# Forwarding not updated CSV files

**URL:** <https://discuss.elastic.co/t/forwarding-not-updated-csv-files/75852>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 21, 2017, 10:09am UTC](https://discuss.elastic.co/t/forwarding-not-updated-csv-files/75852 "2017-02-21T10:09:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![copain9](https://avatars.discourse-cdn.com/v4/letter/c/7ba0ec/32.png) [@copain9](https://discuss.elastic.co/u/copain9)\
**Post date:** [February 21, 2017, 10:09am UTC](https://discuss.elastic.co/t/forwarding-not-updated-csv-files/75852/1 "2017-02-21T10:09:59Z")

</div>

Hi,

I have a software generating batches of logs in a CSV file once per hour. This CSV file is overwritten in one step instead of lines being appended to the previous file and is very formatted (all files are the exact same byte-level size). I tried a lot of configurations using `ignore_older`, `clean_inactive`and `close_eof` as I found in this similar topic : [https://discuss.elastic.co/t/monitor-a-set-of-json-files-in-filebeat/65198/2](https://discuss.elastic.co/t/monitor-a-set-of-json-files-in-filebeat/65198/2)

None of my attempts were successful, filebeat refusing to harvest my files. Am I missing something ? How would you configure filebeat to handle such case ?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 23, 2017, 2:06pm UTC](https://discuss.elastic.co/t/forwarding-not-updated-csv-files/75852/2 "2017-02-23T14:06:54Z")

</div>

I assume the modtime gets updated when new content is added to the file. I would expect in case the file gets updated every hour, that something like `scan_frequency: 10s`, `ignore_older: 1m`, `clean_inactive: 5m`, `close_eof: true` would work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2017, 2:07pm UTC](https://discuss.elastic.co/t/forwarding-not-updated-csv-files/75852/3 "2017-03-23T14:07:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
