# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=127

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 128

---

## [Sysmon Integration with Linux Elastic Agent?](https://discuss.elastic.co/t/sysmon-integration-with-linux-elastic-agent/286861)

<div class="topic-metadata">

**Author:** [@cheapsupps](https://discuss.elastic.co/u/cheapsupps)\
**Replies:** 1\
**Last updated:** [October 18, 2021, 9:53am UTC](https://discuss.elastic.co/t/sysmon-integration-with-linux-elastic-agent/286861 "2021-10-18T09:53:47Z")

</div>

Sysmon for linux is just being released. https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-linux-version-of-the-windows-sysmon-tool/ We all know how the sysmon can be customized to collect useful secur…

---

## [Default values for value interpolation in autodiscovery](https://discuss.elastic.co/t/default-values-for-value-interpolation-in-autodiscovery/286950)

<div class="topic-metadata">

**Author:** [@gwvandesteeg](https://discuss.elastic.co/u/gwvandesteeg)\
**Replies:** 0\
**Last updated:** [October 18, 2021, 5:27am UTC](https://discuss.elastic.co/t/default-values-for-value-interpolation-in-autodiscovery/286950 "2021-10-18T05:27:15Z")

</div>

Is there a way to specify a default value for a value interpolation in the metricbeat configuration. For example: modules.autodiscover: providers: # prometheus resource auto discovery - ty…

---

## [Metricbeat on kubernetes, conflicting configurations](https://discuss.elastic.co/t/metricbeat-on-kubernetes-conflicting-configurations/286585)

<div class="topic-metadata">

**Author:** [@gwvandesteeg](https://discuss.elastic.co/u/gwvandesteeg)\
**Replies:** 2\
**Last updated:** [October 18, 2021, 2:20am UTC](https://discuss.elastic.co/t/metricbeat-on-kubernetes-conflicting-configurations/286585 "2021-10-18T02:20:17Z")

</div>

Been looking at the way to deploy Metricbeat onto our kubernetes cluster and I've been finding conflicting information from two sources. references the material at https://raw.githubusercontent.com/elastic/beats/7.15/…

---

## [How to process these NginX logs? Grok error](https://discuss.elastic.co/t/how-to-process-these-nginx-logs-grok-error/286920)

<div class="topic-metadata">

**Author:** [@stijnos1991](https://discuss.elastic.co/u/stijnos1991)\
**Replies:** 1\
**Last updated:** [October 17, 2021, 1:56pm UTC](https://discuss.elastic.co/t/how-to-process-these-nginx-logs-grok-error/286920 "2021-10-17T13:56:44Z")

</div>

Hello! I'm pretty new to ELK, but I have theoretical and practical background in Cyber Security. As a hobby project I'm trying to setup a simple SIEM, or log collector at home to see how the ELK stack is configured. In…

---

## [Compile mips64 "io/fs" error](https://discuss.elastic.co/t/compile-mips64-io-fs-error/286907)

<div class="topic-metadata">

**Author:** [@alg42](https://discuss.elastic.co/u/alg42)\
**Replies:** 0\
**Last updated:** [October 17, 2021, 4:43am UTC](https://discuss.elastic.co/t/compile-mips64-io-fs-error/286907 "2021-10-17T04:43:42Z")

</div>

I'm trying to compile metricbeat to run on a Ubiquiti Unifi Security Gateway (mips64). I also get the same error when trying to do filebeat. build github.com/elastic/beats/v7/metricbeat: cannot load io/fs: malformed mo…

---

## [Filter computer object password changes](https://discuss.elastic.co/t/filter-computer-object-password-changes/284651)

<div class="topic-metadata">

**Author:** [@WilGG](https://discuss.elastic.co/u/WilGG)\
**Replies:** 8\
**Last updated:** [October 15, 2021, 6:37pm UTC](https://discuss.elastic.co/t/filter-computer-object-password-changes/284651 "2021-10-15T18:37:13Z")

</div>

Good Afternoon Everyone, We are been overwhelmed by computer objects password changes. Does anyone know how to filter this events so we do not skip actual user object password change events ? Thank you!

