# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=157

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 158

---

## [Filebeat not able to send all logs](https://discuss.elastic.co/t/filebeat-not-able-to-send-all-logs/273405)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 0\
**Last updated:** [May 19, 2021, 12:50pm UTC](https://discuss.elastic.co/t/filebeat-not-able-to-send-all-logs/273405 "2021-05-19T12:50:05Z")

</div>

Hello all, I am using filebeat 7.9.3. Recently we did load testing on our server almost 4 hours. During load testing almost 1 and GB files created every hour. File rotation policy is after every 1 hour. Before load tes…

---

## [Filebeat kubernetes reuse inode](https://discuss.elastic.co/t/filebeat-kubernetes-reuse-inode/273390)

<div class="topic-metadata">

**Author:** [@mafr](https://discuss.elastic.co/u/mafr)\
**Replies:** 0\
**Last updated:** [May 19, 2021, 10:55am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-reuse-inode/273390 "2021-05-19T10:55:36Z")

</div>

Hello, i have got a kubernetes enviroment (v1.19.2) with some deployments. Filebeat autodiscover properly "detects" log files, but after first log collect , filebeat are not harvest log files again (maybe after some ti…

---

## [Filebeat and deleted files](https://discuss.elastic.co/t/filebeat-and-deleted-files/273386)

<div class="topic-metadata">

**Author:** [@flaco0](https://discuss.elastic.co/u/flaco0)\
**Replies:** 0\
**Last updated:** [May 19, 2021, 10:32am UTC](https://discuss.elastic.co/t/filebeat-and-deleted-files/273386 "2021-05-19T10:32:13Z")

</div>

Hi, I have a problem with filebeat and deleted files. I don't scrape /var/lib/docker/containers//.log path But when docker do rollup of file logs, the daemon delete file /var/lib/docker/containers//.log.9, then filebe…

---

## [Metricbeat dailing without root access](https://discuss.elastic.co/t/metricbeat-dailing-without-root-access/273302)

<div class="topic-metadata">

**Author:** [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Replies:** 2\
**Last updated:** [May 19, 2021, 10:30am UTC](https://discuss.elastic.co/t/metricbeat-dailing-without-root-access/273302 "2021-05-19T10:30:51Z")

</div>

Hi All, I tried installing metricbeat to my server where IBM MQ is also running, now when I try to start metricbeat using command line . It throws below error \[user@host:/home/user/metricbeat-7.10.0-linux-x86\_64\]$ ./me…

---

## [Cannot deploy functionbeat 7.12.1 to GCP Cloud function](https://discuss.elastic.co/t/cannot-deploy-functionbeat-7-12-1-to-gcp-cloud-function/272206)

<div class="topic-metadata">

**Author:** [@yerome](https://discuss.elastic.co/u/yerome)\
**Replies:** 1\
**Last updated:** [May 19, 2021, 9:38am UTC](https://discuss.elastic.co/t/cannot-deploy-functionbeat-7-12-1-to-gcp-cloud-function/272206 "2021-05-19T09:38:40Z")

</div>

I try to deploy functionbeat 7.12.1 on a cloud function using filebeat 7.12.1-linux-x86\_64. The deployment fail during installation : 2021-05-05T12:51:45.303Z DEBUG \[gcp.executor\] executor/executor.go:76 The executor i…

---

## [How can transfer Fail2ban logs going to Kibana](https://discuss.elastic.co/t/how-can-transfer-fail2ban-logs-going-to-kibana/273252)

<div class="topic-metadata">

**Author:** [@ememman29](https://discuss.elastic.co/u/ememman29)\
**Replies:** 2\
**Last updated:** [May 19, 2021, 2:14am UTC](https://discuss.elastic.co/t/how-can-transfer-fail2ban-logs-going-to-kibana/273252 "2021-05-19T02:14:25Z")

</div>

Hello i have a problem on how i going to transfer my fail2ban logs going to kibana visualization i already installed the filebeat log shipper on my server where fail2ban is installed but the problem is only the message i…

---

## [Elastic Agent removes all metricbeat unix-sock endpoint when any metricbeat is killed](https://discuss.elastic.co/t/elastic-agent-removes-all-metricbeat-unix-sock-endpoint-when-any-metricbeat-is-killed/271581)

