# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=140

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 141

---

## [Filebeat on Ubuntu hosts getting sporadic error: "Error decoding JSON:"](https://discuss.elastic.co/t/filebeat-on-ubuntu-hosts-getting-sporadic-error-error-decoding-json/258783)

<div class="topic-metadata">

**Author:** [@humbeGar](https://discuss.elastic.co/u/humbeGar)\
**Replies:** 9\
**Last updated:** [August 11, 2021, 2:40pm UTC](https://discuss.elastic.co/t/filebeat-on-ubuntu-hosts-getting-sporadic-error-error-decoding-json/258783 "2021-08-11T14:40:03Z")

</div>

Description We are using Filebeat to collect data from multiple systems (~300 different hosts) and OSes ( Windows, Ubuntu, Mac OS). We are collecting around 125Million events coming from .ndjson files per week using Fil…

---

## [Gcp-pubsub error creating input](https://discuss.elastic.co/t/gcp-pubsub-error-creating-input/281084)

<div class="topic-metadata">

**Author:** [@raiz](https://discuss.elastic.co/u/raiz)\
**Replies:** 0\
**Last updated:** [August 11, 2021, 2:20pm UTC](https://discuss.elastic.co/t/gcp-pubsub-error-creating-input/281084 "2021-08-11T14:20:38Z")

</div>

Hello, I'm trying to run filebeat -e and getting this error: 2021-08-11T14:14:24.729Z INFO \[monitoring\] log/log.go:130 Stopping metrics logging. 2021-08-11T14:14:24.729Z INFO instance/beat.go:412 filebeat stopped. 2021…

---

## [Elastic-agent in a docker container](https://discuss.elastic.co/t/elastic-agent-in-a-docker-container/281068)

<div class="topic-metadata">

**Author:** [@NatSav](https://discuss.elastic.co/u/NatSav)\
**Replies:** 1\
**Last updated:** [August 11, 2021, 1:20pm UTC](https://discuss.elastic.co/t/elastic-agent-in-a-docker-container/281068 "2021-08-11T13:20:49Z")

</div>

Hi all. Im trying to run an elastic-agent inside a docker container and im encountering a few issues. I know that docker isnt technically supported however I think im nearly there and im going to persevere with it. I h…

---

## [Auditbeat not updating usernames and process data in file\_integrity module](https://discuss.elastic.co/t/auditbeat-not-updating-usernames-and-process-data-in-file-integrity-module/280983)

<div class="topic-metadata">

**Author:** [@Stud21](https://discuss.elastic.co/u/Stud21)\
**Replies:** 0\
**Last updated:** [August 11, 2021, 4:54am UTC](https://discuss.elastic.co/t/auditbeat-not-updating-usernames-and-process-data-in-file-integrity-module/280983 "2021-08-11T04:54:13Z")

</div>

Hi, I have installed Auditbeat which is working fine. However, when I try to query data related to user creating, deleting files which uses the file\_integrity module, it shows records/documents without the user.names in…

---

## [Exception: Key found in event is not documented!](https://discuss.elastic.co/t/exception-key-found-in-event-is-not-documented/280658)

<div class="topic-metadata">

**Author:** [@Jerry\_Tian](https://discuss.elastic.co/u/Jerry_Tian)\
**Replies:** 1\
**Last updated:** [August 10, 2021, 11:36pm UTC](https://discuss.elastic.co/t/exception-key-found-in-event-is-not-documented/280658 "2021-08-10T23:36:35Z")

</div>

I am at step 5 of the testing phase in creating a custom filebeat module as detailed here Creating a New Filebeat Module | Beats Developer Guide \[master\] | Elastic. However, I failed the test with the following short te…

---

## [Adding modules to Fleet agent](https://discuss.elastic.co/t/adding-modules-to-fleet-agent/280721)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 4\
**Last updated:** [August 10, 2021, 11:30pm UTC](https://discuss.elastic.co/t/adding-modules-to-fleet-agent/280721 "2021-08-10T23:30:43Z")

