# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=165

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 166

---

## [Metricbeat 7.12 cpu usage always zero](https://discuss.elastic.co/t/metricbeat-7-12-cpu-usage-always-zero/270192)

<div class="topic-metadata">

**Author:** [@Chandler-Bin](https://discuss.elastic.co/u/Chandler-Bin)\
**Replies:** 0\
**Last updated:** [April 15, 2021, 6:43am UTC](https://discuss.elastic.co/t/metricbeat-7-12-cpu-usage-always-zero/270192 "2021-04-15T06:43:01Z")

</div>

Testing metricbeat 7.12, I got cpu usage always 0. (memory usage is correct). The metricbeat is running on Windows 2019 and CentOS 7.9 . (both are hyper-v VM) Any idea?

---

## [Filebeat error](https://discuss.elastic.co/t/filebeat-error/270189)

<div class="topic-metadata">

**Author:** [@keerthi\_s](https://discuss.elastic.co/u/keerthi_s)\
**Replies:** 1\
**Last updated:** [April 15, 2021, 6:38am UTC](https://discuss.elastic.co/t/filebeat-error/270189 "2021-04-15T06:38:07Z")

</div>

filebeat\[18723\]: 2021-04-15T02:02:54.874-0400 ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 Failed to connect to backoff(elasticsearch(https://xx.xx.xx.xx:9200)): Get "https://xx.xx…

---

## [Packetbeat data is reverse](https://discuss.elastic.co/t/packetbeat-data-is-reverse/270171)

<div class="topic-metadata">

**Author:** [@ARDiver86](https://discuss.elastic.co/u/ARDiver86)\
**Replies:** 0\
**Last updated:** [April 15, 2021, 3:16am UTC](https://discuss.elastic.co/t/packetbeat-data-is-reverse/270171 "2021-04-15T03:16:22Z")

</div>

I'm noticing that a lot of data coming in from Packetbeat (if not all) is in reverse as far as traffic direction. For example we have a web server nat through a Fortigate firewall for port 443. Packetbeat is reporting th…

---

## [Usage of Winlogbeat on Linux / Parse plaintext windows events files](https://discuss.elastic.co/t/usage-of-winlogbeat-on-linux-parse-plaintext-windows-events-files/270113)

<div class="topic-metadata">

**Author:** [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Replies:** 1\
**Last updated:** [April 14, 2021, 2:52pm UTC](https://discuss.elastic.co/t/usage-of-winlogbeat-on-linux-parse-plaintext-windows-events-files/270113 "2021-04-14T14:52:13Z")

</div>

We have the need to run winlogbeat on Linux. I see that there are no precompiled binaries for Linux which is somewhat understandable. In our usecase winlog events are transported via syslog to a linux VM. There parsin…

---

## [Apikeys and elastic cloud](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856)

<div class="topic-metadata">

**Author:** [@alfredo.deluca](https://discuss.elastic.co/u/alfredo.deluca)\
**Replies:** 6\
**Last updated:** [April 14, 2021, 12:30pm UTC](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856 "2021-04-14T12:30:42Z")

</div>

Hi all. We use elastic cloud 7.12. We have also metricbeat and filebeat running on node and k8s cluster and for their configurations I use cloud.id and cloud.auth has ta user (beats\_setup) with those privileges. Now I'…

---

## [Header transform concern need help](https://discuss.elastic.co/t/header-transform-concern-need-help/269064)

<div class="topic-metadata">

**Author:** [@jkaufmanlr](https://discuss.elastic.co/u/jkaufmanlr)\
**Replies:** 22\
**Last updated:** [April 14, 2021, 12:00pm UTC](https://discuss.elastic.co/t/header-transform-concern-need-help/269064 "2021-04-14T12:00:51Z")

</div>

I have an API POST that I want filebeat to contact. This API calls for having in the header the value: x-api-key : apiToken I have attempted the following \> request.transforms: - set: target: header …

---

## [How to use filebeat to collect only the day's logs](https://discuss.elastic.co/t/how-to-use-filebeat-to-collect-only-the-days-logs/269409)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 16\
**Last updated:** [April 14, 2021, 10:37am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-to-collect-only-the-days-logs/269409 "2021-04-14T10:37:21Z")

