# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=162

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 163

---

## [Change filebeat default index name while using Suricata module](https://discuss.elastic.co/t/change-filebeat-default-index-name-while-using-suricata-module/271302)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 3\
**Last updated:** [April 27, 2021, 11:40am UTC](https://discuss.elastic.co/t/change-filebeat-default-index-name-while-using-suricata-module/271302 "2021-04-27T11:40:25Z")

</div>

Hi! How can I change the filebeat default index name while using Suricata module? Appreciated!

---

## [Dockerfile for Metricbeat based on ubi8](https://discuss.elastic.co/t/dockerfile-for-metricbeat-based-on-ubi8/268210)

<div class="topic-metadata">

**Author:** [@noid999](https://discuss.elastic.co/u/noid999)\
**Replies:** 5\
**Last updated:** [April 27, 2021, 9:41am UTC](https://discuss.elastic.co/t/dockerfile-for-metricbeat-based-on-ubi8/268210 "2021-04-27T09:41:56Z")

</div>

Hi everyone, we are trying to build a Metricbeat Image based on ubi8. There are a lot of information's but no one explaines how this can be archived. I reverse engineered the official Image but there must be another wa…

---

## [Filebeat output to Kafka, how do I do stack monitoring](https://discuss.elastic.co/t/filebeat-output-to-kafka-how-do-i-do-stack-monitoring/271209)

<div class="topic-metadata">

**Author:** [@ktpktr0](https://discuss.elastic.co/u/ktpktr0)\
**Replies:** 5\
**Last updated:** [April 27, 2021, 7:39am UTC](https://discuss.elastic.co/t/filebeat-output-to-kafka-how-do-i-do-stack-monitoring/271209 "2021-04-27T07:39:55Z")

</div>

I output the log to Kafka and how I add filebeat to the stack monitor. I try the following, and it works well, but on kibana, I still don't see the state of filebeat. output.kafka: hosts: \["192.168.1.190:9092"\] topi…

---

## [Using filebeat, cannot read json log to custom index](https://discuss.elastic.co/t/using-filebeat-cannot-read-json-log-to-custom-index/270914)

<div class="topic-metadata">

**Author:** [@thuynh](https://discuss.elastic.co/u/thuynh)\
**Replies:** 2\
**Last updated:** [April 26, 2021, 9:47pm UTC](https://discuss.elastic.co/t/using-filebeat-cannot-read-json-log-to-custom-index/270914 "2021-04-26T21:47:34Z")

</div>

Index template already created. It runs but doesn''t tell me any error and can't see new index which should be call "fb-message-7.12.0-yyyy.mm.dd" I notice other issues i'm missing the param to indicate this is a custo…

---

## [Suricata module question](https://discuss.elastic.co/t/suricata-module-question/271286)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 2\
**Last updated:** [April 26, 2021, 6:41pm UTC](https://discuss.elastic.co/t/suricata-module-question/271286 "2021-04-26T18:41:55Z")

</div>

Hi! In my setup, the "eve" log files are separated by category. Using the Suricata module, how can I send both eve files to elastic? is it possible to use the example below? - module: suricata eve: enabled: true…

---

## [Metricbeat \> Module PostgreSQL \> wrong mapping of blk\_read\_time and blk\_write\_time](https://discuss.elastic.co/t/metricbeat-module-postgresql-wrong-mapping-of-blk-read-time-and-blk-write-time/270722)

<div class="topic-metadata">

**Author:** [@fabski](https://discuss.elastic.co/u/fabski)\
**Replies:** 2\
**Last updated:** [April 26, 2021, 5:50pm UTC](https://discuss.elastic.co/t/metricbeat-module-postgresql-wrong-mapping-of-blk-read-time-and-blk-write-time/270722 "2021-04-26T17:50:48Z")

</div>

Hi, I think there is a bug in the PostgreSQL module of Metricbeat. According to beats/metricbeat/module/postgresql/database/data.go, the following fields are mapped as Integer: "blocks": s.Object{ ... "time": s…

