# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=106

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 107

---

## [Filebeat: Bug: Processor "decode\_json\_fields" with usage of "target"](https://discuss.elastic.co/t/filebeat-bug-processor-decode-json-fields-with-usage-of-target/296972)

<div class="topic-metadata">

**Author:** [@fwetzler](https://discuss.elastic.co/u/fwetzler)\
**Replies:** 13\
**Last updated:** [February 16, 2022, 5:07pm UTC](https://discuss.elastic.co/t/filebeat-bug-processor-decode-json-fields-with-usage-of-target/296972 "2022-02-16T17:07:17Z")

</div>

OS: SLES12, CentOS 7.9 Filebeat Versions: 7.8.0, 7.16.2 After using processor "decode\_json\_fields" WITH "target: 'sometarget' it's impossible to access some extracted json fields with following processors. If you le…

---

## [Metricbeat dashboard setup fails](https://discuss.elastic.co/t/metricbeat-dashboard-setup-fails/296788)

<div class="topic-metadata">

**Author:** [@satherev](https://discuss.elastic.co/u/satherev)\
**Replies:** 3\
**Last updated:** [February 16, 2022, 4:27pm UTC](https://discuss.elastic.co/t/metricbeat-dashboard-setup-fails/296788 "2022-02-16T16:27:30Z")

</div>

Good afternoon, I am unable to set up Metricbeats dashboards. Here is the error I receive: \[root@redacted metricbeat\]# metricbeat setup --dashboards Loading dashboards (Kibana must be running and reachable) Exiting: e…

---

## [My experiences setting up Metricbeat for monitoring an Elastic cluster](https://discuss.elastic.co/t/my-experiences-setting-up-metricbeat-for-monitoring-an-elastic-cluster/297395)

<div class="topic-metadata">

**Author:** [@jacknl](https://discuss.elastic.co/u/jacknl)\
**Replies:** 0\
**Last updated:** [February 16, 2022, 4:21pm UTC](https://discuss.elastic.co/t/my-experiences-setting-up-metricbeat-for-monitoring-an-elastic-cluster/297395 "2022-02-16T16:21:26Z")

</div>

For those who are interested here is my experience deploying Metricbeat with a monitoring cluster ("Stack Monitoring"). In a nutshell: When you monitor a non-trivial Elasticsearch cluster, be sure to add scope: cluste…

---

## [Problem with filebeat](https://discuss.elastic.co/t/problem-with-filebeat/296317)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 3\
**Last updated:** [February 16, 2022, 3:59pm UTC](https://discuss.elastic.co/t/problem-with-filebeat/296317 "2022-02-16T15:59:11Z")

</div>

Hello, I have a problem c filebeat 7.12. The filebeat agent is not working correctly. Initially, 2 sources of logs were configured, data is received from one source, but the second one worked for a month and the data was…

---

## [Drop ipv6 from metricbeat data](https://discuss.elastic.co/t/drop-ipv6-from-metricbeat-data/297158)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 1\
**Last updated:** [February 16, 2022, 3:18pm UTC](https://discuss.elastic.co/t/drop-ipv6-from-metricbeat-data/297158 "2022-02-16T15:18:01Z")

</div>

Hello, I want to drop ipv6 address from metricbeat host.ip document values. How can I do that? I am on 7.16-2

---

## [Metricbeat runtime error: slice bounds out of range](https://discuss.elastic.co/t/metricbeat-runtime-error-slice-bounds-out-of-range/297113)

<div class="topic-metadata">

**Author:** [@tperrot](https://discuss.elastic.co/u/tperrot)\
**Replies:** 1\
**Last updated:** [February 16, 2022, 2:45pm UTC](https://discuss.elastic.co/t/metricbeat-runtime-error-slice-bounds-out-of-range/297113 "2022-02-16T14:45:45Z")

</div>

Hello, I’m currently integrating metricbeat 7.10 on a Linux distribution using Golang 1.14. But a “runtime error: slice bounds out of range” is raised, only on ARMv7 targets, see below. In addition, I integrated fileb…

