# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=124

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 125

---

## [Elastic Agents 7.15 - Not sending data](https://discuss.elastic.co/t/elastic-agents-7-15-not-sending-data/288342)

<div class="topic-metadata">

**Author:** [@Trinity\_Rolling](https://discuss.elastic.co/u/Trinity_Rolling)\
**Replies:** 0\
**Last updated:** [November 3, 2021, 3:29pm UTC](https://discuss.elastic.co/t/elastic-agents-7-15-not-sending-data/288342 "2021-11-03T15:29:28Z")

</div>

Initial installation and setup of the server and agents was successful. I was troubleshooting some issues with the APM Agents not sending data to the server and broke all Fleet and agents. I attempt to undo what I had …

---

## [No data has been received from Functionbeat yet](https://discuss.elastic.co/t/no-data-has-been-received-from-functionbeat-yet/288378)

<div class="topic-metadata">

**Author:** [@spo](https://discuss.elastic.co/u/spo)\
**Replies:** 0\
**Last updated:** [November 3, 2021, 11:52pm UTC](https://discuss.elastic.co/t/no-data-has-been-received-from-functionbeat-yet/288378 "2021-11-03T23:52:56Z")

</div>

Hi, I have installed and configured functionbeat on the elk server. Installation and configuration was successful but unable to pull logs on kibana. functionbeat.yml : functionbeat.provider.aws.endpoint: "s3.amazona…

---

## [Filbeat enable field message visualization](https://discuss.elastic.co/t/filbeat-enable-field-message-visualization/288367)

<div class="topic-metadata">

**Author:** [@Sergio\_Ferreyra](https://discuss.elastic.co/u/Sergio_Ferreyra)\
**Replies:** 0\
**Last updated:** [November 3, 2021, 8:43pm UTC](https://discuss.elastic.co/t/filbeat-enable-field-message-visualization/288367 "2021-11-03T20:43:13Z")

</div>

Hi Team. having an issue with message field in kibana , I need to create a visualization to use in this dashboard, but looks like is not enabled. Example: I saw there is a processor called dissect (Dissect strings | F…

---

## [Metricbeat shard size](https://discuss.elastic.co/t/metricbeat-shard-size/288339)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 0\
**Last updated:** [November 3, 2021, 3:04pm UTC](https://discuss.elastic.co/t/metricbeat-shard-size/288339 "2021-11-03T15:04:04Z")

</div>

I have a quick question about the best roll over shard size for metricbeat data. I understand that it's best to test with your own system but I figure that metricbeat data is so standardized that it would make sense for …

---

## [How to collecting specfic logs with filebeat](https://discuss.elastic.co/t/how-to-collecting-specfic-logs-with-filebeat/288280)

<div class="topic-metadata">

**Author:** [@dhody\_rhmd](https://discuss.elastic.co/u/dhody_rhmd)\
**Replies:** 0\
**Last updated:** [November 3, 2021, 4:42am UTC](https://discuss.elastic.co/t/how-to-collecting-specfic-logs-with-filebeat/288280 "2021-11-03T04:42:30Z")

</div>

I have Filebeat to collecting logs from my kubernetes cluster. In Filebeat configuration I using autodiscover with type kubernetes which collecting logs from stdout container. This is my filebeat.yml: filebeat.autodisc…

---

## [Filebeat Autodiscover template condition is not working](https://discuss.elastic.co/t/filebeat-autodiscover-template-condition-is-not-working/288289)

<div class="topic-metadata">

**Author:** [@vijayebpzr](https://discuss.elastic.co/u/vijayebpzr)\
**Replies:** 0\
**Last updated:** [November 3, 2021, 7:21am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-template-condition-is-not-working/288289 "2021-11-03T07:21:00Z")

</div>

I am trying to get logs from specific container in a kubernetes cluster using filebeat auto discover feature. But the condition is not working. IS there a way to apply the filter condition? filebeat.autodiscover: …

---

## [Filebeat is not sending new events to logstash](https://discuss.elastic.co/t/filebeat-is-not-sending-new-events-to-logstash/288190)

