# Filebeat works for Centos 5.7

**URL:** <https://discuss.elastic.co/t/filebeat-works-for-centos-5-7/76800>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 28, 2017, 2:52pm UTC](https://discuss.elastic.co/t/filebeat-works-for-centos-5-7/76800 "2017-02-28T14:52:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ravikumar\_G](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Post date:** [February 28, 2017, 2:52pm UTC](https://discuss.elastic.co/t/filebeat-works-for-centos-5-7/76800/1 "2017-02-28T14:52:16Z")

</div>

I'm trying for while but not sure filebeat supports centos 5.7 able to install but no luck to strat it any sugessition would be helpful.  
uname -a

2.6.18-274.el5 #1 SMP Fri Jul 8 17:36:59 EDT 2011 x86\_64 x86\_64 x86\_64 GNU/Linux

[root@ccdn-cm-40303-01 (bmcs1) rguttu001c]# rpm --delsign filebeat-5.1.1-i686.rpm  
filebeat-5.1.1-i686.rpm:  
error: filebeat-5.1.1-i686.rpm: open failed: No such file or directory  
[root@xxxxxxxx (bmcs1) rguttu001c]# rpm --delsign filebeat-5.2.1-x86\_64.rpm  
filebeat-5.2.1-x86\_64.rpm:  
[root@xxxxxxx (bmcs1) rguttu001c]# sudo yum -y localinstall --nogpgcheck filebeat-5.2.1-x86\_64.rpm  
Loaded plugins: product-id, security, subscription-manager  
Updating Red Hat repositories.  
Setting up Local Package Process  
Examining filebeat-5.2.1-x86\_64.rpm: filebeat-5.2.1-1.x86\_64  
Marking filebeat-5.2.1-x86\_64.rpm to be installed  
Resolving Dependencies  
--\> Running transaction check  
---\> Package filebeat.x86\_64 0:5.2.1-1 set to be updated  
--\> Finished Dependency Resolution

Dependencies Resolved

# ============================================================================================================================================================================================================ Package Arch Version Repository Size

Installing:  
filebeat x86\_64 5.2.1-1 /filebeat-5.2.1-x86\_64 27 M

# Transaction Summary

Install 1 Package(s)  
Upgrade 0 Package(s)

Total size: 27 M  
Downloading Packages:  
Running rpm\_check\_debug  
Running Transaction Test  
Finished Transaction Test  
Transaction Test Succeeded  
Running Transaction  
Installing : filebeat 1/1  
duration: 0(ms)  
Installed products updated.

Installed:  
filebeat.x86\_64 0:5.2.1-1

Complete!  
[root@ccdn-cm-40303-01 (bmcs1) rguttu001c]# service filebeat start  
Starting filebeat: 2017/02/28 14:44:30.167254 beat.go:267: INFO Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat]  
2017/02/28 14:44:30.167293 beat.go:177: INFO Setup Beat: filebeat; Version: 5.2.1  
2017/02/28 14:44:30.167478 output.go:167: INFO Loading template enabled. Reading template file: /etc/filebeat/filebeat.template.json  
2017/02/28 14:44:30.167843 output.go:178: INFO Loading template enabled for Elasticsearch 2.x. Reading template file: /etc/filebeat/filebeat.template-es2x.json  
2017/02/28 14:44:30.168148 client.go:120: INFO Elasticsearch url: [http://localhost:9200](http://localhost:9200)  
2017/02/28 14:44:30.168197 outputs.go:106: INFO Activated elasticsearch as output plugin.  
2017/02/28 14:44:30.168300 publish.go:291: INFO Publisher name: xxxxx  
2017/02/28 14:44:30.168469 logp.go:219: INFO Metrics logging every 30s  
2017/02/28 14:44:30.168519 async.go:63: INFO Flush Interval set to: 1s  
2017/02/28 14:44:30.168537 async.go:64: INFO Max Bulk Size set to: 50  
Config OK  
FATAL: kernel too old  
/bin/bash: line 1: 2664 Segmentation fault /usr/share/filebeat/bin/filebeat-god -r / -n -p /var/run/filebeat.pid -- /usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat  
[FAILED]

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 28, 2017, 3:57pm UTC](https://discuss.elastic.co/t/filebeat-works-for-centos-5-7/76800/2 "2017-02-28T15:57:55Z")

</div>

Bottom line: Filebeat is not supported on RHEL 5. See the [support matrix](https://www.elastic.co/support/matrix).

The problem you have encountered is with the `filebeat-god` processes which was compiled for a newer version of libc IIRC. So probably if you run `filebeat.sh -e` Filebeat will start up. But if you use `service filebeat start` it will fail. You could hack the /etc/init.d/filebeat script to not use `filebeat-god` or you could compile `filebeat-god` for your system (source is [here](https://github.com/tsg/go-daemon)).

---

<div class="post-metadata">

**Author:** ![Ravikumar\_G](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Post date:** [February 28, 2017, 4:20pm UTC](https://discuss.elastic.co/t/filebeat-works-for-centos-5-7/76800/3 "2017-02-28T16:20:34Z")

</div>

Thanks for your advice it worked perfectly able to ship logs

its there a way i can run as service 🙂

---

<div class="post-metadata">

**Author:** ![Ravikumar\_G](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Post date:** [March 2, 2017, 4:39pm UTC](https://discuss.elastic.co/t/filebeat-works-for-centos-5-7/76800/4 "2017-03-02T16:39:50Z")

</div>

@andrewkroh fixed thanks for your support

l I had to do is create an alternate version of the startup script

this is a workaround solution

the new init.d script is:

```bash
#!/bin/bash
#
# filebeat: Startup script for Filebeat Log Shipper.
#
# chkconfig: 3 80 05
# description: Startup script for Filebeat Log Shipper standalone

FILEBEAT_HOME=/root;
export FILEBEAT_HOME

start() {
       echo -n "Starting Filebeat: "
       echo "Starting Filebeat at `date`" >> $FILEBEAT_HOME/startup.log
       /usr/share/filebeat/bin/filebeat \
      -path.home /usr/share/filebeat \
      -path.config /etc/filebeat \
      -path.data /var/lib/filebeat \
      -path.logs /var/log/filebeat -e &
       sleep 2
       echo "done"
}

stop() {
       echo -n "Stopping Filebeat: "
       echo "Stopping Filebeat at `date`" >> $FILEBEAT_HOME/startup.log
       su $FILEBEAT_OWNER -c "pkill filebeat"
       echo "done"
}

# See how we were called.
case "$1" in
       start)
               start
               ;;
       stop)
               stop
               ;;
       restart)
               stop
               start
               ;;
       status)
               if pgrep -fl "/usr/share/filebeat/bin/filebeat" > /dev/null;then echo running;else echo not running;fi
               ;;
       *)
               echo $"Usage: filebeat {start|stop|restart}"
               exit
esac

```

````auto
# Make the file executable
$ chmod +x /etc/init.d/filebeat-standalone
```

Worked with out issues :)
````

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2017, 4:39pm UTC](https://discuss.elastic.co/t/filebeat-works-for-centos-5-7/76800/5 "2017-03-30T16:39:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
