# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=155

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 156

---

## [Threatintel anomali error: the requested root field is empty](https://discuss.elastic.co/t/threatintel-anomali-error-the-requested-root-field-is-empty/270841)

<div class="topic-metadata">

**Author:** [@buzzdeee](https://discuss.elastic.co/u/buzzdeee)\
**Replies:** 7\
**Last updated:** [May 28, 2021, 7:26am UTC](https://discuss.elastic.co/t/threatintel-anomali-error-the-requested-root-field-is-empty/270841 "2021-05-28T07:26:54Z")

</div>

Hi, I gave the threatintel module a try. Successfully ingesting abuseurl, abusemalware and otx. I've a problem with getting anomali to work. First I figured, I have to uncomment the username/password fields to send def…

---

## [Filebeat ThreatIntel MISP Module](https://discuss.elastic.co/t/filebeat-threatintel-misp-module/274019)

<div class="topic-metadata">

**Author:** [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)\
**Replies:** 2\
**Last updated:** [May 28, 2021, 7:24am UTC](https://discuss.elastic.co/t/filebeat-threatintel-misp-module/274019 "2021-05-28T07:24:32Z")

</div>

Hi, I'm getting this error while trying to use the misp threat intel module: \[input.httpjson-cursor\] v2/request.go:186 error processing response: the requested root field is empty {"input\_sourc…

---

## [\[bug\] setup.dashboards.index not working for filebeat nor winlogbeat](https://discuss.elastic.co/t/bug-setup-dashboards-index-not-working-for-filebeat-nor-winlogbeat/274260)

<div class="topic-metadata">

**Author:** [@gschanuel](https://discuss.elastic.co/u/gschanuel)\
**Replies:** 2\
**Last updated:** [May 27, 2021, 11:45pm UTC](https://discuss.elastic.co/t/bug-setup-dashboards-index-not-working-for-filebeat-nor-winlogbeat/274260 "2021-05-27T23:45:25Z")

</div>

Hello there! I'm using ELK 7.13.0. After setting setup.dashboards.index and setup.dashboards.enabled: true, Dashboards, searches and visualizations are loaded, but Dashboads shows Could not locate that index-pattern (…

---

## [Ingesting evtx logs - error on setup.template.patterns](https://discuss.elastic.co/t/ingesting-evtx-logs-error-on-setup-template-patterns/274123)

<div class="topic-metadata">

**Author:** [@mikecmelanson](https://discuss.elastic.co/u/mikecmelanson)\
**Replies:** 3\
**Last updated:** [May 27, 2021, 11:51pm UTC](https://discuss.elastic.co/t/ingesting-evtx-logs-error-on-setup-template-patterns/274123 "2021-05-27T23:51:36Z")

</div>

I've been trying to make use of winlogbeats to ingest static event logs we get from various clients as we perform forensic investigations for them. I have a pretty nice little solution from Manually upload EVTX log file…

---

## [Custom filebeat index](https://discuss.elastic.co/t/custom-filebeat-index/274063)

<div class="topic-metadata">

**Author:** [@Bryce\_Fernandes](https://discuss.elastic.co/u/Bryce_Fernandes)\
**Replies:** 3\
**Last updated:** [May 27, 2021, 12:03pm UTC](https://discuss.elastic.co/t/custom-filebeat-index/274063 "2021-05-27T12:03:36Z")

</div>

Hi, I want to create filebeat index based on event.module and event.dataset, i am using elasticsearch as output. I have tried the following: setup.template.name: "filebeat" setup.template.pattern: "filebeat-\*" index:…

---

## [Unable to view Partition Reassignment Data in Metricbeat Kafka Dashboard](https://discuss.elastic.co/t/unable-to-view-partition-reassignment-data-in-metricbeat-kafka-dashboard/274134)

<div class="topic-metadata">

**Author:** [@metalshanked](https://discuss.elastic.co/u/metalshanked)\
**Replies:** 0\
**Last updated:** [May 27, 2021, 3:43am UTC](https://discuss.elastic.co/t/unable-to-view-partition-reassignment-data-in-metricbeat-kafka-dashboard/274134 "2021-05-27T03:43:04Z")

</div>

I am facing the same issue as mentioned in the post below.

