# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=143

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 144

---

## [Google workspace moduel complais about missing nextPageToken](https://discuss.elastic.co/t/google-workspace-moduel-complais-about-missing-nextpagetoken/279597)

<div class="topic-metadata">

**Author:** [@maf](https://discuss.elastic.co/u/maf)\
**Replies:** 0\
**Last updated:** [July 26, 2021, 7:31am UTC](https://discuss.elastic.co/t/google-workspace-moduel-complais-about-missing-nextpagetoken/279597 "2021-07-26T07:31:27Z")

</div>

We are using Filebeat 13.3 and we see quite a few errors like this in our logs: 2021-07-26T06:51:44.938Z ERROR \[input.httpjson-cursor\] v2/request.go:188 error processing response: template: :1:16: executi…

---

## [Metricbeat SQL Module : Unable to extract data from a custom query](https://discuss.elastic.co/t/metricbeat-sql-module-unable-to-extract-data-from-a-custom-query/279360)

<div class="topic-metadata">

**Author:** [@VinodKumarPotta](https://discuss.elastic.co/u/VinodKumarPotta)\
**Replies:** 6\
**Last updated:** [July 26, 2021, 2:35am UTC](https://discuss.elastic.co/t/metricbeat-sql-module-unable-to-extract-data-from-a-custom-query/279360 "2021-07-26T02:35:45Z")

</div>

Hi Team, Seek your expert advise on this. I have recently enabled Metricbeat sql module to extract data from a custom query. I have followed the instructions given in sql.yml file (SQL module | Metricbeat Reference \[7…

---

## [Why .monitoring-\* indices has large size of data](https://discuss.elastic.co/t/why-monitoring-indices-has-large-size-of-data/278027)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 3\
**Last updated:** [July 25, 2021, 3:26pm UTC](https://discuss.elastic.co/t/why-monitoring-indices-has-large-size-of-data/278027 "2021-07-25T15:26:53Z")

</div>

I have 11 elasticsearch nodes 3 master node 6 data node and 2 coordinate node.We are running latest version of elasticsearch 7.13.2 we have installed metricbeat and configured in all elasticsearch node we are monitorin…

---

## [Monitor servers/workstations in different locations over internet](https://discuss.elastic.co/t/monitor-servers-workstations-in-different-locations-over-internet/279524)

<div class="topic-metadata">

**Author:** [@nino](https://discuss.elastic.co/u/nino)\
**Replies:** 2\
**Last updated:** [July 24, 2021, 3:42pm UTC](https://discuss.elastic.co/t/monitor-servers-workstations-in-different-locations-over-internet/279524 "2021-07-24T15:42:50Z")

</div>

Hello, i would like to know some best practices about monitoring remote servers/workstations over internet. I mean, servers in different geographical locations other than ELK server: how beats reach ELK?. Ports how be…

---

## [Filebeat and apache logs](https://discuss.elastic.co/t/filebeat-and-apache-logs/279473)

<div class="topic-metadata">

**Author:** [@colttt](https://discuss.elastic.co/u/colttt)\
**Replies:** 1\
**Last updated:** [July 23, 2021, 11:26pm UTC](https://discuss.elastic.co/t/filebeat-and-apache-logs/279473 "2021-07-23T23:26:32Z")

</div>

Hello, we use filebeat to ship the logs from server to graylog. I saw that filebeat has an apache module, I try that but it looks like that it doesn't work. It looks like that it doesn't parse and add extra fields. I cha…

---

## [Filebeat sending all the lines in a log file as one single entries instead of different entries](https://discuss.elastic.co/t/filebeat-sending-all-the-lines-in-a-log-file-as-one-single-entries-instead-of-different-entries/278816)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 4\
**Last updated:** [July 23, 2021, 6:48pm UTC](https://discuss.elastic.co/t/filebeat-sending-all-the-lines-in-a-log-file-as-one-single-entries-instead-of-different-entries/278816 "2021-07-23T18:48:19Z")

</div>

I have installed filebeat on a server to ingest the stderr logs for tomcat instance. When I am trying to send those logs to my logstash instance its sending as one event instead of multiple events. How can I fix that? M…

