# Unable to view catalina.out file in Kibana

**URL:** <https://discuss.elastic.co/t/unable-to-view-catalina-out-file-in-kibana/52344>\
**Category:** Logstash\
**Created:** [June 9, 2016, 2:47pm UTC](https://discuss.elastic.co/t/unable-to-view-catalina-out-file-in-kibana/52344 "2016-06-09T14:47:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rvaedex23](https://avatars.discourse-cdn.com/v4/letter/r/9f8e36/32.png) [@rvaedex23](https://discuss.elastic.co/u/rvaedex23)\
**Post date:** [June 9, 2016, 2:47pm UTC](https://discuss.elastic.co/t/unable-to-view-catalina-out-file-in-kibana/52344/1 "2016-06-09T14:47:16Z")

</div>

I have moved some catalina.out logs from a Production server to the test environment this is where elasticsearch is installed.

I am not able to view the logs. I have set up input/filter/output and I am not seeing the logs. I copied this from an online website.

input {  
file {  
type =\> "tomcat"  
path =\> "/home/catalina/logs/audo01.catalina/catalina.out"  
}  
}

filter {  
grok {  
match =\> {  
"message" =\> "%{COMBINEDAPACHELOG} %{IPORHOST:serverip} %{NUMBER:serverport} %{NUMBER:elapsed\_millis} %{NOTSPACE:sessionid} %{QS:proxiedip} %{QS:loginame}"  
}  
overwrite =\> ["message"]  
remove\_field =\> ["ident", "auth"]  
}  
useragent {  
source =\> "agent"  
target =\> "ua"  
remove\_field =\> ["agent"]  
}  
mutate {  
gsub =\> [  
"request", "?.+", "",  
"proxiedip", "(^"|"$)", "",  
"loginame", "(^"|"$)" , "",  
"referrer", "(^"|"$)" , ""  
]  
}  
if [proxiedip] != "-" {  
mutate {  
replace =\> {  
"clientip" =\> "%{proxiedip}"  
}  
}  
}  
if ![bytes] {  
mutate {  
add\_field =\> {  
"bytes" =\> "0"  
}  
}  
}  
mutate {  
remove\_field =\> ["proxiedip"]  
}  
mutate {  
convert =\> {  
"bytes" =\> "integer"  
"elapsed\_millis" =\> "integer"  
"serverport" =\> "integer"  
}  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {  
if "\_grokparsefailure" not in [tags] {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
hosts =\> "112.22.17.66:9200"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 13, 2016, 8:04pm UTC](https://discuss.elastic.co/t/unable-to-view-catalina-out-file-in-kibana/52344/2 "2016-06-13T20:04:00Z")

</div>

Divide and conquer. Is Logstash reading any events from the input file at all? Do you expect it to read the file from the beginning or just new entries? If the latter, are new entries being added? Does the user that Logstash runs as have access to the input logfile?

---

<div class="post-metadata">

**Author:** ![rvaedex23](https://avatars.discourse-cdn.com/v4/letter/r/9f8e36/32.png) [@rvaedex23](https://discuss.elastic.co/u/rvaedex23)\
**Post date:** [June 13, 2016, 11:33pm UTC](https://discuss.elastic.co/t/unable-to-view-catalina-out-file-in-kibana/52344/3 "2016-06-13T23:33:35Z")

</div>

Magnus,

I expect to read the file from the beginning.  
The files are manually moved to a folder.  
Yes the user has access to the input logfile.  
Do you have a script input/filter/output that I can try to use?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 14, 2016, 5:37am UTC](https://discuss.elastic.co/t/unable-to-view-catalina-out-file-in-kibana/52344/4 "2016-06-14T05:37:16Z")

</div>

> I expect to read the file from the beginning.

Then you must set `start_position => beginning` for the file input. Note that you most likely already have a sincedb file that points to the end of the file, so delete that file or set the file input's `sincedb_path` option to /dev/null to effectively disable sincedb. If the file is older than 24 hours you also need to adjust the `ignore_older` option.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:53am UTC](https://discuss.elastic.co/t/unable-to-view-catalina-out-file-in-kibana/52344/5 "2017-07-06T04:53:14Z")

</div>


