# How does -E flag works

**URL:** <https://discuss.elastic.co/t/how-does-e-flag-works/178530>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 25, 2019, 7:07pm UTC](https://discuss.elastic.co/t/how-does-e-flag-works/178530 "2019-04-25T19:07:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sebastian\_Treu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastian_treu/32/27013_2.png) [@Sebastian\_Treu](https://discuss.elastic.co/u/Sebastian_Treu)\
**Post date:** [April 25, 2019, 7:07pm UTC](https://discuss.elastic.co/t/how-does-e-flag-works/178530/1 "2019-04-25T19:07:47Z")

</div>

Hi, I'm trying to overwrite the output of filebeat.

Motivation is based on my idea of avoid at all cost mounting specific files into docker container, so I though of:

```auto
~$ docker run --user root -it -v "/var/lib/docker/containers:/var/lib/docker/containers:ro" -v "/var/run/docker.sock:/var/run/docker.sock:ro" docker.elas
tic.co/beats/filebeat:7.0.0 -e -strict.perms=false --E output.console.pretty=true
Exiting: error unpacking config data: more than one namespace configured accessing 'output' (source:'filebeat.yml')

```

But it complains just like if it the overwrite was not done. This is what documentation says:

> Flags:  
> -E, --E setting=value Configuration overwrite

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 26, 2019, 12:56pm UTC](https://discuss.elastic.co/t/how-does-e-flag-works/178530/2 "2019-04-26T12:56:05Z")

</div>

By using `-E output.console.pretty=true` you have 2 outputs configured. The default output is elasticsearch. Try:

```auto
... -E output.elasticsearch.enabled=false -E output.console.pretty=true

```

one can actually pass object to -E:

```auto
... -E 'output={elasticsearch.enabled: false, console.pretty: true}'

```

---

<div class="post-metadata">

**Author:** ![Sebastian\_Treu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastian_treu/32/27013_2.png) [@Sebastian\_Treu](https://discuss.elastic.co/u/Sebastian_Treu)\
**Post date:** [April 26, 2019, 5:23pm UTC](https://discuss.elastic.co/t/how-does-e-flag-works/178530/3 "2019-04-26T17:23:49Z")

</div>

@steffens thanks, that worked.

It's pretty anti intuitive that if filebeat won't manage 2 outputs, the command flag adds another option instead of _overwriting_ it. Maybe that should be a feature request to change that behaviour.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2019, 5:23pm UTC](https://discuss.elastic.co/t/how-does-e-flag-works/178530/4 "2019-05-24T17:23:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
