# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=108

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 109

---

## [Configuring aerospike metricbeat module with TLS](https://discuss.elastic.co/t/configuring-aerospike-metricbeat-module-with-tls/294729)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 2\
**Last updated:** [February 8, 2022, 11:45am UTC](https://discuss.elastic.co/t/configuring-aerospike-metricbeat-module-with-tls/294729 "2022-02-08T11:45:19Z")

</div>

I am looking at the code and trying to figure out how I should configure TLS certificates to get access to the aerospike service endpoint with TLS configured. Does anybody have a successful module configuration exampl…

---

## [Filebeat tail\_files in filestream input](https://discuss.elastic.co/t/filebeat-tail-files-in-filestream-input/296282)

<div class="topic-metadata">

**Author:** [@solnicki](https://discuss.elastic.co/u/solnicki)\
**Replies:** 2\
**Last updated:** [February 8, 2022, 10:04am UTC](https://discuss.elastic.co/t/filebeat-tail-files-in-filestream-input/296282 "2022-02-08T10:04:05Z")

</div>

Hi All, Starting from filebeat version 7.15 there is a recommendation to switch from log input type to filestream as log is deprecated. My problem is that filestream apparently does not includes tail\_files config optio…

---

## [Is there any way to exclude Windows Drive on the metricbeat configuration?](https://discuss.elastic.co/t/is-there-any-way-to-exclude-windows-drive-on-the-metricbeat-configuration/296547)

<div class="topic-metadata">

**Author:** [@Gustavo\_Garcia](https://discuss.elastic.co/u/Gustavo_Garcia)\
**Replies:** 0\
**Last updated:** [February 8, 2022, 4:28am UTC](https://discuss.elastic.co/t/is-there-any-way-to-exclude-windows-drive-on-the-metricbeat-configuration/296547 "2022-02-08T04:28:09Z")

</div>

Hello everyone, I have some Windows Servers that have SWAP (pagefile.sys) configured and located in a small disk. As this is a "Standard Configuration" there are lot of events related to this as the disk is almost full …

---

## [지난달 인덱스 생성하는 방법](https://discuss.elastic.co/t/topic/296539)

<div class="topic-metadata">

**Author:** [@m2seo81](https://discuss.elastic.co/u/m2seo81)\
**Replies:** 0\
**Last updated:** [February 8, 2022, 2:27am UTC](https://discuss.elastic.co/t/topic/296539 "2022-02-08T02:27:18Z")

</div>

filebeat 인덱스가 매일 하나씩 쌓여서 index limit 1000 오류가 발생하였습니다. 인덱스를 월별로 만들게 수정하였는데 2월달 데이터는 수집이 되었는데 1월달 인덱스가 생성이 되지 않는 문제가 발생했습니다. 지난달의 인덱스를 어떻게 생성해야 하나요? filebeat - logstash - Elasticsearch로 구성되어 있는 구조입니다.

---

## [Errors Using Iptables Module](https://discuss.elastic.co/t/errors-using-iptables-module/296501)

<div class="topic-metadata">

**Author:** [@Jarbird](https://discuss.elastic.co/u/Jarbird)\
**Replies:** 1\
**Last updated:** [February 8, 2022, 1:50am UTC](https://discuss.elastic.co/t/errors-using-iptables-module/296501 "2022-02-08T01:50:11Z")

</div>

Hello, I have been on a journey trying to use the iptables module in filebeat 7.16.3. I suspected the distro I'm using was not installing something right, specifically missing the modules/iptables directory. I then trie…

---

## [Metricbeat zfs datasets](https://discuss.elastic.co/t/metricbeat-zfs-datasets/296495)

<div class="topic-metadata">

**Author:** [@Combo12](https://discuss.elastic.co/u/Combo12)\
**Replies:** 0\
**Last updated:** [February 7, 2022, 4:17pm UTC](https://discuss.elastic.co/t/metricbeat-zfs-datasets/296495 "2022-02-07T16:17:05Z")

