# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=160

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 161

---

## [Filebeat setup command can not find environment variables](https://discuss.elastic.co/t/filebeat-setup-command-can-not-find-environment-variables/271550)

<div class="topic-metadata">

**Author:** [@user8753123](https://discuss.elastic.co/u/user8753123)\
**Replies:** 2\
**Last updated:** [May 4, 2021, 5:45pm UTC](https://discuss.elastic.co/t/filebeat-setup-command-can-not-find-environment-variables/271550 "2021-05-04T17:45:48Z")

</div>

Hi there, I've read up a lot of the various posts on this topic but cannot seem to find something specific to my particular issue. I've got filebeat running on centos as a service with systemd as per the docs. I'm usin…

---

## [Docker container becomes unresponsive with Elastic Logging Plugin when Elastic server is not available](https://discuss.elastic.co/t/docker-container-becomes-unresponsive-with-elastic-logging-plugin-when-elastic-server-is-not-available/271261)

<div class="topic-metadata">

**Author:** [@UnstableFractal](https://discuss.elastic.co/u/UnstableFractal)\
**Replies:** 3\
**Last updated:** [May 4, 2021, 1:17pm UTC](https://discuss.elastic.co/t/docker-container-becomes-unresponsive-with-elastic-logging-plugin-when-elastic-server-is-not-available/271261 "2021-05-04T13:17:51Z")

</div>

Sometimes a container or a series of containers becomes unresponsive when Elastic server is not available so we can't: restart/stop/kill these containers. Docker logs command is not available for these containers. Docker…

---

## [Connection error between filebeat and kibana](https://discuss.elastic.co/t/connection-error-between-filebeat-and-kibana/272058)

<div class="topic-metadata">

**Author:** [@babi2002](https://discuss.elastic.co/u/babi2002)\
**Replies:** 0\
**Last updated:** [May 4, 2021, 10:43am UTC](https://discuss.elastic.co/t/connection-error-between-filebeat-and-kibana/272058 "2021-05-04T10:43:52Z")

</div>

Hi to all, I'm a newby into the Elastic Stack. I'm installing a wazuh-manager server and I need to monitor our firewalls via syslog. I have configured Wazuh manager, and I receive syslog messages from our firewall. I'v…

---

## [Using Filebeat with ecs logging](https://discuss.elastic.co/t/using-filebeat-with-ecs-logging/272049)

<div class="topic-metadata">

**Author:** [@neko](https://discuss.elastic.co/u/neko)\
**Replies:** 0\
**Last updated:** [May 4, 2021, 8:46am UTC](https://discuss.elastic.co/t/using-filebeat-with-ecs-logging/272049 "2021-05-04T08:46:33Z")

</div>

Hi, I want to have my logs to ECS format before shipping them to elasticsearch cluster. We got a server collecting logs from different equipments, each equipment having its dedicated log directory on the server. Fileb…

---

## [Hmac hash log integrity check](https://discuss.elastic.co/t/hmac-hash-log-integrity-check/272040)

<div class="topic-metadata">

**Author:** [@syn](https://discuss.elastic.co/u/syn)\
**Replies:** 0\
**Last updated:** [May 4, 2021, 7:29am UTC](https://discuss.elastic.co/t/hmac-hash-log-integrity-check/272040 "2021-05-04T07:29:41Z")

</div>

Hi, I'm using graylog with filebeats. each line of log has a hash appended at the end. the hash is supposed to be used for data integrity check. Is there a way for the filebeats harvester to check and match the log da…

---

## [Fleets AWS Integration Clarification](https://discuss.elastic.co/t/fleets-aws-integration-clarification/271262)

<div class="topic-metadata">

**Author:** [@DaveRT](https://discuss.elastic.co/u/DaveRT)\
**Replies:** 4\
**Last updated:** [May 4, 2021, 2:09am UTC](https://discuss.elastic.co/t/fleets-aws-integration-clarification/271262 "2021-05-04T02:09:43Z")

</div>

I'm trying to test the Fleets Beta AWS integration. Initially just with CloudTrail logs before adding others. So far I have done the below: -Created IAM User -Created permissions policy with required permissions, and…

