# Make logstash send logs via lumberjack to logstash

**URL:** <https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261>\
**Category:** Logstash\
**Created:** [June 9, 2015, 11:29pm UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261 "2015-06-09T23:29:25Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jerry\_Hoffmeister](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@Jerry\_Hoffmeister](https://discuss.elastic.co/u/Jerry_Hoffmeister)\
**Post date:** [June 9, 2015, 11:29pm UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/1 "2015-06-09T23:29:25Z")

</div>

I'd like to send logs, jmx data and collectd data to a central elasticsearch server from several clients. I've setup collectd on the client to send data to LS running on the ES server and that works just fine. I can setup logstash-forwarder to send logs to LS on the ES server and that works just fine. Haven't tried it yet but I know to send jmx data, I need to use LS to send to LS on ES so I've tried to configure LS instead of logstash-forwarder to send the logs. I'm able to get logs but can't figure out how to setup the config so I'm able to filter them. lumberjack on sent by LS as opposed to logstash-forwarder doesn't seem to be as rich? How can I even set the type for several different log files so I can parse / filter them? I can set the type when I receive them in LS but they then all get the same type (I can't differentiate between say the apache access and apache error logs).

Or is there a better way?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 10, 2015, 1:32am UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/2 "2015-06-10T01:32:56Z")

</div>

You can send each to a different port and assign a type there or you can use grok to match a specific pattern for each and then apply a type.

---

<div class="post-metadata">

**Author:** ![Jerry\_Hoffmeister](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@Jerry\_Hoffmeister](https://discuss.elastic.co/u/Jerry_Hoffmeister)\
**Post date:** [June 10, 2015, 1:54am UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/3 "2015-06-10T01:54:11Z")

</div>

but not something simple like on the client logstash-forwarder config:

```
{
  "paths": [
    "/var/log/apache2/access.log"
  ],

  "fields": { "type": "apache-access" }
}

```

then on the server:

filter {  
if [type] == "apache-access" {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
date {  
match =\> ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 10, 2015, 2:22am UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/4 "2015-06-10T02:22:29Z")

</div>

Yes, you can do that. Check [the docs](https://github.com/elastic/logstash-forwarder) for more.

---

<div class="post-metadata">

**Author:** ![Jerry\_Hoffmeister](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@Jerry\_Hoffmeister](https://discuss.elastic.co/u/Jerry_Hoffmeister)\
**Post date:** [June 10, 2015, 4:58am UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/5 "2015-06-10T04:58:31Z")

</div>

Yes, you can do that with the logstash-forwarder but I want to do it with the lumberjack output plugin for logstash - I don't want to run both on the same client. I need to run logstash if I want to send more than just logs to ES (jmx data for example).

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 10, 2015, 6:39am UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/6 "2015-06-10T06:39:48Z")

</div>

Set the type at the origin, i.e. in the input plugin:

```
input {
  path => "/var/log/apache2/access.log"
  type => "apache-access"
}
```

---

<div class="post-metadata">

**Author:** ![Jerry\_Hoffmeister](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@Jerry\_Hoffmeister](https://discuss.elastic.co/u/Jerry_Hoffmeister)\
**Post date:** [June 10, 2015, 1:21pm UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/7 "2015-06-10T13:21:44Z")

</div>

I tried that but the type didn't come thru once it got to the other side. I'm probably missing something fundamental... Once I get to the office, I'll include all the details of what happens when I tried that and what my config looked like.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 10, 2015, 2:15pm UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/8 "2015-06-10T14:15:33Z")

</div>

Wild guess: You're using the plain codec. Use the json codec at both ends instead.

---

<div class="post-metadata">

**Author:** ![Jerry\_Hoffmeister](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@Jerry\_Hoffmeister](https://discuss.elastic.co/u/Jerry_Hoffmeister)\
**Post date:** [June 10, 2015, 3:07pm UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/9 "2015-06-10T15:07:53Z")

</div>

Yup - let me try that... I'll get back once I get to the office and try...

---

<div class="post-metadata">

**Author:** ![Jerry\_Hoffmeister](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@Jerry\_Hoffmeister](https://discuss.elastic.co/u/Jerry_Hoffmeister)\
**Post date:** [June 10, 2015, 5:07pm UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/10 "2015-06-10T17:07:48Z")

</div>

Thank you thank you that's just what I needed / was missing. Now I can play with the filters and get what I want 😄 Much appreciated!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:37am UTC](https://discuss.elastic.co/t/make-logstash-send-logs-via-lumberjack-to-logstash/2261/11 "2017-07-06T05:37:51Z")

</div>


