# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=175

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 176

---

## [Disk Metric in Observability \[Elastic Stack 7.11.1\]](https://discuss.elastic.co/t/disk-metric-in-observability-elastic-stack-7-11-1/265913)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 2\
**Last updated:** [March 2, 2021, 10:39am UTC](https://discuss.elastic.co/t/disk-metric-in-observability-elastic-stack-7-11-1/265913 "2021-03-02T10:39:44Z")

</div>

Hi, everyone I have been working with the new version of Elastic Stack (7.11.1) for several days. I would like to know if Elastic team will add Disk metricset in Observability in future versions. Here you are my metric…

---

## [Filebeat http endpoint CORS](https://discuss.elastic.co/t/filebeat-http-endpoint-cors/265712)

<div class="topic-metadata">

**Author:** [@snowfrogdev](https://discuss.elastic.co/u/snowfrogdev)\
**Replies:** 3\
**Last updated:** [March 2, 2021, 9:53am UTC](https://discuss.elastic.co/t/filebeat-http-endpoint-cors/265712 "2021-03-02T09:53:52Z")

</div>

Is there any way to setup CORS when using Filebeat http\_endpoint?

---

## [What happens when winlogbeat cant ship?](https://discuss.elastic.co/t/what-happens-when-winlogbeat-cant-ship/265828)

<div class="topic-metadata">

**Author:** [@jcor](https://discuss.elastic.co/u/jcor)\
**Replies:** 0\
**Last updated:** [March 1, 2021, 4:01pm UTC](https://discuss.elastic.co/t/what-happens-when-winlogbeat-cant-ship/265828 "2021-03-01T16:01:42Z")

</div>

Hey folks, I was curious about what happens when winlogbeat cant communicate with logstash or elastic from the client impact side of things. I haven't seen any impact or issues occur but was curious what events occur. F…

---

## [Audit beat warning](https://discuss.elastic.co/t/audit-beat-warning/265730)

<div class="topic-metadata">

**Author:** [@Paul\_Fleming](https://discuss.elastic.co/u/Paul_Fleming)\
**Replies:** 3\
**Last updated:** [March 1, 2021, 3:24pm UTC](https://discuss.elastic.co/t/audit-beat-warning/265730 "2021-03-01T15:24:01Z")

</div>

Hi Im seeing the following warning when I started auditbeat can someone please help me resolve the following issue thanks. ' feb 28 15:45:11 virtual-machine auditbeat\[4659\]: 2021-02-28T15:45:11.932Z WARN \[…

---

## [Filebeat not considering registry and resending data](https://discuss.elastic.co/t/filebeat-not-considering-registry-and-resending-data/265788)

<div class="topic-metadata">

**Author:** [@gasparuben](https://discuss.elastic.co/u/gasparuben)\
**Replies:** 1\
**Last updated:** [March 1, 2021, 12:00pm UTC](https://discuss.elastic.co/t/filebeat-not-considering-registry-and-resending-data/265788 "2021-03-01T12:00:19Z")

</div>

hi, I am running filebeat on a pod in kubernetes. Filebeat has its registry on an external volume, on a CEPHFS cluster, so I dont lose memory of files being sent after each reboot. Some how this is happening and it lo…

---

## [Metricbeat Kibana Dashboard Request Time-out when there is a Virtual IP in the VM being monitored](https://discuss.elastic.co/t/metricbeat-kibana-dashboard-request-time-out-when-there-is-a-virtual-ip-in-the-vm-being-monitored/265775)

<div class="topic-metadata">

**Author:** [@thesn](https://discuss.elastic.co/u/thesn)\
**Replies:** 0\
**Last updated:** [March 1, 2021, 10:19am UTC](https://discuss.elastic.co/t/metricbeat-kibana-dashboard-request-time-out-when-there-is-a-virtual-ip-in-the-vm-being-monitored/265775 "2021-03-01T10:19:27Z")

</div>

hi, I have ES 7.11.1 and Kibana 7.11.1 setup in docker container (10.6.226.80) using docker-compose in a Linux VM. Also, I have Metricbeat 7.11.1 setup in docker container (10.6.226.104) using docker-compose in a Linux…

---

## [Extract certain values from Url.Query field](https://discuss.elastic.co/t/extract-certain-values-from-url-query-field/265633)

