# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=122

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 123

---

## [Error creating runner from config: metricset 'activemq/(broker, queue, topic)' not found](https://discuss.elastic.co/t/error-creating-runner-from-config-metricset-activemq-broker-queue-topic-not-found/289258)

<div class="topic-metadata">

**Author:** [@Tina\_Rawat](https://discuss.elastic.co/u/Tina_Rawat)\
**Replies:** 0\
**Last updated:** [November 16, 2021, 5:04am UTC](https://discuss.elastic.co/t/error-creating-runner-from-config-metricset-activemq-broker-queue-topic-not-found/289258 "2021-11-16T05:04:47Z")

</div>

Hi Team, I've started metricbeat and enabled activemq and jolokia module. I'm getting---- Error : 2021-11-15T16:19:36.032+0800 ERROR \[reload\] cfgfile/list.go:96 Error creating runner from config: 1 error: 3 errors: me…

---

## [ES 7.15 FileBeats Sophos XG module not separating data into variables](https://discuss.elastic.co/t/es-7-15-filebeats-sophos-xg-module-not-separating-data-into-variables/288577)

<div class="topic-metadata">

**Author:** [@Samy\_Weee](https://discuss.elastic.co/u/Samy_Weee)\
**Replies:** 23\
**Last updated:** [November 16, 2021, 4:59am UTC](https://discuss.elastic.co/t/es-7-15-filebeats-sophos-xg-module-not-separating-data-into-variables/288577 "2021-11-16T04:59:55Z")

</div>

Following This link to configure sophos Module. www.elastic.co/.../filebeat-module-sophos.html I followed the documentation at www.elastic.co/.../filebeat-module-sophos.html and was able to get the data into ES, issue…

---

## [Heartbeat fake timeout](https://discuss.elastic.co/t/heartbeat-fake-timeout/287278)

<div class="topic-metadata">

**Author:** [@guillaumetel10](https://discuss.elastic.co/u/guillaumetel10)\
**Replies:** 5\
**Last updated:** [November 16, 2021, 3:01am UTC](https://discuss.elastic.co/t/heartbeat-fake-timeout/287278 "2021-11-16T03:01:56Z")

</div>

Hi, We use hearbeat to monitor a hundred applications. In general it works well, but sometimes some applications are down (only for a single ping) according to the tool. However, this is not the case according to our t…

---

## [Elastic-agent filebeat logs spams error messages and overflows the memory](https://discuss.elastic.co/t/elastic-agent-filebeat-logs-spams-error-messages-and-overflows-the-memory/289188)

<div class="topic-metadata">

**Author:** [@LaurisJakobsons](https://discuss.elastic.co/u/LaurisJakobsons)\
**Replies:** 0\
**Last updated:** [November 15, 2021, 11:15am UTC](https://discuss.elastic.co/t/elastic-agent-filebeat-logs-spams-error-messages-and-overflows-the-memory/289188 "2021-11-15T11:15:45Z")

</div>

We are running elastic-agent (7.15.1) to monitor Kubernetes cluster we have encountered a problem with filebeat filling the logs with error messages and overflowing the memory causing agent processes (filebeat, metricsbe…

---

## [Filebeat cloudwatch input log\_group\_name\_prefix only starts one input](https://discuss.elastic.co/t/filebeat-cloudwatch-input-log-group-name-prefix-only-starts-one-input/289168)

<div class="topic-metadata">

**Author:** [@Kkakku](https://discuss.elastic.co/u/Kkakku)\
**Replies:** 0\
**Last updated:** [November 15, 2021, 8:31am UTC](https://discuss.elastic.co/t/filebeat-cloudwatch-input-log-group-name-prefix-only-starts-one-input/289168 "2021-11-15T08:31:47Z")

</div>

I'm trying to use aws-cloudwatch input with Filebeat 7.15.2, because I don't want to add every lambda log group separately. I've tried following input config in my filebeat.yml: filebeat.inputs: - type: aws-cloudwatch …

---

## [Microsoft windows clusters](https://discuss.elastic.co/t/microsoft-windows-clusters/289065)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 2\
**Last updated:** [November 15, 2021, 8:23am UTC](https://discuss.elastic.co/t/microsoft-windows-clusters/289065 "2021-11-15T08:23:56Z")

