# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=134

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 135

---

## [Filebeat logstash communication](https://discuss.elastic.co/t/filebeat-logstash-communication/283757)

<div class="topic-metadata">

**Author:** [@Nitzan\_Zaifman](https://discuss.elastic.co/u/Nitzan_Zaifman)\
**Replies:** 0\
**Last updated:** [September 9, 2021, 9:05am UTC](https://discuss.elastic.co/t/filebeat-logstash-communication/283757 "2021-09-09T09:05:35Z")

</div>

Hi, I've took a look at However I still have multiple questions regarding filebeat's logstash output. How many TCP connections are generated? from my testing even with multiple pipelines (the default) and setting u…

---

## [Filebeat - Elasticsearch output is not configured](https://discuss.elastic.co/t/filebeat-elasticsearch-output-is-not-configured/283637)

<div class="topic-metadata">

**Author:** [@X\_T](https://discuss.elastic.co/u/X_T)\
**Replies:** 14\
**Last updated:** [September 9, 2021, 9:31am UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-output-is-not-configured/283637 "2021-09-09T09:31:10Z")

</div>

Hi team, i'm facing an issue when setting up Filebeat 6.5.0 (testing on this version for an upcoming upgrade) in a Windows machine. I know that Filebeat is not the best to use it on Windows but i am just sending logs in…

---

## [Drop Events works only for Linux](https://discuss.elastic.co/t/drop-events-works-only-for-linux/283263)

<div class="topic-metadata">

**Author:** [@fpsouza](https://discuss.elastic.co/u/fpsouza)\
**Replies:** 2\
**Last updated:** [September 9, 2021, 8:51am UTC](https://discuss.elastic.co/t/drop-events-works-only-for-linux/283263 "2021-09-09T08:51:32Z")

</div>

Hello Sirs, Could you please let me know when my drop events below is only working for linux and not for windows platfom? Is tere something that should be difference in the metricbeat.yml file? Follow my metricbeat.yml…

---

## [Unable to create monthly index in filebeat to elasticsearch](https://discuss.elastic.co/t/unable-to-create-monthly-index-in-filebeat-to-elasticsearch/281567)

<div class="topic-metadata">

**Author:** [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Replies:** 3\
**Last updated:** [September 9, 2021, 4:36am UTC](https://discuss.elastic.co/t/unable-to-create-monthly-index-in-filebeat-to-elasticsearch/281567 "2021-09-09T04:36:52Z")

</div>

Hi Team, I am trying to sending logs from couple of my windows servers using filebeat to elasticsearch directly. The index patterns are getting created by default ( filebeat-7.10.2-2021.08.16) however I want to create a…

---

## [Stop Filebeat automatically after it uploaded all log files](https://discuss.elastic.co/t/stop-filebeat-automatically-after-it-uploaded-all-log-files/283473)

<div class="topic-metadata">

**Author:** [@vladik22](https://discuss.elastic.co/u/vladik22)\
**Replies:** 2\
**Last updated:** [September 9, 2021, 4:32am UTC](https://discuss.elastic.co/t/stop-filebeat-automatically-after-it-uploaded-all-log-files/283473 "2021-09-09T04:32:22Z")

</div>

There is an option to configure Filebeat to stop automatically after it uploaded all log files? Before every uploading log file I should to modify them.

---

## [Kafka (topic=): dropping invalid message](https://discuss.elastic.co/t/kafka-topic-dropping-invalid-message/283728)

<div class="topic-metadata">

**Author:** [@flaviawang](https://discuss.elastic.co/u/flaviawang)\
**Replies:** 0\
**Last updated:** [September 9, 2021, 3:49am UTC](https://discuss.elastic.co/t/kafka-topic-dropping-invalid-message/283728 "2021-09-09T03:49:34Z")

</div>

2021-09-08T19:15:47.776+0800 ERROR \[kafka\] kafka/client.go:341 Kafka (topic=ilog-filebeat-test): dropping invalid message

