# Is it possible to forward logs from elasticsearch to qradar

**URL:** <https://discuss.elastic.co/t/is-it-possible-to-forward-logs-from-elasticsearch-to-qradar/362769>\
**Category:** Elasticsearch\
**Created:** [July 9, 2024, 7:56am UTC](https://discuss.elastic.co/t/is-it-possible-to-forward-logs-from-elasticsearch-to-qradar/362769 "2024-07-09T07:56:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![yar](https://avatars.discourse-cdn.com/v4/letter/y/858c86/32.png) [@yar](https://discuss.elastic.co/u/yar)\
**Post date:** [July 9, 2024, 7:56am UTC](https://discuss.elastic.co/t/is-it-possible-to-forward-logs-from-elasticsearch-to-qradar/362769/1 "2024-07-09T07:56:57Z")

</div>

Hi,

I have deployed ELK stack into a couple of VMs. The logs are gathered using fleet agents, and they're being sent into elastic. Is there a way to forward the logs from Elasticsearch to Qradar on-prem deployment? Or should I look into reading the logs from Elasticsearch using Qradar?

At this point I have not tried anything, just looked through various community posts. I expect to forward logs from Elasticsearch to Qradar, or to read logs from Elasticsearch using Qradar.

---

<div class="post-metadata">

**Author:** ![yar](https://avatars.discourse-cdn.com/v4/letter/y/858c86/32.png) [@yar](https://discuss.elastic.co/u/yar)\
**Post date:** [July 10, 2024, 1:11pm UTC](https://discuss.elastic.co/t/is-it-possible-to-forward-logs-from-elasticsearch-to-qradar/362769/2 "2024-07-10T13:11:26Z")

</div>

Okay, so it's not possible to ingest logs with Qradar from Elasticsearch, nor it's possible to forward them from Elasticsearch to Qradar. However, you can use fleet agents to gather the logs, then send them into logstash, and logstash can send the logs both to elastic and qradar. Note, that this approach is going to require paid license, because fleet agents with basic license don't support any other outputs except elasticsearch.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 10, 2024, 2:37pm UTC](https://discuss.elastic.co/t/is-it-possible-to-forward-logs-from-elasticsearch-to-qradar/362769/3 "2024-07-10T14:37:36Z")

</div>

> [@yar](#):
>
> Okay, so it's not possible to ingest logs with Qradar from Elasticsearch, nor it's possible to forward them from Elasticsearch to Qradar

Where did you get this information? Elasticsearch does not send logs anywhere, but you can use a tool like Logstash to query your Elasticsearch data and send it to other destinations.

> [@yar](#):
>
> Note, that this approach is going to require paid license, because fleet agents with basic license don't support any other outputs except elasticsearch.

Not entirely correct, you can use the basic license and have the fleet agents sending logs to Logstash, Elasticsearch or Kafka.

The limitation you have is that you can not have different outputs per different policies, but you can configure your default output to send logs to kafka, elasticsearch or logstash.

---

<div class="post-metadata">

**Author:** ![yar](https://avatars.discourse-cdn.com/v4/letter/y/858c86/32.png) [@yar](https://discuss.elastic.co/u/yar)\
**Post date:** [July 19, 2024, 7:51am UTC](https://discuss.elastic.co/t/is-it-possible-to-forward-logs-from-elasticsearch-to-qradar/362769/4 "2024-07-19T07:51:40Z")

</div>

> [@leandrojmp](#):
>
> Where did you get this information? Elasticsearch does not send logs anywhere, but you can use a tool like Logstash to query your Elasticsearch data and send it to other destinations.

I did not get this information anywhere. I was just wondering whether it's possible. And I found out that it's not, just as you said:)

> [@leandrojmp](#):
>
> Not entirely correct, you can use the basic license and have the fleet agents sending logs to Logstash, Elasticsearch or Kafka.
> 
> The limitation you have is that you can not have different outputs per different policies, but you can configure your default output to send logs to kafka, elasticsearch or logstash.

That's an important clarification. Thank you for the explanation. Actually that was my case. I wanted to use multiple polices with different outputs.
