I have an ingest problem with filebeat and logstash. I have machines with a configuration on it's own to get different type of log files.
my first filebeat.yml file is like this :
my problem is, with the 2nd yml file i have indices like this one : green open logstash-elemental_live-2017.11.22 CvnMPAClRNK9a8MxY63ccQ 1 0 141 0 128.4kb 128.4kb
but with the first file it look like this : green open logstash-%{type}-2017.11.21 1rOpLykcTBK2RyXkLmZd7A 1 0 3004790 0 756.1mb 756.1mb
and the problem is that with kibana when i try to create a new index pattern it has a bug with "logstash-%{type}" (which is not supposed to be like this at the beginning)
Anyone who has a clue why my indices look like "logstash-%{type}..." and not "logstash-wowza..." ?
Anyone who has a clue why my indices look like "logstash-%{type}..." and not "logstash-wowza..." ?
Those events clearly don't have the type field set to anything. Do you really have a leading space on the filebeat.prospectors: line for the wowza logs?
The wowza config is on filebeat 6.0 which mean that "document_type" is ignored and has to be replaced by "fields"
Is the syntax the same, like we just have to change :
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.