# Filbeats not forwarding logs to logstash with back off now error

**URL:** https://discuss.elastic.co/t/filbeats-not-forwarding-logs-to-logstash-with-back-off-now-error/137637
**Category:** Beats
**Tags:** filebeat
**Created:** [June 27, 2018, 1:56pm UTC](https://discuss.elastic.co/t/filbeats-not-forwarding-logs-to-logstash-with-back-off-now-error/137637 "2018-06-27T13:56:00Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![01n12](https://avatars.discourse-cdn.com/v4/letter/0/b38774/32.png) [@01n12](https://discuss.elastic.co/u/01n12)
#### Post date: [June 27, 2018, 1:56pm UTC](https://discuss.elastic.co/t/filbeats-not-forwarding-logs-to-logstash-with-back-off-now-error/137637/1 "2018-06-27T13:56:00Z")

</div>

I'm facing a problem to forward logs from filebeats to logstash, my filbeats always throw a debug value backoff now and the following are logs of it, would some help me and also please help me to reprocess the logs from logstash to elasticsearch by resetting

_LocallevelArticleAttributes/LocallevelArticleAttributes\_MsgLogger.log, offset: 644  
2018-06-27T13:50:40.543Z DEBUG [input] log/input.go:502 File didn't change: /usr/local/applogs/RetailIS\_R4/RT\_I2639\_LocallevelArticleAttributes/LocallevelArticleAttributes\_MsgLogger.log  
2018-06-27T13:50:40.543Z DEBUG [input] log/input.go:168 input states cleaned up. Before: 2, After: 2, Pending: 0  
2018-06-27T13:50:40.572Z DEBUG [input] input/input.go:124 Run input  
2018-06-27T13:50:40.572Z DEBUG [input] log/input.go:147 Start next scan  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:362 Check file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_ArticlePrice/ArticlePrice\_AppLogger.log  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:448 Update existing file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_ArticlePrice/ArticlePrice\_AppLogger.log, offset: 8514  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:502 File didn't change: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_ArticlePrice/ArticlePrice\_AppLogger.log  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:362 Check file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_ArticlePrice/ArticlePrice\_MsgLogger.log  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:448 Update existing file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_ArticlePrice/ArticlePrice\_MsgLogger.log, offset: 914  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:502 File didn't change: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_ArticlePrice/ArticlePrice\_MsgLogger.log  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:168 input states cleaned up. Before: 2, After: 2, Pending: 0  
2018-06-27T13:50:40.573Z DEBUG [input] input/input.go:124 Run input  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:147 Start next scan  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:362 Check file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_M4193\_PricingPBC/PricingPBC\_AppLogger.log  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:448 Update existing file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_M4193\_PricingPBC/PricingPBC\_AppLogger.log, offset: 1784  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:502 File didn't change: /usr/local/applogs/RetailIS\_R4/RT\_M4193\_PricingPBC/PricingPBC\_AppLogger.log  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:362 Check file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_M4193\_PricingPBC/PricingPBC\_MsgLogger.log  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:448 Update existing file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_M4193\_PricingPBC/PricingPBC\_MsgLogger.log, offset: 196  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:502 File didn't change: /usr/local/applogs/RetailIS\_R4/RT\_M4193\_PricingPBC/PricingPBC\_MsgLogger.log  
2018-06-27T13:50:40.573Z DEBUG [input] log/input.go:168 input states cleaned up. Before: 2, After: 2, Pending: 0  
2018-06-27T13:50:40.577Z DEBUG [input] input/input.go:124 Run input  
2018-06-27T13:50:40.577Z DEBUG [input] log/input.go:147 Start next scan  
2018-06-27T13:50:40.577Z DEBUG [input] log/input.go:362 Check file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_GloballevelArticleAttributes/GloballevelArticleAttributes\_AppLogger.log  
2018-06-27T13:50:40.577Z DEBUG [input] log/input.go:448 Update existing file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_GloballevelArticleAttributes/GloballevelArticleAttributes\_AppLogger.log, offset: 18080  
2018-06-27T13:50:40.577Z DEBUG [input] log/input.go:502 File didn't change: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_GloballevelArticleAttributes/GloballevelArticleAttributes\_AppLogger.log  
2018-06-27T13:50:40.577Z DEBUG [input] log/input.go:362 Check file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_GloballevelArticleAttributes/GloballevelArticleAttributes\_MsgLogger.log  
2018-06-27T13:50:40.577Z DEBUG [input] log/input.go:448 Update existing file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_GloballevelArticleAttributes/GloballevelArticleAttributes\_MsgLogger.log, offset: 208  
2018-06-27T13:50:40.577Z DEBUG [input] log/input.go:502 File didn't change: /usr/local/applogs/RetailIS\_R4/RT\_I1273\_GloballevelArticleAttributes/GloballevelArticleAttributes\_MsgLogger.log  
2018-06-27T13:50:40.577Z DEBUG [input] log/input.go:168 input states cleaned up. Before: 2, After: 2, Pending: 0  
2018-06-27T13:50:50.543Z DEBUG [input] input/input.go:124 Run input  
2018-06-27T13:50:50.543Z DEBUG [input] log/input.go:147 Start next scan  
2018-06-27T13:50:50.543Z DEBUG [input] log/input.go:362 Check file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_I2639\_LocallevelArticleAttributes/LocallevelArticleAttributes_

