Beats and Topology Maps


#1

Hi,
In the docs it says that for topology mapping to work elasticsearch must be enabled as an output. In most circumstances users will need to send logs via logstash for sanitisation.

So, will it not be that enabling elasticsearch as an output, to enable this feature, leads to duplication entries in elasticsearch?

Regards,
David


(ruflin) #2

Topology is a feature related to packetbeat where most people connect directly to elasticsearch. The topology option only makes sense for Packetbeat.


#3

I see, it's described in the documentation for filebeat and is described in filebeat.yml. Thanks for clarifying :slightly_smiling:


(DeDe Morton) #4

That's an unfortunate side effect of using shared config options across the Beats (the doc content comes from a shared file). :frowning: I can't remove the description from the Filebeat doc, but I will make sure that the limitation is clearly stated wherever the topology is discussed.


(system) #5