---

## [Doubts about Filebeat Threat Intel Module \[7.12.0\]](https://discuss.elastic.co/t/doubts-about-filebeat-threat-intel-module-7-12-0/270810)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 13\
**Last updated:** [May 27, 2021, 11:33am UTC](https://discuss.elastic.co/t/doubts-about-filebeat-threat-intel-module-7-12-0/270810 "2021-05-27T11:33:04Z")

</div>

Hi, everyone I have been testing with Filebeat Threat Intel module in order to get events from MISP. I have some doubts regarding configuration: I have to disable every input plugin because they are enabled by defau…

---

## [Metricbeat SQL Module storing datetime field as string](https://discuss.elastic.co/t/metricbeat-sql-module-storing-datetime-field-as-string/274178)

<div class="topic-metadata">

**Author:** [@Sathish22](https://discuss.elastic.co/u/Sathish22)\
**Replies:** 0\
**Last updated:** [May 27, 2021, 10:09am UTC](https://discuss.elastic.co/t/metricbeat-sql-module-storing-datetime-field-as-string/274178 "2021-05-27T10:09:07Z")

</div>

Dear Team, We have a custom query to be configured in metricbeat SQL module. And query consist of field with the name as Date\_Time as datetime format. After configured the SQL in sql module, it is pushing Date\_Time fi…

---

## [The Dockerfile of filebeat](https://discuss.elastic.co/t/the-dockerfile-of-filebeat/274162)

<div class="topic-metadata">

**Author:** [@HeGaoYuan](https://discuss.elastic.co/u/HeGaoYuan)\
**Replies:** 0\
**Last updated:** [May 27, 2021, 8:52am UTC](https://discuss.elastic.co/t/the-dockerfile-of-filebeat/274162 "2021-05-27T08:52:03Z")

</div>

Hi, elastic/filebeat team I use the filebeat 7.5.2 docer image in beats/filebeat:7.5.2 | Docker @ Elastic , but I found some question, so I need to add some log to debug. I modify the source code from https://github.c…

---

## [How can i filter errors in filebeat](https://discuss.elastic.co/t/how-can-i-filter-errors-in-filebeat/273893)

<div class="topic-metadata">

**Author:** [@Martin\_perez](https://discuss.elastic.co/u/Martin_perez)\
**Replies:** 4\
**Last updated:** [May 27, 2021, 8:20am UTC](https://discuss.elastic.co/t/how-can-i-filter-errors-in-filebeat/273893 "2021-05-27T08:20:14Z")

</div>

Hi, I have an elk stack mounted, which receives data from two filebeats. I want to configure my filebeat configuration files so that it only collects files whose error is anything other than 500, and I have tried to do …

---

## [Filebeat cannot merge partial events](https://discuss.elastic.co/t/filebeat-cannot-merge-partial-events/274119)

<div class="topic-metadata">

**Author:** [@delta9](https://discuss.elastic.co/u/delta9)\
**Replies:** 1\
**Last updated:** [May 27, 2021, 7:55am UTC](https://discuss.elastic.co/t/filebeat-cannot-merge-partial-events/274119 "2021-05-27T07:55:39Z")

</div>

Hi all. We use filebeat to collect events from pods in k8s cluster. To do this we run it as daemonset and mounts /var/lib/docker/containers, /var/log/pods and /var/log/containers from cluster nodes into filebeat pods. …

---

## [FileBeat Startup error - No paths were defined for input accessing](https://discuss.elastic.co/t/filebeat-startup-error-no-paths-were-defined-for-input-accessing/274014)

<div class="topic-metadata">

**Author:** [@Parveen\_Sharma](https://discuss.elastic.co/u/Parveen_Sharma)\
**Replies:** 4\
**Last updated:** [May 27, 2021, 7:52am UTC](https://discuss.elastic.co/t/filebeat-startup-error-no-paths-were-defined-for-input-accessing/274014 "2021-05-27T07:52:17Z")

