# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=168

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 169

---

## [Winlogbeat keystore windows](https://discuss.elastic.co/t/winlogbeat-keystore-windows/268769)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 6\
**Last updated:** [March 31, 2021, 11:12am UTC](https://discuss.elastic.co/t/winlogbeat-keystore-windows/268769 "2021-03-31T11:12:29Z")

</div>

I have created a keystore for winlogbeats as the administrator and modified winlogbeat.yml When i try and start the service it fails (running as local system) if i run winlogbeat manually it starts I can see the issue…

---

## [High level concepts of elastic stack in containerized environment](https://discuss.elastic.co/t/high-level-concepts-of-elastic-stack-in-containerized-environment/268750)

<div class="topic-metadata">

**Author:** [@siplsag](https://discuss.elastic.co/u/siplsag)\
**Replies:** 2\
**Last updated:** [March 31, 2021, 11:08am UTC](https://discuss.elastic.co/t/high-level-concepts-of-elastic-stack-in-containerized-environment/268750 "2021-03-31T11:08:34Z")

</div>

We think about using an Elastic (ELK) stack to process logs from our servers. We have about ten virtual Ubuntu servers that run on prem. All of those servers run some docker images, currently orchestrated by docker-compo…

---

## [Aggregate data using filebeat](https://discuss.elastic.co/t/aggregate-data-using-filebeat/267907)

<div class="topic-metadata">

**Author:** [@szabgab](https://discuss.elastic.co/u/szabgab)\
**Replies:** 3\
**Last updated:** [March 31, 2021, 6:53am UTC](https://discuss.elastic.co/t/aggregate-data-using-filebeat/267907 "2021-03-31T06:53:09Z")

</div>

I have a log file that looks like this: TIMESTAMP FIELD VALUE e.g. 100 load 1 100 mem 23 100 free 7 103 load 2 103 mem 17 103 free 9 ... I would like to aggregate the lines with the same …

---

## [Logontime logofftime](https://discuss.elastic.co/t/logontime-logofftime/268719)

<div class="topic-metadata">

**Author:** [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Replies:** 3\
**Last updated:** [March 31, 2021, 2:58am UTC](https://discuss.elastic.co/t/logontime-logofftime/268719 "2021-03-31T02:58:29Z")

</div>

hello, I'm currently using winlogbeat for window server monitoring. how to i know logon and logoff time an user on windows server? here's the example of splunk's report

---

## [How to add a field with description for a specific Windows Event ID?](https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617)

<div class="topic-metadata">

**Author:** [@nael\_uchiha](https://discuss.elastic.co/u/nael_uchiha)\
**Replies:** 5\
**Last updated:** [March 31, 2021, 12:22am UTC](https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617 "2021-03-31T00:22:43Z")

</div>

Hello, I need to add some fields and descriptions for a Windows Event ID. For example, for winlog.event\_id = 1111 create a field named rule.description: Our descroption Thank you for your help!

---

## [How to set @timestamp in Filebeat?](https://discuss.elastic.co/t/how-to-set-timestamp-in-filebeat/268804)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 1\
**Last updated:** [March 31, 2021, 12:14am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-in-filebeat/268804 "2021-03-31T00:14:06Z")

</div>

Hi thanks for the wonderful elastic stack! I need to set @timestamp in Filebeat. I have seen this and this. But they seems to be outdated and no updates :frowning:

---

## [Filebeat as a UDP Syslog Listener Dropping Alot of Logs](https://discuss.elastic.co/t/filebeat-as-a-udp-syslog-listener-dropping-alot-of-logs/267132)

<div class="topic-metadata">

**Author:** [@sudont](https://discuss.elastic.co/u/sudont)\
**Replies:** 24\
**Last updated:** [March 30, 2021, 8:04pm UTC](https://discuss.elastic.co/t/filebeat-as-a-udp-syslog-listener-dropping-alot-of-logs/267132 "2021-03-30T20:04:24Z")

