# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=102

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 103

---

## [No data has been received from this module yet message](https://discuss.elastic.co/t/no-data-has-been-received-from-this-module-yet-message/299330)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 1\
**Last updated:** [March 10, 2022, 1:26pm UTC](https://discuss.elastic.co/t/no-data-has-been-received-from-this-module-yet-message/299330 "2022-03-10T13:26:54Z")

</div>

Hi, I have already configured Suricata logs to be fowarded to ES through Filebeat. I am receiving the logs but this message still appears. I am using the Suricata module aswell

---

## [Note in kafka output](https://discuss.elastic.co/t/note-in-kafka-output/299336)

<div class="topic-metadata">

**Author:** [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Replies:** 0\
**Last updated:** [March 10, 2022, 1:03pm UTC](https://discuss.elastic.co/t/note-in-kafka-output/299336 "2022-03-10T13:03:01Z")

</div>

Hello. The doc notes record in kafka topic will be deleted immediately . it’s going to be immediately discarded since the timestamp value is before the last 7 days. However, kafka is deleting the segment according…

---

## [Heartbeat mappings missing](https://discuss.elastic.co/t/heartbeat-mappings-missing/299220)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 4\
**Last updated:** [March 10, 2022, 12:16pm UTC](https://discuss.elastic.co/t/heartbeat-mappings-missing/299220 "2022-03-10T12:16:57Z")

</div>

Hello, I'm using ELK 7.17.0 with Heartbeat 7.17 on Linux. Before starting Heartbeat, I ran the setup command to load index template for Heartbeat and tested the configuration successfully. After starting the Heartbeat …

---

## [Handle short time connection issues - Filebeat](https://discuss.elastic.co/t/handle-short-time-connection-issues-filebeat/299250)

<div class="topic-metadata">

**Author:** [@arvin495](https://discuss.elastic.co/u/arvin495)\
**Replies:** 0\
**Last updated:** [March 9, 2022, 5:26pm UTC](https://discuss.elastic.co/t/handle-short-time-connection-issues-filebeat/299250 "2022-03-09T17:26:29Z")

</div>

Hello Team, we are running 3 node Elasticsearch cluster. All our k8s cluster has filebeats configured - which pushes the logs to Elasticsearch. We have a requirement of upgrading the the Elasticsearch. when I performed…

---

## [Elastic agent not shipping data](https://discuss.elastic.co/t/elastic-agent-not-shipping-data/299236)

<div class="topic-metadata">

**Author:** [@Youssef\_Kaak](https://discuss.elastic.co/u/Youssef_Kaak)\
**Replies:** 1\
**Last updated:** [March 9, 2022, 3:25pm UTC](https://discuss.elastic.co/t/elastic-agent-not-shipping-data/299236 "2022-03-09T15:25:55Z")

</div>

Hello everyone, I am new to ELK. Recently, I got access to a server which is running Vagrant and many other stuff. My mission is to mainly deploy ELK on a VM that will be running on Vagrant. I followed the steps menti…

---

## [Filebeat add\_kubernetes\_metadata pod uid matcher doesn't match poduid for rotated file on AKS](https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-pod-uid-matcher-doesnt-match-poduid-for-rotated-file-on-aks/298938)

<div class="topic-metadata">

**Author:** [@Jayw77](https://discuss.elastic.co/u/Jayw77)\
**Replies:** 5\
**Last updated:** [March 9, 2022, 10:51am UTC](https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-pod-uid-matcher-doesnt-match-poduid-for-rotated-file-on-aks/298938 "2022-03-09T10:51:55Z")

</div>

Hi, As the title suggests, I believe when using pod UID (/var/log/pod) with the below config which was fixed and backported into release v7.17.1, it still cannot get the metadata for the second file when rotated in AKS …

---

## [How to filebeat logs to elastic cloud](https://discuss.elastic.co/t/how-to-filebeat-logs-to-elastic-cloud/299098)

<div class="topic-metadata">

**Author:** [@sulfred](https://discuss.elastic.co/u/sulfred)\
**Replies:** 1\
**Last updated:** [March 9, 2022, 1:41am UTC](https://discuss.elastic.co/t/how-to-filebeat-logs-to-elastic-cloud/299098 "2022-03-09T01:41:54Z")

