# What are the use cases for the file plugin v.s. logstash?

**URL:** <https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250>\
**Category:** Logstash\
**Created:** [June 8, 2016, 7:37pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250 "2016-06-08T19:37:37Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![matanster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matanster/32/32063_2.png) [@matanster](https://discuss.elastic.co/u/matanster)\
**Post date:** [June 8, 2016, 7:37pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/1 "2016-06-08T19:37:37Z")

</div>

Hi,

I have looked at the [file plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-path). and am not quite sure what use cases is it meant for. Other than when sharing some sort of shared network storage, it seems as if this plugin can only ingest files from the local host, which is kind of limited.

Am I missing something or is logstash (e.g. [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html)) the solution to ingesting files from a remote host not sharing network storage?

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 8, 2016, 8:26pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/2 "2016-06-08T20:26:26Z")

</div>

> I have looked at the file plugin. and am not quite sure what use cases is it meant for. Other than when sharing some sort of shared network storage, it seems as if this plugin can only ingest files from the local host, which is kind of limited.

How so? It's a plugin for reading files from locally mounted file systems. If that doesn't fit your use case there are dozens of other Logstash input plugins to choose from.

> Am I missing something or is logstash (e.g. [Elasticsearch output plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html)) the solution to ingesting files from a remote host not sharing network storage?

The file plugin you're referring to is a plugin to Logstash. Comparing that plugin with Logstash itself doesn't make sense.

One normally installs a log shipping agent on all hosts that have logs whose contents you want to collect. The agent sends logs from the remove machines to the box where you want to collect all logs. Logstash, Filebeat, NXLog, and rsyslog are examples of programs capable of doing this.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 8, 2016, 11:55pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/3 "2016-06-08T23:55:12Z")

</div>

If you want to compare it to something, look at filebeat - [https://www.elastic.co/guide/en/beats/filebeat/current/index.html](https://www.elastic.co/guide/en/beats/filebeat/current/index.html)

---

<div class="post-metadata">

**Author:** ![matanster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matanster/32/32063_2.png) [@matanster](https://discuss.elastic.co/u/matanster)\
**Post date:** [June 9, 2016, 9:53pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/4 "2016-06-09T21:53:59Z")

</div>

Yes I've indeed mistaken the file plugin for an elasticsearch plugin rather  
than a logstash one. Now it makes perfects sense.  
Why the bother with logstash forwarder (  
[https://github.com/elastic/logstash-forwarder](https://github.com/elastic/logstash-forwarder)) and filebeat then?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 9, 2016, 10:09pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/5 "2016-06-09T22:09:14Z")

</div>

Per the github page, LSF is deprecated.  
Use filebeat 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 10, 2016, 6:05am UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/6 "2016-06-10T06:05:07Z")

</div>

> Why the bother with logstash forwarder (  
> [GitHub - elastic/logstash-forwarder: An experiment to cut logs in preparation for processing elsewhere. Replaced by Filebeat: https://github.com/elastic/beats/tree/master/filebeat](https://github.com/elastic/logstash-forwarder)) and filebeat then?

Because the disk and RAM overhead of Logstash can be prohibitive for small systems.

---

<div class="post-metadata">

**Author:** ![matanster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matanster/32/32063_2.png) [@matanster](https://discuss.elastic.co/u/matanster)\
**Post date:** [June 10, 2016, 6:32am UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/7 "2016-06-10T06:32:34Z")

</div>

Thanks, I will try the beat! unlike logstash where you installed logstash and then used/added plugins, is it the case that beats are self-contained? I hope the file beat can well handle rotating-file logs and it is not too beta.

---

<div class="post-metadata">

**Author:** ![matanster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matanster/32/32063_2.png) [@matanster](https://discuss.elastic.co/u/matanster)\
**Post date:** [June 10, 2016, 8:58am UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/8 "2016-06-10T08:58:51Z")

</div>

Perhaps I am not used to elastic documentation but it is hard to fine documentation / configuration instructions for the file beat.... and I find it baffling why would you forward beat information to logstash not directly to elastic as mentioned on the website....

> Filebeat protects against this by quickly and reliably shipping logs to Logstash and Elasticsearch for centralized storage and analysis.

can you please advise on both accounts and about the former question on the file beat's overall status?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 10, 2016, 10:01am UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/9 "2016-06-10T10:01:19Z")

</div>

Filebeat does not support parsing logs and extracting fields, which is where Logstash comes in. In Elasticsearch 5.0, the concept of ingest nodes are being introduced, which will allow some processing within Elasticsearch and may allow certain architectures to be simplified by feeding data directly from Filebeat to ingest nodes.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 10, 2016, 12:35pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/10 "2016-06-10T12:35:16Z")

</div>

> unlike logstash where you installed logstash and then used/added plugins, is it the case that beats are self-contained?

Yes. A Beats-based binary is typically statically linked with an on-disk footprint of maybe a few tens of megabytes and a RAM footprint of a few megabytes.

> I hope the file beat can well handle rotating-file logs and it is not too beta.

What gives you the impression that it's beta software?

> Perhaps I am not used to elastic documentation but it is hard to fine documentation / configuration instructions for the file beat....

If I google "filebeat" the second hit is [Filebeat quick start: installation and configuration | Filebeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html). Were you not able to find that documentation or was it hard to understand?

> and I find it baffling why would you forward beat information to logstash not directly to elastic as mentioned on the website....

Logstash is able to process events in various ways that neither Filebeat or Elasticsearch is capable of. You typically don't send the raw logs to ES.

---

<div class="post-metadata">

**Author:** ![matanster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matanster/32/32063_2.png) [@matanster](https://discuss.elastic.co/u/matanster)\
**Post date:** [June 10, 2016, 12:46pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/11 "2016-06-10T12:46:10Z")

</div>

Thanks.  
And still how to configure the file beat is very well conceiled to the beats newb. Can someone point me in the right direction?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 10, 2016, 1:18pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/12 "2016-06-10T13:18:17Z")

</div>

Did you have a look at the documentation link I posted?

---

<div class="post-metadata">

**Author:** ![matanster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matanster/32/32063_2.png) [@matanster](https://discuss.elastic.co/u/matanster)\
**Post date:** [June 10, 2016, 7:14pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/13 "2016-06-10T19:14:45Z")

</div>

Yes, apologies, I didn't notice your message at the time. I really wonder what should the commands `filebeat` and `filebeat-god` be used for. `filebeat` seems to do nothing when I run it, it simply immediately returns without any output nor processes left running by it, as much as I can see.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:53am UTC](https://discuss.elastic.co/t/what-are-the-use-cases-for-the-file-plugin-v-s-logstash/52250/14 "2017-07-06T04:53:34Z")

</div>


