# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=167

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 168

---

## [Health Check on FileBeats Instance from AWS NLB](https://discuss.elastic.co/t/health-check-on-filebeats-instance-from-aws-nlb/269371)

<div class="topic-metadata">

**Author:** [@Ravi342883](https://discuss.elastic.co/u/Ravi342883)\
**Replies:** 2\
**Last updated:** [April 6, 2021, 9:50pm UTC](https://discuss.elastic.co/t/health-check-on-filebeats-instance-from-aws-nlb/269371 "2021-04-06T21:50:15Z")

</div>

Hi All, Could you please help with the below NLB configuration in AWS in-front of FileBeat Instance? When I tried to created the setup, the Target Group always shows unhealthy - Health checks failed. Requirement: 1. D…

---

## [Filebeat AWS S3 Module not working](https://discuss.elastic.co/t/filebeat-aws-s3-module-not-working/268781)

<div class="topic-metadata">

**Author:** [@bapa](https://discuss.elastic.co/u/bapa)\
**Replies:** 6\
**Last updated:** [April 6, 2021, 3:42pm UTC](https://discuss.elastic.co/t/filebeat-aws-s3-module-not-working/268781 "2021-04-06T15:42:30Z")

</div>

Hi Team, We are facing the filebeat aws s3 module issue in version 7.10 ,7.10.1, 7.11.0, 7.11.1, 7.11.2, 7.12.0 We have deployed the filebeat in k8s environment. And the ELK with ECK operator. While we tried to use th…

---

## [Elastic Agent will not upgrade through fleet or locally](https://discuss.elastic.co/t/elastic-agent-will-not-upgrade-through-fleet-or-locally/269337)

<div class="topic-metadata">

**Author:** [@The1WhoPrtNocks](https://discuss.elastic.co/u/The1WhoPrtNocks)\
**Replies:** 0\
**Last updated:** [April 6, 2021, 2:10pm UTC](https://discuss.elastic.co/t/elastic-agent-will-not-upgrade-through-fleet-or-locally/269337 "2021-04-06T14:10:06Z")

</div>

Hi, We deployed the agent to a number of devices for testing. At the time the Elastic stack and Agents were on version 7.10.1 . We have recently upgraded our stack to 7.12.0 and as you would expect the agents in fleet …

---

## [Dropping network events for private IP range through Winlogbeat yml config](https://discuss.elastic.co/t/dropping-network-events-for-private-ip-range-through-winlogbeat-yml-config/269027)

<div class="topic-metadata">

**Author:** [@Psyhil](https://discuss.elastic.co/u/Psyhil)\
**Replies:** 2\
**Last updated:** [April 6, 2021, 1:22pm UTC](https://discuss.elastic.co/t/dropping-network-events-for-private-ip-range-through-winlogbeat-yml-config/269027 "2021-04-06T13:22:28Z")

</div>

Hi there, We are forwarding system network event logs via winlogbeat generated by sysmon and was attempting at dropping internal traffic events using private IP ranges. Seems yml config does not supports wildcard hence…

---

## [How to configure apache.yml in filebeat with multiple paths in var.paths](https://discuss.elastic.co/t/how-to-configure-apache-yml-in-filebeat-with-multiple-paths-in-var-paths/268980)

<div class="topic-metadata">

**Author:** [@Shriram\_Wasule](https://discuss.elastic.co/u/Shriram_Wasule)\
**Replies:** 6\
**Last updated:** [April 6, 2021, 10:59am UTC](https://discuss.elastic.co/t/how-to-configure-apache-yml-in-filebeat-with-multiple-paths-in-var-paths/268980 "2021-04-06T10:59:59Z")

</div>

i am not getting on how i can add multiple paths in var.paths parameter in apache.yml? i have configured one path but i have multiple log files with different names so how can add those paths too? # ====================…

---

## [Use beats to read multiline event excluding some lines in-between](https://discuss.elastic.co/t/use-beats-to-read-multiline-event-excluding-some-lines-in-between/268990)

<div class="topic-metadata">

**Author:** [@lukiovas](https://discuss.elastic.co/u/lukiovas)\
**Replies:** 3\
**Last updated:** [April 6, 2021, 10:52am UTC](https://discuss.elastic.co/t/use-beats-to-read-multiline-event-excluding-some-lines-in-between/268990 "2021-04-06T10:52:59Z")