---

## [Geoip-info fail on auditbeat, filebeat and packetbeack](https://discuss.elastic.co/t/geoip-info-fail-on-auditbeat-filebeat-and-packetbeack/279497)

<div class="topic-metadata">

**Author:** [@b0r1s](https://discuss.elastic.co/u/b0r1s)\
**Replies:** 2\
**Last updated:** [July 23, 2021, 6:28pm UTC](https://discuss.elastic.co/t/geoip-info-fail-on-auditbeat-filebeat-and-packetbeack/279497 "2021-07-23T18:28:38Z")

</div>

Hello everyone o/ I followed this tutorial and after restarting the beats (it's the same steps for all beats) I can't receive any geoip-info fields. Do I need more configs on .yml files?

---

## [Condition in metricbeat](https://discuss.elastic.co/t/condition-in-metricbeat/279425)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 7\
**Last updated:** [July 23, 2021, 2:52pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425 "2021-07-23T14:52:33Z")

</div>

Trying to setup condition in system.yml file for dropping some event when condition meet what I want to do it if this conditions meet drop the event. ( cond1 OR cond2 OR cond3 ) AND ( cond4 OR cond5 ) for example her…

---

## [Winlogbeat disable IPv6 parsing](https://discuss.elastic.co/t/winlogbeat-disable-ipv6-parsing/279450)

<div class="topic-metadata">

**Author:** [@yango](https://discuss.elastic.co/u/yango)\
**Replies:** 0\
**Last updated:** [July 23, 2021, 7:22am UTC](https://discuss.elastic.co/t/winlogbeat-disable-ipv6-parsing/279450 "2021-07-23T07:22:35Z")

</div>

Is it possible to parse only ipv4 formatted field without including ipv6? Right now my host.ip field in elasticsearch includes multiple values of ipv6 and ipv4 at once. I'm using Winlogbeat 7.10.2 OSS.

---

## [Packetbeat 7.13.3 Error parsing handshake message](https://discuss.elastic.co/t/packetbeat-7-13-3-error-parsing-handshake-message/278903)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 1\
**Last updated:** [July 22, 2021, 9:52pm UTC](https://discuss.elastic.co/t/packetbeat-7-13-3-error-parsing-handshake-message/278903 "2021-07-22T21:52:08Z")

</div>

Hello, I am using packetbeat version 7.13.3, I run it since 3 days and it was working, and today I went to check and found out that it stopped since 12 hours, with some warning at the end of the logs and error. Packetb…

---

## [Functionbeat not sending data to Kibana](https://discuss.elastic.co/t/functionbeat-not-sending-data-to-kibana/279278)

<div class="topic-metadata">

**Author:** [@sproctor](https://discuss.elastic.co/u/sproctor)\
**Replies:** 1\
**Last updated:** [July 22, 2021, 7:38pm UTC](https://discuss.elastic.co/t/functionbeat-not-sending-data-to-kibana/279278 "2021-07-22T19:38:19Z")

</div>

This is my first time using elasticsearch. I'm trying to stream my logs from cloudwatch to elastic cloud. I have functionbeat setup in what seemed like the proper manner, though clearly something is amiss. When my monit…

---

## [SQL Permissions for Monitoring Microsoft SQL Server using Metricbeat](https://discuss.elastic.co/t/sql-permissions-for-monitoring-microsoft-sql-server-using-metricbeat/279294)

<div class="topic-metadata">

**Author:** [@mroughton](https://discuss.elastic.co/u/mroughton)\
**Replies:** 1\
**Last updated:** [July 22, 2021, 2:02pm UTC](https://discuss.elastic.co/t/sql-permissions-for-monitoring-microsoft-sql-server-using-metricbeat/279294 "2021-07-22T14:02:30Z")

</div>

I am looking to implement monitoring Microsoft SQL Server using Metricbeat. What are the minimum SQL user permissions needed for performance and transaction log metric sets?

