# Hello World for filebeat

**URL:** <https://discuss.elastic.co/t/hello-world-for-filebeat/197953>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 3, 2019, 9:25pm UTC](https://discuss.elastic.co/t/hello-world-for-filebeat/197953 "2019-09-03T21:25:48Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![spuder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spuder/32/44895_2.png) [@spuder](https://discuss.elastic.co/u/spuder)\
**Post date:** [September 3, 2019, 9:25pm UTC](https://discuss.elastic.co/t/hello-world-for-filebeat/197953/1 "2019-09-03T21:25:48Z")

</div>

I am attempting to do a 'hello-world' with filebeat by reading from a file and outputing to stdout or another file. I find that filebeat does not detect any changes to the log files.

What would a hello-world look like?

What I've tried:

### Attempt 1:

/etc/filebeat/filebeat.yml

```auto
---
filebeat.config:
  modules:
    path: ${path.config}/modules.d/*.yml
    reload.enabled: false
filebeat.input:
- type: log
  enabled: true
  paths:
    - /tmp/input.log
output.console:
  pretty: true

```

I'm starting the service like so:

```auto
filebeat -e

```

Then putting content into the log file

```auto
echo "foobar" >> /tmp/intput.log

```

I find no output in the console

### Attempt 2

I've also attempted to send the output to a new file, with no luck

/etc/filebeat/filebeat.yml

```auto
---
filebeat.config:
  modules:
    path: ${path.config}/modules.d/*.yml
    reload.enabled: false
filebeat.input:
- type: log
  enabled: true
  paths:
    - /tmp/input.log
output.file:
  path: "/tmp/"
  filename: foobar

```

* * *

The output from the filebeat server

```auto
instance/beat.go:292	Setup Beat: filebeat; Version: 7.3.1
2019-09-03T21:24:45.120Z	INFO	[publisher]	pipeline/module.go:97	Beat name: ubuntu-bionic
2019-09-03T21:24:45.121Z	WARN	beater/filebeat.go:152	Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.
2019-09-03T21:24:45.122Z	INFO	instance/beat.go:421	filebeat start running.
2019-09-03T21:24:45.124Z	INFO	registrar/registrar.go:145	Loading registrar data from /var/lib/filebeat/registry/filebeat/data.json
2019-09-03T21:24:45.125Z	INFO	registrar/registrar.go:152	States Loaded from registrar: 0
2019-09-03T21:24:45.126Z	WARN	beater/filebeat.go:368	Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.
2019-09-03T21:24:45.127Z	INFO	crawler/crawler.go:72	Loading Inputs: 1
2019-09-03T21:24:45.128Z	INFO	crawler/crawler.go:106	Loading and starting Inputs completed. Enabled inputs: 0
2019-09-03T21:24:45.129Z	INFO	[monitoring]	log/log.go:118	Starting metrics logging every 30s
2019-09-03T21:24:45.130Z	INFO	cfgfile/reload.go:171	Config reloader started
2019-09-03T21:24:45.130Z	INFO	cfgfile/reload.go:226	Loading of config files completed.
2019-09-03T21:24:48.120Z	INFO	add_cloud_metadata/add_cloud_metadata.go:347	add_cloud_metadata: hosting provider type not detected.

```

How can I configure filebeat to send data from one location to another?

---

<div class="post-metadata">

**Author:** ![Michael\_Madden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_madden/32/46640_2.png) [@Michael\_Madden](https://discuss.elastic.co/u/Michael_Madden)\
**Post date:** [September 3, 2019, 9:47pm UTC](https://discuss.elastic.co/t/hello-world-for-filebeat/197953/2 "2019-09-03T21:47:36Z")

</div>

Hello, thanks for reaching out regarding filebeat. Which operating system and filebeat version are you running?

I would suggest trying to explicitly specify the filebeat config file with the `-c` flag. It may also be useful to enable debugging output.

The following provides examples of both settings:  
[https://www.elastic.co/guide/en/beats/filebeat/current/enable-filebeat-debugging.html](https://www.elastic.co/guide/en/beats/filebeat/current/enable-filebeat-debugging.html)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 3, 2019, 9:52pm UTC](https://discuss.elastic.co/t/hello-world-for-filebeat/197953/3 "2019-09-03T21:52:09Z")

</div>

> [@spuder](#):
>
> echo "foobar" \>\> /tmp/in **t** put.log

Typo?

