# Filebeat and deleted files

**URL:** <https://discuss.elastic.co/t/filebeat-and-deleted-files/273386>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 19, 2021, 10:32am UTC](https://discuss.elastic.co/t/filebeat-and-deleted-files/273386 "2021-05-19T10:32:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![flaco0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flaco0/32/87784_2.png) [@flaco0](https://discuss.elastic.co/u/flaco0)\
**Post date:** [May 19, 2021, 10:32am UTC](https://discuss.elastic.co/t/filebeat-and-deleted-files/273386/1 "2021-05-19T10:32:13Z")

</div>

Hi,

I have a problem with filebeat and deleted files.  
I don't scrape /var/lib/docker/containers/_/_.log path

But when docker do rollup of file logs, the daemon delete file /var/lib/docker/containers/_/_.log.9, then filebeat retain this file and I have problem with disk space in /var/lib/docker.

I don't understand why filebeat use /var/lib/docker/containers/_/_.log? , if I don't use it.  
This is my filebeat configuration:

thanks.

```
filebeat.inputs:
- type: log
paths:
  - /opt/kubernetes/audit/apiserver.log
json.message_key: log
tags: ["audit"]

filebeat.autodiscover:
providers:
  - type: kubernetes
	node: ${NODE_NAME}
	hints.enabled: true
	# Default config hints is enable. You can use annotations to pod level
	hints.default_config:
	  type: container
	  paths:
		- "/var/log/containers/*${data.kubernetes.container.id}.log"
	  multiline:
		pattern: '^[[:space:]]+(at|.{3})|^Caused by:|^java'	
		negate: false
		match: after

processors:
- add_docker_metadata:

- drop_event:
  when.or:
  - regexp:
	  kubernetes.namespace: "^${NAMESPACE}*"
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2021, 12:32pm UTC](https://discuss.elastic.co/t/filebeat-and-deleted-files/273386/2 "2021-06-16T12:32:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
