# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=111

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 112

---

## [What is Auditbeat audit syntax to exclude a process or path?](https://discuss.elastic.co/t/what-is-auditbeat-audit-syntax-to-exclude-a-process-or-path/295117)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 1\
**Last updated:** [January 22, 2022, 7:54pm UTC](https://discuss.elastic.co/t/what-is-auditbeat-audit-syntax-to-exclude-a-process-or-path/295117 "2022-01-22T19:54:56Z")

</div>

I have Auditbeat running with a bunch of CIS benchmark proposed auditd rules. One of my processes generates a bunch of false positive "time change" logs that I would like to filter out. audit: type=1300 audit(1642859012.…

---

## [Metricbeat beat-xpack shows only 1 beat instance per type in Kibana monitoring in custom AWS cluster,](https://discuss.elastic.co/t/metricbeat-beat-xpack-shows-only-1-beat-instance-per-type-in-kibana-monitoring-in-custom-aws-cluster/295072)

<div class="topic-metadata">

**Author:** [@ronaldkonjer](https://discuss.elastic.co/u/ronaldkonjer)\
**Replies:** 1\
**Last updated:** [January 21, 2022, 3:44pm UTC](https://discuss.elastic.co/t/metricbeat-beat-xpack-shows-only-1-beat-instance-per-type-in-kibana-monitoring-in-custom-aws-cluster/295072 "2022-01-21T15:44:24Z")

</div>

I'm trying to configure my logging cluster using metricbeat with the following modules: Enabled: elasticsearch-xpack kibana-xpack logstash-xpack beat-xpack system whereas my metricbeat config looks like this: # A…

---

## [Fields don't show up when events are published](https://discuss.elastic.co/t/fields-dont-show-up-when-events-are-published/294722)

<div class="topic-metadata">

**Author:** [@a11](https://discuss.elastic.co/u/a11)\
**Replies:** 4\
**Last updated:** [January 21, 2022, 3:24pm UTC](https://discuss.elastic.co/t/fields-dont-show-up-when-events-are-published/294722 "2022-01-21T15:24:37Z")

</div>

Hi all, I'm struggling with a windows event to publish. Event xml below, strongs fields aren't publish by Winlogbeat. - \<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"\> - \<System\> \<Provider Name…

---

## [Filebeat not parsing multiline](https://discuss.elastic.co/t/filebeat-not-parsing-multiline/294969)

<div class="topic-metadata">

**Author:** [@ConorTier](https://discuss.elastic.co/u/ConorTier)\
**Replies:** 2\
**Last updated:** [January 21, 2022, 11:56am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-multiline/294969 "2022-01-21T11:56:54Z")

</div>

Here is my scenario - Logstash running on an hosted internal windows server Filebeat running on a linux (Ubuntu) - internally hosted (both can communicate with other internally ok) docker containers running on Linux b…

---

## [User details using auditbeat](https://discuss.elastic.co/t/user-details-using-auditbeat/295018)

<div class="topic-metadata">

**Author:** [@Riya\_patel](https://discuss.elastic.co/u/Riya_patel)\
**Replies:** 0\
**Last updated:** [January 21, 2022, 6:43am UTC](https://discuss.elastic.co/t/user-details-using-auditbeat/295018 "2022-01-21T06:43:05Z")

</div>

How to fetch last login user details using Auditbeat?

---

## [After collecting ES, Kibana shows why the following error occurs, sometimes it does not occur and sometimes it does occur?](https://discuss.elastic.co/t/after-collecting-es-kibana-shows-why-the-following-error-occurs-sometimes-it-does-not-occur-and-sometimes-it-does-occur/295007)

<div class="topic-metadata">

**Author:** [@linuxxin](https://discuss.elastic.co/u/linuxxin)\
**Replies:** 0\
**Last updated:** [January 21, 2022, 2:26am UTC](https://discuss.elastic.co/t/after-collecting-es-kibana-shows-why-the-following-error-occurs-sometimes-it-does-not-occur-and-sometimes-it-does-occur/295007 "2022-01-21T02:26:49Z")

</div>

Bad Request search\_phase\_execution\_exception all shards failed ................

