# Test on beat version doesn't work

**URL:** <https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152>\
**Category:** Logstash\
**Created:** [November 26, 2018, 10:42am UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152 "2018-11-26T10:42:34Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yilmaz\_Cam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yilmaz_cam/32/38046_2.png) [@Yilmaz\_Cam](https://discuss.elastic.co/u/Yilmaz_Cam)\
**Post date:** [November 26, 2018, 10:42am UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152/1 "2018-11-26T10:42:34Z")

</div>

Hello  
Currently i have 2 versions of beat on my infra 5.5 and 6.4, my logstash version is 5.6 so compatible with beat client 5.5 and 6.4.  
I try to detect the beat version of the document and redirect it to correct output. My document in 6.4 doesn't index in elasticsearch but 5.5 works .  
if [beat][version] == "6.4.2" {  
elasticsearch {  
hosts =\> ["172.18.3.192:9200", "172.18.3.191:9200"]  
ssl =\> true  
ssl\_certificate\_verification =\> false  
index =\> "logstash-syslog-hp-v6-%{+YYYY.MM}"  
user =\> "xxxx"  
password =\> "xxxx"  
}  
}  
else {  
elasticsearch {  
hosts =\> ["172.18.3.192:9200", "172.18.3.191:9200"]  
ssl =\> true  
ssl\_certificate\_verification =\> false  
index =\> "logstash-syslog-hp-%{+YYYY.MM}"  
user =\> "xxxxx"  
password =\> "xxxxx"  
}  
}

```
    }

```

Thanks in advance for your help i tried everything .

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 26, 2018, 10:59am UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152/2 "2018-11-26T10:59:24Z")

</div>

> [@Yilmaz\_Cam](#):
>
> if [beat][version] == "6.4.2" {

Try this

```
if [beat][version] == 6.4.2 {

```

---

<div class="post-metadata">

**Author:** ![Yilmaz\_Cam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yilmaz_cam/32/38046_2.png) [@Yilmaz\_Cam](https://discuss.elastic.co/u/Yilmaz_Cam)\
**Post date:** [November 26, 2018, 11:08am UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152/3 "2018-11-26T11:08:35Z")

</div>

Hello  
Thanks for your fast reply, I tried but doesn't work. I wonder if the [beat][version] is correct, on elastic site they say [@metadata] [version] to access to beat version but it doesn't work too. I tried [@metadata][version] or [@metadata][beat][version] or [beat][version] , nothing work ☹

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 26, 2018, 11:11am UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152/4 "2018-11-26T11:11:28Z")

</div>

Can you try this:

```
if "6.4.2" in [beat][version] {
```

---

<div class="post-metadata">

**Author:** ![Yilmaz\_Cam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yilmaz_cam/32/38046_2.png) [@Yilmaz\_Cam](https://discuss.elastic.co/u/Yilmaz_Cam)\
**Post date:** [November 29, 2018, 10:18am UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152/5 "2018-11-29T10:18:58Z")

</div>

same issue .  
bellow the output received by logstash :  
[2018-11-26T12:17:07,378][DEBUG][logstash.pipeline] output received {"event"=\>{"appli\_hostname"=\>"FRCCEISEPT01", "syslog\_severity\_code"=\>5, "offset"=\>217996292, "syslog\_facility"=\>"user-level", "project"=\>"infra", "syslog\_facility\_code"=\>1, "source"=\>"/var/log/messages", "message"=\>"Nov 26 12:16:33 FRCCEISEPT01 journal: E1126 11:16:33.174102 1 authentication.go:62] Unable to authenticate the request due to an error: [x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "kubernetes"), x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "kubernetes")]", "env"=\>"TST", "type"=\>"log", "syslog\_severity"=\>"notice", "tags"=\>["beats\_input\_codec\_plain\_applied", "v6"], "appli\_timestamp"=\>"Nov 26 12:16:33", "received\_from"=\>"{"name":"FRCCEISEPT01"}", "@timestamp"=\>2018-11-26T11:16:33.000Z, "int1"=\>1, "appli"=\>["syslog", "syslog"], "appli\_message"=\>"E1126 11:16:33.174102 1 authentication.go:62] Unable to authenticate the request due to an error: [x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "kubernetes"), x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "kubernetes")]", "received\_at"=\>"2018-11-26T11:16:34.101Z", "@version"=\>"1", "beat"=\>{"name"=\>"FRCCEISEPT01", "hostname"=\>"FRCCEISEPT01", "version"=\>"6.4.2"}, "host"=\>{"name"=\>"FRCCEISEPT01"}, "appli\_program"=\>"journal"}}

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 29, 2018, 10:39am UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152/6 "2018-11-29T10:39:34Z")

</div>

That's not the same issue, please read the error message, it does not like your certificate!

