# Filebeat Elastic working, but filebeat logstash not working

**URL:** <https://discuss.elastic.co/t/filebeat-elastic-working-but-filebeat-logstash-not-working/83121>\
**Category:** Logstash\
**Created:** [April 20, 2017, 9:43pm UTC](https://discuss.elastic.co/t/filebeat-elastic-working-but-filebeat-logstash-not-working/83121 "2017-04-20T21:43:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sLuvpreet33](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sluvpreet33/32/50626_2.png) [@sLuvpreet33](https://discuss.elastic.co/u/sLuvpreet33)\
**Post date:** [April 20, 2017, 9:43pm UTC](https://discuss.elastic.co/t/filebeat-elastic-working-but-filebeat-logstash-not-working/83121/1 "2017-04-20T21:43:14Z")

</div>

Hi, I am searching for a solution to this for past 2 days, but have not found it.

Filebeat can send data to elasticsearch, but it is not working if I am sending it by logstash.

Here is the filebeat.yml file,

```
filebeat.prospectors:
- input_type: log
  paths:  
   - /var/log/syslog
     document_type: syslog

- input_type: log
   paths:
     - /var/log/nginx/kibana_access.log
     document_type: nginx

```

output.logstash:  
hosts: ["localhost:5044"]

This is the input file in logstash,

```
input {
 beats {
   port => 5044
 }
}

```

This is the output file

```
output {
     elasticsearch {
   hosts => ["localhost:9200"]
   manage_template => false
   index => "%{type}-index"
   document_type => "[type]"
 }
}

```

If I create an index by directly outputing to elasticsearch from filebeat, it works perfectly.

The logstash never opens its port 5044, why so ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 21, 2017, 5:32am UTC](https://discuss.elastic.co/t/filebeat-elastic-working-but-filebeat-logstash-not-working/83121/2 "2017-04-21T05:32:08Z")

</div>

> The logstash never opens its port 5044, why so ?

Is Logstash starting at all? Is there anything in Logstash's own log? How did you verify that the port isn't opened?

It looks like your `document_type` lines are indented one step too far.

---

<div class="post-metadata">

**Author:** ![sLuvpreet33](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sluvpreet33/32/50626_2.png) [@sLuvpreet33](https://discuss.elastic.co/u/sLuvpreet33)\
**Post date:** [April 21, 2017, 6:05am UTC](https://discuss.elastic.co/t/filebeat-elastic-working-but-filebeat-logstash-not-working/83121/3 "2017-04-21T06:05:29Z")

</div>

Logs are being written there. Here are a few lines from the log, just pasting 1 from each step,

`[2017-04-21T11:26:29,938][DEBUG][logstash.plugins.registry] On demand adding plugin to the registry {:name=>"beats", :type=>"input", :class=>LogStash::Inputs::Beats}`

`[2017-04-21T11:26:29,958][DEBUG][logstash.codecs.plain] config LogStash::Codecs::Plain/@id = "plain_59be7464-bfed-450a-baa2-35b2101696e3"`

`[2017-04-21T11:26:29,960][DEBUG][logstash.inputs.beats] config LogStash::Inputs::Beats/@port = 5044`

`[2017-04-21T11:26:29,998][DEBUG][logstash.filters.grok] config LogStash::Filters::Grok/@match = {"message"=>"%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\\[%{POSINT:syslog_pid}\\])?: %{GREEDYDATA:syslog_message}"}`

`[2017-04-21T11:26:30,329][DEBUG][logstash.outputs.elasticsearch] config LogStash::Outputs::ElasticSearch/@hosts = [//localhost:9200]`

BUt the Filebeat logs are,

`2017-04-21T02:36:01+05:30 ERR Connecting error publishing events (retrying): dial tcp 127.0.0.1:5044: getsockopt: connection refused`

`2017-04-21T02:36:31+05:30 INFO Non-zero metrics in the last 30s: filebeat.harvester.open_files=2 filebeat.harvester.running=2 filebeat.harvester.started=2 libbeat.publisher.published_events=2046`

---

<div class="post-metadata">

**Author:** ![sLuvpreet33](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sluvpreet33/32/50626_2.png) [@sLuvpreet33](https://discuss.elastic.co/u/sLuvpreet33)\
**Post date:** [April 21, 2017, 6:06am UTC](https://discuss.elastic.co/t/filebeat-elastic-working-but-filebeat-logstash-not-working/83121/4 "2017-04-21T06:06:15Z")

</div>

How can we specify the index name when writing from filebeat to logstash and then to elasticsearch ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 21, 2017, 6:09am UTC](https://discuss.elastic.co/t/filebeat-elastic-working-but-filebeat-logstash-not-working/83121/5 "2017-04-21T06:09:07Z")

</div>

> Logs are being written there. Here are a few lines from the log, just pasting 1 from each step,

Okay, but those are just early debug-level logs. Are there any errors or warnings? Is Logstash starting up properly? Do you have any firewall or similar that might be blocking the access? Have you checked with e.g. netstat whether Logstash is in fact listening on the port?

> How can we specify the index name when writing from filebeat to logstash and then to elasticsearch ?

It's Logstash that chooses the index name based on the `index` option of its elasticsearch output.

---

<div class="post-metadata">

**Author:** ![Nisal\_Thiwanka](https://avatars.discourse-cdn.com/v4/letter/n/2acd7d/32.png) [@Nisal\_Thiwanka](https://discuss.elastic.co/u/Nisal_Thiwanka)\
**Post date:** [April 21, 2017, 6:14am UTC](https://discuss.elastic.co/t/filebeat-elastic-working-but-filebeat-logstash-not-working/83121/6 "2017-04-21T06:14:44Z")

</div>

Have you started a logstash pipeline properly?  
Try to start a pipeline using the following command.  
And include your configuration options in the first-pipeline.conf file  
Go to your bin folder of logstash using the command-line and try to execute the following command and check whether the pipeline has started properly.  
C:\elk\logstash-5.1.2\bin\>logstash -f first-pipeline.conf --config.reload.automatic

After the pipeline has successfully started following message will be displayed.  
11:43:35.045 [[main]-pipeline-manager] INFO logstash.pipeline - Pipeline main started  
11:43:35.120 [Api Webserver] INFO logstash.agent - Successfully started Logstash API endpoint {:port=\>9600}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2017, 6:21am UTC](https://discuss.elastic.co/t/filebeat-elastic-working-but-filebeat-logstash-not-working/83121/7 "2017-05-19T06:21:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
