# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=101

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 102

---

## [Need to Push cloudtrail log to ELK using Filebeat](https://discuss.elastic.co/t/need-to-push-cloudtrail-log-to-elk-using-filebeat/299818)

<div class="topic-metadata">

**Author:** [@Anwar](https://discuss.elastic.co/u/Anwar)\
**Replies:** 0\
**Last updated:** [March 16, 2022, 5:42am UTC](https://discuss.elastic.co/t/need-to-push-cloudtrail-log-to-elk-using-filebeat/299818 "2022-03-16T05:42:42Z")

</div>

Hi, I want to push my cloudtrail logs to elk using filebeat. The Elasticsearch is a customised one. So I can't able to push the filebeat output directly to Elasticsearch. So I will use Logstash as output. From Logstash …

---

## [AWS CloudTrail SQS integration issues](https://discuss.elastic.co/t/aws-cloudtrail-sqs-integration-issues/299783)

<div class="topic-metadata">

**Author:** [@bil15](https://discuss.elastic.co/u/bil15)\
**Replies:** 1\
**Last updated:** [March 16, 2022, 3:16am UTC](https://discuss.elastic.co/t/aws-cloudtrail-sqs-integration-issues/299783 "2022-03-16T03:16:32Z")

</div>

Hello! I'm trying to ingest AWS CloudTrail logs via AWS integration in Fleet using S3 input (SQS). I followed this article to configure CloudTrail logs forwarding to SQS: https://docs.rapid7.com/insightidr/aws-cloudtr…

---

## [Custom Journald logs and Elastic 8](https://discuss.elastic.co/t/custom-journald-logs-and-elastic-8/299805)

<div class="topic-metadata">

**Author:** [@ooraini](https://discuss.elastic.co/u/ooraini)\
**Replies:** 0\
**Last updated:** [March 16, 2022, 12:43am UTC](https://discuss.elastic.co/t/custom-journald-logs-and-elastic-8/299805 "2022-03-16T00:43:25Z")

</div>

The Journald integration is not yet supported in Elastic 8 as indicated in package page: I did a test installation of Elastic 8.1, and indeed the package doesn't appear when searching for it in the integrations page in…

---

## [How to add cluster name in the event using add-kubernetes-metadata processor](https://discuss.elastic.co/t/how-to-add-cluster-name-in-the-event-using-add-kubernetes-metadata-processor/299784)

<div class="topic-metadata">

**Author:** [@Dario\_Louzado](https://discuss.elastic.co/u/Dario_Louzado)\
**Replies:** 0\
**Last updated:** [March 15, 2022, 8:17pm UTC](https://discuss.elastic.co/t/how-to-add-cluster-name-in-the-event-using-add-kubernetes-metadata-processor/299784 "2022-03-15T20:17:12Z")

</div>

Hi, I'm using kubernetes autodiscover with add-kubernetes-metadata processor. In the log event I could not find the kubernetes cluster name. Only the namespace. How can I get this information? Thanks in advance. Reg…

---

## [How to collect containerized elasticsearch logs with filebeat](https://discuss.elastic.co/t/how-to-collect-containerized-elasticsearch-logs-with-filebeat/299118)

<div class="topic-metadata">

**Author:** [@marone](https://discuss.elastic.co/u/marone)\
**Replies:** 7\
**Last updated:** [March 15, 2022, 3:10pm UTC](https://discuss.elastic.co/t/how-to-collect-containerized-elasticsearch-logs-with-filebeat/299118 "2022-03-15T15:10:19Z")

</div>

Hey I am setting up an observaiblity use case to test it with docker, and I want to collect Elasticsearch logs (gc, audit, etc.) using Filebeat. I have Elasticsearch running in a docker container, and I have filebeat ru…

---

## [Agent data gathering behaviour](https://discuss.elastic.co/t/agent-data-gathering-behaviour/299754)

<div class="topic-metadata">

**Author:** [@Sergey\_K](https://discuss.elastic.co/u/Sergey_K)\
**Replies:** 0\
**Last updated:** [March 15, 2022, 3:09pm UTC](https://discuss.elastic.co/t/agent-data-gathering-behaviour/299754 "2022-03-15T15:09:36Z")

</div>

Good Afternoon, Unfortunately couldn't find this information in other sources. Could you please update me on how do the agents (in common) treat collected data while ELK stack is unavailable? Do they drop the data or …

