# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=173

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 174

---

## [Metricbeat 7.10.2 on Win 10: First 10 minutes not logging](https://discuss.elastic.co/t/metricbeat-7-10-2-on-win-10-first-10-minutes-not-logging/266662)

<div class="topic-metadata">

**Author:** [@Jaroslav](https://discuss.elastic.co/u/Jaroslav)\
**Replies:** 2\
**Last updated:** [March 10, 2021, 7:45am UTC](https://discuss.elastic.co/t/metricbeat-7-10-2-on-win-10-first-10-minutes-not-logging/266662 "2021-03-10T07:45:54Z")

</div>

Hello guys, I am running Metricbeat on Windows and observed that first 10 minutes of system events after service restart is not logged anywhere. Is it bug or a feature? Even when I switch to queue.disk, the first data i…

---

## [Stop exporting logs after file reaches a certain size](https://discuss.elastic.co/t/stop-exporting-logs-after-file-reaches-a-certain-size/266652)

<div class="topic-metadata">

**Author:** [@agushchin](https://discuss.elastic.co/u/agushchin)\
**Replies:** 1\
**Last updated:** [March 9, 2021, 7:49pm UTC](https://discuss.elastic.co/t/stop-exporting-logs-after-file-reaches-a-certain-size/266652 "2021-03-09T19:49:03Z")

</div>

Hi, I have the following question/problem: is there a way to stop exporting/propagating logs (either by filebeat or logstash) after the log file reaches a certain size limit? Asking because recently faced an issue caused…

---

## [Filebeat and IIS W3C dynamic headers support](https://discuss.elastic.co/t/filebeat-and-iis-w3c-dynamic-headers-support/265519)

<div class="topic-metadata">

**Author:** [@BkQc](https://discuss.elastic.co/u/BkQc)\
**Replies:** 1\
**Last updated:** [March 9, 2021, 7:25pm UTC](https://discuss.elastic.co/t/filebeat-and-iis-w3c-dynamic-headers-support/265519 "2021-03-09T19:25:45Z")

</div>

Is there any existing module that is enable to automatically account for fields definition in the W3C logs? If not, would it be possible to consider developping one? I know there already is an IIS module but it is based …

---

## [Metrics: There is no data to display (error while fetching resource)](https://discuss.elastic.co/t/metrics-there-is-no-data-to-display-error-while-fetching-resource/266714)

<div class="topic-metadata">

**Author:** [@feva](https://discuss.elastic.co/u/feva)\
**Replies:** 0\
**Last updated:** [March 9, 2021, 3:27pm UTC](https://discuss.elastic.co/t/metrics-there-is-no-data-to-display-error-while-fetching-resource/266714 "2021-03-09T15:27:16Z")

</div>

Hello, I have som troubles with metricbeat and Metrics App in Kibana. I am using metricbeat 7.10 and Kibana 7.10 on a Windows Server 2019. Every now and then I get an error message when I open Metrics App in Kibana: Er…

---

## [Filebeat to index with different structures](https://discuss.elastic.co/t/filebeat-to-index-with-different-structures/266565)

<div class="topic-metadata">

**Author:** [@Edi1](https://discuss.elastic.co/u/Edi1)\
**Replies:** 6\
**Last updated:** [March 9, 2021, 2:00pm UTC](https://discuss.elastic.co/t/filebeat-to-index-with-different-structures/266565 "2021-03-09T14:00:01Z")

</div>

Hello, newby here, My task is to take multiple (8) logs with different formats and using filebeat send them directly to elastic. They should all end inside the same index and each log should be searchable using "level" …

---

## [Barracuda WAF Log Parsing](https://discuss.elastic.co/t/barracuda-waf-log-parsing/266665)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 0\
**Last updated:** [March 9, 2021, 9:38am UTC](https://discuss.elastic.co/t/barracuda-waf-log-parsing/266665 "2021-03-09T09:38:29Z")

</div>

Hi I would appreciate some guidance on debugging the Barracuda WAF Filebeat module. I am running this with Filebeat rather than fleet at the moment as fleet is still in Beta and when I try running it in Fleet I get zer…

