# How to send only the newly added log events instead of the entire content of a log file?

**URL:** <https://discuss.elastic.co/t/how-to-send-only-the-newly-added-log-events-instead-of-the-entire-content-of-a-log-file/79127>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 18, 2017, 9:47am UTC](https://discuss.elastic.co/t/how-to-send-only-the-newly-added-log-events-instead-of-the-entire-content-of-a-log-file/79127 "2017-03-18T09:47:53Z")\
**Posts on this page:** 1\
**Showing post:** 13

<div class="post-metadata">

**Author:** ![Sharath\_Vutpala](https://avatars.discourse-cdn.com/v4/letter/s/9d8465/32.png) [@Sharath\_Vutpala](https://discuss.elastic.co/u/Sharath_Vutpala)\
**Post date:** [March 21, 2017, 11:31am UTC](https://discuss.elastic.co/t/how-to-send-only-the-newly-added-log-events-instead-of-the-entire-content-of-a-log-file/79127/13 "2017-03-21T11:31:00Z")

</div>

I followed the instructions in this topic.

> [@Logstash sending the complete file when new data is added to the log file](https://discuss.elastic.co/t/logstash-sending-the-complete-file-when-new-data-is-added-to-the-log-file/55629):
>
> Hi, Given the log file (apache.log) as input to Logstash, after applying some filter the output data is stored in Elasticsearch. Here, whenever the new data is added to the log file, logstash is sending the complete file to elasticsearch instead of updating the new events. For example, for the first time apache.log file contains 10 lines of data, after parsing this file using logstash i have verified the count in elasticsearch. It's showed me docs.count is "10". After sometime, there are 5 ne…

As mentioned in the above topic, when we use echo to add a line to the log file, the problem is solved. When vi editor is used, the whole file is being shipped to the Elasticsearch.

Use echo to add lines to the log file. That solves the issue.

---

_[View the full topic](https://discuss.elastic.co/t/how-to-send-only-the-newly-added-log-events-instead-of-the-entire-content-of-a-log-file/79127)._
