# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=120

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 121

---

## [Filebeat fails when I configure an ingest-pipeline on filebeat.yml](https://discuss.elastic.co/t/filebeat-fails-when-i-configure-an-ingest-pipeline-on-filebeat-yml/290314)

<div class="topic-metadata">

**Author:** [@feliperuiz](https://discuss.elastic.co/u/feliperuiz)\
**Replies:** 15\
**Last updated:** [November 26, 2021, 9:59pm UTC](https://discuss.elastic.co/t/filebeat-fails-when-i-configure-an-ingest-pipeline-on-filebeat-yml/290314 "2021-11-26T21:59:27Z")

</div>

Hi. I have a filebeat working OK and shipping csv logs to ELK cloud. I have created a new ingest-pipeline on ELK, that takes the message and create some fields: \[ { "csv": { "field": "message", "targe…

---

## [Metricbeat stack monitoring : i/o timeout when connecting to the same node](https://discuss.elastic.co/t/metricbeat-stack-monitoring-i-o-timeout-when-connecting-to-the-same-node/290307)

<div class="topic-metadata">

**Author:** [@preetish\_P](https://discuss.elastic.co/u/preetish_P)\
**Replies:** 0\
**Last updated:** [November 26, 2021, 3:51pm UTC](https://discuss.elastic.co/t/metricbeat-stack-monitoring-i-o-timeout-when-connecting-to-the-same-node/290307 "2021-11-26T15:51:55Z")

</div>

Hi guys, I am trying to setup Stack monitoring using metricbeat to move away from legacy collection. We run on v7.11.2 and RHEL7 with below setup: node 1: Elasticsearch, logstash, kibana node 2: Elasticsearch node 3:…

---

## [Filebeat multiline matching Docker log](https://discuss.elastic.co/t/filebeat-multiline-matching-docker-log/290301)

<div class="topic-metadata">

**Author:** [@exactlyaron](https://discuss.elastic.co/u/exactlyaron)\
**Replies:** 0\
**Last updated:** [November 26, 2021, 3:02pm UTC](https://discuss.elastic.co/t/filebeat-multiline-matching-docker-log/290301 "2021-11-26T15:02:18Z")

</div>

Hello, After a bit of assistance with multiline pattern matching. I'm using filebeat autodiscover Docker provider which is fine sending the logs to logstash, but pattern matching on timestamp doesn't seem to be working…

---

## [Filebeat Installation Error on Linux](https://discuss.elastic.co/t/filebeat-installation-error-on-linux/290279)

<div class="topic-metadata">

**Author:** [@SuhailRumane](https://discuss.elastic.co/u/SuhailRumane)\
**Replies:** 0\
**Last updated:** [November 26, 2021, 11:30am UTC](https://discuss.elastic.co/t/filebeat-installation-error-on-linux/290279 "2021-11-26T11:30:55Z")

</div>

Hi Team, We are getting below error while running the filebeat in our RHEL 7 server. 2021-11-24T03:12:49.750-0600 ERROR \[Elasticsearch\] Elasticsearch/client.go:224 failed to perform any bulk index operations: 500 Inter…

---

## [How to use Filebeat Traefik module with Docker?](https://discuss.elastic.co/t/how-to-use-filebeat-traefik-module-with-docker/290272)

<div class="topic-metadata">

**Author:** [@bluepuma77](https://discuss.elastic.co/u/bluepuma77)\
**Replies:** 0\
**Last updated:** [November 26, 2021, 10:28am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-traefik-module-with-docker/290272 "2021-11-26T10:28:26Z")

</div>

I am using Filebeat with Docker autodiscover. I added the Filebeat Traefik module to the config and it works fine when parsing access logs from the filesystem. My challenge is that Traefik does not do log roll-over. fil…

---

## [Netflow Enrich basic](https://discuss.elastic.co/t/netflow-enrich-basic/289303)

<div class="topic-metadata">

**Author:** [@randomguy](https://discuss.elastic.co/u/randomguy)\
**Replies:** 1\
**Last updated:** [November 26, 2021, 10:18am UTC](https://discuss.elastic.co/t/netflow-enrich-basic/289303 "2021-11-26T10:18:18Z")

</div>

Hi, I started to learn more about neflow in my home lab but soon realized the Filebeat Netflow module is a bit too simple. The short question: is there an easy way to enrich netflow data from filebeat? I think they ca…

