# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=156

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 157

---

## [Installing Filebeat](https://discuss.elastic.co/t/installing-filebeat/273771)

<div class="topic-metadata">

**Author:** [@jasieltego](https://discuss.elastic.co/u/jasieltego)\
**Replies:** 2\
**Last updated:** [May 25, 2021, 12:02am UTC](https://discuss.elastic.co/t/installing-filebeat/273771 "2021-05-25T00:02:34Z")

</div>

Hi All, I have downloaded Filebeat and trying to install per instruction provided on the site. I have extracted it to C:\\Program Files , I have renamed it and ran powershell as admin as well. When I run the command C:…

---

## [Client Timeout error in elastic heartbeat for http POST](https://discuss.elastic.co/t/client-timeout-error-in-elastic-heartbeat-for-http-post/273002)

<div class="topic-metadata">

**Author:** [@Bikram\_Dhoju](https://discuss.elastic.co/u/Bikram_Dhoju)\
**Replies:** 3\
**Last updated:** [May 24, 2021, 7:33pm UTC](https://discuss.elastic.co/t/client-timeout-error-in-elastic-heartbeat-for-http-post/273002 "2021-05-24T19:33:20Z")

</div>

I have an error while trying to apply the heartbeat for the post request. My heartbeat config is: heartbeat.monitors: - type: http ipv4: true mode: any timeout: 30s name: test schedule:…

---

## [Reason for Scale 1000000 for IIS event.duration](https://discuss.elastic.co/t/reason-for-scale-1000000-for-iis-event-duration/273762)

<div class="topic-metadata">

**Author:** [@danielw](https://discuss.elastic.co/u/danielw)\
**Replies:** 6\
**Last updated:** [May 24, 2021, 5:43pm UTC](https://discuss.elastic.co/t/reason-for-scale-1000000-for-iis-event-duration/273762 "2021-05-24T17:43:26Z")

</div>

I'm trying to figure out what is the reason for the scale of 1000000 when using the filebeat module for iis for the duration field. Seems a bit strange when trying to build a dashboard for Reponse Times where every value…

---

## [Problem with shipping configuration (auditbeat)](https://discuss.elastic.co/t/problem-with-shipping-configuration-auditbeat/273729)

<div class="topic-metadata">

**Author:** [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Replies:** 2\
**Last updated:** [May 24, 2021, 1:30pm UTC](https://discuss.elastic.co/t/problem-with-shipping-configuration-auditbeat/273729 "2021-05-24T13:30:45Z")

</div>

I have implemented ELK on a single node with basic security (win server 2016). Elastic search, logstash and kibana are working fine. Now I want to start shipping some data and setting up dashboards. I have win 10 machin…

---

## [Exiting: error connecting to Kibana: fail to get the Kibana version:0](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-0/273734)

<div class="topic-metadata">

**Author:** [@momo1104](https://discuss.elastic.co/u/momo1104)\
**Replies:** 3\
**Last updated:** [May 24, 2021, 2:44pm UTC](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-0/273734 "2021-05-24T14:44:42Z")

</div>

Hello, i'm a newbie trying to send my second dataset, sitting inside my downloads folder (extracted) to kibana. Filebeat, elasticsearch, kibana are all running locahost:5601 is running filebeat.yml config as follow: (…

---

## [Why multiline pattern merge lines that don't respect the regex?](https://discuss.elastic.co/t/why-multiline-pattern-merge-lines-that-dont-respect-the-regex/273656)

<div class="topic-metadata">

**Author:** [@syrine\_chelly](https://discuss.elastic.co/u/syrine_chelly)\
**Replies:** 2\
**Last updated:** [May 24, 2021, 9:12am UTC](https://discuss.elastic.co/t/why-multiline-pattern-merge-lines-that-dont-respect-the-regex/273656 "2021-05-24T09:12:20Z")

</div>

i want my filebeat.yml to combine only the lines that respect the regex multiline.pattern: '^Server \[\[:graph:\]\]\* Line' multiline.negate: true multiline.match: after but actually it combines the other lines that don't…

---

## [Can metricbeat print multiple logs within one event?](https://discuss.elastic.co/t/can-metricbeat-print-multiple-logs-within-one-event/273791)

<div class="topic-metadata">

**Author:** [@CHU\_XU](https://discuss.elastic.co/u/CHU_XU)\
**Replies:** 0\
**Last updated:** [May 24, 2021, 8:19am UTC](https://discuss.elastic.co/t/can-metricbeat-print-multiple-logs-within-one-event/273791 "2021-05-24T08:19:10Z")

