# Wavefront proxy LogsIngester not establish response to Filebeat after 1 hour idle

**URL:** <https://discuss.elastic.co/t/wavefront-proxy-logsingester-not-establish-response-to-filebeat-after-1-hour-idle/187036>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 24, 2019, 3:35am UTC](https://discuss.elastic.co/t/wavefront-proxy-logsingester-not-establish-response-to-filebeat-after-1-hour-idle/187036 "2019-06-24T03:35:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ravi\_Wavefront](https://avatars.discourse-cdn.com/v4/letter/r/e56c9b/32.png) [@ravi\_Wavefront](https://discuss.elastic.co/u/ravi_Wavefront)\
**Post date:** [June 24, 2019, 3:35am UTC](https://discuss.elastic.co/t/wavefront-proxy-logsingester-not-establish-response-to-filebeat-after-1-hour-idle/187036/1 "2019-06-24T03:35:30Z")

</div>

We found that log metric cannot send wavefront if the log file has been idle for ~1 hour.

Filebeat version 6.3.2 (amd64), libbeat 6.3.2

Attached filebeat.yml and logsIngestion.yaml

Steps to reproduce:

1. Write log to file:  
echo -ne "[INFO]xxxyyy\ncom.now.ottid.api.controllers.HomeController\n### Connected database successfully asdf" \>\> /tmp/logs.txt

2. Wait ~1 hour, will get below result on wavefront

3. After the point stopped, write log to file again:  
echo -ne "[INFO]xxxyyy\ncom.now.ottid.api.controllers.HomeController\n### Connected database successfully asdf" \>\> /tmp/logs.txt  
Problem: The log will not show on wavefront

Filebeat log:

Wavefront proxy log:

Already try to restart filebeat, dose not help.

1. Write log to file, but different text:  
echo -ne "[INFO]xxxyyy\ncom.now.ottid.api.controllers.HomeController\n### Connected database successfully" \>\> /tmp/logs.txt

The log will show on wavefront:

1. Write the previous log to file, still not show on wavefront.  
echo -ne "[INFO]xxxyyy\ncom.now.ottid.api.controllers.HomeController\n### Connected database successfully asdf" \>\> /tmp/logs.txt

2. After restart wavefront proxy, wavefront can receive the log again  
echo -ne "[INFO]xxxyyy\ncom.now.ottid.api.controllers.HomeController\n### Connected database successfully asdf" \>\> /tmp/logs.txt[FileBeat Logs]([http://FileBeat](http://FileBeat) Logs)

===============================================================  
yml configuration

filebeat.inputs:

- type: log  
paths:
  - /tmp/logs.txt  
multiline.pattern: '^['  
multiline.negate: true  
multiline.match: after  
harvester\_limit: 0  
fields:  
close\_inactive: 2h  
clean\_inactive: 25h

output:  
logstash:  
hosts: ["localhost:5044"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2019, 3:35am UTC](https://discuss.elastic.co/t/wavefront-proxy-logsingester-not-establish-response-to-filebeat-after-1-hour-idle/187036/2 "2019-07-22T03:35:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
