# Elastic agent (metricbeat logs): Cannot index event publisher.Event

**URL:** <https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364>\
**Category:** Beats\
**Tags:** fleet, metricbeat, elastic-agent\
**Created:** [August 24, 2021, 2:36pm UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364 "2021-08-24T14:36:12Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gomeisa](https://avatars.discourse-cdn.com/v4/letter/g/bcef8e/32.png) [@Gomeisa](https://discuss.elastic.co/u/Gomeisa)\
**Post date:** [August 24, 2021, 2:36pm UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/1 "2021-08-24T14:36:12Z")

</div>

Hi,  
I have recently installed a fleet-managed Elastic Agent on my servers.  
my metricbeat\_monitor-json.log is flooded with this message:

```auto
{"log.level":"warn","@timestamp":"2021-08-24T15:26:57.009+0430","log.logger":"elasticsearch","log.origin":{"file.name":"elasticsearch/client.go","file.line":405},"message":"Cannot index event publisher.Event
{Content:beat.Event{Timestamp:time.Time{wall:0xc04151fdfa1f75b2, ext:100618413248, loc:(*time.Location)(0x55f1d31de540)}, Meta:{\"raw_index\":\"metrics-elastic_agent.elastic_agent-default\"},
 Fields:{\"agent\":{\"ephemeral_id\":\"d58f26d0-b6d5-460b-b58c-f9537f6fa6b9\",\"hostname\":\"WebSite\",\"id\":\"70a0303b-52c6-4545-8255-e792c1874e46\",\"name\":\"WebSite\",\"type\":\"metricbeat\",\"version\":\"7.14.0\"},
\"data_stream\":{\"dataset\":\"elastic_agent.elastic_agent\",\"namespace\":\"default\",\"type\":\"metrics\"},\"ecs\":{\"version\":\"1.10.0\"},\"elastic_agent\":{\"id\":\"70a0303b-52c6-4545-8255-e792c1874e46\",\"process\":\"elastic-agent\",\"snapshot\":false,\"version\":\"7.14.0\"},
\"event\":{\"dataset\":\"elastic_agent.elastic_agent\",\"duration\":3218409,\"module\":\"http\"},\"host\":{\"architecture\":\"x86_64\",\"containerized\":false,\"hostname\":\"WebSite\",\"id\":\"c56358f080224ce980088fdfb18ab45c\",\"ip\":[\"192.168.100.22\",\"fe80::7403:c2ff:fe62:de39\"],\"mac\":[\"76:04:c8:62:dc:39\"],
\"name\":\"WebSite\",\"os\":{\"codename\":\"Core\",\"family\":\"redhat\",\"kernel\":\"3.10.0-1160.25.1.el7.x86_64\",\"name\":\"CentOS Linux\",\"platform\":\"centos\",\"type\":\"linux\",\"version\":\"7 (Core)\"}},\"metricset\":{\"name\":\"json\",\"period\":10000},\"service\":{\"address\":\"http://unix/stats\",\"type\":\"http\"},
\"system\":{\"process\":{\"cpu\":{\"system\":{\"ticks\":90040.000000,\"time\":{\"ms\":90044.000000}},\"total\":{\"ticks\":281690.000000,\"time\":{\"ms\":281699.000000},\"value\":281690.000000},\"user\":{\"ticks\":191650.000000,\"time\":{\"ms\":191655.000000}}},\"fd\":{\"limit\":{\"hard\":4096.000000,\"soft\":1024.000000},\"open\":19.000000},
\"memory\":{\"size\":75580424.000000}}}}, Private:interface {}(nil), TimeSeries:true}, Flags:0x0, Cache:publisher.EventCache{m:common.MapStr(nil)}} (status=400): {\"type\":\"illegal_argument_exception\",\"reason\":\"pipeline with id [metrics-elastic_agent.elastic_agent-0.0.7] does not exist\"}","service.name":"metricbeat","event.dataset":"metricbeat_monitor-json.log","ecs.version":"1.6.0"}

```

I ended up disabling all Metricbeats related logs in "Linux" and "System" integrations.  
Any suggestions would be appreciated.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [August 25, 2021, 7:33am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/2 "2021-08-25T07:33:53Z")

</div>

Which version of Elastic Agent and Kibana are you on? Is it possible that you are on 7.13? Even though the issue should not be seen on 7.13 it should resolve itself when you upgrade to 7.14. Please make sure the `Elastic Agent` integration on the Integrations page in Kibana is on version 1.0 or newer.

