# Kibana info different when sending to ES directly or with logstash

**URL:** <https://discuss.elastic.co/t/kibana-info-different-when-sending-to-es-directly-or-with-logstash/106831>\
**Category:** Logstash\
**Created:** [November 8, 2017, 9:28am UTC](https://discuss.elastic.co/t/kibana-info-different-when-sending-to-es-directly-or-with-logstash/106831 "2017-11-08T09:28:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Timshs](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@Timshs](https://discuss.elastic.co/u/Timshs)\
**Post date:** [November 8, 2017, 9:28am UTC](https://discuss.elastic.co/t/kibana-info-different-when-sending-to-es-directly-or-with-logstash/106831/1 "2017-11-08T09:28:09Z")

</div>

Hi  
For some time I have use Serilog =\> ES =\> Kibana ... and all is good.  
But if I use Logstash like Serilog =\> Logstash =\> ES = Kibana I do not get the same output:

ELASTICSEARCH:  
add key="serilog:using" value="Serilog.Sinks.Elasticsearch"  
add key="serilog:write-to:Elasticsearch.nodeUris" value="[http://10.0.0.7:9200](http://10.0.0.7:9200)"  
add key="serilog:write-to:Elasticsearch.templateName" value="myCustomTemplate"  
add key="serilog:write-to:Elasticsearch.batchPostingLimit" value="50"  
add key="serilog:write-to:Elasticsearch.bufferBaseFilename" value="SerilogElasticBuffer"  
add key="serilog:write-to:Elasticsearch.bufferFileSizeLimitBytes" value="5242880"  
add key="serilog:write-to:Elasticsearch.bufferLogShippingInterval" value="5000"  
Kibana:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55b6adb8cf23f31697add66369b9868957a72812.png)

LOGSTASH:  
add key="serilog:using" value="Serilog.Sinks.Http"  
add key="serilog:write-to:Http.requestUri" value="[http://xx.xxx.xx.xx:5043](http://xx.xxx.xx.xx:5043)"  
add key="serilog:write-to:Http.indexFormat" value="Logstash-{0:yyyy.MM}"  
add key="serilog:write-to:Http.AutoRegisterTemplate" value="True"  
add key="serilog:write-to:Http.TypeName" value="logevent"  
Kibana:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0e0bd906c5f8cfc1e72e644a2d8650cdf03a6957.png)

Logstash.conf  
input {  
tcp {  
port =\> 5043  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

Where did I go wrong with logstash ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2017, 9:28am UTC](https://discuss.elastic.co/t/kibana-info-different-when-sending-to-es-directly-or-with-logstash/106831/2 "2017-12-06T09:28:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
