# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=166

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 167

---

## [Metricbeat - mysql module - galera\_status metricset](https://discuss.elastic.co/t/metricbeat-mysql-module-galera-status-metricset/267508)

<div class="topic-metadata">

**Author:** [@AlexanderN](https://discuss.elastic.co/u/AlexanderN)\
**Replies:** 5\
**Last updated:** [April 11, 2021, 8:57pm UTC](https://discuss.elastic.co/t/metricbeat-mysql-module-galera-status-metricset/267508 "2021-04-11T20:57:02Z")

</div>

Hello! First time poster searching for an answer to a problem that google isn't helpful with. I am using Metricbeat with the mysql module to send metrics from my "5.7.30-log" mysql server with the "galera\_status" metri…

---

## [Winlogbeats remove @metadata, agent and ecs fields](https://discuss.elastic.co/t/winlogbeats-remove-metadata-agent-and-ecs-fields/269764)

<div class="topic-metadata">

**Author:** [@witkacy](https://discuss.elastic.co/u/witkacy)\
**Replies:** 1\
**Last updated:** [April 11, 2021, 1:35pm UTC](https://discuss.elastic.co/t/winlogbeats-remove-metadata-agent-and-ecs-fields/269764 "2021-04-11T13:35:40Z")

</div>

Hello, Is it possible to not include in exported log fields: @metadata, agent and ecs? I added processor - drop\_fields: fields: \["host", "log", "event", "agent", "ecs", "winlog", "@metadata"\] and most of…

---

## [I have this error bash: ./metricbeat: cannot execute binary file: Exec format error](https://discuss.elastic.co/t/i-have-this-error-bash-metricbeat-cannot-execute-binary-file-exec-format-error/269157)

<div class="topic-metadata">

**Author:** [@muradazz](https://discuss.elastic.co/u/muradazz)\
**Replies:** 29\
**Last updated:** [April 10, 2021, 2:56am UTC](https://discuss.elastic.co/t/i-have-this-error-bash-metricbeat-cannot-execute-binary-file-exec-format-error/269157 "2021-04-10T02:56:45Z")

</div>

root@mu:/home/murad/metricbeat-7.12.0-darwin-x86\_64# uname -m x86\_64 root@mu:/home/murad/metricbeat-7.12.0-darwin-x86\_64# file metricbeat metricbeat: Mach-O 64-bit x86\_64 executable, flags:\<|DYLDLINK\> root@mu:/home/m…

---

## [Filebeat kafka ssl output](https://discuss.elastic.co/t/filebeat-kafka-ssl-output/269652)

<div class="topic-metadata">

**Author:** [@madhan\_dhanikachalam](https://discuss.elastic.co/u/madhan_dhanikachalam)\
**Replies:** 4\
**Last updated:** [April 9, 2021, 5:12pm UTC](https://discuss.elastic.co/t/filebeat-kafka-ssl-output/269652 "2021-04-09T17:12:32Z")

</div>

Trying to set up ssl kafka output in filebeat. reading a log file and sending to kafka. non-ssl works fine. for ssl i am trying the below #---- kafka output output.kafka: # initial brokers for reading cluster metadat…

---

## [Filebeat kafka output topic name always in lowercase？](https://discuss.elastic.co/t/filebeat-kafka-output-topic-name-always-in-lowercase/269593)

<div class="topic-metadata">

**Author:** [@xxr](https://discuss.elastic.co/u/xxr)\
**Replies:** 1\
**Last updated:** [April 9, 2021, 8:12am UTC](https://discuss.elastic.co/t/filebeat-kafka-output-topic-name-always-in-lowercase/269593 "2021-04-09T08:12:48Z")

</div>

when configure the kafka output topic, I configure the topic name in uppercase . but when start the filebeat it always create the lowercase topic in kafka and send message to that lowercase name topic. is this the fi…

---

## [Filebeat stopped after reaching EOF, with close\_eof:false](https://discuss.elastic.co/t/filebeat-stopped-after-reaching-eof-with-close-eof-false/269662)

<div class="topic-metadata">

**Author:** [@froheik](https://discuss.elastic.co/u/froheik)\
**Replies:** 0\
**Last updated:** [April 9, 2021, 5:54am UTC](https://discuss.elastic.co/t/filebeat-stopped-after-reaching-eof-with-close-eof-false/269662 "2021-04-09T05:54:07Z")

