# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=116

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 117

---

## [Use processor like translate plugin in logstash for filebeat](https://discuss.elastic.co/t/use-processor-like-translate-plugin-in-logstash-for-filebeat/291987)

<div class="topic-metadata">

**Author:** [@Paf](https://discuss.elastic.co/u/Paf)\
**Replies:** 2\
**Last updated:** [December 21, 2021, 9:40am UTC](https://discuss.elastic.co/t/use-processor-like-translate-plugin-in-logstash-for-filebeat/291987 "2021-12-21T09:40:29Z")

</div>

Hi, I want to use processor like translate plugin in Logstash for Filebeat, to compare a field value with a list from file and add another field if matched. I search processor in Filbeat documentation, but I did not fi…

---

## [\[elastic\_agent.filebeat\]\[error\] failed to perform any bulk index operations: Post "http://ES:9200/\_bulk": context deadline exceeded (Client.Timeout exceeded while awaiting headers)](https://discuss.elastic.co/t/elastic-agent-filebeat-error-failed-to-perform-any-bulk-index-operations-post-http-es-9200-bulk-context-deadline-exceeded-client-timeout-exceeded-while-awaiting-headers/292298)

<div class="topic-metadata">

**Author:** [@Tony\_B\_Kunnath](https://discuss.elastic.co/u/Tony_B_Kunnath)\
**Replies:** 1\
**Last updated:** [December 20, 2021, 6:33pm UTC](https://discuss.elastic.co/t/elastic-agent-filebeat-error-failed-to-perform-any-bulk-index-operations-post-http-es-9200-bulk-context-deadline-exceeded-client-timeout-exceeded-while-awaiting-headers/292298 "2021-12-20T18:33:50Z")

</div>

Getting this error in elastic-agent log: \[elastic\_agent.filebeat\]\[error\] failed to perform any bulk index operations: Post "http://ES:9200/\_bulk": context deadline exceeded (Client.Timeout exceeded while awaiting header…

---

## [Close inactive option in filebeat](https://discuss.elastic.co/t/close-inactive-option-in-filebeat/292458)

<div class="topic-metadata">

**Author:** [@mangesh\_shinde](https://discuss.elastic.co/u/mangesh_shinde)\
**Replies:** 3\
**Last updated:** [December 20, 2021, 5:06pm UTC](https://discuss.elastic.co/t/close-inactive-option-in-filebeat/292458 "2021-12-20T17:06:15Z")

</div>

I do have file which may in active for long time so I cant use close\_inactive option in filebeat so is there any option to disable this. inactivity time might be days so

---

## [Winlogbeat event id missing](https://discuss.elastic.co/t/winlogbeat-event-id-missing/292200)

<div class="topic-metadata">

**Author:** [@aditi\_salunke](https://discuss.elastic.co/u/aditi_salunke)\
**Replies:** 4\
**Last updated:** [December 20, 2021, 2:58pm UTC](https://discuss.elastic.co/t/winlogbeat-event-id-missing/292200 "2021-12-20T14:58:36Z")

</div>

Hello, Will winlogbeat forward the log to Elasticsearch if it is installed on AD and when someone lockout from the system and if the account lockout log is dropping on AD? eg.: if 10 users are getting locked out on the…

---

## [Strigo account SSL issue for mysql](https://discuss.elastic.co/t/strigo-account-ssl-issue-for-mysql/292371)

<div class="topic-metadata">

**Author:** [@kapilsapra](https://discuss.elastic.co/u/kapilsapra)\
**Replies:** 5\
**Last updated:** [December 20, 2021, 12:02pm UTC](https://discuss.elastic.co/t/strigo-account-ssl-issue-for-mysql/292371 "2021-12-20T12:02:33Z")

</div>

I am trying to configure and run filebeat on the mysql server in strigo environment. when i run filebeat i am getting SSL error that certificate signed by some different authority. 2021-12-18T05:35:20.274Z INFO …

---

## [No monitoring data found version 7.16.1](https://discuss.elastic.co/t/no-monitoring-data-found-version-7-16-1/292113)

<div class="topic-metadata">

**Author:** [@marek.vesely](https://discuss.elastic.co/u/marek.vesely)\
**Replies:** 1\
**Last updated:** [December 20, 2021, 7:58am UTC](https://discuss.elastic.co/t/no-monitoring-data-found-version-7-16-1/292113 "2021-12-20T07:58:08Z")

