# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [About the Beats category](https://discuss.elastic.co/t/about-the-beats-category/1067)

<div class="topic-metadata">

**Author:** [@Leslie\_Hawthorn](https://discuss.elastic.co/u/Leslie_Hawthorn)\
**Replies:** 0\
**Last updated:** [May 21, 2015, 9:27am UTC](https://discuss.elastic.co/t/about-the-beats-category/1067 "2015-05-21T09:27:28Z")

</div>

Lightweight data shippers Beats is a free and open platform for single-purpose data shippers. They send data from hundreds or thousands of machines and systems to Logstash or Elasticsearch. Please use the relevant tag f…

---

## [Filebeat postgresql log module produces timestamp fields that are not indexable when using ECS](https://discuss.elastic.co/t/filebeat-postgresql-log-module-produces-timestamp-fields-that-are-not-indexable-when-using-ecs/390640)

<div class="topic-metadata">

**Author:** [@kriller](https://discuss.elastic.co/u/kriller)\
**Replies:** 1\
**Last updated:** [September 24, 2026, 3:57pm UTC](https://discuss.elastic.co/t/filebeat-postgresql-log-module-produces-timestamp-fields-that-are-not-indexable-when-using-ecs/390640 "2026-09-24T15:57:40Z")

</div>

When using the ingest-pipeline that filebeat creates for postgresql logs, the resulting event contains the field postgresql.log.timestamp which conflicts with the ecs@mappings component template. The filebeat-9.5.4-post…

---

## [Filebeat performance, 430 containers](https://discuss.elastic.co/t/filebeat-performance-430-containers/390622)

<div class="topic-metadata">

**Author:** [@zerkms](https://discuss.elastic.co/u/zerkms)\
**Replies:** 0\
**Last updated:** [September 24, 2026, 5:18am UTC](https://discuss.elastic.co/t/filebeat-performance-430-containers/390622 "2026-09-24T05:18:13Z")

</div>

I'm migrating from quite an old ES+fluentbit configuration (logging solution for a small kubernetes cluster). And this is quite simple yet inefficient (?) config I came up with (this file is generated by ECK using the B…

---

## [Filebeat with Salesforce input and batch](https://discuss.elastic.co/t/filebeat-with-salesforce-input-and-batch/390433)

<div class="topic-metadata">

**Author:** [@stephaniearce](https://discuss.elastic.co/u/stephaniearce)\
**Replies:** 1\
**Last updated:** [September 16, 2026, 5:59pm UTC](https://discuss.elastic.co/t/filebeat-with-salesforce-input-and-batch/390433 "2026-09-16T17:59:51Z")

</div>

Can anyone explain why I'm running into this issue? I copied the exact config from the docs here: Salesforce input | Beats Salesforce input: object.batch.enabled: true fails with "map has no entry for key batch\_start\_ti…

---

## [Filebeat and Nanosecond Timestamps](https://discuss.elastic.co/t/filebeat-and-nanosecond-timestamps/389204)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [August 31, 2026, 3:55am UTC](https://discuss.elastic.co/t/filebeat-and-nanosecond-timestamps/389204 "2026-08-31T03:55:37Z")

</div>

Hi, Can I get some clarification around how filebeat handles an inbound timestamp field of nanosecond precision when it uses that field to set @timestamp? Also, can filebeat generate nanosecond timestamps?

---

## [Filebeat now processor seams to be buggy](https://discuss.elastic.co/t/filebeat-now-processor-seams-to-be-buggy/389776)

<div class="topic-metadata">

**Author:** [@Toony](https://discuss.elastic.co/u/Toony)\
**Replies:** 14\
**Last updated:** [August 20, 2026, 12:15pm UTC](https://discuss.elastic.co/t/filebeat-now-processor-seams-to-be-buggy/389776 "2026-08-20T12:15:47Z")

</div>

Hi, It seems the now processor behaves strangely If I set a now processor in filebeat at the top yaml level like this: processors: - now: field: metadata.timeline.t1 and configure Logstash like this: input {…

---

## [Int Overflow produces invalid Filebeat stats](https://discuss.elastic.co/t/int-overflow-produces-invalid-filebeat-stats/389458)

<div class="topic-metadata">

**Author:** [@fleaz](https://discuss.elastic.co/u/fleaz)\
**Replies:** 3\
**Last updated:** [August 17, 2026, 1:09pm UTC](https://discuss.elastic.co/t/int-overflow-produces-invalid-filebeat-stats/389458 "2026-08-17T13:09:48Z")

