# Connecting FileBeats to Logstash

**URL:** <https://discuss.elastic.co/t/connecting-filebeats-to-logstash/44575>\
**Category:** Logstash\
**Created:** [March 16, 2016, 3:11pm UTC](https://discuss.elastic.co/t/connecting-filebeats-to-logstash/44575 "2016-03-16T15:11:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nateuni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nateuni/32/8512_2.png) [@nateuni](https://discuss.elastic.co/u/nateuni)\
**Post date:** [March 16, 2016, 3:11pm UTC](https://discuss.elastic.co/t/connecting-filebeats-to-logstash/44575/1 "2016-03-16T15:11:24Z")

</div>

I have FileBeats running on an ubuntu webserver on EC2. I have opened up the ports, but still I cannot get them to talk to each other.

filebeats starts without errors but I cannot get it to print the apache logs to the console as output.  
Nor can I get logstash to connect to filebeats, as when I load logstash it gives me this error:

{:timestamp=\>"2016-03-16T14:58:48.583000+0000", :message=\>"The error reported is: \n Cannot assign requested address - bind - Cannot assign requested address"}

Here ate my config files.. it has been a long day. Am I overlooking/missing something ?

Filebeat.conf:

```
################### Filebeat Configuration Example #########################

############################# Filebeat ######################################
filebeat:
  # List of prospectors to fetch data.
  prospectors:
    # Each - is a prospector. Below are the prospector specific configurations
    -
      # Paths that should be crawled and fetched. Glob based paths.
      # To fetch all ".log" files from a specific level of subdirectories
      # /var/log/*/*.log can be used.
      # For each file found under this path, a harvester is started.
      # Make sure not file is defined twice as this can lead to unexpected behaviour.
      paths:
        - "/home/bitnami/stack/apache2/logs/access_log"
        #- c:\programdata\elasticsearch\logs\*

      input_type: log

      

############################# Output ##########################################

output:
  logstash:
    # The Logstash hosts
    hosts: ["<LOGSTASH IP>:5044"]

  ### Console output
  console:
    # Pretty print json event
    pretty: true

```

logstash.yml:

```
input {
  beats {
    host => "<FileBeats IP>"
    port => 5044
  }
}

output {
  stdout {
    codec => rubydebug
  }
  kafka {
    bootstrap_servers => "<KAFKA IP>:9092"
    topic_id => "from_logstash"
  }
}
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 17, 2016, 12:50am UTC](https://discuss.elastic.co/t/connecting-filebeats-to-logstash/44575/2 "2016-03-17T00:50:38Z")

</div>

> [@nateuni](#):
>
> ```auto
> input {
> beats {
> host => "52.23.229.250"
> port => 5044
> }
> }
> 
> ```

Remove the `host` line. That's for binding to a specific interface.

---

<div class="post-metadata">

**Author:** ![nateuni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nateuni/32/8512_2.png) [@nateuni](https://discuss.elastic.co/u/nateuni)\
**Post date:** [March 17, 2016, 1:16am UTC](https://discuss.elastic.co/t/connecting-filebeats-to-logstash/44575/3 "2016-03-17T01:16:09Z")

</div>

Oh if I could hug you I would! **virtual hug applied here** Thanks heaps

Can you explain why I didn't need that?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 17, 2016, 4:17am UTC](https://discuss.elastic.co/t/connecting-filebeats-to-logstash/44575/4 "2016-03-17T04:17:58Z")

</div>

Logstash-beats-input accepts connections. It does not initiate connections, so you don't need to specify the IP of the host running Beats.

By default Logstash will listen (aka bind) on all network interfaces. If you want to listen on a specific network interface (e.g. loopback) you would enter the IP address of that interface (for loopback it would be 127.0.0.1).

The default value for `host` is [0.0.0.0](https://en.wikipedia.org/wiki/0.0.0.0) which is sometimes called the "any" address because it means to bind to all interfaces.

You can use a command like `netstat -anp` to see what ports and interfaces that processes are bound to.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/connecting-filebeats-to-logstash/44575/5 "2017-07-06T05:06:33Z")

</div>


