# Filebeat stopped working

**URL:** <https://discuss.elastic.co/t/filebeat-stopped-working/41401>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 10, 2016, 4:16pm UTC](https://discuss.elastic.co/t/filebeat-stopped-working/41401 "2016-02-10T16:16:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [February 10, 2016, 4:16pm UTC](https://discuss.elastic.co/t/filebeat-stopped-working/41401/1 "2016-02-10T16:16:14Z")

</div>

Hey guys,

I noticed that I stopped receiving logs in logstash from the one host I have running filebeat.

If I tail the logs for filebeat and I'm seeing these messages repeating over and over again:

```auto
2016-02-10T11:14:21-05:00 DBG Try to publish %!s(int=40) events to logstash with window size %!s(int=1)
2016-02-10T11:14:21-05:00 DBG %!s(int=1) events out of %!s(int=40) events sent to logstash. Continue sending ...
2016-02-10T11:14:21-05:00 DBG Try to publish %!s(int=39) events to logstash with window size %!s(int=1)
2016-02-10T11:14:21-05:00 DBG %!s(int=1) events out of %!s(int=39) events sent to logstash. Continue sending ...
2016-02-10T11:14:21-05:00 DBG Try to publish %!s(int=38) events to logstash with window size %!s(int=1)
2016-02-10T11:14:21-05:00 DBG %!s(int=1) events out of %!s(int=38) events sent to logstash. Continue sending ...
2016-02-10T11:14:21-05:00 DBG Try to publish %!s(int=37) events to logstash with window size %!s(int=1)
2016-02-10T11:14:21-05:00 DBG %!s(int=1) events out of %!s(int=37) events sent to logstash. Continue sending ...
2016-02-10T11:14:21-05:00 DBG Try to publish %!s(int=36) events to logstash with window size %!s(int=1)

```

My config file is in the next post, as if I include it in this post it's too big.

I'd appreciate any help you may have! 🙂  
Thanks

---

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [February 10, 2016, 4:16pm UTC](https://discuss.elastic.co/t/filebeat-stopped-working/41401/2 "2016-02-10T16:16:40Z")

