# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=135

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 136

---

## [\[mTLS\]\[filebeat-logstash\]\[beat-input-plugin\] Client certificate hostname verification](https://discuss.elastic.co/t/mtls-filebeat-logstash-beat-input-plugin-client-certificate-hostname-verification/282973)

<div class="topic-metadata">

**Author:** [@LotusD](https://discuss.elastic.co/u/LotusD)\
**Replies:** 6\
**Last updated:** [September 6, 2021, 5:58am UTC](https://discuss.elastic.co/t/mtls-filebeat-logstash-beat-input-plugin-client-certificate-hostname-verification/282973 "2021-09-06T05:58:31Z")

</div>

Dear All, I'm trying to set up mTLS between filebeat (client) and logstash (server). I refer to the documents Secure communication with Logstash | Filebeat Reference \[7.14\] | Elastic Filebeat config: output.logstash…

---

## [\[Beat Monitoring\] Beat name is differ with state](https://discuss.elastic.co/t/beat-monitoring-beat-name-is-differ-with-state/283239)

<div class="topic-metadata">

**Author:** [@InJong\_Park](https://discuss.elastic.co/u/InJong_Park)\
**Replies:** 2\
**Last updated:** [September 6, 2021, 2:35am UTC](https://discuss.elastic.co/t/beat-monitoring-beat-name-is-differ-with-state/283239 "2021-09-06T02:35:35Z")

</div>

Hi. Thanks for your attention. metricbeat.yml name: "sample" metricbeat.log 2021-09-03T14:46:12.876+0900 INFO \[publisher\] pipeline/module.go:113 Beat name: sample curl state \[root@ip-01-02-03-04 15:00:04…

---

## [Created simple filebeat module for ProxySQL](https://discuss.elastic.co/t/created-simple-filebeat-module-for-proxysql/283380)

<div class="topic-metadata">

**Author:** [@altuhovsu](https://discuss.elastic.co/u/altuhovsu)\
**Replies:** 0\
**Last updated:** [September 5, 2021, 5:16pm UTC](https://discuss.elastic.co/t/created-simple-filebeat-module-for-proxysql/283380 "2021-09-05T17:16:02Z")

</div>

If anyone needed, I have created (cloned from mysql module) a simple Filebeat module for parsing ProxySQL logs and ship them to ElasticSearch. https://github.com/altuhovsu/filebeat-proxysql-module

---

## [Filebeat retrieve log with current time stamp](https://discuss.elastic.co/t/filebeat-retrieve-log-with-current-time-stamp/283355)

<div class="topic-metadata">

**Author:** [@josh12](https://discuss.elastic.co/u/josh12)\
**Replies:** 0\
**Last updated:** [September 5, 2021, 1:10am UTC](https://discuss.elastic.co/t/filebeat-retrieve-log-with-current-time-stamp/283355 "2021-09-05T01:10:36Z")

</div>

Can I know whether i can retrieve logs bsed on current date. I am planning for \<log path\>/\*.log and set ignore\_older : 1h if this the case, how it works. will it scan all logs and take based on current date and time …

---

## [Why does every log use a different format for the Timestamp?](https://discuss.elastic.co/t/why-does-every-log-use-a-different-format-for-the-timestamp/283346)

<div class="topic-metadata">

**Author:** [@mhare](https://discuss.elastic.co/u/mhare)\
**Replies:** 10\
**Last updated:** [September 4, 2021, 9:19pm UTC](https://discuss.elastic.co/t/why-does-every-log-use-a-different-format-for-the-timestamp/283346 "2021-09-04T21:19:40Z")

</div>

I am using Stack and Filebeat version 7.13.4 on Windows 10 I have a new log to process and it has a new way to represent the timestamp. As soon as I figure one out, they throw me another This one is starts as: 2021/0…

---

## [Filebeat holding open handles on deleted files](https://discuss.elastic.co/t/filebeat-holding-open-handles-on-deleted-files/283192)

<div class="topic-metadata">

**Author:** [@seadub](https://discuss.elastic.co/u/seadub)\
**Replies:** 2\
**Last updated:** [September 3, 2021, 3:39pm UTC](https://discuss.elastic.co/t/filebeat-holding-open-handles-on-deleted-files/283192 "2021-09-03T15:39:06Z")