---

## [Fleet Settings - Elasticsearch output configuration (YAML)](https://discuss.elastic.co/t/fleet-settings-elasticsearch-output-configuration-yaml/294564)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 2\
**Last updated:** [January 20, 2022, 8:26pm UTC](https://discuss.elastic.co/t/fleet-settings-elasticsearch-output-configuration-yaml/294564 "2022-01-20T20:26:25Z")

</div>

Hello everyone, Do I need to create separate agent policies for Linux and Windows hosts? The reason is the ca certs are in different location depending on the OS ssl.certificate\_authorities: \["/etc/elasticsearch/certs…

---

## [Filbeat decode\_csv\_fields processor silently drops fields greater than 1024 characters](https://discuss.elastic.co/t/filbeat-decode-csv-fields-processor-silently-drops-fields-greater-than-1024-characters/294983)

<div class="topic-metadata">

**Author:** [@feliperuiz](https://discuss.elastic.co/u/feliperuiz)\
**Replies:** 0\
**Last updated:** [January 20, 2022, 6:48pm UTC](https://discuss.elastic.co/t/filbeat-decode-csv-fields-processor-silently-drops-fields-greater-than-1024-characters/294983 "2022-01-20T18:48:11Z")

</div>

Hello. I am trying to process some csv files in filebeat with the decode\_csv\_fields processor, but it seems that it is silently dropping fields that are greater than 1024 characters. Here is my filebeat processor config…

---

## [Elastic-agent fails "enroll\_cmd.go:776	Fleet Server - Error - EOF"](https://discuss.elastic.co/t/elastic-agent-fails-enroll-cmd-go-776-fleet-server-error-eof/293779)

<div class="topic-metadata">

**Author:** [@stevebanik](https://discuss.elastic.co/u/stevebanik)\
**Replies:** 1\
**Last updated:** [January 20, 2022, 5:09pm UTC](https://discuss.elastic.co/t/elastic-agent-fails-enroll-cmd-go-776-fleet-server-error-eof/293779 "2022-01-20T17:09:34Z")

</div>

\[root@es1 elastic-agent-7.16.2-linux-x86\_64\]# uname -a Linux es1 3.10.0-1160.49.1.el7.x86\_64 #1 SMP Tue Nov 30 15:51:32 UTC 2021 x86\_64 x86\_64 x86\_64 GNU/Linux \[root@es1 elastic-agent-7.16.2-linux-x86\_64\]# ./elastic-ag…

---

## [Unable to do \`filebeat setup ...\` for custom \`filebeat\` index name](https://discuss.elastic.co/t/unable-to-do-filebeat-setup-for-custom-filebeat-index-name/294968)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 1\
**Last updated:** [January 20, 2022, 4:07pm UTC](https://discuss.elastic.co/t/unable-to-do-filebeat-setup-for-custom-filebeat-index-name/294968 "2022-01-20T16:07:32Z")

</div>

I'm attempting to do a filebeat setup ... with Filebeat 7.16.0/Elasticsearch 7.16.2 for a custom index (foo-filebeat-7.16.0-\*). However, it always loads the template, etc. for filebeat-7.16.0-\*. I'm pretty sure this is a…

---

## [Resource 'filebeat-7.16.2' exists, but it is not an alias](https://discuss.elastic.co/t/resource-filebeat-7-16-2-exists-but-it-is-not-an-alias/294903)

<div class="topic-metadata">

**Author:** [@tejas.tech](https://discuss.elastic.co/u/tejas.tech)\
**Replies:** 2\
**Last updated:** [January 20, 2022, 2:18pm UTC](https://discuss.elastic.co/t/resource-filebeat-7-16-2-exists-but-it-is-not-an-alias/294903 "2022-01-20T14:18:40Z")

</div>

Team, I've installed Filebeat 7.16.2 on two machines, and I'm able to get data from one but not the other, and I'm getting the following problem.

---

## [Metricbeat-7.16.2 does not support billing api version 2019-10-01](https://discuss.elastic.co/t/metricbeat-7-16-2-does-not-support-billing-api-version-2019-10-01/293582)

<div class="topic-metadata">

**Author:** [@adhiraj-g](https://discuss.elastic.co/u/adhiraj-g)\
**Replies:** 3\
**Last updated:** [January 20, 2022, 1:53pm UTC](https://discuss.elastic.co/t/metricbeat-7-16-2-does-not-support-billing-api-version-2019-10-01/293582 "2022-01-20T13:53:28Z")

</div>

Hi @MarianaD , Hope you had a great Christmas and New year Break. Sorry to bother you again. I had upgraded to Elasticsearch version 7.16-2. I am now using metricbeat version 7.16.2. Still its showing that the billing…

---

## [\[Metricbeat\] Process modules produces high load / cpu usage](https://discuss.elastic.co/t/metricbeat-process-modules-produces-high-load-cpu-usage/294923)

