# Logs are not collecting

**URL:** <https://discuss.elastic.co/t/logs-are-not-collecting/56348>\
**Category:** Logstash\
**Created:** [July 26, 2016, 2:46am UTC](https://discuss.elastic.co/t/logs-are-not-collecting/56348 "2016-07-26T02:46:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![disalassalyjose](https://avatars.discourse-cdn.com/v4/letter/d/a88e4f/32.png) [@disalassalyjose](https://discuss.elastic.co/u/disalassalyjose)\
**Post date:** [July 26, 2016, 2:46am UTC](https://discuss.elastic.co/t/logs-are-not-collecting/56348/1 "2016-07-26T02:46:27Z")

</div>

Hi,  
I am able to get the logs from one client server which is windows 12 r2 but not able to get the logs from another client server, below are the configuration that are done in both server side.  
\*\*Server :\*\*Ubuntu 14.04  
**client** : Windows server 2012 r2  
**02-beats-input.conf**  
input {  
beats {  
port =\> 5044  
}  
}

**30-elasticsearch-output.conf**  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
**11-iis--prod.conf** -----This iislog filter configuration for first client:  
filter {  
if [type] == "iis\_prod" {  
grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:datetime} %{IP:server\_ip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:query} %{NUMBER:port} %{NOTSPACE:username} %{IP:client\_ip} %{NOTSPACE:useragent} %{NOTSPACE:referer} %{NUMBER:subresponse} %{NUMBER:scstatus} %{NUMBER:bytes} %{NUMBER:timetaken}" }  
}  
}  
}  
**12-iis--stage.conf** -----This iislog filter configuration for second client:  
filter {  
if [type] == "iis\_stage\_ready" {  
grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:datetime} %{IP:server\_ip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:query} %{NUMBER:port} %{NOTSPACE:username} %{IP:client\_ip} %{NOTSPACE:useragent} %{NOTSPACE:referer} %{NUMBER:subresponse} %{NUMBER:scstatus} %{NUMBER:bytes} %{NUMBER:timetaken}" }  
}  
}

---

<div class="post-metadata">

**Author:** ![jpcarey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpcarey/32/46668_2.png) [@jpcarey](https://discuss.elastic.co/u/jpcarey)\
**Post date:** [July 26, 2016, 4:19am UTC](https://discuss.elastic.co/t/logs-are-not-collecting/56348/2 "2016-07-26T04:19:44Z")

</div>

Are there any specific errors in the filebeat log that should be sending to logstash?

---

<div class="post-metadata">

**Author:** ![disalassalyjose](https://avatars.discourse-cdn.com/v4/letter/d/a88e4f/32.png) [@disalassalyjose](https://discuss.elastic.co/u/disalassalyjose)\
**Post date:** [July 26, 2016, 4:24am UTC](https://discuss.elastic.co/t/logs-are-not-collecting/56348/3 "2016-07-26T04:24:43Z")

</div>

ERR Failed to publish events caused by :EOF. this is the erroe i could find in the filebeat error.

---

<div class="post-metadata">

**Author:** ![jpcarey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpcarey/32/46668_2.png) [@jpcarey](https://discuss.elastic.co/u/jpcarey)\
**Post date:** [July 26, 2016, 4:43am UTC](https://discuss.elastic.co/t/logs-are-not-collecting/56348/4 "2016-07-26T04:43:46Z")

</div>

I would double check that the yaml file is valid (diff against the working yaml config), and that the path to the [filebeat registry file](https://www.elastic.co/guide/en/beats/filebeat/current/_updating_the_registry_file.html) is valid.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:46am UTC](https://discuss.elastic.co/t/logs-are-not-collecting/56348/5 "2017-07-06T04:46:32Z")

</div>


