# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=119

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 120

---

## [Processing gzipped Log Files with Elastic Agent Custom Log Integration?](https://discuss.elastic.co/t/processing-gzipped-log-files-with-elastic-agent-custom-log-integration/290831)

<div class="topic-metadata">

**Author:** [@abolan](https://discuss.elastic.co/u/abolan)\
**Replies:** 0\
**Last updated:** [December 2, 2021, 9:14pm UTC](https://discuss.elastic.co/t/processing-gzipped-log-files-with-elastic-agent-custom-log-integration/290831 "2021-12-02T21:14:03Z")

</div>

Hello, I have an Elastic Cloud environment set up and I'm trying to ingest and parse a number of gzipped log files from a pair of central log repository servers. The Elastic Agent is already installed and communicating …

---

## [Filebeat update and resending of logs](https://discuss.elastic.co/t/filebeat-update-and-resending-of-logs/290803)

<div class="topic-metadata">

**Author:** [@CyberSeppi](https://discuss.elastic.co/u/CyberSeppi)\
**Replies:** 0\
**Last updated:** [December 2, 2021, 5:46pm UTC](https://discuss.elastic.co/t/filebeat-update-and-resending-of-logs/290803 "2021-12-02T17:46:53Z")

</div>

Hi all, just wanted to ask, if you think that scenario feasable. and more interesting would be, how :slight\_smile: I have an ansible project which installs/update filebeat on target machine. Due to the non-generic setu…

---

## [Manage Auditbeat with Elastic-Agent](https://discuss.elastic.co/t/manage-auditbeat-with-elastic-agent/290770)

<div class="topic-metadata">

**Author:** [@marti1](https://discuss.elastic.co/u/marti1)\
**Replies:** 0\
**Last updated:** [December 2, 2021, 1:25pm UTC](https://discuss.elastic.co/t/manage-auditbeat-with-elastic-agent/290770 "2021-12-02T13:25:13Z")

</div>

Hi, I have deployed ElasticAgent to my hosts, and now, I would like to use Auditbeat. Is it possible to deploy and manage Auditbeat with ElasticAgent? I have searched for Auditbeat integration and doesn't exist. Than…

---

## [Deployment of a Fleet-Server](https://discuss.elastic.co/t/deployment-of-a-fleet-server/290750)

<div class="topic-metadata">

**Author:** [@Alphonse\_Kambo](https://discuss.elastic.co/u/Alphonse_Kambo)\
**Replies:** 1\
**Last updated:** [December 2, 2021, 2:24pm UTC](https://discuss.elastic.co/t/deployment-of-a-fleet-server/290750 "2021-12-02T14:24:43Z")

</div>

Hello All, We installed months ago Filebeat, Auditbeat, Metricbeat, Heartbeat and Packetbeat on our stand-alone Elastic-Server. Now we have deployed a Fleet-server to have some experience with it. Something is not cle…

---

## [Query regarding azure monitor\_service.go based logging in metricbeat](https://discuss.elastic.co/t/query-regarding-azure-monitor-service-go-based-logging-in-metricbeat/289804)

<div class="topic-metadata">

**Author:** [@adhiraj-g](https://discuss.elastic.co/u/adhiraj-g)\
**Replies:** 2\
**Last updated:** [December 2, 2021, 1:33pm UTC](https://discuss.elastic.co/t/query-regarding-azure-monitor-service-go-based-logging-in-metricbeat/289804 "2021-12-02T13:33:43Z")

</div>

Hi @Kaiyan\_Sheng / @MarianaD , Hope you both are doing well. While checking metricbeat logs, i observed the following line: 2021-11-22T06:27:25.307-0500 WARN \[azure monitor service\] azure/monitor\_service.go:130 …

---

## [Filebeat setup creates more than one write index - ILM](https://discuss.elastic.co/t/filebeat-setup-creates-more-than-one-write-index-ilm/290679)

<div class="topic-metadata">

**Author:** [@JGreene](https://discuss.elastic.co/u/JGreene)\
**Replies:** 3\
**Last updated:** [December 2, 2021, 1:06pm UTC](https://discuss.elastic.co/t/filebeat-setup-creates-more-than-one-write-index-ilm/290679 "2021-12-02T13:06:04Z")