<div class="topic-metadata">

**Author:** [@adsr](https://discuss.elastic.co/u/adsr)\
**Replies:** 0\
**Last updated:** [January 20, 2022, 9:58am UTC](https://discuss.elastic.co/t/metricbeat-process-modules-produces-high-load-cpu-usage/294923 "2022-01-20T09:58:54Z")

</div>

Hi, after upgrading metricbeat from 7.11.2 to 7.16.3 I notice very high load/cpu usage for the metricbeat process. I narrowed it down to the process module in combination with a python process. Furthermore I tried sev…

---

## [Question: Can I add the IP that issued a command to that command?](https://discuss.elastic.co/t/question-can-i-add-the-ip-that-issued-a-command-to-that-command/294932)

<div class="topic-metadata">

**Author:** [@ziv1](https://discuss.elastic.co/u/ziv1)\
**Replies:** 0\
**Last updated:** [January 20, 2022, 10:47am UTC](https://discuss.elastic.co/t/question-can-i-add-the-ip-that-issued-a-command-to-that-command/294932 "2022-01-20T10:47:09Z")

</div>

Hi, Context: auditbeat on RHEL, auditd module Ideally, I would like to remove a ton of fields that are of no use to a human being (not related to this topic), and add a field that would show me the IP that issued a giv…

---

## [Filebeat mixing pod logs](https://discuss.elastic.co/t/filebeat-mixing-pod-logs/294834)

<div class="topic-metadata">

**Author:** [@mnbill](https://discuss.elastic.co/u/mnbill)\
**Replies:** 0\
**Last updated:** [January 19, 2022, 2:39pm UTC](https://discuss.elastic.co/t/filebeat-mixing-pod-logs/294834 "2022-01-19T14:39:00Z")

</div>

Hello May be anyone can check that ? I am facing mixing logs on windows filebeat. I build a windows filebeat docker image (based on windows server 1909) and i deployed daemonset on k8s cluster, everyting work fine w…

---

## [Add time range filter in this prometheus.yml of metricbeat to get output for a particular time interval](https://discuss.elastic.co/t/add-time-range-filter-in-this-prometheus-yml-of-metricbeat-to-get-output-for-a-particular-time-interval/294822)

<div class="topic-metadata">

**Author:** [@tweet2santosh86](https://discuss.elastic.co/u/tweet2santosh86)\
**Replies:** 2\
**Last updated:** [January 20, 2022, 9:24am UTC](https://discuss.elastic.co/t/add-time-range-filter-in-this-prometheus-yml-of-metricbeat-to-get-output-for-a-particular-time-interval/294822 "2022-01-20T09:24:28Z")

</div>

Hello Team, For metricbeat prometheus module we need output for a particular time interval.. How can we add the filter in at modules.d/prometheus.yml to get the output for a particular time interval.. Request for your …

---

## [McAfee Enterprise Enterprise Security triggers on Auditbeat in /etc/passwd.xx](https://discuss.elastic.co/t/mcafee-enterprise-enterprise-security-triggers-on-auditbeat-in-etc-passwd-xx/294846)

<div class="topic-metadata">

**Author:** [@odehen](https://discuss.elastic.co/u/odehen)\
**Replies:** 2\
**Last updated:** [January 20, 2022, 7:46am UTC](https://discuss.elastic.co/t/mcafee-enterprise-enterprise-security-triggers-on-auditbeat-in-etc-passwd-xx/294846 "2022-01-20T07:46:54Z")

</div>

We are using Elasticsearch 7.16.2 on RHEL with McAfee Enterprise. Apparently an alarm has gone off, namely the PREVENT\_MODIFICATION\_PASSWORDFILES\_LINUX rule because of Auditbeat supposedly attempting to modify /etc/passw…

---

## [Metricbeat for ActiveMQ](https://discuss.elastic.co/t/metricbeat-for-activemq/294359)

<div class="topic-metadata">

**Author:** [@rodentskie](https://discuss.elastic.co/u/rodentskie)\
**Replies:** 10\
**Last updated:** [January 20, 2022, 7:18am UTC](https://discuss.elastic.co/t/metricbeat-for-activemq/294359 "2022-01-20T07:18:45Z")

</div>

Hi, I'm currently working on getting metrics from AWS activemq, but I can't get it on how to install jolokia module. Any idea? We are using a cloud Elasticsearch instance, and we apply our metricbeat using kubernetes ya…

---

## [Heartbeat (7.16.3) - missing required field accessing 'schedule'](https://discuss.elastic.co/t/heartbeat-7-16-3-missing-required-field-accessing-schedule/294782)

