# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=104

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 105

---

## [Secret in Azure module Metricbeat](https://discuss.elastic.co/t/secret-in-azure-module-metricbeat/298412)

<div class="topic-metadata">

**Author:** [@legos765](https://discuss.elastic.co/u/legos765)\
**Replies:** 0\
**Last updated:** [February 28, 2022, 2:34pm UTC](https://discuss.elastic.co/t/secret-in-azure-module-metricbeat/298412 "2022-02-28T14:34:14Z")

</div>

Hello, I'm trying to implement Azure module in Metricbeat version 7.17. And im getting error when it is connecting to Azure: Refresh request failed. Status Code = '401'. Response body: {"error":"invalid\_client","error\_…

---

## [Filebeat w/ Iptables Module to Logstash to Elastic: Expected Fields Not Populated](https://discuss.elastic.co/t/filebeat-w-iptables-module-to-logstash-to-elastic-expected-fields-not-populated/295720)

<div class="topic-metadata">

**Author:** [@Jarbird](https://discuss.elastic.co/u/Jarbird)\
**Replies:** 4\
**Last updated:** [February 28, 2022, 11:49am UTC](https://discuss.elastic.co/t/filebeat-w-iptables-module-to-logstash-to-elastic-expected-fields-not-populated/295720 "2022-02-28T11:49:32Z")

</div>

Hello: I'm pretty new at the ecosystem. I've learned a lot in the past few weeks however I think I've hit a roadblock where I can't seem to figure out why log lines are not being broken out into the expected fields and t…

---

## [Function: cloudwatch, could not deploy, error: bucket 'functionbeat-deploy' already exist and you don't have permission to access it](https://discuss.elastic.co/t/function-cloudwatch-could-not-deploy-error-bucket-functionbeat-deploy-already-exist-and-you-dont-have-permission-to-access-it/293455)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 5\
**Last updated:** [February 28, 2022, 9:10am UTC](https://discuss.elastic.co/t/function-cloudwatch-could-not-deploy-error-bucket-functionbeat-deploy-already-exist-and-you-dont-have-permission-to-access-it/293455 "2022-02-28T09:10:26Z")

</div>

I had version 7.12 deployed of functionbeat, i removed it successfully using ./functionbeat -v -e -d "\*" remove cloudwatch I then configurd version 7.16 version of functionbeat and i am trying to deploy it but i get the…

---

## [Should I prefer beats or Elastic Agent for monitoring application deployed using docker stack and not kubernetes?](https://discuss.elastic.co/t/should-i-prefer-beats-or-elastic-agent-for-monitoring-application-deployed-using-docker-stack-and-not-kubernetes/298079)

<div class="topic-metadata">

**Author:** [@Mahesh\_Abnave](https://discuss.elastic.co/u/Mahesh_Abnave)\
**Replies:** 1\
**Last updated:** [February 28, 2022, 9:07am UTC](https://discuss.elastic.co/t/should-i-prefer-beats-or-elastic-agent-for-monitoring-application-deployed-using-docker-stack-and-not-kubernetes/298079 "2022-02-28T09:07:08Z")

</div>

I have an application up and running in set of docker containers (deployed using docker stack and not kubernetes). I want to do performance monitoring for this application. I am confused about whether I should go for bea…

---

## [DEPRECATED: CommonName field on X.509 certificates](https://discuss.elastic.co/t/deprecated-commonname-field-on-x-509-certificates/298310)

<div class="topic-metadata">

**Author:** [@ariverol](https://discuss.elastic.co/u/ariverol)\
**Replies:** 1\
**Last updated:** [February 27, 2022, 6:38am UTC](https://discuss.elastic.co/t/deprecated-commonname-field-on-x-509-certificates/298310 "2022-02-27T06:38:00Z")

</div>

Hi, I'm having a problem receiving data from a 7.17.0 filebeat to Logstash. If I run filebeat -e test config I see a warning lscommon/config.go:100 DEPRECATED: Treating the CommonName field on X.509 certificates as a h…

---

## [How to set up each pipeline for each index in filebeats?](https://discuss.elastic.co/t/how-to-set-up-each-pipeline-for-each-index-in-filebeats/298319)

