# Centralised logging for Apache

**URL:** https://discuss.elastic.co/t/centralised-logging-for-apache/73825
**Category:** Logstash
**Created:** [February 3, 2017, 10:21am UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825 "2017-02-03T10:21:08Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![vineets928](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineets928/32/94852_2.png) [@vineets928](https://discuss.elastic.co/u/vineets928)
#### Post date: [February 3, 2017, 10:21am UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/1 "2017-02-03T10:21:08Z")

</div>

Hi,  
I am new in elk stack. Please someone help me.

We have 4 application running on apache server. Client don't want to use filebeat to push log individually to logstash as this will affect the performance of the application.  
So, is there any alternate to process log file without filebeat?  
Can we use syslog server and then forward the log to logstash?

Plz help

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [February 5, 2017, 9:37am UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/2 "2017-02-05T09:37:52Z")

</div>

> [@vineets928](#):
>
> Can we use syslog server and then forward the log to logstash?

Yes.

---

<div class="post-metadata">

### Author: ![kopacko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kopacko/32/10733_2.png) [@kopacko](https://discuss.elastic.co/u/kopacko)
#### Post date: [February 6, 2017, 6:23am UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/3 "2017-02-06T06:23:21Z")

</div>

I use syslog-ng to push out system and internal logs to Logstash from all of my servers.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [February 6, 2017, 7:04am UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/4 "2017-02-06T07:04:19Z")

</div>

> Client don't want to use filebeat to push log individually to logstash as this will affect the performance of the application.

How so?

---

<div class="post-metadata">

### Author: ![vineets928](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineets928/32/94852_2.png) [@vineets928](https://discuss.elastic.co/u/vineets928)
#### Post date: [February 6, 2017, 7:37am UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/5 "2017-02-06T07:37:16Z")

</div>

They worried that it will consume resources of production server which in turn affect their performance.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [February 6, 2017, 7:44am UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/6 "2017-02-06T07:44:34Z")

</div>

Well, sending things via syslog isn't completely without cost either and can actually be more problematic since you either have to send data via TCP, which could block your application and/or lose logs, or UDP, which obviously can lead to loss of logs.

Instead of worrying they should measure the impact and weigh the cost against not collecting logs.

---

<div class="post-metadata">

### Author: ![kopacko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kopacko/32/10733_2.png) [@kopacko](https://discuss.elastic.co/u/kopacko)
#### Post date: [February 7, 2017, 4:14pm UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/7 "2017-02-07T16:14:35Z")

</div>

I'd have to agree with Magnus.

The impact is very, very minimal regardless which option is chosen.

---

<div class="post-metadata">

### Author: ![vineets928](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineets928/32/94852_2.png) [@vineets928](https://discuss.elastic.co/u/vineets928)
#### Post date: [February 9, 2017, 10:42am UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/8 "2017-02-09T10:42:24Z")

</div>

@magnusbaeck Thanks....  
Finally they convinced 🙂  
Now we have one more issue.....  
We are sending log from two different host using filebeat to logstash, but we are getting only one hostname in available field in kibana i.e. in our case we are sending log from root@server1 and root@server2. But we are getting only server1 in kibana and also in hostname.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [February 9, 2017, 11:02am UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/9 "2017-02-09T11:02:52Z")

</div>

Check the Filebeat logs on server2.

---

<div class="post-metadata">

### Author: ![kopacko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kopacko/32/10733_2.png) [@kopacko](https://discuss.elastic.co/u/kopacko)
#### Post date: [February 9, 2017, 2:36pm UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/10 "2017-02-09T14:36:52Z")

</div>

And does tcpdump show any incoming packets?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 9, 2017, 2:36pm UTC](https://discuss.elastic.co/t/centralised-logging-for-apache/73825/11 "2017-03-09T14:36:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
