# Filebeat or logstash is better to use

**URL:** <https://discuss.elastic.co/t/filebeat-or-logstash-is-better-to-use/93103>\
**Category:** Logstash\
**Created:** [July 14, 2017, 2:53am UTC](https://discuss.elastic.co/t/filebeat-or-logstash-is-better-to-use/93103 "2017-07-14T02:53:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![P\_Kumar](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@P\_Kumar](https://discuss.elastic.co/u/P_Kumar)\
**Post date:** [July 14, 2017, 2:53am UTC](https://discuss.elastic.co/t/filebeat-or-logstash-is-better-to-use/93103/1 "2017-07-14T02:53:25Z")

</div>

Hi ,  
Logstash can transfer logs to elasticsearch and fillebeat can transfer to logstash then elasticsearch . so if we will use logstash and ignore the filebeat in client machine . Is it ok or any special reason to add filebeat in client box.

---

<div class="post-metadata">

**Author:** ![Yaswanth](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Post date:** [July 14, 2017, 6:31am UTC](https://discuss.elastic.co/t/filebeat-or-logstash-is-better-to-use/93103/2 "2017-07-14T06:31:07Z")

</div>

Hi,

First what are you doing with filebeat or logstash ? Are you just sending to ES without parsing them?

Bascially filebeat is light weight shipper which will send the logs from different sources to one. Logstash is mainly used to parse those logs as per your needs. You can do the parsing in filebeat but not that great as logstash do.

Thanks

---

<div class="post-metadata">

**Author:** ![P\_Kumar](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@P\_Kumar](https://discuss.elastic.co/u/P_Kumar)\
**Post date:** [July 15, 2017, 2:11am UTC](https://discuss.elastic.co/t/filebeat-or-logstash-is-better-to-use/93103/3 "2017-07-15T02:11:25Z")

</div>

Hi ,  
Thanks for responding . I am using logstash and reading the file and then sending file to ES and trying to make the different idex for diff logs files but that is not happening . below is my logstash config file .

nput {  
file {  
path =\> ["/was/AppServer/profiles/Dmgr01/logs/dmgr/\*.log"]  
start\_position =\> "beginning"  
type =\> "Dmgr01"  
ignore\_older =\> "8640000"  
}

```
file {
        path => ["/was/AppServer/profiles/AppSrv01/logs/nodeagent/*.log"]
        start_position => "beginning"
        type => "AppSrv01"
        ignore_older => "8640000"
}

```

}  
filter {  
if [type] == "SystemOut.log" {  
grok {  
match =\> { "message" =\> "%{%{DATESTAMP} %{GREEDYDATA}" }  
}  
}  
}  
output {  
if [type] == "Dmgr01" {  
elasticsearch{  
hosts =\> ["x.x.x.x:9200"]  
index =\> "Hostname\_Dmgr01"  
}  
}else if [type] == "AppSrv01" {  
elasticsearch{  
hosts =\> ["x.x.x.x:9200"]  
index =\> "Hostname\_AppSrv01"  
}  
}else {  
elasticsearch{  
hosts =\> ["x.x.x.x:9200"]  
}

}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 12, 2017, 2:11am UTC](https://discuss.elastic.co/t/filebeat-or-logstash-is-better-to-use/93103/4 "2017-08-12T02:11:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
