# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=145

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 146

---

## [Kubernetes Metadata from Filebeat doesn't apply](https://discuss.elastic.co/t/kubernetes-metadata-from-filebeat-doesnt-apply/278627)

<div class="topic-metadata">

**Author:** [@Leonadius](https://discuss.elastic.co/u/Leonadius)\
**Replies:** 0\
**Last updated:** [July 14, 2021, 8:24am UTC](https://discuss.elastic.co/t/kubernetes-metadata-from-filebeat-doesnt-apply/278627 "2021-07-14T08:24:56Z")

</div>

Dear Team, I'm currently deploying filebeat 7.12 on kubernetes as Daemonset, and sending the logs to elasticsearch on kubernetes also. The problem is, kubernetes metadata doesn't apply on my elasticsearch although i'm …

---

## [Treatments by filebeat files](https://discuss.elastic.co/t/treatments-by-filebeat-files/278539)

<div class="topic-metadata">

**Author:** [@boubou](https://discuss.elastic.co/u/boubou)\
**Replies:** 1\
**Last updated:** [July 13, 2021, 11:56pm UTC](https://discuss.elastic.co/t/treatments-by-filebeat-files/278539 "2021-07-13T23:56:17Z")

</div>

Hello everybody :smiley: I need you to configure my filebeat. In fact, I have two logfiles ( /var/log/alpha.log and /var/log/beta.log ) Now, i want create a pipeline with two different treatments... something like th…

---

## [Override default umask](https://discuss.elastic.co/t/override-default-umask/278437)

<div class="topic-metadata">

**Author:** [@prandelicious](https://discuss.elastic.co/u/prandelicious)\
**Replies:** 2\
**Last updated:** [July 13, 2021, 9:00pm UTC](https://discuss.elastic.co/t/override-default-umask/278437 "2021-07-13T21:00:32Z")

</div>

I understand the dev team has hardcoded the umask to 0027 in libbeats so this applies to all beats apps. Is there a way to override this in the configuration file or CLI parameter?

---

## [Are Beats designed to be used with ILM?](https://discuss.elastic.co/t/are-beats-designed-to-be-used-with-ilm/278168)

<div class="topic-metadata">

**Author:** [@kodka](https://discuss.elastic.co/u/kodka)\
**Replies:** 4\
**Last updated:** [July 13, 2021, 1:02pm UTC](https://discuss.elastic.co/t/are-beats-designed-to-be-used-with-ilm/278168 "2021-07-13T13:02:08Z")

</div>

I'm trying to implement ILM to Filebeat indices, but this popped up in the process: We have different Filebeat versions and multiple modules like docker, access, and many others, but for simplicity, let's take a look at…

---

## [Filebeat: Configuring input from URL](https://discuss.elastic.co/t/filebeat-configuring-input-from-url/278195)

<div class="topic-metadata">

**Author:** [@Conor\_Hennessy](https://discuss.elastic.co/u/Conor_Hennessy)\
**Replies:** 3\
**Last updated:** [July 13, 2021, 12:59pm UTC](https://discuss.elastic.co/t/filebeat-configuring-input-from-url/278195 "2021-07-13T12:59:46Z")

</div>

Hi All, I have used filebeat to parse and send an xml to elasticsearch and it has worked nicely. The xml file was downloaded from a url (something like example.com/example.xml) and I then included the path to the downlo…

---

## [Azure Filebeat issues with dashboard setup and data ingestion](https://discuss.elastic.co/t/azure-filebeat-issues-with-dashboard-setup-and-data-ingestion/274823)

<div class="topic-metadata">

**Author:** [@IsAa](https://discuss.elastic.co/u/IsAa)\
**Replies:** 13\
**Last updated:** [July 13, 2021, 12:56pm UTC](https://discuss.elastic.co/t/azure-filebeat-issues-with-dashboard-setup-and-data-ingestion/274823 "2021-07-13T12:56:56Z")

</div>

Hi people, I am currently new to elk stack and have set up elk locally and also have an elastic cloud instance. So as part of the learning phase I am trying to use filebeat to consume data from Azure. I have followed …

---

## [\[bug query\] duplication mac address in hosts metadata - concern?](https://discuss.elastic.co/t/bug-query-duplication-mac-address-in-hosts-metadata-concern/278370)