</div>

Hey, we recently discovered some strange metrics coming from our Filebeats (8.19.19 running in k8s) because we have an alert to check for queue usage and alert if the queue gets to full. Sometimes the value for "Queue …

---

## [Add the Valkey keys\_with\_volatile\_items keyspace metric](https://discuss.elastic.co/t/add-the-valkey-keys-with-volatile-items-keyspace-metric/389280)

<div class="topic-metadata">

**Author:** [@aglowienka](https://discuss.elastic.co/u/aglowienka)\
**Replies:** 2\
**Last updated:** [August 6, 2026, 3:05pm UTC](https://discuss.elastic.co/t/add-the-valkey-keys-with-volatile-items-keyspace-metric/389280 "2026-08-06T15:05:17Z")

</div>

Valkey ≥ 9.0 reports a per-database keys\_with\_volatile\_items counter in INFO keyspace that Metricbeat's redis.keyspace metricset does not collect. Please add it as redis.keyspace.keys\_with\_volatile\_items (long), alongs…

---

## [Winlogbeat 9.4.3 parsing fields wrong unless include\_xml is supplied](https://discuss.elastic.co/t/winlogbeat-9-4-3-parsing-fields-wrong-unless-include-xml-is-supplied/388680)

<div class="topic-metadata">

**Author:** [@tt-ah](https://discuss.elastic.co/u/tt-ah)\
**Replies:** 2\
**Last updated:** [August 6, 2026, 1:50pm UTC](https://discuss.elastic.co/t/winlogbeat-9-4-3-parsing-fields-wrong-unless-include-xml-is-supplied/388680 "2026-08-06T13:50:15Z")

</div>

Hello everyone! I noticed at least one field being processed incorrectly after updating our Elasticsearch and Winlogbeats to 9.4.3 (from 8.x.x). I do not have other findings yet, but I doubt this is the only case. Appl…

---

## [High Filebeat Disk I/O After Reboot With Ubuntu 24.04](https://discuss.elastic.co/t/high-filebeat-disk-i-o-after-reboot-with-ubuntu-24-04/388881)

<div class="topic-metadata">

**Author:** [@harrelst](https://discuss.elastic.co/u/harrelst)\
**Replies:** 0\
**Last updated:** [July 30, 2026, 3:32am UTC](https://discuss.elastic.co/t/high-filebeat-disk-i-o-after-reboot-with-ubuntu-24-04/388881 "2026-07-30T03:32:40Z")

</div>

We use a Filebeat DaemonSet to collect container logs from nodes in our Kubernetes cluster. I recently added some Ubuntu 24.04 nodes to the cluster, and when Filebeat restarts after a reboot generates around 150 MB/s of …

---

## [Metricbeat SQL Module with cursor rereading rows](https://discuss.elastic.co/t/metricbeat-sql-module-with-cursor-rereading-rows/387286)

<div class="topic-metadata">

**Author:** [@lpeter](https://discuss.elastic.co/u/lpeter)\
**Replies:** 3\
**Last updated:** [June 25, 2026, 7:39am UTC](https://discuss.elastic.co/t/metricbeat-sql-module-with-cursor-rereading-rows/387286 "2026-06-25T07:39:31Z")

</div>

Hello! I think I may have hit a bug where Metricbeat SQL module's cursor state can be read from the wrong Elastic Agent component data path, causing cursor reset and duplicate ingestion. This is on Elastic Agent / Metr…

---

## [Autodiscovery Strategy for Transitioning from Heartbeat to Synthetics](https://discuss.elastic.co/t/autodiscovery-strategy-for-transitioning-from-heartbeat-to-synthetics/387228)

<div class="topic-metadata">

**Author:** [@Cristian\_Pereyra](https://discuss.elastic.co/u/Cristian_Pereyra)\
**Replies:** 1\
**Last updated:** [June 24, 2026, 2:10am UTC](https://discuss.elastic.co/t/autodiscovery-strategy-for-transitioning-from-heartbeat-to-synthetics/387228 "2026-06-24T02:10:57Z")

</div>

Hello everyone. The topic that brings us here is Heartbeat autodiscover. We have many deployments that are going to be modified and we need to automate the detection and creation of monitors. The problem that is added …

---

## [Filebeat memory usage increases overtime until OOM](https://discuss.elastic.co/t/filebeat-memory-usage-increases-overtime-until-oom/387098)

