# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=118

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 119

---

## [Winlogbeat not reading event id](https://discuss.elastic.co/t/winlogbeat-not-reading-event-id/291308)

<div class="topic-metadata">

**Author:** [@aditi\_salunke](https://discuss.elastic.co/u/aditi_salunke)\
**Replies:** 0\
**Last updated:** [December 9, 2021, 9:15am UTC](https://discuss.elastic.co/t/winlogbeat-not-reading-event-id/291308 "2021-12-09T09:15:18Z")

</div>

Hello, Will winlogbeat forward the log to Elasticsearch if it is installed on AD and when someone lockout from the system and if the account lockout log is dropping on AD? eg.: if 10 users are getting locked out on the…

---

## [Filebeat push event in very slow rate](https://discuss.elastic.co/t/filebeat-push-event-in-very-slow-rate/291013)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 5\
**Last updated:** [December 9, 2021, 7:01am UTC](https://discuss.elastic.co/t/filebeat-push-event-in-very-slow-rate/291013 "2021-12-09T07:01:51Z")

</div>

Hi all I have a problems with one of my filebeat installed server. That server is config to get f5 log. then i install filebeat to get log from that server to Elasticsearch. But back before that setup working fine and…

---

## [Filebeat is not sending data to Elasticsearch](https://discuss.elastic.co/t/filebeat-is-not-sending-data-to-elasticsearch/291000)

<div class="topic-metadata">

**Author:** [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)\
**Replies:** 9\
**Last updated:** [December 9, 2021, 4:06am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-data-to-elasticsearch/291000 "2021-12-09T04:06:05Z")

</div>

I'm using running Filebeat version 7.10.0 as container version to ship docker container logs as well as system logs directly to Elasticsearch. Docker logs are shipped fine but system logs are not getting shipped. When I …

---

## [Filebeat service is not stopping](https://discuss.elastic.co/t/filebeat-service-is-not-stopping/291266)

<div class="topic-metadata">

**Author:** [@molasses](https://discuss.elastic.co/u/molasses)\
**Replies:** 0\
**Last updated:** [December 8, 2021, 9:49pm UTC](https://discuss.elastic.co/t/filebeat-service-is-not-stopping/291266 "2021-12-08T21:49:55Z")

</div>

From time to time, attempts to stop filebeat are failing. version: 7.11.1 running as a windows service command to stop filebeat: sc stop filebeat filebeat windows service stops fine most of the time. From time to ti…

---

## [How to remove fields not required while sending log data from file beat](https://discuss.elastic.co/t/how-to-remove-fields-not-required-while-sending-log-data-from-file-beat/290484)

<div class="topic-metadata">

**Author:** [@shi](https://discuss.elastic.co/u/shi)\
**Replies:** 2\
**Last updated:** [December 8, 2021, 6:04pm UTC](https://discuss.elastic.co/t/how-to-remove-fields-not-required-while-sending-log-data-from-file-beat/290484 "2021-12-08T18:04:07Z")

</div>

While sending data from a logfile using file beat through ingest pipeline to index in Elasticsearch, some additional fields not present in the concerned log file is also getting populated. These data are mostly relate…

---

## [Event.dataset: login not present](https://discuss.elastic.co/t/event-dataset-login-not-present/291232)

<div class="topic-metadata">

**Author:** [@sadux](https://discuss.elastic.co/u/sadux)\
**Replies:** 0\
**Last updated:** [December 8, 2021, 2:50pm UTC](https://discuss.elastic.co/t/event-dataset-login-not-present/291232 "2021-12-08T14:50:19Z")

</div>

Hello! Just install Elaticsearch & Kibana & Auditbeat (Ubuntu Server 20.04). Also install auditbeat dashboard. But \[Auditbeat System\] Login Dashboard ECS is empty. I want to see user login count. Some browsing bring me t…

---

## [Can't put http\_endpoint messages to root](https://discuss.elastic.co/t/cant-put-http-endpoint-messages-to-root/290527)

<div class="topic-metadata">

**Author:** [@uhfath](https://discuss.elastic.co/u/uhfath)\
**Replies:** 5\
**Last updated:** [December 8, 2021, 2:38pm UTC](https://discuss.elastic.co/t/cant-put-http-endpoint-messages-to-root/290527 "2021-12-08T14:38:41Z")

