# Logstash VS Filebeat

**URL:** <https://discuss.elastic.co/t/logstash-vs-filebeat/124988>\
**Category:** Logstash\
**Created:** [March 21, 2018, 12:50pm UTC](https://discuss.elastic.co/t/logstash-vs-filebeat/124988 "2018-03-21T12:50:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vigneshprasanna](https://avatars.discourse-cdn.com/v4/letter/v/a3d4f5/32.png) [@Vigneshprasanna](https://discuss.elastic.co/u/Vigneshprasanna)\
**Post date:** [March 21, 2018, 12:50pm UTC](https://discuss.elastic.co/t/logstash-vs-filebeat/124988/1 "2018-03-21T12:50:55Z")

</div>

HI,

I have a doubt why i should use a file beat ?? what is the use of file beat ?? when logstash is able to fetch to fetch the logs.

let me describe a scenario

i have an application running in the server (A) and its log is generated in the folder ALOG  
my ELK is running in a server (B)  
then i can use the "source " part of the logstash to fetch the log that is generated in the server A in the folder ALOG by jest doing a SSL between the server.

please help me to understand why i need filebeat when i have logstash in the Architecture.

thanks in advance

Regards,  
Vigneshprasanna R

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 21, 2018, 6:48pm UTC](https://discuss.elastic.co/t/logstash-vs-filebeat/124988/2 "2018-03-21T18:48:32Z")

</div>

You should use Filebeat if your log file _is not on the same machine_ running Logstash, which seems to be your case.

Your log file is in the **Server A** and your Logstash is running in the **Server B** , so you will need to send your log to Logstash in some way, one of the ways to send the data in the log file is using Filebeat.

---

<div class="post-metadata">

**Author:** ![Vigneshprasanna](https://avatars.discourse-cdn.com/v4/letter/v/a3d4f5/32.png) [@Vigneshprasanna](https://discuss.elastic.co/u/Vigneshprasanna)\
**Post date:** [March 22, 2018, 2:55am UTC](https://discuss.elastic.co/t/logstash-vs-filebeat/124988/3 "2018-03-22T02:55:07Z")

</div>

HI,

what I’m not understanding is that why I should use file beat instead of giving permission to logstash "Source" to get the logs from the server **"A"** by doing a SSL or any of the methods given in the below link  
"[https://www.elastic.co/guide/en/logstash/current/ls-security.html](https://www.elastic.co/guide/en/logstash/current/ls-security.html)"

What is the great advantage of using file beat with logstash is it going to give a level of security while transferring the log data?? Or any level of comfort for hand shake within two servers?? Why file beat??

Please help me in understanding

---

<div class="post-metadata">

**Author:** ![xmatt](https://avatars.discourse-cdn.com/v4/letter/x/5daacb/32.png) [@xmatt](https://discuss.elastic.co/u/xmatt)\
**Post date:** [March 22, 2018, 4:14am UTC](https://discuss.elastic.co/t/logstash-vs-filebeat/124988/4 "2018-03-22T04:14:37Z")

</div>

Hi there, I think you are confused. The article you have linked has nothing to do with sending logs into Logstash and everything to do with Logstash sending into Elasticsearch.

Filebeat is a brilliant, light-weight application that runs on all your servers that you want to send logs FROM. You send from Filebeat TO Logstash, covered by TLS. The Filebeat agent can be pointed at log files and then it will "tail" the file, sending all entries made to that file to your Logstash server, securely. It will also follow logrotated files!

Here's a great link that I followed some time ago. These are old versions of ELK that they're talking about but the configuration about Filebeat to Logstash is still relevant to your question and talks you through both options of creating a TLS Certificate pair (if you use DNS or if you use IP address).

> **[How To Install Elasticsearch, Logstash, and Kibana (ELK Stack) on Ubuntu 14.04 |...](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-04)**
>
> In this tutorial, we will go over the installation of the Elasticsearch ELK Stack on Ubuntu 14.04—that is, Elasticsearch 2.2.x, Logstash 2.2.x, and Kibana 4.4.x. We will also show you how to configure it to gather and visualize the syslogs of your...

Best of luck!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2018, 4:14am UTC](https://discuss.elastic.co/t/logstash-vs-filebeat/124988/5 "2018-04-19T04:14:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
