Logstash File Input sincedb_path vs. Docker Read‑Only Filesystem: Unresolved Path Resolution
0 reputation · 26 Oct 2022, 15:29 UTC
Issue Summary
Logstash’s File Input plugin uses sincedb_path to remember which lines of a file have already been processed. When a pipeline is launched locally, the plugin creates the sincedb file in the current working directory, which is usually writable. In a Docker or Kubernetes deployment, the working directory may be mounted read‑only or relocated, causing the sincedb file to be written to /tmp or not created at all. This leads to duplicate or missing events after a restart.
The documentation states that sincedb_path can be set to an absolute path, but it does not clarify how relative paths are resolved across operating systems or container runtimes, leaving the decision ambiguous.
Unresolved questions:
- What base directory does Logstash use to resolve a relative
sincedb_pathwhen running inside a container? - How can we reliably configure
sincedb_pathto avoid duplicate events in a read‑only environment? - Does Logstash provide a configuration option to override the default relative path resolution?