# Config filebeat only to read last 5 minutes of log file

**URL:** <https://discuss.elastic.co/t/config-filebeat-only-to-read-last-5-minutes-of-log-file/200669>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 23, 2019, 10:32am UTC](https://discuss.elastic.co/t/config-filebeat-only-to-read-last-5-minutes-of-log-file/200669 "2019-09-23T10:32:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ingram\_Gultom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ingram_gultom/32/56569_2.png) [@Ingram\_Gultom](https://discuss.elastic.co/u/Ingram_Gultom)\
**Post date:** [September 23, 2019, 10:32am UTC](https://discuss.elastic.co/t/config-filebeat-only-to-read-last-5-minutes-of-log-file/200669/1 "2019-09-23T10:32:55Z")

</div>

Can filebeat read only last 5 minutes of log file?

From the doc only found tail\_files but its for read latest line of log

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [September 23, 2019, 12:12pm UTC](https://discuss.elastic.co/t/config-filebeat-only-to-read-last-5-minutes-of-log-file/200669/2 "2019-09-23T12:12:42Z")

</div>

[ignore\_older](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#filebeat-input-log-ignore-older) for files

It uses the file last modified time in the directory, not the timestamp on an event, not any timestamp of an event.

---

<div class="post-metadata">

**Author:** ![Ingram\_Gultom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ingram_gultom/32/56569_2.png) [@Ingram\_Gultom](https://discuss.elastic.co/u/Ingram_Gultom)\
**Post date:** [September 26, 2019, 3:10am UTC](https://discuss.elastic.co/t/config-filebeat-only-to-read-last-5-minutes-of-log-file/200669/3 "2019-09-26T03:10:21Z")

</div>

Thank you for you response

Actually I'm talking about event timestamp because my log only one file

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [September 27, 2019, 4:39pm UTC](https://discuss.elastic.co/t/config-filebeat-only-to-read-last-5-minutes-of-log-file/200669/4 "2019-09-27T16:39:43Z")

</div>

This is some logstash filter ruby code to test timestamp skew. It is mostly to address devices that write logs at epoch\_millis = 0 when they reboot until they get a good ntp time.

```
#
# if event timestamp skewed more than 3 days....   
#
ruby {
code => 'if ( Time.now.to_i - event.get("@timestamp").to_i ).abs > 259200 
             event.tag("timeskew")
             event.set("timeskew_original_timestamp", event.get("@timestamp"))
             event.set("@timestamp", LogStash::Timestamp.at(Time.now))
         end'
tag_on_exception => "rubyexception"

```

This could be modified to a shorter time value and do "event.cancel" if time is out of bounds.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2019, 4:39pm UTC](https://discuss.elastic.co/t/config-filebeat-only-to-read-last-5-minutes-of-log-file/200669/5 "2019-10-25T16:39:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
