Hi I have installed Filebeat 5.4 on ubuntu server and where multiple logs like web.log, email.log available, need to forward to logstash server (ELK) to see in kibana.
Here my filebeat.yml file as below
filebeat.prospectors:
- input_type: log
document_type: web_log
paths:
- /var/log/web.log
fields:
log_type: weblog
fields_under_root: true
- input_type: log
document_type: email_log
paths:
- /var/log/email.log
fields:
log_type: emaillog
fields_under_root: true
beat.name: 10.0.0.0
Where in Kibana expecting Discover should have
filebeat.hostname should be hostname of server
where beat.name should be server IP
So I have given beat.name as , but in kibana dashboard its coming as below
July 3rd 2017, 10:50:41.038 log_type:weblog @timestamp:July 3rd 2017, 10:50:41.038 offset:107 @version:1 input_type:log beat.hostname:filebeat-ubuntu beat.name:filebeat-ubuntu beat.version:5.4.2 host:filebeat-ubuntu source:/var/log/web.log message:2017-06-01 12:15:39 INFO PortalUpload- Upload Structure Data webservice invoked from partner Id thyrocare type:web_log tags:beats_input_codec_plain_applied _id:AV0G5L5dcY69oGswS0N3 _type:web_log _index:filebeat-2017.07.03 _score: -
Though I have given beat.name in filebeat.yml, its not reflecting.