# Not accept logs when beats pointing to logstash

**URL:** <https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859>\
**Category:** Beats\
**Tags:** filebeat, auditbeat\
**Created:** [March 31, 2021, 4:07am UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859 "2021-03-31T04:07:21Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [March 31, 2021, 4:07am UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/1 "2021-03-31T04:07:21Z")

</div>

i have 3 beats winlogbeat (server os windows), filebeat and auditbeat (server os linux). when i pointing winlogbeat to logstash there's no problem to receive log.

but when i pointing filebeat and auditbeat to logstash, why no logs are received, but when I point directly to the elasticsearch server the logs are accepted properly?

what's wrong with my configuration?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 31, 2021, 2:33pm UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/2 "2021-03-31T14:33:15Z")

</div>

> [@alipujaistopo](#):
>
> what's wrong with my configuration?

Can we see your configuration (beats and logstash)?

Did you `setup` the indices first? See [Load the Elasticsearch index template | Auditbeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-template.html#load-template-manually)

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 1, 2021, 3:50am UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/3 "2021-04-01T03:50:37Z")

</div>

```
filebeat.inputs:

    # Each - is an input. Most options can be set at the input level, so
    # you can use different inputs for various configurations.
    # Below are the input specific configurations.

    - type: log

      # Change to true to enable this input configuration.
      enabled: true

      # Paths that should be crawled and fetched. Glob based paths.
      paths:
        #- /var/log/*.log
        #- /var/log/messages*
        #- /var/adm/syslog.log
         - /var/log/auth.log
         - /var/log/syslog

        #- c:\programdata\elasticsearch\logs\*

```

here's for the output

```
# ---------------------------- Elasticsearch Output ----------------------------
#output.elasticsearch:
  # Array of hosts to connect to.
  #hosts: ["10.194.11.67:9200"]

  # Protocol - either `http` (default) or `https`.
  #protocol: "https"

  # Authentication credentials - either API key or username/password.
  #api_key: "id:api_key"
  #username: "elastic"
  #password: "changeme"

# ------------------------------ Logstash Output -------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["10.194.11.69:5044"]

  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  #ssl.certificate_authorities: ["/etc/filebeat/logstash-forwarder.crt"]

  # Certificate for SSL client authentication
  #ssl.certificate: "/etc/pki/client/cert.pem"

  # Client Certificate Key
  #ssl.key: "/etc/pki/client/cert.key"
```

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 1, 2021, 3:57am UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/4 "2021-04-01T03:57:55Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/1/3187fb028e47aef8faf0bf93aa481f2f073e0aa5.png)

in logstash i make this 3 file

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 1, 2021, 12:12pm UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/5 "2021-04-01T12:12:08Z")

</div>

Your Filebeat config looks fine. What does `filebeat test output` show?

And when running Filebeat what's in the FIlebeat log?

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 5, 2021, 7:50am UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/6 "2021-04-05T07:50:04Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b13d21c952d181ee9cf74f44ab3514c4b5d83396.png)

the test ouput.  
even though all ports have been opened but why?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/2/62ea6257b383c0c46b991d8dd57d33a322c82de6.png)

filebeat log

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 5, 2021, 2:35pm UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/7 "2021-04-05T14:35:58Z")

</div>

From the filebeat host what happens when you run

`telnet 10.194.11.69 5044`

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 6, 2021, 4:41am UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/8 "2021-04-06T04:41:45Z")

</div>

"no route to host"

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 6, 2021, 4:56am UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/9 "2021-04-06T04:56:00Z")

</div>

Well then you have a network connectivity issue between the filebeat host and the Logstash host that needs to be solved. FW, subnet, routing etc. something

It's not a Filebeat issue.

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 6, 2021, 4:58am UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/10 "2021-04-06T04:58:52Z")

</div>

aaah i see, but when i pointing to server elasticsearch there's no problem, whereas one ip segment with logstash server

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2021, 6:59am UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859/11 "2021-05-04T06:59:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
