# Beats configuration: overlaping between output.elasticsearch and cloud.\*?

**URL:** <https://discuss.elastic.co/t/beats-configuration-overlaping-between-output-elasticsearch-and-cloud/226704>\
**Category:** Beats\
**Created:** [April 6, 2020, 12:05pm UTC](https://discuss.elastic.co/t/beats-configuration-overlaping-between-output-elasticsearch-and-cloud/226704 "2020-04-06T12:05:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ffknob](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ffknob/32/37008_2.png) [@ffknob](https://discuss.elastic.co/u/ffknob)\
**Post date:** [April 6, 2020, 12:05pm UTC](https://discuss.elastic.co/t/beats-configuration-overlaping-between-output-elasticsearch-and-cloud/226704/1 "2020-04-06T12:05:46Z")

</div>

Hi

I'm just curious about the needed settings in a Beat file when the cluster is in the Elastic cloud.

Currently my config files looks like this:

```auto
output.elasticsearch:
  hosts: ["https://....us-east-1.aws.found.io:..."]
  username: "monitor"
  password: "${MONITOR_PASSWORD}"
  compression_level: 3

setup.kibana:
  host: "....us-east-1.aws.found.io:..."
  protocol: "https"

cloud.id: "monitor:...=="
cloud.auth: "monitor:${MONITOR_PASSWORD}"

```

The docs state that I could use the `cloud.*` output to make things easier. But that output doesn't have settings like the `compression_level` for instance.

Could the above configuration be reduced to something like this:

```auto
output.elasticsearch:
  compression_level: 3

cloud.id: "monitor:...=="
cloud.auth: "monitor:${MONITOR_PASSWORD}"

```

1. Should I choose between `output.elasticsearch` or `cloud.*`?
2. Shoul I use both because I want to set the `compression_level`?
3. What is the `setup.kibana` used for? Only to set the dashboards one time for cluster?

Thank you

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 6, 2020, 6:48pm UTC](https://discuss.elastic.co/t/beats-configuration-overlaping-between-output-elasticsearch-and-cloud/226704/2 "2020-04-06T18:48:32Z")

</div>

Hey @ffknob,

Take a look to this documentation page: [https://www.elastic.co/guide/en/beats/filebeat/7.6/configure-cloud-id.html](https://www.elastic.co/guide/en/beats/filebeat/7.6/configure-cloud-id.html)

In principle `cloud.auth` and `cloud.id` only overwrite the options metioned there. Rest of the options can be used the same as if cloud settings were not being used.

---

<div class="post-metadata">

**Author:** ![ffknob](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ffknob/32/37008_2.png) [@ffknob](https://discuss.elastic.co/u/ffknob)\
**Post date:** [April 6, 2020, 7:12pm UTC](https://discuss.elastic.co/t/beats-configuration-overlaping-between-output-elasticsearch-and-cloud/226704/4 "2020-04-06T19:12:57Z")

</div>

Thanks for the answer @jsoriano

I've just read that too fast... Here is the answer in the docs you provided:

```auto
The Cloud ID, which can be found in the Elastic Cloud web console, is used by Filebeat to resolve the Elasticsearch and Kibana URLs. This setting overwrites the output.elasticsearch.hosts and setup.kibana.host settings.

```

So I guess I should set `cloud.*` for the Beat to know to where it should send its data (`output.elasticsearch.hostsl`), but I could also set `output.elasticsearch.compress_level` for example.

Thank you

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 7, 2020, 7:51am UTC](https://discuss.elastic.co/t/beats-configuration-overlaping-between-output-elasticsearch-and-cloud/226704/5 "2020-04-07T07:51:13Z")

</div>

Yes, that's it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2020, 9:51am UTC](https://discuss.elastic.co/t/beats-configuration-overlaping-between-output-elasticsearch-and-cloud/226704/6 "2020-05-05T09:51:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