---

## [FileBeat Not Processing Cisco 2960X Logs](https://discuss.elastic.co/t/filebeat-not-processing-cisco-2960x-logs/283725)

<div class="topic-metadata">

**Author:** [@Brad\_Henderson](https://discuss.elastic.co/u/Brad_Henderson)\
**Replies:** 0\
**Last updated:** [September 9, 2021, 2:52am UTC](https://discuss.elastic.co/t/filebeat-not-processing-cisco-2960x-logs/283725 "2021-09-09T02:52:29Z")

</div>

I am having an issue with getting Filebeat with the Cisco module to process logs from my 2960X switches running version 15.2. The switch is sending logs to Filebeat but when i run a debug I am getting an error that says …

---

## [How Packetbeat for MongoDB](https://discuss.elastic.co/t/how-packetbeat-for-mongodb/282990)

<div class="topic-metadata">

**Author:** [@hope1234567hope](https://discuss.elastic.co/u/hope1234567hope)\
**Replies:** 6\
**Last updated:** [September 9, 2021, 1:33am UTC](https://discuss.elastic.co/t/how-packetbeat-for-mongodb/282990 "2021-09-09T01:33:34Z")

</div>

i Packetbeat for MongoDB，but not find mongodb.query information。only have mongodb.startingFrom mongodb.numberToReturn mongodb.numberToSkip mongodb.fullCollectionName mongodb.cursorId，but not data。 why？ my version i…

---

## [Metricbeat monitor systemd process](https://discuss.elastic.co/t/metricbeat-monitor-systemd-process/283607)

<div class="topic-metadata">

**Author:** [@josh12](https://discuss.elastic.co/u/josh12)\
**Replies:** 6\
**Last updated:** [September 8, 2021, 3:05pm UTC](https://discuss.elastic.co/t/metricbeat-monitor-systemd-process/283607 "2021-09-08T15:05:48Z")

</div>

Can I know, do you have example how i can monitor systemd and few java process. One of it is httpd and java process based on folder for isntance config. usually i do is ps -ef | grep config/

---

## [Creating index name from field value](https://discuss.elastic.co/t/creating-index-name-from-field-value/283677)

<div class="topic-metadata">

**Author:** [@Paintras](https://discuss.elastic.co/u/Paintras)\
**Replies:** 0\
**Last updated:** [September 8, 2021, 2:43pm UTC](https://discuss.elastic.co/t/creating-index-name-from-field-value/283677 "2021-09-08T14:43:47Z")

</div>

Good day, this is my filebeat.yml file: filebeat.config: modules: path: ${path.config}/modules.d/\*.yml reload.enabled: false processors: - add\_cloud\_metadata: ~ - add\_docker\_metadata: ~ …

---

## [Conflicts in Azure Fleet Integrations](https://discuss.elastic.co/t/conflicts-in-azure-fleet-integrations/283236)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 3\
**Last updated:** [September 8, 2021, 1:38pm UTC](https://discuss.elastic.co/t/conflicts-in-azure-fleet-integrations/283236 "2021-09-08T13:38:39Z")

</div>

Hi I think there is an issue with the current Azure logs integration for Fleet (Azure logs integration v0.8.5). I am working with this to try and pull in various logs from Azure and have noticed field conflicts in my l…

---

## [Host details](https://discuss.elastic.co/t/host-details/283616)

<div class="topic-metadata">

**Author:** [@vijay\_kaali](https://discuss.elastic.co/u/vijay_kaali)\
**Replies:** 0\
**Last updated:** [September 8, 2021, 7:08am UTC](https://discuss.elastic.co/t/host-details/283616 "2021-09-08T07:08:50Z")

</div>

Hi i am using 6.8 metricbeat and server is 7.12 . a. add host metricset and got error , so enable add\_host\_metadata : ~ b . as per documentation . add\_host\_metadata it should collect "host":{ "architecture":"x86…

