# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=141

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 142

---

## [Filebeat HttpJson Input Plugin Didnt Work Correctly](https://discuss.elastic.co/t/filebeat-httpjson-input-plugin-didnt-work-correctly/280435)

<div class="topic-metadata">

**Author:** [@kolten](https://discuss.elastic.co/u/kolten)\
**Replies:** 1\
**Last updated:** [August 4, 2021, 1:37pm UTC](https://discuss.elastic.co/t/filebeat-httpjson-input-plugin-didnt-work-correctly/280435 "2021-08-04T13:37:03Z")

</div>

Hi everyone, I want to try httpjson plugin but it didnt work correctly. Filebeat transfer data with binary format so that data didn't correct. I followed this article: HTTP JSON input | Filebeat Reference \[7.14\] | Elas…

---

## [Monitor packet loss with Heartbeat](https://discuss.elastic.co/t/monitor-packet-loss-with-heartbeat/280294)

<div class="topic-metadata">

**Author:** [@Bilanda](https://discuss.elastic.co/u/Bilanda)\
**Replies:** 2\
**Last updated:** [August 4, 2021, 1:06pm UTC](https://discuss.elastic.co/t/monitor-packet-loss-with-heartbeat/280294 "2021-08-04T13:06:25Z")

</div>

Hello, I'm currently testing heartbeat at company level in order to replace Smokeping. Is there any way to monitor packet loss with heartbeat, like Smokeping does ? It's a much needed feature for us, but didn't find t…

---

## [Bug? Heartbeat Browsermonitoring ignoring SSL settings?](https://discuss.elastic.co/t/bug-heartbeat-browsermonitoring-ignoring-ssl-settings/279943)

<div class="topic-metadata">

**Author:** [@Simon\_Becker](https://discuss.elastic.co/u/Simon_Becker)\
**Replies:** 2\
**Last updated:** [August 4, 2021, 10:48am UTC](https://discuss.elastic.co/t/bug-heartbeat-browsermonitoring-ignoring-ssl-settings/279943 "2021-08-04T10:48:08Z")

</div>

Hello all, I am currently setting up the new Browser Monitoring feature for synthetic checks since this is a great new feature. I use heartbeat in docker. I try to ping an internal site in my network. The error messag…

---

## [Filebeat sending two logs in nginx module](https://discuss.elastic.co/t/filebeat-sending-two-logs-in-nginx-module/279951)

<div class="topic-metadata">

**Author:** [@boris\_asapov](https://discuss.elastic.co/u/boris_asapov)\
**Replies:** 1\
**Last updated:** [August 4, 2021, 7:43am UTC](https://discuss.elastic.co/t/filebeat-sending-two-logs-in-nginx-module/279951 "2021-08-04T07:43:10Z")

</div>

hi all, i've configured nginx module in filebeat , send access log to ELK stack ( logstash ) and its working fine but somehow filebeat sending two logs to logstash instead of one my logstash index is : index =\> "%{\[b…

---

## [Metricbeat azure module - Simultaneously fetch multi-dimensional metric values](https://discuss.elastic.co/t/metricbeat-azure-module-simultaneously-fetch-multi-dimensional-metric-values/280326)

<div class="topic-metadata">

**Author:** [@ag\_joeb](https://discuss.elastic.co/u/ag_joeb)\
**Replies:** 0\
**Last updated:** [August 3, 2021, 2:03pm UTC](https://discuss.elastic.co/t/metricbeat-azure-module-simultaneously-fetch-multi-dimensional-metric-values/280326 "2021-08-03T14:03:30Z")

</div>

I'm trying to fetch Cosmos DB metrics from azure using metricbeat's azure module. An example: - module: azure metricsets: - monitor enabled: true period: 30s client\_id: '\<client\_id\>' client\_secret: '\<client\_…

---

## [Af\_ Packet mode, local loopback data problem](https://discuss.elastic.co/t/af-packet-mode-local-loopback-data-problem/280335)

<div class="topic-metadata">

**Author:** [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Replies:** 0\
**Last updated:** [August 3, 2021, 3:12pm UTC](https://discuss.elastic.co/t/af-packet-mode-local-loopback-data-problem/280335 "2021-08-03T15:12:26Z")

