# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=129

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 130

---

## [Filebeat won't start the service. Data path already locked by another beat](https://discuss.elastic.co/t/filebeat-wont-start-the-service-data-path-already-locked-by-another-beat/285989)

<div class="topic-metadata">

**Author:** [@dhody\_rhmd](https://discuss.elastic.co/u/dhody_rhmd)\
**Replies:** 0\
**Last updated:** [October 6, 2021, 7:49am UTC](https://discuss.elastic.co/t/filebeat-wont-start-the-service-data-path-already-locked-by-another-beat/285989 "2021-10-06T07:49:44Z")

</div>

Hello, This is my first time to setup logging stack. My problem is the Filebeat service wont start. filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/lib/systemd…

---

## [Setup FileBeats in AZURE ACI ( Not Azure module )](https://discuss.elastic.co/t/setup-filebeats-in-azure-aci-not-azure-module/285902)

<div class="topic-metadata">

**Author:** [@mklynx](https://discuss.elastic.co/u/mklynx)\
**Replies:** 1\
**Last updated:** [October 5, 2021, 2:03pm UTC](https://discuss.elastic.co/t/setup-filebeats-in-azure-aci-not-azure-module/285902 "2021-10-05T14:03:51Z")

</div>

I am looking for some help. I have an elastic stack running in AZURE. I have an Application container running in ACI that logs to a fileshare. I want to move the logging to the elastic stack. I was thinking to add a fil…

---

## [FileBeat: decode\_json\_fields processor max\_depth option not working](https://discuss.elastic.co/t/filebeat-decode-json-fields-processor-max-depth-option-not-working/285836)

<div class="topic-metadata">

**Author:** [@Denis\_Baryshev](https://discuss.elastic.co/u/Denis_Baryshev)\
**Replies:** 0\
**Last updated:** [October 4, 2021, 3:40pm UTC](https://discuss.elastic.co/t/filebeat-decode-json-fields-processor-max-depth-option-not-working/285836 "2021-10-04T15:40:37Z")

</div>

Plz review

---

## [Send custom metric via MetricBeat](https://discuss.elastic.co/t/send-custom-metric-via-metricbeat/284887)

<div class="topic-metadata">

**Author:** [@maltewhiite](https://discuss.elastic.co/u/maltewhiite)\
**Replies:** 1\
**Last updated:** [October 4, 2021, 12:45pm UTC](https://discuss.elastic.co/t/send-custom-metric-via-metricbeat/284887 "2021-10-04T12:45:28Z")

</div>

We wish to send custom metrics via metricbeat. Specifically we have an integer, which we can get via a command line argument, from a custom program, which we want to send to elastic via Metricbeat. We want to do this, …

---

## [Filebeat 7.12 output.file not working](https://discuss.elastic.co/t/filebeat-7-12-output-file-not-working/285797)

<div class="topic-metadata">

**Author:** [@grazia0912](https://discuss.elastic.co/u/grazia0912)\
**Replies:** 1\
**Last updated:** [October 4, 2021, 9:48am UTC](https://discuss.elastic.co/t/filebeat-7-12-output-file-not-working/285797 "2021-10-04T09:48:29Z")

</div>

Hi, Please advise why this output.file isn't working. I'm on windows and trying to get the events filebeat is sending to my logstash. I don't have access much on the logstash logs and stuff so i'm trying to output the e…

---

## [Filebeat Indexes, Aliases and Errors](https://discuss.elastic.co/t/filebeat-indexes-aliases-and-errors/285769)

<div class="topic-metadata">

**Author:** [@mhare](https://discuss.elastic.co/u/mhare)\
**Replies:** 1\
**Last updated:** [October 3, 2021, 10:05pm UTC](https://discuss.elastic.co/t/filebeat-indexes-aliases-and-errors/285769 "2021-10-03T22:05:26Z")

</div>

I am running ElasticStack 7.13.4 with Filebeat on Windows 10 I am ingesting several types of logs with Filebeat and wanted to put each of them into their own Index. In filebeat I created an input as #-----------------…

