# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=164

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 165

---

## [Elastic Agent Macbook M1](https://discuss.elastic.co/t/elastic-agent-macbook-m1/270578)

<div class="topic-metadata">

**Author:** [@fgierlinger](https://discuss.elastic.co/u/fgierlinger)\
**Replies:** 1\
**Last updated:** [April 19, 2021, 8:52pm UTC](https://discuss.elastic.co/t/elastic-agent-macbook-m1/270578 "2021-04-19T20:52:07Z")

</div>

Are there any plans to release the elastic agent for the new m1 cpu from apple (Darwin aarch64)? Is anybody aware of an unofficial build of the elastic agent for the m1 chip? Currently, there are only builds for Linux a…

---

## [Metricbeat 7.11.1 fail in system fsstat and filesystem: The device is not ready](https://discuss.elastic.co/t/metricbeat-7-11-1-fail-in-system-fsstat-and-filesystem-the-device-is-not-ready/265613)

<div class="topic-metadata">

**Author:** [@Sommerdal](https://discuss.elastic.co/u/Sommerdal)\
**Replies:** 8\
**Last updated:** [April 19, 2021, 8:04pm UTC](https://discuss.elastic.co/t/metricbeat-7-11-1-fail-in-system-fsstat-and-filesystem-the-device-is-not-ready/265613 "2021-04-19T20:04:16Z")

</div>

I keep getting this: module/wrapper.go:259 Error fetching data for metricset system.fsstat: filesystem list: GetFilesystemType failed: GetVolumeInformationW failed: The device is module/wrapper.go:259 Error fetchin…

---

## [Threat Intel module](https://discuss.elastic.co/t/threat-intel-module/269679)

<div class="topic-metadata">

**Author:** [@sbathla](https://discuss.elastic.co/u/sbathla)\
**Replies:** 2\
**Last updated:** [April 19, 2021, 5:15pm UTC](https://discuss.elastic.co/t/threat-intel-module/269679 "2021-04-19T17:15:39Z")

</div>

Hi all, Need one help. I tried to integrate threat intel module in 7.12 version. Post integration I am able to view dashboard for Abuse URL and Abuse malware but not getting results for MISP, Otx, alienvault..Did the re…

---

## [\[Filebeat 7.12\] \[Windows\] Failed to open store 'filebeat' after incorrect Windows reboot](https://discuss.elastic.co/t/filebeat-7-12-windows-failed-to-open-store-filebeat-after-incorrect-windows-reboot/270145)

<div class="topic-metadata">

**Author:** [@akelio](https://discuss.elastic.co/u/akelio)\
**Replies:** 2\
**Last updated:** [April 19, 2021, 12:01pm UTC](https://discuss.elastic.co/t/filebeat-7-12-windows-failed-to-open-store-filebeat-after-incorrect-windows-reboot/270145 "2021-04-19T12:01:32Z")

</div>

Hi! Filebeat 7.12 (x86) on Windows machine cannot start after incorrect OS reboot (possibly after power supply lost). Log shows that registry data files are corrupted. The only way I found to manually start filebeat is…

---

## [Filebeats high IO WAIT version 7.9.2](https://discuss.elastic.co/t/filebeats-high-io-wait-version-7-9-2/270575)

<div class="topic-metadata">

**Author:** [@Ankur\_Mahajan](https://discuss.elastic.co/u/Ankur_Mahajan)\
**Replies:** 0\
**Last updated:** [April 19, 2021, 11:26am UTC](https://discuss.elastic.co/t/filebeats-high-io-wait-version-7-9-2/270575 "2021-04-19T11:26:07Z")

</div>

We are randomly facing a weird issue of IO wait with filebeat 7.9.2. We have around 30 filebeat, metricbeat and heartbeat pipeline to an elasticsearch cluster. I searched this a lot but couldn't find a solution. The ugl…

---

## [Not able to create indexes using multiple logs files in filebeat tags](https://discuss.elastic.co/t/not-able-to-create-indexes-using-multiple-logs-files-in-filebeat-tags/270328)

<div class="topic-metadata">

**Author:** [@balaji\_pal](https://discuss.elastic.co/u/balaji_pal)\
**Replies:** 3\
**Last updated:** [April 19, 2021, 4:51am UTC](https://discuss.elastic.co/t/not-able-to-create-indexes-using-multiple-logs-files-in-filebeat-tags/270328 "2021-04-19T04:51:31Z")

