# How to forward logs from a logstash “agent” to “master”

**URL:** <https://discuss.elastic.co/t/how-to-forward-logs-from-a-logstash-agent-to-master/35639>\
**Category:** Beats\
**Created:** [November 26, 2015, 7:44am UTC](https://discuss.elastic.co/t/how-to-forward-logs-from-a-logstash-agent-to-master/35639 "2015-11-26T07:44:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael\_Bulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_bulla/32/6185_2.png) [@Michael\_Bulla](https://discuss.elastic.co/u/Michael_Bulla)\
**Post date:** [November 26, 2015, 7:44am UTC](https://discuss.elastic.co/t/how-to-forward-logs-from-a-logstash-agent-to-master/35639/1 "2015-11-26T07:44:20Z")

</div>

Until now my ELK setup looks like this

`Logstash Forwarder -> Logstash 1.4 -> Elstatic Search`

Now I want to replace the Forwarder by a full blown Logstash, so I  
can collect data from more inputs than just files and can get rid of the  
lumberjack protocol with its need to secure communication (which made  
always trouble). I also switched to Logstash 2.0.0 and have now the  
following setup

`Logstash 2.0.0 -> Logstash 2.0.0 -> Elastic Search`

I hoped I could use not secured filebeat protocol between the first  
logstash instance and the second, but I don't see any (File)beat output  
for logstash. For now I'm using http, but this seems to be far to slow.

Is there a way to use Filebeat between 2 full blown logstash  
instances, or what would be a appropriate way to let them communicate  
without the need to install more infrastructure like messaging providers  
or things like that?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 26, 2015, 7:58am UTC](https://discuss.elastic.co/t/how-to-forward-logs-from-a-logstash-agent-to-master/35639/2 "2015-11-26T07:58:47Z")

</div>

Have you tried using the [TCP Input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.html) and [TCP Output](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.htmlhttps://www.elastic.co/guide/en/logstash/current/plugins-outputs-tcp.html) plugins?

---

<div class="post-metadata">

**Author:** ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)\
**Post date:** [November 26, 2015, 10:29am UTC](https://discuss.elastic.co/t/how-to-forward-logs-from-a-logstash-agent-to-master/35639/3 "2015-11-26T10:29:25Z")

</div>

The idea behind Filebeat is that it's a lightweight shipper that you install as an agent on your servers to collect data from all your servers and send it to a central Logstash to enrich, parse and transport data. So, the flow would be: Filebeat -\> Logstash 2.1.0 -\> Elasticsearch.

Excepting files, what data would you like to collect? Maybe other Beat can help you here 🙂

Edit: To answer your question, Logstash has a beats-input plugin, but now a beats-output plugin yet. It might get one in the future. Until then, you could use tcp input & tcp output.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 26, 2015, 10:50am UTC](https://discuss.elastic.co/t/how-to-forward-logs-from-a-logstash-agent-to-master/35639/4 "2015-11-26T10:50:47Z")

</div>

TCP output / input should work. As an alternative to have encryption and compression you can use lumberjack input / output: [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-lumberjack.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-lumberjack.html)

---

<div class="post-metadata">

**Author:** ![Michael\_Bulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_bulla/32/6185_2.png) [@Michael\_Bulla](https://discuss.elastic.co/u/Michael_Bulla)\
**Post date:** [November 26, 2015, 11:02am UTC](https://discuss.elastic.co/t/how-to-forward-logs-from-a-logstash-agent-to-master/35639/5 "2015-11-26T11:02:12Z")

</div>

At least in future I will need to connect to JMX beans.  
Since we are monitoring large java server applications small footprint is not a requirement, there is enough memory in thats servers. Flexibility is the more important requirement.

---

<div class="post-metadata">

**Author:** ![Michael\_Bulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_bulla/32/6185_2.png) [@Michael\_Bulla](https://discuss.elastic.co/u/Michael_Bulla)\
**Post date:** [November 26, 2015, 11:04am UTC](https://discuss.elastic.co/t/how-to-forward-logs-from-a-logstash-agent-to-master/35639/6 "2015-11-26T11:04:26Z")

</div>

TCP, reasonable! Could have come myself to that 😀

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 26, 2015, 11:47am UTC](https://discuss.elastic.co/t/how-to-forward-logs-from-a-logstash-agent-to-master/35639/7 "2015-11-26T11:47:31Z")

</div>

@Michael_Bulla Based on this I also created the following issue which could be interesting in the future: [https://github.com/elastic/logstash/issues/4282](https://github.com/elastic/logstash/issues/4282)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:57pm UTC](https://discuss.elastic.co/t/how-to-forward-logs-from-a-logstash-agent-to-master/35639/8 "2017-07-05T21:57:57Z")

</div>