---

## [Filebeat Hints based not grabbing logs](https://discuss.elastic.co/t/filebeat-hints-based-not-grabbing-logs/283634)

<div class="topic-metadata">

**Author:** [@WookWook](https://discuss.elastic.co/u/WookWook)\
**Replies:** 0\
**Last updated:** [September 8, 2021, 9:02am UTC](https://discuss.elastic.co/t/filebeat-hints-based-not-grabbing-logs/283634 "2021-09-08T09:02:13Z")

</div>

Hello I set up Elastic Cloud on Kubernetes on a Managed Azure Redhat Openshift Cluster 4.6 My initial configuration with hints based autodiscover and a default config was working fine. It grabbed all logs and I could d…

---

## [Unable to setup Beats on my local system](https://discuss.elastic.co/t/unable-to-setup-beats-on-my-local-system/283614)

<div class="topic-metadata">

**Author:** [@Adhi](https://discuss.elastic.co/u/Adhi)\
**Replies:** 2\
**Last updated:** [September 8, 2021, 6:51am UTC](https://discuss.elastic.co/t/unable-to-setup-beats-on-my-local-system/283614 "2021-09-08T06:51:09Z")

</div>

Hello, I'm having trouble seting up both filebeat and metricbeat agent in my local system. Im currently using the 14 days free cloud trail version, I have followed the steps given. So whenever I ran setup command, im …

---

## [Combine separated JSON logs in k8s](https://discuss.elastic.co/t/combine-separated-json-logs-in-k8s/283510)

<div class="topic-metadata">

**Author:** [@Dennis\_Haseloff](https://discuss.elastic.co/u/Dennis_Haseloff)\
**Replies:** 1\
**Last updated:** [September 8, 2021, 6:49am UTC](https://discuss.elastic.co/t/combine-separated-json-logs-in-k8s/283510 "2021-09-08T06:49:01Z")

</div>

Hi all, We are using a filebeat daemon set with autodisocover to scrape all container logs which are all in the JSON logstash format. Using docker container runtime, the docker json-file driver splits bigger logs into 1…

---

## [Add output kafka Idempotent](https://discuss.elastic.co/t/add-output-kafka-idempotent/283594)

<div class="topic-metadata">

**Author:** [@Icedroid](https://discuss.elastic.co/u/Icedroid)\
**Replies:** 1\
**Last updated:** [September 8, 2021, 6:30am UTC](https://discuss.elastic.co/t/add-output-kafka-idempotent/283594 "2021-09-08T06:30:11Z")

</div>

I need output to kafka for at most once . Can I create a pull request to beats output kafka as follow: if config.Idempotent { k.Producer.Idempotent = config.Idempotent k.Net.MaxOpenRequests = 1 k.Producer.Require…

---

## [Log kernel messages](https://discuss.elastic.co/t/log-kernel-messages/283593)

<div class="topic-metadata">

**Author:** [@jmcclelland](https://discuss.elastic.co/u/jmcclelland)\
**Replies:** 0\
**Last updated:** [September 8, 2021, 1:21am UTC](https://discuss.elastic.co/t/log-kernel-messages/283593 "2021-09-08T01:21:17Z")

</div>

In my journalbeat.yml file I'm using include\_matches under journalbeat.inputs to restrict the logs shipped to elasticsearch by systemd.units. But... how do I also include the output I get via journalctl -k (kernel messag…

---

## [Filebeat logs not displaying to Kibana](https://discuss.elastic.co/t/filebeat-logs-not-displaying-to-kibana/283385)

<div class="topic-metadata">

**Author:** [@Codedestiny1](https://discuss.elastic.co/u/Codedestiny1)\
**Replies:** 6\
**Last updated:** [September 7, 2021, 10:27pm UTC](https://discuss.elastic.co/t/filebeat-logs-not-displaying-to-kibana/283385 "2021-09-07T22:27:22Z")

</div>

Filebeat YAML configuration files automated by Ansible playbook have been installed on two virtual machines (Web1 & Web2). I can SSH into them and find filebeat systemctl service is running (active). But no log data is d…