---

## [Building metricbeat from source on Mac with no X-Code](https://discuss.elastic.co/t/building-metricbeat-from-source-on-mac-with-no-x-code/285532)

<div class="topic-metadata">

**Author:** [@ss\_22](https://discuss.elastic.co/u/ss_22)\
**Replies:** 3\
**Last updated:** [October 2, 2021, 9:31pm UTC](https://discuss.elastic.co/t/building-metricbeat-from-source-on-mac-with-no-x-code/285532 "2021-10-02T21:31:24Z")

</div>

Hello, I am trying to build the current master branch metricbeat image from source code on my mac (macOS Catalina V10.15.7). I have been following the developer guides. Everything installed and it goes great when I run…

---

## [Fleet Server - \* missing enrollment api key](https://discuss.elastic.co/t/fleet-server-missing-enrollment-api-key/283339)

<div class="topic-metadata">

**Author:** [@bevano](https://discuss.elastic.co/u/bevano)\
**Replies:** 11\
**Last updated:** [October 1, 2021, 5:22pm UTC](https://discuss.elastic.co/t/fleet-server-missing-enrollment-api-key/283339 "2021-10-01T17:22:13Z")

</div>

Hey All, Recently upgraded to 7.14.1 to and am struggling to install fleet server. I am running on-prem and have my self-signed certs setup. Trying to install fleet-server on the same node where elasticsearch is install…

---

## [Grok pattern for IPv6 not working with %{IPORHOST} - Azure Logs - Filebeat 7.14.1](https://discuss.elastic.co/t/grok-pattern-for-ipv6-not-working-with-iporhost-azure-logs-filebeat-7-14-1/285699)

<div class="topic-metadata">

**Author:** [@smandolare](https://discuss.elastic.co/u/smandolare)\
**Replies:** 0\
**Last updated:** [October 1, 2021, 5:09pm UTC](https://discuss.elastic.co/t/grok-pattern-for-ipv6-not-working-with-iporhost-azure-logs-filebeat-7-14-1/285699 "2021-10-01T17:09:11Z")

</div>

Elasticsearch is failing to index events with a 400 error attempting to parse an IPv6 event in the Azure Platform Pipeline: "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[…

---

## [Export file inside pod kubernetes](https://discuss.elastic.co/t/export-file-inside-pod-kubernetes/285668)

<div class="topic-metadata">

**Author:** [@fferraro87](https://discuss.elastic.co/u/fferraro87)\
**Replies:** 0\
**Last updated:** [October 1, 2021, 10:48am UTC](https://discuss.elastic.co/t/export-file-inside-pod-kubernetes/285668 "2021-10-01T10:48:38Z")

</div>

Hi, i'm trying to export some file from pods inside my cluster k8s. now i've that configmap : apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: kube-system labels: k8s-app: filebeat d…

---

## [VSphere Performance Metrics - Metricbeat](https://discuss.elastic.co/t/vsphere-performance-metrics-metricbeat/285665)

<div class="topic-metadata">

**Author:** [@bm.brit](https://discuss.elastic.co/u/bm.brit)\
**Replies:** 0\
**Last updated:** [October 1, 2021, 9:41am UTC](https://discuss.elastic.co/t/vsphere-performance-metrics-metricbeat/285665 "2021-10-01T09:41:24Z")

</div>

Hi, I would like to see IOPS and Total Latency for the Datastore metricset, Throughput and Network like Current Send/Receive KBps, Interface Name of Disk's of the Virtual Host and the same for the Host. I tried the 7.15…

---

## [MySQL metricbeat module error](https://discuss.elastic.co/t/mysql-metricbeat-module-error/285662)

<div class="topic-metadata">

**Author:** [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Replies:** 0\
**Last updated:** [October 1, 2021, 8:43am UTC](https://discuss.elastic.co/t/mysql-metricbeat-module-error/285662 "2021-10-01T08:43:22Z")