</div>

I'm using filebeat to collect logs. The name of the target log is "api-yyyy-mm-dd.log". If you set the paths setting of filebeat as follows, all files will be collected. - type: log paths: - /var/log/api/api-\*.l…

---

## [Adding processed fields with metricbeat processors](https://discuss.elastic.co/t/adding-processed-fields-with-metricbeat-processors/270012)

<div class="topic-metadata">

**Author:** [@m\_x](https://discuss.elastic.co/u/m_x)\
**Replies:** 1\
**Last updated:** [April 14, 2021, 8:12am UTC](https://discuss.elastic.co/t/adding-processed-fields-with-metricbeat-processors/270012 "2021-04-14T08:12:35Z")

</div>

I would like to add some fields to the data sent by Metricbeat. My machines have a hostname like this AA-BBB-CCXX where A, B, C are letters and X numbers. I would like to have : host.group: "AA-BBB-CC" host.number: "X…

---

## [Reading Wazuh data from kafka, write to Elasticsearch using Filebeat and pipeline](https://discuss.elastic.co/t/reading-wazuh-data-from-kafka-write-to-elasticsearch-using-filebeat-and-pipeline/270078)

<div class="topic-metadata">

**Author:** [@ThreatInter](https://discuss.elastic.co/u/ThreatInter)\
**Replies:** 0\
**Last updated:** [April 14, 2021, 6:24am UTC](https://discuss.elastic.co/t/reading-wazuh-data-from-kafka-write-to-elasticsearch-using-filebeat-and-pipeline/270078 "2021-04-14T06:24:50Z")

</div>

Hi, community. I want to read Wazuh data from kafka and write it to Elasticsearch. All way looks like: wazuh-manager-\>filebeat-\>logstash-\>nifi-\>kafka\_\>filebeat-\>elasticsearch. I try to write to elasticsearch using nati…

---

## [Filebeat can't keep up with the logs](https://discuss.elastic.co/t/filebeat-cant-keep-up-with-the-logs/269621)

<div class="topic-metadata">

**Author:** [@grazia0912](https://discuss.elastic.co/u/grazia0912)\
**Replies:** 2\
**Last updated:** [April 14, 2021, 3:25am UTC](https://discuss.elastic.co/t/filebeat-cant-keep-up-with-the-logs/269621 "2021-04-14T03:25:51Z")

</div>

I'm using Filebeat 7.4.2 and it seems to not get all events on my log file. The log file is updating at a high speed cause of huge messages being logged and Filebeat couldn't seem to keep up and send all messages to Logs…

---

## [Systemd\[1\]: Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/systemd-1-failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/269634)

<div class="topic-metadata">

**Author:** [@Elam](https://discuss.elastic.co/u/Elam)\
**Replies:** 1\
**Last updated:** [April 14, 2021, 1:00am UTC](https://discuss.elastic.co/t/systemd-1-failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/269634 "2021-04-14T01:00:59Z")

</div>

Please some one have an idea how to start filebeats to read data from log and send it to elasticsearch. I have this issues: systemd\[1\]: Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch.…

---

## [Yaml: found character that cannot start any token when value starts with "@"](https://discuss.elastic.co/t/yaml-found-character-that-cannot-start-any-token-when-value-starts-with/269778)

<div class="topic-metadata">

**Author:** [@joecullin.skout](https://discuss.elastic.co/u/joecullin.skout)\
**Replies:** 1\
**Last updated:** [April 13, 2021, 11:56pm UTC](https://discuss.elastic.co/t/yaml-found-character-that-cannot-start-any-token-when-value-starts-with/269778 "2021-04-13T23:56:12Z")

</div>

Using o365 filebeat module. Getting this error: cfgfile/list.go:99 Error creating runner from config: Error getting config for fileset o365/audit: Error reading input config: yaml: line 12: found character that ca…

---

## [MongoDB 4.4.4 compatibility with Filebeat 7.12.0](https://discuss.elastic.co/t/mongodb-4-4-4-compatibility-with-filebeat-7-12-0/270013)

