# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=125

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 126

---

## [Fortigate integration with ELK](https://discuss.elastic.co/t/fortigate-integration-with-elk/287323)

<div class="topic-metadata">

**Author:** [@Hamzah](https://discuss.elastic.co/u/Hamzah)\
**Replies:** 3\
**Last updated:** [October 26, 2021, 9:27am UTC](https://discuss.elastic.co/t/fortigate-integration-with-elk/287323 "2021-10-26T09:27:34Z")

</div>

Hi, I am trying to integrate fortigate with Elasticstack. What should be the optimal solution for this integration? 1- Should I use logstash, send fortigate logs to logstash and parse them. 2- Should I use filebeat se…

---

## [Unable to ship docker container logs using Filebeat](https://discuss.elastic.co/t/unable-to-ship-docker-container-logs-using-filebeat/287460)

<div class="topic-metadata">

**Author:** [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)\
**Replies:** 1\
**Last updated:** [October 26, 2021, 12:24am UTC](https://discuss.elastic.co/t/unable-to-ship-docker-container-logs-using-filebeat/287460 "2021-10-26T00:24:01Z")

</div>

I'm using Filebeat native version 7.10.0 to collect all the docker container logs located at /var/lib/docker/containers/container-id/.json . But unable to ship the logs. Below is my filebeat configuration file. Anyone p…

---

## [Removing the “$” sign from event\_data.TargetUserName](https://discuss.elastic.co/t/removing-the-sign-from-event-data-targetusername/285742)

<div class="topic-metadata">

**Author:** [@schroray](https://discuss.elastic.co/u/schroray)\
**Replies:** 0\
**Last updated:** [October 2, 2021, 4:18pm UTC](https://discuss.elastic.co/t/removing-the-sign-from-event-data-targetusername/285742 "2021-10-02T16:18:14Z")

</div>

I found an Elastic blog on a possible dashboard for Winlogbeat logs: Monitoring Windows Logons with Winlogbeat | Elastic Blog I was trying to remove the dollar sign "$" from usernames in the field winlog.event\_data.Targ…

---

## [Filebeat setup dont load because kibana version](https://discuss.elastic.co/t/filebeat-setup-dont-load-because-kibana-version/285712)

<div class="topic-metadata">

**Author:** [@Francisca\_Olave](https://discuss.elastic.co/u/Francisca_Olave)\
**Replies:** 0\
**Last updated:** [October 1, 2021, 7:24pm UTC](https://discuss.elastic.co/t/filebeat-setup-dont-load-because-kibana-version/285712 "2021-10-01T19:24:30Z")

</div>

Hi, I have a single node server with a basic license in ELK and I want to monitor a machine with filebeat but the following error appears: # filebeat setup Overwriting ILM policy is disabled. Set \`setup.ilm.overwrite: …

---

## [Possible to Script Values in Synthetics?](https://discuss.elastic.co/t/possible-to-script-values-in-synthetics/287602)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 2\
**Last updated:** [October 25, 2021, 4:02pm UTC](https://discuss.elastic.co/t/possible-to-script-values-in-synthetics/287602 "2021-10-25T16:02:30Z")

</div>

Hi All, I have a use case where I want to use synthetics to monitor a page, however this page has a URL which requires it to be updated daily with the days date. Kind of like: http://url/\<today's\_day(2021-10-25)\>. Since…

---

## [Filebeat - Datastreams?](https://discuss.elastic.co/t/filebeat-datastreams/287442)

<div class="topic-metadata">

**Author:** [@scott\_stash](https://discuss.elastic.co/u/scott_stash)\
**Replies:** 1\
**Last updated:** [October 25, 2021, 2:08pm UTC](https://discuss.elastic.co/t/filebeat-datastreams/287442 "2021-10-25T14:08:17Z")

</div>

Currently we have configured data streams in our environment and its working as expected with Logstash. For Filebeat do we just use the datastream name as the index value? Or do we create an alias to the datastream and…

---

## [Filebeat holding deleted files which consumes disk space in our production cluster very often, any permenant fix for this?](https://discuss.elastic.co/t/filebeat-holding-deleted-files-which-consumes-disk-space-in-our-production-cluster-very-often-any-permenant-fix-for-this/287560)

<div class="topic-metadata">

**Author:** [@swetha25](https://discuss.elastic.co/u/swetha25)\
**Replies:** 0\
**Last updated:** [October 25, 2021, 9:44am UTC](https://discuss.elastic.co/t/filebeat-holding-deleted-files-which-consumes-disk-space-in-our-production-cluster-very-often-any-permenant-fix-for-this/287560 "2021-10-25T09:44:54Z")

</div>

We don't want any data loss in the production cluster. And this issue is happening very often and we end up in almost full disk utilization every time. Kindly please help us with the solution.

