# Sending Logs to both Elasticsearch & Logstash

**URL:** <https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 23, 2019, 7:22am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755 "2019-07-23T07:22:28Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![w0lfxpunk](https://avatars.discourse-cdn.com/v4/letter/w/73ab20/32.png) [@w0lfxpunk](https://discuss.elastic.co/u/w0lfxpunk)\
**Post date:** [July 23, 2019, 7:22am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755/1 "2019-07-23T07:22:28Z")

</div>

Dear All,  
Is it possible to send logs to Elasticsearch & Logstash both from a server ? For example I want to send some logs to Elasticsearch only say Apache access logs howwever I want o send and parse apache error logs using Logstash. Is it possible?  
Regards  
W0lf

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [July 23, 2019, 8:19am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755/2 "2019-07-23T08:19:54Z")

</div>

It is possible, but not necessarily encouraged. Can you describe your setup in more detail? What is sending the logs from the server?

---

<div class="post-metadata">

**Author:** ![w0lfxpunk](https://avatars.discourse-cdn.com/v4/letter/w/73ab20/32.png) [@w0lfxpunk](https://discuss.elastic.co/u/w0lfxpunk)\
**Post date:** [July 24, 2019, 4:55am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755/3 "2019-07-24T04:55:40Z")

</div>

HI Admiko,  
I am using filebeat to send Apache Logs.  
Thank you  
W0lf

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [July 24, 2019, 5:10am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755/4 "2019-07-24T05:10:31Z")

</div>

Filebeat doesn't support multiple outputs, so you have two options:

1. Have two separate Filebeat instances running on the server, one is talking directly to Elasticsearch and another is talking to Logstash.
2. Send everything to Logstash and parse only error logs, pass access logs to Elasticsearch.

I'd go with second option for easier administration and maintenance 🙂

---

<div class="post-metadata">

**Author:** ![w0lfxpunk](https://avatars.discourse-cdn.com/v4/letter/w/73ab20/32.png) [@w0lfxpunk](https://discuss.elastic.co/u/w0lfxpunk)\
**Post date:** [July 25, 2019, 8:54am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755/5 "2019-07-25T08:54:13Z")

</div>

yep in this case its better to go through Logstash. So logstash process the config file in what order? for example I have below conf files in logstash conf directory  
ssh.conf - for ssh success/ failed attempts with geoip  
Apache.conf - for Apache access/error l ogs with geoip  
which one logstash process first Apache.conf ?

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [July 25, 2019, 8:58am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755/6 "2019-07-25T08:58:49Z")

</div>

Not sure which one of those because ssh.conf starts with lowercase and Apache.conf uppercase. Logstash reads configs in alphabetical order.  
Previously, I used 001-input-_name_.conf scheme in config file naming.  
Nowadays I can mostly get away with using different pipelines, but still follow the naming if there's a need.

---

<div class="post-metadata">

**Author:** ![w0lfxpunk](https://avatars.discourse-cdn.com/v4/letter/w/73ab20/32.png) [@w0lfxpunk](https://discuss.elastic.co/u/w0lfxpunk)\
**Post date:** [July 30, 2019, 10:22am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755/7 "2019-07-30T10:22:40Z")

</div>

ok so its better to name them in an order like 01.apache.conf 02.ssh.conf 03.mysql.conf ?  
now it will process the conf in order of 01,02 & 03

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [July 30, 2019, 10:45am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755/8 "2019-07-30T10:45:46Z")

</div>

Basically yes.  
Logstash concanates all configs into one starting from the first alphanumerically.  
First should come inputs, then filters and last outputs.

[https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html](https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2019, 10:45am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755/9 "2019-08-27T10:45:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