---

## [Confused about ilm, index templates and new indices](https://discuss.elastic.co/t/confused-about-ilm-index-templates-and-new-indices/271996)

<div class="topic-metadata">

**Author:** [@tterranigma](https://discuss.elastic.co/u/tterranigma)\
**Replies:** 0\
**Last updated:** [May 3, 2021, 1:57pm UTC](https://discuss.elastic.co/t/confused-about-ilm-index-templates-and-new-indices/271996 "2021-05-03T13:57:56Z")

</div>

I have a serve where I install some beats (e.g. packetbeat) but I don't enable the systemd service. I only use packetbeat setup --index-management on this server so that the packetbeat index template and the ILM policy g…

---

## [Managing Endpoints Monitored by Heartbeat](https://discuss.elastic.co/t/managing-endpoints-monitored-by-heartbeat/271019)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 1\
**Last updated:** [May 3, 2021, 8:47pm UTC](https://discuss.elastic.co/t/managing-endpoints-monitored-by-heartbeat/271019 "2021-05-03T20:47:46Z")

</div>

Is a more dynamic way to manage hostnames or IPs monitored by Heartbeat other than putting them in the hosts list in the files found in the monitors.d folder? There appears to be a character limit for that array, which i…

---

## [Metricbeat for MySQL fails - "missing required field accessing '0.queries'"](https://discuss.elastic.co/t/metricbeat-for-mysql-fails-missing-required-field-accessing-0-queries/271895)

<div class="topic-metadata">

**Author:** [@rudimk](https://discuss.elastic.co/u/rudimk)\
**Replies:** 2\
**Last updated:** [May 3, 2021, 8:33pm UTC](https://discuss.elastic.co/t/metricbeat-for-mysql-fails-missing-required-field-accessing-0-queries/271895 "2021-05-03T20:33:31Z")

</div>

Hello! I'm setting up Metricbeats on Ubuntu 18.04 to track metrics for a MySQL database. Unfortunately, starting the agent fails with the following error: May 02 11:08:07 ubuntu metricbeat\[69057\]: 2021-05-02T11:08:07.9…

---

## [Can't setup filebeat](https://discuss.elastic.co/t/cant-setup-filebeat/271843)

<div class="topic-metadata">

**Author:** [@angeling](https://discuss.elastic.co/u/angeling)\
**Replies:** 3\
**Last updated:** [May 3, 2021, 2:56pm UTC](https://discuss.elastic.co/t/cant-setup-filebeat/271843 "2021-05-03T14:56:55Z")

</div>

Can anyone help me? I've an elk intance, it's working well, but when I try to setup a new filebeat in another instance it throws me the following: I read that I could remove the filebeat index and then it would work f…

---

## [Filebeat setup without Kibana?](https://discuss.elastic.co/t/filebeat-setup-without-kibana/271958)

<div class="topic-metadata">

**Author:** [@davidwhthomas](https://discuss.elastic.co/u/davidwhthomas)\
**Replies:** 2\
**Last updated:** [May 3, 2021, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-setup-without-kibana/271958 "2021-05-03T14:31:31Z")

</div>

Working on a setup where log data is stored in elasticsearch using filebeat. However, we don't need Kibana (lovely although it is) for this application. The data is queried separately via an API. I read: Configure Kiba…

---

## [Implications of using ECK Beats to write to logs-\* metrics-\*](https://discuss.elastic.co/t/implications-of-using-eck-beats-to-write-to-logs-metrics/271833)

<div class="topic-metadata">

**Author:** [@jam01](https://discuss.elastic.co/u/jam01)\
**Replies:** 3\
**Last updated:** [May 3, 2021, 1:44pm UTC](https://discuss.elastic.co/t/implications-of-using-eck-beats-to-write-to-logs-metrics/271833 "2021-05-03T13:44:32Z")

</div>

Hey guys! We've been building up our Kubernetes platform using ECK and its custom Beat resources. We recently ran into an issue where we needed to apply different ILM policies to different types of data and we found dat…

---

## [Filebeat Azure module not compatible with Maps visualisation](https://discuss.elastic.co/t/filebeat-azure-module-not-compatible-with-maps-visualisation/271910)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 3\
**Last updated:** [May 3, 2021, 1:18pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-not-compatible-with-maps-visualisation/271910 "2021-05-03T13:18:28Z")

