Hi Stephen
thank you for your reply here, appreciate it.
No sorry Stephen, I meant the logs-elastic_agent.packetbeat-default is there, but the packetbeat-* is not.
That is correct, I did not explicit state this, I am new to all this and figured the L in ELK was enough, sorry this was not clear.
I have 2 logstash servers in front of Elasticsearch. Elastic Agents deployed with various integrations, including the packetbeat (renamed to Network Capture I believe).
Nothing have been done on the agent configuration, it runs the default agent config. The same applies to the logstash.yml, I only changed it to support queues (memory->persistent), nothing else have been changed. Perhaps I need to run a plugin, the docs does indicate I don't have to do anything special here, but
The output filter in Fleet UI have been configured to Logstash and I have added support for loadbalancer and 4 workers. This is reflected on the agent side running an inspect.
Literally everything else is runnig as expected(ML jobs, security rules), except for the packetbeat index not being created.
how can I verify this ? api, some version setting ? I made sure 8.7.1 across the stack.
I stopped believing I can not show you this as I have no idea where data is ending up, should they actually arrive, but suggestions are welcome on how to diagnose this further.
That is not possible either as this results in an error messages telling me packetbeat-* is missing
I am looking at my logstash filter, this is configured to handle data_streams, I was wondering if I have to create one more elasticsearch output specifying the :
index => "%{[@metadata][beat]}-%{[@metadata][version]}
?
support ticket sure, last resort.
My main beef with this is, 'most' topics in this forum seems to end with a "DM" or "raise a support ticket". All this is great for the individual having a problem, but what about people with similar problems, the are left behind. All I am saying is, it should be accessible to everybody.
Anyway I not here to change anything, be gentle I am new to all this.