</div>

I have a log: server.name 2021-03-28 10:03:28.648 INFO ... --------------------------- ID: 3974 Address: https://www... Encoding: UTF-8 Http-Method: POST Content-Type: text/xml Headers: {Accept=\[\*/\*\], ... Payload: \<s…

---

## [Vsphere metricbeat perf manager api](https://discuss.elastic.co/t/vsphere-metricbeat-perf-manager-api/269298)

<div class="topic-metadata">

**Author:** [@blambo10](https://discuss.elastic.co/u/blambo10)\
**Replies:** 0\
**Last updated:** [April 6, 2021, 8:27am UTC](https://discuss.elastic.co/t/vsphere-metricbeat-perf-manager-api/269298 "2021-04-06T08:27:12Z")

</div>

Hi All, I've Noticed that the current metricbeat for vsphere, uses the quick stats from the managed objects. Im just wondering if there has been any initiative to write a metric beat that queried the performance manage…

---

## [Not accept logs when beats pointing to logstash](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859)

<div class="topic-metadata">

**Author:** [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Replies:** 9\
**Last updated:** [April 6, 2021, 4:58am UTC](https://discuss.elastic.co/t/not-accept-logs-when-beats-pointing-to-logstash/268859 "2021-04-06T04:58:52Z")

</div>

i have 3 beats winlogbeat (server os windows), filebeat and auditbeat (server os linux). when i pointing winlogbeat to logstash there's no problem to receive log. but when i pointing filebeat and auditbeat to logstash, …

---

## [Filebeat problem with creating own index](https://discuss.elastic.co/t/filebeat-problem-with-creating-own-index/268802)

<div class="topic-metadata">

**Author:** [@lumi](https://discuss.elastic.co/u/lumi)\
**Replies:** 0\
**Last updated:** [March 30, 2021, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-problem-with-creating-own-index/268802 "2021-03-30T14:16:57Z")

</div>

I have problems with creating an index with filebeat i want to create an index for every running module when i add setup.template.enabled: false setup.template.name: "filebeat-%{\[event.module\]}" setup.template.patte…

---

## [Winlogbeat inop filter with more than 2 lines](https://discuss.elastic.co/t/winlogbeat-inop-filter-with-more-than-2-lines/268271)

<div class="topic-metadata">

**Author:** [@KStJ](https://discuss.elastic.co/u/KStJ)\
**Replies:** 3\
**Last updated:** [April 5, 2021, 9:35pm UTC](https://discuss.elastic.co/t/winlogbeat-inop-filter-with-more-than-2-lines/268271 "2021-04-05T21:35:20Z")

</div>

Trying to get Winlogbeat to drop logs matching machine account with impersonation level "%%1833" and logon types 3/4. Winlogbeat will run, but ignore the processor if I have more than 2 conditions. We are running versio…

---

## [How to use elastic-agent docker image?](https://discuss.elastic.co/t/how-to-use-elastic-agent-docker-image/269183)

<div class="topic-metadata">

**Author:** [@klausagnoletti](https://discuss.elastic.co/u/klausagnoletti)\
**Replies:** 3\
**Last updated:** [April 5, 2021, 6:29pm UTC](https://discuss.elastic.co/t/how-to-use-elastic-agent-docker-image/269183 "2021-04-05T18:29:53Z")

</div>

Hi I've been wanting to run elastic-agent as a docker container for quite some time. So I was quite ecstatic when I found out it was available for download at beats/elastic-agent | Docker @ Elastic. However there's no d…

---

## [Fleet without internet access](https://discuss.elastic.co/t/fleet-without-internet-access/268042)

<div class="topic-metadata">

**Author:** [@PD98](https://discuss.elastic.co/u/PD98)\
**Replies:** 1\
**Last updated:** [April 5, 2021, 12:55pm UTC](https://discuss.elastic.co/t/fleet-without-internet-access/268042 "2021-04-05T12:55:08Z")

</div>

Hi, I am currently trying out elastic-agent and fleet. I enabled internet access on the server so that kibana could download packages from EPR for fleet. However upon stopping internet access, I get the "unable to conne…

