# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=110

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 111

---

## [Can't enroll an agent to create Fleet Server (no error shown in log)](https://discuss.elastic.co/t/cant-enroll-an-agent-to-create-fleet-server-no-error-shown-in-log/295375)

<div class="topic-metadata">

**Author:** [@David\_Canos](https://discuss.elastic.co/u/David_Canos)\
**Replies:** 4\
**Last updated:** [January 27, 2022, 8:03am UTC](https://discuss.elastic.co/t/cant-enroll-an-agent-to-create-fleet-server-no-error-shown-in-log/295375 "2022-01-27T08:03:50Z")

</div>

Im following all the steps in the process to create a fleet server in my own cluster. Logstash, elastic and kibana are working fine in https mode. But im not able to install a fleet. Im trying to enroll the agent in t…

---

## [Accessing specific datafields for Prometheus Exporter](https://discuss.elastic.co/t/accessing-specific-datafields-for-prometheus-exporter/295424)

<div class="topic-metadata">

**Author:** [@purple\_key](https://discuss.elastic.co/u/purple_key)\
**Replies:** 2\
**Last updated:** [January 27, 2022, 4:35am UTC](https://discuss.elastic.co/t/accessing-specific-datafields-for-prometheus-exporter/295424 "2022-01-27T04:35:15Z")

</div>

Using Postgres\_Exporter on my PSQL servers and piping them to the Prometheus MetricBeat with a sample config of # Module: prometheus # Docs: https://www.elastic.co/guide/en/beats/metricbeat/7.6/metricbeat-module-prometh…

---

## [Filebeat console repeat logs for filestream input](https://discuss.elastic.co/t/filebeat-console-repeat-logs-for-filestream-input/295435)

<div class="topic-metadata">

**Author:** [@zhiweiv](https://discuss.elastic.co/u/zhiweiv)\
**Replies:** 2\
**Last updated:** [January 27, 2022, 12:26am UTC](https://discuss.elastic.co/t/filebeat-console-repeat-logs-for-filestream-input/295435 "2022-01-27T00:26:17Z")

</div>

After switch input type from log to filestream, there are repeat logs every 10s in filebeat console like following: 2022-01-26T09:06:45.287Z \[file\_watcher\] filestream/fswatch.go:137 Start next scan 2022-01-26T09:06:55.2…

---

## [Could not create the CloudFormation stack request](https://discuss.elastic.co/t/could-not-create-the-cloudformation-stack-request/295437)

<div class="topic-metadata">

**Author:** [@Jason\_Zhang2](https://discuss.elastic.co/u/Jason_Zhang2)\
**Replies:** 4\
**Last updated:** [January 27, 2022, 1:12am UTC](https://discuss.elastic.co/t/could-not-create-the-cloudformation-stack-request/295437 "2022-01-27T01:12:01Z")

</div>

Hi, There We're trying to use functionbeat to add cloudwatch log into Elasticsearch. And it always gave this error 'Could not create the CloudFormation stack request'. This page mentioned that it's caused by region se…

---

## [Elastic Agent installed on Elastic Servers](https://discuss.elastic.co/t/elastic-agent-installed-on-elastic-servers/295489)

<div class="topic-metadata">

**Author:** [@bob.newell](https://discuss.elastic.co/u/bob.newell)\
**Replies:** 0\
**Last updated:** [January 26, 2022, 4:43pm UTC](https://discuss.elastic.co/t/elastic-agent-installed-on-elastic-servers/295489 "2022-01-26T16:43:41Z")

</div>

Is it possible to install the elastic agent on the elastic servers so that they can be included in the log data?

---

## [Metricbeat Index pattern](https://discuss.elastic.co/t/metricbeat-index-pattern/295340)

<div class="topic-metadata">

**Author:** [@Christer\_Palmen](https://discuss.elastic.co/u/Christer_Palmen)\
**Replies:** 2\
**Last updated:** [January 26, 2022, 3:41pm UTC](https://discuss.elastic.co/t/metricbeat-index-pattern/295340 "2022-01-26T15:41:32Z")

</div>

Hello. I have noticed some issues with my metricbeat dashboard. I installed metricbeat 7.14 in 57 hosts before Christmas and the dashboard worked fine. Went to Christmas holidays and came back with noticing an error m…

