# RabbitMQ plugin filebeat questions

**URL:** <https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 20, 2024, 11:50am UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791 "2024-06-20T11:50:11Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![robbyq92](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robbyq92/32/125729_2.png) [@robbyq92](https://discuss.elastic.co/u/robbyq92)\
**Post date:** [June 20, 2024, 11:50am UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791/1 "2024-06-20T11:50:11Z")

</div>

I have a filebeat configured to pull data from a Rabbitmq with its module. Now on the official website it only gives var.paths:

Question, if my Rabbitmq has a username and password and is on a host (ip or url) how do I attack to get there?

```auto
####Filebeat####
- module: rabbitmq
  log:
    enabled: true
    var.paths: ["/var/log/rabbitmq/*.log*"]

```

But where i put user, password, ip or same

> **[RabbitMQ module | Filebeat Reference \[8.14\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-rabbitmq.html)**

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [June 20, 2024, 12:52pm UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791/2 "2024-06-20T12:52:19Z")

</div>

> [@robbyq92](#):
>
> I have a filebeat configured to pull data from a Rabbitmq with its module. Now on the official website it only gives var.paths:
> 
> Question, if my Rabbitmq has a username and password and is on a host (ip or url) how do I attack to get there?
> 
> ```auto
> ####Filebeat####
> - module: rabbitmq
> log:
> enabled: true
> var.paths: ["/var/log/rabbitmq/*.log*"]
> 
> ```
> 
> But where i put user, password, ip or same

Hi,

probably because the RabbitMQ module for Filebeat is designed to ingest RabbitMQ logs, not to connect to the RabbitMQ service directly.

Regards

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 20, 2024, 1:00pm UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791/3 "2024-06-20T13:00:40Z")

</div>

As mentioned in the documentation this module is used to get logs from the RabbitMQ service, not data in RabbitMQ.

> This is the module for parsing [**RabbitMQ log files**](https://www.rabbitmq.com/logging.html) It will only support RabbitMQ default i.e RFC 3339 timestamp format using TIMESTAMP\_ISO8601.

To get data from RabbitMQ you would need to use Logstash and the `rabbitmq` [input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-rabbitmq.html).

---

<div class="post-metadata">

**Author:** ![robbyq92](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robbyq92/32/125729_2.png) [@robbyq92](https://discuss.elastic.co/u/robbyq92)\
**Post date:** [June 20, 2024, 1:50pm UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791/4 "2024-06-20T13:50:01Z")

</div>

mmmm let's see I explain the situation a little.

I have the filebeat with a Redis module and another Rabbitmq module, I want to get to those logs that the Rabbit leaves in /var/logs, so what would be the scenario?

I have a metricbeat that gives me information from those two, but for the filebeat do I need the logstash? I have it mounted on a k3s (kubernetes) so if the filebeat is on the same environment it does not need a host/ip

Basically I need to be able to see the Rabbitmq logs in Kibana, for this I know that the filebeat is for the logs, but for example Rabbitmq has a username and password, don't I have to pass that on to it?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 20, 2024, 2:35pm UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791/5 "2024-06-20T14:35:00Z")

</div>

> [@robbyq92](#):
>
> Basically I need to be able to see the Rabbitmq logs in Kibana, for this I know that the filebeat is for the logs, but for example Rabbitmq has a username and password, don't I have to pass that on to it?

If you want to get the logs that the RabbitMQ server writes inside `/var/log/rabbitmq` then there is no need for username and password and you can use the filebeat module.

The username and password are used to _access_ a queue in RabbitMQ and get data from the queue.

This is a different thing, filebeat can get the logs from the service, but cannot get data from rabbitmq queues.

