# Filebeat 7.3 logging output

**URL:** <https://discuss.elastic.co/t/filebeat-7-3-logging-output/193788>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 5, 2019, 12:10pm UTC](https://discuss.elastic.co/t/filebeat-7-3-logging-output/193788 "2019-08-05T12:10:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mesmer](https://avatars.discourse-cdn.com/v4/letter/m/0ea827/32.png) [@Mesmer](https://discuss.elastic.co/u/Mesmer)\
**Post date:** [August 5, 2019, 12:10pm UTC](https://discuss.elastic.co/t/filebeat-7-3-logging-output/193788/1 "2019-08-05T12:10:22Z")

</div>

I just upgraded from Filebeat 7.0 to Filebeat 7.3 and i notice that it's defaulting back to /var/log/messages output error logs, even though it was configured to have separate logs.

The filebeat process is running the -e flag:

Here's the full PID:

> ```
> /usr/share/filebeat/bin/filebeat -e -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat
> 
> ```

Also having this config in filebeat.yml:

```
logging.to_syslog: false
logging.to_files: true
logging.files:
  path: /var/log/filebeat
  name: filebeat
  keepfiles: 7
  permissions: 0644

```

Anyone else having these issues with Filebeat 7.3 or am i missing something?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2019, 12:10pm UTC](https://discuss.elastic.co/t/filebeat-7-3-logging-output/193788/2 "2019-09-02T12:10:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
