# Unable to get logs from filebeats to logstash

**URL:** <https://discuss.elastic.co/t/unable-to-get-logs-from-filebeats-to-logstash/231726>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 8, 2020, 12:57pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-from-filebeats-to-logstash/231726 "2020-05-08T12:57:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gkvganesh](https://avatars.discourse-cdn.com/v4/letter/g/c4cdca/32.png) [@gkvganesh](https://discuss.elastic.co/u/gkvganesh)\
**Post date:** [May 8, 2020, 12:57pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-from-filebeats-to-logstash/231726/1 "2020-05-08T12:57:43Z")

</div>

I have installed Filebeat in server A (linux server) to send logs to server B (CentOS server). Server B has Elastic, logstash and kibana installed. I followed the steps to configure logstash output in filebeat.yml from the link [https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html)  
However, I am unable to get the logs in logstash installed in Server B. Do I need to mke further changes?

#----------------------------- Logstash output --------------------------------  
output.logstash:

# The Logstash hosts

hosts: ["Server B IP:9600"]  
proxy\_url: socks5://username:password@Server B IP:2233  
index: filebeat  
proxy\_use\_local\_resolver: true

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

---

<div class="post-metadata">

**Author:** ![Hausmeister](https://avatars.discourse-cdn.com/v4/letter/h/f05b48/32.png) [@Hausmeister](https://discuss.elastic.co/u/Hausmeister)\
**Post date:** [May 8, 2020, 1:05pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-from-filebeats-to-logstash/231726/2 "2020-05-08T13:05:25Z")

</div>

Hi Vijay,

to connect to logstash you need to enable an input pipeline in the logstash config.  
input {  
beats {  
host =\> "IPaddress"  
port =\> 5044  
}  
}  
filter {  
...  
}  
output {  
elasticsearch {  
hosts =\> "[http://localhost:9200](http://localhost:9200)"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

This will open a port at the logstash server Filebeat will connect to and forward all events to elastic. Depending on the logs you might also enable some filter, e.g. for apache.

On ServerB you then configure the connection to ServerA:5044.

Cheers  
René

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2020, 1:05pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-from-filebeats-to-logstash/231726/3 "2020-06-05T13:05:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