</div>

I am using filebeat 7.8.1 Following is the filebeat configuration file - type: kubernetes in\_cluster: true tags: - "kubernetes" templates: - condi…

---

## [Filebeat (with ILM) -\> Logstash -\> Elasticsearch not working](https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895)

<div class="topic-metadata">

**Author:** [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Replies:** 5\
**Last updated:** [May 27, 2021, 1:18am UTC](https://discuss.elastic.co/t/filebeat-with-ilm-logstash-elasticsearch-not-working/273895 "2021-05-27T01:18:32Z")

</div>

Hi, I think I am missing some simple settings here. I have enabled the ILM in beats: setup.ilm.enabled: true setup.ilm.rollover\_alias: "log-dev-filebeat" setup.ilm.pattern: "{now/d}-000001" setup.ilm.policy\_name: "fil…

---

## [Merge lines in filebeat](https://discuss.elastic.co/t/merge-lines-in-filebeat/273981)

<div class="topic-metadata">

**Author:** [@syrine\_chelly](https://discuss.elastic.co/u/syrine_chelly)\
**Replies:** 1\
**Last updated:** [May 27, 2021, 1:14am UTC](https://discuss.elastic.co/t/merge-lines-in-filebeat/273981 "2021-05-27T01:14:00Z")

</div>

this is an extract from my file log i want to merge the lines for example under "Server 'ILPPRAGLM', Line 14" in one event every time it finds Server it merges the lines how can i do it without merging the other lin…

---

## [OS X Filebeats resend on reboot when registry device number changes](https://discuss.elastic.co/t/os-x-filebeats-resend-on-reboot-when-registry-device-number-changes/272949)

<div class="topic-metadata">

**Author:** [@psears](https://discuss.elastic.co/u/psears)\
**Replies:** 1\
**Last updated:** [May 26, 2021, 8:24pm UTC](https://discuss.elastic.co/t/os-x-filebeats-resend-on-reboot-when-registry-device-number-changes/272949 "2021-05-26T20:24:29Z")

</div>

We have Macs sending install.log and system.log with filebeat and using the system module. Sometimes on reboot, they will resend everything in one of the log files (usually install.log, which doesn't change as often). Th…

---

## [Auditbeat multiple hosts in one file](https://discuss.elastic.co/t/auditbeat-multiple-hosts-in-one-file/271769)

<div class="topic-metadata">

**Author:** [@Slaughter](https://discuss.elastic.co/u/Slaughter)\
**Replies:** 8\
**Last updated:** [May 26, 2021, 7:11pm UTC](https://discuss.elastic.co/t/auditbeat-multiple-hosts-in-one-file/271769 "2021-05-26T19:11:16Z")

</div>

I'm not allowed to install beats on every server. I'm using audisp to send audit.log messages to a single host where auditbeat runs. Auditbeat is not using the hostname in the message. Everything is listed as coming f…

---

## [Filebeat capacity](https://discuss.elastic.co/t/filebeat-capacity/274096)

<div class="topic-metadata">

**Author:** [@AJ18](https://discuss.elastic.co/u/AJ18)\
**Replies:** 0\
**Last updated:** [May 26, 2021, 4:29pm UTC](https://discuss.elastic.co/t/filebeat-capacity/274096 "2021-05-26T16:29:36Z")

</div>

Hey Team Can anyone help me with what the capacity of a filebeat agent is and how much data it can support? I needed to get an idea of the size of the EC2 instance I should have on my AWS Account, and how many instance…

---

## [Multiple registries for filebeat](https://discuss.elastic.co/t/multiple-registries-for-filebeat/274061)

<div class="topic-metadata">

**Author:** [@Bryce\_Fernandes](https://discuss.elastic.co/u/Bryce_Fernandes)\
**Replies:** 0\
**Last updated:** [May 26, 2021, 1:19pm UTC](https://discuss.elastic.co/t/multiple-registries-for-filebeat/274061 "2021-05-26T13:19:50Z")

</div>

Hi, I wanted to know if we can have multiple registry files rather than one file having multiple values based on modules or something based on file paths. Regards, Bryce Fernandes.

