# Connecting filebeat with elasticseach

**URL:** <https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 7, 2020, 6:56am UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832 "2020-04-07T06:56:13Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daud\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daud_ahmed/32/65655_2.png) [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Post date:** [April 7, 2020, 6:56am UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/1 "2020-04-07T06:56:13Z")

</div>

I have like 5 elastic nodes in total. One node ingest and coordinating node while two are dedicated master nodes and the other two are dedicated data nodes.

I have elasticsearch install on all my five nodes with respective settings.  
What i am confused about and want to know is.  
Does i need to include all the elasticsearch nodes ip addresses in filebeat.yml file  
which is install on seperate node.  
`output.elasticsearch.hosts: ['https://x.x.x.x', '' '',""]`

or i should add only the data nodes. Actually i am really confuse and don't know much about this. Filebeat will be inserting data into elasticsearch so can anyone guide on this.

---

<div class="post-metadata">

**Author:** ![oumy](https://avatars.discourse-cdn.com/v4/letter/o/a88e57/32.png) [@oumy](https://discuss.elastic.co/u/oumy)\
**Post date:** [April 7, 2020, 7:08pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/2 "2020-04-07T19:08:16Z")

</div>

hello, i am trying to do the same thing. dashboards are not working. do i need to install elastic on all my VMs or just in the master one ?

---

<div class="post-metadata">

**Author:** ![Daud\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daud_ahmed/32/65655_2.png) [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Post date:** [April 7, 2020, 7:09pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/3 "2020-04-07T19:09:44Z")

</div>

you have to install elasticsearch on all vms regardless of what type of node you are trying to have a data, ingest or master.

---

<div class="post-metadata">

**Author:** ![Daud\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daud_ahmed/32/65655_2.png) [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Post date:** [April 7, 2020, 7:11pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/4 "2020-04-07T19:11:45Z")

</div>

but you can install kibana on seperate vm as well if you want too..... as far as filebeat or logstash is concerned it will be install from where you want to ship data to elasticsearch .... so it can be directly connected to elasticsearch you will not be needed to install filebeat along elasticsearch on that machine.

---

<div class="post-metadata">

**Author:** ![oumy](https://avatars.discourse-cdn.com/v4/letter/o/a88e57/32.png) [@oumy](https://discuss.elastic.co/u/oumy)\
**Post date:** [April 7, 2020, 7:15pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/5 "2020-04-07T19:15:35Z")

</div>

okey thank you very much. this was helpful hope you can find your answer

---

<div class="post-metadata">

**Author:** ![Daud\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daud_ahmed/32/65655_2.png) [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Post date:** [April 7, 2020, 7:26pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/6 "2020-04-07T19:26:24Z")

</div>

I did lol

---

<div class="post-metadata">

**Author:** ![cporte01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cporte01/32/73781_2.png) [@cporte01](https://discuss.elastic.co/u/cporte01)\
**Post date:** [May 4, 2020, 12:51pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/7 "2020-05-04T12:51:57Z")

</div>

Hi Daud\_Ahmed

Did you ever find out the answer to your original question regarding which hosts must be included in the output.elasticsearch hosts property (master, data, indest)? My guess is it's the data nodes unless you're using logstash or dedicated ingest nodes, but the ingest/pipeline nodes also have to send their data somewhere. I agree it's confusing for a beginner like me. I've searched and searched Elastic's documentation and I just can't find a definite answer. The documentation always just says "Elasticsearch nodes".

---

<div class="post-metadata">

**Author:** ![Daud\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daud_ahmed/32/65655_2.png) [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Post date:** [May 4, 2020, 1:10pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/8 "2020-05-04T13:10:45Z")

</div>

hi @cporte01,

The thing is they have to be ingest nodes........

Basically, you have to include those nodes which includes in elasticsearch.yml file...

node.ingest: true

if your data nodes have this attribute it means they are acting as both data and ingest node so you will point out to them.

But in case you have node.ingest: false and have dedicated ingest nodes then you will includes only those nodes in

**output.elasticsearch.hosts**

Hope this help. Feel free to ask if you have any more question.

---

<div class="post-metadata">

**Author:** ![cporte01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cporte01/32/73781_2.png) [@cporte01](https://discuss.elastic.co/u/cporte01)\
**Post date:** [May 4, 2020, 5:06pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/9 "2020-05-04T17:06:18Z")

</div>

Thank you! I think I finally get it. All Elasticsearch nodes are ingest nodes by default. Our ingest volume is still quite low so until volume increases enough that we need to start using dedicated ingest-only nodes I will send filebeat data to the data nodes. My master-eligible nodes are master-only so they will not be included in the filebeat output.

Thanks again for your help!

---

<div class="post-metadata">

**Author:** ![Daud\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daud_ahmed/32/65655_2.png) [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Post date:** [May 4, 2020, 5:18pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/10 "2020-05-04T17:18:58Z")

</div>

Great @cporte01 ingest nodes need also depend upon the use of ingest pipeline...

---

<div class="post-metadata">

**Author:** ![Daud\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daud_ahmed/32/65655_2.png) [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Post date:** [May 4, 2020, 5:19pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/11 "2020-05-04T17:19:12Z")

</div>

best of luck 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2020, 5:33pm UTC](https://discuss.elastic.co/t/connecting-filebeat-with-elasticseach/226832/12 "2020-06-01T17:33:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
