# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=148

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 149

---

## [Diagnose high CPU usage of beats deployed by Agent](https://discuss.elastic.co/t/diagnose-high-cpu-usage-of-beats-deployed-by-agent/276998)

<div class="topic-metadata">

**Author:** [@netfire](https://discuss.elastic.co/u/netfire)\
**Replies:** 2\
**Last updated:** [June 26, 2021, 2:51am UTC](https://discuss.elastic.co/t/diagnose-high-cpu-usage-of-beats-deployed-by-agent/276998 "2021-06-26T02:51:32Z")

</div>

I'm testing fleet and I have noticed that filebeat and metricbeat use quite a few CPU cycles. I'm using the Windows, System and IIS integrations, and on an 8 vcpu VM, filebeat consistently consumes 20%. Metricbeat consum…

---

## [Will Filebeat ever send my log file content to stdout?](https://discuss.elastic.co/t/will-filebeat-ever-send-my-log-file-content-to-stdout/276988)

<div class="topic-metadata">

**Author:** [@Wade](https://discuss.elastic.co/u/Wade)\
**Replies:** 3\
**Last updated:** [June 25, 2021, 7:39pm UTC](https://discuss.elastic.co/t/will-filebeat-ever-send-my-log-file-content-to-stdout/276988 "2021-06-25T19:39:14Z")

</div>

Is there ever a scenario where filebeat would log the contents of the files it is harvesting to standard out? I am shipping log files to elasticsearch with sensitive information and anything that is written to stdout it …

---

## [Add\_kubernetes\_metadata : handle logs from containerd and docker](https://discuss.elastic.co/t/add-kubernetes-metadata-handle-logs-from-containerd-and-docker/276390)

<div class="topic-metadata">

**Author:** [@orgoz](https://discuss.elastic.co/u/orgoz)\
**Replies:** 0\
**Last updated:** [June 18, 2021, 12:34pm UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-handle-logs-from-containerd-and-docker/276390 "2021-06-18T12:34:56Z")

</div>

Hello, I am using filebeat 7.9.0. I have a k8s cluster with multiple node pools using containerd and docker runtime. I want my logs from these two runtime correctly parsed and with kubernetes metadata. I am using thi…

---

## [Index lifecycle error - 2 index templates matching](https://discuss.elastic.co/t/index-lifecycle-error-2-index-templates-matching/276809)

<div class="topic-metadata">

**Author:** [@ORich](https://discuss.elastic.co/u/ORich)\
**Replies:** 1\
**Last updated:** [June 25, 2021, 9:15am UTC](https://discuss.elastic.co/t/index-lifecycle-error-2-index-templates-matching/276809 "2021-06-25T09:15:58Z")

</div>

Dear experts, here is my filebeat setup: # Set the prefix used in the index lifecycle write alias name. The default alias # name is 'filebeat-%{\[agent.version\]}'. setup.ilm.rollover\_alias: 'filebeat-%{\[agent.version\]}-…

---

## [Filebeat decode\_json\_fields processor keeps giving convert error for GCP module](https://discuss.elastic.co/t/filebeat-decode-json-fields-processor-keeps-giving-convert-error-for-gcp-module/277024)

<div class="topic-metadata">

**Author:** [@stevensim226](https://discuss.elastic.co/u/stevensim226)\
**Replies:** 0\
**Last updated:** [June 25, 2021, 7:55am UTC](https://discuss.elastic.co/t/filebeat-decode-json-fields-processor-keeps-giving-convert-error-for-gcp-module/277024 "2021-06-25T07:55:06Z")

</div>

I keep getting an error that says GoError: failed in processor.convert: conversion of field \[json.protoPayload\] to type \[\[unset\]\] with target field \[json\] failed: field \[json.protoPayload\] is missing: key not found when …

---

## [Duplication while logs are appended in Filebeat](https://discuss.elastic.co/t/duplication-while-logs-are-appended-in-filebeat/277016)

<div class="topic-metadata">

**Author:** [@connectgeeks](https://discuss.elastic.co/u/connectgeeks)\
**Replies:** 0\
**Last updated:** [June 25, 2021, 6:32am UTC](https://discuss.elastic.co/t/duplication-while-logs-are-appended-in-filebeat/277016 "2021-06-25T06:32:05Z")

