# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=128

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 129

---

## [Filebeat multi line stopped working](https://discuss.elastic.co/t/filebeat-multi-line-stopped-working/286397)

<div class="topic-metadata">

**Author:** [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Replies:** 2\
**Last updated:** [October 11, 2021, 5:55pm UTC](https://discuss.elastic.co/t/filebeat-multi-line-stopped-working/286397 "2021-10-11T17:55:50Z")

</div>

Hi, I have been using the filebeat for sometime with multiline pattern. Everything was working fine last week it stopped working. I was using 7.14.1 for filebeat but now i've tried 7.6.2 and 7.15 both. I've been trying…

---

## [Change or disable the elastic-agent grpc.port during fleet server setup in docker container](https://discuss.elastic.co/t/change-or-disable-the-elastic-agent-grpc-port-during-fleet-server-setup-in-docker-container/286388)

<div class="topic-metadata">

**Author:** [@Yustas](https://discuss.elastic.co/u/Yustas)\
**Replies:** 0\
**Last updated:** [October 11, 2021, 3:42pm UTC](https://discuss.elastic.co/t/change-or-disable-the-elastic-agent-grpc-port-during-fleet-server-setup-in-docker-container/286388 "2021-10-11T15:42:08Z")

</div>

Hello. I want run two fleet-agent 7.15 on same host. Becouse one must run in fleet-server mode and other with different policy for retrive syslog events from remoute source. I use docker-compose to cnfigure agents and…

---

## [How to read the log file in a path using regular expression in filebeat](https://discuss.elastic.co/t/how-to-read-the-log-file-in-a-path-using-regular-expression-in-filebeat/286377)

<div class="topic-metadata">

**Author:** [@muralikrishna](https://discuss.elastic.co/u/muralikrishna)\
**Replies:** 0\
**Last updated:** [October 11, 2021, 2:58pm UTC](https://discuss.elastic.co/t/how-to-read-the-log-file-in-a-path-using-regular-expression-in-filebeat/286377 "2021-10-11T14:58:55Z")

</div>

Hello Everyone, I have stuck with an issue to collect/read the logs from a path using regular expression using filebeat. Could some one help me with my issue. Context: I have some servers where the logs are being writt…

---

## [Remove the registry of a concrete input](https://discuss.elastic.co/t/remove-the-registry-of-a-concrete-input/286338)

<div class="topic-metadata">

**Author:** [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Replies:** 0\
**Last updated:** [October 11, 2021, 6:53am UTC](https://discuss.elastic.co/t/remove-the-registry-of-a-concrete-input/286338 "2021-10-11T06:53:27Z")

</div>

hello ! i have a filebeat with two inputs with differents tags and outputs. i want to remove only the registry of one of them. is there any way or parameter to remove the registry or or set the entry to read from the b…

---

## [Beats load balancer feature vs F5 Load balancer](https://discuss.elastic.co/t/beats-load-balancer-feature-vs-f5-load-balancer/286332)

<div class="topic-metadata">

**Author:** [@Ismaeel\_Enjreny](https://discuss.elastic.co/u/Ismaeel_Enjreny)\
**Replies:** 0\
**Last updated:** [October 11, 2021, 5:10am UTC](https://discuss.elastic.co/t/beats-load-balancer-feature-vs-f5-load-balancer/286332 "2021-10-11T05:10:53Z")

</div>

Beats (Filebeat and Heartbeat) provide a way to do load balancing when they send data to output (to Logstash or Elasticsearch), the configuration include the following points: hosts: \["localhost:5044", "localhost:5045"\]…

---

## [Exiting: 9 errors: protocol not available](https://discuss.elastic.co/t/exiting-9-errors-protocol-not-available/286157)

<div class="topic-metadata">

**Author:** [@Johnatan\_Gonzalez\_Ve](https://discuss.elastic.co/u/Johnatan_Gonzalez_Ve)\
**Replies:** 1\
**Last updated:** [October 11, 2021, 12:42am UTC](https://discuss.elastic.co/t/exiting-9-errors-protocol-not-available/286157 "2021-10-11T00:42:45Z")

