# Can filebeat load non .log file into elasticsearch/logstash?

**URL:** <https://discuss.elastic.co/t/can-filebeat-load-non-log-file-into-elasticsearch-logstash/107048>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 9, 2017, 1:38pm UTC](https://discuss.elastic.co/t/can-filebeat-load-non-log-file-into-elasticsearch-logstash/107048 "2017-11-09T13:38:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![yishain11](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Post date:** [November 9, 2017, 1:38pm UTC](https://discuss.elastic.co/t/can-filebeat-load-non-log-file-into-elasticsearch-logstash/107048/1 "2017-11-09T13:38:14Z")

</div>

Hi there.  
I try to load some files from filebeat -\> logstash -\> elasticsearch -\> kibana.  
The thing is that the files I'm trying to load are not .log files, but files without any extension.  
the filebeat.yml is:

filebeat.prospectors:

# Each - is a prospector. Most options can be set at the prospector level, so

# you can use different prospectors for various configurations.

# Below are the prospector specific configurations.

- input\_type: log

# - /var/log/\*.log

```
- /path/to/files/*/subdir/*

```

when I touch in the subdir folder a file with .log extension kibana immediately recognize it.  
What do I need to do in order to see in kibana the files that don't have .log extention? should I use filebeat at all?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 9, 2017, 4:23pm UTC](https://discuss.elastic.co/t/can-filebeat-load-non-log-file-into-elasticsearch-logstash/107048/2 "2017-11-09T16:23:39Z")

</div>

Well, extension or not doesn't matter. What matters is:

- How is the file written too (append only?), or is file ever changed/updated after being written
- Is the file in binary or plain text?

---

<div class="post-metadata">

**Author:** ![yishain11](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Post date:** [November 12, 2017, 7:57am UTC](https://discuss.elastic.co/t/can-filebeat-load-non-log-file-into-elasticsearch-logstash/107048/3 "2017-11-12T07:57:27Z")

</div>

Hi

1. The file is written and being appended. What I'm trying to do is to read the file as it being updated.
2. The file is a text file.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 13, 2017, 5:16pm UTC](https://discuss.elastic.co/t/can-filebeat-load-non-log-file-into-elasticsearch-logstash/107048/4 "2017-11-13T17:16:05Z")

</div>

Filebeat splits by newline characters `\n` or `\r\n`.

If the producer really uses append (some tools don't append, but create a copy + new contents appended) AND newline is used to separate lines/entries, sure you can use filebeat to load the files.

Just make sure the glob pattern can find the files. Have you checked the files are actually found by filebeat, by having a look at filebeat logs (consider enabling debug logging)?

Please properly format logs and configs using the `</>` buttong. At first it wasn't really clear to me you actually posted part of your config. Beats configs are sensitive to indentation. Without proper formatting it's hard to see potential errors.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2017, 5:16pm UTC](https://discuss.elastic.co/t/can-filebeat-load-non-log-file-into-elasticsearch-logstash/107048/5 "2017-12-11T17:16:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
