# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=139

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 140

---

## [Fleet-server and filebeats in one elastic-agent](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355)

<div class="topic-metadata">

**Author:** [@tkarczewski](https://discuss.elastic.co/u/tkarczewski)\
**Replies:** 11\
**Last updated:** [August 17, 2021, 6:42pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355 "2021-08-17T18:42:39Z")

</div>

Hi, How to use one elastic-agent on host where elastic stack is deployed to be as fleet server and filebeat collecting udp syslog messages? I red that elastic agent can be use for fleet server and data collection simult…

---

## [Filebeat input types log and filestream metadata for file path/name differ](https://discuss.elastic.co/t/filebeat-input-types-log-and-filestream-metadata-for-file-path-name-differ/281713)

<div class="topic-metadata">

**Author:** [@Michael\_Savettiere](https://discuss.elastic.co/u/Michael_Savettiere)\
**Replies:** 0\
**Last updated:** [August 17, 2021, 3:21pm UTC](https://discuss.elastic.co/t/filebeat-input-types-log-and-filestream-metadata-for-file-path-name-differ/281713 "2021-08-17T15:21:41Z")

</div>

I have been using beats input type log, but with the 7.14.0 release I noticed that the filestream input type is supposed to be an improvement to the log input type. I noticed that the event meta data differs between the …

---

## [Decode\_json\_fields and array](https://discuss.elastic.co/t/decode-json-fields-and-array/281530)

<div class="topic-metadata">

**Author:** [@s17n](https://discuss.elastic.co/u/s17n)\
**Replies:** 2\
**Last updated:** [August 17, 2021, 12:11pm UTC](https://discuss.elastic.co/t/decode-json-fields-and-array/281530 "2021-08-17T12:11:49Z")

</div>

Hello, It seems decode\_json\_fields can't decode array. This is my log : {"level":"panic","application":"command","stack":\[{"func":"main.func1","line":"51","source":"main.go"},{"func":"gopanic","line":"965","source":"p…

---

## [Filter data using HttpRequest](https://discuss.elastic.co/t/filter-data-using-httprequest/281508)

<div class="topic-metadata">

**Author:** [@fed](https://discuss.elastic.co/u/fed)\
**Replies:** 6\
**Last updated:** [August 17, 2021, 12:02pm UTC](https://discuss.elastic.co/t/filter-data-using-httprequest/281508 "2021-08-17T12:02:12Z")

</div>

Hi! I'm new to the ELK stack and I'd like to know if there's a way to filter the logs in filebeat using a processor that checks some values from an external REST API, and based on the response, it drops or sends the eve…

---

## [Get Windows Defender logs in Logstash using Winlogbeat](https://discuss.elastic.co/t/get-windows-defender-logs-in-logstash-using-winlogbeat/281538)

<div class="topic-metadata">

**Author:** [@Logstash\_logs](https://discuss.elastic.co/u/Logstash_logs)\
**Replies:** 1\
**Last updated:** [August 17, 2021, 11:39am UTC](https://discuss.elastic.co/t/get-windows-defender-logs-in-logstash-using-winlogbeat/281538 "2021-08-17T11:39:43Z")

</div>

Hi, I'm trying to send windows defender logs to logstash using winlogbeat. I added name: Microsoft-Windows-Windows Defender/Operational in winlogbeat.yml file but not getting any logs related to defender only Microsoft…

---

## [Filebeat modules need better documentation (e.g. docker local logging, traefik json logging)](https://discuss.elastic.co/t/filebeat-modules-need-better-documentation-e-g-docker-local-logging-traefik-json-logging/281675)

<div class="topic-metadata">

**Author:** [@bluepuma77](https://discuss.elastic.co/u/bluepuma77)\
**Replies:** 0\
**Last updated:** [August 17, 2021, 11:38am UTC](https://discuss.elastic.co/t/filebeat-modules-need-better-documentation-e-g-docker-local-logging-traefik-json-logging/281675 "2021-08-17T11:38:51Z")

</div>

Hi all, I would like to use filebeat to monitor my container infrastructure. I am wondering why some of the filebeat modules seem so insufficient documented about any details that are beyond the most standard configurat…

---

## [Beats output to Logstash AND Elastic?](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597)

<div class="topic-metadata">

**Author:** [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Replies:** 6\
**Last updated:** [August 17, 2021, 11:36am UTC](https://discuss.elastic.co/t/beats-output-to-logstash-and-elastic/281597 "2021-08-17T11:36:17Z")

</div>

Is it possible to Output to Elasticsearch AND Logstash at the same time from a Beat?

