# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=149

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 150

---

## [How to extract JSON from lambda-generated cloudwatch logs with Functionbeat?](https://discuss.elastic.co/t/how-to-extract-json-from-lambda-generated-cloudwatch-logs-with-functionbeat/276564)

<div class="topic-metadata">

**Author:** [@achristensen](https://discuss.elastic.co/u/achristensen)\
**Replies:** 0\
**Last updated:** [June 21, 2021, 4:17pm UTC](https://discuss.elastic.co/t/how-to-extract-json-from-lambda-generated-cloudwatch-logs-with-functionbeat/276564 "2021-06-21T16:17:56Z")

</div>

I have a fresh Elasticsearch/Kibana instance that I'm trying to feed data to from Cloudwatch. I was able to get Functionbeat set up easily and data flows in as expected, but all of the logs are simply being put into the …

---

## [Filebeat install error on windows server 2003 32 bit](https://discuss.elastic.co/t/filebeat-install-error-on-windows-server-2003-32-bit/276556)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 0\
**Last updated:** [June 21, 2021, 3:04pm UTC](https://discuss.elastic.co/t/filebeat-install-error-on-windows-server-2003-32-bit/276556 "2021-06-21T15:04:57Z")

</div>

Hello team, I am trying to install filebeat 7.9.3 32 bit on windows server 2003 which is 32 bit OS. I tried with taking new file again I thought it is corrupted but no luck. But I am getting following error: Program '…

---

## [Filebeat fortinet module](https://discuss.elastic.co/t/filebeat-fortinet-module/276529)

<div class="topic-metadata">

**Author:** [@Dvir\_Solomon](https://discuss.elastic.co/u/Dvir_Solomon)\
**Replies:** 0\
**Last updated:** [June 21, 2021, 11:26am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module/276529 "2021-06-21T11:26:32Z")

</div>

Hi, totally Newby, I have have setup elastic + kibana + filebeat all on windows server 2019 manually (no service yet). i am using filebeat(syslog) + Fortinet module. Fortinet module was working, after I restarted fil…

---

## [How to use filebeat for pushing misp feeds](https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293)

<div class="topic-metadata">

**Author:** [@Drupad\_Soni](https://discuss.elastic.co/u/Drupad_Soni)\
**Replies:** 5\
**Last updated:** [June 21, 2021, 11:02am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293 "2021-06-21T11:02:14Z")

</div>

Hi Community, I have been working on MISP and Elasticsearch. I have tried with MISP module and Threatintel module. No feeds are getting pushed in ELK. Please guide/

---

## [Monthly indices for rollover using data stream](https://discuss.elastic.co/t/monthly-indices-for-rollover-using-data-stream/276527)

<div class="topic-metadata">

**Author:** [@Bryce\_Fernandes](https://discuss.elastic.co/u/Bryce_Fernandes)\
**Replies:** 0\
**Last updated:** [June 21, 2021, 10:59am UTC](https://discuss.elastic.co/t/monthly-indices-for-rollover-using-data-stream/276527 "2021-06-21T10:59:33Z")

</div>

Hi, Using the blog below I was able to get indices as mentioned in last step. https://www.elastic.co/blog/how-to-manage-elasticsearch-data-multiple-indices-filebeat-ilm-data-streams I am able to get indices as well as…

---

## [408 HTTP Error when running filebeat setup](https://discuss.elastic.co/t/408-http-error-when-running-filebeat-setup/275817)

<div class="topic-metadata">

**Author:** [@pjvilloud](https://discuss.elastic.co/u/pjvilloud)\
**Replies:** 5\
**Last updated:** [June 21, 2021, 10:01am UTC](https://discuss.elastic.co/t/408-http-error-when-running-filebeat-setup/275817 "2021-06-21T10:01:19Z")

</div>

Hello ! I'm trying to run filebeat setup -e on my local machine and it fails with the following error error loading index pattern: returned 408 to import file: \<nil\>. I'm using the latest version of filebeat (7.13.1) an…

