# Filebeat on windows not reading log file

**URL:** <https://discuss.elastic.co/t/filebeat-on-windows-not-reading-log-file/204663>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 22, 2019, 2:13pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-not-reading-log-file/204663 "2019-10-22T14:13:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![computer\_engineer](https://avatars.discourse-cdn.com/v4/letter/c/df788c/32.png) [@computer\_engineer](https://discuss.elastic.co/u/computer_engineer)\
**Post date:** [October 22, 2019, 2:13pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-not-reading-log-file/204663/1 "2019-10-22T14:13:33Z")

</div>

I am attempting to have filebeat read json packets from log files in a specific directory and send to elasticsearch directly, without using logstash. I got the filebeat service to start up but keeping the following message displayed in the powershell console:

```
INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s        
 {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":359},"total": 
 {"ticks":718,"value":718},"user":{"ticks":359}},"handles": 
 {"open":238},"info":{"ephemeral_id":"da200c4c-dff4-4ff5-bdf2- 
 15048ef0d495","uptime":{"ms":150221}},"memstats":...

```

Can anyone help with this? the ELK stack is running in docker but does seem to be working when using the [http://xxx.xxx.xxx.x:5601/](http://xxx.xxx.xxx.x:5601/) browser lookup.

The filebeat.yml config seems to be correct too:

```
filebeat.inputs:
# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.
- type: log
# Change to true to enable this input configuration.
enabled: true
# Paths that should be crawled and fetched. Glob based paths.
paths:
 - C:\var\log\*
 #- c:\programdata\elasticsearch\logs\*

```

....

and the output config:

```
 #============================= Filebeat modules===============
  filebeat.config.modules:
 # Glob pattern for configuration loading
 path: ${path.config}/modules.d/*.yml

 # Set to true to enable config reloading
  reload.enabled: false

 # Period on which files under path should be checked for changes
 #reload.period: 10s

#==================== Elasticsearch template setting #

setup.template.settings:
index.number_of_shards: 1
#index.codec: best_compression
#_source.enabled: false

output.elasticsearch:
# Array of hosts to connect to.
 hosts: ["192.xxx.xxx.x:9200"]
```

---

<div class="post-metadata">

**Author:** ![pmercado](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@pmercado](https://discuss.elastic.co/u/pmercado)\
**Post date:** [October 25, 2019, 11:38am UTC](https://discuss.elastic.co/t/filebeat-on-windows-not-reading-log-file/204663/2 "2019-10-25T11:38:31Z")

</div>

Can you add the `-d "*"` flag to filebeat and check if there is some info during first 30 seconds of execution stating which files are being harvested?

Sounds like it is finding no files at `c:\var\log\*`.  
Could this be a permission issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2019, 11:38am UTC](https://discuss.elastic.co/t/filebeat-on-windows-not-reading-log-file/204663/3 "2019-11-22T11:38:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
