# Metricbeats logging into /var/log/messages

**URL:** <https://discuss.elastic.co/t/metricbeats-logging-into-var-log-messages/315316>\
**Category:** Metrics\
**Created:** [September 28, 2022, 3:02am UTC](https://discuss.elastic.co/t/metricbeats-logging-into-var-log-messages/315316 "2022-09-28T03:02:41Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 28, 2022, 6:17am UTC](https://discuss.elastic.co/t/metricbeats-logging-into-var-log-messages/315316/2 "2022-09-28T06:17:18Z")

</div>

Hi @justinepaulpadayao

How are you starting metricbeat with `systemctl` / `systemd`

Did you see [this](https://www.elastic.co/guide/en/beats/filebeat/8.0/configuration-logging.html)?

> When Filebeat is running on a Linux system with systemd, it uses by default the `-e` command line option, that makes it write all the logging output to stderr so it can be captured by journald. Other outputs are disabled. See [Filebeat and systemd](https://www.elastic.co/guide/en/beats/filebeat/8.0/running-with-systemd.html) to know more and learn how to change this.

I think you just need to follow the example and create a log.conf that looks like this (I think this gets rid the `-e` but I don't have a filebeat installed on linux with a package handy... but this should point you in the right direction, then I think it will honor your logging settings.

```auto
[Service]
Environment="BEAT_LOG_OPTS=

```

---

_[View the full topic](https://discuss.elastic.co/t/metricbeats-logging-into-var-log-messages/315316)._
