# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=126

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 127

---

## [Filebeat AWS module not fetching multi region logs](https://discuss.elastic.co/t/filebeat-aws-module-not-fetching-multi-region-logs/286711)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 2\
**Last updated:** [October 21, 2021, 12:14pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-not-fetching-multi-region-logs/286711 "2021-10-21T12:14:41Z")

</div>

I have configured multiple accounts of AWS with Filebeat AWS module(With help of this thread) to fetch Cloudtrail logs. However, I wonder I am getting only specific region logs. For example, I have configured an S3 noti…

---

## [Filebeat crashed when processing messages from sqs queue](https://discuss.elastic.co/t/filebeat-crashed-when-processing-messages-from-sqs-queue/285145)

<div class="topic-metadata">

**Author:** [@pingz](https://discuss.elastic.co/u/pingz)\
**Replies:** 2\
**Last updated:** [October 21, 2021, 6:43am UTC](https://discuss.elastic.co/t/filebeat-crashed-when-processing-messages-from-sqs-queue/285145 "2021-10-21T06:43:57Z")

</div>

Hi: I am running filebeat 7.15.0 to process S3 object creation event messages from AWS SQS. The queue is configured to receive AWS ELB log files. After a few minutes, filebeat 7.15.0 crashed with the following error. T…

---

## [Filebeat command .\\filebeat.exe setup -e throwing error while parsing kibana response](https://discuss.elastic.co/t/filebeat-command-filebeat-exe-setup-e-throwing-error-while-parsing-kibana-response/287151)

<div class="topic-metadata">

**Author:** [@vijayebpzr](https://discuss.elastic.co/u/vijayebpzr)\
**Replies:** 1\
**Last updated:** [October 20, 2021, 11:06pm UTC](https://discuss.elastic.co/t/filebeat-command-filebeat-exe-setup-e-throwing-error-while-parsing-kibana-response/287151 "2021-10-20T23:06:51Z")

</div>

I am trying to ship some logfiles from my system to a remote ELK cluster. While I try to exec ute the command .\\filebeat.exe setup -e , I am getting the below error. 2 021-10-20T03:34:26.007+0200 ERROR instance/be…

---

## [Filebeat Module's Yaml Config Issue](https://discuss.elastic.co/t/filebeat-modules-yaml-config-issue/287231)

<div class="topic-metadata">

**Author:** [@Cassie\_Danaher](https://discuss.elastic.co/u/Cassie_Danaher)\
**Replies:** 3\
**Last updated:** [October 20, 2021, 9:58pm UTC](https://discuss.elastic.co/t/filebeat-modules-yaml-config-issue/287231 "2021-10-20T21:58:17Z")

</div>

I was under the impression that I could use filebeats keystore, to hold security information and then call those variables in the config file. When I try to do that it throws an error "mapping values are not allowed in …

---

## [Clarification on "Collect Agent Logs" setting for Elastic Agent Policies](https://discuss.elastic.co/t/clarification-on-collect-agent-logs-setting-for-elastic-agent-policies/287021)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 4\
**Last updated:** [October 20, 2021, 3:20pm UTC](https://discuss.elastic.co/t/clarification-on-collect-agent-logs-setting-for-elastic-agent-policies/287021 "2021-10-20T15:20:29Z")

</div>

Hey, I'm wondering how the "Collect Agent Logs" setting works for Elastic Agent. In the past I made the experience that when selecting both "Collect Agent Logs" and "Collect Agent Metrics", it would cause massive amounts…

---

## [Beats cuses high CPU loads when send data](https://discuss.elastic.co/t/beats-cuses-high-cpu-loads-when-send-data/287211)

<div class="topic-metadata">

**Author:** [@Alvaro\_Eixea](https://discuss.elastic.co/u/Alvaro_Eixea)\
**Replies:** 0\
**Last updated:** [October 20, 2021, 2:56pm UTC](https://discuss.elastic.co/t/beats-cuses-high-cpu-loads-when-send-data/287211 "2021-10-20T14:56:00Z")

