# Send metricbeat via logstash as datastream

**URL:** <https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628>\
**Category:** Metrics\
**Created:** [February 15, 2023, 2:39pm UTC](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628 "2023-02-15T14:39:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![A\_Mightiev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_mightiev/32/62186_2.png) [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Post date:** [February 15, 2023, 2:39pm UTC](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628/1 "2023-02-15T14:39:53Z")

</div>

Hi  
I'm trying to send metricbeat data to logstash then store it as datastream into elasticsearch.  
I already have an datastream in elasticsearch "metricbeat-8.6.1", in my dashboards I'm using "metricbeat\*" index pattern  
My problem is that logstash is trying to send to a datastream "metrics" because datastream type only accepts "logs", "metrics", "traces", and "synthetics".  
How can I force logstash to send the metrics into metricbeat-8.6.1 datastream?  
Thanks!  
A

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 15, 2023, 3:23pm UTC](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628/2 "2023-02-15T15:23:08Z")

</div>

I beleive, This page shows the correct logstash configuration

> **[Use ingest pipelines for parsing | Logstash Reference \[8.6\] | Elastic](https://www.elastic.co/guide/en/logstash/current/use-ingest-pipelines.html)**

---

<div class="post-metadata">

**Author:** ![A\_Mightiev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_mightiev/32/62186_2.png) [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Post date:** [February 15, 2023, 3:37pm UTC](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628/3 "2023-02-15T15:37:23Z")

</div>

I already tried this and it fails because my "metricbeat-8.6.1" is a data stream, not a classic index, what I want is to store it as datastream, but I can't set data\_stream\_type into "metricbeat"

```auto
Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"metricbeat-8.6.1", :routing=>nil}, 
{"ecs"=>{"version"=>"8.0.0"}, "tags"=>["beats_input_raw_event"], "@version"=>"1", "@timestamp"=>2023-02-13T16:01:02.611Z, 
"system"=>{"core"=>{"system"=>{"pct"=>0.0594}, "user"=>{"pct"=>0.011}, "idle"=>{"pct"=>0.9297}, "id"=>5, "total"=>{"pct"=>0.0703}}}, 
"metricset"=>{"name"=>"core", "period"=>20000}, "service"=>{"type"=>"system"},
"event"=>{"module"=>"system", "dataset"=>"system.core"}, "type"=>"metricbeat", "version"=>"8.6.1", 
"id"=>"5cb113ea-54aa-4291-9779-65e611401fbe"}}], :response=>{"index"=>{"_index"=>"metricbeat-8.6.1", 
"_id"=>nil, "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"only write ops with an op_type of create are allowed in data streams"}}}}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 15, 2023, 3:55pm UTC](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628/4 "2023-02-15T15:55:52Z")

</div>

Hi @A_Mightiev I don't think you looked close...

I have personally tested Metricbeat -\> Logstash -\> Elasticsearch Cloud 8.x (although I have not tried 8.6.1) today I can do that later...

`action => "create"` \<!----- Not Setting this is cause of your issue

```auto
input {
  beats {
    port => 5044
  }
}

output {
  if [@metadata][pipeline] {
    elasticsearch {
      hosts => "https://061ab24010a2482e9d64729fdb0fd93a.us-east-1.aws.found.io:9243"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
      action => "create" <!----- Not Setting this is cause of your issue
      pipeline => "%{[@metadata][pipeline]}" 
      user => "elastic"
      password => "secret"
    }
  } else {
    elasticsearch {
      hosts => "https://061ab24010a2482e9d64729fdb0fd93a.us-east-1.aws.found.io:9243"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
      action => "create" <!----- Not Setting this is cause of your issue
      user => "elastic"
      password => "secret"
    }
  }

```

---

<div class="post-metadata">

**Author:** ![A\_Mightiev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_mightiev/32/62186_2.png) [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Post date:** [February 15, 2023, 4:41pm UTC](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628/5 "2023-02-15T16:41:24Z")

</div>

Indeed! thanks! It is working!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2023, 4:42pm UTC](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628/6 "2023-03-15T16:42:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
