# Example files for sending nginx, tomcat, postgresql files (from server A) to ELK server (server B)

**URL:** <https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 5, 2016, 2:25pm UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745 "2016-07-05T14:25:42Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![ghx](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@ghx](https://discuss.elastic.co/u/ghx)\
**Post date:** [July 5, 2016, 2:25pm UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/1 "2016-07-05T14:25:42Z")

</div>

Hello,

I just installed ELK server (on server B) and want to send log file for tomcat (catalina.out), nginx (access.log, error.log) and posgresql logs (from server A) using filebeat

I tested it with logs like syslog and similar format

I tested just adding new files like tomcat logs, I receveive the data to ELK server but the format is not correct and filtering is not good

do you have any example of config file for filebeat AND logstash to handle this new entries

thx a lot

G

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 5, 2016, 6:11pm UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/2 "2016-07-05T18:11:19Z")

</div>

Please show your Logstash configuration and some examples of the events that Logstash is receiving. Please use a `stdout { codec => rubydebug }` output so we can see clearly exactly what the events look like.

---

<div class="post-metadata">

**Author:** ![ghx](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@ghx](https://discuss.elastic.co/u/ghx)\
**Post date:** [July 6, 2016, 7:19am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/3 "2016-07-06T07:19:45Z")

</div>

logstash.conf is:

input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

and filebeat.yml is:

filebeat:  
prospectors:  
-  
paths:  
- /var/log/auth.log  
- /var/log/syslog  
- /var/log/postgresql/postgresql-9.4-main.log  
- /var/log/nginx/access.log  
- /var/log/tomcat8/catalina.out  
# - /var/log/\*.log

```
  input_type: log

  document_type: syslog

```

registry\_file: /var/lib/filebeat/registry

output:  
logstash:  
hosts: ["[backup01.antalios.com:5044](http://backup01.antalios.com:5044)"]  
bulk\_max\_size: 1024

```
tls:
  certificate_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

```

shipper:

#logging:

# files:

# rotateeverybytes: 10485760 # = 10MB

logging:  
level: warning  
to\_files: true  
files:  
path: /var/log/filebeat  
name: beat.log  
keepfiles: 7  
rotateeverybytes: 10485760 # 10 MB  
level: debug  
selectors: ["\*"]

actually, since I add the log from catalina, postgres,... logstash crashed in addition to the bad format of the logs  
{:timestamp=\>"2016-07-05T18:50:48.407000+0200", :message=\>"Beats input: the pipeline is blocked, temporary refusing new connection.", :reconnect\_backoff\_sleep=\>0.5, :level=\>:warn}

otherwise, it is ok but without parsing correctly the logs

thx

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 6, 2016, 7:21am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/4 "2016-07-06T07:21:55Z")

</div>

Well, you haven't defined any filters for anything except syslog so it shouldn't be surprising that the other logs aren't parsed. So what do the other events look like? See my previous question.

---

<div class="post-metadata">

**Author:** ![ghx](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@ghx](https://discuss.elastic.co/u/ghx)\
**Post date:** [July 6, 2016, 7:37am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/5 "2016-07-06T07:37:44Z")

</div>

> [@magnusbaeck](#):
>
> stdout { codec =\> rubydebug }

I modified the logstash.conf with adding your lines, is it correct?  
root@backup01:/etc/logstash/conf.d# more logstash.conf  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
stdout { codec =\> rubydebug }  
}

I restarted the logstash process, but nothing in the log  
root@backup01:/etc/logstash/conf.d# more logstash.conf  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 6, 2016, 7:38am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/6 "2016-07-06T07:38:47Z")

</div>

> I modified the logstash.conf with adding your lines, is it correct?

Yes. So what do the events that end up in the Logstash logs look like?

---

<div class="post-metadata">

**Author:** ![ghx](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@ghx](https://discuss.elastic.co/u/ghx)\
**Post date:** [July 6, 2016, 7:52am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/7 "2016-07-06T07:52:42Z")

