# Override logging.level in a Fleet managed Filebeat?

**URL:** <https://discuss.elastic.co/t/override-logging-level-in-a-fleet-managed-filebeat/321688>\
**Category:** Beats\
**Tags:** fleet, beats-module, filebeat\
**Created:** [December 20, 2022, 8:08pm UTC](https://discuss.elastic.co/t/override-logging-level-in-a-fleet-managed-filebeat/321688 "2022-12-20T20:08:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akash\_Deep](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akash_deep/32/100324_2.png) [@Akash\_Deep](https://discuss.elastic.co/u/Akash_Deep)\
**Post date:** [December 20, 2022, 8:08pm UTC](https://discuss.elastic.co/t/override-logging-level-in-a-fleet-managed-filebeat/321688/1 "2022-12-20T20:08:11Z")

</div>

![Screenshot (2)](https://us1.discourse-cdn.com/elastic/original/3X/f/6/f666017bf18c7b466d36069b0d667823e1e1ffdf.png)  
I have a Fleet managed Elastic Agent running as a service which on `systemctl start elastic-agent` starts-up filebeat with some flags(as seen in the picture).

HOW DO I OVERRIDE THE LOGGING.LEVEL IN A MANAGED SETUP?

I've tried to edit the filebeat.yml file and setting the logging.level: debug there but I don't think that would take precedence over something that is passed as a command line parameter.

Any help is appreciated...

[EDIT]: Reading up here - [https://www.elastic.co/guide/en/fleet/8.5/beats-agent-comparison.html#supported-configurations](https://www.elastic.co/guide/en/fleet/8.5/beats-agent-comparison.html#supported-configurations). Does this mean anything in this context??

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 20, 2022, 11:45pm UTC](https://discuss.elastic.co/t/override-logging-level-in-a-fleet-managed-filebeat/321688/2 "2022-12-20T23:45:05Z")

</div>

Hi @Akash_Deep  
Welcome to the community!

Which integration are you using (custom logs?) and what version of the stack?

Logging levels should be supported per the docs you linked.

Also curious what you are trying to solve by increasing the log level.

> [@Akash\_Deep](#):
>
> HOW DO I OVERRIDE THE LOGGING.LEVEL IN A MANAGED SETUP?

Please keep the CAPS to a minimum.

If Custom Logs integration

Advanced Settings -\> Custom Configurations

 ![Screen Shot 2022-12-20 at 3.59.35 PM](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c878ce49b5105c9cf074bd6c1cc2a02aa368b20b.png)

 ![Screen Shot 2022-12-20 at 3.59.01 PM](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9a494876f44db0336d8b36f2fcf73df2da9b718d.png)

---

<div class="post-metadata">

**Author:** ![Akash\_Deep](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akash_deep/32/100324_2.png) [@Akash\_Deep](https://discuss.elastic.co/u/Akash_Deep)\
**Post date:** [December 21, 2022, 5:37am UTC](https://discuss.elastic.co/t/override-logging-level-in-a-fleet-managed-filebeat/321688/3 "2022-12-21T05:37:15Z")

</div>

Hey @stephenb , thanks for your time.

Yes, I am using the custom logs integration with the stack (ver. 8.5.0).

I am trying to debug something that's been failing on Filebeat, hence trying to set the logging level to debug.(See screenshot)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f122aecbc630ec13b61d0b553c8599466920969.png)

I've tried the steps you mentioned about editing the custom configurations but no luck.

My understanding is that the custom configuration won't override something that has been passed as a command line argument while starting up.

Would like to know your thoughts or any other ways I might be able to debug the error I'm getting.

Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 21, 2022, 6:07am UTC](https://discuss.elastic.co/t/override-logging-level-in-a-fleet-managed-filebeat/321688/4 "2022-12-21T06:07:32Z")

</div>

Please don't post images of text, please post formatted text. Images are hard to read and impossible to debug and help. Also, I would have included the few lines following that.

Yeah... I was thinking of something else and those custom parameters are at the input level

See [Here](https://www.elastic.co/guide/en/fleet/7.17/elastic-agent-logging.html#agent-logging-levels)

 ![Screen Shot 2022-12-20 at 10.05.22 PM](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dc39181580658f261cc425e82876a46cffef1d96.jpeg)

---

<div class="post-metadata">

**Author:** ![Akash\_Deep](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akash_deep/32/100324_2.png) [@Akash\_Deep](https://discuss.elastic.co/u/Akash_Deep)\
**Post date:** [December 21, 2022, 6:50am UTC](https://discuss.elastic.co/t/override-logging-level-in-a-fleet-managed-filebeat/321688/6 "2022-12-21T06:50:56Z")

</div>

Thanks @stephenb , you're a savior.

That log-level change dropdown at the bottom never came in sight!

And thanks for the suggestions on writing better community posts. Appreciate it 👍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2023, 8:51am UTC](https://discuss.elastic.co/t/override-logging-level-in-a-fleet-managed-filebeat/321688/7 "2023-01-18T08:51:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
