# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=133

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 134

---

## [Filebeat mssql](https://discuss.elastic.co/t/filebeat-mssql/284175)

<div class="topic-metadata">

**Author:** [@Marcel\_Palme](https://discuss.elastic.co/u/Marcel_Palme)\
**Replies:** 3\
**Last updated:** [September 14, 2021, 9:49pm UTC](https://discuss.elastic.co/t/filebeat-mssql/284175 "2021-09-14T21:49:50Z")

</div>

I'm trying to transfer the mssql log to elastic. This also works so far, but I get the errors all in text fields How can I split this field into individual fields or how can I search for certain keywords in this fiel…

---

## [Latest Winlogbeat for windows Url](https://discuss.elastic.co/t/latest-winlogbeat-for-windows-url/284191)

<div class="topic-metadata">

**Author:** [@operat0r](https://discuss.elastic.co/u/operat0r)\
**Replies:** 1\
**Last updated:** [September 14, 2021, 9:45pm UTC](https://discuss.elastic.co/t/latest-winlogbeat-for-windows-url/284191 "2021-09-14T21:45:32Z")

</div>

Even using wget I can't auto download the latest ZIP for winlogbeat ... I looked on github and all the scripts are doing the same thing with static paths ... is there any way I can have a "latest winlogbeat for winows" U…

---

## [Setting xpack.enabled via Metricbeat Docker hints](https://discuss.elastic.co/t/setting-xpack-enabled-via-metricbeat-docker-hints/284161)

<div class="topic-metadata">

**Author:** [@thilog](https://discuss.elastic.co/u/thilog)\
**Replies:** 1\
**Last updated:** [September 14, 2021, 11:40am UTC](https://discuss.elastic.co/t/setting-xpack-enabled-via-metricbeat-docker-hints/284161 "2021-09-14T11:40:11Z")

</div>

Hi there, is there a way to set the xpack.enabled flag for via Metricbeat Docker hints? I tried using the co.elastic.metrics/xpack.enabled label (on the monitored container), but it does not seem to have an effect. Alt…

---

## [Winlogbeat parse CAPI2 Log](https://discuss.elastic.co/t/winlogbeat-parse-capi2-log/282637)

<div class="topic-metadata">

**Author:** [@Marcel\_Palme](https://discuss.elastic.co/u/Marcel_Palme)\
**Replies:** 2\
**Last updated:** [September 14, 2021, 11:20am UTC](https://discuss.elastic.co/t/winlogbeat-parse-capi2-log/282637 "2021-09-14T11:20:27Z")

</div>

I check the capi2 log in windows. The transmission to Elastic also works partially. Only that not all fields are transferred. Specifically, I need the field under Userdata | certverifyCertificateChainPolicy | certificat…

---

## [Windows filebeat is not shipping logs](https://discuss.elastic.co/t/windows-filebeat-is-not-shipping-logs/281966)

<div class="topic-metadata">

**Author:** [@hellotty](https://discuss.elastic.co/u/hellotty)\
**Replies:** 1\
**Last updated:** [September 14, 2021, 8:58am UTC](https://discuss.elastic.co/t/windows-filebeat-is-not-shipping-logs/281966 "2021-09-14T08:58:07Z")

</div>

Hello, I have elk stack installed on my ubuntu and everything works fine. I installed filebeat on windows 8.1 to transfer the log file to elasticsearch (found on ubuntu) and faced with a problem. When starting the fil…

---

## [Failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure/283809)

<div class="topic-metadata">

**Author:** [@plaroche0](https://discuss.elastic.co/u/plaroche0)\
**Replies:** 5\
**Last updated:** [September 13, 2021, 7:55pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure/283809 "2021-09-13T19:55:37Z")

</div>

I have filebeat installed on a Syncplify server. It will send a couple of logs to ES and then nothing else. The service says it is still running. If I restart the service I get a couple more logs and then nothing unless …

---

## [Filebeat kubernetes provider mixed logs another containers from same pod](https://discuss.elastic.co/t/filebeat-kubernetes-provider-mixed-logs-another-containers-from-same-pod/283784)

