# Filebeat is not sending log entries/logs to logstash server

**URL:** <https://discuss.elastic.co/t/filebeat-is-not-sending-log-entries-logs-to-logstash-server/155227>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 2, 2018, 6:44pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-log-entries-logs-to-logstash-server/155227 "2018-11-02T18:44:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [November 2, 2018, 6:44pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-log-entries-logs-to-logstash-server/155227/1 "2018-11-02T18:44:40Z")

</div>

I have setup filebeat on 3 servers. The filebeat is able to send logs to logstash server without issues from 2 servers.

From 3rd server, i can see file beat is running without any issues and logstash also running on logstash server.

Here is what i can see in the filebeat log

2018-11-02T14:17:29.575-0400 DEBUG [harvester] log/log.go:85 End of file reached: /opt/sp/src/log/app.2018-10-05.19.log; Backoff now.  
2018-11-02T14:17:58.938-0400 DEBUG [multiline] reader/multiline.go:155 Multiline event flushed because timeout reached.  
2018-11-02T14:17:59.302-0400 DEBUG [filter] pipeline/processor.go:157 fail to apply processor client{drop\_fields=prospector, @timestamp, beat, offset, host, source, @metadata, beat.name, beat.hostname, beat.timezone, beat.version, tags, @version, input}: key not found, key not found, key not found, key not found, key not found, key not found, key not found, key not found, key not found, key not found  
2018-11-02T14:29:57.866-0400 DEBUG [multiline] reader/multiline.go:126 Multiline event flushed because timeout reached.  
2018-11-02T14:29:58.736-0400 INFO log/harvester.go:253 File is inactive: /opt/sp/src/log/app.2018-10-06.0.log. Closing because close\_inactive of 5m0s reached.  
2018-11-02T14:29:58.737-0400 DEBUG [harvester] log/harvester.go:484 Stopping harvester for file: /opt/sp/src/log/app.2018-10-06.0.log  
2018-11-02T14:29:58.737-0400 DEBUG [harvester] log/harvester.go:494 Closing file: /opt/sp/src/log/app.2018-10-06.0.log  
2018-11-02T14:29:58.741-0400 DEBUG [harvester] log/harvester.go:364 Update state: /opt/sp/src/log/app.2018-10-06.0.log, offset: 0  
2018-11-02T14:29:59.141-0400 DEBUG [harvester] log/harvester.go:505 harvester cleanup finished for file: /opt/sp/src/log/app.2018-10-06.0.log  
2018-11-02T14:30:03.813-0400 DEBUG [multiline] reader/multiline.go:126 Multiline event flushed because timeout reached.  
2018-11-02T14:30:04.362-0400 INFO log/harvester.go:253 File is inactive: /opt/sp/src/log/app.2018-10-08.0.log. Closing because close\_inactive of 5m0s reached.  
2018-11-02T14:30:04.370-0400 DEBUG [harvester] log/harvester.go:484 Stopping harvester for file: /opt/sp/src/log/app.2018-10-08.0.log  
2018-11-02T14:30:04.370-0400 DEBUG [harvester] log/harvester.go:494 Closing file: /opt/sp/src/log/app.2018-10-08.0.log  
2018-11-02T14:30:04.370-0400 DEBUG [harvester] log/harvester.go:364 Update state: /opt/sp/src/log/app.2018-10-08.0.log, offset: 0  
2018-11-02T14:30:04.540-0400 DEBUG [harvester] log/harvester.go:505 harvester cleanup finished for file: /opt/sp/src/log/app.2018-10-08.0.log  
2018-11-02T14:30:06.262-0400 DEBUG [multiline] reader/multiline.go:126 Multiline event flushed because timeout reached.  
2018-11-02T14:30:06.277-0400 DEBUG [multiline] reader/multiline.go:126 Multiline event flushed because timeout reached.  
2018-11-02T14:30:06.285-0400 INFO log/harvester.go:253 File is inactive: /opt/sp/src/log/app.2018-10-15.0.log. Closing because close\_inactive of 5m0s reached.  
2018-11-02T14:30:06.286-0400 DEBUG [harvester] log/harvester.go:484 Stopping harvester for file: /opt/sp/src/log/app.2018-10-15.0.log  
