# Filebeat Log rotation support

**URL:** <https://discuss.elastic.co/t/filebeat-log-rotation-support/183182>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 28, 2019, 8:02pm UTC](https://discuss.elastic.co/t/filebeat-log-rotation-support/183182 "2019-05-28T20:02:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankitachow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitachow/32/46246_2.png) [@ankitachow](https://discuss.elastic.co/u/ankitachow)\
**Post date:** [May 28, 2019, 8:02pm UTC](https://discuss.elastic.co/t/filebeat-log-rotation-support/183182/1 "2019-05-28T20:02:19Z")

</div>

Hello,

I have an application which does log rotation. The files are written in EventLogFile.0 which gets rolled over to EventLogFile.1, once new logs starts getting written to EventLogFile.0. The rollover happens till 4 files as shown below  
EventLogFile.0 -\> EventLogFile.1  
EventLogFile.1 -\> EventLogFile.2  
EventLogFile.2 -\> EventLogFile.3

The most recent logs will be in EventLogFile.0 whereas the most old logs will be in EventLogFile.3.  
In my solution, I pick up files using Filebeat and then pass it onto Logstash for parsing and then ingest to Elasticsearch.  
How does filebeat handle log rotation? Any specific setting needs to go into Filebeat/logstash?

Thanks  
Ankita

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2019, 8:02pm UTC](https://discuss.elastic.co/t/filebeat-log-rotation-support/183182/2 "2019-06-25T20:02:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