---

## [Question About Null Conditional](https://discuss.elastic.co/t/question-about-null-conditional/297187)

<div class="topic-metadata">

**Author:** [@msr1716](https://discuss.elastic.co/u/msr1716)\
**Replies:** 1\
**Last updated:** [February 16, 2022, 1:31pm UTC](https://discuss.elastic.co/t/question-about-null-conditional/297187 "2022-02-16T13:31:23Z")

</div>

I am using an Elasticsearch ingest pipeline in a Filebeat module, and I see the statement of: if: 'ctx.json?.userIdentity?.userName == null' When json.userIdentity.userName is equal to null, what would the key/value pai…

---

## [Filebeat doesn't load logs into ElasticSearch (Windows)](https://discuss.elastic.co/t/filebeat-doesnt-load-logs-into-elasticsearch-windows/297319)

<div class="topic-metadata">

**Author:** [@Pixelixir](https://discuss.elastic.co/u/Pixelixir)\
**Replies:** 1\
**Last updated:** [February 16, 2022, 10:28am UTC](https://discuss.elastic.co/t/filebeat-doesnt-load-logs-into-elasticsearch-windows/297319 "2022-02-16T10:28:03Z")

</div>

I've read all the setup instructions over and over again but I still don't know how to transfer logs into Elasticsearch (localhost) via Filebeat. Here is my Elasticsearch.yml and Filebeat inputs:

---

## ["Wild swings" in event rate when number of workers increase](https://discuss.elastic.co/t/wild-swings-in-event-rate-when-number-of-workers-increase/297320)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [February 16, 2022, 4:38am UTC](https://discuss.elastic.co/t/wild-swings-in-event-rate-when-number-of-workers-increase/297320 "2022-02-16T04:38:38Z")

</div>

Hi, I'm trying to increase the event rate for my filebeat that is writing Netflow data to Elasticsearch, to keep up with the incoming Netflow traffic. I have already increased max\_bulk\_size to 1000 in filebeat.yml, whic…

---

## [Elasticsearch Basic License Precompiled Beats Downlad for OpenBSD 7.0?](https://discuss.elastic.co/t/elasticsearch-basic-license-precompiled-beats-downlad-for-openbsd-7-0/297310)

<div class="topic-metadata">

**Author:** [@Jarbird](https://discuss.elastic.co/u/Jarbird)\
**Replies:** 2\
**Last updated:** [February 16, 2022, 1:13am UTC](https://discuss.elastic.co/t/elasticsearch-basic-license-precompiled-beats-downlad-for-openbsd-7-0/297310 "2022-02-16T01:13:15Z")

</div>

Hello, I have tried (and failed at the make stage) to compile the OSS version of beats on OpenBSD 7.0. I have since discovered that the OSS version does not have the capabilities that I need. What I'm looking for is a pr…

---

## [Make Errors on OpenBSD 7.0 (Compiling Source)](https://discuss.elastic.co/t/make-errors-on-openbsd-7-0-compiling-source/296662)

<div class="topic-metadata">

**Author:** [@Jarbird](https://discuss.elastic.co/u/Jarbird)\
**Replies:** 1\
**Last updated:** [February 16, 2022, 12:08am UTC](https://discuss.elastic.co/t/make-errors-on-openbsd-7-0-compiling-source/296662 "2022-02-16T00:08:51Z")

</div>

Hello, I have perused the various OpenBSD topics regarding compiling beats (specifically filebeat) on OpenBSD, and have not found a solution to what I'm seeing. OpenBSD 7.0 currently ships a filebeat version which is b…

---

## [Metricbeat 7.16.1 is not available for download](https://discuss.elastic.co/t/metricbeat-7-16-1-is-not-available-for-download/297277)

<div class="topic-metadata">

**Author:** [@cgnusr01](https://discuss.elastic.co/u/cgnusr01)\
**Replies:** 1\
**Last updated:** [February 15, 2022, 11:42pm UTC](https://discuss.elastic.co/t/metricbeat-7-16-1-is-not-available-for-download/297277 "2022-02-15T23:42:39Z")

</div>

When visiting https://www.elastic.co/downloads/past-releases/metricbeat-7-16-1 we get 404 error.

