# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=159

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 160

---

## [Filebeat: How to export logs of specific pods](https://discuss.elastic.co/t/filebeat-how-to-export-logs-of-specific-pods/272444)

<div class="topic-metadata">

**Author:** [@vrathore18](https://discuss.elastic.co/u/vrathore18)\
**Replies:** 0\
**Last updated:** [May 7, 2021, 7:33pm UTC](https://discuss.elastic.co/t/filebeat-how-to-export-logs-of-specific-pods/272444 "2021-05-07T19:33:07Z")

</div>

This is my filebeat config map. apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: kube-system labels: k8s-app: filebeat data: filebeat.yml: |- filebeat.inputs: - type: contain…

---

## [Iptables module unable to parse some logs from UDM-Pro device](https://discuss.elastic.co/t/iptables-module-unable-to-parse-some-logs-from-udm-pro-device/272335)

<div class="topic-metadata">

**Author:** [@JAndritsch](https://discuss.elastic.co/u/JAndritsch)\
**Replies:** 2\
**Last updated:** [May 7, 2021, 2:11pm UTC](https://discuss.elastic.co/t/iptables-module-unable-to-parse-some-logs-from-udm-pro-device/272335 "2021-05-07T14:11:50Z")

</div>

I'm using the Iptables module of Filebeat (master branch on Github, commit ddcf8f1aa) to receive and parse logs from a Unifi Dream Machine Pro over UDP. My module configuration looks like this: - module: iptables log:…

---

## [Filebeat Processors - Can i condition between two vars?](https://discuss.elastic.co/t/filebeat-processors-can-i-condition-between-two-vars/272367)

<div class="topic-metadata">

**Author:** [@ronh](https://discuss.elastic.co/u/ronh)\
**Replies:** 5\
**Last updated:** [May 7, 2021, 2:07pm UTC](https://discuss.elastic.co/t/filebeat-processors-can-i-condition-between-two-vars/272367 "2021-05-07T14:07:08Z")

</div>

Hello, Is it possible to compare between 2 vars in input data? For example: processors: - add\_host\_metadata: netinfo.enabled: true - if: contains: host.ip: $source.ip then: - add\_fie…

---

## [Metricbeat: Cannot index event publisher.Event for org\_opencontainers\_image\_created](https://discuss.elastic.co/t/metricbeat-cannot-index-event-publisher-event-for-org-opencontainers-image-created/272127)

<div class="topic-metadata">

**Author:** [@jmcclure](https://discuss.elastic.co/u/jmcclure)\
**Replies:** 2\
**Last updated:** [May 7, 2021, 12:49pm UTC](https://discuss.elastic.co/t/metricbeat-cannot-index-event-publisher-event-for-org-opencontainers-image-created/272127 "2021-05-07T12:49:37Z")

</div>

Elasticsearch 7.9.3 (OSS) Kibana 7.9.3 (OSS) Metricbeat 7.9.3 Hi, I have the Metricbeat docker module enabled with a number of metricsets. --- - module: docker metricsets: - container - info - cpu …

---

## [Kibana Field name mismatching](https://discuss.elastic.co/t/kibana-field-name-mismatching/272382)

<div class="topic-metadata">

**Author:** [@Nil\_Battey\_Sannata](https://discuss.elastic.co/u/Nil_Battey_Sannata)\
**Replies:** 4\
**Last updated:** [May 7, 2021, 10:39am UTC](https://discuss.elastic.co/t/kibana-field-name-mismatching/272382 "2021-05-07T10:39:20Z")

</div>

How to fix Kibana field name mismatch in Indexing? In below image, For ex. the data which is in winlog.event\_data.Signature and winlog.event\_data.SignatureStatus I want to be in dll.code\_signature.subject\_name and dll.co…

---

## [Filebeat Parsing issue with module aws](https://discuss.elastic.co/t/filebeat-parsing-issue-with-module-aws/271374)

<div class="topic-metadata">

**Author:** [@AJ18](https://discuss.elastic.co/u/AJ18)\
**Replies:** 9\
**Last updated:** [May 7, 2021, 10:36am UTC](https://discuss.elastic.co/t/filebeat-parsing-issue-with-module-aws/271374 "2021-05-07T10:36:29Z")