---

## [Is there a way invoke shell script or python script as part of filebeat output or processor](https://discuss.elastic.co/t/is-there-a-way-invoke-shell-script-or-python-script-as-part-of-filebeat-output-or-processor/279252)

<div class="topic-metadata">

**Author:** [@naresh\_b](https://discuss.elastic.co/u/naresh_b)\
**Replies:** 1\
**Last updated:** [July 22, 2021, 12:24pm UTC](https://discuss.elastic.co/t/is-there-a-way-invoke-shell-script-or-python-script-as-part-of-filebeat-output-or-processor/279252 "2021-07-22T12:24:59Z")

</div>

As part of LSF accounting file monitoring, need some processing(parsing job\_finish event) for each event entry using LSF API (python or c). Want to keep this agent as simple as possible, hence considering to use only fil…

---

## [Filebeat multiline Issue](https://discuss.elastic.co/t/filebeat-multiline-issue/279338)

<div class="topic-metadata">

**Author:** [@gangireddy\_l](https://discuss.elastic.co/u/gangireddy_l)\
**Replies:** 0\
**Last updated:** [July 22, 2021, 5:41am UTC](https://discuss.elastic.co/t/filebeat-multiline-issue/279338 "2021-07-22T05:41:46Z")

</div>

Hi Team, I have an issue in filebeat Multiline pattern, below are my logs and filebeat configuration. sample\_logs 21-04-01 Name Succ Fail Reject Thrput Response time (ms) …

---

## [Packetbeat FLOW and analysis results for individual protocols](https://discuss.elastic.co/t/packetbeat-flow-and-analysis-results-for-individual-protocols/279333)

<div class="topic-metadata">

**Author:** [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Replies:** 0\
**Last updated:** [July 22, 2021, 4:05am UTC](https://discuss.elastic.co/t/packetbeat-flow-and-analysis-results-for-individual-protocols/279333 "2021-07-22T04:05:50Z")

</div>

packetbeat,If HTTP protocol and FLOW analysis are enabled, and an HTTP request comes in and responds normally (whether it returns 200,404), will both HTTP and FLOW be analyzed, or will it only be analyzed and output with…

---

## [Packetbeat7.13.3 default BPF](https://discuss.elastic.co/t/packetbeat7-13-3-default-bpf/279009)

<div class="topic-metadata">

**Author:** [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Replies:** 1\
**Last updated:** [July 22, 2021, 2:07am UTC](https://discuss.elastic.co/t/packetbeat7-13-3-default-bpf/279009 "2021-07-22T02:07:59Z")

</div>

packetbeat7.13.3 default BPF Doesn't seem to work. Officially, my understanding is that when I set up a protocol for monitoring, packetbeat will create a default BPF, Contains only ports for this protocol.but however, …

---

## [Filebeat memory overuse](https://discuss.elastic.co/t/filebeat-memory-overuse/279304)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 0\
**Last updated:** [July 21, 2021, 6:27pm UTC](https://discuss.elastic.co/t/filebeat-memory-overuse/279304 "2021-07-21T18:27:26Z")

</div>

Hi, I spotted that some of the Filebeat processes are using a lot of memory without any good reason. I have about 8 files read by FB and this specific environment is mostly stale. However, even after restart, it hogs up…

---

## [No Uptime Monitors found](https://discuss.elastic.co/t/no-uptime-monitors-found/279046)

<div class="topic-metadata">

**Author:** [@Sam\_Sak1](https://discuss.elastic.co/u/Sam_Sak1)\
**Replies:** 8\
**Last updated:** [July 21, 2021, 3:44pm UTC](https://discuss.elastic.co/t/no-uptime-monitors-found/279046 "2021-07-21T15:44:14Z")

</div>

Hello! After installing a heartbeat-elastic, I'm not able to see endpoints under "Monitors" in Uptime page. The everything what it show is "No Uptime Monitors found", even though it shows data in "Pings over time" and i…

---

## [Filebeat exclude\_lines](https://discuss.elastic.co/t/filebeat-exclude-lines/276892)

<div class="topic-metadata">

**Author:** [@Betorov](https://discuss.elastic.co/u/Betorov)\
**Replies:** 3\
**Last updated:** [July 21, 2021, 2:37pm UTC](https://discuss.elastic.co/t/filebeat-exclude-lines/276892 "2021-07-21T14:37:45Z")