<div class="topic-metadata">

**Author:** [@Cihan\_Tunali](https://discuss.elastic.co/u/Cihan_Tunali)\
**Replies:** 1\
**Last updated:** [April 13, 2021, 11:51pm UTC](https://discuss.elastic.co/t/mongodb-4-4-4-compatibility-with-filebeat-7-12-0/270013 "2021-04-13T23:51:42Z")

</div>

Hi there, I was using MongoDB 4.2.4 with Filebeat 7.9.0 without any problem. After updating MongoDB to 4.4.4 I got GROK problems. I also updated Filebeat to 7.12.0 as well but still got GROK error so that I can not pars…

---

## [Setting multiple pipelines for elasticserach.output](https://discuss.elastic.co/t/setting-multiple-pipelines-for-elasticserach-output/269999)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 1\
**Last updated:** [April 13, 2021, 3:52pm UTC](https://discuss.elastic.co/t/setting-multiple-pipelines-for-elasticserach-output/269999 "2021-04-13T15:52:22Z")

</div>

Hello, Is It possible to use for example metricbeat.yml config file for setting multiple ingest node pipelines for the same document/index? I triend something like this but only the first one work. #-------------------…

---

## [Unable to find elasticsearch, logstash, kibana metrics on stackmonitoring even after having all the .monitoring-\* indices created and the Cluster\_uuid is right](https://discuss.elastic.co/t/unable-to-find-elasticsearch-logstash-kibana-metrics-on-stackmonitoring-even-after-having-all-the-monitoring-indices-created-and-the-cluster-uuid-is-right/269513)

<div class="topic-metadata">

**Author:** [@Pooja](https://discuss.elastic.co/u/Pooja)\
**Replies:** 3\
**Last updated:** [April 8, 2021, 2:19pm UTC](https://discuss.elastic.co/t/unable-to-find-elasticsearch-logstash-kibana-metrics-on-stackmonitoring-even-after-having-all-the-monitoring-indices-created-and-the-cluster-uuid-is-right/269513 "2021-04-08T14:19:09Z")

</div>

Unable to find elasticsearch, logstash, kibana metrics on stackmonitoring even after having all the .monitoring-\* indices created and the Cluster\_uuid is right.

---

## [Timestamp issue with Cisco ios module](https://discuss.elastic.co/t/timestamp-issue-with-cisco-ios-module/269987)

<div class="topic-metadata">

**Author:** [@rs-patrick](https://discuss.elastic.co/u/rs-patrick)\
**Replies:** 0\
**Last updated:** [April 13, 2021, 9:56am UTC](https://discuss.elastic.co/t/timestamp-issue-with-cisco-ios-module/269987 "2021-04-13T09:56:24Z")

</div>

Hello together, If i use the Cisco ios module, i have an issue with the timezone. The field @timestamp contains Z instead of +2.00 (from MEST). Here my example: Here the input logline: Apr 13 08:59:29 test.ch 2916048…

---

## [How to change field type of filebeat modules?](https://discuss.elastic.co/t/how-to-change-field-type-of-filebeat-modules/269966)

<div class="topic-metadata">

**Author:** [@new2\_elk](https://discuss.elastic.co/u/new2_elk)\
**Replies:** 4\
**Last updated:** [April 13, 2021, 9:33am UTC](https://discuss.elastic.co/t/how-to-change-field-type-of-filebeat-modules/269966 "2021-04-13T09:33:57Z")

</div>

Hi guys, I am using the panw module on filebeat to pass log to logstash then pass to Elasticsearch. Then I added 1 more extract field in the "/usr/share/filebeat/module/panw/panos/config/input.yml" but the default type…

---

## [Filebeat Autodiscover Issue](https://discuss.elastic.co/t/filebeat-autodiscover-issue/269970)

<div class="topic-metadata">

**Author:** [@danielc](https://discuss.elastic.co/u/danielc)\
**Replies:** 1\
**Last updated:** [April 13, 2021, 8:19am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-issue/269970 "2021-04-13T08:19:04Z")

</div>

Some errors occurred when I had below filebeat config. How can I fix the issue? org.elasticsearch.index.mapper.MapperParsingException: object mapping for \[json\] tried to parse field \[json\] as object, but found a concret…

