# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=174

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 175

---

## [Metricbeat v7 on FreeBSD system module / memory not working](https://discuss.elastic.co/t/metricbeat-v7-on-freebsd-system-module-memory-not-working/266390)

<div class="topic-metadata">

**Author:** [@michbsd](https://discuss.elastic.co/u/michbsd)\
**Replies:** 1\
**Last updated:** [March 5, 2021, 8:14pm UTC](https://discuss.elastic.co/t/metricbeat-v7-on-freebsd-system-module-memory-not-working/266390 "2021-03-05T20:14:50Z")

</div>

metricbeat version 7.10.1 (amd64), libbeat 7.10.1 \[v7.10.1 built 2021-02-02 03:16:09 +0000 UTC\] Hi, According to the reference (https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-system-memor…

---

## [Ship logs from filebeat to logstash via NGINX reverse proxy](https://discuss.elastic.co/t/ship-logs-from-filebeat-to-logstash-via-nginx-reverse-proxy/266395)

<div class="topic-metadata">

**Author:** [@ccooper](https://discuss.elastic.co/u/ccooper)\
**Replies:** 0\
**Last updated:** [March 5, 2021, 4:55pm UTC](https://discuss.elastic.co/t/ship-logs-from-filebeat-to-logstash-via-nginx-reverse-proxy/266395 "2021-03-05T16:55:16Z")

</div>

My architecture is as follows where only port 80 and 443 are open on the NGINX proxy server: \[filebeat\] -\> \[NGINX - reverse proxy\] -\> \[logstash\] I am attempting to ship logs from filebeat to logstash via an NGINX rever…

---

## [Filebeat logging - ERROR	\[logstash\]	logstash/async.go:280 Failed to publish events caused by: read tcp](https://discuss.elastic.co/t/filebeat-logging-error-logstash-logstash-async-go-280-failed-to-publish-events-caused-by-read-tcp/266330)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 2\
**Last updated:** [March 5, 2021, 4:27pm UTC](https://discuss.elastic.co/t/filebeat-logging-error-logstash-logstash-async-go-280-failed-to-publish-events-caused-by-read-tcp/266330 "2021-03-05T16:27:52Z")

</div>

I am trying to figure out if these timeouts are a bad thing or just notifications of no consequence. From a cmd I can telnet to 10.10.98.102:5044 and the port opens. There is a cert there that I can see with a cURL. T…

---

## [Configuration for Cisco ASA logs](https://discuss.elastic.co/t/configuration-for-cisco-asa-logs/266258)

<div class="topic-metadata">

**Author:** [@rudraram](https://discuss.elastic.co/u/rudraram)\
**Replies:** 3\
**Last updated:** [March 5, 2021, 4:14pm UTC](https://discuss.elastic.co/t/configuration-for-cisco-asa-logs/266258 "2021-03-05T16:14:56Z")

</div>

Hello Team, Can you provide some guidance on how to get Cisco ASA logs to ELK? Documentation here https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-cisco.html doesnt say where to install the filebeat…

---

## [Auditd events created while Auditbeat is down](https://discuss.elastic.co/t/auditd-events-created-while-auditbeat-is-down/266369)

<div class="topic-metadata">

**Author:** [@alanoe](https://discuss.elastic.co/u/alanoe)\
**Replies:** 0\
**Last updated:** [March 5, 2021, 12:47pm UTC](https://discuss.elastic.co/t/auditd-events-created-while-auditbeat-is-down/266369 "2021-03-05T12:47:55Z")

</div>

I'm designing a filesystem operations (file creation, file deletion, file open, permissions change, etc) and process executions tracking application using Auditbeat. This tracking app should not lose events in any case, …

---

## [Filebeat 7.3.1 - Exiting: setup.template.name and setup.template.pattern have to be set if index name is modified](https://discuss.elastic.co/t/filebeat-7-3-1-exiting-setup-template-name-and-setup-template-pattern-have-to-be-set-if-index-name-is-modified/266204)

<div class="topic-metadata">

**Author:** [@dcenaculo](https://discuss.elastic.co/u/dcenaculo)\
**Replies:** 2\
**Last updated:** [March 5, 2021, 9:52am UTC](https://discuss.elastic.co/t/filebeat-7-3-1-exiting-setup-template-name-and-setup-template-pattern-have-to-be-set-if-index-name-is-modified/266204 "2021-03-05T09:52:50Z")