---

## [Filebeat Multiline not working](https://discuss.elastic.co/t/filebeat-multiline-not-working/276506)

<div class="topic-metadata">

**Author:** [@SLIM\_SLIM](https://discuss.elastic.co/u/SLIM_SLIM)\
**Replies:** 0\
**Last updated:** [June 21, 2021, 8:43am UTC](https://discuss.elastic.co/t/filebeat-multiline-not-working/276506 "2021-06-21T08:43:01Z")

</div>

Hi, i want to regroup lines in log file (5 lines max), i want to regroup lines until (default task-XX) This is my filebeat config : fields\_under\_root: true multiline.type: pattern multiline.pattern: '\[0-9\]{4}-\[0-9\]{…

---

## [Winlogbeat Missing Security Events after logfile rotation](https://discuss.elastic.co/t/winlogbeat-missing-security-events-after-logfile-rotation/272179)

<div class="topic-metadata">

**Author:** [@Ed\_28](https://discuss.elastic.co/u/Ed_28)\
**Replies:** 4\
**Last updated:** [June 21, 2021, 8:06am UTC](https://discuss.elastic.co/t/winlogbeat-missing-security-events-after-logfile-rotation/272179 "2021-06-21T08:06:59Z")

</div>

Version: 7.12.0 OS: Windows Server 2016 10 second time frame: 3221 reported 3282 Security event log During that timeframe the security log reaches Max log size and new logfile is created. Event log automatic backup …

---

## [Windows event message field](https://discuss.elastic.co/t/windows-event-message-field/276496)

<div class="topic-metadata">

**Author:** [@michaal1511](https://discuss.elastic.co/u/michaal1511)\
**Replies:** 0\
**Last updated:** [June 21, 2021, 7:39am UTC](https://discuss.elastic.co/t/windows-event-message-field/276496 "2021-06-21T07:39:15Z")

</div>

Hi, how can I parse message string to seperate lines? Example: Line1 = An account was logged off. Subject: Line2 = Security ID: XXXX Line3 = Account Name: XXXX Line4 = Account Domain: XXX Line5 = Logon ID:…

---

## [Filebeat Dissect Processor](https://discuss.elastic.co/t/filebeat-dissect-processor/276350)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 2\
**Last updated:** [June 21, 2021, 5:30am UTC](https://discuss.elastic.co/t/filebeat-dissect-processor/276350 "2021-06-21T05:30:24Z")

</div>

Hi All, I was testing the dissect processor in filebeat with this "%{ip\_address} - %{user} \[%{by\_date|date}\] \\"%{request}\\" %{response\_code} %{response\_size} %{msg\_tail}" and I wanted to test directly to convert the f…

---

## [Cisco AMP Module Filebeat 7.13.1 processing error httpjson-cursor v2](https://discuss.elastic.co/t/cisco-amp-module-filebeat-7-13-1-processing-error-httpjson-cursor-v2/275299)

<div class="topic-metadata">

**Author:** [@mbst83r](https://discuss.elastic.co/u/mbst83r)\
**Replies:** 3\
**Last updated:** [June 21, 2021, 6:08am UTC](https://discuss.elastic.co/t/cisco-amp-module-filebeat-7-13-1-processing-error-httpjson-cursor-v2/275299 "2021-06-21T06:08:20Z")

</div>

Hello, the Cisco AMP module for filebeat logs an error on each execution. ERROR \[input.httpjson-cursor\] v2/request.go:186 error processing response: failed to execute http client.Do: Get "": Get "": unsupported…

---

## [Filebeat JSON file from eventhub or storage account?](https://discuss.elastic.co/t/filebeat-json-file-from-eventhub-or-storage-account/276375)

<div class="topic-metadata">

**Author:** [@Doodle](https://discuss.elastic.co/u/Doodle)\
**Replies:** 1\
**Last updated:** [June 21, 2021, 1:49am UTC](https://discuss.elastic.co/t/filebeat-json-file-from-eventhub-or-storage-account/276375 "2021-06-21T01:49:05Z")

</div>

0 Votes"0 CarolinaZamisnicu-1887 asked · 3 days ago Actions Filebeat JSON file from eventhub or storage account? Hi, How can I sent the logs from database services like Maria DB/MySQL in Azure in a valid JSON directl…

