# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=130

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 131

---

## [Filebeat does not send container logs to elastic cloud](https://discuss.elastic.co/t/filebeat-does-not-send-container-logs-to-elastic-cloud/285461)

<div class="topic-metadata">

**Author:** [@Sharadha\_Krishna](https://discuss.elastic.co/u/Sharadha_Krishna)\
**Replies:** 0\
**Last updated:** [September 29, 2021, 10:10am UTC](https://discuss.elastic.co/t/filebeat-does-not-send-container-logs-to-elastic-cloud/285461 "2021-09-29T10:10:45Z")

</div>

Hi, I have set up log collection from docker containers running on EC2 machines to elastic cloud using file beat. But I don't find the logs on kibana. Note: I have setup my own indexes and ILM and templates. I also fin…

---

## [Does Azure metricbeat module use Consumption API version 2019-10-01](https://discuss.elastic.co/t/does-azure-metricbeat-module-use-consumption-api-version-2019-10-01/285371)

<div class="topic-metadata">

**Author:** [@adhiraj-g](https://discuss.elastic.co/u/adhiraj-g)\
**Replies:** 1\
**Last updated:** [September 29, 2021, 8:40am UTC](https://discuss.elastic.co/t/does-azure-metricbeat-module-use-consumption-api-version-2019-10-01/285371 "2021-09-29T08:40:44Z")

</div>

Hi @MarianaD / @Kaiyan\_Sheng You had mentioned regarding raising an issue for Azure SDK with 2019-10-01 consumption API version. This was the link shared: Provide 2019-10-01 version of consumption APIs · Issue #12452 ·…

---

## [Trouble dissecting characters from a word in a string](https://discuss.elastic.co/t/trouble-dissecting-characters-from-a-word-in-a-string/284924)

<div class="topic-metadata">

**Author:** [@elasticperson](https://discuss.elastic.co/u/elasticperson)\
**Replies:** 3\
**Last updated:** [September 29, 2021, 1:06am UTC](https://discuss.elastic.co/t/trouble-dissecting-characters-from-a-word-in-a-string/284924 "2021-09-29T01:06:45Z")

</div>

Example strings: thing: xabc123def.testing thing: xghi456jkl.testing Given: String will always begin with x there will be 3 alpha characters there will be 3 numeric characters it may or may not have additional chara…

---

## [Filebeats cannot push events to logstash](https://discuss.elastic.co/t/filebeats-cannot-push-events-to-logstash/285249)

<div class="topic-metadata">

**Author:** [@vaclav1](https://discuss.elastic.co/u/vaclav1)\
**Replies:** 5\
**Last updated:** [September 28, 2021, 8:33pm UTC](https://discuss.elastic.co/t/filebeats-cannot-push-events-to-logstash/285249 "2021-09-28T20:33:22Z")

</div>

Dear team, could you please give me a hint what to do? We have all Elasticstack on version 7.9.2 (ELS, Logstash, Filebeats, Kibana). From filebeats towards logstash no TLS is used. Here is the error found in logstash…

---

## [Help with setting up postgresql module on metricbeat with elastic cloud](https://discuss.elastic.co/t/help-with-setting-up-postgresql-module-on-metricbeat-with-elastic-cloud/285361)

<div class="topic-metadata">

**Author:** [@idelix](https://discuss.elastic.co/u/idelix)\
**Replies:** 1\
**Last updated:** [September 28, 2021, 4:16pm UTC](https://discuss.elastic.co/t/help-with-setting-up-postgresql-module-on-metricbeat-with-elastic-cloud/285361 "2021-09-28T16:16:54Z")

</div>

Hello, I did setup postgresql module using metricbeat on linux machine using following guide: and command sudo metricbeat setup -e everything works fine but I'm sending a huge amount of data to elastic cloud which i…

---

## [Metricbeat examples on ECK not working properly](https://discuss.elastic.co/t/metricbeat-examples-on-eck-not-working-properly/285386)

<div class="topic-metadata">

**Author:** [@CHAVE](https://discuss.elastic.co/u/CHAVE)\
**Replies:** 0\
**Last updated:** [September 28, 2021, 3:42pm UTC](https://discuss.elastic.co/t/metricbeat-examples-on-eck-not-working-properly/285386 "2021-09-28T15:42:07Z")

