# \[bug report\]: filebeat can't finish ,if the log file isn’t ending with line terminator(like \\n)

**URL:** <https://discuss.elastic.co/t/bug-report-filebeat-cant-finish-if-the-log-file-isn-t-ending-with-line-terminator-like-n/214835>\
**Category:** Beats\
**Created:** [January 13, 2020, 1:09pm UTC](https://discuss.elastic.co/t/bug-report-filebeat-cant-finish-if-the-log-file-isn-t-ending-with-line-terminator-like-n/214835 "2020-01-13T13:09:20Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![chenyahui](https://avatars.discourse-cdn.com/v4/letter/c/5e9695/32.png) [@chenyahui](https://discuss.elastic.co/u/chenyahui)\
**Post date:** [January 13, 2020, 1:09pm UTC](https://discuss.elastic.co/t/bug-report-filebeat-cant-finish-if-the-log-file-isn-t-ending-with-line-terminator-like-n/214835/1 "2020-01-13T13:09:20Z")

</div>

if a log file isn’t ending with line terminator(like \n), the last line can't be read by harvester.

the harvester of the file will not finished

filebeat version [7.5]

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [January 13, 2020, 7:22pm UTC](https://discuss.elastic.co/t/bug-report-filebeat-cant-finish-if-the-log-file-isn-t-ending-with-line-terminator-like-n/214835/2 "2020-01-13T19:22:19Z")

</div>

I'm not sure this qualifies as a bug. Filebeat needs a way to know that a log entry is complete. By default it uses newlines to make this determination. In other words, if Filebeat doesn't see a newline it assumes bytes are still being added to the log entry, so it isn't ready to be processed further by Filebeat.

---

<div class="post-metadata">

**Author:** ![chenyahui](https://avatars.discourse-cdn.com/v4/letter/c/5e9695/32.png) [@chenyahui](https://discuss.elastic.co/u/chenyahui)\
**Post date:** [January 14, 2020, 2:05am UTC](https://discuss.elastic.co/t/bug-report-filebeat-cant-finish-if-the-log-file-isn-t-ending-with-line-terminator-like-n/214835/3 "2020-01-14T02:05:21Z")

</div>

But if the program is coredumped, it can't ensure output a complete log.

It's a very common case.

Maybe filebeat can offer a configuration item to flush the rest buffer when `close_inactive` is triggered .

After all , the final line terminator never come in this case.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [January 14, 2020, 7:13pm UTC](https://discuss.elastic.co/t/bug-report-filebeat-cant-finish-if-the-log-file-isn-t-ending-with-line-terminator-like-n/214835/5 "2020-01-14T19:13:02Z")

</div>

> [@chenyahui](#):
>
> Maybe filebeat can offer a configuration item to flush the rest buffer when `close_inactive` is triggered .

That's an interesting idea, to have a setting like `close_inactive_flush` or similar.

Would you mind filing a feature request issue for this over here: [Sign in to GitHub · GitHub](https://github.com/elastic/beats/issues/new?template=feature-request.md)? Please describe your use case in as much detail as you can, so developers can build the feature correctly. Thanks!

Shaunak

---

<div class="post-metadata">

**Author:** ![chenyahui](https://avatars.discourse-cdn.com/v4/letter/c/5e9695/32.png) [@chenyahui](https://discuss.elastic.co/u/chenyahui)\
**Post date:** [January 15, 2020, 2:17am UTC](https://discuss.elastic.co/t/bug-report-filebeat-cant-finish-if-the-log-file-isn-t-ending-with-line-terminator-like-n/214835/6 "2020-01-15T02:17:11Z")

</div>

ok, I will~

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 12, 2020, 4:17am UTC](https://discuss.elastic.co/t/bug-report-filebeat-cant-finish-if-the-log-file-isn-t-ending-with-line-terminator-like-n/214835/7 "2020-02-12T04:17:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
