# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=161

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 162

---

## [Filebeat Cisco logs in files](https://discuss.elastic.co/t/filebeat-cisco-logs-in-files/271687)

<div class="topic-metadata">

**Author:** [@Boardsec](https://discuss.elastic.co/u/Boardsec)\
**Replies:** 1\
**Last updated:** [April 29, 2021, 11:55pm UTC](https://discuss.elastic.co/t/filebeat-cisco-logs-in-files/271687 "2021-04-29T23:55:56Z")

</div>

Hi! I’m new to Filebeat, and I’d like to process some already generated ASA logs. How do I set up cisco.yml to ingest from /var/log/cisco/ instead of listening on a socket? Thanks!

---

## [Filebeat with Logstash failed to create Index](https://discuss.elastic.co/t/filebeat-with-logstash-failed-to-create-index/271561)

<div class="topic-metadata">

**Author:** [@madhug](https://discuss.elastic.co/u/madhug)\
**Replies:** 8\
**Last updated:** [April 29, 2021, 11:10pm UTC](https://discuss.elastic.co/t/filebeat-with-logstash-failed-to-create-index/271561 "2021-04-29T23:10:32Z")

</div>

Hi , I am new to ELK stack started exploring the tool. First I had setup ELK stack without filebeat everything is working fine. Wanted to explore the Filebeat after installing and configuring I do not see index create…

---

## [Metricbeat kubernetes volumes type](https://discuss.elastic.co/t/metricbeat-kubernetes-volumes-type/271720)

<div class="topic-metadata">

**Author:** [@andrask](https://discuss.elastic.co/u/andrask)\
**Replies:** 0\
**Last updated:** [April 29, 2021, 9:23pm UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-volumes-type/271720 "2021-04-29T21:23:23Z")

</div>

Metricbeat is providing numbers for volumes in my cluster. However, I find it hard to determine what type a volume is as this data is missing from the fields. Would it be possible to add the type field too? E.g. PV, Conf…

---

## [Heartbeat showing 1/2 of my nodes down](https://discuss.elastic.co/t/heartbeat-showing-1-2-of-my-nodes-down/271680)

<div class="topic-metadata">

**Author:** [@marone](https://discuss.elastic.co/u/marone)\
**Replies:** 2\
**Last updated:** [April 29, 2021, 9:20pm UTC](https://discuss.elastic.co/t/heartbeat-showing-1-2-of-my-nodes-down/271680 "2021-04-29T21:20:20Z")

</div>

Hey I have two nodes of elasticsearch running in two separate VMs in azure, I set up SSL + https for my cluster and secured kibana too running in VM1. I used self signed certificates following this doc. I used the file e…

---

## [EC2 system metrics v/s AWS metrics](https://discuss.elastic.co/t/ec2-system-metrics-v-s-aws-metrics/270598)

<div class="topic-metadata">

**Author:** [@maheshe](https://discuss.elastic.co/u/maheshe)\
**Replies:** 1\
**Last updated:** [April 29, 2021, 5:06pm UTC](https://discuss.elastic.co/t/ec2-system-metrics-v-s-aws-metrics/270598 "2021-04-29T17:06:49Z")

</div>

Using Elastic 7.9 version with 7.9 beats (EFK self managed). Monitoring AWS-EC2 instances Question: Can I just use System Module using Metric beats or AWS EC2 module is required Can you please suggest/comment what mo…

---

## [MetricSet System not being populated for Ubuntu](https://discuss.elastic.co/t/metricset-system-not-being-populated-for-ubuntu/271125)

<div class="topic-metadata">

**Author:** [@maheshe](https://discuss.elastic.co/u/maheshe)\
**Replies:** 1\
**Last updated:** [April 29, 2021, 4:54pm UTC](https://discuss.elastic.co/t/metricset-system-not-being-populated-for-ubuntu/271125 "2021-04-29T16:54:10Z")

</div>

We have configured MetricBeat(7.9 Elastic search 7.9) in the AWS-EC2 Ubuntu 20.04.1 LTS Collecting the filesystem MetricSet. The generated JSON doesn't contain the disk metrics like system.filesystem.used.pct: 0 It sho…

