# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=163

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 164

---

## [Conditions are not working properly. Seems to match documentation](https://discuss.elastic.co/t/conditions-are-not-working-properly-seems-to-match-documentation/270966)

<div class="topic-metadata">

**Author:** [@ARDiver86](https://discuss.elastic.co/u/ARDiver86)\
**Replies:** 9\
**Last updated:** [April 22, 2021, 5:14pm UTC](https://discuss.elastic.co/t/conditions-are-not-working-properly-seems-to-match-documentation/270966 "2021-04-22T17:14:52Z")

</div>

I am attempting to send documents to specific indexes so I can handle the lifecycle better with various types of documents. I just cannot get it to work when trying to involve multiple fields. For example this works: -…

---

## [Auditbeat - can it monitor Apache logs](https://discuss.elastic.co/t/auditbeat-can-it-monitor-apache-logs/270811)

<div class="topic-metadata">

**Author:** [@dddddddddddddddd](https://discuss.elastic.co/u/dddddddddddddddd)\
**Replies:** 1\
**Last updated:** [April 22, 2021, 3:18pm UTC](https://discuss.elastic.co/t/auditbeat-can-it-monitor-apache-logs/270811 "2021-04-22T15:18:30Z")

</div>

hi, please can somebody helps me to know if there is a method to collect apache server logs by auditbeat regards

---

## [Multi Line Pattern](https://discuss.elastic.co/t/multi-line-pattern/270976)

<div class="topic-metadata">

**Author:** [@Anthony\_Azzopardi](https://discuss.elastic.co/u/Anthony_Azzopardi)\
**Replies:** 0\
**Last updated:** [April 22, 2021, 2:51pm UTC](https://discuss.elastic.co/t/multi-line-pattern/270976 "2021-04-22T14:51:01Z")

</div>

I am currently having a hard time trying to parse a customized log to logstash using filebeat. My servers are windows servers, using the latest version of filebeat 7.0.12. the sample log Received XML Message: SECURITYLO…

---

## [Multi Line Pattern](https://discuss.elastic.co/t/multi-line-pattern/270972)

<div class="topic-metadata">

**Author:** [@Anthony\_Azzopardi](https://discuss.elastic.co/u/Anthony_Azzopardi)\
**Replies:** 1\
**Last updated:** [April 22, 2021, 2:46pm UTC](https://discuss.elastic.co/t/multi-line-pattern/270972 "2021-04-22T14:46:08Z")

</div>

Hello everyone, I am currently having a hard time trying to parse a customized log to logstash using filebeat. My servers are windows servers, using the latest version of filebeat 7.0.12. the sample log Received XML Me…

---

## [I'm lost to why beats isn't passing logs to logstash](https://discuss.elastic.co/t/im-lost-to-why-beats-isnt-passing-logs-to-logstash/270626)

<div class="topic-metadata">

**Author:** [@rodrigoross](https://discuss.elastic.co/u/rodrigoross)\
**Replies:** 11\
**Last updated:** [April 22, 2021, 2:42pm UTC](https://discuss.elastic.co/t/im-lost-to-why-beats-isnt-passing-logs-to-logstash/270626 "2021-04-22T14:42:01Z")

</div>

I really didn't want to open a new topic, but I can't seem to understand why my logstash don't receive logs from filebeat. I'm new and used a ELK docker to setup the enviroment. After editing the logstash.conf, I ran th…

---

## [Winlogbeat : read log files](https://discuss.elastic.co/t/winlogbeat-read-log-files/270973)

<div class="topic-metadata">

**Author:** [@Nybble](https://discuss.elastic.co/u/Nybble)\
**Replies:** 0\
**Last updated:** [April 22, 2021, 2:23pm UTC](https://discuss.elastic.co/t/winlogbeat-read-log-files/270973 "2021-04-22T14:23:00Z")

</div>

Hello, My question is simple but I can't really find a clear answer. Is it possible to read a log files with Winlogbeat directly ? My company have some Windows Server with multiple services (AD, DNS, DHCP, ...) and we …

