# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=132

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 133

---

## [Metricbeat doesnt create event when service is down](https://discuss.elastic.co/t/metricbeat-doesnt-create-event-when-service-is-down/284424)

<div class="topic-metadata">

**Author:** [@Deny7](https://discuss.elastic.co/u/Deny7)\
**Replies:** 0\
**Last updated:** [September 16, 2021, 4:59pm UTC](https://discuss.elastic.co/t/metricbeat-doesnt-create-event-when-service-is-down/284424 "2021-09-16T16:59:36Z")

</div>

Hi, Hi, Im using Metricbeat 7.9 and Elastalert for filesystem usage for each mountpoint. I also want to add alerting when linux service is stopped, so I enabled "- service" and "-process" in metricbeat.reference.yml. Wh…

---

## [Filebeat add\_id processor mechanism](https://discuss.elastic.co/t/filebeat-add-id-processor-mechanism/284560)

<div class="topic-metadata">

**Author:** [@Musketeer7](https://discuss.elastic.co/u/Musketeer7)\
**Replies:** 0\
**Last updated:** [September 19, 2021, 11:13am UTC](https://discuss.elastic.co/t/filebeat-add-id-processor-mechanism/284560 "2021-09-19T11:13:36Z")

</div>

Hello everyone. I have this relatively large cluster of ES, where logs from many filebeat instances are being shipped into. There are plenty of duplicates, that we can't identify their origin for sure. And because of re…

---

## [Zeek & ELK integration (A lot of strange fields)](https://discuss.elastic.co/t/zeek-elk-integration-a-lot-of-strange-fields/284547)

<div class="topic-metadata">

**Author:** [@test\_qweqwe](https://discuss.elastic.co/u/test_qweqwe)\
**Replies:** 4\
**Last updated:** [September 18, 2021, 9:02pm UTC](https://discuss.elastic.co/t/zeek-elk-integration-a-lot-of-strange-fields/284547 "2021-09-18T21:02:23Z")

</div>

Hi there, I set up ELK and then beats on Zeek server to send data to Elasticsearch. Everything is good except one: there are a lot of fields - 308 And it creates an element of inconvenience for me to create a searc…

---

## [Filebeat merge input duplicate logs](https://discuss.elastic.co/t/filebeat-merge-input-duplicate-logs/284506)

<div class="topic-metadata">

**Author:** [@dangge](https://discuss.elastic.co/u/dangge)\
**Replies:** 2\
**Last updated:** [September 18, 2021, 6:53am UTC](https://discuss.elastic.co/t/filebeat-merge-input-duplicate-logs/284506 "2021-09-18T06:53:36Z")

</div>

we had meet some linux filesystem error recently,a troublesome thing is that Linux will log a large number of the same logs at a certain point in time.like this: we use filebeat and logstash to record this error and …

---

## [How to apply filebeat to openshift and make use of multiline](https://discuss.elastic.co/t/how-to-apply-filebeat-to-openshift-and-make-use-of-multiline/284528)

<div class="topic-metadata">

**Author:** [@lsy1990](https://discuss.elastic.co/u/lsy1990)\
**Replies:** 0\
**Last updated:** [September 18, 2021, 6:18am UTC](https://discuss.elastic.co/t/how-to-apply-filebeat-to-openshift-and-make-use-of-multiline/284528 "2021-09-18T06:18:04Z")

</div>

I deploy filebeat to openshift 3.11 by daemonset .The log format is json like this below: {"log":"\\u0009at org.springframework.aop.framework.CglibAopProxy$CglibMethodInvocation.invokeJoinpoint(CglibAopProxy.java:746)\\n"…

---

## [Metricbeat setup --dashboards fails: error loading config file](https://discuss.elastic.co/t/metricbeat-setup-dashboards-fails-error-loading-config-file/284495)

<div class="topic-metadata">

**Author:** [@cdalexndr](https://discuss.elastic.co/u/cdalexndr)\
**Replies:** 1\
**Last updated:** [September 17, 2021, 3:15pm UTC](https://discuss.elastic.co/t/metricbeat-setup-dashboards-fails-error-loading-config-file/284495 "2021-09-17T15:15:30Z")