</div>

Turn on af\_packet, a large number of reconnections occur in the traffic sniffed by the local loop. If pcap is turned on, there is no problem. The following figure is a screenshot of the file with the command dump ./pack…

---

## [Auditbeat: Combining data from both (system & file\_integrity) modules](https://discuss.elastic.co/t/auditbeat-combining-data-from-both-system-file-integrity-modules/280281)

<div class="topic-metadata">

**Author:** [@Stud21](https://discuss.elastic.co/u/Stud21)\
**Replies:** 0\
**Last updated:** [August 3, 2021, 7:24am UTC](https://discuss.elastic.co/t/auditbeat-combining-data-from-both-system-file-integrity-modules/280281 "2021-08-03T07:24:06Z")

</div>

I am trying to list events from Auditbeat as below: In Kibana discovery, select Auditbeat index pattern Search for a file say, /etc/auditbeat/auditbeat.yml It lists records that do not show the username for changes/cr…

---

## [Need help with filebeat index pattern - Mapping conflict with host.ip](https://discuss.elastic.co/t/need-help-with-filebeat-index-pattern-mapping-conflict-with-host-ip/279673)

<div class="topic-metadata">

**Author:** [@Cdnvballer](https://discuss.elastic.co/u/Cdnvballer)\
**Replies:** 7\
**Last updated:** [August 2, 2021, 10:18pm UTC](https://discuss.elastic.co/t/need-help-with-filebeat-index-pattern-mapping-conflict-with-host-ip/279673 "2021-08-02T22:18:45Z")

</div>

filebeat index pattern shows warning that host.ip is showing both type ip and text. I believe this is somehow related to IPv6 host.ip is in type text and IPv4 host.ip in type ip how do fix this ? at this point I don't …

---

## [Incorrect Postgres Timestamp with Filebeat & ES](https://discuss.elastic.co/t/incorrect-postgres-timestamp-with-filebeat-es/280152)

<div class="topic-metadata">

**Author:** [@kellizer](https://discuss.elastic.co/u/kellizer)\
**Replies:** 6\
**Last updated:** [August 2, 2021, 5:24pm UTC](https://discuss.elastic.co/t/incorrect-postgres-timestamp-with-filebeat-es/280152 "2021-08-02T17:24:00Z")

</div>

I've been knocking my head on this one for days and can't seem to debug what is happening.. I've setup the filebeat module to stream postgres-13 csv logs into ES - everything works great except the time is out of sync (c…

---

## [Winlogbeat Dashbord Setup Error](https://discuss.elastic.co/t/winlogbeat-dashbord-setup-error/279720)

<div class="topic-metadata">

**Author:** [@Ashwin\_Patil1](https://discuss.elastic.co/u/Ashwin_Patil1)\
**Replies:** 10\
**Last updated:** [August 2, 2021, 3:43pm UTC](https://discuss.elastic.co/t/winlogbeat-dashbord-setup-error/279720 "2021-08-02T15:43:14Z")

</div>

I am trying to setup dashboards, below is the .yml file . # ------------------------------ Logstash Output ------------------------------- output.logstash: # The Logstash hosts hosts: \["172.16.12.18:5044"\] user: "…

---

## [Standard IIS grok templates can't parse](https://discuss.elastic.co/t/standard-iis-grok-templates-cant-parse/279963)

<div class="topic-metadata">

**Author:** [@dmalchikov](https://discuss.elastic.co/u/dmalchikov)\
**Replies:** 4\
**Last updated:** [August 2, 2021, 1:04pm UTC](https://discuss.elastic.co/t/standard-iis-grok-templates-cant-parse/279963 "2021-08-02T13:04:19Z")

</div>

Hi! Can't find a reason... ANy idea? I have errors Provided Grok expressions do not match field value. But it pass if I copy template and data to grokconstructor.appspot.com Standard module IIS template in use (7.13.3) …

---

## [Windows Server 2019 Core Compatibility](https://discuss.elastic.co/t/windows-server-2019-core-compatibility/280019)

<div class="topic-metadata">

**Author:** [@Jimbuctoo](https://discuss.elastic.co/u/Jimbuctoo)\
**Replies:** 1\
**Last updated:** [August 2, 2021, 11:18am UTC](https://discuss.elastic.co/t/windows-server-2019-core-compatibility/280019 "2021-08-02T11:18:06Z")

