# Filebeat intermittent auto discovery states issue

**URL:** <https://discuss.elastic.co/t/filebeat-intermittent-auto-discovery-states-issue/243590>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 3, 2020, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-intermittent-auto-discovery-states-issue/243590 "2020-08-03T14:31:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![raulgs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raulgs/32/68308_2.png) [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Post date:** [August 3, 2020, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-intermittent-auto-discovery-states-issue/243590/1 "2020-08-03T14:31:15Z")

</div>

I just switched from fluentd to filebeat and am seeing the following issues for some logs now.  
Does anyone have an idea where the issue could reside?

```auto
2020-08-03T14:26:23.349Z ERROR [autodiscover] autodiscover/autodiscover.go:210 Auto discover config check failed for config '{
  "docker-json": {
    "cri_flags": true,
    "format": "auto",
    "partial": true,
    "stream": "all"
  },
  "exclude_lines": [
    "^\\s+[\\-`('.|_]"
  ],
  "ignore_older": "48h",
  "multiline": {
    "match": "after",
    "negate": false,
    "pattern": "^[[:space:]]"
  },
  "paths": [
    "/var/log/containers/*-c5913198fe1bcd4fdbf6eca0d777e7d97b3b76ac938d2a0d24122e3af0195011.log"
  ],
  "symlinks": true,
  "type": "container"
}', won't start runner: Can only start an input when all related states are finished: {Id:67529863-2049 Finished:false Fileinfo:0xc004650270 Source:/var/log/containers/grafana-postgres-db-0_sensu-system_postgres-c5913198fe1bcd4fdbf6eca0d777e7d97b3b76ac938d2a0d24122e3af0195011.log Offset:885005 Timestamp:2020-08-03 14:26:18.604698192 +0000 UTC m=+2628.868409771 TTL:-1ns Type:container Meta:map[] FileStateOS:67529863-2049}

```

---

<div class="post-metadata">

**Author:** ![jonny0815](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonny0815/32/73362_2.png) [@jonny0815](https://discuss.elastic.co/u/jonny0815)\
**Post date:** [August 6, 2020, 6:40am UTC](https://discuss.elastic.co/t/filebeat-intermittent-auto-discovery-states-issue/243590/2 "2020-08-06T06:40:30Z")

</div>

I've got the exact same issue. After this error message appears, no logs will be collected for the affected container anymore, until the collecting filebeat instance is restarted.

I'm running filebeat-7.8.1 with elasticsearch-7.8.1

---

<div class="post-metadata">

**Author:** ![yogeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogeek/32/74263_2.png) [@yogeek](https://discuss.elastic.co/u/yogeek)\
**Post date:** [August 20, 2020, 10:10pm UTC](https://discuss.elastic.co/t/filebeat-intermittent-auto-discovery-states-issue/243590/3 "2020-08-20T22:10:24Z")

</div>

I think this can help : [https://github.com/elastic/beats/issues/11834](https://github.com/elastic/beats/issues/11834)

---

<div class="post-metadata">

**Author:** ![raulgs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raulgs/32/68308_2.png) [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Post date:** [August 21, 2020, 5:45am UTC](https://discuss.elastic.co/t/filebeat-intermittent-auto-discovery-states-issue/243590/4 "2020-08-21T05:45:35Z")

</div>

Update to v7.9.0 fixed the issue for me.  
kudos to the elastic-team

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2020, 7:45am UTC](https://discuss.elastic.co/t/filebeat-intermittent-auto-discovery-states-issue/243590/5 "2020-09-18T07:45:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
