# Logstash to logstash communication - beat.hostname

**URL:** <https://discuss.elastic.co/t/logstash-to-logstash-communication-beat-hostname/227168>\
**Category:** Logstash\
**Created:** [April 8, 2020, 3:34pm UTC](https://discuss.elastic.co/t/logstash-to-logstash-communication-beat-hostname/227168 "2020-04-08T15:34:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mtudisco](https://avatars.discourse-cdn.com/v4/letter/m/3d9bf3/32.png) [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Post date:** [April 8, 2020, 3:34pm UTC](https://discuss.elastic.co/t/logstash-to-logstash-communication-beat-hostname/227168/1 "2020-04-08T15:34:30Z")

</div>

Hi, I'm actually have a configuration with Filebeat sending logs to logstash, then logstash parsing information and sending it to differente pipelines, one of the to elasticsearch. In the parsing i use the field beat.hostname to identify the filebeat host from where the information comes.  
Because of network segmentation, now i need to add a second logstash on the other side of the firewall, and make some hosts with filebeat to send to this logstash, and the this logstash sends information to the central one that does the parsing. So Filebeat on host1 sends logs to logstash on host2, logstash on host2 sends information to logstash on host3.

The question is when host3 receives the information, and its going to parse it, in beat.hostname i get host1 (the real origin of the data) or host2 (the intermediate host), the configuratio i plan to use is the one provided in documentation:

Logstash on host2:

```
input{
          beats {
                     port => 5044 
                     ssl => true
                     ssl_key => 'host2.pkcs8.key'
                     ssl_certificate => 'hos2.crt'
                     ssl_certificate_authorities => ["ca.crt"]
                     ssl_verify_mode => "force_peer"
                    }
}
output { 
               lumberjack { 
                                     codec => json 
                                      hosts => "host3" 
                                      ssl_certificate => "host2.crt" 
                                      port => 5044 
                                     }
}

```

Logstash on host3:

```
input { 
                beats { 
                            codec => json 
                            port => 5044 
                            ssl => true 
                            ssl_certificate => "host3.cert" 
                            ssl_key => "host3.key"
                            ssl_certificate_authorities => ["ca.crt"]
                            ssl_verify_mode => "force_peer"
                          }
              }
    filter {
    #the original code
    }
    output {
    #the original output
    }

```

thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 8, 2020, 4:06pm UTC](https://discuss.elastic.co/t/logstash-to-logstash-communication-beat-hostname/227168/2 "2020-04-08T16:06:05Z")

</div>

What is your question?

---

<div class="post-metadata">

**Author:** ![mtudisco](https://avatars.discourse-cdn.com/v4/letter/m/3d9bf3/32.png) [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Post date:** [April 8, 2020, 4:25pm UTC](https://discuss.elastic.co/t/logstash-to-logstash-communication-beat-hostname/227168/3 "2020-04-08T16:25:32Z")

</div>

The question is when host3 receives the information, and its going to parse it, in beat.hostname i get host1 (the real origin of the data) or host2 (the intermediate host)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 8, 2020, 5:46pm UTC](https://discuss.elastic.co/t/logstash-to-logstash-communication-beat-hostname/227168/4 "2020-04-08T17:46:51Z")

</div>

The [beat][hostname] field is added by filebeat, and unless you wrote a filter to modify it then logstash will pass it on unchanged. So you will get host1 if that is where filebeat runs.

---

<div class="post-metadata">

**Author:** ![mtudisco](https://avatars.discourse-cdn.com/v4/letter/m/3d9bf3/32.png) [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Post date:** [April 8, 2020, 8:09pm UTC](https://discuss.elastic.co/t/logstash-to-logstash-communication-beat-hostname/227168/5 "2020-04-08T20:09:10Z")

</div>

Thanks,  
I was further reading and got some doubts about this configuration.

1. [https://github.com/elastic/ruby-lumberjack](https://github.com/elastic/ruby-lumberjack) says that lumberjack is deprecated, is that correcto or refers to other thing?
2. In the configuration of beats, i use ssl\_certificate, ssl\_key and ssl\_certificate\_authorities but in lumberjack only ssl\_certificate, so how does lumberjack and beats verify the ca certificate?

thanks

---

<div class="post-metadata">

**Author:** ![mtudisco](https://avatars.discourse-cdn.com/v4/letter/m/3d9bf3/32.png) [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Post date:** [April 8, 2020, 10:44pm UTC](https://discuss.elastic.co/t/logstash-to-logstash-communication-beat-hostname/227168/6 "2020-04-08T22:44:36Z")

</div>

i'm having trouble with this configuration, when the intermediate logstash try to connect to the destintion i get:

`[ERROR][logstash.outputs.lumberjack] All hosts unavailable, sleeping {:hosts=>["192.168.90.87"], :e=>#<OpenSSL::SSL::SSLError: Connection reset by peer>`

I have generate a ca and certifiecates signed by that ca with elasticsearch-certutil.

Does anyone has made lumberjack to beats work?

thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2020, 10:44pm UTC](https://discuss.elastic.co/t/logstash-to-logstash-communication-beat-hostname/227168/7 "2020-05-06T22:44:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
