# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=171

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 172

---

## [Winlogbeats add public IP info](https://discuss.elastic.co/t/winlogbeats-add-public-ip-info/267542)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 3\
**Last updated:** [March 19, 2021, 1:58am UTC](https://discuss.elastic.co/t/winlogbeats-add-public-ip-info/267542 "2021-03-19T01:58:52Z")

</div>

Is there anyway with winlogbeats to get the devices current public IP and add that to the event data?

---

## [Filebeat output to secured HA Elasticsearch](https://discuss.elastic.co/t/filebeat-output-to-secured-ha-elasticsearch/267702)

<div class="topic-metadata">

**Author:** [@Jose\_Angel\_Morena\_Si](https://discuss.elastic.co/u/Jose_Angel_Morena_Si)\
**Replies:** 1\
**Last updated:** [March 18, 2021, 7:47pm UTC](https://discuss.elastic.co/t/filebeat-output-to-secured-ha-elasticsearch/267702 "2021-03-18T19:47:39Z")

</div>

Hello there, I have successfully deployed an HA Elasticsearch cluster which is has xpack security features enabled. My problem is that I do not really know how to configure filebeat elasticsearch.output, so it can do pe…

---

## [How can I get more fields from vcenter using vsphere module?](https://discuss.elastic.co/t/how-can-i-get-more-fields-from-vcenter-using-vsphere-module/267561)

<div class="topic-metadata">

**Author:** [@Ishaan](https://discuss.elastic.co/u/Ishaan)\
**Replies:** 1\
**Last updated:** [March 18, 2021, 4:15pm UTC](https://discuss.elastic.co/t/how-can-i-get-more-fields-from-vcenter-using-vsphere-module/267561 "2021-03-18T16:15:14Z")

</div>

Is there a way to get more metrics/fields from vcenter using vsphere module? How can I check that what's happening behind the vsphere module?

---

## [How to show filesystem metrics](https://discuss.elastic.co/t/how-to-show-filesystem-metrics/267515)

<div class="topic-metadata">

**Author:** [@CJ\_Chang](https://discuss.elastic.co/u/CJ_Chang)\
**Replies:** 1\
**Last updated:** [March 18, 2021, 4:09pm UTC](https://discuss.elastic.co/t/how-to-show-filesystem-metrics/267515 "2021-03-18T16:09:47Z")

</div>

Hi, I am using metricbeat 7.6. The following is my system.yaml - module: system period: 10s metricsets: - cpu - load - memory - network - process - process\_summary - socket\_summary pr…

---

## [Metricbeat kafka module kerberos authentication](https://discuss.elastic.co/t/metricbeat-kafka-module-kerberos-authentication/265167)

<div class="topic-metadata">

**Author:** [@drewkrrb](https://discuss.elastic.co/u/drewkrrb)\
**Replies:** 4\
**Last updated:** [March 18, 2021, 4:04pm UTC](https://discuss.elastic.co/t/metricbeat-kafka-module-kerberos-authentication/265167 "2021-03-18T16:04:12Z")

</div>

Hi Am trying to enable metricbeat kafka module in my kafka cluster. My kafka cluster uses kerberos auth to access all the topics. Here is my current config: # Module: kafka # Docs: https://www.elastic.co/guide/en/beat…

---

## [Filebeat iowaits issue?](https://discuss.elastic.co/t/filebeat-iowaits-issue/264663)

<div class="topic-metadata">

**Author:** [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Replies:** 15\
**Last updated:** [March 18, 2021, 1:16pm UTC](https://discuss.elastic.co/t/filebeat-iowaits-issue/264663 "2021-03-18T13:16:57Z")

</div>

Hi all, I am running a k8s Cluster that is being suspended every night, due to cost savings, as no one works at this time on the cluster. Unfortunately it seems like fielbeat is not really getting along with that. Ever…

---

## [Metricbeat - SSL Kafka Output (Failed authentication)](https://discuss.elastic.co/t/metricbeat-ssl-kafka-output-failed-authentication/267261)

