# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=170

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 171

---

## [Live updating file](https://discuss.elastic.co/t/live-updating-file/268089)

<div class="topic-metadata">

**Author:** [@Marc2](https://discuss.elastic.co/u/Marc2)\
**Replies:** 0\
**Last updated:** [March 23, 2021, 12:07pm UTC](https://discuss.elastic.co/t/live-updating-file/268089 "2021-03-23T12:07:24Z")

</div>

Hi everyone, I need to update an inputed file which size doesn't change. It consists in a csv file that will be changing every 3 hours. I am doing a test changing manually the csv file by the new one (same size, but dif…

---

## [Drop fields not working in filebeat](https://discuss.elastic.co/t/drop-fields-not-working-in-filebeat/268058)

<div class="topic-metadata">

**Author:** [@none96](https://discuss.elastic.co/u/none96)\
**Replies:** 3\
**Last updated:** [March 23, 2021, 9:25am UTC](https://discuss.elastic.co/t/drop-fields-not-working-in-filebeat/268058 "2021-03-23T09:25:57Z")

</div>

I'm trying to remove fields by using the drop fields, the syntax is as follows : but it doesn't seem to work, any idea why?

---

## [Problem with filebeat prozessors](https://discuss.elastic.co/t/problem-with-filebeat-prozessors/267996)

<div class="topic-metadata">

**Author:** [@UweW](https://discuss.elastic.co/u/UweW)\
**Replies:** 1\
**Last updated:** [March 23, 2021, 9:06am UTC](https://discuss.elastic.co/t/problem-with-filebeat-prozessors/267996 "2021-03-23T09:06:31Z")

</div>

Hi, I run filebeat with a few moduled enabled like cef, cisco and fortinet. In the modules input area I add an tag related to the customer. Later in the processors part of filebeat.yml I use this tag to set correct org…

---

## [Exiting: error loading config file: stat metricbeat.yml: no such file or directory](https://discuss.elastic.co/t/exiting-error-loading-config-file-stat-metricbeat-yml-no-such-file-or-directory/268015)

<div class="topic-metadata">

**Author:** [@Jude\_Lindale](https://discuss.elastic.co/u/Jude_Lindale)\
**Replies:** 1\
**Last updated:** [March 23, 2021, 9:00am UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-stat-metricbeat-yml-no-such-file-or-directory/268015 "2021-03-23T09:00:00Z")

</div>

So I was having problems with metricbeat so I uninstalled it and the reinstalled metricbeat-7.11.2-amd64.deb and when I got to configure it in /etc/metricbeat the metricbeat.yml config file is not there. Please help.

---

## [Packetbeat getting high number of internal logs](https://discuss.elastic.co/t/packetbeat-getting-high-number-of-internal-logs/268054)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 0\
**Last updated:** [March 23, 2021, 8:11am UTC](https://discuss.elastic.co/t/packetbeat-getting-high-number-of-internal-logs/268054 "2021-03-23T08:11:52Z")

</div>

Hi, I can see that packetbeat is giving a high number of logs from internal ip's like (255.255.255.255) larger than the server ip itself! I only need the data related to the the server ip only, I don't know if somebody…

---

## [How can we run filebeat on openwrt?](https://discuss.elastic.co/t/how-can-we-run-filebeat-on-openwrt/267745)

<div class="topic-metadata">

**Author:** [@Husnain](https://discuss.elastic.co/u/Husnain)\
**Replies:** 2\
**Last updated:** [March 23, 2021, 6:58am UTC](https://discuss.elastic.co/t/how-can-we-run-filebeat-on-openwrt/267745 "2021-03-23T06:58:47Z")

</div>

Hii.Can someone tell me that how can we install and run filebeat on openwrt?

