# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=121

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 122

---

## [Filebeat : resource 'filebeat' exists, but it is not an alias](https://discuss.elastic.co/t/filebeat-resource-filebeat-exists-but-it-is-not-an-alias/289228)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 2\
**Last updated:** [November 22, 2021, 9:10pm UTC](https://discuss.elastic.co/t/filebeat-resource-filebeat-exists-but-it-is-not-an-alias/289228 "2021-11-22T21:10:32Z")

</div>

I have ELB set up running in kubernetes. But seeing following logs in filebeats 2021-11-15T18:08:27.786Z ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 Failed to connect to backoff(elasticsearch(http://elasti…

---

## [Installation of metricbeat (any Beat)](https://discuss.elastic.co/t/installation-of-metricbeat-any-beat/289583)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 2\
**Last updated:** [November 22, 2021, 11:22am UTC](https://discuss.elastic.co/t/installation-of-metricbeat-any-beat/289583 "2021-11-22T11:22:44Z")

</div>

I have just installed 7.15 metric beat, but I do not like any of the defaults. Typically when running an msi you can choose all the configurables. How can I achieve the same for the beat installations. I am on windows…

---

## [Filebeat 7.12 to output to multiple kafka topics](https://discuss.elastic.co/t/filebeat-7-12-to-output-to-multiple-kafka-topics/288056)

<div class="topic-metadata">

**Author:** [@itsec](https://discuss.elastic.co/u/itsec)\
**Replies:** 11\
**Last updated:** [November 22, 2021, 10:23am UTC](https://discuss.elastic.co/t/filebeat-7-12-to-output-to-multiple-kafka-topics/288056 "2021-11-22T10:23:15Z")

</div>

Hi, I'm on filebeat 7.12 (Centos7). How do i output to multiple topics Pls advise. filebeat: prospectors: - type: log enabled: true paths: -/opt/xssssss/log/xxx.txt close\_rename: true fields: document\_type: "x…

---

## [Metric beats and WMI](https://discuss.elastic.co/t/metric-beats-and-wmi/289063)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 5\
**Last updated:** [November 21, 2021, 10:09pm UTC](https://discuss.elastic.co/t/metric-beats-and-wmi/289063 "2021-11-21T22:09:12Z")

</div>

It has been suggested that it is possible to configure beats to collect data based on a WMI query. Is this true, and if so is there any useful documentation that you might be able to point me towards? thanks

---

## [FIleBeat not pushing few lines to Logstash](https://discuss.elastic.co/t/filebeat-not-pushing-few-lines-to-logstash/289011)

<div class="topic-metadata">

**Author:** [@nandatibco](https://discuss.elastic.co/u/nandatibco)\
**Replies:** 3\
**Last updated:** [November 20, 2021, 3:30pm UTC](https://discuss.elastic.co/t/filebeat-not-pushing-few-lines-to-logstash/289011 "2021-11-20T15:30:05Z")

</div>

File beat is not pushing all lines in a file to Logstash, and it is not consistent, it skips 3 lines in between. Im new to File Beat, please suggest if I missed any configuration. For example, my log file looks like thi…

---

## [Winlogbeat NewProcessFields Function Missing Parent Process](https://discuss.elastic.co/t/winlogbeat-newprocessfields-function-missing-parent-process/289679)

<div class="topic-metadata">

**Author:** [@elkn00b](https://discuss.elastic.co/u/elkn00b)\
**Replies:** 1\
**Last updated:** [November 19, 2021, 3:12pm UTC](https://discuss.elastic.co/t/winlogbeat-newprocessfields-function-missing-parent-process/289679 "2021-11-19T15:12:14Z")

</div>

Hi Elastic Team, I'm writing to request an update to the winlogbeat Windows Security module to add the parent process ID value for Windows Security event 4688. Lines 2132 to 2142 handle field renames for parent/child p…

---

## [Send Filebeat Internal Monitoring Via Logstash](https://discuss.elastic.co/t/send-filebeat-internal-monitoring-via-logstash/289468)