</div>

Hi, I have Elastic Cloud 7.14.0, using Fleet and an Agent on a Centos 7 server. Works great. I want to enable modules that aren't necessarily a click-and-configure in the Fleet UI. Can i modify some file locally on th…

---

## [Metricbeat daemonset modules fails](https://discuss.elastic.co/t/metricbeat-daemonset-modules-fails/280960)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 0\
**Last updated:** [August 10, 2021, 7:00pm UTC](https://discuss.elastic.co/t/metricbeat-daemonset-modules-fails/280960 "2021-08-10T19:00:55Z")

</div>

I have configured following modules for metricbeat daemonset in AWS EKS modulessystem.yml: |- - module: system period: 10s metricsets: - cpu - load - memory - network …

---

## [How to setup two different output (index, pipeline) with Filebeat](https://discuss.elastic.co/t/how-to-setup-two-different-output-index-pipeline-with-filebeat/280951)

<div class="topic-metadata">

**Author:** [@chriselk](https://discuss.elastic.co/u/chriselk)\
**Replies:** 0\
**Last updated:** [August 10, 2021, 5:06pm UTC](https://discuss.elastic.co/t/how-to-setup-two-different-output-index-pipeline-with-filebeat/280951 "2021-08-10T17:06:09Z")

</div>

I'm trying to setup with one filebeat instance the apache module and the Tomcat module because we have done customisation in the pipeline and would like to have two separate indices I try the following configuration: o…

---

## [Auditbeat: Index file grows rapidly causing No space left issue](https://discuss.elastic.co/t/auditbeat-index-file-grows-rapidly-causing-no-space-left-issue/280492)

<div class="topic-metadata">

**Author:** [@Stud21](https://discuss.elastic.co/u/Stud21)\
**Replies:** 2\
**Last updated:** [August 10, 2021, 5:08am UTC](https://discuss.elastic.co/t/auditbeat-index-file-grows-rapidly-causing-no-space-left-issue/280492 "2021-08-10T05:08:07Z")

</div>

I have noticed that auditbeat index grows very rapidly in Linux using high disk space. It grows to around 500 MB. This fills up the disk space causing 'No space left on device' error. Has someone experienced a similar …

---

## [Index lifecycle error on metricbeat and heartbeat](https://discuss.elastic.co/t/index-lifecycle-error-on-metricbeat-and-heartbeat/280715)

<div class="topic-metadata">

**Author:** [@cool999](https://discuss.elastic.co/u/cool999)\
**Replies:** 2\
**Last updated:** [August 9, 2021, 6:17pm UTC](https://discuss.elastic.co/t/index-lifecycle-error-on-metricbeat-and-heartbeat/280715 "2021-08-09T18:17:08Z")

</div>

Hi Team, In kibana under, in index management under indices its showing 79 indices have lifecycle errors and this no. is getting increased daily on elasticsearch v7.4 I am going through ILM docs, for beats ILM is enabl…

---

## [Elastic Agent with Synthetics Integration- Adding TCP monitor break the Agent](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651)

<div class="topic-metadata">

**Author:** [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Replies:** 6\
**Last updated:** [August 9, 2021, 11:31am UTC](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651 "2021-08-09T11:31:50Z")

</div>

Hi All, I have an Elastic Agent Installed with synthetic integration (heartbeat). Adding HTTP and ICMP monitors work fine but when I tried adding a TCP monitor with the correct host:port format the agent become unhealth…

---

## [Filebeat setup command receives timeout form kibana](https://discuss.elastic.co/t/filebeat-setup-command-receives-timeout-form-kibana/280795)

<div class="topic-metadata">

**Author:** [@azxqw](https://discuss.elastic.co/u/azxqw)\
**Replies:** 0\
**Last updated:** [August 9, 2021, 11:04am UTC](https://discuss.elastic.co/t/filebeat-setup-command-receives-timeout-form-kibana/280795 "2021-08-09T11:04:42Z")

</div>

Hi, I have filebeat installed, and whenever i try to tun the setup command to load dashboards to kibana(from the f5 module) i recieve a timeout error. Kibana is up and running and reacheable, so I dont really understan…