</div>

Hi guys. Need help in that case. Have some trouble with deploying daemonset of filebeat's (releases 7.12 or 7.11.2) in openshift cluster by runtime cri. After starting container, filebeat open harvesters for finded files…

---

## [Using Metricbeat to Monitor MS SQL Server Performance - What Permissions in MS SQL Server?](https://discuss.elastic.co/t/using-metricbeat-to-monitor-ms-sql-server-performance-what-permissions-in-ms-sql-server/267417)

<div class="topic-metadata">

**Author:** [@efaile](https://discuss.elastic.co/u/efaile)\
**Replies:** 1\
**Last updated:** [April 8, 2021, 8:38pm UTC](https://discuss.elastic.co/t/using-metricbeat-to-monitor-ms-sql-server-performance-what-permissions-in-ms-sql-server/267417 "2021-04-08T20:38:43Z")

</div>

Instructions tell you how to install metricbeat and enable the MS SQL server module - but I can find no coverage (anywhere - google, elasticsearch, metricbeat docs) on what the required permissions within MS SQL must be …

---

## [Filebeat fails with connecting to Kibana over GET 127.0.0.1:5601](https://discuss.elastic.co/t/filebeat-fails-with-connecting-to-kibana-over-get-127-0-0-1-5601/269193)

<div class="topic-metadata">

**Author:** [@makrellen](https://discuss.elastic.co/u/makrellen)\
**Replies:** 7\
**Last updated:** [April 8, 2021, 7:10pm UTC](https://discuss.elastic.co/t/filebeat-fails-with-connecting-to-kibana-over-get-127-0-0-1-5601/269193 "2021-04-08T19:10:45Z")

</div>

Description of problem I'm trying to get Filebeat to work on my Ubuntu VPS via docker-compose and I've set it up behind my caddy-reverse proxy and configured everything as I should according to the Filebeat docs, but I …

---

## [Functionbeat environment variables](https://discuss.elastic.co/t/functionbeat-environment-variables/269617)

<div class="topic-metadata">

**Author:** [@sce81](https://discuss.elastic.co/u/sce81)\
**Replies:** 0\
**Last updated:** [April 8, 2021, 3:08pm UTC](https://discuss.elastic.co/t/functionbeat-environment-variables/269617 "2021-04-08T15:08:17Z")

</div>

Hi, i am wondering if it is possible to override the functionbeat.yml parameters using environment variables? eg: i want to send to elasticsearch with credentials stored as encrypted env vars, but i want this configured…

---

## [Field contains CSV want to extract to array of strings](https://discuss.elastic.co/t/field-contains-csv-want-to-extract-to-array-of-strings/269494)

<div class="topic-metadata">

**Author:** [@ian351c](https://discuss.elastic.co/u/ian351c)\
**Replies:** 4\
**Last updated:** [April 8, 2021, 3:00pm UTC](https://discuss.elastic.co/t/field-contains-csv-want-to-extract-to-array-of-strings/269494 "2021-04-08T15:00:36Z")

</div>

Hello all, I am working on migrating from Splunk to ELK for my Palo Alto Networks firewall logs using the pre-built processor in Filebeat. The pipeline is Syslog \> Filebeat \> Elastic. The PANW logs contain two separate …

---

## [AWS NLB config infront of FileBeats Instance](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065)

<div class="topic-metadata">

**Author:** [@Ravi342883](https://discuss.elastic.co/u/Ravi342883)\
**Replies:** 6\
**Last updated:** [April 8, 2021, 2:46pm UTC](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065 "2021-04-08T14:46:40Z")

</div>

Hi All, I'm trying to setup a AWS Network Load Balancer (NLB) in-front of Filebeat instance. Need help in 1. How to configure the NLB & 2. How to do health check in NLB. Note: This setup is to collect the logs from v…

---

## [Filebeat Cisco Module Nexus dissect\_parsing\_error](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-dissect-parsing-error/265662)

<div class="topic-metadata">

**Author:** [@vqjanderson](https://discuss.elastic.co/u/vqjanderson)\
**Replies:** 5\
**Last updated:** [April 8, 2021, 2:15pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-dissect-parsing-error/265662 "2021-04-08T14:15:26Z")

</div>

Not sure why these logs are not being parsed correctly. Are the optimized access logging logs not supported by the module?