<div class="topic-metadata">

**Author:** [@froheik](https://discuss.elastic.co/u/froheik)\
**Replies:** 1\
**Last updated:** [September 13, 2021, 3:55pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-provider-mixed-logs-another-containers-from-same-pod/283784 "2021-09-13T15:55:45Z")

</div>

Hi guys. May be anyone can check that? Im using daemonset of filebeat 7.14.1 in openshift cluster with config filebeat.autodiscover: providers: - type: kubernetes include\_pod\_uid: true …

---

## [Elasticsearch not parsing cloudtrail index](https://discuss.elastic.co/t/elasticsearch-not-parsing-cloudtrail-index/283913)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 3\
**Last updated:** [September 13, 2021, 3:07pm UTC](https://discuss.elastic.co/t/elasticsearch-not-parsing-cloudtrail-index/283913 "2021-09-13T15:07:36Z")

</div>

I'm running into an issue parsing cloudtrail logs from filebeat. I am getting this error from the the ecs logs. WARN \[elasticsearch\] elasticsearch/client.go:408 Cannot index event publisher.Event{Content:beat.Event{Time…

---

## [When using logstash output sends only limited information. Any other output, no problem](https://discuss.elastic.co/t/when-using-logstash-output-sends-only-limited-information-any-other-output-no-problem/283692)

<div class="topic-metadata">

**Author:** [@syunusic](https://discuss.elastic.co/u/syunusic)\
**Replies:** 10\
**Last updated:** [September 13, 2021, 2:17pm UTC](https://discuss.elastic.co/t/when-using-logstash-output-sends-only-limited-information-any-other-output-no-problem/283692 "2021-09-13T14:17:12Z")

</div>

If I use auditbeat (I guess is the same with other beats) and configure elasticsearch or file output I see all information I need. In this example I modify /etc/sudoers' attributes, then I modify it, and then I modify i…

---

## [AWS metricbeat unable to load data in kibana](https://discuss.elastic.co/t/aws-metricbeat-unable-to-load-data-in-kibana/283416)

<div class="topic-metadata">

**Author:** [@Divyank\_Mahalle](https://discuss.elastic.co/u/Divyank_Mahalle)\
**Replies:** 9\
**Last updated:** [September 13, 2021, 12:19pm UTC](https://discuss.elastic.co/t/aws-metricbeat-unable-to-load-data-in-kibana/283416 "2021-09-13T12:19:00Z")

</div>

Hi , I am using metricbeat 7.14. IAM policy given for AWS billing and AWS.yml config file is as follows as stated in AWS billing metricset | Metricbeat Reference \[7.16\] | Elastic Step I followed to start aws and flo…

---

## [Problem with configuration filebeat and output kafka](https://discuss.elastic.co/t/problem-with-configuration-filebeat-and-output-kafka/284032)

<div class="topic-metadata">

**Author:** [@potro\_italiano](https://discuss.elastic.co/u/potro_italiano)\
**Replies:** 0\
**Last updated:** [September 13, 2021, 9:04am UTC](https://discuss.elastic.co/t/problem-with-configuration-filebeat-and-output-kafka/284032 "2021-09-13T09:04:13Z")

</div>

Good morning, I have one machine with filebeat that send data to kafka. The problem is that not send data a kafka and it not register never errors in the log of filebeat. there is telnet connectivity and I did the test…

---

## [Metricbeat AWS module template](https://discuss.elastic.co/t/metricbeat-aws-module-template/284016)

<div class="topic-metadata">

**Author:** [@dwjvaughan](https://discuss.elastic.co/u/dwjvaughan)\
**Replies:** 0\
**Last updated:** [September 13, 2021, 7:37am UTC](https://discuss.elastic.co/t/metricbeat-aws-module-template/284016 "2021-09-13T07:37:47Z")

</div>

I'm using the AWS module in metricbeat (just the Cloudwatch metricset) but I can't seem to find any index templates for it. If I do a metricbeat export template there are no mappings for aws., or more specifically for my…

---

## [How to read filebeat additional values from custom codec plugin?](https://discuss.elastic.co/t/how-to-read-filebeat-additional-values-from-custom-codec-plugin/284015)

