# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=115

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 116

---

## [Problem with pipeline, grok and dashboards](https://discuss.elastic.co/t/problem-with-pipeline-grok-and-dashboards/292818)

<div class="topic-metadata">

**Author:** [@roonick](https://discuss.elastic.co/u/roonick)\
**Replies:** 7\
**Last updated:** [December 30, 2021, 3:04pm UTC](https://discuss.elastic.co/t/problem-with-pipeline-grok-and-dashboards/292818 "2021-12-30T15:04:53Z")

</div>

Good day! I had following task. There was necessary to add additional field of client ip address from nginx logs. I composed next pipeline: filebeat -\> logstash (beats pipeline, frok) -\> Elasticsearch. Grok pattern wo…

---

## [Cisco Duo Integration not working](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 9\
**Last updated:** [December 30, 2021, 11:46am UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746 "2021-12-30T11:46:24Z")

</div>

Hello, I'm looking to ingest Cisco Duo logs, I signed up for a trial of Duo to test this out, but when adding the information to the Fleet integration, no logs are coming through to Elastic. I've followed the instructio…

---

## [Functionbeat missing package io/fs](https://discuss.elastic.co/t/functionbeat-missing-package-io-fs/284975)

<div class="topic-metadata">

**Author:** [@Yero\_Me](https://discuss.elastic.co/u/Yero_Me)\
**Replies:** 11\
**Last updated:** [December 30, 2021, 11:34am UTC](https://discuss.elastic.co/t/functionbeat-missing-package-io-fs/284975 "2021-12-30T11:34:18Z")

</div>

Hello, Since 7.15, deployment for functionbeat on GCP cloud function leads to an error : Function: functionbeat-XXXXX, could not update, error: error while creating function (code: 3): \[89\](/-/jobs/1615821324#L89)Buil…

---

## [Winlogbeat collect log from difference windows log source](https://discuss.elastic.co/t/winlogbeat-collect-log-from-difference-windows-log-source/293166)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 0\
**Last updated:** [December 30, 2021, 2:55am UTC](https://discuss.elastic.co/t/winlogbeat-collect-log-from-difference-windows-log-source/293166 "2021-12-30T02:55:52Z")

</div>

Hi all, In one of my systems i recently change the folder which windows event log get stored. Now i want to know if winlogbeat can collect log from the changed source or i have to change the config file to point to wher…

---

## [Integrations Docs](https://discuss.elastic.co/t/integrations-docs/293093)

<div class="topic-metadata">

**Author:** [@Sagi\_Tiger1](https://discuss.elastic.co/u/Sagi_Tiger1)\
**Replies:** 1\
**Last updated:** [December 29, 2021, 8:41pm UTC](https://discuss.elastic.co/t/integrations-docs/293093 "2021-12-29T20:41:42Z")

</div>

Im trying to locate some docs or guides on how to setup integrations using Kibana but unable to. Is there a specific area these are located in? Im trying to setup vpc flow logs to ES using an Integration but im stuck on …

---

## [How to parse additional kubernetes pods with json fomat logs?](https://discuss.elastic.co/t/how-to-parse-additional-kubernetes-pods-with-json-fomat-logs/293124)

<div class="topic-metadata">

**Author:** [@tarabhavi](https://discuss.elastic.co/u/tarabhavi)\
**Replies:** 0\
**Last updated:** [December 29, 2021, 1:45pm UTC](https://discuss.elastic.co/t/how-to-parse-additional-kubernetes-pods-with-json-fomat-logs/293124 "2021-12-29T13:45:11Z")

</div>

I have a ELK stack with Filebeat as an agent. Works great for collecting logs of existing pods. Here is the helm values for filebeat filebeatConfig: filebeat.yml: | logging.level: error filebeat.autodiscover:…

---

## [Filebeat - Module Elasticsearch 7.16](https://discuss.elastic.co/t/filebeat-module-elasticsearch-7-16/293087)

<div class="topic-metadata">

**Author:** [@cmmourinho](https://discuss.elastic.co/u/cmmourinho)\
**Replies:** 0\
**Last updated:** [December 29, 2021, 5:49am UTC](https://discuss.elastic.co/t/filebeat-module-elasticsearch-7-16/293087 "2021-12-29T05:49:31Z")

