# Logstash Output wrong - Error in visualization \[esaggs\] \> "field" is a required parameter

**URL:** <https://discuss.elastic.co/t/logstash-output-wrong-error-in-visualization-esaggs-field-is-a-required-parameter/215412>\
**Category:** Logstash\
**Created:** [January 17, 2020, 5:29am UTC](https://discuss.elastic.co/t/logstash-output-wrong-error-in-visualization-esaggs-field-is-a-required-parameter/215412 "2020-01-17T05:29:57Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [January 18, 2020, 2:56pm UTC](https://discuss.elastic.co/t/logstash-output-wrong-error-in-visualization-esaggs-field-is-a-required-parameter/215412/4 "2020-01-18T14:56:48Z")

</div>

I have now deleted everything (Index, saved object and everything). I started logstash again...  
Winlogbeat is created as index pattern automatically and also the Dashboard. I still got the errors. It's because the @timestamp is not correctly added and stored in the visualize part.  
Maybe a bug or i'm to stupid ;).

Solution: I have added the @timestamp to the visualizations and saved them. Now I have the Dashboard working. In Logstash I don't see an error.

Output in Logstash:

> output {  
> if [@metadata][beat] {  
> elasticsearch {  
> hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
> manage\_template =\> true  
> index =\> "%{[@metadata][beat]}-%{[@metadata][version]}"  
> }  
> } else {  
> elasticsearch {  
> hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
> index =\> "pf-%{+YYYY.MM.dd}"  
> }  
> }  
> }

---

_[View the full topic](https://discuss.elastic.co/t/logstash-output-wrong-error-in-visualization-esaggs-field-is-a-required-parameter/215412)._
