# Filebeat giving error on start - Unable to read file at end

**URL:** <https://discuss.elastic.co/t/filebeat-giving-error-on-start-unable-to-read-file-at-end/51407>\
**Category:** Beats\
**Created:** [May 31, 2016, 9:29am UTC](https://discuss.elastic.co/t/filebeat-giving-error-on-start-unable-to-read-file-at-end/51407 "2016-05-31T09:29:17Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Varun\_Kapoor](https://avatars.discourse-cdn.com/v4/letter/v/8c91f0/32.png) [@Varun\_Kapoor](https://discuss.elastic.co/u/Varun_Kapoor)\
**Post date:** [May 31, 2016, 9:29am UTC](https://discuss.elastic.co/t/filebeat-giving-error-on-start-unable-to-read-file-at-end/51407/1 "2016-05-31T09:29:17Z")

</div>

Hi

Whenever I am starting the file beat it gives me following error

2016-05-31T09:24:09Z INFO Harvester started for file: -  
2016-05-31T09:24:09Z ERR Unexpected state reading from /dev/stdin; error: read /dev/stdin: resource temporarily unavailable  
2016-05-31T09:24:09Z INFO Read line error: read /dev/stdin: resource temporarily unavailable

I am using `input_type: stdin`

I am using Filebeat - 1.2.3  
OS: Ubuntu 14.04 - 64 Bit

My Config File

```auto
    -
      paths:
        - /var/www/vhosts/xyz/app/tmp/logs/debug.log
      document_type: api-cake-debug
      input_type: stdin
    -
      paths:
        - /var/www/vhosts/xyz/app/tmp/logs/error.log
      document_type: api-cake-error
      input_type: stdin
    -
      paths:
        - /var/www/vhosts/xyz/app/tmp/logs/api.log
      document_type: api-app
      input_type: stdin
    -
      paths:
        - /var/www/vhosts/xyz/tmp/logs/debug.log
      document_type: app-cake-debug
      input_type: stdin
    -
      paths:
        - /var/www/vhosts/xyz/tmp/logs/error.log
      document_type: app-cake-error
      input_type: stdin

```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 31, 2016, 10:20am UTC](https://discuss.elastic.co/t/filebeat-giving-error-on-start-unable-to-read-file-at-end/51407/2 "2016-05-31T10:20:08Z")

</div>

why do you use `input_type: stdin`? Using stding + paths doesn't make much sense to me. Is filebeat started as service? If so, stdin might be closed.

---

<div class="post-metadata">

**Author:** ![Varun\_Kapoor](https://avatars.discourse-cdn.com/v4/letter/v/8c91f0/32.png) [@Varun\_Kapoor](https://discuss.elastic.co/u/Varun_Kapoor)\
**Post date:** [May 31, 2016, 10:24am UTC](https://discuss.elastic.co/t/filebeat-giving-error-on-start-unable-to-read-file-at-end/51407/3 "2016-05-31T10:24:13Z")

</div>

Yes, filebeat is started as service. I didnt get how stdin might be closed in this case?

---

<div class="post-metadata">

**Author:** ![Varun\_Kapoor](https://avatars.discourse-cdn.com/v4/letter/v/8c91f0/32.png) [@Varun\_Kapoor](https://discuss.elastic.co/u/Varun_Kapoor)\
**Post date:** [May 31, 2016, 10:30am UTC](https://discuss.elastic.co/t/filebeat-giving-error-on-start-unable-to-read-file-at-end/51407/4 "2016-05-31T10:30:24Z")

</div>

@steffens: I have setup the same on 1.1.2 i.e. with input\_type:stdin and it was working fine with it. Don't know what's wrong with this one?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 31, 2016, 11:58am UTC](https://discuss.elastic.co/t/filebeat-giving-error-on-start-unable-to-read-file-at-end/51407/5 "2016-05-31T11:58:14Z")

</div>

no idea how it used to work with 'stdin' (@ruflin any idea?). Change `input_type` to `input_type:log`.

---

<div class="post-metadata">

**Author:** ![Varun\_Kapoor](https://avatars.discourse-cdn.com/v4/letter/v/8c91f0/32.png) [@Varun\_Kapoor](https://discuss.elastic.co/u/Varun_Kapoor)\
**Post date:** [May 31, 2016, 1:17pm UTC](https://discuss.elastic.co/t/filebeat-giving-error-on-start-unable-to-read-file-at-end/51407/6 "2016-05-31T13:17:09Z")

</div>

I used stdin then as my log were multiline. Now when i change stdin to log, it starts sending me line by line instead of complete error in a one go.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 1, 2016, 9:56am UTC](https://discuss.elastic.co/t/filebeat-giving-error-on-start-unable-to-read-file-at-end/51407/7 "2016-06-01T09:56:55Z")

</div>

the `input_type` is fully independent of multiline. I don't even see any multiline configured in your sample config.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:51pm UTC](https://discuss.elastic.co/t/filebeat-giving-error-on-start-unable-to-read-file-at-end/51407/8 "2017-07-05T21:51:20Z")

</div>