</div>

So we've been using a single filebeat as a listener for a GOOD amount of Juniper SRX firewalls (like 50 or so) and it's been working really well. We recently did a test and ran a script that fires 10 firewall logs on an…

---

## [Packetbeat for monitoring a microservice](https://discuss.elastic.co/t/packetbeat-for-monitoring-a-microservice/268343)

<div class="topic-metadata">

**Author:** [@Pablo\_Albertengo](https://discuss.elastic.co/u/Pablo_Albertengo)\
**Replies:** 1\
**Last updated:** [March 30, 2021, 4:19pm UTC](https://discuss.elastic.co/t/packetbeat-for-monitoring-a-microservice/268343 "2021-03-30T16:19:23Z")

</div>

Hi! I'm doing my first tests with packetbeat. I wanted to monitor a microservice (basically http codes of responses, latency, size of responses) but it has been impossible so far. The service listens on a specific por…

---

## [Purpose of t\<300 in kuery](https://discuss.elastic.co/t/purpose-of-t-300-in-kuery/268689)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 1\
**Last updated:** [March 30, 2021, 4:17pm UTC](https://discuss.elastic.co/t/purpose-of-t-300-in-kuery/268689 "2021-03-30T16:17:10Z")

</div>

What is the purpose of t\<300 in the ELB 2xx prebuilt dashboard json? \\"filter\\": {\\"query\\": \\"fileset.name : \\\\\\"elb\\\\\\" and http.response.status\_code \>= 200 and http.response.status\_code\\\\t\< 300\\", \\"language\\": \\"kue…

---

## [Filebeat Cisco AMP Module and host.name Error](https://discuss.elastic.co/t/filebeat-cisco-amp-module-and-host-name-error/268510)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 21\
**Last updated:** [March 30, 2021, 2:21pm UTC](https://discuss.elastic.co/t/filebeat-cisco-amp-module-and-host-name-error/268510 "2021-03-30T14:21:22Z")

</div>

We are currently using Python to poll the Cisco AMP API, then Logstash picks up the results, but I noticed there is a new Cisco AMP module for Filebeat, so I figured I would give it a try. There are a few issues I have n…

---

## [Collecting powershell logs with the old beat version](https://discuss.elastic.co/t/collecting-powershell-logs-with-the-old-beat-version/268637)

<div class="topic-metadata">

**Author:** [@Anna\_Foxx](https://discuss.elastic.co/u/Anna_Foxx)\
**Replies:** 1\
**Last updated:** [March 30, 2021, 2:15pm UTC](https://discuss.elastic.co/t/collecting-powershell-logs-with-the-old-beat-version/268637 "2021-03-30T14:15:47Z")

</div>

Hi! In order to collect powershell logs by winlogbeat 6.8, I tried to change config file just adding 2 rows under winlogbeat.event\_logs: -name: Windows Powershell -name: Microsoft-Windows-Powershell/Operational Unfort…

---

## [Winlogbeat Script Processor - processing xml data](https://discuss.elastic.co/t/winlogbeat-script-processor-processing-xml-data/268383)

<div class="topic-metadata">

**Author:** [@omkarg81](https://discuss.elastic.co/u/omkarg81)\
**Replies:** 1\
**Last updated:** [March 30, 2021, 2:13pm UTC](https://discuss.elastic.co/t/winlogbeat-script-processor-processing-xml-data/268383 "2021-03-30T14:13:10Z")

</div>

Trying to add a new javascript processor using the processors section for the Winlogbeat that is reading the Windows Application log events. The custom javascript processor needs to read out an xml from within the actual…

---

## [FileBeat disabling hints.default.default\_config](https://discuss.elastic.co/t/filebeat-disabling-hints-default-default-config/268614)

<div class="topic-metadata">

**Author:** [@Joaquin\_menchaca](https://discuss.elastic.co/u/Joaquin_menchaca)\
**Replies:** 1\
**Last updated:** [March 30, 2021, 2:09pm UTC](https://discuss.elastic.co/t/filebeat-disabling-hints-default-default-config/268614 "2021-03-30T14:09:26Z")