</div>

I am trying the Elastic Cloud. I want to send logs to the cloud with filebeat. I am keep receiving errors: pipeline/output.go:154 Failed to connect to backoff(elasticsearch(https://cloud-name-instance.aws.elastic-clou…

---

## [.management-beats index - can I delete it?](https://discuss.elastic.co/t/management-beats-index-can-i-delete-it/299147)

<div class="topic-metadata">

**Author:** [@lag](https://discuss.elastic.co/u/lag)\
**Replies:** 0\
**Last updated:** [March 8, 2022, 11:30pm UTC](https://discuss.elastic.co/t/management-beats-index-can-i-delete-it/299147 "2022-03-08T23:30:14Z")

</div>

We are preparing for Elastic 8.0 and one of the critical errors we have is .management-beats index that was created prior to 7.0. We are not using this functionality and since beats central management has been discontin…

---

## [Elastic agent enrolled but not sending any data](https://discuss.elastic.co/t/elastic-agent-enrolled-but-not-sending-any-data/298957)

<div class="topic-metadata">

**Author:** [@Youssef\_Kaak](https://discuss.elastic.co/u/Youssef_Kaak)\
**Replies:** 0\
**Last updated:** [March 7, 2022, 11:07am UTC](https://discuss.elastic.co/t/elastic-agent-enrolled-but-not-sending-any-data/298957 "2022-03-07T11:07:21Z")

</div>

Hey everyone, I have recently started to work ELK and my mission is to mainly deploy the stack and use it as a SIEM. I am using agents for data collection instead of Beats. I have enrolled one agent on a remote machine…

---

## [Updating existing Beats deployment from 7.11.1.0 to 7.16.3](https://discuss.elastic.co/t/updating-existing-beats-deployment-from-7-11-1-0-to-7-16-3/299136)

<div class="topic-metadata">

**Author:** [@iamfrakk](https://discuss.elastic.co/u/iamfrakk)\
**Replies:** 0\
**Last updated:** [March 8, 2022, 6:58pm UTC](https://discuss.elastic.co/t/updating-existing-beats-deployment-from-7-11-1-0-to-7-16-3/299136 "2022-03-08T18:58:35Z")

</div>

Hello, I am trying to push out the "Beats" agents into a Windows environment (Servers & Client systems) I will be using SCCM to perform this deployment, and I have found the PowerShell script that Elastic has provided, …

---

## [Filebeat output kafka (processors)](https://discuss.elastic.co/t/filebeat-output-kafka-processors/299071)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 4\
**Last updated:** [March 8, 2022, 5:13pm UTC](https://discuss.elastic.co/t/filebeat-output-kafka-processors/299071 "2022-03-08T17:13:30Z")

</div>

Hi, I have a problem i think in "processors" , I use the output kafka so i created a topic and i send it to logstash so when i run it i just get the message when i want see path,tags,input type.... here my filebeat con…

---

## [Error in beats elastic agent container: open /hostfs/sys/fs/cgroup/io.pressure: no such file or directory](https://discuss.elastic.co/t/error-in-beats-elastic-agent-container-open-hostfs-sys-fs-cgroup-io-pressure-no-such-file-or-directory/299115)

<div class="topic-metadata">

**Author:** [@Josh-a-e](https://discuss.elastic.co/u/Josh-a-e)\
**Replies:** 0\
**Last updated:** [March 8, 2022, 4:20pm UTC](https://discuss.elastic.co/t/error-in-beats-elastic-agent-container-open-hostfs-sys-fs-cgroup-io-pressure-no-such-file-or-directory/299115 "2022-03-08T16:20:35Z")

</div>

On running an elastic agent container (docker.elastic.co/beats/elastic-agent:8.0.1) as a daemon set (configuration here - https://raw.githubusercontent.com/elastic/beats/8.0/deploy/kubernetes/elastic-agent-managed-kubern…

---

## [Setup Fleet on Windows. I cannot get it to work at all](https://discuss.elastic.co/t/setup-fleet-on-windows-i-cannot-get-it-to-work-at-all/299095)