---

## [Test Suite error - time.Local vs time.UTC?](https://discuss.elastic.co/t/test-suite-error-time-local-vs-time-utc/286735)

<div class="topic-metadata">

**Author:** [@hinchliff](https://discuss.elastic.co/u/hinchliff)\
**Replies:** 1\
**Last updated:** [October 15, 2021, 2:04pm UTC](https://discuss.elastic.co/t/test-suite-error-time-local-vs-time-utc/286735 "2021-10-15T14:04:11Z")

</div>

Seeing some failures for make testsuite for libbeat, that seem to be Timezone related. (My computer is in US Eastern.) command \[go test -cover -coverprofile /tmp/gotestcover-1560318489 github.com/elastic/beats/v7/libbe…

---

## [Winlogbeat modules and file ingestion](https://discuss.elastic.co/t/winlogbeat-modules-and-file-ingestion/286845)

<div class="topic-metadata">

**Author:** [@jane](https://discuss.elastic.co/u/jane)\
**Replies:** 0\
**Last updated:** [October 15, 2021, 1:46pm UTC](https://discuss.elastic.co/t/winlogbeat-modules-and-file-ingestion/286845 "2021-10-15T13:46:34Z")

</div>

Hey, Is it possible to apply Security, Sysmon and Powershell modules in winlogbeat.yml if I'm ingesting a file? I'm trying something like this, but it doesn't work :confused: winlogbeat.event\_logs: - name: "C:/LOGS/so…

---

## [Elastic-agent install: Unknown resource](https://discuss.elastic.co/t/elastic-agent-install-unknown-resource/286758)

<div class="topic-metadata">

**Author:** [@jknight](https://discuss.elastic.co/u/jknight)\
**Replies:** 0\
**Last updated:** [October 14, 2021, 4:43pm UTC](https://discuss.elastic.co/t/elastic-agent-install-unknown-resource/286758 "2021-10-14T16:43:21Z")

</div>

I'm trying to install elastic-agent on our server and am getting message: Unknown resource. I'm using the hosted elastic offering and have APM & Fleet enabled. Steps Taken: Download Linux 64-bit tarball to server U…

---

## [What permissions are needed to manage Fleet/Agent Policies/Integrations](https://discuss.elastic.co/t/what-permissions-are-needed-to-manage-fleet-agent-policies-integrations/286650)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 4\
**Last updated:** [October 14, 2021, 4:59pm UTC](https://discuss.elastic.co/t/what-permissions-are-needed-to-manage-fleet-agent-policies-integrations/286650 "2021-10-14T16:59:48Z")

</div>

Hi All, I'm trying to setup RBAC for managing Fleet/Agent Policies/Integrations, but I'm having a hard time finding a list of permissions (Index level and Kibana Space level). Would anyone know where I could find docs f…

---

## [How to configure processor in autodiscover mode?](https://discuss.elastic.co/t/how-to-configure-processor-in-autodiscover-mode/286757)

<div class="topic-metadata">

**Author:** [@Jfree](https://discuss.elastic.co/u/Jfree)\
**Replies:** 0\
**Last updated:** [October 14, 2021, 4:35pm UTC](https://discuss.elastic.co/t/how-to-configure-processor-in-autodiscover-mode/286757 "2021-10-14T16:35:27Z")

</div>

Hi, We have k8s cluster with filebeat configured in autodiscover mode with hints: filebeat.yml: | logging.level: debug filebeat.autodiscover: providers: - type: kubernetes node: ${NODE\_NAME} …

---

## [Can't install Fleet Server on Ubuntu instance](https://discuss.elastic.co/t/cant-install-fleet-server-on-ubuntu-instance/286736)

<div class="topic-metadata">

**Author:** [@Dmitriy\_Esin](https://discuss.elastic.co/u/Dmitriy_Esin)\
**Replies:** 0\
**Last updated:** [October 14, 2021, 2:22pm UTC](https://discuss.elastic.co/t/cant-install-fleet-server-on-ubuntu-instance/286736 "2021-10-14T14:22:34Z")

</div>

Hi all! Unfortunately, I didn't find suitable topics! I have these configs: Fleet settings Tried to enroll and install elastic agent two ways: sudo ./elastic-agent install -f --url=https://10.2.5.2:8220 --f…

