# Lostash taking inputs from Filebeat

**URL:** <https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740>\
**Category:** Logstash\
**Created:** [June 20, 2018, 5:04pm UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740 "2018-06-20T17:04:00Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)\
**Post date:** [June 20, 2018, 5:04pm UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740/1 "2018-06-20T17:04:00Z")

</div>

Hi Team,

Can anyone provide me the configuration file, Where the logstash will be taking input from Filebeat port and creating the same files as output in logstash .

Ex : input \> filebeat text file  
output \> logstash text file

TIA

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 20, 2018, 8:19pm UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740/2 "2018-06-20T20:19:15Z")

</div>

Filebeat will populate a field with the name of the file from which the line was read. You can reference that field in the `path` option of a file output. I suggest you use a `stdout { codec => rubydebug }` output to dump the raw events while you're experimenting with this.

---

<div class="post-metadata">

**Author:** ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)\
**Post date:** [June 21, 2018, 12:28pm UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740/3 "2018-06-21T12:28:39Z")

</div>

this is the code i am using,

input  
{  
beats  
{  
port =\> 5044  
ignore\_older =\>0  
}  
}  
output  
{  
stdout{ codec=\> rubydebus}  
file{  
path = "data\filebeat\logstash.txt"  
}  
}

But i am facing error as Logstash configuration error .Is this the right code or should i write some more logic to it

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 21, 2018, 12:41pm UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740/4 "2018-06-21T12:41:17Z")

</div>

> But i am facing error as Logstash configuration error

**Always** post the exact error message.

---

<div class="post-metadata">

**Author:** ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)\
**Post date:** [June 25, 2018, 5:20am UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740/5 "2018-06-25T05:20:05Z")

</div>

This is the error which i am facing,

And this is the code i am running in logstash

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/9/99cd8639b05322371289c8c2f5047b158efc1a12.png)

Please help me to resolve this issue. I want logstash to read the files which filebeat is passing and want to store in logstash with the same format as filebeat.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 25, 2018, 7:53am UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740/6 "2018-06-25T07:53:26Z")

</div>

Please don't post screenshots. Use copy/paste of the text.

Here's the error message:

> Unknown setting "ignore\_older" for beats

As the message indicates the beats plugin doesn't have an option with that name. The documentation lists all valid options.

---

<div class="post-metadata">

**Author:** ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)\
**Post date:** [June 28, 2018, 12:00pm UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740/7 "2018-06-28T12:00:15Z")

</div>

I removed ignore\_older option , yet i am not able to reach a solution .

My doubt is "Is logstash can really take the .txt or .log files as input from filebeat and save it in logstash output folder as same format "

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 29, 2018, 6:19am UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740/8 "2018-06-29T06:19:05Z")

</div>

> I removed ignore\_older option , yet i am not able to reach a solution .

Look, this will take twice as long if I have to ask for additional details every time you ask a question.

> My doubt is "Is logstash can really take the .txt or .log files as input from filebeat and save it in logstash output folder as same format "

Yes it can.

---

<div class="post-metadata">

**Author:** ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)\
**Post date:** [June 29, 2018, 6:40am UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740/9 "2018-06-29T06:40:30Z")

</div>

> [@magnusbaeck](#):
>
> Yes it can

Thanks Magnus, Will try my best then 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2018, 6:40am UTC](https://discuss.elastic.co/t/lostash-taking-inputs-from-filebeat/136740/10 "2018-07-27T06:40:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