</div>

hi! As per https://github.com/elastic/beats/issues/25725 it doesn't seem to be a built-in solution for monitoring ZFS datasets with metricbeat. Do you have any idea on what's the best way on doing it other than the fol…

---

## [Bizarre Error: bash: ./filebeat: No such file or directory](https://discuss.elastic.co/t/bizarre-error-bash-filebeat-no-such-file-or-directory/296407)

<div class="topic-metadata">

**Author:** [@Jarbird](https://discuss.elastic.co/u/Jarbird)\
**Replies:** 2\
**Last updated:** [February 7, 2022, 3:39pm UTC](https://discuss.elastic.co/t/bizarre-error-bash-filebeat-no-such-file-or-directory/296407 "2022-02-07T15:39:03Z")

</div>

So this is a surreal one... I am having issues with modules not working, and I suspect an unnamed distribution is packaging and/or installing it wrong. At my wits end I decided to manually download the precompiled binari…

---

## [Osquery Live queries: windows endpoints not responding 'action undefined'](https://discuss.elastic.co/t/osquery-live-queries-windows-endpoints-not-responding-action-undefined/296087)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 7\
**Last updated:** [February 7, 2022, 2:40pm UTC](https://discuss.elastic.co/t/osquery-live-queries-windows-endpoints-not-responding-action-undefined/296087 "2022-02-07T14:40:39Z")

</div>

Hello, I installed Osquery manager integration on my endpoints, for linux it worked like magic, while on the windows I get the following results With no errors reported on log files (elastic-agent, osquerybeat, o…

---

## [Filebeat -\> elastic: onConnect callback failed: error loading template](https://discuss.elastic.co/t/filebeat-elastic-onconnect-callback-failed-error-loading-template/296121)

<div class="topic-metadata">

**Author:** [@mevan](https://discuss.elastic.co/u/mevan)\
**Replies:** 2\
**Last updated:** [February 7, 2022, 2:10pm UTC](https://discuss.elastic.co/t/filebeat-elastic-onconnect-callback-failed-error-loading-template/296121 "2022-02-07T14:10:52Z")

</div>

I have followed the instructions here: Grant privileges and roles needed for publishing | Filebeat Reference \[7.17\] | Elastic I have setup.ilm.check\_exists: false set in /etc/filebeat/filebeat.yml See screenshot of my …

---

## [Stalled in creating a new beat](https://discuss.elastic.co/t/stalled-in-creating-a-new-beat/296301)

<div class="topic-metadata">

**Author:** [@YUAN\_YE](https://discuss.elastic.co/u/YUAN_YE)\
**Replies:** 1\
**Last updated:** [February 7, 2022, 1:26pm UTC](https://discuss.elastic.co/t/stalled-in-creating-a-new-beat/296301 "2022-02-07T13:26:38Z")

</div>

I pushed the Beat version back to 7.15 to try to create a new beat, but it stalled while executing the Mage GenerateCustomBeat as per the tutorial I've tried again many times, but each time I get stuck in the same pl…

---

## [Force field processing as "double" instead of "long"](https://discuss.elastic.co/t/force-field-processing-as-double-instead-of-long/296220)

<div class="topic-metadata">

**Author:** [@Dror\_Tirosh](https://discuss.elastic.co/u/Dror_Tirosh)\
**Replies:** 2\
**Last updated:** [February 7, 2022, 1:23pm UTC](https://discuss.elastic.co/t/force-field-processing-as-double-instead-of-long/296220 "2022-02-07T13:23:49Z")

</div>

I try to load json-structured logs using filebeat into kibana. it parses OK, but some values are numeric with very large numbers. filebeat complains that Value \[40000000000000000000\] is out of range for a long"}}, dro…

---

## [How to prevent duplicates in filebeat](https://discuss.elastic.co/t/how-to-prevent-duplicates-in-filebeat/296391)

<div class="topic-metadata">

**Author:** [@Dror\_Tirosh](https://discuss.elastic.co/u/Dror_Tirosh)\
**Replies:** 2\
**Last updated:** [February 7, 2022, 10:46am UTC](https://discuss.elastic.co/t/how-to-prevent-duplicates-in-filebeat/296391 "2022-02-07T10:46:42Z")