<div class="topic-metadata">

**Author:** [@jceddy](https://discuss.elastic.co/u/jceddy)\
**Replies:** 4\
**Last updated:** [November 19, 2021, 2:22pm UTC](https://discuss.elastic.co/t/send-filebeat-internal-monitoring-via-logstash/289468 "2021-11-19T14:22:00Z")

</div>

Basic question: Is there a way to configure Filebeat Internal Monitoring via Logstash? I am trying to add monitoring for Filebeat running on some external systems, but can only send it via Logstash (not directly to Elas…

---

## [Network metric when docker network is awsvpc](https://discuss.elastic.co/t/network-metric-when-docker-network-is-awsvpc/289687)

<div class="topic-metadata">

**Author:** [@mancausoft](https://discuss.elastic.co/u/mancausoft)\
**Replies:** 0\
**Last updated:** [November 19, 2021, 1:04pm UTC](https://discuss.elastic.co/t/network-metric-when-docker-network-is-awsvpc/289687 "2021-11-19T13:04:20Z")

</div>

I'm using metribeat running on ecs, and i can't get metrics from docker that use as network awsvpc. All docker that use bridge network are working fine. Configuration: module: docker enabled: true metricsets: conta…

---

## [Metricbeat : Certificate signed by unknow authority](https://discuss.elastic.co/t/metricbeat-certificate-signed-by-unknow-authority/288391)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 3\
**Last updated:** [November 19, 2021, 1:51am UTC](https://discuss.elastic.co/t/metricbeat-certificate-signed-by-unknow-authority/288391 "2021-11-19T01:51:08Z")

</div>

Hi, I have a metricbeat on debian. It has been a week since the metricbeat service stopped sending data. The cause: ERROR \[esclientleg\] transport/logging.go:37 Error dialing x509: certificate signed by unknown authorit…

---

## [Private key issues connecting beats to logstash & elasticsearch](https://discuss.elastic.co/t/private-key-issues-connecting-beats-to-logstash-elasticsearch/289412)

<div class="topic-metadata">

**Author:** [@K5SF](https://discuss.elastic.co/u/K5SF)\
**Replies:** 5\
**Last updated:** [November 19, 2021, 1:42am UTC](https://discuss.elastic.co/t/private-key-issues-connecting-beats-to-logstash-elasticsearch/289412 "2021-11-19T01:42:01Z")

</div>

Hi all, I am writing to you because I am doing an installation of the suite ELK with Logstash elastic kibana et file beat. Only, during my SSL configuration for logstash I end up with this error " Private key cannot be …

---

## [Input 'aws-s3' failed with: failed to initialize s3 poller: failed to get AWS region for bucket\_arn:](https://discuss.elastic.co/t/input-aws-s3-failed-with-failed-to-initialize-s3-poller-failed-to-get-aws-region-for-bucket-arn/289355)

<div class="topic-metadata">

**Author:** [@sguillen18](https://discuss.elastic.co/u/sguillen18)\
**Replies:** 3\
**Last updated:** [November 18, 2021, 9:41pm UTC](https://discuss.elastic.co/t/input-aws-s3-failed-with-failed-to-initialize-s3-poller-failed-to-get-aws-region-for-bucket-arn/289355 "2021-11-18T21:41:46Z")

</div>

Hello, I'm having trouble using the S3 module as described here I'm authenticating with access and secret key and my .yml begins like this: filebeat.inputs: - type: aws-s3 bucket\_arn: arn:aws:s3:::guillens number…

---

## [Get all IP's and mac's of hosts in network](https://discuss.elastic.co/t/get-all-ips-and-macs-of-hosts-in-network/289585)

<div class="topic-metadata">

**Author:** [@Markus\_Lindner](https://discuss.elastic.co/u/Markus_Lindner)\
**Replies:** 0\
**Last updated:** [November 18, 2021, 11:18am UTC](https://discuss.elastic.co/t/get-all-ips-and-macs-of-hosts-in-network/289585 "2021-11-18T11:18:54Z")

</div>

Hey guys, I want to monitor the hosts in my network and track the ip's and mac's. I use a metricbeat with "add\_host\_metadata" and "add\_cloud\_metadata" processors. Now i can see all IP's and Mac's of the host, but they …

