# Unable to see logs when sending through Logstash

**URL:** <https://discuss.elastic.co/t/unable-to-see-logs-when-sending-through-logstash/110687>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [December 7, 2017, 2:21pm UTC](https://discuss.elastic.co/t/unable-to-see-logs-when-sending-through-logstash/110687 "2017-12-07T14:21:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fab](https://avatars.discourse-cdn.com/v4/letter/f/51bf81/32.png) [@fab](https://discuss.elastic.co/u/fab)\
**Post date:** [December 7, 2017, 2:21pm UTC](https://discuss.elastic.co/t/unable-to-see-logs-when-sending-through-logstash/110687/1 "2017-12-07T14:21:10Z")

</div>

Hi,  
i'm trying to send windows logs through winlogbeat directly to logstash. Everything is done locally from Windows 10 to a VM with Centos 7.

winlogbeat.yml file in windows

```
output.logstash:
hosts: ["192.168.88.129:5044"]

```

logstash.conf file in centos

```
input {
  beats {
    port => 5044
  }
}

# The filter part of this file is commented out to indicate that it is
# optional.
# filter {
#
# }

output {
  elasticsearch {
    hosts => "localhost"
    index => "logstash-%{+YYYY-MM-dd}"
  }
}

```

With a tcdump on port 5044 i saw that logs arrives but i'm still not able to see an index created on elasticsearch or data on kibana.  
Someone can help me?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 8, 2017, 4:02pm UTC](https://discuss.elastic.co/t/unable-to-see-logs-when-sending-through-logstash/110687/2 "2017-12-08T16:02:43Z")

</div>

See the Logstash output configuration that is recommended in our Getting Started documentation: [https://www.elastic.co/guide/en/beats/libbeat/6.0/logstash-installation.html#logstash-setup](https://www.elastic.co/guide/en/beats/libbeat/6.0/logstash-installation.html#logstash-setup)

```auto
output {
  elasticsearch {
    hosts => "localhost:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}" 
    document_type => "%{[@metadata][type]}" 
  }
}

```

Additionally make sure that you [manually install](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html) the Elasticsearch index template because it won't be auto installed when routing the data through LS.

---

<div class="post-metadata">

**Author:** ![fab](https://avatars.discourse-cdn.com/v4/letter/f/51bf81/32.png) [@fab](https://discuss.elastic.co/u/fab)\
**Post date:** [December 12, 2017, 11:12am UTC](https://discuss.elastic.co/t/unable-to-see-logs-when-sending-through-logstash/110687/3 "2017-12-12T11:12:34Z")

</div>

Probably the problem is with the index template that i have to create.  
Have i to export the index template from windows (where i have winlogbeat directly connected with logstash) and install it in centos (where elk is installed)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2018, 11:12am UTC](https://discuss.elastic.co/t/unable-to-see-logs-when-sending-through-logstash/110687/4 "2018-01-09T11:12:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