---

## [Missing MISP docs?](https://discuss.elastic.co/t/missing-misp-docs/297301)

<div class="topic-metadata">

**Author:** [@tofubeats](https://discuss.elastic.co/u/tofubeats)\
**Replies:** 0\
**Last updated:** [February 15, 2022, 10:44pm UTC](https://discuss.elastic.co/t/missing-misp-docs/297301 "2022-02-15T22:44:41Z")

</div>

I have set up a MISP instance and have configured filebeat to query the MISP server. However, I cannot find the actual docs in any indices in logstash. When running journalctl -fu logstash, I see this every few minutes: …

---

## [Filebeat failing to parse docker json-file logs](https://discuss.elastic.co/t/filebeat-failing-to-parse-docker-json-file-logs/297287)

<div class="topic-metadata">

**Author:** [@rectalogic](https://discuss.elastic.co/u/rectalogic)\
**Replies:** 1\
**Last updated:** [February 15, 2022, 8:48pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-parse-docker-json-file-logs/297287 "2022-02-15T20:48:35Z")

</div>

I'm using filebeat 7.12.0 to ingest docker logs using the container input. Log entries in the docker json-file format look like: {"log":"{\\"@timestamp\\":\\"2022-02-15T17:45:26.742Z\\",\\"log.level\\":\\"info\\",\\"message\\":\\"…

---

## [How to do log parsing](https://discuss.elastic.co/t/how-to-do-log-parsing/297112)

<div class="topic-metadata">

**Author:** [@himmana](https://discuss.elastic.co/u/himmana)\
**Replies:** 1\
**Last updated:** [February 15, 2022, 2:40pm UTC](https://discuss.elastic.co/t/how-to-do-log-parsing/297112 "2022-02-15T14:40:24Z")

</div>

This is my log. i used "elastic" and "filebeat" and "kibana" I'm a beginner who just started studying. I want to parse and use the contents of "message". Where should I start and what should we do?

---

## [Fleet Server Settings Elasticsearch CA Fingerprint Rejected](https://discuss.elastic.co/t/fleet-server-settings-elasticsearch-ca-fingerprint-rejected/297218)

<div class="topic-metadata">

**Author:** [@ddth\_2022](https://discuss.elastic.co/u/ddth_2022)\
**Replies:** 3\
**Last updated:** [February 15, 2022, 1:46pm UTC](https://discuss.elastic.co/t/fleet-server-settings-elasticsearch-ca-fingerprint-rejected/297218 "2022-02-15T13:46:10Z")

</div>

I tried entering the base64 encoded Fingerprint of the CA certificate in the Output section of Fleet settings, but I get the error below - The string is most definitely base64 encoded. What can I do to get past this i…

---

## [Fleet: Share integration configuration](https://discuss.elastic.co/t/fleet-share-integration-configuration/296597)

<div class="topic-metadata">

**Author:** [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Replies:** 2\
**Last updated:** [February 15, 2022, 5:08am UTC](https://discuss.elastic.co/t/fleet-share-integration-configuration/296597 "2022-02-15T05:08:52Z")

</div>

Hi all, We just started playing around with Fleet and we stumbled over the following topic: According to the documentation, each agent can only be enrolled in a single policy. The integrations are configured on that po…

---

## [Elasticsearch/client.go:408 Cannot index event](https://discuss.elastic.co/t/elasticsearch-client-go-408-cannot-index-event/297167)

<div class="topic-metadata">

**Author:** [@qubusp](https://discuss.elastic.co/u/qubusp)\
**Replies:** 0\
**Last updated:** [February 14, 2022, 4:01pm UTC](https://discuss.elastic.co/t/elasticsearch-client-go-408-cannot-index-event/297167 "2022-02-14T16:01:49Z")

</div>

2022-02-14T15:46:03.114Z WARN \[elasticsearch\] elasticsearch/client.go:408 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0xbaeb900, ext:63780449718, loc:(\*time.Location)(0x5864aa0)}, Met…

