# How can receive log in elastic siem using logstash

**URL:** <https://discuss.elastic.co/t/how-can-receive-log-in-elastic-siem-using-logstash/248258>\
**Category:** Elastic Security\
**Created:** [September 11, 2020, 3:42am UTC](https://discuss.elastic.co/t/how-can-receive-log-in-elastic-siem-using-logstash/248258 "2020-09-11T03:42:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![111387](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111387/32/75408_2.png) [@111387](https://discuss.elastic.co/u/111387)\
**Post date:** [September 11, 2020, 3:42am UTC](https://discuss.elastic.co/t/how-can-receive-log-in-elastic-siem-using-logstash/248258/1 "2020-09-11T03:42:32Z")

</div>

I installed suricata, and i want using elastic siem  
so. i installed filebeat and send to elastic search and kibana

i well. but i want to using logstash.

i try that filebeat send log to logstash and logstash pass to elasticsearch.

i can see suricata log in kibana but elastic siem not display log.

elastic siem only using filebeat????  
i want to using logstash or redis between filebeat and elastic siem

---

<div class="post-metadata">

**Author:** ![Andrew\_G](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_g/32/49178_2.png) [@Andrew\_G](https://discuss.elastic.co/u/Andrew_G)\
**Post date:** [September 11, 2020, 9:14pm UTC](https://discuss.elastic.co/t/how-can-receive-log-in-elastic-siem-using-logstash/248258/2 "2020-09-11T21:14:13Z")

</div>

Welcome @111387!

The Filebeat [Suricata module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-suricata.html) parses Suricata logs, which are mapped to events modeled by the Elastic Common Schema (ECS). [This blog post](https://www.elastic.co/blog/introducing-the-elastic-common-schema) explains how ECS works, and why it exists.

> i want to using logstash or redis between filebeat and elastic siem

It sounds like [this might be the documentation you're looking for](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html), if, to quote the linked documentation:

> you want to use Logstash to perform additional processing on the data collected by Filebeat

Would you be willing to let us know if that helps?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:12am UTC](https://discuss.elastic.co/t/how-can-receive-log-in-elastic-siem-using-logstash/248258/3 "2022-11-04T08:12:56Z")

</div>