<div class="topic-metadata">

**Author:** [@ryd-devops](https://discuss.elastic.co/u/ryd-devops)\
**Replies:** 3\
**Last updated:** [June 23, 2026, 6:28pm UTC](https://discuss.elastic.co/t/filebeat-memory-usage-increases-overtime-until-oom/387098 "2026-06-23T18:28:25Z")

</div>

We run filebeat (9.4.2) in our kubernetes clusters, mostly using the autodiscoverfeature and annotations. We have a lot of cronjobs and sidecar containers as well.. from a logging perspective filebeat is working great b…

---

## [Cloudwatch Integration State File Conflict](https://discuss.elastic.co/t/cloudwatch-integration-state-file-conflict/386904)

<div class="topic-metadata">

**Author:** [@andreaskapfer](https://discuss.elastic.co/u/andreaskapfer)\
**Replies:** 0\
**Last updated:** [June 19, 2026, 1:38pm UTC](https://discuss.elastic.co/t/cloudwatch-integration-state-file-conflict/386904 "2026-06-19T13:38:26Z")

</div>

Hello, we have registered an agent running on AWS ECS to collect our Kubernetes logs from AWS Cloudwatch. We are using start\_position: lastSync and a persistent AWS EFS volume for the agent's state. We are fetching two…

---

## [Crash in filebeat 9.3.0 on error "concurrent map iteration and map write"](https://discuss.elastic.co/t/crash-in-filebeat-9-3-0-on-error-concurrent-map-iteration-and-map-write/386208)

<div class="topic-metadata">

**Author:** [@grzegorzkw](https://discuss.elastic.co/u/grzegorzkw)\
**Replies:** 1\
**Last updated:** [June 15, 2026, 12:15pm UTC](https://discuss.elastic.co/t/crash-in-filebeat-9-3-0-on-error-concurrent-map-iteration-and-map-write/386208 "2026-06-15T12:15:01Z")

</div>

Hello, One of our filebeat deployments is bumping into the below error which crashes the service overall: fatal error: concurrent map iteration and map write goroutine 1 \[running\]: internal/runtime/maps.fatal({0x69991…

---

## [Haproxy integration: failed fetching haproxy info: not supported](https://discuss.elastic.co/t/haproxy-integration-failed-fetching-haproxy-info-not-supported/386841)

<div class="topic-metadata">

**Author:** [@Florian\_Heigl](https://discuss.elastic.co/u/Florian_Heigl)\
**Replies:** 1\
**Last updated:** [June 12, 2026, 4:45pm UTC](https://discuss.elastic.co/t/haproxy-integration-failed-fetching-haproxy-info-not-supported/386841 "2026-06-12T16:45:09Z")

</div>

Hi, I'm looking at an issue with the haproxy integration. It came up after an update but in this case it might have already been broken before that. the error message I see is: elastic-pfsense-input | {"log.level":"e…

---

## [Filebeat 9.3.1 slow to shutdown, takes \> 50s, using type: filestream,](https://discuss.elastic.co/t/filebeat-9-3-1-slow-to-shutdown-takes-50s-using-type-filestream/386789)

<div class="topic-metadata">

**Author:** [@Alex\_Rune\_Berg](https://discuss.elastic.co/u/Alex_Rune_Berg)\
**Replies:** 0\
**Last updated:** [June 10, 2026, 9:01am UTC](https://discuss.elastic.co/t/filebeat-9-3-1-slow-to-shutdown-takes-50s-using-type-filestream/386789 "2026-06-10T09:01:30Z")

</div>

Our filebeat does not stop quickly after changing it to use the 'type: filestream', we used 'type: log' before and it stopped immediately. We stop filebeat by sending it a -TERM, using pkill -TERM filebeat It normally…

---

## [Filebeat - Single-line JSON log ingestion: expected behavior and required configuration](https://discuss.elastic.co/t/filebeat-single-line-json-log-ingestion-expected-behavior-and-required-configuration/386753)

<div class="topic-metadata">

**Author:** [@aymanmazroui](https://discuss.elastic.co/u/aymanmazroui)\
**Replies:** 2\
**Last updated:** [June 8, 2026, 1:59pm UTC](https://discuss.elastic.co/t/filebeat-single-line-json-log-ingestion-expected-behavior-and-required-configuration/386753 "2026-06-08T13:59:58Z")

