# How can I send logs to elasticsearch

**URL:** <https://discuss.elastic.co/t/how-can-i-send-logs-to-elasticsearch/134059>\
**Category:** Logstash\
**Created:** [May 31, 2018, 1:18pm UTC](https://discuss.elastic.co/t/how-can-i-send-logs-to-elasticsearch/134059 "2018-05-31T13:18:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fabrice.tagne](https://avatars.discourse-cdn.com/v4/letter/f/9de053/32.png) [@fabrice.tagne](https://discuss.elastic.co/u/fabrice.tagne)\
**Post date:** [May 31, 2018, 1:18pm UTC](https://discuss.elastic.co/t/how-can-i-send-logs-to-elasticsearch/134059/1 "2018-05-31T13:18:33Z")

</div>

`Logstash configuration` is in /etc/logstash/logstash.yml the rest in **default**

```auto
# ------------ Metrics Settings --------------
#
# Bind address for the metrics REST endpoint
#
http.host: "127.0.0.1"
#
# Bind port for the metrics REST endpoint, this option also accept a range
# (9600-9700) and logstash will pick up the first available ports.
#
# http.port: 9600-9700
#
# ------------ Debugging Settings --------------
#
# Options for log.level:
# * fatal
# * error
# * warn
# * info (default)
# * debug
# * trace
#
log.level: info
path.logs: /var/log/logstash
#

```

`modules.d configuration`is in `/etc/logstash/conf.d/01-local-dev.conf`

```auto
input {
    file { path => "/var/log/syslog" }
}
output {
stdout { codec => rubydebug }
    elasticsearch {
         hosts => "localhost:9200"
    }
}

```

`Elasticsearch configuration` in /etc/elasticsearch/elasticsearch.yml

```auto
# ---------------------------------- Paths -----------------------------------
#
# Path to directory where to store the data (separate multiple locations by comma):
#
path.data: /var/lib/elasticsearch
#
# Path to log files:
#
path.logs: /var/log/elasticsearch
#
# ----------------------------------- Memory -----------------------------------
#
# Lock the memory on startup:
#
#bootstrap.memory_lock: true
#
# Make sure that the heap size is set to about half the memory available
# on the system and that the owner of the process is allowed to use this
# limit.
#
# Elasticsearch performs poorly when the system is swapping the memory.
#
# ---------------------------------- Network -----------------------------------
#
# Set the bind address to a specific IP (IPv4 or IPv6):
#
network.host: localhost
#
# Set a custom port for HTTP:
#
http.port: 9200
#
# For more information, consult the network module documentation.
#

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 31, 2018, 1:44pm UTC](https://discuss.elastic.co/t/how-can-i-send-logs-to-elasticsearch/134059/2 "2018-05-31T13:44:55Z")

</div>

That configuration looks okay, but keep in mind that with that configuration of the file input it'll only tail the input file (i.e. pick up new lines).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2018, 1:45pm UTC](https://discuss.elastic.co/t/how-can-i-send-logs-to-elasticsearch/134059/3 "2018-06-28T13:45:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