---

## [Filebeat's stdin harvester\_buffer\_size leads to not processing messages](https://discuss.elastic.co/t/filebeats-stdin-harvester-buffer-size-leads-to-not-processing-messages/289597)

<div class="topic-metadata">

**Author:** [@djmcgreal-cc](https://discuss.elastic.co/u/djmcgreal-cc)\
**Replies:** 0\
**Last updated:** [November 18, 2021, 1:31pm UTC](https://discuss.elastic.co/t/filebeats-stdin-harvester-buffer-size-leads-to-not-processing-messages/289597 "2021-11-18T13:31:29Z")

</div>

I'd like to read from stdin to filebeat. It's in JSONL with json set on the stdin input. When I send a single message of about 1600 bytes nothing gets processed, even if I ask the filebeat process to quit. I can get thi…

---

## [Filebeat Pods OOMKilled](https://discuss.elastic.co/t/filebeat-pods-oomkilled/289586)

<div class="topic-metadata">

**Author:** [@pavank](https://discuss.elastic.co/u/pavank)\
**Replies:** 0\
**Last updated:** [November 18, 2021, 12:41pm UTC](https://discuss.elastic.co/t/filebeat-pods-oomkilled/289586 "2021-11-18T12:41:03Z")

</div>

Hi Filebeat version: 7.9.3 I am running Filebeat as a deployment on IBM Kubernetes and reading the logs from a PVC mounted on the cluster. I am seeing Filebeat pods restarting due to OOMKilled. There are some log file…

---

## [Filebeat not sending data consistently](https://discuss.elastic.co/t/filebeat-not-sending-data-consistently/289561)

<div class="topic-metadata">

**Author:** [@likhith1995](https://discuss.elastic.co/u/likhith1995)\
**Replies:** 0\
**Last updated:** [November 18, 2021, 9:34am UTC](https://discuss.elastic.co/t/filebeat-not-sending-data-consistently/289561 "2021-11-18T09:34:56Z")

</div>

Hi Team, Filebeat is not sending data to logstash continuously. Please find the screenshot in attachment. I see every 30 min a spike in the data, and the data goes to 0 events. After multiple restarts the same is repeat…

---

## [Split messages coming from the same port to different indexes](https://discuss.elastic.co/t/split-messages-coming-from-the-same-port-to-different-indexes/289548)

<div class="topic-metadata">

**Author:** [@Sederfo](https://discuss.elastic.co/u/Sederfo)\
**Replies:** 1\
**Last updated:** [November 18, 2021, 9:34am UTC](https://discuss.elastic.co/t/split-messages-coming-from-the-same-port-to-different-indexes/289548 "2021-11-18T09:34:25Z")

</div>

Hi! We use Filebeat and we receive messages from different sources with the same port. Is the a way to send these messages that come from the same port to different indexes? For example, switch messages should only be se…

---

## [Overriding filebeat palo alto modules @timestamp](https://discuss.elastic.co/t/overriding-filebeat-palo-alto-modules-timestamp/289436)

<div class="topic-metadata">

**Author:** [@Sirrah](https://discuss.elastic.co/u/Sirrah)\
**Replies:** 5\
**Last updated:** [November 18, 2021, 3:20am UTC](https://discuss.elastic.co/t/overriding-filebeat-palo-alto-modules-timestamp/289436 "2021-11-18T03:20:56Z")

</div>

Recently, I set up a filebeat to receive palo alto and sophos data. Filebeat module parsed the data as the timestamp. Instead of using the timestamp in log, i want to use the received time as @timestamp. Does there any…

---

## [Ingest mixed container logs with text and JSON \[ECK\]\[filebeat\]](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-eck-filebeat/289464)

<div class="topic-metadata">

**Author:** [@Sven\_Eliasson](https://discuss.elastic.co/u/Sven_Eliasson)\
**Replies:** 2\
**Last updated:** [November 18, 2021, 2:54am UTC](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-eck-filebeat/289464 "2021-11-18T02:54:06Z")

</div>

Hi, I'm trying to digest logs with Filebeat on our Kubernetes cluster which is using ECK on Kubernetes. We are migrating logs to a JSON format, but many legacy or 3rd party containers use plain logs. So we need to suppo…