</div>

v. 6.8.4 We are experiencing issues daily with lingering open file handles on files which have been deleted by another process which has completed daily compression of logs. The files seem to remain open forever until …

---

## [Filebeats/logstash XML parsing](https://discuss.elastic.co/t/filebeats-logstash-xml-parsing/283249)

<div class="topic-metadata">

**Author:** [@Rabin\_Bhattacharya](https://discuss.elastic.co/u/Rabin_Bhattacharya)\
**Replies:** 1\
**Last updated:** [September 3, 2021, 2:06pm UTC](https://discuss.elastic.co/t/filebeats-logstash-xml-parsing/283249 "2021-09-03T14:06:39Z")

</div>

Hi, I am using ELK stack+filebeats in our project and the application log is integration with filebeats. Filebeat is reading the application log. The log is successfully read by logstash. My question is how to parse the…

---

## [Where are Elastic Agent logs parsed](https://discuss.elastic.co/t/where-are-elastic-agent-logs-parsed/283173)

<div class="topic-metadata">

**Author:** [@sideyourspirit](https://discuss.elastic.co/u/sideyourspirit)\
**Replies:** 3\
**Last updated:** [September 3, 2021, 2:05pm UTC](https://discuss.elastic.co/t/where-are-elastic-agent-logs-parsed/283173 "2021-09-03T14:05:57Z")

</div>

Hello, I've got a question about elastic agent. Are the logs collected by the agent parsed on the host right away or is it done in elasticsearch ingest node?

---

## [Reinstall System Integration Assets](https://discuss.elastic.co/t/reinstall-system-integration-assets/283140)

<div class="topic-metadata">

**Author:** [@Alessandro\_Berto](https://discuss.elastic.co/u/Alessandro_Berto)\
**Replies:** 1\
**Last updated:** [September 3, 2021, 1:21pm UTC](https://discuss.elastic.co/t/reinstall-system-integration-assets/283140 "2021-09-03T13:21:56Z")

</div>

Hello, I had to delete some Dashboards that were not functioning properly, unfortunately I discovered way too late that System integrations cannot be reinstalled. Is there a way to only reinstall the assets (more speci…

---

## [OSQuery Manager Integration Mapping IP (\`host.ip\`) as Keyword](https://discuss.elastic.co/t/osquery-manager-integration-mapping-ip-host-ip-as-keyword/283225)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 5\
**Last updated:** [September 3, 2021, 12:33pm UTC](https://discuss.elastic.co/t/osquery-manager-integration-mapping-ip-host-ip-as-keyword/283225 "2021-09-03T12:33:16Z")

</div>

Hi All, I'm using Fleet with the OSQuery Manager integration for 7.14.0, and I noticed that the data stream it created logs-osquery\_manager.result-default is mapping the host.ip field as a keyword. This is causing an is…

---

## [Heartbeat testing Gateway](https://discuss.elastic.co/t/heartbeat-testing-gateway/283174)

<div class="topic-metadata">

**Author:** [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Replies:** 2\
**Last updated:** [September 3, 2021, 11:08am UTC](https://discuss.elastic.co/t/heartbeat-testing-gateway/283174 "2021-09-03T11:08:47Z")

</div>

Hello Team, we have only 1 internet link in our central location and monitoing multiple wan links of multiple locations. When central internet link went down uptime(dashborads) is showing as the all the sites down. Is t…

---

## [Can filebeat's callback method \`Publish(\_ context.Context, batch publisher.Batch) error\` batch events belong to one file](https://discuss.elastic.co/t/can-filebeats-callback-method-publish-context-context-batch-publisher-batch-error-batch-events-belong-to-one-file/279687)

<div class="topic-metadata">

**Author:** [@shoothzj](https://discuss.elastic.co/u/shoothzj)\
**Replies:** 4\
**Last updated:** [September 3, 2021, 8:42am UTC](https://discuss.elastic.co/t/can-filebeats-callback-method-publish-context-context-batch-publisher-batch-error-batch-events-belong-to-one-file/279687 "2021-09-03T08:42:13Z")

