# Filebeat log stdout logstash

**URL:** <https://discuss.elastic.co/t/filebeat-log-stdout-logstash/171771>\
**Category:** Logstash\
**Created:** [March 11, 2019, 1:02pm UTC](https://discuss.elastic.co/t/filebeat-log-stdout-logstash/171771 "2019-03-11T13:02:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wiliamauc85](https://avatars.discourse-cdn.com/v4/letter/w/bc8723/32.png) [@wiliamauc85](https://discuss.elastic.co/u/wiliamauc85)\
**Post date:** [March 11, 2019, 1:02pm UTC](https://discuss.elastic.co/t/filebeat-log-stdout-logstash/171771/1 "2019-03-11T13:02:22Z")

</div>

I'm relatively new to ELK and currently trying to go through this article and I'm trying to just look at the stdout in the logstash console however it doesn't seem to be working.

My filebeat.yml config is on the squid server is

```
filebeat.inputs:
  - type: log
  enabled: true
  paths:
    - /var/log/squid/access.log

output.logstash:
  hosts: ["logstash:5044"]

```

The pipeline config is as follows on the logstash server

```
input {
  beats {
    port => "5044"
  }
}
output {
  stdout { codec => rubydebug }
}

```

Looking at the following guide, it should be relatively straight forward  
[https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html](https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html) and I should be seeing the output on the logstash console, however there's nothing, I'm not sure what i might be missing?

Any pointers?

---

<div class="post-metadata">

**Author:** ![kharvey](https://avatars.discourse-cdn.com/v4/letter/k/d07c76/32.png) [@kharvey](https://discuss.elastic.co/u/kharvey)\
**Post date:** [March 11, 2019, 3:53pm UTC](https://discuss.elastic.co/t/filebeat-log-stdout-logstash/171771/2 "2019-03-11T15:53:35Z")

</div>

Are you running both the logstash and filebeat as services on the systems?

I would recommend for testing to stop the services that are running and use commands to test. That way you can see errors as they arise.

The command I run to start logstash for testing is:

```auto
/usr/share/logstash/bin/logstash --config.reload.automatic --path.settings=/etc/logstash
```

And the command I use for filebeats is:

```auto
/usr/share/filebeat/bin/filebeat -e -c /etc/filebeat/filebeat.yml -d "publish"
```

When I first started, I had a problem with open ports on my logstash server, so my filebeats server kept popping up an error message that it could not connect. So the goal here is to figure out what errors are popping up.

---

<div class="post-metadata">

**Author:** ![wiliamauc85](https://avatars.discourse-cdn.com/v4/letter/w/bc8723/32.png) [@wiliamauc85](https://discuss.elastic.co/u/wiliamauc85)\
**Post date:** [March 12, 2019, 11:12am UTC](https://discuss.elastic.co/t/filebeat-log-stdout-logstash/171771/3 "2019-03-12T11:12:32Z")

</div>

Thanks for the tip, I was running them both as services.  
Stopped the services and then was able to run the commands for both filebeats and logstash, can also see the stdout on the console.

All working as expected now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2019, 11:12am UTC](https://discuss.elastic.co/t/filebeat-log-stdout-logstash/171771/4 "2019-04-09T11:12:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
