# Can't get filebeat to read filestream

**URL:** <https://discuss.elastic.co/t/cant-get-filebeat-to-read-filestream/329598>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 7, 2023, 7:57pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-read-filestream/329598 "2023-04-07T19:57:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![silentfilm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/silentfilm/32/44348_2.png) [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Post date:** [April 7, 2023, 7:57pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-read-filestream/329598/1 "2023-04-07T19:57:19Z")

</div>

I'm trying to switch my filebeat "logs" streams to filestreams. I set up a really simple prospector file:

```auto
---
filebeat.inputs:
- type: filestream
  id: admintools
  paths:
    - '/home/geo/nba/6.3.5.1280/logs/admin-tools/admintools*.log'
  pipeline: nba_app_pipeline

```

However, filbeat can find the file, but doesn't find any filestream inputs:

```auto
2023-04-07T14:32:08.796-0500 DEBUG [cfgfile] cfgfile/cfgfile.go:193 Load config from file: /etc/filebeat/prospector-nba-apps.yml
2023-04-07T14:32:08.796-0500 DEBUG [cfgfile] cfgfile/reload.go:213 Number of module configs found: 0
2023-04-07T14:32:08.796-0500 DEBUG [reload] cfgfile/list.go:63 Starting reload procedure, current runners: 0

```

There is an admintools.log file there that has messages written to it every few seconds.

The filebeat.yml file has this setup:

```auto
filebeat.config.inputs:
  enabled: true
  path: "/etc/filebeat/prospector-*.yml"
  reload.enabled: true
  reload.period: "30s"

```

How can I debug this further?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 8, 2023, 3:21am UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-read-filestream/329598/2 "2023-04-08T03:21:22Z")

</div>

Can you share your entire `filebeat.yml`?

Also, if you are loading external configurations from a folder, like the setting you shared, you need to remove the `filebeat.inputs` from the external configurations and the first line with `---`, the file should start with `-type: filestream`, check the [example in the documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration-reloading.html#load-input-config).

This:

```auto
---
filebeat.inputs:
- type: filestream
  id: admintools
  paths:
    - '/home/geo/nba/6.3.5.1280/logs/admin-tools/admintools*.log'
  pipeline: nba_app_pipeline

```

Should look like this in the prospector file:

```auto
- type: filestream
  id: admintools
  paths:
    - '/home/geo/nba/6.3.5.1280/logs/admin-tools/admintools*.log'
  pipeline: nba_app_pipeline

```

---

<div class="post-metadata">

**Author:** ![silentfilm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/silentfilm/32/44348_2.png) [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Post date:** [April 10, 2023, 7:22pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-read-filestream/329598/3 "2023-04-10T19:22:13Z")

</div>

Thanks, the issue was that I repeated the "filebeat.inputs:" in the external declaration file. Once I removed it, filebeat was working with filestreams.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2023, 9:22pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-read-filestream/329598/4 "2023-05-08T21:22:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
