# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=147

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 148

---

## [Filebeat make update fails for new custom module](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/277578)

<div class="topic-metadata">

**Author:** [@Jerry\_Tian](https://discuss.elastic.co/u/Jerry_Tian)\
**Replies:** 0\
**Last updated:** [July 1, 2021, 4:20pm UTC](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/277578 "2021-07-01T16:20:21Z")

</div>

I followed the instructions from here: Creating a New Filebeat Module | Beats Developer Guide \[master\] | Elastic. make create-module MODULE={module} make create-fileset MODULE={module} FILESET={fileset} make create-fiel…

---

## [Creating custom module for filebeat](https://discuss.elastic.co/t/creating-custom-module-for-filebeat/277566)

<div class="topic-metadata">

**Author:** [@Jerry\_Tian](https://discuss.elastic.co/u/Jerry_Tian)\
**Replies:** 0\
**Last updated:** [July 1, 2021, 2:53pm UTC](https://discuss.elastic.co/t/creating-custom-module-for-filebeat/277566 "2021-07-01T14:53:05Z")

</div>

I was watching this webinar Build Your Own Filebeat Module | Elastic to learn how to create my own module. I wanted to test the pipeline.json file that I wrote for a custom log file but I'm not sure how to do it. In the …

---

## [Tomcat logs in filebeat](https://discuss.elastic.co/t/tomcat-logs-in-filebeat/277313)

<div class="topic-metadata">

**Author:** [@Prasanth\_V](https://discuss.elastic.co/u/Prasanth_V)\
**Replies:** 5\
**Last updated:** [July 1, 2021, 11:03am UTC](https://discuss.elastic.co/t/tomcat-logs-in-filebeat/277313 "2021-07-01T11:03:26Z")

</div>

If I add a tomcat log paths in tomcat.yml..why is it not showing in discover section..could you pls give the solution on this case??

---

## [\[Auditbeat\] Monitoring of files/folders with a space in the path not possible](https://discuss.elastic.co/t/auditbeat-monitoring-of-files-folders-with-a-space-in-the-path-not-possible/277537)

<div class="topic-metadata">

**Author:** [@SECUINFRA](https://discuss.elastic.co/u/SECUINFRA)\
**Replies:** 0\
**Last updated:** [July 1, 2021, 10:10am UTC](https://discuss.elastic.co/t/auditbeat-monitoring-of-files-folders-with-a-space-in-the-path-not-possible/277537 "2021-07-01T10:10:25Z")

</div>

Hi, the monitoring of files/folders with a space in the path was not possible using auditbeat (version 7.13): The following rules all resulted in errors: -w /tmp/folder with space -p r -k test1 -w "/tmp/folder with sp…

---

## [Metricbeat error fetching kube-state-metrics](https://discuss.elastic.co/t/metricbeat-error-fetching-kube-state-metrics/277493)

<div class="topic-metadata">

**Author:** [@anupshrestha](https://discuss.elastic.co/u/anupshrestha)\
**Replies:** 0\
**Last updated:** [June 30, 2021, 7:31pm UTC](https://discuss.elastic.co/t/metricbeat-error-fetching-kube-state-metrics/277493 "2021-06-30T19:31:42Z")

</div>

I am getting the following error in metricbeat deployment that is configured to fetch and push metrics from kube-state-metrics. 2021-06-30T19:25:11.318Z ERROR \[kubernetes.state\_statefulset\] state\_statefulset/state\_state…

---

## [Need clearity of FileBeat Monitoring logs](https://discuss.elastic.co/t/need-clearity-of-filebeat-monitoring-logs/277496)

<div class="topic-metadata">

**Author:** [@Parveen\_Sharma](https://discuss.elastic.co/u/Parveen_Sharma)\
**Replies:** 0\
**Last updated:** [June 30, 2021, 8:11pm UTC](https://discuss.elastic.co/t/need-clearity-of-filebeat-monitoring-logs/277496 "2021-06-30T20:11:50Z")

</div>

Hi, I am new user of filebeat and need to understand few information from the filebeat logs. Currently, I have deployed filebeat on windows system. In the logs metrics information are logged every 30 sec but i am unabl…

