# FileBeat log rollover

**URL:** <https://discuss.elastic.co/t/filebeat-log-rollover/173315>\
**Category:** Beats\
**Created:** [March 21, 2019, 1:26pm UTC](https://discuss.elastic.co/t/filebeat-log-rollover/173315 "2019-03-21T13:26:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kathir\_J](https://avatars.discourse-cdn.com/v4/letter/k/e47774/32.png) [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Post date:** [March 21, 2019, 1:26pm UTC](https://discuss.elastic.co/t/filebeat-log-rollover/173315/1 "2019-03-21T13:26:40Z")

</div>

We are using filebeat to get log. I recently faced an issue which is annoying me.

I have the filebeat configuration as log\*.log because every time when log size reaches 10mb my application creates new log and renames the old log to log1.log.

But now, due to filebeat, my application is unable to create new log as it is being opened by filebeat and log size goes upto GBs.

How should I get rid of the problem?

Basically, filebeat is not allowing Apache log rotation to happen.

---

<div class="post-metadata">

**Author:** ![Kathir\_J](https://avatars.discourse-cdn.com/v4/letter/k/e47774/32.png) [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Post date:** [March 27, 2019, 6:22am UTC](https://discuss.elastic.co/t/filebeat-log-rollover/173315/2 "2019-03-27T06:22:23Z")

</div>

Any reply would be highly appreciated

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 27, 2019, 3:20pm UTC](https://discuss.elastic.co/t/filebeat-log-rollover/173315/3 "2019-03-27T15:20:03Z")

</div>

Could you please share your configuration formatted using `</>`?

---

<div class="post-metadata">

**Author:** ![Kathir\_J](https://avatars.discourse-cdn.com/v4/letter/k/e47774/32.png) [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Post date:** [March 29, 2019, 9:38pm UTC](https://discuss.elastic.co/t/filebeat-log-rollover/173315/4 "2019-03-29T21:38:53Z")

</div>

It's pretty simple as below.  
Whenever log file reaches 10MB, _app.log_ gets rotated to _app1.log_ and so on by our log rotation policy in application.

But since we have filebeat which monitors app.log all the time, it never allows log rotation to happen and instead app.log keeps growing in GBs.

And i do see an option for log rotation through filebeat but what I want is, as our application is already doing log rotation, we don't want filebeat to disturb log rotation.

```
filebeat.inputs:
- type: log
  paths:
    - C:\\ProgramData\\location\\center\\logs\\app*.log* 
  close_renamed: true
fields:
 log-type: "center"
 customer: "abc"
 app-type: "center"
output.logstash:
  hosts: ["<ip>:5044"]
```

---

<div class="post-metadata">

**Author:** ![Kathir\_J](https://avatars.discourse-cdn.com/v4/letter/k/e47774/32.png) [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Post date:** [April 9, 2019, 1:50am UTC](https://discuss.elastic.co/t/filebeat-log-rollover/173315/5 "2019-04-09T01:50:31Z")

</div>

Any reply?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2019, 3:50am UTC](https://discuss.elastic.co/t/filebeat-log-rollover/173315/6 "2019-05-07T03:50:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
