# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=169

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 170

---

## [Filebeat failed to start in PCF](https://discuss.elastic.co/t/filebeat-failed-to-start-in-pcf/268603)

<div class="topic-metadata">

**Author:** [@mgzwarrior](https://discuss.elastic.co/u/mgzwarrior)\
**Replies:** 1\
**Last updated:** [March 28, 2021, 11:00pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-start-in-pcf/268603 "2021-03-28T23:00:56Z")

</div>

Filebeat is failing to start with the following error. ERR Exiting: fileset okta/system is configured but doesn't exist I am attempting to run filebeat as an application in PCF with the input being sys logs from Okta (…

---

## [Issue in metricbeat 7.12](https://discuss.elastic.co/t/issue-in-metricbeat-7-12/268474)

<div class="topic-metadata">

**Author:** [@Aymeric\_Caroff](https://discuss.elastic.co/u/Aymeric_Caroff)\
**Replies:** 2\
**Last updated:** [March 28, 2021, 8:19pm UTC](https://discuss.elastic.co/t/issue-in-metricbeat-7-12/268474 "2021-03-28T20:19:46Z")

</div>

Hi, I've debugging an issue for some time now where metricbeat-7.12 doesn't seem to be able to create a new alias for an index template. About the set up: Elasticsearch 7.12 Kibana 7.12 Metricbeat 7.12 Security enabl…

---

## [Suricata logs over Filebeat](https://discuss.elastic.co/t/suricata-logs-over-filebeat/268538)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 1\
**Last updated:** [March 28, 2021, 4:56pm UTC](https://discuss.elastic.co/t/suricata-logs-over-filebeat/268538 "2021-03-28T16:56:27Z")

</div>

Hi. I am sending Suricata logs with filebeat to a ELK server. I have the eve.json configured to rotate every day at midnight. Logs are being sent to elastic and I can see them in the dashboards and discover tabs. But i…

---

## [MetricBeat as less privileged user](https://discuss.elastic.co/t/metricbeat-as-less-privileged-user/268579)

<div class="topic-metadata">

**Author:** [@tiefseeruebe](https://discuss.elastic.co/u/tiefseeruebe)\
**Replies:** 0\
**Last updated:** [March 28, 2021, 7:55am UTC](https://discuss.elastic.co/t/metricbeat-as-less-privileged-user/268579 "2021-03-28T07:55:37Z")

</div>

Hello, I wonder what would be the most secure way to run Metricbeat with enabled system module with elevated permission to fetch all the details listed here. Some of those details are described as not available as less …

---

## [Filebeat Azure Activity Logs fail to index when field azure.activitylogs.identity.claims is string instead of json](https://discuss.elastic.co/t/filebeat-azure-activity-logs-fail-to-index-when-field-azure-activitylogs-identity-claims-is-string-instead-of-json/268516)

<div class="topic-metadata">

**Author:** [@tobias.berg](https://discuss.elastic.co/u/tobias.berg)\
**Replies:** 0\
**Last updated:** [March 26, 2021, 4:02pm UTC](https://discuss.elastic.co/t/filebeat-azure-activity-logs-fail-to-index-when-field-azure-activitylogs-identity-claims-is-string-instead-of-json/268516 "2021-03-26T16:02:47Z")

</div>

Hi, We have noticed that sometimes, the Azure Activity logs contains serilaized json instead of pure json in the azure.activitylogs.identity field. Thus, these logs fail to index with a mapping parsing exception. We ha…

---

## [Filebeat is not Seeing Log Traffic on Server](https://discuss.elastic.co/t/filebeat-is-not-seeing-log-traffic-on-server/268373)

<div class="topic-metadata">

**Author:** [@byoungman](https://discuss.elastic.co/u/byoungman)\
**Replies:** 4\
**Last updated:** [March 26, 2021, 12:58pm UTC](https://discuss.elastic.co/t/filebeat-is-not-seeing-log-traffic-on-server/268373 "2021-03-26T12:58:29Z")

</div>

I am running into a strange issue with filebeat on one of our production transaction servers. Background: Filebeat on one of our production servers went down for some ‘unknown’ reason (still haven’t figured out why thi…