</div>

λ docker exec -it docker\_metricbeat\_1 sh sh-4.2# metricbeat setup --dashboards Exiting: error loading config file: config file ("metricbeat.yml") can only be writable by the owner but the permissions are "-rwxrwxrwx" (to…

---

## [Send data from filebeat to kafka(with kerberos) failed](https://discuss.elastic.co/t/send-data-from-filebeat-to-kafka-with-kerberos-failed/284479)

<div class="topic-metadata">

**Author:** [@charlielin](https://discuss.elastic.co/u/charlielin)\
**Replies:** 0\
**Last updated:** [September 17, 2021, 11:47am UTC](https://discuss.elastic.co/t/send-data-from-filebeat-to-kafka-with-kerberos-failed/284479 "2021-09-17T11:47:37Z")

</div>

filebeat: filebeat-7.10.2-linux-x86\_64 kafka: kafka\_2.13-2.6.0/ here is my filebeat config: filebeat.inputs: - type: log # Change to true to enable this input configuration. enabled: true fields\_under\_root: tru…

---

## [Metricbeat module system pass with special symbol](https://discuss.elastic.co/t/metricbeat-module-system-pass-with-special-symbol/284451)

<div class="topic-metadata">

**Author:** [@NoobUser404](https://discuss.elastic.co/u/NoobUser404)\
**Replies:** 0\
**Last updated:** [September 17, 2021, 6:55am UTC](https://discuss.elastic.co/t/metricbeat-module-system-pass-with-special-symbol/284451 "2021-09-17T06:55:13Z")

</div>

It is possible to put a any special symbol in the pass to sql? For example: hosts: \["sqlserver://sa:passwith$\<symbol@localhost"\] Because it gives me an error everytime I test it: sql... query... error... ERROR …

---

## [Filebeat add\_docker\_metadata incompatible](https://discuss.elastic.co/t/filebeat-add-docker-metadata-incompatible/284375)

<div class="topic-metadata">

**Author:** [@Bndlr](https://discuss.elastic.co/u/Bndlr)\
**Replies:** 1\
**Last updated:** [September 17, 2021, 12:35am UTC](https://discuss.elastic.co/t/filebeat-add-docker-metadata-incompatible/284375 "2021-09-17T00:35:44Z")

</div>

Hey, i had an Issue with different docker-compose Versions and parse the Metadata. (Infrastructure is: Filebeat -\> Logstash -\> Elasticsearch) First the Error Message from logstash: failed to parse field \[docker.cont…

---

## [When do you run the filebeat setup command?](https://discuss.elastic.co/t/when-do-you-run-the-filebeat-setup-command/284419)

<div class="topic-metadata">

**Author:** [@user8753123](https://discuss.elastic.co/u/user8753123)\
**Replies:** 4\
**Last updated:** [September 16, 2021, 5:54pm UTC](https://discuss.elastic.co/t/when-do-you-run-the-filebeat-setup-command/284419 "2021-09-16T17:54:12Z")

</div>

This is a general question that is probably more obvious to others than to me, sorry in advance. Question: When do you run the filebeat setup command under the below scenario's? I know based on this great answer (thank…

---

## [How beats behave during agent upgradation and installation failed?](https://discuss.elastic.co/t/how-beats-behave-during-agent-upgradation-and-installation-failed/284058)

<div class="topic-metadata">

**Author:** [@Nehal\_Mahida](https://discuss.elastic.co/u/Nehal_Mahida)\
**Replies:** 4\
**Last updated:** [September 16, 2021, 4:03pm UTC](https://discuss.elastic.co/t/how-beats-behave-during-agent-upgradation-and-installation-failed/284058 "2021-09-16T16:03:11Z")

</div>

Hi all, I am new to elastic agents and beats. I wish to know how beats support rollback or do it support? Here are my questions. What happens when agent installation failed in between (suppose filebeat is installed a…

---

## [Where can find doc for winlogbeat processor](https://discuss.elastic.co/t/where-can-find-doc-for-winlogbeat-processor/284344)