---

## [Data path already locked by another beat. Unable to start Harvester](https://discuss.elastic.co/t/data-path-already-locked-by-another-beat-unable-to-start-harvester/269197)

<div class="topic-metadata">

**Author:** [@Shaan](https://discuss.elastic.co/u/Shaan)\
**Replies:** 1\
**Last updated:** [April 5, 2021, 12:46pm UTC](https://discuss.elastic.co/t/data-path-already-locked-by-another-beat-unable-to-start-harvester/269197 "2021-04-05T12:46:41Z")

</div>

Hi ! i am getting following error when i used "filebeat -e" and unable to start the harvester. I don't have any other beat running. And I have filebeat.lock in /usr/share/filebeat/data. I removed it and redeployed it a…

---

## [Filebeat doesn't start any harvesters](https://discuss.elastic.co/t/filebeat-doesnt-start-any-harvesters/269099)

<div class="topic-metadata">

**Author:** [@Misha\_Diordienko](https://discuss.elastic.co/u/Misha_Diordienko)\
**Replies:** 2\
**Last updated:** [April 5, 2021, 7:28am UTC](https://discuss.elastic.co/t/filebeat-doesnt-start-any-harvesters/269099 "2021-04-05T07:28:47Z")

</div>

hi, all Debian 10, Filebeat 7.12, filebeat.yml logging.level: info logging.to\_files: true logging.files: path: /var/log/filebeat name: filebeat keepfiles: 2 permissions: 0644 filebeat.inputs: - type: log …

---

## [Processors \> convert not working when the string includes whitespace](https://discuss.elastic.co/t/processors-convert-not-working-when-the-string-includes-whitespace/269201)

<div class="topic-metadata">

**Author:** [@makeajourney](https://discuss.elastic.co/u/makeajourney)\
**Replies:** 17\
**Last updated:** [April 5, 2021, 4:59am UTC](https://discuss.elastic.co/t/processors-convert-not-working-when-the-string-includes-whitespace/269201 "2021-04-05T04:59:07Z")

</div>

Hello. I am setting up the filebeat. I want to convert the string to double and it has whitespace. I was trying it with dissect. but it's not fit my situation. because that string has not only have numbers. so I've th…

---

## [Filebeat initializing error for s3](https://discuss.elastic.co/t/filebeat-initializing-error-for-s3/269137)

<div class="topic-metadata">

**Author:** [@paano](https://discuss.elastic.co/u/paano)\
**Replies:** 4\
**Last updated:** [April 3, 2021, 2:48pm UTC](https://discuss.elastic.co/t/filebeat-initializing-error-for-s3/269137 "2021-04-03T14:48:41Z")

</div>

I am trying to follow as explained in the elastic blog And getting error: 2021-04-03T01:04:23.845Z ERROR instance/beat.go:971 Exiting: Failed to start crawler: starting input failed: Error while initializing input: Err…

---

## [Ship logs to multiple logstash servers from single filebeat](https://discuss.elastic.co/t/ship-logs-to-multiple-logstash-servers-from-single-filebeat/269147)

<div class="topic-metadata">

**Author:** [@prajwal93](https://discuss.elastic.co/u/prajwal93)\
**Replies:** 1\
**Last updated:** [April 3, 2021, 1:46pm UTC](https://discuss.elastic.co/t/ship-logs-to-multiple-logstash-servers-from-single-filebeat/269147 "2021-04-03T13:46:10Z")

</div>

Currently, I have a requirement to ship logs to multiple logstash endpoints from a single filebeat instances. I don't want to loadbalance, but push same logs to different logstash endpoints. I was not able to find the …

---

## [Filebeat netflow module crashes](https://discuss.elastic.co/t/filebeat-netflow-module-crashes/269126)

<div class="topic-metadata">

**Author:** [@S3l3ct3d](https://discuss.elastic.co/u/S3l3ct3d)\
**Replies:** 2\
**Last updated:** [April 3, 2021, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-netflow-module-crashes/269126 "2021-04-03T13:09:24Z")

</div>

I am currently receiving netflow logs on port 2055 (default) on my Logstash server. I also have filebeat running on this server, which is also currently using the panw and crowdstrike modules with no issues. So the fileb…