<div class="topic-metadata">

**Author:** [@marti1](https://discuss.elastic.co/u/marti1)\
**Replies:** 0\
**Last updated:** [March 15, 2021, 12:32pm UTC](https://discuss.elastic.co/t/metricbeat-ssl-kafka-output-failed-authentication/267261 "2021-03-15T12:32:32Z")

</div>

Hi, I'm trying to configure a secure connection (SSL) between my beat (metricbeat windows) and kafka server, but the handshake is failing. Is my configuration metricbeat.yml OK? output.kafka: # Active enabled: tr…

---

## [Filebeat events doesnt come with ECS compatibility while coming through Logstash](https://discuss.elastic.co/t/filebeat-events-doesnt-come-with-ecs-compatibility-while-coming-through-logstash/266744)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 11\
**Last updated:** [March 18, 2021, 9:52am UTC](https://discuss.elastic.co/t/filebeat-events-doesnt-come-with-ecs-compatibility-while-coming-through-logstash/266744 "2021-03-18T09:52:11Z")

</div>

I am using the Filebeat AWS module to fetch Cloudtrail logs. To load the dashboards, first I configured Filebet output to Elasticsearch and send some data to test and it was having ECS field names. However, while I sent …

---

## [Winlogbeat Parser Modification](https://discuss.elastic.co/t/winlogbeat-parser-modification/267385)

<div class="topic-metadata">

**Author:** [@deeshu](https://discuss.elastic.co/u/deeshu)\
**Replies:** 3\
**Last updated:** [March 18, 2021, 7:09am UTC](https://discuss.elastic.co/t/winlogbeat-parser-modification/267385 "2021-03-18T07:09:39Z")

</div>

Hi Experts.. I've to parse some windows security events which are currently not supported by Winlogbeat and looking to modify the existing parsing capability of Winlogbeat. Looking at the file, it seems that "/module/s…

---

## [Filebeat output elasticsearch max\_retries configuration question](https://discuss.elastic.co/t/filebeat-output-elasticsearch-max-retries-configuration-question/267315)

<div class="topic-metadata">

**Author:** [@tianhao](https://discuss.elastic.co/u/tianhao)\
**Replies:** 2\
**Last updated:** [March 18, 2021, 3:50am UTC](https://discuss.elastic.co/t/filebeat-output-elasticsearch-max-retries-configuration-question/267315 "2021-03-18T03:50:44Z")

</div>

Hi ! I saw the description Filebeat ignores the max\_retries setting and retries indefinitely. in https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#\_max\_retries but in the filebeat configur…

---

## [Connect to Okta module of Filebeat via proxy](https://discuss.elastic.co/t/connect-to-okta-module-of-filebeat-via-proxy/267480)

<div class="topic-metadata">

**Author:** [@Aditya\_Srivastava1](https://discuss.elastic.co/u/Aditya_Srivastava1)\
**Replies:** 2\
**Last updated:** [March 17, 2021, 8:49pm UTC](https://discuss.elastic.co/t/connect-to-okta-module-of-filebeat-via-proxy/267480 "2021-03-17T20:49:06Z")

</div>

Hi, As I want to fetch logs from Okta, I am using filebeat 7.11 to do it. In the modules.d directory of filebeat, I can see configurations for Okta available. I have entered the URL & credentials mentioned there. But n…

---

## [Visualize io stat per process](https://discuss.elastic.co/t/visualize-io-stat-per-process/267527)

<div class="topic-metadata">

**Author:** [@Mario\_Fimiani](https://discuss.elastic.co/u/Mario_Fimiani)\
**Replies:** 1\
**Last updated:** [March 17, 2021, 7:49pm UTC](https://discuss.elastic.co/t/visualize-io-stat-per-process/267527 "2021-03-17T19:49:42Z")

</div>

Hi there is a way to visualize with metricbeat the IO stat per process ?