---

## [What is the source of kubernetes.pod.memory.usage.bytes and kubernetes.pod.cpu.usage.nanocores metrics?](https://discuss.elastic.co/t/what-is-the-source-of-kubernetes-pod-memory-usage-bytes-and-kubernetes-pod-cpu-usage-nanocores-metrics/269053)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 3\
**Last updated:** [April 8, 2021, 9:27am UTC](https://discuss.elastic.co/t/what-is-the-source-of-kubernetes-pod-memory-usage-bytes-and-kubernetes-pod-cpu-usage-nanocores-metrics/269053 "2021-04-08T09:27:45Z")

</div>

I am wondering where the metrics kubernetes.pod.memory.usage.bytes and kubernetes.pod.cpu.usage.nanocores in metricbeat are obtained from? Are they OS statistics? If so, which statistic? I am trying to compare them again…

---

## [Help With Validating This Filebeat Config](https://discuss.elastic.co/t/help-with-validating-this-filebeat-config/269164)

<div class="topic-metadata">

**Author:** [@LongBeachHXC](https://discuss.elastic.co/u/LongBeachHXC)\
**Replies:** 4\
**Last updated:** [April 8, 2021, 3:20am UTC](https://discuss.elastic.co/t/help-with-validating-this-filebeat-config/269164 "2021-04-08T03:20:40Z")

</div>

I am having the toughest time getting filebeat to send logs to my elastic stack. Am I missing something? I have heartbeat and metricbeat working. Filebeat is being fussy with me. filebeat.config: modules: path: ${…

---

## [Filebeat modules not user friendly and missing real references to version and format requirements](https://discuss.elastic.co/t/filebeat-modules-not-user-friendly-and-missing-real-references-to-version-and-format-requirements/268810)

<div class="topic-metadata">

**Author:** [@Mischa\_Diehm](https://discuss.elastic.co/u/Mischa_Diehm)\
**Replies:** 1\
**Last updated:** [April 8, 2021, 3:10am UTC](https://discuss.elastic.co/t/filebeat-modules-not-user-friendly-and-missing-real-references-to-version-and-format-requirements/268810 "2021-04-08T03:10:41Z")

</div>

Hi, many of the filebeat modules have a hint that they were converted from RSA NetWitness log parser XML. After some search and trying to understand how to get to the logformat required by the module I must say that al…

---

## [Use Kafka input in filebeat modules](https://discuss.elastic.co/t/use-kafka-input-in-filebeat-modules/268693)

<div class="topic-metadata">

**Author:** [@LeonT123](https://discuss.elastic.co/u/LeonT123)\
**Replies:** 3\
**Last updated:** [April 8, 2021, 2:46am UTC](https://discuss.elastic.co/t/use-kafka-input-in-filebeat-modules/268693 "2021-04-08T02:46:14Z")

</div>

Hi, Is there anyway to use Kafka input instead of file or other types (.i.e. UDP SYSLOG) in a module? I mean consider the events are available as a Kafka topic (instead of a file). As I checked it seems only file and U…

---

## [Include reference to prebuilt rules for SIEM](https://discuss.elastic.co/t/include-reference-to-prebuilt-rules-for-siem/268700)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 2\
**Last updated:** [April 8, 2021, 2:43am UTC](https://discuss.elastic.co/t/include-reference-to-prebuilt-rules-for-siem/268700 "2021-04-08T02:43:04Z")

</div>

I think it would be very valuable to include a directory that loads the prebuilt SIEM rules\_export.ndjson file in the filebeat configuration. This way if we need to change the default indicies we could modify the json as…

---

## [Filebeat 403 error to SQS](https://discuss.elastic.co/t/filebeat-403-error-to-sqs/269205)

<div class="topic-metadata">

**Author:** [@paano](https://discuss.elastic.co/u/paano)\
**Replies:** 3\
**Last updated:** [April 8, 2021, 12:16am UTC](https://discuss.elastic.co/t/filebeat-403-error-to-sqs/269205 "2021-04-08T00:16:20Z")

</div>

Following the document from elastic blog, S3 log to Elastic using filebeat and SQS, i keep getting error 2021-04-03T13:45:04.022Z ERROR \[input.aws-s3\] awss3/collector.go:101 SQS ReceiveMessageRequest failed: AccessDenie…

---

## [Kubernetes - populate deployment name](https://discuss.elastic.co/t/kubernetes-populate-deployment-name/269308)

<div class="topic-metadata">

**Author:** [@Szymon\_Przepiora](https://discuss.elastic.co/u/Szymon_Przepiora)\
**Replies:** 0\
**Last updated:** [April 6, 2021, 9:06am UTC](https://discuss.elastic.co/t/kubernetes-populate-deployment-name/269308 "2021-04-06T09:06:46Z")