</div>

I don't understand why this doesn't work, any insight appreciated. When I enable hints.default\_config, I do not get anything show up in Kibana. I was following these docs for auto-discovery. My filebeats.yml config is…

---

## [Winlogbeat: best practice for 2003 logs only](https://discuss.elastic.co/t/winlogbeat-best-practice-for-2003-logs-only/268703)

<div class="topic-metadata">

**Author:** [@nathanrstacey](https://discuss.elastic.co/u/nathanrstacey)\
**Replies:** 1\
**Last updated:** [March 30, 2021, 2:03pm UTC](https://discuss.elastic.co/t/winlogbeat-best-practice-for-2003-logs-only/268703 "2021-03-30T14:03:35Z")

</div>

Questions Up Top: -Is there any value in placing these logs onto a 2003 server instead of the Win10 laptop? As in, would Winlogbeat do a better job parsing into ECS if the logs were of the same format as the OS? -Any o…

---

## [Get filebeat latest version](https://discuss.elastic.co/t/get-filebeat-latest-version/268670)

<div class="topic-metadata">

**Author:** [@mirii1994](https://discuss.elastic.co/u/mirii1994)\
**Replies:** 2\
**Last updated:** [March 30, 2021, 9:14am UTC](https://discuss.elastic.co/t/get-filebeat-latest-version/268670 "2021-03-30T09:14:35Z")

</div>

Hi there, Is there some kind of API or a URL that I can check with what's Filebeat's latest version from a script? Thanks!

---

## [Filebeat error failed to publish events caused connection reset by peer](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events-caused-connection-reset-by-peer/268400)

<div class="topic-metadata">

**Author:** [@aneeshansari](https://discuss.elastic.co/u/aneeshansari)\
**Replies:** 5\
**Last updated:** [March 30, 2021, 7:31am UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events-caused-connection-reset-by-peer/268400 "2021-03-30T07:31:26Z")

</div>

Hello Everyone, Need help for following error in filebeat with logstash. error failed to publish events caused by: write tcp 127.0.0.1:random\_port-\>127.0.0.1:5044 write: connection reset by peer I already increased …

---

## [Winlogbeat communicate](https://discuss.elastic.co/t/winlogbeat-communicate/268720)

<div class="topic-metadata">

**Author:** [@raj\_mouriya](https://discuss.elastic.co/u/raj_mouriya)\
**Replies:** 1\
**Last updated:** [March 30, 2021, 3:57am UTC](https://discuss.elastic.co/t/winlogbeat-communicate/268720 "2021-03-30T03:57:29Z")

</div>

Winlogbeat not communicate my elastic search cluster if elastic search master is down . winlogbeat not send logs in my backup elastic search server.

---

## [Runtime error: slice bounds out of range when ingesting Powershell logs](https://discuss.elastic.co/t/runtime-error-slice-bounds-out-of-range-when-ingesting-powershell-logs/268699)

<div class="topic-metadata">

**Author:** [@ruffy91](https://discuss.elastic.co/u/ruffy91)\
**Replies:** 0\
**Last updated:** [March 29, 2021, 8:34pm UTC](https://discuss.elastic.co/t/runtime-error-slice-bounds-out-of-range-when-ingesting-powershell-logs/268699 "2021-03-29T20:34:05Z")

</div>

I am trying to ingest Powershell logs using winlogbeat 7.12 using the following configuration: - name: WEC-Powershell tags: \[forwarded\] processors: - script: when.equals.winlog.channel: Windows-PowerShell …

---

## [Unable to find source.geo.location filebeat aws module](https://discuss.elastic.co/t/unable-to-find-source-geo-location-filebeat-aws-module/268254)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 6\
**Last updated:** [March 29, 2021, 5:35pm UTC](https://discuss.elastic.co/t/unable-to-find-source-geo-location-filebeat-aws-module/268254 "2021-03-29T17:35:55Z")