<div class="topic-metadata">

**Author:** [@kortschak](https://discuss.elastic.co/u/kortschak)\
**Replies:** 1\
**Last updated:** [July 13, 2021, 12:51pm UTC](https://discuss.elastic.co/t/bug-query-duplication-mac-address-in-hosts-metadata-concern/278370 "2021-07-13T12:51:00Z")

</div>

Hi, While working through the creating a beat tutorial I noticed that mac addresses may be duplicated in the hosts metadata on linux. This occurs for virbr interfaces due to virtual bridges generating two interfaces, sh…

---

## [What is filebeat read offset? Why does it change both up and down?](https://discuss.elastic.co/t/what-is-filebeat-read-offset-why-does-it-change-both-up-and-down/278528)

<div class="topic-metadata">

**Author:** [@Matthew\_Field](https://discuss.elastic.co/u/Matthew_Field)\
**Replies:** 0\
**Last updated:** [July 13, 2021, 11:19am UTC](https://discuss.elastic.co/t/what-is-filebeat-read-offset-why-does-it-change-both-up-and-down/278528 "2021-07-13T11:19:23Z")

</div>

I am running filebeat 7.6.2 in docker sending files to logstash. The output performance seems to be limited to around 150 events per second, but the file is being written to around 400 events per second. I am looking at…

---

## [PCF (CloudFoundry) Application rename is not being detected](https://discuss.elastic.co/t/pcf-cloudfoundry-application-rename-is-not-being-detected/278460)

<div class="topic-metadata">

**Author:** [@pausebreathefly](https://discuss.elastic.co/u/pausebreathefly)\
**Replies:** 4\
**Last updated:** [July 13, 2021, 2:02am UTC](https://discuss.elastic.co/t/pcf-cloudfoundry-application-rename-is-not-being-detected/278460 "2021-07-13T02:02:21Z")

</div>

Hi, We have configured the below processors in our filebeat application deployed on TAS or PCF but when we rename any application the changes are not being honored. Is there any additional setting that needs to be confi…

---

## [Drop event in heartbeat](https://discuss.elastic.co/t/drop-event-in-heartbeat/278096)

<div class="topic-metadata">

**Author:** [@guimap](https://discuss.elastic.co/u/guimap)\
**Replies:** 2\
**Last updated:** [July 12, 2021, 5:02pm UTC](https://discuss.elastic.co/t/drop-event-in-heartbeat/278096 "2021-07-12T17:02:02Z")

</div>

I would like drop event when namespace is different of "production" I'm using auto discover kubernetes into my heartbeat.yml heartbeat.autodiscover: # Autodiscover services providers: - type: kubernetes resou…

---

## [Winlogbeat Keystore Command Not working](https://discuss.elastic.co/t/winlogbeat-keystore-command-not-working/278413)

<div class="topic-metadata">

**Author:** [@Ashwin\_Patil1](https://discuss.elastic.co/u/Ashwin_Patil1)\
**Replies:** 0\
**Last updated:** [July 12, 2021, 11:00am UTC](https://discuss.elastic.co/t/winlogbeat-keystore-command-not-working/278413 "2021-07-12T11:00:08Z")

</div>

I am trying to create keystore for winlogbeat, am getting the below error. Can anyone please tell me what is my mistake? C:\\Program Files\\Winlogbeat\\data\>winlogbeat keystore create 'winlogbeat' is not recognized as an i…

---

## [\[Filebeat\] aws-cloudwatch input sends logs only after the filebeat service restarts](https://discuss.elastic.co/t/filebeat-aws-cloudwatch-input-sends-logs-only-after-the-filebeat-service-restarts/278336)

<div class="topic-metadata">

**Author:** [@Luci](https://discuss.elastic.co/u/Luci)\
**Replies:** 0\
**Last updated:** [July 10, 2021, 2:41pm UTC](https://discuss.elastic.co/t/filebeat-aws-cloudwatch-input-sends-logs-only-after-the-filebeat-service-restarts/278336 "2021-07-10T14:41:48Z")

</div>

Filebeats ver: 7.13 I am using the aws-cloudwatch plugin with the following input configuration. \[2021-07-10 13:39:49.883Z:30560:I:\_\_main\_\_:wst-infra:39\] Invoking: sshi on account: beacon-test-tko region: None filebeat…

