# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=113

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 114

---

## [Load index template for beats upgrade](https://discuss.elastic.co/t/load-index-template-for-beats-upgrade/294078)

<div class="topic-metadata">

**Author:** [@Dennis\_Qian](https://discuss.elastic.co/u/Dennis_Qian)\
**Replies:** 2\
**Last updated:** [January 12, 2022, 1:08am UTC](https://discuss.elastic.co/t/load-index-template-for-beats-upgrade/294078 "2022-01-12T01:08:35Z")

</div>

I need to upgrade filebeat 6.8 to 7.16 and winlogbeat 6.3 to 7.16. After reading the upgrade guide, my understanding is that I need to upgrade winlogbeat to 6.8 first, then load index template. However our beats output …

---

## [Are we forced to data streams in 8.0?](https://discuss.elastic.co/t/are-we-forced-to-data-streams-in-8-0/294090)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 0\
**Last updated:** [January 11, 2022, 10:58pm UTC](https://discuss.elastic.co/t/are-we-forced-to-data-streams-in-8-0/294090 "2022-01-11T22:58:52Z")

</div>

I'm researching what we need to do to get off legacy templates. For example, we have several indices like filebeat-7.14.0-index-a, filebeat-7.14.0-index-b, etc. They are different apps and different access rules. Now …

---

## [Fleet Apache access log integration - adding extra data from logs](https://discuss.elastic.co/t/fleet-apache-access-log-integration-adding-extra-data-from-logs/294048)

<div class="topic-metadata">

**Author:** [@ChrisTB](https://discuss.elastic.co/u/ChrisTB)\
**Replies:** 1\
**Last updated:** [January 11, 2022, 10:04pm UTC](https://discuss.elastic.co/t/fleet-apache-access-log-integration-adding-extra-data-from-logs/294048 "2022-01-11T22:04:32Z")

</div>

Hi, We have set up an integration via Fleet/Elastic Agent for Apache. I was wondering if it is possible to add extra data that is present in the access log files, to the data stream, so we can query and visualize it in…

---

## [Elastic Agent SQL Integration](https://discuss.elastic.co/t/elastic-agent-sql-integration/294043)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 1\
**Last updated:** [January 11, 2022, 10:03pm UTC](https://discuss.elastic.co/t/elastic-agent-sql-integration/294043 "2022-01-11T22:03:33Z")

</div>

Hi All, I was wondering if there is or are plans to have an SQL integration for the Elastic Agent that is basically (SQL module | Metricbeat Reference \[7.16\] | Elastic)? I'm looking have a recurring query to collect som…

---

## [Metricbeat cpu](https://discuss.elastic.co/t/metricbeat-cpu/294052)

<div class="topic-metadata">

**Author:** [@joaosf](https://discuss.elastic.co/u/joaosf)\
**Replies:** 0\
**Last updated:** [January 11, 2022, 3:11pm UTC](https://discuss.elastic.co/t/metricbeat-cpu/294052 "2022-01-11T15:11:33Z")

</div>

help, Is there any explication for this kind of values? system.cpu.system.norm.pct=111,851,835.7% metricbeat 7.14

---

## [Metricbeat collecting mongo-metrics is not updated to elasticsearch](https://discuss.elastic.co/t/metricbeat-collecting-mongo-metrics-is-not-updated-to-elasticsearch/293922)

<div class="topic-metadata">

**Author:** [@smileyvignesh](https://discuss.elastic.co/u/smileyvignesh)\
**Replies:** 2\
**Last updated:** [January 11, 2022, 1:58pm UTC](https://discuss.elastic.co/t/metricbeat-collecting-mongo-metrics-is-not-updated-to-elasticsearch/293922 "2022-01-11T13:58:25Z")

</div>

Hello everyone, I'm using the metricbeat to get mongodb metics ("dbstats", "status", "collstats", "metrics") and update it to Elasticsearch via logstash. There is no error seen in the logstash logs or metric beat logs. T…

---

## [IBM HTTP Server](https://discuss.elastic.co/t/ibm-http-server/293862)

<div class="topic-metadata">

**Author:** [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Replies:** 6\
**Last updated:** [January 11, 2022, 1:57pm UTC](https://discuss.elastic.co/t/ibm-http-server/293862 "2022-01-11T13:57:56Z")

</div>

Hello ! Does ELK have modules to monitor with metricbeat and obtain logs previously parsed with filebeat from IBM HTTP servers? Thanks in advanced!

