# Not getting output on Kibana while can see logs on logstash log screen on Docker

**URL:** <https://discuss.elastic.co/t/not-getting-output-on-kibana-while-can-see-logs-on-logstash-log-screen-on-docker/355519>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring, docker\
**Created:** [March 15, 2024, 8:03pm UTC](https://discuss.elastic.co/t/not-getting-output-on-kibana-while-can-see-logs-on-logstash-log-screen-on-docker/355519 "2024-03-15T20:03:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![LeetLee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leetlee/32/124003_2.png) [@LeetLee](https://discuss.elastic.co/u/LeetLee)\
**Post date:** [March 15, 2024, 8:03pm UTC](https://discuss.elastic.co/t/not-getting-output-on-kibana-while-can-see-logs-on-logstash-log-screen-on-docker/355519/1 "2024-03-15T20:03:29Z")

</div>

I'm trying to send Airflow logs to Elasticsearch for monitoring on Kibana using Logstash and Filebeat. However, although I can see logs on the Docker Logstash log screen, those logs cannot be seen on Elasticsearch and Kibana. Where is the error in my configuration and YAML files? Can you guys help me? I've been searching for a solution for nearly a day.

logstash-sample.conf is below:

```auto
  # Beat -> Logstash -> Elasticsearch pipeline.

  input {
    beats {
      type => log
      port => 5044
    }
  }

  filter {}

  output {
    elasticsearch {
      hosts => ["localhost:9200"]
      index => "updatedlogs"
      #user => "elastic"
      #password => "changeme"
    }

    stdout {
      codec => rubydebug
    } 
  }

```

logstash.yml is below:

```auto
http.host: "0.0.0.0"
xpack.monitoring.elasticsearch.hosts: ["http://elasticsearch:9200"] # Docker node name

```

filebeat.yml is below:

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - C:/test/airflow/logs/*/*/*/*.log

output.logstash:
  hosts: ["localhost:5044"]
  enabled: true

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 16, 2024, 1:45pm UTC](https://discuss.elastic.co/t/not-getting-output-on-kibana-while-can-see-logs-on-logstash-log-screen-on-docker/355519/2 "2024-03-16T13:45:16Z")

</div>

> [@LeetLee](#):
>
> However, although I can see logs on the Docker Logstash log screen, those logs cannot be seen on Elasticsearch and Kibana

You need to share the logs, does it have any error on it?

What is the result of running this request on Kibana Dev Tools:

```auto
GET updatedlogs/_search

```

---

<div class="post-metadata">

**Author:** ![LeetLee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leetlee/32/124003_2.png) [@LeetLee](https://discuss.elastic.co/u/LeetLee)\
**Post date:** [March 18, 2024, 4:00pm UTC](https://discuss.elastic.co/t/not-getting-output-on-kibana-while-can-see-logs-on-logstash-log-screen-on-docker/355519/4 "2024-03-18T16:00:40Z")

</div>

I've been getting the following output for days, unfortunately, despite my efforts, I'm still facing the same problem.

```auto
#! Elasticsearch built-in security features are not enabled. Without authentication, your cluster could be accessible to anyone. See https://www.elastic.co/guide/en/elasticsearch/reference/7.17/security-minimal-setup.html to enable security.
{
  "error" : {
    "root_cause" : [
      {
        "type" : "index_not_found_exception",
        "reason" : "no such index [updatedlogs]",
        "resource.type" : "index_or_alias",
        "resource.id" : "updatedlogs",
        "index_uuid" : "_na_",
        "index" : "updatedlogs"
      }
    ],
    "type" : "index_not_found_exception",
    "reason" : "no such index [updatedlogs]",
    "resource.type" : "index_or_alias",
    "resource.id" : "updatedlogs",
    "index_uuid" : "_na_",
    "index" : "updatedlogs"
  },
  "status" : 404
}

```

Also when I was checking filebeat logs I found these ERROR logs.

```auto
ERROR	logstash/async.go:256	Failed to publish events caused by: EOF
ERROR	logstash/async.go:256	Failed to publish events caused by: client is not connected
ERROR	pipeline/output.go:121	Failed to publish events: client is not connected

```

---

<div class="post-metadata">

**Author:** ![LeetLee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leetlee/32/124003_2.png) [@LeetLee](https://discuss.elastic.co/u/LeetLee)\
**Post date:** [April 12, 2024, 5:58pm UTC](https://discuss.elastic.co/t/not-getting-output-on-kibana-while-can-see-logs-on-logstash-log-screen-on-docker/355519/5 "2024-04-12T17:58:38Z")

</div>

I solved the problem a few days ago. The main issue is in docker-compose.yml file where I mounted logstash.conf in the config folder. The correct mounting for the logstash.conf file is specified in the pipeline folder, not config folder. I have provided the correct and wrong mountings below. I hope it helps who is struggling with the same problem as me.

```auto
# WRONG! 
   - ./logstash/logstash.conf:/usr/share/logstash/config/logstash.conf

# CORRECT!
   - ./logstash.conf:/usr/share/logstash/pipeline/logstash.conf
   conf file needs to go into pipeline folder!

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2024, 5:59pm UTC](https://discuss.elastic.co/t/not-getting-output-on-kibana-while-can-see-logs-on-logstash-log-screen-on-docker/355519/6 "2024-05-10T17:59:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