---

## [MultiLine read with File Beat](https://discuss.elastic.co/t/multiline-read-with-file-beat/266642)

<div class="topic-metadata">

**Author:** [@ankitji](https://discuss.elastic.co/u/ankitji)\
**Replies:** 0\
**Last updated:** [March 9, 2021, 6:59am UTC](https://discuss.elastic.co/t/multiline-read-with-file-beat/266642 "2021-03-09T06:59:15Z")

</div>

Hi, I am using filebeat on my hdfs root directories which having lots of log file inside that, for this we also using multiline parser of filebeat. So i just want to confirm on some below queries: Since we are readin…

---

## [Filebeat AWS Module SQS Queue Configurations Errors](https://discuss.elastic.co/t/filebeat-aws-module-sqs-queue-configurations-errors/266593)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 1\
**Last updated:** [March 9, 2021, 5:37am UTC](https://discuss.elastic.co/t/filebeat-aws-module-sqs-queue-configurations-errors/266593 "2021-03-09T05:37:04Z")

</div>

I am configuring filebeat AWS module to fetch Cloudtrail logs from an s3 bucket. I configured my settings from this article. However, somehow filebeat is unable to find SQS queue's region. here is my filebeat.yml input …

---

## [Metricbeat autodiscover configuration to create a new index when a new namespace is created](https://discuss.elastic.co/t/metricbeat-autodiscover-configuration-to-create-a-new-index-when-a-new-namespace-is-created/266616)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 0\
**Last updated:** [March 8, 2021, 10:54pm UTC](https://discuss.elastic.co/t/metricbeat-autodiscover-configuration-to-create-a-new-index-when-a-new-namespace-is-created/266616 "2021-03-08T22:54:39Z")

</div>

Hi I want to crate a new elasticsearch index whenenver a new kubernetes namespace is created. How do I specify this in metricbeat configuration ? For every new namespace created, I need to add some config and also cre…

---

## [AWS elb and vpcflow log filebeat visualizations fail to load properly](https://discuss.elastic.co/t/aws-elb-and-vpcflow-log-filebeat-visualizations-fail-to-load-properly/266608)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 0\
**Last updated:** [March 8, 2021, 9:44pm UTC](https://discuss.elastic.co/t/aws-elb-and-vpcflow-log-filebeat-visualizations-fail-to-load-properly/266608 "2021-03-08T21:44:31Z")

</div>

I am trying to develop more visibility around aws. I'd really like to use the prebuilt dashboards that come with filebeat, but I seem to constantly run into issues with the visualizations for elb and vpcflow logs. My con…

---

## [Monitore mikrotik router logs with ELK](https://discuss.elastic.co/t/monitore-mikrotik-router-logs-with-elk/266026)

<div class="topic-metadata">

**Author:** [@NZHP](https://discuss.elastic.co/u/NZHP)\
**Replies:** 2\
**Last updated:** [March 8, 2021, 7:48pm UTC](https://discuss.elastic.co/t/monitore-mikrotik-router-logs-with-elk/266026 "2021-03-08T19:48:37Z")

</div>

Hi everybody, I installed ELK on my infrastructure, now i want to monitor logs data of my routers and switch with elk stack. So how can process it please ? Thank advance

---

## [A way to index Azure's Secure Scores](https://discuss.elastic.co/t/a-way-to-index-azures-secure-scores/263042)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [March 8, 2021, 7:07pm UTC](https://discuss.elastic.co/t/a-way-to-index-azures-secure-scores/263042 "2021-03-08T19:07:39Z")

</div>

Hello, I was wondering if there is already a way to index Azure's Secure Score metrics into Elasticsearch. A bit like: Grtz Willem

---

## [OSS filebeat error "No such input type exist 'httpjson'"](https://discuss.elastic.co/t/oss-filebeat-error-no-such-input-type-exist-httpjson/266578)

<div class="topic-metadata">

**Author:** [@estebanes22](https://discuss.elastic.co/u/estebanes22)\
**Replies:** 3\
**Last updated:** [March 8, 2021, 4:46pm UTC](https://discuss.elastic.co/t/oss-filebeat-error-no-such-input-type-exist-httpjson/266578 "2021-03-08T16:46:55Z")

</div>

I switched from the elastic licensed filebeat to OSS version and am getting this new error when trying to use httpjson input: Not doing anything special here; was working fine with elastic licensed version.

