# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=138

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 139

---

## [Fiebeat test output error (Java heap size)](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483)

<div class="topic-metadata">

**Author:** [@Ahmed2021](https://discuss.elastic.co/u/Ahmed2021)\
**Replies:** 10\
**Last updated:** [August 23, 2021, 2:50am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483 "2021-08-23T02:50:38Z")

</div>

Hi All Can anyone help one the below error ? the file beat fails the test and we unable to access the Wazuh's dashboard \[root@ELS01 conf\]# filebeat test output elasticsearch: http://1.1.1.1:9200... parse url... OK c…

---

## [Error fetching fields for index pattern file\*](https://discuss.elastic.co/t/error-fetching-fields-for-index-pattern-file/282120)

<div class="topic-metadata">

**Author:** [@\_bugc4t](https://discuss.elastic.co/u/_bugc4t)\
**Replies:** 2\
**Last updated:** [August 23, 2021, 12:22am UTC](https://discuss.elastic.co/t/error-fetching-fields-for-index-pattern-file/282120 "2021-08-23T00:22:53Z")

</div>

Helo, bit new to elastic but I'm trying to get data into my ECK deployment. I'm using Filebeat to do this. I've got one option on the index patterns page with my File name but and I selected file\*. I'm worried that not a…

---

## [Not able to monitor windows events on running metricbeat as a container](https://discuss.elastic.co/t/not-able-to-monitor-windows-events-on-running-metricbeat-as-a-container/282161)

<div class="topic-metadata">

**Author:** [@rajesh\_k](https://discuss.elastic.co/u/rajesh_k)\
**Replies:** 0\
**Last updated:** [August 22, 2021, 8:50am UTC](https://discuss.elastic.co/t/not-able-to-monitor-windows-events-on-running-metricbeat-as-a-container/282161 "2021-08-22T08:50:53Z")

</div>

Not able to monitor windows events on running metricbeat as a container. Metricbeat is launched as container using below command FROM docker.elastic.co/beats/metricbeat:7.14.0 COPY metricbeat.yml /usr/share/metricbeat…

---

## [Metricbeat cannot setup dashboards to AWS Elasticsearch](https://discuss.elastic.co/t/metricbeat-cannot-setup-dashboards-to-aws-elasticsearch/282135)

<div class="topic-metadata">

**Author:** [@buulq90](https://discuss.elastic.co/u/buulq90)\
**Replies:** 1\
**Last updated:** [August 22, 2021, 4:29am UTC](https://discuss.elastic.co/t/metricbeat-cannot-setup-dashboards-to-aws-elasticsearch/282135 "2021-08-22T04:29:36Z")

</div>

Hello all, I'm first using of ELK stack and got some issue when trying to connect the Metricbeat to my AWS Elasticsearch. My environment is as below: AWS Elasticsearch 7.10 Metricbeat OSS 7.10.0 - Windows-x86\_64 …

---

## [Filebeat Monitor app (Visualize or Tail)](https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920)

<div class="topic-metadata">

**Author:** [@Saleem](https://discuss.elastic.co/u/Saleem)\
**Replies:** 5\
**Last updated:** [August 21, 2021, 2:32pm UTC](https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920 "2021-08-21T14:32:18Z")

</div>

Sorry i'm new to the elasticstack, but bear with me I'm trying to setup ES-Kibana-Filebeat for Java application logs processing The specific log files i'm trying to visualize aren't one of the log types with modules T…

---

## [Docker module metricbeat can't reach docker socket](https://discuss.elastic.co/t/docker-module-metricbeat-cant-reach-docker-socket/282130)

<div class="topic-metadata">

**Author:** [@Trung\_Dam1](https://discuss.elastic.co/u/Trung_Dam1)\
**Replies:** 0\
**Last updated:** [August 21, 2021, 4:31am UTC](https://discuss.elastic.co/t/docker-module-metricbeat-cant-reach-docker-socket/282130 "2021-08-21T04:31:36Z")

</div>

Hi everyone I use metricbeat to get metrics from docker swarm, I have metricbeat on node manager and worker but not getting any index on docker, i tried output metricbeat to file but what i get is only system module wh…

---

## [Multiple "-module: auditd" stanzas in config file lead to problems](https://discuss.elastic.co/t/multiple-module-auditd-stanzas-in-config-file-lead-to-problems/282122)

