# Howto retry from begining the today log file into es

**URL:** <https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 19, 2017, 8:41am UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842 "2017-04-19T08:41:46Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)\
**Post date:** [April 19, 2017, 8:41am UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/1 "2017-04-19T08:41:46Z")

</div>

howto retry from begining the today log file into es

when i run follow command

#rm -rf filebeat/data/registry  
#restart filebeat service

the result:  
ES display curent time not today log file begining line

---

<div class="post-metadata">

**Author:** ![maddin2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddin2016/32/16599_2.png) [@maddin2016](https://discuss.elastic.co/u/maddin2016)\
**Post date:** [April 19, 2017, 9:15am UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/2 "2017-04-19T09:15:08Z")

</div>

Then you maybe filter per `@timestamp`. `@timestamp` is always the current UTC time the log was read and not the time the log was created. What you can do is to send your logs to logstash and then filter by a field which contains the timestamp the log was created. See [here](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html)

---

<div class="post-metadata">

**Author:** ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)\
**Post date:** [April 19, 2017, 9:39am UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/3 "2017-04-19T09:39:29Z")

</div>

the file of registry that record the log file offset num every time

so i delete the registry file

---

<div class="post-metadata">

**Author:** ![maddin2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddin2016/32/16599_2.png) [@maddin2016](https://discuss.elastic.co/u/maddin2016)\
**Post date:** [April 19, 2017, 10:12am UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/4 "2017-04-19T10:12:39Z")

</div>

Ok, sorry. I thought you mean the timestamp is not correct. Can please post your filebeat config and maybe the filebeat log.

---

<div class="post-metadata">

**Author:** ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)\
**Post date:** [April 19, 2017, 12:16pm UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/5 "2017-04-19T12:16:56Z")

</div>

i mean curent time logfile : nginx\_perf.log

i want though logstash import ES yesterday log file and two days ago log file and so on  
eg: nginx\_perf.2017-04-15.log nginx\_perf.2017-04-17.log

between 20170415 and 20170417 our cluster crash  
so log file hasn't import ES cluster

now we want import old log into ES cluster

---

<div class="post-metadata">

**Author:** ![maddin2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddin2016/32/16599_2.png) [@maddin2016](https://discuss.elastic.co/u/maddin2016)\
**Post date:** [April 19, 2017, 12:31pm UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/6 "2017-04-19T12:31:08Z")

</div>

What you can do is to set `ignore_older` in your filebeat.yml. For example if you want all logs since 20170415 set this to `96h` or a time range back from now where youre cluster has crash. See [here](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#ignore-older) for more info.

---

<div class="post-metadata">

**Author:** ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)\
**Post date:** [April 19, 2017, 1:14pm UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/7 "2017-04-19T13:14:13Z")

</div>

my way is that we create logstash and filebeat another port used history log file

but elasticserach don't display content

---

<div class="post-metadata">

**Author:** ![maddin2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddin2016/32/16599_2.png) [@maddin2016](https://discuss.elastic.co/u/maddin2016)\
**Post date:** [April 19, 2017, 2:06pm UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/8 "2017-04-19T14:06:27Z")

</div>

I think the best way is to delete all registry files and use the `ignore_older` option instead of using and old registry file. @ruflin, do you have any thoughts?

---

<div class="post-metadata">

**Author:** ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)\
**Post date:** [April 20, 2017, 7:34am UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/9 "2017-04-20T07:34:57Z")

</div>

very sorry i have to ask your some silly question

i feel very insteresting

kibana portal discover item display Diagram

original log file format :

2017-04-20 15:00:30 INFO - 0.0.0.0 1349 domain xxxxxx 1 0  
2017-04-20 15:00:30 INFO - 0.0.0.0 1463 domain xxxxxx 1 0  
2017-04-20 15:00:30 INFO - 0.0.0.0 1459 domain xxxxxxxx 1 0  
2017-04-20 15:00:30 INFO - 0.0.0.0 25607 domain xxxxxxx 0 0

my filebeat.yml :  
filebeat.prospectors:

- input\_type: log  
paths:
  - /home/ops/logs/perf.log  
exclude\_lines: ["DEBUG -"]  
fields:  
logtype: "webservice"

output.logstash:  
hosts: ["1.1.1.2:5043"]

kibana display dataset

```
    time datetime 
    April 20th 2017, 15:26:59.143 2017-04-20 15:11:03 
April 20th 2017, 15:26:59.143	2017-04-20 15:11:03
April 20th 2017, 15:26:59.143	2017-04-20 15:11:03
April 20th 2017, 15:26:59.143	2017-04-20 15:11:03
April 20th 2017, 15:26:59.143	2017-04-20 15:11:03
April 20th 2017, 15:26:59.143	2017-04-20 15:11:03
April 20th 2017, 15:26:59.143	2017-04-20 15:11:03
April 20th 2017, 15:26:59.143	2017-04-20 15:11:03

```

first Column is curent time second Column is from begining line read log file content time so kibana display icon from begging line until current line concentrated in curent time

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [April 21, 2017, 11:21am UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/10 "2017-04-21T11:21:23Z")

</div>

Not 100% sure I fully understand the problem. But if you just want to reship the data from one log file, you have 2 options. Follow the approach suggested by @maddin2016 with removing the registry and use `ignore_older`, or you edit the registry file yourself when filebeat is not running and remove the file you want to reship. But make sure the content stays valid json.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2017, 11:35am UTC](https://discuss.elastic.co/t/howto-retry-from-begining-the-today-log-file-into-es/82842/11 "2017-05-19T11:35:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