---

## [Log viewing through Filebeat](https://discuss.elastic.co/t/log-viewing-through-filebeat/267713)

<div class="topic-metadata">

**Author:** [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Replies:** 2\
**Last updated:** [March 18, 2021, 8:38pm UTC](https://discuss.elastic.co/t/log-viewing-through-filebeat/267713 "2021-03-18T20:38:03Z")

</div>

Hello there, I am trying to explore the possibility of log viewing through Kibana dashboard. I understand the process of setting up logs location in filebeat.yml file and then create index in kibana and then view logs …

---

## [Installing MetricBeat with ElasticSearch7.9.0](https://discuss.elastic.co/t/installing-metricbeat-with-elasticsearch7-9-0/267118)

<div class="topic-metadata">

**Author:** [@maheshe](https://discuss.elastic.co/u/maheshe)\
**Replies:** 1\
**Last updated:** [March 22, 2021, 9:45pm UTC](https://discuss.elastic.co/t/installing-metricbeat-with-elasticsearch7-9-0/267118 "2021-03-22T21:45:14Z")

</div>

We have a self-managed Elastic EFK stack running. Iam trying to setup metric beats on some of our Linux/UNIX AMIs to monitor their CPU metrics. Referred link: https://www.elastic.co/guide/en/beats/metricbeat/7.x/metric…

---

## [Filebeat Cisco module field type randomly changing](https://discuss.elastic.co/t/filebeat-cisco-module-field-type-randomly-changing/268012)

<div class="topic-metadata">

**Author:** [@JackScripter](https://discuss.elastic.co/u/JackScripter)\
**Replies:** 0\
**Last updated:** [March 22, 2021, 7:57pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-field-type-randomly-changing/268012 "2021-03-22T19:57:40Z")

</div>

Hi ! We use 2 filebeat modules (cisco + checkpoint) running on the same server, so it's basically a syslog server. I configured filebeat to use a custom index. For some reason, some field type are mapped incorrectly, es…

---

## [Multiline pattern not working for more complex cases](https://discuss.elastic.co/t/multiline-pattern-not-working-for-more-complex-cases/267407)

<div class="topic-metadata">

**Author:** [@RFeiten](https://discuss.elastic.co/u/RFeiten)\
**Replies:** 4\
**Last updated:** [March 22, 2021, 4:37pm UTC](https://discuss.elastic.co/t/multiline-pattern-not-working-for-more-complex-cases/267407 "2021-03-22T16:37:52Z")

</div>

Hi all! I'm facing an issue while collecting logs using Filebeat (7.x) in conjunction to a pipeline in Logstash. The multi-line scenario has been overcome by checking elastic documentation, however, there are specific …

---

## [Filebeat stopped automatically](https://discuss.elastic.co/t/filebeat-stopped-automatically/267950)

<div class="topic-metadata">

**Author:** [@Tristan\_D](https://discuss.elastic.co/u/Tristan_D)\
**Replies:** 3\
**Last updated:** [March 22, 2021, 1:14pm UTC](https://discuss.elastic.co/t/filebeat-stopped-automatically/267950 "2021-03-22T13:14:30Z")

</div>

Hi, everyone. I have two servers using filebeat-7.10.1. Today I found filebeat stoped automaticaly at the same time. They have worked normaly several days. We didn't kill it, the cpu or mem of the servers didn't have any…

---

## [How to use configure filebeat to filter docker containers using hints-based autodiscovery](https://discuss.elastic.co/t/how-to-use-configure-filebeat-to-filter-docker-containers-using-hints-based-autodiscovery/267813)

<div class="topic-metadata">

**Author:** [@Daniel\_Porter](https://discuss.elastic.co/u/Daniel_Porter)\
**Replies:** 2\
**Last updated:** [March 22, 2021, 12:50pm UTC](https://discuss.elastic.co/t/how-to-use-configure-filebeat-to-filter-docker-containers-using-hints-based-autodiscovery/267813 "2021-03-22T12:50:33Z")

</div>

Hi there, I'm trying to figure out how to configure filebeat (e.g. set a condition) to harvest from certain docker containers when using hints-based autodiscover. My use case is having two instances of filebeat running,…