---

## [With arm64 now officially supported for beats, can we get arm64 beat containers on docker hub?](https://discuss.elastic.co/t/with-arm64-now-officially-supported-for-beats-can-we-get-arm64-beat-containers-on-docker-hub/268214)

<div class="topic-metadata">

**Author:** [@mloebl](https://discuss.elastic.co/u/mloebl)\
**Replies:** 3\
**Last updated:** [March 26, 2021, 12:35pm UTC](https://discuss.elastic.co/t/with-arm64-now-officially-supported-for-beats-can-we-get-arm64-beat-containers-on-docker-hub/268214 "2021-03-26T12:35:18Z")

</div>

Thank you for formally supporting arm64 for the beats! What at the odds of also getting the arm64 beats added to docker hub? Have some arm64 k8s clusters would like to monitor a bit easier. Thanks!

---

## [Problem creating docker container for arm64](https://discuss.elastic.co/t/problem-creating-docker-container-for-arm64/268367)

<div class="topic-metadata">

**Author:** [@suityou01](https://discuss.elastic.co/u/suityou01)\
**Replies:** 1\
**Last updated:** [March 26, 2021, 8:24am UTC](https://discuss.elastic.co/t/problem-creating-docker-container-for-arm64/268367 "2021-03-26T08:24:09Z")

</div>

Hi, I've created a docker image for filebeat for arm64 arch. This is what my simplistic docker file looks like FROM golang:1.15.10 RUN \\ apt-get update \\ && apt-get install -y --no-install-recommends…

---

## [Remove IPV6 from host.ip and host.mac field](https://discuss.elastic.co/t/remove-ipv6-from-host-ip-and-host-mac-field/268095)

<div class="topic-metadata">

**Author:** [@mladen](https://discuss.elastic.co/u/mladen)\
**Replies:** 3\
**Last updated:** [March 26, 2021, 7:58am UTC](https://discuss.elastic.co/t/remove-ipv6-from-host-ip-and-host-mac-field/268095 "2021-03-26T07:58:36Z")

</div>

Hi, after filebeat upgrade (installed as daemonset on openshift) from 7.6.2 to 7.9.1 I get very big amount of data per field for host.ip and host.mac. Before upgrade it was just IP version 4 and now I have multiple line…

---

## [Beats on ppc64le](https://discuss.elastic.co/t/beats-on-ppc64le/268213)

<div class="topic-metadata">

**Author:** [@Bryce\_Fernandes](https://discuss.elastic.co/u/Bryce_Fernandes)\
**Replies:** 1\
**Last updated:** [March 26, 2021, 12:25am UTC](https://discuss.elastic.co/t/beats-on-ppc64le/268213 "2021-03-26T00:25:31Z")

</div>

Hi, I am trying to install beats on ppc64le on Redhat OS on production server. I have tried rpm 32, 64 bit also tried aarch64 bit package but getting error : Package metricbeat is intended for different architecture. …

---

## [Functionbeat Kinesis Record Deaggregation (contribution)](https://discuss.elastic.co/t/functionbeat-kinesis-record-deaggregation-contribution/268420)

<div class="topic-metadata">

**Author:** [@jpaskhay](https://discuss.elastic.co/u/jpaskhay)\
**Replies:** 0\
**Last updated:** [March 25, 2021, 11:47pm UTC](https://discuss.elastic.co/t/functionbeat-kinesis-record-deaggregation-contribution/268420 "2021-03-25T23:47:26Z")

</div>

Hey there, Our team would like to make use of Kinesis record aggregation to save on AWS costs (high throughput of \<1KiB size logs), but it appears FunctionBeat does not currently handle the Kinesis aggregate record form…

---

## [Logviewing - filebeat - Timestamp](https://discuss.elastic.co/t/logviewing-filebeat-timestamp/268375)

<div class="topic-metadata">

**Author:** [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Replies:** 2\
**Last updated:** [March 25, 2021, 8:34pm UTC](https://discuss.elastic.co/t/logviewing-filebeat-timestamp/268375 "2021-03-25T20:34:50Z")

</div>

Hello there, I am exploring ELK capabilities for log viewing. I understand how to ingest log data into elasticsearch through filebeat and viewing from Kibana. but I noticed that if I select timestamp while creating ind…