</div>

I noticed on the Support Matrix, under Winlogbeat, it states Windows Server 2019 but fails to state other Windows Server types \[for 2019\] including Windows Server 2019 Core. For clarity, does Filebeats and Winlogbeats al…

---

## [How to judge whether a TCP connection is successful](https://discuss.elastic.co/t/how-to-judge-whether-a-tcp-connection-is-successful/280156)

<div class="topic-metadata">

**Author:** [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Replies:** 2\
**Last updated:** [August 2, 2021, 11:11am UTC](https://discuss.elastic.co/t/how-to-judge-whether-a-tcp-connection-is-successful/280156 "2021-08-02T11:11:10Z")

</div>

When I enabled packetbeat FLOW How to judge whether the connection to the port succeeds or fails from the data returned by packetbeat I compared the successful and unsuccessful two returned data, as if there was no dif…

---

## [Winlogbeat SSL](https://discuss.elastic.co/t/winlogbeat-ssl/280181)

<div class="topic-metadata">

**Author:** [@Abdullah\_Al-Mansour1](https://discuss.elastic.co/u/Abdullah_Al-Mansour1)\
**Replies:** 1\
**Last updated:** [August 2, 2021, 10:58am UTC](https://discuss.elastic.co/t/winlogbeat-ssl/280181 "2021-08-02T10:58:38Z")

</div>

Hello - I'm performing my first secure install of elastic stack. Everything is going well. I'm at the last leg of the race, ingesting data from Winlogbeat. I created a winlogbeat\_writer role, assigned it to a winlogbeat\_…

---

## [Edit IIS Module Pipeline](https://discuss.elastic.co/t/edit-iis-module-pipeline/280083)

<div class="topic-metadata">

**Author:** [@Dzious](https://discuss.elastic.co/u/Dzious)\
**Replies:** 4\
**Last updated:** [August 2, 2021, 9:55am UTC](https://discuss.elastic.co/t/edit-iis-module-pipeline/280083 "2021-08-02T09:55:58Z")

</div>

Hi, I'm i a company where I need to ingest data from IIS. I've enable the module but i'd like to modify a bit the pipeline. I've found that pipeline are stored in filebeat modules folder (on window : filebeat/module/ii…

---

## [Filebeat unicode json parse error](https://discuss.elastic.co/t/filebeat-unicode-json-parse-error/280167)

<div class="topic-metadata">

**Author:** [@paano](https://discuss.elastic.co/u/paano)\
**Replies:** 3\
**Last updated:** [August 2, 2021, 3:37am UTC](https://discuss.elastic.co/t/filebeat-unicode-json-parse-error/280167 "2021-08-02T03:37:53Z")

</div>

I have worked worked with json earlier, but this json output is unique, and filebeat throws error as Error decoding JSON: invalid character 'u' elk\_filebeat | 2021-08-01T23:33:35.056Z ERROR json/json.go:51 Er…

---

## [Upgrade filebeat and logstash from 5.6 to 6.3](https://discuss.elastic.co/t/upgrade-filebeat-and-logstash-from-5-6-to-6-3/280024)

<div class="topic-metadata">

**Author:** [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Replies:** 3\
**Last updated:** [August 1, 2021, 10:03pm UTC](https://discuss.elastic.co/t/upgrade-filebeat-and-logstash-from-5-6-to-6-3/280024 "2021-08-01T22:03:50Z")

</div>

I am trying to upgrade the filebeat and logstash from 5.6 to 6.3, there are two logstash and a lot of filebeat agents, what should do to upgrade smoothly?

