# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=117

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 118

---

## [Auditbeat update document\_id](https://discuss.elastic.co/t/auditbeat-update-document-id/291902)

<div class="topic-metadata">

**Author:** [@cva](https://discuss.elastic.co/u/cva)\
**Replies:** 0\
**Last updated:** [December 15, 2021, 6:18am UTC](https://discuss.elastic.co/t/auditbeat-update-document-id/291902 "2021-12-15T06:18:01Z")

</div>

Good day! I am sending auditbeat logs to elasticserch via logstash. In logstash output, added document\_id parameter to update document id in elasticserch: if "xml" in \[tags\] { elasticsearch { hosts =\> \[ "loc…

---

## [NGINX Ingress controller + Filebeat with NGINX module](https://discuss.elastic.co/t/nginx-ingress-controller-filebeat-with-nginx-module/291824)

<div class="topic-metadata">

**Author:** [@anton-johansson](https://discuss.elastic.co/u/anton-johansson)\
**Replies:** 1\
**Last updated:** [December 15, 2021, 5:26am UTC](https://discuss.elastic.co/t/nginx-ingress-controller-filebeat-with-nginx-module/291824 "2021-12-15T05:26:33Z")

</div>

Hey! We're using the NGINX Ingress Controller (GitHub - kubernetes/ingress-nginx: NGINX Ingress Controller for Kubernetes), hosted in our Kubernetes cluster. We're using Filebeat deployed as a DaemonSet that parses logs …

---

## [Input 'aws-s3' failed with: failed to initialize s3 poller](https://discuss.elastic.co/t/input-aws-s3-failed-with-failed-to-initialize-s3-poller/288130)

<div class="topic-metadata">

**Author:** [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Replies:** 50\
**Last updated:** [December 15, 2021, 3:05am UTC](https://discuss.elastic.co/t/input-aws-s3-failed-with-failed-to-initialize-s3-poller/288130 "2021-12-15T03:05:25Z")

</div>

Hi, I've been trying to setup AWS module on 7.15 Elastic Stack cluster running as containers to ingest cloudtrail, cloudwatch, elb, s3access and vpcflow events (configured only for cloudtrail atm). However, there seems…

---

## [Auditbeat scan rate setting module: file\_integrity](https://discuss.elastic.co/t/auditbeat-scan-rate-setting-module-file-integrity/291756)

<div class="topic-metadata">

**Author:** [@cva](https://discuss.elastic.co/u/cva)\
**Replies:** 0\
**Last updated:** [December 14, 2021, 7:29am UTC](https://discuss.elastic.co/t/auditbeat-scan-rate-setting-module-file-integrity/291756 "2021-12-14T07:29:00Z")

</div>

My goal is to get the exact number of logs along the path specified in auditbeat in elastic to build a schedule for receiving logs by day in kibana. The problem is that I get several duplicates of the same log in elasti…

---

## [Multiple filebeat config files](https://discuss.elastic.co/t/multiple-filebeat-config-files/291769)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 0\
**Last updated:** [December 14, 2021, 9:47am UTC](https://discuss.elastic.co/t/multiple-filebeat-config-files/291769 "2021-12-14T09:47:23Z")

</div>

I have two different logs format at input so I want to use multiple filebeat yml files and those pointing out to different logstash port my logstash configuration is based on these inputs filebeat1.yml filebeat.input…

---

## [Example dashboard module hasn't appeared](https://discuss.elastic.co/t/example-dashboard-module-hasnt-appeared/291766)

<div class="topic-metadata">

**Author:** [@Mamol27](https://discuss.elastic.co/u/Mamol27)\
**Replies:** 0\
**Last updated:** [December 14, 2021, 9:07am UTC](https://discuss.elastic.co/t/example-dashboard-module-hasnt-appeared/291766 "2021-12-14T09:07:55Z")

</div>

Hi! I configured Filebeat with module kafka. /opt/filebeat/config/filebeat.ym filebeat.inputs: - type: log enabled: false paths: - /var/log/\*.log - type: filestream enabled: false paths: - /var/log/\*.l…