</div>

version Fliebeat, elasticsearch 7.16.2 I use filebeat collect elasticsearch log to another cluster. when i configure var.paths in modules.d/elasticsearch.yml var.paths: \["/var/log/elasticsearch/\*\_server.json"\] f…

---

## [Date Module Filebeat](https://discuss.elastic.co/t/date-module-filebeat/292946)

<div class="topic-metadata">

**Author:** [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Replies:** 1\
**Last updated:** [December 27, 2021, 1:59pm UTC](https://discuss.elastic.co/t/date-module-filebeat/292946 "2021-12-27T13:59:17Z")

</div>

hi, i'm create module fail2ban in filebeat but i have problem in date not match with dicovery kibana: and this is Pipeline module fail2ban: { "date" : { "field" : "fail2ban.date", "target\_…

---

## [Elastic Agent/Fleet Server cannot connect to elasticsearch](https://discuss.elastic.co/t/elastic-agent-fleet-server-cannot-connect-to-elasticsearch/292418)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 6\
**Last updated:** [December 27, 2021, 11:36am UTC](https://discuss.elastic.co/t/elastic-agent-fleet-server-cannot-connect-to-elasticsearch/292418 "2021-12-27T11:36:05Z")

</div>

Hello, I recently deployed Fleet Server with this command. sudo elastic-agent enroll --url=https://fqdn:8220 \\ --fleet-server-es=https://other-fqdn:9200 \\ --fleet-server-service-token=token \\ --fleet-server-polic…

---

## [Rollbar and SendGrid integration](https://discuss.elastic.co/t/rollbar-and-sendgrid-integration/292666)

<div class="topic-metadata">

**Author:** [@Gomathi\_Natarajan](https://discuss.elastic.co/u/Gomathi_Natarajan)\
**Replies:** 1\
**Last updated:** [December 27, 2021, 9:05am UTC](https://discuss.elastic.co/t/rollbar-and-sendgrid-integration/292666 "2021-12-27T09:05:39Z")

</div>

Hi Team, We are trying to integrate our third party services we are using in a ruby on rails application at one place for monitoring in Elastic. We are using the services Rollbar(Error tracking tool https://rollbar.com/)…

---

## [Is there is method to collect multiple types of elasticsearch logs when elasticsearchs and filebeats are deployed with ECK](https://discuss.elastic.co/t/is-there-is-method-to-collect-multiple-types-of-elasticsearch-logs-when-elasticsearchs-and-filebeats-are-deployed-with-eck/292656)

<div class="topic-metadata">

**Author:** [@bruce2](https://discuss.elastic.co/u/bruce2)\
**Replies:** 3\
**Last updated:** [December 27, 2021, 8:13am UTC](https://discuss.elastic.co/t/is-there-is-method-to-collect-multiple-types-of-elasticsearch-logs-when-elasticsearchs-and-filebeats-are-deployed-with-eck/292656 "2021-12-27T08:13:56Z")

</div>

I am using ECK1.6 to deploy Elasticsearch cluster 7.15.2 on k8s，and then using ECK to deploy filebeat to collect Elasticsearch server log, gc log, slowlog, deprecation log. There is an error as same as this issue File…

---

## [Winlogbeat does not start](https://discuss.elastic.co/t/winlogbeat-does-not-start/292952)

<div class="topic-metadata">

**Author:** [@George\_Thomas](https://discuss.elastic.co/u/George_Thomas)\
**Replies:** 1\
**Last updated:** [December 27, 2021, 5:57am UTC](https://discuss.elastic.co/t/winlogbeat-does-not-start/292952 "2021-12-27T05:57:22Z")

</div>

Hey All, I can't seem to start winlogbeat from c:\\programdata\\winlogbeat. It does not work on programfiles either so following a post here i tried it in programdata and still the same. any help would be appreciated.

