# Logstash cannot get filebeat's data

**URL:** <https://discuss.elastic.co/t/logstash-cannot-get-filebeats-data/236955>\
**Category:** Logstash\
**Created:** [June 13, 2020, 2:33am UTC](https://discuss.elastic.co/t/logstash-cannot-get-filebeats-data/236955 "2020-06-13T02:33:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![azteker](https://avatars.discourse-cdn.com/v4/letter/a/aca169/32.png) [@azteker](https://discuss.elastic.co/u/azteker)\
**Post date:** [June 13, 2020, 2:33am UTC](https://discuss.elastic.co/t/logstash-cannot-get-filebeats-data/236955/1 "2020-06-13T02:33:42Z")

</div>

This is my /etc/filebeat/filebeat.yml

```
filebeat.inputs:    
- type: log

      enabled: true

      paths:
        - /var2/log/cloud/test.log

    filebeat.config.modules:
      # Glob pattern for configuration loading
      path: ${path.config}/modules.d/*.yml

      # Set to true to enable config reloading
      reload.enabled: false

      # Period on which files under path should be checked for changes
      #reload.period: 10s

    setup.template.settings:
      index.number_of_shards: 3
      #index.codec: best_compression
      #_source.enabled: false

    setup.dashboards.enabled: false
    setup.dashboards.beat:

    setup.kibana:

      host: "10.28.1.17:80"

      # Optional protocol and basic auth credentials.
      protocol: "http"
      username: "admin"
      password: "admin"

    output.logstash:
      # The Logstash hosts
      hosts: ["10.28.1.17:5044"]

      ssl.enabled: false
      #### we use our generated certificates from ELK
      ssl.certificate_authorities: ["/etc/beat/beat-forwarder.crt"]

      # Certificate for SSL client authentication
      ssl.certificate: "/etc/beat/beat-forwarder.crt"

      # Client Certificate Key
      ssl.key: "/etc/beat/beat-forwarder.key"

    processors:
      - add_host_metadata: ~
      - add_cloud_metadata: ~

    logging.level: info
    logging.to_files: true
    logging.files:
      path: /var/log/filebeat
      name: filebeat
      keepfiles: 7
      permissions: 0644

```

I can telnet 10.28.1.17 5044  
filebeat should work fine

here is my /etc/logstash/conf.d/logstash.conf on 10.28.1.17

```
input {
  tcp {
    port => 5000
    type => syslog
  }
  udp {
    port => 5000
    type => syslog
  }
}

input {
  beats {
    port => "5044"
    ssl => false
    ssl_certificate => ["/usr/share/logstash/beat-forwarder.crt"]
    ssl_key => ["/usr/share/logstash/beat-forwarder.key"]
    ssl_verify_mode => none
  }
}

filter {
  mutate {
    remove_field => ["[host]" ]
  }
  mutate {
    add_field => {
      "host" => "%{[beat][hostname]}"
    }
  }

}

output {
  stdout { }
}

```

I run the logstash by /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/logstash.conf, but no matter how I add lines in the log file /var2/log/cloud/test.log, nothing prints. Can anyone help to see what is wrong?

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [June 13, 2020, 3:10am UTC](https://discuss.elastic.co/t/logstash-cannot-get-filebeats-data/236955/2 "2020-06-13T03:10:48Z")

</div>

you can do filebeat test output to test the logstash output

> [@azteker](#):
>
> but no matter how I add lines in the tracker file,

can you explore more about what do you mean with this?

---

<div class="post-metadata">

**Author:** ![azteker](https://avatars.discourse-cdn.com/v4/letter/a/aca169/32.png) [@azteker](https://discuss.elastic.co/u/azteker)\
**Post date:** [June 13, 2020, 3:11am UTC](https://discuss.elastic.co/t/logstash-cannot-get-filebeats-data/236955/3 "2020-06-13T03:11:38Z")

</div>

@ptamba  
The tracked file configured in filebeat.yml: /var2/log/cloud/test.log

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [June 13, 2020, 10:23am UTC](https://discuss.elastic.co/t/logstash-cannot-get-filebeats-data/236955/4 "2020-06-13T10:23:48Z")

</div>

is your filebeat test output successful ? if logstash is not producing any output , my initial suspect will be that it does not receive any inputs

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2020, 10:23am UTC](https://discuss.elastic.co/t/logstash-cannot-get-filebeats-data/236955/5 "2020-07-11T10:23:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