</div>

I'm using Filebeat-\> Logstash-\> ES setup. 7.x While paring the apache and json logs using, I notice every time the file is appended with new logs I see old logs also getting re-created in elasticsearch. How can I avoid …

---

## [Custom hostnames for agent deployments](https://discuss.elastic.co/t/custom-hostnames-for-agent-deployments/276997)

<div class="topic-metadata">

**Author:** [@netfire](https://discuss.elastic.co/u/netfire)\
**Replies:** 0\
**Last updated:** [June 25, 2021, 2:49am UTC](https://discuss.elastic.co/t/custom-hostnames-for-agent-deployments/276997 "2021-06-25T02:49:17Z")

</div>

I'm testing out fleet. I would like the agents and associated beats to utilize a hostname I provide (or using a template of some sort). The issue I have is that windows hosts are not using the FQDN (in my case it would b…

---

## [\[Heartbeat\] clarify “context deadline exceeds” further](https://discuss.elastic.co/t/heartbeat-clarify-context-deadline-exceeds-further/274305)

<div class="topic-metadata">

**Author:** [@lowry](https://discuss.elastic.co/u/lowry)\
**Replies:** 3\
**Last updated:** [June 25, 2021, 2:36am UTC](https://discuss.elastic.co/t/heartbeat-clarify-context-deadline-exceeds-further/274305 "2021-06-25T02:36:18Z")

</div>

It is learned that Heartbeat employs Golang context to manage the session to do the http check, Getting “context deadline exceeds” error message while accessing a target timeout. However, there’re 2 different cases woul…

---

## [Drop\_event syntax trouble with multiple processors (7.7.1)](https://discuss.elastic.co/t/drop-event-syntax-trouble-with-multiple-processors-7-7-1/276834)

<div class="topic-metadata">

**Author:** [@Mike\_McGuire](https://discuss.elastic.co/u/Mike_McGuire)\
**Replies:** 4\
**Last updated:** [June 25, 2021, 1:30am UTC](https://discuss.elastic.co/t/drop-event-syntax-trouble-with-multiple-processors-7-7-1/276834 "2021-06-25T01:30:38Z")

</div>

This will get past the configuration check, but appears that it filters all events out. I think the OR is what is tripping me up. The other posts I've studied are close, but I can't recreate a working solution. The lo…

---

## [Dynamically determine OS name](https://discuss.elastic.co/t/dynamically-determine-os-name/276956)

<div class="topic-metadata">

**Author:** [@jleon](https://discuss.elastic.co/u/jleon)\
**Replies:** 1\
**Last updated:** [June 25, 2021, 12:14am UTC](https://discuss.elastic.co/t/dynamically-determine-os-name/276956 "2021-06-25T00:14:09Z")

</div>

Hi, In the agent yml file, is there a way to dynamically determine the OS name (windows, Linux, etc) to be included in the log msgs? I'm using filebeats version 7.x. I see this doc for version 6.x using Host fields, b…

---

## [How to index newly parsed fields to be searchable - My Dynamic Template](https://discuss.elastic.co/t/how-to-index-newly-parsed-fields-to-be-searchable-my-dynamic-template/276962)

<div class="topic-metadata">

**Author:** [@rklemer](https://discuss.elastic.co/u/rklemer)\
**Replies:** 0\
**Last updated:** [June 24, 2021, 4:47pm UTC](https://discuss.elastic.co/t/how-to-index-newly-parsed-fields-to-be-searchable-my-dynamic-template/276962 "2021-06-24T16:47:45Z")

</div>

Hello, I'm trying to index custom fields that are parsed from s3 json log, it's not seeming to work, I have these processors: filebeat.inputs: - type: aws-s3 queue\_url: https://sqs.XXX\>XXXX.com/XXXX/XXXXX access\_key…

---

## [Winlogbeat - Not enough storage is available to complete this operation](https://discuss.elastic.co/t/winlogbeat-not-enough-storage-is-available-to-complete-this-operation/275060)

<div class="topic-metadata">

**Author:** [@ELK7](https://discuss.elastic.co/u/ELK7)\
**Replies:** 9\
**Last updated:** [June 24, 2021, 1:01pm UTC](https://discuss.elastic.co/t/winlogbeat-not-enough-storage-is-available-to-complete-this-operation/275060 "2021-06-24T13:01:06Z")