---

## [Heartbeat: Locking-Down Heartbeat and Beats when "HTTP Endpoint" is Enabled on the Beats?](https://discuss.elastic.co/t/heartbeat-locking-down-heartbeat-and-beats-when-http-endpoint-is-enabled-on-the-beats/278292)

<div class="topic-metadata">

**Author:** [@Log\_Gobbler](https://discuss.elastic.co/u/Log_Gobbler)\
**Replies:** 0\
**Last updated:** [July 9, 2021, 4:29pm UTC](https://discuss.elastic.co/t/heartbeat-locking-down-heartbeat-and-beats-when-http-endpoint-is-enabled-on-the-beats/278292 "2021-07-09T16:29:59Z")

</div>

I have a test Heartbeat and test Filebeat (with "HTTP Endpoint" enabled) set-up and working (via Uptime) but they do not have security features enabled/configured between them. I've stored the credentials in the Heartbe…

---

## [Add\_process\_metadata cannot parse pid in integer](https://discuss.elastic.co/t/add-process-metadata-cannot-parse-pid-in-integer/263380)

<div class="topic-metadata">

**Author:** [@Yin\_Zhang](https://discuss.elastic.co/u/Yin_Zhang)\
**Replies:** 3\
**Last updated:** [July 9, 2021, 8:40pm UTC](https://discuss.elastic.co/t/add-process-metadata-cannot-parse-pid-in-integer/263380 "2021-07-09T20:40:03Z")

</div>

Hi all, I got some weird error when using add\_process\_metadata in filebeat 7.10.2. It doesn't seem to like integer value. Given following json input: { "level": "info", "pid": 1, "message": "test1", "tags": \["tag1", "…

---

## [Winlogbeat winlog.event\_data.AccessList process](https://discuss.elastic.co/t/winlogbeat-winlog-event-data-accesslist-process/278303)

<div class="topic-metadata">

**Author:** [@MarceloSamoilenko](https://discuss.elastic.co/u/MarceloSamoilenko)\
**Replies:** 0\
**Last updated:** [July 9, 2021, 6:49pm UTC](https://discuss.elastic.co/t/winlogbeat-winlog-event-data-accesslist-process/278303 "2021-07-09T18:49:08Z")

</div>

Hello everyone, I want to have control of log events using Winlogbeat with parsing event with id 4663, winlog.event\_data.AccessMask's and winlog.event\_data.AccessList's winlog.event\_data.AccessMask: "0x10000" winlog.e…

---

## [Filebeat threatintel module error](https://discuss.elastic.co/t/filebeat-threatintel-module-error/278287)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 0\
**Last updated:** [July 9, 2021, 2:42pm UTC](https://discuss.elastic.co/t/filebeat-threatintel-module-error/278287 "2021-07-09T14:42:19Z")

</div>

Hello, I am trying the new threat intel module, I am having an error in the otx 2021-07-09T16:33:12.322+0200 ERROR \[input.httpjson-cursor.retryablehttp\] go-retryablehttp@v0.6.6/client.go:553 request failed%!(EXTRA stri…

---

## [Filebeat: Incorrect HTTP method after upgrade to 7.13](https://discuss.elastic.co/t/filebeat-incorrect-http-method-after-upgrade-to-7-13/277964)

<div class="topic-metadata">

**Author:** [@PascalTurbo](https://discuss.elastic.co/u/PascalTurbo)\
**Replies:** 3\
**Last updated:** [July 9, 2021, 11:52am UTC](https://discuss.elastic.co/t/filebeat-incorrect-http-method-after-upgrade-to-7-13/277964 "2021-07-09T11:52:07Z")

</div>

Hi There, I'm using filebeat on a windows server with iis module enabled. After upgrading from 7.10 to 7.13 it starts writing this error. I don't understand why, because the documentation lists PUT method and I don't th…

---

## [Filebeat stops working with error message UDP Package size to large](https://discuss.elastic.co/t/filebeat-stops-working-with-error-message-udp-package-size-to-large/278151)