</div>

My input data (which is json-formatted) as a unique field. According to the documentation, this should use it as a unique identifier, and thus pervent duplicates: processor: - fingerprint: fields: \["tx"\] target…

---

## [Beginner here; how do I](https://discuss.elastic.co/t/beginner-here-how-do-i/292514)

<div class="topic-metadata">

**Author:** [@end-user](https://discuss.elastic.co/u/end-user)\
**Replies:** 26\
**Last updated:** [February 7, 2022, 12:34am UTC](https://discuss.elastic.co/t/beginner-here-how-do-i/292514 "2022-02-07T00:34:43Z")

</div>

I'm new to this stack ecosystem and I was hoping someone could point me to the elements that might fit my project. I have a command that I'd like to run on a schedule (like every 10 minutes) that generates some good met…

---

## [Elastic Stack setup with multiple instances of different Beats](https://discuss.elastic.co/t/elastic-stack-setup-with-multiple-instances-of-different-beats/296109)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 3\
**Last updated:** [February 6, 2022, 9:57pm UTC](https://discuss.elastic.co/t/elastic-stack-setup-with-multiple-instances-of-different-beats/296109 "2022-02-06T21:57:34Z")

</div>

Hello, we want to use multiple instances of the different Beats. (File, Metric, Winlog, Packet and Heart) Metricbeat on multiple servers for monitoring, Filebeat on multiple servers for logs and so on. They should col…

---

## [Threatintel/Misp var.filters type making filebeat service stop!](https://discuss.elastic.co/t/threatintel-misp-var-filters-type-making-filebeat-service-stop/296197)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 2\
**Last updated:** [February 6, 2022, 6:30pm UTC](https://discuss.elastic.co/t/threatintel-misp-var-filters-type-making-filebeat-service-stop/296197 "2022-02-06T18:30:59Z")

</div>

Hello, I'm using misp threatintel and i tried to filter data by type but filebeat is keep refusing the configuration and only starts if I remove the filters, even when I tried to use the same example proposed by docume…

---

## [Infoblox module parsing](https://discuss.elastic.co/t/infoblox-module-parsing/296336)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [February 4, 2022, 6:42pm UTC](https://discuss.elastic.co/t/infoblox-module-parsing/296336 "2022-02-04T18:42:28Z")

</div>

Hello, The Infoblox rsa module has 'a lot of room for improvement'.. Multiple fields are very badly parsed. For example a small extract of the network.interface.name field : As you can see there are multiple issues…

---

## [Filebeat as sidecar best practices](https://discuss.elastic.co/t/filebeat-as-sidecar-best-practices/296289)

<div class="topic-metadata">

**Author:** [@rpetre](https://discuss.elastic.co/u/rpetre)\
**Replies:** 0\
**Last updated:** [February 4, 2022, 12:04pm UTC](https://discuss.elastic.co/t/filebeat-as-sidecar-best-practices/296289 "2022-02-04T12:04:06Z")

</div>

I'm using filebeat inside of kubernetes both as daemonset (to capture stdout of all containers), but also as sidecar in specific pods, to ship application logs that are written to shared volumes. The documentation is som…

---

## [Custom logs multiline](https://discuss.elastic.co/t/custom-logs-multiline/295280)

<div class="topic-metadata">

**Author:** [@Requium](https://discuss.elastic.co/u/Requium)\
**Replies:** 1\
**Last updated:** [February 4, 2022, 9:10am UTC](https://discuss.elastic.co/t/custom-logs-multiline/295280 "2022-02-04T09:10:19Z")

</div>

Im trying to add multiline to the custom log integration configuration for elastic agent, i tryied the following way: multiline.type: pattern multiline.pattern: '\[0-9\]{4}-\[0-9\]{2}-\[0-9\]{2}' multiline.negate: true multi…