`echo "foobar" >> /tmp/input.log`

---

<div class="post-metadata">

**Author:** ![spuder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spuder/32/44895_2.png) [@spuder](https://discuss.elastic.co/u/spuder)\
**Post date:** [September 3, 2019, 11:00pm UTC](https://discuss.elastic.co/t/hello-world-for-filebeat/197953/4 "2019-09-03T23:00:43Z")

</div>

I've repeated the above examples 3 times. Once on OSX, once on the official filebeat docker image, and once with an ubuntu 18.04 vagrant vm. All 3 have the same result where filebeat fails to read from a file.

I've tried using globs like this:

```auto
filebeat.input:
- type: log
  enabled: true
  paths:
    - /tmp/*.log

```

I've also tried referencing the file directly

```auto
filebeat.input:
- type: log
  enabled: true
  paths:
    - /tmp/input.log

```

And yes, I've verified I'm not typing the file name

```auto
cat /tmp/input.log
foo
bar
foobar
heyo

```

I've also tried using logs in a different directory since some OS's use a symlink for `/tmp`

```auto
filebeat.input:
- type: log
  enabled: true
  paths:
    - /var/log/input.log

```

Filebeat fails to read the file in all situations.

I am starting filebeat like so:

```auto
filebeat -e

```

I've also tried ensuring filebeat is using the correct config file

```auto
filebeat -e --path.config /etc/filebeat

```

I've also tried not using -e and running filebeat as normal

```auto
filebeat --path.config /etc/filebeat

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 3, 2019, 11:53pm UTC](https://discuss.elastic.co/t/hello-world-for-filebeat/197953/5 "2019-09-03T23:53:37Z")

</div>

EDIT is that still the output section show the output section of `filebeat.yml`

Also what version are you running and it appears you have modules enabled from the first log, what modules did you enable? I am not sure modules plus output to console is supported since the use ingest pipelines which looks like perhaps the error from the the original post.

---

<div class="post-metadata">

**Author:** ![kumarabhi](https://avatars.discourse-cdn.com/v4/letter/k/6a8cbe/32.png) [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Post date:** [September 4, 2019, 6:25pm UTC](https://discuss.elastic.co/t/hello-world-for-filebeat/197953/7 "2019-09-04T18:25:14Z")

</div>

for reading symlinks please use the following setting  
# If symlinks is enabled, symlinks are opened and harvested. The harvester is opening the  
# original for harvesting but will report the symlink name as source.  
symlinks: true

make sure that only console output is enabled and other outputs (Kafka, Redis, Logstash, ElasticSearch, etc ) are disabled

---

<div class="post-metadata">

**Author:** ![spuder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spuder/32/44895_2.png) [@spuder](https://discuss.elastic.co/u/spuder)\
**Post date:** [September 4, 2019, 7:52pm UTC](https://discuss.elastic.co/t/hello-world-for-filebeat/197953/8 "2019-09-04T19:52:10Z")

</div>

While I never did get the file.output working, I was able to get `output.console` working.

There was a typo in the configs:

```auto
file.input:

```

Should be

```auto
file.inputs

```

The full working config is:

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /tmp/foobar.log
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true
  reload.period: 10s
setup.template.settings:
  index.number_of_shards: 1
setup.kibana:
output.elasticsearch:
  enabled: false
output.console:
  enabled: true
  pretty: true
processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~

```

---

<div class="post-metadata">

**Author:** ![kumarabhi](https://avatars.discourse-cdn.com/v4/letter/k/6a8cbe/32.png) [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Post date:** [September 5, 2019, 6:51pm UTC](https://discuss.elastic.co/t/hello-world-for-filebeat/197953/9 "2019-09-05T18:51:19Z")

</div>

Cool

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2019, 6:51pm UTC](https://discuss.elastic.co/t/hello-world-for-filebeat/197953/10 "2019-10-03T18:51:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
