# Creating pipeline Using beats in Windows and sending logs to logstash in linux

**URL:** https://discuss.elastic.co/t/creating-pipeline-using-beats-in-windows-and-sending-logs-to-logstash-in-linux/289191
**Category:** Logstash
**Created:** [November 15, 2021, 11:39am UTC](https://discuss.elastic.co/t/creating-pipeline-using-beats-in-windows-and-sending-logs-to-logstash-in-linux/289191 "2021-11-15T11:39:32Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Divyank\_Mahalle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divyank_mahalle/32/91240_2.png) [@Divyank\_Mahalle](https://discuss.elastic.co/u/Divyank_Mahalle)
#### Post date: [November 15, 2021, 11:39am UTC](https://discuss.elastic.co/t/creating-pipeline-using-beats-in-windows-and-sending-logs-to-logstash-in-linux/289191/1 "2021-11-15T11:39:32Z")

</div>

Hi,

I am creating a pipeline using beats in windows to extract logs in form of txt file in multiple directories and send it to the Linux(server) to logstash to es/kibana.

While running logstash conf pipeline I am getting error of Cannot assign requested address.

Below are the config.Pls let me know if any modification required in config or error coming from somewhere else.

filebeat.yml in windows system-

```auto
# ============================== Filebeat inputs ===============================
filebeat.inputs:
- type: log
  # Change to true to enable this input configuration.
  enabled: true
  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - D:\Test_Data\*
    - D:\Hi\*
    #- c:\programdata\elasticsearch\logs\*

# ------------------------------ Logstash Output -------------------------------
output.logstash:
  # The Logstash hosts
    hosts: ["12.123.12.123:5044"] #Linux Host ip

```

logstash.conf file in Linux-

```auto
input {
       beats{
         host => "12.123.12.123"
         port => 5044
      }
}

filter{<......>}
output{<..........>}

```

Error-Error: Cannot assign requested address

```auto
[INFO] 2021-11-15 16:45:47.684 [[main]<beats] Server - Starting server on port: 5044
[ERROR] 2021-11-15 16:45:53.729 [[main]<beats] javapipeline - A plugin had an unrecoverable error. Will restart this plugin.
  Pipeline_id:main
  Plugin: <LogStash::Inputs::Beats host=>"12.123.12.123", port=>5044, id=>"<>", enable_metric=>true, codec=><LogStash::Codecs::Plain id=>"<>", enable_metric=>true, charset=>"UTF-8">, ssl=>false, add_hostname=>false, ssl_verify_mode=>"none", ssl_peer_metadata=>false, include_codec_tag=>true, ssl_handshake_timeout=>10000, tls_min_version=>1, tls_max_version=>1.2, cipher_suites=>["TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384", "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384", "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256", "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256", "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384", "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384", "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256", "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256"], client_inactivity_timeout=>60, executor_threads=>4>
  Error: Cannot assign requested address
  Exception: Java::JavaNet::BindException
  Stack: sun.nio.ch.Net.bind0(Native Method)

```

ref link-  
[[Configure the Logstash output | Filebeat Reference [7.15] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html)][https://www.youtube.com/watch?v=BGZCEC6Mqkg](https://www.youtube.com/watch?v=BGZCEC6Mqkg)  
Thank you!!!

---

<div class="post-metadata">

### Author: ![ahmed\_charafouddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_charafouddine/32/45129_2.png) [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)
#### Post date: [November 15, 2021, 12:03pm UTC](https://discuss.elastic.co/t/creating-pipeline-using-beats-in-windows-and-sending-logs-to-logstash-in-linux/289191/2 "2021-11-15T12:03:19Z")

</div>

make sure the port is open between these two machines

---

<div class="post-metadata">

### Author: ![Divyank\_Mahalle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divyank_mahalle/32/91240_2.png) [@Divyank\_Mahalle](https://discuss.elastic.co/u/Divyank_Mahalle)
#### Post date: [November 16, 2021, 6:47am UTC](https://discuss.elastic.co/t/creating-pipeline-using-beats-in-windows-and-sending-logs-to-logstash-in-linux/289191/3 "2021-11-16T06:47:14Z")

</div>

Correct @ahmed_charafouddine, It worked.

A Lil query,how can I keep logstash and filebeat pipeline running 24\*7 to get real-time logs fetched in elastic,

```auto
.\filebeat.exe -c filebeat.yml

sudo bin/logstash -f /etc/logstash/conf.d/<...>.conf

```

I run filebeat in PowerShell and got start, stop commands for filebeat, but didn't get a command for how to check the status of filebeat, unlike logstash.

> sudo systemctl status logstash.service

```auto
PS> Start-Service filebeat

PS > Stop-Service filebeat

```

While I run logstash conf file manually, results are getting stored in kibana.

When I schedule pipeline \>\>schedule =\> { every =\> "15s"} or with cron scheduler,it's not working.

```auto
input {
       beats{
        
         port => <....>
      }
  schedule => { cron => "1 * * * * UTC"}
}

```

Currently running filebeat and logstash pipeline manually for testing and working fine.

Thanks!!!

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [November 16, 2021, 4:21pm UTC](https://discuss.elastic.co/t/creating-pipeline-using-beats-in-windows-and-sending-logs-to-logstash-in-linux/289191/4 "2021-11-16T16:21:44Z")

</div>

There is no `schedule` in the beats input, remove that line.

Should be:

```auto
input {
       beats {
         port => "port-number"
      }
}

```

---

<div class="post-metadata">

### Author: ![Divyank\_Mahalle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divyank_mahalle/32/91240_2.png) [@Divyank\_Mahalle](https://discuss.elastic.co/u/Divyank_Mahalle)
#### Post date: [November 16, 2021, 4:30pm UTC](https://discuss.elastic.co/t/creating-pipeline-using-beats-in-windows-and-sending-logs-to-logstash-in-linux/289191/5 "2021-11-16T16:30:09Z")

</div>

Hi @leandrojmp ,

Got it. But currently, to fetch data to kibana I am running logstash conf file manually.It's working fine.

> sudo bin/logstash -f /etc/logstash/conf.d/\<...\>.conf

Is there anything I can do to schedule it or it will run automatically and ingest data to elasticsearch immediately after a new log is ingested in the directory?

Or is there any way to keep logstash pipeline running in Linux 24\*7 to resolve this.

Filebeat is running on windows (server)using this command.

> PS\> Start-Service filebeat

logstash is present in linux server and running.

**Update-**

> Is there anything I can do to schedule it or it will run automatically and ingest data to elasticsearch immediately after a new log is ingested in the directory?

After stopping and starting logstash the inputs beats plugin start sending data via logstash to elasticsearch automatically, so no need to schedule it as it will send data once new data present in directory.

Start/stop logstash does the work.

```auto
systemctl stop service.logstash
systemctl start service.logstash

```

Thanks once again

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 14, 2021, 4:30pm UTC](https://discuss.elastic.co/t/creating-pipeline-using-beats-in-windows-and-sending-logs-to-logstash-in-linux/289191/6 "2021-12-14T16:30:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
