# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=152

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 153

---

## [Filebeat netflow huawei](https://discuss.elastic.co/t/filebeat-netflow-huawei/275515)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 0\
**Last updated:** [June 10, 2021, 4:42am UTC](https://discuss.elastic.co/t/filebeat-netflow-huawei/275515 "2021-06-10T04:42:20Z")

</div>

Hey all, I've been testing netflow from Huawei AR2200 Keep getting the following No template for ID 5000 2021-06-10T14:30:14.874+1000 DEBUG \[input\] input/input.go:139 Run input 2021-06-10T14:30:23.305+1000 DEBUG \[netf…

---

## [Filebeat iis module time taken field](https://discuss.elastic.co/t/filebeat-iis-module-time-taken-field/275504)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 1\
**Last updated:** [June 10, 2021, 3:35am UTC](https://discuss.elastic.co/t/filebeat-iis-module-time-taken-field/275504 "2021-06-10T03:35:49Z")

</div>

Using the filebeat iis module in v7.13, I cannot explicitly see the time taken field. Am I missing something or has it been replaced with event duration? The iis logs exports all fields.

---

## [Kafka publish failed with: kafka: client has run out of available brokers to talk to (Is your cluster reachable?)](https://discuss.elastic.co/t/kafka-publish-failed-with-kafka-client-has-run-out-of-available-brokers-to-talk-to-is-your-cluster-reachable/274805)

<div class="topic-metadata">

**Author:** [@suyannam](https://discuss.elastic.co/u/suyannam)\
**Replies:** 1\
**Last updated:** [June 10, 2021, 2:56am UTC](https://discuss.elastic.co/t/kafka-publish-failed-with-kafka-client-has-run-out-of-available-brokers-to-talk-to-is-your-cluster-reachable/274805 "2021-06-10T02:56:08Z")

</div>

Dear friends, need your help. For last couple of days stuck with below error. we are trying to send application logs to kafka, below is the kafka output config. We want to use kerberose auth type. I am not sure whether …

---

## [Multiline stacktrace in JSON not parsed by Filebeat/seen in Kibana](https://discuss.elastic.co/t/multiline-stacktrace-in-json-not-parsed-by-filebeat-seen-in-kibana/275502)

<div class="topic-metadata">

**Author:** [@jcklie](https://discuss.elastic.co/u/jcklie)\
**Replies:** 1\
**Last updated:** [June 9, 2021, 9:44pm UTC](https://discuss.elastic.co/t/multiline-stacktrace-in-json-not-parsed-by-filebeat-seen-in-kibana/275502 "2021-06-09T21:44:37Z")

</div>

I use JSON Template Layout from Apache log4j to log to jsonl. Then I use Filebeat to ingest this: filebeat.inputs: - type: log enabled: true paths: - /srv/inception-stable/logs/inception-stable.log - /srv/i…

---

## [Filebeat losing logs](https://discuss.elastic.co/t/filebeat-losing-logs/275501)

<div class="topic-metadata">

**Author:** [@devopscanada](https://discuss.elastic.co/u/devopscanada)\
**Replies:** 0\
**Last updated:** [June 9, 2021, 9:38pm UTC](https://discuss.elastic.co/t/filebeat-losing-logs/275501 "2021-06-09T21:38:53Z")

</div>

Hello, see this question for context. I'm running filebeat 7.13.1 in Kubernetes (GKE) with this running configuration: kubectl exec filebeat-filebeat-2rmhh -- filebeat export config filebeat: inputs: - paths: -…

---

## [Auditbeat rules](https://discuss.elastic.co/t/auditbeat-rules/275479)

<div class="topic-metadata">

**Author:** [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Replies:** 0\
**Last updated:** [June 9, 2021, 5:29pm UTC](https://discuss.elastic.co/t/auditbeat-rules/275479 "2021-06-09T17:29:34Z")

</div>

Hi! I have Auditbeat installed on a Linux machine and I want to receive logs for commands like systemctl stop / start syslog but it receives only for status. So, not all commands can be inspected in Kibana. Any idea wha…