---

## [Redis : Failed to fetch redis info for keyspaces: read tcp xxx-\>xxx i/o timeout](https://discuss.elastic.co/t/redis-failed-to-fetch-redis-info-for-keyspaces-read-tcp-xxx-xxx-i-o-timeout/299161)

<div class="topic-metadata">

**Author:** [@masyutka](https://discuss.elastic.co/u/masyutka)\
**Replies:** 1\
**Last updated:** [March 15, 2022, 1:28pm UTC](https://discuss.elastic.co/t/redis-failed-to-fetch-redis-info-for-keyspaces-read-tcp-xxx-xxx-i-o-timeout/299161 "2022-03-15T13:28:02Z")

</div>

Hi , I am trying to use metricbeat (version 7.12.1) module for Redis. Redis cluster is managed AWS ElastiCache. Here is config: module: redis metricsets: \["info", "keyspace"\] enabled: true period: 2m Redis host…

---

## [Filebeat Fortinet module - can't parse event as syslog rfc3164](https://discuss.elastic.co/t/filebeat-fortinet-module-cant-parse-event-as-syslog-rfc3164/297712)

<div class="topic-metadata">

**Author:** [@gflukas](https://discuss.elastic.co/u/gflukas)\
**Replies:** 1\
**Last updated:** [March 15, 2022, 10:20am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-cant-parse-event-as-syslog-rfc3164/297712 "2022-03-15T10:20:10Z")

</div>

Hey guys my journalctl keeps filled with errors. Filebeat Fortinet module - can't parse event as syslog rfc3164. What I can do to fix it? I'm using Ubuntu 20.04. Filebeat version filebeat:amd64/stable 7.16.1 upgradeabl…

---

## [Hability to create daily index to metricbeat](https://discuss.elastic.co/t/hability-to-create-daily-index-to-metricbeat/299302)

<div class="topic-metadata">

**Author:** [@gerardgorrion](https://discuss.elastic.co/u/gerardgorrion)\
**Replies:** 4\
**Last updated:** [March 15, 2022, 9:31am UTC](https://discuss.elastic.co/t/hability-to-create-daily-index-to-metricbeat/299302 "2022-03-15T09:31:01Z")

</div>

Hi all, We are deploying an stack monitoring to eck: Current monitoring are working fine, to Elasticsearch and kibana resources. But we have a problem with the index creation: metricbeat create a single index with for…

---

## [Do filebeat has hostname variable?](https://discuss.elastic.co/t/do-filebeat-has-hostname-variable/298665)

<div class="topic-metadata">

**Author:** [@Gyrops](https://discuss.elastic.co/u/Gyrops)\
**Replies:** 1\
**Last updated:** [March 14, 2022, 7:10pm UTC](https://discuss.elastic.co/t/do-filebeat-has-hostname-variable/298665 "2022-03-14T19:10:44Z")

</div>

I need to configure a hostname variable in my filebeat.yaml configuration file without using host system variable. It's doabble? How is now: fields: source: myhostname How I would like it to be: fields: source: $…

---

## [Failed to start filebeat\_ drop\_fields processors](https://discuss.elastic.co/t/failed-to-start-filebeat-drop-fields-processors/299154)

<div class="topic-metadata">

**Author:** [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Replies:** 6\
**Last updated:** [March 14, 2022, 6:53pm UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-drop-fields-processors/299154 "2022-03-14T18:53:03Z")

</div>

good day I have a problem when I start filebeat I get the following error: and this is my configuration in filebeat.yml # ================================= Processors ================================= processors: #…

---

## [Create service unit for Auditbeat for Debian](https://discuss.elastic.co/t/create-service-unit-for-auditbeat-for-debian/299622)

<div class="topic-metadata">

**Author:** [@helkmaster](https://discuss.elastic.co/u/helkmaster)\
**Replies:** 0\
**Last updated:** [March 14, 2022, 1:16pm UTC](https://discuss.elastic.co/t/create-service-unit-for-auditbeat-for-debian/299622 "2022-03-14T13:16:44Z")

</div>

For DEB and RPM there is by default a serivce unit when you want to start Auditbeat. I currently work on a Debian distribution and I want to create a service unit for Auditbeat because I want to run it in the background…

