# Systemctl start filebeat does not start filebeat

**URL:** <https://discuss.elastic.co/t/systemctl-start-filebeat-does-not-start-filebeat/78330>\
**Category:** Beats\
**Created:** [March 13, 2017, 12:07pm UTC](https://discuss.elastic.co/t/systemctl-start-filebeat-does-not-start-filebeat/78330 "2017-03-13T12:07:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [March 13, 2017, 12:07pm UTC](https://discuss.elastic.co/t/systemctl-start-filebeat-does-not-start-filebeat/78330/1 "2017-03-13T12:07:32Z")

</div>

after changing some configuration  
(I added  
json.message\_key: message  
json.keys\_under\_root: true  
)  
and doing restart to filebeat, filebeat refuses to start  
with nothing showing on the logs...

---

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [March 13, 2017, 12:09pm UTC](https://discuss.elastic.co/t/systemctl-start-filebeat-does-not-start-filebeat/78330/2 "2017-03-13T12:09:09Z")

</div>

Problem was solved (somehow it just started after about an half an hour of retries)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 16, 2017, 3:09pm UTC](https://discuss.elastic.co/t/systemctl-start-filebeat-does-not-start-filebeat/78330/3 "2017-03-16T15:09:09Z")

</div>

When changing config it is useful to run the config test with:

`filebeat.sh -e -configtest`

And when dealing with failures you can run Filebeat in the foreground to see all log output:

`filebeat.sh -e -d "*"`

(-d "\*" enables debug logging)

---

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [March 19, 2017, 4:44pm UTC](https://discuss.elastic.co/t/systemctl-start-filebeat-does-not-start-filebeat/78330/4 "2017-03-19T16:44:59Z")

</div>

Thanks @andrewkroh, this will help me in future configuration!

By any chance do you know if logstash has a feature such as:  
[filebeat.sh](http://filebeat.sh) -e -configtest (I tried [logstash.sh](http://logstash.sh) -e -configtest but with no success)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 19, 2017, 4:58pm UTC](https://discuss.elastic.co/t/systemctl-start-filebeat-does-not-start-filebeat/78330/5 "2017-03-19T16:58:25Z")

</div>

I think the equivalent for LS is

`/usr/share/logstash/bin/logstash --configtest -f <config file or dir>`

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [March 20, 2017, 1:58am UTC](https://discuss.elastic.co/t/systemctl-start-filebeat-does-not-start-filebeat/78330/6 "2017-03-20T01:58:10Z")

</div>

Note that starting with Logstash 5.0, the `--configtest` option was renamed to `--config.test_and_exit`. So the command for testing the config file with version 5.0 and later would look something like this:

`path/to/bin/logstash -f configfile --config.test_and_exit`

See [https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html](https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2017, 12:07pm UTC](https://discuss.elastic.co/t/systemctl-start-filebeat-does-not-start-filebeat/78330/7 "2017-04-03T12:07:37Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