---

## [Get IP and MAC of host](https://discuss.elastic.co/t/get-ip-and-mac-of-host/289457)

<div class="topic-metadata">

**Author:** [@Markus\_Lindner](https://discuss.elastic.co/u/Markus_Lindner)\
**Replies:** 0\
**Last updated:** [November 17, 2021, 1:20pm UTC](https://discuss.elastic.co/t/get-ip-and-mac-of-host/289457 "2021-11-17T13:20:32Z")

</div>

Hey guys, I want to monitor the hosts in my network and track the ip's and mac's. I use a metricbeat with "add\_host\_metadata" and "add\_cloud\_metadata" processors. Now i can see all IP's and Mac's of the host, but they …

---

## [When do I use unique: true?](https://discuss.elastic.co/t/when-do-i-use-unique-true/289492)

<div class="topic-metadata">

**Author:** [@Laszlo\_Stahorszki](https://discuss.elastic.co/u/Laszlo_Stahorszki)\
**Replies:** 0\
**Last updated:** [November 17, 2021, 6:10pm UTC](https://discuss.elastic.co/t/when-do-i-use-unique-true/289492 "2021-11-17T18:10:15Z")

</div>

Using kubernetes module for my metricbeat config, deployed as DaemonSet. metricbeat.config.modules: # Mounted \`metricbeat-daemonset-modules\` configmap: path: ${path.config}/modules.yml # Reload module config…

---

## [When using live reloading, why doesn't filebeat trigger live reloading immediately on first start?](https://discuss.elastic.co/t/when-using-live-reloading-why-doesnt-filebeat-trigger-live-reloading-immediately-on-first-start/289482)

<div class="topic-metadata">

**Author:** [@zhiyanglee](https://discuss.elastic.co/u/zhiyanglee)\
**Replies:** 0\
**Last updated:** [November 17, 2021, 5:16pm UTC](https://discuss.elastic.co/t/when-using-live-reloading-why-doesnt-filebeat-trigger-live-reloading-immediately-on-first-start/289482 "2021-11-17T17:16:24Z")

</div>

In the example below, "reload.period" specifies that the file is checked for changes once every 30 seconds. however, the first time you start filebeat you still have to wait 30 seconds for the configuration file to load,…

---

## [Origin of Recursive Lookup Not Captured](https://discuss.elastic.co/t/origin-of-recursive-lookup-not-captured/289479)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 0\
**Last updated:** [November 17, 2021, 4:16pm UTC](https://discuss.elastic.co/t/origin-of-recursive-lookup-not-captured/289479 "2021-11-17T16:16:37Z")

</div>

I have packetbeat installed on my DNS server. The intent was to capture any DNS traffic from clients on my network. This is working well, I'm seeing client lookups being recorded. However, when my DNS server has to go…

---

## [Rabbit MQ file beat unable to install in ubuntu](https://discuss.elastic.co/t/rabbit-mq-file-beat-unable-to-install-in-ubuntu/289443)

<div class="topic-metadata">

**Author:** [@Anupam\_Mishra](https://discuss.elastic.co/u/Anupam_Mishra)\
**Replies:** 0\
**Last updated:** [November 17, 2021, 12:06pm UTC](https://discuss.elastic.co/t/rabbit-mq-file-beat-unable-to-install-in-ubuntu/289443 "2021-11-17T12:06:32Z")

</div>

curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.15.2-linux-x86\_64.tar.gz tar xzvf filebeat-7.15.2-linux-x86\_64.tar.gz Post execution it does create a folder with filebeat-7.15.2-linux-x86\_6…

---

## [FILEBEAT: hostname inside message not parsed](https://discuss.elastic.co/t/filebeat-hostname-inside-message-not-parsed/288850)

<div class="topic-metadata">

**Author:** [@Sederfo](https://discuss.elastic.co/u/Sederfo)\
**Replies:** 2\
**Last updated:** [November 17, 2021, 3:50pm UTC](https://discuss.elastic.co/t/filebeat-hostname-inside-message-not-parsed/288850 "2021-11-17T15:50:06Z")

</div>

We are using Filebeat for processing Syslog messages sent from switches. We know that the raw Syslog messages contain the hostname of the device (we tested it with RSyslog). The problem is that Filebeat does not read th…