</div>

Hi, I'm using Elastic Stack 7.3.1 and Filebeat 7.3.1. Now, when I try to start the filebeat, the following message appears: PS C:\\filebeat-7.3.1-windows-x86\_64\> .\\filebeat.exe Exiting: setup.template.name and setup.tem…

---

## [Filebeat 7.9.1 can't ship message to Logstash 7.9.1](https://discuss.elastic.co/t/filebeat-7-9-1-cant-ship-message-to-logstash-7-9-1/266338)

<div class="topic-metadata">

**Author:** [@grazia0912](https://discuss.elastic.co/u/grazia0912)\
**Replies:** 0\
**Last updated:** [March 5, 2021, 9:04am UTC](https://discuss.elastic.co/t/filebeat-7-9-1-cant-ship-message-to-logstash-7-9-1/266338 "2021-03-05T09:04:11Z")

</div>

Hi, i have installed Filebeat v7.9.1 on my Windows server and the logstash i am shipping the message is in 7.9.1 as well. However, when i ran the filebeat it seems to not get successful connection to the logstash. Previo…

---

## [Enquiry about sampling in elasticsearch](https://discuss.elastic.co/t/enquiry-about-sampling-in-elasticsearch/266092)

<div class="topic-metadata">

**Author:** [@iammanmale](https://discuss.elastic.co/u/iammanmale)\
**Replies:** 0\
**Last updated:** [March 3, 2021, 11:10am UTC](https://discuss.elastic.co/t/enquiry-about-sampling-in-elasticsearch/266092 "2021-03-03T11:10:49Z")

</div>

As we want to reduce the amount log indexing into ES nodes, i would like to know if filebeat or logstash has filters to do sampling? For example, can the filebeat push only 1 of every 5 lines from the log files to logsta…

---

## [Can't get filebeat 7.x syslogs into elasticsearch](https://discuss.elastic.co/t/cant-get-filebeat-7-x-syslogs-into-elasticsearch/265739)

<div class="topic-metadata">

**Author:** [@Aholzheimer](https://discuss.elastic.co/u/Aholzheimer)\
**Replies:** 3\
**Last updated:** [March 5, 2021, 6:00am UTC](https://discuss.elastic.co/t/cant-get-filebeat-7-x-syslogs-into-elasticsearch/265739 "2021-03-05T06:00:46Z")

</div>

Hi, I'm wondering if anyone else has had this problem. I am in the process up upgrading filebeat on our CentOS 7 servers. They are running filebeat version 6.8 and our ELK stack is 7.10.1. We are planning to upgrade t…

---

## [Rmdir syscall event and file path](https://discuss.elastic.co/t/rmdir-syscall-event-and-file-path/266015)

<div class="topic-metadata">

**Author:** [@alanoe](https://discuss.elastic.co/u/alanoe)\
**Replies:** 2\
**Last updated:** [March 5, 2021, 2:55am UTC](https://discuss.elastic.co/t/rmdir-syscall-event-and-file-path/266015 "2021-03-05T02:55:08Z")

</div>

I'm tracking the rmdir syscall with the following rule: audit\_rules: | -a always,exit -F dir=/sasdata -F arch=b64 -S creat -S open -S openat -S unlink -S unlinkat -S symlink -S symlinkat -S link -S linkat -S renam…

---

## [Reading zookeeper log files -](https://discuss.elastic.co/t/reading-zookeeper-log-files/266308)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 0\
**Last updated:** [March 5, 2021, 1:32am UTC](https://discuss.elastic.co/t/reading-zookeeper-log-files/266308 "2021-03-05T01:32:12Z")

</div>

I use puppet to maintain \*beat across the fleet. If there is a \*beat module in existence I just rename / replace it from the .disabled version. What I don't see to have is a module for zookeeper. It produces a single fi…

---

## [Metricbeat Jolokia module - same jolokia.agent.id for multiple agents](https://discuss.elastic.co/t/metricbeat-jolokia-module-same-jolokia-agent-id-for-multiple-agents/266291)

<div class="topic-metadata">

**Author:** [@igorid70](https://discuss.elastic.co/u/igorid70)\
**Replies:** 0\
**Last updated:** [March 4, 2021, 9:22pm UTC](https://discuss.elastic.co/t/metricbeat-jolokia-module-same-jolokia-agent-id-for-multiple-agents/266291 "2021-03-04T21:22:39Z")