</div>

Hi experts, I'm using metricbeat to log some metrics of my system with http module, output is json style. Somehow there's a data size limitation on single log in my system, is there any way I can have metricbeat output…

---

## [Filebeat gcp module keeps getting hash config error when setting up](https://discuss.elastic.co/t/filebeat-gcp-module-keeps-getting-hash-config-error-when-setting-up/273643)

<div class="topic-metadata">

**Author:** [@stevensim226](https://discuss.elastic.co/u/stevensim226)\
**Replies:** 1\
**Last updated:** [May 24, 2021, 8:00am UTC](https://discuss.elastic.co/t/filebeat-gcp-module-keeps-getting-hash-config-error-when-setting-up/273643 "2021-05-24T08:00:39Z")

</div>

According to this docs, I have set up the gcp.yml file as written with the settings intact (firewall and vpcflow is enable: false) But i keep getting this error whenever I run sudo filebeat setup -e 2021-05-21T09:02:25…

---

## [Getting Error - ORA-00000: DPI-1047: Cannot locate a 64-bit Oracle Client library: "libclntsh.so: cannot open shared object file: No such file or directory elastc](https://discuss.elastic.co/t/getting-error-ora-00000-dpi-1047-cannot-locate-a-64-bit-oracle-client-library-libclntsh-so-cannot-open-shared-object-file-no-such-file-or-directory-elastc/273754)

<div class="topic-metadata">

**Author:** [@mrunalini](https://discuss.elastic.co/u/mrunalini)\
**Replies:** 0\
**Last updated:** [May 23, 2021, 7:58am UTC](https://discuss.elastic.co/t/getting-error-ora-00000-dpi-1047-cannot-locate-a-64-bit-oracle-client-library-libclntsh-so-cannot-open-shared-object-file-no-such-file-or-directory-elastc/273754 "2021-05-23T07:58:59Z")

</div>

HI Everyone, I am trying to connect Oracle DB via Metricbeat ,but getting error- ORA-00000: DPI-1047: Cannot locate a 64-bit Oracle Client library: "libclntsh.so: cannot open shared object file: No such file or directo…

---

## [\[Filebeat\]\[Fortinet Module\] Failed to parse field](https://discuss.elastic.co/t/filebeat-fortinet-module-failed-to-parse-field/273437)

<div class="topic-metadata">

**Author:** [@Danilo\_PC](https://discuss.elastic.co/u/Danilo_PC)\
**Replies:** 2\
**Last updated:** [May 24, 2021, 2:16am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-failed-to-parse-field/273437 "2021-05-24T02:16:25Z")

</div>

Hi, I'm running filebeat 7.12.1 receiving data from my Fortigate (FortiOS v6.4.1 build1637). Looking at filebeat log files, I can see that there is happening and parse error on "fortinet.firewall.cat" field: May 19 12:…

---

## [filebeat+logstash,The number of output events per second cannot break the hard limit (CPU and memory are sufficient)](https://discuss.elastic.co/t/filebeat-logstash-the-number-of-output-events-per-second-cannot-break-the-hard-limit-cpu-and-memory-are-sufficient/273596)

<div class="topic-metadata">

**Author:** [@liuliugang](https://discuss.elastic.co/u/liuliugang)\
**Replies:** 3\
**Last updated:** [May 24, 2021, 1:13am UTC](https://discuss.elastic.co/t/filebeat-logstash-the-number-of-output-events-per-second-cannot-break-the-hard-limit-cpu-and-memory-are-sufficient/273596 "2021-05-24T01:13:59Z")

</div>

FileBeat configuration :2 core 8G Logstahs configuration :8 core 8G FileBeat version and Logstash version 7.10.0 Single node FileBeat sends log to Logstash. The number of data per second is fixed and cannot break the 6…

---

## [ERROR instance/beat.go:971 Exiting: error initializing processors: unexpected expand\_keys option in processors.1.decode\_json\_fields](https://discuss.elastic.co/t/error-instance-beat-go-971-exiting-error-initializing-processors-unexpected-expand-keys-option-in-processors-1-decode-json-fields/271986)

<div class="topic-metadata">

**Author:** [@NiamhAsura](https://discuss.elastic.co/u/NiamhAsura)\
**Replies:** 4\
**Last updated:** [May 22, 2021, 12:35am UTC](https://discuss.elastic.co/t/error-instance-beat-go-971-exiting-error-initializing-processors-unexpected-expand-keys-option-in-processors-1-decode-json-fields/271986 "2021-05-22T00:35:57Z")