---

## [FreeBSD 12 + Filebeat + netflow](https://discuss.elastic.co/t/freebsd-12-filebeat-netflow/269123)

<div class="topic-metadata">

**Author:** [@Yustas](https://discuss.elastic.co/u/Yustas)\
**Replies:** 0\
**Last updated:** [April 2, 2021, 5:03pm UTC](https://discuss.elastic.co/t/freebsd-12-filebeat-netflow/269123 "2021-04-02T17:03:30Z")

</div>

Hello I am installed beats7 by pkg on FreeBSD 12.1 But in installation missing module netflow for filebeat Anybody know how install filebeat with netflow support on freebsd? /usr/ports/sysutils/beats7/pkg-plist %%ME…

---

## [Filebeat to parse mixed data (strings and json)](https://discuss.elastic.co/t/filebeat-to-parse-mixed-data-strings-and-json/267629)

<div class="topic-metadata">

**Author:** [@Olivier\_Gerault](https://discuss.elastic.co/u/Olivier_Gerault)\
**Replies:** 3\
**Last updated:** [April 2, 2021, 10:34am UTC](https://discuss.elastic.co/t/filebeat-to-parse-mixed-data-strings-and-json/267629 "2021-04-02T10:34:54Z")

</div>

Hello, First of all, I'm a new to filebeat, so I may say stupids things. Forgive me in advance. I have to parse a log file that looks like : 2021-03-18 09:33:37,131 -- TYPE -- {"json1": "data", "json2": "data", "json3…

---

## [How to add podip on add\_kubernetes\_metadata processor?](https://discuss.elastic.co/t/how-to-add-podip-on-add-kubernetes-metadata-processor/269006)

<div class="topic-metadata">

**Author:** [@dadayoo](https://discuss.elastic.co/u/dadayoo)\
**Replies:** 6\
**Last updated:** [April 2, 2021, 7:45am UTC](https://discuss.elastic.co/t/how-to-add-podip-on-add-kubernetes-metadata-processor/269006 "2021-04-02T07:45:05Z")

</div>

Hi I'm running filebeat daemonset on my k8s cluster have try different config scenario but do not get the pod ip data here is my config processors: - add\_kubernetes\_metadata: default\_indexers.enabled: tr…

---

## [Help needed on winlogbeat](https://discuss.elastic.co/t/help-needed-on-winlogbeat/269041)

<div class="topic-metadata">

**Author:** [@Ashish\_Lal](https://discuss.elastic.co/u/Ashish_Lal)\
**Replies:** 0\
**Last updated:** [April 1, 2021, 2:18pm UTC](https://discuss.elastic.co/t/help-needed-on-winlogbeat/269041 "2021-04-01T14:18:45Z")

</div>

Hello there, I am new to winlogbeat and elastic stack. I have installed winlogbeat 7.11.0 to monitor windows event logs of a proprietary application (eXX). The windows event log contains entries from 10th March upto 26t…

---

## [\[Filebeat CEF\] Microsoft DNS Overview on Filebeat 7.12](https://discuss.elastic.co/t/filebeat-cef-microsoft-dns-overview-on-filebeat-7-12/268891)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 2\
**Last updated:** [April 1, 2021, 11:44am UTC](https://discuss.elastic.co/t/filebeat-cef-microsoft-dns-overview-on-filebeat-7-12/268891 "2021-04-01T11:44:43Z")

</div>

Hi Team, I'm hoping one of you can get me out of this misery ... I have packetbeat set up on my M$ DNS servers and is collecting some really helpful info. My elasticSearch cluster is running separately and seems to be…

---

## [Metricbeats output.redis excessiv DNS Querries when redis down](https://discuss.elastic.co/t/metricbeats-output-redis-excessiv-dns-querries-when-redis-down/269021)

<div class="topic-metadata">

**Author:** [@brockp](https://discuss.elastic.co/u/brockp)\
**Replies:** 0\
**Last updated:** [April 1, 2021, 10:56am UTC](https://discuss.elastic.co/t/metricbeats-output-redis-excessiv-dns-querries-when-redis-down/269021 "2021-04-01T10:56:48Z")

</div>

We have metricbeats sending data to redis and on to ES. When redis is down metricbeats CPU jumps to 100% and 4 hosts easily create 20,000 DNS requests/second for the list of hosts running redis. Kinda odd it's not cac…

