# Filebeat as service on Windows Server 2008 R2 not work properly

**URL:** <https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 12, 2016, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997 "2016-01-12T15:16:59Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [January 12, 2016, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/1 "2016-01-12T15:16:59Z")

</div>

Hello,

I have finished the the implementation of ELK + filebeat, and on my laptop works well.  
ELK are installed into linux server. And filebeat should monitor files from an windows server 2008.

When I run FileBeat 1.0.1 ( i have tryed also with 1.0.0) from command prompt it works well ( at least it sends messages to Logstash in real time) even if when I had tons of logs (around 50 MB) the system become visible slowly. But as a service (install works properly) it starts to insert logs into ELK but after few hundreds of logs, it freeze and in Registry file is not updated the line of filelog, even if the time of last modify of Registry is changed when I close the service. And for this reason when I start filebeat again it starts to read same logs, and in elasticsearch i have these data as duplicate.  
I have check also the log file of filebeat and I believe this can be the reason:

> 2016-01-12T16:24:05+02:00 ERR Error sending/writing event: write /dev/stdout: The handle is invalid.

What you you think about this issue?

Thank you!  
Ovidiu

P.S. Durring I wrote this email filebeat in command prompt detect and insert over 7000 lines, and seems to be ok.

---

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [January 12, 2016, 3:21pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/2 "2016-01-12T15:21:42Z")

</div>

Update: I have counted the inserted logs after service freeze and i got these numbers: 1024, 431, 479, 479, 1024. this number catch my attention "1024" and i have checked the filebeat.yml and I found this settings:

> # General filebeat configuration options
> 
> # 
> 
> # Event count spool threshold - forces network flush if exceeded
> 
> #spool\_size: `1024`

can be this spool\_size the freeze reason?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 12, 2016, 4:02pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/3 "2016-01-12T16:02:30Z")

</div>

Best way to debug would be if you could set the log level to debug in the config file and post an excerpt here. spool\_size should not be a reason for a freeze.

---

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [January 13, 2016, 10:05am UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/4 "2016-01-13T10:05:57Z")

</div>

Hi Rufin,  
I have made your sugestion, and i have news. Also I have played with spool\_size value and it seems to have a direct impact, i'm not sure if it is the reason of freeze.

With debug activated i have made 3 simulations:

1. spool\_size = 1024 (default). at this test after 1024 messages inserted into elasticsearch it freeze with these logs:

2nd. spool\_size = 2048. at this test after 2048 messages inserted into elasticsearch it freeze with similar logs the the only difference is this:

```
2016-01-13T11:35:21+02:00 DBG Forward preprocessed events
2016-01-13T11:35:21+02:00 DBG output worker: publish 2048 events
2016-01-13T11:35:21+02:00 DBG output worker: publish 2048 events
2016-01-13T11:35:21+02:00 DBG Try to publish %!s(int=2048) events to logstash with window size %!s(int=10)
2016-01-13T11:35:21+02:00 ERR Error sending/writing event: write /dev/stdout: The handle is invalid.
2016-01-13T11:35:21+02:00 DBG %!s(int=10) events out of %!s(int=2048) events sent to logstash. Continue sending ...
2016-01-13T11:35:21+02:00 DBG Try to publish %!s(int=2038) events to logstash with window size %!s(int=15)
2016-01-13T11:35:21+02:00 DBG %!s(int=15) events out of %!s(int=2038) events sent to logstash. Continue sending ...

```

3rd. spool\_size = 100. at this test after 100 messages inserted into elasticsearch it freeze with similar logs.

I have tried to attach also the full file logs of simulations, but seems like i cannot.

Do you have any idea?

Regards,  
Ovidiu

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 13, 2016, 11:00am UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/5 "2016-01-13T11:00:22Z")

</div>

Can you share your filebeat configuration? Despite the `/dev/stdout` error (which is weird), I don't see any signs in the logs of filebeat beeing frozen.

Anything of interest in logstash logs?

---

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [January 13, 2016, 11:19am UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/6 "2016-01-13T11:19:46Z")

</div>

Hi,  
Usually I don't have access to logstash server ( i'm noob in linux), but if you want I can ask for logs. But in order to made this test i use the same logstash instance with 2 windows servers 2008 which sends data to logstash. On one server filebeat run from command prompt (and it works well) in other I trying to make it work as service, both have the same filebeat configuration.  
This is filebeat configuration:

```
filebeat:
  prospectors:
      paths:
       - D:\Logs\Platform_*
      input_type: 
  spool_size: 1024
  registry_file: "D:/ElasticSearch/filebeat1/registry"
output:
  logstash:
    hosts: ["10.98.25.182:9202"]
    index: "st"	
  console:
    pretty: true
shipper:
logging:
  files:
    path: D:/ElasticSearch/filebeat1/Logs
	# i make it bigger for test
    rotateeverybytes: 20971520 # = 20MB 
  level: debug

```

Thank you!  
Ovidiu

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 13, 2016, 1:11pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/7 "2016-01-13T13:11:45Z")

</div>

Are there no log outputs anymore after the above? I would expect about every 10 seconds to appear something like "Start next scan"?