---

## [Need help for getting antivirus data on dashboard from a linux instance](https://discuss.elastic.co/t/need-help-for-getting-antivirus-data-on-dashboard-from-a-linux-instance/271648)

<div class="topic-metadata">

**Author:** [@Hemant\_Dhillan](https://discuss.elastic.co/u/Hemant_Dhillan)\
**Replies:** 0\
**Last updated:** [April 29, 2021, 1:24pm UTC](https://discuss.elastic.co/t/need-help-for-getting-antivirus-data-on-dashboard-from-a-linux-instance/271648 "2021-04-29T13:24:50Z")

</div>

need help in getting the antivirus data from a Linux machine which is currently running metricbeat and showing statistics on the dashboard of kibana .i 've written a small python script which is taking appropirate inform…

---

## [Provided Grok expressions do not match field value: Fortinet 7.12.1](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-fortinet-7-12-1/271523)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 8\
**Last updated:** [April 29, 2021, 1:24pm UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-fortinet-7-12-1/271523 "2021-04-29T13:24:23Z")

</div>

Hello, recently I started a module for logs from fortigate firewalls. - module: fortinet firewall: enabled: true # Set which input to use between tcp, udp (default) or file. #var.input: udp # The in…

---

## [HELP! Exiting: Error in initing input: No paths were defined for input accessing 'filebeat.prospectors.1'](https://discuss.elastic.co/t/help-exiting-error-in-initing-input-no-paths-were-defined-for-input-accessing-filebeat-prospectors-1/271528)

<div class="topic-metadata">

**Author:** [@vv007b](https://discuss.elastic.co/u/vv007b)\
**Replies:** 0\
**Last updated:** [April 28, 2021, 2:55pm UTC](https://discuss.elastic.co/t/help-exiting-error-in-initing-input-no-paths-were-defined-for-input-accessing-filebeat-prospectors-1/271528 "2021-04-28T14:55:37Z")

</div>

PS C:\\Program Files\\Filebeat\> .\\filebeat.exe -e -v 2021-04-28T17:40:17.071+0300 INFO instance/beat.go:592 Home path: \[C:\\Program Files\\Filebeat\] Config path: \[C: Program Files\\Filebeat\] Data path: \[C:\\Program …

---

## [Filebeat Azure module not supporting geoip map visualisation](https://discuss.elastic.co/t/filebeat-azure-module-not-supporting-geoip-map-visualisation/271593)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 0\
**Last updated:** [April 29, 2021, 7:27am UTC](https://discuss.elastic.co/t/filebeat-azure-module-not-supporting-geoip-map-visualisation/271593 "2021-04-29T07:27:40Z")

</div>

I am working with custom index, I copied Filbeat ingest pipeline and just modified name to use for my custom index. When data loaded, I can see geoip lookup data but when I go to create map visualisation it doesn't suppo…

---

## [\[packetbeat\]The response time collected by packetbeat and the database table information collected by MySQL is incorrect](https://discuss.elastic.co/t/packetbeat-the-response-time-collected-by-packetbeat-and-the-database-table-information-collected-by-mysql-is-incorrect/271585)

<div class="topic-metadata">

**Author:** [@q729007453](https://discuss.elastic.co/u/q729007453)\
**Replies:** 2\
**Last updated:** [April 29, 2021, 7:10am UTC](https://discuss.elastic.co/t/packetbeat-the-response-time-collected-by-packetbeat-and-the-database-table-information-collected-by-mysql-is-incorrect/271585 "2021-04-29T07:10:09Z")

</div>

As the title， Among them, the end time is earlier than the start time, and event.duration cannot be captured. and path fetches incorrectly Publish event is as follows 2021-04-28T14:53:43.296+0800 DEBUG \[processors\] pr…

---

## [Filebeat to elasticsearch configuration(mapping)](https://discuss.elastic.co/t/filebeat-to-elasticsearch-configuration-mapping/271031)

<div class="topic-metadata">

**Author:** [@tkkchan](https://discuss.elastic.co/u/tkkchan)\
**Replies:** 2\
**Last updated:** [April 29, 2021, 2:18am UTC](https://discuss.elastic.co/t/filebeat-to-elasticsearch-configuration-mapping/271031 "2021-04-29T02:18:01Z")