---

## [Filebeat is not using custom pipeline mentioned in the output.elasticsearch](https://discuss.elastic.co/t/filebeat-is-not-using-custom-pipeline-mentioned-in-the-output-elasticsearch/277465)

<div class="topic-metadata">

**Author:** [@Mahesh\_Gadagi](https://discuss.elastic.co/u/Mahesh_Gadagi)\
**Replies:** 4\
**Last updated:** [June 30, 2021, 3:24pm UTC](https://discuss.elastic.co/t/filebeat-is-not-using-custom-pipeline-mentioned-in-the-output-elasticsearch/277465 "2021-06-30T15:24:42Z")

</div>

Hello all, Currently, I am using filebeat, elastic search 7.9.1 version and I have added the custom Ingest pipeline to push the logs but still, filebeat creates a new Ingest pipeline as filebeat-7.9.1-haproxy-log-pipeli…

---

## [Filebeat multiline.max\_lines limit](https://discuss.elastic.co/t/filebeat-multiline-max-lines-limit/277474)

<div class="topic-metadata">

**Author:** [@adityasingh](https://discuss.elastic.co/u/adityasingh)\
**Replies:** 0\
**Last updated:** [June 30, 2021, 2:43pm UTC](https://discuss.elastic.co/t/filebeat-multiline-max-lines-limit/277474 "2021-06-30T14:43:13Z")

</div>

Hi, I had a query regarding filebeat's multiline.max\_lines option. I know the default value for this is 500 and we can configure it to a number of our choice and the lines after the configured number will be ignored whi…

---

## [Ship metrics to Graphite](https://discuss.elastic.co/t/ship-metrics-to-graphite/277263)

<div class="topic-metadata">

**Author:** [@raghav1](https://discuss.elastic.co/u/raghav1)\
**Replies:** 2\
**Last updated:** [June 30, 2021, 1:27pm UTC](https://discuss.elastic.co/t/ship-metrics-to-graphite/277263 "2021-06-30T13:27:49Z")

</div>

Is there a way to ship metrics to Graphite ? If yes can you please provide an example.

---

## [Filebeat isn’t shipping the last line of a file](https://discuss.elastic.co/t/filebeat-isn-t-shipping-the-last-line-of-a-file/277459)

<div class="topic-metadata">

**Author:** [@jack5](https://discuss.elastic.co/u/jack5)\
**Replies:** 0\
**Last updated:** [June 30, 2021, 12:36pm UTC](https://discuss.elastic.co/t/filebeat-isn-t-shipping-the-last-line-of-a-file/277459 "2021-06-30T12:36:17Z")

</div>

Hi everyone, I'm new in filebeat, I'm using filebeat+ingest node pipeline to send csv properties into elasticsearch. Unfortunately filebeat doesn't send last line of my csv file. I read https://www.elastic.co/guide/en/…

---

## [\[threatintel Filebeat module\] MISP configuration errors with filebeat threatintel module](https://discuss.elastic.co/t/threatintel-filebeat-module-misp-configuration-errors-with-filebeat-threatintel-module/277448)

<div class="topic-metadata">

**Author:** [@Balor](https://discuss.elastic.co/u/Balor)\
**Replies:** 3\
**Last updated:** [June 30, 2021, 12:35pm UTC](https://discuss.elastic.co/t/threatintel-filebeat-module-misp-configuration-errors-with-filebeat-threatintel-module/277448 "2021-06-30T12:35:42Z")

</div>

Hello All, A question about the Filebeat module " threatintel ". On the MISP configuration . Using Filebeat 7.13.2.The below are the settings that I have tested but shows with errors in the filebeat logs. The config is …

---

## [Filebeat tcp and Udp error](https://discuss.elastic.co/t/filebeat-tcp-and-udp-error/277087)

<div class="topic-metadata">

**Author:** [@Ashwin\_Patil1](https://discuss.elastic.co/u/Ashwin_Patil1)\
**Replies:** 6\
**Last updated:** [June 30, 2021, 11:14am UTC](https://discuss.elastic.co/t/filebeat-tcp-and-udp-error/277087 "2021-06-30T11:14:43Z")

</div>

Am getting the following error, can anyone please help? Exiting: Failed to start crawler: starting input failed: Error while initializing input: you must choose between TCP or UDP. Where do I configure the TCP and UDP…