---

## [Retrive File logs from remote server using file beat without deploying filebeat to remote server](https://discuss.elastic.co/t/retrive-file-logs-from-remote-server-using-file-beat-without-deploying-filebeat-to-remote-server/269894)

<div class="topic-metadata">

**Author:** [@mrunalini](https://discuss.elastic.co/u/mrunalini)\
**Replies:** 1\
**Last updated:** [April 13, 2021, 8:17am UTC](https://discuss.elastic.co/t/retrive-file-logs-from-remote-server-using-file-beat-without-deploying-filebeat-to-remote-server/269894 "2021-04-13T08:17:39Z")

</div>

Hi Team, We have requirement of retrieving file logs from multiple remote server . Remote server will put the file logs in specific folder location , we need to retrieve those logs and share it in Log stash for further…

---

## [How Can I Control JSON Parsing Depth?](https://discuss.elastic.co/t/how-can-i-control-json-parsing-depth/269969)

<div class="topic-metadata">

**Author:** [@danielc](https://discuss.elastic.co/u/danielc)\
**Replies:** 1\
**Last updated:** [April 13, 2021, 8:16am UTC](https://discuss.elastic.co/t/how-can-i-control-json-parsing-depth/269969 "2021-04-13T08:16:50Z")

</div>

In Decode JSON fields | Filebeat Reference \[7.12\] | Elastic max\_depth (Optional) The maximum parsing depth. A value of 1 will decode the JSON objects in fields indicated in fields, a value of 2 will also decode the obj…

---

## [Filebeat Ingests K8S Older Logs](https://discuss.elastic.co/t/filebeat-ingests-k8s-older-logs/269950)

<div class="topic-metadata">

**Author:** [@danielc](https://discuss.elastic.co/u/danielc)\
**Replies:** 1\
**Last updated:** [April 13, 2021, 8:15am UTC](https://discuss.elastic.co/t/filebeat-ingests-k8s-older-logs/269950 "2021-04-13T08:15:06Z")

</div>

I'm using beats/filebeat-kubernetes.yaml at v7.8.1 · elastic/beats · GitHub to ingest K8S. There have been 2 issues: Filebeat picks up older logs when there is an other application deployment and generates old indices …

---

## [Winlogbeat setup error: x509 certificate is valid for \<ip\>, not \<same ip\>](https://discuss.elastic.co/t/winlogbeat-setup-error-x509-certificate-is-valid-for-ip-not-same-ip/269176)

<div class="topic-metadata">

**Author:** [@Michlol\_502](https://discuss.elastic.co/u/Michlol_502)\
**Replies:** 6\
**Last updated:** [April 13, 2021, 7:44am UTC](https://discuss.elastic.co/t/winlogbeat-setup-error-x509-certificate-is-valid-for-ip-not-same-ip/269176 "2021-04-13T07:44:43Z")

</div>

I'm trying to send logs from Winlogbeat to my ELK stack. I did everything according to the official guide and it worked for my host. However, when copying the same winlogbeat directory to my Event Collector server, it di…

---

## [How Do I Change The Format Of A Metric/File Beat Log Field?](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723)

<div class="topic-metadata">

**Author:** [@kss](https://discuss.elastic.co/u/kss)\
**Replies:** 6\
**Last updated:** [April 13, 2021, 3:22am UTC](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723 "2021-04-13T03:22:21Z")

</div>

I am using ElasticSearch FileBeat and MetricBeat to provide logging for my apps. I am using Grafana to visualize this log data. I do have a question though regarding the host.hostname field.... This field is storing t…

---

## [Multiple Tenant in O365 module from Filebeat](https://discuss.elastic.co/t/multiple-tenant-in-o365-module-from-filebeat/269445)

<div class="topic-metadata">

**Author:** [@Sebdb3](https://discuss.elastic.co/u/Sebdb3)\
**Replies:** 3\
**Last updated:** [April 12, 2021, 2:14pm UTC](https://discuss.elastic.co/t/multiple-tenant-in-o365-module-from-filebeat/269445 "2021-04-12T14:14:52Z")

