# Filebeat stopped working

**URL:** <https://discuss.elastic.co/t/filebeat-stopped-working/41401>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 10, 2016, 4:16pm UTC](https://discuss.elastic.co/t/filebeat-stopped-working/41401 "2016-02-10T16:16:14Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [February 10, 2016, 4:16pm UTC](https://discuss.elastic.co/t/filebeat-stopped-working/41401/2 "2016-02-10T16:16:40Z")

</div>

Here's my config file:

```auto

```

[root@web1:/etc/filebeat] #egrep -v "^$|^#|^(._)#" filebeat.yml  
filebeat:  
prospectors:  
-  
paths:  
- /var/log/httpd/jf\_ref.example.com\_access\_log  
document\_type: apache\_ref\_access  
input\_type: log  
fields:  
service: apache  
type: apache\_ref\_access  
-  
paths:  
- /var/log/httpd/jf\_ref.example.com\_error\_log  
document\_type: apache\_ref\_error  
input\_type: log  
fields:  
service: apache  
type: apache\_ref\_error  
-  
paths:  
- /var/log/httpd/jf\_beta.example.com\_access\_log  
document\_type: apache\_beta\_access  
input\_type: log  
fields:  
service: apache  
type: apache\_beta\_access  
-  
paths:  
- /var/log/httpd/jf\_beta.example.com\_error\_log  
input\_type: log  
document\_type: apache\_beta\_error  
fields:  
service: apache  
type: apache\_beta\_error  
-  
paths:  
- /var/log/httpd/jf\_dev.example.com\_access\_log  
document\_type: apache\_dev\_access  
input\_type: log  
fields:  
service: apache  
type: apache\_dev\_access  
-  
paths:  
- /var/log/httpd/jf\_dev.example.com\_error\_log  
document\_type: apache\_dev\_error  
input\_type: log  
fields:  
service: apache  
type: apache\_dev\_error  
-  
paths:  
- /var/log/httpd/jf\_php\_error.log  
document\_type: php  
input\_type: log  
fields:  
service: php  
type: php  
-  
paths:  
- /var/log/nginx/access.log  
document\_type: nginx-access  
input\_type: log  
fields:  
service: nginx  
type: nginx-access  
-  
paths:  
- /var/log/nginx/error.log  
document\_type: nginx-error  
input\_type: log  
fields:  
service: nginx  
type: nginx-error  
-  
paths:  
- /var/log/cassandra/system.log  
- /var/log/cassandra/cassandra.log  
document\_type: cassandra  
input\_type: log  
fields:  
service: cassandra  
type: cassandra  
-  
paths:  
- /var/log/mysqld.log  
document\_type: mysql  
input\_type: log  
fields:  
service: mysql  
type: mysql  
-  
paths:  
- /var/log/mariadb/mariadb.log  
document\_type: mariadb  
input\_type: log  
fields:  
service: mariadb  
type: mariadb  
-  
paths:  
- /var/log/maillog  
- /var/log/mail.log  
document\_type: postfix  
input\_type: postfix  
fields:  
service: postfix  
type: postfix  
-  
paths:  
- /var/log/puppet/puppet.log  
document\_type: puppet  
input\_type: log  
fields:  
service: puppet  
type: puppet  
-  
paths:  
- /var/log/messages  
- /var/log/syslog  
document\_type: syslog  
input\_type: log  
fields:  
service: syslog  
type: syslog  
-  
paths:  
- /var/log/boot.log  
- /var/log/cron  
- /var/log/dmesg  
- /var/log/yum.log  
document\_type: system  
input\_type: log  
fields:  
service: system  
type: system  
-  
paths:  
- /var/log/secure  
document\_type: security  
input\_type: log  
fields:  
service: security  
type: security  
-  
paths:  
- /var/log/varnish/varnish.log  
document\_type: varnish  
input\_type: log  
fields:  
service: varnish  
type: varnish  
-  
paths:  
- /var/log/mcollective.log  
document\_type: mcollective  
input\_type: log  
fields:  
service: mcollective  
type: mcollective  
-  
paths:  
- /var/log/_.log  
- /var/log/_/_.log  
document\_type: catch\_all  
input\_type: log  
fields:  
service: catch\_all  
type: cacth\_all  
registry\_file: /var/lib/filebeat/registry  
output:  
logstash:  
hosts:  
- [logs.example.com:5000](http://logs.example.com:5000)  
index: filebeat  
shipper:  
name: filebeat  
tags: ["example-dev", "web-tier"]  
ignore\_outgoing: true  
refresh\_topology\_freq: 10  
logy\_expire: 15  
logging:  
level: debug  
to\_files: true  
to\_syslog: false  
files:  
path: /var/log/filebeat  
name: filebeat.log  
files: 7

```auto
Thanks
```

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-stopped-working/41401)._