</div>

Hi evreyone, I wanted to use exclude\_lines to exlude all line of a file exept the first one. (I want only the name of the file and his path i don't need his message). filebeat.inputs: - type: log enabled: true #clo…

---

## [Filebeat send log to kafka with haproxy module](https://discuss.elastic.co/t/filebeat-send-log-to-kafka-with-haproxy-module/279141)

<div class="topic-metadata">

**Author:** [@Andrey4ik85](https://discuss.elastic.co/u/Andrey4ik85)\
**Replies:** 6\
**Last updated:** [July 21, 2021, 1:49pm UTC](https://discuss.elastic.co/t/filebeat-send-log-to-kafka-with-haproxy-module/279141 "2021-07-21T13:49:13Z")

</div>

Hello! I am currently experiencing a problem to load haproxy module to parse logs and send it to my kafka servers. The system module has been enabled and verified using "filebeat modules list" filebeat version 7.13.3 …

---

## [Auditbeat ERROR instance/beat.go:971 Exiting: one or more modules must be configured](https://discuss.elastic.co/t/auditbeat-error-instance-beat-go-971-exiting-one-or-more-modules-must-be-configured/279272)

<div class="topic-metadata">

**Author:** [@amardeep.mahato](https://discuss.elastic.co/u/amardeep.mahato)\
**Replies:** 0\
**Last updated:** [July 21, 2021, 1:31pm UTC](https://discuss.elastic.co/t/auditbeat-error-instance-beat-go-971-exiting-one-or-more-modules-must-be-configured/279272 "2021-07-21T13:31:07Z")

</div>

Getting below error while installing auditbeat 7.12.1 on EKS cluster: auditbeat ERROR instance/beat.go:971 Exiting: one or more modules must be configured Could you please help?

---

## [Elastic Agent 7.10.1 - Understanding/Changing Data Destination](https://discuss.elastic.co/t/elastic-agent-7-10-1-understanding-changing-data-destination/279267)

<div class="topic-metadata">

**Author:** [@cpoetzel](https://discuss.elastic.co/u/cpoetzel)\
**Replies:** 0\
**Last updated:** [July 21, 2021, 1:05pm UTC](https://discuss.elastic.co/t/elastic-agent-7-10-1-understanding-changing-data-destination/279267 "2021-07-21T13:05:06Z")

</div>

I walked into an existing ELK stack and an learning as i go. Ihave a 7.10.1 ELK Stack with around 5K Agents depolyed at 7.10.1 using Fleet. \*\* Understanding DATA Destination \*\* Under the Global Fleet Settings it says. …

---

## [Problem with filebeat "failed to add target to root"](https://discuss.elastic.co/t/problem-with-filebeat-failed-to-add-target-to-root/278740)

<div class="topic-metadata">

**Author:** [@ThreatInter](https://discuss.elastic.co/u/ThreatInter)\
**Replies:** 2\
**Last updated:** [July 21, 2021, 11:50am UTC](https://discuss.elastic.co/t/problem-with-filebeat-failed-to-add-target-to-root/278740 "2021-07-21T11:50:24Z")

</div>

Hello, I try to decode escaped\_json using "decode\_json\_fields" processor. I want to add my extracted json fields to root. But in log I see this error: DEBUG \[processors\] processing/processors.go:128 Fail to ap…

---

## [FileBeat to push logs](https://discuss.elastic.co/t/filebeat-to-push-logs/279256)

<div class="topic-metadata">

**Author:** [@Vajb12](https://discuss.elastic.co/u/Vajb12)\
**Replies:** 0\
**Last updated:** [July 21, 2021, 11:15am UTC](https://discuss.elastic.co/t/filebeat-to-push-logs/279256 "2021-07-21T11:15:58Z")

</div>

We have installed filebeat in the server where logfiles are available. In this server, we have application related logs available in individual folders split based on the associated microservice.For eg,Login related logs…

