Filebeat configuration vi /etc/filebeat/filebeat.yml Search for output.elasticsearch and comment-out the lines as follows: [...] output.elasticsearch: # Array of hosts to connect to. hosts: ["YOUR-IP:9200"] [...] Enable the system plugin to handle generic system log files with Filebeat. Enable the plugin: filebeat modules enable system Check the filebeat configuration by: filebeat test config or First you have to move to this directory: /usr/share/filebeat/bin for Test config: ./filebeat test config -c /etc/filebeat/filebeat.yml --path.home /usr/share/filebeat/ --path.data /var/lib/filebeat/ for Test output: ./filebeat test output -c /etc/filebeat/filebeat.yml --path.home /usr/share/filebeat/ --path.data /var/lib/filebeat/ for Setup: ./filebeat setup -c /etc/filebeat/filebeat.yml --path.home /usr/share/filebeat/ --path.data /var/lib/filebeat/ Then start the filebeat: systemctl start filebeat systemctl stop filebeat systemctl restart filebeat systemctl status filebeat