# Unique File Identifier in Filebeat

**URL:** <https://discuss.elastic.co/t/unique-file-identifier-in-filebeat/242507>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 24, 2020, 11:54am UTC](https://discuss.elastic.co/t/unique-file-identifier-in-filebeat/242507 "2020-07-24T11:54:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pulkit007](https://avatars.discourse-cdn.com/v4/letter/p/5e9695/32.png) [@pulkit007](https://discuss.elastic.co/u/pulkit007)\
**Post date:** [July 24, 2020, 11:54am UTC](https://discuss.elastic.co/t/unique-file-identifier-in-filebeat/242507/1 "2020-07-24T11:54:36Z")

</div>

[https://www.elastic.co/guide/en/beats/filebeat/current/how-filebeat-works.html#\_how\_does\_filebeat\_keep\_the\_state\_of\_files](https://www.elastic.co/guide/en/beats/filebeat/current/how-filebeat-works.html#_how_does_filebeat_keep_the_state_of_files)

The above link tells that "For each file, Filebeat stores unique identifiers to detect whether a file was harvested previously."

Now, my questions are :

1. What is the **name** of unique identifier which filebeat uses to keep track of previously harvested files.

2. Where can we find the **value** of this unique identifier?

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [July 27, 2020, 8:40am UTC](https://discuss.elastic.co/t/unique-file-identifier-in-filebeat/242507/2 "2020-07-27T08:40:22Z")

</div>

Well, I assume this is internal implementation of harvesters, you need to take a look at the source code.

Why exactly do you need this information? Are you struggling with log rotation?

---

<div class="post-metadata">

**Author:** ![pulkit007](https://avatars.discourse-cdn.com/v4/letter/p/5e9695/32.png) [@pulkit007](https://discuss.elastic.co/u/pulkit007)\
**Post date:** [July 27, 2020, 8:59am UTC](https://discuss.elastic.co/t/unique-file-identifier-in-filebeat/242507/3 "2020-07-27T08:59:10Z")

</div>

I am struggling with Filebeat processing all logs again for every Pod Restart in Kubernetes.

I have shared my problem here : [Duplicate Entries in Filebeat Registry File For Kubernetes Pod Restart](https://discuss.elastic.co/t/duplicate-entries-in-filebeat-registry-file-for-kubernetes-pod-restart/242564)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2020, 10:59am UTC](https://discuss.elastic.co/t/unique-file-identifier-in-filebeat/242507/4 "2020-08-24T10:59:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
