# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=123

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 124

---

## [Can't drop events from auditbeat](https://discuss.elastic.co/t/cant-drop-events-from-auditbeat/288221)

<div class="topic-metadata">

**Author:** [@sadux](https://discuss.elastic.co/u/sadux)\
**Replies:** 2\
**Last updated:** [November 10, 2021, 10:52am UTC](https://discuss.elastic.co/t/cant-drop-events-from-auditbeat/288221 "2021-11-10T10:52:09Z")

</div>

Hello! Just want to filter some useless logs from auditbeat. Try this config at auditbeat.yml: - module: system processors: - drop\_event: when: equals: event.action: "network\_flow" …

---

## [Heartbeat.yml file number\_of\_replicas not being applied](https://discuss.elastic.co/t/heartbeat-yml-file-number-of-replicas-not-being-applied/288691)

<div class="topic-metadata">

**Author:** [@Daniel.X](https://discuss.elastic.co/u/Daniel.X)\
**Replies:** 2\
**Last updated:** [November 10, 2021, 6:14am UTC](https://discuss.elastic.co/t/heartbeat-yml-file-number-of-replicas-not-being-applied/288691 "2021-11-10T06:14:38Z")

</div>

Heartbeat Version: 7.14.0 Hi there, I configured our heartbeat that runs as sidecar container on AWS ECS using the heartbeat.yml file configuration. I set the number\_of\_replicas to be 0 (see code snippet below). Howeve…

---

## [SQS client ignores the fips flag for the service endpoint](https://discuss.elastic.co/t/sqs-client-ignores-the-fips-flag-for-the-service-endpoint/288687)

<div class="topic-metadata">

**Author:** [@Andrew\_Chang](https://discuss.elastic.co/u/Andrew_Chang)\
**Replies:** 3\
**Last updated:** [November 9, 2021, 10:41pm UTC](https://discuss.elastic.co/t/sqs-client-ignores-the-fips-flag-for-the-service-endpoint/288687 "2021-11-09T22:41:54Z")

</div>

At least in 7.15.1 when using the fips\_enabled flag, only s3 respects the fips configuration. SQS does not. It seems to be hard coded. beats/input.go at master · elastic/beats · GitHub

---

## [Beat for Status Interface Network](https://discuss.elastic.co/t/beat-for-status-interface-network/288826)

<div class="topic-metadata">

**Author:** [@Ing\_Carlos\_Salas](https://discuss.elastic.co/u/Ing_Carlos_Salas)\
**Replies:** 2\
**Last updated:** [November 9, 2021, 10:08pm UTC](https://discuss.elastic.co/t/beat-for-status-interface-network/288826 "2021-11-09T22:08:06Z")

</div>

Hi community I search a beat for view the status of interfaces network for example status up or down, bandwidth, errors THROUGHPUT I need monitoring state of the network interface to run the command, ifconfig IP ADDR …

---

## [Event Filter endpoint agent via Kibana (Fleet) with wildcards](https://discuss.elastic.co/t/event-filter-endpoint-agent-via-kibana-fleet-with-wildcards/288680)

<div class="topic-metadata">

**Author:** [@tfriesen](https://discuss.elastic.co/u/tfriesen)\
**Replies:** 2\
**Last updated:** [November 9, 2021, 5:08pm UTC](https://discuss.elastic.co/t/event-filter-endpoint-agent-via-kibana-fleet-with-wildcards/288680 "2021-11-09T17:08:19Z")

</div>

Situation: I'm deploying endpoint security via Fleet and Elastic agent. Many of the default settings cause the agents to be extremely chatty, shipping many uninteresting, chatty logs. I want to filter out some of these e…

---

## [Unable to parse Timestamp on CEF LOGS](https://discuss.elastic.co/t/unable-to-parse-timestamp-on-cef-logs/288781)

<div class="topic-metadata">

**Author:** [@Mmatos](https://discuss.elastic.co/u/Mmatos)\
**Replies:** 1\
**Last updated:** [November 9, 2021, 3:46pm UTC](https://discuss.elastic.co/t/unable-to-parse-timestamp-on-cef-logs/288781 "2021-11-09T15:46:59Z")

</div>

Hi, I am having problems parsing a set of logs from sophos central Intercept X Antivirus. I am using the sophos tool to download the logs and store them in a File. "Service and Support" Of the multiple formats, the CEF…