---

## [How to manage filebeat logging?](https://discuss.elastic.co/t/how-to-manage-filebeat-logging/290264)

<div class="topic-metadata">

**Author:** [@Priya2](https://discuss.elastic.co/u/Priya2)\
**Replies:** 0\
**Last updated:** [November 26, 2021, 9:54am UTC](https://discuss.elastic.co/t/how-to-manage-filebeat-logging/290264 "2021-11-26T09:54:31Z")

</div>

I want to roll the os-filebeat-out.log, my Logging section in filebeat.yml looks like: logging.level: info logging.to\_files: true logging.files: path: /path/filebeat-7.14.1-linux-x86\_64 name: os-filebeat-out.…

---

## [Drop metadata fields using drop\_fields processor in elastic agent config](https://discuss.elastic.co/t/drop-metadata-fields-using-drop-fields-processor-in-elastic-agent-config/290215)

<div class="topic-metadata">

**Author:** [@clewo](https://discuss.elastic.co/u/clewo)\
**Replies:** 0\
**Last updated:** [November 25, 2021, 8:04pm UTC](https://discuss.elastic.co/t/drop-metadata-fields-using-drop-fields-processor-in-elastic-agent-config/290215 "2021-11-25T20:04:19Z")

</div>

Hi guys, I've issues to drop some metadata fields in the elastic agent config using the drop\_fields processor. I tried to configure the processor in the agent.yml inputs section: inputs: - id: b21f2d23-1bf5-4e0b-852…

---

## [Filebeat sending duplicates events](https://discuss.elastic.co/t/filebeat-sending-duplicates-events/289998)

<div class="topic-metadata">

**Author:** [@josepho](https://discuss.elastic.co/u/josepho)\
**Replies:** 1\
**Last updated:** [November 25, 2021, 4:56pm UTC](https://discuss.elastic.co/t/filebeat-sending-duplicates-events/289998 "2021-11-25T16:56:15Z")

</div>

Hi, Im running Elastic/Logstash/Filebeat v 7.15. I have beats installed on a few debian 9 machines, shipping log files. Everything is working well, except that we get duplicate entries. Seems like filebeat keep reading …

---

## [Issue when create custom index with filebeat in elasticsearch](https://discuss.elastic.co/t/issue-when-create-custom-index-with-filebeat-in-elasticsearch/287976)

<div class="topic-metadata">

**Author:** [@inazo](https://discuss.elastic.co/u/inazo)\
**Replies:** 1\
**Last updated:** [November 25, 2021, 3:44pm UTC](https://discuss.elastic.co/t/issue-when-create-custom-index-with-filebeat-in-elasticsearch/287976 "2021-11-25T15:44:03Z")

</div>

Hello, I need to create custom index for my filebeat agent for each host. Need to separate the data collected for each host. So i'll do this config in my filebeat.yml on the monitored host, after a large number of rese…

---

## [Waiting for a Fleet Server to connect](https://discuss.elastic.co/t/waiting-for-a-fleet-server-to-connect/290069)

<div class="topic-metadata">

**Author:** [@TarasP](https://discuss.elastic.co/u/TarasP)\
**Replies:** 0\
**Last updated:** [November 24, 2021, 1:10pm UTC](https://discuss.elastic.co/t/waiting-for-a-fleet-server-to-connect/290069 "2021-11-24T13:10:01Z")

</div>

Hello I have started Cloud Trial and seeing the same as Waiting for a Fleet Server to connect… error I can see Fleet and APM server is running. I tried restarting it but it doesn't help Can someone please point me w…

---

## [How to disable SSL or pass certifacte in metricbeat](https://discuss.elastic.co/t/how-to-disable-ssl-or-pass-certifacte-in-metricbeat/290124)

<div class="topic-metadata">

**Author:** [@pratik\_jain163](https://discuss.elastic.co/u/pratik_jain163)\
**Replies:** 0\
**Last updated:** [November 25, 2021, 5:52am UTC](https://discuss.elastic.co/t/how-to-disable-ssl-or-pass-certifacte-in-metricbeat/290124 "2021-11-25T05:52:12Z")

</div>

Hi, i am trying to install metricbeat on k8s where in its values file i am passing ES details as below. and i am getting x509: certificate signed by unknown authority and in ES doc i can see this but where i need to…

