# CustomLogs integration turns unhealthy with simple wildcard change

**URL:** <https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [October 19, 2023, 10:36pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423 "2023-10-19T22:36:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![CiscoMT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ciscomt/32/126708_2.png) [@CiscoMT](https://discuss.elastic.co/u/CiscoMT)\
**Post date:** [October 19, 2023, 10:36pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423/1 "2023-10-19T22:36:31Z")

</div>

Hello y'all,

I am trying to break down the different paths I have for app logs in my server into different customLogs integrations.

Originally I was using a single integration of the CustomLog type with path :

```auto
C:\inetpub\Hamilton\*\Logs\*.log

```

This worked fine

Now I am using multiple CustomLogs integrations, i.e:

customlogs called AccountManagement with path:

```auto
C:\inetpub\Hamilton\AccountManagement\Logs

```

customlogs called BookingManagement with path:

```auto
C:\inetpub\Hamilton\BookingManagement\Logs

```

I also tried setting the paths as below, but it didn't work either

```auto
C:\inetpub\Hamilton\BookingManagement\Logs\*.log

```

But as soon as I make this change, both integrations show as Unhealthy, I read that it was possible to use multiple Integrations of this type.

What may I be missing here?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 21, 2023, 10:29pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423/2 "2023-10-21T22:29:31Z")

</div>

Hi @CiscoMT Welcome to the community!

Multiple integrations should work..

> [@CiscoMT](#):
>
> `C:\inetpub\Hamilton\AccountManagement\Logs`

> [@CiscoMT](#):
>
> `C:\inetpub\Hamilton\BookingManagement\Logs`

Are you missing the `\*.log` at the end of both the new integrations

---

<div class="post-metadata">

**Author:** ![CiscoMT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ciscomt/32/126708_2.png) [@CiscoMT](https://discuss.elastic.co/u/CiscoMT)\
**Post date:** [October 25, 2023, 2:17pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423/3 "2023-10-25T14:17:09Z")

</div>

Hi Stephen, Thanks for the welcome!

I think I read in the docs that you cold just leave the folder like that to consume the whole folder. But I did add the \*.logs and we are still getting no logs and the agent still shows as Unhealthy.

```auto
C:\inetpub\Hamilton\AccountManagement\Logs\*.log

```

Looking at the agent logs, I noticed the issue below but I am not sure what it means:

```auto
  "components": [
    {
      "id": "log-default",
      "type": "log",
      "status": "HEALTHY",
      "message": "Healthy: communicating with pid '8520'",
      "units": [
        {
          "id": "log-default-logfile-logs-691a5a32-64ce-4c02-9f5d-d479cd5bb856",
          "type": "input",
          "status": "FAILED",
          "message": "[failed to reloading inputs: 2 errors: Error creating runner from config: Can only start an input when all related states are finished: {Id: native::1441792-2369445-1620868268, Finished: false, Fileinfo: &{19102023.log 32 {2945512199 31064694} {3402349450 31064729} {3402349450 31064729} 0 618885 0 0 {0 0} 1620868268 1441792 2369445 false}, Source: C:\\inetpub\\Hamilton\\AccountManagement\\Logs\\19102023.log, Offset: 1380633, Timestamp: 2023-10-19 16:41:18.6887885 -0400 EDT m=+21657.986057801, TTL: -1ns, Type: log, Meta: map[], FileStateOS: 1441792-2369445-1620868268}; Error creating runner from config: Can only start an input when all related states are finished: {Id: native::1703936-2369502-1620868268, Finished: false, Fileinfo: &{19102023.log 32 {2996491781 31064694} {3402619461 31064729} {3402619461 31064729} 0 908088 0 0 {0 0} 1620868268 1703936 2369502 false}, Source: C:\\inetpub\\Hamilton\\BookingManagement\\Logs\\19102023.log, Offset: 1934646, Timestamp: 2023-10-19 16:41:11.9932887 -0400 EDT m=+21651.290527201, TTL: -1ns, Type: log, Meta: map[], FileStateOS: 1703936-2369502-1620868268}]"
        },

```

---

<div class="post-metadata">

**Author:** ![CiscoMT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ciscomt/32/126708_2.png) [@CiscoMT](https://discuss.elastic.co/u/CiscoMT)\
**Post date:** [October 25, 2023, 3:13pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423/4 "2023-10-25T15:13:27Z")

</div>

It seems like we managed to fix the issue by updating the agent version from 8.7.0 to 8.10.4. Once this was done the agent came back as Healthy, but we were not getting logs.

We also noticed the custom integration was using "-" as part of the dataset name, once this part was fixed we started receiving logs.

Now we are trying to filter in the stream by the dataset name provided in the custom integration but this one is not showing.  
Appreciate any suggestions you could make with that part

Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 25, 2023, 3:20pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423/5 "2023-10-25T15:20:53Z")

</div>

> [@CiscoMT](#):
>
> Now we are trying to filter in the stream by the dataset name provided in the custom integration but this one is not showing.

Not sure what that means I would suggest opening a new topic with a complete description.

I am curious ...

> [@CiscoMT](#):
>
> I think I read in the docs that you cold just leave the folder like that to consume the whole folder.

Where you saw that in the docs, that did not work for me, I always have to provide the file `*.*` or `*.log` or `*` etc I tried just putting the folder / directory and it did not work

---

<div class="post-metadata">

**Author:** ![CiscoMT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ciscomt/32/126708_2.png) [@CiscoMT](https://discuss.elastic.co/u/CiscoMT)\
**Post date:** [October 26, 2023, 3:53pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423/6 "2023-10-26T15:53:34Z")

</div>

Will create a new threat, Thanks following up @stephenb, appreciate the help!

Regarding the \*.log part, funny, I didn't read that in the docs actually. It was a comment you left in some other topic a while ago hehe. Maybe I missed something and this doesn't apply to the custom logs integration.

[Link here](https://discuss.elastic.co/t/path-config-for-custom-log-integration/262158/4)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 26, 2023, 4:08pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423/7 "2023-10-26T16:08:51Z")

</div>

Hi @CiscoMT, Awesome and Funny! I will need to look at that closer..

That was filebeat, but I would expect agent to work the same ... Hmmmmm

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 26, 2023, 4:34pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423/8 "2023-10-26T16:34:53Z")

</div>

@CiscoMT_ **THANKS** _ for pointing that out ... no you need the trailing `*` I fixed that post. That was my misunderstanding not sure why I put that.

So yes now filbeat and agent work the same ... you need the actual file selector

```auto
..../* 
..../*.log 

```

etc

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2023, 4:35pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423/9 "2023-11-23T16:35:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