---

## [Fleet server in Kubernetes](https://discuss.elastic.co/t/fleet-server-in-kubernetes/286727)

<div class="topic-metadata">

**Author:** [@Dmitriy\_Esin](https://discuss.elastic.co/u/Dmitriy_Esin)\
**Replies:** 3\
**Last updated:** [October 25, 2021, 9:32am UTC](https://discuss.elastic.co/t/fleet-server-in-kubernetes/286727 "2021-10-25T09:32:36Z")

</div>

Hi all! I noticed that Elastic Agent has variables for containerized deployment if I run this command: ./elastic-agent container -h Can I deploy Fleet Server, for example in the Kubernetes cluster? I've tried to use…

---

## [Filebeat and Logstash no send Logs](https://discuss.elastic.co/t/filebeat-and-logstash-no-send-logs/287292)

<div class="topic-metadata">

**Author:** [@roxasval](https://discuss.elastic.co/u/roxasval)\
**Replies:** 6\
**Last updated:** [October 25, 2021, 7:28am UTC](https://discuss.elastic.co/t/filebeat-and-logstash-no-send-logs/287292 "2021-10-25T07:28:22Z")

</div>

Hello to all I'm a newbie on Elasticsearch and I'm having some problems: I have a cluster of 2 Elasticsearch (but I do most things with one) and a separate kibana. I would like to retrieve logs from network devices an…

---

## [Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasticsearch at http://172.31.33.170:9200: Get "http://172.31.33.170:9200": net/http: request canceled while waiting for connection (Client.Timeout excee](https://discuss.elastic.co/t/exiting-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts-errors-error-connecting-to-elasticsearch-at-http-172-31-33-170-get-http-172-31-33-170-9200-net-http-request-canceled-while-waiting-for-connection-client-timeout-excee/287391)

<div class="topic-metadata">

**Author:** [@chandra\_mohan1](https://discuss.elastic.co/u/chandra_mohan1)\
**Replies:** 1\
**Last updated:** [October 25, 2021, 3:53am UTC](https://discuss.elastic.co/t/exiting-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts-errors-error-connecting-to-elasticsearch-at-http-172-31-33-170-get-http-172-31-33-170-9200-net-http-request-canceled-while-waiting-for-connection-client-timeout-excee/287391 "2021-10-25T03:53:30Z")

</div>

I am trying to send apache logs but when setup filebeat getting this error: Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasticsearch at http://172.31.33.170:9200:…

---

## [Dashboard setup fails: Unable to bulk\_create index-pattern](https://discuss.elastic.co/t/dashboard-setup-fails-unable-to-bulk-create-index-pattern/287524)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [October 25, 2021, 3:03am UTC](https://discuss.elastic.co/t/dashboard-setup-fails-unable-to-bulk-create-index-pattern/287524 "2021-10-25T03:03:02Z")

</div>

Hi I have installed winlogbeat on a number of machines, and they are successfully shipping logs to Elasticsearch. However, when attempting to setup the dashboards either by setting the config in the winlogbeat.yml file…

---

## [What needs internet connectivity?](https://discuss.elastic.co/t/what-needs-internet-connectivity/287522)

<div class="topic-metadata">

**Author:** [@bevano](https://discuss.elastic.co/u/bevano)\
**Replies:** 0\
**Last updated:** [October 25, 2021, 2:13am UTC](https://discuss.elastic.co/t/what-needs-internet-connectivity/287522 "2021-10-25T02:13:24Z")

</div>

Hi All, I am trying to install the osquerybeat via Elastic-Agent but am facing some problems with the result being, it never installs. I can see it try and download a ZIP on my machine C:\\Program Files\\Elastic\\Agent\\Da…

