# Module system doesn't exists! when trying to enable system module

**URL:** <https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 26, 2018, 8:51pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744 "2018-04-26T20:51:12Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josh\_McDonald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josh_mcdonald/32/30525_2.png) [@Josh\_McDonald](https://discuss.elastic.co/u/Josh_McDonald)\
**Post date:** [April 26, 2018, 8:51pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/1 "2018-04-26T20:51:13Z")

</div>

I'm trying to get system logs from an Ubuntu VM running the latest version of filebeats (installed via apt-get). When I run `sudo ./filebeat modules enable system`, I get an error "Module system doesn't exists!".  
If I run `sudo ./filebeat modules list`, I get blank outputs for Enabled and Disabled.

Did I miss a step somewhere?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 26, 2018, 9:18pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/2 "2018-04-26T21:18:55Z")

</div>

Hi @Josh_McDonald,

If you installed filebeat using `apt-get` you should drop `./` from the command, as filebeat is already in the path. Try with just:

```auto
 sudo filebeat modules list

```

---

<div class="post-metadata">

**Author:** ![Josh\_McDonald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josh_mcdonald/32/30525_2.png) [@Josh\_McDonald](https://discuss.elastic.co/u/Josh_McDonald)\
**Post date:** [April 27, 2018, 12:35am UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/3 "2018-04-27T00:35:12Z")

</div>

I get the same output just using `sudo filebeat modules list`Nothing enabled or disabled.

---

<div class="post-metadata">

**Author:** ![Josh\_McDonald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josh_mcdonald/32/30525_2.png) [@Josh\_McDonald](https://discuss.elastic.co/u/Josh_McDonald)\
**Post date:** [April 27, 2018, 12:37am UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/4 "2018-04-27T00:37:46Z")

</div>

I also tried `sudo filebeat modules enable system`, but I get an error: `Module system doesn't exists!`

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 27, 2018, 9:55am UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/5 "2018-04-27T09:55:30Z")

</div>

Hi @Josh_McDonald, I'm wondering. Did you use our official package from [https://www.elastic.co/downloads/beats/filebeat](https://www.elastic.co/downloads/beats/filebeat) or installed it from somewhere else?

Could you dump the output of `dpkg -L filebeat`? I want to make sure your setup has the module files.

Best regards

---

<div class="post-metadata">

**Author:** ![Josh\_McDonald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josh_mcdonald/32/30525_2.png) [@Josh\_McDonald](https://discuss.elastic.co/u/Josh_McDonald)\
**Post date:** [April 27, 2018, 1:13pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/6 "2018-04-27T13:13:29Z")

</div>

I used the official instructions from here:  
[https://www.elastic.co/guide/en/beats/filebeat/current/setup-repositories.html](https://www.elastic.co/guide/en/beats/filebeat/current/setup-repositories.html)

I can't attach the full output since it won't let me attach a txt file and it's too long to paste into a reply.  
Here are the bits that seem relevant to modules for system. There are a number of others related to modules as well.

/usr/share/filebeat/module

/usr/share/filebeat/module/system  
/usr/share/filebeat/module/system/auth  
/usr/share/filebeat/module/system/auth/ingest  
/usr/share/filebeat/module/system/auth/ingest/pipeline.json  
/usr/share/filebeat/module/system/auth/config  
/usr/share/filebeat/module/system/auth/config/auth.yml  
/usr/share/filebeat/module/system/auth/manifest.yml  
/usr/share/filebeat/module/system/syslog  
/usr/share/filebeat/module/system/syslog/ingest  
/usr/share/filebeat/module/system/syslog/ingest/pipeline.json  
/usr/share/filebeat/module/system/syslog/config  
/usr/share/filebeat/module/system/syslog/config/syslog.yml  
/usr/share/filebeat/module/system/syslog/manifest.yml  
/usr/share/filebeat/module/system/module.yml

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 27, 2018, 2:14pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/7 "2018-04-27T14:14:33Z")

</div>

there should be some more under `/etc/modules.d`, do you see those?

---

<div class="post-metadata">

**Author:** ![Josh\_McDonald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josh_mcdonald/32/30525_2.png) [@Josh\_McDonald](https://discuss.elastic.co/u/Josh_McDonald)\
**Post date:** [April 27, 2018, 2:26pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/8 "2018-04-27T14:26:39Z")

</div>

I have the following related to /etc

/etc/init.d  
/etc/init.d/filebeat  
/etc/filebeat  
/etc/filebeat/modules.d  
/etc/filebeat/modules.d/nginx.yml.disabled  
/etc/filebeat/modules.d/system.yml.disabled  
/etc/filebeat/modules.d/redis.yml.disabled  
/etc/filebeat/modules.d/apache2.yml.disabled  
/etc/filebeat/modules.d/postgresql.yml.disabled  
/etc/filebeat/modules.d/icinga.yml.disabled  
/etc/filebeat/modules.d/kafka.yml.disabled  
/etc/filebeat/modules.d/auditd.yml.disabled  
/etc/filebeat/modules.d/logstash.yml.disabled  
/etc/filebeat/modules.d/osquery.yml.disabled  
/etc/filebeat/modules.d/traefik.yml.disabled  
/etc/filebeat/modules.d/mysql.yml.disabled  
/etc/filebeat/filebeat.yml  
/etc/filebeat/fields.yml  
/etc/filebeat/filebeat.reference.yml

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 27, 2018, 4:37pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/9 "2018-04-27T16:37:37Z")

</div>

Everything seems in place, I would say something on this list should be the issue:

- You are running `sudo filebeat...` from `/usr/share/filbeat` folder, no need for it, depending on your PATH settings it may be using the wrong binary, just run the command from your home, for instance.
- `filebeat.config.modules.path` is wrong, did you change by a chance? You can dump your settings doing `filebeat export config`.

Best regards

---

<div class="post-metadata">

**Author:** ![Josh\_McDonald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josh_mcdonald/32/30525_2.png) [@Josh\_McDonald](https://discuss.elastic.co/u/Josh_McDonald)\
**Post date:** [April 27, 2018, 4:45pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/10 "2018-04-27T16:45:32Z")

</div>

Running from my home directory doesn't have any impact and I get the same results. The modules path may be the root cause here because I believe I likely changed it due to errors before (likely because I was running it incorrectly).  
Here's the config output  
filebeat:  
config:  
modules:  
path: /usr/share/filebeat/modules/\*.yml  
reload:  
enabled: true  
prospectors:

- enabled: false  
paths:
  - /var/log/\*.log  
type: log  
output:  
elasticsearch:  
hosts:
  - 10.136.3.254:9200  
path:  
config: /etc/filebeat  
data: /var/lib/filebeat  
home: /usr/share/filebeat  
logs: /var/log/filebeat  
setup:  
kibana:  
host: 10.136.3.254:5601  
template:  
settings:  
index:  
number\_of\_shards: 3

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 29, 2018, 10:50pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/11 "2018-04-29T22:50:35Z")

</div>

I think you found the root cause :), modules section should look like this:

```auto
#============================= Filebeat modules ===============================

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: false

  # Period on which files under path should be checked for changes
  #reload.period: 10s

```

Then you can try the command without `./` again.

Best regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2018, 10:50pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exists-when-trying-to-enable-system-module/129744/12 "2018-05-27T22:50:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