---

## [Events beat](https://discuss.elastic.co/t/events-beat/281666)

<div class="topic-metadata">

**Author:** [@jubin03](https://discuss.elastic.co/u/jubin03)\
**Replies:** 1\
**Last updated:** [August 17, 2021, 11:22am UTC](https://discuss.elastic.co/t/events-beat/281666 "2021-08-17T11:22:12Z")

</div>

Is it possible to fetch events via API to beats and shipped to log stash or elastic search

---

## [Filebeat harvests system logs even when not specified](https://discuss.elastic.co/t/filebeat-harvests-system-logs-even-when-not-specified/281626)

<div class="topic-metadata">

**Author:** [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Replies:** 0\
**Last updated:** [August 17, 2021, 5:49am UTC](https://discuss.elastic.co/t/filebeat-harvests-system-logs-even-when-not-specified/281626 "2021-08-17T05:49:40Z")

</div>

filebeat.yml: path.config: /Users/sp/servers/filebeat-7.14.0-darwin-x86\_64/ filebeat.config: inputs: enabled: false path: /Users/sp/servers/filebeat-7.14.0-darwin-x86\_64/filebeat.yml filebeat.inputs: - type…

---

## [Error creating runner from config: failed to create input: Can only start an input when all related states are finished:](https://discuss.elastic.co/t/error-creating-runner-from-config-failed-to-create-input-can-only-start-an-input-when-all-related-states-are-finished/281328)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 2\
**Last updated:** [August 17, 2021, 4:34am UTC](https://discuss.elastic.co/t/error-creating-runner-from-config-failed-to-create-input-can-only-start-an-input-when-all-related-states-are-finished/281328 "2021-08-17T04:34:50Z")

</div>

Hi all I get the logs from suricata(eve.json) so I've enabled suricata module in filebeat. But whenever I start filebeat, I got this error. 2021-08-13T18:11:18.650+0900 ERROR \[reload\] cfgfile/list.go:99 Error creating…

---

## [Winlogbeat Sysmon Configuration Registry fields seems to map the wrong value of the registry](https://discuss.elastic.co/t/winlogbeat-sysmon-configuration-registry-fields-seems-to-map-the-wrong-value-of-the-registry/281521)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [August 16, 2021, 7:42pm UTC](https://discuss.elastic.co/t/winlogbeat-sysmon-configuration-registry-fields-seems-to-map-the-wrong-value-of-the-registry/281521 "2021-08-16T19:42:47Z")

</div>

Third attempt to escalate this... Can someone please verify and confirm this bug? Same issue in 7.13.1.. Willem

---

## [Re-create Fleet System Integration Data Streams](https://discuss.elastic.co/t/re-create-fleet-system-integration-data-streams/281443)

<div class="topic-metadata">

**Author:** [@tomukasteris](https://discuss.elastic.co/u/tomukasteris)\
**Replies:** 1\
**Last updated:** [August 16, 2021, 11:45am UTC](https://discuss.elastic.co/t/re-create-fleet-system-integration-data-streams/281443 "2021-08-16T11:45:10Z")

</div>

Hello, By mistake did delete System integration Data Streams. How reinstall/re-create missing data streams for System integration?

