# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=109

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 110

---

## [Metricbeat 7.16.3 error determining cgroups version: error reading /proc/\<PID\>/cgroup:](https://discuss.elastic.co/t/metricbeat-7-16-3-error-determining-cgroups-version-error-reading-proc-pid-cgroup/296100)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 0\
**Last updated:** [February 2, 2022, 4:55pm UTC](https://discuss.elastic.co/t/metricbeat-7-16-3-error-determining-cgroups-version-error-reading-proc-pid-cgroup/296100 "2022-02-02T16:55:45Z")

</div>

These errors keep being generated in the metricbeat logs. 2022-02-02T16:11:02.411Z ERROR metrics/metrics.go:304 error determining cgroups version: error reading /proc/3950736/cgroup: open /proc/3950736/cgroup:…

---

## [Process custom logs format](https://discuss.elastic.co/t/process-custom-logs-format/296092)

<div class="topic-metadata">

**Author:** [@MHQurashi](https://discuss.elastic.co/u/MHQurashi)\
**Replies:** 0\
**Last updated:** [February 2, 2022, 4:28pm UTC](https://discuss.elastic.co/t/process-custom-logs-format/296092 "2022-02-02T16:28:49Z")

</div>

Hi I’m trying to ingest log files with custom format so the line looks like this: \[date and time\]\[tab\]\[info1\]\[tab\]\[info2\]\[pipe\]\[info3\]\[pipe\]\[info4\] So separators are mix of tabs and pipes. Not to mention that last inf…

---

## [Filebeat filtering, drop event processor script](https://discuss.elastic.co/t/filebeat-filtering-drop-event-processor-script/295538)

<div class="topic-metadata">

**Author:** [@finiteAutomate](https://discuss.elastic.co/u/finiteAutomate)\
**Replies:** 11\
**Last updated:** [February 2, 2022, 10:58am UTC](https://discuss.elastic.co/t/filebeat-filtering-drop-event-processor-script/295538 "2022-02-02T10:58:57Z")

</div>

Hello team, Im new on filebeat and i want to ask about processor script on filebeat. I have a log file that contains some event.code. i want to exclude 3 event code based on this condition below from my log event.code…

---

## [Filebeat: Exiting: Error while initializing input: Error creating input. No such input type exist: 'aws-cloudwatch'](https://discuss.elastic.co/t/filebeat-exiting-error-while-initializing-input-error-creating-input-no-such-input-type-exist-aws-cloudwatch/295942)

<div class="topic-metadata">

**Author:** [@h4rdl0ck](https://discuss.elastic.co/u/h4rdl0ck)\
**Replies:** 7\
**Last updated:** [February 2, 2022, 10:24am UTC](https://discuss.elastic.co/t/filebeat-exiting-error-while-initializing-input-error-creating-input-no-such-input-type-exist-aws-cloudwatch/295942 "2022-02-02T10:24:30Z")

</div>

Hello everyone, filebeat stopped because it supposedly doesn't exist for the input type aws-cloudwatch. That's the error-messsage: 2022-02-01T11:02:36.673Z ERROR instance/beat.go:933 Exiting: Error while initializing i…

---

## [Elastic-agent - Elasticsearch node monitoring with Elasticsearch integration](https://discuss.elastic.co/t/elastic-agent-elasticsearch-node-monitoring-with-elasticsearch-integration/295081)

<div class="topic-metadata">

**Author:** [@fselim](https://discuss.elastic.co/u/fselim)\
**Replies:** 2\
**Last updated:** [February 2, 2022, 9:34am UTC](https://discuss.elastic.co/t/elastic-agent-elasticsearch-node-monitoring-with-elasticsearch-integration/295081 "2022-02-02T09:34:24Z")

</div>

Hello, I'm new to the concept of the elastic-agent and I've read through the documentation. With that I've spinned up a fleet server with functioning APM integration and system logs/metrics collection. Now I'm coming t…

---

## [Same IPs are showing in stack monitoring](https://discuss.elastic.co/t/same-ips-are-showing-in-stack-monitoring/295803)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 3\
**Last updated:** [February 2, 2022, 5:37am UTC](https://discuss.elastic.co/t/same-ips-are-showing-in-stack-monitoring/295803 "2022-02-02T05:37:09Z")