---

<div class="post-metadata">

### Author: ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)
#### Post date: [June 27, 2018, 3:17pm UTC](https://discuss.elastic.co/t/filbeats-not-forwarding-logs-to-logstash-with-back-off-now-error/137637/2 "2018-06-27T15:17:13Z")

</div>

Filebeat does not reread files it has already encountered and forwarded to outputs.  
Do you want to reread all logs processed by Filebeat?

---

<div class="post-metadata">

### Author: ![01n12](https://avatars.discourse-cdn.com/v4/letter/0/b38774/32.png) [@01n12](https://discuss.elastic.co/u/01n12)
#### Post date: [June 27, 2018, 9:56pm UTC](https://discuss.elastic.co/t/filbeats-not-forwarding-logs-to-logstash-with-back-off-now-error/137637/3 "2018-06-27T21:56:20Z")

</div>

Yes, I want to reprocess the files and I deleted the filebeat registry in data folder but still not able to reprocess them

---

<div class="post-metadata">

### Author: ![warrior](https://avatars.discourse-cdn.com/v4/letter/w/2bfe46/32.png) [@warrior](https://discuss.elastic.co/u/warrior)
#### Post date: [June 28, 2018, 4:54am UTC](https://discuss.elastic.co/t/filbeats-not-forwarding-logs-to-logstash-with-back-off-now-error/137637/4 "2018-06-28T04:54:43Z")

</div>

@kvch Please help me with the filebeats

---

<div class="post-metadata">

### Author: ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)
#### Post date: [June 28, 2018, 6:22am UTC](https://discuss.elastic.co/t/filbeats-not-forwarding-logs-to-logstash-with-back-off-now-error/137637/5 "2018-06-28T06:22:30Z")

</div>

Could you share the output of `./filebeat -e -d "*"` after deleting the registry file?

---

<div class="post-metadata">

### Author: ![warrior](https://avatars.discourse-cdn.com/v4/letter/w/2bfe46/32.png) [@warrior](https://discuss.elastic.co/u/warrior)
#### Post date: [June 28, 2018, 6:24pm UTC](https://discuss.elastic.co/t/filbeats-not-forwarding-logs-to-logstash-with-back-off-now-error/137637/6 "2018-06-28T18:24:27Z")

</div>

@kvch, the filebeats had processed the logs and the following is the output of logs