</div>

Here's my config file:

```auto

```

[root@web1:/etc/filebeat] #egrep -v "^$|^#|^(._)#" filebeat.yml  
filebeat:  
prospectors:  
-  
paths:  
- /var/log/httpd/jf\_ref.example.com\_access\_log  
document\_type: apache\_ref\_access  
input\_type: log  
fields:  
service: apache  
type: apache\_ref\_access  
-  
paths:  
- /var/log/httpd/jf\_ref.example.com\_error\_log  
document\_type: apache\_ref\_error  
input\_type: log  
fields:  
service: apache  
type: apache\_ref\_error  
-  
paths:  
- /var/log/httpd/jf\_beta.example.com\_access\_log  
document\_type: apache\_beta\_access  
input\_type: log  
fields:  
service: apache  
type: apache\_beta\_access  
-  
paths:  
- /var/log/httpd/jf\_beta.example.com\_error\_log  
input\_type: log  
document\_type: apache\_beta\_error  
fields:  
service: apache  
type: apache\_beta\_error  
-  
paths:  
- /var/log/httpd/jf\_dev.example.com\_access\_log  
document\_type: apache\_dev\_access  
input\_type: log  
fields:  
service: apache  
type: apache\_dev\_access  
-  
paths:  
- /var/log/httpd/jf\_dev.example.com\_error\_log  
document\_type: apache\_dev\_error  
input\_type: log  
fields:  
service: apache  
type: apache\_dev\_error  
-  
paths:  
- /var/log/httpd/jf\_php\_error.log  
document\_type: php  
input\_type: log  
fields:  
service: php  
type: php  
-  
paths:  
- /var/log/nginx/access.log  
document\_type: nginx-access  
input\_type: log  
fields:  
service: nginx  
type: nginx-access  
-  
paths:  
- /var/log/nginx/error.log  
document\_type: nginx-error  
input\_type: log  
fields:  
service: nginx  
type: nginx-error  
-  
paths:  
- /var/log/cassandra/system.log  
- /var/log/cassandra/cassandra.log  
document\_type: cassandra  
input\_type: log  
fields:  
service: cassandra  
type: cassandra  
-  
paths:  
- /var/log/mysqld.log  
document\_type: mysql  
input\_type: log  
fields:  
service: mysql  
type: mysql  
-  
paths:  
- /var/log/mariadb/mariadb.log  
document\_type: mariadb  
input\_type: log  
fields:  
service: mariadb  
type: mariadb  
-  
paths:  
- /var/log/maillog  
- /var/log/mail.log  
document\_type: postfix  
input\_type: postfix  
fields:  
service: postfix  
type: postfix  
-  
paths:  
- /var/log/puppet/puppet.log  
document\_type: puppet  
input\_type: log  
fields:  
service: puppet  
type: puppet  
-  
paths:  
- /var/log/messages  
- /var/log/syslog  
document\_type: syslog  
input\_type: log  
fields:  
service: syslog  
type: syslog  
-  
paths:  
- /var/log/boot.log  
- /var/log/cron  
- /var/log/dmesg  
- /var/log/yum.log  
document\_type: system  
input\_type: log  
fields:  
service: system  
type: system  
-  
paths:  
- /var/log/secure  
document\_type: security  
input\_type: log  
fields:  
service: security  
type: security  
-  
paths:  
- /var/log/varnish/varnish.log  
document\_type: varnish  
input\_type: log  
fields:  
service: varnish  
type: varnish  
-  
paths:  
- /var/log/mcollective.log  
document\_type: mcollective  
input\_type: log  
fields:  
service: mcollective  
type: mcollective  
-  
paths:  
- /var/log/_.log  
- /var/log/_/_.log  
document\_type: catch\_all  
input\_type: log  
fields:  
service: catch\_all  
type: cacth\_all  
registry\_file: /var/lib/filebeat/registry  
output:  
logstash:  
hosts:  
- [logs.example.com:5000](http://logs.example.com:5000)  
index: filebeat  
shipper:  
name: filebeat  
tags: ["example-dev", "web-tier"]  
ignore\_outgoing: true  
refresh\_topology\_freq: 10  
logy\_expire: 15  
logging:  
level: debug  
to\_files: true  
to\_syslog: false  
files:  
path: /var/log/filebeat  
name: filebeat.log  
files: 7

```auto
Thanks
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [February 10, 2016, 4:41pm UTC](https://discuss.elastic.co/t/filebeat-stopped-working/41401/3 "2016-02-10T16:41:22Z")

</div>

Logs look like a bug recently identified in logstash output. We're in the middle of preparing a 1.1.1 version containing a fix. You can try with 1.1.1 snapshot build:

[https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-darwin.tgz](https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-darwin.tgz)  
[https://download.elastic.co/beats/filebeat/filebeat\_1.1.1-SNAPSHOT\_i386.deb](https://download.elastic.co/beats/filebeat/filebeat_1.1.1-SNAPSHOT_i386.deb)  
[https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-x86\_64.rpm](https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-x86_64.rpm)  
[https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-windows.zip](https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-windows.zip)  
[https://download.elastic.co/beats/filebeat/filebeat\_1.1.1-SNAPSHOT\_amd64.deb](https://download.elastic.co/beats/filebeat/filebeat_1.1.1-SNAPSHOT_amd64.deb)  
[https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-x86\_64.tar.gz](https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-x86_64.tar.gz)  
[https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-i686.rpm](https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-i686.rpm)  
[https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-i686.tar.gz](https://download.elastic.co/beats/filebeat/filebeat-1.1.1-SNAPSHOT-i686.tar.gz)

---

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [February 10, 2016, 4:42pm UTC](https://discuss.elastic.co/t/filebeat-stopped-working/41401/4 "2016-02-10T16:42:49Z")

</div>

> [@steffens](#):
>
> Logs look like a bug recently identified in logstash output. We're in the middle of preparing a 1.1.1 version containing a fix. You can try with 1.1.1 snapshot build:

Ok! Relly cool! I've give it a shot. Thanks for the info!! 😁

---

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [February 10, 2016, 5:00pm UTC](https://discuss.elastic.co/t/filebeat-stopped-working/41401/5 "2016-02-10T17:00:50Z")

</div>

Hi Steffens,

I tried the rpm snapshot of filebeat 1.1 that you pointed me to. I uninstalled the 1.0 version with a yum remove command, and then installed the one you suggested:

```auto
[root@web1:~] #rpm -qa |grep filebeat
filebeat-1.1.1~SNAPSHOT-1.x86_64

```

But as I'm tailing the logs I'm finding no change in the errors that I'm seeing:

```auto
2016-02-10T11:59:27-05:00 DBG Try to publish %!s(int=189) events to logstash with window size %!s(int=1)
2016-02-10T11:59:27-05:00 DBG %!s(int=1) events out of %!s(int=189) events sent to logstash. Continue sending ...
2016-02-10T11:59:27-05:00 DBG Try to publish %!s(int=188) events to logstash with window size %!s(int=1)
2016-02-10T11:59:27-05:00 DBG %!s(int=1) events out of %!s(int=188) events sent to logstash. Continue sending ...
2016-02-10T11:59:27-05:00 DBG Try to publish %!s(int=187) events to logstash with window size %!s(int=1)
2016-02-10T11:59:27-05:00 DBG %!s(int=1) events out of %!s(int=187) events sent to logstash. Continue sending ...
2016-02-10T11:59:27-05:00 DBG Try to publish %!s(int=186) events to logstash with window size %!s(int=1)

```

Not sure what to do but wait for a newer version of 1.1, I guess. 😞

---

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [February 10, 2016, 6:28pm UTC](https://discuss.elastic.co/t/filebeat-stopped-working/41401/6 "2016-02-10T18:28:43Z")

</div>

hey slight update here. I uninstalled the filebeat snapshot rpm, then purged my system of all traces of filebeat with the unix find command. Then reinstalled it. Currently it's working again with my original yaml config. Let's hope it stays working! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:55pm UTC](https://discuss.elastic.co/t/filebeat-stopped-working/41401/7 "2017-07-05T21:55:50Z")

</div>