<div class="topic-metadata">

**Author:** [@WanJune](https://discuss.elastic.co/u/WanJune)\
**Replies:** 0\
**Last updated:** [September 13, 2021, 7:33am UTC](https://discuss.elastic.co/t/how-to-read-filebeat-additional-values-from-custom-codec-plugin/284015 "2021-09-13T07:33:12Z")

</div>

Hi. I am currently making Logstash Custom Plugin to analyze WAS logs. I am making a Codec plugin to analyze the unstructured WAS log sent from remote Filebeat. Filter plugin cannot be used because its stream disordere…

---

## [Metricbeat executing every 3 minutes using cron](https://discuss.elastic.co/t/metricbeat-executing-every-3-minutes-using-cron/284014)

<div class="topic-metadata">

**Author:** [@josh12](https://discuss.elastic.co/u/josh12)\
**Replies:** 1\
**Last updated:** [September 13, 2021, 7:35am UTC](https://discuss.elastic.co/t/metricbeat-executing-every-3-minutes-using-cron/284014 "2021-09-13T07:35:44Z")

</div>

Can i know is there cron setting for metricbeat for period as how it was done for heartbeat

---

## [Filebeat config error: Exiting: 1 error: error loading config file: invalid config: yaml: line 87: could not find expected ':'](https://discuss.elastic.co/t/filebeat-config-error-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-87-could-not-find-expected/283969)

<div class="topic-metadata">

**Author:** [@pheempon](https://discuss.elastic.co/u/pheempon)\
**Replies:** 4\
**Last updated:** [September 13, 2021, 4:48am UTC](https://discuss.elastic.co/t/filebeat-config-error-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-87-could-not-find-expected/283969 "2021-09-13T04:48:01Z")

</div>

I keep on getting this error when I try to configure Filebeat. ERROR instance/beat.go:989 Exiting: 1 error: error loading config file: invalid config: yaml: line 87: could not find expected ':' Exiting: 1 error: er…

---

## [Es index segmentation question](https://discuss.elastic.co/t/es-index-segmentation-question/283997)

<div class="topic-metadata">

**Author:** [@shenjiayu](https://discuss.elastic.co/u/shenjiayu)\
**Replies:** 5\
**Last updated:** [September 13, 2021, 2:47am UTC](https://discuss.elastic.co/t/es-index-segmentation-question/283997 "2021-09-13T02:47:53Z")

</div>

Hey, I have a question. I stay at UTC+8, and I use filebeat to collect logs from k8s, then sending to es.But the default index segmentation is decided by UTC, not UTC+8. So I will find logs of 2021.9.1(UTC+8) in filebeat…

---

## [Send .evtx files to elastic cloud using winlogbeat](https://discuss.elastic.co/t/send-evtx-files-to-elastic-cloud-using-winlogbeat/281779)

<div class="topic-metadata">

**Author:** [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Replies:** 3\
**Last updated:** [September 12, 2021, 8:39pm UTC](https://discuss.elastic.co/t/send-evtx-files-to-elastic-cloud-using-winlogbeat/281779 "2021-09-12T20:39:22Z")

</div>

Hi everyone, I've more than 100 .evtx files that have to be sent to elastic cloud using winlogbeat. I know the method to send files one by one using this post But this is a hectic process to provide the path of each fil…

---

## [Visualizing systemd services using Metricbeat (Please help)](https://discuss.elastic.co/t/visualizing-systemd-services-using-metricbeat-please-help/283982)

<div class="topic-metadata">

**Author:** [@josh12](https://discuss.elastic.co/u/josh12)\
**Replies:** 0\
**Last updated:** [September 12, 2021, 4:25pm UTC](https://discuss.elastic.co/t/visualizing-systemd-services-using-metricbeat-please-help/283982 "2021-09-12T16:25:25Z")

</div>

Hi friends, i would like to visualize systemd process. Please advice The below having issue whereby sometimes it spikes sometimes it dont. I am quite confuse

---

## [Filebeat unble set filed name with error](https://discuss.elastic.co/t/filebeat-unble-set-filed-name-with-error/283938)

<div class="topic-metadata">

**Author:** [@josh12](https://discuss.elastic.co/u/josh12)\
**Replies:** 0\
**Last updated:** [September 11, 2021, 2:15pm UTC](https://discuss.elastic.co/t/filebeat-unble-set-filed-name-with-error/283938 "2021-09-11T14:15:25Z")