</div>

module: system period: 10s metricsets: - cpu - load - memory - filesystem - fsstat - network - process - process\_summary - socket\_summary - entropy - core - diskio - socket - service - users process.include\_to…

---

## [Functionbeat cannot process more than 1 message from pub/sub](https://discuss.elastic.co/t/functionbeat-cannot-process-more-than-1-message-from-pub-sub/285903)

<div class="topic-metadata">

**Author:** [@Yero\_Me](https://discuss.elastic.co/u/Yero_Me)\
**Replies:** 0\
**Last updated:** [October 5, 2021, 10:30am UTC](https://discuss.elastic.co/t/functionbeat-cannot-process-more-than-1-message-from-pub-sub/285903 "2021-10-05T10:30:57Z")

</div>

Hello, Since 7.11 up to 7.15, I cannot configure functionbeat to process more than 1 message. I deploy functionbeat on GCP cloud function. Every first message send to cloud function will be properly traited and sent t…

---

## [Elastic Agent Enroll](https://discuss.elastic.co/t/elastic-agent-enroll/286026)

<div class="topic-metadata">

**Author:** [@ravenmx](https://discuss.elastic.co/u/ravenmx)\
**Replies:** 0\
**Last updated:** [October 6, 2021, 12:41pm UTC](https://discuss.elastic.co/t/elastic-agent-enroll/286026 "2021-10-06T12:41:08Z")

</div>

Good Day. Do not tell me by chance whether it is possible to add any custom field to the elastic agent, where I can leave a record when installing the agent and work with it when searching (it seems that this is impossi…

---

## [Metricbeat from source builds x-pack modules but doesnt contain directories in image](https://discuss.elastic.co/t/metricbeat-from-source-builds-x-pack-modules-but-doesnt-contain-directories-in-image/285752)

<div class="topic-metadata">

**Author:** [@ss\_22](https://discuss.elastic.co/u/ss_22)\
**Replies:** 2\
**Last updated:** [October 9, 2021, 3:46pm UTC](https://discuss.elastic.co/t/metricbeat-from-source-builds-x-pack-modules-but-doesnt-contain-directories-in-image/285752 "2021-10-09T15:46:27Z")

</div>

Hello, I have recently built Metricbeat from source code after following the developer guides. I noticed it builds all of the x-pack modules, but at the end of the day the image doesnt contain these module directories. …

---

## [How to remove ipv6 from host.ip](https://discuss.elastic.co/t/how-to-remove-ipv6-from-host-ip/284341)

<div class="topic-metadata">

**Author:** [@xizhimen](https://discuss.elastic.co/u/xizhimen)\
**Replies:** 4\
**Last updated:** [October 9, 2021, 6:40am UTC](https://discuss.elastic.co/t/how-to-remove-ipv6-from-host-ip/284341 "2021-10-09T06:40:59Z")

</div>

background: winlogbeat7.3.2 windows2016 winlogbeat.yml: processors: - add\_host\_metadata: netinfo.enabled: true requirement: in kibana: I want to remove this ipv6 info ,How? THANKS! I try to remove ipv…

---

## [New filebeat module - how to move to production? Template not loading](https://discuss.elastic.co/t/new-filebeat-module-how-to-move-to-production-template-not-loading/285775)

<div class="topic-metadata">

**Author:** [@kelvins](https://discuss.elastic.co/u/kelvins)\
**Replies:** 7\
**Last updated:** [October 8, 2021, 8:18pm UTC](https://discuss.elastic.co/t/new-filebeat-module-how-to-move-to-production-template-not-loading/285775 "2021-10-08T20:18:37Z")

</div>

I have created a new module to Filebeat. To be honest I have been struggling with this for a long time, perhaps a blog post somewhere (creating a new filebeat start to finish) I could find could help me immensely. Anyw…

---

## [Fleet service account permissions for filebeat threat intel](https://discuss.elastic.co/t/fleet-service-account-permissions-for-filebeat-threat-intel/286258)

<div class="topic-metadata">

**Author:** [@albbapm](https://discuss.elastic.co/u/albbapm)\
**Replies:** 0\
**Last updated:** [October 8, 2021, 2:53pm UTC](https://discuss.elastic.co/t/fleet-service-account-permissions-for-filebeat-threat-intel/286258 "2021-10-08T14:53:14Z")

