# Filebeat parsing ftp logs

**URL:** <https://discuss.elastic.co/t/filebeat-parsing-ftp-logs/132615>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 21, 2018, 6:16am UTC](https://discuss.elastic.co/t/filebeat-parsing-ftp-logs/132615 "2018-05-21T06:16:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vijayakumar\_Kannan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakumar_kannan/32/34873_2.png) [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Post date:** [May 21, 2018, 6:16am UTC](https://discuss.elastic.co/t/filebeat-parsing-ftp-logs/132615/1 "2018-05-21T06:16:26Z")

</div>

Hi All,

Using filebeat agent for system and apache modules . the output directly forwarded to elasticsearch then getting the preconfigured kibana dashboards. Now i want to monitor the vsftpd daemon logs and parse it.

I am struck as we can't configure multiple outputs in filebeat . what is the way to do it?

Logfile location

/var/log/vsftpd/vsftpd.log and i have the grok patterns

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [May 22, 2018, 7:51am UTC](https://discuss.elastic.co/t/filebeat-parsing-ftp-logs/132615/2 "2018-05-22T07:51:41Z")

</div>

Hi @Vijayakumar_Kannan,

I'm wondering, why do you need multiple outputs? Do you plan to send the vsftpd logs to a different cluster? Please explain a little bit more about your use case

---

<div class="post-metadata">

**Author:** ![Vijayakumar\_Kannan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakumar_kannan/32/34873_2.png) [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Post date:** [May 22, 2018, 8:07am UTC](https://discuss.elastic.co/t/filebeat-parsing-ftp-logs/132615/3 "2018-05-22T08:07:48Z")

</div>

Currenrtly i use filebeat modules system & apache and forwarding to elasticsearch directly . Now custom requirement i want to parse the FTP logs and build the dashboard. it's recommended that i use the flow of filebeat -\> logstash -\> elasticsearch or filbeat -\> ingest node for FTP logs ( create new filbeat module VSFTP) -\> elasticsearch ?

i would prefer to have a new filebeat module created for vsftpd and then forward elasticsearch. if it's more time consuming than logstash then i will move over logstash oriented workflow.

Any guidance for filebeat module creation ?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [May 22, 2018, 8:38am UTC](https://discuss.elastic.co/t/filebeat-parsing-ftp-logs/132615/4 "2018-05-22T08:38:01Z")

</div>

Awesome!

I would say both approaches have similar complexity, if you want to go for the module, these are the docs on how to do it! [https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html](https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html)

It would be really nice if you contribute it to the beats repository, so more people can benefit from it. Also if you have questions during the process, don't hesitate to ask them in our discuss forum for developers: [https://discuss.elastic.co/c/beats/libbeat](https://discuss.elastic.co/c/beats/libbeat)

Best regrads

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2018, 10:38am UTC](https://discuss.elastic.co/t/filebeat-parsing-ftp-logs/132615/5 "2018-06-19T10:38:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
