# Logstash Filebeat input

**URL:** <https://discuss.elastic.co/t/logstash-filebeat-input/251992>\
**Category:** Logstash\
**Created:** [October 14, 2020, 5:59am UTC](https://discuss.elastic.co/t/logstash-filebeat-input/251992 "2020-10-14T05:59:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jafri6](https://avatars.discourse-cdn.com/v4/letter/j/d26b3c/32.png) [@jafri6](https://discuss.elastic.co/u/jafri6)\
**Post date:** [October 14, 2020, 5:59am UTC](https://discuss.elastic.co/t/logstash-filebeat-input/251992/1 "2020-10-14T05:59:52Z")

</div>

My goal is to setup filebeat on at least 5 systems, and get the data to elasticsearch via logstash.

I imported data via the file plugin earlier for one of my trials, and the data was imported successfully.

I tried the same thing this time with beats input plugin, and I am not receiving the same number of records from the files. Also it added over 100k records with the following tags: `beats_input_codec_plain_applied, _grokparsefailure, _dateparsefailure`

How can I fix this?

---

<div class="post-metadata">

**Author:** ![mastersmit](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@mastersmit](https://discuss.elastic.co/u/mastersmit)\
**Post date:** [October 14, 2020, 6:38am UTC](https://discuss.elastic.co/t/logstash-filebeat-input/251992/2 "2020-10-14T06:38:38Z")

</div>

\_grokparsefailure, \_dateparsefailure

This tags denotes that there is some processing that failed, could you share your logstash snap and also ensure your GROK pattern are correctly configured.

---

<div class="post-metadata">

**Author:** ![jafri6](https://avatars.discourse-cdn.com/v4/letter/j/d26b3c/32.png) [@jafri6](https://discuss.elastic.co/u/jafri6)\
**Post date:** [October 15, 2020, 11:55am UTC](https://discuss.elastic.co/t/logstash-filebeat-input/251992/4 "2020-10-15T11:55:12Z")

</div>

So I am facing a different set of issue every time I try to implement filebeat.

```
input {
	beats {
		port => "5044"
#	codec => "plain"
	}

```

So when I use this input method, without the codec line, all the data I am receiving is in escape characters. When I do add the codec plain. it is returning my data with the 3 tags mentioned above.  
I just simply want to load the log files that I have like I do with file input method -\>

```
   file {
            path => "/home/latech/kcpfinal/*/*.log"
            start_position => "beginning"
            sincedb_path => "/dev/null"
    }

```

What can I do to fix this?

---

<div class="post-metadata">

**Author:** ![jafri6](https://avatars.discourse-cdn.com/v4/letter/j/d26b3c/32.png) [@jafri6](https://discuss.elastic.co/u/jafri6)\
**Post date:** [October 19, 2020, 9:36am UTC](https://discuss.elastic.co/t/logstash-filebeat-input/251992/5 "2020-10-19T09:36:39Z")

</div>

I am not sure what exactly caused the issue that resulted in the \_grokparsefailure and \_dateparesefailure.

I did a clean install of elk on another server, and used the same configuration files and same data and it worked. The logstash config input is beats {port =\> 5044} and it automatically applied the logstash-codec-plain and parsed all data with 0 errors.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2020, 9:36am UTC](https://discuss.elastic.co/t/logstash-filebeat-input/251992/6 "2020-11-16T09:36:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
