# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=144

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 145

---

## [Heartbeat : Panic error using SSL Verification\_mode None](https://discuss.elastic.co/t/heartbeat-panic-error-using-ssl-verification-mode-none/276396)

<div class="topic-metadata">

**Author:** [@tjussey](https://discuss.elastic.co/u/tjussey)\
**Replies:** 4\
**Last updated:** [July 20, 2021, 5:30pm UTC](https://discuss.elastic.co/t/heartbeat-panic-error-using-ssl-verification-mode-none/276396 "2021-07-20T17:30:31Z")

</div>

Hi everyone, I'm using Heartbeat 7.13.1 on Debian 9.13. I setup monitors like this one : heartbeat.monitors: - type: http enabled: true id: anId name: aName urls: \["https//private.fr:59862"\] schedule: '@ever…

---

## [Issue with metricbeat keystore integration](https://discuss.elastic.co/t/issue-with-metricbeat-keystore-integration/278889)

<div class="topic-metadata">

**Author:** [@lokeshv1989](https://discuss.elastic.co/u/lokeshv1989)\
**Replies:** 2\
**Last updated:** [July 20, 2021, 3:13pm UTC](https://discuss.elastic.co/t/issue-with-metricbeat-keystore-integration/278889 "2021-07-20T15:13:21Z")

</div>

Hi there, we are trying to use keystore in metricbeats to protect a password value but looks like the ${pwd} which we use in the metricbeat.yml is not able to reference the pwd value i have set in keystore basically lo…

---

## [Missing events while using Filebeat multiline.flush\_pattern](https://discuss.elastic.co/t/missing-events-while-using-filebeat-multiline-flush-pattern/279175)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 0\
**Last updated:** [July 20, 2021, 2:39pm UTC](https://discuss.elastic.co/t/missing-events-while-using-filebeat-multiline-flush-pattern/279175 "2021-07-20T14:39:27Z")

</div>

Filebeat "multiline.flush\_pattern" is flushing the multiline line event starting with "multiline.pattern" and ending with "multiline.flush\_pattern". I am facing 2 issues with multiline.flush\_pattern, The lines after "…

---

## [Old Elastic Cloud agent policies](https://discuss.elastic.co/t/old-elastic-cloud-agent-policies/279126)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 0\
**Last updated:** [July 20, 2021, 7:47am UTC](https://discuss.elastic.co/t/old-elastic-cloud-agent-policies/279126 "2021-07-20T07:47:28Z")

</div>

Hi, With every new version of Elastic a new "Elastic Cloud agent policy" is created in Fleet. Can I safely delete the old ones? And how? See screenshot. Thanks, Herman

---

## [Elastic-Agent Zombie process](https://discuss.elastic.co/t/elastic-agent-zombie-process/279123)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 0\
**Last updated:** [July 20, 2021, 7:38am UTC](https://discuss.elastic.co/t/elastic-agent-zombie-process/279123 "2021-07-20T07:38:53Z")

</div>

Hi, On all my (freshly installed) Ubuntu servers I installed elastic-agent via the tarball method. On every server there is a 'zombie' elastic-agent process present next to the working elastic-agent. What's going on he…

---

## [Daemonset - collecting the pod's namespace along with log](https://discuss.elastic.co/t/daemonset-collecting-the-pods-namespace-along-with-log/278979)

<div class="topic-metadata">

**Author:** [@Jongz\_Puangput](https://discuss.elastic.co/u/Jongz_Puangput)\
**Replies:** 1\
**Last updated:** [July 20, 2021, 3:00am UTC](https://discuss.elastic.co/t/daemonset-collecting-the-pods-namespace-along-with-log/278979 "2021-07-20T03:00:13Z")

</div>

Hi Guys, I set up Filebeat with the DaemonSet approach. All containers log is shipped to LogStash successfully. However, I'm facing the issue that I cannot differentiate container logs for DEV and QA namespace under the…