---

## [Filebeat hints-based autodiscover with \> 2 streams](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-with-2-streams/273976)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [May 26, 2021, 12:52pm UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-with-2-streams/273976 "2021-05-26T12:52:22Z")

</div>

I'm using hints-based autodiscover for filebeats deployed to a Kubernetes environment. Per the docs, I can direct different streams to different filesets, per the following example for nginx: co.elastic.logs/module: ngi…

---

## [An existing connection was forcibly closed on remote host](https://discuss.elastic.co/t/an-existing-connection-was-forcibly-closed-on-remote-host/274031)

<div class="topic-metadata">

**Author:** [@Bryce\_Fernandes](https://discuss.elastic.co/u/Bryce_Fernandes)\
**Replies:** 0\
**Last updated:** [May 26, 2021, 9:28am UTC](https://discuss.elastic.co/t/an-existing-connection-was-forcibly-closed-on-remote-host/274031 "2021-05-26T09:28:39Z")

</div>

Hi, I have Elk setup of 3 nodes version 7.11.1. It's a new setup and currently I am testing few beats and modules. I have a central server where logs are present and i am using heartbeat, metricbeat, filebeat for same. …

---

## [Possible goroutine leak in sql module when database is not available](https://discuss.elastic.co/t/possible-goroutine-leak-in-sql-module-when-database-is-not-available/273850)

<div class="topic-metadata">

**Author:** [@simioa](https://discuss.elastic.co/u/simioa)\
**Replies:** 2\
**Last updated:** [May 26, 2021, 9:22am UTC](https://discuss.elastic.co/t/possible-goroutine-leak-in-sql-module-when-database-is-not-available/273850 "2021-05-26T09:22:05Z")

</div>

Used metricbeat Version: 7.12.1 Hello, we're using the metricbeat sql module to gather some metrics. During Downtime of our Database, I observed slowly increasing memory consumption from metricbeat. I tried to reprodu…

---

## [Kafka 2.4.1 compatiblity with Logstash and Filebeat 7.10.2](https://discuss.elastic.co/t/kafka-2-4-1-compatiblity-with-logstash-and-filebeat-7-10-2/274029)

<div class="topic-metadata">

**Author:** [@Thilak1](https://discuss.elastic.co/u/Thilak1)\
**Replies:** 0\
**Last updated:** [May 26, 2021, 8:51am UTC](https://discuss.elastic.co/t/kafka-2-4-1-compatiblity-with-logstash-and-filebeat-7-10-2/274029 "2021-05-26T08:51:44Z")

</div>

Hi , I am planning to use ELK 7.10.2 with Kafka 2.4.1. Are filebeat-7.10.2 and logstash-7.10.2 input/output plugins are compatible with Kafka-2.4.1.

---

## [Auditbeat auditd module vs. elastic agent auditd integration](https://discuss.elastic.co/t/auditbeat-auditd-module-vs-elastic-agent-auditd-integration/273983)

<div class="topic-metadata">

**Author:** [@lepepa9493](https://discuss.elastic.co/u/lepepa9493)\
**Replies:** 2\
**Last updated:** [May 26, 2021, 8:07am UTC](https://discuss.elastic.co/t/auditbeat-auditd-module-vs-elastic-agent-auditd-integration/273983 "2021-05-26T08:07:47Z")

</div>

What is the difference between using the auditbeat auditd module and using the elastic agent auditd integration? How can I use the elastic agent auditd integration with a custom auditd rules file or any other configurat…

---

## [Prebuilt Rule Reference](https://discuss.elastic.co/t/prebuilt-rule-reference/273991)

<div class="topic-metadata">

**Author:** [@jasieltego](https://discuss.elastic.co/u/jasieltego)\
**Replies:** 1\
**Last updated:** [May 25, 2021, 11:55pm UTC](https://discuss.elastic.co/t/prebuilt-rule-reference/273991 "2021-05-25T23:55:08Z")

</div>

Hi, I finally have setup my lab environment and fully working now. I'm ready to use prebuilt rules, my question is how, how do I start? I was able to use one rule because it clearly stated in the documentation copy xxxx…

