# How to specified the target location to store the log file

**URL:** <https://discuss.elastic.co/t/how-to-specified-the-target-location-to-store-the-log-file/42831>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 26, 2016, 9:20am UTC](https://discuss.elastic.co/t/how-to-specified-the-target-location-to-store-the-log-file/42831 "2016-02-26T09:20:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![wangxiangbill](https://avatars.discourse-cdn.com/v4/letter/w/ecccb3/32.png) [@wangxiangbill](https://discuss.elastic.co/u/wangxiangbill)\
**Post date:** [February 26, 2016, 9:20am UTC](https://discuss.elastic.co/t/how-to-specified-the-target-location-to-store-the-log-file/42831/1 "2016-02-26T09:20:40Z")

</div>

Hi

I installed the ELK with filebeat few days ago.

I follow up with the blog [https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-04#set-up-filebeat(add-client-servers)](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-04#set-up-filebeat(add-client-servers))

My question is when the logstash server received the log info from the filebeat agent, where the info would be stored?

If i want transfer some logs from some filebeat agent hosts to a specified folder in the logstash server, how can i config it?

Thanks for all your help.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 26, 2016, 9:35am UTC](https://discuss.elastic.co/t/how-to-specified-the-target-location-to-store-the-log-file/42831/2 "2016-02-26T09:35:36Z")

</div>

> My question is when the logstash server received the log info from the filebeat agent, where the info would be stored?

I don't know, where do you _want_ things stored? If you send events to Elasticsearch, isn't that enough?

> If i want transfer some logs from some filebeat agent hosts to a specified folder in the logstash server, how can i config it?

Use a file output and set its `path` option to the desired destination path. I believe Filebeat creates a field with the path of the source file. But why?

---

<div class="post-metadata">

**Author:** ![wangxiangbill](https://avatars.discourse-cdn.com/v4/letter/w/ecccb3/32.png) [@wangxiangbill](https://discuss.elastic.co/u/wangxiangbill)\
**Post date:** [February 26, 2016, 9:58am UTC](https://discuss.elastic.co/t/how-to-specified-the-target-location-to-store-the-log-file/42831/3 "2016-02-26T09:58:20Z")

</div>

Hi brother,

Thanks to got your reply.

Sorry for my strange question, because i am just a newbie of the logstash.

1)If the log info send events to Elasticsearch, then where the info it stored?

2)For some security issue, my team want to store the log to the nfs file system. So we have to specified the folder.  
If i want to transfer the log file /var/log/logtest to the path /var/log/filebeat of logstash host, how can i config it.

Here is my filebeat config of my agent host.

############################# Filebeat ######################################  
filebeat:

# List of prospectors to fetch data.

## prospectors: # Each - is a prospector. Below are the prospector specific configurations

paths:  
- /var/log/auth.log  
- /var/log/syslog  
document\_type: syslog  
-  
paths:  
- /var/log/testlog  
input\_type: log  
document\_type: logtest

output:  
logstash:  
# The Logstash hosts  
hosts: ["10.0.0.4:5044"]  
bulk\_max\_size: 1024  
# Optional TLS. By default is off.  
tls:  
# List of root certificates for HTTPS server verifications  
certificate\_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

### File as output

file:  
# Path to the directory where to save the generated files. The option is mandatory.  
#path: "/tmp/filebeat"  
path: "/var/log/filebeat"  
filename: filebeat

shipper:

logging:  
files:

```
rotateeverybytes: 10485760 # = 10MB
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 26, 2016, 2:30pm UTC](https://discuss.elastic.co/t/how-to-specified-the-target-location-to-store-the-log-file/42831/4 "2016-02-26T14:30:52Z")

</div>

> 1)If the log info send events to Elasticsearch, then where the info it stored?

In Elasticsearch's database.

> If i want to transfer the log file /var/log/logtest to the path /var/log/filebeat of logstash host, how can i config it.

Use the following in your Logstash configuration:

```auto
output {
  file {
    path => "/var/log/filebeat"
  }
}

```

---

<div class="post-metadata">

**Author:** ![wangxiangbill](https://avatars.discourse-cdn.com/v4/letter/w/ecccb3/32.png) [@wangxiangbill](https://discuss.elastic.co/u/wangxiangbill)\
**Post date:** [March 7, 2016, 3:18am UTC](https://discuss.elastic.co/t/how-to-specified-the-target-location-to-store-the-log-file/42831/5 "2016-03-07T03:18:20Z")

</div>

Sorry for late response.

I will try it and hope it will work.

Thanks a for your help.

---

<div class="post-metadata">

**Author:** ![wangxiangbill](https://avatars.discourse-cdn.com/v4/letter/w/ecccb3/32.png) [@wangxiangbill](https://discuss.elastic.co/u/wangxiangbill)\
**Post date:** [March 7, 2016, 6:35am UTC](https://discuss.elastic.co/t/how-to-specified-the-target-location-to-store-the-log-file/42831/6 "2016-03-07T06:35:31Z")

</div>

Hi,

I have update my config file

output {  
if [type] == 'syslog'{  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
path =\> "/var/log/filebeat"  
}  
}  
}

And both the logstash service of the server host and the filebeat service of the client host were restarted.

But when i check the folder of the logstash server, there is no any files were transferred to it.

azureuser@logstashsrv:/var/log/filebeat$ ll  
total 8  
drwxr-xr-x 2 root root 4096 Feb 26 03:46 ./  
drwxrwxr-x 16 root syslog 4096 Mar 7 06:32 ../

I am not sure whether i should update some entries of the filebeat config file of the clinet host?

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2016, 7:09am UTC](https://discuss.elastic.co/t/how-to-specified-the-target-location-to-store-the-log-file/42831/7 "2016-03-07T07:09:37Z")

</div>

No, `path => "/var/log/filebeat"` goes in a separate plugin instance. I realize that made a typo in my last post. I've corrected it now. To be clear, you need this:

```auto
output {
  elasticsearch {
     ...
  }
  file {
    path => "/var/log/filebeat"
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:54pm UTC](https://discuss.elastic.co/t/how-to-specified-the-target-location-to-store-the-log-file/42831/8 "2017-07-05T21:54:53Z")

</div>