<div class="topic-metadata">

**Author:** [@buptubuntu](https://discuss.elastic.co/u/buptubuntu)\
**Replies:** 1\
**Last updated:** [May 18, 2021, 9:58am UTC](https://discuss.elastic.co/t/elastic-agent-removes-all-metricbeat-unix-sock-endpoint-when-any-metricbeat-is-killed/271581 "2021-05-18T09:58:16Z")

</div>

Hi, all We try to use elastic agent to manage beats, and configured agent.monitoring to use a sidecar metricbeat to monitor the managed beats，after all the beats are started，if we kill the sidecar metricbeat process，the…

---

## [Error retrieving logs when using Defender ATP (under Microsoft Module)](https://discuss.elastic.co/t/error-retrieving-logs-when-using-defender-atp-under-microsoft-module/273225)

<div class="topic-metadata">

**Author:** [@ismyhairnice](https://discuss.elastic.co/u/ismyhairnice)\
**Replies:** 0\
**Last updated:** [May 18, 2021, 1:06am UTC](https://discuss.elastic.co/t/error-retrieving-logs-when-using-defender-atp-under-microsoft-module/273225 "2021-05-18T01:06:16Z")

</div>

Hi all I am trying to retrieve some Defender ATP logs from Azure using Microsoft Module and encountered error. Current Filebeat version is 7.12. 2021-05-10T13:01:17.495+0800 ERROR \[input.httpjson-cursor\] v2/reques…

---

## [Create daily index with ILM](https://discuss.elastic.co/t/create-daily-index-with-ilm/273199)

<div class="topic-metadata">

**Author:** [@Matteo\_Rainieri](https://discuss.elastic.co/u/Matteo_Rainieri)\
**Replies:** 1\
**Last updated:** [May 17, 2021, 10:59pm UTC](https://discuss.elastic.co/t/create-daily-index-with-ilm/273199 "2021-05-17T22:59:21Z")

</div>

Hello there. I got a simple question: When i'm using filebeat, i would like to create a daily index and use index lifecycle policies. Im currently using ilm with this settings in filebeat.yml: setup.ilm.enabled: auto…

---

## [Mapping Winlogbeat old version to newest ECS](https://discuss.elastic.co/t/mapping-winlogbeat-old-version-to-newest-ecs/272625)

<div class="topic-metadata">

**Author:** [@Kambing](https://discuss.elastic.co/u/Kambing)\
**Replies:** 2\
**Last updated:** [May 17, 2021, 7:32pm UTC](https://discuss.elastic.co/t/mapping-winlogbeat-old-version-to-newest-ecs/272625 "2021-05-17T19:32:34Z")

</div>

Hi, I have hundreds windows server in production with variety of windows version from windows server 2003 to the windows server 2019 I had tried to install winlogbeat 7.12.1 for windows server 2003 but there's always an…

---

## [Log4j socket appender - filebeat](https://discuss.elastic.co/t/log4j-socket-appender-filebeat/273205)

<div class="topic-metadata">

**Author:** [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Replies:** 0\
**Last updated:** [May 17, 2021, 5:25pm UTC](https://discuss.elastic.co/t/log4j-socket-appender-filebeat/273205 "2021-05-17T17:25:05Z")

</div>

Hello there, I want to use filebeat to collect log4j logs and send directly to Elasticsearch. I tried to find some relevant information but mostly it is about Logstash. can anyone please give me more information on thi…

---

## [Measure network jitter and packet retransmits/drops](https://discuss.elastic.co/t/measure-network-jitter-and-packet-retransmits-drops/272946)

<div class="topic-metadata">

**Author:** [@Tydorius](https://discuss.elastic.co/u/Tydorius)\
**Replies:** 8\
**Last updated:** [May 17, 2021, 5:08pm UTC](https://discuss.elastic.co/t/measure-network-jitter-and-packet-retransmits-drops/272946 "2021-05-17T17:08:28Z")

</div>

I am working on an Elastic Stack that will be used to measure network activity in a testbed for various pieces of equipment. My current hurdle is around measuring jitter and packet retransmits and drops. Has anyone use…