---

## [Logs are not received on the Fleet server](https://discuss.elastic.co/t/logs-are-not-received-on-the-fleet-server/295345)

<div class="topic-metadata">

**Author:** [@b.kaliuzhnyi](https://discuss.elastic.co/u/b.kaliuzhnyi)\
**Replies:** 4\
**Last updated:** [January 26, 2022, 3:02pm UTC](https://discuss.elastic.co/t/logs-are-not-received-on-the-fleet-server/295345 "2022-01-26T15:02:53Z")

</div>

The situation is similar to that of the link: https://discuss.elastic.co/t/elastic-agent-error/282706 I have installed two Elastic Agents, one of them as a Fleet server. Their status is Healthy. The fleet server policy…

---

## [Creating a Custom Beat](https://discuss.elastic.co/t/creating-a-custom-beat/295366)

<div class="topic-metadata">

**Author:** [@Markus\_Lindner](https://discuss.elastic.co/u/Markus_Lindner)\
**Replies:** 1\
**Last updated:** [January 26, 2022, 2:43pm UTC](https://discuss.elastic.co/t/creating-a-custom-beat/295366 "2022-01-26T14:43:36Z")

</div>

Hi, does someone have a current ( 2021 + ) documentation for creating a custom beat? Or an idea how I can deliver custom data to my elastic database? When i try to change a community beat, i cant make (make setup) it. …

---

## [Metricbeats can't recognize kubernetes dns](https://discuss.elastic.co/t/metricbeats-cant-recognize-kubernetes-dns/295389)

<div class="topic-metadata">

**Author:** [@Sebastian\_Randoll\_Le](https://discuss.elastic.co/u/Sebastian_Randoll_Le)\
**Replies:** 1\
**Last updated:** [January 26, 2022, 2:38pm UTC](https://discuss.elastic.co/t/metricbeats-cant-recognize-kubernetes-dns/295389 "2022-01-26T14:38:19Z")

</div>

Hello I'm using ECK 1.19 and I'm implementing monitoring with beat use the following: --- apiVersion: beat.k8s.elastic.co/v1beta1 kind: Beat metadata: name: metricbeat spec: type: metricbeat version: 7.16.2 ela…

---

## [All beats have missing documents or timestamp not accurate](https://discuss.elastic.co/t/all-beats-have-missing-documents-or-timestamp-not-accurate/295065)

<div class="topic-metadata">

**Author:** [@cctk](https://discuss.elastic.co/u/cctk)\
**Replies:** 6\
**Last updated:** [January 26, 2022, 1:38pm UTC](https://discuss.elastic.co/t/all-beats-have-missing-documents-or-timestamp-not-accurate/295065 "2022-01-26T13:38:51Z")

</div>

I am experiencing several documents missing after the upgrade to 7.0. Metricbeat dashboard used to show a regular update of the cpu and memory , however now it now shows a dash (-) for 1m before showing update. this make…

---

## [Duplicate Documents](https://discuss.elastic.co/t/duplicate-documents/295343)

<div class="topic-metadata">

**Author:** [@driveirk](https://discuss.elastic.co/u/driveirk)\
**Replies:** 2\
**Last updated:** [January 26, 2022, 10:15am UTC](https://discuss.elastic.co/t/duplicate-documents/295343 "2022-01-26T10:15:07Z")

</div>

If there are communication problems, then in some cases the logs come 2 or 3 times, all the logs of one call are duplicated. Functionbeat config: functionbeat: provider: aws: deploy\_bucket: functionbeat-dep…

---

## [Filebeats for configuration file](https://discuss.elastic.co/t/filebeats-for-configuration-file/295142)

<div class="topic-metadata">

**Author:** [@ratseba](https://discuss.elastic.co/u/ratseba)\
**Replies:** 4\
**Last updated:** [January 26, 2022, 6:16am UTC](https://discuss.elastic.co/t/filebeats-for-configuration-file/295142 "2022-01-26T06:16:21Z")

</div>

Hi, I need send content of config file from some service to Elasticsearch. This file not change often (max ten times a year). This file have structure like: version=77.1.2 ActiveModule=monitoring, tts, asr LicenseNumbe…

---

## [Ingest Json data into Elastic Search using filebeat](https://discuss.elastic.co/t/ingest-json-data-into-elastic-search-using-filebeat/293510)