---

## [Transfer and indexing data on JSON](https://discuss.elastic.co/t/transfer-and-indexing-data-on-json/277832)

<div class="topic-metadata">

**Author:** [@Wonder\_Garance](https://discuss.elastic.co/u/Wonder_Garance)\
**Replies:** 4\
**Last updated:** [July 19, 2021, 5:53pm UTC](https://discuss.elastic.co/t/transfer-and-indexing-data-on-json/277832 "2021-07-19T17:53:02Z")

</div>

Hello, we have a data server which contains XML and / or JSON data, we want to transform these data on JSON, transfer and indexing them on Elasticsearch. After a quick search, it's possible to use Filebeat. I think File…

---

## [Fleet managed elastic agent enrolled as standalone via AzDo pipeline](https://discuss.elastic.co/t/fleet-managed-elastic-agent-enrolled-as-standalone-via-azdo-pipeline/278863)

<div class="topic-metadata">

**Author:** [@dabo](https://discuss.elastic.co/u/dabo)\
**Replies:** 3\
**Last updated:** [July 19, 2021, 3:22pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-enrolled-as-standalone-via-azdo-pipeline/278863 "2021-07-19T15:22:50Z")

</div>

We are installing elastic agents onto WS2019 VMs via Azure DevOps pipelines. In the pipeline in one particular stage/task there is one powershell script that installs different packages on the server and Elastic Agent i…

---

## [Filebeat unable to parse logs with log4j format](https://discuss.elastic.co/t/filebeat-unable-to-parse-logs-with-log4j-format/278824)

<div class="topic-metadata">

**Author:** [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Replies:** 1\
**Last updated:** [July 19, 2021, 3:24pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-parse-logs-with-log4j-format/278824 "2021-07-19T15:24:19Z")

</div>

Currently we do run Tomcat server with log4j logging framework Filebeat unable to parse logs with log4j format Can any please suggest

---

## [Why wildcard not working? Filebeat 7.13.3](https://discuss.elastic.co/t/why-wildcard-not-working-filebeat-7-13-3/278693)

<div class="topic-metadata">

**Author:** [@Oleg\_Makar21e31](https://discuss.elastic.co/u/Oleg_Makar21e31)\
**Replies:** 1\
**Last updated:** [July 19, 2021, 2:37pm UTC](https://discuss.elastic.co/t/why-wildcard-not-working-filebeat-7-13-3/278693 "2021-07-19T14:37:27Z")

</div>

Why wildcard doesnt working in filebeat? I read all logstash's article about PATH and GLOB (not working too even GLOB constructor is valid) and recursive\_glob.enabled: true and it doesnt working for me!!! Why???? Please…

---

## [Useragent information](https://discuss.elastic.co/t/useragent-information/277786)

<div class="topic-metadata">

**Author:** [@111401](https://discuss.elastic.co/u/111401)\
**Replies:** 6\
**Last updated:** [July 19, 2021, 8:56am UTC](https://discuss.elastic.co/t/useragent-information/277786 "2021-07-19T08:56:04Z")

</div>

Hi, i had parsed netflow via filebeat 7.7.0 and send it to logstash 7.6.2 then elasticsearch 7.6.2, but i see the agent field is only about filebeat, not the client device information. "agent" =\> { "i…

---

## [Exiting: Index management requested but the Elasticsearch output is not configured/enabled](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/276274)

<div class="topic-metadata">

**Author:** [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)\
**Replies:** 5\
**Last updated:** [July 19, 2021, 7:57am UTC](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/276274 "2021-07-19T07:57:08Z")

</div>

While running filebeat setup -e I'm getting this error. Can anyone help me? @Marius\_Iversen 2021-06-17T01:04:54.187-0700 INFO instance/beat.go:665 Home path: \[/usr/share/filebeat\] Config path: \[/etc/filebeat\] Data path…

---

## [Filebeat: How can I add tags to module input in filebeat?](https://discuss.elastic.co/t/filebeat-how-can-i-add-tags-to-module-input-in-filebeat/276781)

