# Get %{\[@metadata\]\[beat\]}-%{\[@metadata\]\[version\]} index

**URL:** <https://discuss.elastic.co/t/get-metadata-beat-metadata-version-index/110281>\
**Category:** Beats\
**Created:** [December 5, 2017, 8:17am UTC](https://discuss.elastic.co/t/get-metadata-beat-metadata-version-index/110281 "2017-12-05T08:17:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [December 5, 2017, 8:17am UTC](https://discuss.elastic.co/t/get-metadata-beat-metadata-version-index/110281/1 "2017-12-05T08:17:09Z")

</div>

I upgraded from 5.6.3 to 6.0 and i have two question:

1. Need upgrade all beat to 6.0 ? v5.6.x conflict with ES 6.0.0?
2. I got %{[@metadata][beat]}-%{[@metadata][version]}-2017-37 in index name.  
Flow data : beat -\> LS forwarder -\> RabbitMQ -\> LS Proccessor -\> ES.

Config in LS forwarder

```
input {
  beats {
    port => 5044
  }
}
filter {
  if [type] == "wineventlog" and [event_id] == 5156 {
    drop { }
  }
  mutate {
   add_field => {"beatname" => "%{[@metadata][beat]}"}
   add_field => {"beattype" => "%{[@metadata][type]}"}
   add_field => {"beatversion" => "%{[@metadata][version]}"}
  }
}

output {
    rabbitmq {
        exchange => "logstash"
        exchange_type => "direct"
        key => "logstash-key"
        host => "10.1.100.10"
        vhost => "elastic-stack"
        durable => true
        persistent => true
        port => 5677
        user => "logstash"
        password => "password"

    }
}

```

Confing LS Proccessor

```
input {
    rabbitmq {
        host => "10.1.100.10"
        queue => "logstash-queue"
        key => "logstash-key"
        exchange => "logstash"
        threads => 5
        exclusive => false
        prefetch_count => 256
        vhost => "elastic-stack"
        port => 5677
        user => "logstash"
        password => "password"
    }

}

output {
    elasticsearch {
        hosts => ["http://node1:9200", "node2:9200", "node3:9200"]
        user => "user"
        password => "passs"
        manage_template => false
        index => "%{beatname}-%{beatversion}-%{+xxxx.ww}"
        #index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+xxxx.ww}"
        document_type => "%{beattype}"
    }
}

```

Somehing wrong in my config? . This config is worked with 5.6.x. i just add more field **beatversion** for 6.0

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 5, 2017, 1:17pm UTC](https://discuss.elastic.co/t/get-metadata-beat-metadata-version-index/110281/2 "2017-12-05T13:17:02Z")

</div>

> Need upgrade all beat to 6.0 ? v5.6.x conflict with ES 6.0.0?

There are some minor differences to the events schema. That's why the template mapping and index names are versioned. Still kibana uses index mapping `<beatname>-*`. Beats 5.6 and 6.0 both work with Elasticsearch 6.0. But if possible ensure all beats using the same version.

No idea about your logstash config. For debugging I would add `stdout { codec => rubydebug }` to the output section, so I can inspect the actual events.

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [December 5, 2017, 1:54pm UTC](https://discuss.elastic.co/t/get-metadata-beat-metadata-version-index/110281/3 "2017-12-05T13:54:50Z")

</div>

> [@steffens](#):
>
> There are some minor differences to the events schema. That's why the template mapping and index names are versioned. Still kibana uses index mapping \<beatname\>-\*. Beats 5.6 and 6.0 both work with Elasticsearch 6.0. But if possible ensure all beats using the same version.

Yeah, when i upgrade success ES and LS to 6.0 an run i got error about mapping index (in log of logstash)  
So if dont upgrade beat version, i must change index name to `<beat name>-<beat-version>-xxxx.ww` right?

Thanks for support!

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 5, 2017, 3:23pm UTC](https://discuss.elastic.co/t/get-metadata-beat-metadata-version-index/110281/4 "2017-12-05T15:23:05Z")

</div>

Yeah, you should include the beat version in the index name.

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [December 12, 2017, 11:51am UTC](https://discuss.elastic.co/t/get-metadata-beat-metadata-version-index/110281/5 "2017-12-12T11:51:49Z")

</div>

Yeah, i solved my problem.  
In my case, i have both of beat 5.4 and 6.0. So i cant use [@metadata][version] because in beat 5.x, dont have this field.  
So i used [beat][vesion]. It worked with beat version 5.4 and 6.0.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2017, 8:17am UTC](https://discuss.elastic.co/t/get-metadata-beat-metadata-version-index/110281/6 "2017-12-26T08:17:12Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
