# Unable to parse files to logstash

**URL:** <https://discuss.elastic.co/t/unable-to-parse-files-to-logstash/105514>\
**Category:** Beats\
**Created:** [October 27, 2017, 6:02am UTC](https://discuss.elastic.co/t/unable-to-parse-files-to-logstash/105514 "2017-10-27T06:02:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shaswata\_Bisi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaswata_bisi/32/23222_2.png) [@Shaswata\_Bisi](https://discuss.elastic.co/u/Shaswata_Bisi)\
**Post date:** [October 27, 2017, 6:02am UTC](https://discuss.elastic.co/t/unable-to-parse-files-to-logstash/105514/1 "2017-10-27T06:02:06Z")

</div>

hi. I am new to elastic search. I tried to send log files through file beat into the logstash but I am not getting any outcome in the console. my configuration file is as follows

input {  
beats {  
host =\> "10.53.56.98"

# The port to listen on

port =\> "5044"

```
	# The paths to your ssl cert and key
	#ssl_certificate => "D:/ELK stack with OS metrics/sslnew/lumberjack.crt"
	#ssl_key => "D:/ELK stack with OS metrics/sslnew/lumberjack.key"

	# Set this to whatever you want.
	#type => "osmetrics"

```

}  
}

filter {

csv {  
separator =\> ","  
columns =\> ["Timestamp",  
"Memory-% Committed Bytes In Use",  
"Memory-Available Bytes",  
"Memory-Available KBytes",  
"Memory-Available MBytes",  
"Memory-Page Faults/sec",  
"Memory-Free System Page Table Entries",  
"PhysicalDisk(\_Total)-Avg. Disk Bytes/Read",  
"PhysicalDisk(\_Total)-Avg. Disk Bytes/Write",  
"PhysicalDisk(\_Total)-Current Disk Queue Length",  
"PhysicalDisk(\_Total)-Disk Read Bytes/sec",  
"PhysicalDisk(\_Total)-Disk Write Bytes/sec",  
"Process(\_Total)-% Processor Time",  
"Process(\_Total)-% User Time",  
"Process(\_Total)-ID Process",  
"Process(\_Total)-Thread Count",  
"Process(\_Total)-Working Set",  
"Process(\_Total)-IO Read Bytes/sec",  
"Process(\_Total)-IO Write Bytes/sec",  
"Processor(\_Total)-% Idle Time",  
"Processor(\_Total)-% Processor Time",  
"Processor(\_Total)-% User Time"]  
}

#if [host] == "INHYICBIVM005"{

mutate {  
update =\> { "host" =\> "Informatica\_Server" }  
}  
#}  
#if [host] == "INHYICBIVM003"{

mutate {  
update =\> { "host" =\> "Datastage\_Server" }  
}  
#}  
#if [host] == "INHYICBIVM008"{

mutate {  
update =\> { "host" =\> "Qlikview\_Server" }  
}  
#}  
#if [host] == "INHYICBIVM011"{

mutate {  
update =\> { "host" =\> "SSIS\_SSRS\_Server" }  
}  
#}  
}

output {  
elasticsearch {  
hosts=\> ["10.53.56.98:9200"]  
index =\> systemosmetricsindex  
}  
stdout{codec =\> rubydebug }  
}

Can you please tell me what is the error ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 27, 2017, 9:48am UTC](https://discuss.elastic.co/t/unable-to-parse-files-to-logstash/105514/2 "2017-10-27T09:48:40Z")

</div>

> host =\> "10.53.56.98"

What address is this?

---

<div class="post-metadata">

**Author:** ![Shaswata\_Bisi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaswata_bisi/32/23222_2.png) [@Shaswata\_Bisi](https://discuss.elastic.co/u/Shaswata_Bisi)\
**Post date:** [October 27, 2017, 10:36am UTC](https://discuss.elastic.co/t/unable-to-parse-files-to-logstash/105514/3 "2017-10-27T10:36:35Z")

</div>

This is the localhost ip address

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 27, 2017, 2:02pm UTC](https://discuss.elastic.co/t/unable-to-parse-files-to-logstash/105514/4 "2017-10-27T14:02:28Z")

</div>

Please format logs and configuration files using the `</>` button. This helps in reading/understanding your configuration.

Start with a very minimal logstash configuration sending to stdout only. No Elasticsearch and no filters...

Also have a look at Filebeat/Logstash logs! Without logs I can't tell any problems.

Also share your filebeat configuration.

Why do you bind logstash to one single device? Is filebeat on remote host or localhost as well?

---

<div class="post-metadata">

**Author:** ![Shaswata\_Bisi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaswata_bisi/32/23222_2.png) [@Shaswata\_Bisi](https://discuss.elastic.co/u/Shaswata_Bisi)\
**Post date:** [October 30, 2017, 7:12am UTC](https://discuss.elastic.co/t/unable-to-parse-files-to-logstash/105514/5 "2017-10-30T07:12:43Z")

</div>

I started minimal logstash configuration and with each working step, i kept on modifying the config file and then it finally worked. thanks a lot

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2017, 6:02am UTC](https://discuss.elastic.co/t/unable-to-parse-files-to-logstash/105514/6 "2017-11-17T06:02:44Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