</div>

Hi, I have a specific use case and I need to know if Filebeat can handle it. My log files consist of a single very long line of JSON (no newline characters), which can be up to 27 MB in size. The entire file content i…

---

## [BUG: Heartbeat goes into a state of writing billions of error logs](https://discuss.elastic.co/t/bug-heartbeat-goes-into-a-state-of-writing-billions-of-error-logs/386726)

<div class="topic-metadata">

**Author:** [@up2neck](https://discuss.elastic.co/u/up2neck)\
**Replies:** 0\
**Last updated:** [June 5, 2026, 6:10am UTC](https://discuss.elastic.co/t/bug-heartbeat-goes-into-a-state-of-writing-billions-of-error-logs/386726 "2026-06-05T06:10:21Z")

</div>

Hello, Since version 9.3.1 of our deployment, that now uses 9.4.2 we observe the following behaviour in Heartbeat: Heartbeat is deployed with Elastic Agent, that controlled by the ECK operator Heartbeat is used for ru…

---

## [Filebeat-logstash question](https://discuss.elastic.co/t/filebeat-logstash-question/386311)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 6\
**Last updated:** [May 13, 2026, 11:48pm UTC](https://discuss.elastic.co/t/filebeat-logstash-question/386311 "2026-05-13T23:48:05Z")

</div>

filebeat.inputs: - type: filestream id: tad-run-logs enabled: true paths: - /run/\*/\*.tl - /run/\*/extra\_info exclude\_files: - '/run/cleanup\_rack/' file\_identity.native: ~ prospe…

---

## [BUG: xml\_query endlessly repeats same record in Winlogbeat 9.2.7+, 9.3](https://discuss.elastic.co/t/bug-xml-query-endlessly-repeats-same-record-in-winlogbeat-9-2-7-9-3/386112)

<div class="topic-metadata">

**Author:** [@lh317](https://discuss.elastic.co/u/lh317)\
**Replies:** 1\
**Last updated:** [April 30, 2026, 3:45pm UTC](https://discuss.elastic.co/t/bug-xml-query-endlessly-repeats-same-record-in-winlogbeat-9-2-7-9-3/386112 "2026-04-30T15:45:02Z")

</div>

I've run into an issue with newer versions of Winlogbeat that attempt to perform gap detection against the Windows channels. First, create any XML query that results in gaps in the record IDs (this should hopefully work…

---

## [Winlogbeat supports for TPM Windows certificates store](https://discuss.elastic.co/t/winlogbeat-supports-for-tpm-windows-certificates-store/386098)

<div class="topic-metadata">

**Author:** [@MiguelN](https://discuss.elastic.co/u/MiguelN)\
**Replies:** 0\
**Last updated:** [April 29, 2026, 2:57pm UTC](https://discuss.elastic.co/t/winlogbeat-supports-for-tpm-windows-certificates-store/386098 "2026-04-29T14:57:01Z")

</div>

I want to deploy per-device client certificates to Windows workstations via Intune SCEP, with the private key generated and bound to the TPM (Microsoft Platform Crypto Provider, non-exportable). Winlogbeat would then use…

---

## [Filebeat filestream offset mismatch when using include\_message with multiline](https://discuss.elastic.co/t/filebeat-filestream-offset-mismatch-when-using-include-message-with-multiline/386057)

<div class="topic-metadata">

**Author:** [@sem1308](https://discuss.elastic.co/u/sem1308)\
**Replies:** 0\
**Last updated:** [April 27, 2026, 7:26pm UTC](https://discuss.elastic.co/t/filebeat-filestream-offset-mismatch-when-using-include-message-with-multiline/386057 "2026-04-27T19:26:47Z")

</div>

Version 8.18.4 Operating System macOS (build & test) Steps to Reproduce 1. Configuration filebeat.inputs: - type: filestream id: filebeat-test paths: - /path/to/log/\* parsers: - include\_message.patterns:…

---

## [Netflow Fleet integration problem](https://discuss.elastic.co/t/netflow-fleet-integration-problem/385965)

<div class="topic-metadata">

**Author:** [@BenoitSERRA](https://discuss.elastic.co/u/BenoitSERRA)\
**Replies:** 0\
**Last updated:** [April 20, 2026, 3:34pm UTC](https://discuss.elastic.co/t/netflow-fleet-integration-problem/385965 "2026-04-20T15:34:47Z")

</div>

Hi all, Not sure if the category is the right one here, but here goes. I've deployed an ELK stack on a server of mine and deployed Fleet and several agents. I've deployed Fleet's Netflow integration and set up my OPNse…

---

## [Metricbeat move to Ceph mgr/dashboard API](https://discuss.elastic.co/t/metricbeat-move-to-ceph-mgr-dashboard-api/385921)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 0\
**Last updated:** [April 16, 2026, 2:32pm UTC](https://discuss.elastic.co/t/metricbeat-move-to-ceph-mgr-dashboard-api/385921 "2026-04-16T14:32:09Z")

</div>

Is there any plans for metricbeat to transition from the deprecated CEPH mgr/restful API to the mgr/dashboard API ?