<div class="topic-metadata">

**Author:** [@jamesm1](https://discuss.elastic.co/u/jamesm1)\
**Replies:** 1\
**Last updated:** [March 1, 2021, 9:49am UTC](https://discuss.elastic.co/t/extract-certain-values-from-url-query-field/265633 "2021-03-01T09:49:52Z")

</div>

I currently have a Fleet module set up to ingest IIS logs into Kibana. Within the logs they contain the filed URL.Query, which holds alot of information. What i would like to do is to turn all of the parameters inside …

---

## [Secured beats in a docker container](https://discuss.elastic.co/t/secured-beats-in-a-docker-container/265682)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [February 27, 2021, 7:21am UTC](https://discuss.elastic.co/t/secured-beats-in-a-docker-container/265682 "2021-02-27T07:21:19Z")

</div>

Hi there, how is the approach to create a secured metricbeat docker container to send data to a secured elastick stack? Background: I have a secured stack, with self signed certificate authority in place. Now I would…

---

## [Extracting some fields from an array item and renaming them with Auditbeat's processors](https://discuss.elastic.co/t/extracting-some-fields-from-an-array-item-and-renaming-them-with-auditbeats-processors/265408)

<div class="topic-metadata">

**Author:** [@alanoe](https://discuss.elastic.co/u/alanoe)\
**Replies:** 3\
**Last updated:** [February 27, 2021, 12:12am UTC](https://discuss.elastic.co/t/extracting-some-fields-from-an-array-item-and-renaming-them-with-auditbeats-processors/265408 "2021-02-27T00:12:54Z")

</div>

I'm trying to use Auditbeat to create a filesystem tracker. When I touch a file in the directory watched by my audit rules, I get the following event from Auditbeat saved to Elasticsearch: { "\_index":"auditbea…

---

## [AIX support](https://discuss.elastic.co/t/aix-support/265666)

<div class="topic-metadata">

**Author:** [@Ismael](https://discuss.elastic.co/u/Ismael)\
**Replies:** 1\
**Last updated:** [February 26, 2021, 8:58pm UTC](https://discuss.elastic.co/t/aix-support/265666 "2021-02-26T20:58:20Z")

</div>

Hello, I'm watching in the Elastic Support Matrix that AIX is not supported by any beat or logstash version. I want to know if you have plans to have this function or if there are other ways to install beats in this S.O…

---

## [AWS S3 based logs integration error using filebeat](https://discuss.elastic.co/t/aws-s3-based-logs-integration-error-using-filebeat/265642)

<div class="topic-metadata">

**Author:** [@dinesh.jiyani](https://discuss.elastic.co/u/dinesh.jiyani)\
**Replies:** 0\
**Last updated:** [February 26, 2021, 5:21pm UTC](https://discuss.elastic.co/t/aws-s3-based-logs-integration-error-using-filebeat/265642 "2021-02-26T17:21:50Z")

</div>

Hi We try to fetch AWS s3 base logs using filebeat but we are getting below error. Elasticsearch version : elasticsearch 7.11.1 Kibana version: kibana 7.11.1 Filebeat version: filebeat-7.11.1 aws.yml module config…

---

## [Filebeat daemon set misses last few lines of log on pod crash](https://discuss.elastic.co/t/filebeat-daemon-set-misses-last-few-lines-of-log-on-pod-crash/265621)

<div class="topic-metadata">

**Author:** [@val](https://discuss.elastic.co/u/val)\
**Replies:** 0\
**Last updated:** [February 26, 2021, 3:03pm UTC](https://discuss.elastic.co/t/filebeat-daemon-set-misses-last-few-lines-of-log-on-pod-crash/265621 "2021-02-26T15:03:49Z")

</div>

I’ve encountered an interesting situation with Filebeat deployed as a daemon set in Openshift (very similar to https://discuss.elastic.co/t/filebeat-missing-end-of-logs-for-k8s-pods/217281). So, we have one dedicated po…

---

## [Unable to Drop desired fields using drop\_fields processors in filebeat](https://discuss.elastic.co/t/unable-to-drop-desired-fields-using-drop-fields-processors-in-filebeat/264654)

<div class="topic-metadata">

**Author:** [@mauryaravi](https://discuss.elastic.co/u/mauryaravi)\
**Replies:** 2\
**Last updated:** [February 26, 2021, 12:15pm UTC](https://discuss.elastic.co/t/unable-to-drop-desired-fields-using-drop-fields-processors-in-filebeat/264654 "2021-02-26T12:15:17Z")