</div>

Hi, I'm running Winlogbeat to send out windows enent-logs to elastic. version 7.12.1 windows 2012R2, 138GB memory, and 300GB free space on C. for some reason , i see we're missing event logs from the security sectio…

---

## [ELK Heartbeat x509: certificate signed by unknown authority for Sectigo CA](https://discuss.elastic.co/t/elk-heartbeat-x509-certificate-signed-by-unknown-authority-for-sectigo-ca/276871)

<div class="topic-metadata">

**Author:** [@ezramiller](https://discuss.elastic.co/u/ezramiller)\
**Replies:** 5\
**Last updated:** [June 24, 2021, 12:36pm UTC](https://discuss.elastic.co/t/elk-heartbeat-x509-certificate-signed-by-unknown-authority-for-sectigo-ca/276871 "2021-06-24T12:36:46Z")

</div>

Hello everyone. I am monitoring some websites and a lot of these websites using Sectigo SSL Certificates. Heartbeat showing these websites with Sectigo certificates as x509: certificate signed by unknown authority. Why i…

---

## [Filebeat configuration without kibana setup is not working](https://discuss.elastic.co/t/filebeat-configuration-without-kibana-setup-is-not-working/276864)

<div class="topic-metadata">

**Author:** [@Mahesh\_Gadagi](https://discuss.elastic.co/u/Mahesh_Gadagi)\
**Replies:** 2\
**Last updated:** [June 24, 2021, 12:15pm UTC](https://discuss.elastic.co/t/filebeat-configuration-without-kibana-setup-is-not-working/276864 "2021-06-24T12:15:36Z")

</div>

Hello, Currently, I have filebeat version 7.9.1 and trying to use it with Elasticsearch 7.9.1, I don't want to load any dashboards to Kibana as I just want to push the data to specific index of Elastic search, I have us…

---

## [fileBeat Accuracy of log collection time](https://discuss.elastic.co/t/filebeat-accuracy-of-log-collection-time/276779)

<div class="topic-metadata">

**Author:** [@Link](https://discuss.elastic.co/u/Link)\
**Replies:** 3\
**Last updated:** [June 24, 2021, 6:40am UTC](https://discuss.elastic.co/t/filebeat-accuracy-of-log-collection-time/276779 "2021-06-24T06:40:33Z")

</div>

HI garylog Collect logs form Filebeat。 Now there is a problem There are multiple logs generated at the same time， Is there a way to make the log time more accurate? 2021-06-14 08:36:40.652Z ----\>2021-06-14 …

---

## [Containerd Metrics](https://discuss.elastic.co/t/containerd-metrics/275548)

<div class="topic-metadata">

**Author:** [@jonas27](https://discuss.elastic.co/u/jonas27)\
**Replies:** 1\
**Last updated:** [June 24, 2021, 5:23am UTC](https://discuss.elastic.co/t/containerd-metrics/275548 "2021-06-24T05:23:47Z")

</div>

Hi, We recently upgraded our container runtime from docker to containerd. Is there a (planned) module to support querying the containerd socket for container metrics? Something like: containerd.yml: |- - module:…

---

## [FileBeat 7.9.1 - Error creating runner from config: Can only start an input when all related states are finished](https://discuss.elastic.co/t/filebeat-7-9-1-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/276867)

<div class="topic-metadata">

**Author:** [@Parveen\_Sharma](https://discuss.elastic.co/u/Parveen_Sharma)\
**Replies:** 0\
**Last updated:** [June 24, 2021, 4:33am UTC](https://discuss.elastic.co/t/filebeat-7-9-1-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/276867 "2021-06-24T04:33:30Z")

</div>

Hi I am using 7.9.1 Fileabeat version and i am observing following error in the log file. 2021-06-24T03:27:53.075Z ERROR \[autodiscover\] cfgfile/list.go:95 Error creating runner from config: Can only start…

---

## [Filebeats 7.12 Cisco ASA module Needs RFC 5424 timestamp](https://discuss.elastic.co/t/filebeats-7-12-cisco-asa-module-needs-rfc-5424-timestamp/276434)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 1\
**Last updated:** [June 24, 2021, 3:09am UTC](https://discuss.elastic.co/t/filebeats-7-12-cisco-asa-module-needs-rfc-5424-timestamp/276434 "2021-06-24T03:09:30Z")

</div>

I hope this helps someone ... I've been having a \*mare getting the Cisco ASA module to recognise logs input to UDP/9001. I could see the records hit my machine via TCPDUMP, but nothing showed up when I ran "filebeat -e"…

