# How can I get data from Filebeat to Flume?

**URL:** <https://discuss.elastic.co/t/how-can-i-get-data-from-filebeat-to-flume/51734>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 2, 2016, 7:40pm UTC](https://discuss.elastic.co/t/how-can-i-get-data-from-filebeat-to-flume/51734 "2016-06-02T19:40:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElastiCrank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticrank/32/673_2.png) [@ElastiCrank](https://discuss.elastic.co/u/ElastiCrank)\
**Post date:** [June 2, 2016, 7:40pm UTC](https://discuss.elastic.co/t/how-can-i-get-data-from-filebeat-to-flume/51734/1 "2016-06-02T19:40:08Z")

</div>

I can't see a simple way to get data from Filebeat into Flume. Any ideas? Maybe due to Filebeat's youth, there just aren't very many generic ways (HTTP, TCP) to get data out of Filebeat?

Filebeat looks like a rare combination of . . .

1. Able to read events recorded in log files while Filebeat wasn't running

2. Compiled or Java

3. Actively developed

Those qualities made me think it would be a good fit for my go-to log file collector for a new system I'm designing.

The main requirement that seems to eliminate so many log collectors is the ability to "catch up" and read all logged events even if they were recorded while the log collector is offline. Due to audit requirements, this system can't miss events due to network connection problems or any other reason; all logged events must be persisted in long-term storage. I'm trying to find a log collector that will do so and therefore avoid having to monkey with how each and every system, app, OS manages log file rotation, etc.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 6, 2016, 10:27am UTC](https://discuss.elastic.co/t/how-can-i-get-data-from-filebeat-to-flume/51734/2 "2016-06-06T10:27:35Z")

</div>

Checking the default source types supported by flume, the spool or kafka source might help getting the logs.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 6, 2016, 12:25pm UTC](https://discuss.elastic.co/t/how-can-i-get-data-from-filebeat-to-flume/51734/3 "2016-06-06T12:25:14Z")

</div>

@ElasticCrank Perhaps you can use Logstash as a middle man as LS has many more outputs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2016, 7:40pm UTC](https://discuss.elastic.co/t/how-can-i-get-data-from-filebeat-to-flume/51734/4 "2016-06-23T19:40:09Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
