# Wowza logs =\> filebeat =\> kibana

**URL:** <https://discuss.elastic.co/t/wowza-logs-filebeat-kibana/231698>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 8, 2020, 10:36am UTC](https://discuss.elastic.co/t/wowza-logs-filebeat-kibana/231698 "2020-05-08T10:36:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jozz](https://avatars.discourse-cdn.com/v4/letter/j/53a042/32.png) [@Jozz](https://discuss.elastic.co/u/Jozz)\
**Post date:** [May 8, 2020, 10:36am UTC](https://discuss.elastic.co/t/wowza-logs-filebeat-kibana/231698/1 "2020-05-08T10:36:57Z")

</div>

I'm looking into getting our wowza logs in kibana. One of my predecessors has set up our ELK stack. I started filebeat, because it wasn't running on the server. I do see exim4 log entry's in kibana, but nothing related to wowza.

This is my filebeat.yml  
I only added the last two entries, related to wowza.

```auto
<code>
#=========================== Filebeat prospectors =============================

filebeat.inputs:
- type: log
  enabled: true
  paths:
    - "/var/log/auth.log"
  fields:
     log_type: authlog

- type: log
  enabled: true
  paths:
    - "/var/log/exim4/mainlog"
  fields:
     log_type: eximlog

- type: log
  enabled: true
  paths:
    - "/var/log/apache2/*https_access.log"
  fields:
     log_type: accesshttpsv1

- type: log
  enabled: true
  paths:
    - "/var/log/apache2/*http_access.log"
  fields:
     log_type: accesshttpv1

- type: log
  enabled: true
  paths:
    - "/var/log/nginx/*https_access.log"
  fields:
     log_type: accessNGINXhttpsv1

- type: log
  enabled: true
  paths:
    - "/var/log/nginx/*http_access.log"
  fields:
     log_type: accessNGINXhttpv1

- type: log
  enabled: true
  paths:
    - "/var/log/haproxy.log"
  fields:
     log_type: haproxylog

- type: log
  enabled: true
  paths:
    - "/usr/local/WowzaStreamingEngine/logs/wowzastreamingengine_access.log"
  fields:
     application: "wowza"

- type: log
  enabled: true
  paths:
    - "/usr/local/WowzaStreamingEngine/logs/wowzastreamingengine_error.log"
  fields:
     application: "wowza"

#================================ Outputs =====================================

#----------------------------- Logstash output --------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["SOMEIPADDRESS:5044"]
  #bulk_max_size: 1024

  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  #ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]
  #certificate_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]
  # Certificate for SSL client authentication
  #ssl.certificate: "/etc/pki/client/cert.pem"
  ssl.enabled: false

  # Client Certificate Key
  #ssl.key: "/etc/pki/client/cert.key"

</code>

```

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [May 11, 2020, 12:42pm UTC](https://discuss.elastic.co/t/wowza-logs-filebeat-kibana/231698/2 "2020-05-11T12:42:08Z")

</div>

Hey @Jozz, welcome to discuss 🙂

How were these logs being collected before? using logstash?

There are some things that you could check:

- Wowza is actually writing logs to these files.
- Filebeat has permissions to read these files.

Please also check in filebeat logs what harvesters it is starting, and if there was any error.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2020, 12:42pm UTC](https://discuss.elastic.co/t/wowza-logs-filebeat-kibana/231698/3 "2020-06-08T12:42:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
