# Filebeat-logstash issue

**URL:** <https://discuss.elastic.co/t/filebeat-logstash-issue/259272>\
**Category:** Logstash\
**Created:** [December 21, 2020, 2:33pm UTC](https://discuss.elastic.co/t/filebeat-logstash-issue/259272 "2020-12-21T14:33:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mustafa.husny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mustafa.husny/32/77154_2.png) [@mustafa.husny](https://discuss.elastic.co/u/mustafa.husny)\
**Post date:** [December 21, 2020, 2:33pm UTC](https://discuss.elastic.co/t/filebeat-logstash-issue/259272/1 "2020-12-21T14:33:11Z")

</div>

I am using ELK 7.6.2  
I have three piplines  
first for the heartbeat  
second for the tcp to forward logs from QRadar  
Third is for filebeat  
I am receiving logs from heartbeat and qradar, but when I installed filebeat on windows machine I can not receive logs from it  
my filebeat config

#=========================== Filebeat inputs =============================

> filebeat.inputs:
> 
> # Each - is an input. Most options can be set at the input level, so
> 
> # you can use different inputs for various configurations.
> 
> # Below are the input specific configurations.
> 
> - type: log

> #============================= Filebeat modules ===============================
> 
> filebeat.config.modules:
> 
> # Glob pattern for configuration loading
> 
> path: ${path.config}/modules.d/\*.yml
> 
> # Set to true to enable config reloading
> 
> reload.enabled: false
> 
> # Period on which files under path should be checked for changes
> 
> #reload.period: 10s
> 
> #----------------------------- Logstash output --------------------------------  
> output.logstash:
> 
> # The Logstash hosts
> 
> hosts: ["ELK:5044"]

logstash pipline for filebeat

> input {  
> tcp {  
> port =\> 5000  
> codec =\> json  
> }  
> }
> 
> filter {  
> date {  
> match =\> ["timeMillis", "UNIX\_MS"]  
> }  
> }
> 
> output {
> 
> # stdout { codec =\> rubydebug }
> 
> elasticsearch {  
> hosts =\> "ip:9200"  
> user =\> "elastic"  
> password =\> "mypassword"  
> index =\> "qradar-%{+YYYY.MM.dd}"  
> }  
> }

piplines.conf

> - pipeline.id: main  
> path.config: "/etc/logstash/conf.d/filebeat.conf"
> 
> - pipeline.id: heartbeat  
> path.config: "/etc/logstash/conf.d/heartbeat.conf"
> 
> - pipeline.id: qradar  
> path.config: "/etc/logstash/conf.d/qradar.conf"

