# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=154

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 155

---

## [Parse line error: parsing CRI timestamp with filebeat 7.9.3](https://discuss.elastic.co/t/parse-line-error-parsing-cri-timestamp-with-filebeat-7-9-3/274666)

<div class="topic-metadata">

**Author:** [@Usman18](https://discuss.elastic.co/u/Usman18)\
**Replies:** 0\
**Last updated:** [June 1, 2021, 5:14pm UTC](https://discuss.elastic.co/t/parse-line-error-parsing-cri-timestamp-with-filebeat-7-9-3/274666 "2021-06-01T17:14:14Z")

</div>

I am using filebeat 7.9.3. The logs are being transferred to kafka. But I see an error in the logs inside docker container of filebeat. The error details are given below: filebeat\_1 | 2021-06-01T17:10:2…

---

## [Could I Get per process read/write diskio using metricbeat?](https://discuss.elastic.co/t/could-i-get-per-process-read-write-diskio-using-metricbeat/274365)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [June 1, 2021, 2:13pm UTC](https://discuss.elastic.co/t/could-i-get-per-process-read-write-diskio-using-metricbeat/274365 "2021-06-01T14:13:41Z")

</div>

Currently metricbeat is only giving me this information "cgroup" =\> { "blkio" =\> { "id" =\> "ssh.service", "path" =\> "/system.slice/ssh.service", …

---

## [Packetbeat Service Stop Automatically Everyday](https://discuss.elastic.co/t/packetbeat-service-stop-automatically-everyday/274621)

<div class="topic-metadata">

**Author:** [@vivek2219](https://discuss.elastic.co/u/vivek2219)\
**Replies:** 0\
**Last updated:** [June 1, 2021, 11:14am UTC](https://discuss.elastic.co/t/packetbeat-service-stop-automatically-everyday/274621 "2021-06-01T11:14:24Z")

</div>

Dear Team, As we check packetbeat service auto stop every day and we need to start it manually. There is no any issue it's working fine after restart/start. Not able to find any issue. please help to resolve this why…

---

## [Filebeat module system don't parse auth log](https://discuss.elastic.co/t/filebeat-module-system-dont-parse-auth-log/272801)

<div class="topic-metadata">

**Author:** [@beci](https://discuss.elastic.co/u/beci)\
**Replies:** 1\
**Last updated:** [June 1, 2021, 10:04am UTC](https://discuss.elastic.co/t/filebeat-module-system-dont-parse-auth-log/272801 "2021-06-01T10:04:50Z")

</div>

Hello all, I am using Filebeat 7.12.1 with the system module The logs send in Elastic without problem, but some failed authentication logs from pam\_unix(sshd:auth) are not parsed. Do you know why? Thank you very m…

---

## [Metricbeat for SSH/Secure log](https://discuss.elastic.co/t/metricbeat-for-ssh-secure-log/274581)

<div class="topic-metadata">

**Author:** [@bs\_aggarwal](https://discuss.elastic.co/u/bs_aggarwal)\
**Replies:** 0\
**Last updated:** [June 1, 2021, 6:06am UTC](https://discuss.elastic.co/t/metricbeat-for-ssh-secure-log/274581 "2021-06-01T06:06:55Z")

</div>

How to import SSH failed attempts reported in /var/log/secure log using metric beat. or alternatively i want to ssh login attempts using metric beat. pls advise.

---

## [Having an issue with filebeat pushing to Elasticsearch](https://discuss.elastic.co/t/having-an-issue-with-filebeat-pushing-to-elasticsearch/271822)

<div class="topic-metadata">

**Author:** [@gentle\_ghost](https://discuss.elastic.co/u/gentle_ghost)\
**Replies:** 21\
**Last updated:** [May 31, 2021, 9:24pm UTC](https://discuss.elastic.co/t/having-an-issue-with-filebeat-pushing-to-elasticsearch/271822 "2021-05-31T21:24:25Z")

</div>

Hello, I am receiving the following error when attempting to push log files to Elasticsearch: Exiting: error loading config file: yaml: line 2: did not find expected key Here is my .yaml file: filebeat.inputs: - ty…