---

## [Connection reset by peer when connecting to Elastic](https://discuss.elastic.co/t/connection-reset-by-peer-when-connecting-to-elastic/296065)

<div class="topic-metadata">

**Author:** [@brampurnot](https://discuss.elastic.co/u/brampurnot)\
**Replies:** 1\
**Last updated:** [February 3, 2022, 9:14pm UTC](https://discuss.elastic.co/t/connection-reset-by-peer-when-connecting-to-elastic/296065 "2022-02-03T21:14:58Z")

</div>

Hi all, I'm trying to setup Heartbeat without Logstash (directly integrated into Elastic ECK) on a kubernetes platform. When the pod is starting, I can see the following error message: Failed to connect to backoff(Ela…

---

## [Connecting Winlogbeat to Elasticsearch over Hibachi virtual lan](https://discuss.elastic.co/t/connecting-winlogbeat-to-elasticsearch-over-hibachi-virtual-lan/296224)

<div class="topic-metadata">

**Author:** [@gicetek](https://discuss.elastic.co/u/gicetek)\
**Replies:** 0\
**Last updated:** [February 3, 2022, 7:52pm UTC](https://discuss.elastic.co/t/connecting-winlogbeat-to-elasticsearch-over-hibachi-virtual-lan/296224 "2022-02-03T19:52:24Z")

</div>

Good day! I'm managing a number of Windows 10 consultant systems that are not domain connected. As part of my duties I needed to connect these hosts and I chose Hamachi as a way to provide for a nice virtual lan. I'm pl…

---

## [GROK Issue between Kibana Console and Pipeline](https://discuss.elastic.co/t/grok-issue-between-kibana-console-and-pipeline/296208)

<div class="topic-metadata">

**Author:** [@kamandohl](https://discuss.elastic.co/u/kamandohl)\
**Replies:** 0\
**Last updated:** [February 3, 2022, 2:47pm UTC](https://discuss.elastic.co/t/grok-issue-between-kibana-console-and-pipeline/296208 "2022-02-03T14:47:41Z")

</div>

Data Set 192.168.0.0 - - \[03/Feb/2022:11:14:38 +0000\] \\"/I/went/to/your/house.html HTTP/1.1\\" 200 109 \\"https://https://grokdebug.herokuapp.com//\\" \\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, …

---

## [Data collection from Proxmox](https://discuss.elastic.co/t/data-collection-from-proxmox/295469)

<div class="topic-metadata">

**Author:** [@vovan13111](https://discuss.elastic.co/u/vovan13111)\
**Replies:** 3\
**Last updated:** [February 3, 2022, 2:47pm UTC](https://discuss.elastic.co/t/data-collection-from-proxmox/295469 "2022-02-03T14:47:09Z")

</div>

Good afternoon. When studying metricbeat for the ability to collect data from kvm, the question arose, will the ability to collect data from proxmox be added, like from vSphere? If this is already possible, then please …

---

## [Upload Windows Event Logs](https://discuss.elastic.co/t/upload-windows-event-logs/295930)

<div class="topic-metadata">

**Author:** [@smam](https://discuss.elastic.co/u/smam)\
**Replies:** 4\
**Last updated:** [February 3, 2022, 12:26pm UTC](https://discuss.elastic.co/t/upload-windows-event-logs/295930 "2022-02-03T12:26:31Z")

</div>

Hello, Where do I find files that i sent via winlogbeat when using the Elasticsearch output? Can I add indexes? And how could I send just a selection of files, that is e.g. stored in some directory? I tried: - name: …

---

## [Configure Beats to only see certain fields in Elasticsearch](https://discuss.elastic.co/t/configure-beats-to-only-see-certain-fields-in-elasticsearch/296161)

<div class="topic-metadata">

**Author:** [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Replies:** 2\
**Last updated:** [February 3, 2022, 9:55am UTC](https://discuss.elastic.co/t/configure-beats-to-only-see-certain-fields-in-elasticsearch/296161 "2022-02-03T09:55:18Z")

