# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=150

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 151

---

## [Filebeat - Unable to change indice name & disable ILM](https://discuss.elastic.co/t/filebeat-unable-to-change-indice-name-disable-ilm/276107)

<div class="topic-metadata">

**Author:** [@shlomia](https://discuss.elastic.co/u/shlomia)\
**Replies:** 2\
**Last updated:** [June 17, 2021, 2:09am UTC](https://discuss.elastic.co/t/filebeat-unable-to-change-indice-name-disable-ilm/276107 "2021-06-17T02:09:09Z")

</div>

Hi, I recently started to use ELK with Filebeat version 7.13.0. I'm trying to change the default indice name that Filebeat is creating: "filebeat-%{\[agent.version\]}-%{+yyyy.MM.dd}" and also disabling the ILM policy …

---

## [Confused about filebeat privileges / ILM](https://discuss.elastic.co/t/confused-about-filebeat-privileges-ilm/276112)

<div class="topic-metadata">

**Author:** [@Balu](https://discuss.elastic.co/u/Balu)\
**Replies:** 0\
**Last updated:** [June 16, 2021, 9:47am UTC](https://discuss.elastic.co/t/confused-about-filebeat-privileges-ilm/276112 "2021-06-16T09:47:07Z")

</div>

Hey folks, I am just starting to work with the ELK stack and I am quite often confused by the documentation. For example while setting up filebeat, Grant privileges and roles needed for publishing tells me When using…

---

## [Elastic-agent and postfix logs](https://discuss.elastic.co/t/elastic-agent-and-postfix-logs/275872)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [June 16, 2021, 10:19pm UTC](https://discuss.elastic.co/t/elastic-agent-and-postfix-logs/275872 "2021-06-16T22:19:02Z")

</div>

Has anyone integrated elastic-agent and postfix in a really good way? As in made the agent split the log messages up into useful fields. I've successfully configured the Custom Logs integration to pull in my postfix log…

---

## [Cannot get Kubernetes Metadata after migrating to Containerd](https://discuss.elastic.co/t/cannot-get-kubernetes-metadata-after-migrating-to-containerd/276203)

<div class="topic-metadata">

**Author:** [@lel\_war](https://discuss.elastic.co/u/lel_war)\
**Replies:** 0\
**Last updated:** [June 16, 2021, 9:56pm UTC](https://discuss.elastic.co/t/cannot-get-kubernetes-metadata-after-migrating-to-containerd/276203 "2021-06-16T21:56:36Z")

</div>

Hello, After I migrated my cluster to containerd, logs are no longer on /var/lib/docker but rather in /var/log/pods///.log and symlinks in /var/log/containers/.log. I configured filebeat with the following and although…

---

## [Monitoring Logstash With Metricbeat](https://discuss.elastic.co/t/monitoring-logstash-with-metricbeat/275637)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [June 16, 2021, 7:12pm UTC](https://discuss.elastic.co/t/monitoring-logstash-with-metricbeat/275637 "2021-06-16T19:12:00Z")

</div>

Recently upgraded my Elastic Stack to 7.13 and have installed metricbeat 7.13.1 on the logstash server for monitoring, but I can get this thing to send monitoring data. The logs indicate a successful connection to my mo…

---

## [Configure Metricbeat not to report process arguments](https://discuss.elastic.co/t/configure-metricbeat-not-to-report-process-arguments/276047)

<div class="topic-metadata">

**Author:** [@spatar](https://discuss.elastic.co/u/spatar)\
**Replies:** 1\
**Last updated:** [June 16, 2021, 5:27pm UTC](https://discuss.elastic.co/t/configure-metricbeat-not-to-report-process-arguments/276047 "2021-06-16T17:27:49Z")

</div>

Is it possible to configure Metricbeat not to include process arguments in the metrics but only process names?