<div class="topic-metadata">

**Author:** [@Mobin](https://discuss.elastic.co/u/Mobin)\
**Replies:** 0\
**Last updated:** [November 2, 2021, 5:56am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-new-events-to-logstash/288190 "2021-11-02T05:56:56Z")

</div>

We have created an elastic stack to monitor logs from the Linux clients. On Linux clients, filebeat is configured to ship the logs to the elastic stack. But our filebeat is not detecting new events in the log file and n…

---

## [Packetbeat Kubernetes metadata processor configuration](https://discuss.elastic.co/t/packetbeat-kubernetes-metadata-processor-configuration/288250)

<div class="topic-metadata">

**Author:** [@loict](https://discuss.elastic.co/u/loict)\
**Replies:** 0\
**Last updated:** [November 2, 2021, 4:52pm UTC](https://discuss.elastic.co/t/packetbeat-kubernetes-metadata-processor-configuration/288250 "2021-11-02T16:52:59Z")

</div>

Hi, We're trying to use the add\_kubernetes\_metadata processor in Packetbeat (7.15.1) to be able to identify the flows generated by the pods and possibly filter by Pods metadata such as namespace, labels, or annotations…

---

## [HTTP JSON input with Split but keeping other fields](https://discuss.elastic.co/t/http-json-input-with-split-but-keeping-other-fields/288089)

<div class="topic-metadata">

**Author:** [@bitnapper](https://discuss.elastic.co/u/bitnapper)\
**Replies:** 1\
**Last updated:** [November 2, 2021, 5:27am UTC](https://discuss.elastic.co/t/http-json-input-with-split-but-keeping-other-fields/288089 "2021-11-02T05:27:35Z")

</div>

Hi, as a learning project I set up a ELK stack to read the status of my Hue Homeautomation installation. I only need to read the sensordata at the moment but I want to keep the association to the bridge. I use filebeat …

---

## [Packetbeat parsing mongodb OP\_MSG](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535)

<div class="topic-metadata">

**Author:** [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Replies:** 8\
**Last updated:** [November 2, 2021, 2:25am UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535 "2021-11-02T02:25:58Z")

</div>

Mongodb version 3.6 and later added 'OP'\_ MSG 'message type. When packet beat parses this type, the output field mongodb is empty. In addition, the most important thing is that there is no end time and no overall respons…

---

## [Panw module](https://discuss.elastic.co/t/panw-module/288163)

<div class="topic-metadata">

**Author:** [@alvaro.cabrera](https://discuss.elastic.co/u/alvaro.cabrera)\
**Replies:** 1\
**Last updated:** [November 1, 2021, 7:19pm UTC](https://discuss.elastic.co/t/panw-module/288163 "2021-11-01T19:19:59Z")

</div>

We have a file beat 7.14.2 installed to receive logs from 45 palolato firewalls, the panw module is enabled to listen on udp and send all data to elastic directly. after this set up we noticed a significant amount of vol…

---

## [Metricbeat lambda](https://discuss.elastic.co/t/metricbeat-lambda/287267)

<div class="topic-metadata">

**Author:** [@Narkomax](https://discuss.elastic.co/u/Narkomax)\
**Replies:** 1\
**Last updated:** [November 1, 2021, 3:07pm UTC](https://discuss.elastic.co/t/metricbeat-lambda/287267 "2021-11-01T15:07:23Z")

</div>

Who can explain me why? We are using metricbeat to monitor AWS Lambdas. Using simple standard dashboard. Today, we have 1 error in cloudwatch in our lambda, but for some reason metricbeat found 4 errors with the same t…

---

## [Filebeat only reads my local machine log files](https://discuss.elastic.co/t/filebeat-only-reads-my-local-machine-log-files/288119)

<div class="topic-metadata">

**Author:** [@Amrbayoumy89](https://discuss.elastic.co/u/Amrbayoumy89)\
**Replies:** 1\
**Last updated:** [November 1, 2021, 2:14pm UTC](https://discuss.elastic.co/t/filebeat-only-reads-my-local-machine-log-files/288119 "2021-11-01T14:14:51Z")

