# Elasticsearch does not send logs to filebeat and/or Logstash

**URL:** <https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405>\
**Category:** Elasticsearch\
**Created:** [February 16, 2021, 10:25am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405 "2021-02-16T10:25:17Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Royal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/royal/32/77467_2.png) [@Royal](https://discuss.elastic.co/u/Royal)\
**Post date:** [February 16, 2021, 10:25am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/1 "2021-02-16T10:25:17Z")

</div>

Our situation is as follows: We have a Kubernetes Cluster with a lot of logs piling up. We would like to get a centralized place for the logs to query through. This centralized place is a local VM, which has Elasticsearch, Kibana, Logstash and Filebeat installed in one place.

The kubernetes cluster (with IP 192.168.253.160) sends the logs to the IP of the local VM (192.168.253.150) and the port of local Elasticsearch (which is 9200). This all works fine and I can see the logs being send to Elasticsearch using Kibana.

Only the problem here is that these logs don't go through Logstash and/or Filebeat, because if I try to put a filter on the Logstash configuration, nothing happens to the logs. Even if I stop Logstash and Filebeat completely, the logs still get send to Elasticsearch no problem.

I'm pretty sure the logs don't need to be send to Elasticsearch port, but when I try to send them to the ports 9600 (which is Logstash) or 5044 (which is Filebeat) the logs don't go through and I can't see them come into Kibana anymore. Maybe I need the use of the HTTP API?

Below I'll provide the changes I made in the configs of Elasticsearch, Logstash and Filebeat:

**Elasticsearch:**

```auto
    nano /etc/elasticsearch/elasticsearch.yml

```

```auto
    # ---------------------------------- Network -----------------------------------
    #
    # Set the bind address to a specific IP (IPv4 or IPv6):
    #
    network.host: 0.0.0.0
    #
    # Set a custom port for HTTP:
    #
    #http.port: 9200
    #
    # For more information, consult the network module documentation.
    #

```

**Filebeat:**

```auto
    nano /etc/filebeat/filebeat.yml

```

```auto
    # ---------------------------- Elasticsearch Output ----------------------------
#output.elasticsearch:
  # Array of hosts to connect to.
  #hosts: ["localhost:9200"]

  # Protocol - either `http` (default) or `https`.
  #protocol: "https"

  # Authentication credentials - either API key or username/password.
  #api_key: "id:api_key"
  #username: "elastic"
  #password: "changeme"

# ------------------------------ Logstash Output -------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["0.0.0.0:5044"]

  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  #ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]

  # Certificate for SSL client authentication
  #ssl.certificate: "/etc/pki/client/cert.pem"

  # Client Certificate Key
  #ssl.key: "/etc/pki/client/cert.key"

```

**Logstash:**  
`nano /etc/logstash/conf.d/02-beats-input.conf`

```auto
input {
  beats {
    port => 5044
  }
}
output {
         stdout { codec => rubydebug }
}

```

Also, I'm very new to all of this and IT in general, so please make it a bit noob friendly. Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 16, 2021, 11:19pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/2 "2021-02-16T23:19:49Z")

</div>

> [@Royal](#):
>
> `hosts: ["0.0.0.0:5044"]`

That's not a valid host to send data to. It needs to be the actual IP of the host running Logstash.

---

<div class="post-metadata">

**Author:** ![Royal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/royal/32/77467_2.png) [@Royal](https://discuss.elastic.co/u/Royal)\
**Post date:** [February 17, 2021, 7:38am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/3 "2021-02-17T07:38:43Z")

</div>

The output of filebeat needs to be sent to logstash on the local VM. When I change this to `hosts: ["localhost:5044"]` still same result.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 17, 2021, 7:40am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/4 "2021-02-17T07:40:17Z")

</div>

Can you telnet `localhost:5044` from the Logstash host?

---

<div class="post-metadata">

**Author:** ![Royal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/royal/32/77467_2.png) [@Royal](https://discuss.elastic.co/u/Royal)\
**Post date:** [February 17, 2021, 7:47am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/5 "2021-02-17T07:47:43Z")

</div>

The Logstash host is the localhost.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 17, 2021, 7:47am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/6 "2021-02-17T07:47:58Z")

</div>

Ok but can you run that?