</div>

Running ELK stack 7.15.2 version I have 3 master node and 3 data nodes and 2 warm nodes.Metricbeat is running in all master nodes.Metricbeat version is 7.15.2. /etc/metricbeat/metricbeat.yml file #####################…

---

## [Tagging events with extracts from grok patterns](https://discuss.elastic.co/t/tagging-events-with-extracts-from-grok-patterns/296004)

<div class="topic-metadata">

**Author:** [@zach\_trio](https://discuss.elastic.co/u/zach_trio)\
**Replies:** 0\
**Last updated:** [February 1, 2022, 9:11pm UTC](https://discuss.elastic.co/t/tagging-events-with-extracts-from-grok-patterns/296004 "2022-02-01T21:11:19Z")

</div>

Hi all, I am using Filebeat to pass logs to Logstash for parsing and ingestion into Elasticsearch. Take this config extract for example: filebeat.inputs: - type: filestream paths: - /opt/containers/sites/\*/html/var…

---

## [Decode\_xml fails on UTF-16 formatted input](https://discuss.elastic.co/t/decode-xml-fails-on-utf-16-formatted-input/295996)

<div class="topic-metadata">

**Author:** [@mesposito](https://discuss.elastic.co/u/mesposito)\
**Replies:** 0\
**Last updated:** [February 1, 2022, 8:17pm UTC](https://discuss.elastic.co/t/decode-xml-fails-on-utf-16-formatted-input/295996 "2022-02-01T20:17:21Z")

</div>

Hi, I am facing an issue where xml\_decode and xml\_decode\_wineventlog fail to parse input data when it is in UTF-16. The following errors are produced: failed in decode\_xml on the "winlog.event\_data.TaskContent" field: e…

---

## [Logs not being harvested after agent restart](https://discuss.elastic.co/t/logs-not-being-harvested-after-agent-restart/294579)

<div class="topic-metadata">

**Author:** [@yelloyonder](https://discuss.elastic.co/u/yelloyonder)\
**Replies:** 9\
**Last updated:** [February 1, 2022, 10:30am UTC](https://discuss.elastic.co/t/logs-not-being-harvested-after-agent-restart/294579 "2022-02-01T10:30:45Z")

</div>

Hi, We are using Elastic Agent to collect logs using the Custom Logs integration. This is on Elastic Cloud. The agent servers are turned off nightly. When the servers come up and the elastic-agent service is started, F…

---

## [Elastic 3node cluster elastic agent configurations](https://discuss.elastic.co/t/elastic-3node-cluster-elastic-agent-configurations/295771)

<div class="topic-metadata">

**Author:** [@Sithija](https://discuss.elastic.co/u/Sithija)\
**Replies:** 1\
**Last updated:** [January 31, 2022, 11:41pm UTC](https://discuss.elastic.co/t/elastic-3node-cluster-elastic-agent-configurations/295771 "2022-01-31T23:41:41Z")

</div>

when elastic running on 3 node cluster and connect the elastic agents to node 1,what if node 1 is down and how to get the logs from agents that connect to node 1?

---

## [Metricbeat Windows Not Reporting File Systems](https://discuss.elastic.co/t/metricbeat-windows-not-reporting-file-systems/295871)

<div class="topic-metadata">

**Author:** [@sdf301](https://discuss.elastic.co/u/sdf301)\
**Replies:** 0\
**Last updated:** [January 31, 2022, 7:33pm UTC](https://discuss.elastic.co/t/metricbeat-windows-not-reporting-file-systems/295871 "2022-01-31T19:33:43Z")

</div>

I have been trying to install Metricbeat (7.16.3) on a Windows 10 system and can't seem to get any file system information. It was running fine for a while but I needed to reinstall it and can't get it working properly a…

---

## [Iptables module not working - filebeat or elastic?](https://discuss.elastic.co/t/iptables-module-not-working-filebeat-or-elastic/295788)

