# Logstash Not able to listen events from Filebeats

**URL:** <https://discuss.elastic.co/t/logstash-not-able-to-listen-events-from-filebeats/94660>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 26, 2017, 3:32pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-listen-events-from-filebeats/94660 "2017-07-26T15:32:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![SandhyaRani](https://avatars.discourse-cdn.com/v4/letter/s/8dc957/32.png) [@SandhyaRani](https://discuss.elastic.co/u/SandhyaRani)\
**Post date:** [July 26, 2017, 3:32pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-listen-events-from-filebeats/94660/1 "2017-07-26T15:32:04Z")

</div>

Hi there!

I'm trying to send logs through filebeats to logstash,  
I have:  
Logstash--on local machine  
filebeat-on local machine  
Elastic search---on host machine(server)

In filebeat.yml I enabled logstash output.  
My filebeat.yml  
================================  
filebeat.prospectors:  
- input\_type: log

```
  paths:
    - /home/sandhyarani/Downloads/logstash-5.4.1/bin/*.log
    
#-------------------------- Elasticsearch output ------------------------------
#output.elasticsearch:
  # Array of hosts to connect to.
   #hosts: ["xx.xx.xxx.xx:9200"] # Optional protocol and basic auth credentials.
  #protocol: "https"
  #username: "elastic"
  #password: "changeme"#----------------------------- Logstash output --------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["localhost:5044"] # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  #ssl.certificate_authorities: ["/etc/pki/root/ca.pem"] # Certificate for SSL client authentication
  #ssl.certificate: "/etc/pki/client/cert.pem" # Client Certificate Key
  #ssl.key: "/etc/pki/client/cert.key"#================================ 

Logstash Conf file:
    =========================================================
                input {
                    stdin {
                      
                    }
                }filter {
                    
                    mutate{ add_field => { "Source" => "SKY"}
                      }
                    
                    environment{
                        add_field => ["my_environment", "Hello World, from %{host}"]
                        }
                    if "exception" not in [tags] { # example output:
                        grok {
                            match => {
                                message => "%{DATESTAMP:timestamp} %{LOGLEVEL:level}( +)\[%{DATA:thread}\] \[%{DATA:mdc}\] %{JAVACLASS:class} - %{JAVALOGMESSAGE:logmessage}"
                    #message => "%{DATESTAMP:timestamp} %{LOGLEVEL:level}( +)\[%{DATA:thread}\] \[%{DATA:mdc}\] %{JAVACLASS:class} - %{GREEDYDATA:logmsg}"
                            }
                            add_tag => ["log"]
                      
                        } if "log" in [tags] { grok {
                                match => {
                                    mdc => "%{DATA:username}:%{DATA:deviceId:int}:%{DATA:sessionId}:%{DATA:userInteraction:int}:%{GREEDYDATA:workflowName}"
                                }
                            }
                            date {
                                timezone => GMT
                                match => [
                                               # "16-12-16 21:58:20,606"
                                    "timestamp", "yy-MM-dd HH:mm:ss,SSS"
                                ]
                            } } }
                    if [level] in ["ERROR", "error"] or [level] in ["FATAL", "fatal"]{
                        mutate {
                            add_tag => ["alert"]
                        }
                    }
                   
                   
                 if [level] in ["TRACE", "trace"] {
                        mutate {
                        replace => {
                        "level" => "%{level}, 0"
                        }
                      }
                    }
                     
                    else if [level] in ["DEBUG", "debug"]{
                        mutate {
                            replace => {
                            "level" => "%{level}, 1"
                        }
                        }
                    }
                   else if [level] in ["INFO", "info"]{
                        mutate {
                            replace => {
                            "level" => "%{level}, 2"
                        }
                        }
                    }
                    else if [level] in ["WARN", "warn"]{
                        mutate {
                            replace => {
                            "level" => "%{level}, 3"
                        }
                        }
                    }
                    else if [level] in ["ERROR", "error"]{
                        mutate {
                            replace => {
                            "level" => "%{level}, 4"
                        }
                        }
                    }
                        else if [level] in ["FATAL", "fatal"]{
                        mutate {
                            replace => {
                            "level" => "%{level}, 5"
                        }
                        }
                    }}
                output {
                    if "_grokparsefailure" in [tags] {
                        stdout { codec => rubydebug {metadata => true }}
                    }
                if "log" in [tags]{
                if "ERROR" in [level]{
                    elasticsearch { hosts => ["xxx.xxx.xxx.com"] }
                }
                else if "WARN" in [level]{
                    elasticsearch { hosts => ["xxx.xxx.xxx.com"] }
                }
                else if "INFO" in [level]{
                    elasticsearch { hosts => ["xxx.xxx.xxx.com"] }
                }
                else if "FATAL" in [level]{
                    elasticsearch { hosts => ["xxx.xxx.xxx.com"] }
                }
                }
                }

```

I enabled logstash output in filebeat.yml:  
when i run filebeat its showing this

 ![](https://us1.discourse-cdn.com/elastic/original/3X/3/0/302ca364a86fc93ea2c330b9dfc84d56d8be3b5f.png)

Could any one help with this?

Thanks!

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [July 26, 2017, 8:55pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-listen-events-from-filebeats/94660/2 "2017-07-26T20:55:25Z")

</div>

It seems to me that Filebeat has already read the log files and saved the states in the registry file. But if you delete the registry file (its path is in the second line of your Filebeat output), all the log files will be read again and sent to Logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2017, 8:55pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-listen-events-from-filebeats/94660/3 "2017-08-23T20:55:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
