# \[Solved\] Filebeat 7.0.1 has no data on \[Filebeat System\] Syslog dashboard ECS

**URL:** <https://discuss.elastic.co/t/solved-filebeat-7-0-1-has-no-data-on-filebeat-system-syslog-dashboard-ecs/182575>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 24, 2019, 7:14am UTC](https://discuss.elastic.co/t/solved-filebeat-7-0-1-has-no-data-on-filebeat-system-syslog-dashboard-ecs/182575 "2019-05-24T07:14:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![TsuWeiQuan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsuweiquan/32/46252_2.png) [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)\
**Post date:** [May 24, 2019, 7:14am UTC](https://discuss.elastic.co/t/solved-filebeat-7-0-1-has-no-data-on-filebeat-system-syslog-dashboard-ecs/182575/1 "2019-05-24T07:14:45Z")

</div>

Hello team,

I have an ELK stack running on 7.0.1 and i have trouble displaying data on the [Filebeat System] Syslog dashboard ECS but i can see logs on the discover panel.  
I have configured a linuxclient to send system logs using filebeat to elasticsearch nodes straight. I am using the system module from filebeat.

My linuxclient is running RHEL 7.0 OS and i am trying to display the important logs on kibana.

**On my linuxclient:**

system.yml

```
- module: system
  # Syslog
  syslog:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/var/log/dmesg"]

    # Convert the timestamp to UTC. Requires Elasticsearch >= 6.1.
    var.convert_timezone: true

  # Authorization logs
  auth:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/var/log/secure"]

    # Convert the timestamp to UTC. Requires Elasticsearch >= 6.1.
    var.convert_timezone: true
[root@linuxclient modules.d]#

```

**filebeat.yml**

```
#=========================== Filebeat inputs =============================

filebeat.inputs:

- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /var/log/messages
    - /var/log/cron
    - /var/log/secure
    #- c:\programdata\elasticsearch\logs\*

  # Exclude lines. A list of regular expressions to match. It drops the lines that are
  # matching any regular expression from the list.
  #exclude_lines: ['^DBG']
  exclude_lines: ['.*monitoring.*']

#============================= Filebeat modules ===============================

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: true

  # Period on which files under path should be checked for changes
  #reload.period: 10s

#==================== Elasticsearch template setting ==========================

setup.template.settings:
  index.number_of_shards: 1
  #index.codec: best_compression
  #_source.enabled: false

#============================== Kibana =====================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.
# This requires a Kibana endpoint configuration.
setup.kibana:

  host: "kibana:5601"

#================================ Outputs =====================================

# Configure what output to use when sending the data collected by the beat.

#-------------------------- Elasticsearch output ------------------------------
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["esnode1:9200", "esnode2:9200", "esnode3:9200"]

  # Optional protocol and basic auth credentials.
  #protocol: "https"
  #username: "elastic"
  #password: "changeme"

#----------------------------- Logstash output --------------------------------
#output.logstash:
  # The Logstash hosts
  # hosts: ["localhost:5044"]

  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  #ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]

  # Certificate for SSL client authentication
  #ssl.certificate: "/etc/pki/client/cert.pem"

  # Client Certificate Key
  #ssl.key: "/etc/pki/client/cert.key"

#================================ Processors =====================================

# Configure processors to enhance or manipulate events generated by the beat.

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~

#================================ Logging =====================================

#logging.level: debug

#logging.selectors: ["*"]

#============================== Xpack Monitoring

#xpack.monitoring.enabled: false

#xpack.monitoring.elasticsearch:

# Migration 

# This allows to enable 6.7 migration aliases
#migration.6_to_7.enabled: true

setup.ilm.enabled: auto
setup.ilm.rollover_alias: "filebeat-linuxclient"
setup.ilm.pattern: "{now/d}-000001"
setup.template.overwrite: true

```

i have deleted some commented configs due to exceeding word count on this post  
Any idea what could be the problem?

---

<div class="post-metadata">

**Author:** ![TsuWeiQuan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsuweiquan/32/46252_2.png) [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)\
**Post date:** [May 27, 2019, 3:00am UTC](https://discuss.elastic.co/t/solved-filebeat-7-0-1-has-no-data-on-filebeat-system-syslog-dashboard-ecs/182575/2 "2019-05-27T03:00:35Z")

</div>

Solved this issue.  
Apparently, my mistake is that i have loaded "- /var/log/messages" in my prospector settings and i should have place this into the system.yml module.  
After that, the dashboard is displaying correctly.

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [May 30, 2019, 5:04pm UTC](https://discuss.elastic.co/t/solved-filebeat-7-0-1-has-no-data-on-filebeat-system-syslog-dashboard-ecs/182575/3 "2019-05-30T17:04:41Z")

</div>

Great! Thanks for posting it here! @TsuWeiQuan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2019, 5:04pm UTC](https://discuss.elastic.co/t/solved-filebeat-7-0-1-has-no-data-on-filebeat-system-syslog-dashboard-ecs/182575/4 "2019-06-27T17:04:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
