# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=103

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 104

---

## [The first connection to logstash is always an error](https://discuss.elastic.co/t/the-first-connection-to-logstash-is-always-an-error/296253)

<div class="topic-metadata">

**Author:** [@driveirk](https://discuss.elastic.co/u/driveirk)\
**Replies:** 7\
**Last updated:** [March 3, 2022, 8:18am UTC](https://discuss.elastic.co/t/the-first-connection-to-logstash-is-always-an-error/296253 "2022-03-03T08:18:51Z")

</div>

When running lambda, I always see "retry" first, and then immediately connect to backoff. How to make logs sent on first connection? Is there any way to enable more readable logs? config functionbeat functionbeat:…

---

## [Filebeat input number fields are recognized as text fields in elastic/kibana](https://discuss.elastic.co/t/filebeat-input-number-fields-are-recognized-as-text-fields-in-elastic-kibana/298717)

<div class="topic-metadata">

**Author:** [@Rick\_Barendse](https://discuss.elastic.co/u/Rick_Barendse)\
**Replies:** 0\
**Last updated:** [March 3, 2022, 9:20am UTC](https://discuss.elastic.co/t/filebeat-input-number-fields-are-recognized-as-text-fields-in-elastic-kibana/298717 "2022-03-03T09:20:28Z")

</div>

I am a newbee to elastic I am not able to solve ollowing issue: I try to load a json file with 2 number fields via filebeat in Elasticsearch. When looking into kibana discovery I see the fields with values but the valu…

---

## [How to configure server logs from different server using filebeat and send logs to logstash which installed on other server](https://discuss.elastic.co/t/how-to-configure-server-logs-from-different-server-using-filebeat-and-send-logs-to-logstash-which-installed-on-other-server/298394)

<div class="topic-metadata">

**Author:** [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Replies:** 1\
**Last updated:** [March 1, 2022, 9:42am UTC](https://discuss.elastic.co/t/how-to-configure-server-logs-from-different-server-using-filebeat-and-send-logs-to-logstash-which-installed-on-other-server/298394 "2022-03-01T09:42:36Z")

</div>

I am probably novice at ELK. I have question how can I configure send logs by filebeat from one server and logstash can collect and show in kibana this logs on other server. ELK installed on one server and filebeat insta…

---

## [About filebeat delay check](https://discuss.elastic.co/t/about-filebeat-delay-check/298688)

<div class="topic-metadata">

**Author:** [@bae\_park](https://discuss.elastic.co/u/bae_park)\
**Replies:** 0\
**Last updated:** [March 3, 2022, 1:36am UTC](https://discuss.elastic.co/t/about-filebeat-delay-check/298688 "2022-03-03T01:36:19Z")

</div>

I am using input as log and output as kafka in filebeat.yml Is the part that is not published in the inflog taken every 30 seconds a delay? If the delay is correct, can you tell how much delay is there? 2022-03-02T17:…

---

## [Netflow - Qos Channels](https://discuss.elastic.co/t/netflow-qos-channels/298681)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [March 2, 2022, 10:45pm UTC](https://discuss.elastic.co/t/netflow-qos-channels/298681 "2022-03-02T22:45:38Z")

</div>

Hi, I want to know if the filebeat module Netflow, has monitor of channels Qos?? Regards,

---

## [Can't seem to use socket dataset on rocky linux](https://discuss.elastic.co/t/cant-seem-to-use-socket-dataset-on-rocky-linux/298102)

<div class="topic-metadata">

**Author:** [@jhbigler](https://discuss.elastic.co/u/jhbigler)\
**Replies:** 7\
**Last updated:** [March 2, 2022, 9:00pm UTC](https://discuss.elastic.co/t/cant-seem-to-use-socket-dataset-on-rocky-linux/298102 "2022-03-02T21:00:08Z")

</div>

Auditbeat version: 7.15.2 Operating system: Rocky Linux (4.18.0-348.12.2.el8\_5.x86\_64) My issue is similar to the one discussed here, but the fixes that were put in 7.10 do not work here. Commenting out the socket data…

