Step 4: Loading the Index Template in Elasticsearch

edit

Step 4: Loading the Index Template in Elasticsearch

edit

Before starting Winlogbeat, you need to load the index template, which lets Elasticsearch know which fields should be analyzed in which way.

The recommended template file is installed by the Winlogbeat packages. You can either configure Winlogbeat to load the template automatically, or you can run a shell command to load the template:

Configuring Winlogbeat to Load the Template

edit

To configure Winlogbeat to load the template, you must enable the elasticsearch output. In the Winlogbeat configuration file, uncomment the template part under elasticsearch output. By default the template is named winlogbeat. Adjust the path to your template file.

output:
  elasticsearch:
    hosts: ["localhost:9200"]

    # A template is used to set the mapping in Elasticsearch
    # By default template loading is disabled and no template is loaded.
    # These settings can be adjusted to load your own template or overwrite existing ones
    template:

      # Template name. By default the template name is winlogbeat.
      #name: "winlogbeat"

      # Path to template file
      path: "winlogbeat.template.json"

      # Overwrite existing template
      #overwrite: false

The template is loaded when you start Winlogbeat. By default, if a template already exists in the index, it is not overwritten. To overwrite an existing template, set overwrite: true in the configuration file.

Running a Shell Command to Load the Template

edit

You can load the template by running the following command:

win:

PS C:\Program Files\Winlogbeat> Invoke-WebRequest -Method Put -InFile winlogbeat.template.json -Uri http://localhost:9200/_template/winlogbeat?pretty

where localhost:9200 is the IP and port where Elasticsearch is listening.

If you’ve already used Winlogbeat to index data into Elasticsearch, the index may contain old documents. After you load the index template, you can delete the old documents from winlogbeat-* to force Kibana to look at the newest documents. Use this command:

curl -XDELETE 'http://localhost:9200/winlogbeat-*'