# Filebeat panics on CentOS 7.2 when stdin is defined as an input

**URL:** <https://discuss.elastic.co/t/filebeat-panics-on-centos-7-2-when-stdin-is-defined-as-an-input/52450>\
**Category:** Beats\
**Created:** [June 10, 2016, 2:40pm UTC](https://discuss.elastic.co/t/filebeat-panics-on-centos-7-2-when-stdin-is-defined-as-an-input/52450 "2016-06-10T14:40:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gaahrdner](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gaahrdner](https://discuss.elastic.co/u/gaahrdner)\
**Post date:** [June 10, 2016, 2:40pm UTC](https://discuss.elastic.co/t/filebeat-panics-on-centos-7-2-when-stdin-is-defined-as-an-input/52450/1 "2016-06-10T14:40:55Z")

</div>

I can't seem to get `stdin` working as an input for `filebeat` when it's running as service under `systemd`.

```
[root@x.x.x.x log]# hostnamectl
   Static hostname:xxxx
Transient hostname:xxxx
         Icon name: computer-vm
           Chassis: vm
        Machine ID: f32e0af35637b5dfcbedcb0a1de8dca1
           Boot ID: 480bcc8e58e6492b92927c8528700be7
    Virtualization: xen
  Operating System: CentOS Linux 7 (Core)
       CPE OS Name: cpe:/o:centos:centos:7
            Kernel: Linux 3.10.0-327.18.2.el7.x86_64
      Architecture: x86-64
[root@x.x.x.x log]# filebeat -version
filebeat version 1.2.3 (amd64)

```

For reference, here is my configuration, two `log` prospectors and a `stdin` prospector:

```
############################# Filebeat ######################################
filebeat:
  prospectors:
    - input_type: stdin
    -
      input_type: log
      paths:
        - /var/lib/mesos/slave/slaves/*/frameworks/*/executors/*/runs/latest/stdout
      fields:
        log_level: stdout
    -
      input_type: log
      paths:
        - /var/lib/mesos/slave/slaves/*/frameworks/*/executors/*/runs/latest/stderr
      fields:
        log_level: stderr
  registry_file: /var/lib/filebeat/registry

###############################################################################
############################# Libbeat Config ##################################
# Base config file used by all other beats for using libbeat features

############################# Output ##########################################

# Configure what outputs to use when sending the data collected by the beat.
# Multiple outputs may be used.
output:

  ### Elasticsearch as output
  elasticsearch:
    # Array of hosts to connect to.
    # Scheme and port can be left out and will be set to the default (http and 9200)
    # In case you specify and additional path, the scheme is required: http://localhost:9200/path
    # IPv6 addresses should always be defined as: https://[2001:db8::1]:9200
    hosts: ["x.x.x.x:9200"]

    index: "filebeat"

    # A template is used to set the mapping in Elasticsearch
    # By default template loading is disabled and no template is loaded.
    # These settings can be adjusted to load your own template or overwrite existing ones
    # template:
    # name: "filebeat"
    # path: "/etc/filebeat/filebeat.template.json"
    # overwrite: true

############################# Shipper #########################################

shipper:

############################# Logging #########################################

logging:
  to_syslog: true

```

Running this in debug mode throws no errors: [https://gist.github.com/gaahrdner/0929a773337801c01a18251f7a1bfdc9](https://gist.github.com/gaahrdner/0929a773337801c01a18251f7a1bfdc9)

However, when restarting the service, filebeat panics: [https://gist.github.com/gaahrdner/d29d15cacbb809f12dd5aa20ec305814](https://gist.github.com/gaahrdner/d29d15cacbb809f12dd5aa20ec305814)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 10, 2016, 11:38pm UTC](https://discuss.elastic.co/t/filebeat-panics-on-centos-7-2-when-stdin-is-defined-as-an-input/52450/2 "2016-06-10T23:38:57Z")

</div>

running filebeat as service fails, due to stdin being closed by systemd. Never use stdin, when running filebeat as standalone service. `stdin` is some special mode (inherited from logstash-forwarder) used to push generated content from scripts via filebeat to logstash/elasticsearch.

---

<div class="post-metadata">

**Author:** ![gaahrdner](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gaahrdner](https://discuss.elastic.co/u/gaahrdner)\
**Post date:** [June 13, 2016, 1:42pm UTC](https://discuss.elastic.co/t/filebeat-panics-on-centos-7-2-when-stdin-is-defined-as-an-input/52450/3 "2016-06-13T13:42:56Z")

</div>

Ok, thanks for your response Steffen. I was attempting to follow the DC/OS documents for logging which specified using logstash-forwarder and `stdin` as input to accept entries from `jouranlctl`, so I'll need to figure out how to do this with filebeat or switch back to `logstash-forwarder`. I'd rather use filebeat, as you an imagine.

[https://docs.mesosphere.com/1.7/administration/logging/elk/](https://docs.mesosphere.com/1.7/administration/logging/elk/)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 13, 2016, 5:06pm UTC](https://discuss.elastic.co/t/filebeat-panics-on-centos-7-2-when-stdin-is-defined-as-an-input/52450/4 "2016-06-13T17:06:59Z")

</div>

How do you run filebeat? The document referenced by you says, write a `logstash.sh` script piping journald output to logstash-forwarder. And run [logstash.sh](http://logstash.sh) script as a service (create systemd service file for custom script and so on). This can be done with filebeat [too.In](http://too.In) your script just run:

```auto
$ journalctl <all-your-opts> | filebeat -c /etc/filebeat/filebeat.yml

```

But you can not pipe to any process running somewhere in background unless you use a fifo, but no idea fifo files are supported by filebeat (most likely not).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 1, 2016, 2:40pm UTC](https://discuss.elastic.co/t/filebeat-panics-on-centos-7-2-when-stdin-is-defined-as-an-input/52450/5 "2016-07-01T14:40:59Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