</div>

Hi, I am trying to use the expand\_keys option as specified in the configuration for decode\_json\_fields. I am getting the following error: ERROR instance/beat.go:971 Exiting: error initializing processors: unexpec…

---

## [Updated field using mapping API does not show in index pattern](https://discuss.elastic.co/t/updated-field-using-mapping-api-does-not-show-in-index-pattern/273708)

<div class="topic-metadata">

**Author:** [@Terry\_Tuna](https://discuss.elastic.co/u/Terry_Tuna)\
**Replies:** 0\
**Last updated:** [May 21, 2021, 10:35pm UTC](https://discuss.elastic.co/t/updated-field-using-mapping-api-does-not-show-in-index-pattern/273708 "2021-05-21T22:35:56Z")

</div>

Hi, I'm using the mapping API to add a field onto my functionbeat index, named message\_visual, which is shown when I made a GET request of the mapping. But the index doesn't show up when I try to look for it on my i…

---

## [Help needed i m having the issue failed to perform any bulk index operations: 500 Internal Server Error](https://discuss.elastic.co/t/help-needed-i-m-having-the-issue-failed-to-perform-any-bulk-index-operations-500-internal-server-error/273308)

<div class="topic-metadata">

**Author:** [@khanio99](https://discuss.elastic.co/u/khanio99)\
**Replies:** 5\
**Last updated:** [May 21, 2021, 3:33pm UTC](https://discuss.elastic.co/t/help-needed-i-m-having-the-issue-failed-to-perform-any-bulk-index-operations-500-internal-server-error/273308 "2021-05-21T15:33:58Z")

</div>

May 18 10:50:36 debian filebeat\[5663\]: 2021-05-18T10:50:36.145-0400 INFO \[license\] licenser/es\_callback.go:51 Elasticsearch license: Basic May 18 10:50:36 debian filebeat\[5663\]: 2021-05-18T10:…

---

## [Fortinet module not parsing from file](https://discuss.elastic.co/t/fortinet-module-not-parsing-from-file/273590)

<div class="topic-metadata">

**Author:** [@Mustafa\_Y](https://discuss.elastic.co/u/Mustafa_Y)\
**Replies:** 5\
**Last updated:** [May 21, 2021, 12:23pm UTC](https://discuss.elastic.co/t/fortinet-module-not-parsing-from-file/273590 "2021-05-21T12:23:16Z")

</div>

Hello, I want to parse fortinet logs from file instead of syslog network. There is an option var.paths in Fortinet module | Filebeat Reference \[master\] | Elastic and var.input . I configured it as below: - module: for…

---

## [Filebeat uses process time instead event time](https://discuss.elastic.co/t/filebeat-uses-process-time-instead-event-time/273646)

<div class="topic-metadata">

**Author:** [@nflinenberg](https://discuss.elastic.co/u/nflinenberg)\
**Replies:** 1\
**Last updated:** [May 21, 2021, 12:15pm UTC](https://discuss.elastic.co/t/filebeat-uses-process-time-instead-event-time/273646 "2021-05-21T12:15:38Z")

</div>

Hi all, Hope you can help me out for the following. We've setup and Elasticstack and configured filebeat to send json logs to elasticsearch, using this configuration: filebeat.inputs: - type: log enabled: true …

---

## [FileBeat + LogsTash port 5044](https://discuss.elastic.co/t/filebeat-logstash-port-5044/271777)

<div class="topic-metadata">

**Author:** [@Paveltest](https://discuss.elastic.co/u/Paveltest)\
**Replies:** 6\
**Last updated:** [May 21, 2021, 7:00am UTC](https://discuss.elastic.co/t/filebeat-logstash-port-5044/271777 "2021-05-21T07:00:03Z")

</div>

Error ERROR#011\[publisher\_pipeline\_output\]#011pipeline/output.go:154#011Failed to connect to backoff(async(tcp://192.168.10.14:5044)). I can not connect on port 5044 with logstash! On the logstash server port 5044 is op…

---

## [Packetbeat hardware / software requirements](https://discuss.elastic.co/t/packetbeat-hardware-software-requirements/271729)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 8\
**Last updated:** [May 20, 2021, 11:20pm UTC](https://discuss.elastic.co/t/packetbeat-hardware-software-requirements/271729 "2021-05-20T23:20:01Z")