<div class="topic-metadata">

**Author:** [@jurgenhaas](https://discuss.elastic.co/u/jurgenhaas)\
**Replies:** 9\
**Last updated:** [January 19, 2022, 10:33pm UTC](https://discuss.elastic.co/t/heartbeat-7-16-3-missing-required-field-accessing-schedule/294782 "2022-01-19T22:33:27Z")

</div>

My heartbeat monitoring is working just fine, but syslog is flooded with error messages like this: Jan 19 08:51:38 bslog1 heartbeat\[32480\]: 2022-01-19T08:51:38.532+0100 ERROR \[reload\] cfgfile/list.go:99 Error creating r…

---

## [Metricbeat-7.16.2 HTTP error 401 in : 401 Unauthorized](https://discuss.elastic.co/t/metricbeat-7-16-2-http-error-401-in-401-unauthorized/294816)

<div class="topic-metadata">

**Author:** [@mwoods269](https://discuss.elastic.co/u/mwoods269)\
**Replies:** 1\
**Last updated:** [January 19, 2022, 5:07pm UTC](https://discuss.elastic.co/t/metricbeat-7-16-2-http-error-401-in-401-unauthorized/294816 "2022-01-19T17:07:43Z")

</div>

Hello, Environment: singlenode sandbox running 7.16.2 Security enabled (TLS inter node comms) No Https Issue: Installed metricbeat and enabled Elasticsearch however node still reporting as self monitored Gett…

---

## [One index/index template per module](https://discuss.elastic.co/t/one-index-index-template-per-module/294823)

<div class="topic-metadata">

**Author:** [@emmanuel\_t](https://discuss.elastic.co/u/emmanuel_t)\
**Replies:** 0\
**Last updated:** [January 19, 2022, 1:48pm UTC](https://discuss.elastic.co/t/one-index-index-template-per-module/294823 "2022-01-19T13:48:26Z")

</div>

Hello, I'd like to enable just a few filebeat modules (let's say nginx, postgresql). And I'd like to have on Elasticsearch one index per module (per month). So... filebeat-nginx-2022-01 and filebeat-postgresql-2022-01. …

---

## [My Filebeat isn't working when pushing Sophos XG firewall logs](https://discuss.elastic.co/t/my-filebeat-isnt-working-when-pushing-sophos-xg-firewall-logs/294799)

<div class="topic-metadata">

**Author:** [@Siyabonga](https://discuss.elastic.co/u/Siyabonga)\
**Replies:** 0\
**Last updated:** [January 19, 2022, 11:15am UTC](https://discuss.elastic.co/t/my-filebeat-isnt-working-when-pushing-sophos-xg-firewall-logs/294799 "2022-01-19T11:15:39Z")

</div>

Hi Guys I am getting the following error when configuring Filebeat can any one please assist? Overwriting ILM policy is disabled. Set setup.ilm.overwrite: true for enabling. Index setup finished. Loading dashboards (K…

---

## [Filebeat.inputs journald: Multiline not working](https://discuss.elastic.co/t/filebeat-inputs-journald-multiline-not-working/294422)

<div class="topic-metadata">

**Author:** [@agallardo](https://discuss.elastic.co/u/agallardo)\
**Replies:** 3\
**Last updated:** [January 19, 2022, 9:22am UTC](https://discuss.elastic.co/t/filebeat-inputs-journald-multiline-not-working/294422 "2022-01-19T09:22:06Z")

</div>

According to \[Journalbeat\] Still no multiline support after 3 years · Issue #27578 · elastic/beats · GitHub, because filebeat can now read the journal and it should support multiline. In the documentation Journald input …

---

## [Argument \`path\` of the module file\_integrity enhancement?](https://discuss.elastic.co/t/argument-path-of-the-module-file-integrity-enhancement/293668)

<div class="topic-metadata">

**Author:** [@krakz](https://discuss.elastic.co/u/krakz)\
**Replies:** 1\
**Last updated:** [January 19, 2022, 9:05am UTC](https://discuss.elastic.co/t/argument-path-of-the-module-file-integrity-enhancement/293668 "2022-01-19T09:05:33Z")

</div>

Hi, The module file\_integrity takes a list of file path, which is useful for binary and configuration file monitoring, but generic users file cannot be monitored otherwise than with the option recursive enable. Is ther…

---

## [Filebeat Non-Root User Permissions](https://discuss.elastic.co/t/filebeat-non-root-user-permissions/294743)

<div class="topic-metadata">

**Author:** [@harry\_cook](https://discuss.elastic.co/u/harry_cook)\
**Replies:** 1\
**Last updated:** [January 19, 2022, 12:37am UTC](https://discuss.elastic.co/t/filebeat-non-root-user-permissions/294743 "2022-01-19T00:37:32Z")

</div>

Can I Install filebeat as a non-root user on on-prem servers ? If yes what/where all permissions do I need to run it as non-root user ?