---

## [\[Metricbeat\] Mysql user permission](https://discuss.elastic.co/t/metricbeat-mysql-user-permission/297018)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 1\
**Last updated:** [February 14, 2022, 3:22pm UTC](https://discuss.elastic.co/t/metricbeat-mysql-user-permission/297018 "2022-02-14T15:22:32Z")

</div>

Hi, I want to know which are the user privilege nedded for each metricset of mysql module: Performance Query Status The documentation talk about only the user root. Regards,

---

## [\[MSSQL module\] - Transaction log stop after few hours](https://discuss.elastic.co/t/mssql-module-transaction-log-stop-after-few-hours/293323)

<div class="topic-metadata">

**Author:** [@Delta32000](https://discuss.elastic.co/u/Delta32000)\
**Replies:** 5\
**Last updated:** [February 14, 2022, 10:07am UTC](https://discuss.elastic.co/t/mssql-module-transaction-log-stop-after-few-hours/293323 "2022-02-14T10:07:21Z")

</div>

I was able to configure the mssql module on metricbeat. I use the ssl config for each Elasticsearch and Kibana. I was able to load the default dashboards in kibana. The thing is that I can see transaction log data for a …

---

## [Is there any way to make Winlogbeat not start automatically?](https://discuss.elastic.co/t/is-there-any-way-to-make-winlogbeat-not-start-automatically/297095)

<div class="topic-metadata">

**Author:** [@Will\_Wu](https://discuss.elastic.co/u/Will_Wu)\
**Replies:** 1\
**Last updated:** [February 14, 2022, 8:56am UTC](https://discuss.elastic.co/t/is-there-any-way-to-make-winlogbeat-not-start-automatically/297095 "2022-02-14T08:56:15Z")

</div>

hey guys! First time using winlogbeat。 is there any method to make Winlogbeat do not start automatically ?

---

## [Winlogbeat setup without direct access to elasticsearch/kibana](https://discuss.elastic.co/t/winlogbeat-setup-without-direct-access-to-elasticsearch-kibana/296949)

<div class="topic-metadata">

**Author:** [@siginigin](https://discuss.elastic.co/u/siginigin)\
**Replies:** 2\
**Last updated:** [February 14, 2022, 7:42am UTC](https://discuss.elastic.co/t/winlogbeat-setup-without-direct-access-to-elasticsearch-kibana/296949 "2022-02-14T07:42:27Z")

</div>

Hello, I have windows servers that have access to logstash, but don't have direct access to Elasticsearch cluster nor kibana. How can I properly setup winlobeat to import dashboards/pipelines/indices/... ? Other beats …

---

## [\[Packetbeat\] How to distinguish netflow from different interface device in log?](https://discuss.elastic.co/t/packetbeat-how-to-distinguish-netflow-from-different-interface-device-in-log/297092)

<div class="topic-metadata">

**Author:** [@492917328](https://discuss.elastic.co/u/492917328)\
**Replies:** 1\
**Last updated:** [February 14, 2022, 4:00am UTC](https://discuss.elastic.co/t/packetbeat-how-to-distinguish-netflow-from-different-interface-device-in-log/297092 "2022-02-14T04:00:32Z")

</div>

Packetbeat supports capturing all messages sent or received by the server on which Packetbeat is installed： packetbeat.interfaces.device: any But when I set the output to Elasticsearch, I found that the field interface…

---

## [How to make a dashboard based on my sql query for?](https://discuss.elastic.co/t/how-to-make-a-dashboard-based-on-my-sql-query-for/297060)

<div class="topic-metadata">

**Author:** [@wasiualhasib](https://discuss.elastic.co/u/wasiualhasib)\
**Replies:** 0\
**Last updated:** [February 12, 2022, 9:45pm UTC](https://discuss.elastic.co/t/how-to-make-a-dashboard-based-on-my-sql-query-for/297060 "2022-02-12T21:45:06Z")

</div>

I want to create a dashboard using custom query such as database count, user list etc. But I did not found any option like this. Anyone can have any idea about it?