---

## [Debug logs explanation](https://discuss.elastic.co/t/debug-logs-explanation/276465)

<div class="topic-metadata">

**Author:** [@grazia0912](https://discuss.elastic.co/u/grazia0912)\
**Replies:** 1\
**Last updated:** [June 21, 2021, 1:38am UTC](https://discuss.elastic.co/t/debug-logs-explanation/276465 "2021-06-21T01:38:40Z")

</div>

Hi, Can someone help me understand what does the below logs mean? I enabled the debug log in my filebeat to check if logstash is acknowledging the messages in a timely manner and if filebeat proceeds only when logstash a…

---

## [Lag in Filebeat to Kibana](https://discuss.elastic.co/t/lag-in-filebeat-to-kibana/275682)

<div class="topic-metadata">

**Author:** [@Ayush\_Agrahari](https://discuss.elastic.co/u/Ayush_Agrahari)\
**Replies:** 5\
**Last updated:** [June 19, 2021, 12:24pm UTC](https://discuss.elastic.co/t/lag-in-filebeat-to-kibana/275682 "2021-06-19T12:24:36Z")

</div>

Hi , I am using Filebeat in Kubernetes env. Data flow is like below Filebeat -\> Logstash -\> ElasticSearch -\> Kibana I am using 7.10.0 version of filebeat I am finding lag in FIlebeat to Kibana. ES & Logstash & Filebe…

---

## [Winlogbeat drop event with process path](https://discuss.elastic.co/t/winlogbeat-drop-event-with-process-path/276430)

<div class="topic-metadata">

**Author:** [@remrem](https://discuss.elastic.co/u/remrem)\
**Replies:** 0\
**Last updated:** [June 19, 2021, 7:57am UTC](https://discuss.elastic.co/t/winlogbeat-drop-event-with-process-path/276430 "2021-06-19T07:57:45Z")

</div>

I want to drop a log for a specific event.code based on process path but it's not working. I have two drop event processor as described below: processors: - drop\_event: when: and: - or: - equals.…

---

## [Metricbeat - Socket summary TCP established filtered by port](https://discuss.elastic.co/t/metricbeat-socket-summary-tcp-established-filtered-by-port/275902)

<div class="topic-metadata">

**Author:** [@IT\_Sniper](https://discuss.elastic.co/u/IT_Sniper)\
**Replies:** 8\
**Last updated:** [June 18, 2021, 4:41pm UTC](https://discuss.elastic.co/t/metricbeat-socket-summary-tcp-established-filtered-by-port/275902 "2021-06-18T16:41:30Z")

</div>

Hello everyone, I have a ELK stack server which receives metrics from several servers, but one of them has a specific application that listens on port TCP/8443. Im aware of the system module of Metricbeats, which suppor…

---

## [Http\_endpoint only accepts JSON, even with a different content\_type](https://discuss.elastic.co/t/http-endpoint-only-accepts-json-even-with-a-different-content-type/276329)

<div class="topic-metadata">

**Author:** [@jhbigler](https://discuss.elastic.co/u/jhbigler)\
**Replies:** 2\
**Last updated:** [June 18, 2021, 3:14pm UTC](https://discuss.elastic.co/t/http-endpoint-only-accepts-json-even-with-a-different-content-type/276329 "2021-06-18T15:14:02Z")

</div>

We would like to use filebeat to accept data from Apache Nifi in the form of a POST request, run it through some processors and send it to Elasticsearch. The documentation on the http\_endpoint seems to suggest that the h…

---

## [Issues with Fleet Server (Elastic Agent Setup) in local Elasticsearch deployment with self signed certificates](https://discuss.elastic.co/t/issues-with-fleet-server-elastic-agent-setup-in-local-elasticsearch-deployment-with-self-signed-certificates/276151)

<div class="topic-metadata">

**Author:** [@SMT\_Mas](https://discuss.elastic.co/u/SMT_Mas)\
**Replies:** 1\
**Last updated:** [June 18, 2021, 12:52pm UTC](https://discuss.elastic.co/t/issues-with-fleet-server-elastic-agent-setup-in-local-elasticsearch-deployment-with-self-signed-certificates/276151 "2021-06-18T12:52:37Z")

