# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=114

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 115

---

## [Configure SSL on Heartbeat with certificates in the system store](https://discuss.elastic.co/t/configure-ssl-on-heartbeat-with-certificates-in-the-system-store/289499)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 6\
**Last updated:** [January 5, 2022, 10:22pm UTC](https://discuss.elastic.co/t/configure-ssl-on-heartbeat-with-certificates-in-the-system-store/289499 "2022-01-05T22:22:14Z")

</div>

I deploy heartbeats on some Windows servers management by an external service provider. The beats collect the staus of service end points exposed by applications on several other hosts. The beats are configured with SSL. …

---

## [Add tags to Filebeat module configuration?](https://discuss.elastic.co/t/add-tags-to-filebeat-module-configuration/293571)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 1\
**Last updated:** [January 5, 2022, 9:51pm UTC](https://discuss.elastic.co/t/add-tags-to-filebeat-module-configuration/293571 "2022-01-05T21:51:14Z")

</div>

Hello Community; This is a simple question, but I cannot find the answer in the filebeat documentation. The filebeat for some hosts is configured with specific input filestreams collecting various logs. In order to mak…

---

## [Windows filebeat cluster privileges](https://discuss.elastic.co/t/windows-filebeat-cluster-privileges/293258)

<div class="topic-metadata">

**Author:** [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Replies:** 2\
**Last updated:** [January 5, 2022, 9:18pm UTC](https://discuss.elastic.co/t/windows-filebeat-cluster-privileges/293258 "2022-01-05T21:18:33Z")

</div>

Hi, I installed Filebeat (7.16.2) on Windows Server, using default PowerShell script and started it as a service. It reads some custom log files and send them to Elasticsearch. It uses a custom index, ILM policy and te…

---

## [Filebeat Syslog RFC 5424 Input With Empty Timestamp](https://discuss.elastic.co/t/filebeat-syslog-rfc-5424-input-with-empty-timestamp/293595)

<div class="topic-metadata">

**Author:** [@jtveite](https://discuss.elastic.co/u/jtveite)\
**Replies:** 0\
**Last updated:** [January 5, 2022, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-syslog-rfc-5424-input-with-empty-timestamp/293595 "2022-01-05T21:06:33Z")

</div>

RFC 5424 explicitly allows timestamp to be a nilvalue. I have a device which generates logs of this format that I am attempting to collect, but filebeat appears to only accept messages that have a timestamp specified. H…

---

## [Filebeat for OS Solaris?](https://discuss.elastic.co/t/filebeat-for-os-solaris/292037)

<div class="topic-metadata">

**Author:** [@DKalin0789e](https://discuss.elastic.co/u/DKalin0789e)\
**Replies:** 3\
**Last updated:** [January 5, 2022, 8:31pm UTC](https://discuss.elastic.co/t/filebeat-for-os-solaris/292037 "2022-01-05T20:31:32Z")

</div>

Hello, can you recommend any officially supported tool/agent/alternative for OS Solaris, like Filebeat, Fluentd, FluentBit, etc. which allows parsing log files, please? We use "collectd" at the moment. It works fine, but…

---

## [Metricbeat host not showing on kibana as well as not creating index](https://discuss.elastic.co/t/metricbeat-host-not-showing-on-kibana-as-well-as-not-creating-index/292567)

<div class="topic-metadata">

**Author:** [@jonoyo](https://discuss.elastic.co/u/jonoyo)\
**Replies:** 13\
**Last updated:** [January 5, 2022, 6:52pm UTC](https://discuss.elastic.co/t/metricbeat-host-not-showing-on-kibana-as-well-as-not-creating-index/292567 "2022-01-05T18:52:01Z")

</div>

After install the metricbeat on localhost elk server its showing on kibana dashboard but when metricbeat installing on another machine metricbeat host are not showing except elk localhost metricbeat host. metricbeat ver…

---

## [Registry blows up after filebeat container restarts](https://discuss.elastic.co/t/registry-blows-up-after-filebeat-container-restarts/293572)

