# HeartBeat issue with matching on response body string

**URL:** https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931
**Category:** Beats
**Tags:** heartbeat
**Created:** [May 22, 2020, 4:24pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931 "2020-05-22T16:24:16Z")
**Posts on this page:** 18
**Page:** 1

<div class="post-metadata">

### Author: ![ozonshak](https://avatars.discourse-cdn.com/v4/letter/o/eb9ed0/32.png) [@ozonshak](https://discuss.elastic.co/u/ozonshak)
#### Post date: [May 22, 2020, 4:24pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/1 "2020-05-22T16:24:16Z")

</div>

Hello. I'm installing HeartBeat for the first time. I've got the basic ping uptime check working. However, I would love to match on a keyword on the page. I keep coming across articles saying this will only match on the entire page body. I've been trying regular expression matches on simple keywords with no luck. Does anyone have an example of how to set this up in the YAML file? Thanks!

---

<div class="post-metadata">

### Author: ![shahzad31](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahzad31/32/51637_2.png) [@shahzad31](https://discuss.elastic.co/u/shahzad31)
#### Post date: [May 23, 2020, 9:49am UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/2 "2020-05-23T09:49:30Z")

</div>

Hi @ozonshak There is an example give on heartbeat config docs [HTTP options | Heartbeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/heartbeat/current/monitor-http-options.html#monitor-http-check)  
something like this

> check.response:  
> status: [200]  
> body:  
> - Saved  
> - saved

---

<div class="post-metadata">

### Author: ![ozonshak](https://avatars.discourse-cdn.com/v4/letter/o/eb9ed0/32.png) [@ozonshak](https://discuss.elastic.co/u/ozonshak)
#### Post date: [May 26, 2020, 10:42am UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/3 "2020-05-26T10:42:53Z")

</div>

Hi @shahzad31. Unfortunately, that does not work. I've already poured over that documentation. For some reason, simple individual words don't see to match anything (I've also tried matching case exactly). I've also tried some regex and JSON (although the latter might be only applicable if the response is in JSON - my response is HTML). I'm not sure what I'm doing wrong.

Does this only work if the entire response matches? Or should I be able to pick out a single word or phrase in the entire response?

---

<div class="post-metadata">

### Author: ![shahzad31](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahzad31/32/51637_2.png) [@shahzad31](https://discuss.elastic.co/u/shahzad31)
#### Post date: [May 27, 2020, 8:37am UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/4 "2020-05-27T08:37:00Z")

</div>

Hi @ozonshak It should match a single word as well, it might be a bug, can you please open an issue [https://github.com/elastic/beats/issues/new?template=bug-report.md](https://github.com/elastic/beats/issues/new?template=bug-report.md) We will try to take a look at it.

---

<div class="post-metadata">

### Author: ![shahzad31](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahzad31/32/51637_2.png) [@shahzad31](https://discuss.elastic.co/u/shahzad31)
#### Post date: [May 27, 2020, 9:28am UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/5 "2020-05-27T09:28:58Z")

</div>

Hi @ozonshak i did bit more digging, and it seems to be working as expected for me, i think one of thing you may need to notice is that make sure, whole body is recorded in response, with parameter

> response.include\_body\_max\_bytes

i think it might be a case that the text you are matching against isn't part of default first 1024 bytes, once you do that, you can verify that if text is part of the body you are receiving in uptime monitor details page in ping history table, like below.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/2/623090e182b8f419642bcfdbc973f206fe8de5b3.png)

---

<div class="post-metadata">

### Author: ![shahzad31](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahzad31/32/51637_2.png) [@shahzad31](https://discuss.elastic.co/u/shahzad31)
#### Post date: [May 27, 2020, 9:33am UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/6 "2020-05-27T09:33:32Z")

</div>

One more thing of consideration is to make sure to check if there is any redirect involved, i was monitoring [https://ir.elastic.co/](https://ir.elastic.co/) but it was actually redirecting to [https://ir.elastic.co/home/default.aspx](https://ir.elastic.co/home/default.aspx), so i was expecting text of actual redirect to match against initial request, but if you haven't set heartbeat to follow redirects , it will match it against first response.

