# Clarification about Filebeat usage is needed

**URL:** https://discuss.elastic.co/t/clarification-about-filebeat-usage-is-needed/73943
**Category:** Beats
**Tags:** filebeat
**Created:** [February 4, 2017, 1:24pm UTC](https://discuss.elastic.co/t/clarification-about-filebeat-usage-is-needed/73943 "2017-02-04T13:24:25Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![John16](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@John16](https://discuss.elastic.co/u/John16)
#### Post date: [February 4, 2017, 1:24pm UTC](https://discuss.elastic.co/t/clarification-about-filebeat-usage-is-needed/73943/1 "2017-02-04T13:24:25Z")

</div>

Hello,

my application writes log file /var/log/app.log.  
At 00:00, this log file is rotated:  
mv /var/log/app.log /var/log/app.log.bak  
kill -1 \<APP\_PID\> --\> re-opens /var/log/app.log

Do I understand it correctly that:

1. filebeat will read app.log all day long and send lines to ES. After log file is rotated, filebeat will notice that filename has changed, read all.log.bak until the end of file and then reopen newly created /var/log/app.log?
2. if for some reason ES becomes unavailable, filebeat will pause reading file and wait for ES to become reachable again. And then it will continue as described in 1)?

Thanks.

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [February 4, 2017, 2:48pm UTC](https://discuss.elastic.co/t/clarification-about-filebeat-usage-is-needed/73943/2 "2017-02-04T14:48:11Z")

</div>

1. Yes, only `app.log.bak` and the new `app.log` will be processed concurrently, in case not all events have been processed yet. Filebeat in general tries to process files concurrently. In case filebeat is not restarted, it will keep the old `app.log` open until it has finished processing it (which is perfectly fine on linux).  
Filebeat remembers files by inode. That is, the log-rotation should use `mv`. This guarantees the file identity did not change.
2. yep

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 4, 2017, 2:48pm UTC](https://discuss.elastic.co/t/clarification-about-filebeat-usage-is-needed/73943/3 "2017-03-04T14:48:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