---

<div class="post-metadata">

**Author:** ![Gomeisa](https://avatars.discourse-cdn.com/v4/letter/g/bcef8e/32.png) [@Gomeisa](https://discuss.elastic.co/u/Gomeisa)\
**Post date:** [August 25, 2021, 12:15pm UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/3 "2021-08-25T12:15:04Z")

</div>

Elastic Agent and Kibana are 7.14.0 and Elastic Agent in integration page is version 1.0.0 . but I haven't add Elastic Agent integration to any of my policies.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [August 26, 2021, 8:02am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/4 "2021-08-26T08:02:48Z")

</div>

I'm asking because of this error in the logs:

```auto
status=400): {\"type\":\"illegal_argument_exception\",\"reason\":\"pipeline with id [metrics-elastic_agent.elastic_agent-0.0.7] does not exist\"}

```

Did you upgrade this setup from 7.13? I'm trying to figure out why this pipeline would still be used. If th elastic\_agent package 1.0 is installed, this pipeline should not be in use anymore. The package is installed by default as elastic\_agent ships logs and metrics (if enabled) to these data streams.

Assuming you upgraded from 7.13, do you see it only in the "old" logs or this keeps happening? If it keeps happening, I'm curious to see what the mapping of the `metrics-elastic_agent.elastic_agent-default`looks like. Especially what the ingest pipeline setting is inside. Any chance you could take a look there? You should see this in Kibana under Index Management -\> Data Streams.

---

<div class="post-metadata">

**Author:** ![Gomeisa](https://avatars.discourse-cdn.com/v4/letter/g/bcef8e/32.png) [@Gomeisa](https://discuss.elastic.co/u/Gomeisa)\
**Post date:** [August 28, 2021, 3:53am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/5 "2021-08-28T03:53:46Z")

</div>

Sorry for the late response.  
I used to have Filebeat and Metricbeat on these servers (version 7.9) but I uninstalled those instances and installed elastic agent 7.14 instead. Elasticsearch and Kibana were upgraded from version 7.13.

> [@ruflin](#):
>
> Assuming you upgraded from 7.13, do you see it only in the "old" logs or this keeps happening

I keep receiving these logs.

> [@ruflin](#):
>
> what the mapping of the `metrics-elastic_agent.elastic_agent-default` looks like.

