# Collecting logs from Azure EH

**URL:** <https://discuss.elastic.co/t/collecting-logs-from-azure-eh/336088>\
**Category:** Logstash\
**Created:** [June 15, 2023, 11:53am UTC](https://discuss.elastic.co/t/collecting-logs-from-azure-eh/336088 "2023-06-15T11:53:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![wedkarz014](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wedkarz014/32/48935_2.png) [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Post date:** [June 15, 2023, 11:53am UTC](https://discuss.elastic.co/t/collecting-logs-from-azure-eh/336088/1 "2023-06-15T11:53:08Z")

</div>

Hello,  
My question is, which tool should i use to collect data from Eh, logstash: [Azure Event Hubs plugin | Logstash Reference [8.8] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-azure_event_hubs.html#plugins-inputs-azure_event_hubs-storage_connection) or filebeat: [Azure eventhub input | Filebeat Reference [8.8] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-azure-eventhub.html) ? Which solution is better and why?

Best  
Patryk

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 15, 2023, 12:05pm UTC](https://discuss.elastic.co/t/collecting-logs-from-azure-eh/336088/2 "2023-06-15T12:05:00Z")

</div>

> [@wedkarz014](#):
>
> Which solution is better and why?

Only you can say as it depends entirely on your use case.

Logstash is more flexible and powerful than Filebeat, but it also needs more resources since it runs on a JVM.

Filebeat is more lightweight, but has some limitations if you need to transform your data and can only have one output.

Normally you would use Logstash if you want to transform your data with multiple filters and enrich or if you need to send it to multiple places at the same time.

While today you can use Ingest Pipelines in Elasticsearch to transform and enrich your data, it is pretty limited compared to Logstash, but this works for many cases, you just need to test to see if you what you want to do can be done without Logstash or not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2023, 12:05pm UTC](https://discuss.elastic.co/t/collecting-logs-from-azure-eh/336088/3 "2023-07-13T12:05:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
