# Filebeat (with ILM) -\> Logstash -\> Elasticsearch not working

**URL:** <https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895>\
**Category:** Beats\
**Tags:** ilm-index-lifecycle-management, filebeat\
**Created:** [May 25, 2021, 6:22am UTC](https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895 "2021-05-25T06:22:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pk.241011](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pk.241011/32/86285_2.png) [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Post date:** [May 25, 2021, 6:22am UTC](https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895/1 "2021-05-25T06:22:15Z")

</div>

Hi,

I think I am missing some simple settings here.  
I have enabled the ILM in beats:

```
setup.ilm.enabled: true
setup.ilm.rollover_alias: "log-dev-filebeat"
setup.ilm.pattern: "{now/d}-000001"
setup.ilm.policy_name: "filebeat_dev_policy"

output.logstash:

  hosts: ["XXXXXX:2222"]
  index: log-dev-filebeat

```

The logstash file has a Elasticsearch output section:

```
output
{
	elasticsearch
	{
			hosts => "XCCCCC:34534"
			index => "%{[@metadata][beat]}-%{[@metadata][version]}"
			timeout => 600
			user => 'TTTTTT'
			password => 'PPPPPP'
	}
}

```

Now the setup is working in the sense that index is created but I see that the index created is **log-dev-filebeat-7.7.0**. It is not followed by the 000001.

Any ideas?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2021, 6:24am UTC](https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895/2 "2021-05-25T06:24:10Z")

</div>

If you have Logstash in the middle, then your output needs to be pointing to the rollover alias.

---

<div class="post-metadata">

**Author:** ![pk.241011](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pk.241011/32/86285_2.png) [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Post date:** [May 25, 2021, 6:38am UTC](https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895/3 "2021-05-25T06:38:10Z")

</div>

I am a bit confused on the output. Is it output section of logstash file? Or in the filebeat.yml?  
I tried with changing the index in the logstash elasticsearch output section to the roll-over alias. But did not work. Do I have to do some bootstrapping thing which many people have been talking about?

```
output
{
	elasticsearch
	{
			hosts => "XCCCCC:34534"
			index => "log-dev-filebeat"
			timeout => 600
			user => 'TTTTTT'
			password => 'PPPPPP'
	}
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2021, 6:42am UTC](https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895/4 "2021-05-25T06:42:42Z")

</div>

> [@pk.241011](#):
>
> Is it output section of logstash file?

Yes that one.

> [@pk.241011](#):
>
> But did not work

What do you mean by that?

---

<div class="post-metadata">

**Author:** ![pk.241011](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pk.241011/32/86285_2.png) [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Post date:** [May 25, 2021, 6:46am UTC](https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895/5 "2021-05-25T06:46:55Z")

</div>

I got an index log-dev-filebeat.

Also GET \_cat/aliases did not list any alias getting created.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 27, 2021, 1:18am UTC](https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895/6 "2021-05-27T01:18:32Z")

</div>

Have u run `filebeat setup` yet? You need to run the setup using th elasticsearch output and then u can push to logstash with the rollover alias. See [Use ingest pipelines for parsing | Logstash Reference [7.13] | Elastic](https://www.elastic.co/guide/en/logstash/current/use-ingest-pipelines.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2021, 3:19am UTC](https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895/7 "2021-06-24T03:19:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
