# \[FIlebeat\] How to get logs default paths for modules?

**URL:** <https://discuss.elastic.co/t/filebeat-how-to-get-logs-default-paths-for-modules/252648>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 20, 2020, 8:37am UTC](https://discuss.elastic.co/t/filebeat-how-to-get-logs-default-paths-for-modules/252648 "2020-10-20T08:37:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [October 20, 2020, 8:37am UTC](https://discuss.elastic.co/t/filebeat-how-to-get-logs-default-paths-for-modules/252648/1 "2020-10-20T08:37:59Z")

</div>

Hello !

I'm using Filebeat (7.8) and module system.

For the **var.paths** of the **syslog fileset** , documentation says : "If this setting is left empty, Filebeat will choose log paths based on your operating system."

How can I get a list of these log path based on my operating system ? I would like to be sure that all required logs are well collected

Thanks for your help ! 🙂

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [October 20, 2020, 9:01am UTC](https://discuss.elastic.co/t/filebeat-how-to-get-logs-default-paths-for-modules/252648/2 "2020-10-20T09:01:04Z")

</div>

Such list do not exist, sorry. If you know the logs you want to parse, just set them in `var.paths`. It's the best way to get all logs you require.

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [October 20, 2020, 9:48am UTC](https://discuss.elastic.co/t/filebeat-how-to-get-logs-default-paths-for-modules/252648/3 "2020-10-20T09:48:55Z")

</div>

Thanks for your response @Mario_Castro

OK. Any way to get that list maybe by a debug function ?

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [October 27, 2020, 1:53pm UTC](https://discuss.elastic.co/t/filebeat-how-to-get-logs-default-paths-for-modules/252648/4 "2020-10-27T13:53:34Z")

</div>

Found ! 🙂

> <https://github.com/elastic/beats/blob/master/filebeat/module/system/auth/manifest.yml#L5>

  

> <https://github.com/elastic/beats/blob/master/filebeat/module/system/syslog/manifest.yml#L5>

@Mario_Castro

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2020, 3:53pm UTC](https://discuss.elastic.co/t/filebeat-how-to-get-logs-default-paths-for-modules/252648/5 "2020-11-24T15:53:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