</div>

Hi I use jolokia module with auto-discovery while the metrics are scrapped from multiple agents. The metrics are properly exported to Elasticsearch, however if I have a few agents from which I collect the same metrics a…

---

## [Sometimes filebeat stops collecting/flushing events](https://discuss.elastic.co/t/sometimes-filebeat-stops-collecting-flushing-events/266187)

<div class="topic-metadata">

**Author:** [@M0rdecay](https://discuss.elastic.co/u/M0rdecay)\
**Replies:** 2\
**Last updated:** [March 4, 2021, 10:17am UTC](https://discuss.elastic.co/t/sometimes-filebeat-stops-collecting-flushing-events/266187 "2021-03-04T10:17:34Z")

</div>

Hello! Please help me figure out the situation Sometimes Filebeat stops collecting/flushing events. On the graph, it looks like this: This does not look like a problem with one of the inputs, since events stop comin…

---

## [Compiling elastic-agent for linux/mips64](https://discuss.elastic.co/t/compiling-elastic-agent-for-linux-mips64/266157)

<div class="topic-metadata">

**Author:** [@kn1ght0w1](https://discuss.elastic.co/u/kn1ght0w1)\
**Replies:** 1\
**Last updated:** [March 4, 2021, 9:52am UTC](https://discuss.elastic.co/t/compiling-elastic-agent-for-linux-mips64/266157 "2021-03-04T09:52:23Z")

</div>

Hi All, I am trying to compile elastic-agent for linux/mips64 and I am getting a bit beyond myself. I cloned the GIT repo and ran the following to try and get it to compile: SNAPSHOT=true DEV=true PLATFORMS=linux/mips6…

---

## [Fit size of filebeat](https://discuss.elastic.co/t/fit-size-of-filebeat/266109)

<div class="topic-metadata">

**Author:** [@The\_Guaz](https://discuss.elastic.co/u/The_Guaz)\
**Replies:** 1\
**Last updated:** [March 4, 2021, 9:38am UTC](https://discuss.elastic.co/t/fit-size-of-filebeat/266109 "2021-03-04T09:38:18Z")

</div>

Hi, Generally filebeat mapping creating a lot of unused fields in my elasticsearch environment. I wonder, because size of the logs are excessivelly large (around 5-6 GB per day). Can I somehow delete unused mapping from…

---

## [Filebeat autodiscover kubernetes appenders error](https://discuss.elastic.co/t/filebeat-autodiscover-kubernetes-appenders-error/266108)

<div class="topic-metadata">

**Author:** [@QCU266](https://discuss.elastic.co/u/QCU266)\
**Replies:** 1\
**Last updated:** [March 4, 2021, 9:37am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-kubernetes-appenders-error/266108 "2021-03-04T09:37:19Z")

</div>

I want to use appenders like @icoolchn , so I test @icoolchn 's configuration, but the filebeat reports the following error(filebeat version 7.9.3): 2021-03-02T12:28:24.673Z INFO instance/beat.go:456 filebeat stopped. 2…

---

## [Filebeat: failed FilterLogEventsRequestRequestCanceled](https://discuss.elastic.co/t/filebeat-failed-filterlogeventsrequestrequestcanceled/266097)

<div class="topic-metadata">

**Author:** [@vishwas\_rajput](https://discuss.elastic.co/u/vishwas_rajput)\
**Replies:** 1\
**Last updated:** [March 4, 2021, 9:36am UTC](https://discuss.elastic.co/t/filebeat-failed-filterlogeventsrequestrequestcanceled/266097 "2021-03-04T09:36:42Z")

</div>

Hi, I am using Filebeat 7.11.1 to fetch CloudWatch logs using given configuration filebeat.inputs: - type: aws-cloudwatch log\_group\_arn: arn:aws:logs:XXX:XXX:\* log\_group\_name: /aws/ …

---

## [Contributing to Fleet with Community Integrations](https://discuss.elastic.co/t/contributing-to-fleet-with-community-integrations/265591)

<div class="topic-metadata">

**Author:** [@rwatts3](https://discuss.elastic.co/u/rwatts3)\
**Replies:** 2\
**Last updated:** [March 4, 2021, 12:42am UTC](https://discuss.elastic.co/t/contributing-to-fleet-with-community-integrations/265591 "2021-03-04T00:42:44Z")

</div>

Greetings, Are there plans or discussions to allow community built integrations, or the ability to load custom built integrations. The Elastic Agent feature is really nice and it would be great if we could build an Int…

