# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=107

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 108

---

## [Filebeat Not able to catch up with rotating container logs](https://discuss.elastic.co/t/filebeat-not-able-to-catch-up-with-rotating-container-logs/296935)

<div class="topic-metadata">

**Author:** [@elk\_follower](https://discuss.elastic.co/u/elk_follower)\
**Replies:** 2\
**Last updated:** [February 11, 2022, 6:17pm UTC](https://discuss.elastic.co/t/filebeat-not-able-to-catch-up-with-rotating-container-logs/296935 "2022-02-11T18:17:22Z")

</div>

We have a situation where container logs are rotated ~5 times with-in a minute and only last 5 files are kept before getting deleted. We have Filebeat running as daemon set in the K8 cluster and it is able to send th…

---

## [Filebeat Lag](https://discuss.elastic.co/t/filebeat-lag/296995)

<div class="topic-metadata">

**Author:** [@Winfield\_Henry](https://discuss.elastic.co/u/Winfield_Henry)\
**Replies:** 0\
**Last updated:** [February 11, 2022, 3:32pm UTC](https://discuss.elastic.co/t/filebeat-lag/296995 "2022-02-11T15:32:38Z")

</div>

Hello, We have recently implemented an internal IDS solution. That solution can generate somewhere in the neighborhood of ~30k logs (json format) per minute. Filebeat has a pre-canned module that we are using and it doe…

---

## [Anomali Limo using Elastic Agent](https://discuss.elastic.co/t/anomali-limo-using-elastic-agent/296965)

<div class="topic-metadata">

**Author:** [@samoz83](https://discuss.elastic.co/u/samoz83)\
**Replies:** 1\
**Last updated:** [February 11, 2022, 3:27pm UTC](https://discuss.elastic.co/t/anomali-limo-using-elastic-agent/296965 "2022-02-11T15:27:24Z")

</div>

Just updated to v8 and enabled the Anomali Limo API using the Elastic Agent, not sure if anyone else has had success using this integration but it doesn't seem to pull any data using the default settings?

---

## [Fleet CEF Processor](https://discuss.elastic.co/t/fleet-cef-processor/296790)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 6\
**Last updated:** [February 11, 2022, 3:20pm UTC](https://discuss.elastic.co/t/fleet-cef-processor/296790 "2022-02-11T15:20:51Z")

</div>

Hello, We are trying to use the CEF integration to parse syslogs sent over from SentinelOne, but are getting an error message on processing which appears to be due to the date format. Error - Text '2022-02-09 00:25:02,…

---

## [No way to specify filebeat 8.0.0 data stream and index template pattern](https://discuss.elastic.co/t/no-way-to-specify-filebeat-8-0-0-data-stream-and-index-template-pattern/296979)

<div class="topic-metadata">

**Author:** [@rouke-broersma](https://discuss.elastic.co/u/rouke-broersma)\
**Replies:** 3\
**Last updated:** [February 11, 2022, 2:45pm UTC](https://discuss.elastic.co/t/no-way-to-specify-filebeat-8-0-0-data-stream-and-index-template-pattern/296979 "2022-02-11T14:45:18Z")

</div>

In filebeat 7.x we were able to specify custom index template and rollover\_alias for the indexes used by filebeat. We use this to split which indices different filebeats send their logs to because some filebeats collect …

---

## [Elastic Agent - error getting cgroup stats: error fetching stats for controller io](https://discuss.elastic.co/t/elastic-agent-error-getting-cgroup-stats-error-fetching-stats-for-controller-io/296906)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 0\
**Last updated:** [February 10, 2022, 9:55pm UTC](https://discuss.elastic.co/t/elastic-agent-error-getting-cgroup-stats-error-fetching-stats-for-controller-io/296906 "2022-02-10T21:55:58Z")

</div>

Hi, Elastic-Agent 7.17 and getting this error for the agents on Raspberry Pi Model 4 - Debian Bullseye elastic-agent filebeat metrcbeat osquerybeat error getting cgroup stats: error fetching stats for controller io…

