# Filebeat is reading my logs, but logs with date time on name, stop incremet

**URL:** <https://discuss.elastic.co/t/filebeat-is-reading-my-logs-but-logs-with-date-time-on-name-stop-incremet/37589>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 18, 2015, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-is-reading-my-logs-but-logs-with-date-time-on-name-stop-incremet/37589 "2015-12-18T16:53:18Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![adsqueiroz](https://avatars.discourse-cdn.com/v4/letter/a/6de8d8/32.png) [@adsqueiroz](https://discuss.elastic.co/u/adsqueiroz)\
**Post date:** [December 18, 2015, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-is-reading-my-logs-but-logs-with-date-time-on-name-stop-incremet/37589/1 "2015-12-18T16:53:19Z")

</div>

Hello folks!

I'm new on FileBeat, Logstash and Elastiscsearch. I'm trying to implement in my work, but I'm having problem with FileBeat.

When I start the service from FileBeat, my logs with date time on name, stop increment.

For example, logs like that:

App20151218.Log

I did searches on the internet, but I couldn't solve this issue.

Follow my FileBeat config:

filebeat:  
prospectors:  
-  
paths:  
- /var/log/pfswf01.log  
- /var/log/pfswf02.log  
- /var/log/pfswf03.log  
- /var/log/pfswf04.log  
document\_type: firewall  
-  
paths:  
- /var/log/syslog-ng.log  
document\_type: syslog  
-  
paths:  
- "/mnt/helicon/Notif/_.Log"  
document\_type: urlnotif  
-  
paths:  
- "/mnt/florina\_LogIIS/logs/LogFiles/W3SVC1/_.log"  
- "/mnt/alpha\_LogIIS/logs/LogFiles/W3SVC1/_.log"  
- "/mnt/daribow\_LogIIS/logs/LogFiles/W3SVC1/_.log"  
- "/mnt/livia\_LogIIS/logs/LogFiles/W3SVC1/_.log"  
- "/mnt/cygni\_LogIIS/logs/LogFiles/W3SVC1/_.log"  
- "/mnt/euterpe\_LogIIS/logs/LogFiles/W3SVC1/_.log"  
- "/mnt/korell\_LogIIS/logs/LogFiles/W3SVC1/_.log"  
- "/mnt/nexon\_LogIIS/logs/LogFiles/W3SVC1/_.log"  
document\_type: iis  
-  
paths:  
- "/mnt/livia/_.Log"  
- "/mnt/rhea/_.Log"  
- "/mnt/cygni/_.Log"  
- "/mnt/sarip/_.Log"  
- "/mnt/euterpe/_.Log"  
- "/mnt/hesperos/_.Log"  
- "/mnt/daribow/_.Log"  
- "/mnt/florina/_.Log"  
- "/mnt/bonde/_.Log"  
- "/mnt/alpha/_.Log"  
- "/mnt/korell/_.Log"  
- "/mnt/vega/_.Log"  
- "/mnt/cinna/_.Log"  
- "/mnt/helicon/_.Log"  
- "/mnt/fomalhaut/_.Log"  
- "/mnt/gamma/_.Log"  
- "/mnt/ifni/_.Log"  
- "/mnt/nexon/\*.Log"  
document\_type: operadoras

```
   spool_size: 1024
   idle_timeout: 5s
   input_type: log
   fields:
   level: debug
   review: 1
   tail_files: false   

```

output:

logstash:

```
  hosts: ["10.1.1.112:5044"]
  index: filebeat

```

file:

path: "/tmp/filebeaat"

filename: filebeat

rotate\_every\_kb: 10000

number\_of\_files: 7

logging:

to\_syslog: false

to\_files: true

files:

```
path: "/var/log"

name: filebeat.log

rotateeverybytes: 10485760 # = 10MB

keepfiles: 7

selectors: ["*"]
level: error

```

I appreciate the attemption.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 18, 2015, 5:01pm UTC](https://discuss.elastic.co/t/filebeat-is-reading-my-logs-but-logs-with-date-time-on-name-stop-incremet/37589/2 "2015-12-18T17:01:09Z")

</div>

In which directory if the file App20151218.Log located?