---

## [Filebeat 7.6.2\_linux\_x86\_64 is not keeping up with the log entries added to .log files](https://discuss.elastic.co/t/filebeat-7-6-2-linux-x86-64-is-not-keeping-up-with-the-log-entries-added-to-log-files/266016)

<div class="topic-metadata">

**Author:** [@bjarvis](https://discuss.elastic.co/u/bjarvis)\
**Replies:** 2\
**Last updated:** [March 3, 2021, 7:23pm UTC](https://discuss.elastic.co/t/filebeat-7-6-2-linux-x86-64-is-not-keeping-up-with-the-log-entries-added-to-log-files/266016 "2021-03-03T19:23:56Z")

</div>

My filebeat instance does send logs, but nowhere enough volume to keep up with the number of log entries that are being added to my log files. The log files grow very quickly, like 2.7-ish Gigabytes per 24 hours. Kafka…

---

## [Filebeat /usr/local/bin/docker-entrypoint line 8: exec: filebeat: not found](https://discuss.elastic.co/t/filebeat-usr-local-bin-docker-entrypoint-line-8-exec-filebeat-not-found/265927)

<div class="topic-metadata">

**Author:** [@Waxman](https://discuss.elastic.co/u/Waxman)\
**Replies:** 7\
**Last updated:** [March 3, 2021, 6:59pm UTC](https://discuss.elastic.co/t/filebeat-usr-local-bin-docker-entrypoint-line-8-exec-filebeat-not-found/265927 "2021-03-03T18:59:41Z")

</div>

Hi There, I faced typical problem with filebeat. No matter which user (filebeat or root) I'm trying to launch filebeat 7.9.2 i'm getting: filebeat | /usr/local/bin/docker-entrypoint: line 8: exec: filebeat: not foun…

---

## [Error if FunctionBeat´s lambda name is changed](https://discuss.elastic.co/t/error-if-functionbeat-s-lambda-name-is-changed/265996)

<div class="topic-metadata">

**Author:** [@jpm](https://discuss.elastic.co/u/jpm)\
**Replies:** 2\
**Last updated:** [March 3, 2021, 1:39pm UTC](https://discuss.elastic.co/t/error-if-functionbeat-s-lambda-name-is-changed/265996 "2021-03-03T13:39:35Z")

</div>

I'm trying to deploy Functionbeat lambda in AWS with a custom name. If I deploy it with the default name, cloudwatch, it works successfully but if I change the default name to any other name, once deployed it doesn't wor…

---

## [Tag logs files from different directories](https://discuss.elastic.co/t/tag-logs-files-from-different-directories/266066)

<div class="topic-metadata">

**Author:** [@Warren\_Hansen](https://discuss.elastic.co/u/Warren_Hansen)\
**Replies:** 2\
**Last updated:** [March 3, 2021, 11:59am UTC](https://discuss.elastic.co/t/tag-logs-files-from-different-directories/266066 "2021-03-03T11:59:58Z")

</div>

Hi, I have the same kind of log file that uses the same grok patterns to match, however they are in different folders and I want to tag them accordingly. How would I go about it? Would something like this work: fi…

---

## [Filebeat json.message\_key tries to parse string as json](https://discuss.elastic.co/t/filebeat-json-message-key-tries-to-parse-string-as-json/265943)

<div class="topic-metadata">

**Author:** [@YG\_BE](https://discuss.elastic.co/u/YG_BE)\
**Replies:** 4\
**Last updated:** [March 3, 2021, 11:10am UTC](https://discuss.elastic.co/t/filebeat-json-message-key-tries-to-parse-string-as-json/265943 "2021-03-03T11:10:48Z")

</div>

Hello, When trying to send logs from my kubernetes cluster on AKS running Filebeat 7.5, I'm running into the following error messages: Error decoding JSON: invalid character 'N' looking for beginning of value E…

---

## [Filebeat HAProxy fields mapping not clear, what is the total active time for the HTTP request?](https://discuss.elastic.co/t/filebeat-haproxy-fields-mapping-not-clear-what-is-the-total-active-time-for-the-http-request/266088)

<div class="topic-metadata">

**Author:** [@bluepuma77](https://discuss.elastic.co/u/bluepuma77)\
**Replies:** 0\
**Last updated:** [March 3, 2021, 10:34am UTC](https://discuss.elastic.co/t/filebeat-haproxy-fields-mapping-not-clear-what-is-the-total-active-time-for-the-http-request/266088 "2021-03-03T10:34:56Z")

