# Best forwarder for elasticsearch

**URL:** https://discuss.elastic.co/t/best-forwarder-for-elasticsearch/45715
**Category:** Elasticsearch
**Created:** [March 29, 2016, 5:18pm UTC](https://discuss.elastic.co/t/best-forwarder-for-elasticsearch/45715 "2016-03-29T17:18:34Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![rajkumar3v](https://avatars.discourse-cdn.com/v4/letter/r/73ab20/32.png) [@rajkumar3v](https://discuss.elastic.co/u/rajkumar3v)
#### Post date: [March 29, 2016, 5:18pm UTC](https://discuss.elastic.co/t/best-forwarder-for-elasticsearch/45715/1 "2016-03-29T17:18:34Z")

</div>

Hi,

```
I am using Graylog + Elastic clusters in my small production setup. Right now am using splunk forwarder to forward logs also using splunk forwarder i can easily run a shell or bash script and forwarding the output to graylog + elastic cluster. 

```

Now I want to create a centralized elastic cluster which can be used by kibana and graylog with dedicated tenant indexes so please suggest me a log forwarder which should have capable to run bash & shell scripts also it should directly forward the logs to elasticsearch.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [March 29, 2016, 8:47pm UTC](https://discuss.elastic.co/t/best-forwarder-for-elasticsearch/45715/2 "2016-03-29T20:47:04Z")

</div>

Why do you want to run shell scripts in a log forwarder?

---

<div class="post-metadata">

### Author: ![rajkumar3v](https://avatars.discourse-cdn.com/v4/letter/r/73ab20/32.png) [@rajkumar3v](https://discuss.elastic.co/u/rajkumar3v)
#### Post date: [March 30, 2016, 2:39pm UTC](https://discuss.elastic.co/t/best-forwarder-for-elasticsearch/45715/3 "2016-03-30T14:39:54Z")

</div>

Hi Mark Walkom, thanks for your reply..

In production we have hundreds of servers, if I want to monitor cpu, memory, and disk utilization of servers I will place a script in splunk forwarder and it run the script with certain time interval and forwarding output along with other logs. like this kind of stuff i want to run scripts in forwarder. In filebeat and logstash i am not able to place scripts.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [March 30, 2016, 9:29pm UTC](https://discuss.elastic.co/t/best-forwarder-for-elasticsearch/45715/4 "2016-03-30T21:29:07Z")

</div>

If you want system metrics just use topbeat!

---

<div class="post-metadata">

### Author: ![rajkumar3v](https://avatars.discourse-cdn.com/v4/letter/r/73ab20/32.png) [@rajkumar3v](https://discuss.elastic.co/u/rajkumar3v)
#### Post date: [March 31, 2016, 4:43pm UTC](https://discuss.elastic.co/t/best-forwarder-for-elasticsearch/45715/5 "2016-03-31T16:43:26Z")

</div>

thank you. Mark Walkom.

---

<div class="post-metadata">

### Author: ![stecino](https://avatars.discourse-cdn.com/v4/letter/s/ea666f/32.png) [@stecino](https://discuss.elastic.co/u/stecino)
#### Post date: [June 17, 2016, 7:45pm UTC](https://discuss.elastic.co/t/best-forwarder-for-elasticsearch/45715/6 "2016-06-17T19:45:35Z")

</div>

Could you please share some details on how splunk forwarder can be configured to send to ELK.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [June 17, 2016, 10:05pm UTC](https://discuss.elastic.co/t/best-forwarder-for-elasticsearch/45715/7 "2016-06-17T22:05:49Z")

</div>

This is not a Splunk forum, you would have to ask them sorry.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 10:42pm UTC](https://discuss.elastic.co/t/best-forwarder-for-elasticsearch/45715/8 "2017-07-05T22:42:38Z")

</div>


