# Link problem between ELK and filebeat

**URL:** <https://discuss.elastic.co/t/link-problem-between-elk-and-filebeat/145503>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 22, 2018, 7:28am UTC](https://discuss.elastic.co/t/link-problem-between-elk-and-filebeat/145503 "2018-08-22T07:28:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![raph](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@raph](https://discuss.elastic.co/u/raph)\
**Post date:** [August 22, 2018, 7:28am UTC](https://discuss.elastic.co/t/link-problem-between-elk-and-filebeat/145503/1 "2018-08-22T07:28:44Z")

</div>

hello,  
Filebeats do not send me anything,Do you have an idea of the problem ?  
\<

> ###################### Filebeat Configuration Example #########################
> 
> # This file is an example configuration file highlighting only the most common
> 
> # options. The filebeat.reference.yml file from the same directory contains all the
> 
> # supported options with more comments. You can use it as a reference.
> 
> # 
> 
> # You can find the full configuration reference here:
> 
> # [Filebeat Reference | Elastic](https://www.elastic.co/guide/en/beats/filebeat/index.html)
> 
> # For more available modules and options, please see the filebeat.reference.yml sample
> 
> # configuration file.
> 
> #=========================== Filebeat inputs =============================
> 
> filebeat.inputs:
> 
> # Each - is an input. Most options can be set at the input level, so
> 
> # you can use different inputs for various configurations.
> 
> # Below are the input specific configurations.
> 
> - document\_type: syslog
> 
> # Change to true to enable this input configuration.
> 
> enabled: true
> 
> # Paths that should be crawled and fetched. Glob based paths.
> 
> paths:  
> #- /var/log/secure  
> #- /var/log/messages  
> #- c:\programdata\elasticsearch\logs\*
> 
> - c:\System32\Winevt\Logs\Security.evtx
> 
> # Exclude lines. A list of regular expressions to match. It drops the lines that are
> 
> # matching any regular expression from the list.
> 
> #exclude\_lines: ['^DBG']
> 
> # Include lines. A list of regular expressions to match. It exports the lines that are
> 
> # matching any regular expression from the list.
> 
> include\_lines: ['^ERR', '^WARN', '^INFO']
> 
> # Exclude files. A list of regular expressions to match. Filebeat drops the files that
> 
> # are matching any regular expression from the list. By default, no files are dropped.
> 
> #exclude\_files: ['.gz$']
> 
> # Optional additional fields. These fields can be freely picked
> 
> # to add additional information to the crawled log files for filtering
> 
> #fields:
> 
> # level: debug
> 
> # review: 1
> 
> ### Multiline options
> 
> # Mutiline can be used for log messages spanning multiple lines. This is common
> 
> # for Java Stack Traces or C-Line Continuation
> 
> # The regexp Pattern that has to be matched. The example pattern matches all lines starting with [
> 
> #multiline.pattern: ^[
> 
> # Defines if the pattern set under pattern should be negated or not. Default is false.
> 
> #multiline.negate: false
> 
> # Match can be set to "after" or "before". It is used to define if lines should be append to a pattern
> 
> # that was (not) matched before or after or as long as a pattern is not matched based on negate.
> 
> # Note: After is the equivalent to previous and before is the equivalent to to next in Logstash
> 
> #multiline.match: after
> 
> #============================= Filebeat modules ===============================
> 
> filebeat.config.modules:
> 
> # Glob pattern for configuration loading
> 
> path: ${path.config}/modules.d/\*.yml
> 
> # Set to true to enable config reloading
> 
> reload.enabled: true
> 
> # Period on which files under path should be checked for changes
> 
> #reload.period: 10s
> 
> #==================== Elasticsearch template setting ==========================
> 
> setup.template.settings:  
> index.number\_of\_shards: 3  
> #index.codec: best\_compression  
> #\_source.enabled: false
> 
> #================================ General =====================================
> 