---

## [Template already exists](https://discuss.elastic.co/t/template-already-exists/287519)

<div class="topic-metadata">

**Author:** [@dev9](https://discuss.elastic.co/u/dev9)\
**Replies:** 5\
**Last updated:** [October 25, 2021, 1:48am UTC](https://discuss.elastic.co/t/template-already-exists/287519 "2021-10-25T01:48:37Z")

</div>

Hi, how do I get rid of this template being mentioned in the log? Attempting to connect to Elasticsearch version 7.15.1 \*\*2021-10-24T16:24:25.161-0400 INFO template/load.go:111 Template "my\_template" already exists and…

---

## [Filebeat can't keep up with logs volume](https://discuss.elastic.co/t/filebeat-cant-keep-up-with-logs-volume/287459)

<div class="topic-metadata">

**Author:** [@nsouth](https://discuss.elastic.co/u/nsouth)\
**Replies:** 3\
**Last updated:** [October 24, 2021, 5:45pm UTC](https://discuss.elastic.co/t/filebeat-cant-keep-up-with-logs-volume/287459 "2021-10-24T17:45:49Z")

</div>

We are trying to run Filebeat on a production server to ship logs to Logstash. However, it is failing to ship logs as quickly as they are being written. If I inspect the Filebeat's registry, it shows that over the past 3…

---

## [Metricbeat, filebeat service failed to start after logstash, kibana servers was rebooted on v7.14](https://discuss.elastic.co/t/metricbeat-filebeat-service-failed-to-start-after-logstash-kibana-servers-was-rebooted-on-v7-14/287426)

<div class="topic-metadata">

**Author:** [@cool999](https://discuss.elastic.co/u/cool999)\
**Replies:** 8\
**Last updated:** [October 24, 2021, 4:19pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat-service-failed-to-start-after-logstash-kibana-servers-was-rebooted-on-v7-14/287426 "2021-10-24T16:19:13Z")

</div>

Hi Team, There was activity to reboot the servers (beats, logstash servers etc.) for patching. I noticed after this, filebeat and metricbeat services were failed (they are enabled to start on reboot). However only hear…

---

## [Filebeat не читает последнюю строку файла](https://discuss.elastic.co/t/filebeat/287500)

<div class="topic-metadata">

**Author:** [@IVHN](https://discuss.elastic.co/u/IVHN)\
**Replies:** 0\
**Last updated:** [October 23, 2021, 8:03pm UTC](https://discuss.elastic.co/t/filebeat/287500 "2021-10-23T20:03:39Z")

</div>

Добрый день. Столкнулся со следующей проблемой - filebeat не читает последнюю строку файла. Вот, например, есть файлик (input.log) со следующим содержимым {7,1560,2}, {7,1562,3}, {7,1564,4}, {7,1565,5}, {7,1571,6} Fi…

---

## [Elastic agent not sending data stream](https://discuss.elastic.co/t/elastic-agent-not-sending-data-stream/286893)

<div class="topic-metadata">

**Author:** [@AdE\_GoD](https://discuss.elastic.co/u/AdE_GoD)\
**Replies:** 2\
**Last updated:** [October 23, 2021, 2:58pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-stream/286893 "2021-10-23T14:58:31Z")

</div>

Hi everyone, I've been wanting to try elastic-agent for quite some time now so I booted up a machine and tried to configure everything, but I've encountered an error that for the love of me I simply cannot fix. I have …

---

## [Packetbeat parsing MongoDB 5.0](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-5-0/287490)

<div class="topic-metadata">

**Author:** [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Replies:** 0\
**Last updated:** [October 23, 2021, 1:47pm UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-5-0/287490 "2021-10-23T13:47:55Z")

</div>

In version 5.0, MongoDB deprecates the following opcodes: OP\_REPLY OP\_UPDATE OP\_INSERT OP\_QUERY \[1\] OP\_GET\_MORE OP\_DELETE OP\_KILL\_CURSORS Instead of these opcodes, use OP\_MSG. Now op\_ MSG information cannot be pars…

---

## [New pfSense integration added to Github, is there's any planned support for Elastic Agent FreeBSD OS?](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970)

<div class="topic-metadata">

**Author:** [@eldadpuzach](https://discuss.elastic.co/u/eldadpuzach)\
**Replies:** 6\
**Last updated:** [October 23, 2021, 2:08pm UTC](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970 "2021-10-23T14:08:09Z")

