# Filebeat stopped harvesting logs

**URL:** <https://discuss.elastic.co/t/filebeat-stopped-harvesting-logs/240863>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 12, 2020, 7:58pm UTC](https://discuss.elastic.co/t/filebeat-stopped-harvesting-logs/240863 "2020-07-12T19:58:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sai\_Avinash\_Duddupud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_avinash_duddupud/32/48265_2.png) [@Sai\_Avinash\_Duddupud](https://discuss.elastic.co/u/Sai_Avinash_Duddupud)\
**Post date:** [July 12, 2020, 7:58pm UTC](https://discuss.elastic.co/t/filebeat-stopped-harvesting-logs/240863/1 "2020-07-12T19:58:49Z")

</div>

Hi all,

I have started filebeat today with the following config and filbeat read logs till 2days ago and now it stopped receiving logs. I have tried restarting the filebeat by deleted the registry folder too, but the result is same.

it just repeats saying **harvester for file is still running**

**filebeat.yml**

```
filebeat.inputs:
- type: log
  paths:
    - /your/path/goes/here/*.log
output.logstash:
  enabled: true
  hosts: ["localhost:5044"]
logging.level: info
logging.to_files: true
logging.files:
  path: /var/log/filebeat
  name: filebeat
  keepfiles: 7
  permissions: 0644

```

**Filebeat logs**

```
|2020-07-12T19:52:57.765Z|DEBUG|[input]|log/input.go:421|Check file for harvesting: /opt/deployment/unityapp/unity/npm-debug.log|
|---|---|---|---|---|
|2020-07-12T19:52:57.765Z|DEBUG|[input]|log/input.go:511|Update existing file for harvesting: /opt/deployment/unityapp/unity/npm-debug.log, offset: 96972|
|2020-07-12T19:52:57.765Z|DEBUG|[input]|log/input.go:563|Harvester for file is still running: /opt/deployment/unityapp/unity/npm-debug.log|
|2020-07-12T19:52:57.765Z|DEBUG|[input]|log/input.go:212|input states cleaned up. Before: 2, After: 2, Pending: 0|
|2020-07-12T19:53:07.765Z|DEBUG|[input]|input/input.go:141|Run input|
|2020-07-12T19:53:07.765Z|DEBUG|[input]|log/input.go:191|Start next scan|
|2020-07-12T19:53:07.765Z|DEBUG|[input]|log/input.go:421|Check file for harvesting: /opt/deployment/unityapp/unity/django_blend.log|
|2020-07-12T19:53:07.765Z|DEBUG|[input]|log/input.go:511|Update existing file for harvesting: /opt/deployment/unityapp/unity/django_blend.log, offset: 222051|
|2020-07-12T19:53:07.765Z|DEBUG|[input]|log/input.go:563|Harvester for file is still running: /opt/deployment/unityapp/unity/django_blend.log|
|2020-07-12T19:53:07.765Z|DEBUG|[input]|log/input.go:421|Check file for harvesting: /opt/deployment/unityapp/unity/npm-debug.log|
|2020-07-12T19:53:07.765Z|DEBUG|[input]|log/input.go:511|Update existing file for harvesting: /opt/deployment/unityapp/unity/npm-debug.log, offset: 96972|
|2020-07-12T19:53:07.765Z|DEBUG|[input]|log/input.go:563|Harvester for file is still running: /opt/deployment/unityapp/unity/npm-debug.log|
|2020-07-12T19:53:07.765Z|DEBUG|[input]|log/input.go:212|input states cleaned up. Before: 2, After: 2, Pending: 0|
|2020-07-12T19:53:17.765Z|DEBUG|[input]|input/input.go:141|Run input|
|2020-07-12T19:53:17.765Z|DEBUG|[input]|log/input.go:191|Start next scan|
|2020-07-12T19:53:17.766Z|DEBUG|[input]|log/input.go:421|Check file for harvesting: /opt/deployment/unityapp/unity/django_blend.log|
|2020-07-12T19:53:17.766Z|DEBUG|[input]|log/input.go:511|Update existing file for harvesting: /opt/deployment/unityapp/unity/django_blend.log, offset: 222051|
|2020-07-12T19:53:17.766Z|DEBUG|[input]|log/input.go:563|Harvester for file is still running: /opt/deployment/unityapp/unity/django_blend.log|
|2020-07-12T19:53:17.766Z|DEBUG|[input]|log/input.go:421|Check file for harvesting: /opt/deployment/unityapp/unity/npm-debug.log|
|2020-07-12T19:53:17.766Z|DEBUG|[input]|log/input.go:511|Update existing file for harvesting: /opt/deployment/unityapp/unity/npm-debug.log, offset: 96972|
|2020-07-12T19:53:17.766Z|DEBUG|[input]|log/input.go:563|Harvester for file is still running: /opt/deployment/unityapp/unity/npm-debug.log|
|2020-07-12T19:53:17.766Z|DEBUG|[input]|log/input.go:212|input states cleaned up. Before: 2, After: 2, Pending: 0|

```

Please suggest how to troubleshoot filebeat inorder to continue receiving the logs from log file

---

<div class="post-metadata">

**Author:** ![kumarabhi](https://avatars.discourse-cdn.com/v4/letter/k/6a8cbe/32.png) [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Post date:** [July 13, 2020, 6:44am UTC](https://discuss.elastic.co/t/filebeat-stopped-harvesting-logs/240863/2 "2020-07-13T06:44:15Z")

</div>

For debugging purpose, please redirect the Filebeat output to stdout

```auto
output {
	stdout { 
	     codec => rubydebug { } 
	}
}

```

Also, look at Harvester closing options in [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-reference-yml.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-reference-yml.html)

Can you also check that some new data is being added to the input file ?

---

<div class="post-metadata">

**Author:** ![Sai\_Avinash\_Duddupud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_avinash_duddupud/32/48265_2.png) [@Sai\_Avinash\_Duddupud](https://discuss.elastic.co/u/Sai_Avinash_Duddupud)\
**Post date:** [July 13, 2020, 9:04am UTC](https://discuss.elastic.co/t/filebeat-stopped-harvesting-logs/240863/3 "2020-07-13T09:04:20Z")

</div>

@kumarabhi , logstash is now receving logs in real time although i couldn't see the logs in filebeat logs to my surprise 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2020, 11:04am UTC](https://discuss.elastic.co/t/filebeat-stopped-harvesting-logs/240863/4 "2020-08-10T11:04:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