</div>

I am using Filebeat Azure module to fetch activity logs and sign-in logs. Logstash is running between Filebeat and Elasticsearch and pushing data to a custom index cloud-audit-azure. Using a custom index to store data p…

---

## [Ship Kubernenetes events logs to kibana](https://discuss.elastic.co/t/ship-kubernenetes-events-logs-to-kibana/271388)

<div class="topic-metadata">

**Author:** [@frozen\_walker](https://discuss.elastic.co/u/frozen_walker)\
**Replies:** 0\
**Last updated:** [April 27, 2021, 1:50pm UTC](https://discuss.elastic.co/t/ship-kubernenetes-events-logs-to-kibana/271388 "2021-04-27T13:50:13Z")

</div>

How can we ship Kubernetes events logs to kibana. ie: That we can get from kubectl get events command. example output: LAST SEEN TYPE REASON OBJECT MESSAGE 47s Warning Failed p…

---

## [Ship Kubernenetes events logs to kibana](https://discuss.elastic.co/t/ship-kubernenetes-events-logs-to-kibana/271390)

<div class="topic-metadata">

**Author:** [@frozen\_walker](https://discuss.elastic.co/u/frozen_walker)\
**Replies:** 0\
**Last updated:** [April 27, 2021, 1:55pm UTC](https://discuss.elastic.co/t/ship-kubernenetes-events-logs-to-kibana/271390 "2021-04-27T13:55:37Z")

</div>

How can we ship Kubernetes events logs to kibana. ie: That we can get from kubectl get events command. example output: LAST SEEN TYPE REASON OBJECT MESSAGE 47s Warning Failed p…

---

## [Metricbeat: failed to publish events -\> security\_exception](https://discuss.elastic.co/t/metricbeat-failed-to-publish-events-security-exception/271505)

<div class="topic-metadata">

**Author:** [@sderungs](https://discuss.elastic.co/u/sderungs)\
**Replies:** 0\
**Last updated:** [April 28, 2021, 12:14pm UTC](https://discuss.elastic.co/t/metricbeat-failed-to-publish-events-security-exception/271505 "2021-04-28T12:14:32Z")

</div>

Hi, While upgrading our environment (self-hosted) from 7.8 to 7.12 I'm trying to setup Metricbeat to monitor my Elasticsearch cluster as described in the deprecation log shown on startup and in the Stack Monitoring in K…

---

## [Filebeat: Exiting: error loading config file: yaml: line 107: could not find expect ':'](https://discuss.elastic.co/t/filebeat-exiting-error-loading-config-file-yaml-line-107-could-not-find-expect/271276)

<div class="topic-metadata">

**Author:** [@itsec](https://discuss.elastic.co/u/itsec)\
**Replies:** 5\
**Last updated:** [May 3, 2021, 4:19am UTC](https://discuss.elastic.co/t/filebeat-exiting-error-loading-config-file-yaml-line-107-could-not-find-expect/271276 "2021-05-03T04:19:52Z")

</div>

Hi, i'm new to filebeat and kafka and i'm trying to learn how to send server logs to kafka. filebeat.inputs: '- type: log Change to true to enable this input configuration. enabled: true Paths that should be crawled …

---

## [How can I monitor the queue of Filebeat](https://discuss.elastic.co/t/how-can-i-monitor-the-queue-of-filebeat/271750)

<div class="topic-metadata">

**Author:** [@Ben\_Tang](https://discuss.elastic.co/u/Ben_Tang)\
**Replies:** 2\
**Last updated:** [May 2, 2021, 11:50pm UTC](https://discuss.elastic.co/t/how-can-i-monitor-the-queue-of-filebeat/271750 "2021-05-02T23:50:08Z")

</div>

I'm currently using the default setting for filebeat, and also sends the monitoring data to an Elasticsearch cluster. My workflow for logs is Filebeat -\> Logstash -\> Elasticsearch Just wondering how can we monitor the …

