# Logstash input beat issue

**URL:** <https://discuss.elastic.co/t/logstash-input-beat-issue/246894>\
**Category:** Logstash\
**Created:** [August 30, 2020, 10:42pm UTC](https://discuss.elastic.co/t/logstash-input-beat-issue/246894 "2020-08-30T22:42:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Carlos\_Xavier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_xavier/32/74478_2.png) [@Carlos\_Xavier](https://discuss.elastic.co/u/Carlos_Xavier)\
**Post date:** [August 30, 2020, 10:42pm UTC](https://discuss.elastic.co/t/logstash-input-beat-issue/246894/1 "2020-08-30T22:42:23Z")

</div>

I getting an issue between filebeat and logstash that I can not uderstand what is gonig on, I need some help with that.  
Let me tell you what is going on...  
The filebeat setting is the following....

```auto
//
filebeat.inputs:

 - type: log
  enabled: true
  tags:
    - Vendas
  paths:
      - /home/vendas.csv
and the logstash.conf is the following ...

input {
  beats {
    port => 5044
    #codec => palin { charset => "ISO-8859-1"}
    #workers => 3
    #queue_size => 72000
    #receive_buffer_bytes => 31457280
  }
}

filter {
    if "Vendas" in [tags]{
     csv {
       separator => ","
       skip_empty_columns => true
       columns => ["nome","unidade","tipo","quantidade","valor","event3","event4"]
         }
       mutate {
          convert => {
          #"epoch_timestamplisted_action" => "integer"
          #"uniqueid" => "string"
          #"queue_name" => "integer"
          #"bridged_channel" => "string"
          #"event" => "string"
          "quantidade" => "integer"
          "valor" => "integer"
          "event3" => "integer"
         }
       }
    }
}

output {
  if "Vendas" in [tags]{
     elasticsearch {
     hosts => "localhost:9200"
     manage_template => false
     index => "%{[@metadata][beat]}-vendas"
     #document_type => "%{[@metadata][type]}"
     }
   }
}
 # for debug purpose of pipeline with command: ./logstash -f /etc/logstash/conf.d/logstash.conf
//

```

also the pipeline.yml is setting as the following ....

```auto
//
- pipeline.id: main
  pipeline.workers: 8
  pipeline.batch.size: 1000
  pipeline.batch.delay: 120
  path.config: "/etc/logstash/conf.d/*.conf"
  #codec: plain { charset => "ISO-8859-1" }
  # workers: 3
  #queue_size: 72000
  #receive_buffer_bytes: 31457280
  queue.type: persisted
//

```

Here is the issue the first content of the file comes with the following situation...

,\*  
11:40:04.423 Vanderleia\_Souza,Unidade-1\_1100,Portabilidade,1,37066,0,\*  
11:40:04.423 Rebeca\_Xavier,Unidade-1\_2100,Portabilidade,1,11706,0,\*  
11:40:04.423 Rayssa\_Lima\_Fernandes\_de\_Souza,Unidade-1\_2100,Novos,1,4791,0,\*  
11:40:04.423 Rayssa\_Lima\_Fernandes\_de\_Souza,Unidade-1\_2100,Portabilidade,1,9052,0,\*  
11:40:04.423 Victoria\_Christina\_Batista�,Unidade-1\_2100,Novos,1,10071,0,\*  
11:40:04.424 Vitoria\_Eberhardt\_Machado\_dos\_Passos,Unidade-2\_6100,Novos,1,2738,0,\*  
11:40:04.424 Vitoria\_Eberhardt\_Machado\_dos\_Passos,Unidade-2\_6100,Novos,1,2965,0,\*  
11:40:04.424 Orestes\_Novaes,Unidade-2\_6100,Portabilidade,1,12724,0,\*  
11:40:04.424 Izadora\_Elizabeth\_Gama\_dos\_Santos,Unidade-2\_5100,Portabilidade,1,13052,0,\*  
11:40:04.424 Lucas\_Catania\_Marques\_De\_Oliveira,Unidade-3\_7100,Novos,1,9494,0,\*  
11:40:04.424 Lucas\_Catania\_Marques\_De\_Oliveira,Unidade-3\_7100,Novos,1,9790,0,\*  
11:40:04.424 Lucas\_Catania\_Marques\_De\_Oliveira,Unidade-3\_7100,Cartao,1,1822,0,\*  
11:40:04.425 Gabrielly\_de\_Lima\_Barbosa,Unidade-3\_7100,Novos,1,6662,0,\*  
11:40:04.425 Igor\_De\_Andrade\_B.\_Mathias,Unidade-3\_7100,Novos,1,11490,0,\*  
11:40:04.425 Igor\_De\_Andrade\_B.\_Mathias,Unidade-3\_7100,Novos,1,11478,0,\*  
11:40:04.425 Igor\_De\_Andrade\_B.\_Mathias,Unidade-3\_7100,Cartao,1,2139,0,\*

before de first line must be the following ...

11:47:34.439 Quesia\_Farias\_da\_Silva,Unidade-2\_3100,Portabilidade,1,11946,0,\*  
11:47:34.439 Andre\_Tavares\_do\_Nascimento,Unidade-2\_3100,Portabilidade,1,11994,0,\*  
11:47:34.439 Tayna\_Donofrio\_Barbosa,Unidade-2\_3100,Novos,1,735,0,\*  
11:47:34.439 Manoela\_Lopes,Unidade-1\_1100,Portabilidade,1,34839,0,\*  
11:47:34.440 Thaillyn\_Tamires\_da\_Silva,Unidade-1\_1100,Portabilidade,1,12594,0,\*  
11:47:34.440 Nayara\_Brandao,Unidade-1\_1100,Portabilidade,1,13787,0,\*  
11:47:34.440 Nayara\_Brandao,Unidade-1\_1100,Portabilidade,1,8274,0,\*  
11:47:34.440 Vanderleia\_Souza,Unidade-1\_1100,Portabilidade,1,14143,0,\*

I don´t know why the data is beeing truncate...

IF i go to the same csv file at the filebeat host and edit it and leave there just the data that it not went to logstash host ..after save the file evey contemt goes to logstash perfectly.

So anyeone already have this situation ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2020, 10:42pm UTC](https://discuss.elastic.co/t/logstash-input-beat-issue/246894/2 "2020-09-27T22:42:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
