# Filebeat System Module - Multi-line Log Generating One Log Per Line

**URL:** <https://discuss.elastic.co/t/filebeat-system-module-multi-line-log-generating-one-log-per-line/236410>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 9, 2020, 7:18pm UTC](https://discuss.elastic.co/t/filebeat-system-module-multi-line-log-generating-one-log-per-line/236410 "2020-06-09T19:18:53Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![uklipse](https://avatars.discourse-cdn.com/v4/letter/u/cdc98d/32.png) [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Post date:** [June 15, 2020, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-system-module-multi-line-log-generating-one-log-per-line/236410/7 "2020-06-15T21:06:02Z")

</div>

So I figured out what was going on. Metricbeat by default will send it's logs to syslog even if you have it defined in the metricbeat.yml config file not to so the filebeat system module was still picking this up. I was able to override the default setting based on this post and this resolved the issue.

> [@Metribeat 7.1.1 not logging to files, only syslog always](https://discuss.elastic.co/t/metribeat-7-1-1-not-logging-to-files-only-syslog-always/187088):
>
> Hello Metricbeat does not stop sending logs to syslog. Even after parameter in metricbeat.yml: logging.to\_syslog: false This happens if you run metricbeat (ubuntu 16.04): service metricbeat start It helps only run with command: /usr/share/metricbeat/bin/metricbeat -c /etc/metricbeat/metricbeat.yml -path.logs /var/log/metricbeat I also noticed that when running through systemd, command has option "-e": /usr/share/metricbeat/bin/metricbeat -e -c /etc/metricbeat/metricbeat.yml ... There m…

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-system-module-multi-line-log-generating-one-log-per-line/236410)._
