# Filebeat Not harvesting, file didn't change - do not use modification time

**URL:** <https://discuss.elastic.co/t/filebeat-not-harvesting-file-didnt-change-do-not-use-modification-time/49834>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 11, 2016, 11:26pm UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-file-didnt-change-do-not-use-modification-time/49834 "2016-05-11T23:26:39Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 26, 2016, 7:18am UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-file-didnt-change-do-not-use-modification-time/49834/7 "2016-05-26T07:18:53Z")

</div>

@logstash_oz Sorry for the late reply. For the timestamp: With this PR ([https://github.com/elastic/beats/pull/1703](https://github.com/elastic/beats/pull/1703)) I introduced a field `last_read` which stores the timestamp when the file was last read (not last modified). Currently this is not taken into account when starting a harvester, but it definitively gives the opportunity to do so. I'm thinking of doing some comparison of last\_read and modTime in the future.

About your LS questions: If you have 3 workers the events should still be sent only once. Filebeat has the at least once principle so it can happen in some cases, that a line is sent more then once. Is it just an edge case that you see events multiple times (for example when a node goes down) or happens that very often?

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-not-harvesting-file-didnt-change-do-not-use-modification-time/49834)._
