# How to send all the content of the files as well as the creation time?

**URL:** https://discuss.elastic.co/t/how-to-send-all-the-content-of-the-files-as-well-as-the-creation-time/110160
**Category:** Beats
**Tags:** filebeat
**Created:** [December 4, 2017, 2:38pm UTC](https://discuss.elastic.co/t/how-to-send-all-the-content-of-the-files-as-well-as-the-creation-time/110160 "2017-12-04T14:38:00Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![anthony-o](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@anthony-o](https://discuss.elastic.co/u/anthony-o)
#### Post date: [December 4, 2017, 2:38pm UTC](https://discuss.elastic.co/t/how-to-send-all-the-content-of-the-files-as-well-as-the-creation-time/110160/1 "2017-12-04T14:38:00Z")

</div>

I would like to configure Filebeat so it would send the whole content of all files of a specific folder (the log files appear in this folder, one file per new event).

I have some problems configuring this use case because **the last line of every file is not sent if there is no carriage return at the very last end of the file**. As I can't add one, this is a blocker issue for me and it seems that it is simply not possible to configure Filebeat to send all the content anyway by looking at [the FAQ](https://www.elastic.co/guide/en/beats/filebeat/current/faq.html#newline-character-required-eof)...

I would like to know also if it is possible to **add the creation time (and/or the modification time) of each file as a metadata or a field** to the Logstash server?

Here is my current configuration of `prospectors.d/http_queries.yml`:

```auto
- type: log
  paths:
    - /var/log/http_queries/*
  multiline:
    pattern: ^POST|^GET
    negate: true
    match: after
  close_eof: true

```

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 7, 2017, 3:36am UTC](https://discuss.elastic.co/t/how-to-send-all-the-content-of-the-files-as-well-as-the-creation-time/110160/2 "2017-12-07T03:36:01Z")

</div>

There is no standard way at the moment to send the complete file as one event if there is no newline as then filebeat assumes it's not a log event. You could "hack" around it potentially with multiline and a timeout.

For the meta data see [https://github.com/elastic/beats/issues/1775](https://github.com/elastic/beats/issues/1775) Currently not possible. For LS to enrich your event it would need also access to the same file system I think.

---

<div class="post-metadata">

### Author: ![anthony-o](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@anthony-o](https://discuss.elastic.co/u/anthony-o)
#### Post date: [December 13, 2017, 7:15pm UTC](https://discuss.elastic.co/t/how-to-send-all-the-content-of-the-files-as-well-as-the-creation-time/110160/3 "2017-12-13T19:15:08Z")

</div>

I tried to use the `timeout` and `close_timeout` parameters as well as define `pattern: .*` without any success (this last parameter is worse as it doesn't even send the content of the files previously sent).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 25, 2017, 2:38pm UTC](https://discuss.elastic.co/t/how-to-send-all-the-content-of-the-files-as-well-as-the-creation-time/110160/4 "2017-12-25T14:38:29Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