</div>

HI, I found that when packetbeat send data to Elasticsearch, CPU loads increases and host freeze. Can I control when the beat send data to Elasticsearch? I mean, Can I have the beats send the data at 04:00, by examp…

---

## [Filebeat trouble with separate indexes per namespace](https://discuss.elastic.co/t/filebeat-trouble-with-separate-indexes-per-namespace/287193)

<div class="topic-metadata">

**Author:** [@WookWook](https://discuss.elastic.co/u/WookWook)\
**Replies:** 0\
**Last updated:** [October 20, 2021, 12:14pm UTC](https://discuss.elastic.co/t/filebeat-trouble-with-separate-indexes-per-namespace/287193 "2021-10-20T12:14:24Z")

</div>

Hello, I currently try to split data into multiple indexes to simplify managing user access only for data from specific namespaces. I know this can be a problem to have too many small indexes. So normally I want to grou…

---

## [HeartBeat Dashboard Customization](https://discuss.elastic.co/t/heartbeat-dashboard-customization/285757)

<div class="topic-metadata">

**Author:** [@John\_kasich](https://discuss.elastic.co/u/John_kasich)\
**Replies:** 1\
**Last updated:** [October 20, 2021, 11:42am UTC](https://discuss.elastic.co/t/heartbeat-dashboard-customization/285757 "2021-10-20T11:42:38Z")

</div>

I would love to build such a dashboard. If anyone can help me, please let me know.

---

## [Problem with filebeat upgrade](https://discuss.elastic.co/t/problem-with-filebeat-upgrade/286693)

<div class="topic-metadata">

**Author:** [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Replies:** 2\
**Last updated:** [October 20, 2021, 6:50am UTC](https://discuss.elastic.co/t/problem-with-filebeat-upgrade/286693 "2021-10-20T06:50:41Z")

</div>

I was using filebeat 7.10 and all ok, now was trying upgrading to 7.15 and I found two problem I have tried to download the version of the link curl -L -O https://raw.githubusercontent.com/elastic/beats/7.15/deploy/kub…

---

## [Lag is there from filebeat to Elasticsearch](https://discuss.elastic.co/t/lag-is-there-from-filebeat-to-elasticsearch/287101)

<div class="topic-metadata">

**Author:** [@Ayush\_Agrahari](https://discuss.elastic.co/u/Ayush_Agrahari)\
**Replies:** 2\
**Last updated:** [October 20, 2021, 4:46am UTC](https://discuss.elastic.co/t/lag-is-there-from-filebeat-to-elasticsearch/287101 "2021-10-20T04:46:11Z")

</div>

Hi , I am using Filebeat in Kubernetes env. Data flow is like below Filebeat -\> Logstash -\> Elasticsearch -\> Kibana I am using 7.9.0 version of filebeat I am finding lag in FIlebeat to Kibana. ES & Logstash & Filebea…

---

## [Importing .evtx files to ELK using WinLogBeat](https://discuss.elastic.co/t/importing-evtx-files-to-elk-using-winlogbeat/287141)

<div class="topic-metadata">

**Author:** [@ThePurple5merf](https://discuss.elastic.co/u/ThePurple5merf)\
**Replies:** 1\
**Last updated:** [October 20, 2021, 12:15am UTC](https://discuss.elastic.co/t/importing-evtx-files-to-elk-using-winlogbeat/287141 "2021-10-20T00:15:02Z")

</div>

I'm trying to upload a set of .evtx files to my ELK Stack environment using WinLogBeat. I haven't been able to find any online resources that really help me out in doing this. I was hoping someone here could help point m…

---

## [Packetbeat Missing fields in tls protocol](https://discuss.elastic.co/t/packetbeat-missing-fields-in-tls-protocol/285598)

<div class="topic-metadata">

**Author:** [@franpom](https://discuss.elastic.co/u/franpom)\
**Replies:** 3\
**Last updated:** [October 19, 2021, 6:46pm UTC](https://discuss.elastic.co/t/packetbeat-missing-fields-in-tls-protocol/285598 "2021-10-19T18:46:02Z")