---

## [Heartbeat autodiscover kubernetes pod](https://discuss.elastic.co/t/heartbeat-autodiscover-kubernetes-pod/290629)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 4\
**Last updated:** [December 14, 2021, 9:02am UTC](https://discuss.elastic.co/t/heartbeat-autodiscover-kubernetes-pod/290629 "2021-12-14T09:02:41Z")

</div>

Hi I want heartbeat to find every single kubernetes pod and send it to Elasticsearch uptime, however all I am able to currently get is the kubernetes nodes. Below is the config. apiVersion: v1 kind: ConfigMap metadata:…

---

## [Trouble setting up Elastic Agent Fleet server on self-managed Elasticsearch setup](https://discuss.elastic.co/t/trouble-setting-up-elastic-agent-fleet-server-on-self-managed-elasticsearch-setup/291443)

<div class="topic-metadata">

**Author:** [@iamuser](https://discuss.elastic.co/u/iamuser)\
**Replies:** 3\
**Last updated:** [December 14, 2021, 8:14am UTC](https://discuss.elastic.co/t/trouble-setting-up-elastic-agent-fleet-server-on-self-managed-elasticsearch-setup/291443 "2021-12-14T08:14:06Z")

</div>

hi all! I'm having a hard time setting up the elastic agent fleet server. The environment: single node Elasticsearch/wazuh installation with filebeat/metricbeat/heartbeat installed on the node host. I used to copy & past…

---

## [Configure filebeat to use API keys](https://discuss.elastic.co/t/configure-filebeat-to-use-api-keys/291726)

<div class="topic-metadata">

**Author:** [@bbangerter](https://discuss.elastic.co/u/bbangerter)\
**Replies:** 2\
**Last updated:** [December 14, 2021, 12:58am UTC](https://discuss.elastic.co/t/configure-filebeat-to-use-api-keys/291726 "2021-12-14T00:58:06Z")

</div>

I have Elasticsearch, kibana, and filebeat (version 7.15.2 for all) running on a CentOS 8 machine using minimal security settings. I now want to get it working with TLS enabled. I have Elasticsearch and kibana working w…

---

## [Filebeat multiline config not working](https://discuss.elastic.co/t/filebeat-multiline-config-not-working/290383)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 5\
**Last updated:** [December 13, 2021, 10:40pm UTC](https://discuss.elastic.co/t/filebeat-multiline-config-not-working/290383 "2021-12-13T22:40:30Z")

</div>

I have a 3rd party app that spits out a text file with multiple lines for a single event. An event has a consistent start line and an end line. I have tried filebeat configurations that grab everything after a specific …

---

## [Heartbeat.yml nano error](https://discuss.elastic.co/t/heartbeat-yml-nano-error/291680)

<div class="topic-metadata">

**Author:** [@Brendanluvsdata](https://discuss.elastic.co/u/Brendanluvsdata)\
**Replies:** 3\
**Last updated:** [December 13, 2021, 6:25pm UTC](https://discuss.elastic.co/t/heartbeat-yml-nano-error/291680 "2021-12-13T18:25:17Z")

</div>

The lab says to type "nano heartbeat". When I do that all I get is gibberish (see attached). I figured out that if you type instead "nano heartbeat.yml" that it opens properly.

---

## [Filebeat decode\_cef messes up fields, when not all header fields are given](https://discuss.elastic.co/t/filebeat-decode-cef-messes-up-fields-when-not-all-header-fields-are-given/291664)

<div class="topic-metadata">

**Author:** [@buzzdeee](https://discuss.elastic.co/u/buzzdeee)\
**Replies:** 0\
**Last updated:** [December 13, 2021, 1:53pm UTC](https://discuss.elastic.co/t/filebeat-decode-cef-messes-up-fields-when-not-all-header-fields-are-given/291664 "2021-12-13T13:53:21Z")

</div>

Hi, the CEF spec found here: https://community.microfocus.com/cfs-file/\_\_key/communityserver-wikis-components-files/00-00-00-00-23/3731.CommonEventFormatV25.pdf it says: CEF uses syslog as a transport mechanism. It us…