> # The name of the shipper that publishes the network data. It can be used to group
> 
> # all the transactions sent by a single shipper in the web interface.
> 
> name: filebeat
> 
> # The tags of the shipper are included in their own field with each
> 
> # transaction published.
> 
> #tags: ["service-X", "web-tier"]
> 
> # Optional fields that you can specify to add additional information to the
> 
> # output.
> 
> #fields:
> 
> # env: staging
> 
> #============================== Dashboards =====================================
> 
> # These settings control loading the sample dashboards to the Kibana index. Loading
> 
> # the dashboards is disabled by default and can be enabled either by setting the
> 
> # options here, or by using the `-setup` CLI flag or the `setup` command.
> 
> #setup.dashboards.enabled: false
> 
> # The URL from where to download the dashboards archive. By default this URL
> 
> # has a value which is computed based on the Beat name and version. For released
> 
> # versions, this URL points to the dashboard archive on the [artifacts.elastic.co](http://artifacts.elastic.co)
> 
> # website.
> 
> #setup.dashboards.url:
> 
> #============================== Kibana =====================================
> 
> # Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.
> 
> # This requires a Kibana endpoint configuration.
> 
> setup.kibana:
> 
> # Kibana Host
> 
> # Scheme and port can be left out and will be set to the default (http and 5601)
> 
> # In case you specify and additional path, the scheme is required: [http://localhost:5601/path](http://localhost:5601/path)
> 
> # IPv6 addresses should always be defined as: https://[2001:db8::1]:5601
> 
> #host: "localhost:5601"
> 
> #============================= Elastic Cloud ==================================
> 
> # These settings simplify using filebeat with the Elastic Cloud ([https://cloud.elastic.co/](https://cloud.elastic.co/)).
> 
> # The cloud.id setting overwrites the `output.elasticsearch.hosts` and
> 
> # `setup.kibana.host` options.
> 
> # You can find the `cloud.id` in the Elastic Cloud web UI.
> 
> #cloud.id:
> 
> # The cloud.auth setting overwrites the `output.elasticsearch.username` and
> 
> # `output.elasticsearch.password` settings. The format is `<user>:<pass>`.
> 
> #cloud.auth:
> 
> #================================ Outputs =====================================
> 
> # Configure what output to use when sending the data collected by the beat.
> 
> #-------------------------- Elasticsearch output ------------------------------  
> #output.elasticsearch:
> 
> # Array of hosts to connect to.
> 
> #hosts: ["localhost:9200"]
> 
> # Optional protocol and basic auth credentials.
> 
> #protocol: "https"  
> #username: "elastic"  
> #password: "changeme"
> 
> #----------------------------- Logstash output --------------------------------  
> output.logstash:
> 
> # The Logstash hosts
> 
> hosts: ["172.20.0.44"]  
> port: 5443  
> ssl.certificate\_authorities: ["./ca.crt"]  
> ssl.certificate: "./logstash-forwarder.crt"  
> ssl.key: "./logstash-forwarder.key"
> 
> # Optional SSL. By default is off.
> 
> # List of root certificates for HTTPS server verifications
> 
> #ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]
> 
> # Certificate for SSL client authentication
> 
> #ssl.certificate: "/etc/pki/client/cert.pem"
> 
> # Client Certificate Key
> 
> #ssl.key: "/etc/pki/client/cert.key"
> 
> #================================ Logging =====================================
> 
> # Sets log level. The default log level is info.
> 
> # Available log levels are: error, warning, info, debug
> 
> logging.level: debug

thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 22, 2018, 9:11am UTC](https://discuss.elastic.co/t/link-problem-between-elk-and-filebeat/145503/2 "2018-08-22T09:11:20Z")

</div>

Please edit your post and use the `</>` (aka code) button to format the config, it will make it much easier to read.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2018, 9:11am UTC](https://discuss.elastic.co/t/link-problem-between-elk-and-filebeat/145503/3 "2018-09-19T09:11:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