</div>

I'm trying to setup ECK on Google Kubernetes Engine following the quickstart guides on ECK. I'm using the default configuration for Kibana and Metricbeat, and the index metricbeat-\* exists on my Elasticsearch cluster. Ho…

---

## [Filebeat: Unable to create dynamic Kafka topic name using Kubernetes metadata](https://discuss.elastic.co/t/filebeat-unable-to-create-dynamic-kafka-topic-name-using-kubernetes-metadata/285316)

<div class="topic-metadata">

**Author:** [@arunporwal](https://discuss.elastic.co/u/arunporwal)\
**Replies:** 1\
**Last updated:** [September 28, 2021, 8:04am UTC](https://discuss.elastic.co/t/filebeat-unable-to-create-dynamic-kafka-topic-name-using-kubernetes-metadata/285316 "2021-09-28T08:04:16Z")

</div>

I am trying to push Kubernetes logs to the Kafka cluster but while pushing logs I want to create a dynamic topic for all the corresponding Kubernetes namespaces. I am using the below configuration but getting errors whi…

---

## [Monitoring Process in Windows](https://discuss.elastic.co/t/monitoring-process-in-windows/285291)

<div class="topic-metadata">

**Author:** [@bevano](https://discuss.elastic.co/u/bevano)\
**Replies:** 2\
**Last updated:** [September 28, 2021, 1:46am UTC](https://discuss.elastic.co/t/monitoring-process-in-windows/285291 "2021-09-28T01:46:18Z")

</div>

Hi All, Currently trying to figure out how to monitor whether a Windows application is Up or Down. Currently using a filter to narrow down it to a specific agent.name (My Server) and process.name (application name) and…

---

## [Multiple elk stack structure](https://discuss.elastic.co/t/multiple-elk-stack-structure/285223)

<div class="topic-metadata">

**Author:** [@escking](https://discuss.elastic.co/u/escking)\
**Replies:** 0\
**Last updated:** [September 27, 2021, 11:41am UTC](https://discuss.elastic.co/t/multiple-elk-stack-structure/285223 "2021-09-27T11:41:08Z")

</div>

Hi all, I have a cluster about elastic stack using kafka connector . I want to migrate to kubernetes infrastructure to provide high availability. So my filebeat's output must send to data other kafka connector. Is it po…

---

## [Using Multiline for individual/specific Modules](https://discuss.elastic.co/t/using-multiline-for-individual-specific-modules/285264)

<div class="topic-metadata">

**Author:** [@User001](https://discuss.elastic.co/u/User001)\
**Replies:** 0\
**Last updated:** [September 27, 2021, 5:47pm UTC](https://discuss.elastic.co/t/using-multiline-for-individual-specific-modules/285264 "2021-09-27T17:47:39Z")

</div>

Hello, I am curious if you can set/override the multiline parameters within individual modules. I am trying to use a commonly configured filebeat instance within a larger project, of which, they currently and/or may not…

---

## [Filebeat slows down as registry file grows](https://discuss.elastic.co/t/filebeat-slows-down-as-registry-file-grows/284903)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 2\
**Last updated:** [September 27, 2021, 4:22pm UTC](https://discuss.elastic.co/t/filebeat-slows-down-as-registry-file-grows/284903 "2021-09-27T16:22:40Z")

</div>

Filebeat version: 7.9.2 OS: Ubuntu 18.04.5 LTS VM: 16 CPU, 64 GB RAM Output: Kafka I have an issue with Filebeat's throughput. There are about 600 files are created every minute and those have around 4000 lines in th…

---

## [Packetbeat "dropping event, queue is blocked (seq=0)"](https://discuss.elastic.co/t/packetbeat-dropping-event-queue-is-blocked-seq-0/285219)

<div class="topic-metadata">

**Author:** [@guido.lamoto](https://discuss.elastic.co/u/guido.lamoto)\
**Replies:** 0\
**Last updated:** [September 27, 2021, 10:18am UTC](https://discuss.elastic.co/t/packetbeat-dropping-event-queue-is-blocked-seq-0/285219 "2021-09-27T10:18:54Z")

</div>

We have a Packetbeat 7.15.0 on Ubuntu 20.04 directly connected to a Debian 10 with Elasticsearch 7.14.1. Packetbeat is running on a a DNS server with an average of 4000 queries/s. This is the configuration file: packet…

