# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=131

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 132

---

## [Filebeat output to existing index](https://discuss.elastic.co/t/filebeat-output-to-existing-index/284329)

<div class="topic-metadata">

**Author:** [@caraboy](https://discuss.elastic.co/u/caraboy)\
**Replies:** 6\
**Last updated:** [September 23, 2021, 12:47pm UTC](https://discuss.elastic.co/t/filebeat-output-to-existing-index/284329 "2021-09-23T12:47:30Z")

</div>

Hi everyone, I'm trying to configure a filebeat output to an existing index but apparently i can't correctly set the template name and pattern. output.elasticsearch.index: "sai5x" setup.template.name: "sai5x" setup.tem…

---

## [Allow winlogbeat to use more processing power](https://discuss.elastic.co/t/allow-winlogbeat-to-use-more-processing-power/284996)

<div class="topic-metadata">

**Author:** [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Replies:** 0\
**Last updated:** [September 23, 2021, 11:24am UTC](https://discuss.elastic.co/t/allow-winlogbeat-to-use-more-processing-power/284996 "2021-09-23T11:24:10Z")

</div>

Hi, is there a setting to allow winlogbeat to use more CPU resources? We are currently testing a config file with about 1700 lines of filtering. We also have another config file with less filtering (about 300) currently…

---

## [Failed to query metric data from kibana](https://discuss.elastic.co/t/failed-to-query-metric-data-from-kibana/284598)

<div class="topic-metadata">

**Author:** [@nehasinha1807](https://discuss.elastic.co/u/nehasinha1807)\
**Replies:** 1\
**Last updated:** [September 23, 2021, 10:13am UTC](https://discuss.elastic.co/t/failed-to-query-metric-data-from-kibana/284598 "2021-09-23T10:13:44Z")

</div>

I deployed ELK Lite and metricbeat on linux in order to observe metrics for my application. but when I open kibana UI and click metric, it shows this error: Error while fetching resource Error Internal Server Error (5…

---

## [Understand the use of certificate requirements while adding a New Agent](https://discuss.elastic.co/t/understand-the-use-of-certificate-requirements-while-adding-a-new-agent/284981)

<div class="topic-metadata">

**Author:** [@Mann\_Mehta](https://discuss.elastic.co/u/Mann_Mehta)\
**Replies:** 0\
**Last updated:** [September 23, 2021, 9:30am UTC](https://discuss.elastic.co/t/understand-the-use-of-certificate-requirements-while-adding-a-new-agent/284981 "2021-09-23T09:30:02Z")

</div>

Here we see, in the production deployment it provide the certificate-based configuration command. Wanted to understand the use of certificate authorities, ES certificate, fleet server certificate, and fleet server ce…

---

## [How to filter in filebeat yml file](https://discuss.elastic.co/t/how-to-filter-in-filebeat-yml-file/284978)

<div class="topic-metadata">

**Author:** [@bae\_park](https://discuss.elastic.co/u/bae_park)\
**Replies:** 0\
**Last updated:** [September 23, 2021, 9:25am UTC](https://discuss.elastic.co/t/how-to-filter-in-filebeat-yml-file/284978 "2021-09-23T09:25:07Z")

</div>

While using kafka input, I want to output only when json data contains a specific string. I tried setting "include\_lines" in filebeat.yml, but it was not filtered properly. When the filebit.yml setting is as follows an…

---

## [Filebeat installed on EulerOS server and trying to start the service but its failing. Please advise](https://discuss.elastic.co/t/filebeat-installed-on-euleros-server-and-trying-to-start-the-service-but-its-failing-please-advise/283427)

<div class="topic-metadata">

**Author:** [@Amit\_Johari](https://discuss.elastic.co/u/Amit_Johari)\
**Replies:** 4\
**Last updated:** [September 23, 2021, 8:50am UTC](https://discuss.elastic.co/t/filebeat-installed-on-euleros-server-and-trying-to-start-the-service-but-its-failing-please-advise/283427 "2021-09-23T08:50:25Z")

</div>

OS version: EulerOS release 2.0 (SP8) ARCH: Linux HOBB14-RK01-PROD-CN-01 4.19.36-vhulk1905.1.0.h276.eulerosv2r8.aarch64 #1 SMP Mon Apr 1 00:00:00 UTC 2019 aarch64 aarch64 aarch64 GNU/Linux Error: \[root@HOBB14-RK01-PRO…