---

## [Help with elesticsearch and metricbeat](https://discuss.elastic.co/t/help-with-elesticsearch-and-metricbeat/276192)

<div class="topic-metadata">

**Author:** [@Gustavo\_Lira](https://discuss.elastic.co/u/Gustavo_Lira)\
**Replies:** 2\
**Last updated:** [June 23, 2021, 3:30pm UTC](https://discuss.elastic.co/t/help-with-elesticsearch-and-metricbeat/276192 "2021-06-23T15:30:50Z")

</div>

I am configuring metricbeat in a node with windows 10 to connect with elasticsearch and kibana, both are configured in a single computer but it does not throw me data in kibana, I attach configuration of metricbeat.yml, …

---

## [Metricbeat elasticsearch module and SSL configuration](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-and-ssl-configuration/274532)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 1\
**Last updated:** [June 23, 2021, 10:12am UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-and-ssl-configuration/274532 "2021-06-23T10:12:27Z")

</div>

tl;dr: I'm having trouble getting metricbeat elasticsearch module to work properly after enabling ssl. Background I followed the tutorials to get ssl/tls set up on my test cluster. There is one node that is the elastic…

---

## [Elastic Agent vs Fluentd/Fluentbit](https://discuss.elastic.co/t/elastic-agent-vs-fluentd-fluentbit/276762)

<div class="topic-metadata">

**Author:** [@CyberWarriorBob](https://discuss.elastic.co/u/CyberWarriorBob)\
**Replies:** 0\
**Last updated:** [June 23, 2021, 9:31am UTC](https://discuss.elastic.co/t/elastic-agent-vs-fluentd-fluentbit/276762 "2021-06-23T09:31:23Z")

</div>

I am unsure if this is the right platform to ask this, but here it goes - I am trying to find out what are the differences between Elastic Agent and Fluentd/Fluentbit, I am trying to find out also if it worth the change…

---

## [AWS ELB ingest pipeline bug](https://discuss.elastic.co/t/aws-elb-ingest-pipeline-bug/276356)

<div class="topic-metadata">

**Author:** [@stephank](https://discuss.elastic.co/u/stephank)\
**Replies:** 7\
**Last updated:** [June 23, 2021, 9:53am UTC](https://discuss.elastic.co/t/aws-elb-ingest-pipeline-bug/276356 "2021-06-23T09:53:23Z")

</div>

I believe there is a bug in the Filebeat AWS ELB ingest pipeline. In Kibana Logs, they show up as: \[aws\]\[access\] 1.2.3.4 "GET HTTP/2.0" 200 152966 Clearly missing the request path. I was able to fix this with the fol…

---

## [Unable to create windows distribution for custom filebeat module that I created](https://discuss.elastic.co/t/unable-to-create-windows-distribution-for-custom-filebeat-module-that-i-created/276745)

<div class="topic-metadata">

**Author:** [@suryatheja.katkam](https://discuss.elastic.co/u/suryatheja.katkam)\
**Replies:** 0\
**Last updated:** [June 23, 2021, 8:28am UTC](https://discuss.elastic.co/t/unable-to-create-windows-distribution-for-custom-filebeat-module-that-i-created/276745 "2021-06-23T08:28:29Z")

</div>

Hi Team, I have created a custom filebeat on linux server using the below documentation available on elastic. I am able to send the log data using the custom module on linux, and visualize the same on Kibana. But wh…

---

## [Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/276176)

<div class="topic-metadata">

**Author:** [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)\
**Replies:** 23\
**Last updated:** [June 23, 2021, 7:04am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/276176 "2021-06-23T07:04:51Z")

</div>

Hi, I have installed native Filebeat and configured filebeat.yml accordingley but when I start the service it gives the below error: Jun 16 10:16:03 picktrack-1b systemd\[1\]: filebeat.service: Service hold-off time ove…

---

## [Winlogbeat Services v. Command Line Implementation](https://discuss.elastic.co/t/winlogbeat-services-v-command-line-implementation/276630)

<div class="topic-metadata">

**Author:** [@chris\_ts24](https://discuss.elastic.co/u/chris_ts24)\
**Replies:** 2\
**Last updated:** [June 22, 2021, 1:44pm UTC](https://discuss.elastic.co/t/winlogbeat-services-v-command-line-implementation/276630 "2021-06-22T13:44:26Z")

