# Elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash

**URL:** <https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/310010>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 19, 2022, 11:54am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/310010 "2022-07-19T11:54:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nguy\_n\_H\_u\_Phu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nguy_n_h_u_phu/32/108508_2.png) [@Nguy\_n\_H\_u\_Phu](https://discuss.elastic.co/u/Nguy_n_H_u_Phu)\
**Post date:** [July 19, 2022, 11:54am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/310010/1 "2022-07-19T11:54:45Z")

</div>

# I have input but cant show output! I need help!

# filebeat.yml

filebeat.inputs:

- type: filestream  
id: router1  
enabled: true  
paths:
  - /u01/redis\_app/run/tomcat-deploy-camidlog/logs/report\_log/report.log  
output.logstash:  
hosts: ["10.79.7.121:5045"]

# test output:

[root@openid121 report\_log]# /usr/share/filebeat/bin/filebeat test output -c /etc/filebeat/filebeatlog.yml  
logstash: 10.79.7.121:5045...  
connection...  
parse host... OK  
dns lookup... OK  
addresses: 10.79.7.121  
dial up... OK  
TLS... WARN secure connection disabled  
talk to server... OK

# log filebeat

2022-07-19T18:06:44.034+0700 INFO instance/beat.go:685 Home path: [/usr/share/filebeat] Config path: [/usr/share/filebeat] Data path: [/usr/share/filebeat/data] Logs path: [/var/log/filebeatlog] Hostfs Path: [/]  
2022-07-19T18:06:44.034+0700 INFO instance/beat.go:693 Beat ID: 15decd44-10a9-44a0-9e70-b60baa0016df  
2022-07-19T18:06:44.035+0700 INFO [seccomp] seccomp/seccomp.go:101 Syscall filter could not be installed because the kernel does not support seccomp  
2022-07-19T18:06:44.035+0700 INFO [beat] instance/beat.go:1039 Beat info {"system\_info": {"beat": {"path": {"config": "/usr/share/filebeat", "data": "/usr/share/filebeat/data", "home": "/usr/share/filebeat", "logs": "/var/log/filebeatlog"}, "type": "filebeat", "uuid": "15decd44-10a9-44a0-9e70-b60baa0016df"}}}  
2022-07-19T18:06:44.035+0700 INFO [beat] instance/beat.go:1048 Build info {"system\_info": {"build": {"commit": "1993ee88a11cb34f61a1fb45c7c3cf50533682cb", "libbeat": "7.17.3", "time": "2022-04-19T09:27:20.000Z", "version": "7.17.3"}}}  
2022-07-19T18:06:44.035+0700 INFO [beat] instance/beat.go:1051 Go runtime info {"system\_info": {"go": {"os":"linux","arch":"amd64","max\_procs":8,"version":"go1.17.8"}}}  
2022-07-19T18:06:44.036+0700 INFO [beat] instance/beat.go:1055 Host info {"system\_info": {"host": {"architecture":"x86\_64","boot\_time":"2021-11-06T00:06:01+07:00","containerized":false,"name":"openid121","ip":["127.0.0.1/8","::1/128","10.79.94.121/24","fe80::2a6e:d4ff:fe88:c7ea/64"],"kernel\_version":"3.10.0-514.el7.x86\_64","mac":["28:6e:d4:88:c7:ea"],"os":{"type":"linux","family":"redhat","platform":"centos","name":"CentOS Linux","version":"7 (Core)","major":7,"minor":3,"patch":1611,"codename":"Core"},"timezone":"ICT","timezone\_offset\_sec":25200,"id":"2161603f9ea14bab9ad24b14d8f10d71"}}}  
2022-07-19T18:06:44.036+0700 INFO [beat] instance/beat.go:1084 Process info {"system\_info": {"process": {"capabilities": {"inheritable":null,"permitted":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend"],"effective":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend"],"bounding":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend"],"ambient":null}, "cwd": "/u01/redis\_app/run/tomcat-deploy-camidapi/logs/report\_log", "exe": "/usr/share/filebeat/bin/filebeat", "name": "filebeat", "pid": 40985, "ppid": 1, "seccomp": {"mode":"disabled"}, "start\_time": "2022-07-19T18:06:43.290+0700"}}}  
2022-07-19T18:06:44.036+0700 INFO instance/beat.go:328 Setup Beat: filebeat; Version: 7.17.3  
2022-07-19T18:06:44.042+0700 INFO [publisher] pipeline/module.go:113 Beat name: openid121  