---

## [Filebeat not working on a particular path](https://discuss.elastic.co/t/filebeat-not-working-on-a-particular-path/270845)

<div class="topic-metadata">

**Author:** [@ashu\_29516](https://discuss.elastic.co/u/ashu_29516)\
**Replies:** 3\
**Last updated:** [April 22, 2021, 12:21pm UTC](https://discuss.elastic.co/t/filebeat-not-working-on-a-particular-path/270845 "2021-04-22T12:21:38Z")

</div>

Hi Everyone, I'm new to Elasticsearch and have been facing an issue with filebeats where I've been observing that logs from certain paths do not seem to get picked when the file in that path is updated. Running filebeat…

---

## [Filebeat to logstash multiline issue with network](https://discuss.elastic.co/t/filebeat-to-logstash-multiline-issue-with-network/270693)

<div class="topic-metadata">

**Author:** [@Ahmed\_Abdulaleem](https://discuss.elastic.co/u/Ahmed_Abdulaleem)\
**Replies:** 3\
**Last updated:** [April 22, 2021, 12:11pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-multiline-issue-with-network/270693 "2021-04-22T12:11:35Z")

</div>

Greetings, I installed file beat 7.12 with multiline pattern and the output is log stash 7.12 the problem is when file beat be in same network subnet the multiline shipped correctly otherwise with a different network…

---

## [Filebeat 6.8.x rotated filehandles filehandles held onto forever](https://discuss.elastic.co/t/filebeat-6-8-x-rotated-filehandles-filehandles-held-onto-forever/270917)

<div class="topic-metadata">

**Author:** [@filipeGuerreiro](https://discuss.elastic.co/u/filipeGuerreiro)\
**Replies:** 0\
**Last updated:** [April 22, 2021, 3:28am UTC](https://discuss.elastic.co/t/filebeat-6-8-x-rotated-filehandles-filehandles-held-onto-forever/270917 "2021-04-22T03:28:49Z")

</div>

Tested on 6.8.4 and 6.8.15. This issue seems to crop up in applications with a high rate of logs. Takes a day or two to get to that point, noticed the file handles count increasing steadily throughout. \[root@ldap-mast…

---

## [Syslog from Aruba Switches](https://discuss.elastic.co/t/syslog-from-aruba-switches/270543)

<div class="topic-metadata">

**Author:** [@Peque](https://discuss.elastic.co/u/Peque)\
**Replies:** 2\
**Last updated:** [April 22, 2021, 1:36am UTC](https://discuss.elastic.co/t/syslog-from-aruba-switches/270543 "2021-04-22T01:36:30Z")

</div>

Hi Forum I've build my first ELK server - and have some incomming data - But I cannot make my Aruba 2530 Switches send the logfiles to elastic - and missing something somewhere. On My Aruba switches - I set the followi…

---

## [Event.created is always 8 hours later then @timestamp](https://discuss.elastic.co/t/event-created-is-always-8-hours-later-then-timestamp/270211)

<div class="topic-metadata">

**Author:** [@new2\_elk](https://discuss.elastic.co/u/new2_elk)\
**Replies:** 3\
**Last updated:** [April 22, 2021, 1:21am UTC](https://discuss.elastic.co/t/event-created-is-always-8-hours-later-then-timestamp/270211 "2021-04-22T01:21:09Z")

</div>

Hi everyone, I am facing a issue that the event.created is always 8 hours later than the @timestamp and the timestamp is the current time which is correct. Below is the example. Time event.created event.timezone …

---

## [Filebeat push same event in multiple indices](https://discuss.elastic.co/t/filebeat-push-same-event-in-multiple-indices/270828)

<div class="topic-metadata">

**Author:** [@screwyy](https://discuss.elastic.co/u/screwyy)\
**Replies:** 1\
**Last updated:** [April 22, 2021, 1:06am UTC](https://discuss.elastic.co/t/filebeat-push-same-event-in-multiple-indices/270828 "2021-04-22T01:06:55Z")

</div>

Hello, is it possible to send the same event into multiple indices in the same elasticsearch cluster? Example filebeat.yml: filebeat.config.inputs: enabled: true path: ${path.config}/inputs/\*.yml reload: en…

