Hello All,
I am trying to send cloud Watch logs from a filebeat server to Elastic Cloud. I am getting following warnings. And not able to see any logs on Elastic cloud Kibana.
Logs from Filebeat:
2021-10-05T12:56:59.465Z WARN [elasticsearch] elasticsearch/client.go:405 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0x0, ext:63732644280, loc:(*time.Location)(nil)}, Meta:{"_id":"35615348924624437956339893240882599504693814538127212554","raw_index":"dev_rds-alias"}, Fields:{"agent":{"ephemeral_id":"63312bd5-4ef8-402a-8bd2-d6668f07c6d9","hostname":"ip-10-31-32-28.ec2.internal","id":"a02d2186-81fa-4564-94ca-adcbd3751774","name":"ip-10-31-32-28.ec2.internal","type":"filebeat","version":"7.14.0"},"awscloudwatch":{"ingestion_time":"2020-08-10T08:18:00.000Z","log_group":"/aws/rds/cluster/payway-dev-aurora-db/general","log_stream":"tf-20200810080249874600000003"},"cloud":{"provider":"aws","region":"us-east-1"},"ecs":{"version":"1.10.0"},"event":{"id":"35615348924624437956339893240882599504693814538127212554","ingested":"2021-10-05T12:56:42.165Z"},"host":{"name":"ip-10-31-32-28.ec2.internal"},"input":{"type":"aws-cloudwatch"},"log.file.path":"/aws/rds/cluster/payway-dev-aurora-db/general/tf-20200810080249874600000003","message":"2020-08-10T08:18:00.143325Z 6 Query\tSELECT durable_lsn, current_read_point, server_id, last_update_timestamp FROM information_schema.replica_host_status;","mime_type":"text/plain; charset=utf-8"}, Private:interface {}(nil), TimeSeries:false}, Flags:0x1, Cache:publisher.EventCache{m:common.MapStr(nil)}} (status=400): {"type":"mapper_parsing_exception","reason":"Field [log.file] must be an object; but it's configured as [flattened] in dynamic template [null]"}
2021-10-05T12:56:59.465Z WARN [elasticsearch] elasticsearch/client.go:405 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0x0, ext:63734214870, loc:(*time.Location)(nil)}, Meta:{"_id":"35650374248836791604351777452586324382930128185918488624","raw_index":"dev_rds-alias"}, Fields:{"agent":{"ephemeral_id":"63312bd5-4ef8-402a-8bd2-d6668f07c6d9","hostname":"ip-10-31-32-28.ec2.internal","id":"a02d2186-81fa-4564-94ca-adcbd3751774","name":"ip-10-31-32-28.ec2.internal","type":"filebeat","version":"7.14.0"},"awscloudwatch":{"ingestion_time":"2020-08-28T12:34:39.000Z","log_group":"/aws/rds/cluster/regapi-aurora-sl/general","log_stream":"regapi-aurora-sl"},"cloud":{"provider":"aws","region":"us-east-1"},"ecs":{"version":"1.10.0"},"event":{"id":"35650374248836791604351777452586324382930128185918488624","ingested":"2021-10-05T12:56:42.166Z"},"host":{"name":"ip-10-31-32-28.ec2.internal"},"input":{"type":"aws-cloudwatch"},"log.file.path":"/aws/rds/cluster/regapi-aurora-sl/general/regapi-aurora-sl","message":"\t\t 1 Query\tset local oscar_local_only_replica_host_status=0","mime_type":"text/plain; charset=utf-8"}, Private:interface {}(nil), TimeSeries:false}, Flags:0x1, Cache:publisher.EventCache{m:common.MapStr(nil)}} (status=400): {"type":"mapper_parsing_exception","reason":"Field [log.file] must be an object; but it's configured as [flattened] in dynamic template [null]"}
2021-10-05T12:56:59.465Z WARN [elasticsearch] elasticsearch/client.go:405 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0x0, ext:63740149735, loc:(*time.Location)(nil)}, Meta:{"_id":"35782726160989469051069842639628427225448656220337668152","raw_index":"dev_rds-alias"}, Fields:{"agent":{"ephemeral_id":"63312bd5-4ef8-402a-8bd2-d6668f07c6d9","hostname":"ip-10-31-32-28.ec2.internal","id":"a02d2186-81fa-4564-94ca-adcbd3751774","name":"ip-10-31-32-28.ec2.internal","type":"filebeat","version":"7.14.0"},"awscloudwatch":{"ingestion_time":"2020-11-05T05:08:59.000Z","log_group":"/aws/rds/cluster/regapi-aurora-sl/error","log_stream":"regapi-aurora-sl"},"cloud":{"provider":"aws","region":"us-east-1"},"ecs":{"version":"1.10.0"},"event":{"id":"35782726160989469051069842639628427225448656220337668152","ingested":"2021-10-05T12:56:42.166Z"},"host":{"name":"ip-10-31-32-28.ec2.internal"},"input":{"type":"aws-cloudwatch"},"log.file.path":"/aws/rds/cluster/regapi-aurora-sl/error/regapi-aurora-sl","message":"2020-11-05 05:08:55 12212 [Note] Plugin 'FEDERATED' is disabled.","mime_type":"text/plain; charset=utf-8"}, Private:interface {}(nil), TimeSeries:false}, Flags:0x1, Cache:publisher.EventCache{m:common.MapStr(nil)}} (status=400): {"type":"mapper_parsing_exception","reason":"Field [log.file] must be an object; but it's configured as [flattened] in dynamic template [null]"}
Can anyone help me with this ?