---

## [How to configure GCS as filebeat input](https://discuss.elastic.co/t/how-to-configure-gcs-as-filebeat-input/291453)

<div class="topic-metadata">

**Author:** [@arvin495](https://discuss.elastic.co/u/arvin495)\
**Replies:** 7\
**Last updated:** [December 13, 2021, 1:13pm UTC](https://discuss.elastic.co/t/how-to-configure-gcs-as-filebeat-input/291453 "2021-12-13T13:13:01Z")

</div>

Hello Team, We are storing our audit logs in GCS bucket. we would like to ingest them to Elasticsearch when required - not regularly - using filebeat. I have checked S3 option where it let us use s3 like storages as inp…

---

## [Where to find a list of newly added integrations for per release?](https://discuss.elastic.co/t/where-to-find-a-list-of-newly-added-integrations-for-per-release/291363)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 4\
**Last updated:** [December 13, 2021, 1:06pm UTC](https://discuss.elastic.co/t/where-to-find-a-list-of-newly-added-integrations-for-per-release/291363 "2021-12-13T13:06:52Z")

</div>

Hi, With every new release of Elastic since Integrations/Fleet were added, there have been new integrations added (from what I can tell). Is there a place I can find a list of integrations and in what release they were …

---

## [Metricbeat showing same ip of elasticsearch nodes](https://discuss.elastic.co/t/metricbeat-showing-same-ip-of-elasticsearch-nodes/291586)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [December 13, 2021, 5:40am UTC](https://discuss.elastic.co/t/metricbeat-showing-same-ip-of-elasticsearch-nodes/291586 "2021-12-13T05:40:04Z")

</div>

1 week ago i upgrade elk stack from 7.13 to 7.15.Everything is fine but today i notice that in stack monitoring page when i click on nodes ,the ip of nodes is same for cross verification i ran GET /cat/nodes it showing m…

---

## [Collecting logs using filebeat over http](https://discuss.elastic.co/t/collecting-logs-using-filebeat-over-http/291578)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 0\
**Last updated:** [December 13, 2021, 3:14am UTC](https://discuss.elastic.co/t/collecting-logs-using-filebeat-over-http/291578 "2021-12-13T03:14:37Z")

</div>

Hi Team, Wondering if the filebeat.log.type can be http or https? I need to pull the logs using https path and using basic auth. Please let me know if that is possible? I am aware it can be possible with httpjson; howe…

---

## [Metricbeat postgresql 13.x, statement module needs update](https://discuss.elastic.co/t/metricbeat-postgresql-13-x-statement-module-needs-update/291530)

<div class="topic-metadata">

**Author:** [@Robin\_Goussey](https://discuss.elastic.co/u/Robin_Goussey)\
**Replies:** 0\
**Last updated:** [December 12, 2021, 7:57am UTC](https://discuss.elastic.co/t/metricbeat-postgresql-13-x-statement-module-needs-update/291530 "2021-12-12T07:57:47Z")

</div>

Hi, I've been trying to get metricbeat to work with postgres. It works fine, however, I noticed some of the default dashboards had no data, after further investigation, I've" found that the time fields are always empty. …

---

## [Filebeat is leaking memory](https://discuss.elastic.co/t/filebeat-is-leaking-memory/291528)

<div class="topic-metadata">

**Author:** [@cva](https://discuss.elastic.co/u/cva)\
**Replies:** 0\
**Last updated:** [December 12, 2021, 6:37am UTC](https://discuss.elastic.co/t/filebeat-is-leaking-memory/291528 "2021-12-12T06:37:33Z")

</div>

There are about 100,000 log files on the VM, the characteristics of the VM OS Windows Server 2019, CPU 4, RAM 4GB. To collect logs and then send them to logstash, filebeat 7.16.0 is used. After starting filebeat, it begi…

---

## [Filebeat harvesting](https://discuss.elastic.co/t/filebeat-harvesting/291514)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 1\
**Last updated:** [December 11, 2021, 10:04pm UTC](https://discuss.elastic.co/t/filebeat-harvesting/291514 "2021-12-11T22:04:31Z")

