# Sending apache logs to elastic search

**URL:** <https://discuss.elastic.co/t/sending-apache-logs-to-elastic-search/93012>\
**Category:** Elasticsearch\
**Created:** [July 13, 2017, 12:57pm UTC](https://discuss.elastic.co/t/sending-apache-logs-to-elastic-search/93012 "2017-07-13T12:57:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rkpotdar](https://avatars.discourse-cdn.com/v4/letter/r/f0a364/32.png) [@rkpotdar](https://discuss.elastic.co/u/rkpotdar)\
**Post date:** [July 13, 2017, 12:57pm UTC](https://discuss.elastic.co/t/sending-apache-logs-to-elastic-search/93012/1 "2017-07-13T12:57:17Z")

</div>

Is it mandatory to have logstash installed to send the logs to elastic search? Can the filbeat not send apache logs directly to elasticsearch?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 13, 2017, 1:14pm UTC](https://discuss.elastic.co/t/sending-apache-logs-to-elastic-search/93012/2 "2017-07-13T13:14:44Z")

</div>

Yes it can. Look at [Filebeat Modules](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules.html). I used it as an example in [this blog post](https://www.elastic.co/blog/filebeat-modiles-access-logs-and-elasticsearch-storage-requirements).

---

<div class="post-metadata">

**Author:** ![rkpotdar](https://avatars.discourse-cdn.com/v4/letter/r/f0a364/32.png) [@rkpotdar](https://discuss.elastic.co/u/rkpotdar)\
**Post date:** [July 13, 2017, 1:54pm UTC](https://discuss.elastic.co/t/sending-apache-logs-to-elastic-search/93012/3 "2017-07-13T13:54:22Z")

</div>

Thanks Christian. I am able to see the logs on Kibana discover section. I now want to install a watcher in ES. The path goes ~/elasticsearch-5.5.0/bin/elasticsearch-plugin and I tried  
sudo /bin/elasticsearch-plugin install watcher  
but it threw an error saying unknown plugin watcher. Same for license.  
Any reason this could happen?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 13, 2017, 2:00pm UTC](https://discuss.elastic.co/t/sending-apache-logs-to-elastic-search/93012/4 "2017-07-13T14:00:27Z")

</div>

For 5.5.0 Watcher is part of X-Pack, so that is what you need to install.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2017, 2:00pm UTC](https://discuss.elastic.co/t/sending-apache-logs-to-elastic-search/93012/5 "2017-08-10T14:00:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
