# Beats output to Logstash AND Elastic?

**URL:** <https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597>\
**Category:** Beats\
**Tags:** filebeat, packetbeat, auditbeat\
**Created:** [August 16, 2021, 7:58pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597 "2021-08-16T19:58:32Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 16, 2021, 7:58pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597/1 "2021-08-16T19:58:33Z")

</div>

Is it possible to Output to Elasticsearch AND Logstash at the same time from a Beat?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 16, 2021, 8:10pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597/2 "2021-08-16T20:10:39Z")

</div>

No, you can use only a single output. So you could send to Logstash and then have Logstash send to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 16, 2021, 9:12pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597/3 "2021-08-16T21:12:22Z")

</div>

But after receiving data in Logstash from beats, what i want is to send the output to different ES hosts(which is easy) but also send in on of them the event as it is, and to the other host i want to send a filtered event. How I'm gonna do that in Logstash pipeline?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 16, 2021, 11:41pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597/4 "2021-08-16T23:41:04Z")

</div>

You can use the pipeline output for this. [Pipeline-to-Pipeline Communication | Logstash Reference [7.14] | Elastic](https://www.elastic.co/guide/en/logstash/current/pipeline-to-pipeline.html)

Create three pipelines. The first pipeline has the `beats` input and it outputs to the two other pipelines. In the other pipelines you can implement the independent filtering logic since the events are copied.

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 17, 2021, 8:47am UTC](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597/5 "2021-08-17T08:47:48Z")

</div>

Indeed Pipeline to Pipeline might save my problem, but i do have a question here. Is it mandatory to put everything into pipelines.yml? Because i have a big pipeline .conf file.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 17, 2021, 11:02am UTC](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597/6 "2021-08-17T11:02:59Z")

</div>

pipelines.yml only declares the pipelines. The config is still contained in .conf files.

```auto
#pipelines.yml
- pipeline.id: my-pipeline_1
  path.config: /etc/path/to/p1.conf
  pipeline.workers: 10
- pipeline.id: my-pipeline_2
  path.config: /etc/path/to/p2.conf
  pipeline.workers: 10

```

Docs: [Multiple Pipelines | Logstash Reference [7.14] | Elastic](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html#multiple-pipelines)

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 17, 2021, 11:36am UTC](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597/7 "2021-08-17T11:36:17Z")

</div>

Ok then, because i saw that in the docs of Pipeline to Pipeline, all the config was inside the pipelines.yml and i thought that was mandatory. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2021, 1:36pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597/8 "2021-09-14T13:36:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
