastic.co/t/sincedb-and-rsync-its-not-a-solution/365822/3 "2024-08-30T15:19:06Z")

</div>

> [@INS](#):
>
> Is there any chance to config some parameters for sincedb for read file only for name,

No. filewatch doesn't care much about the file name, it's just a way to find an inode. If a new inode appears then it is treated as new content. If it is a duplicate of an inode that has already been read then the content will be ingested a second time.

If the name associated with the inode changes then that is typically assumed to be a rotated log file that does not need to be read again.

If the file is copied to another disk then both the device number and inode will change, and filewatch uses the combination of the two to track things.

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [September 3, 2024, 12:55pm UTC](https://discuss.elastic.co/t/sincedb-and-rsync-its-not-a-solution/365822/4 "2024-09-03T12:55:36Z")

</div>

in my case, rsync are works as expected till power on logstash and process the files. So I have doubts that logstash can do something with this file. And then rsync are lost consistency
