# Filebeat read a log repeatly

**URL:** <https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 20, 2019, 7:06am UTC](https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609 "2019-06-20T07:06:50Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![SimonK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simonk/32/45310_2.png) [@SimonK](https://discuss.elastic.co/u/SimonK)\
**Post date:** [June 20, 2019, 7:06am UTC](https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609/1 "2019-06-20T07:06:50Z")

</div>

Hi,

```
I need to collect the automatic test log to analysis.
The log content like this: 
Total Pass Fail
  5 2 0
The automation program will update the number of case.
It does't add a new line or change the size of the file.
Now i'd like filebeat to read the log and send the event periodically.
However, the filebeat just record the offset of last line in the log file. How can i configure the filebeat to read the whole file no matter the log if add a new line?
Thanks.
```

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [June 20, 2019, 9:12am UTC](https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609/2 "2019-06-20T09:12:40Z")

</div>

Hi @SimonK 🙂

I'm afraid that it's not possible to do what you are asking with Filebeat

Regards

---

<div class="post-metadata">

**Author:** ![SimonK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simonk/32/45310_2.png) [@SimonK](https://discuss.elastic.co/u/SimonK)\
**Post date:** [June 21, 2019, 3:02am UTC](https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609/3 "2019-06-21T03:02:41Z")

</div>

Thanks @Mario_Castro  
Do you know if other plugins can fulfill this requirement?

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [June 24, 2019, 8:40am UTC](https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609/4 "2019-06-24T08:40:28Z")

</div>

You can try with Logstash, I'm not sure if it has such an option

---

<div class="post-metadata">

**Author:** ![harshbajaj16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshbajaj16/32/44970_2.png) [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Post date:** [June 24, 2019, 9:21am UTC](https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609/5 "2019-06-24T09:21:41Z")

</div>

Hi @SimonK,

You can do the same by creating a script which delete you filebeat offset file and read again your file with new value.

For this you need to create a script and add cron job for the same.

This is not a solution for filebeat. However, you can achieve your requirement with this if you want.

Regards,  
Harsh Bajaj

---

<div class="post-metadata">

**Author:** ![SimonK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simonk/32/45310_2.png) [@SimonK](https://discuss.elastic.co/u/SimonK)\
**Post date:** [June 25, 2019, 3:03am UTC](https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609/6 "2019-06-25T03:03:42Z")

</div>

Thanks, Harsh. Seems a good solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2019, 3:03am UTC](https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609/7 "2019-07-23T03:03:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