---

## [Elastic agent in a docker container TLS error](https://discuss.elastic.co/t/elastic-agent-in-a-docker-container-tls-error/280534)

<div class="topic-metadata">

**Author:** [@NatSav](https://discuss.elastic.co/u/NatSav)\
**Replies:** 2\
**Last updated:** [August 9, 2021, 8:19am UTC](https://discuss.elastic.co/t/elastic-agent-in-a-docker-container-tls-error/280534 "2021-08-09T08:19:20Z")

</div>

Good afternoon, I am trying to make a docker container with elastic-agent, packetbeat and metricbeat. I am going to add other components later however I want to get these working first. When I try to install elastic-agen…

---

## [Ibm mq module issue in metricbeat](https://discuss.elastic.co/t/ibm-mq-module-issue-in-metricbeat/280761)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 1\
**Last updated:** [August 9, 2021, 6:14am UTC](https://discuss.elastic.co/t/ibm-mq-module-issue-in-metricbeat/280761 "2021-08-09T06:14:52Z")

</div>

Hi all, I am trying to monitor my IBM WebSphere MQ using ibmmq module of metricbeat version 7.13.1. the metricbeat.yml setting is as following: # =========================== Modules configuration =====================…

---

## [Serilog and Filebeat Compatibility](https://discuss.elastic.co/t/serilog-and-filebeat-compatibility/280678)

<div class="topic-metadata">

**Author:** [@christamlyn](https://discuss.elastic.co/u/christamlyn)\
**Replies:** 1\
**Last updated:** [August 8, 2021, 11:14pm UTC](https://discuss.elastic.co/t/serilog-and-filebeat-compatibility/280678 "2021-08-08T23:14:48Z")

</div>

Quite specific to our setup but: we are currently using Filebeat to ship logs to Elasticsearch we want to slowly migrate to using Serilog sinks to ship to Elasticsearch we have a number of dashboards setup for the exis…

---

## [Correct way of configuring metricbeat](https://discuss.elastic.co/t/correct-way-of-configuring-metricbeat/279929)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 2\
**Last updated:** [August 8, 2021, 10:40am UTC](https://discuss.elastic.co/t/correct-way-of-configuring-metricbeat/279929 "2021-08-08T10:40:46Z")

</div>

I am running 11 nodes of elasticsearch cluster which include the following Three master nodes Six data nodes 2 coordinate nodes Earlier i installed and setup metricbeat in all nodes but it leads to consumption of high…

---

## [Deleted ingest pipeline, doh! - Can't get it Back](https://discuss.elastic.co/t/deleted-ingest-pipeline-doh-cant-get-it-back/280687)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 11\
**Last updated:** [August 7, 2021, 8:27am UTC](https://discuss.elastic.co/t/deleted-ingest-pipeline-doh-cant-get-it-back/280687 "2021-08-07T08:27:52Z")

</div>

Hey there, I configured Fleet in the console, installed/enrolled an agent down on my server and configured an integration.. Moments later i got logs and kibana was happy. I'm an idiot and accidently deleted the ingest …

---

## [Filebeat stops publishing logs to Kafka without any error message](https://discuss.elastic.co/t/filebeat-stops-publishing-logs-to-kafka-without-any-error-message/280654)

<div class="topic-metadata">

**Author:** [@rribeiro](https://discuss.elastic.co/u/rribeiro)\
**Replies:** 1\
**Last updated:** [August 6, 2021, 4:15pm UTC](https://discuss.elastic.co/t/filebeat-stops-publishing-logs-to-kafka-without-any-error-message/280654 "2021-08-06T16:15:29Z")

</div>

Hi, An instance of Filebeat 7.13.0 (running on Openshift) stops publishing logs to Kafka after some time. The source logs are read from a NFS volume and are rotated every 5 minutes (a timestamp is added to the filename…

---

## [Kubernetes autodiscover with annotation not working](https://discuss.elastic.co/t/kubernetes-autodiscover-with-annotation-not-working/280621)

<div class="topic-metadata">

**Author:** [@edwardlol](https://discuss.elastic.co/u/edwardlol)\
**Replies:** 0\
**Last updated:** [August 6, 2021, 8:00am UTC](https://discuss.elastic.co/t/kubernetes-autodiscover-with-annotation-not-working/280621 "2021-08-06T08:00:23Z")