</div>

Hi Guys, first of all, I do apologize if this is something that had been answered in the past. What I'm trying to achieve is the following - let's take the Winlogbeat as an example: I'm only interested to see what typ…

---

## [Filebeat cannot assign requested address](https://discuss.elastic.co/t/filebeat-cannot-assign-requested-address/296137)

<div class="topic-metadata">

**Author:** [@sulfred](https://discuss.elastic.co/u/sulfred)\
**Replies:** 4\
**Last updated:** [February 3, 2022, 9:25am UTC](https://discuss.elastic.co/t/filebeat-cannot-assign-requested-address/296137 "2022-02-03T09:25:08Z")

</div>

I am trying to read the syslog information by filebeat. I have my filebeat installed in docker. I get error message ERROR \[syslog\] syslog/input.go:150 Error starting the servererrorlisten tcp 192.168.1.142:…

---

## [Transfer message via filebeat](https://discuss.elastic.co/t/transfer-message-via-filebeat/288793)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 9\
**Last updated:** [February 3, 2022, 9:06am UTC](https://discuss.elastic.co/t/transfer-message-via-filebeat/288793 "2022-02-03T09:06:39Z")

</div>

Lines passed by filebeat are not processed correctly. Part of the line sometimes breaks up into several parts, part of the message arrives, and the other can be shaken altogether. original file Network Management Card…

---

## [Elastic Agent Standalone Kubernetes ICMP Check; Heartbeat won't Start](https://discuss.elastic.co/t/elastic-agent-standalone-kubernetes-icmp-check-heartbeat-wont-start/296005)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 5\
**Last updated:** [February 2, 2022, 11:30pm UTC](https://discuss.elastic.co/t/elastic-agent-standalone-kubernetes-icmp-check-heartbeat-wont-start/296005 "2022-02-02T23:30:55Z")

</div>

Hi All, I'm trying to setup a standalone Elastic Agent config on Kubernetes, but am running into an issue where Heartbeat doesn't start, and eventually enters a failed state. Elastic Agent: 7.16.2 ECK: 1.9.1 Elastics…

---

## [Ansible deployment of Filebeat](https://discuss.elastic.co/t/ansible-deployment-of-filebeat/296132)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 0\
**Last updated:** [February 2, 2022, 10:35pm UTC](https://discuss.elastic.co/t/ansible-deployment-of-filebeat/296132 "2022-02-02T22:35:22Z")

</div>

I was wondering if it was recommended to deploy filebeat through ansible. I am interested in installing and configuring filebeat on multiple machines (each with different log configurations), however I can't seem to find…

---

## [Google Workspace Setup](https://discuss.elastic.co/t/google-workspace-setup/293581)

<div class="topic-metadata">

**Author:** [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Replies:** 4\
**Last updated:** [February 2, 2022, 8:43pm UTC](https://discuss.elastic.co/t/google-workspace-setup/293581 "2022-02-02T20:43:17Z")

</div>

Hello, I'm attempting to start up the Google Workspace Audit Reports Integration in fleet and have successfully followed the steps to create service accounts, grant API access and oAuth IDs. I also have the json file fo…

---

## [Fleet Agent not showing logs - Fleet Agent not opening port syslog (panw module - filebeat)](https://discuss.elastic.co/t/fleet-agent-not-showing-logs-fleet-agent-not-opening-port-syslog-panw-module-filebeat/296111)

<div class="topic-metadata">

**Author:** [@AMe](https://discuss.elastic.co/u/AMe)\
**Replies:** 1\
**Last updated:** [February 2, 2022, 7:23pm UTC](https://discuss.elastic.co/t/fleet-agent-not-showing-logs-fleet-agent-not-opening-port-syslog-panw-module-filebeat/296111 "2022-02-02T19:23:31Z")

</div>

Elastic Agent has not opened the port for Syslog to receive data. Fleet integration - filebeat module - Palo Alto firewall network (panw) - via Syslog. Use Case: I set up a fleet server, created a new policy and added …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=107)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=109)