</div>

I would like to convert the following to a geo\_point type "location": { "properties": { "lat": { "type": "float" }, "lon": { …

---

## [Error building metricbeat 7.12.0](https://discuss.elastic.co/t/error-building-metricbeat-7-12-0/268425)

<div class="topic-metadata">

**Author:** [@Anna\_Yan](https://discuss.elastic.co/u/Anna_Yan)\
**Replies:** 5\
**Last updated:** [March 29, 2021, 4:47pm UTC](https://discuss.elastic.co/t/error-building-metricbeat-7-12-0/268425 "2021-03-29T16:47:59Z")

</div>

Hi, I'm trying to build metricbeat v7.12.0 and I'm getting this error: ~/beats/metricbeat PLATFORMS=linux/amd64 make release  2 ↵  10463  17:5…

---

## [Fleet AWS integration - looking for more info howto setup (IAM role preferred)](https://discuss.elastic.co/t/fleet-aws-integration-looking-for-more-info-howto-setup-iam-role-preferred/267844)

<div class="topic-metadata">

**Author:** [@wmeensvwpfs](https://discuss.elastic.co/u/wmeensvwpfs)\
**Replies:** 4\
**Last updated:** [March 29, 2021, 3:31pm UTC](https://discuss.elastic.co/t/fleet-aws-integration-looking-for-more-info-howto-setup-iam-role-preferred/267844 "2021-03-29T15:31:52Z")

</div>

Hi all, I'm running ECK 1.4.0 on AWS EKS. Elasticsearch and Kibana version is 7.11.2. First off, awesome how it's all shaping up! Also including innovations around Fleet and the Elastic Agent. Really exciting stuff!! A…

---

## [Mssql.performance ignores some metrics (metricbeat)](https://discuss.elastic.co/t/mssql-performance-ignores-some-metrics-metricbeat/268277)

<div class="topic-metadata">

**Author:** [@Francisco\_Gomez1](https://discuss.elastic.co/u/Francisco_Gomez1)\
**Replies:** 5\
**Last updated:** [March 29, 2021, 2:55pm UTC](https://discuss.elastic.co/t/mssql-performance-ignores-some-metrics-metricbeat/268277 "2021-03-29T14:55:18Z")

</div>

Hi. When im trying to use metricbeat to capture my SQL Server performance some metrics that should be included are completly ignored. this is my mssql.yml configuration: I should recieve all performance metrics but i…

---

## [How to use copy-to in filebeat?](https://discuss.elastic.co/t/how-to-use-copy-to-in-filebeat/268499)

<div class="topic-metadata">

**Author:** [@Chris6](https://discuss.elastic.co/u/Chris6)\
**Replies:** 2\
**Last updated:** [March 29, 2021, 2:42pm UTC](https://discuss.elastic.co/t/how-to-use-copy-to-in-filebeat/268499 "2021-03-29T14:42:21Z")

</div>

I am trying to use copy\_to to copy the values of multiple fields into a group field so that it can then be queried as a single field. I found this link copy\_to | Elasticsearch Reference \[7.12\] | Elastic , but when I try …

---

## [Winlogbeat high cpu usage](https://discuss.elastic.co/t/winlogbeat-high-cpu-usage/267625)

<div class="topic-metadata">

**Author:** [@PD98](https://discuss.elastic.co/u/PD98)\
**Replies:** 3\
**Last updated:** [March 29, 2021, 9:49am UTC](https://discuss.elastic.co/t/winlogbeat-high-cpu-usage/267625 "2021-03-29T09:49:54Z")

</div>

Hi, I have installed winlogbeat on my windows server. However it is causing high cpu usage. I am also attaching an image of the same. Any help would be appreciated. Thanks

---

## [Google Workspace Filebeat SAML issue](https://discuss.elastic.co/t/google-workspace-filebeat-saml-issue/266859)

<div class="topic-metadata">

**Author:** [@Hanse00](https://discuss.elastic.co/u/Hanse00)\
**Replies:** 2\
**Last updated:** [March 29, 2021, 9:40am UTC](https://discuss.elastic.co/t/google-workspace-filebeat-saml-issue/266859 "2021-03-29T09:40:33Z")

