# Issue setting up Filebeat for initial use

**URL:** <https://discuss.elastic.co/t/issue-setting-up-filebeat-for-initial-use/185054>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 10, 2019, 8:58pm UTC](https://discuss.elastic.co/t/issue-setting-up-filebeat-for-initial-use/185054 "2019-06-10T20:58:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RFX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rfx/32/47824_2.png) [@RFX](https://discuss.elastic.co/u/RFX)\
**Post date:** [June 10, 2019, 8:58pm UTC](https://discuss.elastic.co/t/issue-setting-up-filebeat-for-initial-use/185054/1 "2019-06-10T20:58:48Z")

</div>

Hi!

I am trying to install filebeat to start scanning some logs, and I am trying to get it to work, and I cannot see why it is not. Service starts. It monitors every 30 seconds. The path is correct... but it does not seem to be doing anything.

```
rendserv1:~ # curl http://localhost:9200/filebeat-*/_count?pretty
{
  "count" : 0,
  "_shards" : {
    "total" : 0,
    "successful" : 0,
    "skipped" : 0,
    "failed" : 0
  }
}

rendserv1:~ # sudo service filebeat status
● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch.
   Loaded: loaded (/usr/lib/systemd/system/filebeat.service; disabled; vendor preset: disabled)
   Active: active (running) since Mon 2019-06-10 15:50:45 CDT; 4min 0s ago
     Docs: https://www.elastic.co/products/beats/filebeat
 Main PID: 9707 (filebeat)
   CGroup: /system.slice/filebeat.service
           └─9707 /usr/share/filebeat/bin/filebeat -e -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat

Jun 10 15:50:46 rendserv1 filebeat[9707]: 2019-06-10T15:50:46.046-0500 INFO cfgfile/reload.go:205 Loading of config files completed.
Jun 10 15:50:49 rendserv1 filebeat[9707]: 2019-06-10T15:50:49.038-0500 INFO add_cloud_metadata/add_cloud_metadata.go:346 add_cloud_metadata: hosting provider type not detected.
Jun 10 15:51:16 rendserv1 filebeat[9707]: 2019-06-10T15:51:16.049-0500 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":1...
Jun 10 15:51:46 rendserv1 filebeat[9707]: 2019-06-10T15:51:46.048-0500 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":4...
Jun 10 15:52:16 rendserv1 filebeat[9707]: 2019-06-10T15:52:16.048-0500 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":6...
Jun 10 15:52:46 rendserv1 filebeat[9707]: 2019-06-10T15:52:46.048-0500 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":8...
Jun 10 15:53:16 rendserv1 filebeat[9707]: 2019-06-10T15:53:16.048-0500 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":1...
Jun 10 15:53:46 rendserv1 filebeat[9707]: 2019-06-10T15:53:46.048-0500 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":1...
Jun 10 15:54:16 rendserv1 filebeat[9707]: 2019-06-10T15:54:16.048-0500 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":1...

```

The YML looks like this:

```
filebeat.inputs:

- type: log
  enabled: true
  paths:
    - /renders/render_logs/job/*/*/*.hst
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true
setup.template.settings:
  index.number_of_shards: 1
setup.kibana:
  host: " ********* :5601"
output.elasticsearch:
  hosts: ["localhost:9200"]
processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~

```

Thank you for any help you might be able to give me.

---

<div class="post-metadata">

**Author:** ![maxozerov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxozerov/32/48068_2.png) [@maxozerov](https://discuss.elastic.co/u/maxozerov)\
**Post date:** [June 11, 2019, 3:33pm UTC](https://discuss.elastic.co/t/issue-setting-up-filebeat-for-initial-use/185054/2 "2019-06-11T15:33:01Z")

</div>

Hello! RFX Ted!  
Maybe some help and debug info:

1. If Linux... just in cmd:  
`filebeat test config`  
`filebeat test output`

2. Logs: (in filebeat.yml)

And if all OK with test - just check debug logs

---

<div class="post-metadata">

**Author:** ![RFX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rfx/32/47824_2.png) [@RFX](https://discuss.elastic.co/u/RFX)\
**Post date:** [June 11, 2019, 4:16pm UTC](https://discuss.elastic.co/t/issue-setting-up-filebeat-for-initial-use/185054/3 "2019-06-11T16:16:36Z")

</div>

```
rendserv1:/var/log/filebeat # filebeat test config
Config OK
rendserv1:/var/log/filebeat # filebeat test output
elasticsearch: http://localhost:9200...
  parse url... OK
  connection...
    parse host... OK
    dns lookup... OK
    addresses: ::1, 127.0.0.1
    dial up... OK
  TLS... WARN secure connection disabled
  talk to server... OK
  version: 7.1.1

```

The funny thing is, once I added the logging, it seemed to work (That is literally the only difference in the files):

```
rendserv1:/var/log/filebeat # curl http://localhost:9200/filebeat-*/_count?pretty
{
  "count" : 143852,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  }
}

```

So thank you!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2019, 4:16pm UTC](https://discuss.elastic.co/t/issue-setting-up-filebeat-for-initial-use/185054/4 "2019-07-09T16:16:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