</div>

Hello, today i updated to latest version of ELK stack because of log4j... I updated from version 7.15.0 which works perfect, but no i don't see monitoring data. In metricbeat logs i see this error: (status=400): {"type…

---

## [Elastic Agent Minimum System Requirements](https://discuss.elastic.co/t/elastic-agent-minimum-system-requirements/292340)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 1\
**Last updated:** [December 20, 2021, 7:39am UTC](https://discuss.elastic.co/t/elastic-agent-minimum-system-requirements/292340 "2021-12-20T07:39:58Z")

</div>

Does anyone know what the minimum system requirements (CPU/RAM/Disk) are for Elastic Agent to properly function? I'm running into some issues with some of the smaller systems I manage, and suspect the issues are caused …

---

## [Filebeat service not starting with nginx, elasticsearch and kibana on aws ec2 instance](https://discuss.elastic.co/t/filebeat-service-not-starting-with-nginx-elasticsearch-and-kibana-on-aws-ec2-instance/292384)

<div class="topic-metadata">

**Author:** [@deepak.tripathi.259](https://discuss.elastic.co/u/deepak.tripathi.259)\
**Replies:** 2\
**Last updated:** [December 20, 2021, 5:10am UTC](https://discuss.elastic.co/t/filebeat-service-not-starting-with-nginx-elasticsearch-and-kibana-on-aws-ec2-instance/292384 "2021-12-20T05:10:20Z")

</div>

I want to display nginx logs on kibana. Elasticsearch and kibana are running fine. Nginx logs are stored in /var/log/nginx/\*.log I installed filebeat and enbled the nginx service with it. filebeat.yml #############…

---

## [Oracle DB performance monitoring with ELK (MetricBeat)](https://discuss.elastic.co/t/oracle-db-performance-monitoring-with-elk-metricbeat/292000)

<div class="topic-metadata">

**Author:** [@tonypro](https://discuss.elastic.co/u/tonypro)\
**Replies:** 1\
**Last updated:** [December 20, 2021, 1:14am UTC](https://discuss.elastic.co/t/oracle-db-performance-monitoring-with-elk-metricbeat/292000 "2021-12-20T01:14:48Z")

</div>

Greetings buddy! Please, I have been struggle on how to monitored an oracle DB instance, using the ELK stack. I read that you can use the metric beat's oracle module to ship data to the Elasticsearch engine. But I am st…

---

## [Metricbeat Elasticsearch module unexpected memory usage on master](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-unexpected-memory-usage-on-master/292361)

<div class="topic-metadata">

**Author:** [@Charles\_Ferguson](https://discuss.elastic.co/u/Charles_Ferguson)\
**Replies:** 0\
**Last updated:** [December 17, 2021, 9:57pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-unexpected-memory-usage-on-master/292361 "2021-12-17T21:57:02Z")

</div>

Hello, I am having an issue with trying to configure metricbeats Elasticsearch module. The specific issue I am seeing is that I have configured a daemonset of metricbeats to collect node and nodes\_stats metrics from all …

---

## [Monitor if a process is running or stopped](https://discuss.elastic.co/t/monitor-if-a-process-is-running-or-stopped/292411)

<div class="topic-metadata">

**Author:** [@Kevin\_Brunette](https://discuss.elastic.co/u/Kevin_Brunette)\
**Replies:** 1\
**Last updated:** [December 19, 2021, 6:40pm UTC](https://discuss.elastic.co/t/monitor-if-a-process-is-running-or-stopped/292411 "2021-12-19T18:40:41Z")

</div>

Hi! I'm trying to do a seemingly simple task of monitoring whether a process is running or stopped on an Ubuntu host. For example I want to know if a Java and Python based app are running or down. I'm aware there are so…

---

## [Heartbeat Browser Monitor Zip URL: not a valid zip file](https://discuss.elastic.co/t/heartbeat-browser-monitor-zip-url-not-a-valid-zip-file/292222)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 9\
**Last updated:** [December 18, 2021, 12:23am UTC](https://discuss.elastic.co/t/heartbeat-browser-monitor-zip-url-not-a-valid-zip-file/292222 "2021-12-18T00:23:42Z")