</div>

Hello Dears, I started to install Elasticsearch, Filebeat and Kibana on my local machine. I have a written text file for Tomcat logs called "tomcatServerlogs.log" and I entered its path in filebeat.yml When I switch to…

---

## [Filebeat Module - Umbrella - Parsing not usable Data](https://discuss.elastic.co/t/filebeat-module-umbrella-parsing-not-usable-data/285632)

<div class="topic-metadata">

**Author:** [@elasticband](https://discuss.elastic.co/u/elasticband)\
**Replies:** 1\
**Last updated:** [November 1, 2021, 12:59pm UTC](https://discuss.elastic.co/t/filebeat-module-umbrella-parsing-not-usable-data/285632 "2021-11-01T12:59:11Z")

</div>

Hey Everyone, I have had pretty decent luck with the Filebeat modules, I currently use multiple Cisco ingestions (ASA, FTD, Meraki), and I have the Umbrella information being recognized and parsed; however I really do n…

---

## [Custom module in filebeat](https://discuss.elastic.co/t/custom-module-in-filebeat/288114)

<div class="topic-metadata">

**Author:** [@Paurav\_Thakkar](https://discuss.elastic.co/u/Paurav_Thakkar)\
**Replies:** 1\
**Last updated:** [November 1, 2021, 10:51am UTC](https://discuss.elastic.co/t/custom-module-in-filebeat/288114 "2021-11-01T10:51:43Z")

</div>

Hi, I am trying to create a custom module that I need for a data source that is not available. This data source exposes an API that can be used to fetch logs. Currently I am using filebeat OSS and the input plugin that I…

---

## [How to send what you want in filebeat](https://discuss.elastic.co/t/how-to-send-what-you-want-in-filebeat/288064)

<div class="topic-metadata">

**Author:** [@root\_linux](https://discuss.elastic.co/u/root_linux)\
**Replies:** 4\
**Last updated:** [November 1, 2021, 4:39am UTC](https://discuss.elastic.co/t/how-to-send-what-you-want-in-filebeat/288064 "2021-11-01T04:39:23Z")

</div>

How can I send only those lines which i want from filebeat to logstash

---

## [Metricbeat error for pulling oracle database metrics with an oracle client](https://discuss.elastic.co/t/metricbeat-error-for-pulling-oracle-database-metrics-with-an-oracle-client/288094)

<div class="topic-metadata">

**Author:** [@nsharath](https://discuss.elastic.co/u/nsharath)\
**Replies:** 0\
**Last updated:** [October 31, 2021, 1:46pm UTC](https://discuss.elastic.co/t/metricbeat-error-for-pulling-oracle-database-metrics-with-an-oracle-client/288094 "2021-10-31T13:46:31Z")

</div>

We are using the following software stack:- Server : RHEL6 (It has oracle client installed. I tried with both full client and thin client) beat : metricbeat-7.9.3-x86\_64 database : Oracle 19 (not installed locally. RH…

---

## [Fleet-server installation error](https://discuss.elastic.co/t/fleet-server-installation-error/288033)

<div class="topic-metadata">

**Author:** [@Duane\_Wylie](https://discuss.elastic.co/u/Duane_Wylie)\
**Replies:** 0\
**Last updated:** [October 29, 2021, 7:37pm UTC](https://discuss.elastic.co/t/fleet-server-installation-error/288033 "2021-10-29T19:37:17Z")

</div>

I'm trying to stand up an on-prem Elasticstack deployment (Ubuntu 20.04 and Elastic 7.15). I have Elasticsearch and Kibana setup and working. I'm in the process of setting up the Fleet-server. I'm getting this message…

---

## [Metricbeat & Mongo 5](https://discuss.elastic.co/t/metricbeat-mongo-5/288037)

<div class="topic-metadata">

**Author:** [@Ziemowit](https://discuss.elastic.co/u/Ziemowit)\
**Replies:** 0\
**Last updated:** [October 29, 2021, 9:18pm UTC](https://discuss.elastic.co/t/metricbeat-mongo-5/288037 "2021-10-29T21:18:08Z")