---

## [Metricbeat Kubernetes Timeout for all nodes except one](https://discuss.elastic.co/t/metricbeat-kubernetes-timeout-for-all-nodes-except-one/274515)

<div class="topic-metadata">

**Author:** [@kiqo](https://discuss.elastic.co/u/kiqo)\
**Replies:** 0\
**Last updated:** [May 31, 2021, 1:53pm UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-timeout-for-all-nodes-except-one/274515 "2021-05-31T13:53:12Z")

</div>

Hi, I’m running Metricbeat in Kubernetes from the yamls here: However I am having an issue where I get these kind of errors on all nodes except one, which work fine, but I get no kubernetes stats on these three nodes …

---

## [Filebeat Multiline.Count\_Lines](https://discuss.elastic.co/t/filebeat-multiline-count-lines/274511)

<div class="topic-metadata">

**Author:** [@Beater](https://discuss.elastic.co/u/Beater)\
**Replies:** 1\
**Last updated:** [May 31, 2021, 1:35pm UTC](https://discuss.elastic.co/t/filebeat-multiline-count-lines/274511 "2021-05-31T13:35:11Z")

</div>

Hello Community, I'm currently using Filebeat to stream my logs to Kafka. Everything works as expected besides the multiline option. I'd like to bulk several lines into one event to stream bigger messages to Kafka as th…

---

## [Exclude lines isn't working with multiline pattern](https://discuss.elastic.co/t/exclude-lines-isnt-working-with-multiline-pattern/274211)

<div class="topic-metadata">

**Author:** [@syrine\_chelly](https://discuss.elastic.co/u/syrine_chelly)\
**Replies:** 1\
**Last updated:** [May 31, 2021, 12:58pm UTC](https://discuss.elastic.co/t/exclude-lines-isnt-working-with-multiline-pattern/274211 "2021-05-31T12:58:56Z")

</div>

this is my filebeat.yml exclude\_lines: \['^\[\[:space:\]\]'\] multiline.pattern: '^(3\[01\]|0\[1-9\]|\[12\]\[0-9\])(-?)(1\[0-2\]|0\[1-9\])(-?)(\[0-9\]{4})' multiline.negate: true multiline.match: after i want to exclude the lines…

---

## [Fleet AWS Cloudtrail integration stops working after upgrading elastic agent to 7.12.0](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120)

<div class="topic-metadata">

**Author:** [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Replies:** 10\
**Last updated:** [May 31, 2021, 12:05pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120 "2021-05-31T12:05:22Z")

</div>

Hi all, We have a working AWS CloudTrail integration with Elastic agent 7.10.1. After upgrading to 7.12 the cloud trail data stops working without any error in the log. I have tried to enabled debug level on agent but …

---

## [Extract the message from an Alert FileBeat](https://discuss.elastic.co/t/extract-the-message-from-an-alert-filebeat/274475)

<div class="topic-metadata">

**Author:** [@Michael\_Dylan\_McAloo](https://discuss.elastic.co/u/Michael_Dylan_McAloo)\
**Replies:** 4\
**Last updated:** [May 31, 2021, 11:17am UTC](https://discuss.elastic.co/t/extract-the-message-from-an-alert-filebeat/274475 "2021-05-31T11:17:15Z")

</div>

I need help because I don't know how to select only the part of the message where it says "NMAP ping sweep Scan". 05/28-10:30:30:52.840974 \[\*\*\] \[1:10000004:1\] "NMAP ping sweep Scan" \[\*\*\] \[Priority: 0\] {TCP} I got this: …

---

## [Winlogbeat Sysmon Configuration Registry fields seems to map the wrong value of the registry](https://discuss.elastic.co/t/winlogbeat-sysmon-configuration-registry-fields-seems-to-map-the-wrong-value-of-the-registry/273733)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [May 31, 2021, 9:17am UTC](https://discuss.elastic.co/t/winlogbeat-sysmon-configuration-registry-fields-seems-to-map-the-wrong-value-of-the-registry/273733 "2021-05-31T09:17:43Z")

</div>

Hello, Just noticed something weird with Sysmon configuration in 7.11 (registry events) As you can see, the actual value of the registry key is in winlog.event\_data.Details while imho this should be in registry.valu…