---

## [Timestamp](https://discuss.elastic.co/t/timestamp/271206)

<div class="topic-metadata">

**Author:** [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Replies:** 2\
**Last updated:** [April 26, 2021, 5:13pm UTC](https://discuss.elastic.co/t/timestamp/271206 "2021-04-26T17:13:21Z")

</div>

Hello everyone, I am trying to use timestamp from my log file instead of the timestamp when my logs were processed. in order to do that, I am using dissect processor and Timestamp processor together as below. processor…

---

## [Elastic Cloud Output not working Tshoot](https://discuss.elastic.co/t/elastic-cloud-output-not-working-tshoot/270465)

<div class="topic-metadata">

**Author:** [@Leon21](https://discuss.elastic.co/u/Leon21)\
**Replies:** 5\
**Last updated:** [April 26, 2021, 4:29pm UTC](https://discuss.elastic.co/t/elastic-cloud-output-not-working-tshoot/270465 "2021-04-26T16:29:45Z")

</div>

Hi I'm trying to push my events from a filebeat module into elastic cloud but could not find them into ES in my filebeat\* indexes. filebeat module gets events from a tcp socket (filebeat listen to it successfully) and …

---

## [Decode\_xml not working](https://discuss.elastic.co/t/decode-xml-not-working/269763)

<div class="topic-metadata">

**Author:** [@witkacy](https://discuss.elastic.co/u/witkacy)\
**Replies:** 5\
**Last updated:** [April 26, 2021, 4:04pm UTC](https://discuss.elastic.co/t/decode-xml-not-working/269763 "2021-04-26T16:04:38Z")

</div>

Hello, I'm using winlogbeats version 7.12 and it works great but I have a question. In my windows log in message field I have an XML. What I would like to do is first check if in that XML in specific field there is a s…

---

## [Filebeat decode\_xml processor missing](https://discuss.elastic.co/t/filebeat-decode-xml-processor-missing/268915)

<div class="topic-metadata">

**Author:** [@Francisco\_Peralta\_Gu](https://discuss.elastic.co/u/Francisco_Peralta_Gu)\
**Replies:** 5\
**Last updated:** [April 26, 2021, 4:03pm UTC](https://discuss.elastic.co/t/filebeat-decode-xml-processor-missing/268915 "2021-04-26T16:03:43Z")

</div>

Hi. I'm facing issues trying to configure decode\_xml processor in filebeat version 7.11. The error is the following: Failed to start crawler: starting input failed: Error while initializing input: the processor ac…

---

## [Winlogbeat If statements](https://discuss.elastic.co/t/winlogbeat-if-statements/271275)

<div class="topic-metadata">

**Author:** [@d-ring](https://discuss.elastic.co/u/d-ring)\
**Replies:** 0\
**Last updated:** [April 26, 2021, 3:18pm UTC](https://discuss.elastic.co/t/winlogbeat-if-statements/271275 "2021-04-26T15:18:51Z")

</div>

I am trying to do some conditional filtering of windows logon events and I am having some difficulty trying to figure out how the if statements work. How I am trying to get things to work is if it is a network logon do …

---

## [Multiple indexnames from 1 filebeat instance with ilm](https://discuss.elastic.co/t/multiple-indexnames-from-1-filebeat-instance-with-ilm/270762)

<div class="topic-metadata">

**Author:** [@Marcel\_van\_Zoggel](https://discuss.elastic.co/u/Marcel_van_Zoggel)\
**Replies:** 4\
**Last updated:** [April 26, 2021, 1:57pm UTC](https://discuss.elastic.co/t/multiple-indexnames-from-1-filebeat-instance-with-ilm/270762 "2021-04-26T13:57:09Z")

</div>

I want to use filebeat on a server with 2 different logfolders. Each folder must go to a different indexname. This i can set via a custom field per input (fe. Field log\_type) in combination with output.elasticsearch.ind…

---

## [Many ttl:-2 states in registry file cause registry file big and makes the performance of filebeat unstable](https://discuss.elastic.co/t/many-ttl-2-states-in-registry-file-cause-registry-file-big-and-makes-the-performance-of-filebeat-unstable/271253)

