# Logstash error read

**URL:** <https://discuss.elastic.co/t/logstash-error-read/101231>\
**Category:** Logstash\
**Created:** [September 20, 2017, 9:00pm UTC](https://discuss.elastic.co/t/logstash-error-read/101231 "2017-09-20T21:00:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Erick\_Garcia\_Perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erick_garcia_perez/32/22244_2.png) [@Erick\_Garcia\_Perez](https://discuss.elastic.co/u/Erick_Garcia_Perez)\
**Post date:** [September 20, 2017, 9:00pm UTC](https://discuss.elastic.co/t/logstash-error-read/101231/1 "2017-09-20T21:00:49Z")

</div>

i'm trying read log of apache\_Access and apache\_error, those are remote log, when i insert, logstash read again the file and insert agin the entries.  
My configuracion file of logstash:  
input {  
file{  
path =\> "/home/clusterelastic/cluster/nodo1/logstash-5.5.2/logsaleer/log\_aceso/accesso"  
type =\> "apache\_access"  
}  
file{  
path =\> "/home/clusterelastic/cluster/nodo1/logstash-5.5.2/logsaleer/log\_error/error"  
type =\> "apache\_error"  
}  
filter {

if [type] in ["apache" , "apache\_access" , "apache-access" ,"access"] {  
grok {  
match =\> ["message"," %{IP:clientip} - - [%{NOTSPACE:date} -%{INT}] "%{WORD:action} /%{WORD}/%{WORD}/%{NOTSPACE:login} %{WORD:protocol}/%{NUMBER:protocolNum}" %{NUMBER:status} %{NUMBER} "%{NOTSPACE}" "%{NOTSPACE:client} (%{WORD}; %{WORD:clientOs}%{GREEDYDATA}"]  
}  
}  
if [type] in ["apache\_error","apache-error","error\_log"] {  
grok {  
match =\> ["message", "[%{DATA:DAY} %{DATA:MONTH} %{DATA:year} : %{DATA:HOUR}] [\php5:%{LOGLEVEL:loglevel}] [pid %{POSINT:pid}]( [client %{IP:client}:%{POSINT:clientport}]) %{GREEDYDATA:message}"]

```
  }
}

```

}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 21, 2017, 4:07am UTC](https://discuss.elastic.co/t/logstash-error-read/101231/2 "2017-09-21T04:07:44Z")

</div>

Logstash isn't really designed to read remote mount files like that. Can you install filebeat on the remote host to ship them?

---

<div class="post-metadata">

**Author:** ![Erick\_Garcia\_Perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erick_garcia_perez/32/22244_2.png) [@Erick\_Garcia\_Perez](https://discuss.elastic.co/u/Erick_Garcia_Perez)\
**Post date:** [September 21, 2017, 2:10pm UTC](https://discuss.elastic.co/t/logstash-error-read/101231/3 "2017-09-21T14:10:26Z")

</div>

Hi, i dont install filebeat, only read a log remote with rsync in opensuse

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 24, 2017, 8:27pm UTC](https://discuss.elastic.co/t/logstash-error-read/101231/4 "2017-09-24T20:27:01Z")

</div>

Unless rsync appends new data to the end of the existing files (emulating what a normal log writer would do) you won't be able to use rsync for this purpose.

---

<div class="post-metadata">

**Author:** ![Erick\_Garcia\_Perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erick_garcia_perez/32/22244_2.png) [@Erick\_Garcia\_Perez](https://discuss.elastic.co/u/Erick_Garcia_Perez)\
**Post date:** [September 25, 2017, 12:28am UTC](https://discuss.elastic.co/t/logstash-error-read/101231/5 "2017-09-25T00:28:29Z")

</div>

Ho can i read a remote log?  
The logs are in the server, the server should read the log that is in another machine.  
I trying read de remote log via rsync

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 25, 2017, 5:37am UTC](https://discuss.elastic.co/t/logstash-error-read/101231/6 "2017-09-25T05:37:54Z")

</div>

The best option is to run Filebeat or Logstash on machines where you want to collect logs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2017, 5:38am UTC](https://discuss.elastic.co/t/logstash-error-read/101231/7 "2017-10-23T05:38:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
