# Filebeat and logs with preallocated space

**URL:** <https://discuss.elastic.co/t/filebeat-and-logs-with-preallocated-space/266223>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 4, 2021, 11:26am UTC](https://discuss.elastic.co/t/filebeat-and-logs-with-preallocated-space/266223 "2021-03-04T11:26:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![111449](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111449/32/79499_2.png) [@111449](https://discuss.elastic.co/u/111449)\
**Post date:** [March 4, 2021, 11:26am UTC](https://discuss.elastic.co/t/filebeat-and-logs-with-preallocated-space/266223/1 "2021-03-04T11:26:55Z")

</div>

Hello!

Legacy software I have to use works on Windows and writes a log in the following way:  
it writes a lot of \u0000 (NULL) symbols into the end of file to preallocate space and then (when it needs to write a log string) consistently replaces NULLs with real data.  
But Filebeat reads NULLs immediately when they appear and sends them to Logstash. Thereby Logstash receives a lot of garbage and most of the real logs are not sent at all.

Is there any solution of this issue?

I've found some topics about \u0000 and buffering like this:

> [@Filebeat 5.0 with multiline, split event data to two events](https://discuss.elastic.co/t/filebeat-5-0-with-multiline-split-event-data-to-two-events/60380/23):
>
> but timeout will not protect you from weird buffering effects, as file pointer is already advanced once this happens.

But there is no solution.

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [March 5, 2021, 9:53am UTC](https://discuss.elastic.co/t/filebeat-and-logs-with-preallocated-space/266223/2 "2021-03-05T09:53:53Z")

</div>

Hm.. could you please share more details regarding your filebeat version?

---

<div class="post-metadata">

**Author:** ![111449](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111449/32/79499_2.png) [@111449](https://discuss.elastic.co/u/111449)\
**Post date:** [March 5, 2021, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-and-logs-with-preallocated-space/266223/3 "2021-03-05T21:06:39Z")

</div>

Hello Marcin!

Version is 7.3.1  
Do you believe Filebeat is designed to manage such a preallocation? Do you know how it does it?

We use Proxmox for virtualization and have found out the following. Filebeat does work correctly when paravirtualized storage backend is old virtio-blk. But the described issue occurs when backend is new virtio-scsi. Could you suggest how it might affect Filebeat?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2021, 11:07pm UTC](https://discuss.elastic.co/t/filebeat-and-logs-with-preallocated-space/266223/4 "2021-04-02T23:07:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