---

## [S3 input plugin](https://discuss.elastic.co/t/s3-input-plugin/267869)

<div class="topic-metadata">

**Author:** [@paano](https://discuss.elastic.co/u/paano)\
**Replies:** 1\
**Last updated:** [March 22, 2021, 10:00am UTC](https://discuss.elastic.co/t/s3-input-plugin/267869 "2021-03-22T10:00:39Z")

</div>

Reading the S3 plugin https://www.elastic.co/guide/en/logstash/current/plugins-inputs-s3.html#plugins-inputs-s3 there is one line Each line from each file generates an event. Files ending in .gz are handled as gzip’ed f…

---

## [Filebeat setup fails to authenticate against Kibana](https://discuss.elastic.co/t/filebeat-setup-fails-to-authenticate-against-kibana/267800)

<div class="topic-metadata">

**Author:** [@sonoroot](https://discuss.elastic.co/u/sonoroot)\
**Replies:** 1\
**Last updated:** [March 22, 2021, 9:32am UTC](https://discuss.elastic.co/t/filebeat-setup-fails-to-authenticate-against-kibana/267800 "2021-03-22T09:32:46Z")

</div>

Hello! I am setting up a PoC for ECK. Kibana is exposed as a Kubernetes Ingress (nginx-controller) on port 80, and I can successfully access via web browser (using the credentials elastic and the password dynamically c…

---

## [Filebeat multiline concatenates all events that does not match the pattern](https://discuss.elastic.co/t/filebeat-multiline-concatenates-all-events-that-does-not-match-the-pattern/267779)

<div class="topic-metadata">

**Author:** [@seso](https://discuss.elastic.co/u/seso)\
**Replies:** 1\
**Last updated:** [March 22, 2021, 9:28am UTC](https://discuss.elastic.co/t/filebeat-multiline-concatenates-all-events-that-does-not-match-the-pattern/267779 "2021-03-22T09:28:49Z")

</div>

I have the following multiline pattern to handle Java stack traces: multiline.type: pattern multiline.pattern: '^\\d{4}-\\d{2}-\\d{2}\\s\\d{2}:\\d{2}:\\d{2}.\\d{3}' multiline.negate: true multiline.match: after It works fin…

---

## [Losing finishing lines of a terminating / crashing container](https://discuss.elastic.co/t/losing-finishing-lines-of-a-terminating-crashing-container/267763)

<div class="topic-metadata">

**Author:** [@AndD](https://discuss.elastic.co/u/AndD)\
**Replies:** 1\
**Last updated:** [March 22, 2021, 9:14am UTC](https://discuss.elastic.co/t/losing-finishing-lines-of-a-terminating-crashing-container/267763 "2021-03-22T09:14:50Z")

</div>

Hello, We are trying to setup Elastic Cloud on Kubernetes 1.4, using Filebeat 7.11.1 to harvest logs of all containers running on our Kubernetes cluster. Since giving an annotation to all Pods we could potentially be i…

---

## [Filebeat netflow module do not start after update to 7.11](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037)

<div class="topic-metadata">

**Author:** [@UweW](https://discuss.elastic.co/u/UweW)\
**Replies:** 7\
**Last updated:** [March 22, 2021, 7:53am UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037 "2021-03-22T07:53:53Z")

</div>

Hi, after updating the stack from 7.10.2 to 7.11 the netflow module will not start anymore. The only message we see every 10 seconds in journal is filebeat\[1976620\]: 2021-02-11T17:40:01.242+0100 ERROR \[r…

---

## [How to create pipeline definition from command line?](https://discuss.elastic.co/t/how-to-create-pipeline-definition-from-command-line/267139)

<div class="topic-metadata">

**Author:** [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Replies:** 2\
**Last updated:** [March 22, 2021, 3:44am UTC](https://discuss.elastic.co/t/how-to-create-pipeline-definition-from-command-line/267139 "2021-03-22T03:44:30Z")