</div>

Hi all I am using filebeat to harvest logs and send data to Elasticsearch. It is noted that log4net is used to create log and log will rotate by size for example in 10m, when log.log size received to 10m, the current l…

---

## [Filebeat Tomcat module Access logs](https://discuss.elastic.co/t/filebeat-tomcat-module-access-logs/291468)

<div class="topic-metadata">

**Author:** [@searchtool](https://discuss.elastic.co/u/searchtool)\
**Replies:** 0\
**Last updated:** [December 10, 2021, 9:01pm UTC](https://discuss.elastic.co/t/filebeat-tomcat-module-access-logs/291468 "2021-12-10T21:01:11Z")

</div>

In response to this previous topic. Documentation mentions tomcat Access logs. This is a module for receiving Apache Tomcat access logs over Syslog or a file. I believe this is not correct and should just be just to…

---

## [Heartbeat config files fail when path variables passed](https://discuss.elastic.co/t/heartbeat-config-files-fail-when-path-variables-passed/289890)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 3\
**Last updated:** [December 10, 2021, 6:42pm UTC](https://discuss.elastic.co/t/heartbeat-config-files-fail-when-path-variables-passed/289890 "2021-12-10T18:42:18Z")

</div>

In order to get my Kibana https heartbeat working, I had to add the standard ssl blob. I used the same blob that I have in all my .yml's that lets everything successfully (mostly) talk over https: ssl.enabled: true …

---

## [Error retrieving database names from Mongo instance: command listDatabases requires authentication](https://discuss.elastic.co/t/error-retrieving-database-names-from-mongo-instance-command-listdatabases-requires-authentication/290779)

<div class="topic-metadata">

**Author:** [@Abhishek\_Sarkate](https://discuss.elastic.co/u/Abhishek_Sarkate)\
**Replies:** 1\
**Last updated:** [December 10, 2021, 6:23pm UTC](https://discuss.elastic.co/t/error-retrieving-database-names-from-mongo-instance-command-listdatabases-requires-authentication/290779 "2021-12-10T18:23:16Z")

</div>

I am trying to integrate elastic-agent in MongoDB replica-set and show mongo metrics on kibana , while trying with below code on mongo.conf security: authorization: enabled keyFile: /etc/keyfile MongoDb version u…

---

## [State metric for a Java Tomcat process always reporting as "sleeping"](https://discuss.elastic.co/t/state-metric-for-a-java-tomcat-process-always-reporting-as-sleeping/291077)

<div class="topic-metadata">

**Author:** [@Kevin\_Brunette](https://discuss.elastic.co/u/Kevin_Brunette)\
**Replies:** 2\
**Last updated:** [December 10, 2021, 5:50pm UTC](https://discuss.elastic.co/t/state-metric-for-a-java-tomcat-process-always-reporting-as-sleeping/291077 "2021-12-10T17:50:20Z")

</div>

I'm running metricbeat oss 7.14.0 on Ubuntu 18.04.6 (Bionic Beaver) LTS and attempting to tell if my Java Tomcat is running or down however; the "state" of the process always reports as "sleeping" regardless of whether t…

---

## [Sequence number for ECS Events received by TCP?](https://discuss.elastic.co/t/sequence-number-for-ecs-events-received-by-tcp/291348)

<div class="topic-metadata">

**Author:** [@Matthias\_W](https://discuss.elastic.co/u/Matthias_W)\
**Replies:** 4\
**Last updated:** [December 10, 2021, 2:27pm UTC](https://discuss.elastic.co/t/sequence-number-for-ecs-events-received-by-tcp/291348 "2021-12-10T14:27:58Z")

</div>

Hi, I have configured my application server (JBoss) to format log messages using the ECS formatter and directly send them to Filebeat via TCP. This works mostly fine - however, there is one issue: Log entries having th…

---

## [Panw module - Another incorrect timestamp issue](https://discuss.elastic.co/t/panw-module-another-incorrect-timestamp-issue/290099)