</div>

Hello everyone ! I recently added the o365 filebeat module for my tenant to a server. Good news it works perfectly but I wanted to add another tenant o365 on the same server, I didn't find any information about that. …

---

## [PacketBeats Oracle support](https://discuss.elastic.co/t/packetbeats-oracle-support/268582)

<div class="topic-metadata">

**Author:** [@tmihaldinec](https://discuss.elastic.co/u/tmihaldinec)\
**Replies:** 3\
**Last updated:** [April 12, 2021, 11:36am UTC](https://discuss.elastic.co/t/packetbeats-oracle-support/268582 "2021-04-12T11:36:24Z")

</div>

Dear all, is there any plan to support Oracle with packetbeat? Most of system we use are using Oracle DB and it would be awesome to have this feature Thanks tomislav

---

## [Need to restart filebeat time to time](https://discuss.elastic.co/t/need-to-restart-filebeat-time-to-time/269845)

<div class="topic-metadata">

**Author:** [@danushkalakmina](https://discuss.elastic.co/u/danushkalakmina)\
**Replies:** 4\
**Last updated:** [April 12, 2021, 9:56am UTC](https://discuss.elastic.co/t/need-to-restart-filebeat-time-to-time/269845 "2021-04-12T09:56:36Z")

</div>

Hi i have issue on filebeat Logs are not showing every 6hours(approximately) in Kibana dashboard. After restarting the filebeat ,Kibana dashboard gets logs again .my filebeat needs to restart around every 6 hours to kee…

---

## [Filebeat setup error Request Time-out](https://discuss.elastic.co/t/filebeat-setup-error-request-time-out/269821)

<div class="topic-metadata">

**Author:** [@Leon2](https://discuss.elastic.co/u/Leon2)\
**Replies:** 3\
**Last updated:** [April 12, 2021, 9:30am UTC](https://discuss.elastic.co/t/filebeat-setup-error-request-time-out/269821 "2021-04-12T09:30:09Z")

</div>

Hi I'm struggeling in setting up filebeat to work with elastic cloud instance. all I'm trying to do is enabling a module( without changing any config, yet) and uplouding dashboard setting from filebeat to elastic cloud …

---

## [How to get JVM Memory used with metricbeat jolokia module](https://discuss.elastic.co/t/how-to-get-jvm-memory-used-with-metricbeat-jolokia-module/267828)

<div class="topic-metadata">

**Author:** [@wifi](https://discuss.elastic.co/u/wifi)\
**Replies:** 4\
**Last updated:** [April 12, 2021, 6:49am UTC](https://discuss.elastic.co/t/how-to-get-jvm-memory-used-with-metricbeat-jolokia-module/267828 "2021-04-12T06:49:33Z")

</div>

I'm trying to use Jolokia + metricbeat to gather Info about the JVM Memory. I did everything like described in the docs but it won't work. https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-jo…

---

## [Filebeat Module Suggestion](https://discuss.elastic.co/t/filebeat-module-suggestion/268426)

<div class="topic-metadata">

**Author:** [@Rohit\_Kumbhar](https://discuss.elastic.co/u/Rohit_Kumbhar)\
**Replies:** 2\
**Last updated:** [April 12, 2021, 1:33am UTC](https://discuss.elastic.co/t/filebeat-module-suggestion/268426 "2021-04-12T01:33:10Z")

</div>

Hi Elasticsearch Developers, This is kind of suggestion post, I want to integrate Versa-Network Logs into Elasticsearch. and it would be much easier if you include that module in Filebeat. Too much fields for ecs map…

---

## [Log\_file\_path](https://discuss.elastic.co/t/log-file-path/267727)

<div class="topic-metadata">

**Author:** [@christos\_zivlas](https://discuss.elastic.co/u/christos_zivlas)\
**Replies:** 9\
**Last updated:** [April 12, 2021, 12:29am UTC](https://discuss.elastic.co/t/log-file-path/267727 "2021-04-12T00:29:09Z")

</div>

Hi i am using filebeat on windows to get some application logs. Messages are harvest using a wildcard path. messages coming in do not contain the path of the log, is there a way to place such a field in the log message?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=164)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=166)
