# How to understand "registry" file in filebeat

**URL:** <https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 19, 2018, 5:57am UTC](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271 "2018-11-19T05:57:38Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [November 20, 2018, 2:06pm UTC](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271/2 "2018-11-20T14:06:19Z")

</div>

Hello @luxiaoxun

I think the following would help.

**Source** : This is the path on disk for the file.  
**Offset** : The last position read.  
**FileStateOS** : This contains the information relative to inode and volume, we use that information to uniquely identify a file on disk, it help us track rename.  
**Timestamp** : Record was last updated at.  
**TTL** : Depenging on the user configuration, this will be used internally to know when to garbage collect the record and clean up some state.  
**count** : number of updates for this specific record. (IIRC)

---

_[View the full topic](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat/157271)._