<div class="topic-metadata">

**Author:** [@Magesh\_02](https://discuss.elastic.co/u/Magesh_02)\
**Replies:** 1\
**Last updated:** [January 26, 2022, 3:06am UTC](https://discuss.elastic.co/t/ingest-json-data-into-elastic-search-using-filebeat/293510 "2022-01-26T03:06:57Z")

</div>

I attempted to import data from a json file into Elasticsearch, but my filebeat had a configuration issue in filebeat.yml or an issue with the input Because my json is regular json, but filebeat only supports ndjson, Fi…

---

## [Fleet - selfhosted production mode 7.16.3](https://discuss.elastic.co/t/fleet-selfhosted-production-mode-7-16-3/294381)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 3\
**Last updated:** [January 26, 2022, 12:11am UTC](https://discuss.elastic.co/t/fleet-selfhosted-production-mode-7-16-3/294381 "2022-01-26T00:11:27Z")

</div>

Hello wonderful people, I'm looking into setting up fleet. So far I have a test server ready and I have generated the certificates using elasticsearch-certutil elasticsearch CA /etc/elasticsearch/certs/elastic-stack-c…

---

## [The Ingest Pipeline for 365 Defender doesn't populate hostname](https://discuss.elastic.co/t/the-ingest-pipeline-for-365-defender-doesnt-populate-hostname/294312)

<div class="topic-metadata">

**Author:** [@hinchliff](https://discuss.elastic.co/u/hinchliff)\
**Replies:** 1\
**Last updated:** [January 25, 2022, 5:39pm UTC](https://discuss.elastic.co/t/the-ingest-pipeline-for-365-defender-doesnt-populate-hostname/294312 "2022-01-25T17:39:51Z")

</div>

We're using the "Microsoft" module in Filebeat to collect data from Microsoft Defender -- both the "defender\_atp" and the "m365\_defender". We're also using the Ingest Pipelines provided via Filebeat to parse and process…

---

## [Pubsub input stopped - context deadline exceeded](https://discuss.elastic.co/t/pubsub-input-stopped-context-deadline-exceeded/293585)

<div class="topic-metadata">

**Author:** [@nitzang1](https://discuss.elastic.co/u/nitzang1)\
**Replies:** 1\
**Last updated:** [January 25, 2022, 4:25pm UTC](https://discuss.elastic.co/t/pubsub-input-stopped-context-deadline-exceeded/293585 "2022-01-25T16:25:00Z")

</div>

Hi all, I'm facing an issue where filebeat pubsub input stop pulling events just after throwing this error: 2022-01-05T15:30:24.404Z ERROR \[gcp.pubsub\] gcppubsub/input.go:141 context deadline exceeded {"pubsub\_project"…

---

## [SiemConnector with Filebeat problem](https://discuss.elastic.co/t/siemconnector-with-filebeat-problem/295365)

<div class="topic-metadata">

**Author:** [@Juan\_Fernandez\_Bernt](https://discuss.elastic.co/u/Juan_Fernandez_Bernt)\
**Replies:** 2\
**Last updated:** [January 25, 2022, 4:05pm UTC](https://discuss.elastic.co/t/siemconnector-with-filebeat-problem/295365 "2022-01-25T16:05:13Z")

</div>

Hello, im trying to use crowdstrike Siem Connector with filebeat. I've been checking some documentation but can't find a way to solve my problem. I think is kind of working but the field message looks like a bunch of h…

---

## [Auditbeat processor ignores drop\_event](https://discuss.elastic.co/t/auditbeat-processor-ignores-drop-event/294917)

<div class="topic-metadata">

**Author:** [@ziv1](https://discuss.elastic.co/u/ziv1)\
**Replies:** 3\
**Last updated:** [January 25, 2022, 1:28pm UTC](https://discuss.elastic.co/t/auditbeat-processor-ignores-drop-event/294917 "2022-01-25T13:28:11Z")

</div>

Hi, Trying to filter out some spam generated by auditbeat using a processor but it looks like, depending on how/where I set it up in the yml, it either completely ignores the processor, or stops processing events all to…

---

## [Fetch installed software details in Elasticsearch using elastic beats](https://discuss.elastic.co/t/fetch-installed-software-details-in-elasticsearch-using-elastic-beats/294527)