I hope this is what you meant.

```auto
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "metrics"
        },
        "codec": "best_compression",
        "mapping": {
          "total_fields": {
            "limit": "10000"
          }
        },
        "refresh_interval": "5s",
        "number_of_shards": "1",
        "final_pipeline": ".fleet_final_pipeline-1",
        "query": {
          "default_field": [
            "cloud.account.id",
            "cloud.availability_zone",
            "cloud.instance.id",
            "cloud.instance.name",
            "cloud.machine.type",
            "cloud.provider",
            "cloud.region",
            "cloud.project.id",
            "cloud.image.id",
            "container.id",
            "container.image.name",
            "container.name",
            "host.architecture",
            "host.domain",
            "host.hostname",
            "host.id",
            "host.mac",
            "host.name",
            "host.os.family",
            "host.os.kernel",
            "host.os.name",
            "host.os.platform",
            "host.os.version",
            "host.os.build",
            "host.os.codename",
            "host.type",
            "elastic_agent.id",
            "elastic_agent.process",
            "elastic_agent.version",
            "system.process.cgroup.id",
            "system.process.cgroup.path",
            "system.process.cgroup.cpu.id",
            "system.process.cgroup.cpu.path",
            "system.process.cgroup.cpuacct.id",
            "system.process.cgroup.cpuacct.path",
            "system.process.cgroup.memory.id",
            "system.process.cgroup.memory.path",
            "system.process.cgroup.blkio.id",
            "system.process.cgroup.blkio.path"
          ]
        },
        "number_of_routing_shards": "30"
      }
    },
    "mappings": {
      "dynamic": "false",
      "_meta": {
        "package": {
          "name": "elastic_agent"
        },
        "managed_by": "ingest-manager",
        "managed": true
      },
      "dynamic_templates": [
        {
          "strings_as_keyword": {
            "match_mapping_type": "string",
            "mapping": {
              "ignore_above": 1024,
              "type": "keyword"
            }
          }
        }
      ],
      "date_detection": false,
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "cloud": {
          "properties": {
            "account": {
              "properties": {
                "id": {
                  "type": "keyword",
                  "ignore_above": 1024
                }
              }
            },
            "availability_zone": {
              "type": "keyword",
              "ignore_above": 1024
            },
            "image": {
              "properties": {
                "id": {
                  "type": "keyword",
                  "ignore_above": 1024
                }
              }
            },
            "instance": {
              "properties": {
                "id": {
                  "type": "keyword",
                  "ignore_above": 1024
                },
                "name": {
                  "type": "keyword",
                  "ignore_above": 1024
                }
              }
            },
            "machine": {
              "properties": {
                "type": {
                  "type": "keyword",
                  "ignore_above": 1024
                }
              }
            },
            "project": {
              "properties": {
                "id": {
                  "type": "keyword",
                  "ignore_above": 1024
                }
              }
            },
            "provider": {
              "type": "keyword",
              "ignore_above": 1024
            },
            "region": {
              "type": "keyword",
              "ignore_above": 1024
            }
          }
        },
        "container": {
          "properties": {
            "id": {
              "type": "keyword",
              "ignore_above": 1024
            },
            "image": {
              "properties": {
                "name": {
                  "type": "keyword",
                  "ignore_above": 1024
                }
              }
            },
            "labels": {
              "type": "object"
            },
            "name": {
              "type": "keyword",
              "ignore_above": 1024
            }
          }
        },

...
...
...
              }
            }
          }
        }
      }
    },
    "aliases": {}
  }
}

```

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [August 30, 2021, 8:22am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/6 "2021-08-30T08:22:33Z")

</div>

The part I'm looking for is the final mapping. I assume what you shared here is the content of the template? [Get mapping API | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html)

If it is the final mapping, it seems only the final ingest pipeline is inside which would be an issue.

---

<div class="post-metadata">

**Author:** ![Gomeisa](https://avatars.discourse-cdn.com/v4/letter/g/bcef8e/32.png) [@Gomeisa](https://discuss.elastic.co/u/Gomeisa)\
**Post date:** [August 31, 2021, 5:37pm UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/7 "2021-08-31T17:37:25Z")

</div>

sorry, here is the result of `GET metrics-elastic_agent.elastic_agent-default/_mapping`:

```auto
{
  ".ds-metrics-elastic_agent.elastic_agent-default-2021.08.14-000001" : {
    "mappings" : {
      "dynamic" : "false",
      "_meta" : {
        "package" : {
          "name" : "elastic_agent"
        },
        "managed_by" : "ingest-manager",
        "managed" : true
      },
      "_data_stream_timestamp" : {
        "enabled" : true
      },
      "dynamic_templates" : [
        {
          "strings_as_keyword" : {
            "match_mapping_type" : "string",
            "mapping" : {
              "ignore_above" : 1024,
              "type" : "keyword"
            }
          }
        }
      ],
      "date_detection" : false,
      "properties" : {
        "@timestamp" : {
          "type" : "date"
        },
        "cloud" : {...},
	"container" : {...},
	"data_stream" : {...},
	"elastic_agent" : {...},
	"host" : {...},
	 "system" :{...}
	  }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 1, 2021, 8:28am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/8 "2021-09-01T08:28:45Z")

</div>

I'm really sorry, I sent you down the wrong path. I thought the settings are also listed under the `_mappings` API call but they are not 🤦‍♂️ Instead there is a separate settings call `GET metrics-elastic_agent.elastic_agent-default/_settings`. The part I'm looking for is if there is any default\_pipeline defined there besides the final pipeline. For metrics, no pipeline should be defined.

---

<div class="post-metadata">

**Author:** ![Gomeisa](https://avatars.discourse-cdn.com/v4/letter/g/bcef8e/32.png) [@Gomeisa](https://discuss.elastic.co/u/Gomeisa)\
**Post date:** [September 1, 2021, 4:19pm UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/9 "2021-09-01T16:19:55Z")

</div>

No worries, here is my metrics settings.  
default\_pipeline is defined, should I remove it?