---

## [Unable to connect to ibm\_mq from metricbeat](https://discuss.elastic.co/t/unable-to-connect-to-ibm-mq-from-metricbeat/273188)

<div class="topic-metadata">

**Author:** [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Replies:** 0\
**Last updated:** [May 17, 2021, 2:57pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-ibm-mq-from-metricbeat/273188 "2021-05-17T14:57:36Z")

</div>

Hi All, I am trying to connect to IBM MQ from metricbeat, in logstash, I have provided all the values required to connect to a queue manager like below :factory: com.ibm.mq.jms.MQQueueConnectionFactory :queue\_manager…

---

## [Metricbeat stuck on "net/http: request canceled (Client.Timeout exceeded while awaiting headers)"](https://discuss.elastic.co/t/metricbeat-stuck-on-net-http-request-canceled-client-timeout-exceeded-while-awaiting-headers/273177)

<div class="topic-metadata">

**Author:** [@just-a-devops-mby](https://discuss.elastic.co/u/just-a-devops-mby)\
**Replies:** 2\
**Last updated:** [May 17, 2021, 2:23pm UTC](https://discuss.elastic.co/t/metricbeat-stuck-on-net-http-request-canceled-client-timeout-exceeded-while-awaiting-headers/273177 "2021-05-17T14:23:05Z")

</div>

Hi! I'm having trouble with loading template into Elasticsearch. My cluster currently contains only one VM. Since i finished it's set up i moved into shipping data from the external VM via Metricbeat... and it didn't …

---

## [Output - support of keydb](https://discuss.elastic.co/t/output-support-of-keydb/273145)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 0\
**Last updated:** [May 17, 2021, 8:57am UTC](https://discuss.elastic.co/t/output-support-of-keydb/273145 "2021-05-17T08:57:55Z")

</div>

Hello, do you plan to support KEYDB (fork of Redis) as a output of Beats?

---

## [Filebeat dropping events](https://discuss.elastic.co/t/filebeat-dropping-events/271653)

<div class="topic-metadata">

**Author:** [@smanoranjan005](https://discuss.elastic.co/u/smanoranjan005)\
**Replies:** 6\
**Last updated:** [May 17, 2021, 7:50am UTC](https://discuss.elastic.co/t/filebeat-dropping-events/271653 "2021-05-17T07:50:38Z")

</div>

Hi, I am using filebeat as daemonset in Kubernetes to transfer application logs to Logstash to Elasticsearch. But the issue here is there is some data drop during this transfer to ES. There is only one filter in filebe…

---

## [How to avoid outputting filebeat logs to /var/log/messages](https://discuss.elastic.co/t/how-to-avoid-outputting-filebeat-logs-to-var-log-messages/272642)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 2\
**Last updated:** [May 17, 2021, 7:31am UTC](https://discuss.elastic.co/t/how-to-avoid-outputting-filebeat-logs-to-var-log-messages/272642 "2021-05-17T07:31:54Z")

</div>

I do not want to output filebeat logs to /var/log/messages. So, I configured to\_syslog and Environment, referring to the following article. However, they do not work. Can you please tell me how to do it correctly? H…

---

## [What's the best practice to use metricbeat for prometeus protocol collection on Kubernetes cluster](https://discuss.elastic.co/t/whats-the-best-practice-to-use-metricbeat-for-prometeus-protocol-collection-on-kubernetes-cluster/273096)

<div class="topic-metadata">

**Author:** [@shoothzj](https://discuss.elastic.co/u/shoothzj)\
**Replies:** 0\
**Last updated:** [May 16, 2021, 1:04am UTC](https://discuss.elastic.co/t/whats-the-best-practice-to-use-metricbeat-for-prometeus-protocol-collection-on-kubernetes-cluster/273096 "2021-05-16T01:04:54Z")

</div>

We are deploying metricbeat as a daemon set to collect vm、docker metrics. It works well. If we want metricbeat to collect Pulsar、Flink(they are Deploy on k8s）'s prometheus metrics. Currently, I found that metricbeat pr…

---

## [Metricbeat Index name not looking quite right](https://discuss.elastic.co/t/metricbeat-index-name-not-looking-quite-right/273086)