---

## [Cannot find the Api query on Metricbeat dashboards](https://discuss.elastic.co/t/cannot-find-the-api-query-on-metricbeat-dashboards/280144)

<div class="topic-metadata">

**Author:** [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Replies:** 0\
**Last updated:** [August 1, 2021, 10:10am UTC](https://discuss.elastic.co/t/cannot-find-the-api-query-on-metricbeat-dashboards/280144 "2021-08-01T10:10:53Z")

</div>

I'm trying to get the API requests that kibana does to the Elasticsearch in order to get the data to visualize. But for metricbeat i cannot find what i want. Specifically on the ECS dashboard at the Host or System overv…

---

## [Filebeat AWS Module No found](https://discuss.elastic.co/t/filebeat-aws-module-no-found/280119)

<div class="topic-metadata">

**Author:** [@mibfb23](https://discuss.elastic.co/u/mibfb23)\
**Replies:** 5\
**Last updated:** [July 31, 2021, 11:49pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-no-found/280119 "2021-07-31T23:49:02Z")

</div>

Hello, having the need to store the cloudtrail logs in elasticsearch, I used the appropriate filebeat module providing it with all the options in this way: - module: aws cloudtrail: enabled: true # AWS SQS q…

---

## [Can't upgrade beats / kibana after enabling security](https://discuss.elastic.co/t/cant-upgrade-beats-kibana-after-enabling-security/279547)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 3\
**Last updated:** [July 31, 2021, 8:04pm UTC](https://discuss.elastic.co/t/cant-upgrade-beats-kibana-after-enabling-security/279547 "2021-07-31T20:04:25Z")

</div>

Prior to enabling security on elasticsearch cluster, I was able to easily upgrade beats by just upgrading the beat binary and letting it run. Since my beat config files (eg filebeat-config.yml) were set with setup.temp…

---

## [Beats for solaris 10](https://discuss.elastic.co/t/beats-for-solaris-10/280037)

<div class="topic-metadata">

**Author:** [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Replies:** 1\
**Last updated:** [July 31, 2021, 5:43pm UTC](https://discuss.elastic.co/t/beats-for-solaris-10/280037 "2021-07-31T17:43:48Z")

</div>

is there any beats who compatible with solaris 10?

---

## [Is it possible to monitor elasticsearch using metricbeat and custom index name?](https://discuss.elastic.co/t/is-it-possible-to-monitor-elasticsearch-using-metricbeat-and-custom-index-name/280084)

<div class="topic-metadata">

**Author:** [@Travis](https://discuss.elastic.co/u/Travis)\
**Replies:** 3\
**Last updated:** [July 31, 2021, 4:44pm UTC](https://discuss.elastic.co/t/is-it-possible-to-monitor-elasticsearch-using-metricbeat-and-custom-index-name/280084 "2021-07-31T16:44:40Z")

</div>

Hello ! I use metricbeat on the whole stack members (Elasticsearch/Logstash/Kibana) to collect system metrics (enabled by default) I use logstash output and custom index name metricbeat.yml : # ----------------------…

---

## [AWSFargate module for Filebeat not working?](https://discuss.elastic.co/t/awsfargate-module-for-filebeat-not-working/279949)

<div class="topic-metadata">

**Author:** [@stec00](https://discuss.elastic.co/u/stec00)\
**Replies:** 4\
**Last updated:** [July 30, 2021, 9:19pm UTC](https://discuss.elastic.co/t/awsfargate-module-for-filebeat-not-working/279949 "2021-07-30T21:19:15Z")

</div>

I am attempting to use the AWSFargate module for Filebeat. Ran the following commands (with placeholder values substituted): ./filebeat.exe modules enable awsfargate ./filebeat -e -E cloud.id=myElasticCloudID -E cloud…

---

## [Problems with error "File was truncated. Begin reading file from offset 0"](https://discuss.elastic.co/t/problems-with-error-file-was-truncated-begin-reading-file-from-offset-0/279959)

<div class="topic-metadata">

**Author:** [@mark\_vr](https://discuss.elastic.co/u/mark_vr)\
**Replies:** 4\
**Last updated:** [July 29, 2021, 5:32pm UTC](https://discuss.elastic.co/t/problems-with-error-file-was-truncated-begin-reading-file-from-offset-0/279959 "2021-07-29T17:32:17Z")

</div>

We use Azure Kubernetes Service, and our HTTP logs are written by the loadbalancer (ingress) to shared Azure storage. I'd like to read these logs and import them to Elasticsearch. I realise reading from shared storage …

---

## [Journalbeat - getting kubernetes metadata](https://discuss.elastic.co/t/journalbeat-getting-kubernetes-metadata/279456)