</div>

I am sending log data to elastic search directly using filebeat 7.10. I want to drop some fields of doc using drop\_fields processors before sending to ES. Filebeat is dropping some fields placed in drop\_fields conf but …

---

## [Custome Index name but getting "0" fields](https://discuss.elastic.co/t/custome-index-name-but-getting-0-fields/265474)

<div class="topic-metadata">

**Author:** [@shaiksubhan](https://discuss.elastic.co/u/shaiksubhan)\
**Replies:** 3\
**Last updated:** [February 26, 2021, 12:06pm UTC](https://discuss.elastic.co/t/custome-index-name-but-getting-0-fields/265474 "2021-02-26T12:06:46Z")

</div>

Hi, I am trying to create custom Index pattern Name and its coming but I am unable to see any fields in that pattern. Any one help me on this ? Below is my yml file ###################### Metricbeat Configuration Exa…

---

## [Cannot drop fields from checkpoint filebeat module](https://discuss.elastic.co/t/cannot-drop-fields-from-checkpoint-filebeat-module/265604)

<div class="topic-metadata">

**Author:** [@lachezar.uzunov](https://discuss.elastic.co/u/lachezar.uzunov)\
**Replies:** 0\
**Last updated:** [February 26, 2021, 11:31am UTC](https://discuss.elastic.co/t/cannot-drop-fields-from-checkpoint-filebeat-module/265604 "2021-02-26T11:31:29Z")

</div>

Hello everyone, I am using filebeat checkpoint module and want to reduce the log size of the logs, cutting fields like destination.geo.city.name. My /etc/filebeat/filebeat.yml contains: - drop\_fields: wh…

---

## [Problem with parsing 'message' field in Winlogbeat](https://discuss.elastic.co/t/problem-with-parsing-message-field-in-winlogbeat/265572)

<div class="topic-metadata">

**Author:** [@ThreatInter](https://discuss.elastic.co/u/ThreatInter)\
**Replies:** 0\
**Last updated:** [February 26, 2021, 7:00am UTC](https://discuss.elastic.co/t/problem-with-parsing-message-field-in-winlogbeat/265572 "2021-02-26T07:00:44Z")

</div>

Hello all! We are using Winlogbeat to collect data from Windows hosts. But we can't understand why 'message' field can't be parsed by Winlogbeat. Can anyone explain why this field doesn't parsed and maybe give answer how…

---

## [Auditbeat File Integrity (Windows OS) Doesn't Capture WHO Changed Files?](https://discuss.elastic.co/t/auditbeat-file-integrity-windows-os-doesnt-capture-who-changed-files/265518)

<div class="topic-metadata">

**Author:** [@efaile](https://discuss.elastic.co/u/efaile)\
**Replies:** 3\
**Last updated:** [February 26, 2021, 4:30am UTC](https://discuss.elastic.co/t/auditbeat-file-integrity-windows-os-doesnt-capture-who-changed-files/265518 "2021-02-26T04:30:50Z")

</div>

We need a File Integrity Monitoring solution for Windows OS's - on the server we use as file servers . To further explain "file servers" - not to monitor remotely across shares which is not supported - but directly on th…

---

## [Filebeat dynamic indices name](https://discuss.elastic.co/t/filebeat-dynamic-indices-name/265363)

<div class="topic-metadata">

**Author:** [@Alex\_Doe](https://discuss.elastic.co/u/Alex_Doe)\
**Replies:** 1\
**Last updated:** [February 25, 2021, 7:30pm UTC](https://discuss.elastic.co/t/filebeat-dynamic-indices-name/265363 "2021-02-25T19:30:08Z")

</div>

Good day. I would like to configure dynamic naming for indices. My filebeat instance is writing data to logastash which is writing to elasticsearch. My configuration is looking like that: output.logstash: hosts: - el…

---

## [Beats modules grok](https://discuss.elastic.co/t/beats-modules-grok/265508)

<div class="topic-metadata">

**Author:** [@Romano](https://discuss.elastic.co/u/Romano)\
**Replies:** 0\
**Last updated:** [February 25, 2021, 3:57pm UTC](https://discuss.elastic.co/t/beats-modules-grok/265508 "2021-02-25T15:57:40Z")

