# Filebeat resend the harvested log many times

**URL:** <https://discuss.elastic.co/t/filebeat-resend-the-harvested-log-many-times/156739>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 14, 2018, 8:45pm UTC](https://discuss.elastic.co/t/filebeat-resend-the-harvested-log-many-times/156739 "2018-11-14T20:45:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![et159](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@et159](https://discuss.elastic.co/u/et159)\
**Post date:** [November 14, 2018, 8:45pm UTC](https://discuss.elastic.co/t/filebeat-resend-the-harvested-log-many-times/156739/1 "2018-11-14T20:45:12Z")

</div>

## I have filebeat sending logs to logstash on AWS, but it's not getting any feedback from logstash, and it resend the files over and over, here is the error msg from Preformatted textilebeat logs , Filebeat version 6.3.2 Filebeat Configuration:

```
type: log
timeout: 1
# Change to true to enable this prospector configuration.
enabled: true
# Paths that should be crawled and fetched. Glob based paths.
paths:
-AAA\*.log
 close_inactive: true
 close_eof: true
#================================ Outputs =====================================
#----------------------------- Logstash output --------------------------------

hosts: ["awscloud.com:5044"]

```

logstash input configurations:

```
  input {
    beats {
	    port => 5044
	     client_inactivity_timeout => 5400
    }
}

```

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77c9f87dc62e26d0fafb5d8a41b0c82284213444.jpeg)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 15, 2018, 3:33pm UTC](https://discuss.elastic.co/t/filebeat-resend-the-harvested-log-many-times/156739/2 "2018-11-15T15:33:55Z")

</div>

Beats need the ACK signal from Logstash. Check network/firewall rules.

Which logstash version are you using?

The timeout is in beats, but the default timeout is like 30s, while Logstash sends a keep-alive signal like every 5s.

---

<div class="post-metadata">

**Author:** ![et159](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@et159](https://discuss.elastic.co/u/et159)\
**Post date:** [November 15, 2018, 7:14pm UTC](https://discuss.elastic.co/t/filebeat-resend-the-harvested-log-many-times/156739/3 "2018-11-15T19:14:52Z")

</div>

Thanks a lot for your reply,,  
I'm using Logstash V6.3.2  
can I disable the ACK for the logstash ?  
I will update the timeout,

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 16, 2018, 1:27pm UTC](https://discuss.elastic.co/t/filebeat-resend-the-harvested-log-many-times/156739/4 "2018-11-16T13:27:15Z")

</div>

No, the ACK can not be disabled. It is required so filebeat knows logs have been actually transmitted.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2018, 1:27pm UTC](https://discuss.elastic.co/t/filebeat-resend-the-harvested-log-many-times/156739/5 "2018-12-14T13:27:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
