Why log comming from filebeat are automaticaly parsed with output elastic and not with logstash


When I set the output to elastic in my filebeat config, all the logs from modules like apache2 are automatically parsed but when I send them to logstash, they are not.

  • Is this a wanted behaviour ?
  • Couldn't they be automatically parsed when sent to logstash ?
  • Who is parsing them when sending them to elastic, elastic or filebeat ?
  • Is it possible to have two output when running a single instance of filebeat ?


This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.