# Elastic-agent -- Sent logs to external SIEM

**URL:** <https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045>\
**Category:** Elastic Security\
**Tags:** fleet\
**Created:** [February 2, 2022, 9:38am UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045 "2022-02-02T09:38:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![fselim](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@fselim](https://discuss.elastic.co/u/fselim)\
**Post date:** [February 2, 2022, 9:38am UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045/1 "2022-02-02T09:38:56Z")

</div>

Goodmorning,

We have installed elastic-agents throughout our environment with everything setup for filebeat and metricbeat monitoring. Though now I'm trying to figure out how to forward logs to an external SIEM when the elastic-agent can't output to logstash.  
Is there a different way of sending logs to our external SIEM other then logstash?

Kind regards,  
Fadi

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [February 2, 2022, 2:12pm UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045/2 "2022-02-02T14:12:27Z")

</div>

No, right now elastic agent can only output to logstash or Elasticsearch.

---

<div class="post-metadata">

**Author:** ![Nima\_Rezainia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nima_rezainia/32/88626_2.png) [@Nima\_Rezainia](https://discuss.elastic.co/u/Nima_Rezainia)\
**Post date:** [February 2, 2022, 3:14pm UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045/3 "2022-02-02T15:14:29Z")

</div>

Hi, just a small clarification: Currently the centrally managed agents are not able to write to Logstash. This is work in progress. You can however write to Logstash if your agents are self-managed.

---

<div class="post-metadata">

**Author:** ![fselim](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@fselim](https://discuss.elastic.co/u/fselim)\
**Post date:** [February 3, 2022, 8:03am UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045/4 "2022-02-03T08:03:57Z")

</div>

Hi, thank you for the quick response. We do use centrally managed agents via fleet. So from what I take it is that right now it is not possible to send logs separately to an external SIEM other then hosting self-managed agents throughout our entire environment?

Is there any ETA on when this will be a possibility?

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [February 3, 2022, 8:56am UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045/5 "2022-02-03T08:56:51Z")

</div>

Hi,

Not entirely;

Sending information from your fleet managed agents can only be done with the output Elasticsearch. However what you can do if you want to forward logs to a secondary solution is  
setting up a logstash instance which queries Elasticsearch and have that pipeline output to your external SIEM.

Setup would then look like:

```auto
elastic agent --> elasticsearch --> logstash --> external siem

```

Logstash would use:

- [elasticsearch input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html)
- [find your ouput](https://www.elastic.co/guide/en/logstash/current/output-plugins.html)  
Added benefit is you can use the filter stage in logstash to convert the events to what your SIEM is expecting.

---

<div class="post-metadata">

**Author:** ![fselim](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@fselim](https://discuss.elastic.co/u/fselim)\
**Post date:** [February 3, 2022, 1:19pm UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045/6 "2022-02-03T13:19:52Z")

</div>

Didn't think of that approach yet indeed, thanks for the thought. But we have quite some indexes that would need to get queried every 10 seconds or even more frequent preferably. Don't know how feasable that is?

I did think of another approach which is to install seperate filebeats (for now) which log to logstash. And then logstash only outputs to SIEM.

Don't quite know which is the better option here.

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [February 3, 2022, 1:37pm UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045/7 "2022-02-03T13:37:01Z")

</div>

What is your usecase of Elasticsearch? As in what size retention etc are you trying to achieve?

---

<div class="post-metadata">

**Author:** ![Nima\_Rezainia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nima_rezainia/32/88626_2.png) [@Nima\_Rezainia](https://discuss.elastic.co/u/Nima_Rezainia)\
**Post date:** [February 3, 2022, 3:26pm UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045/8 "2022-02-03T15:26:19Z")

</div>

supporting logstash as an output for managed agents is the highest priority for the team.  
Once available you should be able to use an output plugin in logstash to create this pipeline (which I believe is your intention):

elastic-agent --\> Logstash ----+----\> external siem  
|  
+---\> Elasticsearch

---

<div class="post-metadata">

**Author:** ![fselim](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@fselim](https://discuss.elastic.co/u/fselim)\
**Post date:** [February 4, 2022, 8:07am UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045/9 "2022-02-04T08:07:47Z")

</div>

Thank you for the response, we'll await this solution then. Should be the best solution for this. Also for message queuing and grok operations (which you don't want on the elastic nodes themselves or the host servers).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 4, 2022, 8:08am UTC](https://discuss.elastic.co/t/elastic-agent-sent-logs-to-external-siem/296045/10 "2022-03-04T08:08:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