---

## [Issues generating custom Beat](https://discuss.elastic.co/t/issues-generating-custom-beat/290111)

<div class="topic-metadata">

**Author:** [@mbhakta](https://discuss.elastic.co/u/mbhakta)\
**Replies:** 0\
**Last updated:** [November 24, 2021, 11:21pm UTC](https://discuss.elastic.co/t/issues-generating-custom-beat/290111 "2021-11-24T23:21:05Z")

</div>

Hello! I'm attempting to create a custom beat using the instructions here: https://www.elastic.co/guide/en/beats/devguide/7.15/newbeat-generate.html and I'm having issues when running mage GenerateCustomBeat I'm run…

---

## [Metricbeat setup to return localhost metrics](https://discuss.elastic.co/t/metricbeat-setup-to-return-localhost-metrics/289880)

<div class="topic-metadata">

**Author:** [@maheshe](https://discuss.elastic.co/u/maheshe)\
**Replies:** 6\
**Last updated:** [November 24, 2021, 2:45pm UTC](https://discuss.elastic.co/t/metricbeat-setup-to-return-localhost-metrics/289880 "2021-11-24T14:45:50Z")

</div>

Running 7.11 Elastic on self managed eks 1.19 with Metricbeats 7.9 running on EC2 instance This is the below configuration of the metricbeat.yaml metricbeat.modules: - module: system metricsets: # - cpu …

---

## [Not receiving logs from Elastic Agent](https://discuss.elastic.co/t/not-receiving-logs-from-elastic-agent/289743)

<div class="topic-metadata">

**Author:** [@eleong](https://discuss.elastic.co/u/eleong)\
**Replies:** 2\
**Last updated:** [November 24, 2021, 2:13pm UTC](https://discuss.elastic.co/t/not-receiving-logs-from-elastic-agent/289743 "2021-11-24T14:13:56Z")

</div>

Hi, I cant seem to receive any logs from elastic agent installed on either Windows or Ubuntu machine. I've searched through the documentations to the best of my abilities but I'm afraid that I'm still too new to Elastic…

---

## [Auditbeat configuration to use the "Modification of OpenSSH binaries" detection rule](https://discuss.elastic.co/t/auditbeat-configuration-to-use-the-modification-of-openssh-binaries-detection-rule/289971)

<div class="topic-metadata">

**Author:** [@aryon](https://discuss.elastic.co/u/aryon)\
**Replies:** 1\
**Last updated:** [November 24, 2021, 1:46pm UTC](https://discuss.elastic.co/t/auditbeat-configuration-to-use-the-modification-of-openssh-binaries-detection-rule/289971 "2021-11-24T13:46:13Z")

</div>

Hello, I am trying to use this detection rule that relies on AuditBeat events: Modification of OpenSSH Binaries | Elastic Security Solution \[7.15\] | Elastic I set up AuditBeat 7.14.2 with the following configuration: a…

---

## [Elastic-agent not respecting the config file parameters](https://discuss.elastic.co/t/elastic-agent-not-respecting-the-config-file-parameters/289898)

<div class="topic-metadata">

**Author:** [@Munavir\_Chavody](https://discuss.elastic.co/u/Munavir_Chavody)\
**Replies:** 3\
**Last updated:** [November 24, 2021, 1:45pm UTC](https://discuss.elastic.co/t/elastic-agent-not-respecting-the-config-file-parameters/289898 "2021-11-24T13:45:15Z")

</div>

Elastic agent doesn't seem to respect the parameters specified in the config file. As per below config, gRPC should bind to 6790. Rather it binds on 6789 (default). agent.grpc: address: localhost port: 6790 Here's …

---

## [Can filebeat autodiscover collect logs from k8s emptydir volume?](https://discuss.elastic.co/t/can-filebeat-autodiscover-collect-logs-from-k8s-emptydir-volume/290071)

<div class="topic-metadata">

**Author:** [@ydy](https://discuss.elastic.co/u/ydy)\
**Replies:** 0\
**Last updated:** [November 24, 2021, 1:17pm UTC](https://discuss.elastic.co/t/can-filebeat-autodiscover-collect-logs-from-k8s-emptydir-volume/290071 "2021-11-24T13:17:27Z")

</div>

Here is my filebeat config yaml, downloaded from Run Filebeat on Kubernetes | Filebeat Reference \[7.15\] | Elastic I can't get log when the templates.config.type is log (yaml below), But when I set this to container I ca…