---

## [Geoip for using maps](https://discuss.elastic.co/t/geoip-for-using-maps/266592)

<div class="topic-metadata">

**Author:** [@David\_Mohamad](https://discuss.elastic.co/u/David_Mohamad)\
**Replies:** 0\
**Last updated:** [March 8, 2021, 5:40pm UTC](https://discuss.elastic.co/t/geoip-for-using-maps/266592 "2021-03-08T17:40:32Z")

</div>

Hi everyone, I'm trying to use geoip to show data on a map. The problem is that the wrong index is showing up. I tried adding a new index template with no luck. This is what I get when I check the json code: "src": { …

---

## [Wrong output](https://discuss.elastic.co/t/wrong-output/266446)

<div class="topic-metadata">

**Author:** [@David\_Mohamad](https://discuss.elastic.co/u/David_Mohamad)\
**Replies:** 2\
**Last updated:** [March 8, 2021, 5:02pm UTC](https://discuss.elastic.co/t/wrong-output/266446 "2021-03-08T17:02:41Z")

</div>

Hi everyone, I recently started using the elastic stack for the first time and I cant seem to find a way to get the desired output. I'm trying to use this data: admintool\[899\] browser=Mozilla%2F5.0 %28Windows NT 10.0…

---

## [What is the difference a between "system.memory.used.bytes" and "vsphere.virtualmachine.memory.used.guest.bytes"?](https://discuss.elastic.co/t/what-is-the-difference-a-between-system-memory-used-bytes-and-vsphere-virtualmachine-memory-used-guest-bytes/266591)

<div class="topic-metadata">

**Author:** [@Ishaan](https://discuss.elastic.co/u/Ishaan)\
**Replies:** 0\
**Last updated:** [March 8, 2021, 4:48pm UTC](https://discuss.elastic.co/t/what-is-the-difference-a-between-system-memory-used-bytes-and-vsphere-virtualmachine-memory-used-guest-bytes/266591 "2021-03-08T16:48:36Z")

</div>

Hello, I have installed metricbeat agent on one of my linux virtual machines, and I'm also collecting metrics using vSphere module from vCenter. So the above virtual machine where the metricbeat agent is installed is a…

---

## [Filebeat i/o timeout error](https://discuss.elastic.co/t/filebeat-i-o-timeout-error/266581)

<div class="topic-metadata">

**Author:** [@iammanmale](https://discuss.elastic.co/u/iammanmale)\
**Replies:** 0\
**Last updated:** [March 8, 2021, 3:36pm UTC](https://discuss.elastic.co/t/filebeat-i-o-timeout-error/266581 "2021-03-08T15:36:46Z")

</div>

We are using filebeat on aws windows machines to push their log to local logstash and then local ES. Recently, some error occurs when I enter the command to test the output status on those AWS machines. The command is…

---

## [CSV file of System Metrics](https://discuss.elastic.co/t/csv-file-of-system-metrics/266573)

<div class="topic-metadata">

**Author:** [@efweber](https://discuss.elastic.co/u/efweber)\
**Replies:** 0\
**Last updated:** [March 8, 2021, 3:06pm UTC](https://discuss.elastic.co/t/csv-file-of-system-metrics/266573 "2021-03-08T15:06:22Z")

</div>

I'm a new elasticsearch user. What I'd like to do is capture a csv file of system metrics. I want to use this data in parallel with captured application data to analyze and then optimize system configuration and make app…

---

## [Contains condition on multiple index - Filebeat](https://discuss.elastic.co/t/contains-condition-on-multiple-index-filebeat/266128)

