# Porspector and harvester

**URL:** <https://discuss.elastic.co/t/porspector-and-harvester/117517>\
**Category:** Logstash\
**Created:** [January 29, 2018, 7:31pm UTC](https://discuss.elastic.co/t/porspector-and-harvester/117517 "2018-01-29T19:31:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bruno\_Ramos\_Dias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bruno_ramos_dias/32/27010_2.png) [@Bruno\_Ramos\_Dias](https://discuss.elastic.co/u/Bruno_Ramos_Dias)\
**Post date:** [January 29, 2018, 7:31pm UTC](https://discuss.elastic.co/t/porspector-and-harvester/117517/1 "2018-01-29T19:31:44Z")

</div>

Somethins seems to be wrong on my configurations of filebat on to logsstash

This is my log when running file beat pointed at a logstash on another server:

2018-01-29T15:48:06-03:00 DBG [prospector] Harvester for file is still running: [confidential].log  
2018-01-29T15:48:06-03:00 DBG [prospector] Prospector states cleaned up. Before: 1, After: 1  
2018-01-29T15:48:11-03:00 DBG [harvester] End of file reached:[confidential].log;  
Backoff now.  
2018-01-29T15:48:15-03:00 INFO Non-zero metrics in the last 30s: beat.info.uptime.ms=30000 beat.memstats.gc\_next=4194304 beat.memstats.memory\_alloc=1497552 beat.memstats.memory\_total=54425192 filebeat.harvester.open\_files=1 filebeat.harvester.running=1 libbeat.config.module.running=0 libbeat.pipeline.clients=1 libbeat.pipeline.events.active=0 registrar.states.current=1  
2018-01-29T15:48:16-03:00 DBG [prospector] Run prospector  
2018-01-29T15:48:16-03:00 DBG [prospector] Start next scan

this is my logstash initialization log:  
[2018-01-29T09:22:37,705][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
[2018-01-29T09:22:38,107][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>1, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>125, :thread=\>"#\<Thread:0x5348aea9@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:245 run\>"}  
[2018-01-29T09:22:39,132][INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=\>"0.0.0.0:5044"}  
[2018-01-29T09:22:39,967][INFO][logstash.pipeline] Pipeline started {"[pipeline.id](http://pipeline.id)"=\>"main"}  
[2018-01-29T09:22:39,982][INFO][logstash.agent] Pipelines running {:count=\>1, :pipelines=\>["main"]}  
[2018-01-29T09:22:40,022][INFO][org.logstash.beats.Server] Starting server on port: 5044  
[2018-01-29T09:22:42,747][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[[http://localhost:9200/](http://localhost:9200/)], :added=\>[[http://127.0.0.1:9200/](http://127.0.0.1:9200/)]}}  
[2018-01-29T09:22:42,748][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://127.0.0.1:9200/](http://127.0.0.1:9200/), :path=\>"/"}  
[2018-01-29T09:22:42,754][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://127.0.0.1:9200/](http://127.0.0.1:9200/)"}

I have also created the filebeat template on elasticsearch but no indexes are generated  
can anyone point me what could be wrong?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2018, 7:31pm UTC](https://discuss.elastic.co/t/porspector-and-harvester/117517/2 "2018-02-26T19:31:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