---

## [High CPU Usage with Winlogbeat (latest version of beats)](https://discuss.elastic.co/t/high-cpu-usage-with-winlogbeat-latest-version-of-beats/275474)

<div class="topic-metadata">

**Author:** [@reconluke](https://discuss.elastic.co/u/reconluke)\
**Replies:** 0\
**Last updated:** [June 9, 2021, 4:04pm UTC](https://discuss.elastic.co/t/high-cpu-usage-with-winlogbeat-latest-version-of-beats/275474 "2021-06-09T16:04:46Z")

</div>

Hello - We are experiencing high CPU usage from the winlogbeat agent on a single system that is generating an extremely high volume of PowerShell Operational logs. Once we remove PowerShell logging entirely, the CPU usag…

---

## [Error using oracle module](https://discuss.elastic.co/t/error-using-oracle-module/275473)

<div class="topic-metadata">

**Author:** [@LagartijaNick](https://discuss.elastic.co/u/LagartijaNick)\
**Replies:** 0\
**Last updated:** [June 9, 2021, 3:58pm UTC](https://discuss.elastic.co/t/error-using-oracle-module/275473 "2021-06-09T15:58:30Z")

</div>

Hi, I'm a newbie. Trying to use filebeat version 7.13.1, I've enabled two modules system and oracle like so: ./filebeat modules enable system oracle. I'm not changing either the system.yml or oracle.yml config files. …

---

## [Metricbeat logs](https://discuss.elastic.co/t/metricbeat-logs/275439)

<div class="topic-metadata">

**Author:** [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Replies:** 1\
**Last updated:** [June 9, 2021, 2:56pm UTC](https://discuss.elastic.co/t/metricbeat-logs/275439 "2021-06-09T14:56:12Z")

</div>

I've installed Metricbeat and it worked, but when I've made the latest update it is not sending any log to Elasticsearch. I've verified command metricbeat test out and everything is green and I have system module enabled…

---

## [Can't parse haproxy logs without IP address in Grok](https://discuss.elastic.co/t/cant-parse-haproxy-logs-without-ip-address-in-grok/273654)

<div class="topic-metadata">

**Author:** [@maar](https://discuss.elastic.co/u/maar)\
**Replies:** 7\
**Last updated:** [June 9, 2021, 2:35pm UTC](https://discuss.elastic.co/t/cant-parse-haproxy-logs-without-ip-address-in-grok/273654 "2021-06-09T14:35:40Z")

</div>

Grok is parsing successfully when Haproxy gives a log - from var/log/haproxy.log - similar to: May 21 08:25:56 ha haproxy\[5089\]: 12.3.45.67:89012 \[21/May/2021:08:25:56.055\] www-https~ wss/wssnode website.domain.com 1/1/…

---

## [Exclude\_Files not working in Filebeat](https://discuss.elastic.co/t/exclude-files-not-working-in-filebeat/275392)

<div class="topic-metadata">

**Author:** [@shubham.tawde](https://discuss.elastic.co/u/shubham.tawde)\
**Replies:** 0\
**Last updated:** [June 9, 2021, 7:51am UTC](https://discuss.elastic.co/t/exclude-files-not-working-in-filebeat/275392 "2021-06-09T07:51:13Z")

</div>

Hi there! I have been trying to exclude a file from a directory, here's the dir structure which I have- var/logs/domain-a/HSC1/HSC1/logger.log var/logs/domain-b/HSC2/HSC2/logger.log var/logs/domain-c/HSC3/HSC3/logger…

---

## [Failed to connect AWS ES cluster](https://discuss.elastic.co/t/failed-to-connect-aws-es-cluster/275314)

<div class="topic-metadata">

**Author:** [@richzw](https://discuss.elastic.co/u/richzw)\
**Replies:** 3\
**Last updated:** [June 9, 2021, 6:13am UTC](https://discuss.elastic.co/t/failed-to-connect-aws-es-cluster/275314 "2021-06-09T06:13:58Z")