---

## [Issues with NXLog log rotation and Filebeat](https://discuss.elastic.co/t/issues-with-nxlog-log-rotation-and-filebeat/297952)

<div class="topic-metadata">

**Author:** [@ganesh\_tarone](https://discuss.elastic.co/u/ganesh_tarone)\
**Replies:** 3\
**Last updated:** [March 2, 2022, 5:14pm UTC](https://discuss.elastic.co/t/issues-with-nxlog-log-rotation-and-filebeat/297952 "2022-03-02T17:14:03Z")

</div>

I am using NXLog to output some events to a .json file. Basically, I'm using nxlog filecycle() method (find more here) to rotate log files. But the way nxlog does it is as below, (For weekly retention as an example) F…

---

## [Filebeat for rotated logs: the old harvest always is handled before new harvest?](https://discuss.elastic.co/t/filebeat-for-rotated-logs-the-old-harvest-always-is-handled-before-new-harvest/298613)

<div class="topic-metadata">

**Author:** [@newtofilebeat](https://discuss.elastic.co/u/newtofilebeat)\
**Replies:** 0\
**Last updated:** [March 2, 2022, 11:41am UTC](https://discuss.elastic.co/t/filebeat-for-rotated-logs-the-old-harvest-always-is-handled-before-new-harvest/298613 "2022-03-02T11:41:43Z")

</div>

we need use filebeat to collect our application logs but the logs will rotated weekly. The log file is updated every 5 minutes My question is: when a.log is rotated to a.log.1 and new file a.log is created, a.log.1 wil…

---

## [Metricbeat produces CPU usage spikes every 10 seconds across different releases](https://discuss.elastic.co/t/metricbeat-produces-cpu-usage-spikes-every-10-seconds-across-different-releases/298592)

<div class="topic-metadata">

**Author:** [@shmelkin](https://discuss.elastic.co/u/shmelkin)\
**Replies:** 0\
**Last updated:** [March 2, 2022, 8:35am UTC](https://discuss.elastic.co/t/metricbeat-produces-cpu-usage-spikes-every-10-seconds-across-different-releases/298592 "2022-03-02T08:35:18Z")

</div>

Hello Elastic, I've seen different types of topics in this board that certain releases of metricbeat had memory leaks and other issues. Currently, I'm preparing some evaluations for a research project that also involve…

---

## [Filebeat Index Name Pattern - timestamp](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255)

<div class="topic-metadata">

**Author:** [@danielc](https://discuss.elastic.co/u/danielc)\
**Replies:** 7\
**Last updated:** [March 2, 2022, 12:11am UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255 "2022-03-02T00:11:29Z")

</div>

Is %{+yyyy.MM.dd} the system time or log file timestamp? Configure the Elasticsearch output | Filebeat Reference \[7.10\] | Elastic output.elasticsearch: hosts: \["http://localhost:9200"\] index: "%{\[fields.log\_type\]}…

---

## [Running Elastic Standalong](https://discuss.elastic.co/t/running-elastic-standalong/298567)

<div class="topic-metadata">

**Author:** [@mwoods269](https://discuss.elastic.co/u/mwoods269)\
**Replies:** 2\
**Last updated:** [March 1, 2022, 11:48pm UTC](https://discuss.elastic.co/t/running-elastic-standalong/298567 "2022-03-01T23:48:32Z")

</div>

Hello, In the process of getting our production cluster configured with a Fleet manager instance but not quite there yet. I am curious what the best approach is if I were to run the elastic agent in stand alone? I am s…

---

## [Elastic Agent Standalone Configuration Validation](https://discuss.elastic.co/t/elastic-agent-standalone-configuration-validation/298562)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [March 1, 2022, 8:49pm UTC](https://discuss.elastic.co/t/elastic-agent-standalone-configuration-validation/298562 "2022-03-01T20:49:26Z")

</div>

Hi All, I was wondering if there is a way with the Elastic Agent in standalone mode to validate a configuration? Looking at the output of the Elastic Agent process: elastic-agent help Usage: elastic-agent \[subcomm…