2022-07-19T18:06:44.043+0700 WARN beater/filebeat.go:202 Filebeat is unable to load the ingest pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the ingest pipelines or are using Logstash pipelines, you can ignore this warning.  
2022-07-19T18:06:44.043+0700 INFO [monitoring] log/log.go:142 Starting metrics logging every 30s  
2022-07-19T18:06:44.043+0700 INFO instance/beat.go:492 filebeat start running.  
2022-07-19T18:06:44.043+0700 INFO memlog/store.go:119 Loading data file of '/usr/share/filebeat/data/registry/filebeat' succeeded. Active transaction id=0  
2022-07-19T18:06:44.043+0700 INFO memlog/store.go:124 Finished loading transaction log file for '/usr/share/filebeat/data/registry/filebeat'. Active transaction id=0  
2022-07-19T18:06:44.043+0700 WARN beater/filebeat.go:411 Filebeat is unable to load the ingest pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the ingest pipelines or are using Logstash pipelines, you can ignore this warning.  
2022-07-19T18:06:44.043+0700 INFO [registrar] registrar/registrar.go:109 States Loaded from registrar: 0  
2022-07-19T18:06:44.043+0700 INFO [crawler] beater/crawler.go:71 Loading Inputs: 1  
2022-07-19T18:06:44.043+0700 INFO [crawler] beater/crawler.go:117 starting input, keys present on the config: [filebeat.inputs.0.enabled filebeat.inputs.0.id filebeat.inputs.0.paths.0 filebeat.inputs.0.type]  
2022-07-19T18:06:44.043+0700 INFO [crawler] beater/crawler.go:148 Starting input (ID: 6004394033242872904)  
2022-07-19T18:06:44.044+0700 INFO [crawler] beater/crawler.go:106 Loading and starting Inputs completed. Enabled inputs: 1  
2022-07-19T18:06:44.044+0700 INFO [input.filestream] compat/compat.go:111 Input filestream starting {"id": "router1"}  
2022-07-19T18:06:44.044+0700 INFO [file\_watcher] filestream/fswatch.go:138 Start next scan  
2022-07-19T18:06:54.045+0700 INFO [file\_watcher] filestream/fswatch.go:138 Start next scan  
2022-07-19T18:07:04.044+0700 INFO [file\_watcher] filestream/fswatch.go:138 Start next scan  
2022-07-19T18:07:14.044+0700 INFO [file\_watcher] filestream/fswatch.go:138 Start next scan  
2022-07-19T18:07:14.051+0700 INFO [monitoring] log/log.go:184 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":50,"time":{"ms":59}},"total":{"ticks":190,"time":{"ms":206},"value":190},"user":{"ticks":140,"time":{"ms":147}}},"handles":{"limit":{"hard":1000000,"soft":1000000},"open":12},"info":{"ephemeral\_id":"90cf46b3-2414-4478-9a91-66f6468a662c","uptime":{"ms":30068},"version":"7.17.3"},"memstats":{"gc\_next":18474688,"memory\_alloc":10726064,"memory\_sys":34161672,"memory\_total":55564688,"rss":108060672},"runtime":{"goroutines":32}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"active":0},"type":"logstash"},"pipeline":{"clients":0,"events":{"active":0},"queue":{"max\_events":4096}}},"registrar":{"states":{"current":0}},"system":{"cpu":{"cores":8},"load":{"1":0.55,"15":0.5,"5":0.52,"norm":{"1":0.0688,"15":0.0625,"5":0.065}}}}}}

---

<div class="post-metadata">

**Author:** ![lzold\_z](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lzold_z/32/108411_2.png) [@lzold\_z](https://discuss.elastic.co/u/lzold_z)\
**Post date:** [July 20, 2022, 7:25am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/310010/2 "2022-07-20T07:25:40Z")

</div>

Are you already check whether the ip and port you're using now in filebeat and logstash are correct?

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [July 21, 2022, 12:47pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/310010/3 "2022-07-21T12:47:48Z")

</div>

Hi, could you please format your post first using `code tags`?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2022, 2:48pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/310010/4 "2022-08-18T14:48:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