</div>

I need to capture metrics that are clustered (microsoft windows), such that specific resources move when the cluster moves. Some resources stay on the node, other move between nodes as the cluster moves. How are \*beats…

---

## [Perf stats](https://discuss.elastic.co/t/perf-stats/289061)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 2\
**Last updated:** [November 15, 2021, 8:22am UTC](https://discuss.elastic.co/t/perf-stats/289061 "2021-11-15T08:22:37Z")

</div>

I have read the guides on configuring windows counters but cannot make any sense of what they are talking about, and the example seems incomplete. Would anyone have an example file that capture cpu, ram, and disk space.…

---

## [Filebeat panics with multiple filestream inputs](https://discuss.elastic.co/t/filebeat-panics-with-multiple-filestream-inputs/289152)

<div class="topic-metadata">

**Author:** [@gwvandesteeg](https://discuss.elastic.co/u/gwvandesteeg)\
**Replies:** 0\
**Last updated:** [November 15, 2021, 3:57am UTC](https://discuss.elastic.co/t/filebeat-panics-with-multiple-filestream-inputs/289152 "2021-11-15T03:57:38Z")

</div>

I'm seeing a bunch of errors when configuring filebeat with multiple filestream input types. The configuration is simple enough, filebeat (7.15.1) running on Ubuntu 18.04 LTS forwards everything to logstash using beats. …

---

## [Error: Exiting: No paths were defined for input accessing config](https://discuss.elastic.co/t/error-exiting-no-paths-were-defined-for-input-accessing-config/289128)

<div class="topic-metadata">

**Author:** [@Rakesh\_Kapoor](https://discuss.elastic.co/u/Rakesh_Kapoor)\
**Replies:** 1\
**Last updated:** [November 14, 2021, 9:11pm UTC](https://discuss.elastic.co/t/error-exiting-no-paths-were-defined-for-input-accessing-config/289128 "2021-11-14T21:11:18Z")

</div>

I setup Elasticsearch and kibana on a secondary laptop and they are accessible from my primary laptop. i am setting up filebeat in my primary laptop. filebeat test config -e returns config ok filebeat run fails with e…

---

## [Filebeat ssl not working](https://discuss.elastic.co/t/filebeat-ssl-not-working/289077)

<div class="topic-metadata">

**Author:** [@dessy53](https://discuss.elastic.co/u/dessy53)\
**Replies:** 0\
**Last updated:** [November 12, 2021, 2:36pm UTC](https://discuss.elastic.co/t/filebeat-ssl-not-working/289077 "2021-11-12T14:36:26Z")

</div>

Continuing the discussion from Filebeat not fowarding to Logstash: filebeat not working after configuring ssl. below is my filebeat.yml file

---

## [Detect when the setup command was already executed on a machine](https://discuss.elastic.co/t/detect-when-the-setup-command-was-already-executed-on-a-machine/288983)

<div class="topic-metadata">

**Author:** [@VirtualEvan](https://discuss.elastic.co/u/VirtualEvan)\
**Replies:** 3\
**Last updated:** [November 12, 2021, 9:18am UTC](https://discuss.elastic.co/t/detect-when-the-setup-command-was-already-executed-on-a-machine/288983 "2021-11-12T09:18:32Z")

</div>

Hi there. I am working on some PowerShell DSC configurations which include installation and setup of Filebeat. In general everything works fine, but I am struggling to find a way to detect if the setup command was alrea…

---

## [Filebeat published syslogs aren't showing up in Kibana](https://discuss.elastic.co/t/filebeat-published-syslogs-arent-showing-up-in-kibana/289050)

<div class="topic-metadata">

**Author:** [@dahe](https://discuss.elastic.co/u/dahe)\
**Replies:** 1\
**Last updated:** [November 12, 2021, 9:00am UTC](https://discuss.elastic.co/t/filebeat-published-syslogs-arent-showing-up-in-kibana/289050 "2021-11-12T09:00:31Z")

</div>

I'm sending generated syslogs from kiwi syslog generator from one machine to another. Filebeat is expecting syslog input and receives them successfully. Filebeat log clearly states that events are being published. But I…

