# Не приходят логи

**URL:** <https://discuss.elastic.co/t/topic/203057>\
**Category:** Вопросы на русском языке\
**Created:** [October 10, 2019, 3:07pm UTC](https://discuss.elastic.co/t/topic/203057 "2019-10-10T15:07:32Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![beren](https://avatars.discourse-cdn.com/v4/letter/b/87869e/32.png) [@beren](https://discuss.elastic.co/u/beren)\
**Post date:** [October 10, 2019, 3:07pm UTC](https://discuss.elastic.co/t/topic/203057/1 "2019-10-10T15:07:32Z")

</div>

Всем привет.

Пытаюсь связать filebeat с ELK 7.4

Создаю в /etc/logstash/conf.d/postfix.conf

```auto
input {
  beats {
    port => 5044
  }
}
output {
        elasticsearch {
            hosts => "localhost:9200"
            index => "postfix1-%{+YYYY.MM.dd}"
        }
}

```

В /etc/filebeat/filebeat.yml

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
      - /var/log/maillog*
output.logstash:
  hosts: ["192.168.199.146:5044"]
xpack.monitoring:
 enabled: true
  elasticsearch:
    hosts: ["http://192.168.199.146:9200"]

```

Но index не появляется в Kibana  
В логах filebeat

```auto
WARN beater/filebeat.go:152 Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.

```

Любая помощь =)

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [October 10, 2019, 3:31pm UTC](https://discuss.elastic.co/t/topic/203057/2 "2019-10-10T15:31:32Z")

</div>

Я бы заменил output в logstash на stdout, чтобы убедиться, что в logstash что-то приходит. Это позволит нам понять где проблема - между filebeat и logstash или logstash и elasticsearch.

---

<div class="post-metadata">

**Author:** ![beren](https://avatars.discourse-cdn.com/v4/letter/b/87869e/32.png) [@beren](https://discuss.elastic.co/u/beren)\
**Post date:** [October 11, 2019, 6:53am UTC](https://discuss.elastic.co/t/topic/203057/3 "2019-10-11T06:53:50Z")

</div>

Теперь в /etc/logstash/conf.d/postfix.conf

> Blockquote  
> input {  
> beats {  
> port =\> 5044  
> }  
> }

output {

