# Change log output of Filebeat

**URL:** <https://discuss.elastic.co/t/change-log-output-of-filebeat/138184>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 2, 2018, 11:01am UTC](https://discuss.elastic.co/t/change-log-output-of-filebeat/138184 "2018-07-02T11:01:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![solo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/solo/32/29084_2.png) [@solo](https://discuss.elastic.co/u/solo)\
**Post date:** [July 2, 2018, 11:01am UTC](https://discuss.elastic.co/t/change-log-output-of-filebeat/138184/1 "2018-07-02T11:01:28Z")

</div>

My logs path is: /var/log/filebeat

How can i change it to /opt/filebeat/log/filebeat.log ?

I cant see any options for changing this in my filebeat.yml file. I only have this:

```
#================================ Logging =====================================

# Sets log level. The default log level is info.
# Available log levels are: error, warning, info, debug
#logging.level: debug

# At debug level, you can selectively enable logging only for some components.
# To enable all selectors use ["*"]. Examples of other selectors are "beat",
# "publish", "service".
#logging.selectors: ["*"]

```

Tried to look at [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-logging.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-logging.html) but it didnt help me.

---

<div class="post-metadata">

**Author:** ![harshbajaj16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshbajaj16/32/44970_2.png) [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Post date:** [July 2, 2018, 11:30am UTC](https://discuss.elastic.co/t/change-log-output-of-filebeat/138184/2 "2018-07-02T11:30:24Z")

</div>

Hi,

Please find below configuration to change the paths. this is the generic you can try according to your requirement.

```
#================================= Paths ======================================

# The home path for the filebeat installation. This is the default base path
# for all other path settings and for miscellaneous files that come with the
# distribution (for example, the sample dashboards).
# If not set by a CLI flag or in the configuration file, the default for the
# home path is the location of the binary.
#path.home:

# The configuration path for the filebeat installation. This is the default
# base path for configuration files, including the main YAML configuration file
# and the Elasticsearch template file. If not set by a CLI flag or in the
# configuration file, the default for the configuration path is the home path.
#path.config: ${path.home}

# The data path for the filebeat installation. This is the default base path
# for all the files in which filebeat needs to store its data. If not set by a
# CLI flag or in the configuration file, the default for the data path is a data
# subdirectory inside the home path.
#path.data: ${path.home}/data

# The logs path for a filebeat installation. This is the default location for
# the Beat's log files. If not set by a CLI flag or in the configuration file,
# the default for the logs path is a logs subdirectory inside the home path.
#path.logs: ${path.home}/logs

```

Regards,  
Harsh

---

<div class="post-metadata">

**Author:** ![solo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/solo/32/29084_2.png) [@solo](https://discuss.elastic.co/u/solo)\
**Post date:** [July 2, 2018, 11:47am UTC](https://discuss.elastic.co/t/change-log-output-of-filebeat/138184/3 "2018-07-02T11:47:44Z")

</div>

Ive added the following to my filebeat.yml:

```
#================================= Paths ======================================

# The home path for the filebeat installation. This is the default base path
# for all other path settings and for miscellaneous files that come with the
# distribution (for example, the sample dashboards).
# If not set by a CLI flag or in the configuration file, the default for the
# home path is the location of the binary.
#path.home:

# The configuration path for the filebeat installation. This is the default
# base path for configuration files, including the main YAML configuration file
# and the Elasticsearch template file. If not set by a CLI flag or in the
# configuration file, the default for the configuration path is the home path.
#path.config: ${path.home}

# The data path for the filebeat installation. This is the default base path
# for all the files in which filebeat needs to store its data. If not set by a
# CLI flag or in the configuration file, the default for the data path is a data
# subdirectory inside the home path.
#path.data: ${path.home}/data

# The logs path for a filebeat installation. This is the default location for
# the Beat's log files. If not set by a CLI flag or in the configuration file,
# the default for the logs path is a logs subdirectory inside the home path.
path.logs: /opt/filebeat/logs

```

Then I get the same log path:

> sudo service filebeat restart  
> 2018-07-02T13:45:00.966+0200 INFO instance/beat.go:468 Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat]  
> 2018-07-02T13:45:00.967+0200 INFO instance/beat.go:475 Beat UUID: 1f9e07f3-e887-4ad5-9e6e-1ca6f371dfcd  
> 2018-07-02T13:45:00.967+0200 INFO instance/beat.go:213 Setup Beat: filebeat; Version: 6.2.4  
> 2018-07-02T13:45:00.968+0200 INFO pipeline/module.go:76 Beat name: xxxxxx

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2018, 11:47am UTC](https://discuss.elastic.co/t/change-log-output-of-filebeat/138184/4 "2018-07-30T11:47:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
