# How can I make logstash automatically send my information to elasticsearch?

**URL:** <https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447>\
**Category:** Elasticsearch\
**Created:** [April 5, 2023, 2:51pm UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447 "2023-04-05T14:51:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raul\_dum](https://avatars.discourse-cdn.com/v4/letter/r/8e8cbc/32.png) [@Raul\_dum](https://discuss.elastic.co/u/Raul_dum)\
**Post date:** [April 5, 2023, 2:51pm UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447/1 "2023-04-05T14:51:28Z")

</div>

Hi

I was wondering if there is a method on how I could make logstash automatically send information to my elasticsearch.I have my config file :

```auto
input {
  stdin {}
}

filter {
  grok {
    match => { "message" => "time=%{TIMESTAMP_ISO8601:time} url=%{URIPATH:url} clientIp=%{IP:clientIp} useragent=\"%{DATA:useragent}\" message=\"%{GREEDYDATA:message}\"" }
  }
  date {
    match => ["time", "ISO8601"]
  }
  json {
    source => "message"
  }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "indexforlogstash"
  }
  stdout {}
}

```

Can I add anything more in my config file so that logstash automatically sends my logs to elasticsearch so I don't have to send them manually every time through command prompt?  
Or is there any other way to solve this problem?The point is I don't want to have to add my log files manually everytime,i want to automate this proccess if possible.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 5, 2023, 4:33pm UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447/2 "2023-04-05T16:33:32Z")

</div>

You need to use a different input for the data. Have a look at the [file input plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html) and use this to have Logstash follow and ingest files in the file system.

---

<div class="post-metadata">

**Author:** ![Raul\_dum](https://avatars.discourse-cdn.com/v4/letter/r/8e8cbc/32.png) [@Raul\_dum](https://discuss.elastic.co/u/Raul_dum)\
**Post date:** [April 7, 2023, 3:51pm UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447/3 "2023-04-07T15:51:54Z")

</div>

Like,could you give me an example please?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 7, 2023, 4:47pm UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447/4 "2023-04-07T16:47:52Z")

</div>

Have a look at [this old blog post](https://www.elastic.co/blog/a-practical-introduction-to-logstash). You can set the `path` parameter to a directory or pattern and have Logstash pick up new files matching this.

If you can provide some more details about the files you are looking to read (format, location and how they are created) it may be easier to help with an example.

---

<div class="post-metadata">

**Author:** ![Raul\_dum](https://avatars.discourse-cdn.com/v4/letter/r/8e8cbc/32.png) [@Raul\_dum](https://discuss.elastic.co/u/Raul_dum)\
**Post date:** [April 9, 2023, 10:17am UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447/5 "2023-04-09T10:17:05Z")

</div>

I'm trying to make logstash pick "error.log" file located at "C:\ELK Stack" which is written in JSON,this is what it looks like

```auto
{ "time": "2023-03-08 17:20:25.3306", "machinename": "RO-ROMOCEAT", "url": " https://london.cylex-uk.co.uk/GB/cylex-uk.co.uk/london/company/test-linda-18856944.html", "clientIp": "127.0.0.1", "useragent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/110.0", "message": "\"GetGeoByIdAsync\" | geoId: {\"CountryCode\":\"GB\", \"Identity\":20417, \"Language\":\"en-GB\"}", "ex": "System.NotImplementedException: The method or operation is not implemented.\r\n at CylexBDDataAccessLayer.MongoDBAccess.GetGeoByIdAsync(GeoId geoId) in D:\\Projects\\CylexBDForSyncronizing\\CylexBDDataAccessLayer\\Mongo\\GeosDbAccessPartial.cs:line 45" }

```

---

<div class="post-metadata">

**Author:** ![Raul\_dum](https://avatars.discourse-cdn.com/v4/letter/r/8e8cbc/32.png) [@Raul\_dum](https://discuss.elastic.co/u/Raul_dum)\
**Post date:** [April 10, 2023, 7:38am UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447/6 "2023-04-10T07:38:20Z")

</div>

I tried it even with this config file :

```auto
input {
  file {
    path => "C:/ELK Stack"
    start_position => "beginning"
    sincedb_path => "nul"
  }
}

filter {
  grok {
    match => { "message" => "time=%{TIMESTAMP_ISO8601:time} url=%{URIPATH:url} clientIp=%{IP:clientIp} useragent=\"%{DATA:useragent}\" message=\"%{GREEDYDATA:message}\"" }
  }
  date {
    match => ["time", "ISO8601"]
  }
  json {
    source => "message"
  }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "logs"
  }
}

```

And it still doesn't work.  
On Windows 10 Pro 64-bit btw 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2023, 7:38am UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447/7 "2023-05-08T07:38:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