---

<div class="post-metadata">

### Author: ![ozonshak](https://avatars.discourse-cdn.com/v4/letter/o/eb9ed0/32.png) [@ozonshak](https://discuss.elastic.co/u/ozonshak)
#### Post date: [May 27, 2020, 12:12pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/7 "2020-05-27T12:12:45Z")

</div>

Thanks @shahzad31. I tried to get this syntax in, but I think I have an error because every time I save the file, my heartbeat checks basically stop. The online documentation doesn't really show an example of these that I can find. I've tried the following:

```auto
#response:
#include_body_max_bytes
#include_body: "always"

#response.include_body_max_bytes
#response.include_body: "always"

```

When drilling into a particular ping check, it is telling me that my response body is currently not being recorded. So, I think you are on the right track here. I just need to get the syntax correct.

---

<div class="post-metadata">

### Author: ![shahzad31](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahzad31/32/51637_2.png) [@shahzad31](https://discuss.elastic.co/u/shahzad31)
#### Post date: [May 27, 2020, 1:12pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/8 "2020-05-27T13:12:31Z")

</div>

@ozonshak So that settings is per monitor, let me show post an example, include\_body\_max\_bytes means number value in bytes

```
  - type: http
    id: ir-elastic-co
    name: Elastic Investor Relations
    urls: ["https://ir.elastic.co/home/default.aspx"]
    schedule: "@every 60s"
    tags: ["org:elastic"]
    response.include_body_max_bytes: 99999
    response.include_body: on_error
    check.response:
      body:
        - Latest

```

There is definitely room in docs improvement, we will keep an eye on it.

---

<div class="post-metadata">

### Author: ![ozonshak](https://avatars.discourse-cdn.com/v4/letter/o/eb9ed0/32.png) [@ozonshak](https://discuss.elastic.co/u/ozonshak)
#### Post date: [May 27, 2020, 2:42pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/9 "2020-05-27T14:42:12Z")

</div>

Thanks @shahzad31. Well, I'm a little closer, but still not working. Adding the response.include\_ entries seem to have been ok (didn't stop the ping). However, as soon as I add the "body:" portion, the heartbeat stopped checking. Here is that portion of my script. Are you able to see anything wrong? As soon as I comment out the "body" and "About" lines, it starts pinging again.

```auto

  # Required TLS protocols
  #supported_protocols: ["TLSv1.0", "TLSv1.1", "TLSv1.2"]

  response.include_body_max_bytes: 99999
  response.include_body: on_error

  # Request settings:
  check.request:
  # Configure HTTP method to use. Only 'HEAD', 'GET' and 'POST' methods are allowed.
  method: "GET"

  # Dictionary of additional HTTP headers to send:
  #headers:

  # Optional request body content
  #body:

  # Expected response settings
  check.response:
    # Expected status code. If not configured or set to 0 any status code not
    # being 404 is accepted.
    status: 200

    # Required response headers.
    #headers:

    # Required response contents.
    body:
        - About

    # Parses the body as JSON, then checks against the given condition expression
    #json:
    #- description: Check for page keyword
    # condition:
    # contains:
    # http.response.body: About

```

---

<div class="post-metadata">

### Author: ![shahzad31](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahzad31/32/51637_2.png) [@shahzad31](https://discuss.elastic.co/u/shahzad31)
#### Post date: [May 27, 2020, 3:27pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/10 "2020-05-27T15:27:22Z")

</div>

Looks ok to me, @andrewvc can you see what might be wrong here?

---

<div class="post-metadata">

### Author: ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)
#### Post date: [May 27, 2020, 3:30pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/11 "2020-05-27T15:30:16Z")

</div>

Hey, jumping in here a little late. So, the body check should match any substring within the first 100MiB.

`response.include_body` and `response.include_body_max_bytes` only effect how much of the body is sent to ES.

I double checked this functionality locally here and it worked with this config:

```auto
- type: http
  id: my-monitor
  name: My Monitor
  urls: 
  - https://www.elastic.co
  schedule: "@every 10s"
  check.response:
    status: 200
    body:
      - elastic

```

@ozonshak can you post a screenshot of the HTTP response details from the monitor overview page, or even better, post a document from ES? Is the validation succeeding or failing?

---

<div class="post-metadata">

### Author: ![ozonshak](https://avatars.discourse-cdn.com/v4/letter/o/eb9ed0/32.png) [@ozonshak](https://discuss.elastic.co/u/ozonshak)
#### Post date: [May 27, 2020, 4:26pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/12 "2020-05-27T16:26:00Z")

</div>

Sorry guys. Can you please guide me to this location? I'm looking on the overview page but there are no HTTP response details. When I drill down into a monitor, I'm not seeing much either. When this fails due to changes in the YML, it stops pinging, so there are no further entries.

