# Not seeing cloudwatch streamed logs via functionbeat in elasticsearch

**URL:** <https://discuss.elastic.co/t/not-seeing-cloudwatch-streamed-logs-via-functionbeat-in-elasticsearch/241005>\
**Category:** Kibana\
**Created:** [July 13, 2020, 3:33pm UTC](https://discuss.elastic.co/t/not-seeing-cloudwatch-streamed-logs-via-functionbeat-in-elasticsearch/241005 "2020-07-13T15:33:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![randoran](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@randoran](https://discuss.elastic.co/u/randoran)\
**Post date:** [July 13, 2020, 3:33pm UTC](https://discuss.elastic.co/t/not-seeing-cloudwatch-streamed-logs-via-functionbeat-in-elasticsearch/241005/1 "2020-07-13T15:33:36Z")

</div>

I am fairly new to Elastic stack and I am trying use functionbeat to stream logs to logstash and then to elasticsearch. I tested my streaming with the following logstash config:

```auto
    input {
      beats {
        port => 5044
      }
    }
    output {
      file {
         path => "/tmp/cloudwatch_out.text"
         codec => rubydebug
         create_if_deleted => true
      }

```

When I tail that file I do see logs streaming into it.

But when I changed the logstash config to go to elasticsearch

```auto
   input {
      beats {
        port => 5044
      }
    }
    output {
      elasticsearch {
        hosts => ["http://localhost:9200"]
        index => "%{[@metadata][beat]}-%{[@metadata][version]}"
      }
    }

```

I created an index and an index pattern  
I then try to run this in the console

```auto
    GET functionbeat-7.8.0/_search
    {
      "query": {
        "match_all": {}
      }
    }

```

A few documents are returned but it doesn't seem to be all the documents and I never see any new documents.  
I also did

```auto
curl -X GET http://localhost:9200/functionbeat-7.8.0/_search?pretty=true

```

With same results. Most of the instructions to set this up seem pretty simple but I suspect I am missing something basic

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/6/66074500c8282c84a2ad01f1039ca8edc552d9c3.png)  
Basically I'm asking how I can see or visualize these logs

---

<div class="post-metadata">

**Author:** ![randoran](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@randoran](https://discuss.elastic.co/u/randoran)\
**Post date:** [July 17, 2020, 6:14pm UTC](https://discuss.elastic.co/t/not-seeing-cloudwatch-streamed-logs-via-functionbeat-in-elasticsearch/241005/2 "2020-07-17T18:14:53Z")

</div>

I figured it out, I need this in the curl command

```auto
-H 'Content-Type: application/json'

```

Full curl command looks like this:

```auto
curl -XGET -H 'Content-Type: application/json' "http://localhost:9200/functionbeat-7.8.0/_search?pretty=true&scroll=10m&size=200" -d'
  {
     "query": {
       "match_all": {}
     }
  }'

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2020, 6:14pm UTC](https://discuss.elastic.co/t/not-seeing-cloudwatch-streamed-logs-via-functionbeat-in-elasticsearch/241005/3 "2020-08-14T18:14:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