</div>

I want to automate the process for preparing below pipeline. i.e by command line , api , etc This is because I want to send logs from filebeat to logstash instead of sending directly to elasticsearch . GET \_ingest/p…

---

## [Packetbeat: Trying to find utilization across network](https://discuss.elastic.co/t/packetbeat-trying-to-find-utilization-across-network/267368)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [March 22, 2021, 2:03am UTC](https://discuss.elastic.co/t/packetbeat-trying-to-find-utilization-across-network/267368 "2021-03-22T02:03:58Z")

</div>

Hi all, I'm trying to find Network devices in network with over 70% utilization. I'm unable to find the data in my packetbeat index. Any way to go about to do visualization. Thanks in Advance.

---

## [Packetbeat : Detecting Top applications usage on Network](https://discuss.elastic.co/t/packetbeat-detecting-top-applications-usage-on-network/267366)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [March 22, 2021, 2:03am UTC](https://discuss.elastic.co/t/packetbeat-detecting-top-applications-usage-on-network/267366 "2021-03-22T02:03:40Z")

</div>

Hi all, I'm using packetbeat and building visualizations based on network data. I'm trying to see top applications usage across network. I'm not getting any data regarding this. Any solution for this. Thanks in adva…

---

## [Help With Validating This Heartbeat Config](https://discuss.elastic.co/t/help-with-validating-this-heartbeat-config/267874)

<div class="topic-metadata">

**Author:** [@LongBeachHXC](https://discuss.elastic.co/u/LongBeachHXC)\
**Replies:** 2\
**Last updated:** [March 22, 2021, 1:53am UTC](https://discuss.elastic.co/t/help-with-validating-this-heartbeat-config/267874 "2021-03-22T01:53:14Z")

</div>

I am having a tough time starting a heartbeat container. I am bind mounting the config file into the path /usr/share/heartbeat/heartbeat.yml. My config file is below. I'm sure this is something simple but I haven't been …

---

## [Filebeat misp module](https://discuss.elastic.co/t/filebeat-misp-module/267843)

<div class="topic-metadata">

**Author:** [@Charles100](https://discuss.elastic.co/u/Charles100)\
**Replies:** 2\
**Last updated:** [March 22, 2021, 1:09am UTC](https://discuss.elastic.co/t/filebeat-misp-module/267843 "2021-03-22T01:09:16Z")

</div>

Hi, I'm playing the filebeat MISP module and getting this error when starting filebeat : : ERROR fileset/factory.go:97 Error creating input: (assert) value of type 'string' not convertible into unsupported go type '…

---

## [Parse JSON in "message" field](https://discuss.elastic.co/t/parse-json-in-message-field/267854)

<div class="topic-metadata">

**Author:** [@surprised\_ferret](https://discuss.elastic.co/u/surprised_ferret)\
**Replies:** 1\
**Last updated:** [March 20, 2021, 2:18pm UTC](https://discuss.elastic.co/t/parse-json-in-message-field/267854 "2021-03-20T14:18:42Z")

</div>

Elastic version 7.11.1 How do I parse a JSON structure (nested, one field has an array) out into separate fields of their own? I'm running filebeat on my k8 instance, this is what my "filebeat.yml" value looks like, i…

---

## [Filebeat 7.10 fails to collect events from multiple kubernetes pods](https://discuss.elastic.co/t/filebeat-7-10-fails-to-collect-events-from-multiple-kubernetes-pods/267406)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 6\
**Last updated:** [March 20, 2021, 1:31pm UTC](https://discuss.elastic.co/t/filebeat-7-10-fails-to-collect-events-from-multiple-kubernetes-pods/267406 "2021-03-20T13:31:55Z")

</div>

Filebeat is configured to collect events from multiple kubernetes pods using or condition. Events from a specific pod are continuously collected but events from another pod are collected very slowly and no events are col…

