# Why do i need Logstash if filebeat can send data to Elasticsearch

**URL:** <https://discuss.elastic.co/t/why-do-i-need-logstash-if-filebeat-can-send-data-to-elasticsearch/70965>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 9, 2017, 4:10pm UTC](https://discuss.elastic.co/t/why-do-i-need-logstash-if-filebeat-can-send-data-to-elasticsearch/70965 "2017-01-09T16:10:35Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sezanawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sezanawa/32/21910_2.png) [@sezanawa](https://discuss.elastic.co/u/sezanawa)\
**Post date:** [January 9, 2017, 4:10pm UTC](https://discuss.elastic.co/t/why-do-i-need-logstash-if-filebeat-can-send-data-to-elasticsearch/70965/1 "2017-01-09T16:10:35Z")

</div>

Hallo Everybody

If i want to centralized the logs in my application Environment. I have installed ELK (Eleasticsearch, Logstash and Kibana) and using Grok file input filter which is working fine on my local machine.

When i want to use it as centralized Solution, i can install it on a VM and on all my applictaion servers Filebeat service which can pick up the data from logfiles and send to Elasticsearch. Kibana is based on Elasticsearch and can show me logs on the basis of Indexes created in Elasticsearch.

Now question is, if its working between Filebeat, Elasticsearch and Kibana , do i still need Logstash? if yes what will be the job of Logstash?

Kind regards

---

<div class="post-metadata">

**Author:** ![Habitual](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/habitual/32/14772_2.png) [@Habitual](https://discuss.elastic.co/u/Habitual)\
**Post date:** [January 9, 2017, 4:58pm UTC](https://discuss.elastic.co/t/why-do-i-need-logstash-if-filebeat-can-send-data-to-elasticsearch/70965/2 "2017-01-09T16:58:11Z")

</div>

I asked myself this very thing about 10 days ago.  
Turns out I needed it for geo data in my input on ELK:  
patterns\_dir =\> ["/opt/logstash/vendor/patterns"]  
and I couldn't find one anywhere else.  
I don't know what else it may affect, but that is what I noticed

I wound up installing logstash-5.1.1.deb

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 9, 2017, 6:02pm UTC](https://discuss.elastic.co/t/why-do-i-need-logstash-if-filebeat-can-send-data-to-elasticsearch/70965/3 "2017-01-09T18:02:34Z")

</div>

> if yes what will be the job of Logstash?

For example:

- Perform event transforms that Filebeat and ES aren't capable of.
- Additional inputs and outputs.

Maybe nothing of this applies to you.

---

<div class="post-metadata">

**Author:** ![sezanawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sezanawa/32/21910_2.png) [@sezanawa](https://discuss.elastic.co/u/sezanawa)\
**Post date:** [January 10, 2017, 8:40am UTC](https://discuss.elastic.co/t/why-do-i-need-logstash-if-filebeat-can-send-data-to-elasticsearch/70965/4 "2017-01-10T08:40:05Z")

</div>

Hi @magnusbaeck

Thanks for precise information. Actually i was looking for to add Filter property in Filebeat so that my nodes send data directly to ES in a format which i am expecting for kibana. But it seems like filebeat does not offer grok filtering method, according to following thread.

> <https://github.com/elastic/beats/issues/679>
>
> Sounds like a pretty obvious win for efficiency, especially seeing as those crea…ting the logs are more likely to know what format they are in.
> 
> There are a couple of golang bindings for grok already in existence:
> https://github.com/jbuchbinder/gogrok
> https://github.com/blakesmith/go-grok
> https://github.com/scalingdata/go-grok
> 
> Happy to take a crack at it myself

but don't you think its enough to use filtering at prospector level can done the job for me. Here is my previous thread (where u already have answered a lot 🙂 ) which show how my logs look like and what grok filter i have applied to parse it.

> [@How to configure ELK (Elasticsearch, Logstash,Kibana) for different application log files and display each application separately in Kibana?](https://discuss.elastic.co/t/how-to-configure-elk-elasticsearch-logstash-kibana-for-different-application-log-files-and-display-each-application-separately-in-kibana/70411/12):
>
> is this my else condition which cause logstash-\* index ? It sounds like you effectively have this: output { if [type] == "OnsuranceAppLog" { elasticsearch { hosts =\> ["localhost:9200"] index =\> "onsurance-%{+YYYY.MM.dd}" } } else { elasticsearch { hosts =\> ["localhost:9200"] } stdout { codec =\> rubydebug } } if [type] == "iis" { elasticsearch { hosts =\> ["localhost:9200"] index =\> "iis-%{+YYYY.MM.dd}" } } else { elas…

Whats your Suggestion? do i still need a Logstash ? i have not yet tested Filebeat and prospector level filtering, that's why asking community about there experiences ?

Thanks in advance  
best regards

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 10, 2017, 10:00am UTC](https://discuss.elastic.co/t/why-do-i-need-logstash-if-filebeat-can-send-data-to-elasticsearch/70965/5 "2017-01-10T10:00:28Z")

</div>

You might be able to use the ingest node feature of ES to parse those logs, but I haven't used it myself. Filebeat and Elasticsearch without the ingest feature won't be sufficient.

---

<div class="post-metadata">

**Author:** ![sezanawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sezanawa/32/21910_2.png) [@sezanawa](https://discuss.elastic.co/u/sezanawa)\
**Post date:** [January 10, 2017, 10:22am UTC](https://discuss.elastic.co/t/why-do-i-need-logstash-if-filebeat-can-send-data-to-elasticsearch/70965/6 "2017-01-10T10:22:29Z")

</div>

@magnusbaeck Thanks a lot for your suggestion. i will try the ingest. let see how good it work for me 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2017, 10:22am UTC](https://discuss.elastic.co/t/why-do-i-need-logstash-if-filebeat-can-send-data-to-elasticsearch/70965/7 "2017-02-07T10:22:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
