# Filebeat error to publish event because EOF

**URL:** <https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 14, 2017, 9:05am UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997 "2017-02-14T09:05:25Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tr\_ng\_Trang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tr_ng_trang/32/13053_2.png) [@Tr\_ng\_Trang](https://discuss.elastic.co/u/Tr_ng_Trang)\
**Post date:** [February 14, 2017, 9:05am UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997/1 "2017-02-14T09:05:25Z")

</div>

hi sir,  
I have a problem about filebeat, the problem need to solve soon( its important), so i sorry because need to send message direct to ask you. :(.  
I have a folder, have some log file, its synchronous with folder tftp ( with other tftp server) so file log have the same name like: abc.log will be replaced by another file abc.log (i can't change name file because some reason, but i can't talk more) so its can summaries that, file log filebeat harverst will be the same name, but can same content or other. filebeat log in /var/log/filebeat show error to publish file in this file because error EOF. do you have any idea about this error.  
Thanks you so much guys.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [February 14, 2017, 11:02am UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997/2 "2017-02-14T11:02:29Z")

</div>

Can you post the actual log from Filebeat and the configuration file that you are using? Hitting EOF is usually not an error, but an expected event in Filebeat.

---

<div class="post-metadata">

**Author:** ![Tr\_ng\_Trang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tr_ng_trang/32/13053_2.png) [@Tr\_ng\_Trang](https://discuss.elastic.co/u/Tr_ng_Trang)\
**Post date:** [February 15, 2017, 2:42am UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997/3 "2017-02-15T02:42:20Z")

</div>

sorry but i forget to save my log before i change logging level of file beat to Debug, so i just have log debug like:  
2017-02-15T04:40:55+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActUserSpace\_A0\_65\_18\_08\_78\_2D\_0.log  
2017-02-15T04:40:55+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActUserSpace\_A0\_65\_18\_08\_78\_2D\_0.log, offset: 868  
2017-02-15T04:40:55+07:00 DBG File didn't change: /etc/tftproot/CscPSIActUserSpace\_A0\_65\_18\_08\_78\_2D\_0.log  
2017-02-15T04:40:55+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActUserSpace\_A0\_65\_18\_43\_08\_6E\_0.log  
2017-02-15T04:40:55+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActUserSpace\_A0\_65\_18\_43\_08\_6E\_0.log, offset: 430  
2017-02-15T04:40:55+07:00 DBG File didn't change: /etc/tftproot/CscPSIActUserSpace\_A0\_65\_18\_43\_08\_6E\_0.log  
2017-02-15T04:40:55+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActUserSpace\_A0\_65\_18\_66\_91\_64\_0.log  
2017-02-15T04:40:55+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActUserSpace\_A0\_65\_18\_66\_91\_64\_0.log, offset: 331  
2017-02-15T04:40:55+07:00 DBG File didn't change: /etc/tftproot/CscPSIActUserSpace\_A0\_65\_18\_66\_91\_64\_0.log  
2017-02-15T04:40:55+07:00 DBG Prospector states cleaned up. Before: 15, After: 15  
2017-02-15T04:40:57+07:00 DBG End of file reached: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_85\_0B\_E3\_0.log; Backoff now.  
2017-02-15T04:40:57+07:00 DBG Run prospector  
2017-02-15T04:40:57+07:00 DBG Start next scan  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_3.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_3.log, offset: 459  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_3.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_testlog.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_testlog.log, offset: 1617  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_testlog.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_0.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_0.log, offset: 104491  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_0.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_1.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_1.log, offset: 104618  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_1.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_2.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_2.log, offset: 104467  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_2.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_3.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_3.log, offset: 459  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_3.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_74\_BA\_0.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_74\_BA\_0.log, offset: 3738  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_74\_BA\_0.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_74\_BA\_6.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_74\_BA\_6.log, offset: 551  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_74\_BA\_6.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_0.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_0.log, offset: 104597  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_66\_91\_64\_0.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_85\_0B\_E3\_0.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_85\_0B\_E3\_0.log, offset: 7571  
2017-02-15T04:40:57+07:00 DBG Harvester for file is still running: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_85\_0B\_E3\_0.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_08\_78\_2D\_0.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_08\_78\_2D\_0.log, offset: 459  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_08\_78\_2D\_0.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_1.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_1.log, offset: 104585  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_1.log  
2017-02-15T04:40:57+07:00 DBG Check file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_2.log  
2017-02-15T04:40:57+07:00 DBG Update existing file for harvesting: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_2.log, offset: 104689  
2017-02-15T04:40:57+07:00 DBG File didn't change: /etc/tftproot/CscPSIActKernelSpace\_A0\_65\_18\_43\_08\_6E\_2.log  
2017-02-15T04:40:57+07:00 DBG Prospector states cleaned up. Before: 15, After: 15  
2017-02-15T04:41:00+07:00 DBG Flushing spooler because of timeout. Events flushed: 0  
2017-02-15T04:41:05+07:00 DBG Flushing spooler because of timeout. Events flushed: 0  
2017-02-15T04:41:05+07:00 DBG Run prospector  
2017-02-15T04:41:05+07:00 DBG Start next scan  
2017-02-15T04:41:05+07:00 DBG Check file for harvesting:  
it really have new file log in dir filebeat read log, but its can't publish event.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [February 15, 2017, 11:23am UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997/4 "2017-02-15T11:23:29Z")

