# FileBeat Optimization

**URL:** <https://discuss.elastic.co/t/filebeat-optimization/63711>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 24, 2016, 7:22am UTC](https://discuss.elastic.co/t/filebeat-optimization/63711 "2016-10-24T07:22:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![manojvenkat](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@manojvenkat](https://discuss.elastic.co/u/manojvenkat)\
**Post date:** [October 24, 2016, 7:22am UTC](https://discuss.elastic.co/t/filebeat-optimization/63711/1 "2016-10-24T07:22:42Z")

</div>

Dear All,

I have Installed Filebeat on my application server and ELK stack on another server. I have configured filebeat output to Elasticsearch and I started seeing logs on Kibana. But in few minutes logs stopped shipping. I restarted Filebeat and Application server and again logs started to display on Kibana for few minutes. Could someone please help me what could be the reason for this. Do I need to optimize/fine tune Filebeat or elasticsearch? I am a newbie to ELK. Appreciate your support. Thanks.

The output in filebeat.yml is configured to Elasticsearch only and commented out other fields.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 24, 2016, 7:56am UTC](https://discuss.elastic.co/t/filebeat-optimization/63711/2 "2016-10-24T07:56:46Z")

</div>

Can you share your filebeat config and log output? In addition, which versions of FB, Elasticsearch and Kibana are you using?

---

<div class="post-metadata">

**Author:** ![manojvenkat](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@manojvenkat](https://discuss.elastic.co/u/manojvenkat)\
**Post date:** [October 24, 2016, 8:22am UTC](https://discuss.elastic.co/t/filebeat-optimization/63711/3 "2016-10-24T08:22:47Z")

</div>

Hi Ruflin,

Below versions are used,

filebeat version: 1.3.1  
elasticsearch version:2.4  
kibana version :4.4.2

---

<div class="post-metadata">

**Author:** ![manojvenkat](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@manojvenkat](https://discuss.elastic.co/u/manojvenkat)\
**Post date:** [October 24, 2016, 8:28am UTC](https://discuss.elastic.co/t/filebeat-optimization/63711/4 "2016-10-24T08:28:15Z")

</div>

Ruflin, I am not able to paste the full yml file here.

Below is what configured in output,

```auto
  elasticsearch:
    # Array of hosts to connect to.
    # Scheme and port can be left out and will be set to the default (http and 9200)
    # In case you specify and additional path, the scheme is required: http://localhost:9200/path
    # IPv6 addresses should always be defined as: https://[2001:db8::1]:9200
    hosts: ["10.30.66.227:9200"]

```

I have not made any other custom changes to YML file.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 25, 2016, 7:14am UTC](https://discuss.elastic.co/t/filebeat-optimization/63711/5 "2016-10-25T07:14:19Z")

</div>

You can use a gist to paste the full log and config and then link it here. Without the log files it is very hard to figure out what is going on.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2016, 7:23am UTC](https://discuss.elastic.co/t/filebeat-optimization/63711/6 "2016-11-14T07:23:18Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