---

## [X509: certificate signed by unknown authority](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/298551)

<div class="topic-metadata">

**Author:** [@sath](https://discuss.elastic.co/u/sath)\
**Replies:** 0\
**Last updated:** [March 1, 2022, 7:24pm UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/298551 "2022-03-01T19:24:09Z")

</div>

Hello, I'm running Elasticsearch 8 and am trying to output files on a Windows machine to Logstash. Now in preparation, I'm trying to get the index setup by running the following: .\\filebeat.exe setup --index-managemen…

---

## [Solr metricbeat module?](https://discuss.elastic.co/t/solr-metricbeat-module/298547)

<div class="topic-metadata">

**Author:** [@MyrdhinBZH](https://discuss.elastic.co/u/MyrdhinBZH)\
**Replies:** 0\
**Last updated:** [March 1, 2022, 6:36pm UTC](https://discuss.elastic.co/t/solr-metricbeat-module/298547 "2022-03-01T18:36:14Z")

</div>

Hello, I would like to monitor my solr servers with my ELK stack but I did not find Solr beat module... has Anyone ever retrieved metrics from solr instances to ELK? Thanks,

---

## [Drop\_event not working via process name or path](https://discuss.elastic.co/t/drop-event-not-working-via-process-name-or-path/298300)

<div class="topic-metadata">

**Author:** [@Josh\_G](https://discuss.elastic.co/u/Josh_G)\
**Replies:** 2\
**Last updated:** [March 1, 2022, 5:31pm UTC](https://discuss.elastic.co/t/drop-event-not-working-via-process-name-or-path/298300 "2022-03-01T17:31:32Z")

</div>

Hi, I'm using the processer in the System integration on Elastic Agent to try and reduce the ingest as we get a lot of noise. I've been doing some testing as I'd like to filter out an event code if the process name is …

---

## [Fleet Server 8.0 w/Docker Compose](https://discuss.elastic.co/t/fleet-server-8-0-w-docker-compose/298077)

<div class="topic-metadata">

**Author:** [@variable](https://discuss.elastic.co/u/variable)\
**Replies:** 0\
**Last updated:** [February 23, 2022, 7:38pm UTC](https://discuss.elastic.co/t/fleet-server-8-0-w-docker-compose/298077 "2022-02-23T19:38:13Z")

</div>

Pre 8.0, you could set an Elastic Agent container as a Fleet Server with Docker environment variables: docker run ... -e "KIBANA\_FLEET\_SETUP=1" \\ -e "FLEET\_ENROLL=1" \\ -e "FLEET\_SERVER\_INSECURE\_HTTP=1" \\ …

---

## [About AWS S3 Input](https://discuss.elastic.co/t/about-aws-s3-input/297922)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 5\
**Last updated:** [March 1, 2022, 4:02pm UTC](https://discuss.elastic.co/t/about-aws-s3-input/297922 "2022-03-01T16:02:33Z")

</div>

Hi, We're considering changes to the structure of our ingestion pipelines. One of those is to have dockerized services write their logs to s3 and then have filebeat read them back before forwarding. Given that we have …

---

## [Fleet managed Elastic Agent - Wrong ES output configuration for Filebeat/Metricbeat](https://discuss.elastic.co/t/fleet-managed-elastic-agent-wrong-es-output-configuration-for-filebeat-metricbeat/297925)

<div class="topic-metadata">

**Author:** [@fuphil](https://discuss.elastic.co/u/fuphil)\
**Replies:** 1\
**Last updated:** [March 1, 2022, 3:03pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-wrong-es-output-configuration-for-filebeat-metricbeat/297925 "2022-03-01T15:03:33Z")

</div>

Hi! I successfully set up a fleet server and 2 more elastic agents on different hosts. They all show up as "healthy" and seem fine in Kibana. I recognized after trying a few integrations, that only the Fleet server i…

---

## [Username in auditbeat file\_integrity module](https://discuss.elastic.co/t/username-in-auditbeat-file-integrity-module/298530)

<div class="topic-metadata">

**Author:** [@sadux](https://discuss.elastic.co/u/sadux)\
**Replies:** 0\
**Last updated:** [March 1, 2022, 2:56pm UTC](https://discuss.elastic.co/t/username-in-auditbeat-file-integrity-module/298530 "2022-03-01T14:56:32Z")

</div>

Hello! We track file creation/deletion/change in Kibana with auditbeat file\_integrity module. Is there a way to see information about user, who create/change/delete file?