</div>

I have a sensor with a i5-4590, 8GB memory running packetbeat and am still getting "dropped\_because\_of\_gaps" I've followed all the directions about enabling af\_packet, etc yet even on a low traffic link (1-5mbps) I stil…

---

## [Why stack\_trace field is not populated in discovery for filebeat-\* index pattern](https://discuss.elastic.co/t/why-stack-trace-field-is-not-populated-in-discovery-for-filebeat-index-pattern/273264)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 0\
**Last updated:** [May 18, 2021, 10:12am UTC](https://discuss.elastic.co/t/why-stack-trace-field-is-not-populated-in-discovery-for-filebeat-index-pattern/273264 "2021-05-18T10:12:35Z")

</div>

Hello, I am ingesting the java logs and when I have severe exceptions I am also having the error.stack\_trace.text field populated however I cannot see any of the error.stack\_trace nor the error.stack\_trace.textfields be…

---

## [Filebeat iptables module](https://discuss.elastic.co/t/filebeat-iptables-module/273319)

<div class="topic-metadata">

**Author:** [@bgreen](https://discuss.elastic.co/u/bgreen)\
**Replies:** 1\
**Last updated:** [May 20, 2021, 9:22pm UTC](https://discuss.elastic.co/t/filebeat-iptables-module/273319 "2021-05-20T21:22:11Z")

</div>

Someone mentioned this in a post in October 2019 but it appears no one responded so I feel like I should ask again - is there a reason the iptables module is missing in the modules.d directory?

---

## [Running ELK Stack - Lab Environment - Ubuntu](https://discuss.elastic.co/t/running-elk-stack-lab-environment-ubuntu/272827)

<div class="topic-metadata">

**Author:** [@momo1104](https://discuss.elastic.co/u/momo1104)\
**Replies:** 8\
**Last updated:** [May 20, 2021, 6:30pm UTC](https://discuss.elastic.co/t/running-elk-stack-lab-environment-ubuntu/272827 "2021-05-20T18:30:00Z")

</div>

a newbie trying to integrate zeek logs and import them to elk stack. Running a lab environment inside Ubuntu 20.04. Elk stack running using Google Cloud Platform Tried to config filebeats, but I might be getting the c…

---

## [FTP logs - Filebeat](https://discuss.elastic.co/t/ftp-logs-filebeat/273430)

<div class="topic-metadata">

**Author:** [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Replies:** 7\
**Last updated:** [May 20, 2021, 4:52pm UTC](https://discuss.elastic.co/t/ftp-logs-filebeat/273430 "2021-05-20T16:52:10Z")

</div>

Hello there, Is there a way to set Filebeat to retrieve al the files from a folder located in a FTP server? if yes, can you please give me more information on how to configure filebeat for that? if no, what is the alte…

---

## [Error initializing beat: error loading config file: stat filebeat.yml: no such file or directory](https://discuss.elastic.co/t/error-initializing-beat-error-loading-config-file-stat-filebeat-yml-no-such-file-or-directory/273415)

<div class="topic-metadata">

**Author:** [@Marc\_Aurnold](https://discuss.elastic.co/u/Marc_Aurnold)\
**Replies:** 3\
**Last updated:** [May 20, 2021, 2:28pm UTC](https://discuss.elastic.co/t/error-initializing-beat-error-loading-config-file-stat-filebeat-yml-no-such-file-or-directory/273415 "2021-05-20T14:28:31Z")

</div>

Hey Teams Elasticsearch, When I am running this command: ./filebeat -e -c filebeat.yml output: -bash: ./filebeat: cannot execute binary file: Exec format error I would like to know which advise can help me to solve …

---

## [Filebeat not writing to index](https://discuss.elastic.co/t/filebeat-not-writing-to-index/273422)

<div class="topic-metadata">

**Author:** [@aidenosi](https://discuss.elastic.co/u/aidenosi)\
**Replies:** 3\
**Last updated:** [May 20, 2021, 1:35pm UTC](https://discuss.elastic.co/t/filebeat-not-writing-to-index/273422 "2021-05-20T13:35:53Z")

</div>

Hello, I've been trying to set up Filebeat (6.8.0) on our Linux machines for a few days now but keep running into this issue where it seems that Filebeat stops communicating/writing to Elastic. Config below: filebeat:…

---

## [MongoDB Module - Memory / Connection issues over time](https://discuss.elastic.co/t/mongodb-module-memory-connection-issues-over-time/273512)

