# Logstash not shipping data to Elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376>\
**Category:** Logstash\
**Created:** [February 23, 2023, 10:41pm UTC](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376 "2023-02-23T22:41:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Technolust](https://avatars.discourse-cdn.com/v4/letter/t/dbc845/32.png) [@Technolust](https://discuss.elastic.co/u/Technolust)\
**Post date:** [February 23, 2023, 10:41pm UTC](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376/1 "2023-02-23T22:41:48Z")

</div>

How do I get logstash to ship data to Elasticsearch? I'm not sure what to change in the logstash.yml file or what section I should change for that matter. My pipelines.yml points to /etc/logstash/conf.d/syslog.conf... This file is pointing to my elasticsearch.

Maybe I'm confused as to the purpose of the logstash.yml vs the syslog.conf.

Any clarification would be amazing because the documentation is impossible to follow...

Thanks,

Joe

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 25, 2023, 6:48pm UTC](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376/2 "2023-02-25T18:48:13Z")

</div>

logstash.yml - parameters related how will LS run, batch size, log info/debug/..., xpack settings etc.  
syslog.conf - configuration related to data processing - input, filter, output.

As always said, and again... add debug in output:

```auto
output {
    elasticsearch {
      hosts => ["http://server:9200"]
      index => "indexname"
    } 

    stdout {codec => rubydebug}
}

```

1. Check is there any data displayed in the command line. Start LS as process not as service.
2. Check does your data come to LS  
`curl http://localhost:9200/_nodes/stats/pipelines?pretty`
3. If there is no data, make another syslog-nofiltering.conf

```auto
input { ... same, copy from /etc/logstash/conf.d/syslog.conf ... }
filter {} # emty, no filtering
output { stdout {codec => rubydebug} }

```

1. Use tcpdump to dump network data for your port.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 25, 2023, 7:50pm UTC](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376/3 "2023-02-25T19:50:43Z")

</div>

> [@Technolust](#):
>
> Maybe I'm confused as to the purpose of the logstash.yml vs the syslog.conf.

`logstash.yml` is the overall configurations of logstash

conf files like ` syslog.conf` are where you describe the input, logic, and output of the actual data processing the "pipelines" that get executed in logstash

There is 1 `logstash.yml` there can be many `.conf` pipeline files

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2023, 7:51pm UTC](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376/4 "2023-03-25T19:51:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
