# Beats' output, logstash or elasticsearh

**URL:** <https://discuss.elastic.co/t/beats-output-logstash-or-elasticsearh/179894>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 7, 2019, 6:35am UTC](https://discuss.elastic.co/t/beats-output-logstash-or-elasticsearh/179894 "2019-05-07T06:35:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gray380](https://avatars.discourse-cdn.com/v4/letter/g/7993a0/32.png) [@gray380](https://discuss.elastic.co/u/gray380)\
**Post date:** [May 7, 2019, 6:35am UTC](https://discuss.elastic.co/t/beats-output-logstash-or-elasticsearh/179894/1 "2019-05-07T06:35:35Z")

</div>

Hi there,

What is the best or recommended way to collect "auth" data within Beats, directly send it to elasticsearch or via logstash?  
For now beats are configured to use "output.logstash" and module "system" is enabled.

So I can find the "authentication failure" with non-parsed message at kibana's "Discover":

```
agent.type filebeat
agent.version 7.0.1
ecs.version 1.0.0
event.dataset system.auth
event.module system
fileset.name auth
suricata.eve.timestamp ... <--- BTW WTF?

```

Also "Syslog" section of "[Filebeat System] SSH login attempts ECS" dashboard contains data, but "Sudo commands" and "SSH logins" are pretty empty.

Could you help with findings.

---

<div class="post-metadata">

**Author:** ![Michal\_Pristas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michal_pristas/32/46639_2.png) [@Michal\_Pristas](https://discuss.elastic.co/u/Michal_Pristas)\
**Post date:** [May 7, 2019, 11:42am UTC](https://discuss.elastic.co/t/beats-output-logstash-or-elasticsearh/179894/2 "2019-05-07T11:42:52Z")

</div>

whether or not use Logstash depends mostly on your use case. if you want to do some advanced parsing or transformation I recommend using Logstash.  
If these transformations are simple enough for beat to handle it you can output to ES directly

---

<div class="post-metadata">

**Author:** ![gray380](https://avatars.discourse-cdn.com/v4/letter/g/7993a0/32.png) [@gray380](https://discuss.elastic.co/u/gray380)\
**Post date:** [May 7, 2019, 11:53am UTC](https://discuss.elastic.co/t/beats-output-logstash-or-elasticsearh/179894/3 "2019-05-07T11:53:42Z")

</div>

Thanks, I understand the concept but seems that there is some issues with embedded kibana's dashboard after "logstashing" the beat's outputs.

---

<div class="post-metadata">

**Author:** ![gray380](https://avatars.discourse-cdn.com/v4/letter/g/7993a0/32.png) [@gray380](https://discuss.elastic.co/u/gray380)\
**Post date:** [May 7, 2019, 1:38pm UTC](https://discuss.elastic.co/t/beats-output-logstash-or-elasticsearh/179894/4 "2019-05-07T13:38:55Z")

</div>

Okay, Kibana's default Visualize uses "event.action" to count ssh login attempts but in my case it should be "system.auth.ssh.event".  
For some reason I can not modify the default Visualize templates.  
Suppose it's okay to close this topic.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2019, 1:38pm UTC](https://discuss.elastic.co/t/beats-output-logstash-or-elasticsearh/179894/5 "2019-06-04T13:38:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
