# Filebeat isn’t assuming the configuration from beat.yml

**URL:** <https://discuss.elastic.co/t/filebeat-isn-t-assuming-the-configuration-from-beat-yml/377850>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 6, 2025, 10:51am UTC](https://discuss.elastic.co/t/filebeat-isn-t-assuming-the-configuration-from-beat-yml/377850 "2025-05-06T10:51:59Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![dglsilva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dglsilva/32/142956_2.png) [@dglsilva](https://discuss.elastic.co/u/dglsilva)\
**Post date:** [May 6, 2025, 10:51am UTC](https://discuss.elastic.co/t/filebeat-isn-t-assuming-the-configuration-from-beat-yml/377850/1 "2025-05-06T10:51:59Z")

</div>

Hello everyone,

I've been trying to get my eck-stack to work, but filebeat and logstash aren't getting along very well.

On the logstash side I saw that it is opening the 5044 beats port and listening.

However Filebeat isn't using the configured logstash output (or even elasticsearch output that I tried) and just tries what I would think is the default output. When I run "filebeat test output" inside one of the pods I get this:

filebeat test output  
elasticsearch: elasticsearch:9200...  
parse url... OK  
connection...  
parse host... OK  
dns lookup... ERROR lookup elasticsearch on 10.43.0.10:53: server misbehaving

Here is what I have configured in the values.yaml:

```auto
config:
  logging.level: debug
  filebeat.autodiscover:
     providers:
       - type: kubernetes
         node: ${NODE_NAME}
         hints.enabled: true
         in_cluster: true
         ssl.certificate_authorities:
          - /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
         hints.default_config:
           type: filestream
           id: kubernetes-container-logs-${data.kubernetes.pod.name}-${data.kubernetes.container.id}
           paths:
           - /var/log/containers/*-${data.kubernetes.container.id}.log
           parsers:
           - container:
               stream: all
               format: auto
           prospector:
            scanner:
              fingerprint.enabled: true
              symlinks: true
           file_identity.fingerprint: ~
  output.logstash:
    hosts: ["logstash.svc:5044"]
    ssl.enabled: false

```