---

## [Calculating packet loss](https://discuss.elastic.co/t/calculating-packet-loss/274364)

<div class="topic-metadata">

**Author:** [@svenvg93](https://discuss.elastic.co/u/svenvg93)\
**Replies:** 2\
**Last updated:** [May 31, 2021, 8:43am UTC](https://discuss.elastic.co/t/calculating-packet-loss/274364 "2021-05-31T08:43:45Z")

</div>

Hello everyone, i'm very new to ELK stack. I am running a home lab for testing. I’m using heartbeat to monitor endpoints availability by ping. Is there a way to calculate the percentage of packet loss. Can’t seem to fi…

---

## [Architecture of elasticsearch-xpack monitoring with Metricbeat](https://discuss.elastic.co/t/architecture-of-elasticsearch-xpack-monitoring-with-metricbeat/274168)

<div class="topic-metadata">

**Author:** [@kodka](https://discuss.elastic.co/u/kodka)\
**Replies:** 2\
**Last updated:** [May 31, 2021, 8:03am UTC](https://discuss.elastic.co/t/architecture-of-elasticsearch-xpack-monitoring-with-metricbeat/274168 "2021-05-31T08:03:24Z")

</div>

Documentation (Collecting Elasticsearch monitoring data with Metricbeat | Elasticsearch Guide \[7.13\] | Elastic) says: "Ideally install a single Metricbeat instance configured with scope: cluster and configure hosts to po…

---

## [Filebeat dissect processor does nothing](https://discuss.elastic.co/t/filebeat-dissect-processor-does-nothing/274438)

<div class="topic-metadata">

**Author:** [@IvanovOleg](https://discuss.elastic.co/u/IvanovOleg)\
**Replies:** 0\
**Last updated:** [May 30, 2021, 3:52pm UTC](https://discuss.elastic.co/t/filebeat-dissect-processor-does-nothing/274438 "2021-05-30T15:52:11Z")

</div>

Hello. I want to parse logs from the java app running in the kubernetes pod. I have a filebeat configuration like this: filebeat.autodiscover: providers: - type: kubernetes templates: - condition.or:…

---

## [Aggregation on time series data (metricbeat and TSVB)](https://discuss.elastic.co/t/aggregation-on-time-series-data-metricbeat-and-tsvb/273455)

<div class="topic-metadata">

**Author:** [@zvazquez](https://discuss.elastic.co/u/zvazquez)\
**Replies:** 4\
**Last updated:** [May 30, 2021, 2:27pm UTC](https://discuss.elastic.co/t/aggregation-on-time-series-data-metricbeat-and-tsvb/273455 "2021-05-30T14:27:54Z")

</div>

Hi all, The scenarios is as follow: We are using metricbeat to capture metrics from multiple Kubernetes clusters into a single Elasticsearch cluster, we have enriched the data by adding a label using the processor, by …

---

## [Configuration to process certain logs with pipeline using Autodiscover](https://discuss.elastic.co/t/configuration-to-process-certain-logs-with-pipeline-using-autodiscover/274407)

<div class="topic-metadata">

**Author:** [@zvazquez](https://discuss.elastic.co/u/zvazquez)\
**Replies:** 1\
**Last updated:** [May 29, 2021, 6:51pm UTC](https://discuss.elastic.co/t/configuration-to-process-certain-logs-with-pipeline-using-autodiscover/274407 "2021-05-29T18:51:49Z")

</div>

Hi, I have filebeats running on Kubernetes with the autodiscover option, I have Ambassador running on the K8 cluster among several other application and I am trying to process the logs for the Ambassador containers diff…

---

## [GROK errors](https://discuss.elastic.co/t/grok-errors/273973)

<div class="topic-metadata">

**Author:** [@NogNeetMachinaal](https://discuss.elastic.co/u/NogNeetMachinaal)\
**Replies:** 2\
**Last updated:** [May 29, 2021, 4:36pm UTC](https://discuss.elastic.co/t/grok-errors/273973 "2021-05-29T16:36:50Z")

</div>

Everyone, Below 2 lines of syslog messages: 2021-05-15T14:24:35.235Z - Omada\[Controller\] \[client:A6-09-A2-5A-31-E3\] was disconnected from network "LAN (default)" on \[osg:90-9A-4A-FD-0D-A5\](connected t\> 2021-05-15T14:24…