<div class="topic-metadata">

**Author:** [@connectgeeks](https://discuss.elastic.co/u/connectgeeks)\
**Replies:** 4\
**Last updated:** [July 19, 2021, 6:38am UTC](https://discuss.elastic.co/t/filebeat-how-can-i-add-tags-to-module-input-in-filebeat/276781 "2021-07-19T06:38:36Z")

</div>

I'm using filebeat module and want to use tag so that I can process different input files based on tags. How can I achieve that ? Below tags doesn't seems to work. modules.d/elasticsearch.yml - module: elasticsearch …

---

## [Deploy Agents on Multiple Servers](https://discuss.elastic.co/t/deploy-agents-on-multiple-servers/278830)

<div class="topic-metadata">

**Author:** [@Ashwin\_Patil1](https://discuss.elastic.co/u/Ashwin_Patil1)\
**Replies:** 4\
**Last updated:** [July 19, 2021, 6:30am UTC](https://discuss.elastic.co/t/deploy-agents-on-multiple-servers/278830 "2021-07-19T06:30:40Z")

</div>

I have to deploy winlogbeat agent on 250 windows servers, what would be the best and efficient way of doing this?

---

## [How to Deploy Agents on Multiple Servers](https://discuss.elastic.co/t/how-to-deploy-agents-on-multiple-servers/279018)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 0\
**Last updated:** [July 19, 2021, 6:29am UTC](https://discuss.elastic.co/t/how-to-deploy-agents-on-multiple-servers/279018 "2021-07-19T06:29:37Z")

</div>

Hello team, I have installed beat agents on single machine and I want to get them installed (filebeat) on 500 windows and 200 linux machine. I don't want to login to each and every machine and install them. I want to r…

---

## [Functionbeat ignores default region - only deploys to us-east-1 (AWS)](https://discuss.elastic.co/t/functionbeat-ignores-default-region-only-deploys-to-us-east-1-aws/276002)

<div class="topic-metadata">

**Author:** [@Phuurl](https://discuss.elastic.co/u/Phuurl)\
**Replies:** 4\
**Last updated:** [July 18, 2021, 7:59pm UTC](https://discuss.elastic.co/t/functionbeat-ignores-default-region-only-deploys-to-us-east-1-aws/276002 "2021-07-18T19:59:38Z")

</div>

Hey, Trying to deploy the latest Functionbeat version (7.13.x), and it appears that Functionbeat is ignoring the AWS\_DEFAULT\_REGION environment variable when deploying - it always deploys to North Virginia (us-east-1) i…

---

## [Metricbeat issue](https://discuss.elastic.co/t/metricbeat-issue/278743)

<div class="topic-metadata">

**Author:** [@raj\_mouriya](https://discuss.elastic.co/u/raj_mouriya)\
**Replies:** 2\
**Last updated:** [July 18, 2021, 2:20pm UTC](https://discuss.elastic.co/t/metricbeat-issue/278743 "2021-07-18T14:20:30Z")

</div>

Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://localhost:5601/api/status fails: fail to execute the HTTP GET request: Get "https://localhost:5601/api/status": dial tcp \[:…

---

## [Filebeat redis module not working](https://discuss.elastic.co/t/filebeat-redis-module-not-working/278965)

<div class="topic-metadata">

**Author:** [@Mason](https://discuss.elastic.co/u/Mason)\
**Replies:** 0\
**Last updated:** [July 17, 2021, 10:35am UTC](https://discuss.elastic.co/t/filebeat-redis-module-not-working/278965 "2021-07-17T10:35:03Z")

</div>

Hi, I am using redis module from filebeat to monitor a redis docker container. (using docker image docker.elastic.co/beats/filebeat:7.13.1) # enable redis module filebeat.modules: - module: redis # redis container fi…

---

## [Filebeat does not pickup rotated logfile from NLog](https://discuss.elastic.co/t/filebeat-does-not-pickup-rotated-logfile-from-nlog/278923)

