# Logs are not updating in elastic search just after installing Xpack

**URL:** <https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012>\
**Category:** Elasticsearch\
**Created:** [February 1, 2018, 11:58am UTC](https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012 "2018-02-01T11:58:20Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![sweta\_khandelwal](https://avatars.discourse-cdn.com/v4/letter/s/c67d28/32.png) [@sweta\_khandelwal](https://discuss.elastic.co/u/sweta_khandelwal)\
**Post date:** [February 1, 2018, 11:58am UTC](https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012/1 "2018-02-01T11:58:21Z")

</div>

Right after installing xpack filebeat stopped shipping of logs in to elastic search. Do I need to do some sort of authentication setting? can someone please reply and help??

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 1, 2018, 3:32pm UTC](https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012/2 "2018-02-01T15:32:38Z")

</div>

Hi,

Yes, filebeat now needs to authenticate as a user with the right permissions. The specific [documentation](https://www.elastic.co/guide/en/beats/filebeat/6.1/securing-beats.html) is pretty thorough, so please start from there and we can address any additional issues you might have setting this up.

---

<div class="post-metadata">

**Author:** ![sweta\_khandelwal](https://avatars.discourse-cdn.com/v4/letter/s/c67d28/32.png) [@sweta\_khandelwal](https://discuss.elastic.co/u/sweta_khandelwal)\
**Post date:** [February 2, 2018, 5:24am UTC](https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012/3 "2018-02-02T05:24:13Z")

</div>

Thanks for reply.

I need to know one more thing that I have installed xpack on KIbana and elastic search. So, do I need to install it on Logstash too??  
Please reply.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 2, 2018, 7:29am UTC](https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012/4 "2018-02-02T07:29:01Z")

</div>

Yes, you most probably do. Again, use the [documentation](https://www.elastic.co/guide/en/x-pack/current/installing-xpack.html) as a starting point and we will be able to help further with any specific issues

---

<div class="post-metadata">

**Author:** ![sweta\_khandelwal](https://avatars.discourse-cdn.com/v4/letter/s/c67d28/32.png) [@sweta\_khandelwal](https://discuss.elastic.co/u/sweta_khandelwal)\
**Post date:** [February 2, 2018, 10:03am UTC](https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012/5 "2018-02-02T10:03:24Z")

</div>

Hi,

I have followed the same link( [https://www.elastic.co/guide/en/beats/filebeat/6.1/beats-basic-auth.html](https://www.elastic.co/guide/en/beats/filebeat/6.1/beats-basic-auth.html)) & created specified user & role in kibana and then attached the user with that role.

Below are the settings which I did in filebeat.yml configuration file.  
output.elasticsearch:

# Array of hosts to connect to.

hosts: ["localhost:9200"]  
index: "filebeat-%{+YYYY.MM.dd}"

# Optional protocol and basic auth credentials.

#protocol: "https"  
username: "filebeat\_internal"  
password: "elastic"

But still filebeat is not shipping the logs. can you tell what I am missing here?

---

<div class="post-metadata">

**Author:** ![sweta\_khandelwal](https://avatars.discourse-cdn.com/v4/letter/s/c67d28/32.png) [@sweta\_khandelwal](https://discuss.elastic.co/u/sweta_khandelwal)\
**Post date:** [February 2, 2018, 11:33am UTC](https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012/6 "2018-02-02T11:33:53Z")

</div>

Hi,

The issue is resolved when I tried to pushed the logs directly from Filebeat to ElasticSearch.

I did the following to resolve it:

1. Created user & role with some specified permission in Kibana and attached that user with that role.
2. In the output section of ElasticSearch in Filebeat.yml. Provided the user & password of Filebeat internal user created in Kibana.
3. Restart the services.

Now, suppose if I want to push the logs via logstash. so is it mandate to install xpack on logstash?? if yes, then what user & password I need to provide in the logstash.yml file??

---

<div class="post-metadata">

**Author:** ![sweta\_khandelwal](https://avatars.discourse-cdn.com/v4/letter/s/c67d28/32.png) [@sweta\_khandelwal](https://discuss.elastic.co/u/sweta_khandelwal)\
**Post date:** [February 14, 2018, 6:51am UTC](https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012/7 "2018-02-14T06:51:37Z")

</div>

can somebody please help me in that??

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 8, 2018, 1:55pm UTC](https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012/8 "2018-03-08T13:55:38Z")

</div>

Hi,

Yes you need to install X-Pack on Logstash too. I have shared the link to documentation above, the specific part that contains instructions for setting the authentication for the Elasticsearch output plugin of Logstash is [this](https://www.elastic.co/guide/en/logstash/current/ls-security.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2018, 1:55pm UTC](https://discuss.elastic.co/t/logs-are-not-updating-in-elastic-search-just-after-installing-xpack/118012/9 "2018-04-05T13:55:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