</div>

Here is my config: filebeat.inputs: - type: http\_endpoint enabled: true listen\_address: 127.0.0.1 listen\_port: 20000 response\_code: 204 response\_body: null prefix: null fields: app\_name: "MedService.UI…

---

## [Elastic Agents, ECK, and Kubernetes namespaces](https://discuss.elastic.co/t/elastic-agents-eck-and-kubernetes-namespaces/291218)

<div class="topic-metadata">

**Author:** [@nuvarov](https://discuss.elastic.co/u/nuvarov)\
**Replies:** 0\
**Last updated:** [December 8, 2021, 1:04pm UTC](https://discuss.elastic.co/t/elastic-agents-eck-and-kubernetes-namespaces/291218 "2021-12-08T13:04:52Z")

</div>

I'm setting up elastic stack on our kubernetes cluster using ECK. One of the ideas is to make sure teams have access to the logs and metrics of workloads only from their kubernetes namespace. This seem to map to the nam…

---

## [Filebeat add\_fields processor](https://discuss.elastic.co/t/filebeat-add-fields-processor/290990)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 4\
**Last updated:** [December 8, 2021, 12:29pm UTC](https://discuss.elastic.co/t/filebeat-add-fields-processor/290990 "2021-12-08T12:29:04Z")

</div>

Hello colleagues; I am trying to add an ECS event.dataset with the add\_fields processor similar to several of the Filebeat modules e.g., the Apache module which add the event datasets apache.access and apache.error. I …

---

## [Closing filebeat due to inactivity of log input file](https://discuss.elastic.co/t/closing-filebeat-due-to-inactivity-of-log-input-file/291198)

<div class="topic-metadata">

**Author:** [@mangesh\_shinde](https://discuss.elastic.co/u/mangesh_shinde)\
**Replies:** 0\
**Last updated:** [December 8, 2021, 9:31am UTC](https://discuss.elastic.co/t/closing-filebeat-due-to-inactivity-of-log-input-file/291198 "2021-12-08T09:31:39Z")

</div>

filebeat is keep stopped due to inactive of input file is there requirement of activity of file. because my logs are there in file and it is active.

---

## [How to access filebeat HAProxy total response time?](https://discuss.elastic.co/t/how-to-access-filebeat-haproxy-total-response-time/289622)

<div class="topic-metadata">

**Author:** [@mmcnl](https://discuss.elastic.co/u/mmcnl)\
**Replies:** 3\
**Last updated:** [December 8, 2021, 1:46am UTC](https://discuss.elastic.co/t/how-to-access-filebeat-haproxy-total-response-time/289622 "2021-12-08T01:46:10Z")

</div>

I have the exact same question as was asked in this topic, which was closed due to no responses. Namely: Where do I find default HAProxy Timers Tr or Ta (which I assume include data/body) in Elastic Filebeat HAProxy fi…

---

## [How to fetch multiple metric dimensions from monitor metric set of azure metricbeat module](https://discuss.elastic.co/t/how-to-fetch-multiple-metric-dimensions-from-monitor-metric-set-of-azure-metricbeat-module/290364)

<div class="topic-metadata">

**Author:** [@adhiraj-g](https://discuss.elastic.co/u/adhiraj-g)\
**Replies:** 1\
**Last updated:** [December 7, 2021, 4:49pm UTC](https://discuss.elastic.co/t/how-to-fetch-multiple-metric-dimensions-from-monitor-metric-set-of-azure-metricbeat-module/290364 "2021-12-07T16:49:28Z")

</div>

Hi there, I was searching for ways to fetch out metric dimension values of azure application Gateway and landed on the following link: Metricbeat azure module - Simultaneously fetch multi-dimensional metric values Appa…

---

## [Exclude binary data filebeat in logfile](https://discuss.elastic.co/t/exclude-binary-data-filebeat-in-logfile/291031)

<div class="topic-metadata">

**Author:** [@MalfuncEddie](https://discuss.elastic.co/u/MalfuncEddie)\
**Replies:** 1\
**Last updated:** [December 7, 2021, 4:43pm UTC](https://discuss.elastic.co/t/exclude-binary-data-filebeat-in-logfile/291031 "2021-12-07T16:43:51Z")