0619\u003c/GLTAB\u003e\u003c/E1WBBAH\u003e\u003c/E1WBB01\u003e\u003c/IDOC\u003e\u003c/ZWBBDLD05\_G01\u003e",  
"input": {  
"type": "log"  
},  
"prospector": {  
"type": "log"  
},  
"fields": {  
"log\_type": "GA"  
},  
"beat": {  
"hostname": "[xxxxx.com](http://xxxxx.com)",  
"version": "6.3.0",  
"name": "[xxxx.com](http://xxxx.com)"  
},  
"host": {  
"name": "[xxxxx.com](http://xxxxx.com)"  
},  
"source": "/opt/webmis/ELKTest/GloballevelArticleAttributes\_AppLogger.log"  
}  
2018-06-28T18:18:09.618Z DEBUG [harvester] log/log.go:85 End of file reached: /opt/webmis/ELKTest/GloballevelArticleAttributes\_AppLogger.log; Backoff now.  
2018-06-28T18:18:09.992Z DEBUG [harvester] log/log.go:85 End of file reached: /opt/webmis/ELKTest/ArticlePrice\_AppLogger.log; Backoff now.  
2018-06-28T18:18:10.046Z DEBUG [logstash] logstash/async.go:142 9 events out of 9 events sent to logstash host 172.23.36.82:5044. Continue sending  
2018-06-28T18:18:10.117Z DEBUG [memqueue] memqueue/ackloop.go:143 ackloop: receive ack [5: 0, 9]  
2018-06-28T18:18:10.117Z DEBUG [memqueue] memqueue/eventloop.go:518 broker ACK events: count=3, start-seq=10, end-seq=12

2018-06-28T18:18:10.118Z DEBUG [memqueue] memqueue/eventloop.go:518 broker ACK events: count=4, start-seq=12, end-seq=15

2018-06-28T18:18:10.118Z DEBUG [memqueue] memqueue/eventloop.go:518 broker ACK events: count=2, start-seq=11, end-seq=12