Are you working with network shares? E.g. file shared from windows system?

---

<div class="post-metadata">

**Author:** ![adsqueiroz](https://avatars.discourse-cdn.com/v4/letter/a/6de8d8/32.png) [@adsqueiroz](https://discuss.elastic.co/u/adsqueiroz)\
**Post date:** [December 18, 2015, 6:04pm UTC](https://discuss.elastic.co/t/filebeat-is-reading-my-logs-but-logs-with-date-time-on-name-stop-incremet/37589/3 "2015-12-18T18:04:59Z")

</div>

Hello Steffens,

this file is located in my shared folders on Windows Servers, for example:

/mnt/nexon/App20151218.Log

Thanks for your reply.

---

<div class="post-metadata">

**Author:** ![adsqueiroz](https://avatars.discourse-cdn.com/v4/letter/a/6de8d8/32.png) [@adsqueiroz](https://discuss.elastic.co/u/adsqueiroz)\
**Post date:** [December 21, 2015, 6:58pm UTC](https://discuss.elastic.co/t/filebeat-is-reading-my-logs-but-logs-with-date-time-on-name-stop-incremet/37589/4 "2015-12-21T18:58:36Z")

</div>

Hi steffens,

is it possible use something like that on FileBeat configuration?

/mnt/nexon/App{YYYYMMDD}.Log

I tried, but unsuccessfully.

I continue searching, but I did not find nothing.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 21, 2015, 7:38pm UTC](https://discuss.elastic.co/t/filebeat-is-reading-my-logs-but-logs-with-date-time-on-name-stop-incremet/37589/5 "2015-12-21T19:38:52Z")

</div>

> [@adsqueiroz](#):
>
> /mnt/nexon/App{YYYYMMDD}.Log

No, this pattern will not work. Just using '/mnt/nexon/App\*.Log' or '/mnt/nexon/\*.Log' should do the trick.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 21, 2015, 7:54pm UTC](https://discuss.elastic.co/t/filebeat-is-reading-my-logs-but-logs-with-date-time-on-name-stop-incremet/37589/6 "2015-12-21T19:54:05Z")

</div>

Windows Server network share might be a problem. If possible try to have filebeat running on server directly.

1. depending on log rotation strategy, rotation might fail due to open files 'blocking' renamings on windows. Consider setting [force\_close\_files](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration-details.html#_force_close_files) to true. This option was introduced for windows. But network shares might complicate matters.

2. When using network shares between different kinds of systems, it might break file identification. e.g. samba might randomly generate file ids if systems are incompatible.

You can try inode being stable on linux using 'ls -i \<filename\>'. multiple times. If inode changes, check for alternative mount options.

All in all I would not try to use any log forwarders via windows/network shares if possible.

---

<div class="post-metadata">

**Author:** ![adsqueiroz](https://avatars.discourse-cdn.com/v4/letter/a/6de8d8/32.png) [@adsqueiroz](https://discuss.elastic.co/u/adsqueiroz)\
**Post date:** [December 22, 2015, 12:16pm UTC](https://discuss.elastic.co/t/filebeat-is-reading-my-logs-but-logs-with-date-time-on-name-stop-incremet/37589/7 "2015-12-22T12:16:18Z")

</div>

Hi Steffens,

thanks a lot for your reply.

I will check with my team, it can be possible install FileBeat directly on ours Windows Servers.

Thanks for the tips.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:57pm UTC](https://discuss.elastic.co/t/filebeat-is-reading-my-logs-but-logs-with-date-time-on-name-stop-incremet/37589/8 "2017-07-05T21:57:21Z")

</div>


