# Filebeat passing over logstash

**URL:** <https://discuss.elastic.co/t/filebeat-passing-over-logstash/194882>\
**Category:** Logstash\
**Created:** [August 12, 2019, 3:57pm UTC](https://discuss.elastic.co/t/filebeat-passing-over-logstash/194882 "2019-08-12T15:57:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Felipe\_Cabral\_Jeroni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felipe_cabral_jeroni/32/51755_2.png) [@Felipe\_Cabral\_Jeroni](https://discuss.elastic.co/u/Felipe_Cabral_Jeroni)\
**Post date:** [August 12, 2019, 3:57pm UTC](https://discuss.elastic.co/t/filebeat-passing-over-logstash/194882/1 "2019-08-12T15:57:32Z")

</div>

Hi guys,

I'm trying to figure out why my filebeat is not sending information to logstach. Instead, it's sending directly to elastic.

When I go to my kibana there is only the filebeat index patter. When I access the elastich utr :[http://172.26.73.113:9200/logstash-\*/\_search?pretty](http://172.26.73.113:9200/logstash-*/_search?pretty), the following result is showed (no results):

```
{

```

"took" : 0,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 0,  
"successful" : 0,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : {  
"value" : 0,  
"relation" : "eq"  
},  
"max\_score" : 0.0,  
"hits" :   
}  
}

Here is my Filebeat configuration:

```
#================================ Outputs =====================================

```

# Configure what output to use when sending the data collected by the beat.

#-------------------------- Elasticsearch output ------------------------------  
##output.elasticsearch:

# Array of hosts to connect to.

#hosts: ["172.26.73.113:9200"]

# Optional protocol and basic auth credentials.

#protocol: "https"  
#username: "elastic"  
#password: "changeme"

#----------------------------- Logstash output --------------------------------  
output.logstash:

# The Logstash hosts

hosts: ["172.26.73.113:5044"]

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]

here my logstash configuration file:

```
input {
beats {
    port => 5044
    host => "172.26.73.113"
}

```

}

output {  
elasticsearch {  
hosts =\> ["172.26.73.113:9200"]  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 4:03pm UTC](https://discuss.elastic.co/t/filebeat-passing-over-logstash/194882/2 "2019-08-12T16:03:33Z")

</div>

Why are you looking for a logstash-\* index. You are setting the index to "%{[@metadata][beat]}-%{+YYYY.MM.dd}", which will be filebeat...

---

<div class="post-metadata">

**Author:** ![Felipe\_Cabral\_Jeroni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felipe_cabral_jeroni/32/51755_2.png) [@Felipe\_Cabral\_Jeroni](https://discuss.elastic.co/u/Felipe_Cabral_Jeroni)\
**Post date:** [August 13, 2019, 7:46am UTC](https://discuss.elastic.co/t/filebeat-passing-over-logstash/194882/3 "2019-08-13T07:46:29Z")

</div>

Hi @Badger,

Thank you for that. If you point, now I can see the logs into [http://172.26.73.113:9200/logstash-\*/\_search?pretty](http://172.26.73.113:9200/logstash-*/_search?pretty) because I've changed the index to: index =\> "logstash-%{+YYYY.MM.dd}"

Thank you again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2019, 7:46am UTC](https://discuss.elastic.co/t/filebeat-passing-over-logstash/194882/4 "2019-09-10T07:46:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