---

## [Filebeat with custom logfile and kubernetes metadata to elasticsearch and kibana](https://discuss.elastic.co/t/filebeat-with-custom-logfile-and-kubernetes-metadata-to-elasticsearch-and-kibana/299403)

<div class="topic-metadata">

**Author:** [@v\_anil](https://discuss.elastic.co/u/v_anil)\
**Replies:** 0\
**Last updated:** [March 11, 2022, 6:40am UTC](https://discuss.elastic.co/t/filebeat-with-custom-logfile-and-kubernetes-metadata-to-elasticsearch-and-kibana/299403 "2022-03-11T06:40:08Z")

</div>

Our applications are deployed in AWS EKS cluster, and for certain reasons we need to write our app logs to separate file lets say ${POD\_NAME}.applog instead of stdout (we mounted /var/log/container/ to the pod /log folde…

---

## [Harvester\_buffer\_size - why increase it?](https://discuss.elastic.co/t/harvester-buffer-size-why-increase-it/299226)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 2\
**Last updated:** [March 14, 2022, 10:04am UTC](https://discuss.elastic.co/t/harvester-buffer-size-why-increase-it/299226 "2022-03-14T10:04:49Z")

</div>

The documentation says what the harvest\_buffer\_size setting of the log input is for, but I don't see anything about why one might want to change it. I noticed that a Filebeat 7.17 instance on a CentOS 7 server that is…

---

## [Beats Logs differentiation based on Environment in Kibana UI](https://discuss.elastic.co/t/beats-logs-differentiation-based-on-environment-in-kibana-ui/299500)

<div class="topic-metadata">

**Author:** [@helper](https://discuss.elastic.co/u/helper)\
**Replies:** 2\
**Last updated:** [March 14, 2022, 9:58am UTC](https://discuss.elastic.co/t/beats-logs-differentiation-based-on-environment-in-kibana-ui/299500 "2022-03-14T09:58:51Z")

</div>

Hi there, I am looking for some help to differentiate the logs which I am sending from various environments to the Elastic. Flow : File Beat -\> Logstash -\> Elastic -\> Kibana. I would like to see the logs which I pushed…

---

## [Monitor/alert beats dropped events](https://discuss.elastic.co/t/monitor-alert-beats-dropped-events/295591)

<div class="topic-metadata">

**Author:** [@smueller](https://discuss.elastic.co/u/smueller)\
**Replies:** 7\
**Last updated:** [March 14, 2022, 8:28am UTC](https://discuss.elastic.co/t/monitor-alert-beats-dropped-events/295591 "2022-03-14T08:28:42Z")

</div>

Hi, i need to alert me on filebeat dropping events. Even better alerting me on the kind of error that lead to the dropping. I'm running filebeat 7.15 on rhel-7. First tack i tried was to use the internal monitorings sys…

---

## [Couldn't run filebeat image](https://discuss.elastic.co/t/couldnt-run-filebeat-image/299590)

<div class="topic-metadata">

**Author:** [@Mariem](https://discuss.elastic.co/u/Mariem)\
**Replies:** 1\
**Last updated:** [March 14, 2022, 8:36am UTC](https://discuss.elastic.co/t/couldnt-run-filebeat-image/299590 "2022-03-14T08:36:38Z")

</div>

Can someone help me solve this problem

---

## [How about collect "request.body.bytes" in Nginx ingest-pipeline provided by Filebeat?](https://discuss.elastic.co/t/how-about-collect-request-body-bytes-in-nginx-ingest-pipeline-provided-by-filebeat/299554)

<div class="topic-metadata">

**Author:** [@Lee\_Sun\_Ro](https://discuss.elastic.co/u/Lee_Sun_Ro)\
**Replies:** 0\
**Last updated:** [March 13, 2022, 5:11am UTC](https://discuss.elastic.co/t/how-about-collect-request-body-bytes-in-nginx-ingest-pipeline-provided-by-filebeat/299554 "2022-03-13T05:11:35Z")

</div>

Hello, I'm a light user of Filebeat. According to the documentation, the nginx.ingress\_controller collects the body size of the http request, but the nginx access module does not. Why is there such a difference? Or am…

---

## [Remove backslash from Json logs in Kibana](https://discuss.elastic.co/t/remove-backslash-from-json-logs-in-kibana/299550)

