# SOLVED - Index Template for filebeat - fails on fields

**URL:** <https://discuss.elastic.co/t/solved-index-template-for-filebeat-fails-on-fields/176745>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 13, 2019, 6:52pm UTC](https://discuss.elastic.co/t/solved-index-template-for-filebeat-fails-on-fields/176745 "2019-04-13T18:52:20Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wayne\_Taylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayne_taylor/32/45984_2.png) [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Post date:** [April 13, 2019, 6:52pm UTC](https://discuss.elastic.co/t/solved-index-template-for-filebeat-fails-on-fields/176745/1 "2019-04-13T18:52:20Z")

</div>

Hi,

Recently we switched from beats -\> ES Cloud to beats -\> logstash -\> ES cloud. In our new cluster we found that the index mappings were not done (per previous post).

I am trying to run the commands per documentation [Load the Elasticsearch index template | Filebeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html) and getting the following error:

> Exiting: error unpacking config data: missing field accessing 'fields.version' (source:'/etc/filebeat/filebeat.yml')

Below is the filebeat.yml file.

```
keystore.path: "${path.config}/filebeat.keystore"

filebeat.config.inputs:
  enabled: true
  path: ${path.config}/configs/*.yml
  reload.enabled: true
  reload.period: 10s
  exclude_files: ['.gz$']

 multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
 multiline.negate: true
 multiline.match: after

#============================= Filebeat modules ===============================

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: true

  # Period on which files under path should be checked for changes
  #reload.period: 10s

#==================== Elasticsearch template setting ==========================

setup.template.settings:
  index.number_of_shards: 1
  index.codec: best_compression
  #_source.enabled: false

#================================ General =====================================

processors:
- add_cloud_metadata: ~
- add_host_metadata:
    netinfo.enabled: true

fields:
  env: "${CLOUD_ENVIRONMENT}"
  version: "${ARTIFACT_VERSION}"
  commit_sha: "${BUILD_TRIGGER_GIT_COMMIT}"
  app_name: "${CLOUD_APP}"
  project_name: "${CLOUD_APP_GROUP}"
  ami_id: "${CLOUD_AMI_ID}"

fields_under_root: true

output.logstash:
  # The Logstash hosts
  hosts: ["myserver:5044"]

```

Any recommendations?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 16, 2019, 8:55am UTC](https://discuss.elastic.co/t/solved-index-template-for-filebeat-fails-on-fields/176745/2 "2019-04-16T08:55:25Z")

</div>

Hi @Wayne_Taylor,

This error can happen with your configuration if `ARTIFACT_VERSION` environment variable is not set. Could you check that?

---

<div class="post-metadata">

**Author:** ![Wayne\_Taylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayne_taylor/32/45984_2.png) [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Post date:** [April 16, 2019, 2:46pm UTC](https://discuss.elastic.co/t/solved-index-template-for-filebeat-fails-on-fields/176745/3 "2019-04-16T14:46:21Z")

</div>

@jsoriano - the variable is available. See attached screenshots to assist.

Wayne

 ![21%20AM](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55de3f6a2a52763ac3c632d2e63de39aa338f862.png) ![56%20AM](https://us1.discourse-cdn.com/elastic/original/3X/3/b/3b2768a4fa83d7a4a83601b0ac8135cc0eee2f33.png)

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 16, 2019, 5:18pm UTC](https://discuss.elastic.co/t/solved-index-template-for-filebeat-fails-on-fields/176745/4 "2019-04-16T17:18:10Z")

</div>

Check if they are also exported.

```auto
export | grep BUILD_TRIGGER_GIT_COMMIT

```

If they are not, export them before running filebeat.

```auto
export BUILD_TRIGGER_GIT_COMMIT

```

---

<div class="post-metadata">

**Author:** ![Wayne\_Taylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayne_taylor/32/45984_2.png) [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Post date:** [April 16, 2019, 10:52pm UTC](https://discuss.elastic.co/t/solved-index-template-for-filebeat-fails-on-fields/176745/5 "2019-04-16T22:52:15Z")

</div>

@jsoriano - thank you that worked. Did i miss something in the docs for this OR something i can contribute back in the docs?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2019, 10:52pm UTC](https://discuss.elastic.co/t/solved-index-template-for-filebeat-fails-on-fields/176745/6 "2019-05-14T22:52:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
