# Separating heartbeat synthetics logs from the rest

**URL:** <https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193>\
**Category:** Beats\
**Tags:** heartbeat\
**Created:** [August 2, 2022, 9:22am UTC](https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193 "2022-08-02T09:22:49Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![djkprojects](https://avatars.discourse-cdn.com/v4/letter/d/d2c977/32.png) [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Post date:** [August 2, 2022, 9:22am UTC](https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193/1 "2022-08-02T09:22:50Z")

</div>

Hello,

I'm setting up Synthetic Monitoring using dockerised heartbeat image and want to separate the synthetics logs from the http/icmp ones. What I've noticed is that with the latest upgrade to 8.3 (or perhaps it was there already in previous versions) there is a template and component templates called synthetics but not being used so my question is what are these templates for?

Thank you

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [August 2, 2022, 3:40pm UTC](https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193/2 "2022-08-02T15:40:57Z")

</div>

Hi @djkprojects,

Which component templates are you talking about? Are those the ones from Elasticsearch: [Create or update component template API | Elasticsearch Guide [8.3] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-component-template.html) ?

In the output section of the configuration file, you can add some index conditions to route events to different indexes depending on their data. [Configure the Elasticsearch output | Heartbeat Reference [8.3] | Elastic](https://www.elastic.co/guide/en/beats/heartbeat/current/elasticsearch-output.html#indices-option-es)

---

<div class="post-metadata">

**Author:** ![djkprojects](https://avatars.discourse-cdn.com/v4/letter/d/d2c977/32.png) [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Post date:** [August 3, 2022, 8:29am UTC](https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193/3 "2022-08-03T08:29:15Z")

</div>

Hi,

They are synthetics-mappings and synthetics-settings and the template using these is synthetics.

What are these for?

Thanks

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [August 3, 2022, 8:53am UTC](https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193/4 "2022-08-03T08:53:24Z")

</div>

@lucasfcosta maybe you can shed some light here?

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [August 3, 2022, 5:41pm UTC](https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193/5 "2022-08-03T17:41:56Z")

</div>

The `heartbeat-*` mappings are for monitors configured directly with heartbeat, while the `synthetics-*` ones are for ones configured via the new monitor management feature (and fleet) in the Uptime app.

In 8.4.0+ browser based monitors will only write to `synthetics-*`, the only reason other monitors still write to `heartbeat-*` is to avoid a breaking change.

As we move forward we'd like most users to transition to using monitor management and pushing monitors into kibana via the `elastic/synthetics` CLI tool, whereupon everything will be in `synthetics-*`. However, these tools are in beta status, so we don't fully recommend them yet.

See [Write a synthetic test | Observability Guide [8.3] | Elastic](https://www.elastic.co/guide/en/observability/current/synthetics-create-test.html) for more info on the push command.

---

<div class="post-metadata">

**Author:** ![lucasfcosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lucasfcosta/32/97382_2.png) [@lucasfcosta](https://discuss.elastic.co/u/lucasfcosta)\
**Post date:** [August 4, 2022, 8:09am UTC](https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193/6 "2022-08-04T08:09:17Z")

</div>

[Reading these docs](https://github.com/elastic/elasticsearch/blob/be7c7415627377a1b795400fb8dfcc6cbdf0e322/docs/reference/indices/put-component-template.asciidoc#index-modules-settings), you can see that the `*-settings` and `*-mappings` templates for synthetics configure, respectively, things like the number of shards, as described [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules.html#index-modules-settings), or the document's fieldsas described [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html#mapping).

If you alter those, you'll be altering the configuration for the underlying backing indices for this data stream, as these templates define those indices' attributes.

---

<div class="post-metadata">

**Author:** ![djkprojects](https://avatars.discourse-cdn.com/v4/letter/d/d2c977/32.png) [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Post date:** [August 4, 2022, 8:28am UTC](https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193/7 "2022-08-04T08:28:37Z")

</div>

Thanks however this doesn't seem to be the case when using dockerised version of heartbeat 8.3.2 for synthetics. All browser type logs are still going to heartbeat-8.3.2 data stream which uses heartbeat template (not synthetics).

Also, both components are pretty much empty:

```auto
POST /_index_template/_simulate
{
  "index_patterns": ["dummy*"],
  "composed_of": ["synthetics-settings","synthetics-mappings"]
}

```

gives:

```auto
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "synthetics"
        },
        "codec": "best_compression",
        "routing": {
          "allocation": {
            "include": {
              "_tier_preference": "data_content"
            }
          }
        }
      }
    },
    "mappings": {
      "properties": {
        "data_stream": {
          "properties": {
            "type": {
              "type": "constant_keyword",
              "value": "synthetics"
            }
          }
        }
      }
    },
    "aliases": {}
  },
  "overlapping": []
}

```

What am I missing here?

The reason why I'm curious about these is because we want to use synthetics template name instead of default heartbeat but worried that it will break something.

Thanks

---

<div class="post-metadata">

**Author:** ![djkprojects](https://avatars.discourse-cdn.com/v4/letter/d/d2c977/32.png) [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Post date:** [August 4, 2022, 8:33am UTC](https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193/8 "2022-08-04T08:33:16Z")

</div>

Thanks,

> Important {es} includes the following built-in component templates:
> 
> - `logs-mappings`
> - `logs-settings`
> - `metrics-mappings`
> - `metrics-settings`
> - `synthetics-mapping`
> - `synthetics-settings`
> 
> **{fleet-guide}/fleet-overview.html[{agent}] uses these templates to configure backing indices for its data streams. If you use {agent} and want to overwrite one of these templates, set the `version` for your replacement template higher than the current version.**
> 
> If you don’t use {agent} and want to disable all built-in component and index templates, set [`stack.templates.enabled`](https://github.com/elastic/elasticsearch/blob/be7c7415627377a1b795400fb8dfcc6cbdf0e322/docs/reference/indices/put-component-template.asciidoc#stack-templates-enabled) to `false` using the [cluster update settings API](https://github.com/elastic/elasticsearch/blob/be7c7415627377a1b795400fb8dfcc6cbdf0e322/docs/reference/indices/put-component-template.asciidoc#cluster-update-settings).

This answers my question.

Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2022, 10:34am UTC](https://discuss.elastic.co/t/separating-heartbeat-synthetics-logs-from-the-rest/311193/9 "2022-09-01T10:34:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
