# Lumberjack plugin

**URL:** <https://discuss.elastic.co/t/lumberjack-plugin/230809>\
**Category:** Logstash\
**Created:** [May 2, 2020, 2:07pm UTC](https://discuss.elastic.co/t/lumberjack-plugin/230809 "2020-05-02T14:07:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![PraveenKT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praveenkt/32/35483_2.png) [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Post date:** [May 2, 2020, 2:07pm UTC](https://discuss.elastic.co/t/lumberjack-plugin/230809/1 "2020-05-02T14:07:56Z")

</div>

I am trying to send Metricbeat ----\> Logstash-1 -------\> Logstash-2 -------\> Elasticsearch.  
I tried both tcp and Lumberjack protocols. Successfully start both logstshes but not found data in elasticsearch.  
``````````lOGSTASH configuration using Lumberjack:``````````````````````  
LOGSTASH-1 OUTPUT

output {  
lumberjack {  
codec =\> json  
hosts =\> ["X.X.X.X"]  
port =\> 5044  
ssl\_certificate =\> "/etc/logstash/conf.d/ca.crt"  
}  
}

LOGSTASH-2 CONFIGURATION::

input {  
beats {  
codec =\> json  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/logstash/conf.d/USLA-PAPP-ELK03.crt"  
ssl\_key =\> "/etc/logstash/conf.d/pkcs8.key"  
}  
}  
output {  
elasticsearch {  
hosts =\> ["node3:9200"]  
manage\_template =\> "false"  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}"  
user =\> "elastic"  
password =\> "xxxxxx"  
}  
}

```auto

I am not able to see the data in kibana. Please help me. I tried both jason and json_lines but no luck.

How do i test logstash-1 sending data to logstash-2 and then to elasticsearch?

Issues until i resolved while using Lumberjack;
- no vaild key error: assign cert and keys to logstash user permission
- use ca cert in logstash-1 output for ssl and http error.
```

---

<div class="post-metadata">

**Author:** ![PraveenKT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praveenkt/32/35483_2.png) [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Post date:** [May 3, 2020, 10:50pm UTC](https://discuss.elastic.co/t/lumberjack-plugin/230809/2 "2020-05-03T22:50:26Z")

</div>

While sending Logstash to logstash using Lumberjack below are few things to must be consider. For me it is working.

BEATS --\>LOGSTASH-1 ---\> LOGSTASH-2 ---\>ELASTICSEARCH

Generate certs for Logstash-2 input, use same certificate in Logstash-1 output.  
Use logstash-2 ip address in Logstash-1 output.  
After copying certs give the same file permissions as other files in /etc/logstash/conf.d/  
Use the same port number in Logstash-1 input and output.  
Use Beats input in Logstash-2.  
Write your own config like input, filters in logstash-1 and filters, output in logstash-2.

Note: Follow the Logstash to logstash documentation in Elastic website.

---

<div class="post-metadata">

**Author:** ![PraveenKT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praveenkt/32/35483_2.png) [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Post date:** [May 7, 2020, 7:18pm UTC](https://discuss.elastic.co/t/lumberjack-plugin/230809/3 "2020-05-07T19:18:32Z")

</div>

openssl pkcs8 -v1 "PBE-SHA1-3DES" -in "ingeststar-key.pem" -topk8 -out "pkcs8.key" -nocrypt

another solution/reason for issue private key is invalid.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2020, 7:33pm UTC](https://discuss.elastic.co/t/lumberjack-plugin/230809/4 "2020-06-04T19:33:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