---

## [How to build beats excluding unwanted modules?](https://discuss.elastic.co/t/how-to-build-beats-excluding-unwanted-modules/285199)

<div class="topic-metadata">

**Author:** [@8e6d5b4d49f69e9edb4c](https://discuss.elastic.co/u/8e6d5b4d49f69e9edb4c)\
**Replies:** 0\
**Last updated:** [September 27, 2021, 7:52am UTC](https://discuss.elastic.co/t/how-to-build-beats-excluding-unwanted-modules/285199 "2021-09-27T07:52:42Z")

</div>

Continuing the discussion from Beats for embedded devices?: I want to use Filebeat on an embedded device where disk is limited. Linked topic is the answer of my question, but outdated. I'm looking for how to build min…

---

## [Aws multi account metric beat setup](https://discuss.elastic.co/t/aws-multi-account-metric-beat-setup/283925)

<div class="topic-metadata">

**Author:** [@sinto](https://discuss.elastic.co/u/sinto)\
**Replies:** 2\
**Last updated:** [September 27, 2021, 7:20am UTC](https://discuss.elastic.co/t/aws-multi-account-metric-beat-setup/283925 "2021-09-27T07:20:24Z")

</div>

Hi Team, Is there any way I can achieve one metricbeat.yml configuration to fetch aws cloudwatch metrics from multiple aws account and each account need seperate indexes something like like metrics-cloud-\[Account-Number…

---

## [After implementation all beats data not showing in discover](https://discuss.elastic.co/t/after-implementation-all-beats-data-not-showing-in-discover/285187)

<div class="topic-metadata">

**Author:** [@savan820](https://discuss.elastic.co/u/savan820)\
**Replies:** 2\
**Last updated:** [September 27, 2021, 4:04am UTC](https://discuss.elastic.co/t/after-implementation-all-beats-data-not-showing-in-discover/285187 "2021-09-27T04:04:38Z")

</div>

when we configured SSL and TLS my all beats output is not showing in discovered. kindly give me the resolution.

---

## [Filebeat module Juniper SRX](https://discuss.elastic.co/t/filebeat-module-juniper-srx/285172)

<div class="topic-metadata">

**Author:** [@jam\_mahmoudi](https://discuss.elastic.co/u/jam_mahmoudi)\
**Replies:** 0\
**Last updated:** [September 26, 2021, 4:08pm UTC](https://discuss.elastic.co/t/filebeat-module-juniper-srx/285172 "2021-09-26T16:08:09Z")

</div>

Hi. guys For using filebeat module juniper what scenario do I need ? 1- should I send all logs to independent server that has filebaet installed? HOW ? 2- how can I use filebeat module Juniper ? 3-. I have two…

---

## [Attempting to start Fleet Server fails](https://discuss.elastic.co/t/attempting-to-start-fleet-server-fails/282859)

<div class="topic-metadata">

**Author:** [@Aiden\_Mitchell](https://discuss.elastic.co/u/Aiden_Mitchell)\
**Replies:** 5\
**Last updated:** [September 26, 2021, 6:13pm UTC](https://discuss.elastic.co/t/attempting-to-start-fleet-server-fails/282859 "2021-09-26T18:13:03Z")

</div>

Hi there! I'm trying to install Fleet Server using the Quick Start deployment mode on an Ubuntu 20.04 instance and it's failing: 2021-08-30T22:47:54.988Z INFO cmd/enroll\_cmd.go:354 Generating self-signed ce…

---

## [Filebeat unable to connect logstash server](https://discuss.elastic.co/t/filebeat-unable-to-connect-logstash-server/285137)

<div class="topic-metadata">

**Author:** [@prat](https://discuss.elastic.co/u/prat)\
**Replies:** 23\
**Last updated:** [September 26, 2021, 12:43pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-connect-logstash-server/285137 "2021-09-26T12:43:42Z")

</div>

Hi Team, I have installed filebeat on a server which is having IP as 192.168.x.x and filebeat is trying to send events to two logstash servers which are having IPs as 10.20.x.x. Currently i see filebeat service is fai…

---

## [Characters coming in non-readable format in ES after sending from filebeat\>logstash\>ES](https://discuss.elastic.co/t/characters-coming-in-non-readable-format-in-es-after-sending-from-filebeat-logstash-es/284645)

