# Logstash as filebeat passthrough

**URL:** <https://discuss.elastic.co/t/logstash-as-filebeat-passthrough/173561>\
**Category:** Logstash\
**Created:** [March 22, 2019, 9:36pm UTC](https://discuss.elastic.co/t/logstash-as-filebeat-passthrough/173561 "2019-03-22T21:36:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kharvey](https://avatars.discourse-cdn.com/v4/letter/k/d07c76/32.png) [@kharvey](https://discuss.elastic.co/u/kharvey)\
**Post date:** [March 22, 2019, 9:36pm UTC](https://discuss.elastic.co/t/logstash-as-filebeat-passthrough/173561/1 "2019-03-22T21:36:26Z")

</div>

Is it possible to pass filebeat logs straight through logstash without logstash doing any processing?

My setup is as follows

```auto
Client using filebeats => beats input on logstash-proxy => tcp output on logstash-proxy => tcp input on logstash => filter => tcp output on logstash => ElasticSearch
```

My problem is that the logstash-proxy is processing my filebeats input and sending a bunch of extra junk to my primary logstash to filter.  
The goal of the logstash-proxy is to build queues for remote sites in case of Internet outages and such without impacting clients. The issue that I have is that the proxy is continually adding JSON stuff to it's output, and changing the information which is breaking my pipelines.

I would prefer not to have to update all of my pipelines to parse out the excess information that the logstash-proxy is adding.

---

<div class="post-metadata">

**Author:** ![kharvey](https://avatars.discourse-cdn.com/v4/letter/k/d07c76/32.png) [@kharvey](https://discuss.elastic.co/u/kharvey)\
**Post date:** [March 23, 2019, 12:09am UTC](https://discuss.elastic.co/t/logstash-as-filebeat-passthrough/173561/2 "2019-03-23T00:09:52Z")

</div>

I have found a large portion of the solution:  
[https://www.elastic.co/guide/en/logstash/current/ls-to-ls.html](https://www.elastic.co/guide/en/logstash/current/ls-to-ls.html)

I have some things working but not everything quite yet. Lumberjack is missing some critical components, but I am working through each error one at a time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2019, 12:09am UTC](https://discuss.elastic.co/t/logstash-as-filebeat-passthrough/173561/3 "2019-04-20T00:09:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