</div>

Hi, I've got a multiline log file that has following structure 2021-12-06 11:36:31,088 .... 2021-12-06 11:36:32,588 ... 2021-12-06 11:36:34,127 --------------------------- ID: 82506 Response-Code: 200 Content-Type: ap…

---

## [O365 module access through proxy](https://discuss.elastic.co/t/o365-module-access-through-proxy/291107)

<div class="topic-metadata">

**Author:** [@sadieshsanjivi](https://discuss.elastic.co/u/sadieshsanjivi)\
**Replies:** 0\
**Last updated:** [December 7, 2021, 9:40am UTC](https://discuss.elastic.co/t/o365-module-access-through-proxy/291107 "2021-12-07T09:40:13Z")

</div>

Hi all I have a problems with using the o365 module in filebeat. In our network in order to reach internet we need to go through a proxy server, and it is because of that the filebeat module cannot connect to the o365 …

---

## [Docker.network\_summary does not take hostfs into account](https://discuss.elastic.co/t/docker-network-summary-does-not-take-hostfs-into-account/290677)

<div class="topic-metadata">

**Author:** [@Julero](https://discuss.elastic.co/u/Julero)\
**Replies:** 3\
**Last updated:** [December 7, 2021, 9:22am UTC](https://discuss.elastic.co/t/docker-network-summary-does-not-take-hostfs-into-account/290677 "2021-12-07T09:22:32Z")

</div>

When using docker.network\_summary, I have the following error: 2021-12-01T13:56:00.159Z INFO module/wrapper.go:266 Error fetching data for metricset docker.network\_summary: error fetching namespace for PID 4…

---

## [Does filebeat re-read the same .log file in a different directory?](https://discuss.elastic.co/t/does-filebeat-re-read-the-same-log-file-in-a-different-directory/290953)

<div class="topic-metadata">

**Author:** [@OAHstasy](https://discuss.elastic.co/u/OAHstasy)\
**Replies:** 2\
**Last updated:** [December 7, 2021, 7:06am UTC](https://discuss.elastic.co/t/does-filebeat-re-read-the-same-log-file-in-a-different-directory/290953 "2021-12-07T07:06:23Z")

</div>

Filebeat version: 7.15 OS: Windows 10 Hello everyone, Let me give you people a short description about my situtation: I configured my filebeat to read all .log files in "\\path\_to\_logs\\logs\\ \* \\ \*.log." My program tha…

---

## [Pipeline/output.go:154 Failed to connect to backoff](https://discuss.elastic.co/t/pipeline-output-go-154-failed-to-connect-to-backoff/290767)

<div class="topic-metadata">

**Author:** [@abhi.logs](https://discuss.elastic.co/u/abhi.logs)\
**Replies:** 10\
**Last updated:** [December 7, 2021, 5:03am UTC](https://discuss.elastic.co/t/pipeline-output-go-154-failed-to-connect-to-backoff/290767 "2021-12-07T05:03:31Z")

</div>

Hello, I'm getting this error, does anyone knows how to solve this? ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 Failed to connect to backoff(elasticsearch(https://xxxxxx:9200)): Connection marked as failed…

---

## [Filebeat decode\_json\_fields failed](https://discuss.elastic.co/t/filebeat-decode-json-fields-failed/291019)

<div class="topic-metadata">

**Author:** [@haoma2514](https://discuss.elastic.co/u/haoma2514)\
**Replies:** 0\
**Last updated:** [December 6, 2021, 8:25am UTC](https://discuss.elastic.co/t/filebeat-decode-json-fields-failed/291019 "2021-12-06T08:25:25Z")

</div>

If the length of the message above is greater than 1116, it will be lost after formatting! When using filebeat decode\_json\_fields to parse json object, if the field content of json key is too long, it will be discarde…

---

## [Ingesting ECS ndjson via http\_endpoint?](https://discuss.elastic.co/t/ingesting-ecs-ndjson-via-http-endpoint/291023)