<div class="topic-metadata">

**Author:** [@barely47](https://discuss.elastic.co/u/barely47)\
**Replies:** 0\
**Last updated:** [August 20, 2021, 11:02pm UTC](https://discuss.elastic.co/t/multiple-module-auditd-stanzas-in-config-file-lead-to-problems/282122 "2021-08-20T23:02:03Z")

</div>

A user of mine took a provided auditbeat.yml config file and converted it into something that included: - module: auditd enabled: true audit\_rules: "-a always,exit -F arch=b32 -S all -k 32bit-abi" user.det…

---

## [Filebeat Tokenizer Cisco Syslog Problem](https://discuss.elastic.co/t/filebeat-tokenizer-cisco-syslog-problem/282121)

<div class="topic-metadata">

**Author:** [@savethebyte](https://discuss.elastic.co/u/savethebyte)\
**Replies:** 0\
**Last updated:** [August 20, 2021, 10:05pm UTC](https://discuss.elastic.co/t/filebeat-tokenizer-cisco-syslog-problem/282121 "2021-08-20T22:05:09Z")

</div>

Hello!, I am receiving the following error when ingesting syslog messages with Filebeat (7.9.3): "error": { "message": "GoError: could not find delimiter: \`\` in remaining: \`\<160\>Aug 20 16:48:25 10.244.127.139 027…

---

## [Not getting index with docker module](https://discuss.elastic.co/t/not-getting-index-with-docker-module/282075)

<div class="topic-metadata">

**Author:** [@Trung\_Dam1](https://discuss.elastic.co/u/Trung_Dam1)\
**Replies:** 0\
**Last updated:** [August 20, 2021, 12:42pm UTC](https://discuss.elastic.co/t/not-getting-index-with-docker-module/282075 "2021-08-20T12:42:56Z")

</div>

Hi everyone, I am new to using elasticsearch I have a problem with metricbeat specifically with the docker module With the configuration as below I have renamed the index with the event.moudle field which will change …

---

## [Unable to communicate with Fleet Server after Upgrade to 7.14](https://discuss.elastic.co/t/unable-to-communicate-with-fleet-server-after-upgrade-to-7-14/280388)

<div class="topic-metadata">

**Author:** [@thleh](https://discuss.elastic.co/u/thleh)\
**Replies:** 15\
**Last updated:** [August 20, 2021, 7:08am UTC](https://discuss.elastic.co/t/unable-to-communicate-with-fleet-server-after-upgrade-to-7-14/280388 "2021-08-20T07:08:18Z")

</div>

Hi, after Upgrading to 7.14 (elasticsearch and elastic-agent hosting fleet-server) i'm unable to start other elastic-agents version 7.14. 2021-08-04T09:11:32.489+0200 ERROR fleet/fleet\_gateway.go:205 Could not communic…

---

## [Packetbeat performance and sizing](https://discuss.elastic.co/t/packetbeat-performance-and-sizing/281769)

<div class="topic-metadata">

**Author:** [@gintek](https://discuss.elastic.co/u/gintek)\
**Replies:** 2\
**Last updated:** [August 20, 2021, 6:04am UTC](https://discuss.elastic.co/t/packetbeat-performance-and-sizing/281769 "2021-08-20T06:04:43Z")

</div>

Hello, I'm planning to use packetbeat on dedicated servers, getting the traffic from mirror ports on switch. Dedicated server will Virtual Machine with Linux of course. I couldn't find in documentation what resources …

---

## [Winlogbeat authorization error on AWS ELK](https://discuss.elastic.co/t/winlogbeat-authorization-error-on-aws-elk/281757)

<div class="topic-metadata">

**Author:** [@Juan\_Gutierrez](https://discuss.elastic.co/u/Juan_Gutierrez)\
**Replies:** 14\
**Last updated:** [August 20, 2021, 4:53am UTC](https://discuss.elastic.co/t/winlogbeat-authorization-error-on-aws-elk/281757 "2021-08-20T04:53:43Z")

</div>

Hi there, I have an AWS Elasticsearch stack - version 7.10 and I would like to ship our fleet of EC2's Windows event logs to it. I've followed the documentation and used an earlier version of Winlogbeat - version 7.12.…