---

<div class="post-metadata">

**Author:** ![Royal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/royal/32/77467_2.png) [@Royal](https://discuss.elastic.co/u/Royal)\
**Post date:** [February 17, 2021, 7:50am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/7 "2021-02-17T07:50:45Z")

</div>

```
telnet localhost 5044

```

```auto
Trying ::1...
Connected to localhost.
Escape character is '^]'.

Connection closed by foreign host.

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 17, 2021, 7:52am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/8 "2021-02-17T07:52:14Z")

</div>

What do your Filebeat logs show?

---

<div class="post-metadata">

**Author:** ![Royal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/royal/32/77467_2.png) [@Royal](https://discuss.elastic.co/u/Royal)\
**Post date:** [February 17, 2021, 7:58am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/9 "2021-02-17T07:58:29Z")

</div>

```auto
Feb 16 09:47:34 test.net filebeat[2868]: 2021-02-16T03:47:34.405-0500 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp 12
Feb 16 09:47:34 test.net filebeat[2868]: 2021-02-16T03:47:34.405-0500 INFO [publisher_pipeline_output] pipeline/output.go:145 Attempting to reconnect to backoff(async(tcp://localhost:5044)) with 2
Feb 16 09:47:34 test.net filebeat[2868]: 2021-02-16T03:47:34.406-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:47:34 test.net filebeat[2868]: 2021-02-16T03:47:34.406-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:47:35 test.net filebeat[2868]: 2021-02-16T03:47:35.891-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:47:43 test.net filebeat[2868]: 2021-02-16T03:47:43.044-0500 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp 12
Feb 16 09:47:43 test.net filebeat[2868]: 2021-02-16T03:47:43.044-0500 INFO [publisher_pipeline_output] pipeline/output.go:145 Attempting to reconnect to backoff(async(tcp://localhost:5044)) with 3
Feb 16 09:47:43 test.net filebeat[2868]: 2021-02-16T03:47:43.048-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:47:43 test.net filebeat[2868]: 2021-02-16T03:47:43.048-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:48:05 test.net filebeat[2868]: 2021-02-16T03:48:05.893-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:48:11 test.net filebeat[2868]: 2021-02-16T03:48:11.661-0500 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp 12
Feb 16 09:48:11 test.net filebeat[2868]: 2021-02-16T03:48:11.661-0500 INFO [publisher_pipeline_output] pipeline/output.go:145 Attempting to reconnect to backoff(async(tcp://localhost:5044)) with 4
Feb 16 09:48:11 test.net filebeat[2868]: 2021-02-16T03:48:11.662-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:48:11 test.net filebeat[2868]: 2021-02-16T03:48:11.662-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:48:11 test.net filebeat[2868]: 2021-02-16T03:48:11.663-0500 INFO [publisher_pipeline_output] pipeline/output.go:151 Connection to backoff(async(tcp://localhost:5044)) established
Feb 16 09:48:35 test.net filebeat[2868]: 2021-02-16T03:48:35.894-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:49:05 test.net filebeat[2868]: 2021-02-16T03:49:05.894-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:49:35 test.net filebeat[2868]: 2021-02-16T03:49:35.894-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:50:05 test.net filebeat[2868]: 2021-02-16T03:50:05.893-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:50:35 test.net filebeat[2868]: 2021-02-16T03:50:35.893-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:50:39 test.net filebeat[2868]: 2021-02-16T03:50:39.977-0500 ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: read tcp [::1]:40178->[::1]:5044: read: connection r
Feb 16 09:50:39 test.net filebeat[2868]: 2021-02-16T03:50:39.977-0500 ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: read tcp [::1]:40178->[::1]:5044: read: connection r
Feb 16 09:50:39 test.net filebeat[2868]: 2021-02-16T03:50:39.977-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:50:39 test.net filebeat[2868]: 2021-02-16T03:50:39.977-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:50:39 test.net filebeat[2868]: 2021-02-16T03:50:39.977-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:50:39 test.net filebeat[2868]: 2021-02-16T03:50:39.977-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:50:40 test.net filebeat[2868]: 2021-02-16T03:50:40.119-0500 ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: client is not connected
Feb 16 09:50:40 test.net filebeat[2868]: 2021-02-16T03:50:40.119-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:50:40 test.net filebeat[2868]: 2021-02-16T03:50:40.119-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:50:41 test.net filebeat[2868]: 2021-02-16T03:50:41.864-0500 ERROR [publisher_pipeline_output] pipeline/output.go:180 failed to publish events: client is not connected
Feb 16 09:50:41 test.net filebeat[2868]: 2021-02-16T03:50:41.864-0500 INFO [publisher_pipeline_output] pipeline/output.go:143 Connecting to backoff(async(tcp://localhost:5044))
Feb 16 09:50:41 test.net filebeat[2868]: 2021-02-16T03:50:41.865-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:50:41 test.net filebeat[2868]: 2021-02-16T03:50:41.865-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:50:45 test.net filebeat[2868]: 2021-02-16T03:50:45.443-0500 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp 12
Feb 16 09:50:45 test.net filebeat[2868]: 2021-02-16T03:50:45.443-0500 INFO [publisher_pipeline_output] pipeline/output.go:145 Attempting to reconnect to backoff(async(tcp://localhost:5044)) with 1
