# Filebeat panics with multiple filestream inputs

**URL:** <https://discuss.elastic.co/t/filebeat-panics-with-multiple-filestream-inputs/289152>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 15, 2021, 3:57am UTC](https://discuss.elastic.co/t/filebeat-panics-with-multiple-filestream-inputs/289152 "2021-11-15T03:57:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gwvandesteeg](https://avatars.discourse-cdn.com/v4/letter/g/839c29/32.png) [@gwvandesteeg](https://discuss.elastic.co/u/gwvandesteeg)\
**Post date:** [November 15, 2021, 3:57am UTC](https://discuss.elastic.co/t/filebeat-panics-with-multiple-filestream-inputs/289152/1 "2021-11-15T03:57:38Z")

</div>

I'm seeing a bunch of errors when configuring filebeat with multiple `filestream` input types.

The configuration is simple enough, filebeat (7.15.1) running on Ubuntu 18.04 LTS forwards everything to logstash using beats.  
There are a few inputs defined, below is an example. With the `exclude_lines` entry commented out, filebeat starts and runs. Uncomment the exclude\_lines directive and it crashes with a panic at

```auto
panic: unlock on unlocked mutex

goroutine 106 [running]:
github.com/elastic/go-concert/unison.Mutex.Unlock(0xc000aaa7e0)
        /go/pkg/mod/github.com/elastic/go-concert@v0.2.0/unison/mutex.go:132 +0x65
github.com/elastic/beats/v7/filebeat/input/filestream/internal/input-logfile.releaseResource(0xc000c760b0)
        /go/src/github.com/elastic/beats/filebeat/input/filestream/internal/input-logfile/harvester.go:296 +0x31
github.com/elastic/beats/v7/filebeat/input/filestream/internal/input-logfile.(*defaultHarvesterGroup).Continue.func1(0x555e16f4a7d8, 0xc000747240, 0x0, 0x0)
        /go/src/github.com/elastic/beats/filebeat/input/filestream/internal/input-logfile/harvester.go:246 +0x37d
github.com/elastic/go-concert/unison.(*TaskGroup).Go.func1(0xc00042a3c8, 0xc0000ab310)
        /go/pkg/mod/github.com/elastic/go-concert@v0.2.0/unison/taskgroup.go:163 +0xb1
created by github.com/elastic/go-concert/unison.(*TaskGroup).Go
        /go/pkg/mod/github.com/elastic/go-concert@v0.2.0/unison/taskgroup.go:159 +0xdc

```

```auto
filebeat.inputs:
  # Template: fail2ban
  - type: filestream
    paths:
      - "/var/log/fail2ban.log*"
    prospector.scanner.exclude_files:
      - '\.gz$'
    rotation.external.strategy.copytruncate:
      suffix_regex: '\.\d+$'
    fields:
      application: fail2ban
# # Generic to all nodes
  # Template: ufw
  - type: filestream
    paths:
      - "/var/log/ufw.log*"
    prospector.scanner.exclude_files:
      - '\.gz$'
    rotation.external.strategy.copytruncate:
      suffix_regex: '\.\d+$'
    fields:
      application: ufw
  # Template: unattended-upgrades
  - type: filestream
    paths:
      - "/var/log/unattended-upgrades/unattended-upgrades-dpkg.log*"
    prospector.scanner.exclude_files:
      - '\.gz$'
    rotation.external.strategy.copytruncate:
      suffix_regex: '\.\d+$'
    # exclude_lines:
    # - '^\s*$'
    parsers:
      - multiline:
          type: pattern
          pattern: '^Log started:\s+\d{4}-\d{2}-\d{2}\s+\d{2}:\d{2}:\d{2}$'
          negate: true
          match: after
    fields:
      application: "unattended-upgrades"
      part: "dpkg-output"

```

Another simple configuration such as:

```auto
filebeat.inputs:
  # Template: fail2ban
  - type: filestream
    paths:
      - "/var/log/fail2ban.log*"
    prospector.scanner.exclude_files:
      - '\.gz$'
    rotation.external.strategy.copytruncate:
      suffix_regex: '\.\d+$'
    fields:
      application: fail2ban
# # Generic to all nodes
  # Template: ufw
  - type: filestream
    paths:
      - "/var/log/ufw.log*"
    prospector.scanner.exclude_files:
      - '\.gz$'
    rotation.external.strategy.copytruncate:
      suffix_regex: '\.\d+$'
    fields:
      application: ufw
  # Template: ubuntu-advantage      
  - type: filestream
    paths:
      - "/var/log/ubuntu-advantage.log*"
    prospector.scanner.exclude_files:
      - '\.gz$'
    rotation.external.strategy.copytruncate:
      suffix_regex: '\.\d+$'
    fields:
      application: ubuntu-advantage      

```

also crashes with the same panic, there's nothing complicated present there in the configurations.

Any thoughts or solutions?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2021, 5:57am UTC](https://discuss.elastic.co/t/filebeat-panics-with-multiple-filestream-inputs/289152/2 "2021-12-13T05:57:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