<div class="topic-metadata">

**Author:** [@mevan](https://discuss.elastic.co/u/mevan)\
**Replies:** 1\
**Last updated:** [January 31, 2022, 2:13pm UTC](https://discuss.elastic.co/t/iptables-module-not-working-filebeat-or-elastic/295788 "2022-01-31T14:13:50Z")

</div>

I'm using filebeat/elastic/kibana 7.16.3 all on the same Ubuntu 20.04.3. I am receiving logs from a number of clients using the filebeat nginx and system modules but I'm having trouble with the iptables module. \*\*\* I do …

---

## [Filebeat as DaemonSet in k8s cluser](https://discuss.elastic.co/t/filebeat-as-daemonset-in-k8s-cluser/295821)

<div class="topic-metadata">

**Author:** [@morb](https://discuss.elastic.co/u/morb)\
**Replies:** 0\
**Last updated:** [January 31, 2022, 10:39am UTC](https://discuss.elastic.co/t/filebeat-as-daemonset-in-k8s-cluser/295821 "2022-01-31T10:39:39Z")

</div>

Hi So I'm using helm to deploy filebeat on k8s cluster. I using bitami helm chart daemonset: Annotations to apply to the daemonset annotations: {} additionals labels labels: {} affinity: {} Include the daemonset e…

---

## [Filtering setup for docker containers not working](https://discuss.elastic.co/t/filtering-setup-for-docker-containers-not-working/295573)

<div class="topic-metadata">

**Author:** [@mitlonik](https://discuss.elastic.co/u/mitlonik)\
**Replies:** 3\
**Last updated:** [January 31, 2022, 6:27am UTC](https://discuss.elastic.co/t/filtering-setup-for-docker-containers-not-working/295573 "2022-01-31T06:27:14Z")

</div>

filtering setup for docker containers not working. I started Elastic Stack without anybody additional settings. And here are my filebeat settings: filebeat.yml filebeat.autodiscover: providers: - type: docker …

---

## [Can I use a filebeat server for centralize log collected data from many different devices?](https://discuss.elastic.co/t/can-i-use-a-filebeat-server-for-centralize-log-collected-data-from-many-different-devices/295541)

<div class="topic-metadata">

**Author:** [@siranee.ja](https://discuss.elastic.co/u/siranee.ja)\
**Replies:** 4\
**Last updated:** [January 31, 2022, 6:16am UTC](https://discuss.elastic.co/t/can-i-use-a-filebeat-server-for-centralize-log-collected-data-from-many-different-devices/295541 "2022-01-31T06:16:54Z")

</div>

This is my example infra as the question. Fortinet device Haproxy Server Apache Server A filebeat server An ELK stack server device a filebeat server …

---

## [No iptables in elasticsearch](https://discuss.elastic.co/t/no-iptables-in-elasticsearch/295770)

<div class="topic-metadata">

**Author:** [@mevan](https://discuss.elastic.co/u/mevan)\
**Replies:** 1\
**Last updated:** [January 30, 2022, 9:38pm UTC](https://discuss.elastic.co/t/no-iptables-in-elasticsearch/295770 "2022-01-30T21:38:13Z")

</div>

I'm very new to filebeat/Elasticsearch so unsure how to debug this. I have filebeat, Elasticsearch and kibana working. I can see many of my logs being ingested from /var/log/syslog. However, although I have the iptables …

---

## [Delete registry on fleet filebeat](https://discuss.elastic.co/t/delete-registry-on-fleet-filebeat/295756)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 0\
**Last updated:** [January 29, 2022, 3:44pm UTC](https://discuss.elastic.co/t/delete-registry-on-fleet-filebeat/295756 "2022-01-29T15:44:09Z")

</div>

Hello, how can I delete the registry to re-index the same log files again? Deleting the integration didnt work. Thanks

---

## [Filebeat filestream input parsers multiline fails](https://discuss.elastic.co/t/filebeat-filestream-input-parsers-multiline-fails/290543)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 18\
**Last updated:** [January 29, 2022, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-filestream-input-parsers-multiline-fails/290543 "2022-01-29T14:31:30Z")

</div>

Hello This is filebeat 7.15.0. I have configured several filebeat log inputs with multiline patterns and it works. Next I change the input type to filestream, while following the documentation. However, when starting t…