---

## [Metric Beats Filesystem metric](https://discuss.elastic.co/t/metric-beats-filesystem-metric/289331)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 2\
**Last updated:** [November 17, 2021, 9:04am UTC](https://discuss.elastic.co/t/metric-beats-filesystem-metric/289331 "2021-11-17T09:04:45Z")

</div>

System filesystem metricset | Metricbeat Reference \[7.15\] | Elastic says that filesystem data is captured in windows however when trying I get INFO module/wrapper.go:259 Error fetching data for metricbeat system.file…

---

## [Windows NPS Logs](https://discuss.elastic.co/t/windows-nps-logs/289115)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 10\
**Last updated:** [November 17, 2021, 7:18am UTC](https://discuss.elastic.co/t/windows-nps-logs/289115 "2021-11-17T07:18:57Z")

</div>

Hello everyone, I've been looking for a filebeat module for NPS Logs but there doesn't appear to be one available. What are my options here? I have winlogbeat which can get stuff from event log but in C:\\Windows\\Logs …

---

## [Exiting: error loading config file: yaml: line 189: did not find expected key](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-189-did-not-find-expected-key/289317)

<div class="topic-metadata">

**Author:** [@armughan](https://discuss.elastic.co/u/armughan)\
**Replies:** 2\
**Last updated:** [November 17, 2021, 6:37am UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-189-did-not-find-expected-key/289317 "2021-11-17T06:37:30Z")

</div>

Hi All, I'm trying to connect Filebeat with Elasticsearch After the configuration of filebeat.yml I'm having "Exiting: error loading config file: yaml: line 189: did not find expected key" filebeat.inputs: - type: log…

---

## [Filebeat drop\_fields processors module does not work](https://discuss.elastic.co/t/filebeat-drop-fields-processors-module-does-not-work/289318)

<div class="topic-metadata">

**Author:** [@bilgicsin](https://discuss.elastic.co/u/bilgicsin)\
**Replies:** 0\
**Last updated:** [November 16, 2021, 11:55am UTC](https://discuss.elastic.co/t/filebeat-drop-fields-processors-module-does-not-work/289318 "2021-11-16T11:55:12Z")

</div>

Hi, We have elastic gold licence. we use filebeat agent to send logs logstash, on logstash we do some transformation and send logs to elasticsearh. Before I was dropping default values on logstash but now I want to dro…

---

## [Heartbeat monitor fails with io error 'EOF'](https://discuss.elastic.co/t/heartbeat-monitor-fails-with-io-error-eof/288644)

<div class="topic-metadata">

**Author:** [@SanderP](https://discuss.elastic.co/u/SanderP)\
**Replies:** 3\
**Last updated:** [November 16, 2021, 11:34am UTC](https://discuss.elastic.co/t/heartbeat-monitor-fails-with-io-error-eof/288644 "2021-11-16T11:34:10Z")

</div>

Hi, I'm trying to do a check on philips-hue.com and my monitor is not giving the correct response. It is showing an io error with EOF in the message. I've been trying to find out why it fails, but am not successful yet: …

---

## [Metric libbeat.output.write.bytes, libbeat.output.read.bytes, libbeat.output.write.errors and libbeat.output.read.errors shows 0 always](https://discuss.elastic.co/t/metric-libbeat-output-write-bytes-libbeat-output-read-bytes-libbeat-output-write-errors-and-libbeat-output-read-errors-shows-0-always/289260)

<div class="topic-metadata">

**Author:** [@mbhavana](https://discuss.elastic.co/u/mbhavana)\
**Replies:** 0\
**Last updated:** [November 16, 2021, 5:30am UTC](https://discuss.elastic.co/t/metric-libbeat-output-write-bytes-libbeat-output-read-bytes-libbeat-output-write-errors-and-libbeat-output-read-errors-shows-0-always/289260 "2021-11-16T05:30:31Z")

</div>

Hello there, i have used REST API "curl -XGET localhost:5066/stats" to get the stats of filebeat.Metrics, libbeat.output.write.bytes, libbeat.output.read.bytes, libbeat.output.write.errors and libbeat.output.read.errors …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=120)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=122)
