# Large log entries getting truncated

**URL:** <https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 18, 2015, 2:43am UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874 "2015-11-18T02:43:02Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chris\_Clifton](https://avatars.discourse-cdn.com/v4/letter/c/82dd89/32.png) [@Chris\_Clifton](https://discuss.elastic.co/u/Chris_Clifton)\
**Post date:** [November 18, 2015, 2:43am UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874/1 "2015-11-18T02:43:02Z")

</div>

Using filebeat v1.0.0~rc2 on Ubuntu 12.04.3 LTS, our large php-error log entries are getting truncated. The log entries are typically between 3k and 8k, common ones are around 4k. The first 1024 bytes is what seems to be getting cut off.

At first thought it was network or logstash related, I took those out of the picture by using the file output in filebeat to send the log output directly to a file on the server where filebeat is installed and watching the php\_error log.

Is this a known issue, how can we be sure the entire entry is sent without getting truncated?

filebeat config on problem host :

```
    filebeat:
  prospectors:
    -
  paths:
    - /mnt/log/php_errors.log
  encoding: utf-8
  input_type: log
  harvester_buffer_size: 16384
  registry_file: /var/lib/filebeat/registry
output:
  file:
    path: "/tmp/filebeat.local.log"
    filename: filebeat
    rotate_every_kb: 10000
    number_of_files: 7
shipper:
logging:
  files:
```

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 18, 2015, 8:21am UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874/2 "2015-11-18T08:21:16Z")

</div>

@Chris_Clifton This should of course not happen. The config file looks good. Any chance to provide me with a log file where the error happens? You can also share it privately.

---

<div class="post-metadata">

**Author:** ![Chris\_Clifton](https://avatars.discourse-cdn.com/v4/letter/c/82dd89/32.png) [@Chris\_Clifton](https://discuss.elastic.co/u/Chris_Clifton)\
**Post date:** [November 18, 2015, 1:52pm UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874/3 "2015-11-18T13:52:00Z")

</div>

Thanks, messaged you file links with the full entries, one of the raw php log, one of the filebeat output file that matches.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 18, 2015, 2:26pm UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874/4 "2015-11-18T14:26:19Z")

</div>

Thanks for reporting. I've managed to create an unit test reproducing this error. Problem has been some internal read buffer being reduced by accident.

You can follow the progress on [github](https://github.com/elastic/filebeat/issues/258)

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 19, 2015, 9:14am UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874/5 "2015-11-19T09:14:55Z")

</div>

This should now be fixed and will be part of the next release. In case you want to test it earlier you can use the nightlies. We recommend to use the nightlies only for testing: [https://beats-nightlies.s3.amazonaws.com/index.html?prefix=filebeat/](https://beats-nightlies.s3.amazonaws.com/index.html?prefix=filebeat/)

---

<div class="post-metadata">

**Author:** ![Chris\_Clifton](https://avatars.discourse-cdn.com/v4/letter/c/82dd89/32.png) [@Chris\_Clifton](https://discuss.elastic.co/u/Chris_Clifton)\
**Post date:** [November 19, 2015, 6:09pm UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874/6 "2015-11-19T18:09:58Z")

</div>

Thank you!

---

<div class="post-metadata">

**Author:** ![stecino](https://avatars.discourse-cdn.com/v4/letter/s/ea666f/32.png) [@stecino](https://discuss.elastic.co/u/stecino)\
**Post date:** [June 15, 2016, 1:21am UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874/7 "2016-06-15T01:21:17Z")

</div>

I am seeing files being truncated, and I am using filebeat-5.0.0-alpha3-linux-x64

2016-06-15T00:05:20Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150000.dump  
2016-06-15T00:10:20Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150005.dump  
2016-06-15T00:15:20Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150010.dump  
2016-06-15T00:20:21Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150015.dump  
2016-06-15T00:25:21Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150020.dump  
2016-06-15T00:30:21Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150025.dump  
2016-06-15T00:35:11Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150030.dump  
2016-06-15T00:40:12Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150035.dump  
2016-06-15T00:45:12Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150040.dump  
2016-06-15T00:50:12Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150045.dum

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 15, 2016, 8:27am UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874/8 "2016-06-15T08:27:08Z")

</div>

This is totally unrelated. Version v1.0.0-rc2 used to have a bug fixed by then. The log message you're reffering to is filebeat having detected the files being forwarded have been changed in size (new file size \< old file size). Please create another topic discussing your problem.

---

<div class="post-metadata">

**Author:** ![stecino](https://avatars.discourse-cdn.com/v4/letter/s/ea666f/32.png) [@stecino](https://discuss.elastic.co/u/stecino)\
**Post date:** [June 15, 2016, 5:30pm UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874/9 "2016-06-15T17:30:10Z")

</div>

> [@stecino](#):
>
> I am seeing files being truncated, and I am using filebeat-5.0.0-alpha3-linux-x64
> 
> 2016-06-15T00:05:20Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150000.dump2016-06-15T00:10:20Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150005.dump2016-06-15T00:15:20Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150010.dump2016-06-15T00:20:21Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150015.dump2016-06-15T00:25:21Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150020.dump2016-06-15T00:30:21Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150025.dump2016-06-15T00:35:11Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150030.dump2016-06-15T00:40:12Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150035.dump2016-06-15T00:45:12Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150040.dump2016-06-15T00:50:12Z INFO File was truncated. Begin reading file from offset 0: /flow\_base\_dir/dump/flows-201606150045.dum

Mi apologies, I didn't realize

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:51pm UTC](https://discuss.elastic.co/t/large-log-entries-getting-truncated/34874/10 "2017-07-05T21:51:10Z")

</div>