<div class="topic-metadata">

**Author:** [@hukaixuan](https://discuss.elastic.co/u/hukaixuan)\
**Replies:** 0\
**Last updated:** [April 26, 2021, 12:16pm UTC](https://discuss.elastic.co/t/many-ttl-2-states-in-registry-file-cause-registry-file-big-and-makes-the-performance-of-filebeat-unstable/271253 "2021-04-26T12:16:53Z")

</div>

how filebeat with k8s autodiscover configuration deal with ttl:-2 states entries when doing cleanup? our registry file got really big and lots of ttl:-2 state in it, seems like they didn't got cleaned thanks a lot f…

---

## [Metricbeat attempting to fetch metrics for unlisted metricset - why?](https://discuss.elastic.co/t/metricbeat-attempting-to-fetch-metrics-for-unlisted-metricset-why/271066)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 2\
**Last updated:** [April 26, 2021, 9:38am UTC](https://discuss.elastic.co/t/metricbeat-attempting-to-fetch-metrics-for-unlisted-metricset-why/271066 "2021-04-26T09:38:10Z")

</div>

I've installed metricbeat (7.12.0) and enabled the elasticsearch-xpack module. And configured it like so: - module: elasticsearch xpack.enabled: true period: 10s scope: cluster hosts: \["my-internal-elb.us-east…

---

## [Autodiscovering logstash nodes in Kubernetes](https://discuss.elastic.co/t/autodiscovering-logstash-nodes-in-kubernetes/270002)

<div class="topic-metadata">

**Author:** [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Replies:** 7\
**Last updated:** [April 26, 2021, 4:20am UTC](https://discuss.elastic.co/t/autodiscovering-logstash-nodes-in-kubernetes/270002 "2021-04-26T04:20:14Z")

</div>

So, I have a Logstash Statefulset running in Kubernetes. I have a headless service defined to establish network connection to the logstash pods. I deployed beats as a deployment using the official docker image, and I wa…

---

## [ZFS Module for Metricbeat](https://discuss.elastic.co/t/zfs-module-for-metricbeat/271202)

<div class="topic-metadata">

**Author:** [@Niecke](https://discuss.elastic.co/u/Niecke)\
**Replies:** 0\
**Last updated:** [April 25, 2021, 7:44pm UTC](https://discuss.elastic.co/t/zfs-module-for-metricbeat/271202 "2021-04-25T19:44:43Z")

</div>

I am looking for the possibility to gather metrics from ZFS pools and datasets. Sadly this seems not to be implemented in metricbeat (Metricbeat: Add support for ZFS metrics · Issue #10848 · elastic/beats · GitHub). I th…

---

## [Filebeat 7.12 event collection rate drops after a period of time](https://discuss.elastic.co/t/filebeat-7-12-event-collection-rate-drops-after-a-period-of-time/271157)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 1\
**Last updated:** [April 24, 2021, 5:42pm UTC](https://discuss.elastic.co/t/filebeat-7-12-event-collection-rate-drops-after-a-period-of-time/271157 "2021-04-24T17:42:59Z")

</div>

I have deployed filebeat 7.12 on a kubernetes cluster for collecting log events. The deployment was smooth and started collecting events as expected. But after a day, after collecting 50K + events the number of events t…

---

## [Filebeat AWS ,Azure Modules: Support Multiple Accounts](https://discuss.elastic.co/t/filebeat-aws-azure-modules-support-multiple-accounts/271177)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 1\
**Last updated:** [April 25, 2021, 1:46pm UTC](https://discuss.elastic.co/t/filebeat-aws-azure-modules-support-multiple-accounts/271177 "2021-04-25T13:46:47Z")

</div>

I have successfully started both the filebeat modules AWS and Azure for a single account. I want to know if Filebeat can support multiple accounts for AWS and Azure. I would like to achieve following scenarios. Get mul…

---

## [Filebeat normal start but no update log to elasticsearch](https://discuss.elastic.co/t/filebeat-normal-start-but-no-update-log-to-elasticsearch/270733)

