# Logstash to collect ES logs and visualize to Kibana

**URL:** <https://discuss.elastic.co/t/logstash-to-collect-es-logs-and-visualize-to-kibana/44526>\
**Category:** Logstash\
**Created:** [March 16, 2016, 8:29am UTC](https://discuss.elastic.co/t/logstash-to-collect-es-logs-and-visualize-to-kibana/44526 "2016-03-16T08:29:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![r.ganeshbabu](https://avatars.discourse-cdn.com/v4/letter/r/4da419/32.png) [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Post date:** [March 16, 2016, 8:29am UTC](https://discuss.elastic.co/t/logstash-to-collect-es-logs-and-visualize-to-kibana/44526/1 "2016-03-16T08:29:06Z")

</div>

Hi All,

We are using Elasticsearch **1.7.3** for our application. Our ES cluster has 3 physical servers with 48 cores of CPU & 256 GB RAM. We are having 3 master nodes, 6 data nodes & 1 client node and having nearly 6 TB of DATA. The cluster has 3 indices es\_chr, es\_cval & es\_item and for es\_chr shard allocated as "1" and for others like es\_cval has "6" and es\_item has "18" primary shards. We have given "2" replicas for all the indices.  
We used marvel for monitoring the cluster and also using shield for authentication purpose. Initial stage we did bulk index for all indices to load the data into ES and then afterwards whenever the changes are happened to the data we normally update the changes through **sync process** to the ES.  
Every day elasticsearch generates own logs files based on the nodes. **How to collect the Elasticsearch logs with the help of logstash and visualize it to kibana?**

Note:- As I am new to logstash and suggest best practices in order to make this possible

Please guide us.

Thanks,  
Ganeshbabu R

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 18, 2016, 2:47am UTC](https://discuss.elastic.co/t/logstash-to-collect-es-logs-and-visualize-to-kibana/44526/2 "2016-03-18T02:47:10Z")

</div>

Looking into my magic crystal ball, it appears that you are a customer(?).  
If so, why not ask the support team about this?

---

<div class="post-metadata">

**Author:** ![r.ganeshbabu](https://avatars.discourse-cdn.com/v4/letter/r/4da419/32.png) [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Post date:** [March 18, 2016, 10:25am UTC](https://discuss.elastic.co/t/logstash-to-collect-es-logs-and-visualize-to-kibana/44526/3 "2016-03-18T10:25:06Z")

</div>

@warkolm

Sure I will 🙂

You have gotta powerful magic crystal ball 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/logstash-to-collect-es-logs-and-visualize-to-kibana/44526/4 "2017-07-06T05:06:29Z")

</div>


