# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=151

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 152

---

## [Winlogbeat pipeline](https://discuss.elastic.co/t/winlogbeat-pipeline/275770)

<div class="topic-metadata">

**Author:** [@lepepa9493](https://discuss.elastic.co/u/lepepa9493)\
**Replies:** 0\
**Last updated:** [June 13, 2021, 5:19pm UTC](https://discuss.elastic.co/t/winlogbeat-pipeline/275770 "2021-06-13T17:19:10Z")

</div>

Hi! I noticed winlogbeat events don't have an event.ingested field like events of other beats. I guess the field is created by an ingest pipeline. But running ".\\winlogbeat.exe setup" creates no pipeline. Is there no d…

---

## [Filebeat autodiscover missing field accessing](https://discuss.elastic.co/t/filebeat-autodiscover-missing-field-accessing/274256)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 2\
**Last updated:** [June 14, 2021, 4:40pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-missing-field-accessing/274256 "2021-06-14T16:40:08Z")

</div>

I am trying to setup filebeat with autodiscover, but container is failing with this error 2021-05-27T19:25:03.029Z ERROR instance/beat.go:971 Exiting: error in autodiscover provider settings: error setting up kubernetes…

---

## [Filebeat AWS Module unable to process Logs from S3](https://discuss.elastic.co/t/filebeat-aws-module-unable-to-process-logs-from-s3/275616)

<div class="topic-metadata">

**Author:** [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Replies:** 4\
**Last updated:** [June 14, 2021, 3:36pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-unable-to-process-logs-from-s3/275616 "2021-06-14T15:36:44Z")

</div>

ELK-Stack: 7.11.2 and Filebeat: 7.11.2 Up until today, Filebeat-AWS Module was able to read messages(vpc logs) from sqs queue. But, of of no-where, I see filebeat is unable to process the vpc-logs. I’m seeing the below …

---

## [Heartbeat](https://discuss.elastic.co/t/heartbeat/275742)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 2\
**Last updated:** [June 14, 2021, 2:39pm UTC](https://discuss.elastic.co/t/heartbeat/275742 "2021-06-14T14:39:36Z")

</div>

I have a json response { "applications": \[ { "name": "APP1", "instances": \[ { "instanceId": "app1", "healthCheckUrl": "http", …

---

## [Elastic-agent stopped working after adding new integration](https://discuss.elastic.co/t/elastic-agent-stopped-working-after-adding-new-integration/275670)

<div class="topic-metadata">

**Author:** [@bravo](https://discuss.elastic.co/u/bravo)\
**Replies:** 2\
**Last updated:** [June 14, 2021, 11:49am UTC](https://discuss.elastic.co/t/elastic-agent-stopped-working-after-adding-new-integration/275670 "2021-06-14T11:49:40Z")

</div>

First of all thank you very much for providing ES Fleet, its so helpful for our small team to manage and monitor nodes easily. We have 20 nodes with elastic-agent and all are working fine except one. In NODE1 elastic-ag…

---

## [FileBeat file type is not correctly set system-wide](https://discuss.elastic.co/t/filebeat-file-type-is-not-correctly-set-system-wide/275794)

<div class="topic-metadata">

**Author:** [@kwoxer](https://discuss.elastic.co/u/kwoxer)\
**Replies:** 2\
**Last updated:** [June 14, 2021, 10:16am UTC](https://discuss.elastic.co/t/filebeat-file-type-is-not-correctly-set-system-wide/275794 "2021-06-14T10:16:54Z")

</div>

I have trouble to set the file type of field via filebeat. Somehow the file type is keyword in the Index Pattern overview But in mappings tab of the Index management it says What is the type of the field now? Thi…

---

## [Need s390x (IBM System Z) support for Elastic Fleet Agent](https://discuss.elastic.co/t/need-s390x-ibm-system-z-support-for-elastic-fleet-agent/274476)

<div class="topic-metadata">

**Author:** [@kycfeel](https://discuss.elastic.co/u/kycfeel)\
**Replies:** 2\
**Last updated:** [June 14, 2021, 9:22am UTC](https://discuss.elastic.co/t/need-s390x-ibm-system-z-support-for-elastic-fleet-agent/274476 "2021-06-14T09:22:05Z")