<div class="topic-metadata">

**Author:** [@chenx319](https://discuss.elastic.co/u/chenx319)\
**Replies:** 1\
**Last updated:** [February 26, 2022, 3:38am UTC](https://discuss.elastic.co/t/how-to-set-up-each-pipeline-for-each-index-in-filebeats/298319 "2022-02-26T03:38:25Z")

</div>

I use one filebeats, to ship two log 1 hightec.log 2 ghslog.log they are different format , I want to set up different pipeline for the each log , can you tell me how to config it ? Thanks! - type : log enable…

---

## [Timestamp timezone](https://discuss.elastic.co/t/timestamp-timezone/297893)

<div class="topic-metadata">

**Author:** [@ziv1](https://discuss.elastic.co/u/ziv1)\
**Replies:** 9\
**Last updated:** [February 25, 2022, 2:09pm UTC](https://discuss.elastic.co/t/timestamp-timezone/297893 "2022-02-25T14:09:48Z")

</div>

That there is problem. Maybe if you only work on one timezone, or on each timezone separately, it's not a problem, but, for us that work in various timezones and pull data form them to a central location, this means w…

---

## [Filebeat keep getting error : ERROR pipeline/output.go:121 Failed to publish events: temporary bulk send failure and needed restart](https://discuss.elastic.co/t/filebeat-keep-getting-error-error-pipeline-output-go-121-failed-to-publish-events-temporary-bulk-send-failure-and-needed-restart/296823)

<div class="topic-metadata">

**Author:** [@roy3861](https://discuss.elastic.co/u/roy3861)\
**Replies:** 2\
**Last updated:** [February 25, 2022, 1:51pm UTC](https://discuss.elastic.co/t/filebeat-keep-getting-error-error-pipeline-output-go-121-failed-to-publish-events-temporary-bulk-send-failure-and-needed-restart/296823 "2022-02-25T13:51:50Z")

</div>

Hi, We are sending cassandra logs to ES via filebeat and after each few days it stop sending entries to ES with following Error is visible in filebeat logs: 2022-02-09T16:04:08.762Z INFO pipeline/output.go:10…

---

## [Fleet agent - x509: certificate signed by unknown authority](https://discuss.elastic.co/t/fleet-agent-x509-certificate-signed-by-unknown-authority/298157)

<div class="topic-metadata">

**Author:** [@gabrielfsousa](https://discuss.elastic.co/u/gabrielfsousa)\
**Replies:** 1\
**Last updated:** [February 25, 2022, 12:35pm UTC](https://discuss.elastic.co/t/fleet-agent-x509-certificate-signed-by-unknown-authority/298157 "2022-02-25T12:35:39Z")

</div>

I have one fleet server, and 3 elastic agents in a K8S cluster. server: --env FLEET\_ENROLL=1\\ --env FLEET\_SERVER\_ENABLE=1\\ --env FLEET\_SERVER\_ELASTICSEARCH\_HOST=$(ELASTICSEARCHHOST)\\ --env FLEET\_SERVER\_SERVICE\_TOKEN=$(…

---

## [FileBeat doesn't understand FQDN](https://discuss.elastic.co/t/filebeat-doesnt-understand-fqdn/298261)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 0\
**Last updated:** [February 25, 2022, 10:03am UTC](https://discuss.elastic.co/t/filebeat-doesnt-understand-fqdn/298261 "2022-02-25T10:03:25Z")

</div>

There seems to be a bug in FileBeat under Windows where Filebeat ignores the domain and assumes it can try contact Kafka with just a hostname. This fails when the filebeat is running in a different domain and the host is…

---

## [Multiline usage](https://discuss.elastic.co/t/multiline-usage/297991)

<div class="topic-metadata">

**Author:** [@Panplumousse](https://discuss.elastic.co/u/Panplumousse)\
**Replies:** 2\
**Last updated:** [February 25, 2022, 9:28am UTC](https://discuss.elastic.co/t/multiline-usage/297991 "2022-02-25T09:28:58Z")

</div>

Hello, I'm new here so first off, hello everyone. Here is my problem. I am using filebeat multiline with java logs Here is my config config: - type: container paths: …