---

## [Error initializing processors: each processor must have exactly one action, but found 2 actions](https://discuss.elastic.co/t/error-initializing-processors-each-processor-must-have-exactly-one-action-but-found-2-actions/270901)

<div class="topic-metadata">

**Author:** [@manojkrishna561994](https://discuss.elastic.co/u/manojkrishna561994)\
**Replies:** 1\
**Last updated:** [April 22, 2021, 12:54am UTC](https://discuss.elastic.co/t/error-initializing-processors-each-processor-must-have-exactly-one-action-but-found-2-actions/270901 "2021-04-22T00:54:27Z")

</div>

I'm installing ELK on my Ubuntu machine. When i'm installing Filebeats it is throwing me this error. When i run this command sudo filebeat modules list im getting this error. root@lucy0094:~# sudo filebeat modules list…

---

## [Metricsets CPU what metric to use](https://discuss.elastic.co/t/metricsets-cpu-what-metric-to-use/270879)

<div class="topic-metadata">

**Author:** [@maheshe](https://discuss.elastic.co/u/maheshe)\
**Replies:** 1\
**Last updated:** [April 21, 2021, 5:44pm UTC](https://discuss.elastic.co/t/metricsets-cpu-what-metric-to-use/270879 "2021-04-21T17:44:49Z")

</div>

On 7.9 Metricbeat-Metricset-CPU metrics I see these two entries. which one should I use for total CPU percentage system.cpu.total.norm.pct 0.026 system.cpu.total.pct 0.211 In the documentation I don't see cpu.total m…

---

## [Metricbeat unable to connect to MongoDB using SCRAM-SHA-256](https://discuss.elastic.co/t/metricbeat-unable-to-connect-to-mongodb-using-scram-sha-256/270849)

<div class="topic-metadata">

**Author:** [@lchdev](https://discuss.elastic.co/u/lchdev)\
**Replies:** 0\
**Last updated:** [April 21, 2021, 1:34pm UTC](https://discuss.elastic.co/t/metricbeat-unable-to-connect-to-mongodb-using-scram-sha-256/270849 "2021-04-21T13:34:14Z")

</div>

Hello ! Metricbeat relies on the community GO driver to connect to a MongoDB cluster. This driver is quite old and has been replaced by an official driver. Since it is now unmaintained, it has not received any updates …

---

## [Why does filebeat create dashboards for disabled modules?](https://discuss.elastic.co/t/why-does-filebeat-create-dashboards-for-disabled-modules/270840)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 2\
**Last updated:** [April 21, 2021, 12:55pm UTC](https://discuss.elastic.co/t/why-does-filebeat-create-dashboards-for-disabled-modules/270840 "2021-04-21T12:55:08Z")

</div>

I recently installed filebeat to monitor and ship my nginx logs. I followed the setup instructions, and included the setup.kibana config details because I wanted the nginx dashboards. However, when running setup filebe…

---

## [Metricbeat - no counter paths were found](https://discuss.elastic.co/t/metricbeat-no-counter-paths-were-found/270166)

<div class="topic-metadata">

**Author:** [@Inammathe\_Inna](https://discuss.elastic.co/u/Inammathe_Inna)\
**Replies:** 1\
**Last updated:** [April 21, 2021, 8:42am UTC](https://discuss.elastic.co/t/metricbeat-no-counter-paths-were-found/270166 "2021-04-21T08:42:59Z")

</div>

Hi, Periodically, we are finding our Windows servers stop sending perfmon metrics (other metrics e.g. cpu from the system module) continue just fine. The current workaround that gets them going again is restarting the …

---

## [Logviewing - Filebeat](https://discuss.elastic.co/t/logviewing-filebeat/270758)

<div class="topic-metadata">

**Author:** [@Akhil2610](https://discuss.elastic.co/u/Akhil2610)\
**Replies:** 0\
**Last updated:** [April 20, 2021, 7:50pm UTC](https://discuss.elastic.co/t/logviewing-filebeat/270758 "2021-04-20T19:50:06Z")