---

## [Filebeat Logs rotating filename with data pattern](https://discuss.elastic.co/t/filebeat-logs-rotating-filename-with-data-pattern/267534)

<div class="topic-metadata">

**Author:** [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Replies:** 2\
**Last updated:** [March 17, 2021, 5:48pm UTC](https://discuss.elastic.co/t/filebeat-logs-rotating-filename-with-data-pattern/267534 "2021-03-17T17:48:28Z")

</div>

Hello, Is there anyway to append a date pattern to Filebeat (or beat in general) to log file That help sometimes for logs rotating Something like this may be ? Thank You logging.files.name: "filebeat-{now/d{yyyy-MM-…

---

## [Apache Docker containers autodiscovery ends up with grok error for error messages](https://discuss.elastic.co/t/apache-docker-containers-autodiscovery-ends-up-with-grok-error-for-error-messages/265746)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 3\
**Last updated:** [March 17, 2021, 3:55pm UTC](https://discuss.elastic.co/t/apache-docker-containers-autodiscovery-ends-up-with-grok-error-for-error-messages/265746 "2021-03-17T15:55:10Z")

</div>

I set up a new instance of Elasticsearch, Kibana, and various beats today. Since my sites are all in containers, I eventually found my way to the autodiscovery settings. I've been able to configure access logs so that F…

---

## [Beats for legacy OS](https://discuss.elastic.co/t/beats-for-legacy-os/266918)

<div class="topic-metadata">

**Author:** [@kunal\_patil](https://discuss.elastic.co/u/kunal_patil)\
**Replies:** 3\
**Last updated:** [March 17, 2021, 11:11am UTC](https://discuss.elastic.co/t/beats-for-legacy-os/266918 "2021-03-17T11:11:39Z")

</div>

Looking for a way to have beats essentially metricbeat, filebeat to work on older operating systems SLES 9, 10 etc to monitor the servers which are hosting legacy applications. I am getting "panic" errors like below for …

---

## [Timestamp processor truncates timestamp and fails to parse](https://discuss.elastic.co/t/timestamp-processor-truncates-timestamp-and-fails-to-parse/267190)

<div class="topic-metadata">

**Author:** [@6NMgfDwZ3](https://discuss.elastic.co/u/6NMgfDwZ3)\
**Replies:** 6\
**Last updated:** [March 17, 2021, 3:09am UTC](https://discuss.elastic.co/t/timestamp-processor-truncates-timestamp-and-fails-to-parse/267190 "2021-03-17T03:09:00Z")

</div>

Hello, I have log messages with a mytimesmap field. This field contains microseconds precision RFC3339/ISO8601 (UTC) style timestamp like 2021-03-14T13:25:49.008906Z. So I'd like to overwrite @timestamp field with myti…

---

## [\[Metricbeat 7.9\] x509: certificate is valid for instance, not localhost](https://discuss.elastic.co/t/metricbeat-7-9-x509-certificate-is-valid-for-instance-not-localhost/266849)

<div class="topic-metadata">

**Author:** [@glitz](https://discuss.elastic.co/u/glitz)\
**Replies:** 1\
**Last updated:** [March 16, 2021, 8:00pm UTC](https://discuss.elastic.co/t/metricbeat-7-9-x509-certificate-is-valid-for-instance-not-localhost/266849 "2021-03-16T20:00:27Z")

</div>

Hello, I'm trying to send data from Metricbeat 7.9 to an already-tls-working Elasticsearch 7.9 but without success...It is a test environment, everything on same server(Elasticsearch, Kibana and Metricbeat) my metricbe…

---

## [Unable to export logs from AKS cluster to kibana for specific pods](https://discuss.elastic.co/t/unable-to-export-logs-from-aks-cluster-to-kibana-for-specific-pods/267277)

<div class="topic-metadata">

**Author:** [@sanjeevsharma-1](https://discuss.elastic.co/u/sanjeevsharma-1)\
**Replies:** 3\
**Last updated:** [March 16, 2021, 7:02pm UTC](https://discuss.elastic.co/t/unable-to-export-logs-from-aks-cluster-to-kibana-for-specific-pods/267277 "2021-03-16T19:02:06Z")

</div>

We are using filebeat.yaml configuration(which is similar to https://github.com/elastic/beats/blob/master/deploy/kubernetes/filebeat/filebeat-daemonset.yaml) to migrate or export all the logs from AKS cluster to Kibana a…

