# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=153

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 154

---

## [Fleet-Server for arm64](https://discuss.elastic.co/t/fleet-server-for-arm64/274900)

<div class="topic-metadata">

**Author:** [@fgierlinger](https://discuss.elastic.co/u/fgierlinger)\
**Replies:** 1\
**Last updated:** [June 7, 2021, 11:02am UTC](https://discuss.elastic.co/t/fleet-server-for-arm64/274900 "2021-06-07T11:02:00Z")

</div>

For all you aarch64/arm64 loving people out there, I ported fleet-server to arm64. If you are running a raspberry pi elastic cluster and are trying out the bleeding edge releases, the last 7.13.x release left you out in…

---

## [Heartbeat remote error: tls: handshake failure](https://discuss.elastic.co/t/heartbeat-remote-error-tls-handshake-failure/274999)

<div class="topic-metadata">

**Author:** [@vaclav1](https://discuss.elastic.co/u/vaclav1)\
**Replies:** 2\
**Last updated:** [June 7, 2021, 10:55am UTC](https://discuss.elastic.co/t/heartbeat-remote-error-tls-handshake-failure/274999 "2021-06-07T10:55:26Z")

</div>

Dear team, I recently enabled TLS on http and wanted to configure heartbeat to communicate with els on HTTPS. I have done following configuration: # ----------------------------------- ElasticSearch connection --------…

---

## [Elastic agents and existing beats](https://discuss.elastic.co/t/elastic-agents-and-existing-beats/274972)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 1\
**Last updated:** [June 7, 2021, 10:54am UTC](https://discuss.elastic.co/t/elastic-agents-and-existing-beats/274972 "2021-06-07T10:54:49Z")

</div>

If i have a server with winlog beat and filebeat iis module, can i install the elastic agent on this with the same integrations or do i need to uninstall the current set of beats?

---

## [Filebeat - Non-zero metrics in the last 30s](https://discuss.elastic.co/t/filebeat-non-zero-metrics-in-the-last-30s/275114)

<div class="topic-metadata">

**Author:** [@sacher](https://discuss.elastic.co/u/sacher)\
**Replies:** 1\
**Last updated:** [June 7, 2021, 10:46am UTC](https://discuss.elastic.co/t/filebeat-non-zero-metrics-in-the-last-30s/275114 "2021-06-07T10:46:08Z")

</div>

The file update has not been detected, but the file has been updated and the ES index has not been written. log 2021-06-04T12:39:30.519Z INFO instance/beat.go:304 Setup Beat: filebeat; Version: 7.12.1 2021-06-04T12:39:…

---

## [Windows elastic agent does not run](https://discuss.elastic.co/t/windows-elastic-agent-does-not-run/274606)

<div class="topic-metadata">

**Author:** [@Enrique\_Pedroza](https://discuss.elastic.co/u/Enrique_Pedroza)\
**Replies:** 1\
**Last updated:** [June 7, 2021, 8:59am UTC](https://discuss.elastic.co/t/windows-elastic-agent-does-not-run/274606 "2021-06-07T08:59:00Z")

</div>

I have installed elastic fleet agent in windows machine. It works fine but to run it as a service at boot it gives error and do not launch. If i manually run it woks, the problem is the windows service. At the moment of…

---

## [Error with](https://discuss.elastic.co/t/error-with/274054)

<div class="topic-metadata">

**Author:** [@Denden](https://discuss.elastic.co/u/Denden)\
**Replies:** 5\
**Last updated:** [June 7, 2021, 9:50am UTC](https://discuss.elastic.co/t/error-with/274054 "2021-06-07T09:50:54Z")

</div>

Hello there, I have a single ELK node, and I have some error that I can't find soutions. One of them is : illegal\_argument\_exception at shard 0index metricbeat-7.11.2-2021.05.26node ugebynP7RImmkUP5TCeGEA Typ…

---

## [Google Workplace no new events](https://discuss.elastic.co/t/google-workplace-no-new-events/275121)

<div class="topic-metadata">

**Author:** [@ab52](https://discuss.elastic.co/u/ab52)\
**Replies:** 0\
**Last updated:** [June 7, 2021, 9:15am UTC](https://discuss.elastic.co/t/google-workplace-no-new-events/275121 "2021-06-07T09:15:08Z")

