# Filebeat and metricbeat logs ending up in /var/log/messages

**URL:** <https://discuss.elastic.co/t/filebeat-and-metricbeat-logs-ending-up-in-var-log-messages/374134>\
**Category:** Elastic Agent\
**Tags:** beats-module, filebeat, metricbeat\
**Created:** [February 5, 2025, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-and-metricbeat-logs-ending-up-in-var-log-messages/374134 "2025-02-05T15:18:10Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![umesh2020](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umesh2020/32/126038_2.png) [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Post date:** [February 5, 2025, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-and-metricbeat-logs-ending-up-in-var-log-messages/374134/1 "2025-02-05T15:18:10Z")

</div>

I am seeing that metricbeat/filebeat running on Linux are logging their messages to /var/log/messages instead of file. Here is my configuration:

```auto
logging.level: info
logging.to_syslog: false
logging.to_files: true
logging.files:
  path: /var/log/metricbeat
  name: metricbeat
  keepfiles: 7
  permissions: 0644

```

```auto
logging.level: info
logging.to_syslog: false
logging.to_files: true
logging.files:
  path: /var/log/filebeat
  name: filebeat
  keepfiles: 7
  permissions: 0644

```

I am using metricbeat version 8.17.1. I also looked into this discussion and ([Metricbeats logging into /var/log/messages - #2 by stephenb](https://discuss.elastic.co/t/metricbeats-logging-into-var-log-messages/315316/2)) and confirmed that BEAT\_LOG\_OPTS is set in my service file

```auto
[Service]

Environment="BEAT_LOG_OPTS="
Environment="BEAT_CONFIG_OPTS=-c /etc/metricbeat/metricbeat.yml"
Environment="BEAT_PATH_OPTS=--path.home /usr/share/metricbeat --path.config /etc/metricbeat --path.data /var/lib/metricbeat --path.logs /var/log/metricbeat"
ExecStart=/usr/share/metricbeat/bin/metricbeat --environment systemd $BEAT_LOG_OPTS $BEAT_CONFIG_OPTS $BEAT_PATH_OPTS
Restart=always

```

Appreciate your help in resolving this.

---

<div class="post-metadata">

**Author:** ![umesh2020](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umesh2020/32/126038_2.png) [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Post date:** [February 10, 2025, 6:53pm UTC](https://discuss.elastic.co/t/filebeat-and-metricbeat-logs-ending-up-in-var-log-messages/374134/2 "2025-02-10T18:53:39Z")

</div>

Looks like enabling --environment systemd options logs the outputs by default to stderr and stdout even though logging.to\_files is set to true. Not sure if this is expected behaviour or not