</div>

Filebeat should not attempt to create / recreate write index if a write index exists. As indices age out with ILM policies and are deleted, subsequent runs of filebeat setup attempt to create the default index of -000001 …

---

## [Activemq module configuration](https://discuss.elastic.co/t/activemq-module-configuration/290540)

<div class="topic-metadata">

**Author:** [@kpanguila](https://discuss.elastic.co/u/kpanguila)\
**Replies:** 6\
**Last updated:** [December 2, 2021, 10:16am UTC](https://discuss.elastic.co/t/activemq-module-configuration/290540 "2021-12-02T10:16:58Z")

</div>

Hello, i hope you are doing great, i am facing an issues on configure my activemq module. i am getting the following error on discover: failed to unmarshal jolokia JSON response '{"error\_type":"java.lang.Exception","er…

---

## [Monitoring ELK Cluster on OpenShift](https://discuss.elastic.co/t/monitoring-elk-cluster-on-openshift/288930)

<div class="topic-metadata">

**Author:** [@gbschenkel](https://discuss.elastic.co/u/gbschenkel)\
**Replies:** 2\
**Last updated:** [December 2, 2021, 9:32am UTC](https://discuss.elastic.co/t/monitoring-elk-cluster-on-openshift/288930 "2021-12-02T09:32:55Z")

</div>

Hi, I have successful deployed Elasticsearch and Kibana on OpenShift, I am currently using internal metrics to get info from Elasticsearch and Kibana nodes. Since Elasticsearch will drop the internal metric and 8.0.0 is …

---

## [Metricbeat Prometheus Autodiscovery](https://discuss.elastic.co/t/metricbeat-prometheus-autodiscovery/290465)

<div class="topic-metadata">

**Author:** [@Lance\_Z](https://discuss.elastic.co/u/Lance_Z)\
**Replies:** 2\
**Last updated:** [December 2, 2021, 9:16am UTC](https://discuss.elastic.co/t/metricbeat-prometheus-autodiscovery/290465 "2021-12-02T09:16:40Z")

</div>

Trying to get metricbeat to scrape prometheus metrics from a service running in EKS. I have followed examples and docs to no avail. And probably many others... I am using the official Helm charts to deploy metricbea…

---

## [Exiting: Index management requested but the Elasticsearch output is not configured/enabled](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/290684)

<div class="topic-metadata">

**Author:** [@adouren](https://discuss.elastic.co/u/adouren)\
**Replies:** 2\
**Last updated:** [December 2, 2021, 8:41am UTC](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/290684 "2021-12-02T08:41:50Z")

</div>

Hi, I configured filebeat.yml with logstash output but I got this error: Exiting: Index management requested but the Elasticsearch output is not configured/enabled filebeat.yml filebeat.config: modules: path: ${…

---

## [Filebeat takes hours to start harvesting logs after restart](https://discuss.elastic.co/t/filebeat-takes-hours-to-start-harvesting-logs-after-restart/290693)

<div class="topic-metadata">

**Author:** [@Dancho](https://discuss.elastic.co/u/Dancho)\
**Replies:** 0\
**Last updated:** [December 1, 2021, 4:17pm UTC](https://discuss.elastic.co/t/filebeat-takes-hours-to-start-harvesting-logs-after-restart/290693 "2021-12-01T16:17:17Z")

</div>

I have to use wildcards in the PATH section since my log files might be in many different locations. filebeat.inputs: - type: log paths: - /folder1/\*/\*/\*/folder2/\*\*/\*.log after filebeat service restart, it tak…

---

## [Metricbeat data not fully visible in elasticsearch](https://discuss.elastic.co/t/metricbeat-data-not-fully-visible-in-elasticsearch/290340)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 6\
**Last updated:** [December 1, 2021, 5:55pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-fully-visible-in-elasticsearch/290340 "2021-12-01T17:55:43Z")

</div>

I am trying to use metricbeat v 7.10.2 ( ELS on same version ) and not able to see all the data for Elasticsearch module. I understand the data is dependent on master node for few metrics so i have configured it individu…

---

## [Filebeat messages missing under high load](https://discuss.elastic.co/t/filebeat-messages-missing-under-high-load/290194)