---

## [AWS Integrations Mapping Error](https://discuss.elastic.co/t/aws-integrations-mapping-error/283502)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 4\
**Last updated:** [September 7, 2021, 5:17pm UTC](https://discuss.elastic.co/t/aws-integrations-mapping-error/283502 "2021-09-07T17:17:08Z")

</div>

Hi I'm hoping this is posted in the correct place. I believe the AWS mappings in the Fleet Integration are missing a mapping for event.created. I am ingesting Cloudtrail logs via Fleet and I'm getting errors stating t…

---

## [Filebeat : how to exclude lines](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306)

<div class="topic-metadata">

**Author:** [@thomas7467](https://discuss.elastic.co/u/thomas7467)\
**Replies:** 6\
**Last updated:** [September 7, 2021, 2:17pm UTC](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306 "2021-09-07T14:17:55Z")

</div>

Hi, Using ELK 7.14.0 release. I'm trying to excludes lines from IIS access log files. I've tried several methods but It still will not work. I've done that previously with logstash, but I prefer use a simplified archi…

---

## [Skip\_newline no effect in filestream parsers.multiline](https://discuss.elastic.co/t/skip-newline-no-effect-in-filestream-parsers-multiline/282913)

<div class="topic-metadata">

**Author:** [@kenix](https://discuss.elastic.co/u/kenix)\
**Replies:** 2\
**Last updated:** [September 7, 2021, 1:48pm UTC](https://discuss.elastic.co/t/skip-newline-no-effect-in-filestream-parsers-multiline/282913 "2021-09-07T13:48:28Z")

</div>

Context: docker.elastic.co/beats/filebeat-oss:7.14.0 image mac os latest Filebeat settings: filebeat.inputs: - type: filestream enabled: true paths: - /usr/var/log/foo.log parsers: - multiline: type…

---

## [Index Speed Capped but Missing ASA logs](https://discuss.elastic.co/t/index-speed-capped-but-missing-asa-logs/283307)

<div class="topic-metadata">

**Author:** [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Replies:** 3\
**Last updated:** [September 7, 2021, 12:15pm UTC](https://discuss.elastic.co/t/index-speed-capped-but-missing-asa-logs/283307 "2021-09-07T12:15:24Z")

</div>

Our current set up is Elasticsearch, Filebeat, and Kibana on the same server for dev purposes (hoping to move to 3 nodes & gold licensing next year) - We are using the cisco.yml module in filebeat to receive ASA …

---

## [Pulse Secure integration](https://discuss.elastic.co/t/pulse-secure-integration/283501)

<div class="topic-metadata">

**Author:** [@tkarczewski](https://discuss.elastic.co/u/tkarczewski)\
**Replies:** 3\
**Last updated:** [September 7, 2021, 11:24am UTC](https://discuss.elastic.co/t/pulse-secure-integration/283501 "2021-09-07T11:24:56Z")

</div>

Hi, How to create integration for Pulse Secure Connect?

---

## [Auditbeat PATH](https://discuss.elastic.co/t/auditbeat-path/283471)

<div class="topic-metadata">

**Author:** [@jam\_mahmoudi](https://discuss.elastic.co/u/jam_mahmoudi)\
**Replies:** 3\
**Last updated:** [September 7, 2021, 5:21am UTC](https://discuss.elastic.co/t/auditbeat-path/283471 "2021-09-07T05:21:22Z")

</div>

Hi guys I have installed and configured َAuditbeat to check a series of specific files and folders in Windows َServer Auditbeat works and Running But when I add the D and E drives to Auditbeat.yml file , the servi…

---

## [Cannot create ingest pipeline(iis, nginx) \[Filebeat 7.14.0 + Elasticsearch 7.8.1\]](https://discuss.elastic.co/t/cannot-create-ingest-pipeline-iis-nginx-filebeat-7-14-0-elasticsearch-7-8-1/283394)

