# Does heartbeat have the ability to capture response headers directly?

**URL:** <https://discuss.elastic.co/t/does-heartbeat-have-the-ability-to-capture-response-headers-directly/231337>\
**Category:** Beats\
**Tags:** heartbeat\
**Created:** [May 6, 2020, 12:15pm UTC](https://discuss.elastic.co/t/does-heartbeat-have-the-ability-to-capture-response-headers-directly/231337 "2020-05-06T12:15:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tholfie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tholfie/32/67823_2.png) [@tholfie](https://discuss.elastic.co/u/tholfie)\
**Post date:** [May 6, 2020, 12:15pm UTC](https://discuss.elastic.co/t/does-heartbeat-have-the-ability-to-capture-response-headers-directly/231337/1 "2020-05-06T12:15:56Z")

</div>

Hello,

I'm currently wondering if Heartbeat has the ability to capture response headers instead of just checking for them, i.e. the event of heartbeat checking an url and then parsing the response headers to elastic.

It would be nice if heartbeat had the possibility to do "http.response.header.contents: always, on error, never"

Is this possible or is it required to combine the inputs form a heartbeat and packetbeat instance, and then create an index pattern?

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [May 6, 2020, 9:17pm UTC](https://discuss.elastic.co/t/does-heartbeat-have-the-ability-to-capture-response-headers-directly/231337/2 "2020-05-06T21:17:05Z")

</div>

Not currently, but it's a relatively easy add. I've created [https://github.com/elastic/beats/pull/18327](https://github.com/elastic/beats/pull/18327) to track this.

The PR as written just lets you turn them on or off. Is there a reason you'd only want them on error? Headers tend to be quite small. We created `on_error` for the body because the contents by default store up to 2KiB.

---

<div class="post-metadata">

**Author:** ![tholfie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tholfie/32/67823_2.png) [@tholfie](https://discuss.elastic.co/u/tholfie)\
**Post date:** [May 13, 2020, 7:22am UTC](https://discuss.elastic.co/t/does-heartbeat-have-the-ability-to-capture-response-headers-directly/231337/3 "2020-05-13T07:22:49Z")

</div>

Thank you Andrew.

There was no particular reason for them to be on\_error. i am not very experienced with elastic yet so i am not thinking correctly at certain moments. but a certain part of our organisation was wondering if capturing the response headers are possible.

thanks again! Hoping this will be merged or available in the future!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2020, 7:22am UTC](https://discuss.elastic.co/t/does-heartbeat-have-the-ability-to-capture-response-headers-directly/231337/4 "2020-06-10T07:22:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