</div>

Dear All, I am currently trying to put some files into ES using Filebeat, and meanwhile I want to see if I can set the mapping(with Filebeat, without calling API for ES). As I see from some logstash config, there's a wa…

---

## [Can I using chinese in condition](https://discuss.elastic.co/t/can-i-using-chinese-in-condition/271339)

<div class="topic-metadata">

**Author:** [@tbs575](https://discuss.elastic.co/u/tbs575)\
**Replies:** 5\
**Last updated:** [April 29, 2021, 1:09am UTC](https://discuss.elastic.co/t/can-i-using-chinese-in-condition/271339 "2021-04-29T01:09:15Z")

</div>

Using filebeat to put log into elastic. it seemed I can not using chinese as condition. output.elasticsearch: hosts: '${ELASTICSEARCH\_HOSTS:http://10.200.101.2:9200/}' pipelines: - pipeline: yibo\_test\_jsondata …

---

## [Filebeat AWS Module S3 input error queueURL is not in format](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850)

<div class="topic-metadata">

**Author:** [@cjm3625](https://discuss.elastic.co/u/cjm3625)\
**Replies:** 9\
**Last updated:** [April 29, 2021, 12:41am UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850 "2021-04-29T00:41:17Z")

</div>

Trying to use filebeat to monitor my AWS resources in ISO environment. It looks like the AWS standard endpoint is hard coded. my filebeat.yml filebeat.inputs: - type: s3 queue\_url: https://sqs.us-iso-east-1.c2s.ic.go…

---

## [Metricbeat not retrieving GCP metrics](https://discuss.elastic.co/t/metricbeat-not-retrieving-gcp-metrics/271562)

<div class="topic-metadata">

**Author:** [@Francisco\_Gomez1](https://discuss.elastic.co/u/Francisco_Gomez1)\
**Replies:** 0\
**Last updated:** [April 28, 2021, 9:50pm UTC](https://discuss.elastic.co/t/metricbeat-not-retrieving-gcp-metrics/271562 "2021-04-28T21:50:00Z")

</div>

Hi im trying to use metricbeat to monitor a GCP instance, i followed all the steps presents in: Monitor Google Cloud Platform | Observability Guide \[7.12\] | Elastic this tutorial. But when i try to test my GCP connectio…

---

## [I want to import only data that are on a several namespaces](https://discuss.elastic.co/t/i-want-to-import-only-data-that-are-on-a-several-namespaces/271521)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 3\
**Last updated:** [April 28, 2021, 8:59pm UTC](https://discuss.elastic.co/t/i-want-to-import-only-data-that-are-on-a-several-namespaces/271521 "2021-04-28T20:59:31Z")

</div>

Hello, I want to injest via filebeat only data from containers that are in a certain namespace. Is there a possibility to do that?

---

## [GCP module - Add cluster\_name for GKE / k8s.io logs](https://discuss.elastic.co/t/gcp-module-add-cluster-name-for-gke-k8s-io-logs/271278)

<div class="topic-metadata">

**Author:** [@aryon](https://discuss.elastic.co/u/aryon)\
**Replies:** 8\
**Last updated:** [April 28, 2021, 4:05pm UTC](https://discuss.elastic.co/t/gcp-module-add-cluster-name-for-gke-k8s-io-logs/271278 "2021-04-28T16:05:05Z")

</div>

Hello, I am using the GCP module to collect GCP audit logs. I noticed that for GKE / k8s.io logs, we do not have the cluster\_name in the ingested event. The field is present in the original event collected in Pub/Sub, …

---

## [Fleet Beta Risks](https://discuss.elastic.co/t/fleet-beta-risks/271467)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 2\
**Last updated:** [April 28, 2021, 1:57pm UTC](https://discuss.elastic.co/t/fleet-beta-risks/271467 "2021-04-28T13:57:53Z")

</div>

Can someone from Elastic tell us what the risks of running Fleet are? when you run Fleet it says : Fleet is under active development and is not intended for use in production environments. This beta release is designed …

