# Filebeat stop reading file after a while

**URL:** <https://discuss.elastic.co/t/filebeat-stop-reading-file-after-a-while/85450>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 11, 2017, 4:40pm UTC](https://discuss.elastic.co/t/filebeat-stop-reading-file-after-a-while/85450 "2017-05-11T16:40:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jonathanaxel](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jonathanaxel](https://discuss.elastic.co/u/jonathanaxel)\
**Post date:** [May 11, 2017, 4:40pm UTC](https://discuss.elastic.co/t/filebeat-stop-reading-file-after-a-while/85450/1 "2017-05-11T16:40:26Z")

</div>

Hi,

I am testing the filebeat app and I have encounter that after a while reading a syslog file it stops reading, I suspect is something related to the type of log, it is configured to rotate once a day at 10 AM, but when start reading the file it stops around 12 o'clock, I have checked the logs of filebeat and don't show any errors, here is my filebeat configuration:

> filebeat.prospectors:

> - input\_type: log

> # Paths that should be crawled and fetched. Glob based paths.
> 
> paths:  
> - /data/rsyslog/\*  
> close\_inactive: 48h  
> output.elasticsearch:
> 
> # Array of hosts to connect to.
> 
> enabled: true  
> hosts: ["localhost:9200"]  
> index: "proxybg-%{+yyyy.MM.dd}"

> # Optional ingest node pipeline. By default no pipeline will be used.
> 
> pipeline: "proxybg"

> # The number of times a particular Elasticsearch index operation is attempted. If
> 
> # the indexing operation doesn't succeed after this many retries, the events are
> 
> # dropped. The default is 3.
> 
> max\_retries: 3

> # Template name. By default the template name is filebeat.
> 
> template.name: "proxybg-\*"

> # Path to template file
> 
> template.path: "${path.config}/proxybg.template.json"

> # Overwrite existing template
> 
> template.overwrite: true

filebeat version 5.4.  
Elasticsearch version 5.4

I am missing something?

Regards,

Jonathan

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 15, 2017, 8:41am UTC](https://discuss.elastic.co/t/filebeat-stop-reading-file-after-a-while/85450/2 "2017-05-15T08:41:02Z")

</div>

Could you share your filebeat log file? Perhaps you can enable `debug` level for the logs to see more details. Is your data directory a shared volume?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2017, 8:41am UTC](https://discuss.elastic.co/t/filebeat-stop-reading-file-after-a-while/85450/3 "2017-06-12T08:41:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