</div>

Hey I have a pretty simple config of Metric Beat metricbeat.modules: - module: mongodb enabled: true hosts: \[ "mongodb://root:secret@mongo" \] I run it in docker (also mongo itself runs in docker). And it work…

---

## [Fleet server Installation error](https://discuss.elastic.co/t/fleet-server-installation-error/287443)

<div class="topic-metadata">

**Author:** [@Ashwin\_Patil1](https://discuss.elastic.co/u/Ashwin_Patil1)\
**Replies:** 3\
**Last updated:** [October 29, 2021, 7:27pm UTC](https://discuss.elastic.co/t/fleet-server-installation-error/287443 "2021-10-29T19:27:00Z")

</div>

How do I trouble shoot this error? localhost:~/elastic-agent-7.15.0-linux-x86\_64 # sudo ./elastic-agent install --url=https://172.16.12.18:8220 \\ \> -f \\ \> --fleet-server-es=https://172.16.12.11:9200 \\ \> --fleet-serve…

---

## [Filebeat to rsyslog, it's possible?](https://discuss.elastic.co/t/filebeat-to-rsyslog-its-possible/288030)

<div class="topic-metadata">

**Author:** [@pi314](https://discuss.elastic.co/u/pi314)\
**Replies:** 1\
**Last updated:** [October 29, 2021, 7:05pm UTC](https://discuss.elastic.co/t/filebeat-to-rsyslog-its-possible/288030 "2021-10-29T19:05:25Z")

</div>

I need to know if it is possible to send a log from filebeat to rsyslog, if possible, can you tell me how? Regards,

---

## [Not able to generate fields.yml files](https://discuss.elastic.co/t/not-able-to-generate-fields-yml-files/287970)

<div class="topic-metadata">

**Author:** [@Paurav\_Thakkar](https://discuss.elastic.co/u/Paurav_Thakkar)\
**Replies:** 0\
**Last updated:** [October 29, 2021, 5:32am UTC](https://discuss.elastic.co/t/not-able-to-generate-fields-yml-files/287970 "2021-10-29T05:32:16Z")

</div>

Hi, I am trying to create a new custom module and I have created a input file that is taking input from an api in json format and in the pipeline.json file I have added the processors that I think are necessary. But when…

---

## [Ship logs from AWS Cloudwatch log group to Opendistro Elasticsearch 7.10.2](https://discuss.elastic.co/t/ship-logs-from-aws-cloudwatch-log-group-to-opendistro-elasticsearch-7-10-2/287464)

<div class="topic-metadata">

**Author:** [@Jijo\_Johny](https://discuss.elastic.co/u/Jijo_Johny)\
**Replies:** 2\
**Last updated:** [October 27, 2021, 5:30pm UTC](https://discuss.elastic.co/t/ship-logs-from-aws-cloudwatch-log-group-to-opendistro-elasticsearch-7-10-2/287464 "2021-10-27T17:30:45Z")

</div>

Is there a way to ship logs from AWS Cloudwatch log group to Opendistro EFK? I am using opendistro which has the Elasticsearch version 7.10.2, that has been provisioned using helm in an EKS cluster. I tried with function…

---

## [Install and configure winlogbeat in syslog server](https://discuss.elastic.co/t/install-and-configure-winlogbeat-in-syslog-server/287793)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 0\
**Last updated:** [October 27, 2021, 12:21pm UTC](https://discuss.elastic.co/t/install-and-configure-winlogbeat-in-syslog-server/287793 "2021-10-27T12:21:05Z")

</div>

Hello, Is it possible to centralize the logs of the windows servers at the level of a SYSLOG server and to install the winlogbeat agent at the level of the latter to parse and send the logs to Elasticsearch? Thank you. …

---

## [{"SystemTotalCpuProvider"} Failed instantiating PerformanceCounter](https://discuss.elastic.co/t/systemtotalcpuprovider-failed-instantiating-performancecounter/287298)

