# Delete filebeat processed file

**URL:** <https://discuss.elastic.co/t/delete-filebeat-processed-file/146607>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 30, 2018, 4:02am UTC](https://discuss.elastic.co/t/delete-filebeat-processed-file/146607 "2018-08-30T04:02:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_kyllr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_kyllr/32/27610_2.png) [@\_kyllr](https://discuss.elastic.co/u/_kyllr)\
**Post date:** [August 30, 2018, 4:02am UTC](https://discuss.elastic.co/t/delete-filebeat-processed-file/146607/1 "2018-08-30T04:02:16Z")

</div>

Hi, does filebeat has a feature that will delete the file after it is processed?  
Or anyone has an idea how to delete the source file itself when all the data has been read?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 30, 2018, 4:59am UTC](https://discuss.elastic.co/t/delete-filebeat-processed-file/146607/2 "2018-08-30T04:59:07Z")

</div>

It does not have that option.

Something like `cat file | filebeat .... && rm file` would work, but you'd need to call it somehow. That does assume the file would process without errors as well, which is a risk if it doesn't.

---

<div class="post-metadata">

**Author:** ![ashnik](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@ashnik](https://discuss.elastic.co/u/ashnik)\
**Post date:** [September 3, 2018, 6:42am UTC](https://discuss.elastic.co/t/delete-filebeat-processed-file/146607/3 "2018-09-03T06:42:54Z")

</div>

Filebeat maintains a registry file which contains the number of bytes read by each file.  
You can write a cronjob to delete the file if the bytes read is equal to the size of the file.  
On Linux, the file is present at /var/lib/filebeat/registry.

Although this is not a clean solution and it would be great if Filebeat can provide an inbuilt feature that does this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2018, 6:43am UTC](https://discuss.elastic.co/t/delete-filebeat-processed-file/146607/4 "2018-10-01T06:43:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
