[Unit] Description=Filebeat sends log files to Logstash or directly to Elasticsearch. Documentation=https://www.elastic.co/products/beats/filebeat Wants=network-online.target After=network-online.target [Service] Environment="FILEBEAT_USER=root" Environment="FILEBEAT_GROUP=root" Environment="FILEBEAT_CONFIG=/etc/filebeat/filebeat.yml" Environment="FILEBEAT_DATADIR=/var/lib/filebeat" Environment="FILEBEAT_LOGDIR=/var/log/filebeat" Environment="FILEBEAT_OPTS=" EnvironmentFile=-/etc/conf.d/filebeat ExecStart=/usr/bin/filebeat -c $FILEBEAT_CONFIG $FILEBEAT_OPTS -path.config /etc/filebeat -path.data ${FILEBEAT_DATADIR} -path.home /usr/share/filebeat -path.logs ${FILEBEAT_LOGDIR} Restart=on-failure User=$FILEBEAT_USER Group=$FILEBEAT_GROUP [Install] WantedBy=multi-user.target