<div class="topic-metadata">

**Author:** [@xizhimen](https://discuss.elastic.co/u/xizhimen)\
**Replies:** 1\
**Last updated:** [September 16, 2021, 2:39pm UTC](https://discuss.elastic.co/t/where-can-find-doc-for-winlogbeat-processor/284344 "2021-09-16T14:39:58Z")

</div>

background: winlogbeat 7.3.2 I see follows code in winlogbeat's security.js (winlogbeat-7.3.2\\module\\security\\config\\security.js) var security = (function () { var path = require("path"); var processor = requ…

---

## [Error: fail to enroll: fail to execute request to fleet-server: status code: 400](https://discuss.elastic.co/t/error-fail-to-enroll-fail-to-execute-request-to-fleet-server-status-code-400/284406)

<div class="topic-metadata">

**Author:** [@b0r1s](https://discuss.elastic.co/u/b0r1s)\
**Replies:** 0\
**Last updated:** [September 16, 2021, 1:23pm UTC](https://discuss.elastic.co/t/error-fail-to-enroll-fail-to-execute-request-to-fleet-server-status-code-400/284406 "2021-09-16T13:23:49Z")

</div>

I'm trying to install Elastic Agent 7.14.1 on Fleet Server 7.14.1 with the following commands: On Windows 10: .\\elastic-agent.exe install -f --url=https://myfleetserver:8220 --enrollment-token=longapitoken --insecure O…

---

## [\[heartbeat\]add feature to enable publisher processor or other processors' debug log for just specific targets](https://discuss.elastic.co/t/heartbeat-add-feature-to-enable-publisher-processor-or-other-processors-debug-log-for-just-specific-targets/281374)

<div class="topic-metadata">

**Author:** [@lowry](https://discuss.elastic.co/u/lowry)\
**Replies:** 3\
**Last updated:** [September 16, 2021, 8:26am UTC](https://discuss.elastic.co/t/heartbeat-add-feature-to-enable-publisher-processor-or-other-processors-debug-log-for-just-specific-targets/281374 "2021-09-16T08:26:56Z")

</div>

Hey Elastic friends, Obviously, there’s some basic and amazing debug features in Elastic heartbeat, however we met a user case these days that current debug features cannot handle it. Given this example, since we have…

---

## [Filebeat custom plugin](https://discuss.elastic.co/t/filebeat-custom-plugin/284222)

<div class="topic-metadata">

**Author:** [@jpchev](https://discuss.elastic.co/u/jpchev)\
**Replies:** 1\
**Last updated:** [September 16, 2021, 8:23am UTC](https://discuss.elastic.co/t/filebeat-custom-plugin/284222 "2021-09-16T08:23:45Z")

</div>

hi there, I'm trying to compile myself filebeat after adding a custom http output plugin: I've followed and then I've added a new folder with my pluing into src/github.com/elastic/beats/libbeat now I can compile fil…

---

## [A New TiDB Module for Filebeat](https://discuss.elastic.co/t/a-new-tidb-module-for-filebeat/283439)

<div class="topic-metadata">

**Author:** [@yifan](https://discuss.elastic.co/u/yifan)\
**Replies:** 1\
**Last updated:** [September 16, 2021, 4:41am UTC](https://discuss.elastic.co/t/a-new-tidb-module-for-filebeat/283439 "2021-09-16T04:41:08Z")

</div>

Hello everyone, I'm a developer from TiDB Community. TiDB is a popular open source HTAP database. TiDB users use tools such as TiUP and TiDB-operator to deploy TiDB clusters in a bare-metal or k8s environment. Many Ti…

---

## [Can we set up multiple output in metricbeat?](https://discuss.elastic.co/t/can-we-set-up-multiple-output-in-metricbeat/284168)

<div class="topic-metadata">

**Author:** [@abhi.logs](https://discuss.elastic.co/u/abhi.logs)\
**Replies:** 3\
**Last updated:** [September 16, 2021, 4:29am UTC](https://discuss.elastic.co/t/can-we-set-up-multiple-output-in-metricbeat/284168 "2021-09-16T04:29:18Z")

</div>

Hello, I want to set up multiple outputs in metricbeat.yml, Is it possible we can set up? output.elasticsearch: hosts: \["abc.com"\] username: "xxxxx" Password: "xxxx" output.elasticsearch: hosts: \["xyz.com"\] usern…