</div>

Hi. In my environment I have various hardware firewalls such as Cisco, and other vendors. And I also have Linux servers, so I log events from Apache, OS and auditd. I log all events to central syslog server, from there I…

---

## [Metricbeat zookeeper module connecting to zookeeper using ssl connection](https://discuss.elastic.co/t/metricbeat-zookeeper-module-connecting-to-zookeeper-using-ssl-connection/262973)

<div class="topic-metadata">

**Author:** [@atamarnath](https://discuss.elastic.co/u/atamarnath)\
**Replies:** 2\
**Last updated:** [February 25, 2021, 2:24pm UTC](https://discuss.elastic.co/t/metricbeat-zookeeper-module-connecting-to-zookeeper-using-ssl-connection/262973 "2021-02-25T14:24:21Z")

</div>

Hi, I am trying to connect to metricbeat zookeeper module to zookeeper through ssl connection. Though I am able to connect in non ssl mode I am unable to connect through ssl. I get the below errors srvr command failed…

---

## [Preserve @timestamp Field for Custom Filebeat JSON logs](https://discuss.elastic.co/t/preserve-timestamp-field-for-custom-filebeat-json-logs/264495)

<div class="topic-metadata">

**Author:** [@Tim\_Estes](https://discuss.elastic.co/u/Tim_Estes)\
**Replies:** 1\
**Last updated:** [February 25, 2021, 9:54am UTC](https://discuss.elastic.co/t/preserve-timestamp-field-for-custom-filebeat-json-logs/264495 "2021-02-25T09:54:39Z")

</div>

I've deployed agents across two machines that are ingesting custom log data stored in json files. However, the @timestamp field present in the log files are not getting preserved. For example, here's a json log generate…

---

## [Filebeat windows service not starting](https://discuss.elastic.co/t/filebeat-windows-service-not-starting/260428)

<div class="topic-metadata">

**Author:** [@vuong43807](https://discuss.elastic.co/u/vuong43807)\
**Replies:** 15\
**Last updated:** [February 25, 2021, 3:44am UTC](https://discuss.elastic.co/t/filebeat-windows-service-not-starting/260428 "2021-02-25T03:44:21Z")

</div>

Hi, I follow up to install Filebeat 7.10.1 on Win server 2016 as below link but could not starting the Filebeat service by powershell or services console. Appreciate to your kindly help. PS C:\\Program Files\\Filebe…

---

## [Migration from self monitored to metricbeat Elasticsearch 7.11](https://discuss.elastic.co/t/migration-from-self-monitored-to-metricbeat-elasticsearch-7-11/265240)

<div class="topic-metadata">

**Author:** [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Replies:** 0\
**Last updated:** [February 23, 2021, 5:57pm UTC](https://discuss.elastic.co/t/migration-from-self-monitored-to-metricbeat-elasticsearch-7-11/265240 "2021-02-23T17:57:20Z")

</div>

I am using Elasticsearch 7.11. I have tried to migrate from self-monitoring of the cluster to metric beats. I have metric beats setup, I can see logs coming through to indices. I have switched the node to the setup mode…

---

## [Metricbeat docker module appears to be leaking file descriptor when metricset cpu, diskio, memory, or network is enabled](https://discuss.elastic.co/t/metricbeat-docker-module-appears-to-be-leaking-file-descriptor-when-metricset-cpu-diskio-memory-or-network-is-enabled/264772)

<div class="topic-metadata">

**Author:** [@jmcclure](https://discuss.elastic.co/u/jmcclure)\
**Replies:** 9\
**Last updated:** [February 24, 2021, 10:57pm UTC](https://discuss.elastic.co/t/metricbeat-docker-module-appears-to-be-leaking-file-descriptor-when-metricset-cpu-diskio-memory-or-network-is-enabled/264772 "2021-02-24T22:57:13Z")

</div>

Environment Metricbeat oss: 7.10.2 Elasticsearch oss: 7.10.2 Docker Engine: 18.09.0 Docker API: 1.39 (minimum version 1.12) OS: CentOS 7.6.1810 Hi, My deployment is on Linux with Docker, where Elasticsearch runs as a…

---

## [MetricBeat Failing on ElasticSearch AWS Instance - Unauthorized - Authentication required](https://discuss.elastic.co/t/metricbeat-failing-on-elasticsearch-aws-instance-unauthorized-authentication-required/265306)