</div>

Hi All, i have configure filebeat to grab the data from Google, but after a period of time it will stop grabbing the data from Google. If i restart the filebeat process ( Centos7.6 : Filebeat v 7.11.2-1 ) new events wil…

---

## [Metricbeat CPU percent on Hyper-V Server](https://discuss.elastic.co/t/metricbeat-cpu-percent-on-hyper-v-server/275083)

<div class="topic-metadata">

**Author:** [@notrix](https://discuss.elastic.co/u/notrix)\
**Replies:** 0\
**Last updated:** [June 6, 2021, 8:50pm UTC](https://discuss.elastic.co/t/metricbeat-cpu-percent-on-hyper-v-server/275083 "2021-06-06T20:50:37Z")

</div>

hey all, currently facing a problem with mericbeat on a Windows Server 2019 with Hyper-V role installed. This server is a pure virtualization server, hosting a lot of VMs. Using metricbeat 7.13.1 and have the following…

---

## [Metricbeat "System Overview" dashboards in Kibana are blank](https://discuss.elastic.co/t/metricbeat-system-overview-dashboards-in-kibana-are-blank/274812)

<div class="topic-metadata">

**Author:** [@jclemons7](https://discuss.elastic.co/u/jclemons7)\
**Replies:** 7\
**Last updated:** [June 5, 2021, 7:38pm UTC](https://discuss.elastic.co/t/metricbeat-system-overview-dashboards-in-kibana-are-blank/274812 "2021-06-05T19:38:13Z")

</div>

Hello, I've been trying to figure this out for a while now.. and initially I thought it had to do with my beats agent no matching my ELK version, but I updated everything today and the problem persists. On the Kibana da…

---

## [Filebeat Filtering - Drop Event when NOT contain field that equals a value](https://discuss.elastic.co/t/filebeat-filtering-drop-event-when-not-contain-field-that-equals-a-value/274463)

<div class="topic-metadata">

**Author:** [@valhalla](https://discuss.elastic.co/u/valhalla)\
**Replies:** 8\
**Last updated:** [June 5, 2021, 6:20pm UTC](https://discuss.elastic.co/t/filebeat-filtering-drop-event-when-not-contain-field-that-equals-a-value/274463 "2021-06-05T18:20:44Z")

</div>

Hi all, I need your help in order to filter some logs. What I need to do is to drop the events of all my logs that don't have an alert object in them with a severity of 3. I want to save in Elasticsearch only those that…

---

## [Filebeat is able to collect events of a pod when deployed in a node but unable to collect events when the same pod is deployed in a different node](https://discuss.elastic.co/t/filebeat-is-able-to-collect-events-of-a-pod-when-deployed-in-a-node-but-unable-to-collect-events-when-the-same-pod-is-deployed-in-a-different-node/275034)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 0\
**Last updated:** [June 5, 2021, 2:20pm UTC](https://discuss.elastic.co/t/filebeat-is-able-to-collect-events-of-a-pod-when-deployed-in-a-node-but-unable-to-collect-events-when-the-same-pod-is-deployed-in-a-different-node/275034 "2021-06-05T14:20:44Z")

</div>

I am using filebeat v7.12.0 to collect events from kubernetes pods. Filebeat is able to collect events from a certain pod when deployed in a node but fails to collect events when the same pod is deployed in a different n…

---

## [The file update has not been detected, but the file has been updated and the ES index has not been written](https://discuss.elastic.co/t/the-file-update-has-not-been-detected-but-the-file-has-been-updated-and-the-es-index-has-not-been-written/274983)

<div class="topic-metadata">

**Author:** [@sacher](https://discuss.elastic.co/u/sacher)\
**Replies:** 0\
**Last updated:** [June 4, 2021, 1:00pm UTC](https://discuss.elastic.co/t/the-file-update-has-not-been-detected-but-the-file-has-been-updated-and-the-es-index-has-not-been-written/274983 "2021-06-04T13:00:55Z")

