# No results when using logstash

**URL:** <https://discuss.elastic.co/t/no-results-when-using-logstash/140016>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 14, 2018, 12:58am UTC](https://discuss.elastic.co/t/no-results-when-using-logstash/140016 "2018-07-14T00:58:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![swgroupw](https://avatars.discourse-cdn.com/v4/letter/s/779978/32.png) [@swgroupw](https://discuss.elastic.co/u/swgroupw)\
**Post date:** [July 14, 2018, 12:58am UTC](https://discuss.elastic.co/t/no-results-when-using-logstash/140016/1 "2018-07-14T00:58:18Z")

</div>

I am new to Elastic Stack and have been experimenting on a single CentOS 7 virtual machine. I have been following the installation and startup guides and have been pretty successful at getting things to work.

I am trying to get filebeat to work with logstash. If I configure the filebeat.yml file to use elasticsearch, results appear in the filebeat kibana dashboards. When I change filebeat.yml to use logstash, remove the /var/lib/filebeat/registry file and clear data with "curl -XDELETE '[http://localhost:9200/filebeat-\*](http://localhost:9200/filebeat-*)'" and restart filebeat the dashboards report no results found.

Using discover in kibana I see that the data is there, but most of the fields are not available when using logstash because they are empty. The fields are available and populated when using elasticsearch.

I have the syslog, logstash and auditd filebeat modules enabled.

Metricbeat works fine with logstash.

Any ideas what to try? I'll send whatever config files or log output needed. I didn't want to spam the list with unnecessary files.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 17, 2018, 8:49am UTC](https://discuss.elastic.co/t/no-results-when-using-logstash/140016/2 "2018-07-17T08:49:15Z")

</div>

The problem here is that when you deleted the `filebeat-*` indices, you also deleted the [index templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html) associated with them.

Beats will automatically set up those index templates for you when using Elasticsearch output, but cannot do so when using Logstash output. In this case you must load the index template manually before indexing any events.

Have a look at:  
[https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html)

---

<div class="post-metadata">

**Author:** ![swgroupw](https://avatars.discourse-cdn.com/v4/letter/s/779978/32.png) [@swgroupw](https://discuss.elastic.co/u/swgroupw)\
**Post date:** [July 17, 2018, 12:46pm UTC](https://discuss.elastic.co/t/no-results-when-using-logstash/140016/3 "2018-07-17T12:46:54Z")

</div>

Thanks for the tip. Based on the link you provided I executed the following commands:

143 systemctl stop filebeat  
144 curl -XDELETE '[http://localhost:9200/filebeat-\*](http://localhost:9200/filebeat-*)'  
145 filebeat setup --template -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["localhost:9200"]'  
146 rm /var/lib/filebeat/registry  
147 systemctl start filebeat

However, the filebeat dashboards still report no results found.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2018, 12:46pm UTC](https://discuss.elastic.co/t/no-results-when-using-logstash/140016/4 "2018-08-14T12:46:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