</div>

Can filebeat's callback method Publish(\_ context.Context, batch publisher.Batch) error batch events belong to one file. For example, harvesting three log a.log, b.log, c.log.Call the method with param Batch only file co…

---

## [Filebeat 7.14 dont send Logs to Kafka](https://discuss.elastic.co/t/filebeat-7-14-dont-send-logs-to-kafka/283185)

<div class="topic-metadata">

**Author:** [@Robsen\_Inc](https://discuss.elastic.co/u/Robsen_Inc)\
**Replies:** 2\
**Last updated:** [September 3, 2021, 7:17am UTC](https://discuss.elastic.co/t/filebeat-7-14-dont-send-logs-to-kafka/283185 "2021-09-03T07:17:06Z")

</div>

Hi all, I noticed that I can't send any logs to Kafka with filebeat 7.14. With 7.12 everything works fine. With the same settings, of course. output.kafka: hosts: \["localhost:9092"\] topic: "testkafka" and activate…

---

## [No results match your search criteria](https://discuss.elastic.co/t/no-results-match-your-search-criteria/283146)

<div class="topic-metadata">

**Author:** [@Ahmet\_Oruc](https://discuss.elastic.co/u/Ahmet_Oruc)\
**Replies:** 1\
**Last updated:** [September 3, 2021, 4:30am UTC](https://discuss.elastic.co/t/no-results-match-your-search-criteria/283146 "2021-09-03T04:30:15Z")

</div>

Hi; I have searched from the Kibana Discover screen where I taken a "no results match your search criteria" error from search.

---

## [Understand cron in heartbeats](https://discuss.elastic.co/t/understand-cron-in-heartbeats/283202)

<div class="topic-metadata">

**Author:** [@Sherabu](https://discuss.elastic.co/u/Sherabu)\
**Replies:** 1\
**Last updated:** [September 3, 2021, 4:24am UTC](https://discuss.elastic.co/t/understand-cron-in-heartbeats/283202 "2021-09-03T04:24:13Z")

</div>

Can I know how to read the Cron below schedule: '\*/5 \* \* \* \* \* \*' # Can I know I want it scheduled in certain timing such as 10 am, 2:30 pm, 4 pm and 7 pm. Can this be done? I also saw we have '@every 5s'. Can we us…

---

## [Filebeat service is running but not logging](https://discuss.elastic.co/t/filebeat-service-is-running-but-not-logging/283204)

<div class="topic-metadata">

**Author:** [@afoster](https://discuss.elastic.co/u/afoster)\
**Replies:** 1\
**Last updated:** [September 3, 2021, 4:23am UTC](https://discuss.elastic.co/t/filebeat-service-is-running-but-not-logging/283204 "2021-09-03T04:23:07Z")

</div>

filebeat status showing running and logs are not writting. I have the logging set to debug in the filebeat.yml my filebeat test config comes back OK. any ideas to get logs?

---

## [Error fetching data for metricset haproxy.info: failed fetching haprox info: not supported](https://discuss.elastic.co/t/error-fetching-data-for-metricset-haproxy-info-failed-fetching-haprox-info-not-supported/283229)

<div class="topic-metadata">

**Author:** [@jelocabral](https://discuss.elastic.co/u/jelocabral)\
**Replies:** 0\
**Last updated:** [September 3, 2021, 1:55am UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-haproxy-info-failed-fetching-haprox-info-not-supported/283229 "2021-09-03T01:55:27Z")

</div>

Dear all, I have the below platform: Red Hat 8 HAProxy 1.8.23 Metricbeat 7.14 with haproxy module enabled Viewing /var/log/messages I can see the following error: Sep 2 16:00:30 SERVER1 metricbeat\[2952173\]: 2021-09…

---

## [Nested and/or statements](https://discuss.elastic.co/t/nested-and-or-statements/283223)

<div class="topic-metadata">

**Author:** [@d-ring](https://discuss.elastic.co/u/d-ring)\
**Replies:** 0\
**Last updated:** [September 2, 2021, 11:00pm UTC](https://discuss.elastic.co/t/nested-and-or-statements/283223 "2021-09-02T23:00:50Z")

