# Logstash data appears but filebeat data not appearing in kibana after x-pack is enabled

**URL:** <https://discuss.elastic.co/t/logstash-data-appears-but-filebeat-data-not-appearing-in-kibana-after-x-pack-is-enabled/89365>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 14, 2017, 10:54am UTC](https://discuss.elastic.co/t/logstash-data-appears-but-filebeat-data-not-appearing-in-kibana-after-x-pack-is-enabled/89365 "2017-06-14T10:54:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![priyam](https://avatars.discourse-cdn.com/v4/letter/p/9fc29f/32.png) [@priyam](https://discuss.elastic.co/u/priyam)\
**Post date:** [June 14, 2017, 10:54am UTC](https://discuss.elastic.co/t/logstash-data-appears-but-filebeat-data-not-appearing-in-kibana-after-x-pack-is-enabled/89365/1 "2017-06-14T10:54:05Z")

</div>

I have configured filebeat to send logs to logstash followed by logstash sending logs to elasticsearch.  
All worked fine .. i could see logstash-\* and filebeat-\* data getting updated in kibana .. until i enabled x-pack security.  
After giving user creds in logtash.conf, i can see the logstash data appear but none appears in filebeat.

My problem looks similar to [Kibana not updating indices after X-Pack installed - #2 by TimV](https://discuss.elastic.co/t/kibana-not-updating-indices-after-x-pack-installed/86016/2)

so i followed the steps mentioned in the article link provided in the topic - [Beats and Security | X-Pack for the Elastic Stack [6.2] | Elastic](https://www.elastic.co/guide/en/x-pack/current/beats.html)

But that did not help.

Also, following [Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/x-pack/current/logstash.html) , placing username and password in input and filter fields results in config errors for me.

Any suggestions?

**filebeat.yml** (cannot see filebeat-\* data in kibana)

> ----------------------------- Logstash output --------------------------------  
> output.logstash:
> 
> # The Logstash hosts
> 
> hosts: ["localhost:5044"]  
> index: "filebeat"  
> username: "filebeat\_internal"  
> password: "changeme"

**logstash.conf** (can see logstash-\* data in kibana but in syslog format instead of json 😔

> input {  
> beats {  
> port =\> 5044  
> codec =\> json  
> }  
> }  
> filter {  
> grok {  
> match =\> { "message" =\> "%{COMBINEDAPACHELOG}"}  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> "localhost:9200"  
> user =\> "elastic"  
> password =\> "changeme"  
> }  
> }

- though elastic being a superuser does not make filebeat work either.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 14, 2017, 11:46am UTC](https://discuss.elastic.co/t/logstash-data-appears-but-filebeat-data-not-appearing-in-kibana-after-x-pack-is-enabled/89365/2 "2017-06-14T11:46:26Z")

</div>

> [@priyam](#):
>
> so i followed the steps mentioned in the article link provided in the topic - [Beats and Security | X-Pack for the Elastic Stack [6.2] | Elastic](https://www.elastic.co/guide/en/x-pack/current/beats.html)

Those instructions are for having Beats send data to Elasticsearch.

Since you are sending data from Beats to Logstash, you shouldn't be using those instructions.

There is no need for a username/password for passing data from beats to logstash.

---

<div class="post-metadata">

**Author:** ![priyam](https://avatars.discourse-cdn.com/v4/letter/p/9fc29f/32.png) [@priyam](https://discuss.elastic.co/u/priyam)\
**Post date:** [June 14, 2017, 11:48am UTC](https://discuss.elastic.co/t/logstash-data-appears-but-filebeat-data-not-appearing-in-kibana-after-x-pack-is-enabled/89365/3 "2017-06-14T11:48:58Z")

</div>

@TimV : okay.. so in that case why is my filebeat-\* data (without user/password also) not appearing while the logstash data appears in kibana ?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 14, 2017, 8:26pm UTC](https://discuss.elastic.co/t/logstash-data-appears-but-filebeat-data-not-appearing-in-kibana-after-x-pack-is-enabled/89365/4 "2017-06-14T20:26:51Z")

</div>

With your filebeat and logstash configuration, I'd expect filebeat send data to logstash (unencrypted, as no TLS/SSL is configured between beats and LS here). As you have not configured the index in the elasticsearch output, all events received from filebeat will be put into the logstash index. See [filebeat getting started guide](https://www.elastic.co/guide/en/beats/filebeat/current/config-filebeat-logstash.html) + follow link to [Logstash Setup](https://www.elastic.co/guide/en/beats/libbeat/5.4/logstash-installation.html#logstash-setup).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2017, 8:27pm UTC](https://discuss.elastic.co/t/logstash-data-appears-but-filebeat-data-not-appearing-in-kibana-after-x-pack-is-enabled/89365/5 "2017-07-12T20:27:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
