# Sending Auditbeat data to Logstash

**URL:** https://discuss.elastic.co/t/sending-auditbeat-data-to-logstash/110420
**Category:** Beats
**Tags:** auditbeat
**Created:** [December 5, 2017, 9:05pm UTC](https://discuss.elastic.co/t/sending-auditbeat-data-to-logstash/110420 "2017-12-05T21:05:23Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![ramzey1981](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@ramzey1981](https://discuss.elastic.co/u/ramzey1981)
#### Post date: [December 5, 2017, 9:05pm UTC](https://discuss.elastic.co/t/sending-auditbeat-data-to-logstash/110420/1 "2017-12-05T21:05:24Z")

</div>

hello folks

Is it possible to send auditbeats data directly to logstash for ingesting rather than directly to elasticsearch. I am doing something similar in filebeats and wanted to know if i can use logastash as an ingestion layer as well with auitbeats. If so similar to filebeats modules is there any particular ingest-convert.sh script to run for the json module files to convert them to work with logstash.

thanks

---

<div class="post-metadata">

### Author: ![ramzey1981](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@ramzey1981](https://discuss.elastic.co/u/ramzey1981)
#### Post date: [December 6, 2017, 4:35pm UTC](https://discuss.elastic.co/t/sending-auditbeat-data-to-logstash/110420/2 "2017-12-06T16:35:41Z")

</div>

i was able to send auditbeats directly to redis output following the doc but are there any special logstash grok filter pattern needed for proper ingestion to the elasticsearch template and dasboards?

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [December 8, 2017, 3:56pm UTC](https://discuss.elastic.co/t/sending-auditbeat-data-to-logstash/110420/3 "2017-12-08T15:56:23Z")

</div>

> [@ramzey1981](#):
>
> Is it possible to send auditbeats data directly to logstash for ingesting rather than directly to elasticsearch.

Yes, simply configure the Logstash output in Auditbeat and it will work. Auditbeat natively sends structured data and does not depend on an outside parser like ingest node.

> [@ramzey1981](#):
>
> but are there any special logstash grok filter pattern needed for proper ingestion to the elasticsearch template and dasboards?

If you use the Logstash output with any Beat you must manually install the Elasticsearch index template. Please see the [getting started guide](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-template.html) on how to load the template.

If you do use Logstash make sure you see how we recommend to configure the ES output here: [Configure the Logstash output | Auditbeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/auditbeat/current/logstash-output.html)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 4, 2022, 5:06am UTC](https://discuss.elastic.co/t/sending-auditbeat-data-to-logstash/110420/4 "2022-11-04T05:06:01Z")

</div>