---

## [Where to find Fleet Integration new additions and changelogs](https://discuss.elastic.co/t/where-to-find-fleet-integration-new-additions-and-changelogs/286636)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 3\
**Last updated:** [November 9, 2021, 9:52am UTC](https://discuss.elastic.co/t/where-to-find-fleet-integration-new-additions-and-changelogs/286636 "2021-11-09T09:52:51Z")

</div>

Is there a way to identify which new Fleet Integrations are added and also a changelog when they are upgraded? Is there a central location for this information? I can only tell right now (maybe incorrectly) via the Inte…

---

## [Specific retention duration for logs (Index Lifecycle Policy)](https://discuss.elastic.co/t/specific-retention-duration-for-logs-index-lifecycle-policy/288635)

<div class="topic-metadata">

**Author:** [@Sco](https://discuss.elastic.co/u/Sco)\
**Replies:** 1\
**Last updated:** [November 9, 2021, 9:48am UTC](https://discuss.elastic.co/t/specific-retention-duration-for-logs-index-lifecycle-policy/288635 "2021-11-09T09:48:27Z")

</div>

Hi guys, I would need some help with Index Lifecycle Policies, and it's setup. I need to set up winlogbeat to store data for X days and delete it afterward. Simple as that. Tried different configurations in ILM but I …

---

## [Filebest not reading log files whos names as numeric only](https://discuss.elastic.co/t/filebest-not-reading-log-files-whos-names-as-numeric-only/288672)

<div class="topic-metadata">

**Author:** [@Azfar](https://discuss.elastic.co/u/Azfar)\
**Replies:** 2\
**Last updated:** [November 9, 2021, 9:46am UTC](https://discuss.elastic.co/t/filebest-not-reading-log-files-whos-names-as-numeric-only/288672 "2021-11-09T09:46:15Z")

</div>

I have log files whose names are in numbers only like "34567854322", these are an application logs and I don't have control to append any extension. Blockquote ls -l total 12 -rw-rw-r-- 1 barakat barakat 1254 Nov 2…

---

## [Functionbeat throwing the error add\_cloud\_metadata: hosting provider type not detected](https://discuss.elastic.co/t/functionbeat-throwing-the-error-add-cloud-metadata-hosting-provider-type-not-detected/288675)

<div class="topic-metadata">

**Author:** [@Jijo\_Johny](https://discuss.elastic.co/u/Jijo_Johny)\
**Replies:** 1\
**Last updated:** [November 9, 2021, 9:38am UTC](https://discuss.elastic.co/t/functionbeat-throwing-the-error-add-cloud-metadata-hosting-provider-type-not-detected/288675 "2021-11-09T09:38:21Z")

</div>

I am trying to connect to the Elasticsearch and Kibana 7.10.2, launched from AWS under open source licence. I am trying to stream the logs from AWS CLoudwatch log group to Kibana, I have finished the set up of functionbe…

---

## [Log on workstation hostname](https://discuss.elastic.co/t/log-on-workstation-hostname/288652)

<div class="topic-metadata">

**Author:** [@insurin](https://discuss.elastic.co/u/insurin)\
**Replies:** 2\
**Last updated:** [November 9, 2021, 7:46am UTC](https://discuss.elastic.co/t/log-on-workstation-hostname/288652 "2021-11-09T07:46:23Z")

</div>

I am using ELK 7.12.1 mainly to log AD events at the minute. I have had a device go missing and I want to track down the last time it was logged on. I have been using user.name.text to locate user logons but I don't thin…

---

## [Filebeat running but now showing iis logs in elasticsearch](https://discuss.elastic.co/t/filebeat-running-but-now-showing-iis-logs-in-elasticsearch/288701)

<div class="topic-metadata">

**Author:** [@mehmood1](https://discuss.elastic.co/u/mehmood1)\
**Replies:** 5\
**Last updated:** [November 9, 2021, 4:02am UTC](https://discuss.elastic.co/t/filebeat-running-but-now-showing-iis-logs-in-elasticsearch/288701 "2021-11-09T04:02:49Z")