</div>

Hi there. I want to install an elastic fleet agent on my s390x system but can't find any other builds except for the generic amd64. Unlink the normal elastic beats, it doesn't really seem like I can build my own binary…

---

## [Nested condition in drop\_event processor](https://discuss.elastic.co/t/nested-condition-in-drop-event-processor/275760)

<div class="topic-metadata">

**Author:** [@remrem](https://discuss.elastic.co/u/remrem)\
**Replies:** 1\
**Last updated:** [June 14, 2021, 9:03am UTC](https://discuss.elastic.co/t/nested-condition-in-drop-event-processor/275760 "2021-06-14T09:03:32Z")

</div>

I want to drop events with the following conditions: "If (event.id=(x or y) AND user.name=a) OR (event.id= z and process.name = 'cmd.exe') " But I just can't figure out the conditions.

---

## [If/Else condition for Output to Elasticsearch](https://discuss.elastic.co/t/if-else-condition-for-output-to-elasticsearch/275790)

<div class="topic-metadata">

**Author:** [@valhalla](https://discuss.elastic.co/u/valhalla)\
**Replies:** 3\
**Last updated:** [June 14, 2021, 9:01am UTC](https://discuss.elastic.co/t/if-else-condition-for-output-to-elasticsearch/275790 "2021-06-14T09:01:32Z")

</div>

Hi team, Would like to ask for your help with regards on having an if else condition on Filebeat’s output to elasticsearch. Would like to check if fields.age ==10 the output to be one array of hosts else other array of …

---

## [Failed to create alias - reason":"alias \[metricbeat-staging\] has more than one write index](https://discuss.elastic.co/t/failed-to-create-alias-reason-alias-metricbeat-staging-has-more-than-one-write-index/275688)

<div class="topic-metadata">

**Author:** [@phlegx](https://discuss.elastic.co/u/phlegx)\
**Replies:** 1\
**Last updated:** [June 14, 2021, 8:50am UTC](https://discuss.elastic.co/t/failed-to-create-alias-reason-alias-metricbeat-staging-has-more-than-one-write-index/275688 "2021-06-14T08:50:48Z")

</div>

Hi there! It seems that when my metricbeat instance gets killed/restarted, something breaks. I always get this error in the metricbeat logs: Index Alias metricbeat-staging setup failed: failed to create alias: {"error…

---

## [How to get the diff value of 2 fields and set it to a new field](https://discuss.elastic.co/t/how-to-get-the-diff-value-of-2-fields-and-set-it-to-a-new-field/275801)

<div class="topic-metadata">

**Author:** [@kwoxer](https://discuss.elastic.co/u/kwoxer)\
**Replies:** 1\
**Last updated:** [June 14, 2021, 8:30am UTC](https://discuss.elastic.co/t/how-to-get-the-diff-value-of-2-fields-and-set-it-to-a-new-field/275801 "2021-06-14T08:30:08Z")

</div>

I want to reference a field in FileBeat to calculate the difference between them. - dissect: tokenizer: '"%{licence}","%{system}","%{part}","%{uses|integer}","%{users|integer}"' field: "message" targ…

---

## [Number of docs count does not match number of json file records](https://discuss.elastic.co/t/number-of-docs-count-does-not-match-number-of-json-file-records/275739)

<div class="topic-metadata">

**Author:** [@rafaell2](https://discuss.elastic.co/u/rafaell2)\
**Replies:** 7\
**Last updated:** [June 13, 2021, 9:58pm UTC](https://discuss.elastic.co/t/number-of-docs-count-does-not-match-number-of-json-file-records/275739 "2021-06-13T21:58:26Z")

</div>

Hi. I am trying to load a json file with 8 records from filebeats to logstash (latest verion 7.13). It looks like i have no errors but when i check number of records at Kibana Index Management i see docs counts = 1 (also…

---

## [Adding Threat Intel Module To Existing Filebeat.yml Installed via Elastic-Agent](https://discuss.elastic.co/t/adding-threat-intel-module-to-existing-filebeat-yml-installed-via-elastic-agent/275775)

<div class="topic-metadata">

**Author:** [@pkward](https://discuss.elastic.co/u/pkward)\
**Replies:** 0\
**Last updated:** [June 13, 2021, 9:56pm UTC](https://discuss.elastic.co/t/adding-threat-intel-module-to-existing-filebeat-yml-installed-via-elastic-agent/275775 "2021-06-13T21:56:25Z")

</div>

Can I add a threat intel module (e.g., otx) to an existing filebeat.yml that was installed via an elastic agent?