</div>

I am working on using some nested and/or statements in my winlogbeat to filter out some noisy logs and I am running into an issue where things are not being dropped as expected. I am curious what I have wrong in this sec…

---

## [Heartbeat data transfer](https://discuss.elastic.co/t/heartbeat-data-transfer/283191)

<div class="topic-metadata">

**Author:** [@selin](https://discuss.elastic.co/u/selin)\
**Replies:** 1\
**Last updated:** [September 2, 2021, 5:36pm UTC](https://discuss.elastic.co/t/heartbeat-data-transfer/283191 "2021-09-02T17:36:32Z")

</div>

Hi friends, can i know i set heartbeat schedule every 5m (5 minutes). Why it is sending data every 2 minutes? timeout is 16 secodns

---

## [Fleet managed Elastic Agent environment/deployment name? custom field?](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565)

<div class="topic-metadata">

**Author:** [@mohsen0](https://discuss.elastic.co/u/mohsen0)\
**Replies:** 11\
**Last updated:** [September 2, 2021, 3:59pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565 "2021-09-02T15:59:26Z")

</div>

Hi I was wondering if there is a way to pass parameters to elastic agents when enrolling happens, to differentiate logs pushed from different environments. On the other hand they are some configuration that can be set …

---

## [Metricbeats Dashboard showing some data only for 10 seconds](https://discuss.elastic.co/t/metricbeats-dashboard-showing-some-data-only-for-10-seconds/283177)

<div class="topic-metadata">

**Author:** [@oicfar](https://discuss.elastic.co/u/oicfar)\
**Replies:** 0\
**Last updated:** [September 2, 2021, 2:09pm UTC](https://discuss.elastic.co/t/metricbeats-dashboard-showing-some-data-only-for-10-seconds/283177 "2021-09-02T14:09:39Z")

</div>

I installed ELK Stack 7.14.x on new server. It works, but the metric dashboard show this only for 10 seconds. For the next 20 seconds it looks so metricbeat is getting this data every 10 seconds # Module: system…

---

## [Fleet of agents healthy but not sending data](https://discuss.elastic.co/t/fleet-of-agents-healthy-but-not-sending-data/282440)

<div class="topic-metadata">

**Author:** [@yzpls](https://discuss.elastic.co/u/yzpls)\
**Replies:** 3\
**Last updated:** [September 2, 2021, 9:23am UTC](https://discuss.elastic.co/t/fleet-of-agents-healthy-but-not-sending-data/282440 "2021-09-02T09:23:10Z")

</div>

I have a Fleet of Elastic Agents running on a fresh k8s cluster (running latest ECK). I added a couple integrations via Kibana, like the Kubernetes metrics. But the Kubernetes Dashboards are all empty, and nothing shows …

---

## [Output to Mutliple Kafka Brokers](https://discuss.elastic.co/t/output-to-mutliple-kafka-brokers/283136)

<div class="topic-metadata">

**Author:** [@JSelastic](https://discuss.elastic.co/u/JSelastic)\
**Replies:** 0\
**Last updated:** [September 2, 2021, 7:55am UTC](https://discuss.elastic.co/t/output-to-mutliple-kafka-brokers/283136 "2021-09-02T07:55:46Z")

</div>

Hi, Our winlogbeat configuration outputs to multiple kafka brokers. We are curious if all of the logs from winlogbeat be sent to all brokers simultaneously or will it only be sent to one broker? Thank you

---

## [PANW Integration - Timezone Offset Problem](https://discuss.elastic.co/t/panw-integration-timezone-offset-problem/282978)

<div class="topic-metadata">

**Author:** [@neil6323](https://discuss.elastic.co/u/neil6323)\
**Replies:** 4\
**Last updated:** [September 1, 2021, 10:09pm UTC](https://discuss.elastic.co/t/panw-integration-timezone-offset-problem/282978 "2021-09-01T22:09:26Z")

</div>

Elastic Cluster Version 7.14.0. I am using Elastic-Agent and the PANW integration to ingest Palo Alto Firewall logs. Once ingested the event times are incorrect by the equivalent of the timezone offset. I have found arti…