<div class="topic-metadata">

**Author:** [@WhyStart](https://discuss.elastic.co/u/WhyStart)\
**Replies:** 3\
**Last updated:** [April 25, 2021, 6:32am UTC](https://discuss.elastic.co/t/filebeat-normal-start-but-no-update-log-to-elasticsearch/270733 "2021-04-25T06:32:17Z")

</div>

I installed filebeta on macos localhost，elk installed on docker desktop for mac,start filebeat log normal output,doesn't seem to have any problems,but it is not transmitted to elasticsearch. filebeat.yml # ============…

---

## [Filebeat sonicwall module not parsing correctly many messages](https://discuss.elastic.co/t/filebeat-sonicwall-module-not-parsing-correctly-many-messages/268232)

<div class="topic-metadata">

**Author:** [@Rodrigo\_Bernardo](https://discuss.elastic.co/u/Rodrigo_Bernardo)\
**Replies:** 6\
**Last updated:** [April 24, 2021, 6:28pm UTC](https://discuss.elastic.co/t/filebeat-sonicwall-module-not-parsing-correctly-many-messages/268232 "2021-04-24T18:28:01Z")

</div>

Hello there, Our Sonicwall generates this message: \<110\> id=yyyy sn=C0EAE4F9FB00 time="2021-03-24 14:35:31 UTC" fw=xx.xx.xx.xx pri=6 c=262144 m=98 msg="Connection Opened" app=49177 appName="General HTTPS" n=2185104…

---

## [Automatic dashboards are not getting created when I change index name in filebeat.yml](https://discuss.elastic.co/t/automatic-dashboards-are-not-getting-created-when-i-change-index-name-in-filebeat-yml/271086)

<div class="topic-metadata">

**Author:** [@Husnain](https://discuss.elastic.co/u/Husnain)\
**Replies:** 6\
**Last updated:** [April 24, 2021, 11:39am UTC](https://discuss.elastic.co/t/automatic-dashboards-are-not-getting-created-when-i-change-index-name-in-filebeat-yml/271086 "2021-04-24T11:39:08Z")

</div>

Hii.I am ingesting netflow data using filebeat netflow module.I have configured "filebeat.yml" file for automatic creation of dashboards.Filebeat creates index with name "filebeat-\*" and it also creates dashboards auto…

---

## [Filebeat & Windows DHCP Logging](https://discuss.elastic.co/t/filebeat-windows-dhcp-logging/271017)

<div class="topic-metadata">

**Author:** [@billkindle](https://discuss.elastic.co/u/billkindle)\
**Replies:** 1\
**Last updated:** [April 24, 2021, 9:45am UTC](https://discuss.elastic.co/t/filebeat-windows-dhcp-logging/271017 "2021-04-24T09:45:36Z")

</div>

I'm trying to locate some examples that are specific to elastic cloud when using filebeat to capture Microsoft DHCP logs. All the examples I find online aren't really matching what I'm seeing in 7.12.0 example files, or …

---

## [Monitoring Sync gateway using ELK](https://discuss.elastic.co/t/monitoring-sync-gateway-using-elk/271134)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 0\
**Last updated:** [April 24, 2021, 9:24am UTC](https://discuss.elastic.co/t/monitoring-sync-gateway-using-elk/271134 "2021-04-24T09:24:15Z")

</div>

Hi all, I am monitoring couchbase database using couchbase module of metricbeat. is there any way to monitor sync gateway ? Regards

---

## [Connecting filebeat to elastic cloud](https://discuss.elastic.co/t/connecting-filebeat-to-elastic-cloud/270788)

<div class="topic-metadata">

**Author:** [@Richard\_Phillips\_Roy](https://discuss.elastic.co/u/Richard_Phillips_Roy)\
**Replies:** 4\
**Last updated:** [April 24, 2021, 5:07am UTC](https://discuss.elastic.co/t/connecting-filebeat-to-elastic-cloud/270788 "2021-04-24T05:07:16Z")

</div>

Hi, I would i configure the output of this filebeat.yml file to send logs to elastic cloud filebeat.inputs: - enabled: true paths: - /data/fatt/log/fatt.log fields: type: Fatt fields\_under\_root…

