# Filebeats ingesting filebeats logs

**URL:** <https://discuss.elastic.co/t/filebeats-ingesting-filebeats-logs/225272>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 26, 2020, 7:13pm UTC](https://discuss.elastic.co/t/filebeats-ingesting-filebeats-logs/225272 "2020-03-26T19:13:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![newmember](https://avatars.discourse-cdn.com/v4/letter/n/ce7236/32.png) [@newmember](https://discuss.elastic.co/u/newmember)\
**Post date:** [March 26, 2020, 7:13pm UTC](https://discuss.elastic.co/t/filebeats-ingesting-filebeats-logs/225272/1 "2020-03-26T19:13:35Z")

</div>

At first I added **/var/log/filebeat/filebeat** as an input in the " **inputs.d/filebeat.yml**" folder.

This created a circular logging issue; ie filebeat would write data to the filebeat log file then re-read that log event in the filebeat log and send it again and then the round robin thing happens.

I stopped filebeat  
I removed the **inputs.d/filebeat.yml**  
I renamed the filebeat cache registry folder " **mv registry registry.old.0325**"  
I then restarted filebeat service

I still see filebeat reading in the filebeat logs.

What did I miss?

Thanks

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 26, 2020, 7:50pm UTC](https://discuss.elastic.co/t/filebeats-ingesting-filebeats-logs/225272/2 "2020-03-26T19:50:53Z")

</div>

Hi,

A few questions to get started:

1. Which version of Filebeat are you using?

2. Could you post your complete Filebeat configuration file?

3. Could you `grep` for `/var/log/filebeat` in `inputs.d/*`, just to make sure it's not there?

4. Could you `grep` for `/var/log/filebeat` in the current Filebeat registry file and post the results here?

5. Also, could you post the output of `lsof -c filebeat`?

Thanks,

Shaunak

---

<div class="post-metadata">

**Author:** ![newmember](https://avatars.discourse-cdn.com/v4/letter/n/ce7236/32.png) [@newmember](https://discuss.elastic.co/u/newmember)\
**Post date:** [March 27, 2020, 1:53am UTC](https://discuss.elastic.co/t/filebeats-ingesting-filebeats-logs/225272/3 "2020-03-27T01:53:04Z")

</div>

Thank you for the quick response. You are great.

As I was gathering things I had one more thought, which was likely the cause or causes. Its interesting that the config passed the test. "filebeat config test"

a.  
"enabed" typo  
b.  
indent was a tab and not two spaces  
c.  
At first I renamed the yml file with an OLD extension to remove this input.

```
[yoyo@traumtech02 etc]# cat /etc/filebeat/inputs.d/filebeat_log.yml.OLD
- type: log

  # Change to true to enable this input configuration.
# enabled: true
  enabed: false
  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /var/log/filebeat/*
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2020, 1:53am UTC](https://discuss.elastic.co/t/filebeats-ingesting-filebeats-logs/225272/4 "2020-04-24T01:53:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