</div>

Hi, I had set up filebeat agent in my AWS account to ship logs from an S3 bucket. The s3 bucket contains Cloudtrail logs and VPC Flow Logs and has Access logging enabled. The file 'filebeat/modules.d/aws.yml' was modi…

---

## [Scan frequency working](https://discuss.elastic.co/t/scan-frequency-working/272406)

<div class="topic-metadata">

**Author:** [@Madhuri\_Penmatsa](https://discuss.elastic.co/u/Madhuri_Penmatsa)\
**Replies:** 0\
**Last updated:** [May 7, 2021, 10:34am UTC](https://discuss.elastic.co/t/scan-frequency-working/272406 "2021-05-07T10:34:41Z")

</div>

I'm new to filebeat and wanted to know how scan\_frequency in filebeat actually works. When using the default scan frequency which is 10s, Our files of size around 400MB (sending the whole file at once using the multili…

---

## [Registry.data.string is null](https://discuss.elastic.co/t/registry-data-string-is-null/272085)

<div class="topic-metadata">

**Author:** [@Nil\_Battey\_Sannata](https://discuss.elastic.co/u/Nil_Battey_Sannata)\
**Replies:** 3\
**Last updated:** [May 7, 2021, 9:39am UTC](https://discuss.elastic.co/t/registry-data-string-is-null/272085 "2021-05-07T09:39:36Z")

</div>

As per below logs from endpoint the field name from kibana registry.data.string should contain the value of data string from ImagePath, but it is giving Null value. the data which I want to be in registry.data.string it …

---

## [How to filter out logs from modules.d configuration?](https://discuss.elastic.co/t/how-to-filter-out-logs-from-modules-d-configuration/272365)

<div class="topic-metadata">

**Author:** [@hazcod](https://discuss.elastic.co/u/hazcod)\
**Replies:** 1\
**Last updated:** [May 7, 2021, 7:50am UTC](https://discuss.elastic.co/t/how-to-filter-out-logs-from-modules-d-configuration/272365 "2021-05-07T07:50:57Z")

</div>

Hi guys, So I am using the checkpoint module, configured in the modules.d directory. Is there a way to omit certain log lines using only the modules.d configuration? Thanks.

---

## [Ability to supply path to custom module?](https://discuss.elastic.co/t/ability-to-supply-path-to-custom-module/271615)

<div class="topic-metadata">

**Author:** [@hazcod](https://discuss.elastic.co/u/hazcod)\
**Replies:** 2\
**Last updated:** [May 7, 2021, 5:40am UTC](https://discuss.elastic.co/t/ability-to-supply-path-to-custom-module/271615 "2021-05-07T05:40:11Z")

</div>

Hi, So we developed a custom filebeat submodule which we'd like to use for filebeat. However there seems no way to specify the path to this module? We cannot copy it into /usr/share/filebeat/modules since that gets ov…

---

## [Elastic Agent fault by Fleet manager](https://discuss.elastic.co/t/elastic-agent-fault-by-fleet-manager/272347)

<div class="topic-metadata">

**Author:** [@root](https://discuss.elastic.co/u/root)\
**Replies:** 0\
**Last updated:** [May 7, 2021, 1:44am UTC](https://discuss.elastic.co/t/elastic-agent-fault-by-fleet-manager/272347 "2021-05-07T01:44:19Z")

</div>

09:30:24.756 elastic\_agent \[elastic\_agent\]\[info\] The Elastic Agent is currently in BETA and should not be used in production 09:30:24.756 elastic\_agent \[elastic\_agent\]\[info\] The Elastic Agent is currently in BETA an…

---

## [Filebeat: Fortinet Module not processing data as it should](https://discuss.elastic.co/t/filebeat-fortinet-module-not-processing-data-as-it-should/272102)

<div class="topic-metadata">

**Author:** [@b0r1s](https://discuss.elastic.co/u/b0r1s)\
**Replies:** 14\
**Last updated:** [May 6, 2021, 9:58pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-not-processing-data-as-it-should/272102 "2021-05-06T21:58:32Z")

</div>

I think I have a similar problem from this post but I can't solve with the solution on the post. Here is my filebeat.yml: # ============================== Filebeat modules ============================== filebeat.confi…

