# Is there a way to configure filebeat to send certain logs as quick as possible?

**URL:** <https://discuss.elastic.co/t/is-there-a-way-to-configure-filebeat-to-send-certain-logs-as-quick-as-possible/266979>\
**Category:** Logstash\
**Created:** [March 11, 2021, 4:50pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-configure-filebeat-to-send-certain-logs-as-quick-as-possible/266979 "2021-03-11T16:50:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmitryyankowski](https://avatars.discourse-cdn.com/v4/letter/d/c77e96/32.png) [@dmitryyankowski](https://discuss.elastic.co/u/dmitryyankowski)\
**Post date:** [March 11, 2021, 4:50pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-configure-filebeat-to-send-certain-logs-as-quick-as-possible/266979/1 "2021-03-11T16:50:32Z")

</div>

I'm wondering if there is a way to get Filebeat to report specific logs as soon as possible.. rather than waiting for the minimum amount of events to send in a batch.

For example:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d04fbae0ff19bafb089b98c8535934f7290a02fb.png)

I have a security detection setup, to send an alert to my email, whenever there's an SSH login event with an IP address that isn't my own.

However at the moment the Elastic Agent I have installed on the linux server is super slow to report the SSH events. I'm assuming because it waits until there are x filebeat logs .. and then send's them all together in a batch, to logstash?

I'd like for my Elastic Agent to send the SSH auth logs as soon as possible.. rather than waiting a certain amount of time... or before there are x amount of logs.

I want to be able to react to this alert as soon as possible... if that makes sense.

Thanks for the help in advance 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2021, 5:01pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-configure-filebeat-to-send-certain-logs-as-quick-as-possible/266979/2 "2021-03-11T17:01:24Z")

</div>

filebeat uses an in-memory queue which is described [here](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-internal-queue.html). The default is to flush the queue after one second. The [default delay](https://www.elastic.co/guide/en/logstash/current/logstash-settings-file.html) for a batch in logstash is 50 milliseconds.

---

<div class="post-metadata">

**Author:** ![dmitryyankowski](https://avatars.discourse-cdn.com/v4/letter/d/c77e96/32.png) [@dmitryyankowski](https://discuss.elastic.co/u/dmitryyankowski)\
**Post date:** [March 11, 2021, 5:20pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-configure-filebeat-to-send-certain-logs-as-quick-as-possible/266979/3 "2021-03-11T17:20:47Z")

</div>

Thanks for the info @Badger Do you know how I would configure this in the Fleet Agent? 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2021, 5:43pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-configure-filebeat-to-send-certain-logs-as-quick-as-possible/266979/4 "2021-03-11T17:43:45Z")

</div>

I did not even know Fleet existed until I just googled it, so I cannot help you there.

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [March 11, 2021, 6:45pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-configure-filebeat-to-send-certain-logs-as-quick-as-possible/266979/5 "2021-03-11T18:45:02Z")

</div>

Have a look at [Policy settings | Fleet User Guide [7.11] | Elastic](https://www.elastic.co/guide/en/fleet/current/elastic-agent-configuration.html) for all configuration options.

The configuration you are looking for is:  
reporting\_threshold  
and  
reporting\_check\_frequency\_sec

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2021, 6:45pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-configure-filebeat-to-send-certain-logs-as-quick-as-possible/266979/6 "2021-04-08T18:45:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
