I have recently upgraded my ELK infrastructure to version 7.0.0. On my elasticsearch nodes, I have also upgraded the filebeat component. The configuration is quite simple, I have only activated the elasticsearch module to index elasticsearch logs. I don't harvest any other logs.
By doing like this, I see that the filebeat log is not written in /var/log/filebeat/filebeat but directly sent to /var/log/messages.
If I disable the elasticsearch module, the /var/log/filebeat/filebeat is created and populated.
Is it the normal behaviour ?