<div class="topic-metadata">

**Author:** [@mhare](https://discuss.elastic.co/u/mhare)\
**Replies:** 3\
**Last updated:** [May 15, 2021, 6:09pm UTC](https://discuss.elastic.co/t/metricbeat-index-name-not-looking-quite-right/273086 "2021-05-15T18:09:04Z")

</div>

I am running v7.7.1 of the stack on a Windows 10 box. It is a pretty basic install, not a lot of customization. I ingest both from filebeat and metricbeat. Filebeat did what I thought it would do, create an Index as fil…

---

## [Filebeat traefik access log into elk](https://discuss.elastic.co/t/filebeat-traefik-access-log-into-elk/272824)

<div class="topic-metadata">

**Author:** [@Enrico\_Gherardo](https://discuss.elastic.co/u/Enrico_Gherardo)\
**Replies:** 1\
**Last updated:** [May 15, 2021, 12:40pm UTC](https://discuss.elastic.co/t/filebeat-traefik-access-log-into-elk/272824 "2021-05-15T12:40:26Z")

</div>

Hello, I'm just starting to use filebeat 7.12 and I'm having problems sending traefik access log to elk. I was able to send the json log to elk with this snippet in the main config filebeat.yml : filebeat.inputs: - ty…

---

## [Collecting docker logs using Filebeats](https://discuss.elastic.co/t/collecting-docker-logs-using-filebeats/272512)

<div class="topic-metadata">

**Author:** [@sfigueroa](https://discuss.elastic.co/u/sfigueroa)\
**Replies:** 4\
**Last updated:** [May 15, 2021, 6:30am UTC](https://discuss.elastic.co/t/collecting-docker-logs-using-filebeats/272512 "2021-05-15T06:30:24Z")

</div>

Hi, I am trying to collect this kind of logs from a docker container: \[1620579277\]\[642e7adc-74e1-4b89-a705-d271846f7ebc\]\[channel1\]\[afca2a976fa482f429fff4a38e2ea49f337a8af1b5dca0de90410ecc792fd5a4\]\[usecase\_cc\]\[set\] ex02 …

---

## [Any way to make winlogbeat config case-insensitive?](https://discuss.elastic.co/t/any-way-to-make-winlogbeat-config-case-insensitive/273032)

<div class="topic-metadata">

**Author:** [@reconluke](https://discuss.elastic.co/u/reconluke)\
**Replies:** 3\
**Last updated:** [May 14, 2021, 6:08pm UTC](https://discuss.elastic.co/t/any-way-to-make-winlogbeat-config-case-insensitive/273032 "2021-05-14T18:08:59Z")

</div>

The title pretty much says it all. I am trying to figure out if there is a way to make my winlogbeat config conditions case insensitive so when I want to exclude something for lets say a file path, I do not have to add a…

---

## [Filebeat Doesn't open port 5066](https://discuss.elastic.co/t/filebeat-doesnt-open-port-5066/273042)

<div class="topic-metadata">

**Author:** [@Matteo\_Rainieri](https://discuss.elastic.co/u/Matteo_Rainieri)\
**Replies:** 1\
**Last updated:** [May 14, 2021, 4:32pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-open-port-5066/273042 "2021-05-14T16:32:19Z")

</div>

Hello there. I'm facing a problem i cannot resolve. I' using filebeat for shipping elasticsearch, kibana and logstash logs and i also use metricbeat for monitor them. In filebeat.yml i have "http.enabled: true" to ope…

---

## [Elasticsearch output for filebeat to get only nginx logs](https://discuss.elastic.co/t/elasticsearch-output-for-filebeat-to-get-only-nginx-logs/272802)

<div class="topic-metadata">

**Author:** [@Sandeep4](https://discuss.elastic.co/u/Sandeep4)\
**Replies:** 0\
**Last updated:** [May 12, 2021, 11:41am UTC](https://discuss.elastic.co/t/elasticsearch-output-for-filebeat-to-get-only-nginx-logs/272802 "2021-05-12T11:41:12Z")

</div>

Hi Everyone, Currently I see all kinds of logs in default logstash index, I have to channelize only nginx logs from filebeat to elastic search. Tried by enabling nginx module, but that did not change anything. Do we h…

---

## [Standalone cluster in Kibana stack monitoring page](https://discuss.elastic.co/t/standalone-cluster-in-kibana-stack-monitoring-page/272960)