</div>

Hello Elastic team:) is it possible to utilize the new pfSense integration to ship logs from PfSense to Elastic Cloud? AFAIK there's no Elastic Agent available for FreeBSD OS.. tnx🙏

---

## [Permission error for custom log integration on Fleet-managed Agent](https://discuss.elastic.co/t/permission-error-for-custom-log-integration-on-fleet-managed-agent/287486)

<div class="topic-metadata">

**Author:** [@Panagiota\_Mitsopoulo](https://discuss.elastic.co/u/Panagiota_Mitsopoulo)\
**Replies:** 0\
**Last updated:** [October 23, 2021, 9:36am UTC](https://discuss.elastic.co/t/permission-error-for-custom-log-integration-on-fleet-managed-agent/287486 "2021-10-23T09:36:22Z")

</div>

Hello! I have a Nodejs app that ingests logs into Elasticsearch Service deployment 7.15.1 using Filebeat. More of less this is the example I've been doing adapted to my needs Ingest logs from a Node.js web application u…

---

## [Multiline logs are not working using filebeat](https://discuss.elastic.co/t/multiline-logs-are-not-working-using-filebeat/287466)

<div class="topic-metadata">

**Author:** [@kemisetti\_pavan\_kuma](https://discuss.elastic.co/u/kemisetti_pavan_kuma)\
**Replies:** 0\
**Last updated:** [October 22, 2021, 8:33pm UTC](https://discuss.elastic.co/t/multiline-logs-are-not-working-using-filebeat/287466 "2021-10-22T20:33:38Z")

</div>

Hi, I have been trying to parse multiline logs by using the sample provided in the filebeat documentation. Not sure of the reason why the logs are not being parse as a single event. Below is my filebeat.yaml file confi…

---

## [How do I export the Composable Templates from beats?](https://discuss.elastic.co/t/how-do-i-export-the-composable-templates-from-beats/287453)

<div class="topic-metadata">

**Author:** [@Micah\_Hunsberger](https://discuss.elastic.co/u/Micah_Hunsberger)\
**Replies:** 0\
**Last updated:** [October 22, 2021, 6:09pm UTC](https://discuss.elastic.co/t/how-do-i-export-the-composable-templates-from-beats/287453 "2021-10-22T18:09:43Z")

</div>

How can I manually add the beats composable index templates? The instructions here: Load the Elasticsearch index template | Winlogbeat Reference \[7.15\] | Elastic only export the legacy template. I prefer to review the …

---

## [Unable to install elastic-logging-plugin (docker plugin) \>= 7.13.0 (beatSocket.sock: connect: no such file or directory)](https://discuss.elastic.co/t/unable-to-install-elastic-logging-plugin-docker-plugin-7-13-0-beatsocket-sock-connect-no-such-file-or-directory/287027)

<div class="topic-metadata">

**Author:** [@goldsky](https://discuss.elastic.co/u/goldsky)\
**Replies:** 1\
**Last updated:** [October 22, 2021, 2:56pm UTC](https://discuss.elastic.co/t/unable-to-install-elastic-logging-plugin-docker-plugin-7-13-0-beatsocket-sock-connect-no-such-file-or-directory/287027 "2021-10-22T14:56:50Z")

</div>

Hello, recently I decided to upgrade my stack to 7.15, during upgrade I discover that I can't install latest elastic-logging-plugin (docker plugin), future investigation shows that only following versions works in my ca…

---

## [Elastic Cloud and Filebeat setup](https://discuss.elastic.co/t/elastic-cloud-and-filebeat-setup/285927)

<div class="topic-metadata">

**Author:** [@Sakshee](https://discuss.elastic.co/u/Sakshee)\
**Replies:** 7\
**Last updated:** [October 22, 2021, 2:51pm UTC](https://discuss.elastic.co/t/elastic-cloud-and-filebeat-setup/285927 "2021-10-22T14:51:44Z")

</div>

Hello All, I am trying to send cloud Watch logs from a filebeat server to Elastic Cloud. I am getting following warnings. And not able to see any logs on Elastic cloud Kibana. Logs from Filebeat: 2021-10-05T12:56:…

