Filebeat is not sending complete logs

I am using docker elk for logs and forwarding logs using filebeat but some logs were sent or some not?

my filebeat.yml ->

filebeat logs in debug mode ->

Filebeat persists the state. So if you started filebeat in the past it only sends the new events. Looking at the log file during startup it finds a lot of files it has a state for it before.

Can you share some more details on which events / logs are not send or does the above already answer your question?

Thanks for quick response

So can you direct me how can I state the files again like. I want all the files to be stated again?

and in my elasticsearch log -

Failed to execute phase [query], all shards failed
at org.elasticsearch.action.ActionListenerResponseHandler.handleException(
at org.elasticsearch.transport.TransportService$DirectResponseChannel.processException(
at org.elasticsearch.transport.TransportService$DirectResponseChannel.sendResponse(
at org.elasticsearch.transport.TransportService$4.onFailure(
at java.util.concurrent.ThreadPoolExecutor.runWorker(
at java.util.concurrent.ThreadPoolExecutor$

If you want to reindex all files, you need to stop filebeat and then remove the registry_file here. In your case it is found here:

Not sure how the elasticsearch query is related to this?

This topic was automatically closed after 21 days. New replies are no longer allowed.