# Elastic Stack shipped dashboards for Kibana

**URL:** <https://discuss.elastic.co/t/elastic-stack-shipped-dashboards-for-kibana/71975>\
**Category:** Beats\
**Created:** [January 18, 2017, 10:17am UTC](https://discuss.elastic.co/t/elastic-stack-shipped-dashboards-for-kibana/71975 "2017-01-18T10:17:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ametad](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@ametad](https://discuss.elastic.co/u/ametad)\
**Post date:** [January 18, 2017, 10:17am UTC](https://discuss.elastic.co/t/elastic-stack-shipped-dashboards-for-kibana/71975/1 "2017-01-18T10:17:41Z")

</div>

Hi community,

I am fairly new to Elastic Stack (or ELK) and I am a bit confused about the role of Logstash in conjunction with the Beats. Because Beats ships with dashboard you can import easily... But these dashboards uses the different Beats indexes (metric, packet, etc.) by default. If you use Logstash, then everything is indexed in 'logstash-\*' by default, or you have to configure Logstash to use different indexes.

You could let the Beats index their data right into Elasticsearch. But then you cannot enrich the data if you want... am I correct?

How would you set this all up when you want to make use of the Beats, Logstash and(!) the dashboards shipped with Beats?

---

<div class="post-metadata">

**Author:** ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)\
**Post date:** [January 18, 2017, 10:52am UTC](https://discuss.elastic.co/t/elastic-stack-shipped-dashboards-for-kibana/71975/2 "2017-01-18T10:52:34Z")

</div>

In the case of Metricbeat and Packetbeat, you can send the data directly to Elasticsearch without the need to send it thought Logstash as the data is already structured. In this case, you can use the sample Kibana dashboards as they are, without the need to change the index.

In the case of Filebeat and Winlogbeat, the data is sent in a raw format and it requires using Logstash or Ingest node plugin in Elasticsearch to parse the logs before sending it to Elasticsearch. This is one of the reasons we don't have a sample dashboard for Filebeat, as we cannot know in advance how the data will look after parsing.

We are working on a new feature (Filebeat modules) that comes with out of the box configuration needed to read, parse and visualize data from various log files formats. This includes Ingest Node pipelines, Elasticsearch templates, Filebeat prospectors configurations, and Kibana dashboards.

---

<div class="post-metadata">

**Author:** ![ametad](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@ametad](https://discuss.elastic.co/u/ametad)\
**Post date:** [January 18, 2017, 11:22am UTC](https://discuss.elastic.co/t/elastic-stack-shipped-dashboards-for-kibana/71975/3 "2017-01-18T11:22:24Z")

</div>

Thank you for your quick reply and bit of insight of what you all are working on!

Those modules are already present I think in the (e.g.) Metricbeat, right? [https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-modules.html](https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-modules.html)  
So this is also coming for Filebeat, nice!

---

<div class="post-metadata">

**Author:** ![ametad](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@ametad](https://discuss.elastic.co/u/ametad)\
**Post date:** [January 18, 2017, 11:25am UTC](https://discuss.elastic.co/t/elastic-stack-shipped-dashboards-for-kibana/71975/4 "2017-01-18T11:25:36Z")

</div>

With those modules for Filebeat, what is the role of Logstash in the Stack is your opinion? Still for enrichment I guess..

---

<div class="post-metadata">

**Author:** ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)\
**Post date:** [January 19, 2017, 10:32am UTC](https://discuss.elastic.co/t/elastic-stack-shipped-dashboards-for-kibana/71975/5 "2017-01-19T10:32:14Z")

</div>

Filebeat modules give you a nice getting started experience, but for advanced functionality you would typically introduce Logstash. For example, you would use Logstash when you need a persistent queue before sending data to Elasticsearch, when you want to send the data to other systems besides Elasticsearch, or when you want to enrich your data by getting more information from external sources.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2017, 10:17am UTC](https://discuss.elastic.co/t/elastic-stack-shipped-dashboards-for-kibana/71975/6 "2017-02-08T10:17:48Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