<div class="topic-metadata">

**Author:** [@graimato](https://discuss.elastic.co/u/graimato)\
**Replies:** 2\
**Last updated:** [March 8, 2021, 12:59pm UTC](https://discuss.elastic.co/t/contains-condition-on-multiple-index-filebeat/266128 "2021-03-08T12:59:28Z")

</div>

Hello, I'm using filebeat to collect information from log but I need to slip them on different Indexes. To do this I'm using indices: - index: "filebeat-%{\[agent.version\]}-api-%{+yyyy.MM.dd}" when.contains: …

---

## [Nasty feedback loop for syslog, if filebeat index is unavailable](https://discuss.elastic.co/t/nasty-feedback-loop-for-syslog-if-filebeat-index-is-unavailable/266537)

<div class="topic-metadata">

**Author:** [@hbogert](https://discuss.elastic.co/u/hbogert)\
**Replies:** 0\
**Last updated:** [March 8, 2021, 10:39am UTC](https://discuss.elastic.co/t/nasty-feedback-loop-for-syslog-if-filebeat-index-is-unavailable/266537 "2021-03-08T10:39:27Z")

</div>

I've been hit hard by this. Multiple machines have filebeat installed with the syslog module. By some other cirumstances, the filebeat index was unavailable this causes filebeat to log to journalctl and thus indirectly …

---

## [Monitor mysql user querries activity](https://discuss.elastic.co/t/monitor-mysql-user-querries-activity/266526)

<div class="topic-metadata">

**Author:** [@Radhouane](https://discuss.elastic.co/u/Radhouane)\
**Replies:** 0\
**Last updated:** [March 8, 2021, 8:53am UTC](https://discuss.elastic.co/t/monitor-mysql-user-querries-activity/266526 "2021-03-08T08:53:51Z")

</div>

Hello, I am new to ELK stacking so I am trying to check all its capabilities. Actually, I am trying to monitor mysql database and see what information I can get using beats agents. One thing I can't find is user/login…

---

## [Metricbeat Error : instance/beat.go:971	Exiting: missing field accessing 'metricbeat.modules.0.hosts.0' (source:'metricbeat.yml'](https://discuss.elastic.co/t/metricbeat-error-instance-beat-go-971-exiting-missing-field-accessing-metricbeat-modules-0-hosts-0-source-metricbeat-yml/266520)

<div class="topic-metadata">

**Author:** [@vbharath2007](https://discuss.elastic.co/u/vbharath2007)\
**Replies:** 0\
**Last updated:** [March 8, 2021, 8:27am UTC](https://discuss.elastic.co/t/metricbeat-error-instance-beat-go-971-exiting-missing-field-accessing-metricbeat-modules-0-hosts-0-source-metricbeat-yml/266520 "2021-03-08T08:27:11Z")

</div>

Hi, I'm trying to deploy metric beat in our environment using helm charts 7.11.2, but the pods are crashing due to below error. Please help me to fix this issue... 2021-03-08T08:09:50.607Z INFO instance/beat.go:304 Se…

---

## [Metricbeat Error: data path already locked by another beat](https://discuss.elastic.co/t/metricbeat-error-data-path-already-locked-by-another-beat/266503)

<div class="topic-metadata">

**Author:** [@bob96589](https://discuss.elastic.co/u/bob96589)\
**Replies:** 0\
**Last updated:** [March 8, 2021, 3:52am UTC](https://discuss.elastic.co/t/metricbeat-error-data-path-already-locked-by-another-beat/266503 "2021-03-08T03:52:10Z")

</div>

Steps to reproduce (run the following command in terminal): docker run -d --name metricbeat docker.elastic.co/beats/metricbeat:7.11.1 docker exec -it metricbeat metricbeat -e Error: 2021-03-08T03:29:41.319Z …

---

## [Filebeat CheckPoint Module](https://discuss.elastic.co/t/filebeat-checkpoint-module/265922)

<div class="topic-metadata">

**Author:** [@Kaarthick](https://discuss.elastic.co/u/Kaarthick)\
**Replies:** 2\
**Last updated:** [March 8, 2021, 5:17am UTC](https://discuss.elastic.co/t/filebeat-checkpoint-module/265922 "2021-03-08T05:17:54Z")

