# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=105

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 106

---

## [Enable and configure the apache2 module](https://discuss.elastic.co/t/enable-and-configure-the-apache2-module/297882)

<div class="topic-metadata">

**Author:** [@Mariem](https://discuss.elastic.co/u/Mariem)\
**Replies:** 1\
**Last updated:** [February 22, 2022, 11:08pm UTC](https://discuss.elastic.co/t/enable-and-configure-the-apache2-module/297882 "2022-02-22T23:08:11Z")

</div>

Hi , i'm installing apache logs and i'm stuck here because i'm using docker can someone help me ?

---

## [Auditbeat do not delete correctly](https://discuss.elastic.co/t/auditbeat-do-not-delete-correctly/297814)

<div class="topic-metadata">

**Author:** [@Tester854](https://discuss.elastic.co/u/Tester854)\
**Replies:** 0\
**Last updated:** [February 21, 2022, 9:27pm UTC](https://discuss.elastic.co/t/auditbeat-do-not-delete-correctly/297814 "2022-02-21T21:27:01Z")

</div>

Hi, I noticed that deleting auditbeat with the parameter (backspressure\_strategy:kernel) audit rules continue to work. There are events from them in dmesg. How to remove auditbeat using (backspressure\_strategy:kernel)…

---

## [Fleet server - how to add a fleet server after added one and deleted](https://discuss.elastic.co/t/fleet-server-how-to-add-a-fleet-server-after-added-one-and-deleted/297762)

<div class="topic-metadata">

**Author:** [@gabrielfsousa](https://discuss.elastic.co/u/gabrielfsousa)\
**Replies:** 3\
**Last updated:** [February 22, 2022, 9:41am UTC](https://discuss.elastic.co/t/fleet-server-how-to-add-a-fleet-server-after-added-one-and-deleted/297762 "2022-02-22T09:41:51Z")

</div>

i deleted my fleet server, want to add a new feet server, but i dont have the "add a fleet sever" window only the window to add the agent.

---

## [Weird behavior after Metricbeat 8.0.0 install](https://discuss.elastic.co/t/weird-behavior-after-metricbeat-8-0-0-install/297501)

<div class="topic-metadata">

**Author:** [@Deathwing182](https://discuss.elastic.co/u/Deathwing182)\
**Replies:** 0\
**Last updated:** [February 17, 2022, 1:53pm UTC](https://discuss.elastic.co/t/weird-behavior-after-metricbeat-8-0-0-install/297501 "2022-02-17T13:53:05Z")

</div>

So I upgraded my cluster to ES 8 a couple days ago...all is well mostly, but on the node doing the cluster monitoring, if I also upgrade Metricbeat to 8.0.0, then I almost immediately start getting weirdness showing up i…

---

## [Filebeat Threat Intel module, multiple Anomali filesets](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761)

<div class="topic-metadata">

**Author:** [@Rob3](https://discuss.elastic.co/u/Rob3)\
**Replies:** 7\
**Last updated:** [February 21, 2022, 5:20pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761 "2022-02-21T17:20:15Z")

</div>

How can multiple Anomali filsets be enabled? For example, if I want to enable both collections 135 and 136 as per below, seems that the last read wins and only collection 136 will be configured. Is this possible? Can'…

---

## [Filebeat Checkpoint Module](https://discuss.elastic.co/t/filebeat-checkpoint-module/297773)

<div class="topic-metadata">

**Author:** [@lazyb0nes](https://discuss.elastic.co/u/lazyb0nes)\
**Replies:** 0\
**Last updated:** [February 21, 2022, 3:01pm UTC](https://discuss.elastic.co/t/filebeat-checkpoint-module/297773 "2022-02-21T15:01:35Z")

</div>

Hi there, So I am having some issues when sendin syslog with the cp\_log\_exporter to filebeat. I have seen no errors in filebeat but the fields aren't parsed. I am running R81.10 as far as version goes on the logserve…