</div>

Hello, everyone, In the fields that packetbeat 7.15.0 captures on the tls protocol, at least the random and ocsp fields are missing Is it possible to add the fields: Handshake Protocol Random Handshake Protocol Exten…

---

## [Filebeat shipping only WARNINGS of haproxy](https://discuss.elastic.co/t/filebeat-shipping-only-warnings-of-haproxy/287098)

<div class="topic-metadata">

**Author:** [@10acc](https://discuss.elastic.co/u/10acc)\
**Replies:** 0\
**Last updated:** [October 19, 2021, 1:55pm UTC](https://discuss.elastic.co/t/filebeat-shipping-only-warnings-of-haproxy/287098 "2021-10-19T13:55:14Z")

</div>

Hello, I am trying to ship my haproxy logs with filebeat to elk cloud This is my /etc/filebeat/modules.d/haproxy.yml - module: haproxy log: enabled: true var.paths: \["/var/log/haproxy.log"\] var.input: "fi…

---

## [Cannot start Metricbeat after adding keystore secret](https://discuss.elastic.co/t/cannot-start-metricbeat-after-adding-keystore-secret/286703)

<div class="topic-metadata">

**Author:** [@rubic](https://discuss.elastic.co/u/rubic)\
**Replies:** 1\
**Last updated:** [October 19, 2021, 1:18pm UTC](https://discuss.elastic.co/t/cannot-start-metricbeat-after-adding-keystore-secret/286703 "2021-10-19T13:18:44Z")

</div>

Hi, I have added a secret from newly created keystore and after this operation mb service is failing to start. I wanted to use only one secret on field, specified in output.kafka: key\_passphrase: "${my\_secret\_pass\_…

---

## [FileBeat multiline.maxLine Limit](https://discuss.elastic.co/t/filebeat-multiline-maxline-limit/287075)

<div class="topic-metadata">

**Author:** [@Anandh\_Kumar](https://discuss.elastic.co/u/Anandh_Kumar)\
**Replies:** 0\
**Last updated:** [October 19, 2021, 10:52am UTC](https://discuss.elastic.co/t/filebeat-multiline-maxline-limit/287075 "2021-10-19T10:52:41Z")

</div>

Hello All, is there a maximum limit for the max\_lines parameter for multiline messages. The lines in the file used in the application may vary and not have a defined maximum limit. In that case is it possible to do a un…

---

## [Filebeat httpjson cursor](https://discuss.elastic.co/t/filebeat-httpjson-cursor/287069)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 0\
**Last updated:** [October 19, 2021, 9:55am UTC](https://discuss.elastic.co/t/filebeat-httpjson-cursor/287069 "2021-10-19T09:55:35Z")

</div>

Hello! How to manually clear state of cursor when using httpjson in filebeat? If I get some data using httpjson-cursor and then delete index in Kibana, containing data from it I can't get this data again. Answers from …

---

## [Metricbeat hidden indexes](https://discuss.elastic.co/t/metricbeat-hidden-indexes/287065)

<div class="topic-metadata">

**Author:** [@bm-ai](https://discuss.elastic.co/u/bm-ai)\
**Replies:** 0\
**Last updated:** [October 19, 2021, 9:14am UTC](https://discuss.elastic.co/t/metricbeat-hidden-indexes/287065 "2021-10-19T09:14:10Z")

</div>

Hi, I've been using ES and Metricbeat for a while now and I've noticed that my ES nodes capacity is getting full pretty fast even though I have ILM enabled on all Metricbeats indexes. I can see many hidden indexes from …

---

## [Saving request.url variable in filebeat httpjson](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 8\
**Last updated:** [October 19, 2021, 9:48am UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700 "2021-10-19T09:48:14Z")

</div>

Good day! The question arose, is it possible to save the last received value of the request.url parameter and then read from it upon request? I use httpjson as an input module with the following settings: # ===========…