---

## [Winlogbeat - Mismatched event.action for event.code](https://discuss.elastic.co/t/winlogbeat-mismatched-event-action-for-event-code/385735)

<div class="topic-metadata">

**Author:** [@coldmint](https://discuss.elastic.co/u/coldmint)\
**Replies:** 1\
**Last updated:** [April 2, 2026, 7:35am UTC](https://discuss.elastic.co/t/winlogbeat-mismatched-event-action-for-event-code/385735 "2026-04-02T07:35:31Z")

</div>

Hello, We’re running a clean install of Winlogbeat with a pretty barebones configuration, but unfortunately we’re noticing logged events transfer with incorrect event.action values for the respective event.code(Such as …

---

## [Duplicate messages observed in Kafka when using Filebeat with disk queue](https://discuss.elastic.co/t/duplicate-messages-observed-in-kafka-when-using-filebeat-with-disk-queue/385693)

<div class="topic-metadata">

**Author:** [@Thirupathi](https://discuss.elastic.co/u/Thirupathi)\
**Replies:** 1\
**Last updated:** [March 30, 2026, 1:38pm UTC](https://discuss.elastic.co/t/duplicate-messages-observed-in-kafka-when-using-filebeat-with-disk-queue/385693 "2026-03-30T13:38:46Z")

</div>

We are observing duplicate messages being published to Kafka from Filebeat, even when the Kafka broker is up and stable. The issue occurs while using the disk queue (queue.disk ) configuration Kafka Output Configuration…

---

## [How to ensure the integrity of filebeat output data during network fluctuations？](https://discuss.elastic.co/t/how-to-ensure-the-integrity-of-filebeat-output-data-during-network-fluctuations/385625)

<div class="topic-metadata">

**Author:** [@h123123123](https://discuss.elastic.co/u/h123123123)\
**Replies:** 0\
**Last updated:** [March 26, 2026, 2:03am UTC](https://discuss.elastic.co/t/how-to-ensure-the-integrity-of-filebeat-output-data-during-network-fluctuations/385625 "2026-03-26T02:03:20Z")

</div>

The version of Filebeat I am using is 9.3.1. I set max\_retries=-1, expecting that during network fluctuations, all data can be sent to Kafka. The actual test result: data is still lost during network fluctuations. I trie…

---

## [\[Elastic Log Driver\] Structured JSON logs breaks when Docker splits large log lines](https://discuss.elastic.co/t/elastic-log-driver-structured-json-logs-breaks-when-docker-splits-large-log-lines/385448)

<div class="topic-metadata">

**Author:** [@empee](https://discuss.elastic.co/u/empee)\
**Replies:** 0\
**Last updated:** [March 14, 2026, 2:10am UTC](https://discuss.elastic.co/t/elastic-log-driver-structured-json-logs-breaks-when-docker-splits-large-log-lines/385448 "2026-03-14T02:10:11Z")

</div>

Summary When using the Elastic Docker Logging Plugin, applications that already emit structured JSON logs cannot reliably ingest them into Elasticsearch because Docker may split large log lines before they reach the logg…

---

## [Syslog parser fails on double backslashes in structured data](https://discuss.elastic.co/t/syslog-parser-fails-on-double-backslashes-in-structured-data/385386)

<div class="topic-metadata">

**Author:** [@briandoesdev](https://discuss.elastic.co/u/briandoesdev)\
**Replies:** 2\
**Last updated:** [March 10, 2026, 1:35pm UTC](https://discuss.elastic.co/t/syslog-parser-fails-on-double-backslashes-in-structured-data/385386 "2026-03-10T13:35:19Z")

</div>

Hello everyone, My org is using the Custom UDP Logs integration to ingest RFC 5424 syslog messages from several network appliances. One of the appliances includes structured data with a parameter value containing a doub…

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=1)