Feb 16 09:50:45 test.net filebeat[2868]: 2021-02-16T03:50:45.443-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:50:45 test.net filebeat[2868]: 2021-02-16T03:50:45.444-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:50:52 test.net filebeat[2868]: 2021-02-16T03:50:52.822-0500 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp [:
Feb 16 09:50:52 test.net filebeat[2868]: 2021-02-16T03:50:52.822-0500 INFO [publisher_pipeline_output] pipeline/output.go:145 Attempting to reconnect to backoff(async(tcp://localhost:5044)) with 2
Feb 16 09:50:52 test.net filebeat[2868]: 2021-02-16T03:50:52.825-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:50:52 test.net filebeat[2868]: 2021-02-16T03:50:52.826-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:51:01 test.net filebeat[2868]: 2021-02-16T03:51:01.082-0500 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp [:
Feb 16 09:51:01 test.net filebeat[2868]: 2021-02-16T03:51:01.082-0500 INFO [publisher_pipeline_output] pipeline/output.go:145 Attempting to reconnect to backoff(async(tcp://localhost:5044)) with 3
Feb 16 09:51:01 test.net filebeat[2868]: 2021-02-16T03:51:01.083-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:51:01 test.net filebeat[2868]: 2021-02-16T03:51:01.083-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:51:05 test.net filebeat[2868]: 2021-02-16T03:51:05.891-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:51:31 test.net filebeat[2868]: 2021-02-16T03:51:31.907-0500 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp [:
Feb 16 09:51:31 test.net filebeat[2868]: 2021-02-16T03:51:31.907-0500 INFO [publisher_pipeline_output] pipeline/output.go:145 Attempting to reconnect to backoff(async(tcp://localhost:5044)) with 4
Feb 16 09:51:31 test.net filebeat[2868]: 2021-02-16T03:51:31.908-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:51:31 test.net filebeat[2868]: 2021-02-16T03:51:31.908-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:51:35 test.net filebeat[2868]: 2021-02-16T03:51:35.895-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:52:05 test.net filebeat[2868]: 2021-02-16T03:52:05.893-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:52:24 test.net filebeat[2868]: 2021-02-16T03:52:24.726-0500 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp [:
Feb 16 09:52:24 test.net filebeat[2868]: 2021-02-16T03:52:24.727-0500 INFO [publisher_pipeline_output] pipeline/output.go:145 Attempting to reconnect to backoff(async(tcp://localhost:5044)) with 5
Feb 16 09:52:24 test.net filebeat[2868]: 2021-02-16T03:52:24.728-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:52:24 test.net filebeat[2868]: 2021-02-16T03:52:24.728-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:52:32 test.net filebeat[2868]: 2021-02-16T03:52:32.237-0500 INFO log/harvester.go:333 File is inactive: /var/log/secure. Closing because close_inactive of 5m0s reached.
Feb 16 09:52:35 test.net filebeat[2868]: 2021-02-16T03:52:35.892-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:53:05 test.net filebeat[2868]: 2021-02-16T03:53:05.893-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:53:20 test.net filebeat[2868]: 2021-02-16T03:53:20.887-0500 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp 12
Feb 16 09:53:20 test.net filebeat[2868]: 2021-02-16T03:53:20.887-0500 INFO [publisher_pipeline_output] pipeline/output.go:145 Attempting to reconnect to backoff(async(tcp://localhost:5044)) with 6
Feb 16 09:53:20 test.net filebeat[2868]: 2021-02-16T03:53:20.888-0500 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Feb 16 09:53:20 test.net filebeat[2868]: 2021-02-16T03:53:20.888-0500 INFO [publisher] pipeline/retry.go:223 done
Feb 16 09:53:35 test.net filebeat[2868]: 2021-02-16T03:53:35.894-0500 INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"
Feb 16 09:54:00 test.net filebeat[2868]: 2021-02-16T03:54:00.458-0500 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp 12

```

Note: I replaced the current hostname to `test.net`

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 17, 2021, 8:02am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/10 "2021-02-17T08:02:21Z")

</div>

And Filebeat is installed on the same host as Logstash right?

---

<div class="post-metadata">

**Author:** ![Royal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/royal/32/77467_2.png) [@Royal](https://discuss.elastic.co/u/Royal)\
**Post date:** [February 17, 2021, 8:02am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/11 "2021-02-17T08:02:30Z")

</div>

yes.

---

<div class="post-metadata">

**Author:** ![Royal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/royal/32/77467_2.png) [@Royal](https://discuss.elastic.co/u/Royal)\
**Post date:** [February 17, 2021, 2:56pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/12 "2021-02-17T14:56:11Z")

</div>

I've found the solution. It had to do with the input of Filebeat and to which port the logs were send to from the Kubernetes cluster. I changed the port to where to send the logs to, to 9201. I changed the filebeat.input like this, so that it listens on port 9021 over tcp protocol:

```auto
filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.
- type: tcp
  hosts: ["localhost:9201"]
#- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  #paths:
    #- /var/log/*.log

```

Also, I had to change the output of Logstash so it got send to Elasticsearch:

```auto
input {
  beats {
    port => 5044
  }
}
output {
  elasticsearch {
    hosts => ["localhost:9200"]
    manage_template => false
    index => "test-index"
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2021, 2:56pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/264405/13 "2021-03-17T14:56:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