---

## [Error after OS upgrade](https://discuss.elastic.co/t/error-after-os-upgrade/286966)

<div class="topic-metadata">

**Author:** [@Zincometal](https://discuss.elastic.co/u/Zincometal)\
**Replies:** 6\
**Last updated:** [October 19, 2021, 9:04am UTC](https://discuss.elastic.co/t/error-after-os-upgrade/286966 "2021-10-19T09:04:23Z")

</div>

Hello all, I'm a newbie to ELK and after many search I've not found a solution. After an OS upgrade Devuan 3 =\> Devuan 4 my filebeat doesn't work. The error in /var/log/filebeat.log is this: Preformatted text2021-10-…

---

## [Elastic-agent install -f](https://discuss.elastic.co/t/elastic-agent-install-f/286753)

<div class="topic-metadata">

**Author:** [@Greg\_R](https://discuss.elastic.co/u/Greg_R)\
**Replies:** 13\
**Last updated:** [October 19, 2021, 9:03am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753 "2021-10-19T09:03:08Z")

</div>

Greetings I'm trying to set up fleet. All along the doc I see: elastic-agent install -f but the -f flag is not documented anywhere (and make the elastic-agent choke in the docker version). What is it for? My goal is …

---

## [Ingesting JSON logs with filebeat and logstash](https://discuss.elastic.co/t/ingesting-json-logs-with-filebeat-and-logstash/286874)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 8\
**Last updated:** [October 19, 2021, 4:47am UTC](https://discuss.elastic.co/t/ingesting-json-logs-with-filebeat-and-logstash/286874 "2021-10-19T04:47:05Z")

</div>

I hope this messages finds the community member's safe and healthy. I am trying to ingest around 600 GB of logs spread across multiple JSON files. Here are few lings of logs (these are scrubbed DNS logs) {"timestamp":"…

---

## [Filebeat \[7.15.0\] hints based discovery does nothing](https://discuss.elastic.co/t/filebeat-7-15-0-hints-based-discovery-does-nothing/287045)

<div class="topic-metadata">

**Author:** [@gwvandesteeg](https://discuss.elastic.co/u/gwvandesteeg)\
**Replies:** 0\
**Last updated:** [October 19, 2021, 3:13am UTC](https://discuss.elastic.co/t/filebeat-7-15-0-hints-based-discovery-does-nothing/287045 "2021-10-19T03:13:27Z")

</div>

Continuing the discussion from Filebeat doesn't send logs to Elasticsearch: We're having the exact same problem as the above which doesn't appear to have ever been resolved. Using filebeat 7.15.0, exact same config as …

---

## [Filebeat Fortinet Firewall Module 7.15.1](https://discuss.elastic.co/t/filebeat-fortinet-firewall-module-7-15-1/287046)

<div class="topic-metadata">

**Author:** [@unknown\_user](https://discuss.elastic.co/u/unknown_user)\
**Replies:** 0\
**Last updated:** [October 19, 2021, 3:16am UTC](https://discuss.elastic.co/t/filebeat-fortinet-firewall-module-7-15-1/287046 "2021-10-19T03:16:35Z")

</div>

I just started using filebeat fortinet module and noticed that the module failed to split the fields on a fortigate 6.4.7 I've resolved the issue by changing, field\_split: " (?=\[a-z\\\\\_\\\\-\]+=)" to field\_split: ",(?=\[a…

---

## [Filebeat. How drop events with IIS module?](https://discuss.elastic.co/t/filebeat-how-drop-events-with-iis-module/286637)

<div class="topic-metadata">

**Author:** [@psyapathy](https://discuss.elastic.co/u/psyapathy)\
**Replies:** 2\
**Last updated:** [October 19, 2021, 1:43am UTC](https://discuss.elastic.co/t/filebeat-how-drop-events-with-iis-module/286637 "2021-10-19T01:43:12Z")

</div>

Hi! I use IIS module for collect IIS logs. I want drop events if field url.path contains "layouts". Where in the config should I use the processors block with drop\_events? In filebeat.yml or iis.yml? Can you show me …

---

## [All Packetbeat dashboards version 7.15.0 don't work: Invalid JSON in search source](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824)