<div class="topic-metadata">

**Author:** [@gooner\_holmes](https://discuss.elastic.co/u/gooner_holmes)\
**Replies:** 0\
**Last updated:** [March 13, 2022, 3:27am UTC](https://discuss.elastic.co/t/remove-backslash-from-json-logs-in-kibana/299550 "2022-03-13T03:27:25Z")

</div>

filebeat.inputs: - type: log paths: - '/var/lib/docker/containers/\*/\*.log' multiline.type: pattern multiline.pattern: '^\\\\' multiline.negate: true multiline.match: after processors: - add\_docker\_metadat…

---

## [Filebeat nginx dashboard kubernetes](https://discuss.elastic.co/t/filebeat-nginx-dashboard-kubernetes/299520)

<div class="topic-metadata">

**Author:** [@Mohsin\_Ijaz](https://discuss.elastic.co/u/Mohsin_Ijaz)\
**Replies:** 0\
**Last updated:** [March 12, 2022, 1:16pm UTC](https://discuss.elastic.co/t/filebeat-nginx-dashboard-kubernetes/299520 "2022-03-12T13:16:04Z")

</div>

Hi, I am new to ELK and IT field started as a devops recently so you can consider me being a complete noob. I am having trouble setting up the filebeat nginx dashboard. deployed the ELK on Kubernetes cluster, using th…

---

## [Connect filebeat to ELK server from 2 different machines](https://discuss.elastic.co/t/connect-filebeat-to-elk-server-from-2-different-machines/298435)

<div class="topic-metadata">

**Author:** [@Dhia\_Saibi](https://discuss.elastic.co/u/Dhia_Saibi)\
**Replies:** 2\
**Last updated:** [March 12, 2022, 9:55am UTC](https://discuss.elastic.co/t/connect-filebeat-to-elk-server-from-2-different-machines/298435 "2022-03-12T09:55:34Z")

</div>

hi i'm asking how can i connect filebeat installed on one machine to ELK server on another machine..who can help me with this process?

---

## [Metricbeat user privileges for data ingest?](https://discuss.elastic.co/t/metricbeat-user-privileges-for-data-ingest/299481)

<div class="topic-metadata">

**Author:** [@kmiklas](https://discuss.elastic.co/u/kmiklas)\
**Replies:** 1\
**Last updated:** [March 11, 2022, 6:08pm UTC](https://discuss.elastic.co/t/metricbeat-user-privileges-for-data-ingest/299481 "2022-03-11T18:08:05Z")

</div>

What are the privileges required for a metricbeat user to receive data? Under (Hamburger) -\> Stack Management -\> Security -\> Users, I've set up a metricbeat user. Its purpose is to receive metrics. What are its require…

---

## [Fleet Server Fails At Start, No Reason Given](https://discuss.elastic.co/t/fleet-server-fails-at-start-no-reason-given/298854)

<div class="topic-metadata">

**Author:** [@CptElasticBand](https://discuss.elastic.co/u/CptElasticBand)\
**Replies:** 1\
**Last updated:** [March 11, 2022, 3:45pm UTC](https://discuss.elastic.co/t/fleet-server-fails-at-start-no-reason-given/298854 "2022-03-11T15:45:55Z")

</div>

Hello. I've been looking around to see if anyone else has experienced a similar issue but I haven't found anything. I've setup an Elasticsearch cluster and Kibana all using SSL certificates created following the Elastic …

---

## [Hashicorp's Nomad monitoring using metricbeat](https://discuss.elastic.co/t/hashicorps-nomad-monitoring-using-metricbeat/299162)

<div class="topic-metadata">

**Author:** [@Uzmasaman\_Chanderki](https://discuss.elastic.co/u/Uzmasaman_Chanderki)\
**Replies:** 1\
**Last updated:** [March 11, 2022, 2:43pm UTC](https://discuss.elastic.co/t/hashicorps-nomad-monitoring-using-metricbeat/299162 "2022-03-11T14:43:50Z")

</div>

I am new to this community and my resources are exhausted. I am trying to implement monitoring on Hashicorp's Nomad using metricbeat but there is no metricbeat.module available for now. Is there any alternative where t…

---

## [Filebeat Zeek module not reading all events with -once option](https://discuss.elastic.co/t/filebeat-zeek-module-not-reading-all-events-with-once-option/299459)