---

## [How do I run multiple filebeat.yml files on Windows?](https://discuss.elastic.co/t/how-do-i-run-multiple-filebeat-yml-files-on-windows/269003)

<div class="topic-metadata">

**Author:** [@pradeep\_gadkari](https://discuss.elastic.co/u/pradeep_gadkari)\
**Replies:** 1\
**Last updated:** [April 1, 2021, 10:05am UTC](https://discuss.elastic.co/t/how-do-i-run-multiple-filebeat-yml-files-on-windows/269003 "2021-04-01T10:05:58Z")

</div>

I have to make a centralized log monitoring system. I have to read logs from multiple locations and parse the logs differently in logstash. All these logs need to be sent to one index to Kibana at the output of logstash. …

---

## [Auditbeat \[7.11.2 and 7.12.0\] memory issue](https://discuss.elastic.co/t/auditbeat-7-11-2-and-7-12-0-memory-issue/268830)

<div class="topic-metadata">

**Author:** [@mareckii](https://discuss.elastic.co/u/mareckii)\
**Replies:** 7\
**Last updated:** [April 1, 2021, 9:38am UTC](https://discuss.elastic.co/t/auditbeat-7-11-2-and-7-12-0-memory-issue/268830 "2021-04-01T09:38:38Z")

</div>

Hi, I see memory issue when i'm using add\_process\_metadata processor. Memory usage is growing until OOM when i remove this processor from my config: I have dump, but I can't upload here.

---

## [Processor not dropping events Beats Winlogbeat](https://discuss.elastic.co/t/processor-not-dropping-events-beats-winlogbeat/268873)

<div class="topic-metadata">

**Author:** [@stinkfly](https://discuss.elastic.co/u/stinkfly)\
**Replies:** 2\
**Last updated:** [April 1, 2021, 2:50am UTC](https://discuss.elastic.co/t/processor-not-dropping-events-beats-winlogbeat/268873 "2021-04-01T02:50:56Z")

</div>

Hi there, V7.11.2 This topic has been addressed before and I've read other people's solutions, no luck. Have tried multiple combinations of and/or to drop windows event logs 4624 or 4634 with LogonType 0,3 or 5. Howe…

---

## [Source.bytes not showing up as a field in elb fileset for aws](https://discuss.elastic.co/t/source-bytes-not-showing-up-as-a-field-in-elb-fileset-for-aws/268675)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 2\
**Last updated:** [March 31, 2021, 7:12pm UTC](https://discuss.elastic.co/t/source-bytes-not-showing-up-as-a-field-in-elb-fileset-for-aws/268675 "2021-03-31T19:12:31Z")

</div>

I am trying to use the aws module for filebeat. My goal is to recreate the ELB Inbound Traffic \[Filebeat AWS\] visualization. It does not work by default. I've added an s3 bucket for collecting elb logs and an s3 bucket n…

---

## [Default log paths used for beats](https://discuss.elastic.co/t/default-log-paths-used-for-beats/268907)

<div class="topic-metadata">

**Author:** [@Bryce\_Fernandes](https://discuss.elastic.co/u/Bryce_Fernandes)\
**Replies:** 3\
**Last updated:** [March 31, 2021, 3:50pm UTC](https://discuss.elastic.co/t/default-log-paths-used-for-beats/268907 "2021-03-31T15:50:04Z")

</div>

Hi, I have an AIX server and cant install beats on it so as a workaround want to forward logs in another server and install beats and read from there. I wanted to know the default paths used by: Metricbeat system mod…

---

## [Metricbeat extreme memory usage](https://discuss.elastic.co/t/metricbeat-extreme-memory-usage/268850)

<div class="topic-metadata">

**Author:** [@Francisco\_Gomez1](https://discuss.elastic.co/u/Francisco_Gomez1)\
**Replies:** 1\
**Last updated:** [March 31, 2021, 3:07pm UTC](https://discuss.elastic.co/t/metricbeat-extreme-memory-usage/268850 "2021-03-31T15:07:51Z")

</div>

I'm getting serius metricbeat memory spikes. i'm currently using metricbeat 7.11 in my server as we can see in the next screenshot the memory usage is just to high. i din't found any error log in the service , i'm no…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=166)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=168)
