# LoLogs are not coming from filebeat to logstash to elasticsearch

**URL:** <https://discuss.elastic.co/t/lologs-are-not-coming-from-filebeat-to-logstash-to-elasticsearch/330509>\
**Category:** Logstash\
**Created:** [April 21, 2023, 10:17am UTC](https://discuss.elastic.co/t/lologs-are-not-coming-from-filebeat-to-logstash-to-elasticsearch/330509 "2023-04-21T10:17:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [April 21, 2023, 10:17am UTC](https://discuss.elastic.co/t/lologs-are-not-coming-from-filebeat-to-logstash-to-elasticsearch/330509/1 "2023-04-21T10:17:23Z")

</div>

Hi, I have installed filebeat on my windows machine. I've enabled the systema nd logstash module.  
Here is the filebeat.yml

```auto
- type: filestream

  # Unique ID among all inputs, an ID is required.
  id: my-filestream-id

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - C:\ProgramData\filebeat\logs\*
  fields:
    type: windows_log
  fields_under_root: true

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: false

output.logstash:
  # The Logstash hosts
  hosts: ["logstash-ip:5044"]

```

```auto
 .\filebeat -e -c "C:\Program Files\Filebeat\filebeat.yml" test output
{"log.level":"info","@timestamp":"2023-04-21T12:47:01.489+0530","log.origin":{"file.name":"instance/beat.go","file.line":724},"message":"Home path: [C:\\Program Files\\Filebeat] Config path: [C:\\Program Files\\Filebeat] Data path: [C:\\Program Files\\Filebeat\\data] Logs path: [C:\\Program Files\\Filebeat\\logs]","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2023-04-21T12:47:01.490+0530","log.origin":{"file.name":"instance/beat.go","file.line":732},"message":"Beat ID: cea733d5-40bd-4c1e-adad-0041a5258c1f","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"warn","@timestamp":"2023-04-21T12:47:04.522+0530","log.logger":"add_cloud_metadata","log.origin":{"file.name":"add_cloud_metadata/provider_aws_ec2.go","file.line":81},"message":"read token request for getting IMDSv2 token returns empty: Put \"http://169.254.169.254/latest/api/token\": context deadline exceeded (Client.Timeout exceeded while awaiting headers). No token in the metadata request will be used.","service.name":"filebeat","ecs.version":"1.6.0"}
logstash: LOGSTASH:5044...
  connection...
    parse host... OK
    dns lookup... OK
    addresses: LOGSTASH IP
    dial up... OK
  TLS... WARN secure connection disabled
  talk to server... OK

```

Here is my logstash pipeline conf file

```auto
input {
  beats {
    port => 5044
  }
}

output {
  elasticsearch {
    hosts => "http://elasticsearch-ip:9200"
    index => "test%{+YYYY.MM.dd}"
    user => "usr"
    password => "pwd"
  }
}

```

When i start logstash the status shows active.  
But the logs are not coming

Here is the status of logstash service

```auto
![image|690x316](upload://q67HPWFDx8kOwk2G8GfjfwxtFLf.png)

```

There are no logs on elasticsearch index

If i run logstash in debug mode  
/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/first\_pipeline.conf --debug

I am getting address already in use. Even after i kill the other logstash process

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2023, 10:17am UTC](https://discuss.elastic.co/t/lologs-are-not-coming-from-filebeat-to-logstash-to-elasticsearch/330509/2 "2023-05-19T10:17:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