---

## [Synthetics 1.0.0-beta.0 + Breaking Changes](https://discuss.elastic.co/t/synthetics-1-0-0-beta-0-breaking-changes/271120)

<div class="topic-metadata">

**Author:** [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Replies:** 0\
**Last updated:** [April 23, 2021, 6:08pm UTC](https://discuss.elastic.co/t/synthetics-1-0-0-beta-0-breaking-changes/271120 "2021-04-23T18:08:53Z")

</div>

We're really excited to announce the 1.0.0-beta.0 version of the Elastic Synthetics JS/TS library. However, don't upgrade to this until the 7.13.0 release is available and you've upgraded to it! This release is in prepar…

---

## [Configure postgresql module with csv fileset through Hints](https://discuss.elastic.co/t/configure-postgresql-module-with-csv-fileset-through-hints/271114)

<div class="topic-metadata">

**Author:** [@lchdev](https://discuss.elastic.co/u/lchdev)\
**Replies:** 0\
**Last updated:** [April 23, 2021, 4:39pm UTC](https://discuss.elastic.co/t/configure-postgresql-module-with-csv-fileset-through-hints/271114 "2021-04-23T16:39:17Z")

</div>

Hi, Running Filebeat 7.12 in Kubernetes, I'm unable to configure the postgresql module to parse CSV logs through hints. I added the following annotations ( logreaper is the sidecar container that outputs postgres csv l…

---

## [Not able to see all the log files which are under filebeat config in kibana](https://discuss.elastic.co/t/not-able-to-see-all-the-log-files-which-are-under-filebeat-config-in-kibana/271101)

<div class="topic-metadata">

**Author:** [@prat](https://discuss.elastic.co/u/prat)\
**Replies:** 3\
**Last updated:** [April 23, 2021, 3:44pm UTC](https://discuss.elastic.co/t/not-able-to-see-all-the-log-files-which-are-under-filebeat-config-in-kibana/271101 "2021-04-23T15:44:36Z")

</div>

not able to see all the log files which are under filebeat config in kibana. In kibana dashboard, choose filebeat-\* and in search selected log.file.path.keyword, then selected equals sign i.e : then auto populated list …

---

## [Is there a way to direct different log formats from the same log to separate pipelines in filebeat?](https://discuss.elastic.co/t/is-there-a-way-to-direct-different-log-formats-from-the-same-log-to-separate-pipelines-in-filebeat/270565)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 4\
**Last updated:** [April 23, 2021, 2:13pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-direct-different-log-formats-from-the-same-log-to-separate-pipelines-in-filebeat/270565 "2021-04-23T14:13:05Z")

</div>

Hello, I am having some logs coming from java app and the logs from jvm is not parsed by the java logger therefore it has a different format. For example: {"@timestamp":"2021-04-19T10:25:51.985Z", "log.level": "INFO", …

---

## [File is inactive: Closing because close\_inactive of 5m0s reached](https://discuss.elastic.co/t/file-is-inactive-closing-because-close-inactive-of-5m0s-reached/271057)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 0\
**Last updated:** [April 23, 2021, 9:17am UTC](https://discuss.elastic.co/t/file-is-inactive-closing-because-close-inactive-of-5m0s-reached/271057 "2021-04-23T09:17:08Z")

</div>

Hi Team! I, like many, have a problem with the filebeat. Data is not reaching to logstash. Before opening the request, I read many posts, but did not find a clear solution to this problem? Pocheiu it doesn't work? Che…

---

## [7.10.1 vs 7.12.0 metricbeat problem](https://discuss.elastic.co/t/7-10-1-vs-7-12-0-metricbeat-problem/271007)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 0\
**Last updated:** [April 22, 2021, 7:37pm UTC](https://discuss.elastic.co/t/7-10-1-vs-7-12-0-metricbeat-problem/271007 "2021-04-22T19:37:15Z")

</div>

I upgraded 7.10.1 to 7.12.0 and now I have two index but it give me lot of weired problem Cannot use field \[agent.version\] due to ambiguities being mapped as \[2\] incompatible types: \[text\] I have data coming in to both…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=161)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=163)