<div class="topic-metadata">

**Author:** [@ivankovnikita1992](https://discuss.elastic.co/u/ivankovnikita1992)\
**Replies:** 0\
**Last updated:** [January 5, 2022, 5:51pm UTC](https://discuss.elastic.co/t/registry-blows-up-after-filebeat-container-restarts/293572 "2022-01-05T17:51:58Z")

</div>

Hello there, I've already read a lot of docs and issues but haven't found any solution for my problem, so hopefully someone can help... Our implementation is pretty simple - filebeat is set as daemonset for kubernetes …

---

## [Filebeat with multiple input - log sources](https://discuss.elastic.co/t/filebeat-with-multiple-input-log-sources/293567)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat1](https://discuss.elastic.co/u/Elie_Sbat1)\
**Replies:** 0\
**Last updated:** [January 5, 2022, 5:19pm UTC](https://discuss.elastic.co/t/filebeat-with-multiple-input-log-sources/293567 "2022-01-05T17:19:35Z")

</div>

Hello, I am using filebeat 7.16 and I am trying to import multiple logs from different directories (.log and .csv). Also, I am trying to creat different index for each one of them. All of this must be done using one fil…

---

## [Filebeat could not send to the kafka](https://discuss.elastic.co/t/filebeat-could-not-send-to-the-kafka/293528)

<div class="topic-metadata">

**Author:** [@flover97](https://discuss.elastic.co/u/flover97)\
**Replies:** 1\
**Last updated:** [January 5, 2022, 2:41pm UTC](https://discuss.elastic.co/t/filebeat-could-not-send-to-the-kafka/293528 "2022-01-05T14:41:29Z")

</div>

Hello everyone, I ran into a problem that filebeat does not send data to kafka. Filebeat connects exactly to the kafka as it creates an empty topic, but the data does not come, I see no errors in the debug. Could there b…

---

## [Collecting JMX statistics from every single pod](https://discuss.elastic.co/t/collecting-jmx-statistics-from-every-single-pod/293540)

<div class="topic-metadata">

**Author:** [@ezopek3](https://discuss.elastic.co/u/ezopek3)\
**Replies:** 0\
**Last updated:** [January 5, 2022, 12:57pm UTC](https://discuss.elastic.co/t/collecting-jmx-statistics-from-every-single-pod/293540 "2022-01-05T12:57:33Z")

</div>

Hello, As my goal, I want to use Jolokia JVM agent with Metricbeat Kubernetes autodiscovery (with Jolokia module) to monitor my Java application statistics. Usually, we use Deployments to deploy our applications with s…

---

## [How to interpret filebeat logs?](https://discuss.elastic.co/t/how-to-interpret-filebeat-logs/293524)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [January 5, 2022, 10:47am UTC](https://discuss.elastic.co/t/how-to-interpret-filebeat-logs/293524 "2022-01-05T10:47:12Z")

</div>

Hi, I'm running filebeat 7.14.0 to ingest Netflow data, which is then stored in Elasticsearch and viewed on Kibana. When I run "filebeat -e", I will see some logs generated by filebeat every 30s. The logs are similar to…

---

## [Osquery causing policy to go unhealthy](https://discuss.elastic.co/t/osquery-causing-policy-to-go-unhealthy/293482)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 0\
**Last updated:** [January 4, 2022, 11:15pm UTC](https://discuss.elastic.co/t/osquery-causing-policy-to-go-unhealthy/293482 "2022-01-04T23:15:49Z")

</div>

Currently running stack version 7.16.2 and am constantly having issues with the osquery manager integration. It keeps causing my agents to go unhealthy. Any reason why it is causing these issues?