<div class="topic-metadata">

**Author:** [@hermanator](https://discuss.elastic.co/u/hermanator)\
**Replies:** 14\
**Last updated:** [October 18, 2021, 11:15pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824 "2021-10-18T23:15:02Z")

</div>

Hello, I can't get the dashboards for packetbeat to work. The list with packetbeat dashboards are visible in Kibana, but after clicking any of them I get the error: Invalid JSON in search source. I've setup packetbeat…

---

## [Filebeat configuration](https://discuss.elastic.co/t/filebeat-configuration/286972)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 0\
**Last updated:** [October 18, 2021, 10:24am UTC](https://discuss.elastic.co/t/filebeat-configuration/286972 "2021-10-18T10:24:51Z")

</div>

I have to read logs from different server so I am using filebeat for that. in filebeat yml file I have mention filebeat.inputs: - type: log enabled: true paths: - /home/3rdisearch-dev/project/mangeshs/logs/ind…

---

## [Receive multiple Logstash inputs with TCP, UDP and Beats](https://discuss.elastic.co/t/receive-multiple-logstash-inputs-with-tcp-udp-and-beats/287020)

<div class="topic-metadata">

**Author:** [@sakshat](https://discuss.elastic.co/u/sakshat)\
**Replies:** 6\
**Last updated:** [October 18, 2021, 9:06pm UTC](https://discuss.elastic.co/t/receive-multiple-logstash-inputs-with-tcp-udp-and-beats/287020 "2021-10-18T21:06:09Z")

</div>

Hi everyone, I am trying to get logs input into logstash using TCP, UDP and Beats. I have applications that drain syslog to logstash using tcp and udp and I also have an application that writes logs to files in a server.…

---

## [Monitoring Cluster stopped receiving data from Production Cluster](https://discuss.elastic.co/t/monitoring-cluster-stopped-receiving-data-from-production-cluster/286876)

<div class="topic-metadata">

**Author:** [@TonyLuc](https://discuss.elastic.co/u/TonyLuc)\
**Replies:** 2\
**Last updated:** [October 18, 2021, 5:03pm UTC](https://discuss.elastic.co/t/monitoring-cluster-stopped-receiving-data-from-production-cluster/286876 "2021-10-18T17:03:59Z")

</div>

Observations OS: Windows Sever 2019 Observations are based on: Metricbeat Version 7.15.0 (amd64), libbeat 7.15.0 \[9023152025ec6251bc6b6c38009b309157f10f17 built 2021-09-16 03:28:25 +0000 UTC\] When MetricBeat A…

---

## [How can I match on all log files except ones containing a string](https://discuss.elastic.co/t/how-can-i-match-on-all-log-files-except-ones-containing-a-string/286415)

<div class="topic-metadata">

**Author:** [@dsdameron](https://discuss.elastic.co/u/dsdameron)\
**Replies:** 2\
**Last updated:** [October 18, 2021, 1:20pm UTC](https://discuss.elastic.co/t/how-can-i-match-on-all-log-files-except-ones-containing-a-string/286415 "2021-10-18T13:20:35Z")

</div>

We are ingesting the our CPanel system's Apache logs with Filebeat's handy apache module. Our configuration is as follows: var.paths: - "/var/log/apache2/domlogs/\*" However, I've hit a snag. I need to grab a…

---

## [Clarification on Output Supported by Elastic Agents - Is Output to Logstash Supported?](https://discuss.elastic.co/t/clarification-on-output-supported-by-elastic-agents-is-output-to-logstash-supported/286777)

<div class="topic-metadata">

**Author:** [@Log\_Gobbler](https://discuss.elastic.co/u/Log_Gobbler)\
**Replies:** 5\
**Last updated:** [October 18, 2021, 1:08pm UTC](https://discuss.elastic.co/t/clarification-on-output-supported-by-elastic-agents-is-output-to-logstash-supported/286777 "2021-10-18T13:08:07Z")

</div>

I apologize ahead of time for posting this in the Beats sub, but it appears there isn't a sub for Elastic Agent. Near the top of this page, it states that "Beats and Elastic Agent can both send data directly to Elastics…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=125)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=127)