---

## [Odd swap metric values with Metricbeat 7.15.2 in Windows](https://discuss.elastic.co/t/odd-swap-metric-values-with-metricbeat-7-15-2-in-windows/288956)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 0\
**Last updated:** [November 11, 2021, 7:00am UTC](https://discuss.elastic.co/t/odd-swap-metric-values-with-metricbeat-7-15-2-in-windows/288956 "2021-11-11T07:00:57Z")

</div>

Hi, everyone I have installed a Metricbeat 7.15.1 in Windows Server 2019. Here you are a screenshot about memory: Metricbeat: Are these values right? I don't understand very well swap metrics. Thanks in advanc…

---

## [Deployment considerations for beats containing dashboards](https://discuss.elastic.co/t/deployment-considerations-for-beats-containing-dashboards/289021)

<div class="topic-metadata">

**Author:** [@jhettich](https://discuss.elastic.co/u/jhettich)\
**Replies:** 0\
**Last updated:** [November 11, 2021, 9:49pm UTC](https://discuss.elastic.co/t/deployment-considerations-for-beats-containing-dashboards/289021 "2021-11-11T21:49:39Z")

</div>

Beats often contain dashboards, which can be imported into Kibana by running the "setup" command. However, beats are typically data shippers that you install as agents on your servers. Since, from a deployment perspect…

---

## [Filebeat source field missing in 7.8](https://discuss.elastic.co/t/filebeat-source-field-missing-in-7-8/289005)

<div class="topic-metadata">

**Author:** [@PMDubuc](https://discuss.elastic.co/u/PMDubuc)\
**Replies:** 5\
**Last updated:** [November 11, 2021, 8:48pm UTC](https://discuss.elastic.co/t/filebeat-source-field-missing-in-7-8/289005 "2021-11-11T20:48:31Z")

</div>

We've recently upgraded our elastic stack and have upgraded our Filebeat version from 5.6.14 to 7.8.1. The old version used to provide a "source" field that contained the path name of the log file. This field is missin…

---

## [Shipping log from an unmanagable folder structure using filebeat](https://discuss.elastic.co/t/shipping-log-from-an-unmanagable-folder-structure-using-filebeat/289014)

<div class="topic-metadata">

**Author:** [@luka.klaric](https://discuss.elastic.co/u/luka.klaric)\
**Replies:** 0\
**Last updated:** [November 11, 2021, 6:46pm UTC](https://discuss.elastic.co/t/shipping-log-from-an-unmanagable-folder-structure-using-filebeat/289014 "2021-11-11T18:46:09Z")

</div>

I am trying to ship log files to logstash using filebeat. The folder structure of the input path is currently very branchy and very big. We have a following structure: \<LOG\_PATH\>/\<STREAM\>/\<WORKFLOW\>/\<TASK\>/\<EXECUTION\_D…

---

## [Fleet Server installation issue](https://discuss.elastic.co/t/fleet-server-installation-issue/287741)

<div class="topic-metadata">

**Author:** [@dmitryyankowski](https://discuss.elastic.co/u/dmitryyankowski)\
**Replies:** 1\
**Last updated:** [November 11, 2021, 5:34pm UTC](https://discuss.elastic.co/t/fleet-server-installation-issue/287741 "2021-11-11T17:34:50Z")

</div>

Note: OS is Ubuntu 20.04 and running Elastic Agent v7.15.1 I'm trying to setup a Fleet Server on my server and Elastic-Agent doesn't seem to be respecting the option for specifying my Fleet Server URL endpoint via the K…

---

## [Error "failed to update state in the registry"](https://discuss.elastic.co/t/error-failed-to-update-state-in-the-registry/289002)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 1\
**Last updated:** [November 11, 2021, 5:21pm UTC](https://discuss.elastic.co/t/error-failed-to-update-state-in-the-registry/289002 "2021-11-11T17:21:52Z")

</div>

Hello! I have a strange error using httpjson-input plugin in filebeat. Everything works fine, I was getting data updates via cursor until now. Now in logs everytime request finished with \> 0 events published I get an er…

---

## [How to configure file beat to send to data stream so that life policy settings can be made use of?](https://discuss.elastic.co/t/how-to-configure-file-beat-to-send-to-data-stream-so-that-life-policy-settings-can-be-made-use-of/288805)

