# Filebeat errors after update to version 7

**URL:** <https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 26, 2019, 9:31am UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607 "2019-04-26T09:31:16Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![cawa](https://avatars.discourse-cdn.com/v4/letter/c/258eb7/32.png) [@cawa](https://discuss.elastic.co/u/cawa)\
**Post date:** [April 26, 2019, 9:31am UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/1 "2019-04-26T09:31:16Z")

</div>

I get a flood of errors since updating the cluster and filebeat to version 7.  
My setup consists of a 2 node elasticsearch cluster and a bunch of servers running filebeat with modules (system, auditd and nginx) shipping logs directly to the es cluster.

I get these `Cannot write to a field alias [host.hostname].` and `Can't get text on a START_OBJECT at 1:***` from every module.

Things I already tried:

- Running filebeat setup

- Deleting the index

- Updating config a bit

(First error is shortened because of char limit)

---

<div class="post-metadata">

**Author:** ![cawa](https://avatars.discourse-cdn.com/v4/letter/c/258eb7/32.png) [@cawa](https://discuss.elastic.co/u/cawa)\
**Post date:** [April 26, 2019, 9:31am UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/2 "2019-04-26T09:31:53Z")

</div>

My config:

```
  ########################### Filebeat Configuration ############################

  #========================== Modules configuration ============================

  filebeat.modules:

  #------------------------------- System Module -------------------------------
  - module: system
    # Syslog
    syslog:
      enabled: true

    # Authorization logs
    auth:
      enabled: true

  #-------------------------------- Audit Module -------------------------------
  - module: auditd
    log:
      enabled: true

  #-------------------------------- Nginx Module -------------------------------
  - module: nginx
    # Access logs
    access:
      enabled: true

      # Set custom paths for the log files. If left empty,
      # Filebeat will choose the paths depending on your OS.
      var.paths: 
        - /var/log/nginx/access.log
        - /var/log/nginx/flo_access.log

      # Input configuration (advanced). Any input configuration option
      # can be added under this section.
      #input:

    # Error logs
    error:
      enabled: true

      # Set custom paths for the log files. If left empty,
      # Filebeat will choose the paths depending on your OS.
      var.paths:
        - /var/log/nginx/error.log
        - /var/log/nginx/flo_error.log

      # Input configuration (advanced). Any input configuration option
      # can be added under this section.
      #input:

  #=========================== Filebeat inputs =============================

  filebeat.inputs:

  # Each - is an input. Most options can be set at the input level, so
  # you can use different inputs for various configurations.
  # Below are the input specific configurations.

  - type: log
    enabled: true
    paths:
      - /opt/tomcat/logs/flo-gui-web.log
      - /opt/tomcat/logs/flo-integration.log

    ### Multiline options
    multiline.pattern: ^([0-9]{4}-[0-9]{2}-[0-9]{2}\s[0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3})
    multiline.negate: true
    multiline.match: after

  - type: log
    enabled: true
    paths:
      - /opt/tomcat/logs/catalina*.log

    ### Multiline options
    multiline.pattern: ^\s{8}
    multiline.negate: false
    multiline.match: after

  #============================= Filebeat modules ===============================

  filebeat.config.modules:
    # Glob pattern for configuration loading
    path: ${path.config}/modules.d/*.yml

    # Set to true to enable config reloading
    reload.enabled: false

    # Period on which files under path should be checked for changes
    #reload.period: 10sFF

  #================================ General =====================================

  # The name of the shipper that publishes the network data. It can be used to group
  # all the transactions sent by a single shipper in the web interface.
  name: server1

  # The tags of the shipper are included in their own field with each
  # transaction published.
  #tags: ["service-X", "web-tier"]

  # Optional fields that you can specify to add additional information to the
  # output.
  #fields:
  # env: staging

  #============================== Dashboards =====================================

  # These settings control loading the sample dashboards to the Kibana index. Loading
  # the dashboards is disabled by default and can be enabled either by setting the
  # options here, or by using the `-setup` CLI flag or the `setup` command.
  setup.dashboards.enabled: false

  # The URL from where to download the dashboards archive. By default this URL
  # has a value which is computed based on the Beat name and version. For released
  # versions, this URL points to the dashboard archive on the artifacts.elastic.co
  # website.
  #setup.dashboards.url:

  #============================== Kibana =====================================

  # Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.
  # This requires a Kibana endpoint configuration.
  setup.kibana:

    # Kibana Host
    # Scheme and port can be left out and will be set to the default (http and 5601)
    # In case you specify and additional path, the scheme is required: http://localhost:5601/path
    # IPv6 addresses should always be defined as: https://[2001:db8::1]:5601
    host: "logs.host.com"

  #================================ Outputs =====================================

  # Configure what output to use when sending the data collected by the beat.

  #----------------------------- Elasticsearch output --------------------------------
  output.elasticsearch:
    # The Elasticsearch hosts
    hosts: ["logs.host.com:9200"]
    index: "filebeat-%{[beat.version]}-%{+xxxx.ww}"

  setup.template.name: "filebeat-7"
  setup.template.pattern: "filebeat-7*"
  setup.template.settings:
    index.number_of_shards: 2
    index.number_of_replicas: 1
  #================================ Logging =====================================

  # Sets log level. The default log level is info.
  # Available log levels are: error, warning, info, debug
  #logging.level: debug

  # At debug level, you can selectively enable logging only for some components.
  # To enable all selectors use ["*"]. Examples of other selectors are "beat",
  # "publish", "service".
  #logging.selectors: ["*"]
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 26, 2019, 3:35pm UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/3 "2019-04-26T15:35:21Z")

</div>

Which filebeat versions did you upgrade from?

Do you have some more complete logs in the Elasticsearch log files?

---

<div class="post-metadata">

**Author:** ![cawa](https://avatars.discourse-cdn.com/v4/letter/c/258eb7/32.png) [@cawa](https://discuss.elastic.co/u/cawa)\
**Post date:** [April 29, 2019, 8:45am UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/4 "2019-04-29T08:45:40Z")

</div>

From 6.7 or 6.6.1

Here you can have a look at the startup log of filebeat:  
[https://pastebin.com/raw/U2YuPLjw](https://pastebin.com/raw/U2YuPLjw)

The error messages are so plenty that it fills up disks really fast

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 29, 2019, 2:58pm UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/5 "2019-04-29T14:58:52Z")

</div>

Which templates are installed? This looks like a mapping error.

---

<div class="post-metadata">

**Author:** ![cawa](https://avatars.discourse-cdn.com/v4/letter/c/258eb7/32.png) [@cawa](https://discuss.elastic.co/u/cawa)\
**Post date:** [April 29, 2019, 4:37pm UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/6 "2019-04-29T16:37:26Z")

</div>

with "filebeat export template" i get this:  
[https://pastebin.com/raw/MM5w16hD](https://pastebin.com/raw/MM5w16hD)

Or what do you mean?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 30, 2019, 10:54am UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/7 "2019-04-30T10:54:51Z")

</div>

I mean the templates already registered with Elasticsearch.