Overview page:

 ![overview_page](https://us1.discourse-cdn.com/elastic/original/3X/5/4/5459751688e641476022e76c349c785c1f7fc731.jpeg)

Drill-down:

 ![drill_down](https://us1.discourse-cdn.com/elastic/original/3X/3/b/3b2587ce3a0983ecb7c3177db3fba63d4f314466.jpeg)

I'm relatively new to working with these tools, so I could also use some assistance in pulling a document out of the heartbeat index. Thanks!

---

<div class="post-metadata">

### Author: ![shahzad31](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahzad31/32/51637_2.png) [@shahzad31](https://discuss.elastic.co/u/shahzad31)
#### Post date: [May 27, 2020, 8:37pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/13 "2020-05-27T20:37:58Z")

</div>

To get a document , you can go to devtools and use query like this

> GET heartbeat-\*/\_search  
> {  
> "size": 2,  
> "query": {  
> "match\_all": {}  
> }  
> }

---

<div class="post-metadata">

### Author: ![ozonshak](https://avatars.discourse-cdn.com/v4/letter/o/eb9ed0/32.png) [@ozonshak](https://discuss.elastic.co/u/ozonshak)
#### Post date: [May 28, 2020, 11:14am UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/14 "2020-05-28T11:14:45Z")

</div>

Thanks @shahzad31. So, this is returning the oldest 2 documents that were "down" failures while I was trying to set this up. Do you have a quick sort that you can please add to that search? I've been trying several ways, but it keeps telling me it can't find a mapping for any fields I try and sort on. Thanks.

FYI - I was able to get a response body by changing the response.include\_body to "always" instead of "on\_error". I see a ton coming back but it won't let me scroll so I can't tell how much of the page it is capturing. I tried using a random string that I could see in the response body, but the heartbeat still stopped pinging entirely as soon as I add the body portion of the YML. Not sure what is wrong with this, but it is not taking any values without crashing the process.

---

<div class="post-metadata">

### Author: ![ozonshak](https://avatars.discourse-cdn.com/v4/letter/o/eb9ed0/32.png) [@ozonshak](https://discuss.elastic.co/u/ozonshak)
#### Post date: [June 2, 2020, 3:49pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/15 "2020-06-02T15:49:48Z")

</div>

Hi @shahzad31. Any further thoughts as to why I'm having this issue? I'm at a total loss. Every time I uncomment the "body" section, it basically stops heartbeat from pinging anything. I haven't been able to see any errors - the entire beat just stops working. Here is that section of the YML file:

```auto
 response.include_body_max_bytes: 99999
  response.include_body: always
  #response.include_body: on_error

  # Request settings:
  check.request:
  # Configure HTTP method to use. Only 'HEAD', 'GET' and 'POST' methods are allowed.
  method: "GET"

  # Dictionary of additional HTTP headers to send:
  #headers:

  # Optional request body content
  #body:

  # Expected response settings
  check.response:
    # Expected status code. If not configured or set to 0 any status code not
    # being 404 is accepted.
    status: 200

    # Required response headers.
    #headers:

    # Required response contents.
    body:
        - Heart

```

If I comment out the "body" and "heart" lines above, Heartbeat starts working again.

---

<div class="post-metadata">

### Author: ![shahzad31](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahzad31/32/51637_2.png) [@shahzad31](https://discuss.elastic.co/u/shahzad31)
#### Post date: [June 3, 2020, 12:57pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/16 "2020-06-03T12:57:33Z")

</div>

Hi @ozonshak, when heartbeat stops working, it must shows you some error in console that why it's not starting.

---

<div class="post-metadata">

### Author: ![ozonshak](https://avatars.discourse-cdn.com/v4/letter/o/eb9ed0/32.png) [@ozonshak](https://discuss.elastic.co/u/ozonshak)
#### Post date: [June 4, 2020, 12:55pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/17 "2020-06-04T12:55:23Z")

</div>

Thanks @shahzad31! I totally forgot you can run this in console mode. I was checking /var/log and output from journalctl, but wasn't seeing any errors. The console showed me an issue with the syntax. Once I searched for the error, it was because I had used a tab character to indent the "-" line, which it doesn't like. Once I changed it to spaces, it started working! Thanks for your help!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 2, 2020, 1:05pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931/18 "2020-07-02T13:05:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
