# Filebeat's logs doesn't create

**URL:** <https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710>\
**Category:** Logstash\
**Created:** [October 16, 2022, 6:01pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710 "2022-10-16T18:01:02Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![sevbans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sevbans/32/112112_2.png) [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Post date:** [October 16, 2022, 6:01pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/1 "2022-10-16T18:01:02Z")

</div>

This is my current configuration file.

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/*.log

output.elasticsearch:
  hosts: ["localhost:9200"]
  username: "elastic"
  password: "1"
  enabled: false

output.logstash:
  hosts: ["localhost:5044"]
  enabled: true

output.console:
  pretty: true

setup.dashboards.enabled: true
setup.kibana:
  host: "localhost:5601"

```

I trying send apache logs to Elasticsearch with filebeat. But it doesn't work properly. Logstash listening port 5044 but my logs doesn't send elasticsearch. How can i solve?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 16, 2022, 6:58pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/2 "2022-10-16T18:58:10Z")

</div>

Any traces in filebeat log?

---

<div class="post-metadata">

**Author:** ![sevbans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sevbans/32/112112_2.png) [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Post date:** [October 16, 2022, 7:27pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/3 "2022-10-16T19:27:27Z")

</div>

it's main problem. there aren't any log in /var/log/filebeat.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 16, 2022, 7:42pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/4 "2022-10-16T19:42:53Z")

</div>

> [@sevbans](#):
>
> ```auto
> output.elasticsearch:
> hosts: ["localhost:9200"]
> username: "elastic"
> password: "1"
> enabled: false
> 
> output.logstash:
> hosts: ["localhost:5044"]
> enabled: true
> 
> output.console:
> pretty: true
> 
> ```

You can't have more than one output enabled, in your cause you have the logstash output and the console output enabled, it will not work.

Filebeat supports only one output at time.

Also, per default filebeat will not create a log file, it will log to stdout, so you should look at `/var/log/messages` or `/var/log/syslog`, depending on your linux distribution.

---

<div class="post-metadata">

**Author:** ![sevbans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sevbans/32/112112_2.png) [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Post date:** [October 16, 2022, 8:16pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/5 "2022-10-16T20:16:57Z")

</div>

Ok. new configuration file:

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/*.log

output.elasticsearch:
  hosts: ["localhost:9200"]
  username: "elastic"
  #password: "1"
  enabled: false

output.logstash:
  hosts: ["localhost:5044"]
  enabled: true

output.console:
  pretty: false

setup.dashboards.enabled: true
setup.kibana:
  host: "localhost:5601"

```

not different. it doesn't send apache logs to elasticsearch.

---

<div class="post-metadata">

**Author:** ![sevbans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sevbans/32/112112_2.png) [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Post date:** [October 16, 2022, 8:23pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/6 "2022-10-16T20:23:25Z")

</div>

my logstash.conf file.

```auto
input {
        beats {
                port => "5044"
        }
}

filter {
        grok {
                match => { "message" => "%{COMBINEDAPACHELOG}" }
        }
        date {
                match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
        }
}

output {
        elasticsearch {
                hosts => ["localhost:9200"]
                index => "apache"
        }

        stdout {}

}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 16, 2022, 8:25pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/7 "2022-10-16T20:25:25Z")

</div>

> [@sevbans](#):
>
> ```auto
> output.console:
> pretty: false
> 
> ```

This is still wrong, it needs to be `enabled: false`, check the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/console-output.html#_enabled_26).

My suggestion is to **remove** these disabled outputs from `filebeat.yml`, let only the logstash output.

---

<div class="post-metadata">

**Author:** ![sevbans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sevbans/32/112112_2.png) [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Post date:** [October 16, 2022, 9:06pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/8 "2022-10-16T21:06:00Z")

</div>

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/*.log

output.logstash:
  hosts: ["localhost:5044"]
  enabled: true

setup.dashboards.enabled: true
setup.kibana:
  host: "localhost:5601"

```

still same. there is nothing on index management.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 16, 2022, 9:53pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/9 "2022-10-16T21:53:07Z")

</div>

You need to provide some logs, without it is impossible to know what the issue may be.

Check the `/var/log/messages` or `/var/log/syslog` for filebeat logs, also check `/var/log/logstash/logstash-plain.log` for logstash logs and `/var/log/elasticsearch/YOUR-CLUSTER.log` for some elasticsearch logs.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 16, 2022, 9:58pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/10 "2022-10-16T21:58:29Z")

</div>

Start filebeat to show live activities

1. filebeat -c filebeat.yml -e  
Must show something, either cannot connect to LS server or registry database already read a file  
Default is /usr/share/filebeat/data/registry

2. Enable logging with debug mode

```auto
logging.level: debug
logging.to_files: true
logging.files:
  path: /path/log
  name: filebeat.log
  keepfiles: 7
  permissions: 0644

```

1. Read [Common problems](https://www.elastic.co/guide/en/beats/filebeat/current/faq.html), Elastic team collected common problems.

2. Check `/var/log/logstash/logstash-plain.log`

---

<div class="post-metadata">

**Author:** ![sevbans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sevbans/32/112112_2.png) [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Post date:** [October 17, 2022, 6:40pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/11 "2022-10-17T18:40:02Z")

</div>

It's works. Thanks bro.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2022, 6:40pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710/12 "2022-11-14T18:40:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