</div>

filebeat and elasticsearch running but now showing iis logs in in browser url http://172.xx.x.xxx:9200/filebeat-\*/\_count?pretty below is my config files { "count" : 0, "\_shards" : { "total" : 0, "successful" : 0, …

---

## [How to run heartbeat in detached (non-interactive) mode](https://discuss.elastic.co/t/how-to-run-heartbeat-in-detached-non-interactive-mode/287601)

<div class="topic-metadata">

**Author:** [@SUMANT\_MISHRA](https://discuss.elastic.co/u/SUMANT_MISHRA)\
**Replies:** 3\
**Last updated:** [November 8, 2021, 2:47pm UTC](https://discuss.elastic.co/t/how-to-run-heartbeat-in-detached-non-interactive-mode/287601 "2021-11-08T14:47:19Z")

</div>

Hi, I have installed heartbeat in a virtual machine in Azure Portal. I am trying to start the heartbeat from my system terminal using SSH. But if I close my terminal it stops the heartbeat that's running in my remote vi…

---

## [How do I use fileBeat filter to filter network logs that receive Rsyslog](https://discuss.elastic.co/t/how-do-i-use-filebeat-filter-to-filter-network-logs-that-receive-rsyslog/288582)

<div class="topic-metadata">

**Author:** [@shuijinglan](https://discuss.elastic.co/u/shuijinglan)\
**Replies:** 0\
**Last updated:** [November 8, 2021, 4:05am UTC](https://discuss.elastic.co/t/how-do-i-use-filebeat-filter-to-filter-network-logs-that-receive-rsyslog/288582 "2021-11-08T04:05:01Z")

</div>

My network device logs point to Rsyslog, fileBeat to Rsyslog pull logs output to Elasticsearch, in Kibana display, I now want to use fileBeat filter to filter log files output to Elasticsearch.I haven't filtered it be…

---

## [Need to filter metrics from clusters which its being sent from](https://discuss.elastic.co/t/need-to-filter-metrics-from-clusters-which-its-being-sent-from/287260)

<div class="topic-metadata">

**Author:** [@sidharth\_vijayakumar](https://discuss.elastic.co/u/sidharth_vijayakumar)\
**Replies:** 3\
**Last updated:** [November 8, 2021, 1:36am UTC](https://discuss.elastic.co/t/need-to-filter-metrics-from-clusters-which-its-being-sent-from/287260 "2021-11-08T01:36:20Z")

</div>

Hi, Current situation is all logs from different cluster are mixed in the same index. We are using metric beats which is running as daemon sets in a cluster. We need same dashboards where we could list out the clusters…

---

## [Talk to server... ERROR 401 Unauthorized: Unauthorized](https://discuss.elastic.co/t/talk-to-server-error-401-unauthorized-unauthorized/288469)

<div class="topic-metadata">

**Author:** [@nasirnjs](https://discuss.elastic.co/u/nasirnjs)\
**Replies:** 1\
**Last updated:** [November 8, 2021, 12:03am UTC](https://discuss.elastic.co/t/talk-to-server-error-401-unauthorized-unauthorized/288469 "2021-11-08T00:03:07Z")

</div>

Hi Experts assist me please .... after install Wazuh I have added agent, when I click agent there is no log showing. Elasticsearch: https://127.0.0.1:9200... parse url... OK connection... parse host... OK dns lookup…

---

## [Filebeat failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-temporary-bulk-send-failure/288566)

<div class="topic-metadata">

**Author:** [@cdalexndr](https://discuss.elastic.co/u/cdalexndr)\
**Replies:** 1\
**Last updated:** [November 7, 2021, 4:34pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-temporary-bulk-send-failure/288566 "2021-11-07T16:34:56Z")

</div>

Filebeat 7.14.1 is stuck in a log loop with failed to publish events: temporary bulk send failure. Turning debug log, it shows: filebeat | 2021-11-07T15:57:49.938Z INFO \[publisher\_pipeline\_output\] pipeline/o…

---

## [Filebeat vs Kinesis agent](https://discuss.elastic.co/t/filebeat-vs-kinesis-agent/288550)

<div class="topic-metadata">

**Author:** [@Nehray](https://discuss.elastic.co/u/Nehray)\
**Replies:** 2\
**Last updated:** [November 6, 2021, 10:35pm UTC](https://discuss.elastic.co/t/filebeat-vs-kinesis-agent/288550 "2021-11-06T22:35:38Z")

</div>

Hi all, I am very new to Elasticsearch. I am looking ways to ingest logs into ES. I am looking for answers why should I choose between filebeat vs Kinesis agent.