---

## [Filebeat with Large Registry/State File Causes \`runtime: program exceeds 10000-thread limit\` on Startup](https://discuss.elastic.co/t/filebeat-with-large-registry-state-file-causes-runtime-program-exceeds-10000-thread-limit-on-startup/295738)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 1\
**Last updated:** [January 29, 2022, 1:29am UTC](https://discuss.elastic.co/t/filebeat-with-large-registry-state-file-causes-runtime-program-exceeds-10000-thread-limit-on-startup/295738 "2022-01-29T01:29:55Z")

</div>

Hi All, I'm seeing an issue, where a Filebeat instead with a large registrar (~33k entries). {"level":"info","timestamp":"2022-01-29T00:32:41.799Z","logger":"registrar","caller":"registrar/registrar.go:109","message":"…

---

## [Assign timestamp value to field in filebeat](https://discuss.elastic.co/t/assign-timestamp-value-to-field-in-filebeat/295734)

<div class="topic-metadata">

**Author:** [@jpfreyen](https://discuss.elastic.co/u/jpfreyen)\
**Replies:** 0\
**Last updated:** [January 29, 2022, 12:08am UTC](https://discuss.elastic.co/t/assign-timestamp-value-to-field-in-filebeat/295734 "2022-01-29T00:08:11Z")

</div>

Hello, Is there a way for me to assign the timestamp value to an add\_field? Like for example: processors: - add\_fields: fields: collectiontime: "@timestamp" This example doesn't work because when I check th…

---

## [\[Winlogbeat\] won't exit; winlogbeat JSON output size is different for same file](https://discuss.elastic.co/t/winlogbeat-wont-exit-winlogbeat-json-output-size-is-different-for-same-file/295706)

<div class="topic-metadata">

**Author:** [@ashimmahara](https://discuss.elastic.co/u/ashimmahara)\
**Replies:** 2\
**Last updated:** [January 28, 2022, 5:03pm UTC](https://discuss.elastic.co/t/winlogbeat-wont-exit-winlogbeat-json-output-size-is-different-for-same-file/295706 "2022-01-28T17:03:17Z")

</div>

Program: Winlogbeat Version: 7.16.3 Operating System: Windows 11 Pro Version 21H2 Build 22000.438 I am trying to convert some archived evtx files to JSON using winlogbeat, however, winlogbeat isn't exiting after proce…

---

## [Elastic Agent RPM and Fleet](https://discuss.elastic.co/t/elastic-agent-rpm-and-fleet/294559)

<div class="topic-metadata">

**Author:** [@thleh](https://discuss.elastic.co/u/thleh)\
**Replies:** 1\
**Last updated:** [January 28, 2022, 3:08pm UTC](https://discuss.elastic.co/t/elastic-agent-rpm-and-fleet/294559 "2022-01-28T15:08:31Z")

</div>

Hi all, i have installed elastic agent on a couple of linux servers. I used the rpm package from repository as installation source and restired the agend afterwards in fleet management. The status of agents are Healthy…

---

## [Filebeat - Multiple VPC logs from different S3 buckets not working](https://discuss.elastic.co/t/filebeat-multiple-vpc-logs-from-different-s3-buckets-not-working/292711)

<div class="topic-metadata">

**Author:** [@antondubek](https://discuss.elastic.co/u/antondubek)\
**Replies:** 14\
**Last updated:** [January 28, 2022, 2:54pm UTC](https://discuss.elastic.co/t/filebeat-multiple-vpc-logs-from-different-s3-buckets-not-working/292711 "2022-01-28T14:54:45Z")

</div>

HI All, Within our AWS account, we have 2 VPC's that output flow logs into individual separate S3 buckets. I have enabled event notifications and connected them to SQS which all works. I also have WAF and ALB logs which…

---

## [Auditbeat Conditional Processing if then else](https://discuss.elastic.co/t/auditbeat-conditional-processing-if-then-else/295697)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [January 28, 2022, 11:49am UTC](https://discuss.elastic.co/t/auditbeat-conditional-processing-if-then-else/295697 "2022-01-28T11:49:31Z")