<div class="topic-metadata">

**Author:** [@shi](https://discuss.elastic.co/u/shi)\
**Replies:** 2\
**Last updated:** [November 11, 2021, 4:36pm UTC](https://discuss.elastic.co/t/how-to-configure-file-beat-to-send-to-data-stream-so-that-life-policy-settings-can-be-made-use-of/288805 "2021-11-11T16:36:39Z")

</div>

How to configure file beat to send to data stream so that life policy settings can be made use of? Also , is there any change to be made about the corresponding setting of ingest pipeline, if we use configuration of da…

---

## [Read from the beginning filebeat](https://discuss.elastic.co/t/read-from-the-beginning-filebeat/288904)

<div class="topic-metadata">

**Author:** [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Replies:** 4\
**Last updated:** [November 11, 2021, 3:37pm UTC](https://discuss.elastic.co/t/read-from-the-beginning-filebeat/288904 "2021-11-11T15:37:02Z")

</div>

hello! Is there any parameter to tell an input in filebeat to read from the beginning of the document? like the start\_position =\> beginnig of logstash Thank you!

---

## [Winlogbeat.exe - Failed: 32bit on 64bit system](https://discuss.elastic.co/t/winlogbeat-exe-failed-32bit-on-64bit-system/288891)

<div class="topic-metadata">

**Author:** [@merida](https://discuss.elastic.co/u/merida)\
**Replies:** 2\
**Last updated:** [November 11, 2021, 1:49pm UTC](https://discuss.elastic.co/t/winlogbeat-exe-failed-32bit-on-64bit-system/288891 "2021-11-11T13:49:34Z")

</div>

Hello, I downloaded winlogbeat-7.15.1-windows-x86 and installed it using "uninstall-service-winlogbeat.ps1" according to the documentation. (WindowsServer2019) PS C:\\program files\\Winlogbeat\> .\\install-service-winlo…

---

## [Discrepancy between elastic agent and metricbeat data](https://discuss.elastic.co/t/discrepancy-between-elastic-agent-and-metricbeat-data/288968)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 0\
**Last updated:** [November 11, 2021, 8:57am UTC](https://discuss.elastic.co/t/discrepancy-between-elastic-agent-and-metricbeat-data/288968 "2021-11-11T08:57:50Z")

</div>

I'm currently trying to decide to use metricbeat or elastic-agent for my system and I'm finding that there is quite a significant difference in the memory reported for each system. Here are the screenshots Here is w…

---

## [Filebeat Configuration: How should be configured output.elasticsearch.index and setup.template](https://discuss.elastic.co/t/filebeat-configuration-how-should-be-configured-output-elasticsearch-index-and-setup-template/288960)

<div class="topic-metadata">

**Author:** [@happyinteger](https://discuss.elastic.co/u/happyinteger)\
**Replies:** 0\
**Last updated:** [November 11, 2021, 7:53am UTC](https://discuss.elastic.co/t/filebeat-configuration-how-should-be-configured-output-elasticsearch-index-and-setup-template/288960 "2021-11-11T07:53:47Z")

</div>

Hello, Here is a section from my filebeat.yml I'm wondering how output.Elasticsearch.index and setup.template.pattern are related each other? Would such a configuration like this lead any problems (or confusion when…

---

## [Potential parsing failure of zeek.smtp.date field through the zeek's filebeat smtp pipeline](https://discuss.elastic.co/t/potential-parsing-failure-of-zeek-smtp-date-field-through-the-zeeks-filebeat-smtp-pipeline/288948)

<div class="topic-metadata">

**Author:** [@eyng](https://discuss.elastic.co/u/eyng)\
**Replies:** 0\
**Last updated:** [November 11, 2021, 5:51am UTC](https://discuss.elastic.co/t/potential-parsing-failure-of-zeek-smtp-date-field-through-the-zeeks-filebeat-smtp-pipeline/288948 "2021-11-11T05:51:00Z")

</div>

Hello, This appears to be a known issue similar to Filebeat Zeek and date parsing with SMTP broken, but the issue still persists in filebeat-7.15.1-x86\_64.rpm module. As the SMTP Date fields format can vary depending on…