---

## [Modjk log monitoring with filebeat](https://discuss.elastic.co/t/modjk-log-monitoring-with-filebeat/276118)

<div class="topic-metadata">

**Author:** [@venkatesh\_prasanth](https://discuss.elastic.co/u/venkatesh_prasanth)\
**Replies:** 1\
**Last updated:** [June 16, 2021, 5:22pm UTC](https://discuss.elastic.co/t/modjk-log-monitoring-with-filebeat/276118 "2021-06-16T17:22:02Z")

</div>

Hi, I want to monitor the modjk log. From Which module i can give the log path for modjk and where should i mention grok filter

---

## [Creating a premade dashboard for my custom beat](https://discuss.elastic.co/t/creating-a-premade-dashboard-for-my-custom-beat/276154)

<div class="topic-metadata">

**Author:** [@blackberrySherbet](https://discuss.elastic.co/u/blackberrySherbet)\
**Replies:** 1\
**Last updated:** [June 16, 2021, 5:20pm UTC](https://discuss.elastic.co/t/creating-a-premade-dashboard-for-my-custom-beat/276154 "2021-06-16T17:20:15Z")

</div>

I have created my own custom beat (by following Creating a New Beat | Beats Developer Guide \[master\] | Elastic). I would like to create a new custom dashboard on Kibana every time a user uploads a new file using this cu…

---

## [Winlogbeat not writing logs to extract path](https://discuss.elastic.co/t/winlogbeat-not-writing-logs-to-extract-path/276157)

<div class="topic-metadata">

**Author:** [@rudraram](https://discuss.elastic.co/u/rudraram)\
**Replies:** 1\
**Last updated:** [June 16, 2021, 3:28pm UTC](https://discuss.elastic.co/t/winlogbeat-not-writing-logs-to-extract-path/276157 "2021-06-16T15:28:41Z")

</div>

I extracted winlogbeat to the following location C:\\Program Files (x86)\\winlogbeat-7.11.1-windows-x86\_64 when I install the service and start the service, i dont see any logs witten to logpath C:\\Program Files (x86)\\w…

---

## [Fleet: Override Elasticsearch URL at policy level](https://discuss.elastic.co/t/fleet-override-elasticsearch-url-at-policy-level/275982)

<div class="topic-metadata">

**Author:** [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Replies:** 2\
**Last updated:** [June 16, 2021, 3:04pm UTC](https://discuss.elastic.co/t/fleet-override-elasticsearch-url-at-policy-level/275982 "2021-06-16T15:04:00Z")

</div>

Hi All, Is it possible to override Elasticsearch URL for fleet on policy Level? I see in the UI we only have global setting. We use Elastic Cloud service. Use Case: For on premise agent it should connect to the publi…

---

## [Using Cisco Fleet Integration](https://discuss.elastic.co/t/using-cisco-fleet-integration/276094)

<div class="topic-metadata">

**Author:** [@helferlein](https://discuss.elastic.co/u/helferlein)\
**Replies:** 1\
**Last updated:** [June 16, 2021, 9:41am UTC](https://discuss.elastic.co/t/using-cisco-fleet-integration/276094 "2021-06-16T09:41:20Z")

</div>

Hi Elastic Users and Team. I managed to install the fleet-server on prem and added the Cisco Fleet Integration to the fleet-server itself. ELK Stack and also the fleetserver is on one virtual machine. So my thought wa…

---

## [Error with HAProxy Dashboards \[ 7.10.2 \]](https://discuss.elastic.co/t/error-with-haproxy-dashboards-7-10-2/275834)

<div class="topic-metadata">

**Author:** [@rodrigo.gz](https://discuss.elastic.co/u/rodrigo.gz)\
**Replies:** 2\
**Last updated:** [June 15, 2021, 9:43am UTC](https://discuss.elastic.co/t/error-with-haproxy-dashboards-7-10-2/275834 "2021-06-15T09:43:16Z")

</div>

Hello! I am trying to monitor a HAProxy with metricbeat and filebeat. ( 7.10.2 ) When I do the setup and start the agent , it starts collecting metrics and logs correctly but the dashboards do not show the collected in…

---

## [Filebeat \> Kafka \> ES \> Kibana](https://discuss.elastic.co/t/filebeat-kafka-es-kibana/275995)

<div class="topic-metadata">

**Author:** [@Robsen\_Inc](https://discuss.elastic.co/u/Robsen_Inc)\
**Replies:** 3\
**Last updated:** [June 16, 2021, 9:05am UTC](https://discuss.elastic.co/t/filebeat-kafka-es-kibana/275995 "2021-06-16T09:05:39Z")