---

## [Unable to install fleet server](https://discuss.elastic.co/t/unable-to-install-fleet-server/282613)

<div class="topic-metadata">

**Author:** [@Dovan](https://discuss.elastic.co/u/Dovan)\
**Replies:** 9\
**Last updated:** [September 1, 2021, 6:57pm UTC](https://discuss.elastic.co/t/unable-to-install-fleet-server/282613 "2021-09-01T18:57:07Z")

</div>

I'm trying to install fleet server on my local server (the same where elasticsearch is installed) and I'm not succeeding. I've tried to uninstall and reinstall elastic-agent 7.14 and it doesn't work. the commands and th…

---

## [Metricbeat failed reading counters: failed collecting counter values: No data to return](https://discuss.elastic.co/t/metricbeat-failed-reading-counters-failed-collecting-counter-values-no-data-to-return/283082)

<div class="topic-metadata">

**Author:** [@Woolis\_Xiibil\_Peek](https://discuss.elastic.co/u/Woolis_Xiibil_Peek)\
**Replies:** 0\
**Last updated:** [September 1, 2021, 4:49pm UTC](https://discuss.elastic.co/t/metricbeat-failed-reading-counters-failed-collecting-counter-values-no-data-to-return/283082 "2021-09-01T16:49:15Z")

</div>

Hi. I'm tyring to read the perfmon of a Windows Server 2016. I'm using the Windows module, but I'm getting this message in Kibana. "failed reading counters: failed collecting counter values: No data to return" I have n…

---

## [Multiple output in Filebeat](https://discuss.elastic.co/t/multiple-output-in-filebeat/283001)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 3\
**Last updated:** [September 1, 2021, 4:39pm UTC](https://discuss.elastic.co/t/multiple-output-in-filebeat/283001 "2021-09-01T16:39:23Z")

</div>

I am trying to setup multiple index outputs from the same filebeat.yml. I have different paths on the same server and I need each path to go to the same logstash but have a different index name. Is it possible?

---

## [Custom analyzers in Packetbeat index template](https://discuss.elastic.co/t/custom-analyzers-in-packetbeat-index-template/283074)

<div class="topic-metadata">

**Author:** [@yotamgod](https://discuss.elastic.co/u/yotamgod)\
**Replies:** 0\
**Last updated:** [September 1, 2021, 4:05pm UTC](https://discuss.elastic.co/t/custom-analyzers-in-packetbeat-index-template/283074 "2021-09-01T16:05:40Z")

</div>

Hi, I recently started using Packetbeat and started adding my own fields to the index template (using the setup.template.append\_fields). I was wondering if there is some way to create a custom analyzer for my custom te…

---

## [Filebeat 7.14.0 filestream input field log.offset is character count of the line](https://discuss.elastic.co/t/filebeat-7-14-0-filestream-input-field-log-offset-is-character-count-of-the-line/282956)

<div class="topic-metadata">

**Author:** [@Michael\_Savettiere](https://discuss.elastic.co/u/Michael_Savettiere)\
**Replies:** 4\
**Last updated:** [September 1, 2021, 2:22pm UTC](https://discuss.elastic.co/t/filebeat-7-14-0-filestream-input-field-log-offset-is-character-count-of-the-line/282956 "2021-09-01T14:22:10Z")

</div>

Using Filebeat 7.14.0 input: filestream and output.console: pretty: true I see that the value of log.offset is the size of the event.message and not the offset from the beginning of the file. I used to use input: log an…

---

## [Filebeat unable to send the data to Elastic search](https://discuss.elastic.co/t/filebeat-unable-to-send-the-data-to-elastic-search/282927)

<div class="topic-metadata">

**Author:** [@miqdaadp](https://discuss.elastic.co/u/miqdaadp)\
**Replies:** 1\
**Last updated:** [September 1, 2021, 12:14pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-send-the-data-to-elastic-search/282927 "2021-09-01T12:14:55Z")

</div>

Hello, I am trying to send the data from server via Filebeat to Elastic search . Trying to see the data on kibana but i cannot see the data on Kibana. It says no Data. When i started the filebeat service its started …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=134)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=136)