---

## [Set up dashboards for Logstash Output](https://discuss.elastic.co/t/set-up-dashboards-for-logstash-output/278989)

<div class="topic-metadata">

**Author:** [@diegz](https://discuss.elastic.co/u/diegz)\
**Replies:** 18\
**Last updated:** [July 21, 2021, 10:07am UTC](https://discuss.elastic.co/t/set-up-dashboards-for-logstash-output/278989 "2021-07-21T10:07:46Z")

</div>

Hi community, I would like to enable dashboards in kibana for metricbeat, heartbeat, filebeat and winlogbeat. On the documentation it says to pass these commands when logstash is in output. What are the settings when …

---

## [403 Forbidden when trying to send logs using Filebeat](https://discuss.elastic.co/t/403-forbidden-when-trying-to-send-logs-using-filebeat/279249)

<div class="topic-metadata">

**Author:** [@OksanaH](https://discuss.elastic.co/u/OksanaH)\
**Replies:** 0\
**Last updated:** [July 21, 2021, 10:04am UTC](https://discuss.elastic.co/t/403-forbidden-when-trying-to-send-logs-using-filebeat/279249 "2021-07-21T10:04:13Z")

</div>

I'm using Filebeat OSS licenced version 7.10, and AWS ElasticSearch 7.10. I use a reverse logging proxy and set up auth like this:proxy\_set\_header Authorization ""; When configuring Filebeat, I use Basic Auth (username…

---

## [Delay betbeen timestamp and event.created on Winlogbeat](https://discuss.elastic.co/t/delay-betbeen-timestamp-and-event-created-on-winlogbeat/279182)

<div class="topic-metadata">

**Author:** [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Replies:** 0\
**Last updated:** [July 20, 2021, 3:43pm UTC](https://discuss.elastic.co/t/delay-betbeen-timestamp-and-event-created-on-winlogbeat/279182 "2021-07-20T15:43:42Z")

</div>

Hello! The problem We have unpredictable flating delay betbeen timestamp and event.created, when process logs with Winlogbeat. Background We use WEF to send logs from Windows host to Windows log collector. Then we us…

---

## [Packetbeat not see some trafic](https://discuss.elastic.co/t/packetbeat-not-see-some-trafic/279229)

<div class="topic-metadata">

**Author:** [@franpom](https://discuss.elastic.co/u/franpom)\
**Replies:** 0\
**Last updated:** [July 21, 2021, 7:05am UTC](https://discuss.elastic.co/t/packetbeat-not-see-some-trafic/279229 "2021-07-21T07:05:10Z")

</div>

Hello, I am trying to set up a sniffer with packetbeat. The sniffer receives the traffic via several mirroring of vlan at the level of a switch. It works very well except for a case identified on a vlan with which I ha…

---

## [Metricbeat: collects k8s pods cpu which is lower than actually used](https://discuss.elastic.co/t/metricbeat-collects-k8s-pods-cpu-which-is-lower-than-actually-used/279215)

<div class="topic-metadata">

**Author:** [@SperChung-11](https://discuss.elastic.co/u/SperChung-11)\
**Replies:** 0\
**Last updated:** [July 21, 2021, 2:17am UTC](https://discuss.elastic.co/t/metricbeat-collects-k8s-pods-cpu-which-is-lower-than-actually-used/279215 "2021-07-21T02:17:31Z")

</div>

We are using metricbeat to collects k8s pods cpu. In the beginning, it can collects the cpu collectly. After running for serveral weeks or serveral months, we found that the pods cpu metricbeat collects is lower than act…

---

## [Object type vs Data type in Filebeat](https://discuss.elastic.co/t/object-type-vs-data-type-in-filebeat/279185)

<div class="topic-metadata">

**Author:** [@gentle\_ghost](https://discuss.elastic.co/u/gentle_ghost)\
**Replies:** 1\
**Last updated:** [July 20, 2021, 8:25pm UTC](https://discuss.elastic.co/t/object-type-vs-data-type-in-filebeat/279185 "2021-07-20T20:25:57Z")

</div>

Hello, I'm circling back on this older discussion I posted about object type vs concrete types trying to push data to elasticsearch using filebeat: The error I've been running into is this: {"type":"mapper\_parsing\_e…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=142)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=144)