---

## [Pulling data from a statsd server](https://discuss.elastic.co/t/pulling-data-from-a-statsd-server/284625)

<div class="topic-metadata">

**Author:** [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Replies:** 2\
**Last updated:** [September 23, 2021, 7:39am UTC](https://discuss.elastic.co/t/pulling-data-from-a-statsd-server/284625 "2021-09-23T07:39:45Z")

</div>

Hi, I need to pull data from a statsd server,whats the best approach to do this? Im trying to import the statsd metrics from a spark jobs using metricbeats but metricbeat is getting the following error ... spark-5a9…

---

## [Filebeat-json.log size and rotation](https://discuss.elastic.co/t/filebeat-json-log-size-and-rotation/283773)

<div class="topic-metadata">

**Author:** [@greggailly](https://discuss.elastic.co/u/greggailly)\
**Replies:** 3\
**Last updated:** [September 23, 2021, 6:56am UTC](https://discuss.elastic.co/t/filebeat-json-log-size-and-rotation/283773 "2021-09-23T06:56:13Z")

</div>

We are having size issues with the filebeat-json.log file. One of our servers had one 122gb filebeat-json.log, are they not supposed to rotate to prevent this ? All of our servers run windows server 2016/2019 and elast…

---

## [Understanding the role of elastic agent processes running in my local system](https://discuss.elastic.co/t/understanding-the-role-of-elastic-agent-processes-running-in-my-local-system/284961)

<div class="topic-metadata">

**Author:** [@Mann\_Mehta](https://discuss.elastic.co/u/Mann_Mehta)\
**Replies:** 1\
**Last updated:** [September 23, 2021, 6:00am UTC](https://discuss.elastic.co/t/understanding-the-role-of-elastic-agent-processes-running-in-my-local-system/284961 "2021-09-23T06:00:00Z")

</div>

After enrolling the elastic agent into my local machine, I see several processes running like elastic\_agent.exe, filebeat.exe, metricbeat.exe etc. I want to know the role of this process in much more detail? Which comm…

---

## [Elastic Agent and Fleet Server Communication](https://discuss.elastic.co/t/elastic-agent-and-fleet-server-communication/284823)

<div class="topic-metadata">

**Author:** [@Mann\_Mehta](https://discuss.elastic.co/u/Mann_Mehta)\
**Replies:** 0\
**Last updated:** [September 22, 2021, 9:06am UTC](https://discuss.elastic.co/t/elastic-agent-and-fleet-server-communication/284823 "2021-09-22T09:06:22Z")

</div>

Need a deeper understanding of how authentication workflow is implemented during the first time installation of elastic agent and how the communication of elastic agent with the fleet server is organized. I have gone th…

---

## [Using Metricbeat AWS Module on Private Subnet EC2](https://discuss.elastic.co/t/using-metricbeat-aws-module-on-private-subnet-ec2/283676)

<div class="topic-metadata">

**Author:** [@roh](https://discuss.elastic.co/u/roh)\
**Replies:** 6\
**Last updated:** [September 23, 2021, 12:36am UTC](https://discuss.elastic.co/t/using-metricbeat-aws-module-on-private-subnet-ec2/283676 "2021-09-23T00:36:06Z")

</div>

Hi all! My client wants to collect ec2, ebs, rds metrics using Metricbeat on private subnet ec2 instance with AWS module. So I searched for ways to do it. Judging by document, there are common services to reach like IA…

---

## [Url.query field loss occurred when useing iis module (ver 7.14.1)](https://discuss.elastic.co/t/url-query-field-loss-occurred-when-useing-iis-module-ver-7-14-1/284926)

<div class="topic-metadata">

**Author:** [@e997cd7e8d9915436150](https://discuss.elastic.co/u/e997cd7e8d9915436150)\
**Replies:** 0\
**Last updated:** [September 22, 2021, 6:27pm UTC](https://discuss.elastic.co/t/url-query-field-loss-occurred-when-useing-iis-module-ver-7-14-1/284926 "2021-09-22T18:27:14Z")

</div>

Actual url parameters are 7,757 out of 215,586 pieces of log. (exclude log header) But i can see only 7,735 pieces of parameters after gathered by iis module. I guess there is a problem in the process of deleti…