---

## [Filebeat .csv file is not updating on Kibana](https://discuss.elastic.co/t/filebeat-csv-file-is-not-updating-on-kibana/270393)

<div class="topic-metadata">

**Author:** [@SHUBHAM\_SALUNKHE](https://discuss.elastic.co/u/SHUBHAM_SALUNKHE)\
**Replies:** 11\
**Last updated:** [April 28, 2021, 1:38pm UTC](https://discuss.elastic.co/t/filebeat-csv-file-is-not-updating-on-kibana/270393 "2021-04-28T13:38:34Z")

</div>

Hi, there are 2 .conf files under conf.d on server where ELK is hosted. one .conf file for jenkins logs & another one for filebeat. filebeat is hosted on another server. So, which .conf file is taken as config file? Al…

---

## [Filebeat Setup error: error loading index pattern: returned 408 to import file](https://discuss.elastic.co/t/filebeat-setup-error-error-loading-index-pattern-returned-408-to-import-file/271400)

<div class="topic-metadata">

**Author:** [@radu990](https://discuss.elastic.co/u/radu990)\
**Replies:** 1\
**Last updated:** [April 28, 2021, 9:25am UTC](https://discuss.elastic.co/t/filebeat-setup-error-error-loading-index-pattern-returned-408-to-import-file/271400 "2021-04-28T09:25:21Z")

</div>

While running filebeat setup, I'm getting the following error: PS C:\\Program Files\\Filebeat\> .\\filebeat.exe setup Overwriting ILM policy is disabled. Set \`setup.ilm.overwrite: true\` for enabling. Index setup finished. …

---

## [Send log filebeat, auditbeat, and winlogbeat](https://discuss.elastic.co/t/send-log-filebeat-auditbeat-and-winlogbeat/271226)

<div class="topic-metadata">

**Author:** [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Replies:** 8\
**Last updated:** [April 28, 2021, 8:42am UTC](https://discuss.elastic.co/t/send-log-filebeat-auditbeat-and-winlogbeat/271226 "2021-04-28T08:42:50Z")

</div>

hi guys, since i setting my elk stack with elastic security. and now they have ssl/tls and https but my beats family can't send log again. help me how to config beats so they can send log again.

---

## [Filebeat exclude\_lines is not working on Openshift](https://discuss.elastic.co/t/filebeat-exclude-lines-is-not-working-on-openshift/271407)

<div class="topic-metadata">

**Author:** [@Ferdous\_Khan](https://discuss.elastic.co/u/Ferdous_Khan)\
**Replies:** 1\
**Last updated:** [April 28, 2021, 8:37am UTC](https://discuss.elastic.co/t/filebeat-exclude-lines-is-not-working-on-openshift/271407 "2021-04-28T08:37:43Z")

</div>

Hello, We have this Filebeat (v7.1) configuration on OpenShift Pod that only excludes lines that have 'ACPI' in it: - type: log paths: - /var/log/kern.log enabled: true exclude\_lines: \['AC…

---

## [Packetbeat on high volume production Windows-AD-DNS-Servers](https://discuss.elastic.co/t/packetbeat-on-high-volume-production-windows-ad-dns-servers/270652)

<div class="topic-metadata">

**Author:** [@Mischa\_Diehm](https://discuss.elastic.co/u/Mischa_Diehm)\
**Replies:** 3\
**Last updated:** [April 28, 2021, 6:07am UTC](https://discuss.elastic.co/t/packetbeat-on-high-volume-production-windows-ad-dns-servers/270652 "2021-04-28T06:07:08Z")

</div>

Hi, we are trying to visualize and permanently record our DNS traffic. The DNS Server is run on Windows 10 and the logs it writes are ok but extending it with packetbeat would increase the visibility a lot. The concerns…

---

## [Documentation or help to autodiscover kubernetes](https://discuss.elastic.co/t/documentation-or-help-to-autodiscover-kubernetes/271443)

<div class="topic-metadata">

**Author:** [@flaco0](https://discuss.elastic.co/u/flaco0)\
**Replies:** 0\
**Last updated:** [April 27, 2021, 9:33pm UTC](https://discuss.elastic.co/t/documentation-or-help-to-autodiscover-kubernetes/271443 "2021-04-27T21:33:43Z")