---

## [Indexing beats hourly](https://discuss.elastic.co/t/indexing-beats-hourly/284271)

<div class="topic-metadata">

**Author:** [@tarekilani](https://discuss.elastic.co/u/tarekilani)\
**Replies:** 1\
**Last updated:** [September 15, 2021, 9:24pm UTC](https://discuss.elastic.co/t/indexing-beats-hourly/284271 "2021-09-15T21:24:00Z")

</div>

Hello, Please i'm searching for a way to index beats hourly in elasticsearch. As you know the default configuration in a beat yml file is : #index: "winlogbeat-%{\[agent.version\]}-%{+yyyy.MM.dd}" I tried changing that …

---

## [Filebeat Dashboard Setup is a Hassle!](https://discuss.elastic.co/t/filebeat-dashboard-setup-is-a-hassle/282468)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 16\
**Last updated:** [September 15, 2021, 9:11pm UTC](https://discuss.elastic.co/t/filebeat-dashboard-setup-is-a-hassle/282468 "2021-09-15T21:11:31Z")

</div>

I'm frustrated!!! It's such a hassle to load sample dashboards dashboards in Kibana, this should be an easy straight forward task. But somehow you guys managed to make it an hole day project. Sorry, but I'm pissed curren…

---

## [Winlogbeat cannot start service](https://discuss.elastic.co/t/winlogbeat-cannot-start-service/284332)

<div class="topic-metadata">

**Author:** [@marshallamey](https://discuss.elastic.co/u/marshallamey)\
**Replies:** 0\
**Last updated:** [September 15, 2021, 8:36pm UTC](https://discuss.elastic.co/t/winlogbeat-cannot-start-service/284332 "2021-09-15T20:36:12Z")

</div>

Hello, I am having the issue where I can start the winlogbeat application from PowerShell or CMD, but when I try to start the service I get the errors: (from services.msc) =\> Error 1053: The serivce did not respond to …

---

## [Why don't Elastic Agent Integrations Leverage @timestamp Sorting?](https://discuss.elastic.co/t/why-dont-elastic-agent-integrations-leverage-timestamp-sorting/284071)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 3\
**Last updated:** [September 15, 2021, 5:06pm UTC](https://discuss.elastic.co/t/why-dont-elastic-agent-integrations-leverage-timestamp-sorting/284071 "2021-09-15T17:06:49Z")

</div>

Hi All, I was doing some research into some possible search performance tuning within my cluster, and I noticed that the Elastic Agent integrations don't leverage sorting the index on @timestamp. In release 7.6, Elasti…

---

## [Metricbeat service is not starting after adding metricbeat keystore](https://discuss.elastic.co/t/metricbeat-service-is-not-starting-after-adding-metricbeat-keystore/284223)

<div class="topic-metadata">

**Author:** [@prat](https://discuss.elastic.co/u/prat)\
**Replies:** 20\
**Last updated:** [September 15, 2021, 4:59pm UTC](https://discuss.elastic.co/t/metricbeat-service-is-not-starting-after-adding-metricbeat-keystore/284223 "2021-09-15T16:59:58Z")

</div>

Hi Team, I am following below link for metricbeat keystore setup on v7.14.0. I created the keystore as, /usr/share/metricbeat/bin/metricbeat keystore --path.config /etc/metricbeat create Created the key cat es\_p…

---

## [Checking if the output.logstash is going to valid host](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 16\
**Last updated:** [September 15, 2021, 1:22pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202 "2021-09-15T13:22:31Z")

</div>

My goal is to verify that the output.logstash is actually being sent to the proper host. My filebeat configuration is set up like so filebeat.inputs: - input\_type: log paths: - /var/log/\*.log - /var/log/\*/\*.l…

---

## [Elastic Agent Issues Sending Logs - How much longer we need to wait?](https://discuss.elastic.co/t/elastic-agent-issues-sending-logs-how-much-longer-we-need-to-wait/284145)

