# Logs are sending to Elasticsearch without 'output' in 'logstash.conf'

**URL:** <https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262>\
**Category:** Logstash\
**Created:** [April 22, 2017, 12:16am UTC](https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262 "2017-04-22T00:16:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Steve\_1](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Steve\_1](https://discuss.elastic.co/u/Steve_1)\
**Post date:** [April 22, 2017, 12:16am UTC](https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262/1 "2017-04-22T00:16:30Z")

</div>

I use Filebeat to forward logs from another server to Logstash and then Logstash sends them to Elasticsearch.  
In `filebeat.yml` I specify output as Logstash but in `logstash.conf` I don't specify output at all. But in Kibana I can see logs are still comming for index `logstash-*`.

Could anybody explain how it is possible to get logs without output in `logstash.conf` file?  
(I run ELK in 3 Docker containers, linking with Elasticsearch)

filebeat.yml:

```
filebeat.prospectors:

- input_type: log
  paths:
    - /var/log/*.log

registry_file: /var/lib/filebeat/registry

output.logstash:
  hosts: ["my_host:5044"]
  ssl.certificate_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

```

logstash.conf:

```
input {
  beats {
    port => 5044
    ssl => true
    ssl_certificate => "/usr/share/logstash/ssl/logstash-forwarder.crt"
    ssl_key => "/usr/share/logstash/ssl/logstash-forwarder.key"
  }
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 22, 2017, 3:06am UTC](https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262/2 "2017-04-22T03:06:57Z")

</div>

Is there more to your LS config?

---

<div class="post-metadata">

**Author:** ![Steve\_1](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Steve\_1](https://discuss.elastic.co/u/Steve_1)\
**Post date:** [April 22, 2017, 5:26am UTC](https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262/3 "2017-04-22T05:26:22Z")

</div>

Only filter, but it doesn't matter. I tried to put wrong server as output and it still worked, it also worked without output as well.

```
filter {
  if [type] == "apache-access" {
    grok {
      match => ["message", "%{COMBINEDAPACHELOG}"]
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 22, 2017, 7:03am UTC](https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262/4 "2017-04-22T07:03:21Z")

</div>

So you have no output?

---

<div class="post-metadata">

**Author:** ![Steve\_1](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Steve\_1](https://discuss.elastic.co/u/Steve_1)\
**Post date:** [April 22, 2017, 5:48pm UTC](https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262/5 "2017-04-22T17:48:19Z")

</div>

Correct, there is no output. And you can see the output for Filebeat is Logstash but not Elasticsearch.  
This is what I have in logstash.conf in Docker container

`/usr/share/logstash/pipeline/logstash.conf`

```
input {
  beats {
    port => 5044
    ssl => true
    ssl_certificate => "/usr/share/logstash/ssl/logstash-forwarder.crt"
    ssl_key => "/usr/share/logstash/ssl/logstash-forwarder.key"
  }
}

filter {
  if [type] == "apache-access" {
    grok {
      match => ["message", "%{COMBINEDAPACHELOG}"]
    }
  }
}

```

But I still can see new logs in Kibana for index `logstash-*` that came from the server with Filebeat installed.  
How is it possible?

---

<div class="post-metadata">

**Author:** ![farazkhan](https://avatars.discourse-cdn.com/v4/letter/f/9fc348/32.png) [@farazkhan](https://discuss.elastic.co/u/farazkhan)\
**Post date:** [April 22, 2017, 6:23pm UTC](https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262/6 "2017-04-22T18:23:46Z")

</div>

I am using logstash 2.4.0

Losgstash process the logs for few minutes and it stops processing.I get the below error in logs.

{:timestamp=\>"2017-04-22T20:23:27.947000+0200", :message=\>"Flushing buffer at interval", :instance=\>"#\<LogStash::Outputs::ElasticSearch::Buffer:0x2266677 @operations\_mutex=#Mutex:0xce19843, @max\_size=500, @operations\_lock=#Java::JavaUtilConcurrentLocks::ReentrantLock:0x8de0d07, @submit\_proc=#Proc:0x7cf8406a@/opt/nedi/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:57, @logger=#\<Cabin::Channel:0x7c5bfc36 @metrics=#\<Cabin::Metrics:0x495708f @metrics\_lock=#Mutex:0x2df36d37, @metrics={}, @channel=#\<Cabin::Channel:0x7c5bfc36 ...\>\>, @subscriber\_lock=#Mutex:0x133683f3, @level=:debug, @subscribers={13206=\>#\<Cabin::Subscriber:0x1f91786d @output=#\<Cabin::Outputs::IO:0x29bd347d @io=#\<File:/var/nedi/logs/logstash\_popfile\_to\_es.log\>, @lock=#Mutex:0xe3313a2\>, @options={}\>, 13208=\>#\<Cabin::Subscriber:0x45688d84 @output=#\<Cabin::Outputs::IO:0x51aed754 @io=#\<IO:fd 1\>, @lock=#Mutex:0x11f01fc0\>, @options={:level=\>:fatal}\>}, @data={}\>, @last\_flush=2017-04-22 20:23:26 +0200, @flush\_interval=1, @stopping=#Concurrent::AtomicBoolean:0x64d098f, @buffer=[], @flush\_thread=#\<Thread:0x217e6a65 run\>\>", :interval=\>1, :level=\>:debug, :file=\>"logstash/outputs/elasticsearch/buffer.rb", :line=\>"90", :method=\>"interval\_flush"}

Please suggest

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 23, 2017, 8:21pm UTC](https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262/7 "2017-04-23T20:21:38Z")

</div>

Create your own thread please.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 23, 2017, 8:22pm UTC](https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262/8 "2017-04-23T20:22:03Z")

</div>

You must have another config file in the directory with an output that is being read.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2017, 8:26pm UTC](https://discuss.elastic.co/t/logs-are-sending-to-elasticsearch-without-output-in-logstash-conf/83262/9 "2017-05-21T20:26:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