---

## [Reading multiline exceptions - filebeat](https://discuss.elastic.co/t/reading-multiline-exceptions-filebeat/297459)

<div class="topic-metadata">

**Author:** [@Rashmika\_Gamage](https://discuss.elastic.co/u/Rashmika_Gamage)\
**Replies:** 5\
**Last updated:** [February 21, 2022, 1:23pm UTC](https://discuss.elastic.co/t/reading-multiline-exceptions-filebeat/297459 "2022-02-21T13:23:26Z")

</div>

I am trying to read IBM websphere logs but as shown in the picture, it is hard to read the logs. since it is hard to find a pattern. Can someone please suggest a method? Also as you can see there are multiple timesta…

---

## [Fleet Server - Certificate Issues](https://discuss.elastic.co/t/fleet-server-certificate-issues/297749)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 0\
**Last updated:** [February 21, 2022, 11:43am UTC](https://discuss.elastic.co/t/fleet-server-certificate-issues/297749 "2022-02-21T11:43:13Z")

</div>

Hello When i try to register Fleet Server using a certificate, it is getting successfully registered. But the problem is, it is throwing "Generating self-signed certificate for Fleet Server" after executing the command …

---

## [Drop event processor not working](https://discuss.elastic.co/t/drop-event-processor-not-working/297720)

<div class="topic-metadata">

**Author:** [@cd-t1-361](https://discuss.elastic.co/u/cd-t1-361)\
**Replies:** 0\
**Last updated:** [February 21, 2022, 7:51am UTC](https://discuss.elastic.co/t/drop-event-processor-not-working/297720 "2022-02-21T07:51:09Z")

</div>

I'm wanting to exclude a particular event if the eventdata contains X value. I've also tried dropping based on just the event id, but for some reason i'm unable to get the event to get dropped & is still being processed. …

---

## [Winlogbeat infinite loop through evtx file and shipping duplicate events when manually shipping events from an evtx file. Starting v7.16.0 to v7.17](https://discuss.elastic.co/t/winlogbeat-infinite-loop-through-evtx-file-and-shipping-duplicate-events-when-manually-shipping-events-from-an-evtx-file-starting-v7-16-0-to-v7-17/297710)

<div class="topic-metadata">

**Author:** [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Replies:** 0\
**Last updated:** [February 21, 2022, 4:37am UTC](https://discuss.elastic.co/t/winlogbeat-infinite-loop-through-evtx-file-and-shipping-duplicate-events-when-manually-shipping-events-from-an-evtx-file-starting-v7-16-0-to-v7-17/297710 "2022-02-21T04:37:50Z")

</div>

Hi, since winlogbeat 7.16.0, when trying to manually ship logs, the beat loops through the evtx file and keeps resending duplicate events until you hit ctrl+C to stop it regardless of the setting no\_more\_events: stop. I …

---

## [Filebeat issue with "cannot index event - dropping event"](https://discuss.elastic.co/t/filebeat-issue-with-cannot-index-event-dropping-event/297707)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 0\
**Last updated:** [February 20, 2022, 11:34pm UTC](https://discuss.elastic.co/t/filebeat-issue-with-cannot-index-event-dropping-event/297707 "2022-02-20T23:34:23Z")

</div>

Hello, I'm using filebeat to parse logs from Elasticsearch audit logs in json format. I'm getting below warnings and don't know what to do with that: WARN \[elasticsearch\] elasticsearch/client.go:414 Cannot inde…

---

## [Filebeat - issue after enable elasticsearch module](https://discuss.elastic.co/t/filebeat-issue-after-enable-elasticsearch-module/297553)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 4\
**Last updated:** [February 20, 2022, 8:03pm UTC](https://discuss.elastic.co/t/filebeat-issue-after-enable-elasticsearch-module/297553 "2022-02-20T20:03:16Z")

</div>

Hello, I would like to filebeat process my Elasticsearch audit logs. When I enable Elasticsearch module (filebeat modules enable Elasticsearch) module is enabled and under modules.d file Elasticsearch.yml.disabled chan…

---

## [Metricbeat installed windows client, but the client system details is not populated in Elasticsearch/ kibana](https://discuss.elastic.co/t/metricbeat-installed-windows-client-but-the-client-system-details-is-not-populated-in-elasticsearch-kibana/296710)

