# \[AWS\] Functionbeat to logstash config problem

**URL:** <https://discuss.elastic.co/t/aws-functionbeat-to-logstash-config-problem/168842>\
**Category:** Beats\
**Tags:** functionbeat\
**Created:** [February 18, 2019, 1:58pm UTC](https://discuss.elastic.co/t/aws-functionbeat-to-logstash-config-problem/168842 "2019-02-18T13:58:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcin\_Druzgala](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcin_druzgala/32/45030_2.png) [@Marcin\_Druzgala](https://discuss.elastic.co/u/Marcin_Druzgala)\
**Post date:** [February 18, 2019, 1:58pm UTC](https://discuss.elastic.co/t/aws-functionbeat-to-logstash-config-problem/168842/1 "2019-02-18T13:58:52Z")

</div>

Hi so I have prepared following config for my functionbeat:

```
functionbeat.provider.aws.deploy_bucket: "functionbeat-deploy"

functionbeat.provider.aws.functions:
  - name: cloudwatch
    enabled: true
    type: cloudwatch_logs
    description: "lambda function for cloudwatch logs"
    triggers:
      - log_group_name: /aws/lambda/test
        filter_pattern: ""

output.logstash:
  hosts: ["url"]
  
processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~

```

But when it runs I can see something like that in logs:

> error unpacking config data: more than one namespace configured accessing 'output'

I've even tried to add section for output.elasticsearch and setting the 'enabled: false' flag but then it complained that I didn't provide hosts for Elasticsearch configuration.

Any ideas?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [February 18, 2019, 8:34pm UTC](https://discuss.elastic.co/t/aws-functionbeat-to-logstash-config-problem/168842/2 "2019-02-18T20:34:24Z")

</div>

> [@Marcin\_Druzgala](#):
>
> error unpacking config data: more than one namespace configured accessing 'output'

Hello @Marcin_Druzgala,

Functionbeat currently only support the elasticsearch output, but we should give you a better error message when you don't have it enabled. I have created this issue [Functionbeat validation of the presence of the Elasticsearch is not done before the pipeline is created. · Issue #10813 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/10813)

---

<div class="post-metadata">

**Author:** ![Marcin\_Druzgala](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcin_druzgala/32/45030_2.png) [@Marcin\_Druzgala](https://discuss.elastic.co/u/Marcin_Druzgala)\
**Post date:** [February 18, 2019, 9:17pm UTC](https://discuss.elastic.co/t/aws-functionbeat-to-logstash-config-problem/168842/3 "2019-02-18T21:17:41Z")

</div>

Hi Pier,

Thanks for the response! Any idea when other output types will be supported?

---

<div class="post-metadata">

**Author:** ![kettunen](https://avatars.discourse-cdn.com/v4/letter/k/46a35a/32.png) [@kettunen](https://discuss.elastic.co/u/kettunen)\
**Post date:** [February 21, 2019, 2:31pm UTC](https://discuss.elastic.co/t/aws-functionbeat-to-logstash-config-problem/168842/4 "2019-02-21T14:31:48Z")

</div>

Hi @pierhugues,

what does "Logstash (optional) for parsing and enhancing the data." mean in [https://www.elastic.co/guide/en/beats/functionbeat/current/functionbeat-getting-started.html](https://www.elastic.co/guide/en/beats/functionbeat/current/functionbeat-getting-started.html)? I thought it means that we can stream logs from Functionbeat to logstash but does it mean something else?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [March 6, 2019, 8:07pm UTC](https://discuss.elastic.co/t/aws-functionbeat-to-logstash-config-problem/168842/5 "2019-03-06T20:07:05Z")

</div>

I will make a PR to remove that from the doc. It should not be there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2019, 10:07am UTC](https://discuss.elastic.co/t/aws-functionbeat-to-logstash-config-problem/168842/6 "2019-03-27T10:07:13Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