<div class="topic-metadata">

**Author:** [@ikbal](https://discuss.elastic.co/u/ikbal)\
**Replies:** 1\
**Last updated:** [September 15, 2021, 12:54pm UTC](https://discuss.elastic.co/t/elastic-agent-issues-sending-logs-how-much-longer-we-need-to-wait/284145 "2021-09-15T12:54:39Z")

</div>

Hello Elastic, I believe you know that this issues has been circulated in the wild and it seems that the issues still exist whereby the agent installed is not transporting windows event logs etc to the Elastic. The one …

---

## [Filebeat running in docker not creating ECS field \`host.name\`](https://discuss.elastic.co/t/filebeat-running-in-docker-not-creating-ecs-field-host-name/284279)

<div class="topic-metadata">

**Author:** [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Replies:** 0\
**Last updated:** [September 15, 2021, 12:07pm UTC](https://discuss.elastic.co/t/filebeat-running-in-docker-not-creating-ecs-field-host-name/284279 "2021-09-15T12:07:17Z")

</div>

I am running a filebeat 7.14.1 in a docker container on a debian host. I am using the modules mysql and system. The filbeat is sending the documents directly to elasticsearch, those are my ingest nodes with the accordin…

---

## [Windows integration for event logs error](https://discuss.elastic.co/t/windows-integration-for-event-logs-error/284169)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 2\
**Last updated:** [September 15, 2021, 9:55am UTC](https://discuss.elastic.co/t/windows-integration-for-event-logs-error/284169 "2021-09-15T09:55:27Z")

</div>

Hi I have had a look at the Windows integration to collect events from the Windows event log but I believe there may be a mapping error. We have an environment where all Windows event logs are forwarded to a central lo…

---

## [Impact of group\_events on Filebeat and Kafka efficiency](https://discuss.elastic.co/t/impact-of-group-events-on-filebeat-and-kafka-efficiency/283414)

<div class="topic-metadata">

**Author:** [@md2](https://discuss.elastic.co/u/md2)\
**Replies:** 1\
**Last updated:** [September 15, 2021, 6:43am UTC](https://discuss.elastic.co/t/impact-of-group-events-on-filebeat-and-kafka-efficiency/283414 "2021-09-15T06:43:10Z")

</div>

Hello team, I have a pretty large fleet of Filebeat instances and all of them ship events to a Kafka cluster with multiple brokers which then got consumed by Logstash. I am currently researching on how to configure File…

---

## [Packetbeat: Decode Https Traffic](https://discuss.elastic.co/t/packetbeat-decode-https-traffic/284194)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 3\
**Last updated:** [September 15, 2021, 12:57am UTC](https://discuss.elastic.co/t/packetbeat-decode-https-traffic/284194 "2021-09-15T00:57:12Z")

</div>

Hi Folks, Is there any way to decode https/ssl traffic using packetbeat ? I have to server/client key do decode the traffic but i dont know how can i use it to decode the traffic. Thks

---

## [Filebeat dont send Logs to Kafka](https://discuss.elastic.co/t/filebeat-dont-send-logs-to-kafka/284200)

<div class="topic-metadata">

**Author:** [@Robsen\_Inc](https://discuss.elastic.co/u/Robsen_Inc)\
**Replies:** 1\
**Last updated:** [September 15, 2021, 12:19am UTC](https://discuss.elastic.co/t/filebeat-dont-send-logs-to-kafka/284200 "2021-09-15T00:19:39Z")

</div>

Hi guys! I have a question, what could be the reason that my Filebeat does not send log messages to the Kafka as soon as the time is behind. (When I stop my virtual machine and like the start no logs arrive, only when …

---

## [Automating Filebeat](https://discuss.elastic.co/t/automating-filebeat/283816)

<div class="topic-metadata">

**Author:** [@peter\_murphy](https://discuss.elastic.co/u/peter_murphy)\
**Replies:** 5\
**Last updated:** [September 14, 2021, 9:53pm UTC](https://discuss.elastic.co/t/automating-filebeat/283816 "2021-09-14T21:53:31Z")

</div>

Hello, I am using Filebeat to send my local device's Osquery log to my self-hosted Elasticsearch via Logstash. The pipeline is working correctly, but only if I trigger Filebeat manually. I'm sure the answer is simple, b…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=131)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=133)