<div class="topic-metadata">

**Author:** [@shi](https://discuss.elastic.co/u/shi)\
**Replies:** 1\
**Last updated:** [February 20, 2022, 4:25pm UTC](https://discuss.elastic.co/t/metricbeat-installed-windows-client-but-the-client-system-details-is-not-populated-in-elasticsearch-kibana/296710 "2022-02-20T16:25:13Z")

</div>

\############### Metricbeat Configured on client as follows ####################### # This file is an example configuration file highlighting only the most common # options. The metricbeat.reference.yml file from the sam…

---

## [Cert error for intial setup of fileBeat](https://discuss.elastic.co/t/cert-error-for-intial-setup-of-filebeat/297614)

<div class="topic-metadata">

**Author:** [@ledufakademy](https://discuss.elastic.co/u/ledufakademy)\
**Replies:** 3\
**Last updated:** [February 20, 2022, 1:17pm UTC](https://discuss.elastic.co/t/cert-error-for-intial-setup-of-filebeat/297614 "2022-02-20T13:17:50Z")

</div>

i follow exactly the documentaion , but we stuck on :slight\_smile: filebeat setup. filebeat setup Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasticsearch at ht…

---

## [How can I use the Elastic-Agent container to collect service logs from another container?](https://discuss.elastic.co/t/how-can-i-use-the-elastic-agent-container-to-collect-service-logs-from-another-container/297683)

<div class="topic-metadata">

**Author:** [@Gibz](https://discuss.elastic.co/u/Gibz)\
**Replies:** 0\
**Last updated:** [February 20, 2022, 5:40am UTC](https://discuss.elastic.co/t/how-can-i-use-the-elastic-agent-container-to-collect-service-logs-from-another-container/297683 "2022-02-20T05:40:19Z")

</div>

My target container contains NGINX logs which I wanted to collect from Elastic Fleet's NGINX Integration. I followed every step, even successfully hosting the fleet server and the agent in two separate containers, what …

---

## [Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/297651)

<div class="topic-metadata">

**Author:** [@Adityadgr8](https://discuss.elastic.co/u/Adityadgr8)\
**Replies:** 3\
**Last updated:** [February 19, 2022, 3:31pm UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/297651 "2022-02-19T15:31:55Z")

</div>

Hello Everyone I am unable to start filebeat service, getting below error: filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/usr/lib/systemd/system/filebeat.serv…

---

## [Log type Filebeat deprectaed and Filestream multiline doesn't works](https://discuss.elastic.co/t/log-type-filebeat-deprectaed-and-filestream-multiline-doesnt-works/297577)

<div class="topic-metadata">

**Author:** [@retina](https://discuss.elastic.co/u/retina)\
**Replies:** 1\
**Last updated:** [February 18, 2022, 8:08pm UTC](https://discuss.elastic.co/t/log-type-filebeat-deprectaed-and-filestream-multiline-doesnt-works/297577 "2022-02-18T20:08:03Z")

</div>

I upgrade one filebeat to 7.16.3 version. When i config my filebeat as always with this config: - type: log enabled: true paths: - xx/yy.log - xx/yy.log - xx/yy.log tags: \["1","2"\] encoding: ISO-8…

---

## [Pass dissect results to next event](https://discuss.elastic.co/t/pass-dissect-results-to-next-event/297507)

<div class="topic-metadata">

**Author:** [@Dancho](https://discuss.elastic.co/u/Dancho)\
**Replies:** 3\
**Last updated:** [February 18, 2022, 3:25pm UTC](https://discuss.elastic.co/t/pass-dissect-results-to-next-event/297507 "2022-02-18T15:25:19Z")

</div>

we use dissect to find some keys, can we pass those fields to the next events till the key will be overwritten? our use case: log file structure contains a header and a body. we need to dissect some values from the hea…

---

## [Elastic Agent/Elastic Endpoint inconsistent connection although the device is up & running](https://discuss.elastic.co/t/elastic-agent-elastic-endpoint-inconsistent-connection-although-the-device-is-up-running/297568)