</div>

Hi Guys, I'm not able to create custom indexes in elastic search using logstash and filebeat. Log flow (Filebeat ==\> logstash ==\> elasticsearch) I have two custom logs files such as /var/log/app1/app1.log and /var/log…

---

## [Heartbeat showing my nodes as down but they are up](https://discuss.elastic.co/t/heartbeat-showing-my-nodes-as-down-but-they-are-up/270406)

<div class="topic-metadata">

**Author:** [@marone](https://discuss.elastic.co/u/marone)\
**Replies:** 4\
**Last updated:** [April 18, 2021, 1:24pm UTC](https://discuss.elastic.co/t/heartbeat-showing-my-nodes-as-down-but-they-are-up/270406 "2021-04-18T13:24:21Z")

</div>

I set up heartbeat with my cluster ELK 7.12 (2 nodes) running on separate VMs, everything working fine, but when I enabled transport ssl and generated certificates for each node, heartbeat keeps showing that my nodes are…

---

## [Fix unmatched quote and non-whitespaces in csv fields (Filebeat and Ingest Pipeline)](https://discuss.elastic.co/t/fix-unmatched-quote-and-non-whitespaces-in-csv-fields-filebeat-and-ingest-pipeline/270492)

<div class="topic-metadata">

**Author:** [@rawartani](https://discuss.elastic.co/u/rawartani)\
**Replies:** 0\
**Last updated:** [April 18, 2021, 12:00pm UTC](https://discuss.elastic.co/t/fix-unmatched-quote-and-non-whitespaces-in-csv-fields-filebeat-and-ingest-pipeline/270492 "2021-04-18T12:00:19Z")

</div>

I am shipping csv data using Filebeat to the Elasticsearch output, I have an ingest pipeline in place to process the events but I am encountering two events failure: (status=400): {"type":"illegal\_argument\_exception","…

---

## [Configuration sharing](https://discuss.elastic.co/t/configuration-sharing/270126)

<div class="topic-metadata">

**Author:** [@speechkey](https://discuss.elastic.co/u/speechkey)\
**Replies:** 3\
**Last updated:** [April 18, 2021, 4:12am UTC](https://discuss.elastic.co/t/configuration-sharing/270126 "2021-04-18T04:12:09Z")

</div>

Hi folks, we have one installation of Elasticsearch & Kibana and multiple teams which logs to it. We deploy our services as Docker containers and each of the Docker hosts has a Filebeat container which ships the logs fr…

---

## [Dissect message playground](https://discuss.elastic.co/t/dissect-message-playground/268207)

<div class="topic-metadata">

**Author:** [@Catalin\_Dinuta](https://discuss.elastic.co/u/Catalin_Dinuta)\
**Replies:** 1\
**Last updated:** [April 17, 2021, 11:57pm UTC](https://discuss.elastic.co/t/dissect-message-playground/268207 "2021-04-17T23:57:14Z")

</div>

Hi community, I searched some playground for dissecting a log message but I was unable to find it, and so I always receive dissect error. The filebeat configuration is: filebeat.inputs: - type: log paths: …

---

## [Getting Data from Syslog into Elasticsearch/Kibana](https://discuss.elastic.co/t/getting-data-from-syslog-into-elasticsearch-kibana/270464)

<div class="topic-metadata">

**Author:** [@bryonadams](https://discuss.elastic.co/u/bryonadams)\
**Replies:** 0\
**Last updated:** [April 17, 2021, 8:33pm UTC](https://discuss.elastic.co/t/getting-data-from-syslog-into-elasticsearch-kibana/270464 "2021-04-17T20:33:49Z")

</div>

I've just gotten my first Filebeats agent running and sending data into Elasticsearch, though I'm not sure why the messages are so long. I'm guessing everything after this @timestamp field is something from Beats or Elas…

---

## [Can I Reduce FileBeat Executeable File Size By Config Something or Comment Something Before build?](https://discuss.elastic.co/t/can-i-reduce-filebeat-executeable-file-size-by-config-something-or-comment-something-before-build/270453)

<div class="topic-metadata">

**Author:** [@yulei](https://discuss.elastic.co/u/yulei)\
**Replies:** 0\
**Last updated:** [April 17, 2021, 4:23pm UTC](https://discuss.elastic.co/t/can-i-reduce-filebeat-executeable-file-size-by-config-something-or-comment-something-before-build/270453 "2021-04-17T16:23:49Z")

