# Filebeat is not reading logs

**URL:** <https://discuss.elastic.co/t/filebeat-is-not-reading-logs/321794>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 21, 2022, 7:05pm UTC](https://discuss.elastic.co/t/filebeat-is-not-reading-logs/321794 "2022-12-21T19:05:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ant2ne](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@ant2ne](https://discuss.elastic.co/u/ant2ne)\
**Post date:** [December 21, 2022, 7:05pm UTC](https://discuss.elastic.co/t/filebeat-is-not-reading-logs/321794/1 "2022-12-21T19:05:55Z")

</div>

root@ub2204elk:/etc/elasticsearch# grep -v "#" elasticsearch.yml |uniq

```auto
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
network.host: localhost

xpack.security.enabled: true

xpack.security.enrollment.enabled: true

xpack.security.http.ssl:
  enabled: false
  keystore.path: certs/http.p12

xpack.security.transport.ssl:
  enabled: true
  verification_mode: certificate
  keystore.path: certs/transport.p12
  truststore.path: certs/transport.p12
cluster.initial_master_nodes: ["ub2204elk"]

http.host: 0.0.0.0

```

root@ub2204elk:/etc/filebeat# l grep -v "#" /etc/filebeat/filebeat.yml |uniq

```auto
filebeat.inputs:

- type: filestream
  id: my-filestream-id
  enabled: false
  paths:
    - /var/log/sys1/*.log

filebeat.config.modules:
  path: /etc/filebeat/modules.d/modules.d/*.yml
  reload.enabled: false

setup.template.settings:
  index.number_of_shards: 1

setup.kibana:
  host: "localhost:5601"

output.elasticsearch:
  hosts: ["localhost:9200"]

  username: "elastic"
  password: "oRPweOskO3ODRgI6Hik-"

processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

```

rsyslog is doing its thing correctly both remote and local elk/rsyslog server. The remote server's logs are in the elk/rsyslog server's /var/log/{remote.servername}.

These are the logs I am most interested in.  
root@ub2204elk:/etc/filebeat# ls -l /var/log/sys1/\*.log

```auto
-rw-r----- 1 syslog adm 270 Dec 21 18:34 /var/log/sys1/anacron.log
-rw-r----- 1 syslog adm 245 Dec 21 17:20 /var/log/sys1/avahi-daemon.log
-rw-r----- 1 syslog adm 63 Dec 21 17:24 /var/log/sys1/cron.log
-rw-r----- 1 syslog adm 36846 Dec 21 18:53 /var/log/sys1/CRON.log
-rw-r----- 1 syslog adm 298 Dec 21 17:23 /var/log/sys1/crontab.log
-rw-r----- 1 syslog adm 2837 Dec 21 18:52 /var/log/sys1/dbus-daemon.log
-rw-r----- 1 syslog adm 172 Dec 21 18:48 /var/log/sys1/fwupd.log
-rw-r----- 1 syslog adm 2249 Dec 21 17:38 /var/log/sys1/kernel.log
-rw-r----- 1 syslog adm 132 Dec 21 18:41 /var/log/sys1/NetworkManager.log
-rw-r----- 1 syslog adm 1119 Dec 21 18:40 /var/log/sys1/nordvpnd.log
-rw-r----- 1 syslog adm 181 Dec 21 17:20 /var/log/sys1/ntpd.log
-rw-r----- 1 syslog adm 4792 Dec 21 18:51 /var/log/sys1/org.freedesktop.thumbnails.Thumb.log
-rw-r----- 1 syslog adm 259 Dec 21 18:14 /var/log/sys1/root.log
-rw-r----- 1 syslog adm 3957 Dec 21 17:32 /var/log/sys1/rsyslogd.log
-rw-r----- 1 syslog adm 24552 Dec 21 18:51 /var/log/sys1/rtkit-daemon.log
-rw-r----- 1 syslog adm 593 Dec 21 17:57 /var/log/sys1/sudo.log
-rw-r----- 1 syslog adm 32889 Dec 21 18:53 /var/log/sys1/systemd.log

```

But, in [http://192.168.1.139:5601](http://192.168.1.139:5601) | discover | Logs | Streams does not show any logs.

Am I looking in the correct place in Kibana for the remote server's logs? If so, Why isn't filebeats putting the logs into ealsticsearch?

(please let me know if you need a peak at any other conf files)

---

<div class="post-metadata">

**Author:** ![Lee\_Hinman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lee_hinman/32/74973_2.png) [@Lee\_Hinman](https://discuss.elastic.co/u/Lee_Hinman)\
**Post date:** [December 21, 2022, 8:33pm UTC](https://discuss.elastic.co/t/filebeat-is-not-reading-logs/321794/2 "2022-12-21T20:33:03Z")

</div>

the filestream input isn't enabled you have:

```auto
enabled: false

```

change that to:

```auto
enabled: true

```

---

<div class="post-metadata">

**Author:** ![ant2ne](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@ant2ne](https://discuss.elastic.co/u/ant2ne)\
**Post date:** [December 21, 2022, 8:43pm UTC](https://discuss.elastic.co/t/filebeat-is-not-reading-logs/321794/3 "2022-12-21T20:43:15Z")

</div>

> [@Lee\_Hinman](#):
>
> `enabled: true`

**I owe you a beer!** As soon as I made that change, the logs showed up in streaming!

(I intentionally have smbd flapping on sys1 every min (via cron) to generate logs for testing)

 ![filebeat.tadaa](https://us1.discourse-cdn.com/elastic/original/3X/7/f/7f3158eb53e48359ee2b07df84d0746525ac1ed8.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2023, 10:44pm UTC](https://discuss.elastic.co/t/filebeat-is-not-reading-logs/321794/4 "2023-01-18T22:44:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
