# Remote filebeat ingest pipeline working with logstash

**URL:** <https://discuss.elastic.co/t/remote-filebeat-ingest-pipeline-working-with-logstash/218289>\
**Category:** Logstash\
**Created:** [February 7, 2020, 8:04am UTC](https://discuss.elastic.co/t/remote-filebeat-ingest-pipeline-working-with-logstash/218289 "2020-02-07T08:04:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mahboubeh](https://avatars.discourse-cdn.com/v4/letter/m/ecd19e/32.png) [@mahboubeh](https://discuss.elastic.co/u/mahboubeh)\
**Post date:** [February 7, 2020, 8:04am UTC](https://discuss.elastic.co/t/remote-filebeat-ingest-pipeline-working-with-logstash/218289/1 "2020-02-07T08:04:52Z")

</div>

Hi  
i have installed logstash 7.4.1 in my vmware and elasticsearch 7.4.1 . besides that i have installed filebeat 7.4.1 in a remote machine and want to send logs with apache module pipeline into my logstash.then logstash send logs to elasticsearch and make an index. my problem is when i run pipeline with the command "./filebeat setup --pipelines --modules apache" and start all services there is no index in elasticsearch.  
i set my logstash ip and port in remote filebeat.yml and disable elasticsearch output . following lines are the content of logstash configuration file  
input {  
beats {  
port =\> 5044  
host =\> "0.0.0.0"  
}  
}

output {  
if [[@metadata](https://github.com/metadata)][pipeline] {  
elasticsearch {  
hosts =\> "127.0.0.1:9200"  
manage\_template =\> false  
index =\> "apache-%{[[@metadata](https://github.com/metadata)][version]}-%{+YYYY.MM.dd}"  
pipeline =\> "%{[[@metadata](https://github.com/metadata)][pipeline]}"  
}  
} else {  
elasticsearch {  
hosts =\> "127.0.0.1:9200"  
manage\_template =\> false  
index =\> "atefeh-%{[[@metadata](https://github.com/metadata)][version]}-%{+YYYY.MM.dd}"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![old\_chocobo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/old_chocobo/32/62268_2.png) [@old\_chocobo](https://discuss.elastic.co/u/old_chocobo)\
**Post date:** [February 7, 2020, 10:01am UTC](https://discuss.elastic.co/t/remote-filebeat-ingest-pipeline-working-with-logstash/218289/2 "2020-02-07T10:01:59Z")

</div>

In order to setup pielines you need direct Elasticsearch connection. Try this:

```
filebeat setup --pipelines -e --modules apache \
  -E output.logstash.enabled=false \
  -E output.elasticsearch.hosts=['https://redacted:9200'] \
  -E output.elasticsearch.username=redacted \
  -E output.elasticsearch.password=redacted
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2020, 10:02am UTC](https://discuss.elastic.co/t/remote-filebeat-ingest-pipeline-working-with-logstash/218289/3 "2020-03-06T10:02:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