---

## [filebeat/Logstash exit](https://discuss.elastic.co/t/filebeat-logstash-exit/286716)

<div class="topic-metadata">

**Author:** [@smam](https://discuss.elastic.co/u/smam)\
**Replies:** 3\
**Last updated:** [October 14, 2021, 12:48pm UTC](https://discuss.elastic.co/t/filebeat-logstash-exit/286716 "2021-10-14T12:48:53Z")

</div>

Hello, I would like to know how: filebeat -e and /usr/share/logstash/bin/logstash should exit? Because they each run for 10 minutes and before not moving further they print: starting.... Logstash start an input lis…

---

## [Okta module causes rate-limit violations](https://discuss.elastic.co/t/okta-module-causes-rate-limit-violations/286721)

<div class="topic-metadata">

**Author:** [@hinchliff](https://discuss.elastic.co/u/hinchliff)\
**Replies:** 0\
**Last updated:** [October 14, 2021, 12:33pm UTC](https://discuss.elastic.co/t/okta-module-causes-rate-limit-violations/286721 "2021-10-14T12:33:46Z")

</div>

In the GitHub issue #23023, a bug is fixed in the httpjson module that caused Filebeat to continue requesting data from Okta even after the rate-limit has been reached. However, Okta continues to tag Filebeat behavior a…

---

## [Filebeat not send logs to logstash on kubernetes](https://discuss.elastic.co/t/filebeat-not-send-logs-to-logstash-on-kubernetes/286671)

<div class="topic-metadata">

**Author:** [@dhody\_rhmd](https://discuss.elastic.co/u/dhody_rhmd)\
**Replies:** 0\
**Last updated:** [October 14, 2021, 4:32am UTC](https://discuss.elastic.co/t/filebeat-not-send-logs-to-logstash-on-kubernetes/286671 "2021-10-14T04:32:45Z")

</div>

Hello, I'm trying to send kubernetes logs with Filebeat and Logstash. I do have some deployment on the same namespace. I tried the suggested configuration for filebeat.yml from elastic in this \[link\].(https://raw.github…

---

## [Fleet Kibana Integration -\> To enable this usage, set xpack.enabled: true on the package config](https://discuss.elastic.co/t/fleet-kibana-integration-to-enable-this-usage-set-xpack-enabled-true-on-the-package-config/286660)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 0\
**Last updated:** [October 13, 2021, 8:19pm UTC](https://discuss.elastic.co/t/fleet-kibana-integration-to-enable-this-usage-set-xpack-enabled-true-on-the-package-config/286660 "2021-10-13T20:19:26Z")

</div>

Hi, How is this done with a Fleet Managed Setup ? xpack.enabled: true Would like to see the Kibana Stats in Stack Monitoring

---

## [AutoDiscover ServiceMonitor CRD on Kubernetes](https://discuss.elastic.co/t/autodiscover-servicemonitor-crd-on-kubernetes/286642)

<div class="topic-metadata">

**Author:** [@julianxhokaxhiu](https://discuss.elastic.co/u/julianxhokaxhiu)\
**Replies:** 0\
**Last updated:** [October 13, 2021, 3:28pm UTC](https://discuss.elastic.co/t/autodiscover-servicemonitor-crd-on-kubernetes/286642 "2021-10-13T15:28:27Z")

</div>

Hi, I have a question about Metricsbeat. I've seen in the official documentation that the service supports AutoDiscovery which is great ( Autodiscover | Metricbeat Reference \[7.15\] | Elastic ). Officially it supports N…

---

## [Mismatch between ECS and Packetbeat 7.1.5 on some fields](https://discuss.elastic.co/t/mismatch-between-ecs-and-packetbeat-7-1-5-on-some-fields/286639)

<div class="topic-metadata">

**Author:** [@Soik](https://discuss.elastic.co/u/Soik)\
**Replies:** 0\
**Last updated:** [October 13, 2021, 2:54pm UTC](https://discuss.elastic.co/t/mismatch-between-ecs-and-packetbeat-7-1-5-on-some-fields/286639 "2021-10-13T14:54:00Z")

</div>

There is a mismatch in the following fields between ECS and Packetbeat 7.1.5: dns.answers.ttl (String in packetbeat - Long in ECS Documentation) dns.id (Integer in packetbeat - String/Keyword in ECS Documentation) Is …

