# How to forward index from filebeat to elasticsearch via logstash

**URL:** https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash/38722
**Category:** Beats
**Tags:** filebeat
**Created:** [January 8, 2016, 12:52pm UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash/38722 "2016-01-08T12:52:54Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)
#### Post date: [January 8, 2016, 12:52pm UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash/38722/1 "2016-01-08T12:52:54Z")

</div>

Hello,

I have this script for filebeat which sends all logs to logstash:

```
filebeat:
  prospectors:
      paths:
       - D:\Logs\*
      input_type: log
  registry_file: "D:/ElasticSearch/filebeat-1.0.0-windows/registry"

  ### Elasticsearch as output
  #=elasticsearch:
    #=hosts: ["localhost:9200"]
    #=username: "admin2"
    #=password: "admin2"
    #=index: "dev"
	
  logstash:
    hosts: ["localhost:9202]
	#also I had tryed with dev with double quote
    index: dev
  console:
    pretty: true
	
shipper:  
logging:
  files:
    path: D:/ElasticSearch/filebeat-1.0.0-windows/Log
    rotateeverybytes: 10485760 # = 10MB

```

This is my script for logstash which forward message received from filebeat to elasticsearch:

```
input {
		
		beats {
		codec => "json"
		port => 9202
	}
}

output {
	stdout { codec => rubydebug }
	elasticsearch { 
		hosts => ["localhost:9200"] 
		user => "admin2"
		password => "admin2"
	}
}

```

I had followed this explanations: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration-details.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration-details.html) but durring this flow I had lost the original index which was setup into filebeat "dev" and instead, my new index is logstash-yy.mm.dd. And I have no idea if the issue is from filebeat or logstash.

When I had tested filebeat directly with elasticsearch the index was correct.

Do you have any idea what I have done wrong?

Thank you!  
Ovidiu

---

<div class="post-metadata">

### Author: ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)
#### Post date: [January 8, 2016, 1:42pm UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash/38722/2 "2016-01-08T13:42:42Z")

</div>

I think in the `elasticsearch` output in the Logstash config, you also need to add this:

```
index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"

```

This is needed because when you set the value of `index` in the Filebeat configuration, that value is passed to Logstash from Filebeat via the `@metadata.beat` JSON field. See [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration-details.html#logstash-output](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration-details.html#logstash-output) for more details.

---

<div class="post-metadata">

### Author: ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)
#### Post date: [January 11, 2016, 8:26am UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash/38722/3 "2016-01-11T08:26:18Z")

</div>

Yes, you're right! It's working.

Thank you!  
Ovidiu

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:56pm UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash/38722/4 "2017-07-05T21:56:54Z")

</div>