</div>

I am currently looking into the haproxy log files to find out how long requests take. Elastic Filebeat has a detailed page about HAProxy fields. haproxy.total\_waiting\_time\_ms Total time in milliseconds spent waiting i…

---

## [Metricbeat - error getting group status: open /proc/\<PID\>/cgroup](https://discuss.elastic.co/t/metricbeat-error-getting-group-status-open-proc-pid-cgroup/264355)

<div class="topic-metadata">

**Author:** [@anoopkv](https://discuss.elastic.co/u/anoopkv)\
**Replies:** 2\
**Last updated:** [March 3, 2021, 6:34am UTC](https://discuss.elastic.co/t/metricbeat-error-getting-group-status-open-proc-pid-cgroup/264355 "2021-03-03T06:34:21Z")

</div>

I have an ELK stack setup in a K8s cluster with security enabled. All components are working fine Installed metricbeat and kube-state-metrics using helm charts, and the containers are not starting, and i see the follow…

---

## [Heartbeat and Elastic Agent](https://discuss.elastic.co/t/heartbeat-and-elastic-agent/266001)

<div class="topic-metadata">

**Author:** [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Replies:** 2\
**Last updated:** [March 3, 2021, 12:20am UTC](https://discuss.elastic.co/t/heartbeat-and-elastic-agent/266001 "2021-03-03T00:20:33Z")

</div>

Hello, If I install Elastic Agent on a Windows 10 machine, and then I want to see the machine in Uptime, why do I need to ping it using Heartbeat? Should not the agent know already it's uptime? Will not this make sense …

---

## [Array\_index\_out\_of\_bounds\_exception during decode\_json\_fields for valid JSON](https://discuss.elastic.co/t/array-index-out-of-bounds-exception-during-decode-json-fields-for-valid-json/266019)

<div class="topic-metadata">

**Author:** [@pearj](https://discuss.elastic.co/u/pearj)\
**Replies:** 0\
**Last updated:** [March 2, 2021, 10:04pm UTC](https://discuss.elastic.co/t/array-index-out-of-bounds-exception-during-decode-json-fields-for-valid-json/266019 "2021-03-02T22:04:40Z")

</div>

I'm trying to use Functionbeat 7.11.1 to get EKS Kubernetes API server logs from Cloud Watch to Elasticsearch. Specifically, I was trying to convert the Kubernetes audit JSON events from a JSON string back into JSON usi…

---

## [Don't see the metrics I expect](https://discuss.elastic.co/t/dont-see-the-metrics-i-expect/265871)

<div class="topic-metadata">

**Author:** [@mcco0l](https://discuss.elastic.co/u/mcco0l)\
**Replies:** 5\
**Last updated:** [March 2, 2021, 2:52pm UTC](https://discuss.elastic.co/t/dont-see-the-metrics-i-expect/265871 "2021-03-02T14:52:15Z")

</div>

Hi there, I'm trying to get some Fargate metrics using Cloudwatch namespaces, but I don't see a way to get them to Kibana. modules.d/aws.yml - module: aws period: 5m access\_key\_id: 'xxxxxxxxxxxxx' …

---

## [Filebeat Error while parsing lastError field in Azure platform logs](https://discuss.elastic.co/t/filebeat-error-while-parsing-lasterror-field-in-azure-platform-logs/265940)

<div class="topic-metadata">

**Author:** [@jmmcorreia](https://discuss.elastic.co/u/jmmcorreia)\
**Replies:** 1\
**Last updated:** [March 2, 2021, 2:08pm UTC](https://discuss.elastic.co/t/filebeat-error-while-parsing-lasterror-field-in-azure-platform-logs/265940 "2021-03-02T14:08:45Z")

</div>

Hi everyone, I'm trying the filebeat beta feature to pull azure platform logs into ES and I'm hitting ing the following issue: When there is an error message on the APIM logs, the field lastError is being added to the …

---

## [Filebeat won't start](https://discuss.elastic.co/t/filebeat-wont-start/265889)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 11\
**Last updated:** [March 2, 2021, 11:31am UTC](https://discuss.elastic.co/t/filebeat-wont-start/265889 "2021-03-02T11:31:06Z")

</div>

I'm trying to link filebeat with logstash, but filebeat suddenly stopped working. When I try systemctl start filebeat, it does not start. If I run systemctl status filebeat, I get the following message. ● filebeat.ser…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=173)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=175)
