# Metricbeat

**URL:** <https://discuss.elastic.co/t/metricbeat/70790>\
**Category:** Beats\
**Created:** [January 6, 2017, 2:38pm UTC](https://discuss.elastic.co/t/metricbeat/70790 "2017-01-06T14:38:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manuel\_Laesser](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@Manuel\_Laesser](https://discuss.elastic.co/u/Manuel_Laesser)\
**Post date:** [January 6, 2017, 2:38pm UTC](https://discuss.elastic.co/t/metricbeat/70790/1 "2017-01-06T14:38:11Z")

</div>

Hello  
I'm pretty new to ELK and installed the whole stack one one machine.

Filebeat and Metricbeat --\> Logstash --\> Elasticsearch \<-- Kibana

Filebeat is working great but today I installed metricbeat. For me it seems, because I'm sending metricbeats trough logstash to elasticsearch that all metrics will be stored in the logstash-\* indicies. I have a logstash-\* and a metricbeats-\* index pattern but if I go to discover in Kibana all Metricbeats Fields appear only if I choose logstash-_. If I choose metricbeats-_ there are no Available or Selected Fields. I think I missed something in /etc/logstash/conf.d/ and send metricbeats data to metricbeats-\* instead logstash-\*.

My Input/Filter/Output file looks like

input {  
beats {  
port =\> "5043"  
}  
}

filter {  
if [type] == "apache-access" {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
} else {  
grok {  
match =\> { "message" =\> "%{SYSLOGBASE} %{GREEDYDATA:msg}" }  
}  
}

output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
hosts =\> ["localhost:9200"]  
user =\> yyyy  
password =\> xxxx  
}  
}

Do I have to create an additional filter to send type metricsets to index metricbeat like described in [https://www.elastic.co/guide/en/beats/metricbeat/current/logstash-output.html](https://www.elastic.co/guide/en/beats/metricbeat/current/logstash-output.html)?

Thank you very much for your help.

Manuel

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 6, 2017, 3:12pm UTC](https://discuss.elastic.co/t/metricbeat/70790/2 "2017-01-06T15:12:41Z")

</div>

You need to add the options to the elasticsearch output as described on the page you linked. These additional outputs specify which index to write the data to. By default data goes to logstash-YYYY.MM.dd but you need it to go to metricbeat-YYYY.MM.dd.

```auto
output {
  elasticsearch {
    host => "localhost"
    port => "9200"
    protocol => "http"
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![Manuel\_Laesser](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@Manuel\_Laesser](https://discuss.elastic.co/u/Manuel_Laesser)\
**Post date:** [January 9, 2017, 8:00am UTC](https://discuss.elastic.co/t/metricbeat/70790/3 "2017-01-09T08:00:59Z")

</div>

> [@andrewkroh](#):
>
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"

Hello Andrew  
Thank you for your answer. It seems that then everything will be sent to metricbeat-\*. I tried with

```
output {
  stdout { codec => rubydebug }
  if [document_type] {
    "%{[@metadata][type]}" {
      elasticsearch {
        hosts => ["localhost:9200"]
        user => xxxx
        password => yyyy
        index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
      }
    } else {
     elasticsearch {
       hosts => ["localhost:9200"]
       user => xxxx
       password => yyyyy
     }
  }
}

```

but this seems to be wrong.

Regars Manuel

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 9, 2017, 11:34pm UTC](https://discuss.elastic.co/t/metricbeat/70790/4 "2017-01-09T23:34:20Z")

</div>

That doesn't look like valid configuration. What condition are you trying to test for?

---

<div class="post-metadata">

**Author:** ![Manuel\_Laesser](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@Manuel\_Laesser](https://discuss.elastic.co/u/Manuel_Laesser)\
**Post date:** [January 10, 2017, 9:57am UTC](https://discuss.elastic.co/t/metricbeat/70790/5 "2017-01-10T09:57:35Z")

</div>

Hello Andrew  
I'm trying to send logs from filebeat to indicies logstash-\* and data coming from metricbeat to indicies metricbeat-\* that's it. IMHO, I think that with the output below everything will be sent to metricbeat-\*

```
output {
  elasticsearch {
    host => "localhost"
    port => "9200"
    protocol => "http"
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }

```

}

After I configured output like this there weren't any messages listed in kibana using indicies logstash-\*

Thank you very much for your help.

Manuel

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 10, 2017, 10:20am UTC](https://discuss.elastic.co/t/metricbeat/70790/6 "2017-01-10T10:20:47Z")

</div>

I think this will get you closer to what you want.

```auto
output {
  if [@metadata][beat] and [@metadata][beat] != "filebeat" {
    # Send all Beat data except Filebeat through this output.
    elasticsearch {
      hosts => ["http://localhost:9200"]
      index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
      document_type => "%{[@metadata][type]}"
    }
  } else {
       elasticsearch {
         hosts => ["http://localhost:9200"]
       }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 27, 2017, 2:38pm UTC](https://discuss.elastic.co/t/metricbeat/70790/7 "2017-01-27T14:38:30Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