---

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [January 13, 2016, 1:15pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/8 "2016-01-13T13:15:27Z")

</div>

I have also other logs like "start netxt scan" But I can't send you to many logs because I'm limited at 5000 chars. Check these:

```
2016-01-13T11:37:20+02:00 DBG Forward preprocessed events
2016-01-13T11:37:20+02:00 DBG output worker: publish 100 events
2016-01-13T11:37:20+02:00 DBG output worker: publish 100 events
2016-01-13T11:37:20+02:00 DBG Try to publish %!s(int=100) events to logstash with window size %!s(int=10)
2016-01-13T11:37:20+02:00 ERR Error sending/writing event: write /dev/stdout: The handle is invalid.
2016-01-13T11:37:20+02:00 DBG %!s(int=10) events out of %!s(int=100) events sent to logstash. Continue sending ...
2016-01-13T11:37:20+02:00 DBG Try to publish %!s(int=90) events to logstash with window size %!s(int=15)
2016-01-13T11:37:21+02:00 DBG %!s(int=15) events out of %!s(int=90) events sent to logstash. Continue sending ...
2016-01-13T11:37:21+02:00 DBG Try to publish %!s(int=75) events to logstash with window size %!s(int=22)
2016-01-13T11:37:21+02:00 DBG %!s(int=22) events out of %!s(int=75) events sent to logstash. Continue sending ...
2016-01-13T11:37:21+02:00 DBG Try to publish %!s(int=53) events to logstash with window size %!s(int=33)
2016-01-13T11:37:21+02:00 DBG %!s(int=33) events out of %!s(int=53) events sent to logstash. Continue sending ...
2016-01-13T11:37:21+02:00 DBG Try to publish %!s(int=20) events to logstash with window size %!s(int=49)
2016-01-13T11:37:21+02:00 DBG %!s(int=20) events out of %!s(int=20) events sent to logstash. Continue sending ...
2016-01-13T11:37:30+02:00 DBG Start next scan
2016-01-13T11:37:30+02:00 DBG scan path D:\Logs\Platform_*
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform_20160112-10.log
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform_20160112-10.log
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform_20160112-10.log
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform_20160112-11.log
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform_20160112-11.log
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform_20160112-11.log
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform_20160112-12.log
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform_20160112-12.log
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform_20160112-12.log
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform_20160112-13.log
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform_20160112-13.log
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform_20160112-13.log
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform_20160112-14.log
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform_20160112-14.log
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform_20160112-14.log
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform_20160112-15.log
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform_20160112-15.log
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform_20160112-15.log
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform_20160112-16.log
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform_20160112-16.log
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform_20160112-16.log
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform_20160112-17.log
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform_20160112-17.log
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform_20160112-17.log
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform_20160112-18.log
```

---

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [January 13, 2016, 1:17pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/9 "2016-01-13T13:17:23Z")

</div>

2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform\_20160112-19.log  
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform\_20160112-19.log  
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform\_20160112-19.log  
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform\_20160113-07.log  
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform\_20160113-07.log  
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform\_20160113-07.log  
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform\_20160113-09.log  
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform\_20160113-09.log  
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform\_20160113-09.log  
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform\_20160113-10.log  
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform\_20160113-10.log  
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform\_20160113-10.log  
2016-01-13T11:37:30+02:00 DBG Check file for harvesting: D:\Logs\Platform\_20160113-11.log  
2016-01-13T11:37:30+02:00 DBG Update existing file for harvesting: D:\Logs\Platform\_20160113-11.log  
2016-01-13T11:37:30+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform\_20160113-11.log  
2016-01-13T11:37:40+02:00 DBG Start next scan  
2016-01-13T11:37:40+02:00 DBG scan path D:\Logs\Platform\_\*  
2016-01-13T11:37:40+02:00 DBG Check file for harvesting: D:\Logs\Platform\_20160112-10.log  
2016-01-13T11:37:40+02:00 DBG Update existing file for harvesting: D:\Logs\Platform\_20160112-10.log  
2016-01-13T11:37:40+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform\_20160112-10.log  
2016-01-13T11:37:40+02:00 DBG Check file for harvesting: D:\Logs\Platform\_20160112-11.log  
2016-01-13T11:37:40+02:00 DBG Update existing file for harvesting: D:\Logs\Platform\_20160112-11.log  
2016-01-13T11:37:40+02:00 DBG Not harvesting, file didn't change: D:\Logs\Platform\_20160112-11.log  
2016-01-13T11:37:40+02:00 DBG Check file for harvesting: D:\Logs\Platform\_20160112-12.log  
etc

---

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [January 13, 2016, 1:30pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/10 "2016-01-13T13:30:58Z")

</div>

OMG! I found the issue!

Seems like windows services don't like to have `console` on, after I remove console, it works well. In few minutes I already have all logs (122k) into elasticsearch. I'm going to have a beer, it was a terrible day.

Thank you for help!

> [@djvidov](#):
>
> filebeat:  
> prospectors:  
> paths:  
> - D:\Logs\Platform\_\*  
> input\_type:  
> spool\_size: 1024  
> registry\_file: "D:/Elasticsearch/filebeat1/registry"  
> output:  
> logstash:  
> hosts: ["10.98.25.182:9202"]  
> index: "st"   
> `console:`  
> ` pretty: true`  
> shipper:  
> logging:  
> files:  
> path: D:/Elasticsearch/filebeat1/Logs  
> # i make it bigger for test  
> rotateeverybytes: 20971520 # = 20MB  
> level: debug

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 13, 2016, 1:35pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/11 "2016-01-13T13:35:10Z")

</div>

Good to hear it works. Enjoy your 🍻

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 13, 2016, 8:35pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/12 "2016-01-13T20:35:45Z")

</div>

As Windows seems not to be able to send to the console output, it also blocks the elasticsearch output. The output in the next major version of filebeat is already improved so the problem is much easier to detect.

---

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [January 14, 2016, 7:53am UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/13 "2016-01-14T07:53:45Z")

</div>

yes, this was the issue. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:56pm UTC](https://discuss.elastic.co/t/filebeat-as-service-on-windows-server-2008-r2-not-work-properly/38997/14 "2017-07-05T21:56:44Z")

</div>