</div>

I unpack all versions of the filebeat-${version}-x86\_64.rpm and stats the size of Executeable Files. I found that after some break changes in version 6.0.0, the size of the Executeable File Jump to 45M from 16M(size …

---

## [Can't get kibana to display filebeat logs with docker auto discovery](https://discuss.elastic.co/t/cant-get-kibana-to-display-filebeat-logs-with-docker-auto-discovery/269810)

<div class="topic-metadata">

**Author:** [@LongBeachHXC](https://discuss.elastic.co/u/LongBeachHXC)\
**Replies:** 3\
**Last updated:** [April 17, 2021, 2:11pm UTC](https://discuss.elastic.co/t/cant-get-kibana-to-display-filebeat-logs-with-docker-auto-discovery/269810 "2021-04-17T14:11:39Z")

</div>

I am trying to leverage the docker auto discovery provider. I followed every tutorial I could find regarding filebeat and I still cannot get Kibana to display the logs. I am trying to get this working with the Elastic Se…

---

## [How can I skip recording an event with these conditions](https://discuss.elastic.co/t/how-can-i-skip-recording-an-event-with-these-conditions/270422)

<div class="topic-metadata">

**Author:** [@jftuga](https://discuss.elastic.co/u/jftuga)\
**Replies:** 1\
**Last updated:** [April 17, 2021, 6:29am UTC](https://discuss.elastic.co/t/how-can-i-skip-recording-an-event-with-these-conditions/270422 "2021-04-17T06:29:07Z")

</div>

I am using winlogbeat. How can I exclude events that meet the following criteria: event\_id = 4670 only when the "related": "user" value ends with a $ (alternatively) the "user": "name" ends with a $ Values that end in…

---

## [Metricset:state\_container slow to ingest and missing configured 10s sample intervals](https://discuss.elastic.co/t/metricset-state-container-slow-to-ingest-and-missing-configured-10s-sample-intervals/269534)

<div class="topic-metadata">

**Author:** [@MnrGreg](https://discuss.elastic.co/u/MnrGreg)\
**Replies:** 4\
**Last updated:** [April 17, 2021, 12:37am UTC](https://discuss.elastic.co/t/metricset-state-container-slow-to-ingest-and-missing-configured-10s-sample-intervals/269534 "2021-04-17T00:37:19Z")

</div>

Observing slow sample rate for module:kubernetes metricset: state\_container on cluster with +-2000 containers. Documents are ingested roughly every 13 seconds. - Versions: metricbeat: 7.12.0 & 6.8.2 kubernetes: 1.19.2 …

---

## [Check input contains.message failed](https://discuss.elastic.co/t/check-input-contains-message-failed/270372)

<div class="topic-metadata">

**Author:** [@joepkemel](https://discuss.elastic.co/u/joepkemel)\
**Replies:** 1\
**Last updated:** [April 16, 2021, 2:33pm UTC](https://discuss.elastic.co/t/check-input-contains-message-failed/270372 "2021-04-16T14:33:09Z")

</div>

Hi, I am trying to make an if contains /else dissect statement. But I can't really figure it out. This is because a log file contains an extra '|' inside a wanted field. For example 'type|timestamp|IP\[xx.xx| port\]|-' and…

---

## [How to configure multiple ingest pipelines on filebeat to load data in elastic cloud](https://discuss.elastic.co/t/how-to-configure-multiple-ingest-pipelines-on-filebeat-to-load-data-in-elastic-cloud/270290)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 4\
**Last updated:** [April 16, 2021, 1:39pm UTC](https://discuss.elastic.co/t/how-to-configure-multiple-ingest-pipelines-on-filebeat-to-load-data-in-elastic-cloud/270290 "2021-04-16T13:39:30Z")

</div>

Hi, I am running filebeat to ingest logging data from kubernetes. I am having various applications for which I have set different pipelines. How can I configure filebeat to be able to use multiple pipelines. Thanks in …

---

## [Period system.cpu.total.pct versus system.cpu.total.norm.pct](https://discuss.elastic.co/t/period-system-cpu-total-pct-versus-system-cpu-total-norm-pct/270229)

<div class="topic-metadata">

**Author:** [@\_Manuel](https://discuss.elastic.co/u/_Manuel)\
**Replies:** 4\
**Last updated:** [April 16, 2021, 11:04am UTC](https://discuss.elastic.co/t/period-system-cpu-total-pct-versus-system-cpu-total-norm-pct/270229 "2021-04-16T11:04:10Z")

