# Example Dashboards - Via Logstash

**URL:** <https://discuss.elastic.co/t/example-dashboards-via-logstash/90662>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 23, 2017, 3:30pm UTC](https://discuss.elastic.co/t/example-dashboards-via-logstash/90662 "2017-06-23T15:30:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![runtman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runtman/32/18136_2.png) [@runtman](https://discuss.elastic.co/u/runtman)\
**Post date:** [June 23, 2017, 3:30pm UTC](https://discuss.elastic.co/t/example-dashboards-via-logstash/90662/1 "2017-06-23T15:30:58Z")

</div>

Hello, I have been reading through various threads in regards to the example dashboards showing "no data found" when logs are being pushed via logstash instead of directly to elasticsearch which begs the question if all beats push to elasticsearch what is the point of logstash in the stack?

Anyway, is there a way to get these fields working if I change some configuration?

Here is my filebeats config:

```
- input_type: log
  paths:
    - /var/log/syslog
  document_type: syslog

- input_type: log
  paths:
    - /var/log/*.log
  document_type: generic_log

- input_type: log
  paths:
    - /var/log/kafka/*.log

```

And below logstash:

```
output {
  elasticsearch {
    hosts => ["xxx:9200"]
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
    user => xxx
    password => xxx
  }
}

```

I guess it may be a lack of understanding on my part, how the example dashboards has all these "fields" to it's disposable, as all I seem to have is "timestamp".

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 26, 2017, 10:50am UTC](https://discuss.elastic.co/t/example-dashboards-via-logstash/90662/2 "2017-06-26T10:50:51Z")

</div>

Which sample dashboards exactly do you mean? The filebeat ones are to be used with filebeat modules, as some parsing is required. The parsing can be either implemented in Logstash or Elasticsearch Ingest Node. As of now, filebeat modules indeed only work with Elasticsearch.

For filebeat modules via Logstash see [this discussion](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/9). Especially [This response](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/7?u=steffens) and [this one](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/9?u=steffens).

---

<div class="post-metadata">

**Author:** ![runtman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runtman/32/18136_2.png) [@runtman](https://discuss.elastic.co/u/runtman)\
**Post date:** [June 26, 2017, 11:06am UTC](https://discuss.elastic.co/t/example-dashboards-via-logstash/90662/3 "2017-06-26T11:06:41Z")

</div>

My apologies, I should have been more clear.

Yes my ultimate goal is to get the fields from the filebeat dashboards into elasticsearch so I can create similar visuals without having to rely on "timestamp"

I will take a look at the links you have provided.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2017, 11:07am UTC](https://discuss.elastic.co/t/example-dashboards-via-logstash/90662/4 "2017-07-24T11:07:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