<div class="topic-metadata">

**Author:** [@Tyler1](https://discuss.elastic.co/u/Tyler1)\
**Replies:** 0\
**Last updated:** [May 13, 2021, 9:27pm UTC](https://discuss.elastic.co/t/standalone-cluster-in-kibana-stack-monitoring-page/272960 "2021-05-13T21:27:13Z")

</div>

How do I get rid of standalone cluster on kibana stack monitoring page which lists logstash nodes that are also showing metricbeat stats under their own production clusters on same monitoring page anyway. I tried added m…

---

## [HearBeat monitor throwing IP SANS error](https://discuss.elastic.co/t/hearbeat-monitor-throwing-ip-sans-error/272916)

<div class="topic-metadata">

**Author:** [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Replies:** 1\
**Last updated:** [May 13, 2021, 8:17pm UTC](https://discuss.elastic.co/t/hearbeat-monitor-throwing-ip-sans-error/272916 "2021-05-13T20:17:41Z")

</div>

Hi All, I am trying to implement hearbeat monitor for one of my application and I am getting below error. I have done below configuration - type: http # List or urls to query urls: \["https://x.x.x.x:9090"\] # Co…

---

## [Error parsing logs Filebeat - APACHE module](https://discuss.elastic.co/t/error-parsing-logs-filebeat-apache-module/272889)

<div class="topic-metadata">

**Author:** [@marti1](https://discuss.elastic.co/u/marti1)\
**Replies:** 1\
**Last updated:** [May 13, 2021, 10:44am UTC](https://discuss.elastic.co/t/error-parsing-logs-filebeat-apache-module/272889 "2021-05-13T10:44:10Z")

</div>

Hi everyone, I have configured my Apache server with Filebeat apache module to load ACCESS and ERROR logs to Elasticsearch but is not working properly, all the logs are not parsed (are raw). This is my configuration: A…

---

## [How to differentiate data based on source log path](https://discuss.elastic.co/t/how-to-differentiate-data-based-on-source-log-path/272872)

<div class="topic-metadata">

**Author:** [@Michael\_M](https://discuss.elastic.co/u/Michael_M)\
**Replies:** 0\
**Last updated:** [May 13, 2021, 2:16am UTC](https://discuss.elastic.co/t/how-to-differentiate-data-based-on-source-log-path/272872 "2021-05-13T02:16:45Z")

</div>

I am new to elastic beats and would like to know if and how to configure file beat so that harvested data contains reference (e.g. full path) to the original log file? I have multiple applications and versions of the sa…

---

## [Duplicate file entries in registry file on system with RAID 5](https://discuss.elastic.co/t/duplicate-file-entries-in-registry-file-on-system-with-raid-5/272856)

<div class="topic-metadata">

**Author:** [@Misha\_Diordienko](https://discuss.elastic.co/u/Misha_Diordienko)\
**Replies:** 0\
**Last updated:** [May 12, 2021, 9:55pm UTC](https://discuss.elastic.co/t/duplicate-file-entries-in-registry-file-on-system-with-raid-5/272856 "2021-05-12T21:55:54Z")

</div>

Hi, Debian 10 linux with software raid 5, 3 ssd disks: ARRAY /dev/md1 level=raid1 num-devices=3 metadata=0.90 UUID=6a96a1c6:818e4a81:5ca9666b:e9209fa3 ARRAY /dev/md2 level=raid1 num-devices=3 metadata=0.90 UUID…

---

## [Error: Exiting: error creating reader for journal: failed to open journal file](https://discuss.elastic.co/t/error-exiting-error-creating-reader-for-journal-failed-to-open-journal-file/218318)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 3\
**Last updated:** [May 12, 2021, 9:50pm UTC](https://discuss.elastic.co/t/error-exiting-error-creating-reader-for-journal-failed-to-open-journal-file/218318 "2021-05-12T21:50:03Z")

</div>

Hi, i am using Elasticstack of version 7.1.1 with x-pack installed. I am trying to run journaldbeat 7.1.1 on my system but its showing the following error 2020-02-07T15:42:10.886+0530 INFO instance/beat.go:280 Setup B…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=156)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=158)