---

## [Custom log collection](https://discuss.elastic.co/t/custom-log-collection/284403)

<div class="topic-metadata">

**Author:** [@Naveen\_Kumar\_Reddy\_S](https://discuss.elastic.co/u/Naveen_Kumar_Reddy_S)\
**Replies:** 2\
**Last updated:** [September 22, 2021, 2:12pm UTC](https://discuss.elastic.co/t/custom-log-collection/284403 "2021-09-22T14:12:10Z")

</div>

How to collect the following information (process, network, metric and Sysmon ) using single agent OR any beat that can collect these information and main thing the output has to be sent to Logstash or ingest pipeline n…

---

## [Migrating Beats to Fleet and Elastic Agent via Puppet](https://discuss.elastic.co/t/migrating-beats-to-fleet-and-elastic-agent-via-puppet/284732)

<div class="topic-metadata">

**Author:** [@maltewhiite](https://discuss.elastic.co/u/maltewhiite)\
**Replies:** 2\
**Last updated:** [September 22, 2021, 12:42pm UTC](https://discuss.elastic.co/t/migrating-beats-to-fleet-and-elastic-agent-via-puppet/284732 "2021-09-22T12:42:49Z")

</div>

Hello We manage everything Elastic via Puppet. That means Beats, Kibana, etc. How do we migrate from Beats to Fleet, with Puppet? Is there even a way to Configure Fleet via Puppet yet? All I can find, are guides that…

---

## [How to make multiline to work when deploy filebeat to openshift 3.11](https://discuss.elastic.co/t/how-to-make-multiline-to-work-when-deploy-filebeat-to-openshift-3-11/284858)

<div class="topic-metadata">

**Author:** [@lsy1990](https://discuss.elastic.co/u/lsy1990)\
**Replies:** 0\
**Last updated:** [September 22, 2021, 11:30am UTC](https://discuss.elastic.co/t/how-to-make-multiline-to-work-when-deploy-filebeat-to-openshift-3-11/284858 "2021-09-22T11:30:46Z")

</div>

I deploy filebeat to openshift 3.11. the log is json format like this : {"log":"W0922 10:48:03.257983 1 reflector.go:341\] github.com/kubernetes-incubator/external-storage/lib/controller/controller.go:668: watch of \*v1.…

---

## [Need to gather the host logs , filebeat running as a container](https://discuss.elastic.co/t/need-to-gather-the-host-logs-filebeat-running-as-a-container/284000)

<div class="topic-metadata">

**Author:** [@mohammed.sabil](https://discuss.elastic.co/u/mohammed.sabil)\
**Replies:** 12\
**Last updated:** [September 22, 2021, 10:44am UTC](https://discuss.elastic.co/t/need-to-gather-the-host-logs-filebeat-running-as-a-container/284000 "2021-09-22T10:44:40Z")

</div>

Hello Team, I am new to ELK and Filebeat. I have ELK stack running on one server using docker-compose. I have Filebeat running on another server as docker container 7.14.1. I have configured filebeat-docker.yml and I…

---

## [Unable to discard hostfs/etc/sv/monit/.kube/ path on my PKS environment](https://discuss.elastic.co/t/unable-to-discard-hostfs-etc-sv-monit-kube-path-on-my-pks-environment/284843)

<div class="topic-metadata">

**Author:** [@oguz\_y](https://discuss.elastic.co/u/oguz_y)\
**Replies:** 0\
**Last updated:** [September 22, 2021, 10:07am UTC](https://discuss.elastic.co/t/unable-to-discard-hostfs-etc-sv-monit-kube-path-on-my-pks-environment/284843 "2021-09-22T10:07:04Z")

</div>

I am using Pivotal Kubernetes clusters on vmware and collecting logs on Splunk. I installed auditbeat and tried to exclude hostfs/etc/sv/monit/.kube/ path but never managed to discard it at file\_integrity module. I tried…

---

## [How to index a .json file located inside a persistent volume on a kubernetes cluster to Elasticsearch](https://discuss.elastic.co/t/how-to-index-a-json-file-located-inside-a-persistent-volume-on-a-kubernetes-cluster-to-elasticsearch/284830)

<div class="topic-metadata">

**Author:** [@Jad\_Sakr](https://discuss.elastic.co/u/Jad_Sakr)\
**Replies:** 2\
**Last updated:** [September 22, 2021, 9:53am UTC](https://discuss.elastic.co/t/how-to-index-a-json-file-located-inside-a-persistent-volume-on-a-kubernetes-cluster-to-elasticsearch/284830 "2021-09-22T09:53:33Z")

