# Debian 7.9 Filebeat 6.5.4 wrong path

**URL:** <https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 22, 2019, 2:59pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261 "2019-01-22T14:59:20Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abraxas](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@Abraxas](https://discuss.elastic.co/u/Abraxas)\
**Post date:** [January 22, 2019, 2:59pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261/1 "2019-01-22T14:59:20Z")

</div>

Hi,  
I am running Debian 7.9 and I have installed filebeat 6.5.4 with apt-get.  
For some reason it starts with wrong paths:  
INFO instance/beat.go:592 Home path: [/usr/share/filebeat/bin] Config path: [/usr/share/filebeat/bin] Data path: [/usr/share/filebeat/bin/data] Logs path: [/usr/share/filebeat/bin/logs]

The init.d/filebeat script seems to be setting them ok:  
PATH=/sbin:/usr/sbin:/bin:/usr/bin  
DESC="Filebeat sends log files to Logstash or directly to Elasticsearch."  
NAME="filebeat"  
DAEMON=/usr/share/{NAME}/bin/{NAME}  
DAEMON\_ARGS="-c /etc/{NAME}/{NAME}.yml -path.home /usr/share/{NAME} -path.config /etc/{NAME} -path.data /var/lib/{NAME} -path.logs /var/log/{NAME}"  
TEST\_ARGS="-e test config"  
PIDFILE=/var/run/filebeat.pid  
WRAPPER="/usr/share/{NAME}/bin/{NAME}-god"  
BEAT\_USER="root"  
WRAPPER\_ARGS="-r / -n -p $PIDFILE"  
SCRIPTNAME=/etc/init.d/filebeat

Is the wrapper messing them up? Any idea how I could fix this?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 22, 2019, 4:01pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261/2 "2019-01-22T16:01:37Z")

</div>

Have you systemd installed or still SysV with init scripts?

Also check your filebeat config file. This file can also overwrite paths.

---

<div class="post-metadata">

**Author:** ![Abraxas](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@Abraxas](https://discuss.elastic.co/u/Abraxas)\
**Post date:** [January 23, 2019, 9:31am UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261/3 "2019-01-23T09:31:31Z")

</div>

Thank you for the reply!  
Still using SysV, and the lines above are from the init script.

In the filebeat config file I only have a config for the modules:  
path: ${path.config}/modules.d/_.yml  
I already tried to manually set it to  
path: /etc/filebeat/modules.d/_.yml  
with no change.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 23, 2019, 12:09pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261/4 "2019-01-23T12:09:33Z")

</div>

Hm. Can you add an `echo ...` before start-stop-daemon so to print the full command to be executed?

---

<div class="post-metadata">

**Author:** ![Abraxas](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@Abraxas](https://discuss.elastic.co/u/Abraxas)\
**Post date:** [January 23, 2019, 12:48pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261/5 "2019-01-23T12:48:33Z")

</div>

This is the output:  
start-stop-daemon --start --pidfile /var/run/filebeat.pid --exec /usr/share/filebeat/bin/filebeat-god -- -r / -n -p /var/run/filebeat.pid -- /usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 24, 2019, 1:13pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261/6 "2019-01-24T13:13:00Z")

</div>

Did anyone modify your init script?

See init script template: [https://github.com/elastic/beats/blob/b17e12c8be44d137ec8cdaffa0a7e07b89219107/dev-tools/packaging/templates/deb/init.sh.tmpl](https://github.com/elastic/beats/blob/b17e12c8be44d137ec8cdaffa0a7e07b89219107/dev-tools/packaging/templates/deb/init.sh.tmpl)

Original start function

```auto
do_start()
{
	# Return
	# 0 if daemon has been started
	# 1 if daemon was already running
	# 2 if daemon could not be started
	start-stop-daemon --start \
                --pidfile $PIDFILE \
		--exec $WRAPPER -- $WRAPPER_ARGS -- $DAEMON $DAEMON_ARGS \
		|| return 2
}

```

`$DAEMON_ARGS` should include the flags setting the paths.

---

<div class="post-metadata">

**Author:** ![Abraxas](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@Abraxas](https://discuss.elastic.co/u/Abraxas)\
**Post date:** [January 24, 2019, 9:15pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261/7 "2019-01-24T21:15:28Z")

</div>

You are right, something is wrong with the DAEMON\_ARGS var.  
I did not modify it:  
DAEMON\_ARGS="-c /etc/{NAME}/{NAME}.yml -path.home /usr/share/{NAME} -path.config /etc/{NAME} -path.data /var/lib/{NAME} -path.logs /var/log/{NAME}"

For some reason it only keeps " -c /etc/filebeat/filebeat.yml "

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 25, 2019, 12:31pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261/8 "2019-01-25T12:31:25Z")

</div>

This is weird. If DAEMON\_ARGS is not modified, it should expand in completion. It's just a string.

Can you try to replace every occurrence of `$DAEMON_ARGS` with the right hand side of DAEMON\_ARGS?

e.g.

```auto
do_start()
{
	# Return
	# 0 if daemon has been started
	# 1 if daemon was already running
	# 2 if daemon could not be started
	start-stop-daemon --start \
                --pidfile $PIDFILE \
		--exec $WRAPPER -- $WRAPPER_ARGS -- $DAEMON -c /etc/${NAME}/${NAME}.yml -path.home /usr/share/${NAME} -path.config /etc/${NAME} -path.data /var/lib/${NAME} -path.logs /var/log/${NAME} \
		|| return 2
}

```

---

<div class="post-metadata">

**Author:** ![Abraxas](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@Abraxas](https://discuss.elastic.co/u/Abraxas)\
**Post date:** [January 25, 2019, 3:30pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261/9 "2019-01-25T15:30:52Z")

</div>

I already tried initially to replace only in do\_start and it did not work.  
After replacing every occurrence it started ok.

Thanks for the help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2019, 3:30pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261/10 "2019-02-22T15:30:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