2018-11-02T14:30:06.286-0400 DEBUG [harvester] log/harvester.go:494 Closing file: /opt/sp/src/log/app.2018-10-15.0.log  
2018-11-02T14:30:06.286-0400 DEBUG [harvester] log/harvester.go:364 Update state: /opt/sp/src/log/app.2018-10-15.0.log, offset: 0  
2018-11-02T14:30:06.308-0400 DEBUG [multiline] reader/multiline.go:126 Multiline event flushed because timeout reached.  
2018-11-02T14:30:06.308-0400 INFO log/harvester.go:253 File is inactive: /opt/sp/src/log/app.2018-10-10.0.log. Closing because close\_inactive of 5m0s reached.  
2018-11-02T14:30:06.308-0400 DEBUG [harvester] log/harvester.go:484 Stopping harvester for file: /opt/sp/src/log/app.2018-10-10.0.log  
2018-11-02T14:30:06.308-0400 DEBUG [harvester] log/harvester.go:494 Closing file: /opt/sp/src/log/app.2018-10-10.0.log  
2018-11-02T14:30:06.308-0400 DEBUG [harvester] log/harvester.go:364 Update state: /opt/sp/src/log/app.2018-10-10.0.log, offset: 0  
2018-11-02T14:30:06.309-0400 DEBUG [harvester] log/harvester.go:505 harvester cleanup finished for file: /opt/sp/src/log/app.2018-10-10.0.log  
2018-11-02T14:30:06.392-0400 DEBUG [multiline] reader/multiline.go:126 Multiline event flushed because timeout reached.  
2018-11-02T14:30:06.397-0400 INFO log/harvester.go:253 File is inactive: /opt/sp/src/log/app.log. Closing because close\_inactive of 5m0s reached.  
2018-11-02T14:30:06.398-0400 DEBUG [harvester] log/harvester.go:484 Stopping harvester for file: /opt/sp/src/log/app.log  
2018-11-02T14:30:06.398-0400 DEBUG [harvester] log/harvester.go:494 Closing file: /opt/sp/src/log/app.log  
2018-11-02T14:30:06.398-0400 DEBUG [harvester] log/harvester.go:364 Update state: /opt/sp/src/log/app.log, offset: 0  
2018-11-02T14:30:06.425-0400 DEBUG [multiline] reader/multiline.go:126 Multiline event flushed because timeout reached.  
2018-11-02T14:30:06.425-0400 INFO log/harvester.go:253 File is inactive: /opt/sp/src/log/app.2018-10-11.0.log. Closing because close\_inactive of 5m0s reached.  
2018-11-02T14:30:06.425-0400 DEBUG [harvester] log/harvester.go:484 Stopping harvester for file: /opt/sp/src/log/app.2018-10-11.0.log  
2018-11-02T14:30:06.425-0400 DEBUG [harvester] log/harvester.go:494 Closing file: /opt/sp/src/log/app.2018-10-11.0.log  
2018-11-02T14:30:06.425-0400 DEBUG [harvester] log/harvester.go:364 Update state: /opt/sp/src/log/app.2018-10-11.0.log, offset: 0  
2018-11-02T14:30:06.561-0400 INFO log/harvester.go:253 File is inactive: /opt/sp/src/log/app.2018-10-13.0.log. Closing because close\_inactive of 5m0s reached.  
2018-11-02T14:30:06.561-0400 DEBUG [harvester] log/harvester.go:484 Stopping harvester for file: /opt/sp/src/log/app.2018-10-13.0.log  
2018-11-02T14:30:06.561-0400 DEBUG [harvester] log/harvester.go:494 Closing file: /opt/sp/src/log/app.2018-10-13.0.log  
2018-11-02T14:30:06.561-0400 DEBUG [harvester] log/harvester.go:364 Update state: /opt/sp/src/log/app.2018-10-13.0.log, offset: 0  
2018-11-02T14:30:06.562-0400 DEBUG [harvester] log/harvester.go:505 harvester cleanup finished for file: /opt/sp/src/log/app.2018-10-15.0.log  
2018-11-02T14:30:06.776-0400 DEBUG [harvester] log/harvester.go:505 harvester cleanup finished for file: /opt/sp/src/log/app.2018-10-13.0.log

Please advice what might be the wrong in conf.

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [November 2, 2018, 8:29pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-log-entries-logs-to-logstash-server/155227/2 "2018-11-02T20:29:09Z")

</div>

Can you run `filebeat export config` and share the exported config?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2018, 8:29pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-log-entries-logs-to-logstash-server/155227/3 "2018-11-30T20:29:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
