# Metribeat 7.1.1 not logging to files, only syslog always

**URL:** <https://discuss.elastic.co/t/metribeat-7-1-1-not-logging-to-files-only-syslog-always/187088>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [June 24, 2019, 9:11am UTC](https://discuss.elastic.co/t/metribeat-7-1-1-not-logging-to-files-only-syslog-always/187088 "2019-06-24T09:11:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rebirther](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rebirther/32/19228_2.png) [@rebirther](https://discuss.elastic.co/u/rebirther)\
**Post date:** [June 24, 2019, 9:11am UTC](https://discuss.elastic.co/t/metribeat-7-1-1-not-logging-to-files-only-syslog-always/187088/1 "2019-06-24T09:11:03Z")

</div>

Hello  
Metricbeat does not stop sending logs to syslog.  
Even after parameter in metricbeat.yml:  
`logging.to_syslog: false`

This happens if you run metricbeat (ubuntu 16.04):  
`service metricbeat start`

It helps only run with command:  
`/usr/share/metricbeat/bin/metricbeat -c /etc/metricbeat/metricbeat.yml -path.logs /var/log/metricbeat`

I also noticed that when running through systemd, command has option **"-e"** :  
`/usr/share/metricbeat/bin/metricbeat -e -c /etc/metricbeat/metricbeat.yml ...`

There may be a problem due to this "-e" option. But I did not find where it comes from. There is no such parameter in the `/etc/init.d/metricbeat` file

---

<div class="post-metadata">

**Author:** ![rebirther](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rebirther/32/19228_2.png) [@rebirther](https://discuss.elastic.co/u/rebirther)\
**Post date:** [June 26, 2019, 7:17am UTC](https://discuss.elastic.co/t/metribeat-7-1-1-not-logging-to-files-only-syslog-always/187088/2 "2019-06-26T07:17:47Z")

</div>

It is strange that this is enabled by default, but I found where syslog output is enabled.

It seems to be starting from version 7.0: [Configure logging | Metricbeat Reference [7.0] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/7.0/configuration-logging.html)

> When Metricbeat is running on a Linux system with systemd, it uses by default the `-e` command line option, that makes it write all the logging output to stderr so it can be captured by journald. Other outputs are disabled. See [Metricbeat and systemd](https://www.elastic.co/guide/en/beats/metricbeat/7.0/running-with-systemd.html) to know more and learn how to change this.

Here is information on how to disable it: [Metricbeat and systemd | Metricbeat Reference [7.0] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/7.0/running-with-systemd.html)

It is very strange that by default metricbeat writes its log to syslog. In metricbeat, by default, `logging.level: info` is enabled, so your syslog file will instantly overflow and it will be difficult to find something useful.

To elastic members:  
Perhaps it is not necessary by default to include output in syslog? Or at least lower logging level?  
Journald is a good tool, but only when there is no unnecessary information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2019, 7:17am UTC](https://discuss.elastic.co/t/metribeat-7-1-1-not-logging-to-files-only-syslog-always/187088/3 "2019-07-24T07:17:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