</div>

Hi We try to connect to AWS ES through file beat, However, the following errors comes up pipeline/output.go:100 Failed to connect to backoff(elasticsearch(https://xxx.us-east-1.es.amazonaws.com:443)): Connection marke…

---

## [Can not go get beats module](https://discuss.elastic.co/t/can-not-go-get-beats-module/275367)

<div class="topic-metadata">

**Author:** [@Montana\_Jony](https://discuss.elastic.co/u/Montana_Jony)\
**Replies:** 0\
**Last updated:** [June 9, 2021, 3:44am UTC](https://discuss.elastic.co/t/can-not-go-get-beats-module/275367 "2021-06-09T03:44:49Z")

</div>

ISSUE \[Elastic-Agent\] Can't go get module · Issue #26200 · elastic/beats · GitHub This is because of wrong file name with double dot

---

## [Filebeat messages dropped until 1PM in china zone](https://discuss.elastic.co/t/filebeat-messages-dropped-until-1pm-in-china-zone/274759)

<div class="topic-metadata">

**Author:** [@boba](https://discuss.elastic.co/u/boba)\
**Replies:** 1\
**Last updated:** [June 9, 2021, 12:53am UTC](https://discuss.elastic.co/t/filebeat-messages-dropped-until-1pm-in-china-zone/274759 "2021-06-09T00:53:46Z")

</div>

Hello, Messages before 1PM (5AM UTC) china time never appeared in graylog. New messages start piping at 1:00PM. All messages before 1:00 never arrived. I have light setup: linux, filebeat, sidecar, graylog, with just 2…

---

## [Metricbeat: configure (or reset) host.id](https://discuss.elastic.co/t/metricbeat-configure-or-reset-host-id/274925)

<div class="topic-metadata">

**Author:** [@BradVido](https://discuss.elastic.co/u/BradVido)\
**Replies:** 3\
**Last updated:** [June 8, 2021, 9:34pm UTC](https://discuss.elastic.co/t/metricbeat-configure-or-reset-host-id/274925 "2021-06-08T21:34:47Z")

</div>

We are using metricbeat to monitor logstash. We have many logstash vm's that are sending the same host.id in their metricbeat data. I'm guessing this is related to the vm's being cloned from the same template. How can …

---

## [GeoIP enrichment not working](https://discuss.elastic.co/t/geoip-enrichment-not-working/275084)

<div class="topic-metadata">

**Author:** [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Replies:** 30\
**Last updated:** [June 8, 2021, 5:56pm UTC](https://discuss.elastic.co/t/geoip-enrichment-not-working/275084 "2021-06-08T17:56:39Z")

</div>

I am trying to setup Geolocation based on IP. I am conecting packetbeat to elastic cloud directly. I have followed instruction from : https://www.elastic.co/guide/en/beats/packetbeat/master/packetbeat-geoip.html But I…

---

## [Okta Filebeat 7.12 Sending Duplicate Events and not Writing to log.json](https://discuss.elastic.co/t/okta-filebeat-7-12-sending-duplicate-events-and-not-writing-to-log-json/275324)

<div class="topic-metadata">

**Author:** [@nferg](https://discuss.elastic.co/u/nferg)\
**Replies:** 0\
**Last updated:** [June 8, 2021, 4:48pm UTC](https://discuss.elastic.co/t/okta-filebeat-7-12-sending-duplicate-events-and-not-writing-to-log-json/275324 "2021-06-08T16:48:47Z")

</div>

I am having trouble with the okta module in filebeats when I upgrade from 7.8.0 to 7.12.1. Upgrading causes filebeats to ship events multiple times, over a long period of time, filling up space on our drives. Additionall…

---

## [Difference between enable Module and fetching logs directly](https://discuss.elastic.co/t/difference-between-enable-module-and-fetching-logs-directly/274177)

<div class="topic-metadata">

**Author:** [@Dzious](https://discuss.elastic.co/u/Dzious)\
**Replies:** 14\
**Last updated:** [June 8, 2021, 3:33pm UTC](https://discuss.elastic.co/t/difference-between-enable-module-and-fetching-logs-directly/274177 "2021-06-08T15:33:57Z")