---

## [Why is there no apmserver module for filebeat?](https://discuss.elastic.co/t/why-is-there-no-apmserver-module-for-filebeat/292850)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 2\
**Last updated:** [December 26, 2021, 1:03am UTC](https://discuss.elastic.co/t/why-is-there-no-apmserver-module-for-filebeat/292850 "2021-12-26T01:03:07Z")

</div>

I see that filebeat contains a lot of elastic stack modules, why is there no apmserver?

---

## [Shipping logs with filebeat and get logs with filebeat](https://discuss.elastic.co/t/shipping-logs-with-filebeat-and-get-logs-with-filebeat/292908)

<div class="topic-metadata">

**Author:** [@Milad\_Akhlaghi](https://discuss.elastic.co/u/Milad_Akhlaghi)\
**Replies:** 0\
**Last updated:** [December 25, 2021, 7:31am UTC](https://discuss.elastic.co/t/shipping-logs-with-filebeat-and-get-logs-with-filebeat/292908 "2021-12-25T07:31:34Z")

</div>

Hi everybody I'm working with elk and I need to take out logstash because my logs are too huge and logstash is making my process slow. so I decided to use filebeat instead. but I want to know is it possible to collect a…

---

## [Metricbeat single run](https://discuss.elastic.co/t/metricbeat-single-run/292721)

<div class="topic-metadata">

**Author:** [@tobias\_c](https://discuss.elastic.co/u/tobias_c)\
**Replies:** 5\
**Last updated:** [December 24, 2021, 6:29pm UTC](https://discuss.elastic.co/t/metricbeat-single-run/292721 "2021-12-24T18:29:03Z")

</div>

Hi all Is it possible to let run metricbeat once and then terminate? So the service (everlasting process) is not wanted. Thanks Tobias

---

## [Filebeat config check isn't reliable](https://discuss.elastic.co/t/filebeat-config-check-isnt-reliable/292807)

<div class="topic-metadata">

**Author:** [@javond](https://discuss.elastic.co/u/javond)\
**Replies:** 1\
**Last updated:** [December 24, 2021, 3:06pm UTC](https://discuss.elastic.co/t/filebeat-config-check-isnt-reliable/292807 "2021-12-24T15:06:27Z")

</div>

With that config fields: domain: XXXXXXXXX filebeat: config: inputs: enabled: true path: /etc/filebeat/inputs.d/\*.yaml reload: enabled: true period: 30s modules: path:…

---

## [GROK Filter not working as expected](https://discuss.elastic.co/t/grok-filter-not-working-as-expected/292796)

<div class="topic-metadata">

**Author:** [@KVerbeeck](https://discuss.elastic.co/u/KVerbeeck)\
**Replies:** 2\
**Last updated:** [December 24, 2021, 3:04pm UTC](https://discuss.elastic.co/t/grok-filter-not-working-as-expected/292796 "2021-12-24T15:04:56Z")

</div>

Hello, While applying custom GROK filters to my sample data, i get unexpected results. Sample Data: hotspot offering lease x.x.x.x for xx:xx:xx:xx:xx:xx without success Grok Pattern: %{WORD:network.name} (?\<client.m…

---

## [Track frontend application UI events? Better way?](https://discuss.elastic.co/t/track-frontend-application-ui-events-better-way/292861)

<div class="topic-metadata">

**Author:** [@nagendrahk](https://discuss.elastic.co/u/nagendrahk)\
**Replies:** 2\
**Last updated:** [December 24, 2021, 4:58am UTC](https://discuss.elastic.co/t/track-frontend-application-ui-events-better-way/292861 "2021-12-24T04:58:05Z")

</div>

I want to build ELK application to track frontend events from my react application. I having two approaches in mind Store events in log file using winston package and later push it to logstash and elastic with filebeat…

---

## [Filebeat, different indices from different CSV](https://discuss.elastic.co/t/filebeat-different-indices-from-different-csv/292724)

<div class="topic-metadata">

**Author:** [@giron](https://discuss.elastic.co/u/giron)\
**Replies:** 1\
**Last updated:** [December 23, 2021, 10:29am UTC](https://discuss.elastic.co/t/filebeat-different-indices-from-different-csv/292724 "2021-12-23T10:29:28Z")

