# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=172

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 173

---

## [Metricbeat - no counter paths were found](https://discuss.elastic.co/t/metricbeat-no-counter-paths-were-found/267224)

<div class="topic-metadata">

**Author:** [@Inammathe\_Inna](https://discuss.elastic.co/u/Inammathe_Inna)\
**Replies:** 0\
**Last updated:** [March 15, 2021, 7:02am UTC](https://discuss.elastic.co/t/metricbeat-no-counter-paths-were-found/267224 "2021-03-15T07:02:19Z")

</div>

Hi, Periodically, we are finding our Windows servers stop sending perfmon metrics (other metrics e.g. cpu from the system module) continue just fine. The current workaround that gets them going again is restarting the …

---

## [Filebeat with a combination of netflow and iis](https://discuss.elastic.co/t/filebeat-with-a-combination-of-netflow-and-iis/267131)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 2\
**Last updated:** [March 15, 2021, 7:21am UTC](https://discuss.elastic.co/t/filebeat-with-a-combination-of-netflow-and-iis/267131 "2021-03-15T07:21:22Z")

</div>

Hi everyone, I have an ELK stack running on Ubuntu 20.04 server which is currently ingesting Filebeat IIS logs from a Windows machine. When I run the filebeat setup command from the Linux server to install the dashboar…

---

## [Get logs from my ip only in Paketbeat](https://discuss.elastic.co/t/get-logs-from-my-ip-only-in-paketbeat/267145)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 0\
**Last updated:** [March 13, 2021, 10:25am UTC](https://discuss.elastic.co/t/get-logs-from-my-ip-only-in-paketbeat/267145 "2021-03-13T10:25:11Z")

</div>

Hi, Can anybody tell how can I set a condition in packetbeat.yml to get traffic from my ip only and not from different subnets? In other words the destination.ip: should be only my ip and any other ip in the subnet. I'…

---

## [Elastic-Agent system logs stops](https://discuss.elastic.co/t/elastic-agent-system-logs-stops/267135)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 0\
**Last updated:** [March 13, 2021, 4:19am UTC](https://discuss.elastic.co/t/elastic-agent-system-logs-stops/267135 "2021-03-13T04:19:52Z")

</div>

Hi, In de default integration 'system' you can add 'system syslog logs' to collect. I added a few logs here. That's working. But every 2 days or so this logging stops. A workaround is to edit the interation, change not…

---

## ['when not' not working](https://discuss.elastic.co/t/when-not-not-working/267114)

<div class="topic-metadata">

**Author:** [@elbadar](https://discuss.elastic.co/u/elbadar)\
**Replies:** 1\
**Last updated:** [March 12, 2021, 7:08pm UTC](https://discuss.elastic.co/t/when-not-not-working/267114 "2021-03-12T19:08:25Z")

</div>

Hi guys, trying to push all log messages that contain 'Failed' or 'ERROR', but doesn't seem to like my syntax. I have looked at the syntax quite a bit but can't seem to nail it down. Didn't find any examples of "when not…

---

## [Is it possible to interpolate a field's value in a string?](https://discuss.elastic.co/t/is-it-possible-to-interpolate-a-fields-value-in-a-string/267027)

<div class="topic-metadata">

**Author:** [@merricat](https://discuss.elastic.co/u/merricat)\
**Replies:** 1\
**Last updated:** [March 12, 2021, 6:52pm UTC](https://discuss.elastic.co/t/is-it-possible-to-interpolate-a-fields-value-in-a-string/267027 "2021-03-12T18:52:08Z")

</div>

Hi there, I've been messing with Filebeat for about 2 days now.. I can't find a way to interpolate a field in another field. Here's what I have: processors: - add\_fields: target: "" fields…

---

## [WinLogBeat and Windows Server 2019](https://discuss.elastic.co/t/winlogbeat-and-windows-server-2019/265539)

<div class="topic-metadata">

**Author:** [@branden999](https://discuss.elastic.co/u/branden999)\
**Replies:** 5\
**Last updated:** [March 12, 2021, 3:08pm UTC](https://discuss.elastic.co/t/winlogbeat-and-windows-server-2019/265539 "2021-03-12T15:08:15Z")