<div class="topic-metadata">

**Author:** [@Matthias\_W](https://discuss.elastic.co/u/Matthias_W)\
**Replies:** 0\
**Last updated:** [December 6, 2021, 9:13am UTC](https://discuss.elastic.co/t/ingesting-ecs-ndjson-via-http-endpoint/291023 "2021-12-06T09:13:02Z")

</div>

Hi, I have a C++ application with a custom logging framework. I was able to modify the framework quite easily to produce ECS-formatted JSON messages. Now, I am trying to use FileBeat to load these log messages into Ela…

---

## [Configuring multiple metricbeats host instances with one elasticsearch and Kibana system dashboard](https://discuss.elastic.co/t/configuring-multiple-metricbeats-host-instances-with-one-elasticsearch-and-kibana-system-dashboard/290846)

<div class="topic-metadata">

**Author:** [@Brendon\_Fernandes](https://discuss.elastic.co/u/Brendon_Fernandes)\
**Replies:** 2\
**Last updated:** [December 6, 2021, 4:33am UTC](https://discuss.elastic.co/t/configuring-multiple-metricbeats-host-instances-with-one-elasticsearch-and-kibana-system-dashboard/290846 "2021-12-06T04:33:12Z")

</div>

Hi, I'm trying to configure system metrics from multiple (3) systems via metricbeats + Elasticsearch \_Kibana (ver 7.15.1 ). However, the index in which it gets into is the default index metricbeat-\* My requirement is to…

---

## [Adding disk mounts to metricbeat system module](https://discuss.elastic.co/t/adding-disk-mounts-to-metricbeat-system-module/290849)

<div class="topic-metadata">

**Author:** [@kshepitzki1](https://discuss.elastic.co/u/kshepitzki1)\
**Replies:** 2\
**Last updated:** [December 6, 2021, 5:52am UTC](https://discuss.elastic.co/t/adding-disk-mounts-to-metricbeat-system-module/290849 "2021-12-06T05:52:49Z")

</div>

Trying to configure the metricbeat system module to monitor additional mounted drives for free disk space % on Linux. This document does not help: https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metr…

---

## [Need help to create setup.template.name and setup.template.pattern:](https://discuss.elastic.co/t/need-help-to-create-setup-template-name-and-setup-template-pattern/290975)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 1\
**Last updated:** [December 6, 2021, 1:40am UTC](https://discuss.elastic.co/t/need-help-to-create-setup-template-name-and-setup-template-pattern/290975 "2021-12-06T01:40:39Z")

</div>

Hello team, I Need help to create setup.template.name and setup.template.pattern I have setup filebeat and rename index name. Can you please help me to setup these two parameter

---

## [Troubleshooting Metricbeat StatsD Module and Custom Metrics](https://discuss.elastic.co/t/troubleshooting-metricbeat-statsd-module-and-custom-metrics/290938)

<div class="topic-metadata">

**Author:** [@Jeremy\_Gillick](https://discuss.elastic.co/u/Jeremy_Gillick)\
**Replies:** 0\
**Last updated:** [December 4, 2021, 1:28am UTC](https://discuss.elastic.co/t/troubleshooting-metricbeat-statsd-module-and-custom-metrics/290938 "2021-12-04T01:28:57Z")

</div>

I installed the Metricbeat StatsD module a few days ago and it's reporting data on the machine it's installed on, but not reporting any custom metrics I send to it. For example: echo "test.metric:1|c" | nc -u -w0 \<IP A…

---

## [Can I apply fleet-managed processors after elasticsearch ingest node pipelines?](https://discuss.elastic.co/t/can-i-apply-fleet-managed-processors-after-elasticsearch-ingest-node-pipelines/290939)

<div class="topic-metadata">

**Author:** [@icious](https://discuss.elastic.co/u/icious)\
**Replies:** 0\
**Last updated:** [December 4, 2021, 1:44am UTC](https://discuss.elastic.co/t/can-i-apply-fleet-managed-processors-after-elasticsearch-ingest-node-pipelines/290939 "2021-12-04T01:44:10Z")

</div>

Hi all, I'm trying to apply reverse DNS lookup to the logs received from my Sophos firewall using the "DNS" processor of filebeat, but so far I didn't have any luck with that using the Sophos fleet-managed integration. …

