# Filebeat blocking generation of new log files by IIS

**URL:** <https://discuss.elastic.co/t/filebeat-blocking-generation-of-new-log-files-by-iis/116903>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 24, 2018, 5:16pm UTC](https://discuss.elastic.co/t/filebeat-blocking-generation-of-new-log-files-by-iis/116903 "2018-01-24T17:16:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gasparuben](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gasparuben/32/50393_2.png) [@gasparuben](https://discuss.elastic.co/u/gasparuben)\
**Post date:** [January 24, 2018, 5:16pm UTC](https://discuss.elastic.co/t/filebeat-blocking-generation-of-new-log-files-by-iis/116903/1 "2018-01-24T17:16:02Z")

</div>

From time to time we are noting that filebeat some how is blocking generation of new log files by IIS process (w3wp.exe).  
We follow a very standard ELK stack. Filebeat version 5.6.3 (64bits) runs on a WIndows 2008 R2 Enterprise server. It runs as a windows service, with following configuration for the collector:

```
...
- input_type: log
  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - E:\Logfiles\EWS\Ews_2*
  fields:  
    document_type: ews
  close_inactive: 5m
  close_renamed: true
  close_removed: true
  exclude_lines: ["^#"]
...

```

On the Windows system I see the open attributes as:

```
C:\..\SysinternalsSuite\handle.exe -u Ews_20180124

filebeat.exe pid: 19800 type: File NT AUTHORITY\SYSTEM 708: E:\Logfiles\EWS\Ews_20180124-142.LOG
filebeat.exe pid: 19800 type: File NT AUTHORITY\SYSTEM 7F4: E:\Logfiles\EWS\Ews_20180124-143.LOG
w3wp.exe pid: 19580 type: File NT AUTHORITY\SYSTEM 56B4: E:\Logfiles\EWS\Ews_20180124-143.LOG

C:\..\SysinternalsSuite\handle.exe | findstr /C:Ews_20180124-143.LOG
  7F4: File (RWD) E:\Logfiles\EWS\Ews_20180124-143.LOG
 56B4: File (R--) E:\Logfiles\EWS\Ews_20180124-143.LOG

```

Which is what I would expect.

To add more evidences, IIS creates the log file like :

```
|Desired Access:|Generic Write, Read Attributes|
|---|---|
|Disposition:|OpenIf|
|Options:|Synchronous IO Non-Alert, Non-Directory File, Open No Recall|
|Attributes:|n/a|
|ShareMode:|Read|
|AllocationSize:|0|
|OpenResult:|Created|

```

The symptoms reported are that from time to time we are missing the generation of new log files. So IIS fails to log new information on the old log file (rotation is done by size) while no new files are generated. Restarting the filebeat windows service seems like solving the issue.

Any hint?  
Thank you!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 25, 2018, 5:17pm UTC](https://discuss.elastic.co/t/filebeat-blocking-generation-of-new-log-files-by-iis/116903/2 "2018-01-25T17:17:22Z")

</div>

> [@gasparuben](#):
>
> Which is what I would expect.

Me too. Thanks for providing detailed debug information.

I don't have personal experience with IIS logging. So IIS is writing `E:\Logfiles\EWS\Ews_20180124-143.LOG` and then when it reaches a certain size it will start writing to `E:\Logfiles\EWS\Ews_20180124-144.LOG` (assuming it's in the same day)?

If so, I don't see how Filebeat would block the creation of the new file. Could IIS be blocked on a delete? Filebeat should allow for deleted as evidenced by the `D` is the share mode for the filebeat handle.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2018, 5:17pm UTC](https://discuss.elastic.co/t/filebeat-blocking-generation-of-new-log-files-by-iis/116903/3 "2018-02-22T17:17:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