</div>

I want to enable log collecting on specific pods (or namespace, but I'm trying to enable it on pods first). I disabled hints/default\_config filebeat.autodiscover: providers: - type: kubernetes node: ${NODE\_…

---

## [Module:kubernetes / metricset:event fails to gather FailedScheduling events](https://discuss.elastic.co/t/module-kubernetes-metricset-event-fails-to-gather-failedscheduling-events/280597)

<div class="topic-metadata">

**Author:** [@MnrGreg](https://discuss.elastic.co/u/MnrGreg)\
**Replies:** 0\
**Last updated:** [August 5, 2021, 8:37pm UTC](https://discuss.elastic.co/t/module-kubernetes-metricset-event-fails-to-gather-failedscheduling-events/280597 "2021-08-05T20:37:06Z")

</div>

When moving from kubernetes 1.19.1 to 1.20.5 metricset:event no longer gathers .reason:FailedScheduling events. Noticed the kubernetes event structure has changed. 1.19.1: { "apiVersion": "v1", …

---

## [Unknown field 'DisablePAFXFAST' in struct literal of type sarama.GSSAPIConfig](https://discuss.elastic.co/t/unknown-field-disablepafxfast-in-struct-literal-of-type-sarama-gssapiconfig/280579)

<div class="topic-metadata">

**Author:** [@jpfreyen](https://discuss.elastic.co/u/jpfreyen)\
**Replies:** 0\
**Last updated:** [August 5, 2021, 6:11pm UTC](https://discuss.elastic.co/t/unknown-field-disablepafxfast-in-struct-literal-of-type-sarama-gssapiconfig/280579 "2021-08-05T18:11:27Z")

</div>

I inherited a fairly old beats plugin project using filebeat 7.10. Its import() in main is defined as: package main import ( "os" "github.com/elastic/beats/v7/filebeat/beater" inputs "github.c…

---

## [Dynamic index name with ILM](https://discuss.elastic.co/t/dynamic-index-name-with-ilm/280563)

<div class="topic-metadata">

**Author:** [@DoctorRobot](https://discuss.elastic.co/u/DoctorRobot)\
**Replies:** 0\
**Last updated:** [August 5, 2021, 4:48pm UTC](https://discuss.elastic.co/t/dynamic-index-name-with-ilm/280563 "2021-08-05T16:48:24Z")

</div>

Hi, I currently have this setup which works fine: --- apiVersion: beat.k8s.elastic.co/v1beta1 kind: Beat metadata: name: filebeat namespace: elasticsearch ... setup: ilm: enabled: false template: name: …

---

## [Conditions with environment variables](https://discuss.elastic.co/t/conditions-with-environment-variables/280462)

<div class="topic-metadata">

**Author:** [@Loulou](https://discuss.elastic.co/u/Loulou)\
**Replies:** 3\
**Last updated:** [August 5, 2021, 12:39pm UTC](https://discuss.elastic.co/t/conditions-with-environment-variables/280462 "2021-08-05T12:39:02Z")

</div>

Hi, I am trying to have a different input for filebeat if a certain environment variable is set: - type: log enabled: ${VAR} paths: - MyPath1 - type: log enabled: not ${VAR} paths: - MyPath2 I know the…

---

## [Syslog date in ingest node pipeline ahead](https://discuss.elastic.co/t/syslog-date-in-ingest-node-pipeline-ahead/279345)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 3\
**Last updated:** [August 5, 2021, 9:39am UTC](https://discuss.elastic.co/t/syslog-date-in-ingest-node-pipeline-ahead/279345 "2021-08-05T09:39:07Z")

</div>

Hi, I am experiencing a strange thing with the date in the syslog log in filebeat. I am using the default ingest node pipeline (logs-system.syslog-0.12.7) which creates a new timestamp based on the system.syslog.timesta…