---

## [Creating a filebeat module](https://discuss.elastic.co/t/creating-a-filebeat-module/287413)

<div class="topic-metadata">

**Author:** [@elasticfran](https://discuss.elastic.co/u/elasticfran)\
**Replies:** 6\
**Last updated:** [October 22, 2021, 2:14pm UTC](https://discuss.elastic.co/t/creating-a-filebeat-module/287413 "2021-10-22T14:14:25Z")

</div>

Hey there! I am trying to write a custom filebeat module, which are the proper guidelines to follow ? Found Creating a New Beat | Beats Developer Guide \[7.12\] | Elastic which i find pretty comprehensive but i wonder wh…

---

## [IIS FTP Logs](https://discuss.elastic.co/t/iis-ftp-logs/287395)

<div class="topic-metadata">

**Author:** [@Bingdom](https://discuss.elastic.co/u/Bingdom)\
**Replies:** 1\
**Last updated:** [October 22, 2021, 12:16pm UTC](https://discuss.elastic.co/t/iis-ftp-logs/287395 "2021-10-22T12:16:00Z")

</div>

Hello, In our setup, I have managed to retrieve the webserver IIS logs - which works great However, it appears for the IIS module, it's only compatible with the IIS webserver. We host our FTP servers via IIS. I'm wond…

---

## [How to push log from Filebeat to Logstash/Elasticsearch affer setting secure TSL?](https://discuss.elastic.co/t/how-to-push-log-from-filebeat-to-logstash-elasticsearch-affer-setting-secure-tsl/287386)

<div class="topic-metadata">

**Author:** [@nhattanmai](https://discuss.elastic.co/u/nhattanmai)\
**Replies:** 0\
**Last updated:** [October 22, 2021, 4:34am UTC](https://discuss.elastic.co/t/how-to-push-log-from-filebeat-to-logstash-elasticsearch-affer-setting-secure-tsl/287386 "2021-10-22T04:34:28Z")

</div>

Dear all, I configured Encrypt traffic between Kibana and Elasticsearch successfully and now I can start Kibana (not yet https) and connected Elasticsearch Here is Elasticsearch's setting: network.host: 0.0.0.0 disco…

---

## [winlog.event\_data.Image.keyword not populated](https://discuss.elastic.co/t/winlog-event-data-image-keyword-not-populated/287342)

<div class="topic-metadata">

**Author:** [@mcreedjr](https://discuss.elastic.co/u/mcreedjr)\
**Replies:** 2\
**Last updated:** [October 21, 2021, 6:53pm UTC](https://discuss.elastic.co/t/winlog-event-data-image-keyword-not-populated/287342 "2021-10-21T18:53:12Z")

</div>

I am shipping logs from a Windows 10 machine with Process auditing enabled in the Windows using 7.15 version of winlogbeats to logstash, and then in turn Elasticsearch. As an example, I am trying to use a detection rule…

---

## [Add custom tag to zeek filebeat module](https://discuss.elastic.co/t/add-custom-tag-to-zeek-filebeat-module/287349)

<div class="topic-metadata">

**Author:** [@kcrawford19](https://discuss.elastic.co/u/kcrawford19)\
**Replies:** 0\
**Last updated:** [October 21, 2021, 6:33pm UTC](https://discuss.elastic.co/t/add-custom-tag-to-zeek-filebeat-module/287349 "2021-10-21T18:33:27Z")

</div>

Hello, I am configuring an ELK stack and would like to use filebeat to read in zeek logs. Below is a snippet of my filebeat module configuration: # cat /etc/filebeat/modules.d/zeek.yml - module: zeek capture\_loss: …

---

## [Azure configuration for metricbeat](https://discuss.elastic.co/t/azure-configuration-for-metricbeat/287275)

<div class="topic-metadata">

**Author:** [@Nishant\_Saxena](https://discuss.elastic.co/u/Nishant_Saxena)\
**Replies:** 0\
**Last updated:** [October 21, 2021, 8:37am UTC](https://discuss.elastic.co/t/azure-configuration-for-metricbeat/287275 "2021-10-21T08:37:02Z")

</div>

I followed the instructions given on Azure Metricbeat But nowhere it is given that which Roles needs to be assigned in Azure to get the data. I'm facing this issue Not sure which permission needs to be given in azu…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=124)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=126)
