# Filebeat TCP input with Nginx Module

**URL:** <https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 30, 2020, 7:01am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618 "2020-03-30T07:01:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [March 30, 2020, 7:01am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618/1 "2020-03-30T07:01:35Z")

</div>

Hi ,

My setup:  
Elasticsearch & Kibana - 7.5.2  
Filebeat - 7.5.x

I have a Filebeat(NGINX-1) listen on TCP input to recieve Proxy logs from a remote NGINX server(NGINX-2) sending logs through Logstash TCP output.  
My question is how to use a Filebeat.input : TCP method to ingest logs from NGINX-2 (remote proxy) and parse the logs within the same filebeat index using the currently running"nginx" module.

Also NGINX2 cannot send logs directly to Elasticsearch nodes.

I know how to configure logstash and parse the logs separately, but i would like to explore using one filebeat tcp input with nginx module enabled.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [March 30, 2020, 8:54am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618/2 "2020-03-30T08:54:52Z")

</div>

Hi @karnamonkster!

I'm not sure if I completely understand your question of what you are trying to achieve.  
However, you can always use Filebeat's `nginx` module to parse the logs of an nginx server (from `/var/log/nginx.log` for instance) and ship them directly to Elasticsearch. This requires that to install Filebeat agent on the same machine with the nginx server so as Filebeat to be able to access the logs' file.

---

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [March 30, 2020, 9:29am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618/3 "2020-03-30T09:29:41Z")

</div>

@ChrsMark

Let me clarify the case:  
I have 2 NGINX servers.  
One of them(NGINX-1) can reach Elasticsearch nodes and is sending the Nginx data perfectly fine through Filebeat

The other one (NGINX-2) cannot reach Elasticsearch node and can only communicate to NGINX-1 to send logs on a given port (say 5044) .

So i wanted to know if NGINX-1 filebeat input as TCP can consume the logs and parse the NGINX-2 logs as well.

---

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [March 31, 2020, 7:27am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618/4 "2020-03-31T07:27:57Z")

</div>

Hi @ChrsMark

I am able to send the logs through TCP input to the filebeat  
But is there a way to parse the message field in ECS format similar to nginx module

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [March 31, 2020, 8:24am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618/5 "2020-03-31T08:24:49Z")

</div>

Hi!

I don't think you redirect the tcp input to a module right now. You can always use processors to customize your fields. [Script processor](https://www.elastic.co/guide/en/beats/filebeat/master/processor-script.html) might be handy here.

In addition, I would try to redirect the logs I receive to a file and then have a second Filebeat collecting from this file using nginx module.

C.

---

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [March 31, 2020, 8:30am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618/6 "2020-03-31T08:30:22Z")

</div>

Hi @ChrsMark ,

I have managed to push the logs from the remote Nginx to this one using rsyslog.  
But all i need where i can specify a GROK pattern, I remember there used to be a GROK processor, but not sure how do i use that with my filebeat.input (TCP) block.

I will look at the script processor as suggested.

---

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [April 1, 2020, 5:16am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618/7 "2020-04-01T05:16:18Z")

</div>

Hi @ChrsMark,

I finally managed to get what i wanted.  
Didn't know it was that easy.

1. Moved my remote NGINX-2logs to a folder on NGINX-1 Machine say at

/var/log/NGINX2/access.log  
/var/log/NGINX2/error.log

1. Now since the NGINX modules only checks on the default path as configured in the nginx module manifest.yml located at:

2. So made a slight change by adding the NGINX2 log paths under default path variable.  
And that was it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2020, 5:16am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618/8 "2020-04-29T05:16:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
