# Skipping older files

**URL:** <https://discuss.elastic.co/t/skipping-older-files/79653>\
**Category:** Logstash\
**Created:** [March 22, 2017, 9:27pm UTC](https://discuss.elastic.co/t/skipping-older-files/79653 "2017-03-22T21:27:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![blacklobo](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blacklobo](https://discuss.elastic.co/u/blacklobo)\
**Post date:** [March 22, 2017, 9:27pm UTC](https://discuss.elastic.co/t/skipping-older-files/79653/1 "2017-03-22T21:27:12Z")

</div>

How can I get Logstash to open and process files modified more than 24 hours ago?

Logstash is skipping files that were written over 24 hours ago. I found a topic that references the Logstash forwarder accepting a "dead time" setting, which appears to allow you to adjust this. However I do not see it as an available setting for input file.

**logged message:**  
{:timestamp=\>"2017-03-22T16:56:25.516000-0400", :message=\>"\_discover\_file: /log\_storage/upload/\*.dat: new: /log\_storage/upload/REF.AA.201703181100.dat (exclude is [])", :level=\>:debug, :file=\>"filewatch/watch.rb", :line=\>"310", :method=\>"\_discover\_file"}  
{:timestamp=\>"2017-03-22T16:56:25.517000-0400", :message=\>"\_discover\_file: /log\_storage/upload/REF.AA.201703181100.dat: skipping because it was last modified more than 86400.0 seconds ago", :level=\>:debug, :file=\>"filewatch/watch.rb", :line=\>"330", :method=\>"\_discover\_file"}

I have tried setting the ignore\_older setting to a value older than my files but that doesn't work as expect. Though in the debug logs it shows it opening the files and writing an entry to sincedb it doesn't actually process the contents of the file.

**logged message with "ignore\_older" set to 864000:**  
{:timestamp=\>"2017-03-22T17:12:21.600000-0400", :message=\>"\_open\_file: /log\_storage/upload/REF.AA.201703181100.dat: opening", :level=\>:debug, :file=\>"filewatch/tail\_base.rb", :line=\>"86", :method=\>"\_open\_file"}  
{:timestamp=\>"2017-03-22T17:12:21.601000-0400", :message=\>"/log\_storage/upload/REF.AA.201703181100.dat: initial create, no sincedb, seeking to end 48865762", :level=\>:debug, :file=\>"filewatch/tail\_base.rb", :line=\>"149", :method=\>"\_add\_to\_sincedb"}  
{:timestamp=\>"2017-03-22T17:12:21.608000-0400", :message=\>"each: file grew: /log\_storage/upload/REF.AA.201703181100.dat: old size 0, new size 48865762", :level=\>:debug, :file=\>"filewatch/watch.rb", :line=\>"254", :method=\>"each"}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 23, 2017, 6:04am UTC](https://discuss.elastic.co/t/skipping-older-files/79653/2 "2017-03-23T06:04:22Z")

</div>

Are you setting `start_position => beginning` for your file input?

---

<div class="post-metadata">

**Author:** ![blacklobo](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blacklobo](https://discuss.elastic.co/u/blacklobo)\
**Post date:** [March 23, 2017, 1:03pm UTC](https://discuss.elastic.co/t/skipping-older-files/79653/3 "2017-03-23T13:03:58Z")

</div>

Thank you for the response. I did not have it set. After setting it, Logstash still did not read older files. However when I set "start\_position" to beginning AND I set "ignore\_older" to greater than 86,400 seconds Logstash would read older files. So it appears at least in Logstash 2.3.4, "ignore\_older" is set to 86,400 by default.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 23, 2017, 1:30pm UTC](https://discuss.elastic.co/t/skipping-older-files/79653/4 "2017-03-23T13:30:42Z")

</div>

Yes, in Logstash 2.3 the documented default value is 86400: [https://www.elastic.co/guide/en/logstash/2.3/plugins-inputs-file.html#plugins-inputs-file-ignore\_older](https://www.elastic.co/guide/en/logstash/2.3/plugins-inputs-file.html#plugins-inputs-file-ignore_older)

---

<div class="post-metadata">

**Author:** ![blacklobo](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blacklobo](https://discuss.elastic.co/u/blacklobo)\
**Post date:** [March 23, 2017, 1:46pm UTC](https://discuss.elastic.co/t/skipping-older-files/79653/5 "2017-03-23T13:46:01Z")

</div>

That was my problem I was looking at the current documentation, not the documentation for 2.3. Thank you for your support.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2017, 1:46pm UTC](https://discuss.elastic.co/t/skipping-older-files/79653/6 "2017-04-20T13:46:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