---

## [Error logging container json files with filebeat](https://discuss.elastic.co/t/error-logging-container-json-files-with-filebeat/290912)

<div class="topic-metadata">

**Author:** [@Guillaume84](https://discuss.elastic.co/u/Guillaume84)\
**Replies:** 0\
**Last updated:** [December 3, 2021, 3:48pm UTC](https://discuss.elastic.co/t/error-logging-container-json-files-with-filebeat/290912 "2021-12-03T15:48:11Z")

</div>

Hello, I am struggling for days on parsing a simple airflow json file from a k8s container Log format: {"asctime": "2021-12-02 17:04:34,450", "filename": "standard\_task\_runner.py", "lineno": 77, "levelname": "INFO", "…

---

## [Filebeat with sophos module](https://discuss.elastic.co/t/filebeat-with-sophos-module/290867)

<div class="topic-metadata">

**Author:** [@sanil.ramachandran](https://discuss.elastic.co/u/sanil.ramachandran)\
**Replies:** 0\
**Last updated:** [December 3, 2021, 10:40am UTC](https://discuss.elastic.co/t/filebeat-with-sophos-module/290867 "2021-12-03T10:40:00Z")

</div>

Hello, I am very new to elk. I have managed to install elasticsearch,kibana and filebeat in ubuntu server, managed to enable sophos module and manged to receive syslog messages from the appliance using rsyslog server. …

---

## [Filebeat data not indexed](https://discuss.elastic.co/t/filebeat-data-not-indexed/290801)

<div class="topic-metadata">

**Author:** [@Angelo\_Capone](https://discuss.elastic.co/u/Angelo_Capone)\
**Replies:** 0\
**Last updated:** [December 2, 2021, 5:24pm UTC](https://discuss.elastic.co/t/filebeat-data-not-indexed/290801 "2021-12-02T17:24:08Z")

</div>

Hi, i'm using filebeat 7.15.1 running as a docker container with the following configuration: filebeat.config: modules: path: ${path.config}/modules.d/\*.yml reload.enabled: true reload.period: 60s filebe…

---

## [Monitor GCE VM commands](https://discuss.elastic.co/t/monitor-gce-vm-commands/286988)

<div class="topic-metadata">

**Author:** [@\_bugc4t](https://discuss.elastic.co/u/_bugc4t)\
**Replies:** 1\
**Last updated:** [December 3, 2021, 9:27am UTC](https://discuss.elastic.co/t/monitor-gce-vm-commands/286988 "2021-12-03T09:27:31Z")

</div>

I've got a running filebeat ECK cluster. However, I've got a new requirement to incorporate VM commands and processes from another GCP project for analysis. I've looked into the GCP Ops Agent and Auditbeat but neither s…

---

## [Filebeat k8s - autodiscover for podman.sock not working](https://discuss.elastic.co/t/filebeat-k8s-autodiscover-for-podman-sock-not-working/290857)

<div class="topic-metadata">

**Author:** [@cal2](https://discuss.elastic.co/u/cal2)\
**Replies:** 0\
**Last updated:** [December 3, 2021, 9:11am UTC](https://discuss.elastic.co/t/filebeat-k8s-autodiscover-for-podman-sock-not-working/290857 "2021-12-03T09:11:55Z")

</div>

Hi Ok i've got filebeat running on kubernetes (k3s) via helm. All is working totally fine for gathering the cluster logs. I also have podman running on the same nodes and i'd like to use the docker autodiscover provide…

---

## [Filebeat/Logstash Delay](https://discuss.elastic.co/t/filebeat-logstash-delay/290856)

<div class="topic-metadata">

**Author:** [@Sumit\_Yadav](https://discuss.elastic.co/u/Sumit_Yadav)\
**Replies:** 0\
**Last updated:** [December 3, 2021, 9:06am UTC](https://discuss.elastic.co/t/filebeat-logstash-delay/290856 "2021-12-03T09:06:06Z")

</div>

Hi Team I have a self managed elastic cluster. We are using Filebeat -\> logstash -\> Elasticsearch cluster-\> Kibana setup. All 7.15v with basic license. Data transferred through out the day is around 260GB. Filebeat hav…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=117)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=119)