</div>

For reference on what works and what doesn't in processors in auditbeat. Adding multiple conditions(like an OR condition) works fine like this: processors: - if: equals: process.executable: "/home/…

---

## [Journalbeat is being stuck](https://discuss.elastic.co/t/journalbeat-is-being-stuck/295312)

<div class="topic-metadata">

**Author:** [@qwinkler](https://discuss.elastic.co/u/qwinkler)\
**Replies:** 2\
**Last updated:** [January 28, 2022, 10:33am UTC](https://discuss.elastic.co/t/journalbeat-is-being-stuck/295312 "2022-01-28T10:33:36Z")

</div>

Journalbeat stuck for an unknown reason. Also, this only happens on the nodes with more logs than on the other ones. There are around 5 logs per second (which I don't think is a big load), but still. Here is an actual b…

---

## [Winlogbeat output config problems](https://discuss.elastic.co/t/winlogbeat-output-config-problems/295628)

<div class="topic-metadata">

**Author:** [@jlareos](https://discuss.elastic.co/u/jlareos)\
**Replies:** 5\
**Last updated:** [January 28, 2022, 10:21am UTC](https://discuss.elastic.co/t/winlogbeat-output-config-problems/295628 "2022-01-28T10:21:01Z")

</div>

Hi everyone! I have installed in a VMWare machine the Security Onion OS. On the same machine i have installed winlogbeat and i'm having problems with the yml file. When i execute this command ./winlogbeat test config …

---

## [Filebeat. "from kafka to kafka transfer"](https://discuss.elastic.co/t/filebeat-from-kafka-to-kafka-transfer/295342)

<div class="topic-metadata">

**Author:** [@faringot](https://discuss.elastic.co/u/faringot)\
**Replies:** 8\
**Last updated:** [January 28, 2022, 7:31am UTC](https://discuss.elastic.co/t/filebeat-from-kafka-to-kafka-transfer/295342 "2022-01-28T07:31:26Z")

</div>

Good day, I'm trying to set up data transfer from one Kafka to another using Filebeat. The current version does not work with SASL\_SSL and I have downloaded 8.0.0-rc1. Found a new error: "Exiting: module kafka is confi…

---

## [Osquery manger integration won't work on Windows](https://discuss.elastic.co/t/osquery-manger-integration-wont-work-on-windows/295529)

<div class="topic-metadata">

**Author:** [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Replies:** 3\
**Last updated:** [January 27, 2022, 3:03pm UTC](https://discuss.elastic.co/t/osquery-manger-integration-wont-work-on-windows/295529 "2022-01-27T15:03:44Z")

</div>

Hi, I have unsuccessfully been trying to integrate Osquery to elastic-agent on windows but every time I enroll an agent, its status changes to unhealthy a few seconds after enrolling. The log file is ful…

---

## ["url.full" field not viewing in Packetbeat 7.16.3](https://discuss.elastic.co/t/url-full-field-not-viewing-in-packetbeat-7-16-3/294954)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 3\
**Last updated:** [January 27, 2022, 1:18pm UTC](https://discuss.elastic.co/t/url-full-field-not-viewing-in-packetbeat-7-16-3/294954 "2022-01-27T13:18:38Z")

</div>

Hi, I've upgraded Packetbeat version from 7.16.0 to 7.16.3 but since then I've never seen the url.full: field in the packetbeats logs although: 1- I'm visiting urls to have some traffic which should log the url.full: f…

---

## [If then else not working in FileBeat processor](https://discuss.elastic.co/t/if-then-else-not-working-in-filebeat-processor/295560)

<div class="topic-metadata">

**Author:** [@ziv1](https://discuss.elastic.co/u/ziv1)\
**Replies:** 1\
**Last updated:** [January 27, 2022, 12:28pm UTC](https://discuss.elastic.co/t/if-then-else-not-working-in-filebeat-processor/295560 "2022-01-27T12:28:00Z")

</div>

I'm trying to setup some processors in a filebeat.yml to process some logs before sending to ELK. An important part of the processing is determining the "level" of the event, which is not always included in the line in …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=108)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=110)