```
   stdout { }

```

}  
Перезапуск logstash, но ничего не пришло.

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [October 11, 2019, 7:16am UTC](https://discuss.elastic.co/t/topic/203057/4 "2019-10-11T07:16:44Z")

</div>

Если ничего - то, наверное, до него сообщения от filebeat не доходят, либо filebeat ничего из логов не подцепляет. В логах в этих что-нибудь появляется? Пользователь под которым filebeat запущен доступ к ним имеет? Порт 5044 не заблокирован? В логах filebeat еще что-нибудь есть?

---

<div class="post-metadata">

**Author:** ![beren](https://avatars.discourse-cdn.com/v4/letter/b/87869e/32.png) [@beren](https://discuss.elastic.co/u/beren)\
**Post date:** [October 11, 2019, 7:44am UTC](https://discuss.elastic.co/t/topic/203057/5 "2019-10-11T07:44:28Z")

</div>

В /etc/filebeat/filebeat.yml

> Blockquote  
> filebeat.inputs:

- type: log  
enabled: true  
paths:  
- /var/log/maillog\*  
output.logstash:  
hosts: ["192.168.199.146:5044"]

Порты не заблокированы, с filebeat 5044 телнетиться.

Вот полный лог filbeat

> Blockquote  
> 2019-10-11T03:30:30.292-0400 INFO instance/beat.go:607 Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat]  
> 2019-10-11T03:30:30.292-0400 INFO instance/beat.go:615 Beat ID: 1a3f0e19-0b95-4d3e-881a-d37400468513  
> 2019-10-11T03:30:30.292-0400 INFO [beat] instance/beat.go:903 Beat info {"system\_info": {"beat": {"path": {"config": "/etc/filebeat", "data": "/var/lib/filebeat", "home": "/usr/share/filebeat", "logs": "/var/log/filebeat"}, "type": "filebeat", "uuid": "1a3f0e19-0b95-4d3e-881a-d37400468513"}}}  
> 2019-10-11T03:30:30.292-0400 INFO [beat] instance/beat.go:912 Build info {"system\_info": {"build": {"commit": "f940c36884d3749901a9c99bea5463a6030cdd9c", "libbeat": "7.4.0", "time": "2019-09-27T07:45:44.000Z", "version": "7.4.0"}}}  
> 2019-10-11T03:30:30.292-0400 INFO [beat] instance/beat.go:915 Go runtime info {"system\_info": {"go": {"os":"linux","arch":"amd64","max\_procs":1,"version":"go1.12.9"}}}  
> 2019-10-11T03:30:30.293-0400 INFO [beat] instance/beat.go:919 Host info {"system\_info": {"host": {"architecture":"x86\_64","boot\_time":"2019-10-10T06:15:26-04:00","containerized":false,"name":"[mail.test.ru](http://mail.test.ru)","ip":["127.0.0.1/8","::1/128","192.168.199.145/24","fe80::277c:61b3:ac2:bc8c/64"],"kernel\_version":"3.10.0-957.el7.x86\_64","mac":["00:0c:29:cb:1a:3d"],"os":{"family":"redhat","platform":"centos","name":"CentOS Linux","version":"7 (Core)","major":7,"minor":6,"patch":1810,"codename":"Core"},"timezone":"EDT","timezone\_offset\_sec":-14400,"id":"b27e5adbf8a1485faffe0eeec83f47f2"}}}  
> 2019-10-11T03:30:30.294-0400 INFO [beat] instance/beat.go:948 Process info {"system\_info": {"process": {"capabilities": {"inheritable":null,"permitted":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend"],"effective":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend"],"bounding":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend"],"ambient":null}, "cwd": "/var/log", "exe": "/usr/share/filebeat/bin/filebeat", "name": "filebeat", "pid": 11533, "ppid": 10829, "seccomp": {"mode":"disabled"}, "start\_time": "2019-10-11T03:30:29.400-0400"}}}  
> 2019-10-11T03:30:30.294-0400 INFO instance/beat.go:292 Setup Beat: filebeat; Version: 7.4.0  
> 2019-10-11T03:30:30.296-0400 INFO [publisher] pipeline/module.go:97 Beat name: [mail.test.ru](http://mail.test.ru)  
> 2019-10-11T03:30:30.296-0400 WARN beater/filebeat.go:152 Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.

А как понять под каким пользователем запускается filebeat ?

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [October 11, 2019, 10:55am UTC](https://discuss.elastic.co/t/topic/203057/6 "2019-10-11T10:55:11Z")

</div>

> А как понять под каким пользователем запускается filebeat ?

Обычно под root-ом, но все зависит от того, как вы его сконфигурировали

Может @Dima_I сможет помочь с этим?

---

<div class="post-metadata">

**Author:** ![beren](https://avatars.discourse-cdn.com/v4/letter/b/87869e/32.png) [@beren](https://discuss.elastic.co/u/beren)\
**Post date:** [October 11, 2019, 11:06am UTC](https://discuss.elastic.co/t/topic/203057/7 "2019-10-11T11:06:29Z")

</div>

Спасибо. Проблема решена. На самом деле в лог ничего сегодня не писалось.

---

<div class="post-metadata">

**Author:** ![Dima\_I](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dima_i/32/54877_2.png) [@Dima\_I](https://discuss.elastic.co/u/Dima_I)\
**Post date:** [October 11, 2019, 5:06pm UTC](https://discuss.elastic.co/t/topic/203057/8 "2019-10-11T17:06:40Z")

</div>

На CentOS7/RHEL:  
systemctl cat filebeat.service  
ps uax | grep filebeat

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2019, 5:06pm UTC](https://discuss.elastic.co/t/topic/203057/9 "2019-11-08T17:06:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
