# Read logs using the ELK stack from the remote server

**URL:** <https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142>\
**Category:** Logstash\
**Created:** [September 11, 2019, 8:12pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142 "2019-09-11T20:12:14Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Konstantin\_Doncov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/konstantin_doncov/32/53595_2.png) [@Konstantin\_Doncov](https://discuss.elastic.co/u/Konstantin_Doncov)\
**Post date:** [September 11, 2019, 8:12pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/1 "2019-09-11T20:12:14Z")

</div>

I have successfully installed the `Elastic` stack(`Elasticsearch` + `Logstash` + `Kibana`) and can use it with `Logback` logs on the local machine. But now I need to read the logs from the remote server. I think there is no need to install entire `ELK` stack on the remote server, at least because `ELK` consumes some resources. Now I have only one remote server and my plan looks like this: I can setup the `ELK` stack on the my local machine and when I need to check the logs, I can connect the `Logstash` to the remote server and read the logs. Easily. But I have two questions:

1. Is this a fine way to do this? I also thought about adding `Filebeats` to this pipeline, but I think I don't need it, because I will not have a constantly turned on computer that will constantly receive logs. I am looking for a simple solution for reading logs five to ten times a day.

2. How can I implement this?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 12, 2019, 5:16am UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/2 "2019-09-12T05:16:55Z")

</div>

Logstash does not support reading logs from remote servers so I would recommend installing Filebeat on the remote hosts.

---

<div class="post-metadata">

**Author:** ![Konstantin\_Doncov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/konstantin_doncov/32/53595_2.png) [@Konstantin\_Doncov](https://discuss.elastic.co/u/Konstantin_Doncov)\
**Post date:** [September 12, 2019, 2:45pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/3 "2019-09-12T14:45:41Z")

</div>

Ok, thanks. And what I need to do next if we take into account the requirements(I will not have a constantly turned on computer that will constantly receive logs)? Is it better to connect Filebeat to Elasticsearch or Logstash on the local machine?

---

<div class="post-metadata">

**Author:** ![Konstantin\_Doncov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/konstantin_doncov/32/53595_2.png) [@Konstantin\_Doncov](https://discuss.elastic.co/u/Konstantin_Doncov)\
**Post date:** [September 14, 2019, 10:06pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/4 "2019-09-14T22:06:55Z")

</div>

I tried to use Filebeat, but it always tried to reconnect to Logstash("Attempting to reconnect to backoff"), I think it didn't think for such use. Or do I need to change some configuration for read logs on demand(let's call it like that)?

---

<div class="post-metadata">

**Author:** ![endersonmaia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/endersonmaia/32/17308_2.png) [@endersonmaia](https://discuss.elastic.co/u/endersonmaia)\
**Post date:** [September 14, 2019, 10:42pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/5 "2019-09-14T22:42:40Z")

</div>

filebeat can send it directly to elasticsearch, if the processors in the filebeat are enough, you could skip the logstash

obviously, according to your requirements and scale, logstash should help with the load, and having 2 logstashs to forward mesasges to the elasticsearch cluster

---

<div class="post-metadata">

**Author:** ![Konstantin\_Doncov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/konstantin_doncov/32/53595_2.png) [@Konstantin\_Doncov](https://discuss.elastic.co/u/Konstantin_Doncov)\
**Post date:** [September 14, 2019, 11:12pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/7 "2019-09-14T23:12:14Z")

</div>

Thanks, for your response. Can you explain in more detail your second part about the scheme with two Logstashes?

---

<div class="post-metadata">

**Author:** ![endersonmaia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/endersonmaia/32/17308_2.png) [@endersonmaia](https://discuss.elastic.co/u/endersonmaia)\
**Post date:** [September 15, 2019, 10:11pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/8 "2019-09-15T22:11:06Z")

</div>

you can configure the output of your `filebeat` to send to more than one `logstash` according to the documentation

> **[Configure the Logstash output | Filebeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html#loadbalance)**

> **loadbalance**
> 
> If set to true and multiple Logstash hosts are configured, the output plugin load balances published events onto all Logstash hosts. If set to false, the output plugin sends all events to only one host (determined at random) and will switch to another host if the selected one becomes unresponsive. The default value is false.
> 
> ```auto
> output.logstash:
> hosts: ["localhost:5044", "localhost:5045"]
> loadbalance: true
> index: filebeat
> 
> ```

---

<div class="post-metadata">

**Author:** ![Konstantin\_Doncov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/konstantin_doncov/32/53595_2.png) [@Konstantin\_Doncov](https://discuss.elastic.co/u/Konstantin_Doncov)\
**Post date:** [September 15, 2019, 10:52pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/9 "2019-09-15T22:52:08Z")

</div>

But I don't need this. I want to produce logs on the remote server, and when I need to check the logs I want to connect to this server and read them using ELK on my local machine. Please check my first post.  
So, how can I do this?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 16, 2019, 5:48am UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/10 "2019-09-16T05:48:09Z")

</div>

Logstash and Filebeat do not support reading logs from remote machines so you need to install Filebeat on the machine where the logs reside.

---

<div class="post-metadata">

**Author:** ![Konstantin\_Doncov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/konstantin_doncov/32/53595_2.png) [@Konstantin\_Doncov](https://discuss.elastic.co/u/Konstantin_Doncov)\
**Post date:** [September 16, 2019, 12:46pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/11 "2019-09-16T12:46:44Z")

</div>

I already installed Filebeat on the machine where the logs reside, but it always tried to reconnect to Logstash("Attempting to reconnect to backoff") if Logstash is offline. I already said about this, please check it.

---

<div class="post-metadata">

**Author:** ![Konstantin\_Doncov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/konstantin_doncov/32/53595_2.png) [@Konstantin\_Doncov](https://discuss.elastic.co/u/Konstantin_Doncov)\
**Post date:** [September 16, 2019, 4:35pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/12 "2019-09-16T16:35:01Z")

</div>

So, how can I configure ELK for this purpose? Or I just can't do this?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 16, 2019, 5:14pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/13 "2019-09-16T17:14:42Z")

</div>

For Filebeat to be able to connect to Logstash they need to be up at the same time. If this is not possible another route might be to have Filebeat send data directly to Elasticsearch and use an ingest node pipeline to process it there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2019, 5:14pm UTC](https://discuss.elastic.co/t/read-logs-using-the-elk-stack-from-the-remote-server/199142/14 "2019-10-14T17:14:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