---

## [Metricbeat internal collection not sending data to elasticsearch](https://discuss.elastic.co/t/metricbeat-internal-collection-not-sending-data-to-elasticsearch/277441)

<div class="topic-metadata">

**Author:** [@luminance](https://discuss.elastic.co/u/luminance)\
**Replies:** 0\
**Last updated:** [June 30, 2021, 9:53am UTC](https://discuss.elastic.co/t/metricbeat-internal-collection-not-sending-data-to-elasticsearch/277441 "2021-06-30T09:53:12Z")

</div>

I am running a Metricbeat 7.13.2 (first tried with 7.7.1) on Ubuntu 18.04 which is supposed to send monitoring data to Elastic Cloud instance (7.10.0) using the internal collection, but I don't understand where things ar…

---

## [Packetbeat index template clone](https://discuss.elastic.co/t/packetbeat-index-template-clone/277437)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 0\
**Last updated:** [June 30, 2021, 9:21am UTC](https://discuss.elastic.co/t/packetbeat-index-template-clone/277437 "2021-06-30T09:21:21Z")

</div>

Hello, I would like to run packetbeat in 2 machines, and I would like to create 2 users, where the user 1 can see only logs of the first machine and user 2 can see only the logs of 2nd machine. To do so, I began by clo…

---

## [Filebeat output empty JSON array as "null" instead of "\[\]"](https://discuss.elastic.co/t/filebeat-output-empty-json-array-as-null-instead-of/276604)

<div class="topic-metadata">

**Author:** [@ijingo](https://discuss.elastic.co/u/ijingo)\
**Replies:** 1\
**Last updated:** [June 30, 2021, 7:49am UTC](https://discuss.elastic.co/t/filebeat-output-empty-json-array-as-null-instead-of/276604 "2021-06-30T07:49:23Z")

</div>

Filebeat output empty JSON array as "null" instead of \[ \]. The original line of JSON is as follows, in which "array\_field" is an empty array. {"body": {"array\_field": \[\]}} However, after output, the "array\_field" is c…

---

## [How to force filebeat to send older logs to logstash without duplication](https://discuss.elastic.co/t/how-to-force-filebeat-to-send-older-logs-to-logstash-without-duplication/277405)

<div class="topic-metadata">

**Author:** [@rojin](https://discuss.elastic.co/u/rojin)\
**Replies:** 0\
**Last updated:** [June 30, 2021, 4:27am UTC](https://discuss.elastic.co/t/how-to-force-filebeat-to-send-older-logs-to-logstash-without-duplication/277405 "2021-06-30T04:27:29Z")

</div>

Hello, I have set up the Filebeat to send logs to Logstash. How can I make it send older logs that had not been parsed, to Logstash? Will the logs that have been parsed up to now be duplicated? Can I specify a period of…

---

## [Module status](https://discuss.elastic.co/t/module-status/277348)

<div class="topic-metadata">

**Author:** [@viridiana](https://discuss.elastic.co/u/viridiana)\
**Replies:** 0\
**Last updated:** [June 29, 2021, 12:08pm UTC](https://discuss.elastic.co/t/module-status/277348 "2021-06-29T12:08:27Z")

</div>

Hello, my problem is that I am generating windows metrics for azure and all the steps are executed correctly but when I want to see the Module status it tells me "No data has been received from this module yet" and cmd a…

---

## [Metricbeat not pulling logs from AWS CWAgent namespace](https://discuss.elastic.co/t/metricbeat-not-pulling-logs-from-aws-cwagent-namespace/277119)

<div class="topic-metadata">

**Author:** [@sumeshms](https://discuss.elastic.co/u/sumeshms)\
**Replies:** 1\
**Last updated:** [June 29, 2021, 3:58pm UTC](https://discuss.elastic.co/t/metricbeat-not-pulling-logs-from-aws-cwagent-namespace/277119 "2021-06-29T15:58:26Z")

</div>

Hello I am trying to pull logs from AWS Cloudwatch metricset with the below configuration. Unfortunately no logs received at the metricbeat end. - module: aws period: 300s access\_key\_id: 'xxxxxxx' secret\_access\_…