</div>

hello ! im trying to use de mysql module of metricbeat but it only works without performance and query. some visualizations work fine but others don't, I guess this occurs because I can't activate performance and qu…

---

## [How does Packetbeat match DNS Queries with Answers?](https://discuss.elastic.co/t/how-does-packetbeat-match-dns-queries-with-answers/285657)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 0\
**Last updated:** [October 1, 2021, 7:39am UTC](https://discuss.elastic.co/t/how-does-packetbeat-match-dns-queries-with-answers/285657 "2021-10-01T07:39:00Z")

</div>

We are maintaining some authoritative DNS resolvers and consider to use Packetbeat / Elasticsearch for statistic generation, alerting and so on. Its very nice that Packetbeat is capable of matching queries with responses…

---

## [Filebeat setup error at kibana](https://discuss.elastic.co/t/filebeat-setup-error-at-kibana/285626)

<div class="topic-metadata">

**Author:** [@vnikh15](https://discuss.elastic.co/u/vnikh15)\
**Replies:** 2\
**Last updated:** [October 1, 2021, 5:28am UTC](https://discuss.elastic.co/t/filebeat-setup-error-at-kibana/285626 "2021-10-01T05:28:28Z")

</div>

Hi Everyone , I am trying to display filebeat\* indices at kibana but the file beat setup is giving below error:- error connecting to kibana: fail to get the kibana version: http get request to h "http://localhost:5601/…

---

## [Trouble Building Metricbeat Cont](https://discuss.elastic.co/t/trouble-building-metricbeat-cont/285638)

<div class="topic-metadata">

**Author:** [@ss\_22](https://discuss.elastic.co/u/ss_22)\
**Replies:** 1\
**Last updated:** [September 30, 2021, 11:42pm UTC](https://discuss.elastic.co/t/trouble-building-metricbeat-cont/285638 "2021-09-30T23:42:15Z")

</div>

Hello, I am trying to build the current master branch metricbeat image from source code on my mac (macOS Catalina V10.15.7). I have been following the developer guides. Everything installed and it goes great when I run…

---

## [One or multiple metricbeat indices?](https://discuss.elastic.co/t/one-or-multiple-metricbeat-indices/285216)

<div class="topic-metadata">

**Author:** [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Replies:** 3\
**Last updated:** [September 30, 2021, 9:45pm UTC](https://discuss.elastic.co/t/one-or-multiple-metricbeat-indices/285216 "2021-09-30T21:45:51Z")

</div>

Hi there. I am installing machines with metricbeat to measure metrics. At the time of implementing it, I have the doubt if it is better to have a single index ({Agent} - {version}) or multiple indexes ({Agent} -{versio…

---

## [Winlogbeat - Sysmon Module and Even.Code: 1 Missing](https://discuss.elastic.co/t/winlogbeat-sysmon-module-and-even-code-1-missing/285620)

<div class="topic-metadata">

**Author:** [@elasticband](https://discuss.elastic.co/u/elasticband)\
**Replies:** 0\
**Last updated:** [September 30, 2021, 5:40pm UTC](https://discuss.elastic.co/t/winlogbeat-sysmon-module-and-even-code-1-missing/285620 "2021-09-30T17:40:53Z")

</div>

I am having a problem with Winlogbeats not sending or not properly parsing all the Sysmon event.code fields. I have been testing beign able to event code: 1 for process creations like "whoami.exe", but when I started to …

---

## [Authentication in elastic agent](https://discuss.elastic.co/t/authentication-in-elastic-agent/284979)

<div class="topic-metadata">

**Author:** [@Paurav\_Thakkar](https://discuss.elastic.co/u/Paurav_Thakkar)\
**Replies:** 2\
**Last updated:** [September 30, 2021, 1:17pm UTC](https://discuss.elastic.co/t/authentication-in-elastic-agent/284979 "2021-09-30T13:17:29Z")

</div>

Hi, I am trying to understand how the authentication is handled in elastic agent for Elasticsearch. just like we have multiple options to configure beats to send data to Elasticsearch by giving api\_key, id/pass or certi…

