# Filebeat to send logs to Logstash and ES

**URL:** <https://discuss.elastic.co/t/filebeat-to-send-logs-to-logstash-and-es/199092>\
**Category:** Elasticsearch\
**Created:** [September 11, 2019, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-to-send-logs-to-logstash-and-es/199092 "2019-09-11T14:23:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ghaith\_Haddad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghaith_haddad/32/49288_2.png) [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Post date:** [September 11, 2019, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-to-send-logs-to-logstash-and-es/199092/1 "2019-09-11T14:23:44Z")

</div>

Hello everyone,

So i have filebeat configured in an apache server AWS EC2 instance and another EC2 instance which has logstash and elasticsearch. i can send log files to the ec2 instance to logstash but i can only display them on the console. How can i forward those files to elasticsearch and actually be able to see them or go through them i can't figure it out. Because i also have kibana setup and i need to view all the logs from the apache server and also a bunch of other servers as well.

Any help or guidance is GREATLY APPRECIATED!

Cheers!

---

<div class="post-metadata">

**Author:** ![hunsw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsw/32/93637_2.png) [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Post date:** [September 11, 2019, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-to-send-logs-to-logstash-and-es/199092/2 "2019-09-11T14:31:10Z")

</div>

This shouldn't be hard, in your Logstash configuration just add an ES output. The index name will be the field you specify in Filebeat's fields/index.

```auto
output {
  elasticsearch {
    hosts => [
      "elasticsearch01.example.com:9200",
      "elasticsearch02.example.com:9200" ]
    index => "%{[index]}"

  }
}

```

---

<div class="post-metadata">

**Author:** ![Ghaith\_Haddad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghaith_haddad/32/49288_2.png) [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Post date:** [September 11, 2019, 2:39pm UTC](https://discuss.elastic.co/t/filebeat-to-send-logs-to-logstash-and-es/199092/3 "2019-09-11T14:39:02Z")

</div>

ok after i do that how can i know for sure that logstash and es recieved the files?

---

<div class="post-metadata">

**Author:** ![Ghaith\_Haddad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghaith_haddad/32/49288_2.png) [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Post date:** [September 11, 2019, 2:42pm UTC](https://discuss.elastic.co/t/filebeat-to-send-logs-to-logstash-and-es/199092/4 "2019-09-11T14:42:43Z")

</div>

wait just to double check, what do u mean by the index/fields in filebeat? like in my filebeat output config it just goes to logstash server on port 5044 i didnt specify any fields

---

<div class="post-metadata">

**Author:** ![hunsw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsw/32/93637_2.png) [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Post date:** [September 12, 2019, 7:24am UTC](https://discuss.elastic.co/t/filebeat-to-send-logs-to-logstash-and-es/199092/5 "2019-09-12T07:24:25Z")

</div>

##### `fields`

Optional fields that you can specify to add additional information to the output.

[https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#filebeat-input-log-fields](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#filebeat-input-log-fields)

```auto
fields:
  index: myindexname

```

---

<div class="post-metadata">

**Author:** ![Ghaith\_Haddad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghaith_haddad/32/49288_2.png) [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Post date:** [September 13, 2019, 2:28pm UTC](https://discuss.elastic.co/t/filebeat-to-send-logs-to-logstash-and-es/199092/6 "2019-09-13T14:28:15Z")

</div>

ok but where is myindexname configured? is it done at filebeat first or what exactly because honestly im very confused and i can't find any decent tutorials or guides on this thank you for your help!

---

<div class="post-metadata">

**Author:** ![hunsw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsw/32/93637_2.png) [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Post date:** [September 24, 2019, 11:19am UTC](https://discuss.elastic.co/t/filebeat-to-send-logs-to-logstash-and-es/199092/7 "2019-09-24T11:19:41Z")

</div>

Bit late to respond, but... anyway...

**myindexname** is just a name you come up with. If you collect system logs, you can call your index **syslog.** If you collect all kind of logs, you can call it **logs** or **logstash**.

## Tiny tutorial

You need to set up Filebeat and Logstash. These are by default configured in /etc/filebeat  
/filebeat.yml and /etc/logstash/logstash.yml.

For starters, delete everything from these files, because 95% of these are comments anyway. If you need the default contents later (e.g. the explanations), it's all out there on GitHub.

Now in Filebeat's yml (still /etc/filebeat/filebeat.yml 🙂 ) you need to specify an input and an output, e.g. Logstash if you fancy that:

```auto
filebeat.inputs:
- type: log
  - /var/log/messages
  fields:
    index: syslog

output.logstash
  hosts: ["mylogstash.example.com:5044"]

```

That's all for a very very basic FB setup.

In Logstash's yml (at /etc/logstash/logstash.yml) specify the data and log directories:

```auto
path.data: /var/lib/logstash
path.log: /var/log/logstash

```

Create a config file for your inputs/outputs, e.g.

```auto
input {
  beats {
    port => "5044"
  }
}
output {
  elasticsearch {
    hosts => [
      "elasticsearch01.example.com:9200",
      "elasticsearch02.example.com:9200" ]
    index => "%{[index]}"

  }
}

```

Again, this is a quite basic approach, but should work as soon as you restart Filebeat and Logstash. Your server's /var/log/messages will end up in a syslog index.

Be aware that a single syslog index will not be sufficient if you start collecting logs from many servers. There are techniques to handle this (e.g daily/weekly/monthly indexes, aliasing/rollover, etc.), you just need to read the Elastic documentation to learn about them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2019, 11:19am UTC](https://discuss.elastic.co/t/filebeat-to-send-logs-to-logstash-and-es/199092/8 "2019-10-22T11:19:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