</div>

log 2021-06-04T12:39:30.519Z INFO instance/beat.go:304 Setup Beat: filebeat; Version: 7.12.1 2021-06-04T12:39:30.519Z INFO eslegclient/connection.go:99 elasticsearch url: http://xxx:19200 2021-06-04T12:39:30.520Z INFO \[…

---

## [PostgreSQL grok problem](https://discuss.elastic.co/t/postgresql-grok-problem/273284)

<div class="topic-metadata">

**Author:** [@Cihan\_Tunali](https://discuss.elastic.co/u/Cihan_Tunali)\
**Replies:** 11\
**Last updated:** [June 4, 2021, 12:54pm UTC](https://discuss.elastic.co/t/postgresql-grok-problem/273284 "2021-06-04T12:54:15Z")

</div>

Hello, I am using PostgreSQL 12 with Filebeat 7.12. I followed (PostgreSQL module | Filebeat Reference \[8.11\] | Elastic) to configure filebeat. Right now Filebeat is sending the logs but I can see, there is a GROK failu…

---

## [Metricbeat IIS Module - which IIS services does it monitor](https://discuss.elastic.co/t/metricbeat-iis-module-which-iis-services-does-it-monitor/274977)

<div class="topic-metadata">

**Author:** [@abidub](https://discuss.elastic.co/u/abidub)\
**Replies:** 0\
**Last updated:** [June 4, 2021, 11:44am UTC](https://discuss.elastic.co/t/metricbeat-iis-module-which-iis-services-does-it-monitor/274977 "2021-06-04T11:44:01Z")

</div>

Hi there, I am configuring ansible to enable IIS module in Metricbeat "if" the IIS services are installed, however, I want to understand exactly which IIS services must be running for metricbeat to be able to gather IIS…

---

## [Proofpoint Syslog SSL](https://discuss.elastic.co/t/proofpoint-syslog-ssl/274965)

<div class="topic-metadata">

**Author:** [@Jojoke](https://discuss.elastic.co/u/Jojoke)\
**Replies:** 0\
**Last updated:** [June 4, 2021, 9:17am UTC](https://discuss.elastic.co/t/proofpoint-syslog-ssl/274965 "2021-06-04T09:17:01Z")

</div>

Hello Everyone ! I am trying to install the proofpoint module on filebeat and I have a small problem. My filebeat receives the data, but can't read it because it's encrypted. My proofpoint is the SaaS version = my sys…

---

## [Cisco ASA/FTD parsing in filebeat](https://discuss.elastic.co/t/cisco-asa-ftd-parsing-in-filebeat/274961)

<div class="topic-metadata">

**Author:** [@Andy\_Clark](https://discuss.elastic.co/u/Andy_Clark)\
**Replies:** 0\
**Last updated:** [June 4, 2021, 8:29am UTC](https://discuss.elastic.co/t/cisco-asa-ftd-parsing-in-filebeat/274961 "2021-06-04T08:29:28Z")

</div>

Is there a way within the filebeat config to get the log.source.address with just an IP address in, whenever I direct syslog traffic to the filebeat collector the sender IP address and the sending port are present within…

---

## [Packetbeat and Wireless network cards](https://discuss.elastic.co/t/packetbeat-and-wireless-network-cards/274938)

<div class="topic-metadata">

**Author:** [@tanner8302](https://discuss.elastic.co/u/tanner8302)\
**Replies:** 0\
**Last updated:** [June 4, 2021, 3:09am UTC](https://discuss.elastic.co/t/packetbeat-and-wireless-network-cards/274938 "2021-06-04T03:09:59Z")

</div>

I am looking some help in configuring the packetbeat.yml to sniff the wireless network card. I have installed NPCAP on the windows machine, I enabled raw traffic during the install. I then opened a command prompt and e…

---

## [Journalbeats - Error Creating Reader for Local Journal](https://discuss.elastic.co/t/journalbeats-error-creating-reader-for-local-journal/273064)

<div class="topic-metadata">

**Author:** [@Jimbuctoo](https://discuss.elastic.co/u/Jimbuctoo)\
**Replies:** 1\
**Last updated:** [June 3, 2021, 8:32pm UTC](https://discuss.elastic.co/t/journalbeats-error-creating-reader-for-local-journal/273064 "2021-06-03T20:32:03Z")

