# File beats compared to Log4j SocketAppender

**URL:** <https://discuss.elastic.co/t/file-beats-compared-to-log4j-socketappender/36601>\
**Category:** Beats\
**Created:** [December 8, 2015, 4:58am UTC](https://discuss.elastic.co/t/file-beats-compared-to-log4j-socketappender/36601 "2015-12-08T04:58:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ari/32/4689_2.png) [@ari](https://discuss.elastic.co/u/ari)\
**Post date:** [December 8, 2015, 4:58am UTC](https://discuss.elastic.co/t/file-beats-compared-to-log4j-socketappender/36601/1 "2015-12-08T04:58:22Z")

</div>

I see that this article is now marked as no longer recommended: [https://www.elastic.co/blog/logging-elasticsearch-events-with-logstash-and-elasticsearch](https://www.elastic.co/blog/logging-elasticsearch-events-with-logstash-and-elasticsearch)

What is it about the article which is now bad? Why would I prefer writing a log to file and the piping that to logstash using FileBeats rather than sending the data directly over TCP to logstash? What would be the advantage and why should we be now ignoring that article?

Cheers  
Ari

---

<div class="post-metadata">

**Author:** ![ari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ari/32/4689_2.png) [@ari](https://discuss.elastic.co/u/ari)\
**Post date:** [December 8, 2015, 10:49am UTC](https://discuss.elastic.co/t/file-beats-compared-to-log4j-socketappender/36601/2 "2015-12-08T10:49:25Z")

</div>

I think I can answer my own question. The log4j input plugin for logstash is pretty much abandoned. [https://github.com/logstash-plugins/logstash-input-log4j2](https://github.com/logstash-plugins/logstash-input-log4j2)

The old plugin works only for log4j 1.x which no-one would use these days for a new project. And the new plugin has had zero work done on it yet.

There was an old ticket and someone created a patch, but sadly after several years of neglect the patch is now 404. [https://logstash.jira.com/browse/LOGSTASH-1578](https://logstash.jira.com/browse/LOGSTASH-1578)

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 8, 2015, 12:51pm UTC](https://discuss.elastic.co/t/file-beats-compared-to-log4j-socketappender/36601/3 "2015-12-08T12:51:18Z")

</div>

One additional advantage of using filebeat is that it can connect to multiple logstash instances and do some load balancing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:57pm UTC](https://discuss.elastic.co/t/file-beats-compared-to-log4j-socketappender/36601/4 "2017-07-05T21:57:37Z")

</div>