<div class="topic-metadata">

**Author:** [@hajeve](https://discuss.elastic.co/u/hajeve)\
**Replies:** 1\
**Last updated:** [December 1, 2021, 1:44pm UTC](https://discuss.elastic.co/t/filebeat-messages-missing-under-high-load/290194 "2021-12-01T13:44:07Z")

</div>

We need help with the following problem: We are receiving BIG IP F5 request-logs via F5 High Speed Logging in dedicated filebeat pods (8) in our production environment in Azure cloud. These filebeat pods are connected …

---

## [Filebeat on kubernetes: cant make it work without cluster roles](https://discuss.elastic.co/t/filebeat-on-kubernetes-cant-make-it-work-without-cluster-roles/290586)

<div class="topic-metadata">

**Author:** [@Guillaume84](https://discuss.elastic.co/u/Guillaume84)\
**Replies:** 5\
**Last updated:** [December 1, 2021, 1:39pm UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes-cant-make-it-work-without-cluster-roles/290586 "2021-12-01T13:39:36Z")

</div>

Hello, I am trying to deploy a filebeat container (not daemonset) on a k8s cluster (kub 1.21) Used image: elastic/filebeat:7.8.1 Image starts correctly but i can't have the filebeat working correctly : E1130 15:47:41…

---

## [\`kubernetes.volume.fs.used.pct\` has incorrect type in index template](https://discuss.elastic.co/t/kubernetes-volume-fs-used-pct-has-incorrect-type-in-index-template/290440)

<div class="topic-metadata">

**Author:** [@lepouletsuisse](https://discuss.elastic.co/u/lepouletsuisse)\
**Replies:** 2\
**Last updated:** [December 1, 2021, 9:26am UTC](https://discuss.elastic.co/t/kubernetes-volume-fs-used-pct-has-incorrect-type-in-index-template/290440 "2021-12-01T09:26:28Z")

</div>

It seems that field kubernetes.volume.fs.used.pct has an incorrect type in the index template metrics-kubernetes.volume (automatically generated by metricbeat or fleet). The type specified by the template's mapping is l…

---

## [Winlogbeat 7.15.1 with sysmon missing fields task and message on Windows Server 2022](https://discuss.elastic.co/t/winlogbeat-7-15-1-with-sysmon-missing-fields-task-and-message-on-windows-server-2022/289675)

<div class="topic-metadata">

**Author:** [@sytser](https://discuss.elastic.co/u/sytser)\
**Replies:** 9\
**Last updated:** [December 1, 2021, 6:55am UTC](https://discuss.elastic.co/t/winlogbeat-7-15-1-with-sysmon-missing-fields-task-and-message-on-windows-server-2022/289675 "2021-12-01T06:55:39Z")

</div>

The issue is that on a Windows Server 2022 version with Winlogbeat v7.15.1 and Sysmon v13.24. Some how on Windows Server 2022 Winlogbeat doesn't send the fields task and message to Logstash v7.15.2. If we use the same …

---

## [Shipping Postfix logs to ELK stack](https://discuss.elastic.co/t/shipping-postfix-logs-to-elk-stack/290603)

<div class="topic-metadata">

**Author:** [@DoDuyen162000](https://discuss.elastic.co/u/DoDuyen162000)\
**Replies:** 2\
**Last updated:** [November 30, 2021, 9:54pm UTC](https://discuss.elastic.co/t/shipping-postfix-logs-to-elk-stack/290603 "2021-11-30T21:54:36Z")

</div>

Hello, Well this is not actually an issue rather query. I have been playing with ELK stack for a few days. I have a working ELK stack running on Ubuntu 20.4. Now, I want to ship mail logs (postfix logs) to my ELK stack…

---

## [Creating different indexes for different modules from filebeat](https://discuss.elastic.co/t/creating-different-indexes-for-different-modules-from-filebeat/290499)

<div class="topic-metadata">

**Author:** [@Lenny](https://discuss.elastic.co/u/Lenny)\
**Replies:** 7\
**Last updated:** [November 30, 2021, 7:47pm UTC](https://discuss.elastic.co/t/creating-different-indexes-for-different-modules-from-filebeat/290499 "2021-11-30T19:47:50Z")