---

## [No Data for Metricbeat AWS billing estimated charges](https://discuss.elastic.co/t/no-data-for-metricbeat-aws-billing-estimated-charges/272132)

<div class="topic-metadata">

**Author:** [@Sathish22](https://discuss.elastic.co/u/Sathish22)\
**Replies:** 2\
**Last updated:** [May 6, 2021, 4:05pm UTC](https://discuss.elastic.co/t/no-data-for-metricbeat-aws-billing-estimated-charges/272132 "2021-05-06T16:05:00Z")

</div>

Dear Team, We have configured Metricbeat with AWS module for AWS billing metrics PFB configuration - module: aws period: 24h metricsets: - billing role\_arn: xxxxxxxxxxxxxxxx cost\_explorer\_config: group\_…

---

## [Heartbeat issue when matching on response body string negatively](https://discuss.elastic.co/t/heartbeat-issue-when-matching-on-response-body-string-negatively/270542)

<div class="topic-metadata">

**Author:** [@Nipun1](https://discuss.elastic.co/u/Nipun1)\
**Replies:** 1\
**Last updated:** [May 6, 2021, 3:26pm UTC](https://discuss.elastic.co/t/heartbeat-issue-when-matching-on-response-body-string-negatively/270542 "2021-05-06T15:26:16Z")

</div>

Hi all, I am setting up a heartbeat monitor (version 7.5.0) for an API whose response can be of the following types #response is okay, API can be considered up { "usersList": \[ { "firstName": "L…

---

## [Filebeat dissect line break](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274)

<div class="topic-metadata">

**Author:** [@mostpha456](https://discuss.elastic.co/u/mostpha456)\
**Replies:** 6\
**Last updated:** [May 6, 2021, 2:06pm UTC](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274 "2021-05-06T14:06:11Z")

</div>

Hello, i am using dissect processor to parse a multiline log. i got the error dissect\_parsing\_error, i think it s because of the \\n. Do you have any idea where i can find any exemple of filebeat dissect for multiline. …

---

## [Metricbeat in Kubernetes only get processes from the container and not the host (Windows)](https://discuss.elastic.co/t/metricbeat-in-kubernetes-only-get-processes-from-the-container-and-not-the-host-windows/272128)

<div class="topic-metadata">

**Author:** [@jproulx](https://discuss.elastic.co/u/jproulx)\
**Replies:** 2\
**Last updated:** [May 6, 2021, 1:22pm UTC](https://discuss.elastic.co/t/metricbeat-in-kubernetes-only-get-processes-from-the-container-and-not-the-host-windows/272128 "2021-05-06T13:22:14Z")

</div>

Context I am trying to setup metricbeat 7.12 as a DaemonSet in an Azure Kubernetes Cluster on a Nano Windows Server host. I based my Kubernetes config of metricbeat on this document. In this document, the ConfigMap nam…

---

## [Log-rotation with Beats](https://discuss.elastic.co/t/log-rotation-with-beats/272165)

<div class="topic-metadata">

**Author:** [@Keerthana\_Manoharan](https://discuss.elastic.co/u/Keerthana_Manoharan)\
**Replies:** 1\
**Last updated:** [May 6, 2021, 8:27am UTC](https://discuss.elastic.co/t/log-rotation-with-beats/272165 "2021-05-06T08:27:10Z")

</div>

I am trying to figure out the best possible method for enabling log rotation. The beats is deployed in Kubernetes as daemon set, its input file is stored in a shared location accessed by multiple pods, writing to it. A…

---

## [Can Heartbeat use basic auth to log into a website](https://discuss.elastic.co/t/can-heartbeat-use-basic-auth-to-log-into-a-website/270208)

<div class="topic-metadata">

**Author:** [@Simon\_Becker](https://discuss.elastic.co/u/Simon_Becker)\
**Replies:** 3\
**Last updated:** [May 6, 2021, 5:34am UTC](https://discuss.elastic.co/t/can-heartbeat-use-basic-auth-to-log-into-a-website/270208 "2021-05-06T05:34:34Z")

</div>

Hello Elasticians, I am trying out the new Synthetics Module in Heartbeat. The webserver I am trying to check has a basic auth feature implemented. So before I can access the webpage I need to use user and password to …

