# How to configure Filebeat.yml to listen logs via TCP

**URL:** <https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 3, 2019, 6:15am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475 "2019-05-03T06:15:46Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![maran2karan](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@maran2karan](https://discuss.elastic.co/u/maran2karan)\
**Post date:** [May 3, 2019, 6:15am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/1 "2019-05-03T06:15:46Z")

</div>

Hello,

I have configured the Logstash to listen logs from application via TCP using logback. the Same i have to do for filebeat where filebeat should listen the logs via TCP and send to logstash.  
Could anyone help on this?  
Posted below the configuration which i made for logstash to listen logs from TCP from application via TCP.

Logback(in application):

\<?xml version="1.0" encoding="UTF-8"?\> 127.0.0.1:4560 

Logstah.yml

input {

tcp {  
port =\> 4560  
}

}

filter {  
date {  
match =\> ["timeMillis", "UNIX\_MS"]  
}  
}

output{  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "app-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"

}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [May 3, 2019, 6:19am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/2 "2019-05-03T06:19:47Z")

</div>

Why do you want filebeat to listen for TCP? Filebeat is used to read files and send them to elasticsearch or logstash or somewhere else. There are lots of blogs on using filebeat to read files and send them. Just do a quick Google search for it.

---

<div class="post-metadata">

**Author:** ![maran2karan](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@maran2karan](https://discuss.elastic.co/u/maran2karan)\
**Post date:** [May 3, 2019, 6:23am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/3 "2019-05-03T06:23:46Z")

</div>

Thanks for an quick reply. If we specify the path in file beat configuration its works.  
Am new to ELK, may be my question was wrong. Ok here, let me tell you that , I do not want to specify the path as static, i need to collect logs from multiple server dynamically and sends to logstash. Do you have any idea on this?

My scenario,

I have Multiple server name it server-1, 2, 3, 4 ...

In server-1 I have installed the ELK and filebeat. And remaining server which is server-2,3,4.. where my application runs and generating logs. So now i need to collect all these logs from server-2,3,4.. via server-1 filebeat configuration and send to logstash. Could anyone give a ideas on it how to implement.

Thanks!

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [May 4, 2019, 7:29am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/4 "2019-05-04T07:29:20Z")

</div>

Why via server 1? You need to install filebeat or logstash on every node you want to collect logs from. Or use syslog if that is an option, to forward to a logstash node. Have you read any of the blogs on log management using ELK?

---

<div class="post-metadata">

**Author:** ![maran2karan](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@maran2karan](https://discuss.elastic.co/u/maran2karan)\
**Post date:** [May 6, 2019, 8:19am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/5 "2019-05-06T08:19:53Z")

</div>

Sorry for delay.  
Yes I red about it. but everyone saying that need to specify the log filr path in filebeat configuration, But that's not needed for me. is there any other way ? Or if you have any blog link about kindly share it .Thanks.

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [May 6, 2019, 4:09pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/6 "2019-05-06T16:09:37Z")

</div>

Its not needed for you?? How else is filebeat to know which files to forward???

---

<div class="post-metadata">

**Author:** ![maran2karan](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@maran2karan](https://discuss.elastic.co/u/maran2karan)\
**Post date:** [May 7, 2019, 6:18am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/7 "2019-05-07T06:18:16Z")

</div>

okay. Please gimme a solution for my above scenario. If possible post a sample configuration for logstash ans filebeat.

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [May 7, 2019, 8:58pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/8 "2019-05-07T20:58:26Z")

</div>

You just said it worked when you configured the path. So then do that on all the nodes.

---

<div class="post-metadata">

**Author:** ![maran2karan](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@maran2karan](https://discuss.elastic.co/u/maran2karan)\
**Post date:** [May 8, 2019, 5:28am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/9 "2019-05-08T05:28:36Z")

</div>

That's what i said that i don't want to specify a path. Do we have alternative any like TCP?

I don't want to specify a location of file man. See , if we are in localhost. ok. we can see the file location and we can specify. suppose for an example when we change the location of log file , we need to change the filebeat or logstash config file to update the path every time. In prod env we can't go each n every time to update the path of file in case of changing the file location frequently. Do you have any better solution for this?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 8, 2019, 5:43am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/10 "2019-05-08T05:43:30Z")

</div>

In recent versions, 6.3 onwards if I recall correctly, [Filebeat supports a TCP input](https://www.elastic.co/guide/en/beats/filebeat/7.0/filebeat-input-tcp.html) which I guess you could use.

---

<div class="post-metadata">

**Author:** ![maran2karan](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@maran2karan](https://discuss.elastic.co/u/maran2karan)\
**Post date:** [May 8, 2019, 5:44am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/11 "2019-05-08T05:44:40Z")

</div>

HI,  
Do you have sample config for that? If so could you please post here. Thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 8, 2019, 5:45am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/12 "2019-05-08T05:45:09Z")

</div>

Have a look at the docs. I have myself never used it.

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [May 8, 2019, 8:44pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/13 "2019-05-08T20:44:50Z")

</div>

So you cannot configure path, but having to change the application to log to a tcp recipient is OK? If so why not let the app send the logs straight to a logstash server?

---

<div class="post-metadata">

**Author:** ![maran2karan](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@maran2karan](https://discuss.elastic.co/u/maran2karan)\
**Post date:** [May 9, 2019, 5:30am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/14 "2019-05-09T05:30:35Z")

</div>

HI

I have configured filebeat to listen logs via TCP. Thanks.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 9, 2019, 5:43am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/15 "2019-05-09T05:43:53Z")

</div>

One potential issue to be aware of when logging via TCP from an application is that any back-pressure applied through the pipeline could cause Filebeat/Logstash to stop reading, which could in turn have an impact on the application itself.

---

<div class="post-metadata">

**Author:** ![maran2karan](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@maran2karan](https://discuss.elastic.co/u/maran2karan)\
**Post date:** [May 9, 2019, 5:46am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/16 "2019-05-09T05:46:15Z")

</div>

ohh. . Then what we can do for this kind of problem?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 9, 2019, 5:50am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/17 "2019-05-09T05:50:28Z")

</div>

You can [configure Filebeat to spool data to disk](https://www.elastic.co/guide/en/beats/filebeat/7.0/configuring-internal-queue.html), which can handle temporary problems and provide less risk of affecting the application.

---

<div class="post-metadata">

**Author:** ![maran2karan](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@maran2karan](https://discuss.elastic.co/u/maran2karan)\
**Post date:** [May 9, 2019, 6:46am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/18 "2019-05-09T06:46:22Z")

</div>

ok. Let me give a try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2019, 6:46am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475/19 "2019-06-06T06:46:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