</div>

I have a code that collects data and dumps it in a .json file. In this file, every line is a json object. I was following this guide https://www.elastic.co/guide/en/cloud-on-k8s/current/index.html to run Elastic on kube…

---

## [Copy value of @timestamp to another field](https://discuss.elastic.co/t/copy-value-of-timestamp-to-another-field/284634)

<div class="topic-metadata">

**Author:** [@mostpha456](https://discuss.elastic.co/u/mostpha456)\
**Replies:** 4\
**Last updated:** [September 22, 2021, 9:26am UTC](https://discuss.elastic.co/t/copy-value-of-timestamp-to-another-field/284634 "2021-09-22T09:26:03Z")

</div>

Hello, I am trying to copy the value of @timestamp to new field timestamp keeping the same format. Is that possible ? Do you have any suggestion ? Thank you. Mustapha

---

## [Are Elastic Beats capable enough to ingest data into Splunk?](https://discuss.elastic.co/t/are-elastic-beats-capable-enough-to-ingest-data-into-splunk/284804)

<div class="topic-metadata">

**Author:** [@spzala](https://discuss.elastic.co/u/spzala)\
**Replies:** 2\
**Last updated:** [September 22, 2021, 6:02am UTC](https://discuss.elastic.co/t/are-elastic-beats-capable-enough-to-ingest-data-into-splunk/284804 "2021-09-22T06:02:37Z")

</div>

Hey, Currently, We are using various beats to ingest data into our Elasticsearch. But now, we also encountered a use case in which we need to ingest data into Splunk using the same beats. Is it doable? If yes then can s…

---

## [Settings for logging.files for reading from dir then delete files once read](https://discuss.elastic.co/t/settings-for-logging-files-for-reading-from-dir-then-delete-files-once-read/284737)

<div class="topic-metadata">

**Author:** [@robnew](https://discuss.elastic.co/u/robnew)\
**Replies:** 1\
**Last updated:** [September 21, 2021, 10:28pm UTC](https://discuss.elastic.co/t/settings-for-logging-files-for-reading-from-dir-then-delete-files-once-read/284737 "2021-09-21T22:28:54Z")

</div>

I want to use Filebeat to read from a directory to ingest the log files, then to delete (sinkhole) the files once read and ingested into Elasticsearch. Is this achievable with Filebeat?

---

## [Where I can find Journalbeat in Kibana?](https://discuss.elastic.co/t/where-i-can-find-journalbeat-in-kibana/284544)

<div class="topic-metadata">

**Author:** [@abhi.logs](https://discuss.elastic.co/u/abhi.logs)\
**Replies:** 8\
**Last updated:** [September 21, 2021, 9:34pm UTC](https://discuss.elastic.co/t/where-i-can-find-journalbeat-in-kibana/284544 "2021-09-21T21:34:38Z")

</div>

Hello, I'm trying to identify journalbeat in Kibana. Where I'll get journalbeat information in Kibana dashboard? Can anyone help me ?

---

## [Filebeats does not create custom-named indices and hangs if ILM is disabled](https://discuss.elastic.co/t/filebeats-does-not-create-custom-named-indices-and-hangs-if-ilm-is-disabled/283894)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 3\
**Last updated:** [September 21, 2021, 8:40pm UTC](https://discuss.elastic.co/t/filebeats-does-not-create-custom-named-indices-and-hangs-if-ilm-is-disabled/283894 "2021-09-21T20:40:51Z")

</div>

All details and code snippets are included into the SO post: elasticsearch - Elastic Filebeat does not index into custom indices with mappings - Stack Overflow Below is the summary with the latest updates: I am trying …

---

## [Filebeat configuration log file path won't load](https://discuss.elastic.co/t/filebeat-configuration-log-file-path-wont-load/284720)

<div class="topic-metadata">

**Author:** [@Vincent001](https://discuss.elastic.co/u/Vincent001)\
**Replies:** 0\
**Last updated:** [September 21, 2021, 12:14pm UTC](https://discuss.elastic.co/t/filebeat-configuration-log-file-path-wont-load/284720 "2021-09-21T12:14:21Z")

</div>

Hello, I have a custom configuration for filebeat for logging: logging.level: warning logging.to\_files: true logging.files: path: /var/log/filebeat/ name: filebeatVdpQueries keepfiles: 7 permissions: 0644 But …