<div class="topic-metadata">

**Author:** [@Nessworthy](https://discuss.elastic.co/u/Nessworthy)\
**Replies:** 0\
**Last updated:** [May 20, 2021, 11:03am UTC](https://discuss.elastic.co/t/mongodb-module-memory-connection-issues-over-time/273512 "2021-05-20T11:03:17Z")

</div>

Agent OS: Amazon Linux 2 AMI 2.0.20210326.0 x86\_64 HVM gp2 Type: t3.medium (v)CPUs: 2 Memory: 4GB MongoDB Version: 4.0.19 Metricbeat Version: 6.6.0 I have the following configuration for the module: - hosts: \[…

---

## [Kubernetes Module of Metricbeat does not get metrics \[7.9.2 with Kubernetes 1.21.1\]](https://discuss.elastic.co/t/kubernetes-module-of-metricbeat-does-not-get-metrics-7-9-2-with-kubernetes-1-21-1/272996)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 0\
**Last updated:** [May 14, 2021, 8:45am UTC](https://discuss.elastic.co/t/kubernetes-module-of-metricbeat-does-not-get-metrics-7-9-2-with-kubernetes-1-21-1/272996 "2021-05-14T08:45:28Z")

</div>

Hi, everyone I have been testing with a new version of Kubernetes, in this case, 1.21.1. I use Metricbeat in order to get metrics of containers, pods and nodes. Here you are my config: apiVersion: v1 kind: ConfigMap m…

---

## [Filebeat not able to send all logs](https://discuss.elastic.co/t/filebeat-not-able-to-send-all-logs/273488)

<div class="topic-metadata">

**Author:** [@msjsitl](https://discuss.elastic.co/u/msjsitl)\
**Replies:** 0\
**Last updated:** [May 20, 2021, 8:10am UTC](https://discuss.elastic.co/t/filebeat-not-able-to-send-all-logs/273488 "2021-05-20T08:10:26Z")

</div>

Hello all, I am using filebeat 7.9.3. Recently we did load testing on our server almost 4 hours. During load testing almost 1 and GB files created every hour. File rotation policy is after every 1 hour. Before load tes…

---

## [Error 403 Forbidden when connect to Microsoft Defender API](https://discuss.elastic.co/t/error-403-forbidden-when-connect-to-microsoft-defender-api/273232)

<div class="topic-metadata">

**Author:** [@ismyhairnice](https://discuss.elastic.co/u/ismyhairnice)\
**Replies:** 0\
**Last updated:** [May 18, 2021, 6:00am UTC](https://discuss.elastic.co/t/error-403-forbidden-when-connect-to-microsoft-defender-api/273232 "2021-05-18T06:00:29Z")

</div>

Hi all I am trying to connect to Microsoft Defender API using Elastic Filebeat. I followed the instructions here https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/exposed-apis-create-app-webapp?v…

---

## [Using Keystores - not working (v6.6.0)](https://discuss.elastic.co/t/using-keystores-not-working-v6-6-0/273362)

<div class="topic-metadata">

**Author:** [@anaconda2196](https://discuss.elastic.co/u/anaconda2196)\
**Replies:** 1\
**Last updated:** [May 20, 2021, 1:49am UTC](https://discuss.elastic.co/t/using-keystores-not-working-v6-6-0/273362 "2021-05-20T01:49:58Z")

</div>

Hello, I'm trying to use a keystore value in my metricbeatbeat configuration and I can't seem to get it working... I have created initContainer in that I am just creating keystore and add my elasticsearch password in E…

---

## [Trying to setup Filebeat with ILM - enabling ILM seems to prevent index from appearing in Elastic](https://discuss.elastic.co/t/trying-to-setup-filebeat-with-ilm-enabling-ilm-seems-to-prevent-index-from-appearing-in-elastic/273211)

<div class="topic-metadata">

**Author:** [@aidenosi](https://discuss.elastic.co/u/aidenosi)\
**Replies:** 2\
**Last updated:** [May 19, 2021, 2:32pm UTC](https://discuss.elastic.co/t/trying-to-setup-filebeat-with-ilm-enabling-ilm-seems-to-prevent-index-from-appearing-in-elastic/273211 "2021-05-19T14:32:51Z")

</div>

Hello all, Been trying to set up ILM for our existing Logstash/filebeat deployments. I've successfully set it up for Logstash, but am having issues with Filebeat. Whenever I add the ILM settings to filebeat.yml, the ind…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=155)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=157)
