While running fresh Elastic stack version 6.0.0 alpha, most Packetbeat events cannot be indexed.
I have loaded Packetbeat template into Elasticsearch before running Logstash and Packetbeat. Logstash only indexes events with one type and reports error when trying to index different type.
By default Elasticsearch 6.0.0 forces single type indices, while Packetbeat is using multiple types (http,icmp,flow).
index.mapping.single_type : false to the index template fixes the problem.