---

## [Filebeat stops sending data to Logstash and hence Elasticsearch after a few hundred thousand documents, works again on restarting Filebeat container](https://discuss.elastic.co/t/filebeat-stops-sending-data-to-logstash-and-hence-elasticsearch-after-a-few-hundred-thousand-documents-works-again-on-restarting-filebeat-container/279984)

<div class="topic-metadata">

**Author:** [@sanjogmehta](https://discuss.elastic.co/u/sanjogmehta)\
**Replies:** 4\
**Last updated:** [August 5, 2021, 9:27am UTC](https://discuss.elastic.co/t/filebeat-stops-sending-data-to-logstash-and-hence-elasticsearch-after-a-few-hundred-thousand-documents-works-again-on-restarting-filebeat-container/279984 "2021-08-05T09:27:15Z")

</div>

I am a new to Elastic stack and I am using Filebeat AWS module's vpcflow to fetch data from S3 through SQS. It works fine for a few hundred thousand documents, but after that I don't see any new document in Elasticsearch…

---

## [Negative CPU Usage on default dashboard "\[Elastic Agent\] Agent metrics"](https://discuss.elastic.co/t/negative-cpu-usage-on-default-dashboard-elastic-agent-agent-metrics/279762)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [August 5, 2021, 9:25am UTC](https://discuss.elastic.co/t/negative-cpu-usage-on-default-dashboard-elastic-agent-agent-metrics/279762 "2021-08-05T09:25:03Z")

</div>

Hello, Added a few Elastic agents to my Elastic Cloud trial and after 24 hours, I noticed negative CPU Usages on the builtin "\[Elastic Agent\] Agent metrics" dashboard.. After checking the configuration, the TSVB vis…

---

## [Filebeat sonicwall module](https://discuss.elastic.co/t/filebeat-sonicwall-module/280469)

<div class="topic-metadata">

**Author:** [@WilGG](https://discuss.elastic.co/u/WilGG)\
**Replies:** 1\
**Last updated:** [August 5, 2021, 1:08am UTC](https://discuss.elastic.co/t/filebeat-sonicwall-module/280469 "2021-08-05T01:08:42Z")

</div>

Hi Everyone, Can someone provide me with a SonicWall module sample config file for filebeat? When I try to modify sonicwall.yml, the filebeat service crashes. when it is set to default comment state I am able to run th…

---

## [Filebeat multiline log into ES/Kib](https://discuss.elastic.co/t/filebeat-multiline-log-into-es-kib/280478)

<div class="topic-metadata">

**Author:** [@marc\_b](https://discuss.elastic.co/u/marc_b)\
**Replies:** 0\
**Last updated:** [August 4, 2021, 10:31pm UTC](https://discuss.elastic.co/t/filebeat-multiline-log-into-es-kib/280478 "2021-08-04T22:31:29Z")

</div>

Hi, Searching for assistance here if possible. I have log files that are created by using the 'SET' command piped into a file. (exporting environment variables) in the example shape below - ALLUSERSPROFILE=C:\\ProgramD…

---

## [Azure Signin data =\> field \[message\] already exists](https://discuss.elastic.co/t/azure-signin-data-field-message-already-exists/278446)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [August 4, 2021, 8:06pm UTC](https://discuss.elastic.co/t/azure-signin-data-field-message-already-exists/278446 "2021-08-04T20:06:28Z")

</div>

Hello, I've seen multiple occurences in the Azure signin logs where user.name was not populated. Those documents always have an error.message containing "field \[message\] already exists". This seem like a bug.. The mess…

---

## [Custom logs Filebeat Index](https://discuss.elastic.co/t/custom-logs-filebeat-index/280454)

<div class="topic-metadata">

**Author:** [@marcosvmauri](https://discuss.elastic.co/u/marcosvmauri)\
**Replies:** 0\
**Last updated:** [August 4, 2021, 3:17pm UTC](https://discuss.elastic.co/t/custom-logs-filebeat-index/280454 "2021-08-04T15:17:50Z")

</div>

Hi! I have a Filebeat server configured to capture IIS logs. And I would like to capture custom logs, but after parameterizing the filebeat.yaml files and placing the logs in the indicated folder, I cannot view the log…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=139)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=141)