---

## [Configuring filebeat.yml](https://discuss.elastic.co/t/configuring-filebeat-yml/273775)

<div class="topic-metadata">

**Author:** [@jasieltego](https://discuss.elastic.co/u/jasieltego)\
**Replies:** 5\
**Last updated:** [May 24, 2021, 7:49am UTC](https://discuss.elastic.co/t/configuring-filebeat-yml/273775 "2021-05-24T07:49:59Z")

</div>

Hi, I'm following instructions on the documentation provided on this site to configure filebeat.yml file. filebeat.inputs: - type: log paths: - /path/to/file/logstash-tutorial.log output.logstash: hosts: \["loc…

---

## [FileBeat HTTPJSON input split.type of list?](https://discuss.elastic.co/t/filebeat-httpjson-input-split-type-of-list/273965)

<div class="topic-metadata">

**Author:** [@PhilipWhiteside](https://discuss.elastic.co/u/PhilipWhiteside)\
**Replies:** 0\
**Last updated:** [May 25, 2021, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-httpjson-input-split-type-of-list/273965 "2021-05-25T15:18:44Z")

</div>

Hello, I'm struggling to perform a subsplit with a type of list. It appears only array, map, and string is supported. Am I not understanding something? Or is there a way to make this work? config response: split:…

---

## [How to configure Filebeat to ingest logs from nested workflow directories created after Filebeat starts](https://discuss.elastic.co/t/how-to-configure-filebeat-to-ingest-logs-from-nested-workflow-directories-created-after-filebeat-starts/273336)

<div class="topic-metadata">

**Author:** [@1steve](https://discuss.elastic.co/u/1steve)\
**Replies:** 1\
**Last updated:** [May 25, 2021, 2:55pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-ingest-logs-from-nested-workflow-directories-created-after-filebeat-starts/273336 "2021-05-25T14:55:51Z")

</div>

Similar to the question here, we need to ingest log files from a nested directory structure. However, different from that question and many other use cases, we are not ingesting logs from a static, persistent service or …

---

## [Metricbeat Oracle module only supoorted with docker image](https://discuss.elastic.co/t/metricbeat-oracle-module-only-supoorted-with-docker-image/273755)

<div class="topic-metadata">

**Author:** [@mrunalini](https://discuss.elastic.co/u/mrunalini)\
**Replies:** 3\
**Last updated:** [May 25, 2021, 1:09pm UTC](https://discuss.elastic.co/t/metricbeat-oracle-module-only-supoorted-with-docker-image/273755 "2021-05-25T13:09:10Z")

</div>

Hi ALL, As per mentioned on official ELK site ,Metribeat oracle module is only tested with docker image of oracle version 12c and instant client of version 18.1. so is oracle module supported for non docker image. Pl…

---

## [Filebeat: How to not send logs from kube-system namespace](https://discuss.elastic.co/t/filebeat-how-to-not-send-logs-from-kube-system-namespace/273876)

<div class="topic-metadata">

**Author:** [@vrathore18](https://discuss.elastic.co/u/vrathore18)\
**Replies:** 2\
**Last updated:** [May 25, 2021, 10:39am UTC](https://discuss.elastic.co/t/filebeat-how-to-not-send-logs-from-kube-system-namespace/273876 "2021-05-25T10:39:11Z")

</div>

I tried all possible solutions mentioned here and StackOverflow. But not able to exclude logs from kube-system namespaces. Basically, I am getting logs from all the namespaces. data: filebeat.yml: |- filebeat.inpu…

---

## [Can filebeats access the lifecycle policies on Elasticsearch?](https://discuss.elastic.co/t/can-filebeats-access-the-lifecycle-policies-on-elasticsearch/273882)

<div class="topic-metadata">

**Author:** [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Replies:** 3\
**Last updated:** [May 25, 2021, 3:35am UTC](https://discuss.elastic.co/t/can-filebeats-access-the-lifecycle-policies-on-elasticsearch/273882 "2021-05-25T03:35:30Z")

</div>

In case of logstash I was able to specify an existing policy name in the Elasticsearch output. Something like: output { elasticsearch { hosts =\> "http://XXXXXXXXXXX" ilm\_…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=154)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=156)