---

## [Filebeat - avoid data duplication during switch over](https://discuss.elastic.co/t/filebeat-avoid-data-duplication-during-switch-over/293319)

<div class="topic-metadata">

**Author:** [@sandeepmuthathi](https://discuss.elastic.co/u/sandeepmuthathi)\
**Replies:** 1\
**Last updated:** [January 4, 2022, 10:11pm UTC](https://discuss.elastic.co/t/filebeat-avoid-data-duplication-during-switch-over/293319 "2022-01-04T22:11:54Z")

</div>

I've a scenario where I need to read the file contents from an NFS mount point using filebeat. Also, I need to install another filebeat instance on another system incase the first machine (where i installed filebeat) goe…

---

## [Filebeat parsing long log](https://discuss.elastic.co/t/filebeat-parsing-long-log/293438)

<div class="topic-metadata">

**Author:** [@Milad\_Akhlaghi](https://discuss.elastic.co/u/Milad_Akhlaghi)\
**Replies:** 0\
**Last updated:** [January 4, 2022, 11:49am UTC](https://discuss.elastic.co/t/filebeat-parsing-long-log/293438 "2022-01-04T11:49:01Z")

</div>

Hi Friends, i have a long log and i'm trying to parse it with javascript this is the filebeat config that i have: filebeat.inputs: - type: log enabled: true paths: - /root/logtest/test.log # clean\_removed: tr…

---

## [Parse Exchange Message tracking logs via Dissect filebeat processor](https://discuss.elastic.co/t/parse-exchange-message-tracking-logs-via-dissect-filebeat-processor/293445)

<div class="topic-metadata">

**Author:** [@a.gavric](https://discuss.elastic.co/u/a.gavric)\
**Replies:** 8\
**Last updated:** [January 4, 2022, 2:06pm UTC](https://discuss.elastic.co/t/parse-exchange-message-tracking-logs-via-dissect-filebeat-processor/293445 "2022-01-04T14:06:47Z")

</div>

Hello everyone i have been trying to ingest and parse Exchange message tracking logs via filebeat dissect processor to generate fields i need from the log rather than the beat dumping the entire log into the message fiel…

---

## [Filebeat read file from beginning always when restart](https://discuss.elastic.co/t/filebeat-read-file-from-beginning-always-when-restart/293325)

<div class="topic-metadata">

**Author:** [@sc.lai](https://discuss.elastic.co/u/sc.lai)\
**Replies:** 1\
**Last updated:** [January 4, 2022, 11:38am UTC](https://discuss.elastic.co/t/filebeat-read-file-from-beginning-always-when-restart/293325 "2022-01-04T11:38:23Z")

</div>

I have a problem with filebeat running on Linux, every time I stop the filebeat and then start it, it always read file from the beginning. The log file uploaded by windows batch every 5 minutes, steps as below: put t…

---

## [AWS Beanstalk and Elastic Cloud Filebeat](https://discuss.elastic.co/t/aws-beanstalk-and-elastic-cloud-filebeat/293385)

<div class="topic-metadata">

**Author:** [@tsoeiro](https://discuss.elastic.co/u/tsoeiro)\
**Replies:** 0\
**Last updated:** [January 3, 2022, 9:00pm UTC](https://discuss.elastic.co/t/aws-beanstalk-and-elastic-cloud-filebeat/293385 "2022-01-03T21:00:13Z")

</div>

I have a docker container running on AWS Beanstalk. Is it possible to ingest my docker container logs into Elasticsearch (Cloud service) using Filebeats? Could not find a proper Elastic Integration ingest option for Be…

---

## [Exiting: error loading template: failed to load template: couldn't load template: 400 Bad Request:](https://discuss.elastic.co/t/exiting-error-loading-template-failed-to-load-template-couldnt-load-template-400-bad-request/292423)

<div class="topic-metadata">

**Author:** [@mshah](https://discuss.elastic.co/u/mshah)\
**Replies:** 3\
**Last updated:** [January 4, 2022, 12:34am UTC](https://discuss.elastic.co/t/exiting-error-loading-template-failed-to-load-template-couldnt-load-template-400-bad-request/292423 "2022-01-04T00:34:10Z")

</div>

Hi All, I am new to Elastic stack and trying out a PoC to get approval but i am unable to get winlogBeat or File beat working. Tried multiple time and looked around online but not sure where i am missing. I get below e…

---

## [Alert when a service stops on linux](https://discuss.elastic.co/t/alert-when-a-service-stops-on-linux/293003)

<div class="topic-metadata">

**Author:** [@derek.olds](https://discuss.elastic.co/u/derek.olds)\
**Replies:** 3\
**Last updated:** [January 3, 2022, 5:39pm UTC](https://discuss.elastic.co/t/alert-when-a-service-stops-on-linux/293003 "2022-01-03T17:39:33Z")

</div>

I can get a list of processes running on a host, but I don't get a signal when the process stops. Do I need to set something up to track number of records over a given time? Is there an easier way?

