# Filebeat is running, but can't detect filelogs is changed

**URL:** <https://discuss.elastic.co/t/filebeat-is-running-but-cant-detect-filelogs-is-changed/143253>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 7, 2018, 7:17am UTC](https://discuss.elastic.co/t/filebeat-is-running-but-cant-detect-filelogs-is-changed/143253 "2018-08-07T07:17:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Quang\_Tho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quang_tho/32/34192_2.png) [@Quang\_Tho](https://discuss.elastic.co/u/Quang_Tho)\
**Post date:** [August 7, 2018, 7:17am UTC](https://discuss.elastic.co/t/filebeat-is-running-but-cant-detect-filelogs-is-changed/143253/1 "2018-08-07T07:17:35Z")

</div>

I am deploy filebeat for shipping docker logs to elk.  
Filebeat is running but cannot ship log to logstash.  
is any missing here, please check for me.

--- docker-compose.yml -----

```auto
version: "3.6"
services:
################# WEB ###################
  nginx:
      image: nginx:1.14.0
      ports:
        - 80:80
      volumes:
        - type: volume
          source: nginx-config
          target: /etc/nginx
        - type: volume
          source: nginx-doc-root
          target: /usr/share/nginx/html
      deploy:
        replicas: 1
        placement:
          constraints:
           - node.labels.type == web

  filebeat:
    image: docker.elastic.co/beats/filebeat:6.3.2
    volumes:
      - type: volume
        source: filebeat-config
        target: /usr/share/filebeat/
    deploy:
      replicas: 1
      placement:
        constraints:
         - node.labels.type == web

################### MONITOR ###############
  elasticsearch:
    image: docker.elastic.co/elasticsearch/elasticsearch:6.3.2
    ports:
      - 9200:9200
      - 9300:9300
    environment:
      ES_JAVA_OPTS: "-Xms512m -Xmx512m"
    volumes:
      - type: volume
        source: elasticsearch
        target: /usr/share/elasticsearch/config/
    deploy:
      replicas: 1
      placement:
        constraints:
          - node.labels.type == monitor

#### indexer
  logstash:
    image: docker.elastic.co/logstash/logstash:6.3.2
    ports:
      - 5044:5044
    volumes:
      - type: volume
        source: logstash-p
        target: /usr/share/logstash/pipeline/
      - type: volume
        source: logstash-config
        target: /usr/share/logstash/config/
    depends_on:
      - elasticsearch
    deploy:
      replicas: 1
      placement:
        constraints:
         - node.labels.type == monitor

### UI
  kibana:
    image: docker.elastic.co/kibana/kibana:6.3.2
    ports:
      - 5601:5601
    environment:
      ELASTICSEARCH_URL: http://elasticsearch:9200
    depends_on:
      - elasticsearch
    volumes:
      - type: volume
        source: kibana
        target: /usr/share/kibana/config
    deploy:
      replicas: 1
      placement:
        constraints:
         - node.labels.type == monitor

volumes:
  elasticsearch:
  logstash-p:
  logstash-config:
  kibana:
  filebeat-config:
  nginx-config:
  nginx-doc-root:
```

Here are filebeat.yml for test.

```auto
filebeat.inputs:
- type: log
  paths:
    - /var/lib/docker/containers/*/*.log

logging.level: debug
logging.selectors: ["*"]

output.console:
  pretty: true
```

Some logs from Filebeat:

```auto
2018-08-07T07:11:58.774Z INFO [monitoring] log/log.go:124 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":370,"time":{"ms":5}},"total":{"ticks":660,"time":{"ms":9},"value":660},"user":{"ticks":290,"time":{"ms":4}}},"info":{"ephemeral_id":"cb1e279d-16f2-4c1f-a72b-f0acaa155a84","uptime":{"ms":1530041}},"memstats":{"gc_next":4194304,"memory_alloc":1749184,"memory_total":12509528}}, **"filebeat":{"harvester":{"open_files":0,"running":0}},**"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":2,"events":{"active":0}}},"registrar":{"states":{"current":0}},"system":{"load":{"1":0.04,"15":0.05,"5":0.06,"norm":{"1":0.01,"15":0.0125,"5":0.015}}}}}}
```

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 7, 2018, 10:40am UTC](https://discuss.elastic.co/t/filebeat-is-running-but-cant-detect-filelogs-is-changed/143253/2 "2018-08-07T10:40:59Z")

</div>

Hi @Quang_Tho and welcome 🙂

`filebeat` needs access to the log files, in your configuration the input path is set to `/var/lib/docker/containers/*/*.log`, that is a path in the host, but this path is not mounted as a volume in the filebeat docker.  
You may also want to use the [`add_docker_metadata` processor](https://www.elastic.co/guide/en/beats/filebeat/6.3/add-docker-metadata.html) or the [docker autodiscover provider](https://www.elastic.co/guide/en/beats/filebeat/6.3/configuration-autodiscover.html#_docker_2), in that case you will also need to mount the docker socket.

Regarding shipping the logs to logstash, in your configuration the output is set to console only, if you want the logs to be shipped to logstash you need to configure a [logstash output](https://www.elastic.co/guide/en/beats/filebeat/6.3/logstash-output.html) instead.

---

<div class="post-metadata">

**Author:** ![Quang\_Tho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quang_tho/32/34192_2.png) [@Quang\_Tho](https://discuss.elastic.co/u/Quang_Tho)\
**Post date:** [August 9, 2018, 4:24am UTC](https://discuss.elastic.co/t/filebeat-is-running-but-cant-detect-filelogs-is-changed/143253/3 "2018-08-09T04:24:21Z")

</div>

@jsoriano  
it is working.  
thanks you very much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2018, 4:24am UTC](https://discuss.elastic.co/t/filebeat-is-running-but-cant-detect-filelogs-is-changed/143253/4 "2018-09-06T04:24:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
