# Beats configuration help

**URL:** https://discuss.elastic.co/t/beats-configuration-help/216081
**Category:** Beats
**Created:** [January 22, 2020, 2:47pm UTC](https://discuss.elastic.co/t/beats-configuration-help/216081 "2020-01-22T14:47:52Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Walter\_Hiranpat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/walter_hiranpat/32/53309_2.png) [@Walter\_Hiranpat](https://discuss.elastic.co/u/Walter_Hiranpat)
#### Post date: [January 22, 2020, 2:47pm UTC](https://discuss.elastic.co/t/beats-configuration-help/216081/1 "2020-01-22T14:47:53Z")

</div>

I have deploy an elastic stack mostly using just kibana and elasticsearch (3 master, 5 data, 5 ingest nodes) version 7.5 . I have about 20 application servers and that I installed the beats on each of these servers. It seems to work for a while but after a week or so the beats would stop send beats data and store it locally. This cause the application servers to crash because it would consume majority of the disk drive (use default beats configuration with only modification to elasticsearch and kibana host url).

I should also mention that the elasticsearch cluster, each individual host disk space still have enough disk space.

I didn't seem to have this issue before on older edition. Does this have to do with how I configure the beats or is this due to something else?

Thank you,

---

<div class="post-metadata">

### Author: ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)
#### Post date: [January 23, 2020, 6:19pm UTC](https://discuss.elastic.co/t/beats-configuration-help/216081/2 "2020-01-23T18:19:43Z")

</div>

Hey @Walter_Hiranpat,

In principle Beats only store data locally if [disk spool](https://www.elastic.co/guide/en/beats/filebeat/7.5/configuring-internal-queue.html) is configured. How do you see that beats store data locally?

Having the disk full can be a reason why Beats stop working properly. Could it be that the disk is getting full because of other reasons?

What version were you using before?

---

<div class="post-metadata">

### Author: ![Walter\_Hiranpat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/walter_hiranpat/32/53309_2.png) [@Walter\_Hiranpat](https://discuss.elastic.co/u/Walter_Hiranpat)
#### Post date: [January 24, 2020, 3:27pm UTC](https://discuss.elastic.co/t/beats-configuration-help/216081/3 "2020-01-24T15:27:51Z")

</div>

Hello Jsoriano,

I am see that the logs are store /var/logs on the application server. however the elasticsearch still have over 40% space remainding and I have a serverless function to expand the ebs of the elasticsearch servers.

I don't think it is the application fault because we ran the application for over a year now and it didn't have an effect and when we turn off the beats and remove the logs that are stored locally. The application server would start working fine and didn't display any issues.

I am using the 7.2 version for elasticsearch, kibana and beats.

---

<div class="post-metadata">

### Author: ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)
#### Post date: [January 24, 2020, 6:50pm UTC](https://discuss.elastic.co/t/beats-configuration-help/216081/4 "2020-01-24T18:50:10Z")

</div>

Do you mean that Beats logs are stored in `/var/logs` and they take all the disk space?

This shouldn't happen, could you check what is the size of Beats logs, and if there is something flooding the logs?

How are you deploying Beats in these machines? If you are deploying them in docker, or in machines with systemd you can configure Beats to log to standard output/error and then they don't log to files.

---

<div class="post-metadata">

### Author: ![Walter\_Hiranpat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/walter_hiranpat/32/53309_2.png) [@Walter\_Hiranpat](https://discuss.elastic.co/u/Walter_Hiranpat)
#### Post date: [February 12, 2020, 4:39am UTC](https://discuss.elastic.co/t/beats-configuration-help/216081/5 "2020-02-12T04:39:37Z")

</div>

The beats are stored in /var/logs/filebeats/ or what their corresponding beats name. They are rpm install onto the machine. The some of beats logs size were as big as 58GB. The beats messages says the elasticsearch is no longer available. Even though we can see elasticsearch still have space and plenty of room still.

We have destroy the environment and respin a new elasticsearch cluster. but I am just trying to figure out what would have cause this to happen and how to avoid it.

---

<div class="post-metadata">

### Author: ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)
#### Post date: [February 12, 2020, 10:38am UTC](https://discuss.elastic.co/t/beats-configuration-help/216081/6 "2020-02-12T10:38:24Z")

</div>

> [@Walter\_Hiranpat](#):
>
> The beats messages says the elasticsearch is no longer available.

I think you should focus on investigating this, beats are going to continue logging errors if the problem connecting with Elasticsearch persists.

It is weird in any case that the beats logs reach 58GB, they should be rotated before according to the default log settings [Configure logging | Metricbeat Reference [7.5] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/7.5/configuration-logging.html) Have you tried to modify these logging options?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 11, 2020, 12:38pm UTC](https://discuss.elastic.co/t/beats-configuration-help/216081/7 "2020-03-11T12:38:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
