# How does Filebeat Redis module work for Slow Logs?

**URL:** <https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 8, 2019, 9:21pm UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028 "2019-12-08T21:21:13Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![dandago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dandago/32/56215_2.png) [@dandago](https://discuss.elastic.co/u/dandago)\
**Post date:** [December 8, 2019, 9:21pm UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/1 "2019-12-08T21:21:13Z")

</div>

The configuration file of the Redis module for Filebeat seems to support normal logs (from the Redis server's log file) and slowlogs (from the API)... see:

> <https://github.com/elastic/beats/blob/master/filebeat/modules.d/redis.yml.disabled>

I can understand how the logs are picked up from the log files, but I had no idea that Filebeat had the capability to issue a command to a server and thus retrieve information. Is there any documentation on how this feature works, and in what format the slowlogs are shipped?

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 9, 2019, 9:34am UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/2 "2019-12-09T09:34:01Z")

</div>

Hi!

You can find the Module's documentation here: [https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-redis.html](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-redis.html)

Thanks!

---

<div class="post-metadata">

**Author:** ![dandago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dandago/32/56215_2.png) [@dandago](https://discuss.elastic.co/u/dandago)\
**Post date:** [December 12, 2019, 11:36pm UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/3 "2019-12-12T23:36:56Z")

</div>

Hi, thanks for the doc link. I understand where Filebeat is getting the slowlogs from, however I was looking for more detail in how this works in Filebeat, given that Filebeat is meant to monitor files. I was also looking for the format/structure in which they are shipped.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 13, 2019, 9:13am UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/4 "2019-12-13T09:13:19Z")

</div>

Hey,

Filebeat can also retrieve "logs" from remote systems like hosts or queues like Kafka, or Amazon S3. The idea is that everything that can be parsed as log line can be parsed by Filebeat.

Regarding the fields you can find the list [here](https://www.elastic.co/guide/en/beats/filebeat/master/exported-fields-redis.html#_slowlog_4).

Thanks!

---

<div class="post-metadata">

**Author:** ![dandago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dandago/32/56215_2.png) [@dandago](https://discuss.elastic.co/u/dandago)\
**Post date:** [December 13, 2019, 9:38am UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/5 "2019-12-13T09:38:14Z")

</div>

Awesome, thanks!

Is it required to use the Redis filebeat module for shipping slowlogs, or can it be configured without it?

I'm looking to ship Redis logs to a third party managed ELK, so it's not possible to set up the pipeline and resources that the module seems to expect.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 13, 2019, 10:04am UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/6 "2019-12-13T10:04:02Z")

</div>

Hmm,

you need a way to collect the logs and send them to the Logstash node of ELK right? If so , yeah you need Filebeat on the node you want to monitor.

---

<div class="post-metadata">

**Author:** ![dandago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dandago/32/56215_2.png) [@dandago](https://discuss.elastic.co/u/dandago)\
**Post date:** [December 13, 2019, 10:16am UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/7 "2019-12-13T10:16:14Z")

</div>

Yes, send them to Logstash node of ELK, that's right. I can use Filebeat to ship Redis logs, but is it also possible to ship the slowlogs without being able to set up the environment (pipeline etc)?

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 13, 2019, 1:04pm UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/8 "2019-12-13T13:04:37Z")

</div>

You can send the events from Filebeat directly to Elasticsearch if you want to by-pass Logstash. I don't see a way to avoid using Filebeat.

Let me know!

---

<div class="post-metadata">

**Author:** ![dandago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dandago/32/56215_2.png) [@dandago](https://discuss.elastic.co/u/dandago)\
**Post date:** [December 13, 2019, 1:23pm UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/9 "2019-12-13T13:23:10Z")

</div>

I'm saying to avoid using the Redis module, not avoid using Filebeat. Filebeat is a must. Logstash is irrelevant.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 13, 2019, 1:25pm UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/10 "2019-12-13T13:25:10Z")

</div>

Got it! In order to get slowlogs you need Redis Module yeah.

---

<div class="post-metadata">

**Author:** ![dandago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dandago/32/56215_2.png) [@dandago](https://discuss.elastic.co/u/dandago)\
**Post date:** [December 13, 2019, 1:48pm UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/11 "2019-12-13T13:48:26Z")

</div>

Great, thanks for clarifying! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2020, 1:48pm UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028/12 "2020-01-10T13:48:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