</div>

Having trouble getting WinLogBeat to continue sending logs to Logstash. Prior to last week, I was running a virtual WEC (Windows Event Collector) on Windows Server 2016 with WinLogBeat 6.8 forwarding to a Logstash 6.7.2 …

---

## [Packetbeat logging traffic from Ip with different subnet](https://discuss.elastic.co/t/packetbeat-logging-traffic-from-ip-with-different-subnet/267057)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 0\
**Last updated:** [March 12, 2021, 8:38am UTC](https://discuss.elastic.co/t/packetbeat-logging-traffic-from-ip-with-different-subnet/267057 "2021-03-12T08:38:30Z")

</div>

Hi, I'm receiving logs from packetbeat from an IP with different subnet. Like my ip is 192.168.0.100 on network card index 1 for example, and I'm getting logs from this Ip and 192.168.1.92 which has different subnet. I…

---

## [Filebeat not sending kubernetes metadata](https://discuss.elastic.co/t/filebeat-not-sending-kubernetes-metadata/267054)

<div class="topic-metadata">

**Author:** [@Martinho\_MOREIRA](https://discuss.elastic.co/u/Martinho_MOREIRA)\
**Replies:** 0\
**Last updated:** [March 12, 2021, 8:20am UTC](https://discuss.elastic.co/t/filebeat-not-sending-kubernetes-metadata/267054 "2021-03-12T08:20:25Z")

</div>

Hi, I just upgrade my filebeat from 7.10.2 to 7.11.2 and kubernetes metadata are missing now: Here is my configuration file. Did I miss something ? filebeat.inputs: - type: container paths: - /var/log/container…

---

## [How to send different logs to logstash and elasticsearch](https://discuss.elastic.co/t/how-to-send-different-logs-to-logstash-and-elasticsearch/267038)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 1\
**Last updated:** [March 12, 2021, 8:04am UTC](https://discuss.elastic.co/t/how-to-send-different-logs-to-logstash-and-elasticsearch/267038 "2021-03-12T08:04:30Z")

</div>

It turns out that filebeat.yml can send the output to elasticsearch or logstash. Is it possible to change the destination depending on the logs collected by filebeat? For example, is it possible to send general logs th…

---

## [Filebeat getting error when parsing json](https://discuss.elastic.co/t/filebeat-getting-error-when-parsing-json/267033)

<div class="topic-metadata">

**Author:** [@hackercat](https://discuss.elastic.co/u/hackercat)\
**Replies:** 0\
**Last updated:** [March 12, 2021, 4:59am UTC](https://discuss.elastic.co/t/filebeat-getting-error-when-parsing-json/267033 "2021-03-12T04:59:46Z")

</div>

Hi there, Really new to the filebeat. I have a beat config like below. filebeat.inputs: - type: log enabled: true paths: - /tmp/api\_json.log fields: log\_group: gitlab\_test log\_id: api\_json json.key…

---

## [PacketBeat DNS protocol wrong registered\_domain when uppercase](https://discuss.elastic.co/t/packetbeat-dns-protocol-wrong-registered-domain-when-uppercase/267021)

<div class="topic-metadata">

**Author:** [@glee](https://discuss.elastic.co/u/glee)\
**Replies:** 0\
**Last updated:** [March 12, 2021, 1:52am UTC](https://discuss.elastic.co/t/packetbeat-dns-protocol-wrong-registered-domain-when-uppercase/267021 "2021-03-12T01:52:44Z")

</div>

Goodday. I'm monitoring my powerdns with packetbeat and elasticsearch. When domain query with all lowercase, everything is fine. ex) dig sub.example.co.kr dns.question.name : sub.example.co.kr dns.question.registered…

---

## [Filebeat timestamp conversion from PST to EST](https://discuss.elastic.co/t/filebeat-timestamp-conversion-from-pst-to-est/265414)

<div class="topic-metadata">

**Author:** [@mguttula](https://discuss.elastic.co/u/mguttula)\
**Replies:** 4\
**Last updated:** [March 11, 2021, 11:22pm UTC](https://discuss.elastic.co/t/filebeat-timestamp-conversion-from-pst-to-est/265414 "2021-03-11T23:22:44Z")

</div>

Input file has PST timestamp like "2020 Feb 12 13:54:07:447 GMT -0800" in a message event like below: 2020 Feb 12 13:54:07:447 GMT -0800 myservice Error \[mybusinessworks\] BWENGINE-100001 process initialization failed fo…