---

## [Metricbeat docker compose environment variables](https://discuss.elastic.co/t/metricbeat-docker-compose-environment-variables/298009)

<div class="topic-metadata">

**Author:** [@TobiasSackmann](https://discuss.elastic.co/u/TobiasSackmann)\
**Replies:** 2\
**Last updated:** [March 1, 2022, 2:52pm UTC](https://discuss.elastic.co/t/metricbeat-docker-compose-environment-variables/298009 "2022-03-01T14:52:52Z")

</div>

Hi all, I am trying to set up stack monitoring using docker via docker compose. Here is a sample I found on the Internet that uses the ELASTICSEARCH\_HOSTS variable. I'd like to define more in this section like the modu…

---

## [Elastic 8.0.0 - Stack Monitoring - All nodes are listed as Master Nodes](https://discuss.elastic.co/t/elastic-8-0-0-stack-monitoring-all-nodes-are-listed-as-master-nodes/298260)

<div class="topic-metadata">

**Author:** [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)\
**Replies:** 6\
**Last updated:** [March 1, 2022, 1:52pm UTC](https://discuss.elastic.co/t/elastic-8-0-0-stack-monitoring-all-nodes-are-listed-as-master-nodes/298260 "2022-03-01T13:52:26Z")

</div>

I just set Stack Monitoring with Metricbeat for an Elasticsearch 8.0 cluster and I noticed a weird thing: all nodes are reported as Master Nodes (see the star icon in the screenshot below). Any idea what I did wrong?

---

## [Unable to install Fleet Server](https://discuss.elastic.co/t/unable-to-install-fleet-server/298516)

<div class="topic-metadata">

**Author:** [@Adrian\_Palka](https://discuss.elastic.co/u/Adrian_Palka)\
**Replies:** 0\
**Last updated:** [March 1, 2022, 1:39pm UTC](https://discuss.elastic.co/t/unable-to-install-fleet-server/298516 "2022-03-01T13:39:15Z")

</div>

Hi, I've got a problem with installing fleet server. Fleet server enrolls with no errors, but kibana it's stuck in "updating" state. I was trying to install it with my own ssl (in pem format), with quick start (insecur…

---

## [Unable to use of beats (here journalbeat) with AWS ElasticSearch 7.x](https://discuss.elastic.co/t/unable-to-use-of-beats-here-journalbeat-with-aws-elasticsearch-7-x/298506)

<div class="topic-metadata">

**Author:** [@obourdon](https://discuss.elastic.co/u/obourdon)\
**Replies:** 1\
**Last updated:** [March 1, 2022, 12:24pm UTC](https://discuss.elastic.co/t/unable-to-use-of-beats-here-journalbeat-with-aws-elasticsearch-7-x/298506 "2022-03-01T12:24:11Z")

</div>

As detailed in https://github.com/elastic/beats/issues/30192 I used to have a perfectly working AWS ES 6.8 + journalbeat OSS 7.12.1 setup I also know about the breaking change of beats 7.13.0 which prevented me from up…

---

## [Error during make update while creating custom filebeat module](https://discuss.elastic.co/t/error-during-make-update-while-creating-custom-filebeat-module/298407)

<div class="topic-metadata">

**Author:** [@kkouramenos](https://discuss.elastic.co/u/kkouramenos)\
**Replies:** 3\
**Last updated:** [March 1, 2022, 10:31am UTC](https://discuss.elastic.co/t/error-during-make-update-while-creating-custom-filebeat-module/298407 "2022-03-01T10:31:55Z")

</div>

Trying to create a custom module for filebeat. I passed successfully the make create-module, make create-fileset, create and test the pipeline, make create-fields. When running make update I get the following mage upda…