2018-06-28T18:18:10.118Z DEBUG [memqueue] memqueue/ackloop.go:111 ackloop: return ack to broker loop:9  
2018-06-28T18:18:10.118Z DEBUG [memqueue] memqueue/ackloop.go:114 ackloop: done send ack  
2018-06-28T18:18:10.118Z DEBUG [acker] beater/acker.go:47 stateful ack {"count": 9}  
2018-06-28T18:18:10.118Z DEBUG [registrar] registrar/registrar.go:232 Processing 9 events  
2018-06-28T18:18:10.118Z DEBUG [registrar] registrar/registrar.go:202 Registrar state updates processed. Count: 9  
2018-06-28T18:18:10.118Z DEBUG [registrar] registrar/registrar.go:263 Write registry file: /opt/webmis/filebeat-6.3.0-linux-x86\_64/data/registry  
2018-06-28T18:18:10.128Z DEBUG [registrar] registrar/registrar.go:290 Registry file updated. 5 states written.  
2018-06-28T18:18:10.204Z DEBUG [harvester] log/log.go:85 End of file reached: /opt/webmis/ELKTest/LocallevelArticleAttributes\_AppLogger.log; Backoff now.  
2018-06-28T18:18:10.618Z DEBUG [harvester] log/log.go:85 End of file reached: /opt/webmis/ELKTest/GloballevelArticleAttributes\_AppLogger.log; Backoff now.  
2018-06-28T18:18:10.768Z DEBUG [harvester] log/log.go:85 End of file reached: /usr/local/applogs/RetailIS\_R4/RT\_M4193\_PricingPBC/PricingPBC\_MsgLogger.log; Backoff now.  
2018-06-28T18:18:10.768Z DEBUG [harvester] log/log.go:85 End of file reached: /usr/local/applogs/RetailIS\_R4/RT\_M4193\_PricingPBC/PricingPBC\_AppLogger.log; Backoff now.  
2018-06-28T18:18:11.992Z DEBUG [harvester] log/log.go:85 End of file reached: /opt/webmis/ELKTest/ArticlePrice\_AppLogger.log; Backoff now.  
2018-06-28T18:18:12.204Z DEBUG [harvester] log/log.go:85 End of file reached: /opt/webmis/ELKTest/LocallevelArticleAttributes\_AppLogger.log; Backoff now.  
2018-06-28T18:18:12.618Z DEBUG [harvester] log/log.go:85 End of file reached: /opt/webmis/ELKTest/GloballevelArticleAttributes\_AppLogger.log; Backoff now.  
2018-06-28T18:18:13.307Z DEBUG [input] input/input.go:124 Run input  
2018-06-28T18:18:13.307Z DEBUG [input] log/input.go:147 Start next scan  
2018-06-28T18:18:13.307Z DEBUG [input] log/input.go:362 Check file for harvesting: /opt/webmis/ELKTest/GloballevelArticleAttributes\_AppLogger.log  
2018-06-28T18:18:13.307Z DEBUG [input] log/input.go:448 Update existing file for harvesting: /opt/webmis/ELKTest/GloballevelArticleAttributes\_AppLogger.log, offset: 6968086  
2018-06-28T18:18:13.307Z DEBUG [input] log/input.go:500 Harvester for file is still running: /opt/webmis/ELKTest/GloballevelArticleAttributes\_AppLogger.log  
2018-06-28T18:18:13.307Z DEBUG [input] log/input.go:168 input states cleaned up. Before: 1, After: 1, Pending: 0  
2018-06-28T18:18:13.316Z DEBUG [input] input/input.go:124 Run input  
2018-06-28T18:18:13.316Z DEBUG [input] log/input.go:147 Start next scan  
2018-06-28T18:18:13.316Z DEBUG [input] log/input.go:362 Check file for harvesting: /opt/webmis/ELKTest/LocallevelArticleAttributes\_AppLogger.log  
2018-06-28T18:18:13.316Z DEBUG [input] log/input.go:448 Update existing file for harvesting: /opt/webmis/ELKTest/LocallevelArticleAttributes\_AppLogger.log, offset: 6055946  
2018-06-28T18:18:13.316Z DEBUG [input] log/input.go:500 Harvester for file is still running: /opt/webmis/ELKTest/LocallevelArticleAttributes\_AppLogger.log  
2018-06-28T18:18:13.316Z DEBUG [input] log/input.go:168 input states cleaned up. Before: 1, After: 1, Pending: 0  
2018-06-28T18:18:13.318Z DEBUG [input] input/input.go:124 Run input  
2018-06-28T18:18:13.318Z DEBUG [input] log/input.go:147 Start next scan  
2018-06-28T18:18:13.318Z DEBUG [input] log/input.go:362 Check file for harvesting: /opt/webmis/ELKTest/ArticlePrice\_AppLogger.log  
2018-06-28T18:18:13.318Z DEBUG [input] log/input.go:448 Update existing file for harvesting: /opt/webmis/ELKTest/ArticlePrice\_AppLogger.log, offset: 5744535  
2018-06-28T18:18:13.318Z DEBUG [input] log/input.go:500 Harvester for file is still running: /opt/webmis/ELKTest/ArticlePrice\_AppLogger.log  
2018-06-28T18:18:13.318Z DEBUG [input] log/input.go:168 input states cleaned up. Before: 1, After: 1, Pending: 0  
2018-06-28T18:18:13.324Z DEBUG [input] input/input.go:124 Run input  
2018-06-28T18:18:13.324Z DEBUG [input] log/input.go:147 Start next scan  
2018-06-28T18:18:13.324Z DEBUG [input] log/input.go:362 Check file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_M4193\_PricingPBC/PricingPBC\_AppLogger.log  
2018-06-28T18:18:13.324Z DEBUG [input] log/input.go:448 Update existing file for harvesting: /usr/local/applogs/RetailIS\_R4/RT\_M4193\_PricingPBC/PricingPBC\_AppLogger.log, offset: 1784

---

<div class="post-metadata">

### Author: ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)
#### Post date: [July 6, 2018, 12:58pm UTC](https://discuss.elastic.co/t/filbeats-not-forwarding-logs-to-logstash-with-back-off-now-error/137637/7 "2018-07-06T12:58:54Z")

</div>

If I understood you correctly, you need to change the configuration of Filebeat to forward logs to Logstash instead of Elasticsearch, delete the registry file and send the logs again.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 3, 2018, 12:58pm UTC](https://discuss.elastic.co/t/filbeats-not-forwarding-logs-to-logstash-with-back-off-now-error/137637/8 "2018-08-03T12:58:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
