# Filebeat/logstash installation and configuration

**URL:** <https://discuss.elastic.co/t/filebeat-logstash-installation-and-configuration/88797>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 9, 2017, 7:02am UTC](https://discuss.elastic.co/t/filebeat-logstash-installation-and-configuration/88797 "2017-06-09T07:02:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![richagautam](https://avatars.discourse-cdn.com/v4/letter/r/9e8a1a/32.png) [@richagautam](https://discuss.elastic.co/u/richagautam)\
**Post date:** [June 9, 2017, 7:02am UTC](https://discuss.elastic.co/t/filebeat-logstash-installation-and-configuration/88797/1 "2017-06-09T07:02:16Z")

</div>

Hi,

I have to install and configure filebeat and logstash in CentOS7 OS for an assingment.

Filebeat will be on one server and logstash will be on another server i.e both will be on different server.

I am planning to use following steps to install and configure filebeat and logstash .  
Please suggest me whether i am using right steps or not

# Install Java

1.Download Java 8 JDK with the wget command.  
wget --no-cookies --no-check-certificate --header "Cookie: gpw\_e24=http:%2F%[2Fwww.oracle.com](http://2Fwww.oracle.com)%2F; oraclelicense=accept-securebackup-cookie" "[http://download.oracle.com/otn-pub/java/jdk/8u77-b02/jdk-8u77-linux-x64.rpm](http://download.oracle.com/otn-pub/java/jdk/8u77-b02/jdk-8u77-linux-x64.rpm)"  
2.Then install it with this rpm command;  
rpm -ivh jdk-8u77-linux-x64.rpm  
3.Finally, check java JDK version to ensure that it is working properly.  
java -version

# ========================================= Install and Configure Logstash

1.Download Logstash and install it with rpm.  
wget [https://artifacts.elastic.co/downloads/logstash/logstash-5.1.1.rpm](https://artifacts.elastic.co/downloads/logstash/logstash-5.1.1.rpm) rpm -ivh logstash-5.1.1.rpm  
2.Generate a new SSL certificate  
3.Go to the tls directory and edit the openssl.cnf file.  
cd /etc/pki/tls  
vim openssl.cnf  
4.Add a new line in the '[v3\_ca]' section for the server identification.  
v3\_ca ]

```
     # Server IP Address
       subjectAltName = IP: logstash_server_ip

```

5.Save and exit.  
6.Generate the certificate file with the openssl command.  
openssl req -config /etc/pki/tls/openssl.cnf -x509 -days 3650 -batch -nodes -newkey rsa:2048 -keyout /etc/pki/tls/private/logstash-forwarder.key -out /etc/pki/tls/certs/logstash-forwarder.crt

7.The certificate files can be found in the '/etc/pki/tls/certs/' and '/etc/pki/tls/private/' directories.

# ======================================== Install and configure filebeat

1.Login to the filebeat server.  
ssh root@client1IP

2.Copy the certificate file with the scp command.  
scp root@elk-serverIP:~/logstash-forwarder.crt . TYPE elk-server password

3.Create a new directory and move certificate file to that directory.  
sudo mkdir -p /etc/pki/tls/certs/ mv ~/logstash-forwarder.crt /etc/pki/tls/certs/

4.Download Filebeat and install it with rpm.  
wget [https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-5.1.1-x86\_64.rpm](https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-5.1.1-x86_64.rpm) rpm -ivh filebeat-5.1.1-x86\_64.rpm

5.Filebeat has been installed, go to the configuration directory and edit the file 'filebeat.yml'.

```
 cd /etc/filebeat/
  vim filebeat.yml
  
   paths: Log file Path
   
Add a new configuration on line 26 to define the syslog type files.
  document-type: mylog
  
6.output.logstash:
  # The Logstash hosts
   hosts: ["10.0.15.10:5443"]
   bulk_max_size: 1024
   ssl.certificate_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]
   template.name: "filebeat"
   template.path: "filebeat.template.json"
   template.overwrite: false  
  
7.Save the file and exit vim.
8.Add Filebeat to start at boot time and start it.
   sudo systemctl enable filebeat
   sudo systemctl start filebeat  

```

Please advice whether these steps are correct or not.  
What is the purpose of ssl certificate and i have to copy the logstash certificate to filebeat??

Thanks

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 15, 2017, 12:00am UTC](https://discuss.elastic.co/t/filebeat-logstash-installation-and-configuration/88797/2 "2017-06-15T00:00:40Z")

</div>

Those steps seem reasonable (I don't see where Logstash is actually configured). You can review the [Filebeat Getting Started](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html) to compare with our recommended installation steps. And there is a separate guide about [securing the communication](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ssl-logstash.html) between Filebeat and Logstash.

> [@richagautam](#):
>
> What is the purpose of ssl certificate and i have to copy the logstash certificate to filebeat??

The purpose of copying the CA certification is to enable Filebeat to trust the certificate presented by the LS server.

---

<div class="post-metadata">

**Author:** ![Nikhilpawar1985](https://avatars.discourse-cdn.com/v4/letter/n/e68b1a/32.png) [@Nikhilpawar1985](https://discuss.elastic.co/u/Nikhilpawar1985)\
**Post date:** [June 19, 2017, 8:26pm UTC](https://discuss.elastic.co/t/filebeat-logstash-installation-and-configuration/88797/3 "2017-06-19T20:26:59Z")

</div>

If not using X-pack , how to generate logstash ca certificate for filebeat agents ?  
Can someone guide on this ?

---

<div class="post-metadata">

**Author:** ![Pandiyan\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pandiyan_m/32/19404_2.png) [@Pandiyan\_M](https://discuss.elastic.co/u/Pandiyan_M)\
**Post date:** [June 26, 2017, 5:52am UTC](https://discuss.elastic.co/t/filebeat-logstash-installation-and-configuration/88797/4 "2017-06-26T05:52:19Z")

</div>

You can also comment tls certificate if dont want to secure where your infra is secured, check do you really need template or go with default one. Rest steps are fine.

🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2017, 5:52am UTC](https://discuss.elastic.co/t/filebeat-logstash-installation-and-configuration/88797/5 "2017-07-24T05:52:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
