# Overriding output from command line

**URL:** <https://discuss.elastic.co/t/overriding-output-from-command-line/178868>\
**Category:** Beats\
**Created:** [April 29, 2019, 8:49am UTC](https://discuss.elastic.co/t/overriding-output-from-command-line/178868 "2019-04-29T08:49:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Maciej\_Krasuski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maciej_krasuski/32/45212_2.png) [@Maciej\_Krasuski](https://discuss.elastic.co/u/Maciej_Krasuski)\
**Post date:** [April 29, 2019, 8:49am UTC](https://discuss.elastic.co/t/overriding-output-from-command-line/178868/1 "2019-04-29T08:49:33Z")

</div>

I'd like to debug processing of events by production `filebeat.yml` trying to redirect input and output for filebeat to console. Input can be redefined by -E with no problems but output redirection is fairly impossible.

Assuming filebeat.yml like

```auto
... 
output: logstash.hosts: ['host:port'] 
...

```

if we run

`filebeat -E 'output={console:{pretty:true}}'`

we encounter error about 'more than one output'. In my opinion this -E should override whole definition of output, but seems only merge to one in .yml file. Is this bug in -E application? Is there any other possibility of redirection of output with no modification to original .yml file

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [May 3, 2019, 5:49pm UTC](https://discuss.elastic.co/t/overriding-output-from-command-line/178868/2 "2019-05-03T17:49:23Z")

</div>

You also need to disable the output defined in your config. Try:

```auto
filebeat -E output.logstash.enabled=false -E 'output={console:{pretty:true}}'

```

This is expected behavior, not a bug.

---

<div class="post-metadata">

**Author:** ![Maciej\_Krasuski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maciej_krasuski/32/45212_2.png) [@Maciej\_Krasuski](https://discuss.elastic.co/u/Maciej_Krasuski)\
**Post date:** [May 3, 2019, 6:50pm UTC](https://discuss.elastic.co/t/overriding-output-from-command-line/178868/3 "2019-05-03T18:50:47Z")

</div>

In my opinion, for sure, this is not bug related to 'output' behavior, but maybe bug to overriding the config. One could think that `-E path={object def}` should redefine _whole_ config object pointed by `path` (i.e. deleting other props defined in .yml), and not only append `{object def}` to it. For some configurations this could be crucial.

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [May 3, 2019, 7:26pm UTC](https://discuss.elastic.co/t/overriding-output-from-command-line/178868/4 "2019-05-03T19:26:28Z")

</div>

I was going to suggest that you open an enhancement request, but I see you've already done that. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2019, 9:26pm UTC](https://discuss.elastic.co/t/overriding-output-from-command-line/178868/5 "2019-05-31T21:26:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