---

## [Metricbeat.system.memory fields are sending incorrect values](https://discuss.elastic.co/t/metricbeat-system-memory-fields-are-sending-incorrect-values/266973)

<div class="topic-metadata">

**Author:** [@Ishaan](https://discuss.elastic.co/u/Ishaan)\
**Replies:** 0\
**Last updated:** [March 11, 2021, 4:08pm UTC](https://discuss.elastic.co/t/metricbeat-system-memory-fields-are-sending-incorrect-values/266973 "2021-03-11T16:08:38Z")

</div>

It seems metricbeat system memory module is sending used memory value into free memory and free memory into used. For example: System.memory.total = 29320122368 system.memory.free = 280305664 system.memory. used = 29…

---

## [Metrics from metricbeat do not display in elk but exist in metricbeat console](https://discuss.elastic.co/t/metrics-from-metricbeat-do-not-display-in-elk-but-exist-in-metricbeat-console/266966)

<div class="topic-metadata">

**Author:** [@111451](https://discuss.elastic.co/u/111451)\
**Replies:** 0\
**Last updated:** [March 11, 2021, 3:26pm UTC](https://discuss.elastic.co/t/metrics-from-metricbeat-do-not-display-in-elk-but-exist-in-metricbeat-console/266966 "2021-03-11T15:26:44Z")

</div>

docker-compose.yml metricbeat: container\_name: metricbeat user: root #To read the docker socket image: docker.elastic.co/beats/metricbeat:7.11.1 logging: options: max-file: "3" max-…

---

## [Auditbeat 7.x file integrity module](https://discuss.elastic.co/t/auditbeat-7-x-file-integrity-module/266738)

<div class="topic-metadata">

**Author:** [@Mohammad\_Etemad](https://discuss.elastic.co/u/Mohammad_Etemad)\
**Replies:** 1\
**Last updated:** [March 11, 2021, 1:16pm UTC](https://discuss.elastic.co/t/auditbeat-7-x-file-integrity-module/266738 "2021-03-11T13:16:41Z")

</div>

Hello, I am using auditbeat to track file changes via the file integrity module. This works for a couple of minutes and logs the changes to files, but then stops working and no changes are detected anymore. Running audi…

---

## [\[error connecting to Elasticsearch at https:certificate signed by unknown authority](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-at-https-certificate-signed-by-unknown-authority/266678)

<div class="topic-metadata">

**Author:** [@Ana\_11](https://discuss.elastic.co/u/Ana_11)\
**Replies:** 3\
**Last updated:** [March 9, 2021, 1:22pm UTC](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-at-https-certificate-signed-by-unknown-authority/266678 "2021-03-09T13:22:05Z")

</div>

Hi I have enabled secure communication in my elasticsearch deployment. https is enabled and elasticsearch and kibana is working as expected. Now when im trying to ingest the winlogbeat logs im getting the following erro…

---

## [Unable to write not equal condition with filebeat processor](https://discuss.elastic.co/t/unable-to-write-not-equal-condition-with-filebeat-processor/266934)

<div class="topic-metadata">

**Author:** [@Sourabh\_Sharma1](https://discuss.elastic.co/u/Sourabh_Sharma1)\
**Replies:** 0\
**Last updated:** [March 11, 2021, 11:44am UTC](https://discuss.elastic.co/t/unable-to-write-not-equal-condition-with-filebeat-processor/266934 "2021-03-11T11:44:36Z")

</div>

\` dissect: tokenizer: '"%{pid|integer} - %{service.name} - %{service.status}"' field: "message" target\_prefix: "" drop\_event: when: not: equals: pid|integer: "105" smaple logs: "321 - App01 - WebServer is st…

---

## [Different ILM alias based on fields like indeces](https://discuss.elastic.co/t/different-ilm-alias-based-on-fields-like-indeces/266919)

<div class="topic-metadata">

**Author:** [@abev](https://discuss.elastic.co/u/abev)\
**Replies:** 0\
**Last updated:** [March 11, 2021, 10:13am UTC](https://discuss.elastic.co/t/different-ilm-alias-based-on-fields-like-indeces/266919 "2021-03-11T10:13:42Z")