</div>

I am trying to use the elastic agent via fleet and filebeat to gather threat intel. I realize this is currently not working out of the box. That being said, I think I can massage it and get it working but I have some q…

---

## [How do I not send metadata from filebeat to Graylog?](https://discuss.elastic.co/t/how-do-i-not-send-metadata-from-filebeat-to-graylog/286253)

<div class="topic-metadata">

**Author:** [@s79](https://discuss.elastic.co/u/s79)\
**Replies:** 0\
**Last updated:** [October 8, 2021, 2:36pm UTC](https://discuss.elastic.co/t/how-do-i-not-send-metadata-from-filebeat-to-graylog/286253 "2021-10-08T14:36:27Z")

</div>

I am using filebeats directly to send json data to graylog. The fields @metadata\_\_id, @metadata\_beat, @metadata\_type, @metadata\_version are constants, and @timestamp is not needed since the time is in the message. All th…

---

## [Metricbeat not creating Index correctly](https://discuss.elastic.co/t/metricbeat-not-creating-index-correctly/285863)

<div class="topic-metadata">

**Author:** [@mhare](https://discuss.elastic.co/u/mhare)\
**Replies:** 4\
**Last updated:** [October 8, 2021, 2:36pm UTC](https://discuss.elastic.co/t/metricbeat-not-creating-index-correctly/285863 "2021-10-08T14:36:25Z")

</div>

I am running Stack version 7.13.4 with Metricbeat Everything seemed to be working fine, then we wanted to remove all the metricbeat data and start over. So we stopped metricbeat, and deleted all of the Metricbeat indexe…

---

## [handleSQSMessage failed: json unmarshal sqs message body failed at offset 1 with syntax error: invalid character 'T' looking for beginning of value](https://discuss.elastic.co/t/handlesqsmessage-failed-json-unmarshal-sqs-message-body-failed-at-offset-1-with-syntax-error-invalid-character-t-looking-for-beginning-of-value/286249)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 0\
**Last updated:** [October 8, 2021, 2:11pm UTC](https://discuss.elastic.co/t/handlesqsmessage-failed-json-unmarshal-sqs-message-body-failed-at-offset-1-with-syntax-error-invalid-character-t-looking-for-beginning-of-value/286249 "2021-10-08T14:11:11Z")

</div>

I am trying to trouble shoot an issue. I have a set of logs from ecs that are to be sent to an sqs queue. The container logs show that the logs are being sent. However, when I poll the sqs queue none of the messages are …

---

## [Elastic Agent built-in Filebeat](https://discuss.elastic.co/t/elastic-agent-built-in-filebeat/286214)

<div class="topic-metadata">

**Author:** [@bil\_15](https://discuss.elastic.co/u/bil_15)\
**Replies:** 0\
**Last updated:** [October 8, 2021, 9:31am UTC](https://discuss.elastic.co/t/elastic-agent-built-in-filebeat/286214 "2021-10-08T09:31:24Z")

</div>

Hello! I've installed Elastic Agent on Ubuntu and enabled AuditD integration for it (it's attached to an agent) I left all the configurations by default. Now, when I'm trying to elastic\_agent.filebeat data stream I'm …

---

## [Read Last 3 moth Historic Log from Windows Events Log](https://discuss.elastic.co/t/read-last-3-moth-historic-log-from-windows-events-log/286182)

<div class="topic-metadata">

**Author:** [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Replies:** 1\
**Last updated:** [October 8, 2021, 9:31am UTC](https://discuss.elastic.co/t/read-last-3-moth-historic-log-from-windows-events-log/286182 "2021-10-08T09:31:07Z")

</div>

I am planning to install winlog beat in one of my Windows host. How can we read last 3 month historic logs( logs generated before the winlogbeat installation) from windows event log. My requirement is to read the…

---

## [How can we update value of a field in a document in a bulk not a single document](https://discuss.elastic.co/t/how-can-we-update-value-of-a-field-in-a-document-in-a-bulk-not-a-single-document/286192)