---

## [How to connect beats to elasticsearch, when elasticsearch using ssl/tls](https://discuss.elastic.co/t/how-to-connect-beats-to-elasticsearch-when-elasticsearch-using-ssl-tls/271735)

<div class="topic-metadata">

**Author:** [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Replies:** 19\
**Last updated:** [May 6, 2021, 2:36am UTC](https://discuss.elastic.co/t/how-to-connect-beats-to-elasticsearch-when-elasticsearch-using-ssl-tls/271735 "2021-05-06T02:36:27Z")

</div>

what should i do to make all of my beat can send log to my elasticsearch since i setting ssl/tls to my elasticsearch. this my configuration and the log ##################### Filebeat Configuration Example ##############…

---

## [Issues with starting Filebeat 7.9.1](https://discuss.elastic.co/t/issues-with-starting-filebeat-7-9-1/272215)

<div class="topic-metadata">

**Author:** [@OtienoC](https://discuss.elastic.co/u/OtienoC)\
**Replies:** 1\
**Last updated:** [May 6, 2021, 12:11am UTC](https://discuss.elastic.co/t/issues-with-starting-filebeat-7-9-1/272215 "2021-05-06T00:11:33Z")

</div>

Having issues starting filebeat installed in RHEL8 . Error is related to kibana wanting permissions. Output error is below: Last login: Tue Apr 27 14:39:31 2021 from 10.147.4.244 # ausearch -c 'filebeat' --raw | audit2…

---

## [Filebeat Syslog isn't Opening Port](https://discuss.elastic.co/t/filebeat-syslog-isnt-opening-port/272126)

<div class="topic-metadata">

**Author:** [@odin-bb](https://discuss.elastic.co/u/odin-bb)\
**Replies:** 4\
**Last updated:** [May 5, 2021, 11:59pm UTC](https://discuss.elastic.co/t/filebeat-syslog-isnt-opening-port/272126 "2021-05-05T23:59:37Z")

</div>

Good Afternoon, First off, thank you for whatever help/suggestions you provide. I recently posted in the r/elasticsearch trying to understand the difference between logstash and filebeat and was greatly helped by someo…

---

## [Filebeat - regarding Harvestor & Registry](https://discuss.elastic.co/t/filebeat-regarding-harvestor-registry/272205)

<div class="topic-metadata">

**Author:** [@tushar\_saurabh](https://discuss.elastic.co/u/tushar_saurabh)\
**Replies:** 0\
**Last updated:** [May 5, 2021, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-regarding-harvestor-registry/272205 "2021-05-05T14:23:14Z")

</div>

I an new to Elastic world and have been reading the documents and analyzing the current ELK setup. Filebeat version is 6.0. Question # 1: Harvestor is created for each file. Harvestor is closed if it is inactive. The cl…

---

## [Filebeat stops harvesting files](https://discuss.elastic.co/t/filebeat-stops-harvesting-files/272190)

<div class="topic-metadata">

**Author:** [@boernd](https://discuss.elastic.co/u/boernd)\
**Replies:** 0\
**Last updated:** [May 5, 2021, 1:22pm UTC](https://discuss.elastic.co/t/filebeat-stops-harvesting-files/272190 "2021-05-05T13:22:40Z")

</div>

Filebeat vesion: 7.10 Filebeat sometimes throws the following errors and stops harvesting a file: Harvester could not be started on existing file: /var/lib/docker/containers/acaeae7d8182fc7c78a5066a178593640ce4fbc920b4…

---

## [Parsing logs filebeat](https://discuss.elastic.co/t/parsing-logs-filebeat/272011)

<div class="topic-metadata">

**Author:** [@mostpha456](https://discuss.elastic.co/u/mostpha456)\
**Replies:** 3\
**Last updated:** [May 5, 2021, 12:04pm UTC](https://discuss.elastic.co/t/parsing-logs-filebeat/272011 "2021-05-05T12:04:51Z")

</div>

Hello, I m using filebeat to parse my logs I have logs of the following format: ID: xxx Date: xxx Message: xxx is it possible to send the logs to elasticsearch by adding the fields ID, Date, Message and their value…

---

## [EC on k8s - Beats dashboards not showing CPU Usage data](https://discuss.elastic.co/t/ec-on-k8s-beats-dashboards-not-showing-cpu-usage-data/272122)