</div>

Hi folks, I have a question regarding the Filebeat configuration. Because if I send the syslog data (with the syslog module) directly from Filebeat to Elasticsearch, the ready dashboard works (from the tutorial, see pic…

---

## [Filebeat - Saving what files Filebeat has Processed in ES](https://discuss.elastic.co/t/filebeat-saving-what-files-filebeat-has-processed-in-es/276097)

<div class="topic-metadata">

**Author:** [@scott\_stash](https://discuss.elastic.co/u/scott_stash)\
**Replies:** 0\
**Last updated:** [June 16, 2021, 8:03am UTC](https://discuss.elastic.co/t/filebeat-saving-what-files-filebeat-has-processed-in-es/276097 "2021-06-16T08:03:25Z")

</div>

I have a system setup where log files in a folder are processed by FB-\> LS -ES, once they are processed some reports/scripts are ran for the data in ES and the output is sent to a user. To accomplish this I have written…

---

## [Auditbeat Process Dashboard](https://discuss.elastic.co/t/auditbeat-process-dashboard/276077)

<div class="topic-metadata">

**Author:** [@yango](https://discuss.elastic.co/u/yango)\
**Replies:** 0\
**Last updated:** [June 16, 2021, 4:22am UTC](https://discuss.elastic.co/t/auditbeat-process-dashboard/276077 "2021-06-16T04:22:46Z")

</div>

I am using auditbeat 7.10.2 OSS, only modules included in auditbeat.yml are audited and file\_integrity. I need to analyze processes and login events, is it possible to add other modules? If yes, how?

---

## [Filebeat is not authenticating with elasticsearch after xpack was enabled](https://discuss.elastic.co/t/filebeat-is-not-authenticating-with-elasticsearch-after-xpack-was-enabled/275909)

<div class="topic-metadata">

**Author:** [@Antonio\_Chadwick](https://discuss.elastic.co/u/Antonio_Chadwick)\
**Replies:** 5\
**Last updated:** [June 15, 2021, 10:07pm UTC](https://discuss.elastic.co/t/filebeat-is-not-authenticating-with-elasticsearch-after-xpack-was-enabled/275909 "2021-06-15T22:07:09Z")

</div>

Hi Team, I have a local setup that running ubuntu which i have elasticsearch and kibana running on, and a separate box running centOS, which has filebeat installed on this is the server. I want to monitor logs from this…

---

## [How to drop a block of lines in logstash filter?](https://discuss.elastic.co/t/how-to-drop-a-block-of-lines-in-logstash-filter/276053)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 0\
**Last updated:** [June 15, 2021, 8:29pm UTC](https://discuss.elastic.co/t/how-to-drop-a-block-of-lines-in-logstash-filter/276053 "2021-06-15T20:29:50Z")

</div>

I have these lines in my websphere Systemout.log file: \*\*\*\*\*\*\*\*\*\*\*\* Start Display Current Environment \*\*\*\*\*\*\*\*\*\*\*\* line 1 line 2 line 3 line 4 line 5 line 7 \*\*\*\*\*\*\*\*\*\*\*\*\* End Display Current Environment \*\*\*\*\*\*\*\*\*\*\*\*\* H…

---

## [Filebeat Stops Processing logs for AWS module](https://discuss.elastic.co/t/filebeat-stops-processing-logs-for-aws-module/275993)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 7\
**Last updated:** [June 15, 2021, 7:38pm UTC](https://discuss.elastic.co/t/filebeat-stops-processing-logs-for-aws-module/275993 "2021-06-15T19:38:56Z")

</div>

I am facing exactly the same issue as this thread Filebeat stops proccessing s3 input with no error. Also, I experienced sometimes Filebeat suddenly stops processing data for other modules too, I faced it with Gsuite mo…