---

## [Log viewing - ELK](https://discuss.elastic.co/t/log-viewing-elk/268106)

<div class="topic-metadata">

**Author:** [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Replies:** 4\
**Last updated:** [March 25, 2021, 3:31pm UTC](https://discuss.elastic.co/t/log-viewing-elk/268106 "2021-03-25T15:31:54Z")

</div>

Hello there, I have set up the following configuration in filebeat config file but it is not picking up the second input. not sure why filebeat.inputs: type: log enabled: true paths: C:\\ELK7.9.2\\Logs\*.log type: …

---

## [Elasticsearch Load Balancer Recommendation](https://discuss.elastic.co/t/elasticsearch-load-balancer-recommendation/268286)

<div class="topic-metadata">

**Author:** [@muthucse](https://discuss.elastic.co/u/muthucse)\
**Replies:** 3\
**Last updated:** [March 25, 2021, 1:53pm UTC](https://discuss.elastic.co/t/elasticsearch-load-balancer-recommendation/268286 "2021-03-25T13:53:38Z")

</div>

The cluster has 5 hot nodes, 3 warm nodes and 3 dedicated master nodes (on-premise). We process the logs from multiple applications using Beats plugin. As we have option in Beats to add array of data nodes with loadbalan…

---

## [Mapping conflict after upgrade filebeat to to 7.12](https://discuss.elastic.co/t/mapping-conflict-after-upgrade-filebeat-to-to-7-12/268338)

<div class="topic-metadata">

**Author:** [@molekuul](https://discuss.elastic.co/u/molekuul)\
**Replies:** 0\
**Last updated:** [March 25, 2021, 12:34pm UTC](https://discuss.elastic.co/t/mapping-conflict-after-upgrade-filebeat-to-to-7-12/268338 "2021-03-25T12:34:02Z")

</div>

Hi, After the filebeat upgrade from 7.11.1 to 7.12.0 I get an Mapping conflict for field: postgresql.log.error.code It seems like in 7.11.1 this field has a type long but in 7.12 the type is keyword How can I fix thi…

---

## [ERR Failed to publish events caused by: write tcp - wsasend: An existing connection was forcibly closed by the remote host](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-write-tcp-wsasend-an-existing-connection-was-forcibly-closed-by-the-remote-host/268321)

<div class="topic-metadata">

**Author:** [@My\_Google\_Account](https://discuss.elastic.co/u/My_Google_Account)\
**Replies:** 0\
**Last updated:** [March 25, 2021, 10:47am UTC](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-write-tcp-wsasend-an-existing-connection-was-forcibly-closed-by-the-remote-host/268321 "2021-03-25T10:47:59Z")

</div>

good afternoon! logstash version is 5.6.2, filebeat for windows version is 5.1.1, i have a problem with one of our filebeat agents and see in filebeat log file this: ERR Failed to publish events caused by: write tcp - w…

---

## [RabbitMQ ingest pipeline can't parse some log entries](https://discuss.elastic.co/t/rabbitmq-ingest-pipeline-cant-parse-some-log-entries/268317)

<div class="topic-metadata">

**Author:** [@amelnyk](https://discuss.elastic.co/u/amelnyk)\
**Replies:** 0\
**Last updated:** [March 25, 2021, 10:14am UTC](https://discuss.elastic.co/t/rabbitmq-ingest-pipeline-cant-parse-some-log-entries/268317 "2021-03-25T10:14:24Z")

</div>

Some logs (Erlang VM) can't be parsed by the provided grok expression, example log entries: 2019-07-29 14:14:43.032 \[error\] emulator Discarding message {'$gen\_call',{\<0.442.0\>,#Ref\<0.3746561768.1184890881.104501\>},stat}…

---

## [Fix kibana dashboards for filebeat aws module](https://discuss.elastic.co/t/fix-kibana-dashboards-for-filebeat-aws-module/268270)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 0\
**Last updated:** [March 24, 2021, 10:12pm UTC](https://discuss.elastic.co/t/fix-kibana-dashboards-for-filebeat-aws-module/268270 "2021-03-24T22:12:53Z")

</div>

I am very excited about the new dashboards feature for filebeat. I am trying to use custom indicies to differentiate between vpc flow logs, elb access logs, and cloudtrail logs. The issue is that the dashboards do not lo…