<div class="topic-metadata">

**Author:** [@1a2k3m](https://discuss.elastic.co/u/1a2k3m)\
**Replies:** 0\
**Last updated:** [October 8, 2021, 7:12am UTC](https://discuss.elastic.co/t/how-can-we-update-value-of-a-field-in-a-document-in-a-bulk-not-a-single-document/286192 "2021-10-08T07:12:15Z")

</div>

Hi team, i am a new joiner to this discussion, i want to update field of a document in Elasticsearch on Devtools. and i want update all the document in one go, i mean to say i want to update more that 10 document in one…

---

## [When disable close\_removed, why also need disable clean\_removed](https://discuss.elastic.co/t/when-disable-close-removed-why-also-need-disable-clean-removed/286188)

<div class="topic-metadata">

**Author:** [@honghong516](https://discuss.elastic.co/u/honghong516)\
**Replies:** 0\
**Last updated:** [October 8, 2021, 7:02am UTC](https://discuss.elastic.co/t/when-disable-close-removed-why-also-need-disable-clean-removed/286188 "2021-10-08T07:02:43Z")

</div>

close\_removed edit When this option is enabled, Filebeat closes the harvester when a file is removed. Normally a file should only be removed after it’s inactive for the duration specified by close\_inactive . However, if …

---

## [Setup Metricbeat only for one module](https://discuss.elastic.co/t/setup-metricbeat-only-for-one-module/286145)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 1\
**Last updated:** [October 8, 2021, 2:55am UTC](https://discuss.elastic.co/t/setup-metricbeat-only-for-one-module/286145 "2021-10-08T02:55:03Z")

</div>

Hi, Last time i set up metricbeat with two modules enabled. Metricbeat created all possible dashboards for me, even those for disabled modules. How can I ask metricbeat to create dashboards/saved object for only activa…

---

## [\[Filebeat\] Metadata (Content-Type octet-stream) in S3 file - silently ignores 'Publish event'](https://discuss.elastic.co/t/filebeat-metadata-content-type-octet-stream-in-s3-file-silently-ignores-publish-event/286082)

<div class="topic-metadata">

**Author:** [@Maksim](https://discuss.elastic.co/u/Maksim)\
**Replies:** 2\
**Last updated:** [October 7, 2021, 11:15pm UTC](https://discuss.elastic.co/t/filebeat-metadata-content-type-octet-stream-in-s3-file-silently-ignores-publish-event/286082 "2021-10-07T23:15:51Z")

</div>

First debug log: If Object-string like: 2021-10-06/2021-10-06T23:13:06.107Z-test@simulator.json filebeat silently drop output 2021-10-06T23:13:08.827Z DEBUG \[input.aws-s3.sqs\] awss3/sqs.go:77 Received 1 SQS messages. …

---

## [Filebeat setup error](https://discuss.elastic.co/t/filebeat-setup-error/286147)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 0\
**Last updated:** [October 7, 2021, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-setup-error/286147 "2021-10-07T14:44:09Z")

</div>

Hi there. After upgrading to Filebeat 7.15 i get this error on filebeat setup root@suricata:~# sudo filebeat setup Overwriting ILM policy is disabled. Set \`setup.ilm.overwrite: true\` for enabling. Index setup finished…

---

## [Unable to deploy functionbeat on S3](https://discuss.elastic.co/t/unable-to-deploy-functionbeat-on-s3/285621)

<div class="topic-metadata">

**Author:** [@Priyam\_Maheshwari](https://discuss.elastic.co/u/Priyam_Maheshwari)\
**Replies:** 1\
**Last updated:** [October 7, 2021, 12:28pm UTC](https://discuss.elastic.co/t/unable-to-deploy-functionbeat-on-s3/285621 "2021-10-07T12:28:32Z")

</div>

I keep getting the following error Function: cloudwatchlogging, could not deploy, error: bucket 'functionbeat-advertising' already exist and you don't have permission to access it: unknown endpoint, could not resolve en…

---

## [Metricbeat with Zookeper module](https://discuss.elastic.co/t/metricbeat-with-zookeper-module/285487)

<div class="topic-metadata">

**Author:** [@Lidya\_Aguero](https://discuss.elastic.co/u/Lidya_Aguero)\
**Replies:** 1\
**Last updated:** [October 6, 2021, 2:48pm UTC](https://discuss.elastic.co/t/metricbeat-with-zookeper-module/285487 "2021-10-06T14:48:39Z")

