# Filebeat 7.0.0

**URL:** <https://discuss.elastic.co/t/filebeat-7-0-0/179478>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 3, 2019, 6:32am UTC](https://discuss.elastic.co/t/filebeat-7-0-0/179478 "2019-05-03T06:32:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pascal72](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@Pascal72](https://discuss.elastic.co/u/Pascal72)\
**Post date:** [May 3, 2019, 6:32am UTC](https://discuss.elastic.co/t/filebeat-7-0-0/179478/1 "2019-05-03T06:32:18Z")

</div>

Hi,

I have recently upgraded my ELK infrastructure to version 7.0.0. On my elasticsearch nodes, I have also upgraded the filebeat component. The configuration is quite simple, I have only activated the elasticsearch module to index elasticsearch logs. I don't harvest any other logs.  
By doing like this, I see that the filebeat log is not written in /var/log/filebeat/filebeat but directly sent to /var/log/messages.  
If I disable the elasticsearch module, the /var/log/filebeat/filebeat is created and populated.

Is it the normal behaviour ?

Regards,  
Pascal

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2019, 6:32am UTC](https://discuss.elastic.co/t/filebeat-7-0-0/179478/2 "2019-05-31T06:32:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