---

## [Winlogbeat 7.13.0 expected int but got type string in equals condition](https://discuss.elastic.co/t/winlogbeat-7-13-0-expected-int-but-got-type-string-in-equals-condition/274273)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 5\
**Last updated:** [June 15, 2021, 5:17pm UTC](https://discuss.elastic.co/t/winlogbeat-7-13-0-expected-int-but-got-type-string-in-equals-condition/274273 "2021-06-15T17:17:58Z")

</div>

I've upgraded to the latest version and winlogbeat is not sending data anymore The changes in 7.13.0 Change event.code and winlog.event\_id from int to keyword. I'm seeing a lot of these WARN \[conditions\] condit…

---

## [High Disk IO utilization in filebeat and logstash nodes](https://discuss.elastic.co/t/high-disk-io-utilization-in-filebeat-and-logstash-nodes/276032)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 0\
**Last updated:** [June 15, 2021, 4:30pm UTC](https://discuss.elastic.co/t/high-disk-io-utilization-in-filebeat-and-logstash-nodes/276032 "2021-06-15T16:30:55Z")

</div>

I see high Disk IO utilization in nodes where filebeat and logstash pods are running. This is lowering the event collection rates in all the nodes. I do not know what are the factors that are effecting the event collect…

---

## [Heartbeat ask for unnecessary cluster privileges at startup](https://discuss.elastic.co/t/heartbeat-ask-for-unnecessary-cluster-privileges-at-startup/275814)

<div class="topic-metadata">

**Author:** [@iorfix](https://discuss.elastic.co/u/iorfix)\
**Replies:** 5\
**Last updated:** [June 15, 2021, 2:28pm UTC](https://discuss.elastic.co/t/heartbeat-ask-for-unnecessary-cluster-privileges-at-startup/275814 "2021-06-15T14:28:43Z")

</div>

Hi all, I'm using Heartbeat 7.13.1. I first setup templates and ILM policy with elastic superuser, and then I start heartbeat using a ristrected "apikey" user. However, I have this error at startup: {"log.level":"err…

---

## [Beats 7.13.1 Helm Charts Missing/Removed?](https://discuss.elastic.co/t/beats-7-13-1-helm-charts-missing-removed/275854)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 2\
**Last updated:** [June 15, 2021, 1:24pm UTC](https://discuss.elastic.co/t/beats-7-13-1-helm-charts-missing-removed/275854 "2021-06-15T13:24:58Z")

</div>

I was trying to upgrade a helm deployment of Filebeat and Metricbeat to 7.13.1 and noticed that only 7.13.0 is available for it. 7.13.1 was available last week. Were the 7.13.1 charts removed for a specific reason?

---

## [Error with IIS Dashboards \[ 7.10.2 \]](https://discuss.elastic.co/t/error-with-iis-dashboards-7-10-2/276007)

<div class="topic-metadata">

**Author:** [@rodrigo.gz](https://discuss.elastic.co/u/rodrigo.gz)\
**Replies:** 0\
**Last updated:** [June 15, 2021, 1:22pm UTC](https://discuss.elastic.co/t/error-with-iis-dashboards-7-10-2/276007 "2021-06-15T13:22:11Z")

</div>

Hello! I am trying to monitor an IIS with metricbeat and filebeat. When I do the setup and start the agent, it starts collecting metrics and logs correctly but, the dashboards do not show the collected information as e…

---

## [Metricbeat and Logstash](https://discuss.elastic.co/t/metricbeat-and-logstash/275391)

<div class="topic-metadata">

**Author:** [@stefan0s](https://discuss.elastic.co/u/stefan0s)\
**Replies:** 3\
**Last updated:** [June 15, 2021, 10:43am UTC](https://discuss.elastic.co/t/metricbeat-and-logstash/275391 "2021-06-15T10:43:53Z")

</div>

Hello, I have installed logstash to collect logs and send to elasticsearch. Logstash is configured to keep indexes in hourly base. I need now to install metricbeat modules and also send to elasticsearch in hourly base …

---

## [How to monitor the beats using prometheus](https://discuss.elastic.co/t/how-to-monitor-the-beats-using-prometheus/275394)

