Yes that's correct. I can't see the event at all altough i do see 'elasticsearch.gc' events.
output {
if [@metadata][pipeline] {
elasticsearch {
hosts => ["https://elastic_server01:9200", "https://elastic_server02.bk.datev.de:9200"]
manage_template => false
index => "%{[@metadata][beat]}-%{[@metadata][version]}"
pipeline => "%{[@metadata][pipeline]}"
user => "logstash_writer"
password => "${elasticsearch.password}"
}
} else {
elasticsearch {
hosts => ["https://elastic_server01.bk.datev.de:9200", "https://elastic_server02.bk.datev.de:9200"]
manage_template => false
index => "%{[@metadata][beat]}-%{[@metadata][version]}"
user => "logstash_writer"
password => "${elasticsearch.password}"
}
}
stdout { codec => rubydebug }
}
EDIT: I found the event:
Mar 05 10:31:15 my_server02 logstash[13800]: "event" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "module" => "elasticsearch",
Mar 05 10:31:15 my_server02 logstash[13800]: "dataset" => "elasticsearch.server",
Mar 05 10:31:15 my_server02 logstash[13800]: "timezone" => "+01:00"
Mar 05 10:31:15 my_server02 logstash[13800]: },
Mar 05 10:31:15 my_server02 logstash[13800]: "@timestamp" => 2020-03-05T09:31:09.815Z,
Mar 05 10:31:15 my_server02 logstash[13800]: "ecs" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "version" => "1.4.0"
Mar 05 10:31:15 my_server02 logstash[13800]: },
Mar 05 10:31:15 my_server02 logstash[13800]: "fileset" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "name" => "server"
Mar 05 10:31:15 my_server02 logstash[13800]: },
Mar 05 10:31:15 my_server02 logstash[13800]: "agent" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "version" => "7.6.0",
Mar 05 10:31:15 my_server02 logstash[13800]: "id" => "972693ee-ca89-4755-9d13-a07ca3e7938e",
Mar 05 10:31:15 my_server02 logstash[13800]: "type" => "filebeat",
Mar 05 10:31:15 my_server02 logstash[13800]: "ephemeral_id" => "ef2f4a2e-4649-4a05-96e2-6aca66e2bd8b",
Mar 05 10:31:15 my_server02 logstash[13800]: "hostname" => "my_server02"
Mar 05 10:31:15 my_server02 logstash[13800]: },
Mar 05 10:31:15 my_server02 logstash[13800]: "host" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "hostname" => "my_server02",
Mar 05 10:31:15 my_server02 logstash[13800]: "id" => "3c4c59e5f48c4a4a93f7287374e2cc3b",
Mar 05 10:31:15 my_server02 logstash[13800]: "containerized" => false,
Mar 05 10:31:15 my_server02 logstash[13800]: "architecture" => "x86_64",
Mar 05 10:31:15 my_server02 logstash[13800]: "name" => "my_server02",
Mar 05 10:31:15 my_server02 logstash[13800]: "version" => "1.4.0"
Mar 05 10:31:15 my_server02 logstash[13800]: },
Mar 05 10:31:15 my_server02 logstash[13800]: "fileset" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "name" => "server"
Mar 05 10:31:15 my_server02 logstash[13800]: },
Mar 05 10:31:15 my_server02 logstash[13800]: "agent" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "version" => "7.6.0",
Mar 05 10:31:15 my_server02 logstash[13800]: "id" => "972693ee-ca89-4755-9d13-a07ca3e7938e",
Mar 05 10:31:15 my_server02 logstash[13800]: "type" => "filebeat",
Mar 05 10:31:15 my_server02 logstash[13800]: "ephemeral_id" => "ef2f4a2e-4649-4a05-96e2-6aca66e2bd8b",
Mar 05 10:31:15 my_server02 logstash[13800]: "hostname" => "my_server02"
Mar 05 10:31:15 my_server02 logstash[13800]: },
Mar 05 10:31:15 my_server02 logstash[13800]: "host" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "hostname" => "my_server02",
Mar 05 10:31:15 my_server02 logstash[13800]: "id" => "3c4c59e5f48c4a4a93f7287374e2cc3b",
Mar 05 10:31:15 my_server02 logstash[13800]: "containerized" => false,
Mar 05 10:31:15 my_server02 logstash[13800]: "architecture" => "x86_64",
Mar 05 10:31:15 my_server02 logstash[13800]: "name" => "my_server02",
Mar 05 10:31:15 my_server02 logstash[13800]: "os" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "kernel" => "3.10.0-1062.12.1.el7.x86_64",
Mar 05 10:31:15 my_server02 logstash[13800]: "platform" => "rhel",
Mar 05 10:31:15 my_server02 logstash[13800]: "version" => "7.7 (Maipo)",
Mar 05 10:31:15 my_server02 logstash[13800]: "family" => "redhat",
Mar 05 10:31:15 my_server02 logstash[13800]: "codename" => "Maipo",
Mar 05 10:31:15 my_server02 logstash[13800]: "name" => "Red Hat Enterprise Linux Server"
Mar 05 10:31:15 my_server02 logstash[13800]: }
Mar 05 10:31:15 my_server02 logstash[13800]: },
Mar 05 10:31:15 my_server02 logstash[13800]: "message" => "[2020-03-05T10:31:08,439][INFO ][o.e.n.Node ] [my_server02] started",
Mar 05 10:31:15 my_server02 logstash[13800]: "tags" => [
Mar 05 10:31:15 my_server02 logstash[13800]: [0] "beats_input_codec_plain_applied",
Mar 05 10:31:15 my_server02 logstash[13800]: [1] "node_started"
Mar 05 10:31:15 my_server02 logstash[13800]: ],
Mar 05 10:31:15 my_server02 logstash[13800]: "service" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "type" => "elasticsearch"
Mar 05 10:31:15 my_server02 logstash[13800]: },
Mar 05 10:31:15 my_server02 logstash[13800]: "log" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "offset" => 126301,
Mar 05 10:31:15 my_server02 logstash[13800]: "file" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "path" => "/u01/services/elasticsearch/logs/P244_Lab_server.log"
Mar 05 10:31:15 my_server02 logstash[13800]: }
Mar 05 10:31:15 my_server02 logstash[13800]: },
Mar 05 10:31:15 my_server02 logstash[13800]: "restart_begin" => 2020-03-05T09:30:49.359Z
Mar 05 10:31:15 my_server02 logstash[13800]: }
Mar 05 10:31:15 my_server02 logstash[13800]: {
Mar 05 10:31:15 my_server02 logstash[13800]: "@version" => "1",
Mar 05 10:31:15 my_server02 logstash[13800]: "input" => {
Mar 05 10:31:15 my_server02 logstash[13800]: "type" => "log"
Mar 05 10:31:15 my_server02 logstash[13800]: },