# Unable to read files in persistent queue for logstash

**URL:** <https://discuss.elastic.co/t/unable-to-read-files-in-persistent-queue-for-logstash/221935>\
**Category:** Logstash\
**Created:** [March 3, 2020, 6:46pm UTC](https://discuss.elastic.co/t/unable-to-read-files-in-persistent-queue-for-logstash/221935 "2020-03-03T18:46:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![raghuveera](https://avatars.discourse-cdn.com/v4/letter/r/3e96dc/32.png) [@raghuveera](https://discuss.elastic.co/u/raghuveera)\
**Post date:** [March 3, 2020, 6:46pm UTC](https://discuss.elastic.co/t/unable-to-read-files-in-persistent-queue-for-logstash/221935/1 "2020-03-03T18:46:06Z")

</div>

I have recently enabled persistent queue configuration for logstash. I do see some files in location  
/var/lib/logstash/queue/\<pipeline\_id\>/, named as checkpoint.head and page.50. But, when i try to cat and read the files i am not able to understand in which format they are written.  
So, trying to understand what this checkpoint.head and page files are?  
How, do we know if the events received by input are stored in queue and are then processed to push in to elastic search.  
And also which file system does logstash use for persistent queue in linux machine?  
Any help in understanding the persistent queue and monitoring it's functionality is appreciated.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [March 3, 2020, 9:48pm UTC](https://discuss.elastic.co/t/unable-to-read-files-in-persistent-queue-for-logstash/221935/2 "2020-03-03T21:48:30Z")

</div>

Use the l[ogstash monitoring api](https://www.elastic.co/guide/en/logstash/current/monitoring-logstash.html#monitoring-logstash) to see queue size.

All events are "persisted" to these files before logstash attempts to process them, so input is written to disk before processing (filter and output) is attempted.

I don't think looking at these files is a documented api 🙂

Which filesystem is fromlogstash.yml path.data, usually /var/lib/logstash, at lest for RH Linux flavors.

---

<div class="post-metadata">

**Author:** ![raghuveera](https://avatars.discourse-cdn.com/v4/letter/r/3e96dc/32.png) [@raghuveera](https://discuss.elastic.co/u/raghuveera)\
**Post date:** [March 3, 2020, 10:02pm UTC](https://discuss.elastic.co/t/unable-to-read-files-in-persistent-queue-for-logstash/221935/3 "2020-03-03T22:02:54Z")

</div>

I am not clear with the file system part you have mentioned.  
The queue files are located in /var/lib/logstash/queue/ ...  
But, which filesystem or disk does logstash use to write it events in to?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [March 4, 2020, 3:36am UTC](https://discuss.elastic.co/t/unable-to-read-files-in-persistent-queue-for-logstash/221935/4 "2020-03-04T03:36:11Z")

</div>

Logstash output is configured in various output plugins, usually logstash sends via tcp to an elasticsearch cluster.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2020, 3:36am UTC](https://discuss.elastic.co/t/unable-to-read-files-in-persistent-queue-for-logstash/221935/5 "2020-04-01T03:36:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
