# Query Regarding Filebeat

**URL:** <https://discuss.elastic.co/t/query-regarding-filebeat/147672>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [September 7, 2018, 7:51am UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672 "2018-09-07T07:51:59Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akhilesh-Tiwari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh-tiwari/32/32965_2.png) [@Akhilesh-Tiwari](https://discuss.elastic.co/u/Akhilesh-Tiwari)\
**Post date:** [September 7, 2018, 7:51am UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/1 "2018-09-07T07:51:59Z")

</div>

```
HI @magnusbaeck and @elastic  

My Requirement is, Reading the logs from filebeat in windows System and push that logs
into a different windows system's File. without using logstash and elasticsearch. 

    is it possible or not?
    if it is possible then how?

I have already done this for same windows system but stuck in pushing logs in different windows.
 can you please suggest me for that.

```

filebeat.yml is-

```
- input_type: log 

  paths:
    - C:/WalletLogs/Info.log 
  include_lines: ["<cap_identifier: cap-c0@lition>"] 

output:
  file:
    path: "C:/ProgramData/filebeat/logs"
    filename: Cap_Logs
    rotate_every_kb: 10000
    number_of_files: 7

```

then what should i need to add for pushing logs into different windows system.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 7, 2018, 10:42am UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/2 "2018-09-07T10:42:02Z")

</div>

You could write the output file to a network volume shared by the host of Filebeat and the output machine. Once you mounted the volume, set `output.file.path` to a path on the volume and run Filebeat as always.

---

<div class="post-metadata">

**Author:** ![Akhilesh-Tiwari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh-tiwari/32/32965_2.png) [@Akhilesh-Tiwari](https://discuss.elastic.co/u/Akhilesh-Tiwari)\
**Post date:** [September 7, 2018, 12:12pm UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/3 "2018-09-07T12:12:19Z")

</div>

Hi @kvch,

Is it possible to send logs without using shared network volume, because i have to stored output logs into a different target machines.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 7, 2018, 12:16pm UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/4 "2018-09-07T12:16:17Z")

</div>

No, filebeat cannot forward events to a remote machine and write to file there.

---

<div class="post-metadata">

**Author:** ![Akhilesh-Tiwari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh-tiwari/32/32965_2.png) [@Akhilesh-Tiwari](https://discuss.elastic.co/u/Akhilesh-Tiwari)\
**Post date:** [September 7, 2018, 12:28pm UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/5 "2018-09-07T12:28:31Z")

</div>

okk, Thanks a lot for confirmation.

---

<div class="post-metadata">

**Author:** ![Akhilesh-Tiwari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh-tiwari/32/32965_2.png) [@Akhilesh-Tiwari](https://discuss.elastic.co/u/Akhilesh-Tiwari)\
**Post date:** [September 7, 2018, 1:35pm UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/6 "2018-09-07T13:35:09Z")

</div>

Hi @kvch @elastic

can you suggest me what lines need to add in the filebeat.yml to put the logs into network VOLUME.  
"P:/Public/FileBeat\_Cap\_Logs" is the path of my Network Volume and my filebeat.yml is-

```
- input_type: log 

  paths:
    - C:/WalletLogs/Info.log 
  include_lines: ["<cap_identifier: cap-c0@lition>"] 

output:
  file:
    path: "P:/Public/FileBeat_Cap_Logs"
    filename: Cap_Logs
    rotate_every_kb: 10000
    number_of_files: 7
    permissions: 0600

```

But it is still not pushing logs and create any file into network volume.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 8, 2018, 12:32am UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/7 "2018-09-08T00:32:52Z")

</div>

Is it possible you have already sent the events from `Info.log`? Filebeat does not reread already encountered events.  
If not, could you share the debug logs of Filebeat (`filebeat -e -d "*"`)?

---

<div class="post-metadata">

**Author:** ![Akhilesh-Tiwari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh-tiwari/32/32965_2.png) [@Akhilesh-Tiwari](https://discuss.elastic.co/u/Akhilesh-Tiwari)\
**Post date:** [September 10, 2018, 7:22am UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/8 "2018-09-10T07:22:18Z")

</div>

HI @elastic @kvch,

In my info.log there are multiple transaction in a second so filebeat reads continuously and push data into local(same server) but when i am trying to push data in network shared drive, there is no any effect i mean neither logs are pushing and not create any file into network volume.

is it possible to Sending the logs from Filebeat to a shared network network volume?  
if yes then how please suggest me.

my configuration file is:

**filebeat.yml**

```
- input_type: log 

  paths:
    - C:/WalletLogs/Info.log 
  include_lines: ["<cap_identifier: cap-c0@lition>"] 

output:
  file:
    path: "P:/Public/FileBeat_Cap_Logs"
    filename: Cap_Logs
    rotate_every_kb: 10000
    number_of_files: 7
    permissions: 0600

```

**P:/Public/FileBeat\_Cap\_Logs"** is the path of my Shared Network Volume directory.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 10, 2018, 10:58am UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/10 "2018-09-10T10:58:32Z")

</div>

It is possible to write logs to a shared volume.  
Could you please share your debug logs to see what is happening in your Filebeat instance?

---

<div class="post-metadata">

**Author:** ![Akhilesh-Tiwari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh-tiwari/32/32965_2.png) [@Akhilesh-Tiwari](https://discuss.elastic.co/u/Akhilesh-Tiwari)\
**Post date:** [September 10, 2018, 1:31pm UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/11 "2018-09-10T13:31:19Z")

</div>

Hi @kvch @elastic @

The issue has been resolved, issue was in permission.  
Thanks a lot for support.

I have another issue-  
after pushing data into Network Volume some decoding in the logs.

**my original log is-**

`<Log_Created_Date: 2018/09/10 19:08:37> <Log_Level: INFO> <Class_Name: org.appfuse.MyAuthenticationSuccessHandler> <Tab_Name: User Tracker Details> <User_Name: c-yogitaw> <Action: Login Success> <LoginTime: 2018-09-10 19:08:37.62> <Ip Address: 0:0:0:0:0:0:0:1> <Platform: Windows> <Browser: CHROME> <SessionId: FA89E5415FFB82CB50000327D2C2D299> <TrackerId: 2176801> <crisil_cap_identifier: crisil_cap-c0@lition>`

**After pushing log into Network Volume:**

`"\u003cLog_Created_Date: 2018/09/10 19:08:37\u003e \u003cLog_Level: INFO\u003e \u003cClass_Name: org.appfuse.MyAuthenticationSuccessHandler\u003e \u003cTab_Name: User Tracker Details\u003e \u003cUser_Name: c-yogitaw\u003e \u003cAction: Login Success\u003e \u003cLoginTime: 2018-09-10 19:08:37.62\u003e \u003cIp Address: 0:0:0:0:0:0:0:1\u003e \u003cPlatform: Windows\u003e \u003cBrowser: CHROME\u003e \u003cSessionId: FA89E5415FFB82CB50000327D2C2D299\u003e \u003cTrackerId: 2176801\u003e \u003ccrisil_cap_identifier: crisil_cap-c0@lition\u003e"`

Here i think "\<" Decoded in "\u003c" and  
"\>" Decoded in "\u003e" .

what is the solution for this issue.  
I want original log after pushing in network volume.

Can you suggest me please.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2018, 1:31pm UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672/12 "2018-10-08T13:31:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
