# Need Direction on how to proceed forward with Filebeat, Logstash and Kibana

**URL:** <https://discuss.elastic.co/t/need-direction-on-how-to-proceed-forward-with-filebeat-logstash-and-kibana/85464>\
**Category:** Beats\
**Created:** [May 11, 2017, 6:39pm UTC](https://discuss.elastic.co/t/need-direction-on-how-to-proceed-forward-with-filebeat-logstash-and-kibana/85464 "2017-05-11T18:39:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Delly](https://avatars.discourse-cdn.com/v4/letter/d/85f322/32.png) [@Delly](https://discuss.elastic.co/u/Delly)\
**Post date:** [May 11, 2017, 6:39pm UTC](https://discuss.elastic.co/t/need-direction-on-how-to-proceed-forward-with-filebeat-logstash-and-kibana/85464/1 "2017-05-11T18:39:32Z")

</div>

Hi, I am a newbie on ELK. I am trying to get all my logs in formatted form in Kibana. For this, I had stored some sample logs in Local Directory (C:\logs). I had setup Elasticsearch, Logstash and Kibana on the same machine (since I am in testing stage). I also setup a filebeat on the same machine too. Now I am able to fetch data from the logs in Kibana with filebeat-\* as index. But the default output of Kibana is not what I wanted, I need some customized output there. I am lost here and need direction on how to go ahead on these following questions.  
I want to create index and the fields by myself (default one is filebeat-\*), where do I need to make changes, is it logstash.json, or filebeat.yml?  
I need to run the elasticsearch queries on those data retrieved from filebeat, what is the best way of doing that?

My log looks like this:  
2017-05-07 20:03:31.8752: ZAP (Id = ZAA-22, EP = 1.1.1.1) - Fatal error.  
Something Occured

Desired Output:  
TimeStamp: 2017-05-07 20:03:31.8752  
Type: ZAP  
Id: ZAA-22  
HostIP: 1.1.1.1  
Error: Fatal error  
Message: Something Occured

This looks like a generic kind of question, but I think lot of Starters like me will be benefited from this.  
Thank you in advance.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 11, 2017, 7:03pm UTC](https://discuss.elastic.co/t/need-direction-on-how-to-proceed-forward-with-filebeat-logstash-and-kibana/85464/2 "2017-05-11T19:03:14Z")

</div>

You should have a look at the [Logstash Getting Started Guide](https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html).

You'll read the log lines with Filebeat and ship them to Logstash. Then in Logstash you can use a series of filters, including [grok](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) and [date](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html), to parse and enrich the data from your logs and create the desired fields. Then ship the data to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2017, 6:46pm UTC](https://discuss.elastic.co/t/need-direction-on-how-to-proceed-forward-with-filebeat-logstash-and-kibana/85464/3 "2017-06-01T18:46:15Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