</div>

Hello everyone, Hope you are doing well! I am exploring the possibilities of log viewing through Kibana. I am new to ELK so pardon me for asking dumb questions. I am using version 7.9.2 for ELK and filebeat as well. so…

---

## [Putting mass archived log files to Elasticsearch using Filebeat](https://discuss.elastic.co/t/putting-mass-archived-log-files-to-elasticsearch-using-filebeat/270441)

<div class="topic-metadata">

**Author:** [@h8h](https://discuss.elastic.co/u/h8h)\
**Replies:** 2\
**Last updated:** [April 20, 2021, 7:29pm UTC](https://discuss.elastic.co/t/putting-mass-archived-log-files-to-elasticsearch-using-filebeat/270441 "2021-04-20T19:29:51Z")

</div>

Hello, I am working in forensics and have a lot of log files, each 100MB in size. I feel very uncomfortable using filebeat because it throws a lot of "too many open files" errors. I am not sure if every file is being p…

---

## [Autodiscover on ECK not harvesting logs](https://discuss.elastic.co/t/autodiscover-on-eck-not-harvesting-logs/270750)

<div class="topic-metadata">

**Author:** [@twiggy](https://discuss.elastic.co/u/twiggy)\
**Replies:** 0\
**Last updated:** [April 20, 2021, 6:30pm UTC](https://discuss.elastic.co/t/autodiscover-on-eck-not-harvesting-logs/270750 "2021-04-20T18:30:28Z")

</div>

Hello everyone, I'm trying to implement autodiscover with filebeat using ECK. Basic feature at the moment, using : config: filebeat.autodiscover: providers: - type: kubernetes …

---

## [Custom index filter](https://discuss.elastic.co/t/custom-index-filter/270714)

<div class="topic-metadata">

**Author:** [@ARDiver86](https://discuss.elastic.co/u/ARDiver86)\
**Replies:** 1\
**Last updated:** [April 20, 2021, 3:39pm UTC](https://discuss.elastic.co/t/custom-index-filter/270714 "2021-04-20T15:39:49Z")

</div>

I am attempting to put specific messages from sysmon into their own index so I can apply a separate lifecycle policy to them. I thought I had this policy correct but it does not seem to be working properly. The query I …

---

## [Prometheus Federation Metricbeat - No index and document in ES](https://discuss.elastic.co/t/prometheus-federation-metricbeat-no-index-and-document-in-es/270726)

<div class="topic-metadata">

**Author:** [@dekim](https://discuss.elastic.co/u/dekim)\
**Replies:** 0\
**Last updated:** [April 20, 2021, 2:11pm UTC](https://discuss.elastic.co/t/prometheus-federation-metricbeat-no-index-and-document-in-es/270726 "2021-04-20T14:11:14Z")

</div>

Hello, We currently have a Kubernetes cluster that has a Prometheus Installation. I'm looking to export the Prometheus gathered metrics to Elastic so we can create Kibana dashboard; using the Federation approach (so we…

---

## [Metricbeat dashboard strange behaviour](https://discuss.elastic.co/t/metricbeat-dashboard-strange-behaviour/267401)

<div class="topic-metadata">

**Author:** [@alfredo.deluca](https://discuss.elastic.co/u/alfredo.deluca)\
**Replies:** 8\
**Last updated:** [April 20, 2021, 11:01am UTC](https://discuss.elastic.co/t/metricbeat-dashboard-strange-behaviour/267401 "2021-04-20T11:01:11Z")

</div>

Hi all. I am using elastic.co cloud 7.11.1 and I have 2 different metricbeat sitting in 2 different k8s clusters sending all the metrics to ELK. The first one works fine and I can see all the metrics in kibana but when…

---

## [Force filebeat resend ONE particular file](https://discuss.elastic.co/t/force-filebeat-resend-one-particular-file/267115)

<div class="topic-metadata">

**Author:** [@notricky](https://discuss.elastic.co/u/notricky)\
**Replies:** 18\
**Last updated:** [April 20, 2021, 10:11am UTC](https://discuss.elastic.co/t/force-filebeat-resend-one-particular-file/267115 "2021-04-20T10:11:09Z")