<div class="topic-metadata">

**Author:** [@ddaloia](https://discuss.elastic.co/u/ddaloia)\
**Replies:** 2\
**Last updated:** [December 10, 2021, 2:33am UTC](https://discuss.elastic.co/t/panw-module-another-incorrect-timestamp-issue/290099 "2021-12-10T02:33:00Z")

</div>

Hi friends. I am really struggling on this one. I can not figure out why all my ingested logs are showing up at the wrong time. It appears that all my firewall logs for each day are being grouped into a 3 hour window for…

---

## [Make/deploy fail](https://discuss.elastic.co/t/make-deploy-fail/291372)

<div class="topic-metadata">

**Author:** [@Steph\_van\_Schalkwyk](https://discuss.elastic.co/u/Steph_van_Schalkwyk)\
**Replies:** 0\
**Last updated:** [December 9, 2021, 11:26pm UTC](https://discuss.elastic.co/t/make-deploy-fail/291372 "2021-12-09T23:26:31Z")

</div>

/dev-tools/deploy and $make clean fail with: make\[1\]: Leaving directory '/home/steph/go/src/github.com/elastic/beats/x-pack/packetbeat' make\[1\]: Entering directory '/home/steph/go/src/github.com/elastic/beats/x-pack/l…

---

## [Multi-line Filebeat templates don't work with filebeat.inputs - type: filestream](https://discuss.elastic.co/t/multi-line-filebeat-templates-dont-work-with-filebeat-inputs-type-filestream/274510)

<div class="topic-metadata">

**Author:** [@cva](https://discuss.elastic.co/u/cva)\
**Replies:** 1\
**Last updated:** [December 9, 2021, 6:06pm UTC](https://discuss.elastic.co/t/multi-line-filebeat-templates-dont-work-with-filebeat-inputs-type-filestream/274510 "2021-12-09T18:06:07Z")

</div>

I ran into a multiline processing problem in Filebeat when the filebeat.inputs: parameters specify type: filestream - the logs of the file stream are not analyzed according to the requirements of multiline. pattern: '^\[\[…

---

## [Filebeat keystore for basic security](https://discuss.elastic.co/t/filebeat-keystore-for-basic-security/291257)

<div class="topic-metadata">

**Author:** [@bbangerter](https://discuss.elastic.co/u/bbangerter)\
**Replies:** 2\
**Last updated:** [December 9, 2021, 4:13pm UTC](https://discuss.elastic.co/t/filebeat-keystore-for-basic-security/291257 "2021-12-09T16:13:44Z")

</div>

I am running Elasticsearch 7.15.2 on CentOS 8 and have it successfully taking in logs from filebeat with a clear password in the yml file. I'm trying to get it running with a keystore, but am running into issues. My ou…

---

## [Parse Substring to JSON](https://discuss.elastic.co/t/parse-substring-to-json/291333)

<div class="topic-metadata">

**Author:** [@hami2608](https://discuss.elastic.co/u/hami2608)\
**Replies:** 1\
**Last updated:** [December 9, 2021, 4:09pm UTC](https://discuss.elastic.co/t/parse-substring-to-json/291333 "2021-12-09T16:09:05Z")

</div>

Hi, i have a Droptailer Pod in my Kubernetes Cluster with the following log example: 2021-12-09 13:46:32 +0000 UTC {"DPT":"161","DST":"XXX.XXX.XXX.XXX","ID":"54321","IN":"vrf104009","LEN":"48","MAC":"XX:XX:XX:XX:XX:XX…

---

## [Elastic Agent Consuming allot of resources on the Endpoint](https://discuss.elastic.co/t/elastic-agent-consuming-allot-of-resources-on-the-endpoint/290791)

<div class="topic-metadata">

**Author:** [@geekzy](https://discuss.elastic.co/u/geekzy)\
**Replies:** 1\
**Last updated:** [December 9, 2021, 11:42am UTC](https://discuss.elastic.co/t/elastic-agent-consuming-allot-of-resources-on-the-endpoint/290791 "2021-12-09T11:42:24Z")

</div>

Hi All, We have been testing the elastic-agent for a while across multiple endpoints on our environment and started noticing a few issues. Initially we noticed on several of our higher spec laptops that Endpoint securit…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=116)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=118)