<div class="topic-metadata">

**Author:** [@Akon](https://discuss.elastic.co/u/Akon)\
**Replies:** 0\
**Last updated:** [March 8, 2022, 1:41pm UTC](https://discuss.elastic.co/t/setup-fleet-on-windows-i-cannot-get-it-to-work-at-all/299095 "2022-03-08T13:41:47Z")

</div>

Hello, I cant seem to get Elastic Fleet Server to run on Windows. I tried the official and this solution aswell. We have set up security with a certificate but every possible way does not seem to work. I used this co…

---

## [Heartbeat: Populate monitor.name from field value](https://discuss.elastic.co/t/heartbeat-populate-monitor-name-from-field-value/299010)

<div class="topic-metadata">

**Author:** [@Jeff\_Morton](https://discuss.elastic.co/u/Jeff_Morton)\
**Replies:** 2\
**Last updated:** [March 8, 2022, 2:26pm UTC](https://discuss.elastic.co/t/heartbeat-populate-monitor-name-from-field-value/299010 "2022-03-08T14:26:31Z")

</div>

Greetings, I'm trying to dynamically populate the heartbeat monitor name (monitor.name field) dynamically from a predefined kubernetes label. I've attempted using the copy\_field processor, but this doesn't appear to wo…

---

## [Dropping specific container labels from fields](https://discuss.elastic.co/t/dropping-specific-container-labels-from-fields/298309)

<div class="topic-metadata">

**Author:** [@Dario\_Louzado](https://discuss.elastic.co/u/Dario_Louzado)\
**Replies:** 2\
**Last updated:** [March 8, 2022, 12:47pm UTC](https://discuss.elastic.co/t/dropping-specific-container-labels-from-fields/298309 "2022-03-08T12:47:13Z")

</div>

Hello. I'm trying to clean-up my logging events as much as possible in order to save bandwidth and disk space in Elasticsearch. I want to delete specific labels and preserve others. Below is my full YAML file: name: …

---

## [Filebeat should omit timestamp in logs when ran via systemd](https://discuss.elastic.co/t/filebeat-should-omit-timestamp-in-logs-when-ran-via-systemd/299087)

<div class="topic-metadata">

**Author:** [@XANi](https://discuss.elastic.co/u/XANi)\
**Replies:** 0\
**Last updated:** [March 8, 2022, 12:20pm UTC](https://discuss.elastic.co/t/filebeat-should-omit-timestamp-in-logs-when-ran-via-systemd/299087 "2022-03-08T12:20:46Z")

</div>

Currently logs via systemd look like this: Mar 08 13:13:10 appserv1 filebeat\[22055\]: 2022-03-08T13:13:10.657+0100 INFO instance/beat.go:694 Beat ID: 70152ff2-5b2e-4c03-a60c-eedffb110c54 and the timestamp is doub…

---

## [Send custom data to Elastic](https://discuss.elastic.co/t/send-custom-data-to-elastic/299060)

<div class="topic-metadata">

**Author:** [@nfeliciano](https://discuss.elastic.co/u/nfeliciano)\
**Replies:** 0\
**Last updated:** [March 8, 2022, 9:31am UTC](https://discuss.elastic.co/t/send-custom-data-to-elastic/299060 "2022-03-08T09:31:41Z")

</div>

Hello, I've been using metricbeat to monitor machine standard values successfully, like cpu memory and io. I can plot the values on the Kibana dashboards. Now I also want to send application custom data. I can extract …

---

## [Functionbeat Cannot index event - security\_exception](https://discuss.elastic.co/t/functionbeat-cannot-index-event-security-exception/299016)

<div class="topic-metadata">

**Author:** [@carl0s](https://discuss.elastic.co/u/carl0s)\
**Replies:** 0\
**Last updated:** [March 7, 2022, 11:05pm UTC](https://discuss.elastic.co/t/functionbeat-cannot-index-event-security-exception/299016 "2022-03-07T23:05:40Z")

</div>

After upgrading to 7.17 none of my logs are being processed, lots of 403 errors: { "type": "security\_exception", "reason": "action \[indices:data/write/bulk\[s\]\] is unauthorized for API key id \[\<removed\>\] of user …

---

## [Issue with installing metric beat & collecting data](https://discuss.elastic.co/t/issue-with-installing-metric-beat-collecting-data/298855)