<div class="topic-metadata">

**Author:** [@Tirtharaj\_Karbotkar1](https://discuss.elastic.co/u/Tirtharaj_Karbotkar1)\
**Replies:** 3\
**Last updated:** [January 25, 2022, 11:13am UTC](https://discuss.elastic.co/t/fetch-installed-software-details-in-elasticsearch-using-elastic-beats/294527 "2022-01-25T11:13:27Z")

</div>

Hi all, I am trying to fetch installed software details from my system (windows) into the Elasticsearch. Does any one have idea how to do the same? I have tried using metricbeat but at most I can get the running proce…

---

## [Helm chart - readinessProbe failure without errors](https://discuss.elastic.co/t/helm-chart-readinessprobe-failure-without-errors/295091)

<div class="topic-metadata">

**Author:** [@aumthanki](https://discuss.elastic.co/u/aumthanki)\
**Replies:** 2\
**Last updated:** [January 24, 2022, 2:21pm UTC](https://discuss.elastic.co/t/helm-chart-readinessprobe-failure-without-errors/295091 "2022-01-24T14:21:39Z")

</div>

Hi, Has anyone been forced to tweak the readinessprobe for the filebeat chart? readinessProbe: exec: command: - sh - -c - | #!/usr/bin/env bash -e filebeat test output failureThreshold: 3 initialDelaySeconds: …

---

## [Extract the Key from MQTT JSON message](https://discuss.elastic.co/t/extract-the-key-from-mqtt-json-message/295185)

<div class="topic-metadata">

**Author:** [@folderman](https://discuss.elastic.co/u/folderman)\
**Replies:** 11\
**Last updated:** [January 25, 2022, 9:26am UTC](https://discuss.elastic.co/t/extract-the-key-from-mqtt-json-message/295185 "2022-01-25T09:26:11Z")

</div>

Hi All, I have a problem with my testing device support MQTT. Here is the MQTT message: {"device\_info": {"uuid": "XXXXXX","fw\_ver": "V1.5.0" },"measures": \[{"n":"co2", "u":"ppm", "v":1155.995},{"n":"voc", "u":"ppm", "v…

---

## [Metricbeat - Not creating any logfile](https://discuss.elastic.co/t/metricbeat-not-creating-any-logfile/295266)

<div class="topic-metadata">

**Author:** [@sujeetkp](https://discuss.elastic.co/u/sujeetkp)\
**Replies:** 0\
**Last updated:** [January 24, 2022, 5:59pm UTC](https://discuss.elastic.co/t/metricbeat-not-creating-any-logfile/295266 "2022-01-24T17:59:19Z")

</div>

I am trying to set up metric beat for my CentOS7 host. I have explictly mentioned the logfile location for the metricbeat and the logging level is debug, but I dont see a log file created. I can see the logs in journalct…

---

## [FileBeats Syslog not being sent to Elastic Cloud](https://discuss.elastic.co/t/filebeats-syslog-not-being-sent-to-elastic-cloud/295300)

<div class="topic-metadata">

**Author:** [@wekimop](https://discuss.elastic.co/u/wekimop)\
**Replies:** 0\
**Last updated:** [January 25, 2022, 4:43am UTC](https://discuss.elastic.co/t/filebeats-syslog-not-being-sent-to-elastic-cloud/295300 "2022-01-25T04:43:11Z")

</div>

Hello, i am trying to use the System integration in my Elastic Security agent to capture syslog data from /var/log/syslog file. I am also doing the same on another server but using a FileBeat instance, sending output to …

---

## [Functionbeat GCP pub/sub requiring storage entry point when only pub/sub is enabled](https://discuss.elastic.co/t/functionbeat-gcp-pub-sub-requiring-storage-entry-point-when-only-pub-sub-is-enabled/295254)

<div class="topic-metadata">

**Author:** [@Sebastian\_Borys](https://discuss.elastic.co/u/Sebastian_Borys)\
**Replies:** 4\
**Last updated:** [January 24, 2022, 9:24pm UTC](https://discuss.elastic.co/t/functionbeat-gcp-pub-sub-requiring-storage-entry-point-when-only-pub-sub-is-enabled/295254 "2022-01-24T21:24:44Z")