---

<div class="post-metadata">

**Author:** ![robbyq92](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robbyq92/32/125729_2.png) [@robbyq92](https://discuss.elastic.co/u/robbyq92)\
**Post date:** [June 20, 2024, 2:49pm UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791/6 "2024-06-20T14:49:56Z")

</div>

that it, i need de logs from the service with filebeat.

so, the config it ok?  
`- module: rabbitmq log: enabled: true var.paths: ["/var/log/rabbitmq/*.log*"]`

or i need to put this:

```auto
- module: rabbitmq
  log:
    enabled: true
    paths: ["/var/log/rabbitmq/*.log*"]

```

---

<div class="post-metadata">

**Author:** ![robbyq92](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robbyq92/32/125729_2.png) [@robbyq92](https://discuss.elastic.co/u/robbyq92)\
**Post date:** [June 21, 2024, 6:47am UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791/7 "2024-06-21T06:47:30Z")

</div>

i have k3s and in my kibana.yaml i have this:

```auto
apiVersion: v1
data:
  filebeat.yml: |
    filebeat.modules:
    - module: rabbitmq
      log:
        enabled: true
        var.paths: ["/var/log/containers/m*rabbit*.log", "/var/log/containers/*rabbit*.log", "-/var/log/rabbitmq/*.log"]
    - module: redis
      log:
        enabled: true
        var.paths: ["/var/log/redis/redis-server.log*"]
      slowlog:
        enabled: true
        var.hosts: ["redis.svc.cluster.local:6379"]
    filebeat.inputs:
    - type: container
      paths:
        - /var/log/containers/*.log
      processors:
      - add_kubernetes_metadata:
          host: ${NODE_NAME}
          matchers:
          - logs_path:
              logs_path: "/var/log/containers/"
    - type: log
      enabled: true
      paths:
        - /var/log/containers/*rabbitmq*/*.log
        - /var/log/containers/m*rabbit*.log
      fields:
        log_type: rabbitmq
      fields_under_root: true
    filebeat.inputs:
    - type: filestream
      id: rabbitmq
      paths:
        - /var/log/containers/*rabbitmq*/*.log
        - /var/log/containers/m*rabbit*.log
        - /var/log/rabbitmq/*.log

```

any error?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 21, 2024, 12:14pm UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791/8 "2024-06-21T12:14:31Z")

</div>

No idea, I do not use Kubernetes.

But I don't think this is correct.

Is the `/var/log/rabbitmq` path available **inside** the filebeat pod?

Where is your RabbitMQ service running?

---

<div class="post-metadata">

**Author:** ![robbyq92](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robbyq92/32/125729_2.png) [@robbyq92](https://discuss.elastic.co/u/robbyq92)\
**Post date:** [June 25, 2024, 7:15am UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791/9 "2024-06-25T07:15:04Z")

</div>

this path no, i have path containers who have a rabbitmq

so i need to see this in kibana  
 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/2/9/29bf5a01102cc7e555bc0f12f911b5bfe25106c1.png)

rabbitmq.log.pid but i dont know how to configure

and this i can found

![imagen](https://us1.discourse-cdn.com/elastic/original/3X/b/3/b319166ed626bb101be2b4d1b3d103645cdbc8ca.png)

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/0/3/034b9c80d36882301cc14dd3f283b77a7e25e86a.png)

the logs is in /var/log/pods/ and i have the logs in this directory for rabbitmq

---

<div class="post-metadata">

**Author:** ![robbyq92](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robbyq92/32/125729_2.png) [@robbyq92](https://discuss.elastic.co/u/robbyq92)\
**Post date:** [June 26, 2024, 2:41pm UTC](https://discuss.elastic.co/t/rabbitmq-plugin-filebeat-questions/361791/10 "2024-06-26T14:41:28Z")

</div>

Solved:

```auto
    - type: container
      paths:
        - /var/log/containers/*rabbitmq*/*.log
        - /var/log/pods/*rabbitmq*/*.log
      processors:
      - add_kubernetes_metadata:
          host: ${NODE_NAME}
          in_cluster: true
          matchers:
          - logs_path:
                - /var/log/pods/*rabbitmq*/
                - /var/log/containers/*rabbitmq*/
                - /var/log/pods/rabbitmq*/
      - dissect:
          tokenizer: "%{[@metadata][log]} %{rabbitmq.log.pid} %{[@metadata][message]}"
          field: "message"
          target_prefix: "rabbitmq"

```