---

## [How can I add kubernetes metadata for my cri-containerd pods](https://discuss.elastic.co/t/how-can-i-add-kubernetes-metadata-for-my-cri-containerd-pods/294706)

<div class="topic-metadata">

**Author:** [@jianwu](https://discuss.elastic.co/u/jianwu)\
**Replies:** 0\
**Last updated:** [January 18, 2022, 2:49pm UTC](https://discuss.elastic.co/t/how-can-i-add-kubernetes-metadata-for-my-cri-containerd-pods/294706 "2022-01-18T14:49:43Z")

</div>

I am using filebeat 7.16.2 to collect containers stdout which run-time is containerd. MY kubernetes' versin v1.20.10, and containerd version is v1.19.0. Below is some of my filebeat.yaml filebeat.inputs: - type…

---

## [Not able to parse below multiple json objects i have lot of json objects like this please provide filebeat input and logstsah configuration for this thank you in advance](https://discuss.elastic.co/t/not-able-to-parse-below-multiple-json-objects-i-have-lot-of-json-objects-like-this-please-provide-filebeat-input-and-logstsah-configuration-for-this-thank-you-in-advance/294550)

<div class="topic-metadata">

**Author:** [@aravindpatel](https://discuss.elastic.co/u/aravindpatel)\
**Replies:** 0\
**Last updated:** [January 17, 2022, 8:53am UTC](https://discuss.elastic.co/t/not-able-to-parse-below-multiple-json-objects-i-have-lot-of-json-objects-like-this-please-provide-filebeat-input-and-logstsah-configuration-for-this-thank-you-in-advance/294550 "2022-01-17T08:53:17Z")

</div>

{ "id": "AAA", "num": "-17.3595", "num": "-145.494", "name": "Anaa", "author": "Anaaauthor", "place": "Tuamotu-Gambier", "landmark": "French Polynesia", "spcid": "12512819", "target": "Pacific/Midway", "mob": …

---

## [ES password containing comma can't be passed as environment variable](https://discuss.elastic.co/t/es-password-containing-comma-cant-be-passed-as-environment-variable/294450)

<div class="topic-metadata">

**Author:** [@BitPatty](https://discuss.elastic.co/u/BitPatty)\
**Replies:** 1\
**Last updated:** [January 17, 2022, 4:36pm UTC](https://discuss.elastic.co/t/es-password-containing-comma-cant-be-passed-as-environment-variable/294450 "2022-01-17T16:36:25Z")

</div>

I'm passing the password as environment variable to heartbeat.yml on ES 7.16.1 as follows: heartbeat.yml: output: elasticsearch: password: '${ELASTICSEARCH\_PASSWORD}' When using ELASTICSEARCH\_PASSWORD="foo,bar" …

---

## [Metricbeat and Elasticsearch Breaker Limit](https://discuss.elastic.co/t/metricbeat-and-elasticsearch-breaker-limit/294419)

<div class="topic-metadata">

**Author:** [@MichaelCoetzee](https://discuss.elastic.co/u/MichaelCoetzee)\
**Replies:** 1\
**Last updated:** [January 17, 2022, 10:38am UTC](https://discuss.elastic.co/t/metricbeat-and-elasticsearch-breaker-limit/294419 "2022-01-17T10:38:32Z")

</div>

Hi All. We have a Kubernetes cluster with Elasticsearch and Metricbeat We collect quite a lot of data with Metricbeat and sometimes our Elasticsearch cluster might go down during some maintenance and as i understand it…

---

## [Elastic Agent - State persistence in Docker](https://discuss.elastic.co/t/elastic-agent-state-persistence-in-docker/294352)

<div class="topic-metadata">

**Author:** [@bar0n36](https://discuss.elastic.co/u/bar0n36)\
**Replies:** 2\
**Last updated:** [January 17, 2022, 8:49am UTC](https://discuss.elastic.co/t/elastic-agent-state-persistence-in-docker/294352 "2022-01-17T08:49:50Z")

</div>

Hi, I am looking for best practice guidance when running the Elastic Agent and integrations in Docker containers. I have no issues getting them running (the documentation needs a bit of love as there are some inconsisten…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=110)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=112)
