# Need Logstash logs like filebeat

**URL:** <https://discuss.elastic.co/t/need-logstash-logs-like-filebeat/150729>\
**Category:** Logstash\
**Created:** [October 2, 2018, 3:51pm UTC](https://discuss.elastic.co/t/need-logstash-logs-like-filebeat/150729 "2018-10-02T15:51:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nithin\_Venugopal](https://avatars.discourse-cdn.com/v4/letter/n/8c91f0/32.png) [@Nithin\_Venugopal](https://discuss.elastic.co/u/Nithin_Venugopal)\
**Post date:** [October 2, 2018, 3:51pm UTC](https://discuss.elastic.co/t/need-logstash-logs-like-filebeat/150729/1 "2018-10-02T15:51:52Z")

</div>

Is there any way to get logstash to log how filebeat does as below

`{"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":0,"time":{"ms":9}},"total":{"ticks":10,"time":{"ms":23},"value":10},"user":{"ticks":10,"time":{"ms":14}}},"info":{"ephemeral_id":"2csdf7c-9825-4c32-a01f-0sdfsdfb9","uptime":{"ms":2869}},"memstats":{"gc_next":4194304,"memory_alloc":1644472,"memory_total":3801848,"rss":21393408}},"filebeat":{"harvester":{"open_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0},"reloads":1},"output":{"type":"elasticsearch"},"pipeline":{"clients":0,"events":{"active":0}}},"registrar":{"states":{"current":0},"writes":{"success":1,"total":1}},"system":{"cpu":{"cores":1},"load":{"1":0,"15":0,"5":0,"norm":{"1":0,"15":0,"5":0}}}}}}`

Especially I am looking at "harvester":{"open\_files":0,"running":0}. This is produced frequently by filebeat. Can logstash do the same? And no I don't want to use both filebeat and logstash

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 3, 2018, 5:37pm UTC](https://discuss.elastic.co/t/need-logstash-logs-like-filebeat/150729/2 "2018-10-03T17:37:53Z")

</div>

I don't believe this is possible. What are you trying to accomplish?

---

<div class="post-metadata">

**Author:** ![Nithin\_Venugopal](https://avatars.discourse-cdn.com/v4/letter/n/8c91f0/32.png) [@Nithin\_Venugopal](https://discuss.elastic.co/u/Nithin_Venugopal)\
**Post date:** [October 3, 2018, 8:19pm UTC](https://discuss.elastic.co/t/need-logstash-logs-like-filebeat/150729/3 "2018-10-03T20:19:17Z")

</div>

While I was using filebeat, I used to monitor open and running files before stopping the service. In case of logstash, I need to access each file from sincedb, check if bytes matches the actual file and then stop the service (which is little complex).

**My scenario:** I have lot of docker based batch jobs. Each job runs in one container and produces lots of log files which has to be streamed to elasticsearch. Docker kills the container once the job is finished which deletes the log files as well. So I need an infinite loop checker to make sure all the files are transferred before the container is killed.

---

<div class="post-metadata">

**Author:** ![Nithin\_Venugopal](https://avatars.discourse-cdn.com/v4/letter/n/8c91f0/32.png) [@Nithin\_Venugopal](https://discuss.elastic.co/u/Nithin_Venugopal)\
**Post date:** [October 11, 2018, 3:43pm UTC](https://discuss.elastic.co/t/need-logstash-logs-like-filebeat/150729/4 "2018-10-11T15:43:13Z")

</div>

Any help on this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2018, 3:43pm UTC](https://discuss.elastic.co/t/need-logstash-logs-like-filebeat/150729/5 "2018-11-08T15:43:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