</div>

Hi everyone, I believe I've discovered a bug in the Google Workspace module for Filebeat. Posting here first per the instructions on GitHub. When using the Google Workspace module, all sub-modules but SAML logging (Adm…

---

## [Heartbeat failed to start on adding new monitor](https://discuss.elastic.co/t/heartbeat-failed-to-start-on-adding-new-monitor/267343)

<div class="topic-metadata">

**Author:** [@Unni\_Kuttan](https://discuss.elastic.co/u/Unni_Kuttan)\
**Replies:** 1\
**Last updated:** [March 29, 2021, 8:45am UTC](https://discuss.elastic.co/t/heartbeat-failed-to-start-on-adding-new-monitor/267343 "2021-03-29T08:45:02Z")

</div>

Upon adding a new monitor(of type tcp) to heartbeat.yml, the heartbeat service stopped . Tried to start heartbeat from CLI , thrown the error Exiting: could not create monitor: error unpacking monitor plugin config: …

---

## [Alert when specific Windows Service is down](https://discuss.elastic.co/t/alert-when-specific-windows-service-is-down/268635)

<div class="topic-metadata">

**Author:** [@kbalys](https://discuss.elastic.co/u/kbalys)\
**Replies:** 0\
**Last updated:** [March 29, 2021, 8:25am UTC](https://discuss.elastic.co/t/alert-when-specific-windows-service-is-down/268635 "2021-03-29T08:25:03Z")

</div>

Hi, I am using metric beats 7.11.2 and I am reporting the Windows Services from Windows module. I receive a state for about ~150 windows services. I would like to have an alert when a given subset of them filtered by n…

---

## [Getting attached error when trying to access from Kibana dashboard](https://discuss.elastic.co/t/getting-attached-error-when-trying-to-access-from-kibana-dashboard/268631)

<div class="topic-metadata">

**Author:** [@nani\_V](https://discuss.elastic.co/u/nani_V)\
**Replies:** 0\
**Last updated:** [March 29, 2021, 6:39am UTC](https://discuss.elastic.co/t/getting-attached-error-when-trying-to-access-from-kibana-dashboard/268631 "2021-03-29T06:39:24Z")

</div>

---

## [How can only show some fields with Kibana + Filebeat?](https://discuss.elastic.co/t/how-can-only-show-some-fields-with-kibana-filebeat/268616)

<div class="topic-metadata">

**Author:** [@Joaquin\_menchaca](https://discuss.elastic.co/u/Joaquin_menchaca)\
**Replies:** 1\
**Last updated:** [March 29, 2021, 12:52am UTC](https://discuss.elastic.co/t/how-can-only-show-some-fields-with-kibana-filebeat/268616 "2021-03-29T00:52:07Z")

</div>

I am just getting started with ES + Kibana + Filebeat. How can I create a visual list of just the log lines form docker containers? I was able to capture log activity using this: Filebeat + Dgraph Docker Exploration …

---

## [Filebeat.yml correct configuration on MAC OS - docker autodiscover -- Docker daemon at unix:///var/run/docker.sock](https://discuss.elastic.co/t/filebeat-yml-correct-configuration-on-mac-os-docker-autodiscover-docker-daemon-at-unix-var-run-docker-sock/266923)

<div class="topic-metadata">

**Author:** [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Replies:** 2\
**Last updated:** [March 28, 2021, 11:38pm UTC](https://discuss.elastic.co/t/filebeat-yml-correct-configuration-on-mac-os-docker-autodiscover-docker-daemon-at-unix-var-run-docker-sock/266923 "2021-03-28T23:38:48Z")

</div>

Guys, I am new to Docker. Am running Docker on my MAC. I've created on my docker-compose file this configuration: filebeat: depends\_on: - kibana - logstash container\_name: fileb…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=167)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=169)
