# How to understand "registry" file in filebeat

**URL:** <https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 19, 2018, 5:57am UTC](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271 "2018-11-19T05:57:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![luxiaoxun](https://avatars.discourse-cdn.com/v4/letter/l/c2a13f/32.png) [@luxiaoxun](https://discuss.elastic.co/u/luxiaoxun)\
**Post date:** [November 19, 2018, 5:57am UTC](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271/1 "2018-11-19T05:57:38Z")

</div>

I know that "registry" is for "tracking files that filebeat is harvesting or is harvested", but for details, how to understand it.  
Take following as example, what does "timestamp" and "ttl" mean ?  
{  
"source": "D:\aaaa\history\20181119.log",  
"offset": 96657420,  
"FileStateOS": {  
"idxhi": 393216,  
"idxlo": 7245,  
"vol": 707258545  
},  
"timestamp": "2018-11-19T10:21:27.6784958+08:00",  
"ttl": -1000000000,  
"count": 88781,  
"ignore": 0  
}

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [November 20, 2018, 2:06pm UTC](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271/2 "2018-11-20T14:06:19Z")

</div>

Hello @luxiaoxun

I think the following would help.

**Source** : This is the path on disk for the file.  
**Offset** : The last position read.  
**FileStateOS** : This contains the information relative to inode and volume, we use that information to uniquely identify a file on disk, it help us track rename.  
**Timestamp** : Record was last updated at.  
**TTL** : Depenging on the user configuration, this will be used internally to know when to garbage collect the record and clean up some state.  
**count** : number of updates for this specific record. (IIRC)

---

<div class="post-metadata">

**Author:** ![luxiaoxun](https://avatars.discourse-cdn.com/v4/letter/l/c2a13f/32.png) [@luxiaoxun](https://discuss.elastic.co/u/luxiaoxun)\
**Post date:** [November 21, 2018, 2:36am UTC](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271/3 "2018-11-21T02:36:02Z")

</div>

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2018, 2:40am UTC](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271/4 "2018-12-19T02:40:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