<div class="topic-metadata">

**Author:** [@rolandmueller](https://discuss.elastic.co/u/rolandmueller)\
**Replies:** 2\
**Last updated:** [July 9, 2021, 11:21am UTC](https://discuss.elastic.co/t/filebeat-stops-working-with-error-message-udp-package-size-to-large/278151 "2021-07-09T11:21:17Z")

</div>

Hello As in the log files it's recommeded to report this I would like todo so. I have Filebeat installed (7.13.2) on Windows Server 2019 (1809). We have Air Watch Cloud Connector (19.12) configured for sending Syslog da…

---

## [What is best practice for indexing for hot/warm/cold...daily indices?](https://discuss.elastic.co/t/what-is-best-practice-for-indexing-for-hot-warm-cold-daily-indices/278196)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 1\
**Last updated:** [July 9, 2021, 9:00am UTC](https://discuss.elastic.co/t/what-is-best-practice-for-indexing-for-hot-warm-cold-daily-indices/278196 "2021-07-09T09:00:58Z")

</div>

I have a ILM policy for 7 days in hot, 23 days in warm and the rest in cold. Should I have a new index created every day for this?

---

## [Winlogbeat timestamp different with event create time](https://discuss.elastic.co/t/winlogbeat-timestamp-different-with-event-create-time/278160)

<div class="topic-metadata">

**Author:** [@Jacky1](https://discuss.elastic.co/u/Jacky1)\
**Replies:** 2\
**Last updated:** [July 9, 2021, 3:38am UTC](https://discuss.elastic.co/t/winlogbeat-timestamp-different-with-event-create-time/278160 "2021-07-09T03:38:46Z")

</div>

Dears I got a very strange problem. We installed winlogbeat v7.2 and directly shipped windows event log to ES, configurations about winlogbeat as below: name: Security ignore\_older: 24h name: Microsoft-Windows-NTLM/O…

---

## [Netflow Configuration](https://discuss.elastic.co/t/netflow-configuration/278176)

<div class="topic-metadata">

**Author:** [@Ashwin\_Patil1](https://discuss.elastic.co/u/Ashwin_Patil1)\
**Replies:** 1\
**Last updated:** [July 8, 2021, 4:15pm UTC](https://discuss.elastic.co/t/netflow-configuration/278176 "2021-07-08T16:15:01Z")

</div>

what would be the best way to ingest netflow traffic in elastic? I couldn't find much info about this on elastic website.

---

## [Can No Longer Use Range Condition to Drop Events By Event ID?](https://discuss.elastic.co/t/can-no-longer-use-range-condition-to-drop-events-by-event-id/278206)

<div class="topic-metadata">

**Author:** [@eafrost.cissp](https://discuss.elastic.co/u/eafrost.cissp)\
**Replies:** 0\
**Last updated:** [July 8, 2021, 4:05pm UTC](https://discuss.elastic.co/t/can-no-longer-use-range-condition-to-drop-events-by-event-id/278206 "2021-07-08T16:05:39Z")

</div>

This post is a continuation of https://discuss.elastic.co/t/winlogbeat-7-13-0-expected-int-but-got-type-string-in-equals-condition/274273/3, which didn't produce a complete solution for me. With the change of data type f…

---

## [Remove first few characters from log file - filebeat](https://discuss.elastic.co/t/remove-first-few-characters-from-log-file-filebeat/277475)

<div class="topic-metadata">

**Author:** [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Replies:** 2\
**Last updated:** [July 1, 2021, 2:27pm UTC](https://discuss.elastic.co/t/remove-first-few-characters-from-log-file-filebeat/277475 "2021-07-01T14:27:54Z")

</div>

Hi Team, We are using filbeat as an agent to pull the logs from different servers, a few of the logs have prefixes that get stuck in front of actual log events. In order to parse the log files we need to remove these p…

---

## [Beats with ILM](https://discuss.elastic.co/t/beats-with-ilm/278177)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 0\
**Last updated:** [July 8, 2021, 11:02am UTC](https://discuss.elastic.co/t/beats-with-ilm/278177 "2021-07-08T11:02:51Z")

</div>

I am using Elastic cloud and have configured an Index Lifecycle Policy. We initially had a trial period with Elastic and have started pulling in data via filebeats, winlogbeats etc, which have created their own index te…