<div class="topic-metadata">

**Author:** [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Replies:** 1\
**Last updated:** [September 24, 2021, 12:51pm UTC](https://discuss.elastic.co/t/characters-coming-in-non-readable-format-in-es-after-sending-from-filebeat-logstash-es/284645 "2021-09-24T12:51:01Z")

</div>

Hi Team, Im tring to get .log files from linux servers to ES using filebeat, logstash and then to ES however when it reaches ES, below is the outcome Y\\xD9\\xE7IU\\xC8JC\\xD5\\u000FW\\x8EC'\\x95j\\x8A\\x86\\xC4kRm\\xABFݯ\\x87C\\u0…

---

## [Osquerybeat standalone without elastic-agent?](https://discuss.elastic.co/t/osquerybeat-standalone-without-elastic-agent/284872)

<div class="topic-metadata">

**Author:** [@buzzdeee](https://discuss.elastic.co/u/buzzdeee)\
**Replies:** 5\
**Last updated:** [September 24, 2021, 12:02pm UTC](https://discuss.elastic.co/t/osquerybeat-standalone-without-elastic-agent/284872 "2021-09-24T12:02:51Z")

</div>

Hi, I'm currently using various \*beats deployed to servers and clients. For a number of reasons, I have my beats output to logstash, before they are sent to Elasticsearch. I'm evaluating elastic-agent, to at least repla…

---

## [Alternative to SQS queue for AWS log ingest](https://discuss.elastic.co/t/alternative-to-sqs-queue-for-aws-log-ingest/284911)

<div class="topic-metadata">

**Author:** [@kbirhan](https://discuss.elastic.co/u/kbirhan)\
**Replies:** 3\
**Last updated:** [September 24, 2021, 11:56am UTC](https://discuss.elastic.co/t/alternative-to-sqs-queue-for-aws-log-ingest/284911 "2021-09-24T11:56:26Z")

</div>

The documentation for the AWS module states "It uses filebeat s3 input to get log files from AWS S3 buckets with SQS notification or directly polling list of S3 objects in an S3 bucket. The use of SQS notification is pre…

---

## [Logstash metricbeat monitoring issue](https://discuss.elastic.co/t/logstash-metricbeat-monitoring-issue/285064)

<div class="topic-metadata">

**Author:** [@jalaine](https://discuss.elastic.co/u/jalaine)\
**Replies:** 0\
**Last updated:** [September 24, 2021, 9:27am UTC](https://discuss.elastic.co/t/logstash-metricbeat-monitoring-issue/285064 "2021-09-24T09:27:03Z")

</div>

Good Morning, I have kind of a strange use case, and am hoping someone might be able to help me out. I have a monitoring cluster and a production cluster. It is a strange contractual issue, but we want the customer to h…

---

## [Auditbeat on docker fails to run auditd module](https://discuss.elastic.co/t/auditbeat-on-docker-fails-to-run-auditd-module/284399)

<div class="topic-metadata">

**Author:** [@MarshalHex](https://discuss.elastic.co/u/MarshalHex)\
**Replies:** 16\
**Last updated:** [September 24, 2021, 8:58am UTC](https://discuss.elastic.co/t/auditbeat-on-docker-fails-to-run-auditd-module/284399 "2021-09-24T08:58:20Z")

</div>

Hi! I'm setting up Auditbeat to run on amazon linux EC2 instance. When I run the default install and config for auditbeat, everything works fine for auditbeat auditd module and I can configure my rules to be implemente…

---

## [Exiting: Failed to create Beat meta file: open /usr/share/heartbeat/data/meta.json.new: permission denied](https://discuss.elastic.co/t/exiting-failed-to-create-beat-meta-file-open-usr-share-heartbeat-data-meta-json-new-permission-denied/284717)

<div class="topic-metadata">

**Author:** [@WookWook](https://discuss.elastic.co/u/WookWook)\
**Replies:** 3\
**Last updated:** [September 24, 2021, 7:57am UTC](https://discuss.elastic.co/t/exiting-failed-to-create-beat-meta-file-open-usr-share-heartbeat-data-meta-json-new-permission-denied/284717 "2021-09-24T07:57:15Z")