</div>

Hi, I'm trying to use the Heartbeat Browser monitor with the Zip URL source, but am running into a weird issue. Has anyone gotten Zip URL to work with GitLab zip urls? I get the following error when Heartbeat tries to…

---

## [How to specify the index to send the logs of specific microservice](https://discuss.elastic.co/t/how-to-specify-the-index-to-send-the-logs-of-specific-microservice/290038)

<div class="topic-metadata">

**Author:** [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Replies:** 4\
**Last updated:** [December 17, 2021, 4:12pm UTC](https://discuss.elastic.co/t/how-to-specify-the-index-to-send-the-logs-of-specific-microservice/290038 "2021-12-17T16:12:30Z")

</div>

Hi, I'm working with GKE and Elastic cloud. I have configured filebeat in my k8s cluster and is working fine, but is sending all the logs to one index, and I would like for some specific services send the logs to anothe…

---

## [Loose output permissions given to Elastic Agent](https://discuss.elastic.co/t/loose-output-permissions-given-to-elastic-agent/292297)

<div class="topic-metadata">

**Author:** [@DamianoChini](https://discuss.elastic.co/u/DamianoChini)\
**Replies:** 2\
**Last updated:** [December 17, 2021, 2:39pm UTC](https://discuss.elastic.co/t/loose-output-permissions-given-to-elastic-agent/292297 "2021-12-17T14:39:44Z")

</div>

Hi all! If in Fleet I configure a Policy without any integration, the Elastic Agents associated with that Policy receive output permissions on logs-\*, metrics-\*, traces-\* and synthetics-\*. This means that these Elasti…

---

## [Winlogbeat - Need Help with Drop\_fields](https://discuss.elastic.co/t/winlogbeat-need-help-with-drop-fields/291926)

<div class="topic-metadata">

**Author:** [@0xf](https://discuss.elastic.co/u/0xf)\
**Replies:** 3\
**Last updated:** [December 17, 2021, 1:41pm UTC](https://discuss.elastic.co/t/winlogbeat-need-help-with-drop-fields/291926 "2021-12-17T13:41:15Z")

</div>

So basically what i would like to do is drop everything from the fields and manually include a few. So to say, i want to drop every field that im not putting/specifying in this config file. In this case i tried to spec…

---

## [Metricbeat only sending some kube-state-metrics to elastic](https://discuss.elastic.co/t/metricbeat-only-sending-some-kube-state-metrics-to-elastic/292142)

<div class="topic-metadata">

**Author:** [@bagdus](https://discuss.elastic.co/u/bagdus)\
**Replies:** 3\
**Last updated:** [December 17, 2021, 12:50pm UTC](https://discuss.elastic.co/t/metricbeat-only-sending-some-kube-state-metrics-to-elastic/292142 "2021-12-17T12:50:40Z")

</div>

Hello I've been struggling with an issue i have with metricbeats kubernetes module. Specifically the processing of kube-state-metrics. Versions: kube-state-metrics 2.2.4 Metricbeat/ELK 7.15 The issue: Scraping of k…

---

## [Host.name FQDN](https://discuss.elastic.co/t/host-name-fqdn/292252)

<div class="topic-metadata">

**Author:** [@Anton75](https://discuss.elastic.co/u/Anton75)\
**Replies:** 0\
**Last updated:** [December 17, 2021, 4:00am UTC](https://discuss.elastic.co/t/host-name-fqdn/292252 "2021-12-17T04:00:38Z")

</div>

Hi! Is it possible to get FQDN hostname from agent host (like hostname -f in Linux)? In my case filebeat sends short hostname, like hostname -s. Hosts are RedHat 7.9. Thank you.

