# Filebeat not picking up log files

**URL:** <https://discuss.elastic.co/t/filebeat-not-picking-up-log-files/293910>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 10, 2022, 3:56pm UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-log-files/293910 "2022-01-10T15:56:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aamir\_mustafa](https://avatars.discourse-cdn.com/v4/letter/a/f14d63/32.png) [@aamir\_mustafa](https://discuss.elastic.co/u/aamir_mustafa)\
**Post date:** [January 10, 2022, 3:56pm UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-log-files/293910/1 "2022-01-10T15:56:57Z")

</div>

Hello Team,  
I'm using Filebeat 7.10.2 to ship logs directly to Elasticsearch. But I'm facing an issue while giving input to filebeat. Filebeat only picks up one log file even when I'm specifying to read all files from input directory in filebeat.yml.  
Here's my filebeat.yml config:

```auto
filebeat.inputs:

- type: log
  enabled: true
  paths:
    - /usr/local/logdirectory/pkt_20*.log

output.elasticsearch:
  hosts: "localhost:9200"
  username: admin
  password: admin

```

The logdirectory folder contains multiple files named as **pkt\_20220101.log** , **pkt\_20220102.log** and so on. Filebeat only picks up the **pkt\_20220110.log** file and ignores the rest. Could anyone from the team help me out with this issue?

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [January 10, 2022, 4:21pm UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-log-files/293910/2 "2022-01-10T16:21:20Z")

</div>

Hi!

`paths` setting is a glob based setting as mentioned at [Log input | Filebeat Reference [7.16] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#input-paths). Maybe the pattern you are setting is not correct. Could you check the debug logs of Filebeat for any indicators?

C.

---

<div class="post-metadata">

**Author:** ![aamir\_mustafa](https://avatars.discourse-cdn.com/v4/letter/a/f14d63/32.png) [@aamir\_mustafa](https://discuss.elastic.co/u/aamir_mustafa)\
**Post date:** [January 11, 2022, 4:55am UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-log-files/293910/3 "2022-01-11T04:55:37Z")

</div>

Hello ChrsMark,

I've checked the debug logs of Filebeat and can see that the harvester starts only for files with pattern like **pkt\_2022011x.log** and not the pattern that I've specified in `paths`. I've tried several different glob patterns but none of them seem to work.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [January 11, 2022, 9:30am UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-log-files/293910/4 "2022-01-11T09:30:49Z")

</div>

Hi!

This is weird. Not sure what could be the problem here 🤔 .  
Could you try with something like `/usr/local/logdirectory/*.log`? If so what happens?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2022, 11:31am UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-log-files/293910/5 "2022-02-08T11:31:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