---

## [Metricbeat is not sending cluster\_stats for elasticsearch module](https://discuss.elastic.co/t/metricbeat-is-not-sending-cluster-stats-for-elasticsearch-module/274378)

<div class="topic-metadata">

**Author:** [@Cousin\_John](https://discuss.elastic.co/u/Cousin_John)\
**Replies:** 0\
**Last updated:** [May 28, 2021, 8:30pm UTC](https://discuss.elastic.co/t/metricbeat-is-not-sending-cluster-stats-for-elasticsearch-module/274378 "2021-05-28T20:30:57Z")

</div>

I am having the same issue as this closed post: I am trying to monitor our Elasticsearch cluster 2.x with metricbeat 7.7.1. Metricbeat is sending over the data for node, node\_stats but for some reason it's not sending …

---

## [Installing filebeat on dockers question](https://discuss.elastic.co/t/installing-filebeat-on-dockers-question/274370)

<div class="topic-metadata">

**Author:** [@Kaleb](https://discuss.elastic.co/u/Kaleb)\
**Replies:** 0\
**Last updated:** [May 28, 2021, 6:37pm UTC](https://discuss.elastic.co/t/installing-filebeat-on-dockers-question/274370 "2021-05-28T18:37:03Z")

</div>

I'm new Elastic Stack. I've been able to install Elasticsearch and Kibana via Docker using the instructions on elastic.co. However, I'm having some difficulty installing filebeats using the directions on elastic.co. Afte…

---

## [Url.extension not populated](https://discuss.elastic.co/t/url-extension-not-populated/274278)

<div class="topic-metadata">

**Author:** [@peasead](https://discuss.elastic.co/u/peasead)\
**Replies:** 2\
**Last updated:** [May 28, 2021, 2:24pm UTC](https://discuss.elastic.co/t/url-extension-not-populated/274278 "2021-05-28T14:24:35Z")

</div>

I am trying to get Packetbeat to populate the url.extension field. It is in ECS and reported as an exported field for Packetbeat, but I cannot get it to work. In the below example, I would think it should be url.extensi…

---

## [Filebeat setup -e fails Error kibana fail to get version](https://discuss.elastic.co/t/filebeat-setup-e-fails-error-kibana-fail-to-get-version/274337)

<div class="topic-metadata">

**Author:** [@Peter\_Boos](https://discuss.elastic.co/u/Peter_Boos)\
**Replies:** 0\
**Last updated:** [May 28, 2021, 12:15pm UTC](https://discuss.elastic.co/t/filebeat-setup-e-fails-error-kibana-fail-to-get-version/274337 "2021-05-28T12:15:53Z")

</div>

I have Kibana and elastic search running, in a non clustered local environment. This has been running filebeat for maybe a year or a little less. Between a test machine and a Elk server. Its a pretty basic config, log…

---

## [When trying to run filebeat setup Exiting: 1 error: error loading config file](https://discuss.elastic.co/t/when-trying-to-run-filebeat-setup-exiting-1-error-error-loading-config-file/274233)

<div class="topic-metadata">

**Author:** [@thrak](https://discuss.elastic.co/u/thrak)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 9:12am UTC](https://discuss.elastic.co/t/when-trying-to-run-filebeat-setup-exiting-1-error-error-loading-config-file/274233 "2021-05-28T09:12:24Z")

</div>

Hello I just want to preface this with the fact that I am running an older version of beats, version 7.7.1, it's in production and we don't have a schedule yet to upgrade so we are stuck at this version for now. Wheneve…

---

## [Unable to start and stop filebeat](https://discuss.elastic.co/t/unable-to-start-and-stop-filebeat/274232)

<div class="topic-metadata">

**Author:** [@msjsitl](https://discuss.elastic.co/u/msjsitl)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 9:10am UTC](https://discuss.elastic.co/t/unable-to-start-and-stop-filebeat/274232 "2021-05-28T09:10:13Z")

</div>

Hello team, I am unable to start and stop filebeat . getting error like failed to stop filebeat. Can you please help on this. PFB filebeat logs: 2021-05-26T14:08:56.070-0400 INFO instance/beat.go:640 Home path: \[/usr…