</div>

I am working on an issue with Journalbeats v7.9.2 where I am unable to get the service to start after the initial Journalbeats install. I am working in a number of Linux environments and the same version of Journalbeats …

---

## [Metricbeats does not ship data](https://discuss.elastic.co/t/metricbeats-does-not-ship-data/274904)

<div class="topic-metadata">

**Author:** [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Replies:** 0\
**Last updated:** [June 3, 2021, 5:38pm UTC](https://discuss.elastic.co/t/metricbeats-does-not-ship-data/274904 "2021-06-03T17:38:54Z")

</div>

Hi I have successfuly connected metric beat to the elastic cloud instance. I have setup dashboards, indexes and mapping. However, I can not open dashboards and there is no data under "observability-metrics". This are lo…

---

## [Query regarding Azure module in Metricbeat](https://discuss.elastic.co/t/query-regarding-azure-module-in-metricbeat/273469)

<div class="topic-metadata">

**Author:** [@adhiraj-g](https://discuss.elastic.co/u/adhiraj-g)\
**Replies:** 4\
**Last updated:** [June 3, 2021, 5:36pm UTC](https://discuss.elastic.co/t/query-regarding-azure-module-in-metricbeat/273469 "2021-06-03T17:36:15Z")

</div>

Hi There, For Azure Module in metricbeat, we are required to create a service principal with relevant access permissions in order to access metrics data from Azure. In case of Azure setup with multiple ADs, how do we m…

---

## [Error loading config file: yaml: line 177: could not find expected ':'](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-177-could-not-find-expected/274430)

<div class="topic-metadata">

**Author:** [@1234](https://discuss.elastic.co/u/1234)\
**Replies:** 2\
**Last updated:** [June 3, 2021, 5:32pm UTC](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-177-could-not-find-expected/274430 "2021-06-03T17:32:49Z")

</div>

\# These settings simplify using Filebeat with the Elastic Cloud (https://cloud.elastic.co/) #The cloud.id setting overwrites the output.elasticsearch.hosts and setup.kibana.host options. You can find the cloud.id in…

---

## [Filebeat not reading the input log file](https://discuss.elastic.co/t/filebeat-not-reading-the-input-log-file/274854)

<div class="topic-metadata">

**Author:** [@Ashwani\_Shukla](https://discuss.elastic.co/u/Ashwani_Shukla)\
**Replies:** 3\
**Last updated:** [June 3, 2021, 11:06am UTC](https://discuss.elastic.co/t/filebeat-not-reading-the-input-log-file/274854 "2021-06-03T11:06:55Z")

</div>

I am trying to fetch data using beats input from a log file whose path I have given in filebeat.yml. But the log file is not read by the logstash while running. filebeat.inputs: - type: log enabled: true paths: …

---

## [Unable to see nginx response time field on kibana](https://discuss.elastic.co/t/unable-to-see-nginx-response-time-field-on-kibana/274563)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 4\
**Last updated:** [June 3, 2021, 6:32am UTC](https://discuss.elastic.co/t/unable-to-see-nginx-response-time-field-on-kibana/274563 "2021-06-03T06:32:50Z")

</div>

Hello Team, Our architecture is Beats--\>Logstash--\>Elasticsaerch--\>Kibana and version is 7.10.2 for whole ELK stack. We are sending the nginx access logs on logstash using Filebeat nginx module and at logstash we are u…

---

## [Error in autodiscover provider settings: error setting up docker autodiscover provider](https://discuss.elastic.co/t/error-in-autodiscover-provider-settings-error-setting-up-docker-autodiscover-provider/274822)

<div class="topic-metadata">

**Author:** [@justindn](https://discuss.elastic.co/u/justindn)\
**Replies:** 0\
**Last updated:** [June 3, 2021, 4:33am UTC](https://discuss.elastic.co/t/error-in-autodiscover-provider-settings-error-setting-up-docker-autodiscover-provider/274822 "2021-06-03T04:33:31Z")