---

## [How to Convert array fields from beats to compatible array fields of Splunk HEC input viai Logstash](https://discuss.elastic.co/t/how-to-convert-array-fields-from-beats-to-compatible-array-fields-of-splunk-hec-input-viai-logstash/284683)

<div class="topic-metadata">

**Author:** [@sibiv196](https://discuss.elastic.co/u/sibiv196)\
**Replies:** 0\
**Last updated:** [September 21, 2021, 6:33am UTC](https://discuss.elastic.co/t/how-to-convert-array-fields-from-beats-to-compatible-array-fields-of-splunk-hec-input-viai-logstash/284683 "2021-09-21T06:33:46Z")

</div>

This is the logstash output to splunk HEC input event endpoint. "fields":"{\\"netcool\_fields\_community\\":\\"AGENT\_HB\\",\\"metric\_name:status\\":1}"}" I am not sure what is failing . Events are not getting indexed to metric…

---

## [Default Nginx access log pipeline does not process all user-agents from Logs](https://discuss.elastic.co/t/default-nginx-access-log-pipeline-does-not-process-all-user-agents-from-logs/284488)

<div class="topic-metadata">

**Author:** [@Nishad\_Angre](https://discuss.elastic.co/u/Nishad_Angre)\
**Replies:** 0\
**Last updated:** [September 17, 2021, 1:47pm UTC](https://discuss.elastic.co/t/default-nginx-access-log-pipeline-does-not-process-all-user-agents-from-logs/284488 "2021-09-17T13:47:10Z")

</div>

Hi, I have configured a Nginx access log with filebeat using default pipeline. I am using elasticsearch version 7.14.1 This pipeline however does not parse all the user-agents which come from nginx logs. PFB few examp…

---

## [Best practice for JSON logging (e.g. timestamp processing)](https://discuss.elastic.co/t/best-practice-for-json-logging-e-g-timestamp-processing/284472)

<div class="topic-metadata">

**Author:** [@crazylogging](https://discuss.elastic.co/u/crazylogging)\
**Replies:** 2\
**Last updated:** [September 21, 2021, 1:04am UTC](https://discuss.elastic.co/t/best-practice-for-json-logging-e-g-timestamp-processing/284472 "2021-09-21T01:04:59Z")

</div>

Hi, I'm quite new to the elastic stack so please excuse the question if it doesn't make any sense. I've got an application (let's call it JBoss) which runs in a docker container (all components in my scenario do so) an…

---

## [Heartbeat - Synthetics/Browser Monitor get TLS Certificate Information](https://discuss.elastic.co/t/heartbeat-synthetics-browser-monitor-get-tls-certificate-information/284629)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 2\
**Last updated:** [September 20, 2021, 4:41pm UTC](https://discuss.elastic.co/t/heartbeat-synthetics-browser-monitor-get-tls-certificate-information/284629 "2021-09-20T16:41:07Z")

</div>

Hi All, I was wondering if there is a way to get the Synthetic/Browser monitor of Heartbeat to collect the TLS Certificate information against the initial URL. Currently, when setting up a Browser monitor, I also need …

---

## [Heartbeat http not providing any ping result](https://discuss.elastic.co/t/heartbeat-http-not-providing-any-ping-result/283948)

<div class="topic-metadata">

**Author:** [@josh12](https://discuss.elastic.co/u/josh12)\
**Replies:** 1\
**Last updated:** [September 20, 2021, 1:47pm UTC](https://discuss.elastic.co/t/heartbeat-http-not-providing-any-ping-result/283948 "2021-09-20T13:47:39Z")

</div>

Below is my code. When i check, it always showing summary.up is true. I test using postman i receive 400 bad request - type: http id: my-site name: MY Site enabled: true schedule: '@every 5s' hosts: \["https://…

---

## [Heartbeat response code showing 200 but it is actually 502](https://discuss.elastic.co/t/heartbeat-response-code-showing-200-but-it-is-actually-502/284589)

<div class="topic-metadata">

**Author:** [@ezramiller](https://discuss.elastic.co/u/ezramiller)\
**Replies:** 3\
**Last updated:** [September 20, 2021, 1:46pm UTC](https://discuss.elastic.co/t/heartbeat-response-code-showing-200-but-it-is-actually-502/284589 "2021-09-20T13:46:34Z")

</div>

Hello everyone! So I have a bunch of website monitors and one of them right not working and showing 502 Bad gateway (Chrome inspect also showing status 502). But my heartbeat (v. 7.14.0) showing response status 200. Any…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=130)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=132)