---

## [Timestamp not being overwriten (ECS)](https://discuss.elastic.co/t/timestamp-not-being-overwriten-ecs/288544)

<div class="topic-metadata">

**Author:** [@vcaleffi](https://discuss.elastic.co/u/vcaleffi)\
**Replies:** 2\
**Last updated:** [November 6, 2021, 6:41pm UTC](https://discuss.elastic.co/t/timestamp-not-being-overwriten-ecs/288544 "2021-11-06T18:41:03Z")

</div>

Hello, I'm very new to filebeat and I'm trying to import logs created by my application (PHP - symfony). The application uses monolog and ECS formatter to write to a log file. Monolog configuration: monolog: handl…

---

## [Fleet server setup documentation incorrect when using quickstart + (elastic with TLS)](https://discuss.elastic.co/t/fleet-server-setup-documentation-incorrect-when-using-quickstart-elastic-with-tls/288526)

<div class="topic-metadata">

**Author:** [@tfriesen](https://discuss.elastic.co/u/tfriesen)\
**Replies:** 0\
**Last updated:** [November 5, 2021, 8:38pm UTC](https://discuss.elastic.co/t/fleet-server-setup-documentation-incorrect-when-using-quickstart-elastic-with-tls/288526 "2021-11-05T20:38:48Z")

</div>

The documentation for setting up a fleet server, both the online guide and via the 'Add a fleet server', don't account for a situation where Elasticsearch is configured with TLS, but you want to use Quickstart for settin…

---

## [Some cgroup metrics are missing from output](https://discuss.elastic.co/t/some-cgroup-metrics-are-missing-from-output/288524)

<div class="topic-metadata">

**Author:** [@vPilot](https://discuss.elastic.co/u/vPilot)\
**Replies:** 0\
**Last updated:** [November 5, 2021, 7:44pm UTC](https://discuss.elastic.co/t/some-cgroup-metrics-are-missing-from-output/288524 "2021-11-05T19:44:30Z")

</div>

I've got several systems that I have recently started collecting data on via Metricbeat, and am running into an issue on several of them. Particularly, I have a couple of systems that are not reporting back system.proces…

---

## [Missing Beats data in Kibana Stack monitoring interface](https://discuss.elastic.co/t/missing-beats-data-in-kibana-stack-monitoring-interface/288514)

<div class="topic-metadata">

**Author:** [@Fangy](https://discuss.elastic.co/u/Fangy)\
**Replies:** 1\
**Last updated:** [November 5, 2021, 6:31pm UTC](https://discuss.elastic.co/t/missing-beats-data-in-kibana-stack-monitoring-interface/288514 "2021-11-05T18:31:32Z")

</div>

Hello. I'm trying to monitor beat agents on a brand new cluster. Metricbeat is configured to send data to a separate one-node monitoring cluster. Elastic nodes and Kibana monitoring data are displayed correctly, but th…

---

## [Add tag to filebeat modules](https://discuss.elastic.co/t/add-tag-to-filebeat-modules/288314)

<div class="topic-metadata">

**Author:** [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Replies:** 5\
**Last updated:** [November 5, 2021, 4:53pm UTC](https://discuss.elastic.co/t/add-tag-to-filebeat-modules/288314 "2021-11-05T16:53:46Z")

</div>

hello! I am trying to send the logs with the filebeat mysql module to my logstash and it already obtains the pipeline and does the parsing correctly. How can I differentiate both inputs ( Slowlog and errror ) to apply…

---

## [Elastic Agent Crashes Status Code: 0](https://discuss.elastic.co/t/elastic-agent-crashes-status-code-0/287264)

<div class="topic-metadata">

**Author:** [@Ramguru\_Nageswaran](https://discuss.elastic.co/u/Ramguru_Nageswaran)\
**Replies:** 1\
**Last updated:** [November 5, 2021, 4:42pm UTC](https://discuss.elastic.co/t/elastic-agent-crashes-status-code-0/287264 "2021-11-05T16:42:09Z")