</div>

How should I force a filebeat to resend just only one particular file. Or how may I drop for only one certain file its offset to force filebeat start processing this one file again? Again, I'm talknig only about one co…

---

## [Metricbeat 7.12.0: Empty modules list](https://discuss.elastic.co/t/metricbeat-7-12-0-empty-modules-list/270680)

<div class="topic-metadata">

**Author:** [@orfeas2021](https://discuss.elastic.co/u/orfeas2021)\
**Replies:** 0\
**Last updated:** [April 20, 2021, 9:35am UTC](https://discuss.elastic.co/t/metricbeat-7-12-0-empty-modules-list/270680 "2021-04-20T09:35:42Z")

</div>

Hi! I use beat agents to monitor applications deployed on Openstack VMs. I Installed and configured metricbeat (7.12.0) but when I run metricbeat modules list the list is empty. while in my elk-master node I have i…

---

## [Include user.name field in journalbeat](https://discuss.elastic.co/t/include-user-name-field-in-journalbeat/270668)

<div class="topic-metadata">

**Author:** [@Nicoske](https://discuss.elastic.co/u/Nicoske)\
**Replies:** 0\
**Last updated:** [April 20, 2021, 7:39am UTC](https://discuss.elastic.co/t/include-user-name-field-in-journalbeat/270668 "2021-04-20T07:39:27Z")

</div>

Hi! I have a quite minimalist journalbeat config pushing my journal to elasticsearch but I'm missing the user.name field (I have user.id). I see that it is disabled by default in the reference, but in my index settings …

---

## [Send AIX logs to logstash](https://discuss.elastic.co/t/send-aix-logs-to-logstash/270640)

<div class="topic-metadata">

**Author:** [@dddddddddddddddd](https://discuss.elastic.co/u/dddddddddddddddd)\
**Replies:** 2\
**Last updated:** [April 20, 2021, 12:04am UTC](https://discuss.elastic.co/t/send-aix-logs-to-logstash/270640 "2021-04-20T00:04:04Z")

</div>

Hi there I would know if filebeat supports the AIX machine? if not how can I send logs from AIX machines to logstash thanks

---

## [Filebeat -e running for a long time](https://discuss.elastic.co/t/filebeat-e-running-for-a-long-time/270292)

<div class="topic-metadata">

**Author:** [@thrak](https://discuss.elastic.co/u/thrak)\
**Replies:** 1\
**Last updated:** [April 19, 2021, 11:31pm UTC](https://discuss.elastic.co/t/filebeat-e-running-for-a-long-time/270292 "2021-04-19T23:31:10Z")

</div>

Hello I am running a new installation of filebeat 7.12.0. I was initially getting an ILM error and so had the indices removed for filebeats. Now when I run the filebeat -e setup, it seems to run for ever. I let it go fo…

---

## [Filebeat Harvester not being started for files](https://discuss.elastic.co/t/filebeat-harvester-not-being-started-for-files/270639)

<div class="topic-metadata">

**Author:** [@Usman18](https://discuss.elastic.co/u/Usman18)\
**Replies:** 0\
**Last updated:** [April 19, 2021, 11:27pm UTC](https://discuss.elastic.co/t/filebeat-harvester-not-being-started-for-files/270639 "2021-04-19T23:27:30Z")

</div>

I am running Filebeat inside docker container. My Filebeat service is working correctly on mac os and ubuntu machine but on another ubuntu vm it's not working. Harvesters are not started for the files neither connection …

---

## [Import logs using filebeat for a java app running on kubernetes](https://discuss.elastic.co/t/import-logs-using-filebeat-for-a-java-app-running-on-kubernetes/270625)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 1\
**Last updated:** [April 19, 2021, 9:11pm UTC](https://discuss.elastic.co/t/import-logs-using-filebeat-for-a-java-app-running-on-kubernetes/270625 "2021-04-19T21:11:07Z")

</div>

Hello I am reading the documentation of now to format and read logs on a Java app that is running in kubernetes here. In this documentation said to enable hint based discovery and add the annotation that are using the l…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=162)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=164)
