# Sincedb files not created

**URL:** <https://discuss.elastic.co/t/sincedb-files-not-created/25542>\
**Category:** Logstash\
**Created:** [July 14, 2015, 5:42pm UTC](https://discuss.elastic.co/t/sincedb-files-not-created/25542 "2015-07-14T17:42:25Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![vilas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vilas/32/613_2.png) [@vilas](https://discuss.elastic.co/u/vilas)\
**Post date:** [July 14, 2015, 5:42pm UTC](https://discuss.elastic.co/t/sincedb-files-not-created/25542/1 "2015-07-14T17:42:25Z")

</div>

Hi,  
The following is my sample Logstash configuration for file input:

```auto
file {
                path => ".../logs/sample.log"
                start_position => "beginning"
                type => "sample"
                sincedb_path => "$HOME/logstash/sincedb/"
}

```

I see that no sincedb files are being created.  
I also tried the following:

```auto
# without slash at the end of the path
file {
           ...                
           sincedb_path => "$HOME/logstash/sincedb"
}

# directly providing wildcard for sincedb files
file {
           ...                
           sincedb_path => "$HOME/logstash/sincedb/.sincedb*"
}

```

None of them seems to be working.  
**What is the correct way to give sincedb path?**  
Need help on this.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2015, 8:18pm UTC](https://discuss.elastic.co/t/sincedb-files-not-created/25542/2 "2015-07-14T20:18:52Z")

</div>

I wouldn't assume that $HOME is expanded here. Also, I suspect `sincedb_path` should point to a file rather than a directory. Increasing the log verbosity with `--verbose` or even `--debug` should give more insights into what's going on.

Any particular reason why you want to set `sincedb_path`? The default value is fine in most circumstances.

---

<div class="post-metadata">

**Author:** ![vilas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vilas/32/613_2.png) [@vilas](https://discuss.elastic.co/u/vilas)\
**Post date:** [July 14, 2015, 9:27pm UTC](https://discuss.elastic.co/t/sincedb-files-not-created/25542/3 "2015-07-14T21:27:12Z")

</div>

@magnusbaeck

I shall check with --debug information.

As I understand, whenever we bounce the logstash, if I don't set sincedb\_path:

- if start\_position =\> beginning : **logs would be read again**
- else start\_position =\> end : **logs written during the bouncing would be missed**

So, I would require sincedb\_path to avoid the above two scenarios.

Please correct me if I am wrong.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 15, 2015, 5:56am UTC](https://discuss.elastic.co/t/sincedb-files-not-created/25542/4 "2015-07-15T05:56:06Z")

</div>

Logstash will generate a sincedb path based on the filename pattern so regardless it'll always remember where it left off as long as you don't change the filename pattern. So yes, there are occasions where setting `sincedb_path` makes sense but I'd say that people are overusing it.

---

<div class="post-metadata">

**Author:** ![vilas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vilas/32/613_2.png) [@vilas](https://discuss.elastic.co/u/vilas)\
**Post date:** [July 15, 2015, 5:10pm UTC](https://discuss.elastic.co/t/sincedb-files-not-created/25542/5 "2015-07-15T17:10:12Z")

</div>

@magnusbaeck

Are you saying that sincedb files are being saved in some path based on filename pattern? But we might not have write permissions in those paths. I haven't seen sincedb files anywhere yet.  
Can you please elaborate. Because, its important not to loose any data after bouncing logstash.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 15, 2015, 6:12pm UTC](https://discuss.elastic.co/t/sincedb-files-not-created/25542/6 "2015-07-15T18:12:44Z")

</div>

[As documented](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-sincedb_path), the `sincedb_path` default causes files to be written to $HOME, i.e. the home directory of whatever user that Logstash runs as (typically logstash). It's a reasonable assumption that those files will be writable to Logstash. See below for the code that sets `sincedb_path` dynamically when the user hasn't set it.

And again, if you increase the logging verbosity Logstash will tell you more about the location of the sincedb files.

> <https://github.com/logstash-plugins/logstash-input-file/blob/11ed55fe65b6f09a0b552e5158214f1c5f14c0a2/lib/logstash/inputs/file.rb#L107-L109>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:34am UTC](https://discuss.elastic.co/t/sincedb-files-not-created/25542/7 "2017-07-06T05:34:32Z")

</div>