---

## [Connection reset by peer](https://discuss.elastic.co/t/connection-reset-by-peer/281667)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 1\
**Last updated:** [August 20, 2021, 12:58am UTC](https://discuss.elastic.co/t/connection-reset-by-peer/281667 "2021-08-20T00:58:31Z")

</div>

filebeat now emits the following error 2021-08-17T06:00:10.472+0900 ERROR \[logstash\] logstash/async.go:280 Failed to publish events caused by: write tcp XXX.XXX.XXX.XXX:XXX-\>XXX.XXX.XXX.XXX:XXX: write: conne…

---

## [Metricbeat ZFS capture volume size](https://discuss.elastic.co/t/metricbeat-zfs-capture-volume-size/282012)

<div class="topic-metadata">

**Author:** [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Replies:** 0\
**Last updated:** [August 19, 2021, 9:26pm UTC](https://discuss.elastic.co/t/metricbeat-zfs-capture-volume-size/282012 "2021-08-19T21:26:10Z")

</div>

After a few hours I've been unable to get Metricbeat to read ZFS stats. It looks like GitHub - maireanu/zfsbeat has gone stale as the last work was 2 years ago. Seeing as ZFS is nodev in /proc/filesystems the default f…

---

## [Okta filebeat module ingest pipeline not running](https://discuss.elastic.co/t/okta-filebeat-module-ingest-pipeline-not-running/281917)

<div class="topic-metadata">

**Author:** [@LiamSennitt](https://discuss.elastic.co/u/LiamSennitt)\
**Replies:** 3\
**Last updated:** [August 19, 2021, 1:39pm UTC](https://discuss.elastic.co/t/okta-filebeat-module-ingest-pipeline-not-running/281917 "2021-08-19T13:39:08Z")

</div>

The Okta filebeat module doesn't appear to be executing the ingest pipeline as expected and returns events in the structure below. { "@timestamp": "", "@metadata": { "beat": "filebeat", "type": "\_doc…

---

## [TLS... WARN secure connection disabled talk to server... ERROR Get "http://192.168.0.101:9200": EOF](https://discuss.elastic.co/t/tls-warn-secure-connection-disabled-talk-to-server-error-get-http-192-168-0-101-9200-eof/281969)

<div class="topic-metadata">

**Author:** [@Dubey\_Ravi\_vinod](https://discuss.elastic.co/u/Dubey_Ravi_vinod)\
**Replies:** 0\
**Last updated:** [August 19, 2021, 1:17pm UTC](https://discuss.elastic.co/t/tls-warn-secure-connection-disabled-talk-to-server-error-get-http-192-168-0-101-9200-eof/281969 "2021-08-19T13:17:18Z")

</div>

Getting this error, while configuration of winlogbeat. winlogbeat.yml winlogbeat.event\_logs: - name: Application ignore\_older: 72h - name: System - name: Security processors: - script: …

---

## [Filebeat god restart](https://discuss.elastic.co/t/filebeat-god-restart/281723)

<div class="topic-metadata">

**Author:** [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Replies:** 7\
**Last updated:** [August 19, 2021, 1:21pm UTC](https://discuss.elastic.co/t/filebeat-god-restart/281723 "2021-08-19T13:21:47Z")

</div>

I want to restart an old Filebeat service after modifying its output. This is the result of ps -eaf | grep filebeat: root 6405 1 0 2020 ? 00:00:00 /usr/share/filebeat/bin/filebeat-god -r / -n -p /var/…

---

## [Does filebeats import MongoDB collections to ES?](https://discuss.elastic.co/t/does-filebeats-import-mongodb-collections-to-es/281965)

<div class="topic-metadata">

**Author:** [@evo](https://discuss.elastic.co/u/evo)\
**Replies:** 0\
**Last updated:** [August 19, 2021, 1:00pm UTC](https://discuss.elastic.co/t/does-filebeats-import-mongodb-collections-to-es/281965 "2021-08-19T13:00:08Z")

</div>

Hi, Sorry for the basic question but I am finding the docs a bit confusing. I am trying to create an ES search index for a large (1TB) mongodb and I am trying to find out how to do that. I cam across filebeat and saw …

