# One prospector stops

**URL:** <https://discuss.elastic.co/t/one-prospector-stops/54410>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 30, 2016, 1:05pm UTC](https://discuss.elastic.co/t/one-prospector-stops/54410 "2016-06-30T13:05:23Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)\
**Post date:** [June 30, 2016, 1:05pm UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/1 "2016-06-30T13:05:23Z")

</div>

Hello,

I have a filebeat config with two prospectors and one stops working after a couple days. The other one keeps on working normally.

Is there any way to debug why this is happening. I checked the log files and it just logs that there are no changes in the file.

After the restart it finds the new data.

Kind regards,

Uros

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 2, 2016, 4:50am UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/2 "2016-07-02T04:50:47Z")

</div>

What version are you on? What OS?  
Have you tried running with debug?  
What differences are there between the two?

---

<div class="post-metadata">

**Author:** ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)\
**Post date:** [July 4, 2016, 6:49am UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/3 "2016-07-04T06:49:05Z")

</div>

Hello,

OS is Win 2012 R2, filebeat is 1.2.3.

Yes, I have running it with debug, but there are no errors in the logs. It only logs no changes in file (_Not harvesting, file didn't change:_)

The prospectors are identical, expect for one exclude\_lines directive in the prospector that is the problem.

Kind regards,

Uros

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [July 4, 2016, 7:46am UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/4 "2016-07-04T07:46:19Z")

</div>

Are you fetching files from a mounted volume?

---

<div class="post-metadata">

**Author:** ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)\
**Post date:** [July 4, 2016, 8:44am UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/5 "2016-07-04T08:44:55Z")

</div>

It´s a normal windows disk drive.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [July 5, 2016, 7:59am UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/6 "2016-07-05T07:59:52Z")

</div>

Can you share your config file? Does it work if you remove the exclude\_lines directive?

---

<div class="post-metadata">

**Author:** ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)\
**Post date:** [July 5, 2016, 10:08am UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/7 "2016-07-05T10:08:59Z")

</div>

Here is my config:

```
filebeat:
  prospectors:
    -
      paths:
        - E:/SoftwareAG/ARIS9/server/bin/work/work_businesspublisher_m/base/webapps/businesspublisher/log/monitoring/webAccess-*.log
      encoding: utf-8
      input_type: log
      exclude_lines: ["^#"]
      document_type: arislogweb
    -
      paths:
        - E:/SoftwareAG/ARIS9/server/bin/work/work_businesspublisher_m/base/webapps/businesspublisher/log/monitoring/modelAccess-*.log
      encoding: utf-8	  
      input_type: log
      document_type: arislogmodel
      close_older: 1h
  registry_file: "C:/ProgramData/filebeat/registry"

output:
  logstash:
      hosts: ["somehost:5044"]
    tls:
      certificate_authorities: ["C:/Program Files/filebeat/chain.cer"]
      certificate: "C:/Program Files/filebeat/cert.cer"
      certificate_key: "C:/Program Files/filebeat/cert.key"

logging:
   to_files: true
   files:
     path: C:/ProgramData/filebeat
     name: filebeat_debug
     rotateeverybytes: 10485760 # = 10MB
     keepfiles: 7
   selectors: ["*"]
   level: debug

```

I have just removed the closed\_older from the top prospector. Just for testing. Next I will remove the exclude directive, probably tomorrow.

Kind regards,  
Uros

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 5, 2016, 1:43pm UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/8 "2016-07-05T13:43:51Z")

</div>

did just skim over your config, but: Never use double quotes `"` for regular expressions, but use single quotes `'`. There are 5 different kind of string formats in YAML with different escaping rules.

---

<div class="post-metadata">

**Author:** ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)\
**Post date:** [July 5, 2016, 2:18pm UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/9 "2016-07-05T14:18:21Z")

</div>

Thanks. I changed the exclude\_lines directive...or did you mean I should use single quotes everywhere in the config?

Kind regards,

Uros

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 5, 2016, 8:10pm UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/10 "2016-07-05T20:10:39Z")

</div>

it's up to you when you use single quotes. Advantage of single-quotes is, you don't have to deal with YAML based escaping rules. For example windows file paths can be written with backslash (e.g. copy'n paste path) if single quote is used.

---

<div class="post-metadata">

**Author:** ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)\
**Post date:** [July 7, 2016, 8:43am UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/11 "2016-07-07T08:43:02Z")

</div>

Thanks. Didn't know that.

---

<div class="post-metadata">

**Author:** ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)\
**Post date:** [July 11, 2016, 7:11am UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/12 "2016-07-11T07:11:28Z")

</div>

Hello,

could it be that it has something to do with the way the original app is writing the log file. It looks kinda strange, since there are changes in the log file, but the last access or last write date do not get changed. Could that have to do something with filebeat?

Kind regards,

Uros

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [July 12, 2016, 9:42am UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/13 "2016-07-12T09:42:34Z")

</div>

@Uros_Meglic Yes, that is a common problem with shared drives. It is recommended to install filebeat on each edge server. There are some improvements in the 5.0.0-alpha releases related to this in case you are interested to try it out: [https://beats-nightlies.s3.amazonaws.com/index.html?prefix=filebeat/](https://beats-nightlies.s3.amazonaws.com/index.html?prefix=filebeat/)

---

<div class="post-metadata">

**Author:** ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)\
**Post date:** [July 12, 2016, 12:28pm UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/14 "2016-07-12T12:28:45Z")

</div>

This log file is not on a shared (network) drive or what do you mean exactly with shared drives?

Can I use the 5.0 filebeat with older logstash server?

Kind regards,

Uros

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2016, 1:05pm UTC](https://discuss.elastic.co/t/one-prospector-stops/54410/16 "2016-07-21T13:05:23Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