---

## [Filebeat Nginx ingress controller module doesn't work in 7.11+](https://discuss.elastic.co/t/filebeat-nginx-ingress-controller-module-doesnt-work-in-7-11/271804)

<div class="topic-metadata">

**Author:** [@Evgeni\_Gordeev](https://discuss.elastic.co/u/Evgeni_Gordeev)\
**Replies:** 6\
**Last updated:** [May 2, 2021, 6:36pm UTC](https://discuss.elastic.co/t/filebeat-nginx-ingress-controller-module-doesnt-work-in-7-11/271804 "2021-05-02T18:36:14Z")

</div>

This configuration used to work in Elastic Stack 7.10. It stopped in 7.11 and doesn't work in 7.12 as well. Elastic: 7.12.1 ES Helm chart: 7.12.1 Kubernetes: 1.18 ingress-nginx Helm chart: 3.19.0 (ingress-nginx contr…

---

## [Google\_workspace poll loads of data](https://discuss.elastic.co/t/google-workspace-poll-loads-of-data/268255)

<div class="topic-metadata">

**Author:** [@mkorayem](https://discuss.elastic.co/u/mkorayem)\
**Replies:** 10\
**Last updated:** [May 1, 2021, 7:41pm UTC](https://discuss.elastic.co/t/google-workspace-poll-loads-of-data/268255 "2021-05-01T19:41:11Z")

</div>

Hi, Using filebeat 7.12 and 7.11.2 google\_workspace does not respect the var.initial\_interval so it polls huge amount of data and also polls it multiple times confirmed from Google API dashboard too. \> |2021-03-24T20:3…

---

## [Does it support the collection of UDP traffic on the specified port number?](https://discuss.elastic.co/t/does-it-support-the-collection-of-udp-traffic-on-the-specified-port-number/270521)

<div class="topic-metadata">

**Author:** [@angelyouyou](https://discuss.elastic.co/u/angelyouyou)\
**Replies:** 4\
**Last updated:** [May 1, 2021, 7:05am UTC](https://discuss.elastic.co/t/does-it-support-the-collection-of-udp-traffic-on-the-specified-port-number/270521 "2021-05-01T07:05:54Z")

</div>

Does it support the collection of UDP traffic on the specified port number?

---

## [Filebeat Not Using Provided Credentials File w/ GCP Module](https://discuss.elastic.co/t/filebeat-not-using-provided-credentials-file-w-gcp-module/271801)

<div class="topic-metadata">

**Author:** [@cappy](https://discuss.elastic.co/u/cappy)\
**Replies:** 3\
**Last updated:** [May 1, 2021, 6:39am UTC](https://discuss.elastic.co/t/filebeat-not-using-provided-credentials-file-w-gcp-module/271801 "2021-05-01T06:39:19Z")

</div>

Version: 7.12.1 I am getting the following when trying to enable the GCP module, using audit, firewall, and vpcflow filesets using var.credentials\_file: /etc/filebeat/filebeat/creds.json : Exiting: Failed to start craw…

---

## [Nanosecond & filebeats & netflow](https://discuss.elastic.co/t/nanosecond-filebeats-netflow/271814)

<div class="topic-metadata">

**Author:** [@dorbye](https://discuss.elastic.co/u/dorbye)\
**Replies:** 0\
**Last updated:** [April 30, 2021, 4:34pm UTC](https://discuss.elastic.co/t/nanosecond-filebeats-netflow/271814 "2021-04-30T16:34:51Z")

</div>

Hello, I've an issue with filebeats and netflow : I use softflowd to send netflow metrics with a nanosecond precision to filebeats But, after decoding filebeats only send with a nanosecond precision : (part of htt…

---

## [Filebeat - GCP Module - No paths were defined for input accessing config](https://discuss.elastic.co/t/filebeat-gcp-module-no-paths-were-defined-for-input-accessing-config/271016)

<div class="topic-metadata">

**Author:** [@cappy](https://discuss.elastic.co/u/cappy)\
**Replies:** 2\
**Last updated:** [April 30, 2021, 2:13pm UTC](https://discuss.elastic.co/t/filebeat-gcp-module-no-paths-were-defined-for-input-accessing-config/271016 "2021-04-30T14:13:56Z")