---

## [Adding multiple input files](https://discuss.elastic.co/t/adding-multiple-input-files/296832)

<div class="topic-metadata">

**Author:** [@abhi.logs](https://discuss.elastic.co/u/abhi.logs)\
**Replies:** 5\
**Last updated:** [February 11, 2022, 7:05am UTC](https://discuss.elastic.co/t/adding-multiple-input-files/296832 "2022-02-11T07:05:19Z")

</div>

Hello, Is it possible to add two inputs files in filebeat.yml? Example:- - /etc/filebeat/inputs.d/\*.yml - /etc/filebeat-oss/inputs.d/\*.yml I wanna add these two files in filebeat.yml under filebeat.config.inp…

---

## [Filebeat can be collected normally after starting and will stop automatically soon](https://discuss.elastic.co/t/filebeat-can-be-collected-normally-after-starting-and-will-stop-automatically-soon/296925)

<div class="topic-metadata">

**Author:** [@y792872131](https://discuss.elastic.co/u/y792872131)\
**Replies:** 0\
**Last updated:** [February 11, 2022, 3:05am UTC](https://discuss.elastic.co/t/filebeat-can-be-collected-normally-after-starting-and-will-stop-automatically-soon/296925 "2022-02-11T03:05:58Z")

</div>

An error is as follows:

---

## [Set indices based on (sub) module name](https://discuss.elastic.co/t/set-indices-based-on-sub-module-name/296850)

<div class="topic-metadata">

**Author:** [@tartaarsap](https://discuss.elastic.co/u/tartaarsap)\
**Replies:** 3\
**Last updated:** [February 10, 2022, 5:20pm UTC](https://discuss.elastic.co/t/set-indices-based-on-sub-module-name/296850 "2022-02-10T17:20:24Z")

</div>

I'm trying to send my log files into multiple indices based on a sub (module) value. With the code below it works for the main module. output.elasticsearch: # Array of hosts to connect to. hosts: \["localhost:9200"\] …

---

## [Metricbeat unable to start](https://discuss.elastic.co/t/metricbeat-unable-to-start/295399)

<div class="topic-metadata">

**Author:** [@mmmguy](https://discuss.elastic.co/u/mmmguy)\
**Replies:** 4\
**Last updated:** [February 10, 2022, 3:57pm UTC](https://discuss.elastic.co/t/metricbeat-unable-to-start/295399 "2022-02-10T15:57:30Z")

</div>

Anyone ever have issues getting the metricbeat service to start on a 2012 R2 server where the filebeat log says Exiting: can not convert 'object' into 'string' accessing '0.hosts.0' (source:'C:\\ProgramData\\Elastic\\Beats\\…

---

## [Unable to deploy Functionbeat 7.16.3](https://discuss.elastic.co/t/unable-to-deploy-functionbeat-7-16-3/296857)

<div class="topic-metadata">

**Author:** [@Bhavani\_Ananth](https://discuss.elastic.co/u/Bhavani_Ananth)\
**Replies:** 0\
**Last updated:** [February 10, 2022, 2:38pm UTC](https://discuss.elastic.co/t/unable-to-deploy-functionbeat-7-16-3/296857 "2022-02-10T14:38:25Z")

</div>

Elasticsearch version : 7.16.3 Functionbeat: 7.16.3 OS : Ubuntu 20.04.3 LTS a. When I try to deploy functionbeat (version 7.16.3) in S3 bucket, I get the following exception Function: cloudwatch, could not deploy, er…

---

## [Does Filebeat plan to support Data Streams?](https://discuss.elastic.co/t/does-filebeat-plan-to-support-data-streams/296851)

<div class="topic-metadata">

**Author:** [@brsolomon](https://discuss.elastic.co/u/brsolomon)\
**Replies:** 3\
**Last updated:** [February 10, 2022, 2:33pm UTC](https://discuss.elastic.co/t/does-filebeat-plan-to-support-data-streams/296851 "2022-02-10T14:33:20Z")

