# How to check if filebeat is up to date with the input file

**URL:** <https://discuss.elastic.co/t/how-to-check-if-filebeat-is-up-to-date-with-the-input-file/156989>\
**Category:** Beats\
**Created:** [November 16, 2018, 7:07am UTC](https://discuss.elastic.co/t/how-to-check-if-filebeat-is-up-to-date-with-the-input-file/156989 "2018-11-16T07:07:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aakash\_Ratkal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aakash_ratkal/32/48716_2.png) [@Aakash\_Ratkal](https://discuss.elastic.co/u/Aakash_Ratkal)\
**Post date:** [November 16, 2018, 7:07am UTC](https://discuss.elastic.co/t/how-to-check-if-filebeat-is-up-to-date-with-the-input-file/156989/1 "2018-11-16T07:07:13Z")

</div>

I am using filebeat to ingest my log file. I need to handle the case where my application scales down and on of the instance is terminated. In this case, is there any way, I can check if all my log lines have been ingested? I need some kind of flag which says filebeat is up to date (or no backlog pending).

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 16, 2018, 1:46pm UTC](https://discuss.elastic.co/t/how-to-check-if-filebeat-is-up-to-date-with-the-input-file/156989/2 "2018-11-16T13:46:59Z")

</div>

Some people use a script reading the registry file from time to time.

Also see this enhancement request: [https://github.com/elastic/beats/issues/7743](https://github.com/elastic/beats/issues/7743)

---

<div class="post-metadata">

**Author:** ![Aakash\_Ratkal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aakash_ratkal/32/48716_2.png) [@Aakash\_Ratkal](https://discuss.elastic.co/u/Aakash_Ratkal)\
**Post date:** [November 27, 2018, 6:31am UTC](https://discuss.elastic.co/t/how-to-check-if-filebeat-is-up-to-date-with-the-input-file/156989/3 "2018-11-27T06:31:52Z")

</div>

Can you please elaborate on the script you mentioned?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 27, 2018, 11:15am UTC](https://discuss.elastic.co/t/how-to-check-if-filebeat-is-up-to-date-with-the-input-file/156989/4 "2018-11-27T11:15:06Z")

</div>

The registry file is in JSON. Updates are atomic (using rename). So users sometimes use python (or other scripting language) to parse the JSON. It's one array objects, each containing the file name, inode, device id, read offset and others. You can easily inspect the file using `jq`.

The format and contents is considered private, though. That is it might change one day. We are aware people read the registry file and we will try not to break it if possible, but you never know.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2018, 1:15pm UTC](https://discuss.elastic.co/t/how-to-check-if-filebeat-is-up-to-date-with-the-input-file/156989/5 "2018-12-25T13:15:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
