# Elasticsearch does not receive Filebeat data

**URL:** <https://discuss.elastic.co/t/elasticsearch-does-not-receive-filebeat-data/222342>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 5, 2020, 4:38pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-receive-filebeat-data/222342 "2020-03-05T16:38:46Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Axl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axl/32/45475_2.png) [@Axl](https://discuss.elastic.co/u/Axl)\
**Post date:** [March 6, 2020, 9:23am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-receive-filebeat-data/222342/4 "2020-03-06T09:23:43Z")

</div>

I think I solved my problem.

[This post saved me](https://discuss.elastic.co/t/solved-cant-get-logstash-to-catch-cowrie-filebeat/165866/3): my logstash configuration had the same issue, where I was using `if [type] == "cowrie" {` instead of the correct `if [fields][document_type] == "cowrie"`.

Once I modified this and restarted logstash, I started seeing useful data in the logstash data.  
Then, I want back to Kibana. I don't fully understand indexes to be honest, but from log messages, I know I needed to create one. So, I created an index pattern for `logstash-*` (which is the name of my logstash logs). It found all the interesting fields of my logs (e.g timestamp, arch, data, geoip\_cityname...). Then, in Discover, I can see my data 🙂

Note I still have MapperParsingExceptions in my `/var/log/elasticsearch/elasticsearch.log`, and in logstash logs, I still have many warnings `Could not index event to Elasticsearch.`. I'll look into that, but probably a different issue.

---

_[View the full topic](https://discuss.elastic.co/t/elasticsearch-does-not-receive-filebeat-data/222342)._
