pylogbeat
Simple, incomplete implementation of the Beats protocol used by Elastic Beats and Logstash.
Decision gist · record as of 2026-08-14
Yes, if you are already using Logstash with beats input and need a Python client. The package is stable, dependency-free, and actively maintained. However, the incomplete protocol implementation and aging maintenance status (264 days since last release) mean it is best suited for straightforward send-and-acknowledge workflows; verify compatibility with your Logstash version and confirm the protocol gaps do not affect your use case before adopting.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python >= 3.11.
- Logstash server must be >= 5.6.12 or >= 6.4.0 due to a known bug in earlier versions.
- Low friction installation as a pure-Python wheel with no runtime dependencies.
License · maintenance · safety
Apache License 2.0 (permissive) — Licensed under Apache License 2.0 (permissive), imposing no significant restrictions on use or distribution in most contexts.
last release 2025-11-23 (264 days) · last repo commit 2025-11-23 · 17 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,155,229 downloads/mo, #4,290 on PyPI
Alternatives
Verify before relying
from pylogbeat import PyLogBeatClient
message = {'@timestamp': '2018-01-02T01:02:03', '@version': '1', 'message': 'hello world'}
with PyLogBeatClient('localhost', 5959, ssl_enable=False) as client:
client.send([message])- Whether the Beats protocol implementation is feature-complete or whether gaps beyond 'sending data and waiting for ACK' affect real-world use.
- Current compatibility with recent Logstash versions beyond the documented requirement of Logstash >= 5.6.12 or >= 6.4.0.
What it is and what it does
PyLogBeat is a client library that implements the Beats protocol, an Elastic-defined transport mechanism for sending log messages and structured data to Logstash or other compatible services. Unlike raw TCP or UDP, the Beats protocol includes server acknowledgment, so the client knows whether data was received and what needs to be resent, providing higher reliability for log delivery.
The library accepts messages as dictionaries, JSON strings, or bytes, and supports both plain and SSL-encrypted connections. It is intentionally incomplete—the protocol specification is not officially published—and implements the core send-and-acknowledge flow. The package has no external runtime dependencies, making installation straightforward, but it requires Python 3.11 or later and a compatible Logstash version to function.
Use it for
- Send application logs from Python services to a Logstash beats input with guaranteed delivery acknowledgment.
- Ship structured event data (with timestamps, metadata, and context) to Logstash for centralized log aggregation.
- Replace direct TCP/UDP logging with a protocol that confirms receipt, reducing log loss in production environments.
- Integrate Python applications into an Elastic Stack (Beats/Logstash/Elasticsearch) logging pipeline.
- Use SSL-encrypted connections to send logs securely to a remote Logstash server with certificate validation.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are already using Logstash with beats input and need a Python client.
The package is stable, dependency-free, and actively maintained. However, the incomplete protocol implementation and aging maintenance status (264 days since last release) mean it is best suited for straightforward send-and-acknowledge workflows; verify compatibility with your Logstash version and confirm the protocol gaps do not affect your use case before adopting.
Install
pylogbeat on PyPI
Before you install
Low friction installation as a pure-Python wheel with no runtime dependencies. Maintenance status is aging—last release was 264 days ago, though the repository remains active and the package is marked Production/Stable.
Requires Python >= 3.11. Logstash server must be >= 5.6.12 or >= 6.4.0 due to a known bug in earlier versions.
License in practice
Licensed under Apache License 2.0 (permissive), imposing no significant restrictions on use or distribution in most contexts.
Quickstart
from pylogbeat import PyLogBeatClient
message = {'@timestamp': '2018-01-02T01:02:03', '@version': '1', 'message': 'hello world'}
with PyLogBeatClient('localhost', 5959, ssl_enable=False) as client:
client.send([message])
Verify before relying
- Whether the Beats protocol implementation is feature-complete or whether gaps beyond 'sending data and waiting for ACK' affect real-world use.
- Current compatibility with recent Logstash versions beyond the documented requirement of Logstash >= 5.6.12 or >= 6.4.0.
Package facts
| License | Apache License 2.0 permissive |
| Python support | Supports the current Python release >=3.11 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Aging 264 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,155,229 / month, #4,290 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Topic :: Internet :: WWW/HTTPTopic :: Software Development :: Libraries :: Python ModulesTopic :: System :: Logging |
Evidence: pylogbeat-2.1.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “logstash beats protocol client”
- pylogbeatPyLogBeat sends log messages and structured data to Logstash's beats…
- python3-logstashA Python logging handler that forwards log messages to Logstash via…
- python-logstashSends Python log records to Logstash over UDP or TCP, formatting them…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also python-logstash · python3-logstash · python-logstash-async · logstash_formatter · JSON-log-formatter · ecs-logging · elastic-opentelemetry · pygelf · pygrok · google-cloud-logging