Logstash to OpenObserve Configuration Issue

TLDR Chris experiences issues setting up winlogbeat->logstash->openobserve, and seeks a solution. Hengfei suggests disabling healthcheck in logstash.

Photo of Chris
Mon, 12 Jun 2023 16:22:47 UTC

hi..... I currently have windows event logs flowing winlogbeat->logstash->elasticsearch, and am trying to do winlogbeat->logstash->openobserve.... i've tried the logstash elasticsearch output but can't get the healthcheck against openobserve to succeed - i think it is receiving html instead of json when looking for the version number..... i've also tried the logstash http output, and i see events going into openobserve but each results in took:0 with no events being ingested.... does anyone have a recipe for logstash->openobserve? i have managed winlogbeat->openobserve as a test and it ingests fine, but i'm constrained to having logstash in the middle

Photo of Hengfei
Mon, 12 Jun 2023 16:52:39 UTC

because of healthcheck, can you disable healthcheck in logstash?