---

## [Filebeat daemon set misses last few lines of log on pod crash](https://discuss.elastic.co/t/filebeat-daemon-set-misses-last-few-lines-of-log-on-pod-crash/286640)

<div class="topic-metadata">

**Author:** [@TimWardFS](https://discuss.elastic.co/u/TimWardFS)\
**Replies:** 0\
**Last updated:** [October 13, 2021, 3:14pm UTC](https://discuss.elastic.co/t/filebeat-daemon-set-misses-last-few-lines-of-log-on-pod-crash/286640 "2021-10-13T15:14:30Z")

</div>

I have seen a number of posts saying that when a Kubernetes pod crashes Filebeat loses the last few lines of log output, including, of course, the actual error message that tells you why the pod crashed. All the ones I'…

---

## [Filebeat 7.13.4 + Kubernetes 1.20: Hints-Based Autodiscover](https://discuss.elastic.co/t/filebeat-7-13-4-kubernetes-1-20-hints-based-autodiscover/286421)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [October 13, 2021, 2:40pm UTC](https://discuss.elastic.co/t/filebeat-7-13-4-kubernetes-1-20-hints-based-autodiscover/286421 "2021-10-13T14:40:54Z")

</div>

We just upgraded our Kubernetes cluster to 1.20 (current version of filebeat is 7.13.4). Of course, this means that Kubernetes logs are no longer in the same place they were under 1.19, and instead are in the following l…

---

## [How to run multiple instances of Filebeat for the same input/output?](https://discuss.elastic.co/t/how-to-run-multiple-instances-of-filebeat-for-the-same-input-output/286539)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 5\
**Last updated:** [October 13, 2021, 12:38pm UTC](https://discuss.elastic.co/t/how-to-run-multiple-instances-of-filebeat-for-the-same-input-output/286539 "2021-10-13T12:38:03Z")

</div>

Hi, is there a recommended way to run multiple instances if Filebeat, on different physical servers (VMs) that would process data from the same input and into the same output (ES index)? Basically to have an option to …

---

## [Can't connect hosts to the Fleet Server](https://discuss.elastic.co/t/cant-connect-hosts-to-the-fleet-server/286450)

<div class="topic-metadata">

**Author:** [@Dmitriy\_Esin](https://discuss.elastic.co/u/Dmitriy_Esin)\
**Replies:** 17\
**Last updated:** [October 13, 2021, 11:26am UTC](https://discuss.elastic.co/t/cant-connect-hosts-to-the-fleet-server/286450 "2021-10-13T11:26:17Z")

</div>

Hi all! I need your help! I have a self-hosted ELK (not cloud) I've enrolled the Fleet Server for SIEM using this manual for a self-managed server with default parameters in elastic-agent.yml I need to connect hosts …

---

## [Deleted the winlog index by mistake](https://discuss.elastic.co/t/deleted-the-winlog-index-by-mistake/286565)

<div class="topic-metadata">

**Author:** [@Marcelle\_Lic](https://discuss.elastic.co/u/Marcelle_Lic)\
**Replies:** 1\
**Last updated:** [October 13, 2021, 3:49am UTC](https://discuss.elastic.co/t/deleted-the-winlog-index-by-mistake/286565 "2021-10-13T03:49:57Z")

</div>

I deleted my winlogbeat index by mistake and I have been trying hard to reindex the events but no luck for the last few weeks, either I get Root-error or code 404 or Invalid index name, an alias exists with the same na…

---

## [Upgrade Error: Cannot write to a field alias \[host.hostname\]](https://discuss.elastic.co/t/upgrade-error-cannot-write-to-a-field-alias-host-hostname/286543)

<div class="topic-metadata">

**Author:** [@Karthik\_ek](https://discuss.elastic.co/u/Karthik_ek)\
**Replies:** 0\
**Last updated:** [October 12, 2021, 7:50pm UTC](https://discuss.elastic.co/t/upgrade-error-cannot-write-to-a-field-alias-host-hostname/286543 "2021-10-12T19:50:44Z")

</div>

Hi, Can you please help here. I'm getting error after upgrading from filebeat 6.8.6 to filebeat 7.9.2. I see the below error in the logs folder: Cannot write to a field alias \[host.hostname\] 2021-10-12T10:34:28.800-0…

