# Filebeat prospectors autoreload not working

**URL:** https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815
**Category:** Beats
**Tags:** filebeat
**Created:** [July 26, 2018, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815 "2018-07-26T15:58:27Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![Eshwar\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eshwar_kumar/32/26079_2.png) [@Eshwar\_Kumar](https://discuss.elastic.co/u/Eshwar_Kumar)
#### Post date: [July 26, 2018, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815/1 "2018-07-26T15:58:27Z")

</div>

Hello All,

Is there any way for auto reloading filebeat config after changing prospector fields? Below is my sample config:

```
filebeat.prospectors:
- type: log
  enabled: true
  paths:
    #- /var/log/*.log
    - C:\ELK\filebeat-6.1.1-windows-x86_64\*.log

  fields:
    level: error
 
filebeat.config:
  prospectors:
    enabled: true
    path: C:\ELK\filebeat-6.1.1-windows-x86_64\*.yml
    reload.enabled: true
    reload.period: 10s
#----------------------------- Logstash output --------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["localhost:5044"]

```

I have a requirement of changing field value. If I change prospector field value, filebeat not effecting those changes until restart.

Please help me if we have any alternative to make this work.

-Thanks

---

<div class="post-metadata">

### Author: ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)
#### Post date: [July 26, 2018, 8:44pm UTC](https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815/2 "2018-07-26T20:44:49Z")

</div>

Hello @Eshwar_Kumar, I think there is a small problem with your configuration if you look at the [documentation](https://www.elastic.co/guide/en/beats/filebeat/6.3/_live_reloading.html).

I would remove the following:

```auto
filebeat.config:
  prospectors:
    enabled: true
    path: C:\ELK\filebeat-6.1.1-windows-x86_64\*.yml
    reload.enabled: true
    reload.period: 10s

```

and replace it with

```auto
filebeat.config.inputs:
  enabled: true
  path: C:\ELK\filebeat-6.1.1-windows-x86_64\*.yml
  reload.enabled: true
  reload.period: 10s

```

After you just create a new file in the reloading path, that file must have a `yml` extension. In the file you just define the prospector.

```auto
- type: log
  enabled: true
  paths:
    - C:\ELK\filebeat-6.1.1-windows-x86_64\*.log

  fields:
    level: error

```

See the [load external configuration](https://www.elastic.co/guide/en/beats/filebeat/6.3/filebeat-configuration-reloading.html) documentation for more details.

---

<div class="post-metadata">

### Author: ![Eshwar\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eshwar_kumar/32/26079_2.png) [@Eshwar\_Kumar](https://discuss.elastic.co/u/Eshwar_Kumar)
#### Post date: [July 27, 2018, 4:54am UTC](https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815/3 "2018-07-27T04:54:11Z")

</div>

Thanks. Correct me if i am wrong. You are saying to create a new yml file which will be relaoded automatically without filebeat restart. But I am looking for a feature where if I change a field value in existing yml file ( changing field "level" value as "warn" in my scenario) that field should get updated for new logs without filebeat restart. I am wondering if we have this feature in filebeat.

- Thank you

---

<div class="post-metadata">

### Author: ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)
#### Post date: [July 27, 2018, 12:45pm UTC](https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815/4 "2018-07-27T12:45:30Z")

</div>

@Eshwar_Kumar not everything in the Filebeat configuration support live reload, but **prospector** related configuration supports live reloading when you define them in externals file.

In the case you are describing updating the field value from error to warn will trigger a reload.

---

<div class="post-metadata">

### Author: ![Eshwar\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eshwar_kumar/32/26079_2.png) [@Eshwar\_Kumar](https://discuss.elastic.co/u/Eshwar_Kumar)
#### Post date: [July 27, 2018, 4:30pm UTC](https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815/5 "2018-07-27T16:30:37Z")

</div>

I am newbie for this. I seriously not understood filebeat configuration and external configuration. As per my knowledge i am using filebeat.yml and i am running as "filebeat -e -c "filebeat.yml" -d "publish"". In this filebeat.yml i am mentioning prospectors which contains path and fileds to be added. Should i add same prospectors with new field values in external.yml? If not please give me sample filebeat.yml and external.yml files what to be tested. My requirement is just if i change a field value of a prospector, without reload that field value should get updated for my new logs. Please help on this.

- Thanks

---

<div class="post-metadata">

### Author: ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)
#### Post date: [July 27, 2018, 5:05pm UTC](https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815/6 "2018-07-27T17:05:09Z")

</div>

@Eshwar_Kumar I gave you the filebeat.yml configuration and the configuration for the external file in the [comment](https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815/2?u=pierhugues) above, Like I've said you will remove the prospector definition from the filebeat.yml file and just define them in the external file. When Filebeat is running and you change the external files Filebeat will reload the configuration and use the new prospector definition.

The modification will not change how you start Filebeat you will still use the same command and arguments.

---

<div class="post-metadata">

### Author: ![Eshwar\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eshwar_kumar/32/26079_2.png) [@Eshwar\_Kumar](https://discuss.elastic.co/u/Eshwar_Kumar)
#### Post date: [July 28, 2018, 8:35am UTC](https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815/7 "2018-07-28T08:35:05Z")

</div>

Seems I am missing something.

filebeat.yml:

```
    filebeat.config.inputs:
      enabled: true
      path: C:\ELK\filebeat-6.1.1-windows-x86_64\*.yml
      reload.enabled: true
      reload.period: 10s

```

`1.yml` in `C:\ELK\filebeat-6.1.1-windows-x86_64\` directory:

```
- type: log
  enabled: true
  paths:
    - C:\ELK\filebeat-6.1.1-windows-x86_64\1.log

  fields:
    level: error

```

Started filebeat with `filebeat -e -c filebeat.yml -d "publish"` . Logs flowing good with field name `level` and value `error`.

Now created`2.yml` in same directory `C:\ELK\filebeat-6.1.1-windows-x86_64\` as:  
`2.yml:`

```
- type: log
  enabled: true
  paths:
    - C:\ELK\filebeat-6.1.1-windows-x86_64\2.log

  fields:
    level: warn

```

2.log file lines were not flowing in the filebeat. I have changed field value of `level` in 1.yml from `error` to `debug`. Now new logs were still getting value for field `level` as `error` not `debug`.

I followed exactly same as per documents specified and the confs you commented.

I tried filebeat 6.1 and 6.3 as well.

Please suggest me where i am doing mistake.

Thanks.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 25, 2018, 8:35am UTC](https://discuss.elastic.co/t/filebeat-prospectors-autoreload-not-working/141815/8 "2018-08-25T08:35:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