</div>

Hello I have a metricbeat.yml file for system.cpu like metricbeat.modules: - module: system period: 150s metricsets: - cpu - load - memory - network - process - process\_summary cpu.metrics…

---

## [Oracle Metrics through metricbeat](https://discuss.elastic.co/t/oracle-metrics-through-metricbeat/270182)

<div class="topic-metadata">

**Author:** [@Dhruvil\_Doshi](https://discuss.elastic.co/u/Dhruvil_Doshi)\
**Replies:** 3\
**Last updated:** [April 16, 2021, 7:42am UTC](https://discuss.elastic.co/t/oracle-metrics-through-metricbeat/270182 "2021-04-16T07:42:40Z")

</div>

I am using ELK 7.10 Basic version. I want to get oracle metrics from metricbeat. I enabled oracle module from below command : metricbeat modules enable oracle I installed oracle client and set it's path as system varia…

---

## [Filebeat failed to collect docker metadata](https://discuss.elastic.co/t/filebeat-failed-to-collect-docker-metadata/270321)

<div class="topic-metadata">

**Author:** [@ktpktr0](https://discuss.elastic.co/u/ktpktr0)\
**Replies:** 0\
**Last updated:** [April 16, 2021, 3:20am UTC](https://discuss.elastic.co/t/filebeat-failed-to-collect-docker-metadata/270321 "2021-04-16T03:20:05Z")

</div>

I use filebeat to collect docker container logs. The log is collected by ID, but the corresponding container name cannot be collected. So I tried to add metadata for the docker container, but I couldn't succeed（Auto disc…

---

## [Is metricbeat pod sending right host metadata on kubernetes?](https://discuss.elastic.co/t/is-metricbeat-pod-sending-right-host-metadata-on-kubernetes/270177)

<div class="topic-metadata">

**Author:** [@roh](https://discuss.elastic.co/u/roh)\
**Replies:** 2\
**Last updated:** [April 16, 2021, 12:15am UTC](https://discuss.elastic.co/t/is-metricbeat-pod-sending-right-host-metadata-on-kubernetes/270177 "2021-04-16T00:15:49Z")

</div>

Hi all! Thanks to you guys that I could deploy metricbeat pods on AWS EKS easily because of yaml file on documentation. I added add\_host\_metadata processor and watched how host os data comes and it was like below: "h…

---

## [Problem when activating Flattened field type on Filebeat fields.yml](https://discuss.elastic.co/t/problem-when-activating-flattened-field-type-on-filebeat-fields-yml/270168)

<div class="topic-metadata">

**Author:** [@Laamimech\_Salah](https://discuss.elastic.co/u/Laamimech_Salah)\
**Replies:** 0\
**Last updated:** [April 15, 2021, 2:43am UTC](https://discuss.elastic.co/t/problem-when-activating-flattened-field-type-on-filebeat-fields-yml/270168 "2021-04-15T02:43:00Z")

</div>

Hello, We encounter an error like the one in the following example ,when we activate Flattened field type on the template /etc/filebeat/fields.yml : Filebeat version : 7.6.2 Elasticsearch version : 7.6.2 2021-04-15T0…

---

## [Functionbeat for logs available in S3 bucket](https://discuss.elastic.co/t/functionbeat-for-logs-available-in-s3-bucket/270305)

<div class="topic-metadata">

**Author:** [@Shivani92](https://discuss.elastic.co/u/Shivani92)\
**Replies:** 0\
**Last updated:** [April 15, 2021, 7:55pm UTC](https://discuss.elastic.co/t/functionbeat-for-logs-available-in-s3-bucket/270305 "2021-04-15T19:55:16Z")

</div>

Can we use functionbeat to ship logs available in s3 bucket to Elasticsearch? If yes, kindly explain flow and functionbeat configuration a bit.

---

## [Filebeat Zeek module doesn’t add ECS fields to zeek logs](https://discuss.elastic.co/t/filebeat-zeek-module-doesn-t-add-ecs-fields-to-zeek-logs/270047)

<div class="topic-metadata">

**Author:** [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Replies:** 2\
**Last updated:** [April 15, 2021, 4:36pm UTC](https://discuss.elastic.co/t/filebeat-zeek-module-doesn-t-add-ecs-fields-to-zeek-logs/270047 "2021-04-15T16:36:27Z")

</div>

Hi all, I followed the official documentation and I’ve changed zeek’s output to json logs but somehow zeek module from Filebeat does’t enrich data with ECS fields. Filebeat sends the logs, but without adding the extra f…

