# New to elastic having issue with file beat

**URL:** <https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 7, 2016, 12:20am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560 "2016-01-07T00:20:03Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ronald\_Hill](https://avatars.discourse-cdn.com/v4/letter/r/a9a28c/32.png) [@Ronald\_Hill](https://discuss.elastic.co/u/Ronald_Hill)\
**Post date:** [January 7, 2016, 12:20am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/1 "2016-01-07T00:20:03Z")

</div>

- Restarting Sends log files to Logstash or directly to Elasticsearch. filebeat 2016/01/07 00:17:05.443037 outputs.go:105: ERR failed to initialize elasticsearch plugin as output: no host configuration found  
Error Initialising publisher: no host configuration found  
2016/01/07 00:17:05.443131 beat.go:101: CRIT no host configuration found

help pls

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 7, 2016, 12:40am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/2 "2016-01-07T00:40:55Z")

</div>

Providing your config will help us help you.

---

<div class="post-metadata">

**Author:** ![Ronald\_Hill](https://avatars.discourse-cdn.com/v4/letter/r/a9a28c/32.png) [@Ronald\_Hill](https://discuss.elastic.co/u/Ronald_Hill)\
**Post date:** [January 7, 2016, 12:46am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/3 "2016-01-07T00:46:28Z")

</div>

```
  paths:
     - /var/log/auth.log
     - /var/log/syslog

```

# - /var/log/\*.log

...

...  
document\_type: syslog  
...

...  
output:

### Elasticsearch as output

elasticsearch:  
enabled: false  
...

### Logstash as output

logstash:  
# The Logstash hosts  
hosts: ["10.x.x.x:5044"]

...  
tls:  
# List of root certificates for HTTPS server verifications  
certificate\_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 7, 2016, 12:48am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/4 "2016-01-07T00:48:56Z")

</div>

Is that the whole thing? Why are there so many `...` sections?

The error specifically says [quote="Ronald\_Hill, post:1, topic:38560"]  
no host configuration found  
[/quote]  
for your ES section, so providing all of that would be useful.

---

<div class="post-metadata">

**Author:** ![Ronald\_Hill](https://avatars.discourse-cdn.com/v4/letter/r/a9a28c/32.png) [@Ronald\_Hill](https://discuss.elastic.co/u/Ronald_Hill)\
**Post date:** [January 7, 2016, 1:10am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/5 "2016-01-07T01:10:46Z")

</div>

well i followed the configuration on

[https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-0](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-0)

maybe thats my first issue

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 7, 2016, 1:11am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/6 "2016-01-07T01:11:35Z")

</div>

That link doesn't exist.

---

<div class="post-metadata">

**Author:** ![Ronald\_Hill](https://avatars.discourse-cdn.com/v4/letter/r/a9a28c/32.png) [@Ronald\_Hill](https://discuss.elastic.co/u/Ronald_Hill)\
**Post date:** [January 7, 2016, 1:12am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/7 "2016-01-07T01:12:43Z")

</div>

> **[How To Install Elasticsearch, Logstash, and Kibana (ELK Stack) on Ubuntu 14.04 |...](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-04)**
>
> In this tutorial, we will go over the installation of the Elasticsearch ELK Stack on Ubuntu 14.04—that is, Elasticsearch 2.2.x, Logstash 2.2.x, and Kibana 4.4.x. We will also show you how to configure it to gather and visualize the syslogs of your...

---

<div class="post-metadata">

**Author:** ![Ronald\_Hill](https://avatars.discourse-cdn.com/v4/letter/r/a9a28c/32.png) [@Ronald\_Hill](https://discuss.elastic.co/u/Ronald_Hill)\
**Post date:** [January 7, 2016, 1:13am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/8 "2016-01-07T01:13:52Z")

</div>

I followed all the steps and the only error im getting is with filebeat.yml i know its something simple that im missing but i cant see what it is. thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 7, 2016, 1:16am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/9 "2016-01-07T01:16:03Z")

</div>

As mentioned, it'd help if you posted/linked to your complete filebeat config.  
If you don't want to post that then just the entire output section.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 7, 2016, 1:27am UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/10 "2016-01-07T01:27:56Z")

</div>

The tutorial you followed is not up to date. Follow our official [getting-started guide](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html).

The `enabled: false` and `enabled: true` options were removed while Filebeat was in beta. They are not present in the configuration file shipped with Filebeat. You should either comment out or remove the outputs that you are not using (i.e. elasticsearch, file, console). Here is the documentation for all of the [configuration options](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration-details.html) for Filebeat 1.0.1.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:57pm UTC](https://discuss.elastic.co/t/new-to-elastic-having-issue-with-file-beat/38560/11 "2017-07-05T21:57:02Z")

</div>