</div>

Hi Team, I'm using filebeat 7.10.0 and am new to filebeat. I have enabled the checkpoint module for parsing the checkpoint logs of different event types. So in checkpoint.yml i have configured input as - module: ch…

---

## [Filebeat pods restarting with "fatal error: concurrent map read and map write"](https://discuss.elastic.co/t/filebeat-pods-restarting-with-fatal-error-concurrent-map-read-and-map-write/265961)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 5\
**Last updated:** [March 3, 2021, 11:44am UTC](https://discuss.elastic.co/t/filebeat-pods-restarting-with-fatal-error-concurrent-map-read-and-map-write/265961 "2021-03-03T11:44:26Z")

</div>

I have deployed Filebeat -\> Logstash -\> elasticseach -\> kibana in OKD-3.11 running on Openstack Centos-7.6 VMs. Using oss docker images for the deployment. docker.elastic.co/beats/filebeat-oss:7.9.3 docker.elastic.co/l…

---

## [Auditbeat wont start](https://discuss.elastic.co/t/auditbeat-wont-start/266491)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 0\
**Last updated:** [March 7, 2021, 10:00pm UTC](https://discuss.elastic.co/t/auditbeat-wont-start/266491 "2021-03-07T22:00:53Z")

</div>

I get 3 different errors msgs: unable to guess one or more required parameters: guess\_sockaddr\_in failed -or- unable to guess one or more required parameters: guess\_udp\_sendmsg failed -or- unable to guess one or mor…

---

## [Rapid7 InsightVM Nexpose integration missing in 7.11.0](https://discuss.elastic.co/t/rapid7-insightvm-nexpose-integration-missing-in-7-11-0/265238)

<div class="topic-metadata">

**Author:** [@florinsfetea](https://discuss.elastic.co/u/florinsfetea)\
**Replies:** 1\
**Last updated:** [March 7, 2021, 9:54pm UTC](https://discuss.elastic.co/t/rapid7-insightvm-nexpose-integration-missing-in-7-11-0/265238 "2021-03-07T21:54:22Z")

</div>

I had previously(7.9) configured a Fleet policy with Rapid7 Nexpose integration. Now after migrating to 7.11.0 my policy is there but the integration is failing. Also if I search for the integration itself I cannot…

---

## [Journalbeat has no dashboards?](https://discuss.elastic.co/t/journalbeat-has-no-dashboards/266426)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [March 6, 2021, 6:28pm UTC](https://discuss.elastic.co/t/journalbeat-has-no-dashboards/266426 "2021-03-06T18:28:36Z")

</div>

Hi there, can it be that journalbeats has no predifined dashboards on board? Doing this: /usr/share/journalbeat/bin# ./journalbeat setup -e -c /etc/journalbeat/journalbeat.yml --dashboards I do not get anything in Ki…

---

## [The filebeat and logstash connections will be refused](https://discuss.elastic.co/t/the-filebeat-and-logstash-connections-will-be-refused/266094)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 1\
**Last updated:** [March 5, 2021, 10:15pm UTC](https://discuss.elastic.co/t/the-filebeat-and-logstash-connections-will-be-refused/266094 "2021-03-05T22:15:50Z")

</div>

I want filebeat and logstash to communicate with each other to collect multiple log files. I have run the following test command for filebeat, but the connection is refused. What is the reason for this? filebeat -e -c…

---

## [Filebeat and logs with preallocated space](https://discuss.elastic.co/t/filebeat-and-logs-with-preallocated-space/266223)

<div class="topic-metadata">

**Author:** [@111449](https://discuss.elastic.co/u/111449)\
**Replies:** 2\
**Last updated:** [March 5, 2021, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-and-logs-with-preallocated-space/266223 "2021-03-05T21:06:39Z")

</div>

Hello! Legacy software I have to use works on Windows and writes a log in the following way: it writes a lot of \\u0000 (NULL) symbols into the end of file to preallocate space and then (when it needs to write a log str…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=172)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=174)
