# Error in filebeat when sending logs to kibana

**URL:** <https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314>\
**Category:** Beats\
**Created:** [April 11, 2019, 4:10am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314 "2019-04-11T04:10:05Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![huzefabootwala](https://avatars.discourse-cdn.com/v4/letter/h/65b543/32.png) [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Post date:** [April 11, 2019, 4:10am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/1 "2019-04-11T04:10:05Z")

</div>

Hello,  
I have set up Elasticsearch (6.7.1) and kibana on my local machine.  
Have installed Filebeat and logstash on a VM for testing and for shipping logs from VM to my local machine.

Filebeat config:

```
#=========================== Filebeat inputs =============================
setup.template.overwrite: true
filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.

- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
   # - /var/log/*.log
   - C:\Test\*.*
    #- c:\programdata\elasticsearch\logs\*
#----------------------------- Logstash output --------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["VMIP:5044"]
#============================== Kibana =====================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.
# This requires a Kibana endpoint configuration.
setup.kibana:

  # Kibana Host
  # Scheme and port can be left out and will be set to the default (http and 5601)
  # In case you specify and additional path, the scheme is required: http://localhost:5601/path
  # IPv6 addresses should always be defined as: https://[2001:db8::1]:5601
  hosts: ["http://localmachineIP:9200"]

```

Logstash config:

```
input {
  beats {
    port => 5044
  }
}

output {
  elasticsearch {
    hosts => ["http://localmachineIP:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
    #user => "elastic"
    #password => "changeme"
  }
}

```

I am getting this error in Filebeat logs:

`error loading C:\Program Files\Filebeat\kibana\7\dashboard\osquery-rootkit.json: blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];. Response: {"objects":[{"id":"6ec10290-f4aa-11e7-8647-534bb4c21040-ecs","type":"visualization",`

Filebeat folder have full permissions to read and write.  
I do not have enough disk space. Can this be a reason?  
Any help would be appreciated.  
Thanx.

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [April 11, 2019, 6:28am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/2 "2019-04-11T06:28:41Z")

</div>

Your index is probably locked because you don't have enough disk space. Try freeing up some space and then manually resetting the index lock from the Dev Tools Console:

```auto
PUT /your-index/_settings
{
  "index.blocks.read_only_allow_delete": null
}

```

See the [documentation about disk-based shard allocation](https://www.elastic.co/guide/en/elasticsearch/reference/6.7/disk-allocator.html) if you want to know why this happens.

---

<div class="post-metadata">

**Author:** ![huzefabootwala](https://avatars.discourse-cdn.com/v4/letter/h/65b543/32.png) [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Post date:** [April 16, 2019, 12:57am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/3 "2019-04-16T00:57:40Z")

</div>

Hello,  
I made some space in C drive on my VM and installed elasticsearch and kibana on a new machine.  
I have added the ip of my new machine in filebeat.yml  
setup.kibana:

```
  # Kibana Host
  # Scheme and port can be left out and will be set to the default (http and 5601)
  # In case you specify and additional path, the scheme is required: http://localhost:5601/path
  # IPv6 addresses should always be defined as: https://[2001:db8::1]:5601
  hosts: ["http://NewMachineIP:5601"]

```

Still its giving me this error  
|INFO|[publisher]|pipeline/module.go:97|Beat name: VM\_HBOOTWALA|  
|---|---|---|---|  
|2019-04-16T10:53:32.034+1000|INFO|kibana/client.go:118|Kibana url: http://localhost:5601|  
|2019-04-16T10:53:34.047+1000|ERROR|instance/beat.go:802|Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to [http://localhost:5601/api/status](http://localhost:5601/api/status) fails: fail to execute the HTTP GET request: Get [http://localhost:5601/api/status:](http://localhost:5601/api/status:) dial tcp 127.0.0.1:5601: connectex: No connection could be made because the target machine actively refused it.. Response:|

Is it still because of space? I have 6.5gb free in C drive in my VM.  
What am I doing wrong?  
Thanx.

