# Using Filebeat modules and logstash conf

**URL:** <https://discuss.elastic.co/t/using-filebeat-modules-and-logstash-conf/212373>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 18, 2019, 4:46pm UTC](https://discuss.elastic.co/t/using-filebeat-modules-and-logstash-conf/212373 "2019-12-18T16:46:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![admin\_berlin](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@admin\_berlin](https://discuss.elastic.co/u/admin_berlin)\
**Post date:** [December 18, 2019, 4:46pm UTC](https://discuss.elastic.co/t/using-filebeat-modules-and-logstash-conf/212373/1 "2019-12-18T16:46:54Z")

</div>

Hi,

i'am trying to use the apache ECS dashboards, but the panels only display "No results found".

Heres my setup: Webserver (with Filebeat and apache module enabled) --\> Logstash (with multiple inputs and outputs ) --\> Elastisearch --\> Kibana

Please help :S

My configurations:  
filebeat.yml  
#----------------------------- Logstash output --------------------------------  
output.logstash:  
# The Logstash hosts  
hosts: ["172.22.64.62:5044"]

logstash.conf  
############## INPUT  
input {

```
# alle system logs
beats {
  port => 5544
  type => syslog
}

# alle apache logs
beats {
  port => 5044
  type => apache
}

# alle netflow logs
beats {
  port => 2255
  type => netflow
}

```

}

############## FILTER

filter {  
}

############## OUTPUT

output {

if [type] == "netflow" {  
elasticsearch {  
hosts =\> ["172.22.64.63:9200"]  
pipeline =\> "%{[@metadata][pipeline]}"  
user =\> xxxxx  
password =\> xxxxx  
index =\> "logstash-netflow-%{+YYYY.MM.dd}"  
}  
}

if [type] == "syslog" {  
elasticsearch {  
hosts =\> ["172.22.64.63:9200"]  
user =\> xxxxx  
password =\> xxxxx  
index =\> "logstash-syslog-%{+YYYY.MM.dd}"  
}  
}

```
if [type] == "apache" {
  elasticsearch {
    hosts => ["172.22.64.63:9200"]
    pipeline => "%{[@metadata][pipeline]}"
    user => xxxxx
    password => xxxxx
    index => "logstash-apache-%{+YYYY.MM.dd}"
   }
}

```

}

It seems like that something went wrong in the logstash config.  
When i use the elasticsearch output in the filebeat from the webserver, everything works fine.

thanks in advance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2020, 4:46pm UTC](https://discuss.elastic.co/t/using-filebeat-modules-and-logstash-conf/212373/2 "2020-01-15T16:46:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