<div class="topic-metadata">

**Author:** [@ZiaulAfiq](https://discuss.elastic.co/u/ZiaulAfiq)\
**Replies:** 0\
**Last updated:** [February 18, 2022, 7:21am UTC](https://discuss.elastic.co/t/elastic-agent-elastic-endpoint-inconsistent-connection-although-the-device-is-up-running/297568 "2022-02-18T07:21:16Z")

</div>

Hi all! Can I know why does the elastic agent/endpoint sometimes does not shows online although it shows here on the fleet dashboard? Thanks!

---

## [Metricbeat-Kubernetes startup error when upgrading from version 7.2 to 7.16.1](https://discuss.elastic.co/t/metricbeat-kubernetes-startup-error-when-upgrading-from-version-7-2-to-7-16-1/297276)

<div class="topic-metadata">

**Author:** [@cgnusr01](https://discuss.elastic.co/u/cgnusr01)\
**Replies:** 6\
**Last updated:** [February 18, 2022, 8:42am UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-startup-error-when-upgrading-from-version-7-2-to-7-16-1/297276 "2022-02-18T08:42:28Z")

</div>

At a recently upgraded cluster from version 7.2 to 7.16.1, we tried to update Metricbeat for Kubernetes PODs. However on startup we got the following error: ERROR metrics/metrics.go:304 error determining cgroups vers…

---

## [Metricbeat http module query Confluent Cloud Metrics](https://discuss.elastic.co/t/metricbeat-http-module-query-confluent-cloud-metrics/297569)

<div class="topic-metadata">

**Author:** [@henriksped209](https://discuss.elastic.co/u/henriksped209)\
**Replies:** 0\
**Last updated:** [February 18, 2022, 7:22am UTC](https://discuss.elastic.co/t/metricbeat-http-module-query-confluent-cloud-metrics/297569 "2022-02-18T07:22:49Z")

</div>

Hi I have a task where I need to figure out how to collect metrics from Confluent Cloud in ELK Stack. I have been looking into metricbeat http module and I'm able to query metrics from the Confluent Cloud API: https://…

---

## [Variable in setup.template.json.path file not work?](https://discuss.elastic.co/t/variable-in-setup-template-json-path-file-not-work/297520)

<div class="topic-metadata">

**Author:** [@acidborn601](https://discuss.elastic.co/u/acidborn601)\
**Replies:** 0\
**Last updated:** [February 17, 2022, 4:36pm UTC](https://discuss.elastic.co/t/variable-in-setup-template-json-path-file-not-work/297520 "2022-02-17T16:36:01Z")

</div>

Hello! I use Elasticsearch 7.15.1 with filebeat 7.15.1 and have some questions: First: i use this config on filebeat and work fine: setup.template: enabled: true settings: index.number\_of\_shards: 5 index.n…

---

## ["Module elasticsearch doesn't exist!" Error in FileBeat](https://discuss.elastic.co/t/module-elasticsearch-doesnt-exist-error-in-filebeat/297518)

<div class="topic-metadata">

**Author:** [@Molly\_Fraser](https://discuss.elastic.co/u/Molly_Fraser)\
**Replies:** 0\
**Last updated:** [February 17, 2022, 4:27pm UTC](https://discuss.elastic.co/t/module-elasticsearch-doesnt-exist-error-in-filebeat/297518 "2022-02-17T16:27:30Z")

</div>

I keep getting the error "Module Elasticsearch doesn't exist!" when running "./filebeat module enable Elasticsearch" in both powershell and cmd using administrator privileges and normal. I am using Windows 10 with 7.15 …

---

## [Fleet agent custom log integration multiline settings](https://discuss.elastic.co/t/fleet-agent-custom-log-integration-multiline-settings/297124)

<div class="topic-metadata">

**Author:** [@thwint](https://discuss.elastic.co/u/thwint)\
**Replies:** 1\
**Last updated:** [February 17, 2022, 10:02am UTC](https://discuss.elastic.co/t/fleet-agent-custom-log-integration-multiline-settings/297124 "2022-02-17T10:02:55Z")