---

## [Filebeat negate regexp](https://discuss.elastic.co/t/filebeat-negate-regexp/286502)

<div class="topic-metadata">

**Author:** [@Marcus\_Juttner](https://discuss.elastic.co/u/Marcus_Juttner)\
**Replies:** 1\
**Last updated:** [October 12, 2021, 6:59pm UTC](https://discuss.elastic.co/t/filebeat-negate-regexp/286502 "2021-10-12T18:59:11Z")

</div>

Hello How can I negate this processors: - drop\_event: when: regexp: message: "^\[0-9\]" I want to read only lines beginning with a number and ignore all others. Thank you Marcus

---

## [Filebeat doesn't harvest folder structure](https://discuss.elastic.co/t/filebeat-doesnt-harvest-folder-structure/286374)

<div class="topic-metadata">

**Author:** [@luka.klaric](https://discuss.elastic.co/u/luka.klaric)\
**Replies:** 2\
**Last updated:** [October 12, 2021, 12:55pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-harvest-folder-structure/286374 "2021-10-12T12:55:35Z")

</div>

I am having the issue that filebeat (7.8) somehow 'ingores' my folder structure. This is the part of the filebeat.yml related to the folder structure: - type: log paths: - "/folder1/folder2/folder3/log…

---

## [Metricbeat openmetrics module ignores 'metrics\_path' parameter](https://discuss.elastic.co/t/metricbeat-openmetrics-module-ignores-metrics-path-parameter/286495)

<div class="topic-metadata">

**Author:** [@AuroraBorealis](https://discuss.elastic.co/u/AuroraBorealis)\
**Replies:** 0\
**Last updated:** [October 12, 2021, 1:00pm UTC](https://discuss.elastic.co/t/metricbeat-openmetrics-module-ignores-metrics-path-parameter/286495 "2021-10-12T13:00:21Z")

</div>

Hello, I use Metricbeat 7.15 to collect metrics from a JBoss EAP application server. The applicaion-specific metrics are available at: http://localhost:10090/metrics/application I configured the openmetrics module like…

---

## [Filebeat can not get correct logs](https://discuss.elastic.co/t/filebeat-can-not-get-correct-logs/286456)

<div class="topic-metadata">

**Author:** [@Chen\_xa](https://discuss.elastic.co/u/Chen_xa)\
**Replies:** 0\
**Last updated:** [October 12, 2021, 9:13am UTC](https://discuss.elastic.co/t/filebeat-can-not-get-correct-logs/286456 "2021-10-12T09:13:51Z")

</div>

I created a yaml file to deploy filebeat in my cluster. And I configured the right container log path. But when I see the filebeat logs I found out that all containers' ID is not same with the path. Here is my yaml: …

---

## [Send with many filebeat to one beat. "Inputbeat"](https://discuss.elastic.co/t/send-with-many-filebeat-to-one-beat-inputbeat/286221)

<div class="topic-metadata">

**Author:** [@Felix\_Kutscher](https://discuss.elastic.co/u/Felix_Kutscher)\
**Replies:** 7\
**Last updated:** [October 12, 2021, 9:11am UTC](https://discuss.elastic.co/t/send-with-many-filebeat-to-one-beat-inputbeat/286221 "2021-10-12T09:11:09Z")

</div>

Hello, situation: We use Logstash as a forwarder. Many filebeats send to one Logstash. (filebeat--\>forwarder-logstash--\>logstash--\>elastic) But the logstash is only a forwarder and very unstable. Now my question: Is…

---

## [Heartbeat and custom authentication](https://discuss.elastic.co/t/heartbeat-and-custom-authentication/286345)

<div class="topic-metadata">

**Author:** [@TommasoMoroni](https://discuss.elastic.co/u/TommasoMoroni)\
**Replies:** 1\
**Last updated:** [October 11, 2021, 6:00pm UTC](https://discuss.elastic.co/t/heartbeat-and-custom-authentication/286345 "2021-10-11T18:00:48Z")

</div>

Hi, I would like to configure Heartbeat in order to sample an authenticated http endpoint. This endpoint is authenticated with a JWT token, which I have to obtain with another call with basic auth. Is it possible to i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=126)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=128)
