# Logstash Configuration Doubt

**URL:** <https://discuss.elastic.co/t/logstash-configuration-doubt/37461>\
**Category:** Logstash\
**Created:** [December 17, 2015, 11:46am UTC](https://discuss.elastic.co/t/logstash-configuration-doubt/37461 "2015-12-17T11:46:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shabinhashim](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@shabinhashim](https://discuss.elastic.co/u/shabinhashim)\
**Post date:** [December 17, 2015, 11:46am UTC](https://discuss.elastic.co/t/logstash-configuration-doubt/37461/1 "2015-12-17T11:46:14Z")

</div>

HI,

I need a setup to monitor logs from 100 different machines. I checked beats framework and it seems i cannot install a package in the machine. Also does beats support Multi-line? Also as per this page [https://www.elastic.co/guide/en/logstash/current/deploying-and-scaling.html](https://www.elastic.co/guide/en/logstash/current/deploying-and-scaling.html) , its better to send the data from logs to a message layer, then process it and then send to elastic search. I couldn't find a kafka output for beats.

So If i run very minimal logstash instance on tte 100 machines, with no processing and indexing, (Just throw the data to kafka with a multi-line filter added), will it have significant performance impact compared to using beats?

---

<div class="post-metadata">

**Author:** ![rclarke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rclarke/32/68604_2.png) [@rclarke](https://discuss.elastic.co/u/rclarke)\
**Post date:** [December 17, 2015, 12:29pm UTC](https://discuss.elastic.co/t/logstash-configuration-doubt/37461/2 "2015-12-17T12:29:32Z")

</div>

Hello Shabinhashim,

Filebeat does not (currently) do multiline - each line is sent as an individual event.

If you want to send beats to Kafka, you will have to use Logstash as an interim.

Your best solution if possible would be to ensure that your application writing the logs creates single-line (json encoded) log lines so that you can use filebeat to transport to logstash, and from there on to Elasticsearch , kafka etc.

Cheers,  
-Robin-

---

<div class="post-metadata">

**Author:** ![shabinhashim](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@shabinhashim](https://discuss.elastic.co/u/shabinhashim)\
**Post date:** [December 17, 2015, 12:44pm UTC](https://discuss.elastic.co/t/logstash-configuration-doubt/37461/3 "2015-12-17T12:44:01Z")

</div>

First of all thanks for the prompt reply.  
The application cannot be changed to log into a singe line.😒

If i run logstash instances itself in the 100 machines (which does basic forwading) will it impact the performance of the machine compared to using beats?

Thanks  
Shabin

---

<div class="post-metadata">

**Author:** ![rclarke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rclarke/32/68604_2.png) [@rclarke](https://discuss.elastic.co/u/rclarke)\
**Post date:** [December 17, 2015, 1:39pm UTC](https://discuss.elastic.co/t/logstash-configuration-doubt/37461/4 "2015-12-17T13:39:08Z")

</div>

Yes - filebeat is very light, logstash requires a JVM with the usual memory consumption.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:18am UTC](https://discuss.elastic.co/t/logstash-configuration-doubt/37461/5 "2017-07-06T05:18:02Z")

</div>


