# Fileset 6.4.0: Error: elasticsearch/log is configured but doesn't exist

**URL:** <https://discuss.elastic.co/t/fileset-6-4-0-error-elasticsearch-log-is-configured-but-doesnt-exist/146921>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 31, 2018, 10:23pm UTC](https://discuss.elastic.co/t/fileset-6-4-0-error-elasticsearch-log-is-configured-but-doesnt-exist/146921 "2018-08-31T22:23:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alsheh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alsheh/32/36799_2.png) [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Post date:** [August 31, 2018, 10:23pm UTC](https://discuss.elastic.co/t/fileset-6-4-0-error-elasticsearch-log-is-configured-but-doesnt-exist/146921/1 "2018-08-31T22:23:16Z")

</div>

I'm using the Filebeat Elasticsearch module introduced in filebeat 6.4.0, but I get this error when I run filebeat:

```auto
ERROR	[autodiscover]	cfgfile/list.go:104	Error creating runner from config: Fileset elasticsearch/log is configured but doesn't exist

```

Any ideas why the Filebeat Elasticsearch module isn't working as expected?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 3, 2018, 8:16am UTC](https://discuss.elastic.co/t/fileset-6-4-0-error-elasticsearch-log-is-configured-but-doesnt-exist/146921/2 "2018-09-03T08:16:33Z")

</div>

Could you please share your full config formatted using `</>`?

---

<div class="post-metadata">

**Author:** ![Alsheh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alsheh/32/36799_2.png) [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Post date:** [September 5, 2018, 11:14pm UTC](https://discuss.elastic.co/t/fileset-6-4-0-error-elasticsearch-log-is-configured-but-doesnt-exist/146921/3 "2018-09-05T23:14:38Z")

</div>

@kvch  
Please find below the config file. I think the reason why I get the error mentioned above is because I'm running filebeat and elasticsearch inside separate docker containers so filebeat doesn't have access to elasticsearch log path. Sharing a volume between the two containers might resolve the problem.

```auto
filebeat.config.modules:
  enabled: true
  path: /usr/share/filebeat/modules.d/*.yml

filebeat.autodiscover:
  providers:
    - type: docker
      templates:
        - condition:
            contains:
              docker.container.image: elasticsearch
          config:
            - module: elasticsearch
              log:
                input:
                  type: docker
                  containers:
                    path: '/usr/share/filebeat/containers/'
                    stream: 'all'
                    ids:
                      - '${data.docker.container.id}'

output.elasticsearch:
  hosts: '${ES_HOSTS}'
setup.kibana:
  host: "kibana"

xpack.monitoring.enabled: True

```

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 6, 2018, 7:28am UTC](https://discuss.elastic.co/t/fileset-6-4-0-error-elasticsearch-log-is-configured-but-doesnt-exist/146921/4 "2018-09-06T07:28:30Z")

</div>

The problem is that Filebeat cannot find the `elasticsearch/log` fileset you configured. Is `/usr/share/filebeat/module` is accessible to Filebeat and contains the fileset?

---

<div class="post-metadata">

**Author:** ![Alsheh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alsheh/32/36799_2.png) [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Post date:** [September 6, 2018, 5:45pm UTC](https://discuss.elastic.co/t/fileset-6-4-0-error-elasticsearch-log-is-configured-but-doesnt-exist/146921/5 "2018-09-06T17:45:40Z")

</div>

Running the commands below inside the filebeat container indicates that the module filesets are accessible to filebeat:

```auto
[root@773170d8886b module]# pwd
/usr/share/filebeat/module
[root@773170d8886b module]# ls
apache2 elasticsearch iis kibana mongodb nginx postgresql system
auditd icinga kafka logstash mysql osquery redis traefik
[root@773170d8886b module]# ls elasticsearch/
audit deprecation gc module.yml server slowlog
[root@773170d8886b module]#

```

I shared a volume between elasticsearch (points to`/usr/share/elasticsearch/logs`) and filebeat (points to `/var/log/elasticsearch`) and I change the `log` fileset to the `server` fileset in the filebeat config

```auto
           ...
          config:
            - module: elasticsearch
              server: # <----------------- Using server fileset
                input:
                  type: docker
                  containers:
          ...

```

but the only logs being collected is for the `gc` fileset. I tried different filebsets such as `audit`, `deprecation`, `slowlog` but still I am only getting the `gc` fileset logs. Listing the content of where the elasticsearch are in filebeat container shows the following:

```auto
[root@773170d8886b module]# ls /var/log/elasticsearch/
gc.log gc.log.01 gc.log.03 gc.log.05 gc.log.07 gc.log.09 gc.log.11
gc.log.00 gc.log.02 gc.log.04 gc.log.06 gc.log.08 gc.log.10 gc.log.12

```

Listing the content of the elasticsearch logs folder inside the elasticsearch container:

```auto
[elasticsearch@e038c94710e0 ~]$ pwd
/usr/share/elasticsearch
[elasticsearch@e038c94710e0 ~]$ ls logs/
gc.log gc.log.01 gc.log.03 gc.log.05 gc.log.07 gc.log.09 gc.log.11
gc.log.00 gc.log.02 gc.log.04 gc.log.06 gc.log.08 gc.log.10 gc.log.12

```

How do I pick up the other logs for the other filesets, especially the ones being printed to the console?

NOTE: I am using the default log location for all the filebeat elasticsearch filesets which is `/var/log/elasticsearch/`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2018, 5:45pm UTC](https://discuss.elastic.co/t/fileset-6-4-0-error-elasticsearch-log-is-configured-but-doesnt-exist/146921/6 "2018-10-04T17:45:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