---

## [Metric Beat AWS Billing](https://discuss.elastic.co/t/metric-beat-aws-billing/265654)

<div class="topic-metadata">

**Author:** [@vinay9](https://discuss.elastic.co/u/vinay9)\
**Replies:** 2\
**Last updated:** [March 20, 2021, 5:18am UTC](https://discuss.elastic.co/t/metric-beat-aws-billing/265654 "2021-03-20T05:18:19Z")

</div>

Any help on this is appreciated, I am using metricbeat to get the data from aws cloud watch and cost explorer, from Elasticsearch and to kibana dashboard i was able successfully get the all metrics for ec2 from aws. But …

---

## [Packetbeat will not GET Kibana HTTPS](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210)

<div class="topic-metadata">

**Author:** [@Elks2020](https://discuss.elastic.co/u/Elks2020)\
**Replies:** 6\
**Last updated:** [March 20, 2021, 4:09am UTC](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210 "2021-03-20T04:09:35Z")

</div>

Hello everyone, I need help to figure-out the following problem to be fixed where the packetbeat won't start! :tired\_face: ' ' ' packetbeat\[523584\]: Exiting: error connecting to Kibana: fail to get the Kibana version…

---

## [Mulitline pattern in docker autodiscover](https://discuss.elastic.co/t/mulitline-pattern-in-docker-autodiscover/267647)

<div class="topic-metadata">

**Author:** [@d01](https://discuss.elastic.co/u/d01)\
**Replies:** 2\
**Last updated:** [March 19, 2021, 11:06am UTC](https://discuss.elastic.co/t/mulitline-pattern-in-docker-autodiscover/267647 "2021-03-19T11:06:39Z")

</div>

I have the following logs coming from a docker container: 2021-03-17T13:43:43+0000 DEBUG \[\_\_main\_\_.\<module\>\] Debug 2021-03-17T13:43:43+0000 INFO \[\_\_main\_\_.\<module\>\] Info 2021-03-17T13:43:43+0000 WARNI…

---

## [Filebeat error when importing logs](https://discuss.elastic.co/t/filebeat-error-when-importing-logs/267395)

<div class="topic-metadata">

**Author:** [@Liliana\_Novais](https://discuss.elastic.co/u/Liliana_Novais)\
**Replies:** 8\
**Last updated:** [March 19, 2021, 10:27am UTC](https://discuss.elastic.co/t/filebeat-error-when-importing-logs/267395 "2021-03-19T10:27:33Z")

</div>

Hello, I configured my elasticsearch with file beat. When my file is changed I get the following error from filebeat: can someone helpme understand this error?

---

## [Filebeat PostgreSQL module not parsing message](https://discuss.elastic.co/t/filebeat-postgresql-module-not-parsing-message/267464)

<div class="topic-metadata">

**Author:** [@martinfrancois](https://discuss.elastic.co/u/martinfrancois)\
**Replies:** 2\
**Last updated:** [March 19, 2021, 9:01am UTC](https://discuss.elastic.co/t/filebeat-postgresql-module-not-parsing-message/267464 "2021-03-19T09:01:37Z")

</div>

We are using filebeat 7.11.0 along with the postgresql module. However for some reason, the message attribute seems not to be touched, although some metadata seems to be added by the module. Our log messages look to be …

---

## [Cloud aws module IAM permissions for filebeat](https://discuss.elastic.co/t/cloud-aws-module-iam-permissions-for-filebeat/267617)

<div class="topic-metadata">

**Author:** [@AJ18](https://discuss.elastic.co/u/AJ18)\
**Replies:** 3\
**Last updated:** [March 19, 2021, 5:21am UTC](https://discuss.elastic.co/t/cloud-aws-module-iam-permissions-for-filebeat/267617 "2021-03-19T05:21:44Z")

</div>

What are the minimum set of permissions the cloud-aws plugin requires to work with filebeat?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=169)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=171)