<div class="topic-metadata">

**Author:** [@gr33nberet](https://discuss.elastic.co/u/gr33nberet)\
**Replies:** 0\
**Last updated:** [February 24, 2021, 9:35am UTC](https://discuss.elastic.co/t/metricbeat-failing-on-elasticsearch-aws-instance-unauthorized-authentication-required/265306 "2021-02-24T09:35:24Z")

</div>

Hello everyone, I'm having issues setting up MetricBeat on AWS ES Instance, I'm getting the following error : ERROR instance/beat.go:971 Exiting: 1 error: error loading index pattern: returned 401 to import file: \<nil\>.…

---

## [Elastic Agent attempting to push data to the wrong URL](https://discuss.elastic.co/t/elastic-agent-attempting-to-push-data-to-the-wrong-url/264184)

<div class="topic-metadata">

**Author:** [@coreysabia](https://discuss.elastic.co/u/coreysabia)\
**Replies:** 8\
**Last updated:** [February 24, 2021, 9:06pm UTC](https://discuss.elastic.co/t/elastic-agent-attempting-to-push-data-to-the-wrong-url/264184 "2021-02-24T21:06:09Z")

</div>

I have spun up an Elastic Cloud on Kubernetes cluster with Let's Encrypt SSL certificates with a domain name I own. All of these SSL certs are running properly, as well as my cluster. I have tested this locally and publi…

---

## [Remote Elasticsearch Cluster monitoring through Metricbeat not disabling metricset](https://discuss.elastic.co/t/remote-elasticsearch-cluster-monitoring-through-metricbeat-not-disabling-metricset/264964)

<div class="topic-metadata">

**Author:** [@silversonic](https://discuss.elastic.co/u/silversonic)\
**Replies:** 0\
**Last updated:** [February 20, 2021, 11:31pm UTC](https://discuss.elastic.co/t/remote-elasticsearch-cluster-monitoring-through-metricbeat-not-disabling-metricset/264964 "2021-02-20T23:31:11Z")

</div>

Hello, Scratching my head on this one. I'm setting up remote elasticsearch monitoring for a production cluster and sending metrics to a second elasticsearch cluster to handle observing the production cluster. Everythi…

---

## [Filebeat Helm deployment reports use of deprected k8s api](https://discuss.elastic.co/t/filebeat-helm-deployment-reports-use-of-deprected-k8s-api/262671)

<div class="topic-metadata">

**Author:** [@Rodrigo\_LN](https://discuss.elastic.co/u/Rodrigo_LN)\
**Replies:** 1\
**Last updated:** [February 24, 2021, 3:12pm UTC](https://discuss.elastic.co/t/filebeat-helm-deployment-reports-use-of-deprected-k8s-api/262671 "2021-02-24T15:12:56Z")

</div>

Helm based deployment of Filebeat, and ES produce the following warnings: W0128 13:25:59.736302 3118 warnings.go:70\] rbac.authorization.k8s.io/v1beta1 ClusterRole is deprecated in v1.17+, unavailable in v1.22+; use r…

---

## [How to specify names of different files in metricbeat.config.modules.path config option in metricbeat](https://discuss.elastic.co/t/how-to-specify-names-of-different-files-in-metricbeat-config-modules-path-config-option-in-metricbeat/265224)

<div class="topic-metadata">

**Author:** [@Usman18](https://discuss.elastic.co/u/Usman18)\
**Replies:** 2\
**Last updated:** [February 24, 2021, 9:48am UTC](https://discuss.elastic.co/t/how-to-specify-names-of-different-files-in-metricbeat-config-modules-path-config-option-in-metricbeat/265224 "2021-02-24T09:48:13Z")

</div>

I want to specify different names of files separately in metricbeat.config.modules.path configuration. Actually, I have some yml files in a folders for each module but I want to reload only yml files of few modules. How …

---

## [Zstd support](https://discuss.elastic.co/t/zstd-support/264947)

<div class="topic-metadata">

**Author:** [@Andrii](https://discuss.elastic.co/u/Andrii)\
**Replies:** 1\
**Last updated:** [February 24, 2021, 5:11am UTC](https://discuss.elastic.co/t/zstd-support/264947 "2021-02-24T05:11:36Z")

</div>

Hello, Are there any plans to support zstd compression for kafka output? zstd support was fixed in sarama 1.26.0

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=174)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=176)