</div>

Hello, I'm trying to install Elastic Agent with a local ELK Environment and have no luck because of Fleet Server issues. Server Info: ELK on version 7.13.1 with self-signed certificates running in Docker containers o…

---

## [Metricbeat elasticsearch-xpack not reliably sending data to monitoring cluster](https://discuss.elastic.co/t/metricbeat-elasticsearch-xpack-not-reliably-sending-data-to-monitoring-cluster/275842)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 14\
**Last updated:** [June 18, 2021, 10:51am UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-xpack-not-reliably-sending-data-to-monitoring-cluster/275842 "2021-06-18T10:51:47Z")

</div>

I've installed metricbeat to ship monitoring metrics from my elastic cluster to a separate cluster, but from what I can see, despite the period of collection being 10s, it's hardly ever sending any actual data: Does …

---

## [Office 365 Module , Filebeat, Logstash, and Elastic Search](https://discuss.elastic.co/t/office-365-module-filebeat-logstash-and-elastic-search/276231)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 3\
**Last updated:** [June 18, 2021, 7:38am UTC](https://discuss.elastic.co/t/office-365-module-filebeat-logstash-and-elastic-search/276231 "2021-06-18T07:38:31Z")

</div>

Im current using the Office 365 module but Im having several issues. First, I use Logstash for processsing (mostly because I put data in daily indexes). All I do in Logstash is take the data and pass it to Elasticsearch…

---

## [Filebeat on windows 10 client not work](https://discuss.elastic.co/t/filebeat-on-windows-10-client-not-work/276332)

<div class="topic-metadata">

**Author:** [@dia](https://discuss.elastic.co/u/dia)\
**Replies:** 0\
**Last updated:** [June 18, 2021, 4:32am UTC](https://discuss.elastic.co/t/filebeat-on-windows-10-client-not-work/276332 "2021-06-18T04:32:32Z")

</div>

filebeat service is running, but I see nothing from it on elasticsearch filebeat index below is from Linux client and it is working fine.. curl -XGET "https://d4850cf616524f54b7ec7628ed283e2a.deyaa.lab:9243/\_cat/indice…

---

## [Connection logs in Azure from Azure Filebeat Module](https://discuss.elastic.co/t/connection-logs-in-azure-from-azure-filebeat-module/276306)

<div class="topic-metadata">

**Author:** [@Doodle](https://discuss.elastic.co/u/Doodle)\
**Replies:** 0\
**Last updated:** [June 17, 2021, 7:31pm UTC](https://discuss.elastic.co/t/connection-logs-in-azure-from-azure-filebeat-module/276306 "2021-06-17T19:31:43Z")

</div>

Hello, I would want make a dashboard where I want to see all my connection logs from my Azure Filebeat module to Elastic. Sort of a granularity for my SaaS. Because right now I can only see the activity logs as a bulk, …

---

## [Payload content length greater than maximum allowed: 1048576](https://discuss.elastic.co/t/payload-content-length-greater-than-maximum-allowed-1048576/276303)

<div class="topic-metadata">

**Author:** [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)\
**Replies:** 1\
**Last updated:** [June 18, 2021, 2:46am UTC](https://discuss.elastic.co/t/payload-content-length-greater-than-maximum-allowed-1048576/276303 "2021-06-18T02:46:52Z")

</div>

Hi, I am working on log data(present on client machine) to monitor on Kibana server(present on differnt machine). I started with setup and installation of Filebeat on the client machine and enabled logstash elasticserac…

---

## [Filebeat conditional hint default config](https://discuss.elastic.co/t/filebeat-conditional-hint-default-config/275668)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 1\
**Last updated:** [June 17, 2021, 8:29pm UTC](https://discuss.elastic.co/t/filebeat-conditional-hint-default-config/275668 "2021-06-17T20:29:16Z")

</div>

Hi, I have following use case: I am using hint based auto discover feature and I want to provide more than one default config based on for example kubernetes.namespace.name. Semantically: "If namespace = X apply defau…