</div>

Does Filebeat plan to support Data Streams, and if so, what is the expected development timeline? Per docs, Prior to Elasticsearch 7.9, you’d typically use an index alias with a write index to manage time series data.…

---

## [Connection marked as failed because the onConnect callback failed](https://discuss.elastic.co/t/connection-marked-as-failed-because-the-onconnect-callback-failed/296834)

<div class="topic-metadata">

**Author:** [@abhi.logs](https://discuss.elastic.co/u/abhi.logs)\
**Replies:** 1\
**Last updated:** [February 10, 2022, 2:20pm UTC](https://discuss.elastic.co/t/connection-marked-as-failed-because-the-onconnect-callback-failed/296834 "2022-02-10T14:20:29Z")

</div>

Getting this error when I enabled envoy module. Connection marked as failed because the onConnect callback failed: 1 error: error loading pipeline for fileset envoyproxy/log: couldn't load pipeline: couldn't load json. …

---

## [Multiline pattern for javaserver log not working](https://discuss.elastic.co/t/multiline-pattern-for-javaserver-log-not-working/296803)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 2\
**Last updated:** [February 10, 2022, 12:05pm UTC](https://discuss.elastic.co/t/multiline-pattern-for-javaserver-log-not-working/296803 "2022-02-10T12:05:55Z")

</div>

Hello team, I am trying to write multline pattern for below log line. But it is not working. It is displaying seperate line for each "at" record. Can you please help me on this to write multiline pattern Log line: \[2…

---

## [Auditbeat collects old data on Linux system](https://discuss.elastic.co/t/auditbeat-collects-old-data-on-linux-system/296814)

<div class="topic-metadata">

**Author:** [@Bo\_Pham\_Nguyen](https://discuss.elastic.co/u/Bo_Pham_Nguyen)\
**Replies:** 0\
**Last updated:** [February 10, 2022, 8:29am UTC](https://discuss.elastic.co/t/auditbeat-collects-old-data-on-linux-system/296814 "2022-02-10T08:29:12Z")

</div>

Hi team, we are facing an issue when installing Auditbeat on a new machine that collects historical data 2020 2021. Any way to fix this? This is the configuration for Auditbeat auditbeat.modules: - module: system d…

---

## [Trying to add readiness and liveness to filebeat](https://discuss.elastic.co/t/trying-to-add-readiness-and-liveness-to-filebeat/296785)

<div class="topic-metadata">

**Author:** [@anu2](https://discuss.elastic.co/u/anu2)\
**Replies:** 0\
**Last updated:** [February 9, 2022, 9:01pm UTC](https://discuss.elastic.co/t/trying-to-add-readiness-and-liveness-to-filebeat/296785 "2022-02-09T21:01:29Z")

</div>

k8s version-v1.19.16 filebeat version 7.7.1 i am trying to add readiness and liveness to my code. livenessProbe: exec: command: - sh - -c - | #!/usr/bi…

---

## [Advice on upgrade winlogbeat v6.4.2 to latest 7.17.0](https://discuss.elastic.co/t/advice-on-upgrade-winlogbeat-v6-4-2-to-latest-7-17-0/296617)

<div class="topic-metadata">

**Author:** [@SuperDolas](https://discuss.elastic.co/u/SuperDolas)\
**Replies:** 2\
**Last updated:** [February 9, 2022, 2:24pm UTC](https://discuss.elastic.co/t/advice-on-upgrade-winlogbeat-v6-4-2-to-latest-7-17-0/296617 "2022-02-09T14:24:35Z")

</div>

Ola First time using the software and would like some help please. I have a few servers still using v6.4.2 and I would like to go to the latest version 7.17.0 What is the best way to get there? Remove all v6 and inst…

---

## [Multiple hosts per monitor confuses certificate validation since 7.17.0](https://discuss.elastic.co/t/multiple-hosts-per-monitor-confuses-certificate-validation-since-7-17-0/296062)

