# Filebeat log Not Coming to Logstash

**URL:** <https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 2, 2020, 10:23am UTC](https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608 "2020-07-02T10:23:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sumitsahay](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@sumitsahay](https://discuss.elastic.co/u/sumitsahay)\
**Post date:** [July 2, 2020, 10:23am UTC](https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608/1 "2020-07-02T10:23:46Z")

</div>

Hi All,

I am having fliebeat install on my client machine and elk masternode on different vm. I Configured everything though logs are not coming to Kibana index and index is not getting created.

 ![logstashconf](https://us1.discourse-cdn.com/elastic/original/3X/8/9/899b17161b1f572cc986bb0d6dafaf8f3bb7af0e.jpeg) ![filebeat](https://us1.discourse-cdn.com/elastic/original/3X/0/1/01ab01560120173dd2d65dbca1c178bd432e7f11.jpeg)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 2, 2020, 10:45am UTC](https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608/2 "2020-07-02T10:45:36Z")

</div>

Welcome!

Please don't post images of text as they are hard to read, may not display correctly for everyone, and are not searchable.

Instead, paste the text and format it with `</>` icon or pairs of triple backticks (```), and check the preview window to make sure it's properly formatted before posting it. This makes it more likely that your question will receive a useful answer.

It would be great if you could update your post to solve this.

---

<div class="post-metadata">

**Author:** ![sumitsahay](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@sumitsahay](https://discuss.elastic.co/u/sumitsahay)\
**Post date:** [July 2, 2020, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608/3 "2020-07-02T14:31:11Z")

</div>

Thanks a lot for your reply, I 'll do that here as suggested by you, I am new to this forum.  
indent preformatted text by 4 spaces  
`input {  
beats {  
port =\> 5044  
type =\> syslog  
ssl\_certificate =\> "/etc/ssl/logstash\_frwrd.crt"  
ssl\_key =\> "/etc/ssl/logstash-forwarder.key"  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
#index =\> ["waf"]  
index =\> ["waf-(date '+%Y-%m-%d\_%H-%M-%S')"]  
}  
stdout { codec =\> rubydebug }  
}`  
filebeat.inputs:

- input\_type: log  
paths:
  - /var/log/\*.log

  - /opt/test.log  
output.logstash:  
#output:  
#The Logstash hosts  
logstash:  
enabled: true  
hosts: ["172.31.192.3:5044"]  
index: "waf-(date '+%Y-%m-%d\_%H-%M-%S')"  
tls:  
ssl.certificate: ["/etc/ssl/logstash\_frwrd.crt"]  
ssl.key: "/etc/ssl/logstash-forwarder.key"

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 2, 2020, 2:43pm UTC](https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608/4 "2020-07-02T14:43:16Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

---

<div class="post-metadata">

**Author:** ![sumitsahay](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@sumitsahay](https://discuss.elastic.co/u/sumitsahay)\
**Post date:** [July 2, 2020, 3:28pm UTC](https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608/5 "2020-07-02T15:28:32Z")

</div>

Is that ok.  
\<

```auto
input {
  beats {
    port => 5044
    type => syslog
    ssl_certificate => "/etc/ssl/logstash_frwrd.crt"
    ssl_key => "/etc/ssl/logstash-forwarder.key"
  }
}

filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    #index => ["waf"]
    index => ["waf-(date '+%Y-%m-%d_%H-%M-%S')"]
  }
  stdout { codec => rubydebug }
}

```

/\>

filebeat.yml  
\<

```auto
output.logstash:
logstash:
  enabled: true
  hosts: ["172.31.192.3:5044"]
  index: "waf-(date '+%Y-%m-%d_%H-%M-%S')"
  tls:
    ssl.certificate: ["/etc/ssl/logstash_frwrd.crt"]
    ssl.key: "/etc/ssl/logstash-forwarder.key"

```

/\>

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 3, 2020, 10:09am UTC](https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608/6 "2020-07-03T10:09:19Z")

</div>

Thank you.

As you have:

```
stdout { codec => rubydebug }

```

Can you see anything in the Logstash console/logs?  
You should see the events coming.

That said, although I'm not a Logstash expert, I'm unsure about this:

```
index => ["waf-(date '+%Y-%m-%d_%H-%M-%S')"]

```

[The doc says](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-index):

> - Value type is [string](https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html#string)
> - Default value is `"logstash-%{+yyyy.MM.dd}"`
> 
> The index to write events to. This can be dynamic using the `%{foo}` syntax. The default value will partition your indices by day so you can more easily delete old data or only search specific date ranges. Indexes may not contain uppercase characters. For weekly indexes ISO 8601 format is recommended, eg. logstash-%{+xxxx.ww}. LS uses Joda to format the index pattern from event timestamp. Joda formats are defined [here](http://www.joda.org/joda-time/apidocs/org/joda/time/format/DateTimeFormat.html).

So I'm not sure where this `(date '+%Y-%m-%d_%H-%M-%S')` is coming from...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2020, 12:09pm UTC](https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608/7 "2020-07-31T12:09:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