</div>

I'm trying to use the GCP module for Filebeat 7.11.2, but when using the following config: filebeat.modules: - module: gcp audit: enabled: true var.project\_id: project1234 var.topic: topic1234 var.subs…

---

## [Filebeat Pipeline debug output Publish event](https://discuss.elastic.co/t/filebeat-pipeline-debug-output-publish-event/271522)

<div class="topic-metadata">

**Author:** [@Leon21](https://discuss.elastic.co/u/Leon21)\
**Replies:** 3\
**Last updated:** [April 30, 2021, 1:45pm UTC](https://discuss.elastic.co/t/filebeat-pipeline-debug-output-publish-event/271522 "2021-04-30T13:45:54Z")

</div>

Hi, I'm struggling with an issue in ingest pipeline for Okta module that seems not working and I could not view events on either dashboards or in Discover panel via searching. I enabled debug output of filebeat and it …

---

## [Filebeat reading entire mounted azure file from start](https://discuss.elastic.co/t/filebeat-reading-entire-mounted-azure-file-from-start/271394)

<div class="topic-metadata">

**Author:** [@dthemg](https://discuss.elastic.co/u/dthemg)\
**Replies:** 3\
**Last updated:** [April 30, 2021, 12:23pm UTC](https://discuss.elastic.co/t/filebeat-reading-entire-mounted-azure-file-from-start/271394 "2021-04-30T12:23:57Z")

</div>

Hi I have an Azure file that I want to monitor using FileBeat. I am using the helm chart for this purpose, with the following values.yaml: nodeSelector: { beta.kubernetes.io/os: linux } extraVolumes: - name: mod…

---

## [Filebeat output bad permissions](https://discuss.elastic.co/t/filebeat-output-bad-permissions/271500)

<div class="topic-metadata">

**Author:** [@seddikalaouiismaili](https://discuss.elastic.co/u/seddikalaouiismaili)\
**Replies:** 1\
**Last updated:** [April 30, 2021, 10:36am UTC](https://discuss.elastic.co/t/filebeat-output-bad-permissions/271500 "2021-04-30T10:36:42Z")

</div>

hi, These are my filebeat configuration: filebeat.inputs: - type: log paths: - /var/log/file1.log - /var/log/file2.log output.file: path: "/var/log/" filename: "all.log" permissions: 0644 rot…

---

## [Metricbeat module aws elb metricbeat](https://discuss.elastic.co/t/metricbeat-module-aws-elb-metricbeat/271658)

<div class="topic-metadata">

**Author:** [@tchek14](https://discuss.elastic.co/u/tchek14)\
**Replies:** 0\
**Last updated:** [April 29, 2021, 1:56pm UTC](https://discuss.elastic.co/t/metricbeat-module-aws-elb-metricbeat/271658 "2021-04-29T13:56:57Z")

</div>

Hi, I have configured metricbeat with aws module for elb like following: module: aws period: 5m credential\_profile\_name: wazuh shared\_credential\_file: /xxxxxx/credentials metricsets: cloudwatch metrics: namespac…

---

## [File output extension](https://discuss.elastic.co/t/file-output-extension/270940)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 1\
**Last updated:** [April 30, 2021, 2:43am UTC](https://discuss.elastic.co/t/file-output-extension/270940 "2021-04-30T02:43:04Z")

</div>

Is there a way to control the extension of the files created in the file output? I want to be able to name the files packetbeat.1.json for example rather than the default packetbeat.1 etc Also is it possible to use the…

---

## [Parsing multiple files with Filebeat](https://discuss.elastic.co/t/parsing-multiple-files-with-filebeat/271591)

<div class="topic-metadata">

**Author:** [@tkkchan](https://discuss.elastic.co/u/tkkchan)\
**Replies:** 8\
**Last updated:** [April 30, 2021, 1:20am UTC](https://discuss.elastic.co/t/parsing-multiple-files-with-filebeat/271591 "2021-04-30T01:20:29Z")

</div>

Dear all, I have several JSON files that I wish to parse with Filebeat; and I read the following: https://stackoverflow.com/questions/39983918/can-filebeat-use-multiple-config-files I used the code in the above soluti…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=159)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=161)