</div>

Hi experts, I trying to change fields value. But it not working. Any idea? OLD VALUE fields: pattern: my\_error \`\` NEW VALUE fields: pattern: error \`\`

---

## [Filebeat only reading new lines](https://discuss.elastic.co/t/filebeat-only-reading-new-lines/283858)

<div class="topic-metadata">

**Author:** [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Replies:** 1\
**Last updated:** [September 11, 2021, 12:18am UTC](https://discuss.elastic.co/t/filebeat-only-reading-new-lines/283858 "2021-09-11T00:18:28Z")

</div>

Hi! my filebeat is reading only new lines and that's perfect but, how can i tell filebeat to read from the beggining of the file? Thank you

---

## [Filebeat v7.14.0 Error in Loading Pipeline](https://discuss.elastic.co/t/filebeat-v7-14-0-error-in-loading-pipeline/283407)

<div class="topic-metadata">

**Author:** [@Mary\_Cane\_Bandohan](https://discuss.elastic.co/u/Mary_Cane_Bandohan)\
**Replies:** 9\
**Last updated:** [September 11, 2021, 12:11am UTC](https://discuss.elastic.co/t/filebeat-v7-14-0-error-in-loading-pipeline/283407 "2021-09-11T00:11:58Z")

</div>

Can someone please help us troubleshoot the error we're having after installing Filebeat version 7.14.0 in our CentOS server? We have disabled ILM in the filebeat.yml file. Our Elasticsearch and Kibana versions are cur…

---

## [Office 365 module: data is not showing in dashboard and beat fails after 1 hour](https://discuss.elastic.co/t/office-365-module-data-is-not-showing-in-dashboard-and-beat-fails-after-1-hour/282709)

<div class="topic-metadata">

**Author:** [@jared.smith](https://discuss.elastic.co/u/jared.smith)\
**Replies:** 6\
**Last updated:** [September 10, 2021, 3:47am UTC](https://discuss.elastic.co/t/office-365-module-data-is-not-showing-in-dashboard-and-beat-fails-after-1-hour/282709 "2021-09-10T03:47:56Z")

</div>

After installing and configuring the Office 365 Module according to instructions here, I'm seeing a couple of issues. After running successfully for (exactly) 1 hour, the o365beat process on the Windows 10 machine fail…

---

## [Lerna output json](https://discuss.elastic.co/t/lerna-output-json/283854)

<div class="topic-metadata">

**Author:** [@cskiwi](https://discuss.elastic.co/u/cskiwi)\
**Replies:** 2\
**Last updated:** [September 10, 2021, 9:41am UTC](https://discuss.elastic.co/t/lerna-output-json/283854 "2021-09-10T09:41:11Z")

</div>

Hi, I'm trying to setup my logging, for my application, but this is running via lerna. Which means it outputs first the package name and then the log Which makes the output look like this: info cli using local versio…

---

## [Filebeat 7.9+ Registry Format](https://discuss.elastic.co/t/filebeat-7-9-registry-format/283843)

<div class="topic-metadata">

**Author:** [@scott\_stash](https://discuss.elastic.co/u/scott_stash)\
**Replies:** 2\
**Last updated:** [September 10, 2021, 11:23am UTC](https://discuss.elastic.co/t/filebeat-7-9-registry-format/283843 "2021-09-10T11:23:24Z")

</div>

I run a script that checks the status of processing by comparing the file offset in the registry log.json to the byte size on the OS. The offset is generally saved in two places: log.json -\> multiple lines /d/d/d/d/d/…

---

## [Metricbeat - filesystem How does metricbeat decide what filesystems to monitor?](https://discuss.elastic.co/t/metricbeat-filesystem-how-does-metricbeat-decide-what-filesystems-to-monitor/283828)

<div class="topic-metadata">

**Author:** [@Newbie2019](https://discuss.elastic.co/u/Newbie2019)\
**Replies:** 1\
**Last updated:** [September 10, 2021, 9:27am UTC](https://discuss.elastic.co/t/metricbeat-filesystem-how-does-metricbeat-decide-what-filesystems-to-monitor/283828 "2021-09-10T09:27:53Z")