---

## [Filebeat not picking up log files](https://discuss.elastic.co/t/filebeat-not-picking-up-log-files/293910)

<div class="topic-metadata">

**Author:** [@aamir\_mustafa](https://discuss.elastic.co/u/aamir_mustafa)\
**Replies:** 3\
**Last updated:** [January 11, 2022, 9:30am UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-log-files/293910 "2022-01-11T09:30:49Z")

</div>

Hello Team, I'm using Filebeat 7.10.2 to ship logs directly to Elasticsearch. But I'm facing an issue while giving input to filebeat. Filebeat only picks up one log file even when I'm specifying to read all files from i…

---

## [How to check Microsoft 365 service health](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 6\
**Last updated:** [January 11, 2022, 7:53am UTC](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089 "2022-01-11T07:53:08Z")

</div>

Hello experts! I have a question - How to check Microsoft 365 service health? As far as I know, there is a module for auditing logs in the filebeat. But I would like to get the status of o365 services. Is there such a …

---

## [Rottating policy Elastic Agent logs](https://discuss.elastic.co/t/rottating-policy-elastic-agent-logs/293880)

<div class="topic-metadata">

**Author:** [@marti1](https://discuss.elastic.co/u/marti1)\
**Replies:** 2\
**Last updated:** [January 11, 2022, 7:24am UTC](https://discuss.elastic.co/t/rottating-policy-elastic-agent-logs/293880 "2022-01-11T07:24:05Z")

</div>

Hi, Elastic Agent creates a log for each integration (Ex: /Library/Elastic/Agent/data/elastic-agent-08e204/logs/default/metricbeat-json.log). Is it possible to define rotating policy (reaching specific size or defining …

---

## [Filebeat with GCP module failed to start](https://discuss.elastic.co/t/filebeat-with-gcp-module-failed-to-start/293977)

<div class="topic-metadata">

**Author:** [@NohimX](https://discuss.elastic.co/u/NohimX)\
**Replies:** 0\
**Last updated:** [January 11, 2022, 6:46am UTC](https://discuss.elastic.co/t/filebeat-with-gcp-module-failed-to-start/293977 "2022-01-11T06:46:02Z")

</div>

I tried to configure filebeat GCP module to get audit logs from Google Cloud, and it failed to start. Failed to start crawler: creating module reloader failed: error checking input configuration: no authentication crede…

---

## [Filebeat makes too many API calls choking and bringing down the Kubernetes cluster](https://discuss.elastic.co/t/filebeat-makes-too-many-api-calls-choking-and-bringing-down-the-kubernetes-cluster/293797)

<div class="topic-metadata">

**Author:** [@ayush\_mundra](https://discuss.elastic.co/u/ayush_mundra)\
**Replies:** 2\
**Last updated:** [January 11, 2022, 6:21am UTC](https://discuss.elastic.co/t/filebeat-makes-too-many-api-calls-choking-and-bringing-down-the-kubernetes-cluster/293797 "2022-01-11T06:21:30Z")

</div>

Hi, We have filebeat version: 7.12.0 running as a daemonset on all our production K8s clusters. Recently, we faced a catastrophic situation where our whole K8s cluster with around 300+ nodes was brought down by filebeat…

---

## [Heartbeat (7.15.2) - aws\_elb autodiscover only sends data for single listener while more should be included](https://discuss.elastic.co/t/heartbeat-7-15-2-aws-elb-autodiscover-only-sends-data-for-single-listener-while-more-should-be-included/293757)