---

## [Filebeat Logstash "Invalid version of beats protocol: 69" error](https://discuss.elastic.co/t/filebeat-logstash-invalid-version-of-beats-protocol-69-error/274275)

<div class="topic-metadata">

**Author:** [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 9:06am UTC](https://discuss.elastic.co/t/filebeat-logstash-invalid-version-of-beats-protocol-69-error/274275 "2021-05-28T09:06:48Z")

</div>

I am hosting the logstash in EC2. And filebeat is running on my windows environment. I consistently see this error in the logs. And what is tripping me is that filebeats is able to send to logstash. There is no loadba…

---

## [What's the correct value to set setup.dashboards.beat for o365 module?](https://discuss.elastic.co/t/whats-the-correct-value-to-set-setup-dashboards-beat-for-o365-module/274276)

<div class="topic-metadata">

**Author:** [@gschanuel](https://discuss.elastic.co/u/gschanuel)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 9:02am UTC](https://discuss.elastic.co/t/whats-the-correct-value-to-set-setup-dashboards-beat-for-o365-module/274276 "2021-05-28T09:02:23Z")

</div>

Hello there! I'm using ELK and filebeat, both v7.13.0 I enabled o365 module on filebeat configs and enabled setup.dashboards as below setup.dashboards: enabled: true index: "azure-\*" beat: "o365" setup.kibana: …

---

## [Filebeat 7.13 not compatible with elasticsearch-oss 7.10.2](https://discuss.elastic.co/t/filebeat-7-13-not-compatible-with-elasticsearch-oss-7-10-2/274037)

<div class="topic-metadata">

**Author:** [@confuseduser](https://discuss.elastic.co/u/confuseduser)\
**Replies:** 3\
**Last updated:** [May 28, 2021, 8:58am UTC](https://discuss.elastic.co/t/filebeat-7-13-not-compatible-with-elasticsearch-oss-7-10-2/274037 "2021-05-28T08:58:40Z")

</div>

Filebeat 7.13 is not compatible with elastichsearch-oss 7.10.2. May 26 10:21:39 server1 filebeat\[24814\]: 2021-05-26T10:21:39.231+0200 ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 …

---

## [Filebeat Question](https://discuss.elastic.co/t/filebeat-question/274290)

<div class="topic-metadata">

**Author:** [@Alvinong](https://discuss.elastic.co/u/Alvinong)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 8:33am UTC](https://discuss.elastic.co/t/filebeat-question/274290 "2021-05-28T08:33:15Z")

</div>

Hi to all, I had faced 2 question. Is it possible to send a log file from server and transfer/synchronize to MSSQL Server Management Studio using filebeat? and is it possible to use filebeat only without using Elastic…

---

## [Filebeat agent to get s3 Logs](https://discuss.elastic.co/t/filebeat-agent-to-get-s3-logs/274303)

<div class="topic-metadata">

**Author:** [@AJ18](https://discuss.elastic.co/u/AJ18)\
**Replies:** 0\
**Last updated:** [May 28, 2021, 8:28am UTC](https://discuss.elastic.co/t/filebeat-agent-to-get-s3-logs/274303 "2021-05-28T08:28:40Z")

</div>

Hi Team, How many filebeat instances are ideally recommended to get 80 GBs of data per month from s3 buckets for various services like VPC Flow Logs, CLoudtrail Logs, OS logs, etc.? Is there are a way to ensure high av…

---

## [Filebeat agent to get Operating System Logs](https://discuss.elastic.co/t/filebeat-agent-to-get-operating-system-logs/274101)

<div class="topic-metadata">

**Author:** [@AJ18](https://discuss.elastic.co/u/AJ18)\
**Replies:** 4\
**Last updated:** [May 28, 2021, 8:25am UTC](https://discuss.elastic.co/t/filebeat-agent-to-get-operating-system-logs/274101 "2021-05-28T08:25:24Z")

</div>

Hi Team, I am using Filebeat agent to get logs from an S3 bucket in my AWS Account and push them into Elasticsearch for visualisation. I wish to also collect some logs from EC2 instances of OS Linux or Windows (syslogs…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=153)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=155)