</div>

Hi, I've recently enabled the IIS Module on filebeat. Once the module enabled and configured, i've looked at the IIS Filebeat dashboard. unfortunately there was no data to see. After some research, i've found this webs…

---

## [Filebeat modules purpose?](https://discuss.elastic.co/t/filebeat-modules-purpose/275316)

<div class="topic-metadata">

**Author:** [@rebug](https://discuss.elastic.co/u/rebug)\
**Replies:** 0\
**Last updated:** [June 8, 2021, 3:31pm UTC](https://discuss.elastic.co/t/filebeat-modules-purpose/275316 "2021-06-08T15:31:39Z")

</div>

I just tested for the first time a Filebeat module. If I'm right, the purpose of a module is to have a ready-to-use pattern and dashboard, with a little data enrichment. So I don't undestand what is going on because th…

---

## [Cisco ASA module ingest pipeline parsing failure 7.13](https://discuss.elastic.co/t/cisco-asa-module-ingest-pipeline-parsing-failure-7-13/275294)

<div class="topic-metadata">

**Author:** [@mbst83r](https://discuss.elastic.co/u/mbst83r)\
**Replies:** 0\
**Last updated:** [June 8, 2021, 11:49am UTC](https://discuss.elastic.co/t/cisco-asa-module-ingest-pipeline-parsing-failure-7-13/275294 "2021-06-08T11:49:43Z")

</div>

Hello, the ingest pipeline is not parsing the IPSEC messages from the Cisco ASA (602303/602304) correctly. I am using filebeat 7.13.1 and the problem is in the filebeat-7.13.1-cisco-asa-asa-ftd-pipeline. 2021-06-08T13:…

---

## [Beats status monitoring](https://discuss.elastic.co/t/beats-status-monitoring/275286)

<div class="topic-metadata">

**Author:** [@ThreatInter](https://discuss.elastic.co/u/ThreatInter)\
**Replies:** 0\
**Last updated:** [June 8, 2021, 10:31am UTC](https://discuss.elastic.co/t/beats-status-monitoring/275286 "2021-06-08T10:31:33Z")

</div>

Hey, community. I have question - is it possible to make beats send some sort of keepalive messages? I want to know if my beats agents (winlogbeat, auditbeat, filebeat) in active state, and their services up.

---

## [\[Filebeat\] module kafka var.kafka\_home not work](https://discuss.elastic.co/t/filebeat-module-kafka-var-kafka-home-not-work/275262)

<div class="topic-metadata">

**Author:** [@yandd](https://discuss.elastic.co/u/yandd)\
**Replies:** 1\
**Last updated:** [June 8, 2021, 8:50am UTC](https://discuss.elastic.co/t/filebeat-module-kafka-var-kafka-home-not-work/275262 "2021-06-08T08:50:58Z")

</div>

Version: 7.13.1 Operating System: CentOS Linux release 7.6.1810 (Core) Discuss Forum URL: Steps to Reproduce: Run: filebeat modules enable kafka Edit: modules.d/kafka.yml# Module: kafka # Docs: https://www.…

---

## [Replace legacy collector with metricbeat](https://discuss.elastic.co/t/replace-legacy-collector-with-metricbeat/272952)

<div class="topic-metadata">

**Author:** [@kodka](https://discuss.elastic.co/u/kodka)\
**Replies:** 1\
**Last updated:** [June 8, 2021, 8:52am UTC](https://discuss.elastic.co/t/replace-legacy-collector-with-metricbeat/272952 "2021-06-08T08:52:52Z")

</div>

I can't understand how this works: What metricsets do i need to have enabled in order to have everything that legacy collectors scrapes as data. And do i need to have different metricsets configured for master and data…

---

## [Fanotify vs inotify](https://discuss.elastic.co/t/fanotify-vs-inotify/275213)

<div class="topic-metadata">

**Author:** [@nwed](https://discuss.elastic.co/u/nwed)\
**Replies:** 0\
**Last updated:** [June 8, 2021, 12:15am UTC](https://discuss.elastic.co/t/fanotify-vs-inotify/275213 "2021-06-08T00:15:56Z")