</div>

09:32:28.601 elastic\_agent \[elastic\_agent\]\[error\] Could not communicate with fleet-server Checking API will retry, error: status code: 0, fleet-server returned an error: , message: Unknown resource. 09:41:24.952 elastic\_…

---

## [\[Filebeat\] Override Module Ingest Pipeline at Runtime](https://discuss.elastic.co/t/filebeat-override-module-ingest-pipeline-at-runtime/288432)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 6\
**Last updated:** [November 5, 2021, 2:50pm UTC](https://discuss.elastic.co/t/filebeat-override-module-ingest-pipeline-at-runtime/288432 "2021-11-05T14:50:43Z")

</div>

TL;DR Can I override the ingest pipeline for a filebeat module at runtime from modules.d/module.yml? The Rest of the Story I use the apache module with filebeat to capture logs on the Apache servers in our environment. …

---

## [Filebeat modules and inputs](https://discuss.elastic.co/t/filebeat-modules-and-inputs/288412)

<div class="topic-metadata">

**Author:** [@MalfuncEddie](https://discuss.elastic.co/u/MalfuncEddie)\
**Replies:** 1\
**Last updated:** [November 5, 2021, 12:27pm UTC](https://discuss.elastic.co/t/filebeat-modules-and-inputs/288412 "2021-11-05T12:27:16Z")

</div>

Hi, I'm a bit confused how modules work or if what I am trying to do is even possible. I got logs from a mssql instance that logs to an eventhub in azure. If I configure the filebeat agent to read the event hub it is s…

---

## [Metricbeat 7.15.1 Will Not Start](https://discuss.elastic.co/t/metricbeat-7-15-1-will-not-start/288429)

<div class="topic-metadata">

**Author:** [@ty9001](https://discuss.elastic.co/u/ty9001)\
**Replies:** 8\
**Last updated:** [November 5, 2021, 12:21pm UTC](https://discuss.elastic.co/t/metricbeat-7-15-1-will-not-start/288429 "2021-11-05T12:21:20Z")

</div>

Hello! I have noticed in the past few weeks my Metricbeat 7.15.1 monitoring doesn't seem to work. I finally figured out the service won't stay started properly. I was using Fedora 34 and have currently rolled out a new s…

---

## [Fleet + AWS Metrics IAM Visual Editor explanation](https://discuss.elastic.co/t/fleet-aws-metrics-iam-visual-editor-explanation/288491)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 0\
**Last updated:** [November 5, 2021, 11:53am UTC](https://discuss.elastic.co/t/fleet-aws-metrics-iam-visual-editor-explanation/288491 "2021-11-05T11:53:38Z")

</div>

Can some give an explanation of usage of the visual editors and of we need this setup for the new Fleet-Managed AWS Integration as this is taken from the old Metricbeat AWS Module. Is the resource for VisualEditor1 & Vi…

---

## [Unable to enroll fleet server as assinged policy does not have fleet server input](https://discuss.elastic.co/t/unable-to-enroll-fleet-server-as-assinged-policy-does-not-have-fleet-server-input/277846)

<div class="topic-metadata">

**Author:** [@cheapsupps](https://discuss.elastic.co/u/cheapsupps)\
**Replies:** 26\
**Last updated:** [November 5, 2021, 7:26am UTC](https://discuss.elastic.co/t/unable-to-enroll-fleet-server-as-assinged-policy-does-not-have-fleet-server-input/277846 "2021-11-05T07:26:27Z")

</div>

Hi, I am setting up fleet-server in air-gap environment. However, I am unable to enroll the fleet-server to elasticsearch. I am having the below error. 2021-07-05T22:37:11.552+0800 INFO cmd/enroll\_cmd.go:300 Ge…

---

## [Filebeat isn't keeping up with our logs](https://discuss.elastic.co/t/filebeat-isnt-keeping-up-with-our-logs/288398)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 0\
**Last updated:** [November 4, 2021, 11:03am UTC](https://discuss.elastic.co/t/filebeat-isnt-keeping-up-with-our-logs/288398 "2021-11-04T11:03:33Z")

</div>

Filebeat 6.8.20 running on CentOS 7.9 We're using Filebeat to send some logs to our Elasticsearch cluster (by way of Logstash and a Kafka layer which provides retention in case of cluster downtime) and as the data volum…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=122)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=124)