---

## [Kibana failed to query logs. Procedure](https://discuss.elastic.co/t/kibana-failed-to-query-logs-procedure/298254)

<div class="topic-metadata">

**Author:** [@linuxxin](https://discuss.elastic.co/u/linuxxin)\
**Replies:** 0\
**Last updated:** [February 25, 2022, 8:39am UTC](https://discuss.elastic.co/t/kibana-failed-to-query-logs-procedure/298254 "2022-02-25T08:39:46Z")

</div>

Search Error Bad Request appears when Kibana queries the index I built my own index

---

## [Metric Beat - Best Practices](https://discuss.elastic.co/t/metric-beat-best-practices/298247)

<div class="topic-metadata">

**Author:** [@iamnaveenkumart](https://discuss.elastic.co/u/iamnaveenkumart)\
**Replies:** 0\
**Last updated:** [February 25, 2022, 7:18am UTC](https://discuss.elastic.co/t/metric-beat-best-practices/298247 "2022-02-25T07:18:09Z")

</div>

HI All, We are in progress of setting up Beat for all our service and server. Can you please share some link or documentation for Best Practices which need follow will configure an beat like period, refresh\_list\_interva…

---

## [Filebeat ingest](https://discuss.elastic.co/t/filebeat-ingest/298242)

<div class="topic-metadata">

**Author:** [@Anwar](https://discuss.elastic.co/u/Anwar)\
**Replies:** 0\
**Last updated:** [February 25, 2022, 5:02am UTC](https://discuss.elastic.co/t/filebeat-ingest/298242 "2022-02-25T05:02:32Z")

</div>

Hi Team, I want to use the below ingest directly in the Filebeat.yml file. I have made changes for few processor. need to know -\> how to use grok, Geoip, user-agent and scripts. Please help me on the same. Because,…

---

## [Barracuda WAF log input format](https://discuss.elastic.co/t/barracuda-waf-log-input-format/298214)

<div class="topic-metadata">

**Author:** [@JGreene](https://discuss.elastic.co/u/JGreene)\
**Replies:** 0\
**Last updated:** [February 24, 2022, 8:07pm UTC](https://discuss.elastic.co/t/barracuda-waf-log-input-format/298214 "2022-02-24T20:07:09Z")

</div>

Continuing the discussion from Barracuda WAF Log Parsing: We are seeking guidance on how to configure the Barracuda WAF logs to output to Filebeat in a format that is accepted by the provided following scripts in the mo…

---

## [Filebeat after v7.12 does not show dependency information](https://discuss.elastic.co/t/filebeat-after-v7-12-does-not-show-dependency-information/298012)

<div class="topic-metadata">

**Author:** [@bharathrajask](https://discuss.elastic.co/u/bharathrajask)\
**Replies:** 1\
**Last updated:** [February 24, 2022, 5:56pm UTC](https://discuss.elastic.co/t/filebeat-after-v7-12-does-not-show-dependency-information/298012 "2022-02-24T17:56:46Z")

</div>

Hi Team, We are using the filebeat 3pp in our project. We use few scanning tools like (trivy, anchore) to detect the vulnerabilities in the filebeat project. Till v7.12, we were able to detect the vulnerabilities. But a…

---

## [Filebeat to Analyse Old Apache Logs](https://discuss.elastic.co/t/filebeat-to-analyse-old-apache-logs/297894)

<div class="topic-metadata">

**Author:** [@inf](https://discuss.elastic.co/u/inf)\
**Replies:** 1\
**Last updated:** [February 24, 2022, 4:30pm UTC](https://discuss.elastic.co/t/filebeat-to-analyse-old-apache-logs/297894 "2022-02-24T16:30:24Z")

</div>

Hi there, I have a set of old Apache logs that I have in an existing Elastic Stack, where it was piped in to the Elasticsearch node using Filebeat with no modules enabled. I would like to analyse this set of old Apache…