---

## [Elastic Agent ElasticSearch integration doesn't work with custom CA](https://discuss.elastic.co/t/elastic-agent-elasticsearch-integration-doesnt-work-with-custom-ca/290041)

<div class="topic-metadata">

**Author:** [@CarolinDohmen](https://discuss.elastic.co/u/CarolinDohmen)\
**Replies:** 0\
**Last updated:** [November 24, 2021, 10:38am UTC](https://discuss.elastic.co/t/elastic-agent-elasticsearch-integration-doesnt-work-with-custom-ca/290041 "2021-11-24T10:38:21Z")

</div>

Hi, I would like to use the Elasticsearch integration with Elastic Agents managed by Fleet. We have a self-managed Elasticsearch cluster running in Kubernetes and we are using self-signed certificates for the ES. I have…

---

## [There are wrong values with memory usage in kubernetes metricbeat module](https://discuss.elastic.co/t/there-are-wrong-values-with-memory-usage-in-kubernetes-metricbeat-module/288261)

<div class="topic-metadata">

**Author:** [@Sergio\_Ferreyra](https://discuss.elastic.co/u/Sergio_Ferreyra)\
**Replies:** 4\
**Last updated:** [November 24, 2021, 3:53am UTC](https://discuss.elastic.co/t/there-are-wrong-values-with-memory-usage-in-kubernetes-metricbeat-module/288261 "2021-11-24T03:53:17Z")

</div>

Hi team, Having an issue with the values of this metric. kubernetes.node.memory.usage.bytes Looks like is not taking the proper values, for example: I am using that metric to get the memory usage but is not the cor…

---

## [Fleet Server and Elastic Agents not working when adding nodeSelectors](https://discuss.elastic.co/t/fleet-server-and-elastic-agents-not-working-when-adding-nodeselectors/289996)

<div class="topic-metadata">

**Author:** [@GerardoManzo](https://discuss.elastic.co/u/GerardoManzo)\
**Replies:** 0\
**Last updated:** [November 23, 2021, 11:18pm UTC](https://discuss.elastic.co/t/fleet-server-and-elastic-agents-not-working-when-adding-nodeselectors/289996 "2021-11-23T23:18:34Z")

</div>

Hi, I'm trying to setup a cluster using the ECK operator 1.8.0 and a GKE cluster with dedicated node pools: 1 node pool for Elasticsearch masters in europe-west1-b 1 node pool in europe-west1-b and in europe-west1-d fo…

---

## [Packetbeat - full URL on HTTPS traffic?](https://discuss.elastic.co/t/packetbeat-full-url-on-https-traffic/289945)

<div class="topic-metadata">

**Author:** [@EdgeSync](https://discuss.elastic.co/u/EdgeSync)\
**Replies:** 1\
**Last updated:** [November 23, 2021, 5:20pm UTC](https://discuss.elastic.co/t/packetbeat-full-url-on-https-traffic/289945 "2021-11-23T17:20:24Z")

</div>

Is it possible to get the full URL from HTTPS traffic. I would like to be able to view the full URI that a client is attempting to access. e.g. https://myserver.com/some\_part/this\_file.exe I have packetbeat monitoring…

---

## [Elastic-Agent healthy but sends no logs](https://discuss.elastic.co/t/elastic-agent-healthy-but-sends-no-logs/289742)

<div class="topic-metadata">

**Author:** [@jobr97](https://discuss.elastic.co/u/jobr97)\
**Replies:** 2\
**Last updated:** [November 23, 2021, 5:04pm UTC](https://discuss.elastic.co/t/elastic-agent-healthy-but-sends-no-logs/289742 "2021-11-23T17:04:24Z")

</div>

Hi, Im trying to use Elastic Agent on my Windows 10 machine. I have sucessfully enrolled the machine and can see it marked as healty in the agent overview. However there is no log data delivered from the agent and also …

---

## [Best practices on multiple syslog sources](https://discuss.elastic.co/t/best-practices-on-multiple-syslog-sources/289951)

<div class="topic-metadata">

**Author:** [@eleong](https://discuss.elastic.co/u/eleong)\
**Replies:** 1\
**Last updated:** [November 23, 2021, 2:13pm UTC](https://discuss.elastic.co/t/best-practices-on-multiple-syslog-sources/289951 "2021-11-23T14:13:14Z")