---

## [Transferring log files via Filebeat to Logstash and then Elasticsearch](https://discuss.elastic.co/t/transferring-log-files-via-filebeat-to-logstash-and-then-elasticsearch/281471)

<div class="topic-metadata">

**Author:** [@Nisha2297](https://discuss.elastic.co/u/Nisha2297)\
**Replies:** 4\
**Last updated:** [August 16, 2021, 5:01am UTC](https://discuss.elastic.co/t/transferring-log-files-via-filebeat-to-logstash-and-then-elasticsearch/281471 "2021-08-16T05:01:53Z")

</div>

Hi, I am exploring on Elastic Stack and working on creating a pipeline to fetch logs via filbeat/metricbeat to logstash and then to Elasticsearch. I have updated the filebeat.yml/metricbeat.yml and logstash.conf file. C…

---

## [How to monitor Kubernetes Pod's status?](https://discuss.elastic.co/t/how-to-monitor-kubernetes-pods-status/281488)

<div class="topic-metadata">

**Author:** [@avi-devops](https://discuss.elastic.co/u/avi-devops)\
**Replies:** 1\
**Last updated:** [August 16, 2021, 2:41am UTC](https://discuss.elastic.co/t/how-to-monitor-kubernetes-pods-status/281488 "2021-08-16T02:41:24Z")

</div>

Hello Experts, I am very new to this wonderful platform, hence learning slowly to grab this technology. Meanwhile, I was wondering how to monitor and display Kubernetes pod status in Kibana ? Please let me know your v…

---

## [How to Change Default Index Pattern on Filebeat dashboards on Kibana](https://discuss.elastic.co/t/how-to-change-default-index-pattern-on-filebeat-dashboards-on-kibana/281486)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 4\
**Last updated:** [August 15, 2021, 7:51pm UTC](https://discuss.elastic.co/t/how-to-change-default-index-pattern-on-filebeat-dashboards-on-kibana/281486 "2021-08-15T19:51:42Z")

</div>

Hi. I am having a hard time trying to figure this out. I changed the default index name to suricata-ids. Also, added this line in order to use this new index on the default dashboards. But still, default dashboa…

---

## [HTTPJson Input Request Transforms](https://discuss.elastic.co/t/httpjson-input-request-transforms/281481)

<div class="topic-metadata">

**Author:** [@Oliver2](https://discuss.elastic.co/u/Oliver2)\
**Replies:** 0\
**Last updated:** [August 15, 2021, 2:47pm UTC](https://discuss.elastic.co/t/httpjson-input-request-transforms/281481 "2021-08-15T14:47:45Z")

</div>

Im trying to create a custom input for: I can get it to produce events fine with the following config: - type: httpjson config\_version: 2 interval: 1h request.url: https://services.nvd.nist.gov/rest/json/cves/1.…

---

## [The resident memory of the filebeat keep increasing if hitting the "harvester\_limit"](https://discuss.elastic.co/t/the-resident-memory-of-the-filebeat-keep-increasing-if-hitting-the-harvester-limit/281473)

<div class="topic-metadata">

**Author:** [@VinothNarasimhan](https://discuss.elastic.co/u/VinothNarasimhan)\
**Replies:** 0\
**Last updated:** [August 15, 2021, 7:19am UTC](https://discuss.elastic.co/t/the-resident-memory-of-the-filebeat-keep-increasing-if-hitting-the-harvester-limit/281473 "2021-08-15T07:19:40Z")

</div>

Hi, We used the filebeat to ship the logs to logstash. We used the filebeat version 7.3.1. We do set the harvester\_limit: 30 close\_timeout: 15 close\_inactive: 5m for the input. It works fine for a while . At certain t…

---

## [Harvester could not be started on new file & registry already stopped](https://discuss.elastic.co/t/harvester-could-not-be-started-on-new-file-registry-already-stopped/281444)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 0\
**Last updated:** [August 14, 2021, 2:50pm UTC](https://discuss.elastic.co/t/harvester-could-not-be-started-on-new-file-registry-already-stopped/281444 "2021-08-14T14:50:56Z")

</div>

I am using filebeat-oss v7.12.0 in order to collect events from kubernetes pods using autodiscover. It is expected to collect 5450 events from 5450 pods but fails to harvest for 150 pods and contains the following error…