<div class="topic-metadata">

**Author:** [@Vinay\_Menon1](https://discuss.elastic.co/u/Vinay_Menon1)\
**Replies:** 4\
**Last updated:** [March 7, 2022, 9:08pm UTC](https://discuss.elastic.co/t/issue-with-installing-metric-beat-collecting-data/298855 "2022-03-07T21:08:07Z")

</div>

Hi, Please help I am trying to execute this PowerShell script in my windows system to get Metricbeat data to elastic but it does not work as intended , The script runs properly by downloading the metric beat file to c:\\…

---

## [Filebeat: MISP automation](https://discuss.elastic.co/t/filebeat-misp-automation/298963)

<div class="topic-metadata">

**Author:** [@filip.wozniak](https://discuss.elastic.co/u/filip.wozniak)\
**Replies:** 0\
**Last updated:** [March 7, 2022, 12:08pm UTC](https://discuss.elastic.co/t/filebeat-misp-automation/298963 "2022-03-07T12:08:03Z")

</div>

Greetings! Is there any way to make MISP module update deleted entries from MISP so they will be deleted also in Elasticsearch? Yours, Filip

---

## [Winlogbeat - Footprint as a shipper?](https://discuss.elastic.co/t/winlogbeat-footprint-as-a-shipper/298937)

<div class="topic-metadata">

**Author:** [@arunhk3](https://discuss.elastic.co/u/arunhk3)\
**Replies:** 0\
**Last updated:** [March 7, 2022, 7:41am UTC](https://discuss.elastic.co/t/winlogbeat-footprint-as-a-shipper/298937 "2022-03-07T07:41:17Z")

</div>

Hi All, I have a question where I would like to know the footprint (resource usage) when Winlogbeat is operating on a Windows Server when collecting and shipping logs. Also I would like to know as to what would happen …

---

## [Field Available in Discovery, but Not in Visualization](https://discuss.elastic.co/t/field-available-in-discovery-but-not-in-visualization/298903)

<div class="topic-metadata">

**Author:** [@cyberphor](https://discuss.elastic.co/u/cyberphor)\
**Replies:** 0\
**Last updated:** [March 6, 2022, 3:56am UTC](https://discuss.elastic.co/t/field-available-in-discovery-but-not-in-visualization/298903 "2022-03-06T03:56:39Z")

</div>

Hello, I'm running Elasticsearch, Kibana, and Winlogbeat (all of which are version 8.0.1) on a Windows 10 desktop. When I query for event.code:4104 using the "Discovery" tab, one of the available fields is powershell.f…

---

## [Filebeat checkpoint module not getting data from syslog](https://discuss.elastic.co/t/filebeat-checkpoint-module-not-getting-data-from-syslog/298864)

<div class="topic-metadata">

**Author:** [@mfloris](https://discuss.elastic.co/u/mfloris)\
**Replies:** 1\
**Last updated:** [March 4, 2022, 5:36pm UTC](https://discuss.elastic.co/t/filebeat-checkpoint-module-not-getting-data-from-syslog/298864 "2022-03-04T17:36:36Z")

</div>

I'm trying send CheckPoint Firewall logs to Elasticsearch 8.0. I have machine A 192.168.1.123 running Rsyslog receiving logs on port 514 that logs to a file and machine B 192.168.1.234 running Elasticsearch and Kibana. …

---

## [Metricbeat : Error fetching data for metricset elasticsearch](https://discuss.elastic.co/t/metricbeat-error-fetching-data-for-metricset-elasticsearch/298792)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 3\
**Last updated:** [March 4, 2022, 3:49pm UTC](https://discuss.elastic.co/t/metricbeat-error-fetching-data-for-metricset-elasticsearch/298792 "2022-03-04T15:49:08Z")

</div>

I have setup metricbeat in kubernetes with following deployment manifest DaemonSet--- apiVersion: v1 kind: ServiceAccount metadata: name: metricbeat namespace: kube-logging labels: app: metricbeat --- apiVe…

---

## ['Index' json 'message' field without Logstash but within Filebeat? Filebeat \> ES \> Kibana](https://discuss.elastic.co/t/index-json-message-field-without-logstash-but-within-filebeat-filebeat-es-kibana/298775)