---

## [Override agent.name, or add custom fields to fleet managed agents?](https://discuss.elastic.co/t/override-agent-name-or-add-custom-fields-to-fleet-managed-agents/285073)

<div class="topic-metadata">

**Author:** [@buzzdeee](https://discuss.elastic.co/u/buzzdeee)\
**Replies:** 3\
**Last updated:** [September 30, 2021, 12:37pm UTC](https://discuss.elastic.co/t/override-agent-name-or-add-custom-fields-to-fleet-managed-agents/285073 "2021-09-30T12:37:43Z")

</div>

Hi, currently I deploy the \*beats with salt, and in the beats config file, I use to set the name: That name: field then in Elasticsearch/kibana shows up as the agent.name in the indices. This allows me easily to fin…

---

## [ECS - Exported fields origin of rsa.foo.\*](https://discuss.elastic.co/t/ecs-exported-fields-origin-of-rsa-foo/285554)

<div class="topic-metadata">

**Author:** [@CamTheMan](https://discuss.elastic.co/u/CamTheMan)\
**Replies:** 1\
**Last updated:** [September 30, 2021, 10:56am UTC](https://discuss.elastic.co/t/ecs-exported-fields-origin-of-rsa-foo/285554 "2021-09-30T10:56:00Z")

</div>

I'm currently implementing 'ECS' for our in house products and I was wondering what the origin or meaning of the 'rsa' fields are? It is unusual in that they span multiple vendors and am wondering what the 'rsa' acronym…

---

## [Metricbeat](https://discuss.elastic.co/t/metricbeat/285124)

<div class="topic-metadata">

**Author:** [@savan820](https://discuss.elastic.co/u/savan820)\
**Replies:** 5\
**Last updated:** [September 30, 2021, 5:31am UTC](https://discuss.elastic.co/t/metricbeat/285124 "2021-09-30T05:31:24Z")

</div>

couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasticsearch at https://localhost:9200: Get "https://localhost:9200": x509: certificate signed by unknown authority\]

---

## [Heartbeat Synthetics/Browser Monitoring Inline Source with expect](https://discuss.elastic.co/t/heartbeat-synthetics-browser-monitoring-inline-source-with-expect/285518)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 2\
**Last updated:** [September 29, 2021, 10:59pm UTC](https://discuss.elastic.co/t/heartbeat-synthetics-browser-monitoring-inline-source-with-expect/285518 "2021-09-29T22:59:58Z")

</div>

Hi All, I'm trying to a browser monitor that checks to make sure a selector doesn't exist after a button is clicked. I'm using the inline source, but am getting an error about expect not being defined: Code: step('Sav…

---

## [Monitoring Veeam Backup Jobs](https://discuss.elastic.co/t/monitoring-veeam-backup-jobs/284401)

<div class="topic-metadata">

**Author:** [@Xabi](https://discuss.elastic.co/u/Xabi)\
**Replies:** 3\
**Last updated:** [September 29, 2021, 9:38pm UTC](https://discuss.elastic.co/t/monitoring-veeam-backup-jobs/284401 "2021-09-29T21:38:52Z")

</div>

Hi guys, I'm interested in monitoring our veem backup jobs. Especially the events related to the execution of jobs. any suggestions?

---

## [Filebeat: error json decode](https://discuss.elastic.co/t/filebeat-error-json-decode/285302)

<div class="topic-metadata">

**Author:** [@mohammed.sabil](https://discuss.elastic.co/u/mohammed.sabil)\
**Replies:** 1\
**Last updated:** [September 29, 2021, 9:37pm UTC](https://discuss.elastic.co/t/filebeat-error-json-decode/285302 "2021-09-29T21:37:47Z")

</div>

Hello Team and @john.akash, Hope you are doing good. I am also trying to push log message data to ES so that I can filter the data and create visualization. Here is my sample log "@timestamp" =\> 2021-09-28T04:51:22.…