---

## [Cannot install osquery-manager](https://discuss.elastic.co/t/cannot-install-osquery-manager/281311)

<div class="topic-metadata">

**Author:** [@cheapsupps](https://discuss.elastic.co/u/cheapsupps)\
**Replies:** 2\
**Last updated:** [August 13, 2021, 11:36am UTC](https://discuss.elastic.co/t/cannot-install-osquery-manager/281311 "2021-08-13T11:36:39Z")

</div>

Hi, I have deployed elasticsearch + kibana + package registry in the air-gap environment. However, I am having problem deploying the osquery-manager to my agent. Below is the error at my agent. {"log.level":"info","@ti…

---

## [\[Elastic Agent 7.14\] \[Kubernetes provider\] How to dedot labels and annotations](https://discuss.elastic.co/t/elastic-agent-7-14-kubernetes-provider-how-to-dedot-labels-and-annotations/281230)

<div class="topic-metadata">

**Author:** [@mohsen0](https://discuss.elastic.co/u/mohsen0)\
**Replies:** 2\
**Last updated:** [August 13, 2021, 9:05am UTC](https://discuss.elastic.co/t/elastic-agent-7-14-kubernetes-provider-how-to-dedot-labels-and-annotations/281230 "2021-08-13T09:05:36Z")

</div>

I deploy the stand-alone elastic agent using the following (Run Elastic Agent standalone on Kubernetes | Fleet User Guide \[7.14\] | Elastic). if the pods are labeled or annotated by labels with . in their name. it will …

---

## [Metricbeat Perfmon configuration help](https://discuss.elastic.co/t/metricbeat-perfmon-configuration-help/280526)

<div class="topic-metadata">

**Author:** [@JP00](https://discuss.elastic.co/u/JP00)\
**Replies:** 1\
**Last updated:** [August 13, 2021, 12:00am UTC](https://discuss.elastic.co/t/metricbeat-perfmon-configuration-help/280526 "2021-08-13T00:00:00Z")

</div>

Hi, I'm new to the ELK stack and I'm currently trying to configure an environment that sends basic Windows server performance metrics (CPU/RAM usage, HDD space remaining, etc.) to a remote Kibana server. Currently I hav…

---

## [Problem with filebeat configuration \[windows\]](https://discuss.elastic.co/t/problem-with-filebeat-configuration-windows/281069)

<div class="topic-metadata">

**Author:** [@KarolinaSii](https://discuss.elastic.co/u/KarolinaSii)\
**Replies:** 1\
**Last updated:** [August 12, 2021, 10:56pm UTC](https://discuss.elastic.co/t/problem-with-filebeat-configuration-windows/281069 "2021-08-12T22:56:10Z")

</div>

Hi, I have problem with filebeat in Windows 10. I've got an error 2021-08-11T15:09:17.139+0200 ERROR instance/beat.go:989 Exiting: setup.template.name and setup.template.pattern have to be set if index name is…

---

## [Drop events from metricbeat is not working](https://discuss.elastic.co/t/drop-events-from-metricbeat-is-not-working/281208)

<div class="topic-metadata">

**Author:** [@fpsouza](https://discuss.elastic.co/u/fpsouza)\
**Replies:** 2\
**Last updated:** [August 12, 2021, 1:51pm UTC](https://discuss.elastic.co/t/drop-events-from-metricbeat-is-not-working/281208 "2021-08-12T13:51:42Z")

</div>

Hello Folks, as you can see below, I'm not being able to drop event when doesn't have "system". Could u please let me know if if is possible to do that? I really appreciate your help and time processors: drop\_event…

---

## [Filebeat doesn't catchup with suricata eve.json](https://discuss.elastic.co/t/filebeat-doesnt-catchup-with-suricata-eve-json/281153)

<div class="topic-metadata">

**Author:** [@3c2c2ff5](https://discuss.elastic.co/u/3c2c2ff5)\
**Replies:** 6\
**Last updated:** [August 12, 2021, 12:20pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-catchup-with-suricata-eve-json/281153 "2021-08-12T12:20:02Z")

</div>

Hello ELK community, I am fairly new to the subject ELK stack, I am trying to setup an IDS with suricata and ELK, the initial setup went pretty good, but I realized that the suricata events from eve.json are not getting…

