# Elastic-agent ingest interval

**URL:** <https://discuss.elastic.co/t/elastic-agent-ingest-interval/357921>\
**Category:** Elastic Agent\
**Tags:** fleet, integrations\
**Created:** [April 22, 2024, 3:43pm UTC](https://discuss.elastic.co/t/elastic-agent-ingest-interval/357921 "2024-04-22T15:43:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nml1988](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nml1988/32/120871_2.png) [@nml1988](https://discuss.elastic.co/u/nml1988)\
**Post date:** [April 22, 2024, 3:43pm UTC](https://discuss.elastic.co/t/elastic-agent-ingest-interval/357921/1 "2024-04-22T15:43:18Z")

</div>

Hi people!  
I need your help with a requirement.

I installed an elastic-agent 8.11.4 on a windows server to read and send data from .csv files by integrating fleet 'custom logs'.

The agent was installed by default.

Currently the agent reads and ingests the data every 1 hour, but I need this action to be done every 15 minutes.

I have searched for information and I can't find the key.

Is there any parameter that I can modify so that the agent sends the data of the csv reports every 15 minutes?

Thank you very much!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 26, 2024, 6:21pm UTC](https://discuss.elastic.co/t/elastic-agent-ingest-interval/357921/2 "2024-05-26T18:21:40Z")

</div>

Hi @nml1988  
Sorry we didn't see this.. have you solved this?

Can you share your configuration?

How much data is in the csv files?

How are the written and updae

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 14, 2025, 8:42pm UTC](https://discuss.elastic.co/t/elastic-agent-ingest-interval/357921/3 "2025-05-14T20:42:46Z")

</div>

Hi @nml1988

do you still need help on this?

If you are using Custom Logs Filestream

The file is scanned every 10s by default.

> **[filestream input | Elastic Documentation](https://www.elastic.co/docs/reference/beats/filebeat/filebeat-input-filestream#filebeat-input-filestream-scan-frequency)**
>
> Use the filestream input to read lines from active log files. It is the new, improved alternative to the log input. It comes with various improvements...

The default is 10s

> `prospector.scanner.check_interval` How often Filebeat checks for new files in the paths that are specified for harvesting. For example, if you specify a glob like `/var/log/*`, the directory is scanned for files using the frequency specified by `check_interval`. Specify 1s to scan the directory as frequently as possible without causing Filebeat to scan too frequently. We do not recommend to set this value `<1s`.  
> If you require log lines to be sent in near real time do not use a very low `check_interval` but adjust `close.on_state_change.inactive` so the file handler stays open and constantly polls your files.  
> The default setting is 10s.

So in short if you post a new file ... it should be read within 10s

If you append new lines to an existing file it should be read almost immediately like `tail`

If you are using the Deprecated Log Intput it is also 10s

> **[Log input | Elastic Documentation](https://www.elastic.co/docs/reference/beats/filebeat/filebeat-input-log#filebeat-input-log-scan-frequency)**
>
> Use the log input to read lines from log files. To configure this input, specify a list of glob-based paths that must be crawled to locate and fetch the...