</div>

{  
"message" =\> " **_---------- FETCHDATASERVICE LISTE nb\_msg\_recues--------_** \*\*\*\*\* 10",  
"@version" =\> "1",  
"@timestamp" =\> "2016-07-06T07:50:50.382Z",  
"beat" =\> {  
"hostname" =\> "yoda",  
"name" =\> "yoda"  
},  
"source" =\> "/var/log/tomcat8/catalina.out",  
"count" =\> 1,  
"fields" =\> nil,  
"offset" =\> 477072,  
"type" =\> "syslog",  
"input\_type" =\> "log",  
"host" =\> "yoda",  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied",  
[1] "\_grokparsefailure"  
],  
"syslog\_severity\_code" =\> 5,  
"syslog\_facility\_code" =\> 1,  
"syslog\_facility" =\> "user-level",  
"syslog\_severity" =\> "notice"  
}  
{  
"message" =\> "Jul 5 17:01:02 sd-50775 /usr/bin/filebeat[16586]: registrar.go:146: Write registry file: /var/lib/filebeat/registry",  
"@version" =\> "1",  
"@timestamp" =\> "2016-07-05T15:01:02.000Z",  
"source" =\> "/var/log/syslog",  
"offset" =\> 9101529542,  
"type" =\> "syslog",  
"input\_type" =\> "log",  
"count" =\> 1,  
"fields" =\> nil,  
"beat" =\> {  
"hostname" =\> "sd-50775",  
"name" =\> "sd-50775"  
},  
"host" =\> "sd-50775",  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied"  
],  
"syslog\_timestamp" =\> "Jul 5 17:01:02",  
"syslog\_hostname" =\> "sd-50775",  
"syslog\_program" =\> "/usr/bin/filebeat",  
"syslog\_pid" =\> "16586",  
"syslog\_message" =\> "registrar.go:146: Write registry file: /var/lib/filebeat/registry",  
"received\_at" =\> "2016-07-06T07:50:55.099Z",  
"received\_from" =\> "sd-50775",  
"syslog\_severity\_code" =\> 5,  
"syslog\_facility\_code" =\> 1,  
"syslog\_facility" =\> "user-level",  
"syslog\_severity" =\> "notice"  
}  
{  
"message" =\> "///////////FETCHDATASERVICE : tout le message---------_-_-\*--------- RestroomRawAmqpMessage{deviceIdentifier='121', satisfactionCounter=SatisfactionCounter{identifier='sc\_121\_2016-07-05T15:52:52Z', deviceIdentifier='121', cycleIdentifier='121\_2016-07-05T15:52:52Z', veryGood=317, good=273, bad=274, veryBad=272, begin=2016-07-05T15:52:52Z, end=2016-07-05T15:52:52Z}, peopleCounter=PeopleCounter{identifier='pc\_121\_2016-07-05T15:52:52Z', deviceIdentifier='121', cycleIdentifier='c\_121\_2016-07-05T15:52:52Z', inputCount=316, outputCount=270, begin=2016-07-05T15:52:52Z, end=2016-07-05T15:52:52Z}, serialNumberButton='00001648a8a1', cleaning=Cleaning{identifier='cl\_121\_2016-07-05T15:52:52Z', badgeIdentifier='00001648a8a1', deviceIdentifier='121', cycleIdentifier='121\_2016-07-05T15:52:52Z', begin=Tue Jul 05 17:22:52 CEST 2016, end=Tue Jul 05 17:52:52 CEST 2016}, remainingTime=0, cleaningDuration=1800, gps=com.antalios.dal.localisation.GpsLocation@31971b0, isCleaningStarted=false, isCleaningEnded=false}",  
"@version" =\> "1",  
"@timestamp" =\> "2016-07-06T07:50:50.382Z",  
"input\_type" =\> "log",  
"count" =\> 1,  
"offset" =\> 477188,  
"type" =\> "syslog",  
"beat" =\> {  
"hostname" =\> "yoda",  
"name" =\> "yoda"  
},  
"source" =\> "/var/log/tomcat8/catalina.out",  
"fields" =\> nil,  
"host" =\> "yoda",  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied",  
[1] "\_grokparsefailure"  
],  
"syslog\_severity\_code" =\> 5,  
"syslog\_facility\_code" =\> 1,  
"syslog\_facility" =\> "user-level",  
"syslog\_severity" =\> "notice"

---

<div class="post-metadata">

**Author:** ![ghx](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@ghx](https://discuss.elastic.co/u/ghx)\
**Post date:** [July 6, 2016, 7:53am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/8 "2016-07-06T07:53:56Z")

