# ELK/Logstash in Swarm

**URL:** <https://discuss.elastic.co/t/elk-logstash-in-swarm/205189>\
**Category:** Logstash\
**Created:** [October 25, 2019, 6:16am UTC](https://discuss.elastic.co/t/elk-logstash-in-swarm/205189 "2019-10-25T06:16:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![stinkfly](https://avatars.discourse-cdn.com/v4/letter/s/85f322/32.png) [@stinkfly](https://discuss.elastic.co/u/stinkfly)\
**Post date:** [October 25, 2019, 6:16am UTC](https://discuss.elastic.co/t/elk-logstash-in-swarm/205189/1 "2019-10-25T06:16:24Z")

</div>

Hi there,

I've deployed sebp/elk ([https://hub.docker.com/r/sebp/elk/](https://hub.docker.com/r/sebp/elk/)) in a 3 node swarm. It comes up fine. If I point winlogbeat to Elasticsearch, it works fine. However, I find that if I set Logstash as the target for winlogbeat, then it seems like the containers and their IDs are different every time the swarm is restarted and winlogbeat generates errors about not being to contact logstash. This obviously makes it impossible to set any Logstash conf files

Am I misunderstanding how it works?

winlogbeat -\> Logstash (in ELK Swarm) -\> Elasticsearch (same swarm) (no good)  
winlogbeat -\> Elasticsearch (in same ELK Swarm) ok

Do I need to use docker compose with swarm?

Thanks  
Stinkfly

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2019, 6:16am UTC](https://discuss.elastic.co/t/elk-logstash-in-swarm/205189/2 "2019-11-22T06:16:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