<div class="topic-metadata">

**Author:** [@ronaldkonjer](https://discuss.elastic.co/u/ronaldkonjer)\
**Replies:** 3\
**Last updated:** [January 11, 2022, 2:58am UTC](https://discuss.elastic.co/t/heartbeat-7-15-2-aws-elb-autodiscover-only-sends-data-for-single-listener-while-more-should-be-included/293757 "2022-01-11T02:58:26Z")

</div>

I try to get heartbeat with aws\_elb autodiscovery to work. Though I'm able to get data visible in kibana, it is always a single listener from a single lb. Whereas I have 3 lb setup and it logs that it fetched 16 listener…

---

## [Filebeat cannot detect modified ingested files](https://discuss.elastic.co/t/filebeat-cannot-detect-modified-ingested-files/293837)

<div class="topic-metadata">

**Author:** [@park\_rage](https://discuss.elastic.co/u/park_rage)\
**Replies:** 4\
**Last updated:** [January 10, 2022, 10:04pm UTC](https://discuss.elastic.co/t/filebeat-cannot-detect-modified-ingested-files/293837 "2022-01-10T22:04:23Z")

</div>

I am configuring the ELK + filebeat environment using docker-compose , but the environment and configuration are as follows. Environment: MacOS Functions to be implemented: Collect the /Users/mymac/dev/logs/app.log…

---

## [Filebeat Module O365 API URI?](https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471)

<div class="topic-metadata">

**Author:** [@elasticband](https://discuss.elastic.co/u/elasticband)\
**Replies:** 5\
**Last updated:** [January 10, 2022, 7:23pm UTC](https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471 "2022-01-10T19:23:15Z")

</div>

I am trying to get some support from Microsoft because I am not seeing all the login data I see in the Azure AD Console via the O365 Module. They would like to know what URI the module is using for API calls and I am not…

---

## [Filebeat duplicates events after restart](https://discuss.elastic.co/t/filebeat-duplicates-events-after-restart/293917)

<div class="topic-metadata">

**Author:** [@pilincom](https://discuss.elastic.co/u/pilincom)\
**Replies:** 0\
**Last updated:** [January 10, 2022, 5:07pm UTC](https://discuss.elastic.co/t/filebeat-duplicates-events-after-restart/293917 "2022-01-10T17:07:51Z")

</div>

I'm using Filebeat 7.16.2 to ship logs to Logstash -\> ES. For some reason every time I restart filebeat service, it scans all files in the log directory again and sends them to logstash. registry directory is accessible…

---

## [Scale monitoring using metricbeat](https://discuss.elastic.co/t/scale-monitoring-using-metricbeat/293891)

<div class="topic-metadata">

**Author:** [@motkele](https://discuss.elastic.co/u/motkele)\
**Replies:** 3\
**Last updated:** [January 10, 2022, 1:46pm UTC](https://discuss.elastic.co/t/scale-monitoring-using-metricbeat/293891 "2022-01-10T13:46:04Z")

</div>

Hello, I have a very specific question regarding the way to collect metrics using metricbeat. I would like to collect the metrics from all the services running on the server (and for which a metricbeat module is availa…

---

## [Metricbeat showing "server's certificate chain verification is disabled"](https://discuss.elastic.co/t/metricbeat-showing-servers-certificate-chain-verification-is-disabled/287759)

<div class="topic-metadata">

**Author:** [@gboer](https://discuss.elastic.co/u/gboer)\
**Replies:** 9\
**Last updated:** [January 10, 2022, 1:38pm UTC](https://discuss.elastic.co/t/metricbeat-showing-servers-certificate-chain-verification-is-disabled/287759 "2022-01-10T13:38:14Z")

</div>

Hello, As far as I can see, I've set up Metricbeat to correctly validate/use SSL, but it still gives the following warning when running 'metricbeat test output': server's certificate chain verification is disabled My …

---

## [FIlebeat IIS module](https://discuss.elastic.co/t/filebeat-iis-module/293257)

<div class="topic-metadata">

**Author:** [@rckvwijk](https://discuss.elastic.co/u/rckvwijk)\
**Replies:** 11\
**Last updated:** [January 10, 2022, 1:31pm UTC](https://discuss.elastic.co/t/filebeat-iis-module/293257 "2022-01-10T13:31:31Z")

