# Logstash pipeline for parsing with filebeat module

**URL:** https://discuss.elastic.co/t/logstash-pipeline-for-parsing-with-filebeat-module/203424
**Category:** Beats
**Tags:** filebeat
**Created:** [October 14, 2019, 9:59am UTC](https://discuss.elastic.co/t/logstash-pipeline-for-parsing-with-filebeat-module/203424 "2019-10-14T09:59:51Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)
#### Post date: [October 14, 2019, 9:59am UTC](https://discuss.elastic.co/t/logstash-pipeline-for-parsing-with-filebeat-module/203424/1 "2019-10-14T09:59:51Z")

</div>

Hello Team,

Currently we are using ELK 6.4.0 but now we want to upgrade on ELK 7.4.0 to use SIEM feature. So we are setting up our testing environment first before making change in prod environment.

In ELK version 6.4.0 i have used logstash pipeline for parsing to use the filebeat dashboard because we are using Logstash. I have followed the below link at that time:

[Logstash pipeline](https://www.elastic.co/guide/en/logstash/5.6/logstash-config-for-filebeat-modules.html)

Earlier we have no need to enable filebeat module to use logstash pipeline and its working fine.

In version ELK 7.4.0 i used same approach but it didn't work. Then i search the documentation  
[Logstash pipeline for parsing](https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html)

Form this document i understand that we need to enable the filebeat module also e.g system, nginx etc and then we can use logstash pipeline for parsing but it was not required in earlier version like 6.4.0.  
I am going in right way or not?

Please help me.

Thanks.

---

<div class="post-metadata">

### Author: ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)
#### Post date: [October 15, 2019, 6:19am UTC](https://discuss.elastic.co/t/logstash-pipeline-for-parsing-with-filebeat-module/203424/2 "2019-10-15T06:19:28Z")

</div>

After reading the documentation i am able to implement it.

But filebeat logs are going into `syslog`. I want to send them in `/var/log/filebeat`. I have tried below config in `filebeat.yml`:

```auto
logging.level: info
logging.to_files: true
logging.files:
  path: /var/log/filebeat
  name: filebeat
  keepfiles: 7
  permissions: 0644

```

But still logs are goes into `syslog`

Can you please help me on this issue?

Thanks.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 12, 2019, 7:13am UTC](https://discuss.elastic.co/t/logstash-pipeline-for-parsing-with-filebeat-module/203424/4 "2019-11-12T07:13:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