</div>

Hello all, I try to setup a custom log policy for our java logs. Previously we used filebeat and had the following lines in filebeat.yml to configure multiline log entries: multiline: match: after negate: tru…

---

## ["existing\_package" spam](https://discuss.elastic.co/t/existing-package-spam/297455)

<div class="topic-metadata">

**Author:** [@ziv1](https://discuss.elastic.co/u/ziv1)\
**Replies:** 0\
**Last updated:** [February 17, 2022, 8:55am UTC](https://discuss.elastic.co/t/existing-package-spam/297455 "2022-02-17T08:55:45Z")

</div>

Hi, Earlier today from the server I'm testing Auditbeat on, I got a spam of several hundred "existing\_package" events. (For reference, RHEL) I get the exact same spam every day. Considering it was around 5AM, I don't …

---

## [Control data sampling by netflow](https://discuss.elastic.co/t/control-data-sampling-by-netflow/297425)

<div class="topic-metadata">

**Author:** [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Replies:** 0\
**Last updated:** [February 16, 2022, 11:20pm UTC](https://discuss.elastic.co/t/control-data-sampling-by-netflow/297425 "2022-02-16T23:20:57Z")

</div>

Good morning I would like to know how I can control the data that is sent by netflow to filebeat-kibana, since it generates many documents per minute, I want to know if I can configure the data sampling and only send me…

---

## [SQL Module missing in Metricbeat](https://discuss.elastic.co/t/sql-module-missing-in-metricbeat/297423)

<div class="topic-metadata">

**Author:** [@vPilot](https://discuss.elastic.co/u/vPilot)\
**Replies:** 0\
**Last updated:** [February 16, 2022, 10:49pm UTC](https://discuss.elastic.co/t/sql-module-missing-in-metricbeat/297423 "2022-02-16T22:49:52Z")

</div>

Since the PostgreSQL module doesn't support replication monitoring, or custom queries like the MySQL module, I am hoping to use the SQL module to connect and run the queries I need against Postgres. However, I am not see…

---

## [Read encrypted windows event logs](https://discuss.elastic.co/t/read-encrypted-windows-event-logs/297380)

<div class="topic-metadata">

**Author:** [@EliWallic](https://discuss.elastic.co/u/EliWallic)\
**Replies:** 4\
**Last updated:** [February 16, 2022, 10:30pm UTC](https://discuss.elastic.co/t/read-encrypted-windows-event-logs/297380 "2022-02-16T22:30:31Z")

</div>

Hello community, for security reasons I have some eventlogs encrypted with an certificate. Windows native its possible to decrypt them in order to get access again. Is it also possible with winlogbeat or filebeat? Be…

---

## [Error fetching data for metricset linux.pageinfo](https://discuss.elastic.co/t/error-fetching-data-for-metricset-linux-pageinfo/297049)

<div class="topic-metadata">

**Author:** [@CaSi](https://discuss.elastic.co/u/CaSi)\
**Replies:** 1\
**Last updated:** [February 16, 2022, 9:05pm UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-linux-pageinfo/297049 "2022-02-16T21:05:33Z")

</div>

Hello, I am using metricbeat 7.16.3 on centos 8 stream. The ‘pageinfo’ metricset in the linux module spams my logs with this error message: ERROR module/wrapper.go:259 Error fetching data for metricset li…

---

## [Filebeat issue with json logs from ES audit](https://discuss.elastic.co/t/filebeat-issue-with-json-logs-from-es-audit/297404)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 0\
**Last updated:** [February 16, 2022, 6:29pm UTC](https://discuss.elastic.co/t/filebeat-issue-with-json-logs-from-es-audit/297404 "2022-02-16T18:29:25Z")

</div>

Hello, I have following issue. I created on latest Elasticsearch audit logs (ES ver 7.16.3) with json format, and tried to impement filebeat to sending logs to ES. My audit logs looks like as below: {"type":"audit",…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=104)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=106)
