# Logstash is not outputing the data to elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 14, 2016, 10:26pm UTC](https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574 "2016-07-14T22:26:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![dubul](https://avatars.discourse-cdn.com/v4/letter/d/9f8e36/32.png) [@dubul](https://discuss.elastic.co/u/dubul)\
**Post date:** [July 14, 2016, 10:26pm UTC](https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574/1 "2016-07-14T22:26:30Z")

</div>

io/console not supported; tty will not be manipulated  
Settings: Default pipeline workers: 4  
←[31mConnection refused: connect {:class=\>"Manticore::SocketException", :level=\>:error}←[0m  
Pipeline main started

===========\>\>\>\>\>\>\>\>\>\>\>\>\>\>\>\>\>\>\>\>,\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<\<================``  
here is the logstash.conf

input {  
beats {  
port =\> 5044  
}  
}

output {  
elasticsearch {  
hosts =\> "10.32.12.22:9200"  
}  
file {  
path =\> "E:\logs\testing"  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 14, 2016, 11:35pm UTC](https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574/2 "2016-07-14T23:35:13Z")

</div>

> [@dubul](#):
>
> Connection refused

Can you connect to ES? `curl 10.32.12.22:9200`.

---

<div class="post-metadata">

**Author:** ![dubul](https://avatars.discourse-cdn.com/v4/letter/d/9f8e36/32.png) [@dubul](https://discuss.elastic.co/u/dubul)\
**Post date:** [July 14, 2016, 11:38pm UTC](https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574/3 "2016-07-14T23:38:29Z")

</div>

@warkolm I have installed elk on single server. I'm trying to ship the data from other windows machine to elk server using filebeat

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 14, 2016, 11:49pm UTC](https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574/4 "2016-07-14T23:49:58Z")

</div>

Right, well maybe if you post your beats config we can help more 🙂

---

<div class="post-metadata">

**Author:** ![dubul](https://avatars.discourse-cdn.com/v4/letter/d/9f8e36/32.png) [@dubul](https://discuss.elastic.co/u/dubul)\
**Post date:** [July 14, 2016, 11:56pm UTC](https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574/5 "2016-07-14T23:56:30Z")

</div>

filebeat:

# List of prospectors to fetch data.

prospectors:  
# Each - is a prospector. Below are the prospector specific configurations  
-  
paths:  
#- /var/log/\*.log  
- E:\Application\logs\*.log  
#- c:\programdata\elasticsearch\logs\*

```
  # Configure the file encoding for reading files with international characters
  # following the W3C recommendation for HTML5 (http://www.w3.org/TR/encoding).
  # Some sample encodings:
  # plain, utf-8, utf-16be-bom, utf-16be, utf-16le, big5, gb18030, gbk,
  # hz-gb-2312, euc-kr, euc-jp, iso-2022-jp, shift-jis, ...
  #encoding: plain

  # Type of the files. Based on this the way the file is read is decided.
  # The different types cannot be mixed in one prospector
  #
  # Possible options are:
  # * log: Reads every line of the log file (default)
  # * stdin: Reads the standard in
  input_type: log

```

registry\_file: "C:/ProgramData/filebeat/registry"  
Output  
logstash:  
# The Logstash hosts  
hosts: ["10.32.12.22:5044"]

---

<div class="post-metadata">

**Author:** ![dubul](https://avatars.discourse-cdn.com/v4/letter/d/9f8e36/32.png) [@dubul](https://discuss.elastic.co/u/dubul)\
**Post date:** [July 15, 2016, 12:02am UTC](https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574/6 "2016-07-15T00:02:00Z")

</div>

@warkolm  
just changed the logstash host output in the config and path of prospectors in the filebeat.yml. Everything is same

---

<div class="post-metadata">

**Author:** ![dubul](https://avatars.discourse-cdn.com/v4/letter/d/9f8e36/32.png) [@dubul](https://discuss.elastic.co/u/dubul)\
**Post date:** [July 15, 2016, 3:13am UTC](https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574/7 "2016-07-15T03:13:01Z")

</div>

@warkolm Thanks for your response

I have changed the output to elasticsearch in filebeat.yml. I dont see any index on elasticsearch and kibana.  
i have started filebeat by using the command ./filebeat -e -c filebeat.yml -d "publish". I can see it publishing events, but i dont find it on the elasticsearch and kibana.

I want to move the file with logs on machine A to machine B[elk server]. Can Anyone help me out in solving the issue. I want to move the logs from the machine A to elk server and get stored and displayed on kibana.

Can anyone guide me in this, and how to give the path for this log files to get stored in elk server ( for example i want to store it in F:\logs.

execuse me for the bad presentation if i'm wrong.

---

<div class="post-metadata">

**Author:** ![medcl.net](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/medcl.net/32/4414_2.png) [@medcl.net](https://discuss.elastic.co/u/medcl.net)\
**Post date:** [July 25, 2016, 12:35pm UTC](https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574/8 "2016-07-25T12:35:39Z")

</div>

Hi, @dubul  
the first thing you may try is to make sure elasticsearch is working well, can you check out the by

```auto
curl 10.32.12.22:9200

```

it should return the version info of elasticsearch,please make sure that.

and you want to store log files in elk server, actually the log fils will stored into elasticsearch, kibana doesn't store logs, kibana read logs from elasticsearch, elasticsearch have its own storage and format, like`elasticsearch/data` it depends how you installed it, you can search elasticsearch by call "\_search" api, like,

```auto
curl 10.32.12.22:9200/_search

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2016, 10:27pm UTC](https://discuss.elastic.co/t/logstash-is-not-outputing-the-data-to-elasticsearch/55574/9 "2016-08-04T22:27:01Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