```auto
curl http://<host>:9200/_template/filebeat*

```

Have you had a Filebeat 5.x installation in the past? In this case you might have a template that overlaps with the Filebeat 6.x/7.x templates.

---

<div class="post-metadata">

**Author:** ![cawa](https://avatars.discourse-cdn.com/v4/letter/c/258eb7/32.png) [@cawa](https://discuss.elastic.co/u/cawa)\
**Post date:** [April 30, 2019, 11:29am UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/8 "2019-04-30T11:29:49Z")

</div>

No filebeat 5.x installed previously, i think 6.4 was current when I setup stuff up for the first time.

Anyway heres the output:  
[https://pastebin.com/raw/SU6xBUdj](https://pastebin.com/raw/SU6xBUdj)

And here the output curling just for filebeat-7\*:  
[https://pastebin.com/raw/4QVKrHXZ](https://pastebin.com/raw/4QVKrHXZ)

Thanks for the support so far 😄

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 2, 2019, 12:49pm UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/9 "2019-05-02T12:49:00Z")

</div>

I found this likely very old template in your output:

```auto
  "filebeat": {
    "order": 1,
    "index_patterns": [
      "filebeat-*"
    ],
    "settings": {
      "index": {
        "mapping": {
          "total_fields": {
            "limit": "10000"
          }
        },
        "refresh_interval": "5s",
        "number_of_routing_shards": "30",
        "number_of_shards": "1",
        "number_of_replicas": "1"
      }
    },
    ...
 }

```

---

<div class="post-metadata">

**Author:** ![cawa](https://avatars.discourse-cdn.com/v4/letter/c/258eb7/32.png) [@cawa](https://discuss.elastic.co/u/cawa)\
**Post date:** [May 2, 2019, 2:08pm UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/10 "2019-05-02T14:08:25Z")

</div>

Thanks, deleting that and running filebeat setup again seems to have fixed the issue.  
I would have never found this, thanks a bunch!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 30, 2019, 2:08pm UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607/11 "2019-05-30T14:08:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