</div>

I have a question, how does metricbeat decide what filesystems it will monitor? I configured the system module, made sure that metricsets filesystem was added, made sure no FS were being ignored, but I still could not s…

---

## [Action \[indices:admin/auto\_create\] is unauthorized for API key id \[####\] of user \[elastic/fleet-server\] on indices \[metricbeat-7.14.1-2021.09.08\], this action is granted by the index privileges \[auto\_configure,create\_index,manage,all\]](https://discuss.elastic.co/t/action-indices-admin-auto-create-is-unauthorized-for-api-key-id-of-user-elastic-fleet-server-on-indices-metricbeat-7-14-1-2021-09-08-this-action-is-granted-by-the-index-privileges-auto-configure-create-index-manage-all/283608)

<div class="topic-metadata">

**Author:** [@hamiland](https://discuss.elastic.co/u/hamiland)\
**Replies:** 29\
**Last updated:** [September 10, 2021, 7:16am UTC](https://discuss.elastic.co/t/action-indices-admin-auto-create-is-unauthorized-for-api-key-id-of-user-elastic-fleet-server-on-indices-metricbeat-7-14-1-2021-09-08-this-action-is-granted-by-the-index-privileges-auto-configure-create-index-manage-all/283608 "2021-09-10T07:16:16Z")

</div>

Hi All, I'm a bit green in the Elastic world so please bear with me. I have Fleet agents deployed to our Windows hosts, however I am having issues when Either "Collect Windows perfmon and service metrics" in the Window…

---

## [Miscellaneous Questions on the back of Ricardo's all you want too know about filebeat](https://discuss.elastic.co/t/miscellaneous-questions-on-the-back-of-ricardos-all-you-want-too-know-about-filebeat/283528)

<div class="topic-metadata">

**Author:** [@George\_Leonard](https://discuss.elastic.co/u/George_Leonard)\
**Replies:** 7\
**Last updated:** [September 10, 2021, 12:44am UTC](https://discuss.elastic.co/t/miscellaneous-questions-on-the-back-of-ricardos-all-you-want-too-know-about-filebeat/283528 "2021-09-10T00:44:15Z")

</div>

As I was working through Ricardo's Youtube video I ended with the below below question, I posted them in the Video comment section but thinking might get more traction reposting here. I'm a total noob wrt EK still, and …

---

## [System Integration Filters](https://discuss.elastic.co/t/system-integration-filters/283588)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 3\
**Last updated:** [September 9, 2021, 10:54pm UTC](https://discuss.elastic.co/t/system-integration-filters/283588 "2021-09-09T22:54:09Z")

</div>

Hello, For the System integration for elastic-agent, I was curious if we could filter by log level, or eliminate various Event ID's that we may not want to collect due to noise. Collection of all informational logs at s…

---

## [MISP objects cannot be stored in Elastic & Kibana](https://discuss.elastic.co/t/misp-objects-cannot-be-stored-in-elastic-kibana/283780)

<div class="topic-metadata">

**Author:** [@Abanob\_Medhat](https://discuss.elastic.co/u/Abanob_Medhat)\
**Replies:** 0\
**Last updated:** [September 9, 2021, 1:13pm UTC](https://discuss.elastic.co/t/misp-objects-cannot-be-stored-in-elastic-kibana/283780 "2021-09-09T13:13:28Z")

</div>

Hi , I have a problem with MISP integration with Filebeat & ELK. I'm using Virustotal module on MISP and the results of virustotoal are saved in objects in the same Event . the problem is that all objects cannot be sa…

---

## [Linux file beat configuration not working](https://discuss.elastic.co/t/linux-file-beat-configuration-not-working/283731)

<div class="topic-metadata">

**Author:** [@Kannan\_Rajendran](https://discuss.elastic.co/u/Kannan_Rajendran)\
**Replies:** 1\
**Last updated:** [September 9, 2021, 10:18am UTC](https://discuss.elastic.co/t/linux-file-beat-configuration-not-working/283731 "2021-09-09T10:18:34Z")

</div>

i'm trying to take log from linux machine with oracle database installed. Based on the below configuration the filebeat doesn't pull any info to elastic search. filebeat.inputs: - type: log enabled: true paths: …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=132)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=134)