---

## [Filebeat is not recognized on kibana](https://discuss.elastic.co/t/filebeat-is-not-recognized-on-kibana/296484)

<div class="topic-metadata">

**Author:** [@sulfred](https://discuss.elastic.co/u/sulfred)\
**Replies:** 0\
**Last updated:** [February 7, 2022, 2:47pm UTC](https://discuss.elastic.co/t/filebeat-is-not-recognized-on-kibana/296484 "2022-02-07T14:47:08Z")

</div>

I am running my elk stack through docker containers. The Elasticsearch and kibana are running normally. I have a filebeat receiving syslog and netflow on 2 different port. The problem is that the connection is refused wh…

---

## [Event risk score (Filebeat Checkpoint)](https://discuss.elastic.co/t/event-risk-score-filebeat-checkpoint/296576)

<div class="topic-metadata">

**Author:** [@elasticfran](https://discuss.elastic.co/u/elasticfran)\
**Replies:** 0\
**Last updated:** [February 8, 2022, 10:40am UTC](https://discuss.elastic.co/t/event-risk-score-filebeat-checkpoint/296576 "2022-02-08T10:40:51Z")

</div>

Hey there, I am wondering how the risk score works in the filebeat checkpoint index. I see a risk score spanning from 0 to 5, does anyone know how this index was designed ? I guess 5 is critical and 0 is kind of "beni…

---

## [Windows Security Logs Winlogbeat](https://discuss.elastic.co/t/windows-security-logs-winlogbeat/297387)

<div class="topic-metadata">

**Author:** [@Nicat\_A](https://discuss.elastic.co/u/Nicat_A)\
**Replies:** 2\
**Last updated:** [February 23, 2022, 1:36pm UTC](https://discuss.elastic.co/t/windows-security-logs-winlogbeat/297387 "2022-02-23T13:36:15Z")

</div>

I am using winlogbeat to send windows logs but i can\`t see security logst except 4624 what can i do?

---

## [Filebeat 7.10 aws cloudtrail is not parsing the output as shown in documentation](https://discuss.elastic.co/t/filebeat-7-10-aws-cloudtrail-is-not-parsing-the-output-as-shown-in-documentation/298111)

<div class="topic-metadata">

**Author:** [@Anwar](https://discuss.elastic.co/u/Anwar)\
**Replies:** 1\
**Last updated:** [February 24, 2022, 5:21am UTC](https://discuss.elastic.co/t/filebeat-7-10-aws-cloudtrail-is-not-parsing-the-output-as-shown-in-documentation/298111 "2022-02-24T05:21:19Z")

</div>

Hi, I have configured aws clodutrail module using filebeat to push the logs to Elasticsearch. Logs are pushed to the elk. But am facing two issues. Messages are showing in string instead of json If i used processor an…

---

## [Metricbeat Custom Module Registration issue](https://discuss.elastic.co/t/metricbeat-custom-module-registration-issue/298101)

<div class="topic-metadata">

**Author:** [@tweet2santosh86](https://discuss.elastic.co/u/tweet2santosh86)\
**Replies:** 0\
**Last updated:** [February 24, 2022, 1:02am UTC](https://discuss.elastic.co/t/metricbeat-custom-module-registration-issue/298101 "2022-02-24T01:02:55Z")

</div>

Hello Team, We are trying to create custom metricbeat module by following the link Creating a Metricset | Beats Developer Guide \[master\] | Elastic.. but it seems the new module is not getting registered. We are not get…

---

## [Get output value of powershell script](https://discuss.elastic.co/t/get-output-value-of-powershell-script/297768)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 4\
**Last updated:** [February 23, 2022, 5:02pm UTC](https://discuss.elastic.co/t/get-output-value-of-powershell-script/297768 "2022-02-23T17:02:38Z")

</div>

Hi, In winlogbeat, I'm able to get the body of PowerShell script that is executed on device using: powershell.file.script\_block\_text: But is there a way to get the 'stdout' or return / output of the script? Regrdas,

---

## [Run Elastic Agent and Auditbeat](https://discuss.elastic.co/t/run-elastic-agent-and-auditbeat/298061)

<div class="topic-metadata">

**Author:** [@lethalMango](https://discuss.elastic.co/u/lethalMango)\
**Replies:** 1\
**Last updated:** [February 23, 2022, 4:40pm UTC](https://discuss.elastic.co/t/run-elastic-agent-and-auditbeat/298061 "2022-02-23T16:40:08Z")