---

## [Filebeat CEF Checkpoint errors](https://discuss.elastic.co/t/filebeat-cef-checkpoint-errors/278040)

<div class="topic-metadata">

**Author:** [@rainierwolf](https://discuss.elastic.co/u/rainierwolf)\
**Replies:** 5\
**Last updated:** [July 8, 2021, 8:44am UTC](https://discuss.elastic.co/t/filebeat-cef-checkpoint-errors/278040 "2021-07-08T08:44:03Z")

</div>

Hello team, I have been testing this solution for a short time and it seems very powerful. I have enabled Filebeat with the CEF module for the logs of our Checkpoint platform. I have configured filebeat indicated in the…

---

## [Filebeat Multiline - requires pattern to repeat?](https://discuss.elastic.co/t/filebeat-multiline-requires-pattern-to-repeat/277982)

<div class="topic-metadata">

**Author:** [@MrDecisive](https://discuss.elastic.co/u/MrDecisive)\
**Replies:** 1\
**Last updated:** [July 7, 2021, 11:30am UTC](https://discuss.elastic.co/t/filebeat-multiline-requires-pattern-to-repeat/277982 "2021-07-07T11:30:07Z")

</div>

I have a file like this. \[2021-04-22T13:10:06.549Z\] Start new event \[2021-04-22T13:10:06.549Z\] + set \[2021-04-22T13:10:06.549Z\] BUILD\_NUMBER=401 \[2021-04-22T13:10:06.549Z\] BRANCH\_NAME=develop \[2021-04-22T13:10:06.549Z\] …

---

## [Parsing logs of FIlebeat and send to Elastic search](https://discuss.elastic.co/t/parsing-logs-of-filebeat-and-send-to-elastic-search/277944)

<div class="topic-metadata">

**Author:** [@ranvijaysanu](https://discuss.elastic.co/u/ranvijaysanu)\
**Replies:** 2\
**Last updated:** [July 7, 2021, 2:24am UTC](https://discuss.elastic.co/t/parsing-logs-of-filebeat-and-send-to-elastic-search/277944 "2021-07-07T02:24:37Z")

</div>

I am using filebeat to ship the logs directly to elastic search and then visualizing it in Kibana. I want to parse the message field to fetch the response code(200 as per the below screenshot) as a separate field in Kib…

---

## [Cisco Filebeat Issues](https://discuss.elastic.co/t/cisco-filebeat-issues/277890)

<div class="topic-metadata">

**Author:** [@codersoul](https://discuss.elastic.co/u/codersoul)\
**Replies:** 4\
**Last updated:** [July 7, 2021, 1:36am UTC](https://discuss.elastic.co/t/cisco-filebeat-issues/277890 "2021-07-07T01:36:18Z")

</div>

Hi, I'm working with Filebeat and Cisco Module in a Lab. I am ingesting data from Cisco AMP, everything work as expected , but I getting this error in Filebeat logs. Jul 02 09:26:48 cstxsvngs01 filebeat\[25410\]: 2021-07…

---

## [Filebeat: Exiting: Failed to start crawler: creating module reloader failed: string value is not set accessing 'connection\_string'](https://discuss.elastic.co/t/filebeat-exiting-failed-to-start-crawler-creating-module-reloader-failed-string-value-is-not-set-accessing-connection-string/276552)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 5\
**Last updated:** [July 6, 2021, 7:27pm UTC](https://discuss.elastic.co/t/filebeat-exiting-failed-to-start-crawler-creating-module-reloader-failed-string-value-is-not-set-accessing-connection-string/276552 "2021-07-06T19:27:14Z")

</div>

Hello Im suddenly getting this error in Filebeat. Im not sure really where to look at I wasnt getting this error before. Any ideas? Thank you

---

## [Packetbeat filter](https://discuss.elastic.co/t/packetbeat-filter/275087)

<div class="topic-metadata">

**Author:** [@luweijun](https://discuss.elastic.co/u/luweijun)\
**Replies:** 11\
**Last updated:** [July 6, 2021, 4:07pm UTC](https://discuss.elastic.co/t/packetbeat-filter/275087 "2021-07-06T16:07:41Z")

</div>

How does packetbeat filter its own data packets sent to es, because the server itself sends data to es:9200 in the collected data. How to filter the information in this part.

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=144)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=146)