---

## [Filebeat holding deleted files... please help with 'correct' values to use in close\_inactive, etc](https://discuss.elastic.co/t/filebeat-holding-deleted-files-please-help-with-correct-values-to-use-in-close-inactive-etc/281956)

<div class="topic-metadata">

**Author:** [@baldpoem54](https://discuss.elastic.co/u/baldpoem54)\
**Replies:** 0\
**Last updated:** [August 19, 2021, 12:35pm UTC](https://discuss.elastic.co/t/filebeat-holding-deleted-files-please-help-with-correct-values-to-use-in-close-inactive-etc/281956 "2021-08-19T12:35:53Z")

</div>

Hoping the community here can help me as google hasn't. I have a case where filebeat is holding deleted files open until the process is recycled. I know there on configs to help address this, but I'm struggling on what…

---

## [Filebeat multiline pattern for PHP stack trace](https://discuss.elastic.co/t/filebeat-multiline-pattern-for-php-stack-trace/281003)

<div class="topic-metadata">

**Author:** [@Thessis940](https://discuss.elastic.co/u/Thessis940)\
**Replies:** 1\
**Last updated:** [August 19, 2021, 8:38am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-for-php-stack-trace/281003 "2021-08-19T08:38:06Z")

</div>

I am trying to import the PHP FPM logs into an ELK stack. For this I use the filebeat to read the files. Before sending this data to logstash, the multiline log entries should be merged. For this I built this filebeat c…

---

## [Can a winlogbeats agent be used as a relay?](https://discuss.elastic.co/t/can-a-winlogbeats-agent-be-used-as-a-relay/281892)

<div class="topic-metadata">

**Author:** [@jeromeat](https://discuss.elastic.co/u/jeromeat)\
**Replies:** 1\
**Last updated:** [August 19, 2021, 12:53am UTC](https://discuss.elastic.co/t/can-a-winlogbeats-agent-be-used-as-a-relay/281892 "2021-08-19T00:53:46Z")

</div>

Is it possible for one Windows server running Winlogbeats to forward its windows event logs to another Windows server running Winlogbeats that can then forward/relay them to elastic? I'd prefer not to go through the com…

---

## [How to upgrade Logstash in Filebeat + Logstash pipeline?](https://discuss.elastic.co/t/how-to-upgrade-logstash-in-filebeat-logstash-pipeline/280984)

<div class="topic-metadata">

**Author:** [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Replies:** 5\
**Last updated:** [August 18, 2021, 7:03pm UTC](https://discuss.elastic.co/t/how-to-upgrade-logstash-in-filebeat-logstash-pipeline/280984 "2021-08-18T19:03:14Z")

</div>

I'm working on a system that uses Filebeat (v7.8) with Logstash output (v2.2.4). Filebeat reads files from a specific folder and publishes the data to Logstash which in turn sends the output to RabbitMQ. I need to upgr…

---

## [How to understand the new registry file in filebeat](https://discuss.elastic.co/t/how-to-understand-the-new-registry-file-in-filebeat/281865)

<div class="topic-metadata">

**Author:** [@Opeyemi\_Onikute](https://discuss.elastic.co/u/Opeyemi_Onikute)\
**Replies:** 0\
**Last updated:** [August 18, 2021, 5:47pm UTC](https://discuss.elastic.co/t/how-to-understand-the-new-registry-file-in-filebeat/281865 "2021-08-18T17:47:17Z")

</div>

This is a follow-up to this question about understanding how the registry file works: How to understand "registry" file in filebeat Since version 7, the registry file has changed to a sub-directory structure and I need …

---

## [Filebeat/Logstash doesn't send system.auth.\*.\* field data to Elastic Search - v 7.14](https://discuss.elastic.co/t/filebeat-logstash-doesnt-send-system-auth-field-data-to-elastic-search-v-7-14/281793)

<div class="topic-metadata">

**Author:** [@angheladrianclaudiu](https://discuss.elastic.co/u/angheladrianclaudiu)\
**Replies:** 2\
**Last updated:** [August 18, 2021, 3:01pm UTC](https://discuss.elastic.co/t/filebeat-logstash-doesnt-send-system-auth-field-data-to-elastic-search-v-7-14/281793 "2021-08-18T15:01:12Z")