</div>

Hi all, Just asking some expert opinions here, my main objective currently is to ingest syslogs from multiple sources (assuming there are 10 different brands and syslog streams). I understand that there are ways to add…

---

## [Filebeat on RHEL not sending to Logstash from all managed servers](https://discuss.elastic.co/t/filebeat-on-rhel-not-sending-to-logstash-from-all-managed-servers/289952)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 0\
**Last updated:** [November 23, 2021, 1:36pm UTC](https://discuss.elastic.co/t/filebeat-on-rhel-not-sending-to-logstash-from-all-managed-servers/289952 "2021-11-23T13:36:30Z")

</div>

Good Morning; I have an odd situation with regards to my Filebeat installation. I have it installed on all of my RHEL v.8, and out of the 5 I have it installed on, only 2 are sending the information to logstash, where …

---

## [Multiline Filebeat suppresses lines](https://discuss.elastic.co/t/multiline-filebeat-suppresses-lines/289609)

<div class="topic-metadata">

**Author:** [@Tornis](https://discuss.elastic.co/u/Tornis)\
**Replies:** 1\
**Last updated:** [November 23, 2021, 12:58pm UTC](https://discuss.elastic.co/t/multiline-filebeat-suppresses-lines/289609 "2021-11-23T12:58:10Z")

</div>

Hey guys, I have a problem in the filbeat multline that is not concatenating correctly with the defined pattern. When I look at the result using it through the output.console I see that it suppresses part of the line th…

---

## [CPU Total/Free Virtual Machine with vSphere Module \[Metricbeat 7.15.2\]](https://discuss.elastic.co/t/cpu-total-free-virtual-machine-with-vsphere-module-metricbeat-7-15-2/289449)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 5\
**Last updated:** [November 23, 2021, 10:26am UTC](https://discuss.elastic.co/t/cpu-total-free-virtual-machine-with-vsphere-module-metricbeat-7-15-2/289449 "2021-11-23T10:26:45Z")

</div>

Hi, everyone I have configured vSphere module in Metricbeat 7.15.2 in order to get metrics from my VMware hosts and VMs. Metricbeat send all VM memory metrics, here you are: vsphere.virtualmachine.memory.free.guest.by…

---

## [Filebeat : module mysql and Problem with \\n in mysql slow query log](https://discuss.elastic.co/t/filebeat-module-mysql-and-problem-with-n-in-mysql-slow-query-log/289869)

<div class="topic-metadata">

**Author:** [@toger](https://discuss.elastic.co/u/toger)\
**Replies:** 0\
**Last updated:** [November 22, 2021, 7:42pm UTC](https://discuss.elastic.co/t/filebeat-module-mysql-and-problem-with-n-in-mysql-slow-query-log/289869 "2021-11-22T19:42:01Z")

</div>

We are using filebeat with active mysql module to send to ES slow query multiline. On kibana mysql slowlog discover view, the field mysql.slowlog.query is EMPTY in the Data Table (because of ^M or \\n in the sql query). …

---

## [Elastic Agent environment variables file](https://discuss.elastic.co/t/elastic-agent-environment-variables-file/289713)

<div class="topic-metadata">

**Author:** [@Craig\_Lawson](https://discuss.elastic.co/u/Craig_Lawson)\
**Replies:** 3\
**Last updated:** [November 22, 2021, 11:58pm UTC](https://discuss.elastic.co/t/elastic-agent-environment-variables-file/289713 "2021-11-22T23:58:49Z")

</div>

Hi all, I'm not 100% sure where to submit a request to change so figured I would start here... While installing elastic agent using the generic linux package I have battled for some time to get it to work with a web pr…

---

## [Trouble with sending logs from filebeat to elasticsearch](https://discuss.elastic.co/t/trouble-with-sending-logs-from-filebeat-to-elasticsearch/289761)

<div class="topic-metadata">

**Author:** [@Butovoboy](https://discuss.elastic.co/u/Butovoboy)\
**Replies:** 7\
**Last updated:** [November 22, 2021, 10:24pm UTC](https://discuss.elastic.co/t/trouble-with-sending-logs-from-filebeat-to-elasticsearch/289761 "2021-11-22T22:24:14Z")

</div>

Hello, everyone! I have an Elasticsearch with kibana started in docker. And I also have filebeat running running on the server and sending logs to Elasticsearch. So, I have there is no logs in kibana, but all dashboards…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=119)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=121)
