# Missing logs with rotate log

**URL:** <https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 30, 2016, 12:01pm UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401 "2016-06-30T12:01:41Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Amos\_Shahar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amos_shahar/32/55444_2.png) [@Amos\_Shahar](https://discuss.elastic.co/u/Amos_Shahar)\
**Post date:** [June 30, 2016, 12:01pm UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/1 "2016-06-30T12:01:41Z")

</div>

hi,  
I am using filebeat (version 1.2.3-1 on AWS linux AMI) to forward to logstash and I have missing logs (every time the file rotates I think).  
the specific file is rotating every 20M and in the peak time it is rotating every 1-2 minutes, rotation name is:  
filename.log, filename.log.1,filename.log.2 ....  
Relevant yaml conf:  
paths:  
- /my\_path/\*.log  
ignore\_older: 24h  
scan\_frequency: 1s  
tail\_files: false

logstash:  
hosts: ["[ls-mydomain.com:4055](http://ls-mydomain.com:4055)"]  
loadbalance: true

any idea what can be wrong? how to troubleshoot it?  
In general, does filebeat can handle log rotate in such load? please note that there are many other files that filebeat is configured to ship but those that have no load are fine.

tried to change the parameters above but it is not solved.

Thanks,  
Amos

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 1, 2016, 5:35am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/2 "2016-07-01T05:35:47Z")

</div>

Exactly how are the files rotated? Are they renamed? Or copied and truncated?

---

<div class="post-metadata">

**Author:** ![Amos\_Shahar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amos_shahar/32/55444_2.png) [@Amos\_Shahar](https://discuss.elastic.co/u/Amos_Shahar)\
**Post date:** [July 1, 2016, 10:35pm UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/3 "2016-07-01T22:35:05Z")

</div>

I am not sure. it uses log4j and as I mentioned the names are as follow:  
filename.log  
filename.log.1  
filename.log.2  
....

Amos

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 2, 2016, 11:50am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/4 "2016-07-02T11:50:26Z")

</div>

you glob pattern does not match the renamed files. Thusly filebeat has problems finding these rotated files.

---

<div class="post-metadata">

**Author:** ![Amos\_Shahar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amos_shahar/32/55444_2.png) [@Amos\_Shahar](https://discuss.elastic.co/u/Amos_Shahar)\
**Post date:** [July 5, 2016, 8:19pm UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/5 "2016-07-05T20:19:30Z")

</div>

I tried with all patterns ("log.\*", ".log", "log\*") but still have missing messages.  
The only configuration that solve the problem is when I set the file rotation to a very big file (so there is no rotation) and than I get exactly ALL the messages. it seems that filebeat has issues with log rotating in high volume.  
anyone any idea?

Amos

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [July 6, 2016, 6:58am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/6 "2016-07-06T06:58:35Z")

</div>

It seems like you are hitting this bug here: [https://github.com/elastic/beats/pull/1954](https://github.com/elastic/beats/pull/1954)

Could you try the nightly build to see if this resolves your problem? [https://beats-nightlies.s3.amazonaws.com/index.html?prefix=filebeat/](https://beats-nightlies.s3.amazonaws.com/index.html?prefix=filebeat/)

The problem gets more sever as your scan\_frequency is quite low.

---

<div class="post-metadata">

**Author:** ![Amos\_Shahar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amos_shahar/32/55444_2.png) [@Amos\_Shahar](https://discuss.elastic.co/u/Amos_Shahar)\
**Post date:** [July 6, 2016, 12:19pm UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/7 "2016-07-06T12:19:00Z")

</div>

Issue has been resolved with this version - Thanks!  
filebeat-5.0.0-alpha5-SNAPSHOT-x86\_64.rpm

When will you have a stable release with this bug fix?

Amos

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [July 11, 2016, 8:21am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/8 "2016-07-11T08:21:30Z")

</div>

Glad it works with the most recent version. The first beta with these changes should be release in the next weeks.

---

<div class="post-metadata">

**Author:** ![Amos\_Shahar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amos_shahar/32/55444_2.png) [@Amos\_Shahar](https://discuss.elastic.co/u/Amos_Shahar)\
**Post date:** [July 12, 2016, 6:41am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/9 "2016-07-12T06:41:16Z")

</div>

I am sorry but after a hour or two it stopped working again ....  
It is a show stopper to the whole project. filebeat forward few logs every minute while I have more than 2000 log lines every minute.  
What information do you need in order to help solving this issue?

Amos

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [July 12, 2016, 8:16am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/10 "2016-07-12T08:16:26Z")

</div>

Can you post part of your log file? Please set the log level to at least INFO, best would be DEBUG to see all the details.

---

<div class="post-metadata">

**Author:** ![Amos\_Shahar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amos_shahar/32/55444_2.png) [@Amos\_Shahar](https://discuss.elastic.co/u/Amos_Shahar)\
**Post date:** [July 12, 2016, 10:23am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/11 "2016-07-12T10:23:34Z")

</div>

I can send the log file and the content of some of the files to you but I prefer not to publish as there is customer information involved. do you have an email?

Thanks,  
Amos

---

<div class="post-metadata">

**Author:** ![Amos\_Shahar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amos_shahar/32/55444_2.png) [@Amos\_Shahar](https://discuss.elastic.co/u/Amos_Shahar)\
**Post date:** [July 12, 2016, 10:57am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/12 "2016-07-12T10:57:01Z")

</div>

you can see the filebeat INFO file at:  
[http://open-voip.org/images/0/08/Filebeat.txt](http://open-voip.org/images/0/08/Filebeat.txt)  
and the registry file:  
[http://open-voip.org/images/b/b7/Registry.txt](http://open-voip.org/images/b/b7/Registry.txt)

the problematic file is webSocket.log

Thanks,  
Amos

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [July 13, 2016, 6:28pm UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/13 "2016-07-13T18:28:43Z")

</div>

Thanks for sharing some log files here. I had a quick look at the filebeat log and there is nothing really suspicious. It publishes very 30s between 30-60k events which sounds like enough to me to cover your case above.

Can you share the log lines from when you think that not all events are published? Or is that the case with the excerpt you shared? Can you share again the full config that you used for these tests?

---

<div class="post-metadata">

**Author:** ![Amos\_Shahar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amos_shahar/32/55444_2.png) [@Amos\_Shahar](https://discuss.elastic.co/u/Amos_Shahar)\
**Post date:** [July 17, 2016, 11:38am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/14 "2016-07-17T11:38:20Z")

</div>

here is the conf file:

```auto
filebeat.prospectors:
- input_type: log
  paths:
    - /logs/tnet/webSocketEvents.log
    - /logs/tnet/FIX*.log
    - /logs/tnet/tomcatS*.log
    - /logs/tnet/dbPr*.log
  ignore_older: 2m
  fields:
    level: info

```

I tried few option with ignore\_older parameter - all failed

Thanks,  
Amos

```auto

output.logstash:
  hosts: ["ls-mydomain.com:4055"]

```

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [July 18, 2016, 6:27am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/15 "2016-07-18T06:27:10Z")

</div>

Did you try not to use `ignore_older`?

Can you share the log lines from when you think that not all events are published? Or is that the case with the excerpt you shared?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2016, 12:02pm UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401/16 "2016-07-21T12:02:26Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
