# How to check whether logsash is parsing data from a filebeat

**URL:** <https://discuss.elastic.co/t/how-to-check-whether-logsash-is-parsing-data-from-a-filebeat/144424>\
**Category:** Logstash\
**Created:** [August 14, 2018, 10:53pm UTC](https://discuss.elastic.co/t/how-to-check-whether-logsash-is-parsing-data-from-a-filebeat/144424 "2018-08-14T22:53:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![iamlearner123](https://avatars.discourse-cdn.com/v4/letter/i/bcef8e/32.png) [@iamlearner123](https://discuss.elastic.co/u/iamlearner123)\
**Post date:** [August 14, 2018, 10:53pm UTC](https://discuss.elastic.co/t/how-to-check-whether-logsash-is-parsing-data-from-a-filebeat/144424/1 "2018-08-14T22:53:35Z")

</div>

Hi,

Is there a way to know whether the log stash is parsing data from a particular filebeat or not. I am sending the data from file beat to logstash and there were configuration errors in logstash but i couldn't see the index getting created in elasticsearch. In order troubleshoot, i am trying to understand whether the logstash is parsing data or not .

Thanks

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [August 15, 2018, 4:52am UTC](https://discuss.elastic.co/t/how-to-check-whether-logsash-is-parsing-data-from-a-filebeat/144424/2 "2018-08-15T04:52:52Z")

</div>

You could use the stdout filter in Logstash to see if events are getting parsed. If there are config errors, Logstash will not index data to Elasticsearch.

You could refer to the Logstash logs for any errors.

---

<div class="post-metadata">

**Author:** ![iamlearner123](https://avatars.discourse-cdn.com/v4/letter/i/bcef8e/32.png) [@iamlearner123](https://discuss.elastic.co/u/iamlearner123)\
**Post date:** [August 15, 2018, 9:30pm UTC](https://discuss.elastic.co/t/how-to-check-whether-logsash-is-parsing-data-from-a-filebeat/144424/3 "2018-08-15T21:30:39Z")

</div>

Thank you for the reply ... but when I configure the filebeat with only one log file, I could see that data is getting indexed in elastic search.

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [August 16, 2018, 1:18am UTC](https://discuss.elastic.co/t/how-to-check-whether-logsash-is-parsing-data-from-a-filebeat/144424/4 "2018-08-16T01:18:16Z")

</div>

Could you please post your logstash and filebeat config?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2018, 1:18am UTC](https://discuss.elastic.co/t/how-to-check-whether-logsash-is-parsing-data-from-a-filebeat/144424/5 "2018-09-13T01:18:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