<div class="topic-metadata">

**Author:** [@PayBas](https://discuss.elastic.co/u/PayBas)\
**Replies:** 7\
**Last updated:** [February 9, 2022, 2:09pm UTC](https://discuss.elastic.co/t/multiple-hosts-per-monitor-confuses-certificate-validation-since-7-17-0/296062 "2022-02-09T14:09:46Z")

</div>

Since upgrading Heartbeat to 7.17.0 all my monitors have gone haywire. It seems that if you define multiple hosts per monitor like so: - type: http id: cicd name: CI/CD hosts: - https://a.corp.internal - …

---

## [Secure setting is unauthorized](https://discuss.elastic.co/t/secure-setting-is-unauthorized/295264)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 3\
**Last updated:** [February 9, 2022, 1:50pm UTC](https://discuss.elastic.co/t/secure-setting-is-unauthorized/295264 "2022-02-09T13:50:49Z")

</div>

I tried to use basic authentication credentials in metricbeat.yml I set monitor, read\_ilm and read\_pipeline as cluster privileges for role metricbeat\_writer. But I got 403 error code. ERROR \[publisher\_pipeline\_output\] …

---

## [Beats automaticaly create empty indices](https://discuss.elastic.co/t/beats-automaticaly-create-empty-indices/296348)

<div class="topic-metadata">

**Author:** [@Pysel](https://discuss.elastic.co/u/Pysel)\
**Replies:** 2\
**Last updated:** [February 9, 2022, 11:52am UTC](https://discuss.elastic.co/t/beats-automaticaly-create-empty-indices/296348 "2022-02-09T11:52:40Z")

</div>

Hello, is there a config to disable the Beats automaticaly creating indices for their version ? To give a better explanation, I have some beats writing to custom indices, we are all fine there but those beats still creat…

---

## [Get Collect Smart data from disks](https://discuss.elastic.co/t/get-collect-smart-data-from-disks/296681)

<div class="topic-metadata">

**Author:** [@vovan13111](https://discuss.elastic.co/u/vovan13111)\
**Replies:** 0\
**Last updated:** [February 9, 2022, 6:44am UTC](https://discuss.elastic.co/t/get-collect-smart-data-from-disks/296681 "2022-02-09T06:44:08Z")

</div>

Good afternoon. I saw in one of the old requests, the question of whether it is possible to collect smart data from disks. Is there such a possibility already or not yet?

---

## [Mapping field values](https://discuss.elastic.co/t/mapping-field-values/296646)

<div class="topic-metadata">

**Author:** [@Dror\_Tirosh](https://discuss.elastic.co/u/Dror_Tirosh)\
**Replies:** 3\
**Last updated:** [February 9, 2022, 6:29am UTC](https://discuss.elastic.co/t/mapping-field-values/296646 "2022-02-09T06:29:31Z")

</div>

I have input events that have multiple "keyword" fields. These are IDs (or "guids") of entities that I later collect statistics for. However, the resulting graph "legend" shows those "GUID" values, and I'd like to map t…

---

## [Ingest Pipeline ID not working for UDP Integration](https://discuss.elastic.co/t/ingest-pipeline-id-not-working-for-udp-integration/296668)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 2\
**Last updated:** [February 9, 2022, 4:48am UTC](https://discuss.elastic.co/t/ingest-pipeline-id-not-working-for-udp-integration/296668 "2022-02-09T04:48:00Z")

</div>

Hello, We are using the Custom UDP integration in Fleet to ingest logs from Untangle firewalls. I've created an ingest pipeline, called Untangle, that should parse the message field sent over from the integration. Whe…

---

## [How filebeat read the content of the file](https://discuss.elastic.co/t/how-filebeat-read-the-content-of-the-file/295674)

<div class="topic-metadata">

**Author:** [@sixsenseninja](https://discuss.elastic.co/u/sixsenseninja)\
**Replies:** 3\
**Last updated:** [February 9, 2022, 2:53am UTC](https://discuss.elastic.co/t/how-filebeat-read-the-content-of-the-file/295674 "2022-02-09T02:53:14Z")

