# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=176

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 177

---

## [Is it possible to configure dynamic indices with ILM?](https://discuss.elastic.co/t/is-it-possible-to-configure-dynamic-indices-with-ilm/264497)

<div class="topic-metadata">

**Author:** [@sarahw](https://discuss.elastic.co/u/sarahw)\
**Replies:** 2\
**Last updated:** [February 24, 2021, 1:02am UTC](https://discuss.elastic.co/t/is-it-possible-to-configure-dynamic-indices-with-ilm/264497 "2021-02-24T01:02:21Z")

</div>

We currently use a single filebeat config with ILM disabled to ingest logs from an IIS web application and IIS access/error logs using the IIS module. We have been using filebeat to generate daily indices, but now we wou…

---

## [How to connect Winlogbeat to Elasticsearch dockrized Cluster using SSL?](https://discuss.elastic.co/t/how-to-connect-winlogbeat-to-elasticsearch-dockrized-cluster-using-ssl/265013)

<div class="topic-metadata">

**Author:** [@Cyber](https://discuss.elastic.co/u/Cyber)\
**Replies:** 1\
**Last updated:** [February 23, 2021, 10:51pm UTC](https://discuss.elastic.co/t/how-to-connect-winlogbeat-to-elasticsearch-dockrized-cluster-using-ssl/265013 "2021-02-23T22:51:38Z")

</div>

For the past week I am trying to connect a Winlogbeat(Which is on my host machine) To an elasticsearch Cluster that I set up on an Ubuntu VM using dockers. Following this tutorial. (In the tutorial they don't explain ho…

---

## [Filebeat errors on setup - Apache ingest pipelines failing to load](https://discuss.elastic.co/t/filebeat-errors-on-setup-apache-ingest-pipelines-failing-to-load/265134)

<div class="topic-metadata">

**Author:** [@QueenAmidala](https://discuss.elastic.co/u/QueenAmidala)\
**Replies:** 7\
**Last updated:** [February 23, 2021, 10:24pm UTC](https://discuss.elastic.co/t/filebeat-errors-on-setup-apache-ingest-pipelines-failing-to-load/265134 "2021-02-23T22:24:50Z")

</div>

So here is my problem it seems filbeats setup is failing for me. I get a bunch of empty error messages \*\*"Exiting: 1 error: Error setting up ML for apache\_ecs: 17 errors: ; ; ; ; ; ; ; ; ; ; error while".\*\* I'm thinkin…

---

## [Few questions about Elastic Agent 7.10.2](https://discuss.elastic.co/t/few-questions-about-elastic-agent-7-10-2/264641)

<div class="topic-metadata">

**Author:** [@dvo](https://discuss.elastic.co/u/dvo)\
**Replies:** 5\
**Last updated:** [February 23, 2021, 6:25pm UTC](https://discuss.elastic.co/t/few-questions-about-elastic-agent-7-10-2/264641 "2021-02-23T18:25:42Z")

</div>

The Windows agent installation is a little confusing. You download the zip and extract it to Program Files\\elastic-agent. When you run the command to install the agent service and get it talking with Fleet, a new but n…

---

## [Filebeat not starting log aggregation on some kubernetes worker nodes](https://discuss.elastic.co/t/filebeat-not-starting-log-aggregation-on-some-kubernetes-worker-nodes/265204)

<div class="topic-metadata">

**Author:** [@lbenton](https://discuss.elastic.co/u/lbenton)\
**Replies:** 0\
**Last updated:** [February 23, 2021, 1:26pm UTC](https://discuss.elastic.co/t/filebeat-not-starting-log-aggregation-on-some-kubernetes-worker-nodes/265204 "2021-02-23T13:26:55Z")

</div>

Hi All, I've run into an issue with filebeat in kubernetes, but only on some worker nodes. If useful, here's a bit of background -Deployed using helm, via terraform -currently 16 worker nodes, 7 of which filebeat ref…

---

## [Beginner Questions - Interaction Filebeat and Modules and General Q](https://discuss.elastic.co/t/beginner-questions-interaction-filebeat-and-modules-and-general-q/265173)

