I installed Heartbeat and changed the pipeline to be (Heartbeat ==> Logstash ===> Elasticsearch) and I loaded the heartbeat dashboards,
Also I have its logs, and logs forwarded from (IBM Qradar),
My issue is the document in qradar index is the same for the heartbeat index, and when I stop the heartbeat I get the correct document.
(Heartbeat document overwrite other logs )
I tested it on version 7.6.2
Also tested it on 7.9.2 but the logs shipped using filebeat overwrite the heartbeat documents
I am using Filebeat to collect our applications logs,
Heartbeat is used to monitor the application (soap-http-tcp), and changed the pipeline of heartbeat to send the response to logstash to parse some data, this step requires loading heartbeat dashboards in kibana,
All logs sent to logstassh then to elasticsearch.
No sir,
I have pipeline for each one (one for qradar as syslog and one for filebeat and one for Heartbeat) and each one is created and I created index pattern for each one of them, and to make sure that I am working right I tried to stop the heartbeat service and everything goes okay, each index has its own document
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.