Tool Comparison · 2026 Edition

Filebeat vs Logstash: Lightweight Shipper or Rich Pipeline?

Filebeat and Logstash are two components of the Elastic Stack. Filebeat is a tiny Go-based log shipper. Logstash is a Java-based data processor. They solve different problems — most production ELK stacks use both. Here's when and how.

TL;DR

Key takeaways

  • Filebeat ships log files to a destination (Elasticsearch, Logstash, Kafka). It is written in Go, uses tens of MB of RAM, and has minimal CPU overhead.
  • Logstash is a general-purpose ETL pipeline. It can read from many sources (Beats, Kafka, syslog, HTTP), run complex filters (grok, mutate, geoip), and write to many destinations.
  • Typical production: Filebeat on each host → Logstash (parse, enrich) → Elasticsearch. Filebeat alone can also write directly to Elasticsearch for simple cases.
  • The two are complementary, not competitors. 'Use both' is the usual answer.

Filebeat: the lightweight shipper

Filebeat is a single Go binary (~30 MB) that tails log files, tracks offsets, and streams events upstream.

It supports modules for common log formats (nginx, apache, mysql, kubernetes) with ready-made parsers.

Resource overhead: typically 20–60 MB RAM, <1% CPU on a busy host. Safe to install on every production node.

No complex filter language — field extraction is handled either in Filebeat modules (ingest pipeline sent to Elasticsearch) or downstream in Logstash.

Logstash: the rich processor

Logstash runs on the JVM and typically needs 500 MB+ RAM per instance. It is heavier and usually deployed as a central tier, not per-host.

The filter DSL supports grok (regex parsing), mutate (field transforms), geoip (IP → location), date (parse timestamps), kv, split, drop, and ~100 others.

Logstash can also run complex routing: send errors to one Elasticsearch cluster, metrics to another, and warnings to Slack.

If you need parsing and enrichment that Filebeat modules can't do, Logstash is where it belongs.

Performance and scale

Filebeat scales horizontally (one per host). Throughput depends on disk read speed; typically tens of MB/s per host.

Logstash scales horizontally too, but as a central tier. A single Logstash node handles ~5–15k events/sec depending on filter complexity.

If Logstash becomes the bottleneck, teams either tune pipeline workers, split pipelines, or move to Elasticsearch ingest pipelines (processor-based alternative).

In Kubernetes, Fluent Bit (an alternative to Filebeat written in C) is often chosen for even lower resource usage.

Modern alternatives: ingest pipelines, Fluent Bit, Vector

Elasticsearch ingest pipelines move Logstash-style processing into Elasticsearch itself — simpler ops when it fits.

Fluent Bit is a smaller alternative to Filebeat for Kubernetes (3 MB binary, <10 MB RAM); it includes basic parsing.

Vector (by Datadog, open source) is a newer Rust-based agent that can replace both Filebeat and Logstash with better perf.

For managed log pipelines without running any of this yourself, Atatus Logs accepts syslog, Filebeat, Fluent Bit, Vector, and OTel natively — the pipeline becomes someone else's problem.

Side-by-side comparison

Filebeat

Pros

  • Tiny Go binary (~30 MB)
  • Low resource overhead
  • Modules for common log formats
  • Safe for every host

Cons

  • Minimal filter capability
  • Routes to one destination at a time
  • Needs Logstash or ingest pipelines for parsing

Pricing: Free (Apache 2.0)

Best for: Shipping logs with minimal overhead

Logstash

Pros

  • Rich filter DSL (grok, mutate, geoip)
  • Multi-source, multi-destination
  • Complex routing
  • Mature ecosystem

Cons

  • Heavy (JVM, 500 MB+ RAM)
  • Operational overhead
  • Can be a bottleneck

Pricing: Free (Elastic License / Apache 2.0 for OSS)

Best for: Central log parsing + enrichment

Atatus Logs

Pros

  • Managed ingest + storage + search
  • Accepts Filebeat, Fluent Bit, Vector, OTel
  • Built-in parsing + enrichment
  • Correlated with APM traces

Cons

  • SaaS by default (on-prem available)

Pricing: Flat per-host, logs included

Best for: Teams who want logs without running the pipeline

Verdict

Filebeat ships logs; Logstash transforms and routes them. They complement each other in the ELK stack. For small deployments, Filebeat + Elasticsearch ingest pipelines is enough. For complex parsing, add Logstash. For a fully managed alternative that accepts Filebeat and Fluent Bit input directly, Atatus Logs replaces the whole pipeline.

Ship Filebeat logs to Atatus (managed storage + search)

Unified APM, logs, RUM, infrastructure monitoring, and SIEM in one AI observability platform. Flat pricing, zero bill shock.