---

## [Index filebeat panw error](https://discuss.elastic.co/t/index-filebeat-panw-error/281192)

<div class="topic-metadata">

**Author:** [@newbie313](https://discuss.elastic.co/u/newbie313)\
**Replies:** 0\
**Last updated:** [August 12, 2021, 10:47am UTC](https://discuss.elastic.co/t/index-filebeat-panw-error/281192 "2021-08-12T10:47:28Z")

</div>

I'm using filebeat-7.3.2 and configure panw.yml open port 514, the data from palo alto already received ( i check using tshark) but there is error come in the index management shows: Index lifecycle error illegal\_argum…

---

## [Fleet/Elastic-Agent trusted information from certificate](https://discuss.elastic.co/t/fleet-elastic-agent-trusted-information-from-certificate/281028)

<div class="topic-metadata">

**Author:** [@wsnet](https://discuss.elastic.co/u/wsnet)\
**Replies:** 1\
**Last updated:** [August 12, 2021, 7:21am UTC](https://discuss.elastic.co/t/fleet-elastic-agent-trusted-information-from-certificate/281028 "2021-08-12T07:21:12Z")

</div>

Hello, With 7.14.0 Elasticsearch has started validating agent.id using the .fleet\_final\_pipeline-1 (see the PR), which greatly improves security. While using Elastic-Agent to fetch information from servers, e.g. web-lo…

---

## [Filebeats can see new lines in file only after restart](https://discuss.elastic.co/t/filebeats-can-see-new-lines-in-file-only-after-restart/281159)

<div class="topic-metadata">

**Author:** [@station72](https://discuss.elastic.co/u/station72)\
**Replies:** 0\
**Last updated:** [August 12, 2021, 6:48am UTC](https://discuss.elastic.co/t/filebeats-can-see-new-lines-in-file-only-after-restart/281159 "2021-08-12T06:48:13Z")

</div>

I have a log file. It named access.log Each 30min new lines appears in this file from remote server (by synchronization). My filebeat config filebeat.inputs: - type: filestream scan\_frequency: 10s paths: - /sr…

---

## [Heartbeat setup failing because of incorrect user](https://discuss.elastic.co/t/heartbeat-setup-failing-because-of-incorrect-user/280870)

<div class="topic-metadata">

**Author:** [@Heroj04](https://discuss.elastic.co/u/Heroj04)\
**Replies:** 3\
**Last updated:** [August 11, 2021, 11:53pm UTC](https://discuss.elastic.co/t/heartbeat-setup-failing-because-of-incorrect-user/280870 "2021-08-11T23:53:58Z")

</div>

I'm trying to setup heartbeat on my new elastic stack server but it is failing because the user doesn't have permission to create indices. It seems to be using the writer user instead of the setup user that has the corr…

---

## [Filebeat modules](https://discuss.elastic.co/t/filebeat-modules/280852)

<div class="topic-metadata">

**Author:** [@leemase004](https://discuss.elastic.co/u/leemase004)\
**Replies:** 13\
**Last updated:** [August 11, 2021, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-modules/280852 "2021-08-11T15:18:57Z")

</div>

I have, hopefully, a very simple question: We have filebeat (zeek module) running on SERVER A. Filebeat takes it to kafka where it is then pulled down by logstash. The zeek.conf file in logstash is completely barren. It…

---

## [\[heartbeat\]how to get performace test on heartbeat](https://discuss.elastic.co/t/heartbeat-how-to-get-performace-test-on-heartbeat/274304)

<div class="topic-metadata">

**Author:** [@lowry](https://discuss.elastic.co/u/lowry)\
**Replies:** 8\
**Last updated:** [August 11, 2021, 3:02pm UTC](https://discuss.elastic.co/t/heartbeat-how-to-get-performace-test-on-heartbeat/274304 "2021-08-11T15:02:25Z")

</div>

Hi Elastic friends, Have a question for the performance of heartbeat. Assuming there’re 90K targets need to be monitored via heartbeat, in some case, like there’re 30% to 50% targets, maybe even worse, there’re 60%~80%…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=138)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=140)