---

## [Zscaler Module issue](https://discuss.elastic.co/t/zscaler-module-issue/277354)

<div class="topic-metadata">

**Author:** [@Sunflower](https://discuss.elastic.co/u/Sunflower)\
**Replies:** 0\
**Last updated:** [June 29, 2021, 1:10pm UTC](https://discuss.elastic.co/t/zscaler-module-issue/277354 "2021-06-29T13:10:56Z")

</div>

Hi, I enabled the Zscaler module and edited its YAML file module: zscaler zia: enabled: true # Set which input to use between udp (default), tcp or file. var.input: tcp var.syslog\_host: 0.0.0.0 var.syslog\_port…

---

## [Filebeat Modules](https://discuss.elastic.co/t/filebeat-modules/276949)

<div class="topic-metadata">

**Author:** [@leemase004](https://discuss.elastic.co/u/leemase004)\
**Replies:** 3\
**Last updated:** [June 29, 2021, 10:51am UTC](https://discuss.elastic.co/t/filebeat-modules/276949 "2021-06-29T10:51:55Z")

</div>

We inherited a cluster and are trying to update the ingest pipeline (ES version 7.6) Context: When we do GET ingest/pipeline there is a 15k line pipeline. It has all the processors from the filebeat modules they have up…

---

## [Prevent duplicates when enrolling, scripted unenroll?](https://discuss.elastic.co/t/prevent-duplicates-when-enrolling-scripted-unenroll/277331)

<div class="topic-metadata">

**Author:** [@tjfred](https://discuss.elastic.co/u/tjfred)\
**Replies:** 0\
**Last updated:** [June 29, 2021, 9:53am UTC](https://discuss.elastic.co/t/prevent-duplicates-when-enrolling-scripted-unenroll/277331 "2021-06-29T09:53:14Z")

</div>

Hello, Testing Fleet here on our Cloud deployment. I'm building an installer for Elastic Agent that gives us greater control when deploying to endpoints via our management system. My questions: Agent allows enrollin…

---

## [Filbeat to logstash extremely slow](https://discuss.elastic.co/t/filbeat-to-logstash-extremely-slow/277311)

<div class="topic-metadata">

**Author:** [@Zyrel](https://discuss.elastic.co/u/Zyrel)\
**Replies:** 0\
**Last updated:** [June 29, 2021, 7:52am UTC](https://discuss.elastic.co/t/filbeat-to-logstash-extremely-slow/277311 "2021-06-29T07:52:10Z")

</div>

Hi everybody; I have Filebeat 7.12 deployed as a DaemonSet on a EKS Cluster, fetching the logs from containers filtered by namespace; persistence queue on disk is enabled with a max size of 10GB. Filebeat ships logs to…

---

## [AKS Custom log to Kibana](https://discuss.elastic.co/t/aks-custom-log-to-kibana/277298)

<div class="topic-metadata">

**Author:** [@shankar\_ananth](https://discuss.elastic.co/u/shankar_ananth)\
**Replies:** 0\
**Last updated:** [June 29, 2021, 7:03am UTC](https://discuss.elastic.co/t/aks-custom-log-to-kibana/277298 "2021-06-29T07:03:59Z")

</div>

Hi all, We are routing the application logs to a file in an aks pod in different path. I am not sure where i should map this path in the filebeat.yaml to push these logs to kibana. Any one please help me to fix this.

---

## [How to send our custom created logs to elasticsearch for indexing using beats](https://discuss.elastic.co/t/how-to-send-our-custom-created-logs-to-elasticsearch-for-indexing-using-beats/277290)

<div class="topic-metadata">

**Author:** [@mstrbgn](https://discuss.elastic.co/u/mstrbgn)\
**Replies:** 0\
**Last updated:** [June 29, 2021, 6:10am UTC](https://discuss.elastic.co/t/how-to-send-our-custom-created-logs-to-elasticsearch-for-indexing-using-beats/277290 "2021-06-29T06:10:29Z")

</div>

I need to visualize my organization service log in kibana. But i am unable to find any ways how can i send my logs to elasticsearch for indexing and later to kibana for visualizing. Any Help will be appreciable