</div>

Hi all, We are exporting a csv using cronjob and put it inside a a folder. A filebeat will process and read the file before for visualization in Kibana. (Filebeat and the folder are in the same host) The csv is a very …

---

## [Metricbeat and Elastic Security](https://discuss.elastic.co/t/metricbeat-and-elastic-security/296637)

<div class="topic-metadata">

**Author:** [@holobolo0815](https://discuss.elastic.co/u/holobolo0815)\
**Replies:** 0\
**Last updated:** [February 8, 2022, 4:38pm UTC](https://discuss.elastic.co/t/metricbeat-and-elastic-security/296637 "2022-02-08T16:38:28Z")

</div>

Hello, So I have setup Elasticsearch security. Usual logging works fine using a logstash\_internal user using the appropriate role recommended by the docs. I'm having a hard time however finding out how to configure Met…

---

## [Is it possible to enrich windows integration logs ?!](https://discuss.elastic.co/t/is-it-possible-to-enrich-windows-integration-logs/295143)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 6\
**Last updated:** [February 8, 2022, 8:58pm UTC](https://discuss.elastic.co/t/is-it-possible-to-enrich-windows-integration-logs/295143 "2022-02-08T20:58:42Z")

</div>

Hi, I'm using windows integration to collect windows event logs, the integration settings offer a field to specify processor, but when try to use enrich processor I stop receiving new logs and i got the following error …

---

## [How to tell the state of an IIS app pool via the IIS metrics from Metricbeat](https://discuss.elastic.co/t/how-to-tell-the-state-of-an-iis-app-pool-via-the-iis-metrics-from-metricbeat/294171)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 6\
**Last updated:** [February 8, 2022, 8:15pm UTC](https://discuss.elastic.co/t/how-to-tell-the-state-of-an-iis-app-pool-via-the-iis-metrics-from-metricbeat/294171 "2022-02-08T20:15:19Z")

</div>

Hi All, I'm trying to determine the state of an IIS app pool (running/stopped/disabled/etc...) that is monitor by Metricbeat. However, it doesn't appear that Metricbeat includes the state of the app pool in its metric …

---

## [Filebeat 8.0.0-rc2 dynamic data stream name](https://discuss.elastic.co/t/filebeat-8-0-0-rc2-dynamic-data-stream-name/296397)

<div class="topic-metadata">

**Author:** [@WouterAA](https://discuss.elastic.co/u/WouterAA)\
**Replies:** 7\
**Last updated:** [February 8, 2022, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-8-0-0-rc2-dynamic-data-stream-name/296397 "2022-02-08T16:53:14Z")

</div>

Hello, we use filebeat on a k8s cluster to store logs per namespace. On filebeat 7 we create an index per namespace. Filebeat 8.0.0-rc2 uses data streams by default, which we think is a more elegant solution. However it …

---

## [Filebeat multiple index + ilm + index\_template](https://discuss.elastic.co/t/filebeat-multiple-index-ilm-index-template/296638)

<div class="topic-metadata">

**Author:** [@cedricHA](https://discuss.elastic.co/u/cedricHA)\
**Replies:** 0\
**Last updated:** [February 8, 2022, 4:52pm UTC](https://discuss.elastic.co/t/filebeat-multiple-index-ilm-index-template/296638 "2022-02-08T16:52:40Z")

</div>

Hello, In filebeat I use several indexes depending on the module. I use the basic filebeat model based on the indexes to keep the field architecture. filebeat-7.16.2-\* setup.template.enabled: true setup.template.nam…

---

## [Unable to monitor all logstash pipelines](https://discuss.elastic.co/t/unable-to-monitor-all-logstash-pipelines/296491)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 3\
**Last updated:** [February 8, 2022, 1:33pm UTC](https://discuss.elastic.co/t/unable-to-monitor-all-logstash-pipelines/296491 "2022-02-08T13:33:23Z")

</div>

Dears, I have 7 logstash and deployed metricbeat on all of them for monitoring purpose. out of all these on one logstash i am getting only pipeline in monitoring (5 pipelines are present on this logstash node) all the …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=106)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=108)