</div>

Hi all, I'm sending windows logs via winlogbeat (v.7.13.2) to a logstash instance (v.7.13.0), which processes the logs and sends them to an ES index "winlogs" (v.7.13.0). I've set up the pipeline (no logstash filter yet…

---

## [How to deploy an elastic-agent in fleet against an elasticsearch with a self-signed certificate?](https://discuss.elastic.co/t/how-to-deploy-an-elastic-agent-in-fleet-against-an-elasticsearch-with-a-self-signed-certificate/276575)

<div class="topic-metadata">

**Author:** [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Replies:** 0\
**Last updated:** [June 21, 2021, 7:31pm UTC](https://discuss.elastic.co/t/how-to-deploy-an-elastic-agent-in-fleet-against-an-elasticsearch-with-a-self-signed-certificate/276575 "2021-06-21T19:31:58Z")

</div>

Hi, I deployed a fleet server using elastic-agent, which runs fine. For the deployment of an elastic-agent I use --insecure, because the fleet server, Kibana, and elasticsearch use a self-signed certificate. I get a c…

---

## [PacketBeats: Record the request and response of transactions that cannot be identified by a valid protocol under tcp](https://discuss.elastic.co/t/packetbeats-record-the-request-and-response-of-transactions-that-cannot-be-identified-by-a-valid-protocol-under-tcp/276610)

<div class="topic-metadata">

**Author:** [@manning23](https://discuss.elastic.co/u/manning23)\
**Replies:** 0\
**Last updated:** [June 22, 2021, 6:36am UTC](https://discuss.elastic.co/t/packetbeats-record-the-request-and-response-of-transactions-that-cannot-be-identified-by-a-valid-protocol-under-tcp/276610 "2021-06-22T06:36:23Z")

</div>

I hope to record the request and response of transactions that cannot be identified by a valid protocol under tcp. :slight\_smile: like this type: unknow-tcp enable: true send\_request: true send\_response: true

---

## [Connecting Filebeat-Azure by proxy](https://discuss.elastic.co/t/connecting-filebeat-azure-by-proxy/276514)

<div class="topic-metadata">

**Author:** [@daniele.saccon](https://discuss.elastic.co/u/daniele.saccon)\
**Replies:** 1\
**Last updated:** [June 22, 2021, 3:48am UTC](https://discuss.elastic.co/t/connecting-filebeat-azure-by-proxy/276514 "2021-06-22T03:48:49Z")

</div>

Hi everybody, we are trying to use Filebeat's Azure module to extract data from Azure but we are unable to connect to proxy. Filebeat (version 7.9) is installed on Windows Server 2008 in the internal network and to con…

---

## [Using Filebeat to fetch CrowdStrike Falcon Data Replicator (FDR) logs with S3 SQS](https://discuss.elastic.co/t/using-filebeat-to-fetch-crowdstrike-falcon-data-replicator-fdr-logs-with-s3-sqs/276395)

<div class="topic-metadata">

**Author:** [@meatwad](https://discuss.elastic.co/u/meatwad)\
**Replies:** 2\
**Last updated:** [June 21, 2021, 8:37pm UTC](https://discuss.elastic.co/t/using-filebeat-to-fetch-crowdstrike-falcon-data-replicator-fdr-logs-with-s3-sqs/276395 "2021-06-21T20:37:31Z")

</div>

I'm interested in using Filebeat to fetch CrowdStrike Falcon Data Replicator (FDR) logs with the aws-s3 plugin, and use its parallel processing functionality due to the sheer volume of data FDR produces. But I'm running…

---

## [Heartbeat: HTTP check with dynamic url prameter](https://discuss.elastic.co/t/heartbeat-http-check-with-dynamic-url-prameter/275813)

<div class="topic-metadata">

**Author:** [@ibexit](https://discuss.elastic.co/u/ibexit)\
**Replies:** 1\
**Last updated:** [June 21, 2021, 4:43pm UTC](https://discuss.elastic.co/t/heartbeat-http-check-with-dynamic-url-prameter/275813 "2021-06-21T16:43:44Z")

</div>

Hi, we´re trying to have some kind of dynamic parameter in the monitored URL in order to prevent the existing cache infrastructure deliver the response. We need to check the underlying infrastructure and not the cache. …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=147)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=149)