</div>

Hello, I'm very new to elk stack so please bear with me. I'm learning Elastic Stack from scratch and I have paid for and taken a few classes, but none of the classes I have gone through seem to go very in depth for the i…

---

## [Heartbeat automatic import dashboards failed](https://discuss.elastic.co/t/heartbeat-automatic-import-dashboards-failed/290572)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 7\
**Last updated:** [November 30, 2021, 7:25pm UTC](https://discuss.elastic.co/t/heartbeat-automatic-import-dashboards-failed/290572 "2021-11-30T19:25:36Z")

</div>

Hey there, using ELK v.7.15.2 I was trying to import Heartbeat dashboards into Kibana. I set the following parameters: setup.dashboards.enabled: true but I am facing the following error: Exiting: Error importing Ki…

---

## [Heartbeat processors variable in docker-compose file](https://discuss.elastic.co/t/heartbeat-processors-variable-in-docker-compose-file/290582)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 1\
**Last updated:** [November 30, 2021, 7:16pm UTC](https://discuss.elastic.co/t/heartbeat-processors-variable-in-docker-compose-file/290582 "2021-11-30T19:16:59Z")

</div>

Hi, is it possible to provide variable required by a specific processor (i.e. add\_observer\_metadata) directly into docker-compose file? Something like: command: \> heartbeat -e -E processors.add\_observer\_meta…

---

## [How could I reserve message filed with json.keys\_under\_root is set](https://discuss.elastic.co/t/how-could-i-reserve-message-filed-with-json-keys-under-root-is-set/290275)

<div class="topic-metadata">

**Author:** [@xxdoor](https://discuss.elastic.co/u/xxdoor)\
**Replies:** 1\
**Last updated:** [November 30, 2021, 7:35am UTC](https://discuss.elastic.co/t/how-could-i-reserve-message-filed-with-json-keys-under-root-is-set/290275 "2021-11-30T07:35:22Z")

</div>

Hi, I'm using filebeat to collect my logs from servers. I'm confused whether it's possible to reserve message filed when I set json.keys\_under\_root true. The fields I hava set: - type: docker containers: path: "…

---

## [Filebeat: Time different between ingest time and Message log time](https://discuss.elastic.co/t/filebeat-time-different-between-ingest-time-and-message-log-time/290394)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat1](https://discuss.elastic.co/u/Elie_Sbat1)\
**Replies:** 4\
**Last updated:** [November 30, 2021, 6:31am UTC](https://discuss.elastic.co/t/filebeat-time-different-between-ingest-time-and-message-log-time/290394 "2021-11-30T06:31:06Z")

</div>

Hello, Currently, I am using Elasticsearch v7.11 and filebeat v7.15 And I am retrieving owa logs from a directory on exchange. I noticed that the "@timestamp" and log message was way different. After further troubleshoo…

---

## [Configuration of beats that come with elastic-agent and fleet](https://discuss.elastic.co/t/configuration-of-beats-that-come-with-elastic-agent-and-fleet/290489)

<div class="topic-metadata">

**Author:** [@poulaone](https://discuss.elastic.co/u/poulaone)\
**Replies:** 2\
**Last updated:** [November 30, 2021, 6:23am UTC](https://discuss.elastic.co/t/configuration-of-beats-that-come-with-elastic-agent-and-fleet/290489 "2021-11-30T06:23:27Z")

</div>

Hello, I search information about the beats configurations through elastic-agent and fleet. For exemple, for the filebeat agent installed with elastic-agent, how can i disable metrics or enable a path monitoring ? Tha…

---

## [Filebeat: create new module fails consistently on a Windows machine](https://discuss.elastic.co/t/filebeat-create-new-module-fails-consistently-on-a-windows-machine/290496)

<div class="topic-metadata">

**Author:** [@Zee\_Grinch](https://discuss.elastic.co/u/Zee_Grinch)\
**Replies:** 0\
**Last updated:** [November 29, 2021, 10:57pm UTC](https://discuss.elastic.co/t/filebeat-create-new-module-fails-consistently-on-a-windows-machine/290496 "2021-11-29T22:57:30Z")

</div>

$make create-module MODULE=mytestmodule keeps failing abruptly with the dreaded : Unknown target specified: "create-module", no matter what tweaks I have been tried to my environment. this is a Windows 10 64b followe…