</div>

Hi all, I need your help to understand where or what is wrong. I need to read different file csv (for now 4 csv) and write the data in 4 indexs on elastic using Filebeat. This configuration with 2 CSV, 2 indexs and 2 p…

---

## [Filebeat kafka input using multiline parser gives no output](https://discuss.elastic.co/t/filebeat-kafka-input-using-multiline-parser-gives-no-output/292290)

<div class="topic-metadata">

**Author:** [@rsniper](https://discuss.elastic.co/u/rsniper)\
**Replies:** 1\
**Last updated:** [December 23, 2021, 5:27am UTC](https://discuss.elastic.co/t/filebeat-kafka-input-using-multiline-parser-gives-no-output/292290 "2021-12-23T05:27:39Z")

</div>

I have posted the issue on stackoverflow as well Filebeat kafka input using multiline parser gives no output Filebeat is configured to use input from kafka and output to file When the multiline setting is turned off, …

---

## [Setup Filebeat to run as a service](https://discuss.elastic.co/t/setup-filebeat-to-run-as-a-service/292726)

<div class="topic-metadata">

**Author:** [@vharabor](https://discuss.elastic.co/u/vharabor)\
**Replies:** 2\
**Last updated:** [December 22, 2021, 8:25pm UTC](https://discuss.elastic.co/t/setup-filebeat-to-run-as-a-service/292726 "2021-12-22T20:25:40Z")

</div>

I've setup Filebeat on AWS Amazon Linux 2 AMI using the setup instruction here : (Filebeat quick start: installation and configuration | Filebeat Reference \[7.16\] | Elastic) So basically : curl -L -O https://artifacts.…

---

## [Elastic-agent : endpoint-security.sock no such file or directory](https://discuss.elastic.co/t/elastic-agent-endpoint-security-sock-no-such-file-or-directory/292293)

<div class="topic-metadata">

**Author:** [@Lnood5](https://discuss.elastic.co/u/Lnood5)\
**Replies:** 3\
**Last updated:** [December 22, 2021, 4:08pm UTC](https://discuss.elastic.co/t/elastic-agent-endpoint-security-sock-no-such-file-or-directory/292293 "2021-12-22T16:08:41Z")

</div>

Hello, I work with self-managed stack v7.16.1 I have a probleme with endpoint security deployment elastic-agent diagnostics give for endpoint this error: elastic-agent diagnostics \* name: endpoint-security …

---

## [Linear increase cpu/memory utilization on auditbeat 7.15.0 or later](https://discuss.elastic.co/t/linear-increase-cpu-memory-utilization-on-auditbeat-7-15-0-or-later/292653)

<div class="topic-metadata">

**Author:** [@samuel.john](https://discuss.elastic.co/u/samuel.john)\
**Replies:** 0\
**Last updated:** [December 22, 2021, 8:40am UTC](https://discuss.elastic.co/t/linear-increase-cpu-memory-utilization-on-auditbeat-7-15-0-or-later/292653 "2021-12-22T08:40:00Z")

</div>

Hello, I've got running many auditbeat on linux. Recently, I've upgrade from auditbeat version 7.5.x to 7.15.2 But unexpected some server error occurred in this version. When "auditd" error continues to occur, the CP…

---

## [Metricbeat sql module with dynamic database values](https://discuss.elastic.co/t/metricbeat-sql-module-with-dynamic-database-values/292623)

<div class="topic-metadata">

**Author:** [@nsharath](https://discuss.elastic.co/u/nsharath)\
**Replies:** 0\
**Last updated:** [December 22, 2021, 12:29am UTC](https://discuss.elastic.co/t/metricbeat-sql-module-with-dynamic-database-values/292623 "2021-12-22T00:29:32Z")

</div>

I am using metricbeat 7.15 version with sql module enabled. I have a huge list of databases and currently my sql module config size is very big. I would like to know how to send the database name (e.g. database1, databa…