</div>

{  
"message" =\> "Jul 5 16:48:21 sd-79181 /usr/bin/filebeat[10795]: publish.go:109: Publish: {#012 "@timestamp": "2016-07-05T14:48:10.268Z",#012 "beat": {#012 "hostname": "yoda",#012 "name": "yoda"#012 },#012 "count": 1,#012 "fields": null,#012 "input\_type": "log",#012 "message": "Jul 5 16:16:38 sd-79181 /usr/bin/filebeat[10795]: publish.go:109: Publish: {#012 \"@timestamp\": \"2016-07-05T14:16:26.023Z\",#012 \"beat\": {#012 \"hostname\": \"yoda\",#012 \"name\": \"yoda\"#012 },#012 \"count\": 1,#012 \"fields\": null,#012 \"input\_type\": \"log\",#012 \"message\": \"Jul 5 15:55:36 sd-79181 /usr/bin/filebeat[10795]: publish.go:109: Publish: {#012 \\\"@timestamp\\\": \\\"2016-07-05T13:55:30.318Z\\\",#012 \\\"beat\\\": {#012 \\\"hostname\\\": \\\"yoda\\\",#012 \\\"name\\\": \\\"yoda\\\"#012 },#012 \\\"count\\\": 1,#012 \\\"fields\\\": null,#012 \\\"input\_type\\\": \\\"log\\\",#012 \\\"message\\\": \\\"Jul 5 15:38:17 sd-79181 /usr/bin/filebeat[10795]: publish.go:109: Publish: {#012 \\\\\\\"@timestamp\\\\\\\": \\\\\\\"2016-07-05T13:38:05.450Z\\\\\\\",#012 \\\\\\\"beat\\\\\\\": {#012 \\\\\\\"hostname\\\\\\\": \\\\\\\"yoda\\\\\\\",#012 \\\\\\\"name\\\\\\\": \\\\\\\"yoda\\\\\\\"#012 },#012 \\\\\\\"count\\\\\\\": 1,#012 \\\\\\\"fields\\\\\\\": null,#012 \\\\\\\"input\_type\\\\\\\": \\\\\\\"log\\\\\\\",#012 \\\\\\\"message\\\\\\\": \\\\\\\"Jul 5 15:24:36 sd-79181 /usr/bin/filebeat[10795]: publish.go:109: Publish: {#012 \\\\\\\\\\\\\\\"@timestamp\\\\\\\\\\\\\\\": \\\\\\\\\\\\\\\"2016-07-05T13:24:26.477Z\\\\\\\\\\\\\\\",#012 \\\\\\\\\\\\\\\"beat\\\\\\\\\\\\\\\": {#012 \\\\\\\\\\\\\\\"hostname\\\\\\\\\\\\\\\": \\\\\\\\\\\\\\\"yoda\\\\\\\\\\\\\\\",#012 \\\\\\\\\\\\\\\"name\\\\\\\\\\\\\\\": \\\\\\\\\\\\\\\"yoda\\\\\\\\\\\\\\\"#012 },#012 \\\\\\\\\\\\\\\"count\\\\\\\\\\\\\\\": 1,#012 \\\\\\\\\\\\\\\"fields\\\\\\\\\\\\\\\": null,#012 \\\\\\\\\\\\\\\"input\_type\\\\\\\\\\\\\\\": \\\\\\\\\\\\\\\"log\\\\\\\\\\\\\\\",#012 \\\\\\\\\\\\\\\"message\\\\\\\\\\\\\\\": \\\\\\\\\\\\\\\"Jul 5 15:14:10 sd-79181 /usr/bin/filebeat[10795]: publish.go:109: Publish: {#012 \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"@timestamp\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\": \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"2016-07-05T13:13:56.810Z\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\",#012 \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"beat\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\": {#012 \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"hostname\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\": \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"yoda\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\",#012 \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"name\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\": \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"yoda\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"#012 },#012 \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"count\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\": 1,#012 \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"fields\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\": null,#012 \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"input\_type\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\": \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"log\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\",#012 \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"message\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\": \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"Jul 5 15:06:28 sd-79181 /usr/bin/filebeat[10795]: publish.go:109: Publish: {#012 \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\"@timestamp\

---

<div class="post-metadata">

**Author:** ![ghx](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@ghx](https://discuss.elastic.co/u/ghx)\
**Post date:** [July 6, 2016, 7:54am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/9 "2016-07-06T07:54:37Z")

</div>

logs files are so big, one day more than 20GB with so few info...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 6, 2016, 7:56am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/10 "2016-07-06T07:56:55Z")

</div>

Start by changing your Filebeat configuration to not send all logs with the "syslog" type, because then you don't know at the Logstash end what kind of events they are and how they should be parsed. Split your single prospector into multiple prospectors that monitor different files and have different document types.

---

<div class="post-metadata">

**Author:** ![ghx](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@ghx](https://discuss.elastic.co/u/ghx)\
**Post date:** [July 6, 2016, 9:37am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/11 "2016-07-06T09:37:11Z")

</div>

thx, do you have an example of file ? filebeat and logstash ?  
thx

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [July 11, 2016, 8:17am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/12 "2016-07-11T08:17:37Z")

</div>

Best is to check the guide here. See note on `-` is a prospector: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration.html)

---

<div class="post-metadata">

**Author:** ![ghx](https://avatars.discourse-cdn.com/v4/letter/g/58f4c7/32.png) [@ghx](https://discuss.elastic.co/u/ghx)\
**Post date:** [July 11, 2016, 9:00am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/13 "2016-07-11T09:00:43Z")

</div>

hello,

I already checked the docs, but seems incredible to not find any examples of common log files used by apache, nginx, tomcat, etc...  
more easy to start and customize

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 11, 2016, 9:38am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/14 "2016-07-11T09:38:12Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/config-examples.html](https://www.elastic.co/guide/en/logstash/current/config-examples.html) contains an Apache example that probably works with Nginx and Tomcat too,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2016, 2:26pm UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745/15 "2016-07-26T14:26:25Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