</div>

Hello, on kube we currently leverage two iterations of the file\_integrity module. First, we monitor paths under /hostfs, this has been stable for us. Second, we use the auditbeat.autodiscover with containerd to monitor c…

---

## [Heartbeat Maximum No. of Monitors](https://discuss.elastic.co/t/heartbeat-maximum-no-of-monitors/274206)

<div class="topic-metadata">

**Author:** [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Replies:** 1\
**Last updated:** [June 7, 2021, 11:09pm UTC](https://discuss.elastic.co/t/heartbeat-maximum-no-of-monitors/274206 "2021-06-07T23:09:21Z")

</div>

Saw this thread way back 4 years ago but it seems like there's no update or similar thread regarding this. We wanted to monitor millions of websites/services atleast once a day. We can run a job that can configure the …

---

## [Total number of file descriptors in system](https://discuss.elastic.co/t/total-number-of-file-descriptors-in-system/275199)

<div class="topic-metadata">

**Author:** [@crash0er](https://discuss.elastic.co/u/crash0er)\
**Replies:** 0\
**Last updated:** [June 7, 2021, 8:27pm UTC](https://discuss.elastic.co/t/total-number-of-file-descriptors-in-system/275199 "2021-06-07T20:27:35Z")

</div>

Hello, How can I get total number of file descriptors in elastic metricbeat? I referred to this commit but this is only per process. Reference: System fields | Metricbeat Reference \[7.13\] | Elastic Is there a system.…

---

## [Filebeat now reading the files with numbers](https://discuss.elastic.co/t/filebeat-now-reading-the-files-with-numbers/275195)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 0\
**Last updated:** [June 7, 2021, 7:57pm UTC](https://discuss.elastic.co/t/filebeat-now-reading-the-files-with-numbers/275195 "2021-06-07T19:57:36Z")

</div>

My log files are named with numbers for example 45678.rdlog and the filebeat couldn't able to read it and if I re name the file to something like test.rdlog it can able to read it. these logs are generated by rundeck an…

---

## [Metricbeat AWS credentials not working for Non-region endpoint](https://discuss.elastic.co/t/metricbeat-aws-credentials-not-working-for-non-region-endpoint/275191)

<div class="topic-metadata">

**Author:** [@swontonsoup](https://discuss.elastic.co/u/swontonsoup)\
**Replies:** 0\
**Last updated:** [June 7, 2021, 7:29pm UTC](https://discuss.elastic.co/t/metricbeat-aws-credentials-not-working-for-non-region-endpoint/275191 "2021-06-07T19:29:23Z")

</div>

This is similar to Metricbeat AWS module endpoint not working correctly. I tested on 7.13.1, but I think this should persist to current master branch. So I tried 3 different configurations and am unable to get the desir…

---

## [Winlogbeat drop\_fields not working](https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129)

<div class="topic-metadata">

**Author:** [@Billz1026](https://discuss.elastic.co/u/Billz1026)\
**Replies:** 5\
**Last updated:** [June 7, 2021, 6:20pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129 "2021-06-07T18:20:48Z")

</div>

Hi All, I have configured Winlogbeat to drop some fields from all the events using below configuration. But it seems the "drop\_fields" process is not applying to the events since I can see those fields in the Kibana. C…

---

## [\[filebeat azure module\] storage account permissions](https://discuss.elastic.co/t/filebeat-azure-module-storage-account-permissions/275172)

<div class="topic-metadata">

**Author:** [@daniele.saccon](https://discuss.elastic.co/u/daniele.saccon)\
**Replies:** 0\
**Last updated:** [June 7, 2021, 3:37pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-storage-account-permissions/275172 "2021-06-07T15:37:25Z")

</div>

Hi everybody, the storage\_account used in the Azure module of Filebeat what permissions does require? Thanks Daniele

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=151)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=153)