</div>

Can you also post your configuration file, please?

---

<div class="post-metadata">

**Author:** ![Tr\_ng\_Trang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tr_ng_trang/32/13053_2.png) [@Tr\_ng\_Trang](https://discuss.elastic.co/u/Tr_ng_Trang)\
**Post date:** [February 16, 2017, 7:27am UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997/5 "2017-02-16T07:27:10Z")

</div>

sry for my late. this is my configuration in filebeat. i think its normal.  
filebeat.prospectors:

- paths:
  - "/var/log/CscPSIActUserSpace\_A0\_65\_18\_54\_B0\_FC\*"  
fields: {log\_type: user\_log}

- paths:
  - "/var/log/CscPSIActKernelSpace\_A0\_65\_18\_54\_B0\_FC\*"  
fields: {log\_type: sys\_log}  
registry\_file: /var/lib/filebeat/registry

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 16, 2017, 9:57pm UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997/6 "2017-02-16T21:57:49Z")

</div>

Can you share the full log file and format it with 3 ticks around it so the indentation is correct?

---

<div class="post-metadata">

**Author:** ![Tr\_ng\_Trang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tr_ng_trang/32/13053_2.png) [@Tr\_ng\_Trang](https://discuss.elastic.co/u/Tr_ng_Trang)\
**Post date:** [February 17, 2017, 3:08am UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997/7 "2017-02-17T03:08:53Z")

</div>

i check my configure, its right, filebeat already running correct. But now, i dont need to solve this problem, i have another problem with filebeat, it can't read log have multi line, but i have configured to multi line like:

# The regexp Pattern that has to be matched. The example pattern matches all lines starting with [

multiline.pattern: ^[LOG]

# Defines if the pattern set under pattern should be negated or not. Default is false.

multiline.negate: true

# Match can be set to "after" or "before". It is used to define if lines should be append to a pattern

# that was (not) matched before or after or as long as a pattern is not matched based on negate.

# Note: After is the equivalent to previous and before is the equivalent to to next in Logstash

multiline.match: after  
and my log have format like:  
[LOG]afafdsf  
adf  
dsf  
sf  
ffafad

but if i have just 1 file log, it working good, but if my filebeat configure to receive 2 source file log or more, its not working right.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 17, 2017, 7:24am UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997/8 "2017-02-17T07:24:05Z")

</div>

Can you open a new topic as this will not match the title anymore? Please make sure if you post configs to put it in as code for the formatting.

---

<div class="post-metadata">

**Author:** ![Tr\_ng\_Trang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tr_ng_trang/32/13053_2.png) [@Tr\_ng\_Trang](https://discuss.elastic.co/u/Tr_ng_Trang)\
**Post date:** [February 20, 2017, 2:59am UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997/9 "2017-02-20T02:59:00Z")

</div>

thanks for your feedback, i will do it next time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2017, 2:59am UTC](https://discuss.elastic.co/t/filebeat-error-to-publish-event-because-eof/74997/10 "2017-03-20T02:59:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