---

## [Error writing registrar state to statestore: failed in store/get operation on store 'filebeat'](https://discuss.elastic.co/t/error-writing-registrar-state-to-statestore-failed-in-store-get-operation-on-store-filebeat/277265)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 0\
**Last updated:** [June 28, 2021, 6:34pm UTC](https://discuss.elastic.co/t/error-writing-registrar-state-to-statestore-failed-in-store-get-operation-on-store-filebeat/277265 "2021-06-28T18:34:16Z")

</div>

I am using filebeat 7.12.0 autodiscover to collect events from kubernetes pods. The filebeat log contains an error message as, 2021-06-28T09:56:42.626Z ERROR \[registrar\] registrar/registrar.go:205 Erro…

---

## [Configure filebeat to route logs from providers (with hints enabled) to specific elastic instances](https://discuss.elastic.co/t/configure-filebeat-to-route-logs-from-providers-with-hints-enabled-to-specific-elastic-instances/277267)

<div class="topic-metadata">

**Author:** [@mitesh](https://discuss.elastic.co/u/mitesh)\
**Replies:** 0\
**Last updated:** [June 28, 2021, 6:48pm UTC](https://discuss.elastic.co/t/configure-filebeat-to-route-logs-from-providers-with-hints-enabled-to-specific-elastic-instances/277267 "2021-06-28T18:48:11Z")

</div>

Hi, I am quite new to the ELK stack and would appreciate some guidance on the brief mentioned in the subject. My goal is to have multiple providers (nginx1, nginx2) broadcasting beats events with hints enabled to fileb…

---

## [Override geo location for packetbeat](https://discuss.elastic.co/t/override-geo-location-for-packetbeat/277185)

<div class="topic-metadata">

**Author:** [@termcap](https://discuss.elastic.co/u/termcap)\
**Replies:** 0\
**Last updated:** [June 28, 2021, 8:13am UTC](https://discuss.elastic.co/t/override-geo-location-for-packetbeat/277185 "2021-06-28T08:13:26Z")

</div>

Hi, I have enabled geo enrichment according to this document and its working file. Unfortunately, my private network address is not from the private range(its a public range we use internally) and thus the geo locati…

---

## [Drop\_Fields doesn't work - Filebeat](https://discuss.elastic.co/t/drop-fields-doesnt-work-filebeat/277183)

<div class="topic-metadata">

**Author:** [@Billz1026](https://discuss.elastic.co/u/Billz1026)\
**Replies:** 0\
**Last updated:** [June 28, 2021, 7:58am UTC](https://discuss.elastic.co/t/drop-fields-doesnt-work-filebeat/277183 "2021-06-28T07:58:01Z")

</div>

Hi All, I have configured filebeat to read IIS logs using the IIS module. In the same time, I want to drop unwanted fields to save the space of my ES server. I have enabled the IIS module using below command. .\\filebe…

---

## [Help with Indexing log with custom time instead of timestamp](https://discuss.elastic.co/t/help-with-indexing-log-with-custom-time-instead-of-timestamp/277126)

<div class="topic-metadata">

**Author:** [@Core\_Sec](https://discuss.elastic.co/u/Core_Sec)\
**Replies:** 6\
**Last updated:** [June 27, 2021, 6:35pm UTC](https://discuss.elastic.co/t/help-with-indexing-log-with-custom-time-instead-of-timestamp/277126 "2021-06-27T18:35:27Z")

</div>

Hi everyone I've established ELK with GitHub - deviantony/docker-elk: The Elastic stack (ELK) powered by Docker and Compose. I have log with timestamp included - //{"type":"CustoumLogType","Param1":1,"Param2":1,"Param…

---

## [How to send synology device logs to elk](https://discuss.elastic.co/t/how-to-send-synology-device-logs-to-elk/269555)

<div class="topic-metadata">

**Author:** [@jubin03](https://discuss.elastic.co/u/jubin03)\
**Replies:** 6\
**Last updated:** [June 26, 2021, 5:59am UTC](https://discuss.elastic.co/t/how-to-send-synology-device-logs-to-elk/269555 "2021-06-26T05:59:38Z")

</div>

Do we need to install filbeat on Synology for sending logs to elk

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=146)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=148)
