# Debugging lost data in logstash coming from filebeat

**URL:** <https://discuss.elastic.co/t/debugging-lost-data-in-logstash-coming-from-filebeat/327110>\
**Category:** Logstash\
**Created:** [March 6, 2023, 5:07pm UTC](https://discuss.elastic.co/t/debugging-lost-data-in-logstash-coming-from-filebeat/327110 "2023-03-06T17:07:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mayer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayer/32/42164_2.png) [@mayer](https://discuss.elastic.co/u/mayer)\
**Post date:** [March 6, 2023, 5:07pm UTC](https://discuss.elastic.co/t/debugging-lost-data-in-logstash-coming-from-filebeat/327110/1 "2023-03-06T17:07:51Z")

</div>

Dear All,  
I am running a central ELK stack 8.6.2 with logstash to collect data from some server around. More than 2 years ago I compiled filebeat by myself as it was not available on ARM architecture. With a minimal configuration I read data from a file and send it to central logstash and then to elasticsearch DB where I can see data via kibana.  
Now filebeat is available as packaged on ARM architecture and I installed this packages. With a similar minimal configuration I started filebeat. With tcpdump I see that data is transferred on the configured port between these two servers, but I don't see the data in ELK.

Now my question how can I debug where my data get lost ? The logs don't give me an answer.

Kind regards  
Hans

--

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2023, 5:08pm UTC](https://discuss.elastic.co/t/debugging-lost-data-in-logstash-coming-from-filebeat/327110/2 "2023-04-03T17:08:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
