# Filebeat Need Restart To send Logs

**URL:** <https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 12, 2016, 8:55am UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266 "2016-09-12T08:55:05Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Me\_Cloud](https://avatars.discourse-cdn.com/v4/letter/m/f4b2a3/32.png) [@Me\_Cloud](https://discuss.elastic.co/u/Me_Cloud)\
**Post date:** [September 12, 2016, 8:55am UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/1 "2016-09-12T08:55:05Z")

</div>

Hallo all,  
i was first using filebeat, i have a problem with my filebeat.  
i cannot send logs to logstash dynamically?  
because in my case, my filebeat not pushing the logs to logstash dynamically.  
so, i have to manually restart filebeat each and everytime so as to send the  
logs from filebeat to logstash.  
So please let me know about this.  
Please help me to solve this.  
Thankyou

and this is my logstash conf

/etc/logstash/conf.d/input.conf

```
input {
beats {
port => 5044
ssl => true
ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
}
}

```

/etc/logstash/conf.d/output.conf

```
output {
elasticsearch {
hosts => ["localhost:9200"]
sniffing => true
manage_template => false
index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
document_type => "%{[@metadata][type]}"
}
}

```

/etc/logstash/conf.d/filter.conf

```
filter {
if [type] == "syslog" {
grok {
match => { "message" => "%{SYSLOGLINE}" }
}
date {
match => ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
}
}
}

```

my file beat config

```
filebeat:
# List of prospectors to fetch data.
prospectors:
# Each - is a prospector. Below are the prospector specific configurations
-
  # Paths that should be crawled and fetched. Glob based paths.
  # To fetch all ".log" files from a specific level of subdirectories
  # /var/log/*/*.log can be used.
  # For each file found under this path, a harvester is started.
  # Make sure not file is defined twice as this can lead to unexpected beha$
  paths:
    - /var/log/*.log
    - /var/log/httpd/*_log

    #- c:\programdata\elasticsearch\logs\*

tls:
  # List of root certificates for HTTPS server verifications
  certificate_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

```

why i know my filebeat didn't send log dynamic because in my access\_log there is a log and when i see in my kibana there is nothing, but after i restart my filebeat the log send and i can see it in my kibana.

this is my kibana [http://104.197.159.180:5601/](http://104.197.159.180:5601/)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [September 12, 2016, 9:18am UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/2 "2016-09-12T09:18:46Z")

</div>

is the formatting of you `filebeat.yml` file correct? It seem to miss any output configuration and even the rest looks pretty off.

---

<div class="post-metadata">

**Author:** ![Me\_Cloud](https://avatars.discourse-cdn.com/v4/letter/m/f4b2a3/32.png) [@Me\_Cloud](https://discuss.elastic.co/u/Me_Cloud)\
**Post date:** [September 12, 2016, 9:31am UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/3 "2016-09-12T09:31:45Z")

</div>

that's not all @steffens

this my output

```
### Logstash as output
logstash:
# The Logstash hosts
hosts: ["104.197.159.180:5044"]

# Number of workers per Logstash host.
#worker: 1

# The maximum number of events to bulk into a single batch window. The
# default is 2048.
bulk_max_size: 2048

```

that's all that i change, and the other still same

and  
input\_type: log  
document\_type: syslog

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 12, 2016, 2:09pm UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/4 "2016-09-12T14:09:57Z")

</div>

Can you share your full config file as a gist so we can confirm that the indentation is correct? What do you see in the log files?

---

<div class="post-metadata">

**Author:** ![Me\_Cloud](https://avatars.discourse-cdn.com/v4/letter/m/f4b2a3/32.png) [@Me\_Cloud](https://discuss.elastic.co/u/Me_Cloud)\
**Post date:** [September 12, 2016, 4:45pm UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/5 "2016-09-12T16:45:29Z")

</div>

Thank you guys, i was done fix my filebeat problem.  
i use crontab to make schedule to restart my filebeat.

Cheers!

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 13, 2016, 5:44am UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/6 "2016-09-13T05:44:39Z")

</div>

I still don't understand why you need to restart filebeat.

---

<div class="post-metadata">

**Author:** ![Me\_Cloud](https://avatars.discourse-cdn.com/v4/letter/m/f4b2a3/32.png) [@Me\_Cloud](https://discuss.elastic.co/u/Me_Cloud)\
**Post date:** [September 14, 2016, 2:59am UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/7 "2016-09-14T02:59:40Z")

</div>

because i can't send log from client server to logstash in elk server dynamic so i need to restart filebeat.

i use kibana to web interface, i try to open apache in client server and in /var/log/httpd/access\_log there is a log but in my kibana didn't show anything. but after i restart my filebeat kibana show the log.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 14, 2016, 8:33am UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/8 "2016-09-14T08:33:05Z")

</div>

Filebeat is designed to always send the most recent lines to elasticsearch / logstash.

If you restart filebeat, does it send all the new lines once and then stops working until you restart it next time?

---

<div class="post-metadata">

**Author:** ![Me\_Cloud](https://avatars.discourse-cdn.com/v4/letter/m/f4b2a3/32.png) [@Me\_Cloud](https://discuss.elastic.co/u/Me_Cloud)\
**Post date:** [September 14, 2016, 9:45am UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/9 "2016-09-14T09:45:30Z")

</div>

hmm yes, so what should i do bro?  
because i am newbie about this ☹

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 15, 2016, 6:07am UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/10 "2016-09-15T06:07:34Z")

</div>

Best is to check the logs of filebeat and logstash for any additional info on why it is hanging. Can also share details on this question above: "If you restart filebeat, does it send all the new lines once and then stops working until you restart it next time?"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2016, 8:55am UTC](https://discuss.elastic.co/t/filebeat-need-restart-to-send-logs/60266/11 "2016-10-03T08:55:10Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