---

## [Azure Filebeat Module - 412 error](https://discuss.elastic.co/t/azure-filebeat-module-412-error/276305)

<div class="topic-metadata">

**Author:** [@Doodle](https://discuss.elastic.co/u/Doodle)\
**Replies:** 0\
**Last updated:** [June 17, 2021, 7:28pm UTC](https://discuss.elastic.co/t/azure-filebeat-module-412-error/276305 "2021-06-17T19:28:03Z")

</div>

Hi, I recently used the filebeat module from Azure and it seems that I receive the logs extremely hard. They are delayed and when they finally come, they come in a bulk. Do you know why this is happening? As an analyst …

---

## [Filebeat with event-hub-kafka output, pulish fails: client has run out of available brokers to talk to](https://discuss.elastic.co/t/filebeat-with-event-hub-kafka-output-pulish-fails-client-has-run-out-of-available-brokers-to-talk-to/276263)

<div class="topic-metadata">

**Author:** [@Klaus\_zhong](https://discuss.elastic.co/u/Klaus_zhong)\
**Replies:** 0\
**Last updated:** [June 17, 2021, 11:54am UTC](https://discuss.elastic.co/t/filebeat-with-event-hub-kafka-output-pulish-fails-client-has-run-out-of-available-brokers-to-talk-to/276263 "2021-06-17T11:54:34Z")

</div>

Description I am using Filebeat to stream my log file to azure event hub and with the configuration as kafka output, the connection to host ip can be established (read from the log below), but when it try to publish topi…

---

## [Filebeat](https://discuss.elastic.co/t/filebeat/276224)

<div class="topic-metadata">

**Author:** [@SLIM\_SLIM](https://discuss.elastic.co/u/SLIM_SLIM)\
**Replies:** 0\
**Last updated:** [June 17, 2021, 7:26am UTC](https://discuss.elastic.co/t/filebeat/276224 "2021-06-17T07:26:37Z")

</div>

Hi, i want to regroup lines in log file (5 lines max), i want to regroup lines until (default task-XX) This is my filebeat config : fields\_under\_root: true multiline.type: pattern multiline.pattern: '\[0-9\]{4}-\[0-…

---

## [Jolokia module - tomcat](https://discuss.elastic.co/t/jolokia-module-tomcat/276220)

<div class="topic-metadata">

**Author:** [@venkatesh\_prasanth](https://discuss.elastic.co/u/venkatesh_prasanth)\
**Replies:** 0\
**Last updated:** [June 17, 2021, 5:39am UTC](https://discuss.elastic.co/t/jolokia-module-tomcat/276220 "2021-06-17T05:39:37Z")

</div>

Hi, I have multiple tomcat running on same server in different ports. localhost:80 localhost:8081 now how i can use same metricbeat jolokia module to monitor the both. and i metricbeat tomcat dashboard i would like t…

---

## [Can I use beat input in filebeat.yml and modules with different tag?](https://discuss.elastic.co/t/can-i-use-beat-input-in-filebeat-yml-and-modules-with-different-tag/276114)

<div class="topic-metadata">

**Author:** [@venkatesh\_prasanth](https://discuss.elastic.co/u/venkatesh_prasanth)\
**Replies:** 2\
**Last updated:** [June 17, 2021, 4:10am UTC](https://discuss.elastic.co/t/can-i-use-beat-input-in-filebeat-yml-and-modules-with-different-tag/276114 "2021-06-17T04:10:22Z")

</div>

Hi, I am using filebeat. i use apache module to collect log from apache. but want to collect the log from tomcat and index it in another index. can i use filebeat input in filebeat.yml and module in same time? but i wa…

---

## [Have to create multiple rollover\_alias for multiple inputs with ILM](https://discuss.elastic.co/t/have-to-create-multiple-rollover-alias-for-multiple-inputs-with-ilm/276212)

<div class="topic-metadata">

**Author:** [@ELK\_sanjay](https://discuss.elastic.co/u/ELK_sanjay)\
**Replies:** 1\
**Last updated:** [June 17, 2021, 3:33am UTC](https://discuss.elastic.co/t/have-to-create-multiple-rollover-alias-for-multiple-inputs-with-ilm/276212 "2021-06-17T03:33:18Z")

</div>

I have an issue creating multiple rollover\_alias for multiple inputs with ILM. But not getting an exact answer. Thanks in Advance..!!

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=148)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=150)