</div>

I am upgrading our environment to use Elastic Agent. Currently we use Auditbeat, Winglogbeat and Filebeat. From what I can see Winlog and Filebeat are implemented, Auditbeat (specifically around file integrity monitori…

---

## [Packetbeat Logstash and Elastic cloud](https://discuss.elastic.co/t/packetbeat-logstash-and-elastic-cloud/298034)

<div class="topic-metadata">

**Author:** [@kasuma](https://discuss.elastic.co/u/kasuma)\
**Replies:** 4\
**Last updated:** [February 23, 2022, 3:42pm UTC](https://discuss.elastic.co/t/packetbeat-logstash-and-elastic-cloud/298034 "2022-02-23T15:42:03Z")

</div>

Hello, I have a problem were my dashboard showing an "error" message when data are loaded from logstash, but if i load data directly from packetbeat to elastic cloud everything is working This is my setup: packetbeat.…

---

## [Filebeat not sending data to Elasticsearch, index\_not\_found\_exception](https://discuss.elastic.co/t/filebeat-not-sending-data-to-elasticsearch-index-not-found-exception/298047)

<div class="topic-metadata">

**Author:** [@nspeaks](https://discuss.elastic.co/u/nspeaks)\
**Replies:** 1\
**Last updated:** [February 23, 2022, 3:03pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-data-to-elasticsearch-index-not-found-exception/298047 "2022-02-23T15:03:45Z")

</div>

I am using this guide: How To Build A Security Information and Event Management (SIEM) System with Suricata and the Elastic Stack on Rocky Linux 8 | DigitalOcean to install Suricata along with ELK stack on a Rocky Linux…

---

## [Filebeat httpjson input](https://discuss.elastic.co/t/filebeat-httpjson-input/297730)

<div class="topic-metadata">

**Author:** [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Replies:** 4\
**Last updated:** [February 23, 2022, 2:17pm UTC](https://discuss.elastic.co/t/filebeat-httpjson-input/297730 "2022-02-23T14:17:48Z")

</div>

Hi Im trying to use filebeat httpjson to ingest some mongodb atlas metrics but Im struggling with the authentication, Its looks by the way the examples in mongo atlas site that they use digest authentication example cu…

---

## [Why only elasticsearch container starts and kibana and filebeat containers are not getting up?](https://discuss.elastic.co/t/why-only-elasticsearch-container-starts-and-kibana-and-filebeat-containers-are-not-getting-up/298040)

<div class="topic-metadata">

**Author:** [@Mahesh\_Abnave](https://discuss.elastic.co/u/Mahesh_Abnave)\
**Replies:** 0\
**Last updated:** [February 23, 2022, 1:19pm UTC](https://discuss.elastic.co/t/why-only-elasticsearch-container-starts-and-kibana-and-filebeat-containers-are-not-getting-up/298040 "2022-02-23T13:19:41Z")

</div>

I have an application running on six services (or containers) running on an existing docker network. I have deployed them on my local machine using docker stack deploy command. I wanted to create another set of container…

---

## [Filebeat-kafka-logstash](https://discuss.elastic.co/t/filebeat-kafka-logstash/298001)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 0\
**Last updated:** [February 23, 2022, 10:01am UTC](https://discuss.elastic.co/t/filebeat-kafka-logstash/298001 "2022-02-23T10:01:22Z")

</div>

Hi, I would like to know when to use kafka between filebeat and logstash and why? I have multipath in filebeat and each path has its own working and one logstash.conf file. Is this a good idea or is there another more…

---

## [Winlogbeat Index](https://discuss.elastic.co/t/winlogbeat-index/297803)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 3\
**Last updated:** [February 23, 2022, 2:33am UTC](https://discuss.elastic.co/t/winlogbeat-index/297803 "2022-02-23T02:33:26Z")

</div>

Hello there, I´m trying the elk stack 8 and I´m a bit lost. Configured the security portion and when I send the logs over to the Elasticsearch cluster, I cannot see the index on index management. But I can see after tick…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=103)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=105)