```auto
{
  ".ds-metrics-elastic_agent.elastic_agent-default-2021.08.14-000001" : {
    "settings" : {
      "index" : {
        "mapping" : {
          "total_fields" : {
            "limit" : "10000"
          }
        },
        "refresh_interval" : "5s",
        "hidden" : "true",
        "provided_name" : ".ds-metrics-elastic_agent.elastic_agent-default-2021.08.14-000001",
        "query" : {
          "default_field" : [
            "cloud.account.id",
            "cloud.availability_zone",
            "cloud.instance.id",
            "cloud.instance.name",
            "cloud.machine.type",
            "cloud.provider",
            "cloud.region",
            "cloud.project.id",
            "cloud.image.id",
            "container.id",
            "container.image.name",
            "container.name",
            "host.architecture",
            "host.domain",
            "host.hostname",
            "host.id",
            "host.mac",
            "host.name",
            "host.os.family",
            "host.os.kernel",
            "host.os.name",
            "host.os.platform",
            "host.os.version",
            "host.os.build",
            "host.os.codename",
            "host.type",
            "elastic_agent.id",
            "elastic_agent.process",
            "elastic_agent.version",
            "system.process.cgroup.id",
            "system.process.cgroup.path",
            "system.process.cgroup.cpu.id",
            "system.process.cgroup.cpu.path",
            "system.process.cgroup.cpuacct.id",
            "system.process.cgroup.cpuacct.path",
            "system.process.cgroup.memory.id",
            "system.process.cgroup.memory.path",
            "system.process.cgroup.blkio.id",
            "system.process.cgroup.blkio.path"
          ]
        },
        "creation_date" : "1628955030431",
        "number_of_replicas" : "1",
        "uuid" : "pSLp9eZITpy1f9Vy4iSm1w",
        "version" : {
          "created" : "7130299"
        },
        "lifecycle" : {
          "name" : "metrics"
        },
        "codec" : "best_compression",
        "routing" : {
          "allocation" : {
            "include" : {
              "_tier_preference" : "data_hot"
            }
          }
        },
        "number_of_shards" : "1",
        "default_pipeline" : "metrics-elastic_agent.elastic_agent-0.0.7"
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 2, 2021, 11:28am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/10 "2021-09-02T11:28:33Z")

</div>

Here we have the problem:

```auto
 "default_pipeline" : "metrics-elastic_agent.elastic_agent-0.0.7"

```

As you are on 7.14 and have Elastic Agent package version 1.0.0, the question is why this is still there.

@nchaulet @joshdover During upgrade of the package, if there is no conflict mapping change, we just apply the new settings and mappings. I'm now wondering if there is maybe an issue with updating the settings.

@Gomeisa I would expect, that a rollover of the data stream should solve your issue: [Rollover API | Elasticsearch Guide [master] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/master/indices-rollover-index.html) This assumes that in the settings of the template for Elastic Agent is the correct pipeline. @nchaulet Is there a pipeline for metrics?

---

<div class="post-metadata">

**Author:** ![Gomeisa](https://avatars.discourse-cdn.com/v4/letter/g/bcef8e/32.png) [@Gomeisa](https://discuss.elastic.co/u/Gomeisa)\
**Post date:** [September 4, 2021, 3:47am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/11 "2021-09-04T03:47:23Z")

</div>

@ruflin thank you 🙏

using `POST metrics-elastic_agent.elastic_agent-default/_rollover` solved my problem.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 6, 2021, 7:37am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/12 "2021-09-06T07:37:14Z")

</div>

Great to hear it solved your issue. On our end we still need to figure out how you ended up in this situation (which should not happen).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2021, 9:37am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364/13 "2021-10-04T09:37:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