<div class="topic-metadata">

**Author:** [@joakim.aberg](https://discuss.elastic.co/u/joakim.aberg)\
**Replies:** 0\
**Last updated:** [October 21, 2021, 10:06am UTC](https://discuss.elastic.co/t/systemtotalcpuprovider-failed-instantiating-performancecounter/287298 "2021-10-21T10:06:11Z")

</div>

We get the following error on both our Staging and Production evironment. log.level:Error message:{"SystemTotalCpuProvider"} Failed instantiating PerformanceCounter - please make sure the current user has permissions to …

---

## [Does filebeat support azure service principal](https://discuss.elastic.co/t/does-filebeat-support-azure-service-principal/287771)

<div class="topic-metadata">

**Author:** [@heimo](https://discuss.elastic.co/u/heimo)\
**Replies:** 0\
**Last updated:** [October 27, 2021, 8:07am UTC](https://discuss.elastic.co/t/does-filebeat-support-azure-service-principal/287771 "2021-10-27T08:07:50Z")

</div>

Does filebeat support azure service principal , to replace service account to access Azure AKS(Kubernetes) , to get metadata of the kubernetes?

---

## [Unable to install elastic-logging-plugin (docker plugin) \>= 7.13.0 (beatSocket.sock: connect: no such file or directory)](https://discuss.elastic.co/t/unable-to-install-elastic-logging-plugin-docker-plugin-7-13-0-beatsocket-sock-connect-no-such-file-or-directory/287716)

<div class="topic-metadata">

**Author:** [@Freddyus](https://discuss.elastic.co/u/Freddyus)\
**Replies:** 0\
**Last updated:** [October 26, 2021, 4:19pm UTC](https://discuss.elastic.co/t/unable-to-install-elastic-logging-plugin-docker-plugin-7-13-0-beatsocket-sock-connect-no-such-file-or-directory/287716 "2021-10-26T16:19:52Z")

</div>

Error when installing elastic-logging-plugin version higher than 7.12.1. Can you please tell me what could be the problem? #docker plugin install elastic/elastic-logging-plugin:7.15.1 Plugin "elastic/elastic-logging-pl…

---

## [RabbitMQ Module Errors in logs](https://discuss.elastic.co/t/rabbitmq-module-errors-in-logs/287715)

<div class="topic-metadata">

**Author:** [@valleram](https://discuss.elastic.co/u/valleram)\
**Replies:** 0\
**Last updated:** [October 26, 2021, 4:15pm UTC](https://discuss.elastic.co/t/rabbitmq-module-errors-in-logs/287715 "2021-10-26T16:15:14Z")

</div>

Hi All, I'm using Metricbeat 7.3, I've enabled the RabbitMQ module and I'm getting below error in logs. I'm running version 3.7.15 of RabbitMQ. 2021-10-26T10:29:19.683-0500 ERROR \[rabbitmq.queue\] queue/data.go:97 erro…

---

## [Exiting: Index management requested but the Elasticsearch output is not configured/enabled](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/287700)

<div class="topic-metadata">

**Author:** [@Nil\_Battey\_Sannata](https://discuss.elastic.co/u/Nil_Battey_Sannata)\
**Replies:** 0\
**Last updated:** [October 26, 2021, 1:59pm UTC](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/287700 "2021-10-26T13:59:18Z")

</div>

Hi, I am unable to setup filebeat to send logs to logstash, I followed few solutions of setting up index management using Elasticsearch output then delete old document but the issue is still exist. I have also disabled…

---

## [Deploy metricbeat to Windows nodes in Kubernetes](https://discuss.elastic.co/t/deploy-metricbeat-to-windows-nodes-in-kubernetes/287683)

<div class="topic-metadata">

**Author:** [@mihai.albert](https://discuss.elastic.co/u/mihai.albert)\
**Replies:** 0\
**Last updated:** [October 26, 2021, 10:51am UTC](https://discuss.elastic.co/t/deploy-metricbeat-to-windows-nodes-in-kubernetes/287683 "2021-10-26T10:51:17Z")

</div>

There's already clear documentation on how to manually install the metricbeat agent to various operating systems, including Windows, here. It can also be deployed using the Helm charts shown here, making it very easy to …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=123)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=125)
