# Logs transfer thru Filebeat to Logstash

**URL:** <https://discuss.elastic.co/t/logs-transfer-thru-filebeat-to-logstash/127978>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 13, 2018, 1:16pm UTC](https://discuss.elastic.co/t/logs-transfer-thru-filebeat-to-logstash/127978 "2018-04-13T13:16:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashurawat](https://avatars.discourse-cdn.com/v4/letter/a/bb73d2/32.png) [@ashurawat](https://discuss.elastic.co/u/ashurawat)\
**Post date:** [April 13, 2018, 1:17pm UTC](https://discuss.elastic.co/t/logs-transfer-thru-filebeat-to-logstash/127978/1 "2018-04-13T13:17:00Z")

</div>

Please suggest the best technique to be used while sending the data thru filebeat to logstash

1. Filebeat directly sending the data to logstash
2. Filebeat should send the data to REDIS/KAFKA and then from their logstash is reading it.

Please suggest with advantages and disadvantages of both.

Thanks

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 13, 2018, 4:11pm UTC](https://discuss.elastic.co/t/logs-transfer-thru-filebeat-to-logstash/127978/2 "2018-04-13T16:11:46Z")

</div>

There isn't one "best technique" as it depends a lot on your requirements and architecture. There are some existing blog posts discussing queueing and I've linked them below.

Also take a look at using the [persistent queue feature](https://www.elastic.co/guide/en/logstash/current/persistent-queues.html) that's part of the Logstash as an alternative to putting a queue between Beat and Logstash.

Blogs

- [https://www.elastic.co/blog/logstash-persistent-queue](https://www.elastic.co/blog/logstash-persistent-queue)
- [https://www.elastic.co/blog/just-enough-kafka-for-the-elastic-stack-part1](https://www.elastic.co/blog/just-enough-kafka-for-the-elastic-stack-part1)
- [https://www.elastic.co/blog/just-enough-kafka-for-the-elastic-stack-part2](https://www.elastic.co/blog/just-enough-kafka-for-the-elastic-stack-part2)

---

<div class="post-metadata">

**Author:** ![ashurawat](https://avatars.discourse-cdn.com/v4/letter/a/bb73d2/32.png) [@ashurawat](https://discuss.elastic.co/u/ashurawat)\
**Post date:** [April 13, 2018, 4:17pm UTC](https://discuss.elastic.co/t/logs-transfer-thru-filebeat-to-logstash/127978/3 "2018-04-13T16:17:37Z")

</div>

Thank you so much Andrew. I will surely try those.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2018, 4:18pm UTC](https://discuss.elastic.co/t/logs-transfer-thru-filebeat-to-logstash/127978/4 "2018-05-11T16:18:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