</div>

Hi there, We're using filebeat with great succes for most of our logging but we've received a new request from within the organisation. They want to ingest the IIS logs from our Windows Server 2016 machine but even thou…

---

## [Anyone else have tried to monitor harbor?](https://discuss.elastic.co/t/anyone-else-have-tried-to-monitor-harbor/293795)

<div class="topic-metadata">

**Author:** [@dengyun19900722](https://discuss.elastic.co/u/dengyun19900722)\
**Replies:** 1\
**Last updated:** [January 9, 2022, 10:39pm UTC](https://discuss.elastic.co/t/anyone-else-have-tried-to-monitor-harbor/293795 "2022-01-09T22:39:45Z")

</div>

Anyone else have tried to monitor harbor?

---

## [How to parse AWS Cloudfront logs](https://discuss.elastic.co/t/how-to-parse-aws-cloudfront-logs/293690)

<div class="topic-metadata">

**Author:** [@leo-baltus](https://discuss.elastic.co/u/leo-baltus)\
**Replies:** 4\
**Last updated:** [January 8, 2022, 9:49am UTC](https://discuss.elastic.co/t/how-to-parse-aws-cloudfront-logs/293690 "2022-01-08T09:49:04Z")

</div>

Tring to get filebeat to parse AWS Cloudfront logs. SQS seem to work. but once in ES I see: Provided Grok expressions do not match field value: \[2022-01-06\\t20:06:28\\tFRA56-C2\\t1729\\t3.125.241.170\\tGET\\tdtc81dn1qkg0w.c…

---

## [Elastic Agent Crashes and Restarts Every Second on Windows 11](https://discuss.elastic.co/t/elastic-agent-crashes-and-restarts-every-second-on-windows-11/293789)

<div class="topic-metadata">

**Author:** [@res260](https://discuss.elastic.co/u/res260)\
**Replies:** 0\
**Last updated:** [January 7, 2022, 10:59pm UTC](https://discuss.elastic.co/t/elastic-agent-crashes-and-restarts-every-second-on-windows-11/293789 "2022-01-07T22:59:22Z")

</div>

Hey, I just setup the Elastic Stack to act as a SIEM and successfully deployed the Elastic Agent on 2 systems: my personnal laptop (running windows 10 pro) and my ubuntu 20 VPS. Both work fine. However, when trying to i…

---

## [Hints based autodiscovery not working as described in documentation](https://discuss.elastic.co/t/hints-based-autodiscovery-not-working-as-described-in-documentation/293150)

<div class="topic-metadata">

**Author:** [@gehgerds](https://discuss.elastic.co/u/gehgerds)\
**Replies:** 1\
**Last updated:** [January 7, 2022, 5:33pm UTC](https://discuss.elastic.co/t/hints-based-autodiscovery-not-working-as-described-in-documentation/293150 "2022-01-07T17:33:43Z")

</div>

I'm following documentation on hints based autodiscovery. I want to use annotations to control which pods logs are being discovered. When I use example config like this, then all containers in cluster gets discovered and…

---

## [Filebeat Kafka Input not able to process Messages](https://discuss.elastic.co/t/filebeat-kafka-input-not-able-to-process-messages/293255)

<div class="topic-metadata">

**Author:** [@cyber\_crab](https://discuss.elastic.co/u/cyber_crab)\
**Replies:** 4\
**Last updated:** [January 7, 2022, 5:07pm UTC](https://discuss.elastic.co/t/filebeat-kafka-input-not-able-to-process-messages/293255 "2022-01-07T17:07:06Z")

</div>

Hi everyone, I'm currently facing an issue with the Filebeat Kafka input. The event flow is Data Source \> Logstash \> Kafka \> Filebeat \> Logstash \> Elasticsearch. Kafka is used to handle event ingestion spikes and ES clu…

---

## [How to read log files from remote location](https://discuss.elastic.co/t/how-to-read-log-files-from-remote-location/293746)

