# Filebeat doesn't update log file and limits file to 2048 lines

**URL:** <https://discuss.elastic.co/t/filebeat-doesnt-update-log-file-and-limits-file-to-2048-lines/53964>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 26, 2016, 1:48pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-update-log-file-and-limits-file-to-2048-lines/53964 "2016-06-26T13:48:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dan2](https://avatars.discourse-cdn.com/v4/letter/d/74df32/32.png) [@Dan2](https://discuss.elastic.co/u/Dan2)\
**Post date:** [June 26, 2016, 1:48pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-update-log-file-and-limits-file-to-2048-lines/53964/1 "2016-06-26T13:48:29Z")

</div>

Hi,

I'm new to this.

I want Filebeat to update the output file each time the log gets updated.  
What's happening now is that Filebeat creates a file with only the existing lines that fit "inclued\_lines" that I've entered.

Another problem that I have is that the new file that Filebeat creates is limited to 204 lines.  
For example - If I have a log file with 5k lines, only the first 2048 will be written to the new file.

############################# Filebeat ######################################  
filebeat:

# List of prospectors to fetch data.

prospectors:  
# Each - is a prospector. Below are the prospector specific configurations  
-

```
  paths:
    - C:\nexperience\logs\handsets\syslog.004562.02.log
    #- c:\programdata\elasticsearch\logs\*

  input_type: log

  include_lines: ["DEBUG"]

  scan_frequency: 5s

```

registry\_file: "C:/ProgramData/filebeat/registry"

output:

### Elasticsearch as output

elasticsearch:  
# Array of hosts to connect to.  
# Scheme and port can be left out and will be set to the default (http and 9200)  
# In case you specify and additional path, the scheme is required: [http://localhost:9200/path](http://localhost:9200/path)  
# IPv6 addresses should always be defined as: https://[2001:db8::1]:9200  
hosts: ["localhost:9200"]

```
template:

  # Template name. By default the template name is filebeat.
  #name: "filebeat"

  # Path to template file
  path: "filebeat.template.json"

```

### File as output

file:  
# Path to the directory where to save the generated files. The option is mandatory.  
path: "/tmp/filebeat"

```
# Name of the generated files. The default is `filebeat` and it generates files: `filebeat`, `filebeat.1`, `filebeat.2`, etc.
filename: filebeat

# Maximum size in kilobytes of each file. When this size is reached, the files are
# rotated. The default value is 10 MB.
#rotate_every_kb: 10000

# Maximum number of files under path. When this number of files is reached, the
# oldest file is deleted and the rest are shifted from last to first. The default
# is 7 files.
number_of_files: 2

```

### Console output

# console:

```
# Pretty print json event
#pretty: false

```

############################# Shipper #########################################

shipper:

############################# Logging #########################################

logging:

files:

```
rotateeverybytes: 10485760 # = 10MB
```

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [June 26, 2016, 4:55pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-update-log-file-and-limits-file-to-2048-lines/53964/2 "2016-06-26T16:55:32Z")

</div>

I've moved this to the appropriate category.

---

<div class="post-metadata">

**Author:** ![Dan2](https://avatars.discourse-cdn.com/v4/letter/d/74df32/32.png) [@Dan2](https://discuss.elastic.co/u/Dan2)\
**Post date:** [June 27, 2016, 7:14am UTC](https://discuss.elastic.co/t/filebeat-doesnt-update-log-file-and-limits-file-to-2048-lines/53964/3 "2016-06-27T07:14:59Z")

</div>

Thanks, but I've already solved this.  
You can close the thread.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 27, 2016, 10:10am UTC](https://discuss.elastic.co/t/filebeat-doesnt-update-log-file-and-limits-file-to-2048-lines/53964/4 "2016-06-27T10:10:20Z")

</div>

would be nice to write down the solutions for others running into similar issues.

---

<div class="post-metadata">

**Author:** ![Dan2](https://avatars.discourse-cdn.com/v4/letter/d/74df32/32.png) [@Dan2](https://discuss.elastic.co/u/Dan2)\
**Post date:** [June 27, 2016, 1:07pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-update-log-file-and-limits-file-to-2048-lines/53964/5 "2016-06-27T13:07:04Z")

</div>

SOLUTION:  
for the problem I had with the file writing only 2048 lines:  
I've changed "spool\_size" value to 10000.

for not updating the file:  
In output section I had 'elasticsearch' and 'file' uncommented, so I just commented 'elasticsearch' with all its fields.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 27, 2016, 1:16pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-update-log-file-and-limits-file-to-2048-lines/53964/6 "2016-06-27T13:16:57Z")

</div>

it should not be required to increase the spool size. Once (all) outputs confirmed something written, the next lines will be processed and pushed. Having had 2048 events sounds like file output being successful, but output pipeline still hanging on elasticsearch output due to not getting an ACK (or not being able to connect).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:51pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-update-log-file-and-limits-file-to-2048-lines/53964/7 "2017-07-05T21:51:05Z")

</div>


