# Once in a while, filebeat lost first charactor while collect log

**URL:** <https://discuss.elastic.co/t/once-in-a-while-filebeat-lost-first-charactor-while-collect-log/164982>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 21, 2019, 6:29am UTC](https://discuss.elastic.co/t/once-in-a-while-filebeat-lost-first-charactor-while-collect-log/164982 "2019-01-21T06:29:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![guisong](https://avatars.discourse-cdn.com/v4/letter/g/e19b73/32.png) [@guisong](https://discuss.elastic.co/u/guisong)\
**Post date:** [January 21, 2019, 6:29am UTC](https://discuss.elastic.co/t/once-in-a-while-filebeat-lost-first-charactor-while-collect-log/164982/1 "2019-01-21T06:29:22Z")

</div>

Once in a while, filebeat lost first charactor while collect log,for example,message start with timestamp string,but it lost some charactors when I get message from elasticsearch.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/0/10a0ded36256b66d5c8c7a6bfb0d7aea77650895.png)  
In fact message is start with string "2019-01-20 05:28:21,343Z",and process print log without any error,message is complete in log file.  
filebeat collect log,and send to logstash,and logstash send to elasticsearch.  
please tell me some problem happened,how to solve this problem.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 22, 2019, 11:39am UTC](https://discuss.elastic.co/t/once-in-a-while-filebeat-lost-first-charactor-while-collect-log/164982/2 "2019-01-22T11:39:47Z")

</div>

Can you share your filebeat config?

Do you do any processing in logstash? Is there a chance the character can get lost in logstash?

---

<div class="post-metadata">

**Author:** ![guisong](https://avatars.discourse-cdn.com/v4/letter/g/e19b73/32.png) [@guisong](https://discuss.elastic.co/u/guisong)\
**Post date:** [January 22, 2019, 2:00pm UTC](https://discuss.elastic.co/t/once-in-a-while-filebeat-lost-first-charactor-while-collect-log/164982/3 "2019-01-22T14:00:32Z")

</div>

OK.as follow:

```auto
- input_type: log
  enabled: true
  paths:
    - /opt/iot/cig/karaf/data/log/*.log
  fields:
    iotteam: vehiclesuit
    iotservice: cig
    logtype: cig-log
  fields_under_root: true
  max_bytes: 512000
  close_timeout: 300m
  multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
  multiline.negate: true
  multiline.match: after
  spool_size: 1024
  idle_timeout: 10s
  registry_file: registry

```

Yes,I catch timestamp of log and cover timestamp of filebeat. filter config of logstash:

```auto
    grok {
      match => { "message" => "%{TIMESTAMP_ISO8601:logTimestamp}" }
    }
    date { match => ["logTimestamp", "ISO8601"] }

```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 23, 2019, 11:34am UTC](https://discuss.elastic.co/t/once-in-a-while-filebeat-lost-first-charactor-while-collect-log/164982/4 "2019-01-23T11:34:25Z")

</div>

Please format logs and configs using the `</>` button in the editor.

Which beat version are you using?

Can you share you complete config file. The one you posted doesn't seem either complete or correct.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2019, 11:34am UTC](https://discuss.elastic.co/t/once-in-a-while-filebeat-lost-first-charactor-while-collect-log/164982/5 "2019-02-20T11:34:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
