# Filebeat, File was truncated. Begin reading file from offset 0

**URL:** <https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 9, 2017, 4:05pm UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526 "2017-02-09T16:05:40Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![KDerksen](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@KDerksen](https://discuss.elastic.co/u/KDerksen)\
**Post date:** [February 9, 2017, 4:05pm UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/1 "2017-02-09T16:05:40Z")

</div>

Filebeat version: 5.1.2  
OS: Debian Jessie

I am trying to set up an IIS log dashboard for the company i work for.  
So i set up a Filebeat\>Logstash\>Elasticsearch\>Grafana server.  
For a few days i thought everything was working as intended. I got pretty graphs, but after actually analyzing the data and logs i found out the data is duplicating. At the start of each day or hour (depending on what i set the IIS log schedule on) i get correct data, but after 20 minutes the data [duplicates.at](http://duplicates.at) that point i get the following message in my logs.

2017-02-09T15:20:12+01:00 INFO File was truncated. Begin reading file from offset 0: /

This repeats every 20-30 minutes.

Everything i tried so far is comming up short.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 10, 2017, 9:12am UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/2 "2017-02-10T09:12:37Z")

</div>

What is the log rotation algorithm you are using?  
Can you share your config file?

---

<div class="post-metadata">

**Author:** ![KDerksen](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@KDerksen](https://discuss.elastic.co/u/KDerksen)\
**Post date:** [February 10, 2017, 9:57am UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/3 "2017-02-10T09:57:24Z")

</div>

We are using the following logging settings in IIS.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/e1aa3600c155215b286d51ab8dad1ab681afc842.png)  
We share that folder over the network and mount it to /home/Domain/  
The schedule was set to daily before.  
And this is the config file we are using for filebeat.

[http://pastebin.com/Q2FPynBR](http://pastebin.com/Q2FPynBR)

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 13, 2017, 9:22am UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/4 "2017-02-13T09:22:36Z")

</div>

So the log volume you are reading from is a shared volume? We strongly recommend not to use network voumes and install filebeat directly on the edge nodes.

---

<div class="post-metadata">

**Author:** ![chris060986](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris060986/32/23107_2.png) [@chris060986](https://discuss.elastic.co/u/chris060986)\
**Post date:** [February 16, 2017, 12:49pm UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/5 "2017-02-16T12:49:40Z")

</div>

I have the same problem. I'am using filebeat on a Raspberry PI and try to collect the logs from network volumes. My access to the edge nodes is very limited, but logs are shared on this volumes. Any hints on my config?

`filebeat.prospectors:

- input\_type: log

tail\_files: true  
name: 0000000001de8394-beats

output.kafka:  
enabled: true  
hosts:  
- "hostname1:9092"  
- "hostname2:9092"

topic: TEST\_TOPIC  
version: 0.10.0  
worker: 4  
max\_retries: -1  
compression: none  
required\_acks: 1  
flush\_interval: 1s  
client\_id: 0000000001de8394

path.data: /var/filebeat/data

logging.to\_files: true  
logging.files:  
path: /var/log/filebeat  
name: filebeat`

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 16, 2017, 10:05pm UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/6 "2017-02-16T22:05:19Z")

</div>

@chris060986 What do you mean exactly by the same problem? Do you also get file truncated messages?

---

<div class="post-metadata">

**Author:** ![chris060986](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris060986/32/23107_2.png) [@chris060986](https://discuss.elastic.co/u/chris060986)\
**Post date:** [February 17, 2017, 7:12am UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/7 "2017-02-17T07:12:25Z")

</div>

Hi,  
yes I also get file truncated messages, but more often than 20 to 30 minutes. I've done some investigation on this problem and I figure out the problem isn't filebeat. I think its the way the volume is mounted. Also with the unix command tail -f or tail -F I received the file truncated message and when I pipe the output auf tail in a file there are also duplicates in it. Without rotating the log files or anything else.

So maybe its the implementation of the network protocol or some inconsistence between unix filesystem (where fb is running) and windows (where logs are written).

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 20, 2017, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/8 "2017-02-20T12:56:29Z")

</div>

@chris060986 What is the shared file system you are using? Do you have a flaky network connection?

---

<div class="post-metadata">

**Author:** ![chris060986](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris060986/32/23107_2.png) [@chris060986](https://discuss.elastic.co/u/chris060986)\
**Post date:** [February 27, 2017, 5:09pm UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/9 "2017-02-27T17:09:31Z")

</div>

@ruflin  
The network connection is very stable. Both, the log producer and the log-collector are in the same local 1gb-ethernet. The producer is a windows XP system and the logs are mounted into a raspian system via samba. The mounted volume is read-only.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 1, 2017, 8:13am UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/10 "2017-03-01T08:13:09Z")

</div>

Shared file systems are tricky, as sometimes content is cached and other interesting wiered things. That is why we strongly recommend to install filebeat on the edge nodes. Can you try to install it directly on the host machine?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2017, 8:13am UTC](https://discuss.elastic.co/t/filebeat-file-was-truncated-begin-reading-file-from-offset-0/74526/11 "2017-03-29T08:13:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
