# Filebeat.yml not recognized environment variable

**URL:** <https://discuss.elastic.co/t/filebeat-yml-not-recognized-environment-variable/350087>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [December 28, 2023, 2:59pm UTC](https://discuss.elastic.co/t/filebeat-yml-not-recognized-environment-variable/350087 "2023-12-28T14:59:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alejandro\_Avila\_Pere](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alejandro_avila_pere/32/124156_2.png) [@Alejandro\_Avila\_Pere](https://discuss.elastic.co/u/Alejandro_Avila_Pere)\
**Post date:** [December 28, 2023, 2:59pm UTC](https://discuss.elastic.co/t/filebeat-yml-not-recognized-environment-variable/350087/1 "2023-12-28T14:59:37Z")

</div>

Hello everyone, I am trying to obtain the logs generated by the console in a container that has a backend with the ECS format from the `@elastic/ecs-winston-format` library, with a filebeat service. However, it does not recognize the environment variables specified in the service definition, so for it to connect correctly I have to literally pass the address. I leave you my current configuration hoping someone can help me. Thank you very much in advance

docker-compose.yml file

```auto
version: '3.9'

services:
  node_microservice:
    container_name: node_bff_microservice
    image: node_microservice
    restart: always
    build:
      context: .
      dockerfile: Dockerfile
    environment:
      - ENV=local:docker
      - HOST=0.0.0.0
      - PORT=3336
    ports:
      - '3336:3336'
    networks:
      - elk
    labels:
      co.elastic.logs/json.overwrite_keys: 'true'
      co.elastic.logs/json.add_error_key: 'true'
      co.elastic.logs/json.expand_keys: 'true'
  filebeat:
    container_name: filebeat
    image: docker.elastic.co/beats/filebeat:8.11.3
    user: root
    command: >
      --strict.perms=false -e
      -E output.elasticsearch.hosts=elasticsearch:9400
    volumes:
      - ./filebeat.yml:/usr/share/filebeat/filebeat.yml:ro
      - /var/lib/docker/containers:/var/lib/docker/containers:ro
      - /var/run/docker.sock:/var/run/docker.sock:ro
    environment:
      - ELASTICSEARCH_HOST=elasticsearch:9200
      - KIBANA_HOST=kibana:5601
      - ELASTICSEARCH_USERNAME=elastic
      - ELASTICSEARCH_PASSWORD=change
    networks:
      - elk

networks:
  elk:
    external: true

```

filebeat.yml

```auto
filebeat.config:
  modules:
    path: ${path.config}/modules.d/*.yml
    reload.enabled: false

filebeat.autodiscover:
  providers:
    - type: docker
      hints.enabled: true

processors:
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_host_metadata: ~

setup.kibana:
  host: "${ KIBANA_HOST:kibana:5601 }"

output.elasticsearch:
  hosts: "${ ELASTICSEARCH_HOST:elasticsearch:9200 }". => If I remove the default value it doesn't work
  #username: ${ELASTICSEARCH_USERNAME}
  #password: ${ELASTICSEARCH_PASSWORD}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 31, 2023, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-yml-not-recognized-environment-variable/350087/2 "2023-12-31T18:52:09Z")

</div>

Hi @Alejandro_Avila_Pere Welcome to the community.

> [@Alejandro\_Avila\_Pere](#):
>
> `${ ELASTICSEARCH_HOST`

Silly question why do have that leading space?

`${ ELASTICSEARCH_HOST`  
`..^`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 28, 2024, 8:52pm UTC](https://discuss.elastic.co/t/filebeat-yml-not-recognized-environment-variable/350087/3 "2024-01-28T20:52:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