---

## [ERROR instance/beat.go:971 Exiting: resource 'filebeat-7.12.0' exists, but it is not an alias](https://discuss.elastic.co/t/error-instance-beat-go-971-exiting-resource-filebeat-7-12-0-exists-but-it-is-not-an-alias/270139)

<div class="topic-metadata">

**Author:** [@thrak](https://discuss.elastic.co/u/thrak)\
**Replies:** 4\
**Last updated:** [April 15, 2021, 2:17pm UTC](https://discuss.elastic.co/t/error-instance-beat-go-971-exiting-resource-filebeat-7-12-0-exists-but-it-is-not-an-alias/270139 "2021-04-15T14:17:05Z")

</div>

Hello, I am in the process of installing filebeats 7.12 on some elastic cluster nodes in my dev environment and when I run: sudo filebeat setup -e On one of my nodes, I receive this error. ERROR instance/beat.go:971…

---

## [Filebeat systemd not writing logs to log directory](https://discuss.elastic.co/t/filebeat-systemd-not-writing-logs-to-log-directory/270247)

<div class="topic-metadata">

**Author:** [@madhan\_dhanikachalam](https://discuss.elastic.co/u/madhan_dhanikachalam)\
**Replies:** 0\
**Last updated:** [April 15, 2021, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-systemd-not-writing-logs-to-log-directory/270247 "2021-04-15T14:04:48Z")

</div>

I have filebeat 7.12 and have the below systemd service \[Unit\] Description=Filebeat sends log files to Logstash or directly to Elasticsearch. Documentation=https://www.elastic.co/products/beats/filebeat Wants=network-on…

---

## [Filebeat to kafka failure](https://discuss.elastic.co/t/filebeat-to-kafka-failure/270163)

<div class="topic-metadata">

**Author:** [@madhan\_dhanikachalam](https://discuss.elastic.co/u/madhan_dhanikachalam)\
**Replies:** 4\
**Last updated:** [April 15, 2021, 1:57pm UTC](https://discuss.elastic.co/t/filebeat-to-kafka-failure/270163 "2021-04-15T13:57:56Z")

</div>

filebeat on server 1 seems to send log data to kafka perfectly, no issues.. set up filebeat on server2 to send log data to kafka and get the below error 2021-04-14T20:46:28.475-0400 INFO \[publisher\] pipeline/…

---

## [Negative Kafka partition bug](https://discuss.elastic.co/t/negative-kafka-partition-bug/270046)

<div class="topic-metadata">

**Author:** [@cbrown184](https://discuss.elastic.co/u/cbrown184)\
**Replies:** 1\
**Last updated:** [April 13, 2021, 11:38pm UTC](https://discuss.elastic.co/t/negative-kafka-partition-bug/270046 "2021-04-13T23:38:01Z")

</div>

Hi - we use Filebeat to output our logs to Kafka. We got hit by a nasty bug in prod where Filebeat gets stuck in an endless loop. It was previously documented on this thread Filebeat kafka output hash.hash get negative …

---

## [Winlogbeats path based on date](https://discuss.elastic.co/t/winlogbeats-path-based-on-date/270161)

<div class="topic-metadata">

**Author:** [@witkacy](https://discuss.elastic.co/u/witkacy)\
**Replies:** 1\
**Last updated:** [April 15, 2021, 8:35am UTC](https://discuss.elastic.co/t/winlogbeats-path-based-on-date/270161 "2021-04-15T08:35:04Z")

</div>

Hello, Is it possible put result logs to file/folder with name based on actual time? So that for each day I would have separate folder with logs like c:/tmp/20210415/logFile1... c:/tmp/20210416/logFile1... c:/tmp/20…

---

## [FILEBEAT module Fortinet : Provided Grok expressions do not match field value](https://discuss.elastic.co/t/filebeat-module-fortinet-provided-grok-expressions-do-not-match-field-value/269986)

<div class="topic-metadata">

**Author:** [@Alex\_Lum](https://discuss.elastic.co/u/Alex_Lum)\
**Replies:** 9\
**Last updated:** [April 15, 2021, 8:12am UTC](https://discuss.elastic.co/t/filebeat-module-fortinet-provided-grok-expressions-do-not-match-field-value/269986 "2021-04-15T08:12:37Z")

</div>

Hello, I send fortigate logs via rsylog on /var/log/fortigate\* files. I 've configured filebeat with fortinet module. On kibana, i get this : Provided Grok expressions do not match field value It was working with udp…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=163)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=165)