<div class="topic-metadata">

**Author:** [@Aamir\_Sheraz](https://discuss.elastic.co/u/Aamir_Sheraz)\
**Replies:** 1\
**Last updated:** [January 7, 2022, 1:58pm UTC](https://discuss.elastic.co/t/how-to-read-log-files-from-remote-location/293746 "2022-01-07T13:58:43Z")

</div>

I want to read log files from different location/systems. I am able to read multiple files on the same system but there is requirement to read files from another location/system remotely as well without installing fileb…

---

## [Using functionbeat environment variables](https://discuss.elastic.co/t/using-functionbeat-environment-variables/293707)

<div class="topic-metadata">

**Author:** [@Sultan](https://discuss.elastic.co/u/Sultan)\
**Replies:** 0\
**Last updated:** [January 7, 2022, 6:12am UTC](https://discuss.elastic.co/t/using-functionbeat-environment-variables/293707 "2022-01-07T06:12:03Z")

</div>

Hi, We are trying to use functionbeat to deploy a lambda function in AWS which eventually would ship kinesis logs to our elastic cloud. We do not want to keep the elastic credentials (ie. cloud.auth, cloud.id etc) in th…

---

## [Continuously read from .evtx logfile?](https://discuss.elastic.co/t/continuously-read-from-evtx-logfile/293658)

<div class="topic-metadata">

**Author:** [@Andreas\_Falk](https://discuss.elastic.co/u/Andreas_Falk)\
**Replies:** 3\
**Last updated:** [January 7, 2022, 3:06am UTC](https://discuss.elastic.co/t/continuously-read-from-evtx-logfile/293658 "2022-01-07T03:06:38Z")

</div>

(crosspost from slack) Hi, We are trying to get the logs from our netapp cifs shares. Netapp exports their logs to a smb share and writes .evtx files there. And with the help of mounting and pointing winlogbeat to th…

---

## [Enable elasticsearch module from filebeat and trying to send data to elasticsearch but getting below error](https://discuss.elastic.co/t/enable-elasticsearch-module-from-filebeat-and-trying-to-send-data-to-elasticsearch-but-getting-below-error/293654)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 0\
**Last updated:** [January 6, 2022, 2:30pm UTC](https://discuss.elastic.co/t/enable-elasticsearch-module-from-filebeat-and-trying-to-send-data-to-elasticsearch-but-getting-below-error/293654 "2022-01-06T14:30:42Z")

</div>

Hello team, I have enable Elasticsearch module from filebeat and trying to send data to Elasticsearch but getting below error. Can you please help me here. Username and password is correct. but still showing below erro…

---

## [Installing Fleet agent on servers with existing winlogbeats/filebeats etc](https://discuss.elastic.co/t/installing-fleet-agent-on-servers-with-existing-winlogbeats-filebeats-etc/293547)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 2\
**Last updated:** [January 6, 2022, 7:49am UTC](https://discuss.elastic.co/t/installing-fleet-agent-on-servers-with-existing-winlogbeats-filebeats-etc/293547 "2022-01-06T07:49:40Z")

</div>

I have a number of servers where i manually installed filebeat/winlogbeat/metricbeat etc. What impact does that have if i wish to now use the Fleet agent and policies to collect this data? Do i need to manually uninsta…

---

## [Filebeat docker input type with different paths](https://discuss.elastic.co/t/filebeat-docker-input-type-with-different-paths/293495)

<div class="topic-metadata">

**Author:** [@sahinguler](https://discuss.elastic.co/u/sahinguler)\
**Replies:** 3\
**Last updated:** [January 6, 2022, 6:05am UTC](https://discuss.elastic.co/t/filebeat-docker-input-type-with-different-paths/293495 "2022-01-06T06:05:02Z")

</div>

Hi everyone, I use filebeat for storing docker logs. My docker containers logs path is /home/docker/containers/${data.docker.container.id}/\*.log. But filebeat scans /var/lib/docker/containers/${data.docker.container.id…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=112)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=114)
