# Logstash does not receive logs from Filebeat on another machine

**URL:** <https://discuss.elastic.co/t/logstash-does-not-receive-logs-from-filebeat-on-another-machine/132951>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 23, 2018, 8:41am UTC](https://discuss.elastic.co/t/logstash-does-not-receive-logs-from-filebeat-on-another-machine/132951 "2018-05-23T08:41:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![koko191](https://avatars.discourse-cdn.com/v4/letter/k/a587f6/32.png) [@koko191](https://discuss.elastic.co/u/koko191)\
**Post date:** [May 23, 2018, 8:41am UTC](https://discuss.elastic.co/t/logstash-does-not-receive-logs-from-filebeat-on-another-machine/132951/1 "2018-05-23T08:41:49Z")

</div>

This is a dummy setup for me to play with the Elastic stack before getting into the production environment.

**My setup:**  
I'm running two Ubuntu 16.04 VMs using VirtualBox. These two instances have been configured to communicate with each other (I hope) as `telnet` and `ping` from one to the other works properly.

On one VM (IP 10.0.2.4), I install Elasticsearch, Logstash, Kibana, Filebeat and some more Beats. Filebeat outputs to Logstash via port 5050:

```auto
output.logstash:
  hosts: ["10.0.2.4:5050"]

```

The other Beats output directly to Elasticsearch:

```auto
output.elasticsearch:
  hosts: ["10.0.2.4:9200"]

```

On the other VM (IP 10.0.2.5), I install Elasticsearch (not in use, only to store index replicas), Kibana, and the Beats. So no Logstash on this VM. Filebeat also outputs to the first VM but through another port 5051:

```auto
output.logstash:
  hosts: ["10.0.2.4:5051"]

```

While the other Beats also output to Elasticsearch on the first VM:

```auto
output.elasticsearch:
  hosts: ["10.0.2.4:9200"]

```

So all Beats outputs are to the first VM.  
All Beats configs have been properly commented. So no Elasticsearch output on Filebeat and no Logstash output on the other Beats.

Logstash input setting:

```auto
input {
  beats {
    port => "5050"
  }
  beats {
    port => "5051"
  }
}

```

**Results:**  
All Beats on 10.0.2.4 work properly. Logstash receives the logs from Filebeat on 10.0.2.4 and passes it to Elasticsearch. I can see the data on Kibana.  
On 10.0.2.5, all Beats except for Filebeat work properly. I can see the data from 10.0.2.5 on Kibana. The problem is with Filebeat on 10.0.2.5. Logstash doesn't receive anything from Filebeat on the second VM. `telnet 10.0.2.4 5051` from the second VM works.

Am I doing this correctly? Or do I have to install Logstash on the second VM then outputs to Elasticsearch on the first VM?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [May 23, 2018, 9:05am UTC](https://discuss.elastic.co/t/logstash-does-not-receive-logs-from-filebeat-on-another-machine/132951/2 "2018-05-23T09:05:32Z")

</div>

Could you please share the debug logs of the problematic Filebeat? (`./filebeat -e -d "*"`)

---

<div class="post-metadata">

**Author:** ![koko191](https://avatars.discourse-cdn.com/v4/letter/k/a587f6/32.png) [@koko191](https://discuss.elastic.co/u/koko191)\
**Post date:** [May 23, 2018, 9:18am UTC](https://discuss.elastic.co/t/logstash-does-not-receive-logs-from-filebeat-on-another-machine/132951/3 "2018-05-23T09:18:19Z")

</div>

I forgot to enable the prospector 😑 Everything is working now

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2018, 9:18am UTC](https://discuss.elastic.co/t/logstash-does-not-receive-logs-from-filebeat-on-another-machine/132951/4 "2018-06-20T09:18:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