---

## [How can I know disk space each partition of my host?](https://discuss.elastic.co/t/how-can-i-know-disk-space-each-partition-of-my-host/297059)

<div class="topic-metadata">

**Author:** [@wasiualhasib](https://discuss.elastic.co/u/wasiualhasib)\
**Replies:** 0\
**Last updated:** [February 12, 2022, 9:35pm UTC](https://discuss.elastic.co/t/how-can-i-know-disk-space-each-partition-of-my-host/297059 "2022-02-12T21:35:58Z")

</div>

I want to know each partition information like linux commands: df -h or free -m Is it possible using ELK?

---

## [Reverse dns lookup for elastic-agent](https://discuss.elastic.co/t/reverse-dns-lookup-for-elastic-agent/296971)

<div class="topic-metadata">

**Author:** [@VoncinaMihael](https://discuss.elastic.co/u/VoncinaMihael)\
**Replies:** 3\
**Last updated:** [February 12, 2022, 3:20am UTC](https://discuss.elastic.co/t/reverse-dns-lookup-for-elastic-agent/296971 "2022-02-12T03:20:45Z")

</div>

Hi, I'm trying to find a way to resolve IP to host, for logs ingested from elastic-agents. Within Filebeat i can use dns processor, but i don't know how to do this for agent data...

---

## [Filebeat httpjson chained requests](https://discuss.elastic.co/t/filebeat-httpjson-chained-requests/296959)

<div class="topic-metadata">

**Author:** [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Replies:** 1\
**Last updated:** [February 11, 2022, 9:56pm UTC](https://discuss.elastic.co/t/filebeat-httpjson-chained-requests/296959 "2022-02-11T21:56:55Z")

</div>

Hi is there a way to chain multiple httpjson requests? Let's say I need to do a first query to an endpoint to get a hosts lists, and then another one to another url constructed using the hosts that I got from the first q…

---

## [ERROR metrics/metrics.go:380](https://discuss.elastic.co/t/error-metrics-metrics-go-380/297026)

<div class="topic-metadata">

**Author:** [@rcts](https://discuss.elastic.co/u/rcts)\
**Replies:** 0\
**Last updated:** [February 11, 2022, 9:43pm UTC](https://discuss.elastic.co/t/error-metrics-metrics-go-380/297026 "2022-02-11T21:43:46Z")

</div>

Hello guys, i need help to fix issue. I don't know what to do \< 2022-02-11T21:37:34.802Z ERROR metrics/metrics.go:380 error getting cgroup stats: error fetching stats for controller io: error fetching IO stats: error f…

---

## [License Question: x-pack Modules](https://discuss.elastic.co/t/license-question-x-pack-modules/296975)

<div class="topic-metadata">

**Author:** [@Jarbird](https://discuss.elastic.co/u/Jarbird)\
**Replies:** 4\
**Last updated:** [February 11, 2022, 9:42pm UTC](https://discuss.elastic.co/t/license-question-x-pack-modules/296975 "2022-02-11T21:42:19Z")

</div>

Hello, I have been struggling to get the netflow module working. The error I keep ending up with is: 2022-02-11T07:49:28.539-0500 ERROR instance/beat.go:1015 Exiting: Failed to start crawler: creating module rel…

---

## [Winlogbeat repeats batches of event logs](https://discuss.elastic.co/t/winlogbeat-repeats-batches-of-event-logs/296519)

<div class="topic-metadata">

**Author:** [@dhelk](https://discuss.elastic.co/u/dhelk)\
**Replies:** 2\
**Last updated:** [February 11, 2022, 8:03pm UTC](https://discuss.elastic.co/t/winlogbeat-repeats-batches-of-event-logs/296519 "2022-02-11T20:03:12Z")

</div>

I am testing uploading Windows EVTX to Elastic using Winlogbeat and Logstash, and when opening several evtx files the Winlogbeat will not terminate the processing job, but will instead keep trying to resubmit. I original…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=105)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=107)