---

## [Metricbeat "Failed due to panic.{"panic": "runtime error: index out of range \[0\]"](https://discuss.elastic.co/t/metricbeat-failed-due-to-panic-panic-runtime-error-index-out-of-range-0/267047)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 4\
**Last updated:** [March 16, 2021, 4:41pm UTC](https://discuss.elastic.co/t/metricbeat-failed-due-to-panic-panic-runtime-error-index-out-of-range-0/267047 "2021-03-16T16:41:18Z")

</div>

I am using the Metricbeat AWS module while starting Metricbeat, I am facing the following error. I went through Git issues but seems it's fixed in the version I am using. I am pasting my aws.yml as well for reference. E…

---

## [Configure Input and Modules at the same time for Filebeat](https://discuss.elastic.co/t/configure-input-and-modules-at-the-same-time-for-filebeat/266575)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 4\
**Last updated:** [March 16, 2021, 2:37pm UTC](https://discuss.elastic.co/t/configure-input-and-modules-at-the-same-time-for-filebeat/266575 "2021-03-16T14:37:53Z")

</div>

Hi, I have following scenario: One filebeat installation to collect icinga logs. For this I am using icinga module On the same host I have another application's logs, which are located in different path and have d…

---

## [Configure SSL/TLS beats for Windows](https://discuss.elastic.co/t/configure-ssl-tls-beats-for-windows/267346)

<div class="topic-metadata">

**Author:** [@ravenmx](https://discuss.elastic.co/u/ravenmx)\
**Replies:** 1\
**Last updated:** [March 16, 2021, 11:45am UTC](https://discuss.elastic.co/t/configure-ssl-tls-beats-for-windows/267346 "2021-03-16T11:45:21Z")

</div>

Hello. I can not configure metricbeat for Windows. It is required to configure ssl / tsl connection before logstash. but the agent does not accept system paths (C: \\ path \\ to \\ beats \\ sslCA.pem). therefore I can not sp…

---

## [Using the heartbeat (6.8.3) keystore prevents heartbeat windows service starting](https://discuss.elastic.co/t/using-the-heartbeat-6-8-3-keystore-prevents-heartbeat-windows-service-starting/267353)

<div class="topic-metadata">

**Author:** [@halltony](https://discuss.elastic.co/u/halltony)\
**Replies:** 0\
**Last updated:** [March 16, 2021, 11:06am UTC](https://discuss.elastic.co/t/using-the-heartbeat-6-8-3-keystore-prevents-heartbeat-windows-service-starting/267353 "2021-03-16T11:06:45Z")

</div>

I am trying to use the heartbeat keystore to store credentials used to authenticate with my Elastic Search cluster. The configuration works fine when run from a command line but when I use it via a windows service the s…

---

## [Sophos central endpoint alerts logs](https://discuss.elastic.co/t/sophos-central-endpoint-alerts-logs/267323)

<div class="topic-metadata">

**Author:** [@Ana\_11](https://discuss.elastic.co/u/Ana_11)\
**Replies:** 0\
**Last updated:** [March 16, 2021, 6:45am UTC](https://discuss.elastic.co/t/sophos-central-endpoint-alerts-logs/267323 "2021-03-16T06:45:16Z")

</div>

Hi I want to ingest sophos intercept x endpoint logs to elasticsearch. Through API im getting the alerts on syslog but the sophos filebeat module does not support alerts as it says it support only firewall logs. can u t…

---

## [Filebeat is overwriting the pipeline specified in Elastic on start](https://discuss.elastic.co/t/filebeat-is-overwriting-the-pipeline-specified-in-elastic-on-start/266825)

<div class="topic-metadata">

**Author:** [@JamblaInc](https://discuss.elastic.co/u/JamblaInc)\
**Replies:** 7\
**Last updated:** [March 15, 2021, 2:54pm UTC](https://discuss.elastic.co/t/filebeat-is-overwriting-the-pipeline-specified-in-elastic-on-start/266825 "2021-03-15T14:54:19Z")

