# Filebeat =\> Logstash in Elastic Cloud

**URL:** <https://discuss.elastic.co/t/filebeat-logstash-in-elastic-cloud/176064>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 9, 2019, 3:46pm UTC](https://discuss.elastic.co/t/filebeat-logstash-in-elastic-cloud/176064 "2019-04-09T15:46:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![carlduevel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlduevel/32/43792_2.png) [@carlduevel](https://discuss.elastic.co/u/carlduevel)\
**Post date:** [April 9, 2019, 3:46pm UTC](https://discuss.elastic.co/t/filebeat-logstash-in-elastic-cloud/176064/1 "2019-04-09T15:46:37Z")

</div>

I am evaluating Elastic Cloud and the preferred usage pattern would be to send log data with Filebeat to Logstash in the Cloud so we would just need to worry about Filebeat being configured the right way.

In the documentation I just found two options:

1. Filebeat (Local) to Elasticsearch (Cloud)
2. Logstash (Local) to Elasticsearch (Cloud)

So is our preferred way: Filebeat (local) to Logstash (Cloud) possible? Any pointers to documentation I missed are welcome.

Thanks in advance!  
Carl

---

<div class="post-metadata">

**Author:** ![BKG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bkg/32/43591_2.png) [@BKG](https://discuss.elastic.co/u/BKG)\
**Post date:** [April 9, 2019, 4:37pm UTC](https://discuss.elastic.co/t/filebeat-logstash-in-elastic-cloud/176064/2 "2019-04-09T16:37:28Z")

</div>

Elastic's cloud offering only has Kibana and Elasticsearch. You will still need to run your own Logstash instance if you definitely need it.

There's nothing wrong with running logstash on a publicly available IP address as long as you secure it properly.

To give you some insight into our setup, we have Filebeat pushing to Logstash which is running on the LAN, which then transforms data and drops unnecessary data, then forwards it to Elasticsearch which is running on Elastic Cloud.

We also have Metricbeat running on all of our hosts which is configured to send events **directly** to Elasticsearch. We made this descision because we didn't want our entire site to appear offline if logstash went down.

---

<div class="post-metadata">

**Author:** ![carlduevel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlduevel/32/43792_2.png) [@carlduevel](https://discuss.elastic.co/u/carlduevel)\
**Post date:** [April 9, 2019, 4:47pm UTC](https://discuss.elastic.co/t/filebeat-logstash-in-elastic-cloud/176064/3 "2019-04-09T16:47:22Z")

</div>

Thanks for your answer and your insight into your setup.  
I you sure about logstash not being part of the offering?  
I am asking because under "Management" in Kibana I can configure and deploy logstash pipelines.

---

<div class="post-metadata">

**Author:** ![BKG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bkg/32/43591_2.png) [@BKG](https://discuss.elastic.co/u/BKG)\
**Post date:** [April 9, 2019, 4:49pm UTC](https://discuss.elastic.co/t/filebeat-logstash-in-elastic-cloud/176064/4 "2019-04-09T16:49:36Z")

</div>

> [@carlduevel](#):
>
> under "Management" in Kibana I can configure and deploy logstash pipelines.

This only allows you to deploy configuration to Logstash instances that are set up for central management. Same for Beats.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2019, 4:49pm UTC](https://discuss.elastic.co/t/filebeat-logstash-in-elastic-cloud/176064/5 "2019-05-07T16:49:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