<div class="topic-metadata">

**Author:** [@paleocomburo](https://discuss.elastic.co/u/paleocomburo)\
**Replies:** 1\
**Last updated:** [July 16, 2021, 3:54pm UTC](https://discuss.elastic.co/t/filebeat-does-not-pickup-rotated-logfile-from-nlog/278923 "2021-07-16T15:54:20Z")

</div>

Hello, I'm currently trying to get our structured event logging into Elastic Search. We have a .NET 5 application that is running in a Docker container and it runs on a CentOS 7 server, where it writes the log to a serv…

---

## [Functionbeat 1.11 cannot process more than one message on cloud function](https://discuss.elastic.co/t/functionbeat-1-11-cannot-process-more-than-one-message-on-cloud-function/278905)

<div class="topic-metadata">

**Author:** [@yerome](https://discuss.elastic.co/u/yerome)\
**Replies:** 0\
**Last updated:** [July 16, 2021, 1:10pm UTC](https://discuss.elastic.co/t/functionbeat-1-11-cannot-process-more-than-one-message-on-cloud-function/278905 "2021-07-16T13:10:35Z")

</div>

Hello, When I deploy functionbeat 1.11 on a GCP Cloud function, functionbeat always crashes after having to deal with the second event coming from pub/sub. Error message shows a panic crash like this : WARN\\t\[cfgwarn\]…

---

## [Functionbeat 1.12 and 1.13 cannot deploy on GCP Cloud function](https://discuss.elastic.co/t/functionbeat-1-12-and-1-13-cannot-deploy-on-gcp-cloud-function/278901)

<div class="topic-metadata">

**Author:** [@yerome](https://discuss.elastic.co/u/yerome)\
**Replies:** 0\
**Last updated:** [July 16, 2021, 12:58pm UTC](https://discuss.elastic.co/t/functionbeat-1-12-and-1-13-cannot-deploy-on-gcp-cloud-function/278901 "2021-07-16T12:58:09Z")

</div>

Because cloud function uses goland 1.13 and since 1.12 version of functionbeat is using goland 1.15 the deployment doesn't work. At the end of the deployment those errors appear : DEBUG \[gcp\] gcp/cli\_manager.go:47 Depl…

---

## [Filebeat autodiscover for local log Docker driver](https://discuss.elastic.co/t/filebeat-autodiscover-for-local-log-docker-driver/278878)

<div class="topic-metadata">

**Author:** [@llsousa](https://discuss.elastic.co/u/llsousa)\
**Replies:** 0\
**Last updated:** [July 16, 2021, 10:21am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-for-local-log-docker-driver/278878 "2021-07-16T10:21:01Z")

</div>

Hi, there, first post here. Suppose this Filebeat autodiscover configuration for Docker containers: filebeat.autodiscover: providers: - type: docker hints.enabled: true hints.default\_config.enabled: f…

---

## [Unable to view elastic-agent logs in Fleet](https://discuss.elastic.co/t/unable-to-view-elastic-agent-logs-in-fleet/278117)

<div class="topic-metadata">

**Author:** [@tcaudill](https://discuss.elastic.co/u/tcaudill)\
**Replies:** 5\
**Last updated:** [July 15, 2021, 6:44pm UTC](https://discuss.elastic.co/t/unable-to-view-elastic-agent-logs-in-fleet/278117 "2021-07-15T18:44:21Z")

</div>

I have successfully configured Fleet and have deployed a few elastic-agents in my infrastructure. When I go to Management - Fleet - Agents, select an agent, and then select logs, nothing shows. However, if I go to Kiba…

---

## [Change distribution version number](https://discuss.elastic.co/t/change-distribution-version-number/278719)

<div class="topic-metadata">

**Author:** [@prandelicious](https://discuss.elastic.co/u/prandelicious)\
**Replies:** 2\
**Last updated:** [July 15, 2021, 2:32pm UTC](https://discuss.elastic.co/t/change-distribution-version-number/278719 "2021-07-15T14:32:44Z")

</div>

Every time I run make release, it always creates beats-8.0.0-platform.tar.gz. Is there a way to change the version number?

