# Can't see logs population on ELK machine from different different filebeat machines?

**URL:** <https://discuss.elastic.co/t/cant-see-logs-population-on-elk-machine-from-different-different-filebeat-machines/121456>\
**Category:** Logstash\
**Created:** [February 26, 2018, 9:02am UTC](https://discuss.elastic.co/t/cant-see-logs-population-on-elk-machine-from-different-different-filebeat-machines/121456 "2018-02-26T09:02:59Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashish\_khulbe](https://avatars.discourse-cdn.com/v4/letter/a/ea5d25/32.png) [@ashish\_khulbe](https://discuss.elastic.co/u/ashish_khulbe)\
**Post date:** [February 26, 2018, 9:02am UTC](https://discuss.elastic.co/t/cant-see-logs-population-on-elk-machine-from-different-different-filebeat-machines/121456/1 "2018-02-26T09:02:59Z")

</div>

Hi Team,

I am new to ELK , just installed ELK and filebeat 2 days ago.  
I am able to see logs from 2 different filebeat clients logs in ELK machine, when working in ubuntu for syslog(default logs).

But, When working with custom index and type for custom filter/match specific line, it is not working. The same filter, index are working fine when using windows setup (but without filebeat) in single machine setup.

1. I made a sample log file (tsyslog in /var/log/).  
[DEBUG]:[test385231]:[admin]:[Jan 17 04:56:23]:[h5vnkdksvj6dmij14]:[INIT]:[Event.Pre\_deploymentevent\_check\_started]:[com.aricent.openstackdeploy.VMDeployLauncher{1}:68]

2. Configured filebeat.yml

filebeat:

# List of prospectors to fetch data.

prospectors:  
-  
paths:  
- /var/log/tsyslog  
document\_type: type  
registry\_file: /var/lib/filebeat/registry  
---- rest settings are similar -----

## Filter used:-

## filter { if [type] == "tsyslog" { grok { match =\> { "message" =\> "[%{LOGLEVEL:Severity}]:[%{SYSLOGHOST:Host\_Name}]:[%{DATA:User\_Name}]:[%{SYSLOGTIMESTAMP:timestamp}]:[%{DATA:Session\_ID}]:[%{DATA:Function\_Name}]:[%{DATA:Event}]:[%{GREEDYDATA:message}]" } add\_field =\> ["received\_at", "%{@timestamp}"] add\_field =\> ["received\_from", "%{host}"] add\_field =\> ["received\_user", "%{User\_Name}"] add\_field =\> ["received\_session", "%{Session\_ID}"] add\_field =\> ["received\_Function\_Name", "%{Function\_Name}"] add\_field =\> ["received\_event", "%{Event}"] } syslog\_pri { } date { match =\> ["syslog\_timestamp", "YYYY MMM dd HH:mm:ss", "YYYY MMM dd HH:mm:ss"] } } } ~

## output { elasticsearch { hosts =\> ["localhost:9200"] sniffing =\> true manage\_template =\> false index =\> "test3" document\_type =\> "test3type" } }

Thanks in advance  
Ashu

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2018, 9:03am UTC](https://discuss.elastic.co/t/cant-see-logs-population-on-elk-machine-from-different-different-filebeat-machines/121456/2 "2018-03-26T09:03:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