</div>

I am using Filebeat to collect CloudWatch logs and I have modified the ingest node pipeline to extract and index some more information from the logs. However, when Filebeat has restarted the extra processors that I added…

---

## [Filebeat to parse json array](https://discuss.elastic.co/t/filebeat-to-parse-json-array/267301)

<div class="topic-metadata">

**Author:** [@vantoryc](https://discuss.elastic.co/u/vantoryc)\
**Replies:** 2\
**Last updated:** [March 15, 2021, 9:00pm UTC](https://discuss.elastic.co/t/filebeat-to-parse-json-array/267301 "2021-03-15T21:00:08Z")

</div>

Hi, We are currently using filebeats to send logs to our Graylog. So far it has worked out fine for as as the logs were single line. Now we want to add logs from another folder but the logs are are multiline json array…

---

## [Setup filebeat custom nginx access logs path inside docker container](https://discuss.elastic.co/t/setup-filebeat-custom-nginx-access-logs-path-inside-docker-container/267189)

<div class="topic-metadata">

**Author:** [@cdalexndr](https://discuss.elastic.co/u/cdalexndr)\
**Replies:** 1\
**Last updated:** [March 15, 2021, 7:13pm UTC](https://discuss.elastic.co/t/setup-filebeat-custom-nginx-access-logs-path-inside-docker-container/267189 "2021-03-15T19:13:05Z")

</div>

How to configure a filebeat running inside a docker container to get access logs from nginx running in another container? Nginx access logs are not in default location so the paths must be configured. I've tried using …

---

## [Set order of filebeat inputs](https://discuss.elastic.co/t/set-order-of-filebeat-inputs/267157)

<div class="topic-metadata">

**Author:** [@SKiD](https://discuss.elastic.co/u/SKiD)\
**Replies:** 1\
**Last updated:** [March 15, 2021, 6:26pm UTC](https://discuss.elastic.co/t/set-order-of-filebeat-inputs/267157 "2021-03-15T18:26:09Z")

</div>

Hey, I want to ship lines from Filebeat to Logstash in a specific input order. The reason I want to do that is that the documents of the second input are basing on the documents of the second input. This means I update …

---

## [Filebeat error during install](https://discuss.elastic.co/t/filebeat-error-during-install/267257)

<div class="topic-metadata">

**Author:** [@Liliana\_Novais](https://discuss.elastic.co/u/Liliana_Novais)\
**Replies:** 5\
**Last updated:** [March 15, 2021, 4:29pm UTC](https://discuss.elastic.co/t/filebeat-error-during-install/267257 "2021-03-15T16:29:00Z")

</div>

Hello, I am trying to configure Filebeat. When I input this command: .\\filebeat.exe modules list I am having the following error: Error initializing beat: error loading config file: yaml: line 157: did not find expec…

---

## [Elastic Agent healthy, but no data streams](https://discuss.elastic.co/t/elastic-agent-healthy-but-no-data-streams/265699)

<div class="topic-metadata">

**Author:** [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Replies:** 9\
**Last updated:** [March 15, 2021, 2:20pm UTC](https://discuss.elastic.co/t/elastic-agent-healthy-but-no-data-streams/265699 "2021-03-15T14:20:10Z")

</div>

The Elastic Agent (7.11.1) is installed on a single Windows 10 test system and showing as 'Healthy' in Fleet, but I have no data appearing in streams. I have xpack security working with self generated certs - I have l…

---

## [Configure module Auditd with Kubectl \[Auditbeat 7.9.2\]](https://discuss.elastic.co/t/configure-module-auditd-with-kubectl-auditbeat-7-9-2/267048)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 1\
**Last updated:** [March 15, 2021, 2:19pm UTC](https://discuss.elastic.co/t/configure-module-auditd-with-kubectl-auditbeat-7-9-2/267048 "2021-03-15T14:19:27Z")

</div>

Hi, everyone I have been working with module Audit Module in order to log any execution of kubectl. Here you are my config: auditbeat.modules: - module: auditd audit\_rules: | -a always,exit -F exe=/usr/bin/kubec…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=170)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=172)