---

## [Using Filebeat with Large JSON logs](https://discuss.elastic.co/t/using-filebeat-with-large-json-logs/268261)

<div class="topic-metadata">

**Author:** [@jamesjuxly](https://discuss.elastic.co/u/jamesjuxly)\
**Replies:** 0\
**Last updated:** [March 24, 2021, 7:58pm UTC](https://discuss.elastic.co/t/using-filebeat-with-large-json-logs/268261 "2021-03-24T19:58:48Z")

</div>

Hello, I'm using an ELK stack with filebeat to ship JSON logs from docker containers (kubernetes) to elastic. The problem I'm having is that large log entries seem to be skipped. Is there a setting to change to allow th…

---

## [Failed to update meta file permissions: chmod /usr/share/filebeat/data/registry/filebeat/meta.json: operation not permitted](https://discuss.elastic.co/t/failed-to-update-meta-file-permissions-chmod-usr-share-filebeat-data-registry-filebeat-meta-json-operation-not-permitted/268244)

<div class="topic-metadata">

**Author:** [@mdeheegher](https://discuss.elastic.co/u/mdeheegher)\
**Replies:** 0\
**Last updated:** [March 24, 2021, 4:41pm UTC](https://discuss.elastic.co/t/failed-to-update-meta-file-permissions-chmod-usr-share-filebeat-data-registry-filebeat-meta-json-operation-not-permitted/268244 "2021-03-24T16:41:31Z")

</div>

I am using FileBeat to transfer my kubernetes nginx-ingress controller logs to ElasticSearch. I deploy a pod with a filebeat container in it. I configure the filebeat "path.data" to a fileshare on Azure, to prevent that …

---

## [Build filebeat x-pack cannot export dashboard](https://discuss.elastic.co/t/build-filebeat-x-pack-cannot-export-dashboard/227015)

<div class="topic-metadata">

**Author:** [@Mike\_Ware](https://discuss.elastic.co/u/Mike_Ware)\
**Replies:** 1\
**Last updated:** [March 24, 2021, 3:59pm UTC](https://discuss.elastic.co/t/build-filebeat-x-pack-cannot-export-dashboard/227015 "2021-03-24T15:59:36Z")

</div>

Once x-pack filebeat is build I cannot export dashboards. ''' MODULE=zeek ID=7cbb5410-3700-11e9-aa6d-ff445a78330c mage exportDashboard Error while connecting to Kibana: fail to get the Kibana version: HTTP GET reques…

---

## [Palo Alto integration with USERID \[SIEM Feature\]](https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 5\
**Last updated:** [March 24, 2021, 3:13pm UTC](https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173 "2021-03-24T15:13:57Z")

</div>

Hi, everyone I have been working with Palo Alto and Filebeat over several days. I have looked on Elastic documentation that it currently supports messages of Traffic and Threat types. Is it considered to parsing User-I…

---

## [Numeric value (1.8446744073709552e+19) out of range of long](https://discuss.elastic.co/t/numeric-value-1-8446744073709552e-19-out-of-range-of-long/268229)

<div class="topic-metadata">

**Author:** [@Alex\_Gilko](https://discuss.elastic.co/u/Alex_Gilko)\
**Replies:** 0\
**Last updated:** [March 24, 2021, 2:40pm UTC](https://discuss.elastic.co/t/numeric-value-1-8446744073709552e-19-out-of-range-of-long/268229 "2021-03-24T14:40:08Z")

</div>

"reason":"failed to parse field \[body.data.bar\_codes.frame\_id\] of type \[long\] in document with id 'LGaLZHgBVlMsC7cJsQlT'. Preview of field's value: '1.8446744073709552E19'","caused\_by":{"type":"input\_coercion\_exception",…

---

## [Kubernetes Events MetricBeat filter duplicate entries](https://discuss.elastic.co/t/kubernetes-events-metricbeat-filter-duplicate-entries/267064)

<div class="topic-metadata">

**Author:** [@webmutation](https://discuss.elastic.co/u/webmutation)\
**Replies:** 5\
**Last updated:** [March 24, 2021, 2:25pm UTC](https://discuss.elastic.co/t/kubernetes-events-metricbeat-filter-duplicate-entries/267064 "2021-03-24T14:25:01Z")