<div class="topic-metadata">

**Author:** [@Bingu\_Shim](https://discuss.elastic.co/u/Bingu_Shim)\
**Replies:** 2\
**Last updated:** [September 7, 2021, 3:15am UTC](https://discuss.elastic.co/t/cannot-create-ingest-pipeline-iis-nginx-filebeat-7-14-0-elasticsearch-7-8-1/283394 "2021-09-07T03:15:39Z")

</div>

Hi I was using filebeat 7.7.1 with Elasticsearch 7.8.1 and had no problem with collecting iis and nginx logs. But, when I upgraded filebeat from 7.7.1 to 7.14.0 I got these errors logs from Elasticsearch. {"type": "se…

---

## [Fleet Server - Error - x509: certificate signed by unknown authority](https://discuss.elastic.co/t/fleet-server-error-x509-certificate-signed-by-unknown-authority/283168)

<div class="topic-metadata">

**Author:** [@JimG](https://discuss.elastic.co/u/JimG)\
**Replies:** 1\
**Last updated:** [September 6, 2021, 1:52pm UTC](https://discuss.elastic.co/t/fleet-server-error-x509-certificate-signed-by-unknown-authority/283168 "2021-09-06T13:52:13Z")

</div>

Hi everyone :slight\_smile: Im trying to make a test setup with a Ubuntu 20.04 , running with docker. I use docker-compose to make elastic agent/fleet server, but i cant make it work with a self signed certificate for f…

---

## [Index pattern options alternatives](https://discuss.elastic.co/t/index-pattern-options-alternatives/283450)

<div class="topic-metadata">

**Author:** [@Babadofar](https://discuss.elastic.co/u/Babadofar)\
**Replies:** 2\
**Last updated:** [September 6, 2021, 1:25pm UTC](https://discuss.elastic.co/t/index-pattern-options-alternatives/283450 "2021-09-06T13:25:50Z")

</div>

I tried Installing filebeat 7.14 in kubernetes on a new elastic cluster. In the old cluster I had over 5000 fields in the filebeat index pattern, which made it impossible to add new fields. In the new index in the new cl…

---

## [Unable to test output with Filebeat to Elasticsearch](https://discuss.elastic.co/t/unable-to-test-output-with-filebeat-to-elasticsearch/282654)

<div class="topic-metadata">

**Author:** [@jhaos](https://discuss.elastic.co/u/jhaos)\
**Replies:** 1\
**Last updated:** [September 6, 2021, 9:38am UTC](https://discuss.elastic.co/t/unable-to-test-output-with-filebeat-to-elasticsearch/282654 "2021-09-06T09:38:56Z")

</div>

Hi there, I'm trying to send the logs from Filebeat to Elasticsearch but I'm stuck with a problem regarding credentials or certification. I have the following configuration in filebeat.yml filebeat.modules: -…

---

## [Elastic agent (metricbeat logs): Cannot index event publisher.Event](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364)

<div class="topic-metadata">

**Author:** [@Gomeisa](https://discuss.elastic.co/u/Gomeisa)\
**Replies:** 11\
**Last updated:** [September 6, 2021, 7:37am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364 "2021-09-06T07:37:14Z")

</div>

Hi, I have recently installed a fleet-managed Elastic Agent on my servers. my metricbeat\_monitor-json.log is flooded with this message: {"log.level":"warn","@timestamp":"2021-08-24T15:26:57.009+0430","log.logger":"ela…

---

## [How to reduce the memory usage of filebeat](https://discuss.elastic.co/t/how-to-reduce-the-memory-usage-of-filebeat/283401)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 6\
**Last updated:** [September 6, 2021, 6:05am UTC](https://discuss.elastic.co/t/how-to-reduce-the-memory-usage-of-filebeat/283401 "2021-09-06T06:05:20Z")

</div>

I am using filebeat to collect log files. I'm using filebeat to collect log files, and on one of my servers, filebeat's memory usage is high. I would like to limit the memory usage of filebeat. I have set up queue.mem …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=133)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=135)