---

## [Jolokia Module Event Field Does not Work](https://discuss.elastic.co/t/jolokia-module-event-field-does-not-work/290464)

<div class="topic-metadata">

**Author:** [@chrismuzyn](https://discuss.elastic.co/u/chrismuzyn)\
**Replies:** 0\
**Last updated:** [November 29, 2021, 4:44pm UTC](https://discuss.elastic.co/t/jolokia-module-event-field-does-not-work/290464 "2021-11-29T16:44:30Z")

</div>

Hi Everyone, We are using Metricbeat's Jolokia plugin to autodiscover and then query Jolokia for several metrics from different mbeans. Per the documentation here: The event setting is optional. Use this setting to g…

---

## [Disable metrics logging in Elastic Agent managed by Fleet](https://discuss.elastic.co/t/disable-metrics-logging-in-elastic-agent-managed-by-fleet/290420)

<div class="topic-metadata">

**Author:** [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Replies:** 0\
**Last updated:** [November 29, 2021, 10:28am UTC](https://discuss.elastic.co/t/disable-metrics-logging-in-elastic-agent-managed-by-fleet/290420 "2021-11-29T10:28:39Z")

</div>

Hi All, We use Fleet managed Elastic Agent and have a lot of "Non-zero metrics in the last 30s" in our log that we want to remove. Is there a way to disable that logging? I see there is a new option in standalone elas…

---

## [Filebeat multiline pattern](https://discuss.elastic.co/t/filebeat-multiline-pattern/290414)

<div class="topic-metadata">

**Author:** [@Divya\_Bansal](https://discuss.elastic.co/u/Divya_Bansal)\
**Replies:** 0\
**Last updated:** [November 29, 2021, 9:36am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern/290414 "2021-11-29T09:36:51Z")

</div>

There are stacktrace starting with three different pattern:- 1-\[ERROR\] 2- \[ERROR\] 3-ERROR or 2021-11-26 00:01:20.563 what should be the multiline pattern for parsing lines or stack trace starting with above different…

---

## [Two different date formats from logs. Handle with one multiline.pattern?](https://discuss.elastic.co/t/two-different-date-formats-from-logs-handle-with-one-multiline-pattern/290402)

<div class="topic-metadata">

**Author:** [@alexander.jansson](https://discuss.elastic.co/u/alexander.jansson)\
**Replies:** 0\
**Last updated:** [November 29, 2021, 8:19am UTC](https://discuss.elastic.co/t/two-different-date-formats-from-logs-handle-with-one-multiline-pattern/290402 "2021-11-29T08:19:01Z")

</div>

Hi, I'm trying to match two different time formats within different application logs (two out of five use ISO8601, the other three DD-MM-YYYY HH:mm:ss,mmm. I figured I'd be able to solve it like this: multiline.patt…

---

## [Mutiple - files in tmp](https://discuss.elastic.co/t/mutiple-files-in-tmp/290358)

<div class="topic-metadata">

**Author:** [@msalem](https://discuss.elastic.co/u/msalem)\
**Replies:** 1\
**Last updated:** [November 28, 2021, 11:03pm UTC](https://discuss.elastic.co/t/mutiple-files-in-tmp/290358 "2021-11-28T23:03:32Z")

</div>

Hello support, I have a folder with mutiple files generated there. -folder1 ---- tmp1 ---- tmp2 ---- etc. each file like tmp1, will have mutiple lines. how do Load each file as a message instead of reading each li…

---

## [Should I keep beat version in index-template?](https://discuss.elastic.co/t/should-i-keep-beat-version-in-index-template/290335)

<div class="topic-metadata">

**Author:** [@noFancyStuff](https://discuss.elastic.co/u/noFancyStuff)\
**Replies:** 0\
**Last updated:** [November 27, 2021, 4:27pm UTC](https://discuss.elastic.co/t/should-i-keep-beat-version-in-index-template/290335 "2021-11-27T16:27:37Z")

</div>

Hi there, Hi have a very basic ES setup with winlogbeat configured with default options everywhere. By default, Winlogbeat loads index templates named winlogbeat-%{\[agent.version\]}-\* in ES. Because of that, any changes…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=118)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=120)
