# Send Logstash logs to Kibana remote server

**URL:** https://discuss.elastic.co/t/send-logstash-logs-to-kibana-remote-server/240060
**Category:** Kibana
**Created:** [July 6, 2020, 8:51pm UTC](https://discuss.elastic.co/t/send-logstash-logs-to-kibana-remote-server/240060 "2020-07-06T20:51:19Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Sai\_Avinash\_Duddupud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_avinash_duddupud/32/48265_2.png) [@Sai\_Avinash\_Duddupud](https://discuss.elastic.co/u/Sai_Avinash_Duddupud)
#### Post date: [July 6, 2020, 8:51pm UTC](https://discuss.elastic.co/t/send-logstash-logs-to-kibana-remote-server/240060/1 "2020-07-06T20:51:19Z")

</div>

I am new to ELK Stack and trying to view logs on kibana which is hosted on different server. Following are my configurations for **Filebeat** and **logstash** in my **localhost pc** and **logstash is succesfully recieving logs from filbeat.**

I am facing a lot of confusion in creating an index pattern in kibana. how do i know the index variable parameters **[@metadata][beat]** and **[@metadata][version]** present in output node in logstash.conf so that i will create an index pattern and access the same in kibana discover page

**filebeat.yml**

```
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /home/sai_avinash/Documents/refactor/unityapp/unity/media/*.log

output.logstash:
  enabled: true
  hosts: ["localhost:5044"]

```

**logstash.conf**

```
input {
  beats {
    port => 5044
    ssl => false
  }
}

filter {
  grok {
    match => { "message" => "%{TIMESTAMP_ISO8601:timestamp}] %{LOGLEVEL:loglevel}\|%{GREEDYDATA:module}\|%{GREEDYDATA:content}" }
  }
  date {
    locale => "en"
    match => ["timestamp", "YYYY-MM-dd HH:mm:ss"]
    target => "@timestamp"
    timezone => "America/New_York"
  }
}

output {
  elasticsearch {
    hosts => "elk_server_ip:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}" 
  }
  stdout { codec => rubydebug { metadata => true } }
}
```

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 7, 2020, 1:26am UTC](https://discuss.elastic.co/t/send-logstash-logs-to-kibana-remote-server/240060/2 "2020-07-07T01:26:27Z")

</div>

Welcome to our community! 😃

> [@Sai\_Avinash\_Duddupud](#):
>
> how do i know the index variable parameters **[@metadata][beat]** and **[@metadata][version]** present in output node in logstash.conf so that i will create an index pattern and access the same in kibana discover page

You don't need to know what they are, but they will usually be something like;

- `[@metadata][beat]` - filebeat, metricbeat, etc
- `[@metadata][version]` - 7.8.0 or 7.7.1 etc

When you create the pattern in Kibana, just use `filebeat-*` or `metricbeat-*`.

Also if you are only doing simple grok and timestamp matching via Logstash, you can also look at using the [Ingest API](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html) to reduce some of your complexity.

---

<div class="post-metadata">

### Author: ![Sai\_Avinash\_Duddupud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_avinash_duddupud/32/48265_2.png) [@Sai\_Avinash\_Duddupud](https://discuss.elastic.co/u/Sai_Avinash_Duddupud)
#### Post date: [July 7, 2020, 8:15am UTC](https://discuss.elastic.co/t/send-logstash-logs-to-kibana-remote-server/240060/3 "2020-07-07T08:15:00Z")

</div>

thanks @warkolm i found it in kibana indices list but since there are so many listed, is it possible to write a custom index name instead of the entire pattern like following?

can i replace  
`index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}" `

with  
`index => "avinash*" `

now will **avinash** \* get created on **elk\_server\_ip:9200/\_cat/indices?**

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 7, 2020, 8:15am UTC](https://discuss.elastic.co/t/send-logstash-logs-to-kibana-remote-server/240060/4 "2020-07-07T08:15:17Z")

</div>

You can, yes.

---

<div class="post-metadata">

### Author: ![Sai\_Avinash\_Duddupud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_avinash_duddupud/32/48265_2.png) [@Sai\_Avinash\_Duddupud](https://discuss.elastic.co/u/Sai_Avinash_Duddupud)
#### Post date: [July 7, 2020, 8:59am UTC](https://discuss.elastic.co/t/send-logstash-logs-to-kibana-remote-server/240060/5 "2020-07-07T08:59:33Z")

</div>

@warkolm I have created the following index under output node in logstash.conf...its been more than 30 min, still blend\_test doesn't reflect in the kibana indices server

```
elasticsearch {
    hosts => "elk_server_ip:9200"
    manage_template => false
    index => "blend_test*" 
  }

```

Please suggest if am doing something wrong....FYI, I have also restarted filebeat and logstash as well

---

<div class="post-metadata">

### Author: ![Sai\_Avinash\_Duddupud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_avinash_duddupud/32/48265_2.png) [@Sai\_Avinash\_Duddupud](https://discuss.elastic.co/u/Sai_Avinash_Duddupud)
#### Post date: [July 7, 2020, 8:19pm UTC](https://discuss.elastic.co/t/send-logstash-logs-to-kibana-remote-server/240060/6 "2020-07-07T20:19:01Z")

</div>

@warkolm did I make any mistake? Please suggest a workaround if so.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 4, 2020, 8:19pm UTC](https://discuss.elastic.co/t/send-logstash-logs-to-kibana-remote-server/240060/7 "2020-08-04T20:19:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