<div class="topic-metadata">

**Author:** [@dlohin](https://discuss.elastic.co/u/dlohin)\
**Replies:** 2\
**Last updated:** [March 11, 2022, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-zeek-module-not-reading-all-events-with-once-option/299459 "2022-03-11T13:50:15Z")

</div>

I am using Filebeat 8.0.1 inside of a container and trying to utilize it to read through a bunch of Zeek logs formatted in JSON and ending the process when finished. Ending nicely with an error code is critical because …

---

## [Delay to Metribeat system input data into Elasticsearch](https://discuss.elastic.co/t/delay-to-metribeat-system-input-data-into-elasticsearch/299348)

<div class="topic-metadata">

**Author:** [@Thiago\_Paiva](https://discuss.elastic.co/u/Thiago_Paiva)\
**Replies:** 0\
**Last updated:** [March 10, 2022, 3:15pm UTC](https://discuss.elastic.co/t/delay-to-metribeat-system-input-data-into-elasticsearch/299348 "2022-03-10T15:15:40Z")

</div>

Hi Everyone, I'm monitoring a Linux server with metricbeat, but I noticed a delay for the input of metrics into Elastic (Discover - Kibana). Time is approximately 2 minutes. My configuration is 3 master elastic nodes th…

---

## [\[Filebeat\] Specify Elasticsearch Ingest Pipeline with Hints-Based Autodiscover](https://discuss.elastic.co/t/filebeat-specify-elasticsearch-ingest-pipeline-with-hints-based-autodiscover/298545)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 1\
**Last updated:** [March 10, 2022, 6:19pm UTC](https://discuss.elastic.co/t/filebeat-specify-elasticsearch-ingest-pipeline-with-hints-based-autodiscover/298545 "2022-03-10T18:19:55Z")

</div>

How can I specify a custom Elasticsearch Ingest Pipeline for use with hints-based autodiscover. E.g., I would like to be able to include it as a pod annotation, rather than hardcode it into the autodiscover specification…

---

## [Merticbeat Error dialing x509: certificate is valid for 127.0.0.1, not 172.16.0.204](https://discuss.elastic.co/t/merticbeat-error-dialing-x509-certificate-is-valid-for-127-0-0-1-not-172-16-0-204/299323)

<div class="topic-metadata">

**Author:** [@Spyros\_Agriopoulos](https://discuss.elastic.co/u/Spyros_Agriopoulos)\
**Replies:** 2\
**Last updated:** [March 10, 2022, 3:19pm UTC](https://discuss.elastic.co/t/merticbeat-error-dialing-x509-certificate-is-valid-for-127-0-0-1-not-172-16-0-204/299323 "2022-03-10T15:19:18Z")

</div>

Metricbeat has stopped working and is giving me Error dialing x509: certificate is valid for 127.0.0.1, not x.x.x.x after a yum update. Other instances that are using the exact same certificate are working fine. Any i…

---

## [Combine filebeat logs to ship to Elastic Search based on unique trace id (without Logstash)](https://discuss.elastic.co/t/combine-filebeat-logs-to-ship-to-elastic-search-based-on-unique-trace-id-without-logstash/298968)

<div class="topic-metadata">

**Author:** [@shikha1](https://discuss.elastic.co/u/shikha1)\
**Replies:** 4\
**Last updated:** [March 10, 2022, 1:50pm UTC](https://discuss.elastic.co/t/combine-filebeat-logs-to-ship-to-elastic-search-based-on-unique-trace-id-without-logstash/298968 "2022-03-10T13:50:34Z")

</div>

I have configured filebeat for shipping logs of my spring boot application directly to Elasticsearch without configuration of logstash. I want to configure filebeat multiline regex in a way that it can combine all the lo…

---

## [Output.kafka filebeat (possible to add field ?)](https://discuss.elastic.co/t/output-kafka-filebeat-possible-to-add-field/299332)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 2\
**Last updated:** [March 10, 2022, 1:32pm UTC](https://discuss.elastic.co/t/output-kafka-filebeat-possible-to-add-field/299332 "2022-03-10T13:32:16Z")

</div>

Hi, I would like to know if it is possible to add a field in the kafka output filebeat.yml: output.kafka: hosts: \["127.0.0.1:9092"\] topic: '%{\[fields.kafka\_topic\]}' codec.format: string: '%{\[message\]}' par…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=100)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=102)