</div>

I setup Elastic Cloud on Kubernetes on Openshift 4.6. Right now with the following services (Elasticsearch/Kibana/Filebeat) I am now failing to get Heartbeat running. I had it running on another Testcluster without any …

---

## [Metricbeat not getting the Logstash Containers](https://discuss.elastic.co/t/metricbeat-not-getting-the-logstash-containers/285045)

<div class="topic-metadata">

**Author:** [@ajcb](https://discuss.elastic.co/u/ajcb)\
**Replies:** 0\
**Last updated:** [September 24, 2021, 3:44am UTC](https://discuss.elastic.co/t/metricbeat-not-getting-the-logstash-containers/285045 "2021-09-24T03:44:14Z")

</div>

So I deployed metricbeat on an ECS cluster, in the "Number of Containers" visualization in the default Docker dashboard, it says 15 running. but in the "Docker Containers" visualization, the containers aren't 15, when I …

---

## [Packetbeat tls capture does not have server.bytes and source.bytes?](https://discuss.elastic.co/t/packetbeat-tls-capture-does-not-have-server-bytes-and-source-bytes/285044)

<div class="topic-metadata">

**Author:** [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Replies:** 0\
**Last updated:** [September 24, 2021, 3:13am UTC](https://discuss.elastic.co/t/packetbeat-tls-capture-does-not-have-server-bytes-and-source-bytes/285044 "2021-09-24T03:13:07Z")

</div>

Hi All, packetbeat when capturing http, there are source.bytes and server.bytes Is there a way to get that for https as well? Regards, Michael

---

## [Failed to connect to backoff](https://discuss.elastic.co/t/failed-to-connect-to-backoff/284922)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 4\
**Last updated:** [September 24, 2021, 2:20am UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff/284922 "2021-09-24T02:20:02Z")

</div>

I set up minimum and basic TLS security for the Elasticsearch cluster. The metricbeat cannot push data to the Elasticsearch node. Here is the error in log file. metricbeat\[26335\]: 2021-09-22T18:08:39.471Z ERROR \[publish…

---

## [Elastic Agent on Ubuntu 14.04 constantly updating, never makes a connection](https://discuss.elastic.co/t/elastic-agent-on-ubuntu-14-04-constantly-updating-never-makes-a-connection/285036)

<div class="topic-metadata">

**Author:** [@robrien](https://discuss.elastic.co/u/robrien)\
**Replies:** 1\
**Last updated:** [September 23, 2021, 11:50pm UTC](https://discuss.elastic.co/t/elastic-agent-on-ubuntu-14-04-constantly-updating-never-makes-a-connection/285036 "2021-09-23T23:50:40Z")

</div>

I have a server I am unable to get the elastic agent to run on. When running the elastic-agent commands I am not finding much relevant in my searches. Error: failed to communicate with Elastic Agent daemon: rpc error: …

---

## [No Release Notes for Fleet or Elastic Agent for 7.14.2 or 7.15](https://discuss.elastic.co/t/no-release-notes-for-fleet-or-elastic-agent-for-7-14-2-or-7-15/285008)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 4\
**Last updated:** [September 23, 2021, 11:30pm UTC](https://discuss.elastic.co/t/no-release-notes-for-fleet-or-elastic-agent-for-7-14-2-or-7-15/285008 "2021-09-23T23:30:57Z")

</div>

Hi All, I noticed there are only release notes for 7.14.0 and 7.14.1 under the release notes section. Am I missing an area where I can find release notes for the newer versions of Fleet and Elastic Agent?

---

## [Filebeat modules config: failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/filebeat-modules-config-failed-to-publish-events-temporary-bulk-send-failure/284948)

<div class="topic-metadata">

**Author:** [@cdalexndr](https://discuss.elastic.co/u/cdalexndr)\
**Replies:** 3\
**Last updated:** [September 23, 2021, 4:06pm UTC](https://discuss.elastic.co/t/filebeat-modules-config-failed-to-publish-events-temporary-bulk-send-failure/284948 "2021-09-23T16:06:07Z")

</div>

Just upgraded elastic stack from 7.10.1 to 7.14.1, and now filebeat doesn't work! Filebeat logs repeats the following lines: filebeat | 2021-09-22T21:57:46.145Z INFO \[esclientleg\] eslegclient/connecti…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=129)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=131)