</div>

When I try to setup filebeat I get this error: filebeat | Exiting: error in autodiscover provider settings: error setting up docker autodiscover provider: Cannot connect to the Docker daemon at unix:///var/run/docker…

---

## [Metricbeat in customized index](https://discuss.elastic.co/t/metricbeat-in-customized-index/274586)

<div class="topic-metadata">

**Author:** [@venkatesh\_prasanth](https://discuss.elastic.co/u/venkatesh_prasanth)\
**Replies:** 4\
**Last updated:** [June 2, 2021, 10:38am UTC](https://discuss.elastic.co/t/metricbeat-in-customized-index/274586 "2021-06-02T10:38:56Z")

</div>

Am planning to use metricbeat via logstash, if i do that will mapping can be done automatically orelse i have to grok it? can i push to customized index and use the default metricbeat index

---

## [FileBeat error](https://discuss.elastic.co/t/filebeat-error/274709)

<div class="topic-metadata">

**Author:** [@Michael\_Dylan\_McAloo](https://discuss.elastic.co/u/Michael_Dylan_McAloo)\
**Replies:** 1\
**Last updated:** [June 2, 2021, 10:06am UTC](https://discuss.elastic.co/t/filebeat-error/274709 "2021-06-02T10:06:08Z")

</div>

I'm using FileBeat for dissect a Snort Alert but I have this message error when I try it. Error message:

---

## [Error initializing beat: error loading config file: yaml: line 19: did not find expected key](https://discuss.elastic.co/t/error-initializing-beat-error-loading-config-file-yaml-line-19-did-not-find-expected-key/274706)

<div class="topic-metadata">

**Author:** [@adarshr4](https://discuss.elastic.co/u/adarshr4)\
**Replies:** 0\
**Last updated:** [June 2, 2021, 7:33am UTC](https://discuss.elastic.co/t/error-initializing-beat-error-loading-config-file-yaml-line-19-did-not-find-expected-key/274706 "2021-06-02T07:33:11Z")

</div>

hi all, when am trying to sudo metricbeat modules enable elasticsearch-xpack it will triggered the following alert. Error initializing beat: error loading config file: yaml: line 19: did not find expected key please re…

---

## [Filebeat setting for removing harvested files from registry file?](https://discuss.elastic.co/t/filebeat-setting-for-removing-harvested-files-from-registry-file/274679)

<div class="topic-metadata">

**Author:** [@Resington\_R](https://discuss.elastic.co/u/Resington_R)\
**Replies:** 0\
**Last updated:** [June 1, 2021, 7:17pm UTC](https://discuss.elastic.co/t/filebeat-setting-for-removing-harvested-files-from-registry-file/274679 "2021-06-01T19:17:38Z")

</div>

I am a newbie, I am running Filebeat in my application server, to transfer log files to logstash server. My Application server creates new log files once in every 3 minutes 24x7 (i.e., 480 files per day). These files are…

---

## [V7.13.0 breaks OSS distributions](https://discuss.elastic.co/t/v7-13-0-breaks-oss-distributions/274568)

<div class="topic-metadata">

**Author:** [@Dan\_Bason](https://discuss.elastic.co/u/Dan_Bason)\
**Replies:** 3\
**Last updated:** [June 1, 2021, 7:26pm UTC](https://discuss.elastic.co/t/v7-13-0-breaks-oss-distributions/274568 "2021-06-01T19:26:40Z")

</div>

I've only tested with Metricbeat, but I assume most of the beats will be affected in v7.13.0. Connections to OSS distributions of Elasticsearch now fail due to a new license check introduced in libbeat (they throw an er…

---

## [Reading data from winlogbeats](https://discuss.elastic.co/t/reading-data-from-winlogbeats/274673)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 0\
**Last updated:** [June 1, 2021, 6:27pm UTC](https://discuss.elastic.co/t/reading-data-from-winlogbeats/274673 "2021-06-01T18:27:54Z")

</div>

I have been using a single system install of Elastic Stack and have been able to see information come in through my Kibana. I currently have FileBeats, WinlogBeats and MetricBeats installed and working. I am getting in…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=152)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=154)
