Hello!
I am using ELK stack version 5.2 latest.
I'm trying to configure the FIlebeat. My configuration is Filebeat > Elasticsearch > Kibana.
However there is something wrong and I couldn't figure it out. There are some errors in the log and the index is not created on Kibana.
I have configured index template file for Filebeat.
I have deleted data by curl -XDELETE 'http://localhost:9200/filebeat-*' and configured filebeat index template by using below command, but still index issue persists.
PS C:\Program Files\Filebeat> Invoke-WebRequest -Method Put -InFile filebeat.template.json -Uri http://localhost:9200/_template/filebeat?pretty
please find http://localhost:9200/_template/filebeat?pretty data below.
{
"filebeat" : {
"order" : 0,
"template" : "filebeat-*",
"settings" : {
"index" : {
"mapping" : {
"total_fields" : {
"limit" : "10000"
}
},
"refresh_interval" : "5s"
}
},
"mappings" : {
"_default_" : {
"_meta" : {
"version" : "5.2.0"
},
"dynamic_templates" : [
{
"strings_as_keyword" : {
"mapping" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"match_mapping_type" : "string"
}
}
],
"_all" : {
"norms" : false
},
"properties" : {
"@timestamp" : {
"type" : "date"
},
"offset" : {
"type" : "long"
},
"meta" : {
"properties" : {
"cloud" : {
"properties" : {
"machine_type" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"availability_zone" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"instance_id" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"project_id" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"provider" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"region" : {
"ignore_above" : 1024,
"type" : "keyword"
}
}
}
}
},
"beat" : {
"properties" : {
"hostname" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"name" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"version" : {
"ignore_above" : 1024,
"type" : "keyword"
}
}
},
"input_type" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"source" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"message" : {
"norms" : false,
"type" : "text"
},
"type" : {
"ignore_above" : 1024,
"type" : "keyword"
},
"tags" : {
"ignore_above" : 1024,
"type" : "keyword"
}
}
}
},
"aliases" : { }
}
}
Please help us in creating filebeat index pattern.