I start the service using systemctl

I can telnet from my windows machine to ELK machine on port 5044

sample of filebeat logs

> | 2020-12-21T15:10:46.218+0200 | INFO | [monitoring] | log/log.go:145 | Non-zero metrics in the last 30s | {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":62},"total":{"ticks":311,"time":{"ms":16},"value":311},"user":{"ticks":249,"time":{"ms":16}}},"handles":{"open":169},"info":{"ephemeral\_id":"fc74c7bf-bf32-4fc8-ae14-8bd53d923764","uptime":{"ms":1382417}},"memstats":{"gc\_next":9814304,"memory\_alloc":4971112,"memory\_total":15764888,"rss":8192},"runtime":{"goroutines":26}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"registrar":{"states":{"current":0}}}}} |
> | --- | --- | --- | --- | --- | --- |
> | 2020-12-21T15:11:16.219+0200 | INFO | [monitoring] | log/log.go:145 | Non-zero metrics in the last 30s | {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":62},"total":{"ticks":327,"value":327},"user":{"ticks":265}},"handles":{"open":169},"info":{"ephemeral\_id":"fc74c7bf-bf32-4fc8-ae14-8bd53d923764","uptime":{"ms":1412417}},"memstats":{"gc\_next":9814304,"memory\_alloc":5010584,"memory\_total":15804360},"runtime":{"goroutines":26}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"registrar":{"states":{"current":0}}}}} |
> | 2020-12-21T15:11:46.219+0200 | INFO | [monitoring] | log/log.go:145 | Non-zero metrics in the last 30s | {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":62},"total":{"ticks":327,"value":327},"user":{"ticks":265}},"handles":{"open":169},"info":{"ephemeral\_id":"fc74c7bf-bf32-4fc8-ae14-8bd53d923764","uptime":{"ms":1442416}},"memstats":{"gc\_next":9814304,"memory\_alloc":5055768,"memory\_total":15849544,"rss":4096},"runtime":{"goroutines":26}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"registrar":{"states":{"current":0}}}}} |
> | 2020-12-21T15:12:16.219+0200 | INFO | [monitoring] | log/log.go:145 | Non-zero metrics in the last 30s | {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":62},"total":{"ticks":327,"value":327},"user":{"ticks":265}},"handles":{"open":169},"info":{"ephemeral\_id":"fc74c7bf-bf32-4fc8-ae14-8bd53d923764","uptime":{"ms":1472416}},"memstats":{"gc\_next":9819616,"memory\_alloc":4908352,"memory\_total":15898536,"rss":-126976},"runtime":{"goroutines":26}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"registrar":{"states":{"current":0}}}}} |
> | 2020-12-21T15:12:46.219+0200 | INFO | [monitoring] | log/log.go:145 | Non-zero metrics in the last 30s | {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":62},"total":{"ticks":327,"value":327},"user":{"ticks":265}},"handles":{"open":169},"info":{"ephemeral\_id":"fc74c7bf-bf32-4fc8-ae14-8bd53d923764","uptime":{"ms":1502416}},"memstats":{"gc\_next":9819616,"memory\_alloc":4963368,"memory\_total":15953552},"runtime":{"goroutines":26}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"registrar":{"states":{"current":0}}}}} |
> | 2020-12-21T15:13:16.219+0200 | INFO | [monitoring] | log/log.go:145 | Non-zero metrics in the last 30s | {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":62},"total":{"ticks":327,"value":327},"user":{"ticks":265}},"handles":{"open":169},"info":{"ephemeral\_id":"fc74c7bf-bf32-4fc8-ae14-8bd53d923764","uptime":{"ms":1532416}},"memstats":{"gc\_next":9819616,"memory\_alloc":5005096,"memory\_total":15995280},"runtime":{"goroutines":26}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"registrar":{"states":{"current":0}}}}} |
> | 2020-12-21T15:13:46.220+0200 | INFO | [monitoring] | log/log.go:145 | Non-zero metrics in the last 30s | {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":62},"total":{"ticks":327,"value":327},"user":{"ticks":265}},"handles":{"open":169},"info":{"ephemeral\_id":"fc74c7bf-bf32-4fc8-ae14-8bd53d923764","uptime":{"ms":1562418}},"memstats":{"gc\_next":9819616,"memory\_alloc":5055416,"memory\_total":16045600},"runtime":{"goroutines":26}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"registrar":{"states":{"current":0}}}}} |
> | 2020-12-21T15:14:16.220+0200 | INFO | [monitoring] | log/log.go:145 | Non-zero metrics in the last 30s | {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":62},"total":{"ticks":342,"time":{"ms":15},"value":342},"user":{"ticks":280,"time":{"ms":15}}},"handles":{"open":169},"info":{"ephemeral\_id":"fc74c7bf-bf32-4fc8-ae14-8bd53d923764","uptime":{"ms":1592416}},"memstats":{"gc\_next":9814304,"memory\_alloc":4911088,"memory\_total":16093632,"rss":4096},"runtime":{"goroutines":26}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"registrar":{"states":{"current":0}}}}} |
> | 2020-12-21T15:14:46.220+0200 | INFO | [monitoring] | log/log.go:145 | Non-zero metrics in the last 30s | {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":62},"total":{"ticks":342,"value":342},"user":{"ticks":280}},"handles":{"open":169},"info":{"ephemeral\_id":"fc74c7bf-bf32-4fc8-ae14-8bd53d923764","uptime":{"ms":1622417}},"memstats":{"gc\_next":9814304,"memory\_alloc":4961272,"memory\_total":16143816},"runtime":{"goroutines":26}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"registrar":{"states":{"current":0}}}}} |
> | 2020-12-21T15:15:16.220+0200 | INFO | [monitoring] | log/log.go:145 | Non-zero metrics in the last 30s | {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":62},"total":{"ticks":342,"value":342},"user":{"ticks":280}},"handles":{"open":169},"info":{"ephemeral\_id":"fc74c7bf-bf32-4fc8-ae14-8bd53d923764","uptime":{"ms":1652416}},"memstats":{"gc\_next":9814304,"memory\_alloc":5007304,"memory\_total":16189848},"runtime":{"goroutines":26}},"filebeat":{"harvester":{"open\_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"registrar":{"states":{"current":0}}}}} |

I can not find index in kibana to create index pattern  
Tried to check traffic using tcpdump utility but I can not receive any traffic

please please advice

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 21, 2020, 2:48pm UTC](https://discuss.elastic.co/t/filebeat-logstash-issue/259272/2 "2020-12-21T14:48:22Z")

</div>

I think you shared the wrong config file in your question, the pipeline you shared seems to be the qradar pipeline.

Share the config of your `filebeat` pipeline.

---

<div class="post-metadata">

**Author:** ![mustafa.husny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mustafa.husny/32/77154_2.png) [@mustafa.husny](https://discuss.elastic.co/u/mustafa.husny)\
**Post date:** [December 21, 2020, 6:32pm UTC](https://discuss.elastic.co/t/filebeat-logstash-issue/259272/3 "2020-12-21T18:32:19Z")

</div>

Sorry my bad

> input {  
> beats {  
> port =\> 5044  
> ssl =\> false  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> ["[http://elk:9200](http://elk:9200)"]  
> index =\> "logs-%{[host][name]}-%{IP}-%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> user =\> "elastic"  
> password =\> "mypassword"  
> }  
> }

I can not put the configuration with its indentation

---

<div class="post-metadata">

**Author:** ![mustafa.husny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mustafa.husny/32/77154_2.png) [@mustafa.husny](https://discuss.elastic.co/u/mustafa.husny)\
**Post date:** [December 23, 2020, 3:16am UTC](https://discuss.elastic.co/t/filebeat-logstash-issue/259272/4 "2020-12-23T03:16:37Z")

</div>

Any idea

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 20, 2021, 3:16am UTC](https://discuss.elastic.co/t/filebeat-logstash-issue/259272/5 "2021-01-20T03:16:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