---

## [Winlogbeat high cpu & log volume](https://discuss.elastic.co/t/winlogbeat-high-cpu-log-volume/288942)

<div class="topic-metadata">

**Author:** [@reconluke](https://discuss.elastic.co/u/reconluke)\
**Replies:** 0\
**Last updated:** [November 11, 2021, 2:14am UTC](https://discuss.elastic.co/t/winlogbeat-high-cpu-log-volume/288942 "2021-11-11T02:14:23Z")

</div>

What is considered a "safe" number of daily logs from winlogbeat? What number of daily logs have you experienced issues from winlogbeat? I know these are hard to answer because there are many many variables, but I am c…

---

## [Missing socket metrics in 'System' integration in Fleet](https://discuss.elastic.co/t/missing-socket-metrics-in-system-integration-in-fleet/288865)

<div class="topic-metadata">

**Author:** [@dabo](https://discuss.elastic.co/u/dabo)\
**Replies:** 2\
**Last updated:** [November 10, 2021, 2:13pm UTC](https://discuss.elastic.co/t/missing-socket-metrics-in-system-integration-in-fleet/288865 "2021-11-10T14:13:43Z")

</div>

Hi, Can see that there is System socket\_summary metrics setting in System Integration in Fleet. Are there any plans to add system socket metrics to System integration as well? We are on 7.13.1. Is this maybe added in …

---

## [How to add new fields in ingest pipeline based on conditons?](https://discuss.elastic.co/t/how-to-add-new-fields-in-ingest-pipeline-based-on-conditons/288640)

<div class="topic-metadata">

**Author:** [@sidharth\_vijayakumar](https://discuss.elastic.co/u/sidharth_vijayakumar)\
**Replies:** 2\
**Last updated:** [November 10, 2021, 2:05pm UTC](https://discuss.elastic.co/t/how-to-add-new-fields-in-ingest-pipeline-based-on-conditons/288640 "2021-11-10T14:05:45Z")

</div>

Need to add a new field called app\_statuscode for in filebeat. The condition is that if message field contains 404 or 502 the value of app\_statuscode must be set to failed. If the Message field contains 200 OK then the …

---

## [Reset file offset once the harvester reaches end of file](https://discuss.elastic.co/t/reset-file-offset-once-the-harvester-reaches-end-of-file/288847)

<div class="topic-metadata">

**Author:** [@vasu01](https://discuss.elastic.co/u/vasu01)\
**Replies:** 1\
**Last updated:** [November 10, 2021, 1:46pm UTC](https://discuss.elastic.co/t/reset-file-offset-once-the-harvester-reaches-end-of-file/288847 "2021-11-10T13:46:11Z")

</div>

Is there a configuration property available in filebeat to start the harvester always from the beginning? The harvester should start from the beginning of the file irrespective of the update. We have specific logs (non-…

---

## [Prometheus via micrometer from spring](https://discuss.elastic.co/t/prometheus-via-micrometer-from-spring/288636)

<div class="topic-metadata">

**Author:** [@Ziemowit](https://discuss.elastic.co/u/Ziemowit)\
**Replies:** 1\
**Last updated:** [November 10, 2021, 1:23pm UTC](https://discuss.elastic.co/t/prometheus-via-micrometer-from-spring/288636 "2021-11-10T13:23:51Z")

</div>

I am exposing the memory metrics in Prometheus format from my spring application via micrometer. The response is following: # HELP jvm\_buffer\_count\_buffers An estimate of the number of buffers in the pool # TYPE jvm\_bu…

---

## [How cloud I build the filebeat image after change some code in beats/libbeat?](https://discuss.elastic.co/t/how-cloud-i-build-the-filebeat-image-after-change-some-code-in-beats-libbeat/288278)

<div class="topic-metadata">

**Author:** [@Icedroid](https://discuss.elastic.co/u/Icedroid)\
**Replies:** 6\
**Last updated:** [November 10, 2021, 12:29pm UTC](https://discuss.elastic.co/t/how-cloud-i-build-the-filebeat-image-after-change-some-code-in-beats-libbeat/288278 "2021-11-10T12:29:06Z")

</div>

I have add following code in the file beats/libbeat/kafka/config.go: if config.EnableIdempotent { k.Producer.Idempotent = true k.Net.MaxOpenRequests = 1 k.Producer.RequiredAcks = sarama.WaitForAll } Now I don't k…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=121)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=123)