---

## [Best way to define multiple processors based on a group of conditions](https://discuss.elastic.co/t/best-way-to-define-multiple-processors-based-on-a-group-of-conditions/275732)

<div class="topic-metadata">

**Author:** [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Replies:** 2\
**Last updated:** [June 13, 2021, 10:21am UTC](https://discuss.elastic.co/t/best-way-to-define-multiple-processors-based-on-a-group-of-conditions/275732 "2021-06-13T10:21:02Z")

</div>

Hi all I have been trying to work out the way define multiple processors based on a group of conditions. The below snippet doesn't seem to be working but hopefully it will give you an idea of what I am trying to accompli…

---

## [Filebeat not reading the files with names saved as numbers](https://discuss.elastic.co/t/filebeat-not-reading-the-files-with-names-saved-as-numbers/275741)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 1\
**Last updated:** [June 13, 2021, 6:05am UTC](https://discuss.elastic.co/t/filebeat-not-reading-the-files-with-names-saved-as-numbers/275741 "2021-06-13T06:05:40Z")

</div>

My log files are named with numbers for example 45678.rdlog and the filebeat couldn't able to read it and if I re name the file to something like test.rdlog it can able to read it. these logs are generated by rundeck an…

---

## [Filebeat 503 method not allowed](https://discuss.elastic.co/t/filebeat-503-method-not-allowed/275720)

<div class="topic-metadata">

**Author:** [@burtonrs](https://discuss.elastic.co/u/burtonrs)\
**Replies:** 1\
**Last updated:** [June 11, 2021, 9:02pm UTC](https://discuss.elastic.co/t/filebeat-503-method-not-allowed/275720 "2021-06-11T21:02:15Z")

</div>

Filebeat is attempting to send logs, but not working at all. Getting error below. HELP!!!! 2021-06-11T15:25:54.596-0400 DEBUG \[input\] input/input.go:139 Run input 2021-06-11T15:25:54.597-0400 DEBUG \[inpu…

---

## [Filebeat 7.6.1 - persistence of logs](https://discuss.elastic.co/t/filebeat-7-6-1-persistence-of-logs/274702)

<div class="topic-metadata">

**Author:** [@ramachandranmr88](https://discuss.elastic.co/u/ramachandranmr88)\
**Replies:** 1\
**Last updated:** [June 11, 2021, 7:10pm UTC](https://discuss.elastic.co/t/filebeat-7-6-1-persistence-of-logs/274702 "2021-06-11T19:10:02Z")

</div>

I am new to using ELK. I have the following configuration: Filebeat—\>Logstash—\>Elasticsearch—\>Kibana. I have the following questions When filebeat service is stopped while Logstash is still running and later when f…

---

## [Whats the meaning of "gt" and "lte" in the field called "monitor.timespan"?](https://discuss.elastic.co/t/whats-the-meaning-of-gt-and-lte-in-the-field-called-monitor-timespan/275667)

<div class="topic-metadata">

**Author:** [@mar-ro](https://discuss.elastic.co/u/mar-ro)\
**Replies:** 1\
**Last updated:** [June 11, 2021, 2:43pm UTC](https://discuss.elastic.co/t/whats-the-meaning-of-gt-and-lte-in-the-field-called-monitor-timespan/275667 "2021-06-11T14:43:18Z")

</div>

Hello! I just see in "heartbeat" index a field called "monitor.timespan" which contains the following: { "lt": "2021-06-11T09:58:59.034Z", "gte": "2021-06-11T09:58:54.034Z" } What's the meaning of "lt" and "gte"? …