</div>

Hi, I'm trying to populate a field kubernetes.deployment.name. I'm getting only the higher level kubernetes.replicaset.name . There isn't any error in the log. My config: filebeat: enabled: true filebeatConfig: …

---

## [Filebeat azure module error code 409 BlobAlreadyExists](https://discuss.elastic.co/t/filebeat-azure-module-error-code-409-blobalreadyexists/269251)

<div class="topic-metadata">

**Author:** [@sguerrero](https://discuss.elastic.co/u/sguerrero)\
**Replies:** 1\
**Last updated:** [April 7, 2021, 5:03pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-error-code-409-blobalreadyexists/269251 "2021-04-07T17:03:38Z")

</div>

Hi, I'm getting this error from filebeat: Apr 05 15:14:43 SOMETHING filebeat\[410843\]: / \_\_\_\_/ \_\_\_\_\_ \_\_\_\_ / /\_/ / / /\_ \_\_/ /\_ \_\_\_\_\_ Apr 05 15:14:43 SOMETHING filebeat\[410843\]: / \_\_/ | | / / \_ \\/ \_\_ \\/ \_\_/ /\_/…

---

## [How can i create different indices for different module](https://discuss.elastic.co/t/how-can-i-create-different-indices-for-different-module/269095)

<div class="topic-metadata">

**Author:** [@Shriram\_Wasule](https://discuss.elastic.co/u/Shriram_Wasule)\
**Replies:** 11\
**Last updated:** [April 7, 2021, 4:45pm UTC](https://discuss.elastic.co/t/how-can-i-create-different-indices-for-different-module/269095 "2021-04-07T16:45:03Z")

</div>

Hello, i have two modules activated Apache and tomcat,, i want to store logs of this two in two different indices for better result but i am not able to get how to do that. please help me to set this configuration in m…

---

## [Filebeat won't get geo\_points field type](https://discuss.elastic.co/t/filebeat-wont-get-geo-points-field-type/269501)

<div class="topic-metadata">

**Author:** [@Chris6](https://discuss.elastic.co/u/Chris6)\
**Replies:** 0\
**Last updated:** [April 7, 2021, 4:40pm UTC](https://discuss.elastic.co/t/filebeat-wont-get-geo-points-field-type/269501 "2021-04-07T16:40:39Z")

</div>

I have a json line of input that foes through filebeat. The line is in this format: {"first": "text", "second": "text", "@timestamp": "2021-02-25T08:54:04Z", "location": \[-71.34, 41.12\] } I am trying to get the location…

---

## [Filebeat autodiscovery in Kubernetes/EKS and multiple outputs](https://discuss.elastic.co/t/filebeat-autodiscovery-in-kubernetes-eks-and-multiple-outputs/268272)

<div class="topic-metadata">

**Author:** [@bplies](https://discuss.elastic.co/u/bplies)\
**Replies:** 1\
**Last updated:** [April 7, 2021, 4:02pm UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-in-kubernetes-eks-and-multiple-outputs/268272 "2021-04-07T16:02:26Z")

</div>

Scenario A shared K8s cluster with several different apps all needing their app-specific logs collected by Filebeat. Each different app's logs are substantially different (some plaintext, some json with differing field…

---

## [Filebeat configuration module path issue](https://discuss.elastic.co/t/filebeat-configuration-module-path-issue/268871)

<div class="topic-metadata">

**Author:** [@tkkchan](https://discuss.elastic.co/u/tkkchan)\
**Replies:** 4\
**Last updated:** [April 7, 2021, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-configuration-module-path-issue/268871 "2021-04-07T14:16:11Z")

</div>

Dear All, I am trying to follow this tutorial here to build a dashboard on some public data sets. However, whenever I tried to run ./filebeat, the following error appeared: 2021-03-31T14:19:44.685+0800 ERROR \[mod…

---

## [Filebeat Crowdstrike Module doesn't handle unix timestamps of 0 correctly](https://discuss.elastic.co/t/filebeat-crowdstrike-module-doesnt-handle-unix-timestamps-of-0-correctly/269045)

<div class="topic-metadata">

**Author:** [@anon68795679](https://discuss.elastic.co/u/anon68795679)\
**Replies:** 10\
**Last updated:** [April 7, 2021, 2:05pm UTC](https://discuss.elastic.co/t/filebeat-crowdstrike-module-doesnt-handle-unix-timestamps-of-0-correctly/269045 "2021-04-07T14:05:33Z")

