# Failed to start filebeat. Ubuntu 16.04

**URL:** https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520
**Category:** Beats
**Tags:** filebeat
**Created:** [November 29, 2017, 6:53am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520 "2017-11-29T06:53:51Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![purpleturtle99](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@purpleturtle99](https://discuss.elastic.co/u/purpleturtle99)
#### Post date: [November 29, 2017, 6:53am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520/1 "2017-11-29T06:53:52Z")

</div>

When I run: sudo systemctl status filebeat on my Ubuntu16.04 client  
I get the following error:  
Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; vendor preset:  
Active: failed (Result: exit-code) since Wed 2017-11-29 06:46:57 GMT; 2s ago  
Docs: [https://www.elastic.co/guide/en/beats/filebeat/current/index.html](https://www.elastic.co/guide/en/beats/filebeat/current/index.html)  
Process: 23097 ExecStart=/usr/share/filebeat/bin/filebeat -c /etc/filebeat/fil  
Main PID: 23097 (code=exited, status=1/FAILURE)

Nov 29 06:46:57 ubu-1704 systemd[1]: filebeat.service: Main process exited, code  
Nov 29 06:46:57 ubu-1704 systemd[1]: filebeat.service: Unit entered failed state  
Nov 29 06:46:57 ubu-1704 systemd[1]: filebeat.service: Failed with result 'exit-  
Nov 29 06:46:57 ubu-1704 systemd[1]: filebeat.service: Service hold-off time ove  
Nov 29 06:46:57 ubu-1704 systemd[1]: Stopped filebeat.  
Nov 29 06:46:57 ubu-1704 systemd[1]: filebeat.service: Start request repeated to  
Nov 29 06:46:57 ubu-1704 systemd[1]: Failed to start filebeat.  
Nov 29 06:46:57 ubu-1704 systemd[1]: filebeat.service: Unit entered failed state  
Nov 29 06:46:57 ubu-1704 systemd[1]: filebeat.service: Failed with result 'exit-  
here is a copy of my /etc/filebeat/filebeat.yml  
###################### Filebeat Configuration Example #########################

# This file is an example configuration file highlighting only the most common

# options. The filebeat.full.yml file from the same directory contains all the

# supported options with more comments. You can use it as a reference.

# 

# You can find the full configuration reference here:

# [https://www.elastic.co/guide/en/beats/filebeat/index.html](https://www.elastic.co/guide/en/beats/filebeat/index.html)

#=========================== Filebeat prospectors =============================

filebeat.prospectors:

# Each - is a prospector. Most options can be set at the prospector level, so

# you can use different prospectors for various configurations.

# Below are the prospector specific configurations.

```
- input_type:syslog

```

# Paths that should be crawled and fetched. Glob based paths.

paths:  
#- /var/log/\*.log  
- /var/log/auth.log  
- /var/log/syslog  
#- c:\programdata\elasticsearch\logs\*

# Exclude lines. A list of regular expressions to match. It drops the lines that are

# matching any regular expression from the list.

#exclude\_lines: ["^DBG"]

# Include lines. A list of regular expressions to match. It exports the lines that are

# matching any regular expression from the list.

#include\_lines: ["^ERR", "^WARN"]

# Exclude files. A list of regular expressions to match. Filebeat drops the files that

# are matching any regular expression from the list. By default, no files are dropped.

#exclude\_files: [".gz$"]

# Optional additional fields. These field can be freely picked

# to add additional information to the crawled log files for filtering

#fields:

# level: debug

# review: 1

### Multiline options

# Mutiline can be used for log messages spanning multiple lines. This is common

# for Java Stack Traces or C-Line Continuation

# The regexp Pattern that has to be matched. The example pattern matches all lines starting with [

#multiline.pattern: ^[

# Defines if the pattern set under pattern should be negated or not. Default is false.

#multiline.negate: false

# Match can be set to "after" or "before". It is used to define if lines should be append to a pattern

# that was (not) matched before or after or as long as a pattern is not matched based on negate.

# Note: After is the equivalent to previous and before is the equivalent to to next in Logstash

#multiline.match: after

#================================ General =====================================

# The name of the shipper that publishes the network data. It can be used to group

# all the transactions sent by a single shipper in the web interface.

#name:

# The tags of the shipper are included in their own field with each

# transaction published.

#tags: ["service-X", "web-tier"]

# Optional fields that you can specify to add additional information to the

# output.

#fields:

# env: staging

#================================ Outputs =====================================

# Configure what outputs to use when sending the data collected by the beat.

# Multiple outputs may be used.

#-------------------------- Elasticsearch output ------------------------------  
#output.elasticsearch:

# Array of hosts to connect to.

#hosts: ["localhost:9200"]

# Optional protocol and basic auth credentials.

#protocol: "https"  
#username: "elastic"  
#password: "changeme"

#----------------------------- Logstash output --------------------------------  
output.logstash:

# The Logstash hosts

```
    hosts: ["elk-master:5443"]

```

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

ssl.certificate\_authorities: ["/etc/filebeat/logstash.crt"]  
[template.name](http://template.name): "filebeat"  
template.path: "filebeat.template.json"  
template.overwrite: false

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

#================================ Logging =====================================

# Sets log level. The default log level is info.

# Available log levels are: critical, error, warning, info, debug

#logging.level: debug

# At debug level, you can selectively enable logging only for some components.

# To enable all selectors use ["\*"]. Examples of other selectors are "beat",

# "publish", "service".

#logging.selectors: ["\*"]

Also when I tried to run  
sudo filebeat -configtest -c filebeat.yml -e  
I get this: sudo: filebeat: command not found but filebeat is installed  
filebeat is already the newest version (5.6.4).

All help appreciated

---

<div class="post-metadata">

### Author: ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)
#### Post date: [November 29, 2017, 10:52am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520/2 "2017-11-29T10:52:39Z")

</div>

Could you check logs under `/var/log/filebeat`? It should give you some insights on what's going on. You can paste them here if you don't get it fixed

---

<div class="post-metadata">

### Author: ![purpleturtle99](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@purpleturtle99](https://discuss.elastic.co/u/purpleturtle99)
#### Post date: [November 29, 2017, 11:47am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520/3 "2017-11-29T11:47:48Z")

</div>

Thanks for the advise Carlos. But there aren't any log file/s in there for filebeat in /var/logt????

---

<div class="post-metadata">

### Author: ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)
#### Post date: [November 29, 2017, 2:33pm UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520/4 "2017-11-29T14:33:30Z")

</div>

Sorry,

What version and package type of filebeat are you using?

---

<div class="post-metadata">

### Author: ![purpleturtle99](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@purpleturtle99](https://discuss.elastic.co/u/purpleturtle99)
#### Post date: [November 30, 2017, 5:15am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520/5 "2017-11-30T05:15:44Z")

</div>

filebeat is already the newest version (5.6.4) is what I get when trying to run sudo apt install filebeat

---

<div class="post-metadata">

### Author: ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)
#### Post date: [November 30, 2017, 11:06am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520/6 "2017-11-30T11:06:21Z")

</div>

Perhaps you can try to launch filebeat by hand and see what's the error, just run:

```auto
# sudo filebeat -e -v

```

---

<div class="post-metadata">

### Author: ![purpleturtle99](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@purpleturtle99](https://discuss.elastic.co/u/purpleturtle99)
#### Post date: [December 1, 2017, 2:14pm UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520/7 "2017-12-01T14:14:08Z")

</div>

ubu\_1704@ubu-1704:/var/log$ sudo filebeat -e -v  
[sudo] password for ubu\_1704:  
sudo: filebeat: command not found

this is what I get

---

<div class="post-metadata">

### Author: ![purpleturtle99](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@purpleturtle99](https://discuss.elastic.co/u/purpleturtle99)
#### Post date: [December 3, 2017, 7:44am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520/8 "2017-12-03T07:44:46Z")

</div>

There is no log files and also installed filebeat on a Centos machine same result fails to start and no logfiles  
either

version filebeat -5.6.4-1 .x86\_64

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 31, 2017, 7:44am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-ubuntu-16-04/109520/9 "2017-12-31T07:44:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