</div>

Deploying functionbeat on GCP with entry point RunPubSub returns an error complaining about storage entry point, which I am not using. I get the following error upon deploy Deployment failure: Build failed: # functions…

---

## [Filebeat Elastic Kibana - Json based Log Processing](https://discuss.elastic.co/t/filebeat-elastic-kibana-json-based-log-processing/295224)

<div class="topic-metadata">

**Author:** [@RashidKhan](https://discuss.elastic.co/u/RashidKhan)\
**Replies:** 4\
**Last updated:** [January 24, 2022, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-elastic-kibana-json-based-log-processing/295224 "2022-01-24T13:25:51Z")

</div>

Hi Team, I have a log file that has mixed structure, some are multiple line json, some are single line json and some are plain text. My goal is to Parse Json and send to elastic, and ignore the plain text. I read thro…

---

## [Auditbeat 7.16.2 crashes servers due to memory issues](https://discuss.elastic.co/t/auditbeat-7-16-2-crashes-servers-due-to-memory-issues/295047)

<div class="topic-metadata">

**Author:** [@JensVanDeynse](https://discuss.elastic.co/u/JensVanDeynse)\
**Replies:** 1\
**Last updated:** [January 24, 2022, 2:06pm UTC](https://discuss.elastic.co/t/auditbeat-7-16-2-crashes-servers-due-to-memory-issues/295047 "2022-01-24T14:06:34Z")

</div>

Hello ELK version: 7.16.2 Auditbeat version: 7.16.2 I'm trying to set up an Elastic SIEM cluster which is as of now running the way it should but we are still experiencing a memory issue with auditbeat. It seems that…

---

## [Filebeat: Kafka Input doesn't push the topic offset](https://discuss.elastic.co/t/filebeat-kafka-input-doesnt-push-the-topic-offset/292436)

<div class="topic-metadata">

**Author:** [@Giero](https://discuss.elastic.co/u/Giero)\
**Replies:** 6\
**Last updated:** [January 24, 2022, 12:54pm UTC](https://discuss.elastic.co/t/filebeat-kafka-input-doesnt-push-the-topic-offset/292436 "2022-01-24T12:54:07Z")

</div>

I'm using Filebeat 7.16.0 with Kafka Input and Elasticsearch Output. Previously I had java application to take care of this flow. I'm using the same consumer group as previous java application and messages appear in El…

---

## [Multiple Index](https://discuss.elastic.co/t/multiple-index/294012)

<div class="topic-metadata">

**Author:** [@graimato](https://discuss.elastic.co/u/graimato)\
**Replies:** 2\
**Last updated:** [January 24, 2022, 12:43pm UTC](https://discuss.elastic.co/t/multiple-index/294012 "2022-01-24T12:43:13Z")

</div>

Dear all I have a problem with filebeat configuration. I enable two different module and I need to write log in two different index , myindex-module1-data myindex-module2-data Is it possible? I read about filebeat.p…

---

## [Change index name for threatintel module, good idea?](https://discuss.elastic.co/t/change-index-name-for-threatintel-module-good-idea/295158)

<div class="topic-metadata">

**Author:** [@xentoo](https://discuss.elastic.co/u/xentoo)\
**Replies:** 1\
**Last updated:** [January 24, 2022, 3:12am UTC](https://discuss.elastic.co/t/change-index-name-for-threatintel-module-good-idea/295158 "2022-01-24T03:12:09Z")

</div>

Hello, I am trying to change the name of the index for threatintel module from "filebeat" to "threatintel". It does not make much sense to me to bury these documents amongst millions of logs. Or does it? Am I missing s…

---

## [Cant get grok working with nginx log](https://discuss.elastic.co/t/cant-get-grok-working-with-nginx-log/293061)

<div class="topic-metadata">

**Author:** [@Constantine](https://discuss.elastic.co/u/Constantine)\
**Replies:** 5\
**Last updated:** [December 29, 2021, 12:59pm UTC](https://discuss.elastic.co/t/cant-get-grok-working-with-nginx-log/293061 "2021-12-29T12:59:55Z")

</div>

Hi, Can someone help me with nginx logs please. I have full nginx log: 2021-12-28T17:00:34+00:00 site="demo" server="demotest" dest\_port="443" dest\_ip="172.19.0.3" src="172.31.27.65" src\_ip="172.31.27.65" user="-" tim…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=109)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=111)