</div>

Hi, Crowdstrike store events with a ProcessEndTime of "0". For example shortened json: { "event": { "ProcessStartTime": 1617278228, "ProcessEndTime": 0, } } Both fields are parsed by the same…

---

## [Filebeat : Exiting: No outputs are defined. Please define one under the output section](https://discuss.elastic.co/t/filebeat-exiting-no-outputs-are-defined-please-define-one-under-the-output-section/269478)

<div class="topic-metadata">

**Author:** [@sourabhjain104](https://discuss.elastic.co/u/sourabhjain104)\
**Replies:** 0\
**Last updated:** [April 7, 2021, 1:58pm UTC](https://discuss.elastic.co/t/filebeat-exiting-no-outputs-are-defined-please-define-one-under-the-output-section/269478 "2021-04-07T13:58:09Z")

</div>

Hello All, I am trying to send logs data from my local drive to logstash using filebeat 7.11.0. I was able to do it successfully and also create index pattern in kibana. I wanted to do some modification so I deleted m…

---

## [Ingest\_pipeline - Elastic Cloud](https://discuss.elastic.co/t/ingest-pipeline-elastic-cloud/268175)

<div class="topic-metadata">

**Author:** [@evgeniy777](https://discuss.elastic.co/u/evgeniy777)\
**Replies:** 3\
**Last updated:** [April 7, 2021, 10:46am UTC](https://discuss.elastic.co/t/ingest-pipeline-elastic-cloud/268175 "2021-04-07T10:46:55Z")

</div>

Hi all ! i'm using Elastic Cloud solution and FileBeat on my servers. made a simple ingest\_pipeline for parsing my custom app logs. On Filebeat config i'm defining "cloud.auth:" and "cloud.id:", but i don't know how…

---

## [Filebeat eslog-%{\[elasticsearch.cluster.name\]}-%{\[fileset.name\]}-%{+yyyy.MM.dd} not work](https://discuss.elastic.co/t/filebeat-eslog-elasticsearch-cluster-name-fileset-name-yyyy-mm-dd-not-work/268861)

<div class="topic-metadata">

**Author:** [@asasas234](https://discuss.elastic.co/u/asasas234)\
**Replies:** 5\
**Last updated:** [April 7, 2021, 6:54am UTC](https://discuss.elastic.co/t/filebeat-eslog-elasticsearch-cluster-name-fileset-name-yyyy-mm-dd-not-work/268861 "2021-04-07T06:54:29Z")

</div>

output.elasticsearch: # Array of hosts to connect to. hosts: \["localhost:9200"\] index: "eslog-%{\[elasticsearch.cluster.name\]}-%{\[fileset.name\]}-%{+yyyy.MM.dd}" I found that the above configuration will cause error…

---

## [Missing fields option in filebeat xml\_decode](https://discuss.elastic.co/t/missing-fields-option-in-filebeat-xml-decode/269406)

<div class="topic-metadata">

**Author:** [@Francisco\_Peralta\_Gu](https://discuss.elastic.co/u/Francisco_Peralta_Gu)\
**Replies:** 0\
**Last updated:** [April 7, 2021, 6:35am UTC](https://discuss.elastic.co/t/missing-fields-option-in-filebeat-xml-decode/269406 "2021-04-07T06:35:44Z")

</div>

Hi. We are facing issues configuring xml\_decode in Filebeat version 7.12.0: instance/beat.go:971 Exiting: Failed to start crawler: starting input failed: Error while initializing input: missing fields option in fil…

---

## [Problem with Metricbeat 7.10.1 and windows server 2012](https://discuss.elastic.co/t/problem-with-metricbeat-7-10-1-and-windows-server-2012/269330)

<div class="topic-metadata">

**Author:** [@emolto](https://discuss.elastic.co/u/emolto)\
**Replies:** 0\
**Last updated:** [April 6, 2021, 12:58pm UTC](https://discuss.elastic.co/t/problem-with-metricbeat-7-10-1-and-windows-server-2012/269330 "2021-04-06T12:58:24Z")

</div>

Hi, I'm just start using metricbeat to monitor a windows server 2012 machine. I've installed an configured successfully metricbeat 7.10.1. I've enabled windows module to collect cpu usage. The data collected is sent d…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=165)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=167)
