# One-line log file

**URL:** <https://discuss.elastic.co/t/one-line-log-file/354060>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 25, 2024, 4:48pm UTC](https://discuss.elastic.co/t/one-line-log-file/354060 "2024-02-25T16:48:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kamil2](https://avatars.discourse-cdn.com/v4/letter/k/3ab097/32.png) [@Kamil2](https://discuss.elastic.co/u/Kamil2)\
**Post date:** [February 25, 2024, 4:48pm UTC](https://discuss.elastic.co/t/one-line-log-file/354060/1 "2024-02-25T16:48:12Z")

</div>

Is it possible for filebeat to send the entire contents of the log file to index every specific time interval? I want to save the state of a specific process to a file, overwrite the file each time and not keep historical data in this file.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [February 27, 2024, 9:50am UTC](https://discuss.elastic.co/t/one-line-log-file/354060/2 "2024-02-27T09:50:13Z")

</div>

Can you just save each state file as a new name (include a timestamp?) And configure Filebeat with a wildcard?

---

<div class="post-metadata">

**Author:** ![Kamil2](https://avatars.discourse-cdn.com/v4/letter/k/3ab097/32.png) [@Kamil2](https://discuss.elastic.co/u/Kamil2)\
**Post date:** [February 27, 2024, 8:19pm UTC](https://discuss.elastic.co/t/one-line-log-file/354060/3 "2024-02-27T20:19:05Z")

</div>

I don't want to keep additional log files on the system. Saving the state to new files every time causes a problem that I wanted to avoid.  
I currently have one log file. Each time I send the process status with a new timestamp to the log file. Filebeat doesn't read this one line as updated. I think there is some maker in the filebeat configuration and if I don't reset it every time, it won't start reading the file from the beginning, but will wait until something is added on subsequent lines.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 27, 2024, 8:30pm UTC](https://discuss.elastic.co/t/one-line-log-file/354060/4 "2024-02-27T20:30:35Z")

</div>

> [@Kamil2](#):
>
> Filebeat doesn't read this one line as updated. I think there is some maker in the filebeat configuration and if I don't reset it every time, it won't start reading the file from the beginning, but will wait until something is added on subsequent lines.

Filebeat _tails_ logs, so it needs a new line to read an event, if you have just one single line in the file it may not read it.

You could add a single empty line to your file to solve this.

Also, filebeat keeps track of what it already read, if you are writing to the same file then you need to make sure that the inode of the file will change (delete the olde one and write a new one), or filebeat also may not read it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2024, 10:31pm UTC](https://discuss.elastic.co/t/one-line-log-file/354060/5 "2024-03-26T22:31:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