---

## [Elastic pipeline](https://discuss.elastic.co/t/elastic-pipeline/275679)

<div class="topic-metadata">

**Author:** [@stefanskv](https://discuss.elastic.co/u/stefanskv)\
**Replies:** 2\
**Last updated:** [June 11, 2021, 11:11am UTC](https://discuss.elastic.co/t/elastic-pipeline/275679 "2021-06-11T11:11:19Z")

</div>

Why after upgrade to 7.13 version, Elastic started using new Ingest Node Pipelines (for example filebeat-7.13.1-cisco-asa-asa-ftd-pipeline ). The thing is i have problem with parsing source ip field. Can I configure tha…

---

## [Can i use modules and input at same time with different tag?](https://discuss.elastic.co/t/can-i-use-modules-and-input-at-same-time-with-different-tag/275651)

<div class="topic-metadata">

**Author:** [@venkatesh\_prasanth](https://discuss.elastic.co/u/venkatesh_prasanth)\
**Replies:** 0\
**Last updated:** [June 11, 2021, 6:17am UTC](https://discuss.elastic.co/t/can-i-use-modules-and-input-at-same-time-with-different-tag/275651 "2021-06-11T06:17:58Z")

</div>

Hi, I am using filebeat. i use apache module to collect log from apache. but want to collect the log from tomcat and index it in another index. can i use filebeat input in filebeat.yml and module in same time? but i wa…

---

## [Configure filebeat to read log with frequent events](https://discuss.elastic.co/t/configure-filebeat-to-read-log-with-frequent-events/275644)

<div class="topic-metadata">

**Author:** [@SulRin](https://discuss.elastic.co/u/SulRin)\
**Replies:** 0\
**Last updated:** [June 11, 2021, 5:32am UTC](https://discuss.elastic.co/t/configure-filebeat-to-read-log-with-frequent-events/275644 "2021-06-11T05:32:50Z")

</div>

Добрый день! Подскажите как настроить filebeat, чтобы он мог работать с логом, у которого частота событий 10-20 сообщений в секунду. дебаг filebeat -e -c filebeat.yml -d "\*", так повторяется очень долго, и нет сбро…

---

## [Is it possible to process AWS Cloudwatch logs using the nginx module?](https://discuss.elastic.co/t/is-it-possible-to-process-aws-cloudwatch-logs-using-the-nginx-module/275438)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 5\
**Last updated:** [June 10, 2021, 8:34pm UTC](https://discuss.elastic.co/t/is-it-possible-to-process-aws-cloudwatch-logs-using-the-nginx-module/275438 "2021-06-10T20:34:48Z")

</div>

I have a service deployed to ECS which is basically an nginx instance. I want to ingest the logs using filebeat - I can do this using the aws cloudwatch input type, but it doesn't grok the message field like the nginx m…

---

## [Will Filebeat Traefik module parse CLF or JSON access logs?](https://discuss.elastic.co/t/will-filebeat-traefik-module-parse-clf-or-json-access-logs/274781)

<div class="topic-metadata">

**Author:** [@bluepuma77](https://discuss.elastic.co/u/bluepuma77)\
**Replies:** 2\
**Last updated:** [June 10, 2021, 7:54pm UTC](https://discuss.elastic.co/t/will-filebeat-traefik-module-parse-clf-or-json-access-logs/274781 "2021-06-10T19:54:10Z")

</div>

I check the documentation but it doesn't tell if the module will parse the CLF or JSON log file format of Traefik? Which format should I use? Cheers bluepuma

---

## [Ingest AWS-CloudTrail Logs](https://discuss.elastic.co/t/ingest-aws-cloudtrail-logs/273464)

<div class="topic-metadata">

**Author:** [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Replies:** 10\
**Last updated:** [June 10, 2021, 7:45pm UTC](https://discuss.elastic.co/t/ingest-aws-cloudtrail-logs/273464 "2021-06-10T19:45:46Z")

</div>

I’m trying to extract & ingest AWS-Cloudtrail logs using Filebeat-7.10.0 AWS-module. I’m seeing the below error when filebeat is started & fails in starting further until I disable the AWS filebeat module. {"file.name"…