</div>

Hi team, I want config some filebeats to kubernetes. I have problems to understand somethings about like setting my need it. I think that need more documentation, have some guide or similar out of elasticsearch web ref…

---

## [Juniper log ingestion](https://discuss.elastic.co/t/juniper-log-ingestion/270964)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 7\
**Last updated:** [April 27, 2021, 7:15pm UTC](https://discuss.elastic.co/t/juniper-log-ingestion/270964 "2021-04-27T19:15:24Z")

</div>

I am trying to ingest juniper log via filebeat using juniper module but it does not give me systemname and RT\_FLOW anywhere in my ELK data. how do I get that? source = dc-fw1 Can I modify this module and add my own p…

---

## [Timestamp - Filebeat](https://discuss.elastic.co/t/timestamp-filebeat/270900)

<div class="topic-metadata">

**Author:** [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Replies:** 7\
**Last updated:** [April 27, 2021, 4:34pm UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900 "2021-04-27T16:34:26Z")

</div>

Hello everyone, Hope you are doing well! I am exploring the possibilities of log viewing through Kibana. I am using version 7.9.2 for ELK and filebeat as well. so I am sending logs through filebeat directly to Elasticse…

---

## [Ship Kubernenetes events to kibana](https://discuss.elastic.co/t/ship-kubernenetes-events-to-kibana/271389)

<div class="topic-metadata">

**Author:** [@frozen\_walker](https://discuss.elastic.co/u/frozen_walker)\
**Replies:** 4\
**Last updated:** [April 27, 2021, 3:09pm UTC](https://discuss.elastic.co/t/ship-kubernenetes-events-to-kibana/271389 "2021-04-27T15:09:34Z")

</div>

How can we ship Kubernetes events logs to kibana. ie: That we can get from kubectl get events command. example output: LAST SEEN TYPE REASON OBJECT MESSAGE 47s Warning Failed p…

---

## [Filebeat loading whole csv again, if new entries are added](https://discuss.elastic.co/t/filebeat-loading-whole-csv-again-if-new-entries-are-added/271150)

<div class="topic-metadata">

**Author:** [@tushar.bansal](https://discuss.elastic.co/u/tushar.bansal)\
**Replies:** 5\
**Last updated:** [April 27, 2021, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-loading-whole-csv-again-if-new-entries-are-added/271150 "2021-04-27T13:25:50Z")

</div>

Hi, I am trying to send csv(remote server) to elasticsearch(local server). For this, I am using filebeat on remote server to send csv to logstash on local server. logstash listens for beats and sends it to elastic. Th…

---

## [Filebeat does not mount volume](https://discuss.elastic.co/t/filebeat-does-not-mount-volume/271269)

<div class="topic-metadata">

**Author:** [@ata](https://discuss.elastic.co/u/ata)\
**Replies:** 3\
**Last updated:** [April 27, 2021, 12:28pm UTC](https://discuss.elastic.co/t/filebeat-does-not-mount-volume/271269 "2021-04-27T12:28:06Z")

</div>

Hi, I was running filebeat 7.10.1 on EKS 1.18 and everything was fine, after the EKS upgrade of EKS to 1.19 filebeat container cannot mount its volume: MountVolume.SetUp failed for volume "docker-sock" : hostPath type …

---

## [Elastic Agent and/or Filebeat](https://discuss.elastic.co/t/elastic-agent-and-or-filebeat/270967)

<div class="topic-metadata">

**Author:** [@insurin](https://discuss.elastic.co/u/insurin)\
**Replies:** 1\
**Last updated:** [April 27, 2021, 11:57am UTC](https://discuss.elastic.co/t/elastic-agent-and-or-filebeat/270967 "2021-04-27T11:57:28Z")

</div>

HI all. I have followed this guide ELK-SIEM/Deployment-Guide at main · watsoninfosec/ELK-SIEM · GitHub This installs ElasticSearch, Kibana, Logstash and Filebeat on Ubuntu. I have 3 Windows Servers showing as healthy. E…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=160)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=162)
