# @metadata.beats not sending data to filebeat index

**URL:** <https://discuss.elastic.co/t/metadata-beats-not-sending-data-to-filebeat-index/85592>\
**Category:** Logstash\
**Created:** [May 12, 2017, 3:14pm UTC](https://discuss.elastic.co/t/metadata-beats-not-sending-data-to-filebeat-index/85592 "2017-05-12T15:14:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![cwhite](https://avatars.discourse-cdn.com/v4/letter/c/c6cbf5/32.png) [@cwhite](https://discuss.elastic.co/u/cwhite)\
**Post date:** [May 12, 2017, 3:14pm UTC](https://discuss.elastic.co/t/metadata-beats-not-sending-data-to-filebeat-index/85592/1 "2017-05-12T15:14:07Z")

</div>

New to Elastic.

When I am trying to output filebeat log file thru logstash with the following config:

> output {  
> elasticsearch {  
> hosts =\> "localhost:9200"  
> manage\_template =\> false  
> index =\> "%{[metadata][beat]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }

Indexes are being created called "%{[metadata][beat]}-2017.05.11" rather than "filebeat-2017.05.11".

Winlogbeat seems to work as expected using the @metadata.beat value.

Any direction on how to correct this? I would like indexes populated dynamically by the respective beats module.

> input {  
> beats {  
> port =\> "5044"  
> }  
> }  
> filter {  
> if [type] == "log" {  
> grok {  
> match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:eventtime} %{WORD:action} %{WORD:protocol} %{IP:source\_ip} %{IP:destination\_ip} %{USERNAME:src-port} %{USERNAME:dst-port} %{USERNAME:size} %{USERNAME:tcpflags} %{USERNAME:tcpsyn} %{USERNAME:tcpack} %{USERNAME:tcpwin} %{USERNAME:icmptype} %{USERNAME:icmpcode} %{USERNAME:info} %{WORD:direction}" }  
> }  
> mutate {  
> remove\_field =\> ["message","icmpcode","icmptype","size","tcpack","tcpflags","tcpsyn","tcpwin"]  
> }  
> date {  
> match =\> ["eventtime","yyyy-MM-dd HH:mm:ss"]  
> }  
> }  
> }  
> output {  
> stdout { codec =\> rubydebug {metadata =\> true } }  
> elasticsearch {  
> hosts =\> "localhost:9200"  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 16, 2017, 5:15am UTC](https://discuss.elastic.co/t/metadata-beats-not-sending-data-to-filebeat-index/85592/2 "2017-05-16T05:15:07Z")

</div>

What does `stdout { codec => rubydebug {metadata => true } }` produce? is there a `[@metadata][beat]` field present there for Filebeat events?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 13, 2017, 5:27am UTC](https://discuss.elastic.co/t/metadata-beats-not-sending-data-to-filebeat-index/85592/3 "2017-06-13T05:27:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