---

## [See autodiscovery generated configs](https://discuss.elastic.co/t/see-autodiscovery-generated-configs/275567)

<div class="topic-metadata">

**Author:** [@Moshe\_Avni](https://discuss.elastic.co/u/Moshe_Avni)\
**Replies:** 0\
**Last updated:** [June 10, 2021, 12:39pm UTC](https://discuss.elastic.co/t/see-autodiscovery-generated-configs/275567 "2021-06-10T12:39:59Z")

</div>

Hi, on the autodiscovery docs, it says: On start, Filebeat will scan existing containers and launch the proper configs for them. Is there a way to see the 'launched' configurations to debug if something is wrong with…

---

## [Documentation is lacking, how annotation should be used?](https://discuss.elastic.co/t/documentation-is-lacking-how-annotation-should-be-used/275564)

<div class="topic-metadata">

**Author:** [@Moshe\_Avni](https://discuss.elastic.co/u/Moshe_Avni)\
**Replies:** 0\
**Last updated:** [June 10, 2021, 12:07pm UTC](https://discuss.elastic.co/t/documentation-is-lacking-how-annotation-should-be-used/275564 "2021-06-10T12:07:36Z")

</div>

Hi, I'm reading the hint based autodiscovery and there should be an example for EVERY annotation, not for some. This annotation: co.elastic.logs/exclude\_lines is documented as a list of regular expressions, what is t…

---

## [Lower Filebeat memory usage](https://discuss.elastic.co/t/lower-filebeat-memory-usage/274896)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 1\
**Last updated:** [June 10, 2021, 11:53am UTC](https://discuss.elastic.co/t/lower-filebeat-memory-usage/274896 "2021-06-10T11:53:52Z")

</div>

Hi, I'm trying to give Filebeat as little memory as possible. My main issue is that I have a ton of independent containers on a VM and sometimes (due to network issues) Filebeat can't forward all the logs. However, afte…

---

## [Metricbeat events not indexed in Elasticsearch](https://discuss.elastic.co/t/metricbeat-events-not-indexed-in-elasticsearch/274998)

<div class="topic-metadata">

**Author:** [@Hugues\_Bernard](https://discuss.elastic.co/u/Hugues_Bernard)\
**Replies:** 2\
**Last updated:** [June 10, 2021, 11:36am UTC](https://discuss.elastic.co/t/metricbeat-events-not-indexed-in-elasticsearch/274998 "2021-06-10T11:36:14Z")

</div>

I configured metricbeat on one node of a 3 nodes elasticsearch cluster. Metricbeat output is set to a separate elasticsearch on a dedicated VM used for monitoring data only. Metricbeat is sending events every 10 secon…

---

## [Change index pattern used by metricbeat for monitoring logstash](https://discuss.elastic.co/t/change-index-pattern-used-by-metricbeat-for-monitoring-logstash/275452)

<div class="topic-metadata">

**Author:** [@BradVido](https://discuss.elastic.co/u/BradVido)\
**Replies:** 3\
**Last updated:** [June 10, 2021, 11:03am UTC](https://discuss.elastic.co/t/change-index-pattern-used-by-metricbeat-for-monitoring-logstash/275452 "2021-06-10T11:03:50Z")

</div>

We use metricbeat to monitor logstash, and it creates daily index patterns like: .monitoring-logstash-7-mb-2021.06.09 We'd prefer monthly index patterns, but can't seem to find any way to change it. Is it possible to …

---

## [Multiple string match to create index in filebeat](https://discuss.elastic.co/t/multiple-string-match-to-create-index-in-filebeat/275549)

<div class="topic-metadata">

**Author:** [@rahul30](https://discuss.elastic.co/u/rahul30)\
**Replies:** 0\
**Last updated:** [June 10, 2021, 9:40am UTC](https://discuss.elastic.co/t/multiple-string-match-to-create-index-in-filebeat/275549 "2021-06-10T09:40:29Z")

</div>

I want to create multiple index in filebeat by string in message - indices: - index: "billingproxy-%{+yyyy.MM.dd}" regexp: message: '(billingproxy & \\(squid-1\\))' - index:…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=150)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=152)
