# After starting filebeat, prospectors initially pushes some logs and then stops

**URL:** <https://discuss.elastic.co/t/after-starting-filebeat-prospectors-initially-pushes-some-logs-and-then-stops/36420>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 4, 2015, 7:56pm UTC](https://discuss.elastic.co/t/after-starting-filebeat-prospectors-initially-pushes-some-logs-and-then-stops/36420 "2015-12-04T19:56:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matthew\_Prinvale](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@Matthew\_Prinvale](https://discuss.elastic.co/u/Matthew_Prinvale)\
**Post date:** [December 4, 2015, 7:56pm UTC](https://discuss.elastic.co/t/after-starting-filebeat-prospectors-initially-pushes-some-logs-and-then-stops/36420/1 "2015-12-04T19:56:10Z")

</div>

Edit: I must have missed a part where you had to remove the elasticsearch portion from the config.yml. In previous versions removing it broke it.

Hopefully I explain this correct: Running filebeat with two prospectors (configs below). After I start filebeat the syslog and corelogger prospector launch and initially pushes some logs but then after a quick burst, stops shipping them. The log files in question continually get written to (about 2 or 3 lines/second) and it's nothing significant in terms of size.

version: filebeat 1.0.0

### filebeat.yml

```
filebeat:
  registry_file: /var/lib/filebeat/registry
  config_dir: /etc/filebeat

output:
  elasticsearch:
    enabled: false
    hosts: ["localhost:9200"]

logstash:
  enabled: true
  hosts: ["my-host.com:5044"]

shipper:

```

### syslog.yml

```
filebeat:
  prospectors:
  -
      paths:
      - /var/log/syslog
      - /var/log/auth.log

     input_type: log
     document_type: syslog

```

### corelogger.yml

```
filebeat:
  prospectors:
  -
      paths:
      - /var/log/myapp/stats.log

     input_type: log
     document_type: corelogger

```

I looked over some of the default configs for the prospector but I don't see one that makes sense to change outside of its default value. Any help is appreciated.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 5, 2015, 9:31pm UTC](https://discuss.elastic.co/t/after-starting-filebeat-prospectors-initially-pushes-some-logs-and-then-stops/36420/2 "2015-12-05T21:31:35Z")

</div>

The only strange thing I saw in your config is the indentation of the - after the prospector, but I assume that is only a copy / paste problem as you said, initially it works. Would it be possible that you run filebeat with the -e -d "\*" flags? This will produce some more debugging output and should get give some deeper insights. What OS are you using?

Did you ever try to put both prospectors directly in the filebeat.yml file?

---

<div class="post-metadata">

**Author:** ![Matthew\_Prinvale](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@Matthew\_Prinvale](https://discuss.elastic.co/u/Matthew_Prinvale)\
**Post date:** [December 8, 2015, 8:53pm UTC](https://discuss.elastic.co/t/after-starting-filebeat-prospectors-initially-pushes-some-logs-and-then-stops/36420/3 "2015-12-08T20:53:17Z")

</div>

Issue solved. Edited OP

---

<div class="post-metadata">

**Author:** ![Noebas](https://avatars.discourse-cdn.com/v4/letter/n/7ba0ec/32.png) [@Noebas](https://discuss.elastic.co/u/Noebas)\
**Post date:** [January 3, 2016, 5:30pm UTC](https://discuss.elastic.co/t/after-starting-filebeat-prospectors-initially-pushes-some-logs-and-then-stops/36420/4 "2016-01-03T17:30:08Z")

</div>

EDIT:

seems not the same after closer inspection

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:57pm UTC](https://discuss.elastic.co/t/after-starting-filebeat-prospectors-initially-pushes-some-logs-and-then-stops/36420/5 "2017-07-05T21:57:07Z")

</div>