---

## [Fortinet module fails to install](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777)

<div class="topic-metadata">

**Author:** [@Gorillabiscuit](https://discuss.elastic.co/u/Gorillabiscuit)\
**Replies:** 8\
**Last updated:** [September 29, 2021, 7:22pm UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777 "2021-09-29T19:22:58Z")

</div>

I inherited an ELK stack and recently upgraded my firewall. We can send syslog to filebeat, which I'm doing, and then filebeat should be sending to ES. When I try and run the filebeat setup -e from the remote server I ge…

---

## [Elastic-agent-control.sock: operation not supported on socket](https://discuss.elastic.co/t/elastic-agent-control-sock-operation-not-supported-on-socket/285101)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 4\
**Last updated:** [September 29, 2021, 4:06pm UTC](https://discuss.elastic.co/t/elastic-agent-control-sock-operation-not-supported-on-socket/285101 "2021-09-29T16:06:01Z")

</div>

Hey there, I have an Elasticsearch and Kibana instance running via Docker images (I have configured the secure option). Now I am trying to install the elastic-agent to start the Fleet Server but I am facing this error: …

---

## [Filebeat stops shipping events under load](https://discuss.elastic.co/t/filebeat-stops-shipping-events-under-load/285409)

<div class="topic-metadata">

**Author:** [@mirzmaster](https://discuss.elastic.co/u/mirzmaster)\
**Replies:** 2\
**Last updated:** [September 29, 2021, 2:27pm UTC](https://discuss.elastic.co/t/filebeat-stops-shipping-events-under-load/285409 "2021-09-29T14:27:01Z")

</div>

I have observed that when Filebeat is shipping container logs which are rapidly growing in size, it reaches some threshold and then just stops shipping events from that logfile. This behaviour was initially suspected to…

---

## [Filebeat stop sending the logs bulk index operations: 400 Bad Request](https://discuss.elastic.co/t/filebeat-stop-sending-the-logs-bulk-index-operations-400-bad-request/285479)

<div class="topic-metadata">

**Author:** [@abhi.logs](https://discuss.elastic.co/u/abhi.logs)\
**Replies:** 0\
**Last updated:** [September 29, 2021, 1:17pm UTC](https://discuss.elastic.co/t/filebeat-stop-sending-the-logs-bulk-index-operations-400-bad-request/285479 "2021-09-29T13:17:19Z")

</div>

Filebeat is not sending logs to elastic host. showing some error ERROR \[publisher\_pipeline\_output\] pipeline/output.go:180 failed to publish events: 400 Bad Request: Collected errors: \*\* Error 0: failed to encode bundle…

---

## [Want to exclude lines in file having "etluser" keyword](https://discuss.elastic.co/t/want-to-exclude-lines-in-file-having-etluser-keyword/284850)

<div class="topic-metadata">

**Author:** [@Amit\_Johari](https://discuss.elastic.co/u/Amit_Johari)\
**Replies:** 9\
**Last updated:** [September 29, 2021, 11:55am UTC](https://discuss.elastic.co/t/want-to-exclude-lines-in-file-having-etluser-keyword/284850 "2021-09-29T11:55:49Z")

</div>

hello team, we want to exclude lines in file having "etluser" keyword. we added this in yml file . Is this correct way to achieve the goal or any other way ? exclude\_lines: \['etluser'\] we have multiple filepath added …

---

## [Is Fleet server able to run synthetic monitoring?](https://discuss.elastic.co/t/is-fleet-server-able-to-run-synthetic-monitoring/285268)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 3\
**Last updated:** [September 29, 2021, 11:40am UTC](https://discuss.elastic.co/t/is-fleet-server-able-to-run-synthetic-monitoring/285268 "2021-09-29T11:40:39Z")

</div>

Hey there, I am trying to use the Fleet server to test the synthetic monitoring feature. Using a Docker-compose I am running a single instance for Elasticsearch Kibana Fleet server I would like to know what is the m…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=128)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=130)