---

## [Libbeat or Official Beat Delivery Guarantees with Logstash Ingest?](https://discuss.elastic.co/t/libbeat-or-official-beat-delivery-guarantees-with-logstash-ingest/292220)

<div class="topic-metadata">

**Author:** [@benatsb](https://discuss.elastic.co/u/benatsb)\
**Replies:** 0\
**Last updated:** [December 16, 2021, 8:35pm UTC](https://discuss.elastic.co/t/libbeat-or-official-beat-delivery-guarantees-with-logstash-ingest/292220 "2021-12-16T20:35:42Z")

</div>

Hello, I'm looking for an overview and in-depth details on elastic beat delivery guarantees including queuing with Logstash, but information is hard to find... I have only been able to find information regarding Filebe…

---

## [Elastic Agent/Fleet Limit how many agents get a policy update at once](https://discuss.elastic.co/t/elastic-agent-fleet-limit-how-many-agents-get-a-policy-update-at-once/292175)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 4\
**Last updated:** [December 16, 2021, 6:14pm UTC](https://discuss.elastic.co/t/elastic-agent-fleet-limit-how-many-agents-get-a-policy-update-at-once/292175 "2021-12-16T18:14:12Z")

</div>

Hi All, I was wondering if there is a way to limit the number of agents that can pull an updated policy at once? The reason for this, is I have noticed that in large deployments where I perform a policy update (i.e.: a…

---

## [Beat templates and ECS generator](https://discuss.elastic.co/t/beat-templates-and-ecs-generator/292159)

<div class="topic-metadata">

**Author:** [@Thomas74](https://discuss.elastic.co/u/Thomas74)\
**Replies:** 0\
**Last updated:** [December 16, 2021, 1:29pm UTC](https://discuss.elastic.co/t/beat-templates-and-ecs-generator/292159 "2021-12-16T13:29:35Z")

</div>

Hi, I wonder if I can generate an index template for every beats via ECS generator repo : GitHub - elastic/ecs: Elastic Common Schema It could be easier to generate one big file, with custom configs (example number …

---

## [Dashboard setup fails: Unable to bulk\_create index-pattern](https://discuss.elastic.co/t/dashboard-setup-fails-unable-to-bulk-create-index-pattern/292007)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 4\
**Last updated:** [December 16, 2021, 9:07am UTC](https://discuss.elastic.co/t/dashboard-setup-fails-unable-to-bulk-create-index-pattern/292007 "2021-12-16T09:07:46Z")

</div>

Hello, I have encountered the same problem as the user in this post. I configured metricbeat and filebeat with the kibana\_system user. Should I create a new user that runs as a kibana\_system user and add some rights? W…

---

## [Monitoring WIndows Server](https://discuss.elastic.co/t/monitoring-windows-server/292111)

<div class="topic-metadata">

**Author:** [@labate](https://discuss.elastic.co/u/labate)\
**Replies:** 0\
**Last updated:** [December 16, 2021, 8:44am UTC](https://discuss.elastic.co/t/monitoring-windows-server/292111 "2021-12-16T08:44:36Z")

</div>

HI everyone, I don't understand why I'm not able to view the monitoring of my Windows server on the Metric menu on Kibana. I see the metric when I go in "Discover" menu but not in the metric menu. After some research I …

---

## [Auditbeat, filebeat and journalbeat in kubernetes](https://discuss.elastic.co/t/auditbeat-filebeat-and-journalbeat-in-kubernetes/291805)

<div class="topic-metadata">

**Author:** [@Dmitriy\_Esin](https://discuss.elastic.co/u/Dmitriy_Esin)\
**Replies:** 1\
**Last updated:** [December 15, 2021, 6:24pm UTC](https://discuss.elastic.co/t/auditbeat-filebeat-and-journalbeat-in-kubernetes/291805 "2021-12-15T18:24:51Z")

</div>

Hi all! I want to get an assistant with filebeat and auditbeat deployed in the k8s cluster. Here are my yamls: Auditbeat: Filebeat: It runs successfully and has logs: Auditbeat: Fiebeat: But I can't see any d…

---

## [Multiline.pattern for my log](https://discuss.elastic.co/t/multiline-pattern-for-my-log/291973)

<div class="topic-metadata">

**Author:** [@bourak\_justbourak](https://discuss.elastic.co/u/bourak_justbourak)\
**Replies:** 0\
**Last updated:** [December 15, 2021, 12:53pm UTC](https://discuss.elastic.co/t/multiline-pattern-for-my-log/291973 "2021-12-15T12:53:45Z")

</div>

Hi please help me what multiline.pattern is good for my log? My log contains blank line in the middle. Thanks a lot. 2021-12-08 01:00:00.020 DEBUG --- \[TaskScheduler-1\] \[c.i.f.g.c.s.d.InputService :\] : …