---

## [Cisco IOS Fleet integration unable to properly grok generated messages](https://discuss.elastic.co/t/cisco-ios-fleet-integration-unable-to-properly-grok-generated-messages/293375)

<div class="topic-metadata">

**Author:** [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Replies:** 0\
**Last updated:** [January 3, 2022, 5:20pm UTC](https://discuss.elastic.co/t/cisco-ios-fleet-integration-unable-to-properly-grok-generated-messages/293375 "2022-01-03T17:20:14Z")

</div>

I've just begun working with some of the fleet integrations, specifically v1.2 of the Cisco\_IOS version and have some of our switches sending data properly and being received. However, every entry is unable to properly p…

---

## [Unable to add custom analyzer](https://discuss.elastic.co/t/unable-to-add-custom-analyzer/293373)

<div class="topic-metadata">

**Author:** [@maviles](https://discuss.elastic.co/u/maviles)\
**Replies:** 0\
**Last updated:** [January 3, 2022, 4:37pm UTC](https://discuss.elastic.co/t/unable-to-add-custom-analyzer/293373 "2022-01-03T16:37:38Z")

</div>

Greetings, I'm unable to add a custom analyzer "tokenizer" to an existing, up and running index. I'm able to add the same custom analyzer creating a new index and reindexing an old one to a recently created one. However…

---

## [Monitoring Logstash using Metricbeat](https://discuss.elastic.co/t/monitoring-logstash-using-metricbeat/293344)

<div class="topic-metadata">

**Author:** [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Replies:** 7\
**Last updated:** [January 3, 2022, 2:44pm UTC](https://discuss.elastic.co/t/monitoring-logstash-using-metricbeat/293344 "2022-01-03T14:44:04Z")

</div>

Hi, I have 3 instances of Logstash and want to monitor them in Kibana This is my /etc/metricbeat/modules.d/logstash-xpack.yml configuration: # Module: logstash # Docs: https://www.elastic.co/guide/en/beats/metricbeat/…

---

## [FileBeat How to control the ports used](https://discuss.elastic.co/t/filebeat-how-to-control-the-ports-used/293296)

<div class="topic-metadata">

**Author:** [@gaogao110](https://discuss.elastic.co/u/gaogao110)\
**Replies:** 5\
**Last updated:** [January 3, 2022, 1:23pm UTC](https://discuss.elastic.co/t/filebeat-how-to-control-the-ports-used/293296 "2022-01-03T13:23:30Z")

</div>

During use, the program will randomly start the port, is there any way to control ?

---

## [Some puzzle about filebeat version7.x rpm installation](https://discuss.elastic.co/t/some-puzzle-about-filebeat-version7-x-rpm-installation/293312)

<div class="topic-metadata">

**Author:** [@mmgithub123](https://discuss.elastic.co/u/mmgithub123)\
**Replies:** 2\
**Last updated:** [January 3, 2022, 12:59pm UTC](https://discuss.elastic.co/t/some-puzzle-about-filebeat-version7-x-rpm-installation/293312 "2022-01-03T12:59:47Z")

</div>

about this topic，there are some discuss before，for example： and but，the basic question is ，when we install filebeat use rpm follow this page ：Filebeat quick start: installation and configuration | Filebeat Reference…

---

## [Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data)](https://discuss.elastic.co/t/exiting-data-path-already-locked-by-another-beat-please-make-sure-that-multiple-beats-are-not-sharing-the-same-data-path-path-data/293158)