</div>

Having setup a default ELK stack on Kubernetes cluster I deployed MetricBeat also as default... everything works well, excepts I get duplicated entries for the same data, due to the daemonSet (I have 3 worker nodes on th…

---

## [Parse json from inside message](https://discuss.elastic.co/t/parse-json-from-inside-message/267269)

<div class="topic-metadata">

**Author:** [@Alex\_Gilko](https://discuss.elastic.co/u/Alex_Gilko)\
**Replies:** 5\
**Last updated:** [March 24, 2021, 2:16pm UTC](https://discuss.elastic.co/t/parse-json-from-inside-message/267269 "2021-03-24T14:16:17Z")

</div>

i trying to parse json from inside message . filebeat.autodiscover: providers: - type: docker hints.enabled: true used this in file beat used labels in docker-compose labels: co.elastic.logs/json.keys\_u…

---

## [Unable to start filebeat for apache logs](https://discuss.elastic.co/t/unable-to-start-filebeat-for-apache-logs/268094)

<div class="topic-metadata">

**Author:** [@Shriram\_Wasule](https://discuss.elastic.co/u/Shriram_Wasule)\
**Replies:** 7\
**Last updated:** [March 24, 2021, 2:08pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-for-apache-logs/268094 "2021-03-24T14:08:08Z")

</div>

i am not able to get solution for error saying "Exiting: Failed to start crawler: creating module reloader failed: 1 error: invalid config: yaml: line 13: could not fin d expected ':'" following is my apache.yml file #…

---

## [Where is log.file.path in the doc?](https://discuss.elastic.co/t/where-is-log-file-path-in-the-doc/268217)

<div class="topic-metadata">

**Author:** [@fabulias](https://discuss.elastic.co/u/fabulias)\
**Replies:** 0\
**Last updated:** [March 24, 2021, 1:40pm UTC](https://discuss.elastic.co/t/where-is-log-file-path-in-the-doc/268217 "2021-03-24T13:40:06Z")

</div>

Hi, we're using filebeats for a lot of months, I know when we use log input automatically are created some object fields host agent log Currently, I'm using log.file.path but in specific doesn't appear in the doc. But…

---

## [Filebeat multi-path configuration for send logs to Logstash](https://discuss.elastic.co/t/filebeat-multi-path-configuration-for-send-logs-to-logstash/267599)

<div class="topic-metadata">

**Author:** [@Nagavardhan25](https://discuss.elastic.co/u/Nagavardhan25)\
**Replies:** 5\
**Last updated:** [March 24, 2021, 9:44am UTC](https://discuss.elastic.co/t/filebeat-multi-path-configuration-for-send-logs-to-logstash/267599 "2021-03-24T09:44:44Z")

</div>

Hi, I have one config file in filebeat, i am trying to add two paths for reading the logs from two different locations and under feilds i have created two directories for storing the values in logstash side. Below is th…

---

## [Deployment of functionbeat on AWS](https://discuss.elastic.co/t/deployment-of-functionbeat-on-aws/268183)

<div class="topic-metadata">

**Author:** [@workaholicrohit](https://discuss.elastic.co/u/workaholicrohit)\
**Replies:** 0\
**Last updated:** [March 24, 2021, 9:07am UTC](https://discuss.elastic.co/t/deployment-of-functionbeat-on-aws/268183 "2021-03-24T09:07:46Z")

</div>

How can we configure the functionbeat on AWS to push sqs data to Elastic? Do we need to install and configure functionbeat on an EC2 to configure the .yml file?

---

## [New / Breaking Browser Heartbeat Config Syntax in 7.12](https://discuss.elastic.co/t/new-breaking-browser-heartbeat-config-syntax-in-7-12/268150)

<div class="topic-metadata">

**Author:** [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Replies:** 0\
**Last updated:** [March 24, 2021, 12:31am UTC](https://discuss.elastic.co/t/new-breaking-browser-heartbeat-config-syntax-in-7-12/268150 "2021-03-24T00:31:55Z")

</div>

To our synthetics / browser monitor users, with the release of 7.12 today you'll notice a new, improved syntax for specifying browser monitors. Please see our updated docs for more info. Here's a sample of the new confi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=168)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=170)