<div class="topic-metadata">

**Author:** [@rodwastaken](https://discuss.elastic.co/u/rodwastaken)\
**Replies:** 1\
**Last updated:** [May 5, 2021, 10:31am UTC](https://discuss.elastic.co/t/ec-on-k8s-beats-dashboards-not-showing-cpu-usage-data/272122 "2021-05-05T10:31:27Z")

</div>

Hello friends, im hoping you can guide me or help with an issue im having with metricbeats dashboard especifically and focusing on -\>""\[Metricbeat System\] Host overview ECS. Some of the gauge visualizations on the dash…

---

## [Filebeat Config Failure](https://discuss.elastic.co/t/filebeat-config-failure/272061)

<div class="topic-metadata">

**Author:** [@Himani\_Tawade](https://discuss.elastic.co/u/Himani_Tawade)\
**Replies:** 1\
**Last updated:** [May 5, 2021, 9:58am UTC](https://discuss.elastic.co/t/filebeat-config-failure/272061 "2021-05-05T09:58:42Z")

</div>

Hi All, I am pretty new to the ELK stack. I am trying to create multiple indices for different logs coming from the application. I am not using logstash and I am getting json logs from the app. But when I am trying t…

---

## [Does Filebeat take in logs missed when it is stopped?](https://discuss.elastic.co/t/does-filebeat-take-in-logs-missed-when-it-is-stopped/272130)

<div class="topic-metadata">

**Author:** [@shifenglim](https://discuss.elastic.co/u/shifenglim)\
**Replies:** 3\
**Last updated:** [May 5, 2021, 7:58am UTC](https://discuss.elastic.co/t/does-filebeat-take-in-logs-missed-when-it-is-stopped/272130 "2021-05-05T07:58:01Z")

</div>

I have filebeat 7.8.1 streaming logs to my elasticsearch via this setup Application -\> Logfile -\> Filebeat -\> Logstash -\> Elasticsearch The application team is concerned if Filebeat is down, it will cause logs to be mi…

---

## [Filebeat and Winlogbeat](https://discuss.elastic.co/t/filebeat-and-winlogbeat/271780)

<div class="topic-metadata">

**Author:** [@insurin](https://discuss.elastic.co/u/insurin)\
**Replies:** 6\
**Last updated:** [May 4, 2021, 11:48pm UTC](https://discuss.elastic.co/t/filebeat-and-winlogbeat/271780 "2021-05-04T23:48:41Z")

</div>

I am enrolling my Windows servers in Fleet on ELK 7.12. I can see lots of 'logs-\* via discover relating to these servers. Do I need to manually install winlogbeat and or filebeat in addition to what I already have. My c…

---

## [Apply conditions in http monitor , heartbeat](https://discuss.elastic.co/t/apply-conditions-in-http-monitor-heartbeat/270587)

<div class="topic-metadata">

**Author:** [@Kartikey\_Bhatore](https://discuss.elastic.co/u/Kartikey_Bhatore)\
**Replies:** 1\
**Last updated:** [May 4, 2021, 6:35pm UTC](https://discuss.elastic.co/t/apply-conditions-in-http-monitor-heartbeat/270587 "2021-05-04T18:35:06Z")

</div>

Hello , I am using heartbeat 6.5.3 Do we have a option to apply conditions at the time of http URL check. eg if URL1 is up then only check URL 2 , if URL2 status is also UP then only status : UP if URL1 is down then …

---

## [Fleet Agents hitting 100% CPU usage](https://discuss.elastic.co/t/fleet-agents-hitting-100-cpu-usage/271529)

<div class="topic-metadata">

**Author:** [@MichaelHuff](https://discuss.elastic.co/u/MichaelHuff)\
**Replies:** 19\
**Last updated:** [May 4, 2021, 6:18pm UTC](https://discuss.elastic.co/t/fleet-agents-hitting-100-cpu-usage/271529 "2021-05-04T18:18:48Z")

</div>

We put the elastic-agent for fleet onto our VDI infrastructure. Each VDI machine started out with 2 vCPUs and 4 GB RAM. We installed the elastic-agent through fleet. The machine performed fine for a few hours then became…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=158)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=160)