<div class="topic-metadata">

**Author:** [@GB88](https://discuss.elastic.co/u/GB88)\
**Replies:** 1\
**Last updated:** [March 3, 2022, 11:21pm UTC](https://discuss.elastic.co/t/index-json-message-field-without-logstash-but-within-filebeat-filebeat-es-kibana/298775 "2022-03-03T23:21:38Z")

</div>

Hello, on to the next challange. I've setup Elasticsearch, Kibana and Filebeat. Filebeat is sending json files to ES\>Kibana. This part is working. Though, in Kibana the data is only in the 'Discover' menu. A few ques…

---

## [Winlogbeat issue with ca\_trusted\_fingerprint keystore](https://discuss.elastic.co/t/winlogbeat-issue-with-ca-trusted-fingerprint-keystore/298561)

<div class="topic-metadata">

**Author:** [@bcantrell](https://discuss.elastic.co/u/bcantrell)\
**Replies:** 1\
**Last updated:** [March 3, 2022, 9:39pm UTC](https://discuss.elastic.co/t/winlogbeat-issue-with-ca-trusted-fingerprint-keystore/298561 "2022-03-03T21:39:10Z")

</div>

Hello, I am new to setting up ELK stack, currently working in a lab environment to understand setup before moving to production. Everything is on 8.0. The problem I am having with Winlogbeat is that when I have a keys…

---

## [Winlogbeat](https://discuss.elastic.co/t/winlogbeat/296963)

<div class="topic-metadata">

**Author:** [@AnisBY](https://discuss.elastic.co/u/AnisBY)\
**Replies:** 1\
**Last updated:** [March 3, 2022, 9:23pm UTC](https://discuss.elastic.co/t/winlogbeat/296963 "2022-03-03T21:23:35Z")

</div>

Hi all, trying to find out what is the root cause of this error : // ERROR checkpoint/checkpoint.go:200 rename X:\\Directory\\winlogbeat\\data.winlogbeat.yml.new X:\\Directory\\winlogbeat\\data.winlogbeat.yml: Access is den…

---

## [Can't get Windows winlogbeat 8.0 to run- The system cannot find the path](https://discuss.elastic.co/t/cant-get-windows-winlogbeat-8-0-to-run-the-system-cannot-find-the-path/298670)

<div class="topic-metadata">

**Author:** [@eafrost.cissp](https://discuss.elastic.co/u/eafrost.cissp)\
**Replies:** 2\
**Last updated:** [March 3, 2022, 1:08pm UTC](https://discuss.elastic.co/t/cant-get-windows-winlogbeat-8-0-to-run-the-system-cannot-find-the-path/298670 "2022-03-03T13:08:48Z")

</div>

I upgraded my Elastic Stack on Windows from 7.17.0 to 8.0. I installed both metricbeat and winlogbeat 8.0 using the .msi files. Metricbeat runs fine. I cannot get winlogbeat to start. Winlogbeat fails because it cannot f…

---

## [Filebeat is down after start](https://discuss.elastic.co/t/filebeat-is-down-after-start/297390)

<div class="topic-metadata">

**Author:** [@ocervera](https://discuss.elastic.co/u/ocervera)\
**Replies:** 2\
**Last updated:** [March 3, 2022, 11:14am UTC](https://discuss.elastic.co/t/filebeat-is-down-after-start/297390 "2022-03-03T11:14:37Z")

</div>

Hello, I have installed in a Centos, Wazuh Manager+ Filebeat and the latter seems to work fine but after a while the filebeat.service suddenly stops working. systemctl status filebeat.service shows: × filebeat.service…

---

## [Metric Beat and Jolokia Module](https://discuss.elastic.co/t/metric-beat-and-jolokia-module/298724)

<div class="topic-metadata">

**Author:** [@deralch](https://discuss.elastic.co/u/deralch)\
**Replies:** 0\
**Last updated:** [March 3, 2022, 10:09am UTC](https://discuss.elastic.co/t/metric-beat-and-jolokia-module/298724 "2022-03-03T10:09:43Z")

</div>

Hey there, i'm trying to get following metrics out of the tomcat: My config: jmx.mappings: - mbean: 'Catalina:type=Manager,host=localhost,context=/guidemo' attributes: - attr: activeSessions …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=101)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=103)