---

## [Can you use copy\_fields processor for @timestamp in winlogbeat](https://discuss.elastic.co/t/can-you-use-copy-fields-processor-for-timestamp-in-winlogbeat/239501)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 0\
**Last updated:** [July 1, 2020, 2:12pm UTC](https://discuss.elastic.co/t/can-you-use-copy-fields-processor-for-timestamp-in-winlogbeat/239501 "2020-07-01T14:12:49Z")

</div>

Hi guys, Does anyone know if there is a way to copy the @timestamp value from winlogbeat json to a separate field (for troubleshooting purposes) using winlogbeat.yml file? I'm trying to use the copy fields processor: …

---

## [Collecting logs with rsyslog instead of beats](https://discuss.elastic.co/t/collecting-logs-with-rsyslog-instead-of-beats/298425)

<div class="topic-metadata">

**Author:** [@Khammassi\_HoussemEdd](https://discuss.elastic.co/u/Khammassi_HoussemEdd)\
**Replies:** 0\
**Last updated:** [February 28, 2022, 3:54pm UTC](https://discuss.elastic.co/t/collecting-logs-with-rsyslog-instead-of-beats/298425 "2022-02-28T15:54:45Z")

</div>

i got used to use beats (especially filebeat ) to collect logs from linux machines and send them to logstash where i do parsing and filtering .. there is a while since i have heard about rsyslog and i tried it and it's…

---

## [Heartbeat HTTP pings fails with 403](https://discuss.elastic.co/t/heartbeat-http-pings-fails-with-403/298289)

<div class="topic-metadata">

**Author:** [@venkat\_swaminathan](https://discuss.elastic.co/u/venkat_swaminathan)\
**Replies:** 1\
**Last updated:** [February 28, 2022, 4:32pm UTC](https://discuss.elastic.co/t/heartbeat-http-pings-fails-with-403/298289 "2022-02-28T16:32:05Z")

</div>

Hi Team, Strange heartbeat is failing with 403 response but we are getting valid 200 responses via CURL & Browser . Below is the configuration used for setting up the heartbeat any advice here will be helpful. I have …

---

## [Adding site error logs to elastic stack](https://discuss.elastic.co/t/adding-site-error-logs-to-elastic-stack/298363)

<div class="topic-metadata">

**Author:** [@Shorthills](https://discuss.elastic.co/u/Shorthills)\
**Replies:** 4\
**Last updated:** [February 28, 2022, 4:07pm UTC](https://discuss.elastic.co/t/adding-site-error-logs-to-elastic-stack/298363 "2022-02-28T16:07:02Z")

</div>

Hi, New user here. My installation is properly pulling error logs from: /var/log/nginx/error.log\* But how do I make it so it also pulls the individual error log data from the sites as in this pattern: /var/log/nginx…

---

## [Impossible to overwrite "host.ip" when using Custom Logs integration](https://discuss.elastic.co/t/impossible-to-overwrite-host-ip-when-using-custom-logs-integration/298348)

<div class="topic-metadata">

**Author:** [@Twyzz](https://discuss.elastic.co/u/Twyzz)\
**Replies:** 4\
**Last updated:** [February 28, 2022, 3:25pm UTC](https://discuss.elastic.co/t/impossible-to-overwrite-host-ip-when-using-custom-logs-integration/298348 "2022-02-28T15:25:01Z")

</div>

Hi, I'm trying to get the correct IP for the host.ip property in my logs documents, to be able to utilize all the built in links in kibana but unfortunately I cannot get it to work. The setup is quite easy. I'm running…

---

## [Fleet agent - Kubernetes Dashboard](https://discuss.elastic.co/t/fleet-agent-kubernetes-dashboard/298282)

<div class="topic-metadata">

**Author:** [@gabrielfsousa](https://discuss.elastic.co/u/gabrielfsousa)\
**Replies:** 1\
**Last updated:** [February 28, 2022, 3:03pm UTC](https://discuss.elastic.co/t/fleet-agent-kubernetes-dashboard/298282 "2022-02-28T15:03:51Z")

</div>

i dont have any dashboard, how i add it ?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=102)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=104)