<div class="topic-metadata">

**Author:** [@sujitk72](https://discuss.elastic.co/u/sujitk72)\
**Replies:** 1\
**Last updated:** [January 3, 2022, 12:35pm UTC](https://discuss.elastic.co/t/exiting-data-path-already-locked-by-another-beat-please-make-sure-that-multiple-beats-are-not-sharing-the-same-data-path-path-data/293158 "2022-01-03T12:35:53Z")

</div>

I have removed 5x and installed 7x that is not working. ./filebeat -e -d "\*" 2021-12-30T02:52:25.982+0530 INFO instance/beat.go:686 Home path: \[/app/filebeat-7.16.2-linux-x86\_64\] Config path: \[/app/filebeat-7.16.2-linu…

---

## [Load index template through logstash](https://discuss.elastic.co/t/load-index-template-through-logstash/293328)

<div class="topic-metadata">

**Author:** [@okopnik](https://discuss.elastic.co/u/okopnik)\
**Replies:** 1\
**Last updated:** [January 3, 2022, 12:17pm UTC](https://discuss.elastic.co/t/load-index-template-through-logstash/293328 "2022-01-03T12:17:19Z")

</div>

For a while, I've been shipping events from winlogbeat to logstash and then to elastic. I used my own, very basic template. I cannot figure out how to load the winlogbeat template to elastic. Is it possible to do this wh…

---

## [Metricbeat doesn't monitor all instances](https://discuss.elastic.co/t/metricbeat-doesnt-monitor-all-instances/293321)

<div class="topic-metadata">

**Author:** [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Replies:** 2\
**Last updated:** [January 3, 2022, 8:52am UTC](https://discuss.elastic.co/t/metricbeat-doesnt-monitor-all-instances/293321 "2022-01-03T08:52:37Z")

</div>

Hi dears I have 3 instances of Logstash, and a Metricbeat (on another server) The problem is Metricbeat just shows one of the Logstash instances in "Stack Monitoring" The relative config of logstash.yml node 1: # --…

---

## [Elastic Agent + Fleet in AWS ECS Fargate](https://discuss.elastic.co/t/elastic-agent-fleet-in-aws-ecs-fargate/293226)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 2\
**Last updated:** [January 1, 2022, 2:29am UTC](https://discuss.elastic.co/t/elastic-agent-fleet-in-aws-ecs-fargate/293226 "2022-01-01T02:29:28Z")

</div>

I want to run Elastic Agent in ECS task container and manage it with a Fleet policy. I can't seem to find anyone whose written about this before and I'm a little stuck. Running Elastic Cloud 7.15 In general, should I …

---

## [Registry not working in filebeat 7.16.1](https://discuss.elastic.co/t/registry-not-working-in-filebeat-7-16-1/292464)

<div class="topic-metadata">

**Author:** [@bbailey](https://discuss.elastic.co/u/bbailey)\
**Replies:** 4\
**Last updated:** [December 31, 2021, 12:16pm UTC](https://discuss.elastic.co/t/registry-not-working-in-filebeat-7-16-1/292464 "2021-12-31T12:16:35Z")

</div>

I have recently updated from filebeat 7.7.1 to 7.16.1 running in docker and finding that even though the registry is persisted, each time I restart the filebeat container all logs are being re-read When I reverted from …

---

## [Issue with Keystore on winlogbeat](https://discuss.elastic.co/t/issue-with-keystore-on-winlogbeat/293138)

<div class="topic-metadata">

**Author:** [@sbemiller](https://discuss.elastic.co/u/sbemiller)\
**Replies:** 9\
**Last updated:** [December 30, 2021, 4:30pm UTC](https://discuss.elastic.co/t/issue-with-keystore-on-winlogbeat/293138 "2021-12-30T16:30:55Z")

</div>

Elastic 7.15.1 I have read through a lot of discussions on how to solve this issue but nothing is working. I am working on an install process for the winlogbeat service. The Service installs and starts with no issues …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=113)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=115)