---

<div class="post-metadata">

**Author:** ![Yilmaz\_Cam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yilmaz_cam/32/38046_2.png) [@Yilmaz\_Cam](https://discuss.elastic.co/u/Yilmaz_Cam)\
**Post date:** [November 29, 2018, 10:59am UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152/7 "2018-11-29T10:59:18Z")

</div>

> [@Yilmaz\_Cam](#):
>
> 26 12:16:33 FRCCEISEPT01 journal: E1126 11:16:33.174102 1 authentication.go:62] Unable to authenticate the request due to an error: [x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "kubernetes"), x509: certificate signed by

- 

Hi in fact the the part about ssl certificates is the content of the messages field received by the client :

"message"=\>;"Nov 26 12:16:33 FRCCEISEPT01 journal: E1126 11:16:33.174102 1 authentication.go:62] Unable to authenticate the request due to an error: [x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "kubernetes"), x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "kubernetes"

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 29, 2018, 11:20am UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152/8 "2018-11-29T11:20:08Z")

</div>

My apologies!

Can you please post your full config?

---

<div class="post-metadata">

**Author:** ![Yilmaz\_Cam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yilmaz_cam/32/38046_2.png) [@Yilmaz\_Cam](https://discuss.elastic.co/u/Yilmaz_Cam)\
**Post date:** [November 30, 2018, 4:20pm UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152/9 "2018-11-30T16:20:29Z")

</div>

Sorry for late reply,  
**- filebeat client 6.4**  
filebeat.yml :  
filebeat:  
registry\_file: /var/lib/filebeat/registry  
config\_dir: /etc/filebeat/conf.d  
prospectors:  
-  
paths:  
- /var/log/messages  
- /var/log/secure  
input\_type: log  
fields\_under\_root: true  
fields:  
project: infra  
env: TST  
appli: syslog  
document\_type: syslog  
force\_close\_files: true

output:  
logstash:  
hosts: ["XXXXX:5044", "XXXXXXXX:5044"]  
loadbalance: false  
enable: true  
ssl:  
certificate\_authorities: ["/etc/filebeat/logstash.crt"]  
verification\_mode: "none"

shipper:  
logging:  
level: error  
to\_syslog: false  
to\_files: true  
files:  
path: /var/log/filebeat  
name: filebeat.log  
rotateeverybytes: 99999999999  
keepfiles: 2

\*\*Logstash server 5.6 \*\*  
- config file :  
input {  
beats {  
port =\> 5044  
type =\> "log"  
ssl =\> true  
ssl\_certificate =\> "/etc/logstash/logstash.crt"  
ssl\_key =\> "/etc/logstash/logstash.key"  
ssl\_verify\_mode =\> "none"  
}  
}

filter {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:appli\_timestamp} %{SYSLOGHOST:appli\_hostname} %{DATA:appli\_program}(?:[%{POSINT:appli\_pid}])?: %{GREEDYDATA:appli\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
tag\_on\_failure =\> ["soucis-grok"]  
}  
}  
output {  
if [@metadata][version] == "6.4.2" {  
elasticsearch {  
hosts =\> ["XXXXX:9200", "XXXX:9200"]  
ssl =\> true  
ssl\_certificate\_verification =\> false  
index =\> "system-hp-%{+YYYY.MM}"  
user =\> "XXXX"  
password =\> "XXXX"  
}  
}  
else {  
elasticsearch {  
hosts =\> ["172.18.3.192:9200", "172.18.3.191:9200"]  
ssl =\> true  
ssl\_certificate\_verification =\> false  
index =\> "logstash-syslog-hp-%{+YYYY.MM}"  
user =\> "XXX"  
password =\> "XXX"  
}  
}  
}  
**template file on elastic (5.6)**  
{  
"system-hp": {  
"order": 0,  
"version": 50001,  
"template": "system-hp-_",  
"settings": {  
"index": {  
"number\_of\_shards": "3",  
"refresh\_interval": "5s"  
}  
},  
"mappings": {  
"default": {  
"dynamic\_templates": [  
{  
"message\_field": {  
"path\_match": "message",  
"match\_mapping\_type": "string",  
"mapping": {  
"type": "text",  
"norms": false  
}  
}  
},  
{  
"string\_fields": {  
"match": "_",  
"match\_mapping\_type": "string",  
"mapping": {  
"type": "text",  
"norms": false,  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
}  
}  
}  
],  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"@version": {  
"type": "keyword"  
}  
}  
}  
},  
"aliases": {}  
}  
}

The document that should go in logstash-syslog-hp-\* are fine and works, but the index system-hp-\* where filebeat client 6.4 should be indexed doesn't work no index created no document .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2018, 4:20pm UTC](https://discuss.elastic.co/t/test-on-beat-version-doesnt-work/158152/10 "2018-12-28T16:20:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