---

## [Metricbeat, http: server gave HTTP response to HTTPS client](https://discuss.elastic.co/t/metricbeat-http-server-gave-http-response-to-https-client/291835)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 2\
**Last updated:** [December 15, 2021, 3:33pm UTC](https://discuss.elastic.co/t/metricbeat-http-server-gave-http-response-to-https-client/291835 "2021-12-15T15:33:25Z")

</div>

Hi all, I am trying to activate basic security http in my ELK stack. My Elasticsearch version is 7.16.1. I create Elasticsearch-ssl-http.zip and add related files to config folder of Elasticsearch and kibana. Also I add…

---

## [Filebeat failed to publish events](https://discuss.elastic.co/t/filebeat-failed-to-publish-events/292001)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 0\
**Last updated:** [December 15, 2021, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events/292001 "2021-12-15T15:18:14Z")

</div>

Hi all, I am using ELK version 7.12.1 to harvest data using filebeat and then send them logstash. I have two nodes of logstash (10.0.0.1:5044 and 10.0.0.2:5044) My filebeat output config is as following: output.logst…

---

## [Beats are not vulnerable to Log4j2 RCE](https://discuss.elastic.co/t/beats-are-not-vulnerable-to-log4j2-rce/291992)

<div class="topic-metadata">

**Author:** [@dave101](https://discuss.elastic.co/u/dave101)\
**Replies:** 2\
**Last updated:** [December 15, 2021, 2:27pm UTC](https://discuss.elastic.co/t/beats-are-not-vulnerable-to-log4j2-rce/291992 "2021-12-15T14:27:46Z")

</div>

Hi there, maybe some can confirm the follow for us. A few days ago we read this article concerning the log4j vulnerability. Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31 Here it …

---

## [Monitor Fstab entry using metricbeat](https://discuss.elastic.co/t/monitor-fstab-entry-using-metricbeat/291980)

<div class="topic-metadata">

**Author:** [@abhi.logs](https://discuss.elastic.co/u/abhi.logs)\
**Replies:** 0\
**Last updated:** [December 15, 2021, 1:15pm UTC](https://discuss.elastic.co/t/monitor-fstab-entry-using-metricbeat/291980 "2021-12-15T13:15:16Z")

</div>

Hello, Can we monitor Fstab entry in metricbeat?

---

## [Unable to initialize Fleet as i get internal server error in kibana logs and on GUI "Default policy could not be added. system is not installed, add system to \`xpack.fleet.packages\` or remove it from system-1" i'm using 3 nodes cluster for elasticsearch](https://discuss.elastic.co/t/unable-to-initialize-fleet-as-i-get-internal-server-error-in-kibana-logs-and-on-gui-default-policy-could-not-be-added-system-is-not-installed-add-system-to-xpack-fleet-packages-or-remove-it-from-system-1-im-using-3-nodes-cluster-for-elasticsearch/291555)

<div class="topic-metadata">

**Author:** [@amr\_hamdy](https://discuss.elastic.co/u/amr_hamdy)\
**Replies:** 1\
**Last updated:** [December 15, 2021, 12:47pm UTC](https://discuss.elastic.co/t/unable-to-initialize-fleet-as-i-get-internal-server-error-in-kibana-logs-and-on-gui-default-policy-could-not-be-added-system-is-not-installed-add-system-to-xpack-fleet-packages-or-remove-it-from-system-1-im-using-3-nodes-cluster-for-elasticsearch/291555 "2021-12-15T12:47:39Z")

</div>

---

## [Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to http://localhost:5601/api/status fails: fail to execute the HTTP GET request](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-http-localhost-5601-api-status-fails-fail-to-execute-the-http-get-request/291933)

<div class="topic-metadata">

**Author:** [@M\_Solis](https://discuss.elastic.co/u/M_Solis)\
**Replies:** 1\
**Last updated:** [December 15, 2021, 9:20am UTC](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-http-localhost-5601-api-status-fails-fail-to-execute-the-http-get-request/291933 "2021-12-15T09:20:51Z")

</div>

Hello Everyone, I'm new to ELK Stack. Im trying to run the winlogbeat on a windows server but I'm experiencing some issues. Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to http:/…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=115)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=117)
