# Logstash can't send logs to ES

**URL:** <https://discuss.elastic.co/t/logstash-cant-send-logs-to-es/95875>\
**Category:** Logstash\
**Created:** [August 4, 2017, 11:39am UTC](https://discuss.elastic.co/t/logstash-cant-send-logs-to-es/95875 "2017-08-04T11:39:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![snah95](https://avatars.discourse-cdn.com/v4/letter/s/e79b87/32.png) [@snah95](https://discuss.elastic.co/u/snah95)\
**Post date:** [August 4, 2017, 11:39am UTC](https://discuss.elastic.co/t/logstash-cant-send-logs-to-es/95875/1 "2017-08-04T11:39:56Z")

</div>

Hello everyone!

I have a little problem with my ELK Stack. My Logstash container gathers logs from Filebeat, but it can't pass them to Elasticsearch. I tried many methods described in another topics, but with no success. I am able to use this:

curl -XPUT "[http://hostname:9200/test/test/1](http://hostname:9200/test/test/1)" -d '{}'

I am also able to send logs directly from Filebeat to Elasticsearch. So I think that Logstash is my problem.

Some info:  
Logstash version: 5.5.1  
Elasticsearch version: 5.5.1  
Kibana version: 5.5.1  
Error in ES log:

> > Content type detection for rest requests is deprecated. Specify the content type using the [Content-Type] header.

Logstash.yml

input {  
tcp {  
port =\> 5044  
start\_position =\> beginning  
}  
}

/\* filter {  
grok {  
patterns\_dir =\> ["./patterns"]  
match =\> { "message" =\> %{TIME:time}[%{LOGLEVEL:loglevel}] %{DATA:class} - %{GREEDYDATA:message}" }  
}  
}\*/

output {  
elasticsearch {  
hosts =\> "IP of Docker:9200"  
codec =\> "json"  
}  
}

Logstash.conf

http.host: "0.0.0.0"  
path.config: /usr/share/logstash/pipeline  
xpack.monitoring.enabled: false

I am using offical Docker images from [docker.elastic.co](http://docker.elastic.co).

Thank You in advance for Your help!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 4, 2017, 12:48pm UTC](https://discuss.elastic.co/t/logstash-cant-send-logs-to-es/95875/2 "2017-08-04T12:48:26Z")

</div>

The tcp input doesn't have a `start_position` option and `/* ... */` comments aren't supported so I doubt Logstash is starting at all.

---

<div class="post-metadata">

**Author:** ![snah95](https://avatars.discourse-cdn.com/v4/letter/s/e79b87/32.png) [@snah95](https://discuss.elastic.co/u/snah95)\
**Post date:** [August 4, 2017, 12:58pm UTC](https://discuss.elastic.co/t/logstash-cant-send-logs-to-es/95875/3 "2017-08-04T12:58:59Z")

</div>

Thank You for Your answer.

start\_position and comments are new lines I added when I was searching for solution. I'm still learning about ELK and I make many stupid mistakes. But Logstash is running and when I use "docker logs logstash" command I see all logs sent from Filebeat.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 4, 2017, 1:13pm UTC](https://discuss.elastic.co/t/logstash-cant-send-logs-to-es/95875/4 "2017-08-04T13:13:36Z")

</div>

Remove `codec => json` from your elasticsearch output.

---

<div class="post-metadata">

**Author:** ![snah95](https://avatars.discourse-cdn.com/v4/letter/s/e79b87/32.png) [@snah95](https://discuss.elastic.co/u/snah95)\
**Post date:** [August 4, 2017, 1:32pm UTC](https://discuss.elastic.co/t/logstash-cant-send-logs-to-es/95875/5 "2017-08-04T13:32:34Z")

</div>

Still nothing. I don't know what's going on. Before server's reset everything was working like a charm, but now I can only send logs directly from Filebeat 😕

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2017, 1:32pm UTC](https://discuss.elastic.co/t/logstash-cant-send-logs-to-es/95875/6 "2017-09-01T13:32:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