---

## [Kafka output dropping single message every time connection to kafka is lost](https://discuss.elastic.co/t/kafka-output-dropping-single-message-every-time-connection-to-kafka-is-lost/278632)

<div class="topic-metadata">

**Author:** [@tporeba](https://discuss.elastic.co/u/tporeba)\
**Replies:** 2\
**Last updated:** [July 15, 2021, 12:43pm UTC](https://discuss.elastic.co/t/kafka-output-dropping-single-message-every-time-connection-to-kafka-is-lost/278632 "2021-07-15T12:43:18Z")

</div>

I tested the behaviour of filebeat kafka output when connection to kafka is lost and recovered. Events are correctly redelivered even if the connection is down for a few minutes, but I observe a single event (probably fi…

---

## [Winlogbeat Original Field remove](https://discuss.elastic.co/t/winlogbeat-original-field-remove/278768)

<div class="topic-metadata">

**Author:** [@Frack](https://discuss.elastic.co/u/Frack)\
**Replies:** 0\
**Last updated:** [July 15, 2021, 11:07am UTC](https://discuss.elastic.co/t/winlogbeat-original-field-remove/278768 "2021-07-15T11:07:23Z")

</div>

Hi, Why some field are remove when convert to ECS ? For exemple DestinationIsIpv6 from sysmon: 'winlog.event\_data.SourceIsIpv6' is remove after create 'network.type'. As I have to work with beat agent and industrial…

---

## [413 Request Entity Too Large - metricbeat error on elected MASTER node](https://discuss.elastic.co/t/413-request-entity-too-large-metricbeat-error-on-elected-master-node/278732)

<div class="topic-metadata">

**Author:** [@anon17386273](https://discuss.elastic.co/u/anon17386273)\
**Replies:** 0\
**Last updated:** [July 15, 2021, 3:46am UTC](https://discuss.elastic.co/t/413-request-entity-too-large-metricbeat-error-on-elected-master-node/278732 "2021-07-15T03:46:27Z")

</div>

Is there a limitation that metricbeat can collect from the elected MASTER node? I have 300 data nodes with metricbeats having no issue running but when it comes to the collecting metrics from the elected MASTER, i encou…

---

## [Display log.level](https://discuss.elastic.co/t/display-log-level/278501)

<div class="topic-metadata">

**Author:** [@yango](https://discuss.elastic.co/u/yango)\
**Replies:** 4\
**Last updated:** [July 15, 2021, 3:34am UTC](https://discuss.elastic.co/t/display-log-level/278501 "2021-07-15T03:34:10Z")

</div>

Is there any way to display log.level field in kibana while using filebeat/auditbeat?

---

## [Can you tell me on average what would be the consumption of the agent filebeat?](https://discuss.elastic.co/t/can-you-tell-me-on-average-what-would-be-the-consumption-of-the-agent-filebeat/278669)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 0\
**Last updated:** [July 14, 2021, 1:37pm UTC](https://discuss.elastic.co/t/can-you-tell-me-on-average-what-would-be-the-consumption-of-the-agent-filebeat/278669 "2021-07-14T13:37:09Z")

</div>

Can you tell me on average what would be the consumption of the agent filebeat? I know it depends on many things, but if there is an indication like this: if it's just a file that generates so many lines per second, the …

---

## [ElasticSearch not collect System metrics by metricBeat agent](https://discuss.elastic.co/t/elasticsearch-not-collect-system-metrics-by-metricbeat-agent/278043)

<div class="topic-metadata">

**Author:** [@bhamidpour](https://discuss.elastic.co/u/bhamidpour)\
**Replies:** 3\
**Last updated:** [July 14, 2021, 9:24am UTC](https://discuss.elastic.co/t/elasticsearch-not-collect-system-metrics-by-metricbeat-agent/278043 "2021-07-14T09:24:47Z")

</div>

Hi, I used this document to run metricbeat agent. kibana path: https://elastic.mydomain.com:5601 elastic path: http://elastic.mydomain.com:9200 (without TLS) after set configurations in "/etc/metricbeat/metricbeat.ym…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=143)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=145)