<div class="topic-metadata">

**Author:** [@PeterFulier](https://discuss.elastic.co/u/PeterFulier)\
**Replies:** 2\
**Last updated:** [June 15, 2021, 10:26am UTC](https://discuss.elastic.co/t/how-to-monitor-the-beats-using-prometheus/275394 "2021-06-15T10:26:11Z")

</div>

Hello, I am trying to find a way to expose beats (especially the metricbeat) statistics to prometheus to have the option to monitor the correct functionality of metricbeat in terms of its connection to elastic. Current…

---

## [Metricbeat system module CPU missing fields](https://discuss.elastic.co/t/metricbeat-system-module-cpu-missing-fields/275837)

<div class="topic-metadata">

**Author:** [@phani\_akkina](https://discuss.elastic.co/u/phani_akkina)\
**Replies:** 1\
**Last updated:** [June 15, 2021, 8:57am UTC](https://discuss.elastic.co/t/metricbeat-system-module-cpu-missing-fields/275837 "2021-06-15T08:57:09Z")

</div>

Metricbeat System module CPU missing fields of nice, iowait, softirq, irq, and others for Windows and its reporting all for Linux VMS. Earlier we used the 6.1 version and its reported all the values but after the upgrad…

---

## [I want to get Notification if Filebeat get down](https://discuss.elastic.co/t/i-want-to-get-notification-if-filebeat-get-down/275960)

<div class="topic-metadata">

**Author:** [@Rohit\_Kumbhar](https://discuss.elastic.co/u/Rohit_Kumbhar)\
**Replies:** 1\
**Last updated:** [June 15, 2021, 8:40am UTC](https://discuss.elastic.co/t/i-want-to-get-notification-if-filebeat-get-down/275960 "2021-06-15T08:40:20Z")

</div>

Hi, I want to Uptime monitoring of Filebeat and if Filebeat gets down I should get slack notification regarding that. Is their any url for Filebeat so i can monitor it through Heartbeat? Thanks, Regards Rohit

---

## [Excessive disk usage ( ~80M/s) filebeat](https://discuss.elastic.co/t/excessive-disk-usage-80m-s-filebeat/275655)

<div class="topic-metadata">

**Author:** [@111304](https://discuss.elastic.co/u/111304)\
**Replies:** 1\
**Last updated:** [June 15, 2021, 8:38am UTC](https://discuss.elastic.co/t/excessive-disk-usage-80m-s-filebeat/275655 "2021-06-15T08:38:51Z")

</div>

Hi, I am using filebeat 7.6.0 vesrion on each server. I have a 3 node elastic cluster 6.8.16 version and Graylog version 4.0.8-1. In one run, I found that filebeat writes to disk (~ 80 Mbps), although normal writes (~ 2…

---

## [Elastic Fleet Agent Upgrade failing](https://discuss.elastic.co/t/elastic-fleet-agent-upgrade-failing/272502)

<div class="topic-metadata">

**Author:** [@The1WhoPrtNocks](https://discuss.elastic.co/u/The1WhoPrtNocks)\
**Replies:** 8\
**Last updated:** [June 15, 2021, 8:01am UTC](https://discuss.elastic.co/t/elastic-fleet-agent-upgrade-failing/272502 "2021-06-15T08:01:46Z")

</div>

Hi, Whenever I try to upgrade an agent via fleet it fails with the following; \[elastic\_agent\]\[error\] failed to dispatch actions, error: failed upgrade of agent binary: 2 errors occurred: \* package 'C:\\Program Files\\El…

---

## [Owner name not showing when file is deleted](https://discuss.elastic.co/t/owner-name-not-showing-when-file-is-deleted/275750)

<div class="topic-metadata">

**Author:** [@shikran](https://discuss.elastic.co/u/shikran)\
**Replies:** 0\
**Last updated:** [June 13, 2021, 5:37am UTC](https://discuss.elastic.co/t/owner-name-not-showing-when-file-is-deleted/275750 "2021-06-13T05:37:26Z")

</div>

i have configured auditbeat for windows server for file intergity monitoring, but when i delete a file it does not show who has deleted this?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=149)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=151)