</div>

hey guys, I’m trying to send different logs to different ILM aliases I’ve found it here for indexes: https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#indices-option-es and here for ILM: h…

---

## [Drop kubernetes metadata](https://discuss.elastic.co/t/drop-kubernetes-metadata/266885)

<div class="topic-metadata">

**Author:** [@Nurlan199206](https://discuss.elastic.co/u/Nurlan199206)\
**Replies:** 0\
**Last updated:** [March 11, 2021, 5:52am UTC](https://discuss.elastic.co/t/drop-kubernetes-metadata/266885 "2021-03-11T05:52:42Z")

</div>

i'm trying drop some unneccesary fields, but i still see metadata i follow this docs: https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html "ecs": { "version": "1.1.0" }, "host": { …

---

## [Filebeat low throughput and slow log files read](https://discuss.elastic.co/t/filebeat-low-throughput-and-slow-log-files-read/266905)

<div class="topic-metadata">

**Author:** [@aksadvance](https://discuss.elastic.co/u/aksadvance)\
**Replies:** 0\
**Last updated:** [March 11, 2021, 8:31am UTC](https://discuss.elastic.co/t/filebeat-low-throughput-and-slow-log-files-read/266905 "2021-03-11T08:31:46Z")

</div>

Filebeat log transfer latency We have observed the high latency on Filebeat while publishing the logs to Logstash, this latency is more than 2 hours. We are using the below setup for log transfer. Filebeat (11 nodes) -\>…

---

## [Filebeat 7.10.1 and 7.11.0 not able to send the logs from windows servers to logstash and getting stuck at \[Api Webserver\] agent - Successfully started Logstash API endpoint {:port=\>9600}](https://discuss.elastic.co/t/filebeat-7-10-1-and-7-11-0-not-able-to-send-the-logs-from-windows-servers-to-logstash-and-getting-stuck-at-api-webserver-agent-successfully-started-logstash-api-endpoint-port-9600/266420)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 8\
**Last updated:** [March 11, 2021, 3:06am UTC](https://discuss.elastic.co/t/filebeat-7-10-1-and-7-11-0-not-able-to-send-the-logs-from-windows-servers-to-logstash-and-getting-stuck-at-api-webserver-agent-successfully-started-logstash-api-endpoint-port-9600/266420 "2021-03-11T03:06:26Z")

</div>

I installed filebeat v7.10.1 on a windows 2016 server. I am trying to send a log file from that server to logstash server and I am using the beats plugin to parse the data. When I am running the beats config file it get…

---

## [Grok... is it just me or is it really that difficult?](https://discuss.elastic.co/t/grok-is-it-just-me-or-is-it-really-that-difficult/266872)

<div class="topic-metadata">

**Author:** [@louis12356](https://discuss.elastic.co/u/louis12356)\
**Replies:** 0\
**Last updated:** [March 11, 2021, 12:15am UTC](https://discuss.elastic.co/t/grok-is-it-just-me-or-is-it-really-that-difficult/266872 "2021-03-11T00:15:50Z")

</div>

Hey, for some days now i try to figure out how to properly use grok to filter my logfiles. I use the classic? setup with filebeat as the input of logstash and elasticsearch and kibana for visualizing. So far i managed…

---

## [Metricbeat doesn't recognize the process](https://discuss.elastic.co/t/metricbeat-doesnt-recognize-the-process/263176)

<div class="topic-metadata">

**Author:** [@xyz2](https://discuss.elastic.co/u/xyz2)\
**Replies:** 8\
**Last updated:** [March 10, 2021, 9:51pm UTC](https://discuss.elastic.co/t/metricbeat-doesnt-recognize-the-process/263176 "2021-03-10T21:51:10Z")

</div>

HI, I have configured metricbeat to check the process status. I have noticed that it doesn't get the process info sometimes even if the process was running. It is possible that the process was not active some times bu…

---

## [Crowdstrike dashboard doesn't load on Kibana](https://discuss.elastic.co/t/crowdstrike-dashboard-doesnt-load-on-kibana/266840)

<div class="topic-metadata">

**Author:** [@uforoid](https://discuss.elastic.co/u/uforoid)\
**Replies:** 0\
**Last updated:** [March 10, 2021, 4:32pm UTC](https://discuss.elastic.co/t/crowdstrike-dashboard-doesnt-load-on-kibana/266840 "2021-03-10T16:32:36Z")