<div class="topic-metadata">

**Author:** [@DetlefG](https://discuss.elastic.co/u/DetlefG)\
**Replies:** 1\
**Last updated:** [July 29, 2021, 1:35pm UTC](https://discuss.elastic.co/t/journalbeat-getting-kubernetes-metadata/279456 "2021-07-29T13:35:45Z")

</div>

Hi, I'm trying to run Journalbeat with processor 'add\_kubernetes\_metadata' to get the metadata of the kubernetes cluster. Journalbeat is running on the kubernetes nodes started by a daemonset with the following configu…

---

## [Query on kibana space.id](https://discuss.elastic.co/t/query-on-kibana-space-id/279255)

<div class="topic-metadata">

**Author:** [@hsdevaraja](https://discuss.elastic.co/u/hsdevaraja)\
**Replies:** 2\
**Last updated:** [July 29, 2021, 1:33pm UTC](https://discuss.elastic.co/t/query-on-kibana-space-id/279255 "2021-07-29T13:33:42Z")

</div>

Hi, I was rereferring below link for setting up of Kibana spaces for logs isolation based on environment domain. We have single instance of Elastic search & Kibana(7.10.2) & Our requirement is create different Kibana …

---

## [Winlogbeat Dashboard](https://discuss.elastic.co/t/winlogbeat-dashboard/279814)

<div class="topic-metadata">

**Author:** [@insurin](https://discuss.elastic.co/u/insurin)\
**Replies:** 1\
**Last updated:** [July 29, 2021, 10:08am UTC](https://discuss.elastic.co/t/winlogbeat-dashboard/279814 "2021-07-29T10:08:32Z")

</div>

Can anyone help me get my dashboard working again. I deleted an index ( winlog 7.1.12.0) and a new one got made (winlog 7.1.12.1) but now I get loads of errors when using the built-in dashboard I'm not sure where to sta…

---

## [Metricbeat errors due to missing manage permission](https://discuss.elastic.co/t/metricbeat-errors-due-to-missing-manage-permission/279867)

<div class="topic-metadata">

**Author:** [@MaximK](https://discuss.elastic.co/u/MaximK)\
**Replies:** 2\
**Last updated:** [July 29, 2021, 8:49am UTC](https://discuss.elastic.co/t/metricbeat-errors-due-to-missing-manage-permission/279867 "2021-07-29T08:49:13Z")

</div>

Metricbeat configured with user elastic I have error org.elasticsearch.ElasticsearchSecurityException: action \[indices:admin/rollover\] is unauthorized for user \[remote\_monitoring\_user\] with roles \[remote\_monitoring\_col…

---

## [Filebeat autodiscover for Kubernetes uses inconsistent log files path by default](https://discuss.elastic.co/t/filebeat-autodiscover-for-kubernetes-uses-inconsistent-log-files-path-by-default/279834)

<div class="topic-metadata">

**Author:** [@NicolasCa](https://discuss.elastic.co/u/NicolasCa)\
**Replies:** 1\
**Last updated:** [July 29, 2021, 8:10am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-for-kubernetes-uses-inconsistent-log-files-path-by-default/279834 "2021-07-29T08:10:32Z")

</div>

Hi, I have trouble when deploying Filebeat in my Kubernetes cluster (v1.21.1) using ECK. The deployment spec is the following: apiVersion: beat.k8s.elastic.co/v1beta1 kind: Beat metadata: name: filebeat spec: type:…

---

## [Filebeat running on Kubernetes connected to Elasticsearch using SSL](https://discuss.elastic.co/t/filebeat-running-on-kubernetes-connected-to-elasticsearch-using-ssl/279946)

<div class="topic-metadata">

**Author:** [@jllorente](https://discuss.elastic.co/u/jllorente)\
**Replies:** 0\
**Last updated:** [July 29, 2021, 7:30am UTC](https://discuss.elastic.co/t/filebeat-running-on-kubernetes-connected-to-elasticsearch-using-ssl/279946 "2021-07-29T07:30:54Z")

</div>

I would like to use filebeat on Kubernetes and connect it to a secured Elasticsearch server, using certificates. I did a search to find how to do this but only found an un-answered related question. After some test I go…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=140)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=142)