</div>

I've installed ELK stack with steps described here: Current Elastic Release (7.14) Current Kibana Release (7.14) Current Logstash Release (7.14) Current Filebeat Release (7.14) I also used the Logstash configuration…

---

## [Filebeat does not process any files after restart](https://discuss.elastic.co/t/filebeat-does-not-process-any-files-after-restart/281536)

<div class="topic-metadata">

**Author:** [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Replies:** 6\
**Last updated:** [August 18, 2021, 2:55pm UTC](https://discuss.elastic.co/t/filebeat-does-not-process-any-files-after-restart/281536 "2021-08-18T14:55:12Z")

</div>

Hi, We restarted filebeat in our server today and after restarting no new logs are pushed to logstash anymore. Here is the config that we use for the input: filebeat.inputs: - type: log enabled: true paths: - /v…

---

## [Use Filebeat for CSV logs?](https://discuss.elastic.co/t/use-filebeat-for-csv-logs/281722)

<div class="topic-metadata">

**Author:** [@ChrisClem1](https://discuss.elastic.co/u/ChrisClem1)\
**Replies:** 1\
**Last updated:** [August 18, 2021, 12:21pm UTC](https://discuss.elastic.co/t/use-filebeat-for-csv-logs/281722 "2021-08-18T12:21:51Z")

</div>

I am new to elastic. I have many gigabytes of csv logs that I want to load into elastic. I assume that I use filebeat. What do I need to configure in filebeat apart from the path to the logs (/home/assessor/Desktop/audi…

---

## [Port need to open for filebeat and logstash](https://discuss.elastic.co/t/port-need-to-open-for-filebeat-and-logstash/281762)

<div class="topic-metadata">

**Author:** [@naaviin](https://discuss.elastic.co/u/naaviin)\
**Replies:** 2\
**Last updated:** [August 18, 2021, 10:21am UTC](https://discuss.elastic.co/t/port-need-to-open-for-filebeat-and-logstash/281762 "2021-08-18T10:21:15Z")

</div>

Hi friends, I have open using firewalld port 5044 in ELK server. I i open source IP and source Port in ELK server. However i am hitting connection refuse when i telnet to logstash from beats server telnet 192.168.1.101…

---

## [Avoid logging password when using hint based autodiscover](https://discuss.elastic.co/t/avoid-logging-password-when-using-hint-based-autodiscover/281797)

<div class="topic-metadata">

**Author:** [@Rasmus\_Breinholm\_Rom](https://discuss.elastic.co/u/Rasmus_Breinholm_Rom)\
**Replies:** 0\
**Last updated:** [August 18, 2021, 9:24am UTC](https://discuss.elastic.co/t/avoid-logging-password-when-using-hint-based-autodiscover/281797 "2021-08-18T09:24:49Z")

</div>

Hi When using Hint based autodiscover, it is possible to configure usernames and password for modules like MySql using labels on a docker container. The problem with this is that all labels are logged into elasticsearc…

---

## [Journalbeat and logfiles](https://discuss.elastic.co/t/journalbeat-and-logfiles/281013)

<div class="topic-metadata">

**Author:** [@colttt](https://discuss.elastic.co/u/colttt)\
**Replies:** 1\
**Last updated:** [August 18, 2021, 7:42am UTC](https://discuss.elastic.co/t/journalbeat-and-logfiles/281013 "2021-08-18T07:42:30Z")

</div>

Hello short question, is it possible that journalbeat also read normal logfiles (like from nginx/apache) or does it read just journald? And if yes, have I to pay attention to something? thanks in advanced!

---

## [Filebeat with syslog input loses millisecond precision](https://discuss.elastic.co/t/filebeat-with-syslog-input-loses-millisecond-precision/281748)

<div class="topic-metadata">

**Author:** [@chaserb](https://discuss.elastic.co/u/chaserb)\
**Replies:** 0\
**Last updated:** [August 17, 2021, 8:26pm UTC](https://discuss.elastic.co/t/filebeat-with-syslog-input-loses-millisecond-precision/281748 "2021-08-17T20:26:55Z")

</div>

Hello, I have filebeat 7.12.0 on Debian 10 with two log inputs and one syslog input all going to the same index in an elasticsearch output. For the log inputs, I'm seeing @timestamp values in the index with millisecond …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=137)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=139)
