I've set up a 7.11 Kibana-Elastisearch-Logstash-Beats stack more-or-less successfully, but I am unable to configure metricbeat to use logstash. (I am able to see metricbeat data sending it directly to elastisearch.)
Following the tutorial, at Add user information in Logstash | Elasticsearch Reference [7.11] | Elastic, step 3 on this page says that the link Getting started with the Elastic Stack | Getting Started [7.11] | Elastic showed how to configure metricbeat to use logstash, but it doesn't. The referenced tutorial only explains how to configure metricbeat to use elasticsearch directly. I have been unable to find a tutorial explaining how to get metricbeat to feed logstash, and have been unable to figure out how to do it. I'm guessing it isn't complicated, but that I'm just missing something that will be obvious in retrospect.
I also wanted to report what appears to be an error in the tutorial.
To answer the obvious question, "What's your goal?" the answer is simple--I just want to understand how to do this. Once I get it working, I'll evaluate whether logstash is helping in this use case.
That's what I assumed initially and tried it; no errors, but also no data going to Kibana. I'm assuming there are specific metricbeat Logstash ingest/parsing/output files required, but can't find any tutorials on that. I have a Logstash pipeline set up based on the link you provided, and it's working for filebeats.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.