# Issue with systemd startup and keystore values

**URL:** <https://discuss.elastic.co/t/issue-with-systemd-startup-and-keystore-values/197520>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 30, 2019, 12:31pm UTC](https://discuss.elastic.co/t/issue-with-systemd-startup-and-keystore-values/197520 "2019-08-30T12:31:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![stwilliams](https://avatars.discourse-cdn.com/v4/letter/s/6a8cbe/32.png) [@stwilliams](https://discuss.elastic.co/u/stwilliams)\
**Post date:** [August 30, 2019, 12:31pm UTC](https://discuss.elastic.co/t/issue-with-systemd-startup-and-keystore-values/197520/1 "2019-08-30T12:31:08Z")

</div>

We are rolling out a cluster with security high on the list of targets - so using SSL, authentication etc

In our filebeat.yml, we have  
output.elasticsearch.username = "${ES\_USER}"  
output.elasticsearch.password = "${ES\_PASS}"

and we have stored the relevant data in the filebeat keystore.

when we run systemctl start filebeat, we get an error  
instance/beat.go:877 - Exiting: error initializing publisher: missing field accessing 'output.elasticsearch.username' (source:'/etc/filebeat/filebeat.yml')

but if we run the start command manually, it works....

So we are deducing that systemd is doing something with these variables before filebeat gets a look in.  
We have tried quoting - single and double - / escaping but it still fails.

Any ideas?

I have entered the values into the yaml file and it works as expected but then that exposes the username and the password to prying eyes so _not good_.

---

<div class="post-metadata">

**Author:** ![stwilliams](https://avatars.discourse-cdn.com/v4/letter/s/6a8cbe/32.png) [@stwilliams](https://discuss.elastic.co/u/stwilliams)\
**Post date:** [August 30, 2019, 1:23pm UTC](https://discuss.elastic.co/t/issue-with-systemd-startup-and-keystore-values/197520/2 "2019-08-30T13:23:16Z")

</div>

Solved this by simplying the ExecStart file to ...filebeat -c ...yml  
and deleting all that environment lines.

Also removed the command line overriding so logging settings in yaml file actually works as expected.

Answer: Keep systemd simple....

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2019, 1:23pm UTC](https://discuss.elastic.co/t/issue-with-systemd-startup-and-keystore-values/197520/3 "2019-09-27T13:23:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