---

## [Journalbeat can't create an alias and fails to work](https://discuss.elastic.co/t/journalbeat-cant-create-an-alias-and-fails-to-work/201875)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 6\
**Last updated:** [December 21, 2021, 5:09pm UTC](https://discuss.elastic.co/t/journalbeat-cant-create-an-alias-and-fails-to-work/201875 "2021-12-21T17:09:29Z")

</div>

Journalbeat is having issues getting started. It seems like it fails to create an alias? journalctl -l --follow -u journalbeat eventually spits this out: Oct 01 15:33:43 hostname journalbeat\[30589\]: 2019-10-01T15:33:43…

---

## [Filebeat Azure plugin parsing error on azure.signinlogs.properties.authentication\_requirement\_policies field](https://discuss.elastic.co/t/filebeat-azure-plugin-parsing-error-on-azure-signinlogs-properties-authentication-requirement-policies-field/292586)

<div class="topic-metadata">

**Author:** [@vgarric](https://discuss.elastic.co/u/vgarric)\
**Replies:** 0\
**Last updated:** [December 21, 2021, 5:08pm UTC](https://discuss.elastic.co/t/filebeat-azure-plugin-parsing-error-on-azure-signinlogs-properties-authentication-requirement-policies-field/292586 "2021-12-21T17:08:20Z")

</div>

hi, we get drops with some logs from Azure signinlogs linked to the azure.signinlogs.properties.authentication\_requirement\_policies field parsing. Here is the logs from filebeat with azure module : 2021-12-21T15:24:27…

---

## [Version-specific beats index template for every update required?](https://discuss.elastic.co/t/version-specific-beats-index-template-for-every-update-required/292582)

<div class="topic-metadata">

**Author:** [@hafneren](https://discuss.elastic.co/u/hafneren)\
**Replies:** 0\
**Last updated:** [December 21, 2021, 4:14pm UTC](https://discuss.elastic.co/t/version-specific-beats-index-template-for-every-update-required/292582 "2021-12-21T16:14:26Z")

</div>

Hi, I'm trying to improve the security of my Elastic Stack through a least privilege architecture consisting of winlogbeat, filebeat, auditbeat -\> logstash -\> Elasticsearch & Kibana. My goal is that the different beats …

---

## [Monitor Filebeat's Uptime](https://discuss.elastic.co/t/monitor-filebeats-uptime/292480)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 1\
**Last updated:** [December 21, 2021, 3:26pm UTC](https://discuss.elastic.co/t/monitor-filebeats-uptime/292480 "2021-12-21T15:26:38Z")

</div>

Can Heartbeat be configured to monitor a filebeat instance and alert when that beat goes down? Is there another way to determine when a beat is not running when it should be? During version upgrades sometime a beat wil…

---

## [Filebeat harvesting](https://discuss.elastic.co/t/filebeat-harvesting/292376)

<div class="topic-metadata">

**Author:** [@Milad\_Akhlaghi](https://discuss.elastic.co/u/Milad_Akhlaghi)\
**Replies:** 2\
**Last updated:** [December 21, 2021, 12:44pm UTC](https://discuss.elastic.co/t/filebeat-harvesting/292376 "2021-12-21T12:44:35Z")

</div>

Hi everybody , i need some help on filebeat harvesting a log file . i have a problem and i need to know which logfile that already exist is harvesting by filebeat and how can i know that harvest is finished and how i ca…

---

## [Run Winlogbeat service under a custom account](https://discuss.elastic.co/t/run-winlogbeat-service-under-a-custom-account/292465)

<div class="topic-metadata">

**Author:** [@a.gavric](https://discuss.elastic.co/u/a.gavric)\
**Replies:** 1\
**Last updated:** [December 21, 2021, 11:11am UTC](https://discuss.elastic.co/t/run-winlogbeat-service-under-a-custom-account/292465 "2021-12-21T11:11:17Z")

</div>

Hi, I've been having some difficulties setting up winglobeat to run as a service under a custom domain account with logon as a service rights on a windows 2016 server. The reason we are doing that is to be compliant with…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=114)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=116)