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [April 16, 2019, 1:28am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/4 "2019-04-16T01:28:26Z")

</div>

in firebeat.yml  
setup.kibana:  
host: "[https://xxxxxxx:5601](https://xxxxxxx:5601)"

allso need run `firebat setup`

---

<div class="post-metadata">

**Author:** ![huzefabootwala](https://avatars.discourse-cdn.com/v4/letter/h/65b543/32.png) [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Post date:** [April 16, 2019, 1:31am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/5 "2019-04-16T01:31:51Z")

</div>

You mean filebeat setup?  
Install filebeat again or just stop and start service?  
Thanx.

---

<div class="post-metadata">

**Author:** ![huzefabootwala](https://avatars.discourse-cdn.com/v4/letter/h/65b543/32.png) [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Post date:** [April 16, 2019, 1:35am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/6 "2019-04-16T01:35:26Z")

</div>

Getting the same error.

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [April 16, 2019, 1:39am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/7 "2019-04-16T01:39:40Z")

</div>

> [@huzefabootwala](#):
>
> filebeat.yml  
> setup.kibana:

> [@huzefabootwala](#):
>
> hosts: ["[http://NewMachineIP:5601](http://NewMachineIP:5601)"]

this is not hosts:  
try `host: "http://NewMachineIP:5601"`

---

<div class="post-metadata">

**Author:** ![huzefabootwala](https://avatars.discourse-cdn.com/v4/letter/h/65b543/32.png) [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Post date:** [April 16, 2019, 1:44am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/8 "2019-04-16T01:44:42Z")

</div>

Worked with this host: IP:5601

---

<div class="post-metadata">

**Author:** ![huzefabootwala](https://avatars.discourse-cdn.com/v4/letter/h/65b543/32.png) [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Post date:** [April 16, 2019, 2:00am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/9 "2019-04-16T02:00:49Z")

</div>

So now I can see the index pattern filebeat-\* in kibana but no logs when I click on Discover. I tried changing the time as well but no results.  
Technically, I should see logstash index since I am pushing logs from filebeat to logstash then to elastic search.

---

<div class="post-metadata">

**Author:** ![huzefabootwala](https://avatars.discourse-cdn.com/v4/letter/h/65b543/32.png) [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Post date:** [April 16, 2019, 2:15am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/10 "2019-04-16T02:15:36Z")

</div>

I can see the logs now in kibana under filebeat index.  
Just curious, why is there no logstash index and only filebeat?

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [April 16, 2019, 2:24am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/11 "2019-04-16T02:24:14Z")

</div>

you use filebeat -\>es not filebeat-\> logstash-\>es  
this no logstash\* index

---

<div class="post-metadata">

**Author:** ![b6cc858bb03d29d07420](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/b6cc858bb03d29d07420/32/43565_2.png) [@b6cc858bb03d29d07420](https://discuss.elastic.co/u/b6cc858bb03d29d07420)\
**Post date:** [April 16, 2019, 4:34am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/12 "2019-04-16T04:34:17Z")

</div>



---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [April 16, 2019, 5:30am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/13 "2019-04-16T05:30:26Z")

</div>

The output events are written to the Filebeat index because you've set `index` to use the name passed in the Beats metadata: `index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"`. For a more detailed explanation, see the section about [versioned beats indices](https://www.elastic.co/guide/en/logstash/6.7/plugins-inputs-beats.html#plugins-inputs-beats-versioned-indexes) in the docs. If you're planning to use the pre-built Beats dashboards, you generally do want to use this setting.

If you _don't_ specify the `index` setting in the elasticsearch output stage, the name defaults to `logstash-%{+YYYY.MM.dd}`.

---

<div class="post-metadata">

**Author:** ![huzefabootwala](https://avatars.discourse-cdn.com/v4/letter/h/65b543/32.png) [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Post date:** [April 16, 2019, 5:49am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/14 "2019-04-16T05:49:03Z")

</div>

I just mentioned index =\> "logstash" in logstash config file.  
This is the reason for the confusion that I can see filebeat-\* index in kibana.

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [April 16, 2019, 7:52am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/15 "2019-04-16T07:52:40Z")

</div>

use `filebeat setup`  
it will add the index...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2019, 9:52am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314/16 "2019-05-14T09:52:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