</div>

I try use Metricbeat 7.15.0 with Zookeeper module and receive this messages in Elasticsearch: error.message: error obtaining serverid: no 'serverId' found in 'conf' response zookeeper.yml: - module: zookeeper enable…

---

## [Filebeat 6.8.18 - output to logstash instead of direct to elastic](https://discuss.elastic.co/t/filebeat-6-8-18-output-to-logstash-instead-of-direct-to-elastic/286012)

<div class="topic-metadata">

**Author:** [@Heebie](https://discuss.elastic.co/u/Heebie)\
**Replies:** 0\
**Last updated:** [October 6, 2021, 10:38am UTC](https://discuss.elastic.co/t/filebeat-6-8-18-output-to-logstash-instead-of-direct-to-elastic/286012 "2021-10-06T10:38:43Z")

</div>

Hello, I'm trying to deploy filebeats using the "Official Elastic helm chart for Filebeat" from github.com/elastic/helm-charts... and it seems to only have the ability to output to Elasticsearch directly, but I need to …

---

## [Dropped Netflow packets in filebeat](https://discuss.elastic.co/t/dropped-netflow-packets-in-filebeat/283837)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 1\
**Last updated:** [October 6, 2021, 10:28am UTC](https://discuss.elastic.co/t/dropped-netflow-packets-in-filebeat/283837 "2021-10-06T10:28:08Z")

</div>

Hi, I'm ingesting Netflow traffic using filebeat's netflow module (for the first time), and I think there are dropped packets. I'm wondering if there is anything I can do to reduce or eliminate dropped packets. I start…

---

## [Running multiple filebeat instances to handle netflow load](https://discuss.elastic.co/t/running-multiple-filebeat-instances-to-handle-netflow-load/284237)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 2\
**Last updated:** [October 6, 2021, 10:21am UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances-to-handle-netflow-load/284237 "2021-10-06T10:21:37Z")

</div>

Hi, I'm currently running Filebeat v7.14 with the Netflow module to send Netflow traffic directly into Elasticsearch. However, when I look at the Filebeat monitoring stats, it appears that I'm dropping packets. I'm thin…

---

## [Performanceissue with Filebeat and Netflow Input](https://discuss.elastic.co/t/performanceissue-with-filebeat-and-netflow-input/284268)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 6\
**Last updated:** [October 6, 2021, 10:20am UTC](https://discuss.elastic.co/t/performanceissue-with-filebeat-and-netflow-input/284268 "2021-10-06T10:20:09Z")

</div>

Hi folks, we are importing flow data into our 10 Node Elasticsearch cluster via Filebeat netflow Input. The Stack is running on 7.14.0. Unfortunately I am witnessing performance pressure and after all the debugging and …

---

## [Elastic Agent TLS Auth Handshake Failed - Internal Error](https://discuss.elastic.co/t/elastic-agent-tls-auth-handshake-failed-internal-error/285816)

<div class="topic-metadata">

**Author:** [@millap](https://discuss.elastic.co/u/millap)\
**Replies:** 1\
**Last updated:** [October 6, 2021, 9:35am UTC](https://discuss.elastic.co/t/elastic-agent-tls-auth-handshake-failed-internal-error/285816 "2021-10-06T09:35:37Z")

</div>

Hi all, I wonder if anyone's able to offer some advice, or pointers on troubleshooting an issue we have with a number of clients managed by Fleet. We're running 7.13.0, and have just started deploying to Windows endpoi…

---

## [Metricbeat beat module](https://discuss.elastic.co/t/metricbeat-beat-module/285991)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 0\
**Last updated:** [October 6, 2021, 7:57am UTC](https://discuss.elastic.co/t/metricbeat-beat-module/285991 "2021-10-06T07:57:48Z")

</div>

Good Morning, I have enabled metricbeats on a few of our network sensors that are running filebeat. I am able to run metricbeat with the system module without a problem. When I try to run the beat module I start getting…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=127)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=129)
