Failed to upload elasticsearch logs to elasticsearch/kibana with filebeat module


I´m new to elasticsearch and today I tried to send some elasticsearch server logs up to my elastic-stack with filebeat, using filebeat modules.
Unfortunately, it didn´t work...
I don´t know how I can fix this or what's going wrong.
I followed the tutorial step by step.
It would be great if somebody could help me.

Here´s one of the logs I found in elasticsearch logs:

[2019-02-18T08:32:56,130][DEBUG][o.e.a.b.TransportShardBulkAction] [nodeOne] [filebeat-6.5.4-2019.02.18][0] failed to execute bulk item (index) index {[filebeat-6.5.4-2019.02.18][doc][TvSF_2gBl-K6nb03pieQ], source[n/a, actual length: [3.9kb], max length: 2kb]}
org.elasticsearch.index.mapper.MapperParsingException: failed to parse field [@timestamp] of type [date]
	at org.elasticsearch.index.mapper.FieldMapper.parse( ~[elasticsearch-6.5.4.jar:6.5.4]
	at org.elasticsearch.index.mapper.DocumentParser.parseObjectOrField( ~[elasticsearch-6.5.4.jar:6.5.4]
	at org.elasticsearch.index.mapper.DocumentParser.parseValue( ~[elasticsearch-6.5.4.jar:6.5.4]
	at org.elasticsearch.index.mapper.DocumentParser.innerParseObject( ~[elasticsearch-6.5.4.jar:6.5.4]
	at org.elasticsearch.index.mapper.DocumentParser.parseObjectOrNested( ~[elasticsearch-6.5.4.jar:6.5.4]
	at org.elasticsearch.index.mapper.DocumentParser.internalParseDocument( ~[elasticsearch-6.5.4.jar:6.5.4]
	at org.elasticsearch.index.mapper.DocumentParser.parseDocument( ~[elasticsearch-6.5.4.jar:6.5.4]
	at org.elasticsearch.index.mapper.DocumentMapper.parse( ~[elasticsearch-6.5.4.jar:6.5.4]
	at org.elasticsearch.index.shard.IndexShard.prepareIndex( ~[elasticsearch-6.5.4.jar:6.5.4]
	at org.elasticsearch.index.shard.IndexShard.applyIndexOperation( ~[elasticsearch-6.5.4.jar:6.5.4]
	at org.elasticsearch.index.shard.IndexShard.applyIndexOperationOnPrimary( ~[elasticsearch-6.5.4.jar:6.5.4]

That's my filebeat config:


#=========================== Filebeat inputs =============================

- type: log
  enabled: false
    - /var/log/*.log

#============================= Filebeat modules ===============================
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false
#============================== Kibana =====================================
  host: "localhost:5601"

#-------------------------- Elasticsearch output ------------------------------
  hosts: ["localhost:9200"]

  - add_host_metadata: ~
  - add_cloud_metadata: ~

modules.d config:

- module: elasticsearch
  # Server log
    enabled: true
    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
        - C:/ELK/Test/data/elasticsearch.log.*

    enabled: false
    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.

    enabled: false
    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.

    enabled: false
    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.

    enabled: false
    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.

Which tutorial?

The Configuring Filebeat tutorial.
link to tutorial

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.