</div>

Hi everyone, I installed all the crowdstrike falcon SIEM, filebeat is able to retrieve all the data and upload them on elastic, I did "filebeat setup" to upload all the dashboards on kibana, but the crowdstrike dashboar…

---

## [ILM is not getting disabled in metricbeat with helm chart install](https://discuss.elastic.co/t/ilm-is-not-getting-disabled-in-metricbeat-with-helm-chart-install/266838)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 0\
**Last updated:** [March 10, 2021, 4:14pm UTC](https://discuss.elastic.co/t/ilm-is-not-getting-disabled-in-metricbeat-with-helm-chart-install/266838 "2021-03-10T16:14:08Z")

</div>

Hi I am trying. to disable ILM on metricbeat in k8s environment. I am installing metricbeat using helm chart and modified values.yml to disable the ILM. However, in the logs, I see that ILM is always enabled. Can yo…

---

## [Auditd log - creating a single event from log lines with same ID](https://discuss.elastic.co/t/auditd-log-creating-a-single-event-from-log-lines-with-same-id/266827)

<div class="topic-metadata">

**Author:** [@alanoe](https://discuss.elastic.co/u/alanoe)\
**Replies:** 0\
**Last updated:** [March 10, 2021, 3:09pm UTC](https://discuss.elastic.co/t/auditd-log-creating-a-single-event-from-log-lines-with-same-id/266827 "2021-03-10T15:09:00Z")

</div>

I was using auditbeat to track audit events. However, if it goes down for a long time, I lose events, as I mentioned in https://discuss.elastic.co/t/auditd-events-created-while-auditbeat-is-down/266369. Due to that, my t…

---

## [Filebeat: Error while retrieving FD information: error getting number of open FD: key not found](https://discuss.elastic.co/t/filebeat-error-while-retrieving-fd-information-error-getting-number-of-open-fd-key-not-found/266822)

<div class="topic-metadata">

**Author:** [@meissen](https://discuss.elastic.co/u/meissen)\
**Replies:** 0\
**Last updated:** [March 10, 2021, 2:37pm UTC](https://discuss.elastic.co/t/filebeat-error-while-retrieving-fd-information-error-getting-number-of-open-fd-key-not-found/266822 "2021-03-10T14:37:58Z")

</div>

Hello, after upgrading filebeat to version 7.9.0 I'm getting the following error : Filebeat: Error while retrieving FD information: error getting number of open FD: key not found the filebeat agent is started via the …

---

## [Has error making http request: Get "http://npipe/state": been fixed yet for Elastic Agent 7.10.2?](https://discuss.elastic.co/t/has-error-making-http-request-get-http-npipe-state-been-fixed-yet-for-elastic-agent-7-10-2/266722)

<div class="topic-metadata">

**Author:** [@dvo](https://discuss.elastic.co/u/dvo)\
**Replies:** 4\
**Last updated:** [March 10, 2021, 2:25pm UTC](https://discuss.elastic.co/t/has-error-making-http-request-get-http-npipe-state-been-fixed-yet-for-elastic-agent-7-10-2/266722 "2021-03-10T14:25:05Z")

</div>

I'm testing a single Windows agent, and Kibana is littered with these errors, and it looks bad to the potential customer. I've got to get it cleaned up. error making http request: Get "http://npipe/state": open \\default…

---

## [Filebeat-7.10.2-mongodb-log-pipeline: cannot write to a field alias \[cloud.availability\_zone\]](https://discuss.elastic.co/t/filebeat-7-10-2-mongodb-log-pipeline-cannot-write-to-a-field-alias-cloud-availability-zone/266783)

<div class="topic-metadata">

**Author:** [@ORich](https://discuss.elastic.co/u/ORich)\
**Replies:** 1\
**Last updated:** [March 10, 2021, 10:00am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-mongodb-log-pipeline-cannot-write-to-a-field-alias-cloud-availability-zone/266783 "2021-03-10T10:00:08Z")

</div>

Dear experts, after migration from 6.8.13 to 7.10.2, MongoDB events logged are no more properly parsed by the factory mongodb ingest pipelines. To be honest, I have no idea about the root cause. Many thanks for your he…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=171)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=173)