<div class="topic-metadata">

**Author:** [@maxxlight](https://discuss.elastic.co/u/maxxlight)\
**Replies:** 0\
**Last updated:** [February 23, 2021, 7:35am UTC](https://discuss.elastic.co/t/beginner-questions-interaction-filebeat-and-modules-and-general-q/265173 "2021-02-23T07:35:49Z")

</div>

Hey, im new to ELK Stack and installed a Linux Server with Filebeat, Logstash, Elastic and Kibana. I want to get the syslog and netflow Streams from Palo Alto FW / Cisco 2900 Series / WLAN and some more other Syslog D…

---

## [Filebeat kafka output hash.hash get negative partition cause stuck](https://discuss.elastic.co/t/filebeat-kafka-output-hash-hash-get-negative-partition-cause-stuck/265153)

<div class="topic-metadata">

**Author:** [@Vvv](https://discuss.elastic.co/u/Vvv)\
**Replies:** 0\
**Last updated:** [February 23, 2021, 5:27am UTC](https://discuss.elastic.co/t/filebeat-kafka-output-hash-hash-get-negative-partition-cause-stuck/265153 "2021-02-23T05:27:58Z")

</div>

Summarry I use filebeat to collect logs and output to kafka. Due to partition.hash.hash config hash message then mod to select partition, in some situation, this may cause filebeat stuck, e.g.: massage: 2304669687 hash…

---

## [Kafka output with SASL\_SSL authentication -- message to topic failed](https://discuss.elastic.co/t/kafka-output-with-sasl-ssl-authentication-message-to-topic-failed/265156)

<div class="topic-metadata">

**Author:** [@Abhijit\_Talukdar](https://discuss.elastic.co/u/Abhijit_Talukdar)\
**Replies:** 0\
**Last updated:** [February 23, 2021, 5:57am UTC](https://discuss.elastic.co/t/kafka-output-with-sasl-ssl-authentication-message-to-topic-failed/265156 "2021-02-23T05:57:06Z")

</div>

Connection established 2021-02-23T04:37:47.565Z INFO \[publisher\_pipeline\_output\] pipeline/output.go:143 Connecting to kafka(xxxxxxxxxxxxxxxxxxxxxxxxx:9093,yyyyyyyyyyyyyyyyyyyyyyyyy:9093,zzzzzzzzzzzzzzzzzz…

---

## [Non-zero metrics in the last 30s](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/264939)

<div class="topic-metadata">

**Author:** [@Marc2](https://discuss.elastic.co/u/Marc2)\
**Replies:** 3\
**Last updated:** [February 22, 2021, 10:29pm UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/264939 "2021-02-22T22:29:27Z")

</div>

Hi, I'm completely new to ELK and I need to create an index in ElasticSearch using Filebeat. When I execute Filebeat.exe it doesn't create the index and it says: 2021-02-20T09:23:57.477+0100 INFO \[monitoring\] log/log.g…

---

## [File beat version 6.8.13, not parsing ngnix logs from docker container using dissect processor](https://discuss.elastic.co/t/file-beat-version-6-8-13-not-parsing-ngnix-logs-from-docker-container-using-dissect-processor/265114)

<div class="topic-metadata">

**Author:** [@sainumpud](https://discuss.elastic.co/u/sainumpud)\
**Replies:** 0\
**Last updated:** [February 22, 2021, 7:11pm UTC](https://discuss.elastic.co/t/file-beat-version-6-8-13-not-parsing-ngnix-logs-from-docker-container-using-dissect-processor/265114 "2021-02-22T19:11:05Z")

</div>

Hi, File beat version 6.8.13 running on VM, I am trying to parse this ngnix container log into separate fields for reporting on unique clientIP address and browser details to show reports on Kibana. I added dissect pro…

---

## [Heartbeat HTTP Monitor - GET with JSON Body and Response](https://discuss.elastic.co/t/heartbeat-http-monitor-get-with-json-body-and-response/262168)

<div class="topic-metadata">

**Author:** [@bbek](https://discuss.elastic.co/u/bbek)\
**Replies:** 4\
**Last updated:** [February 22, 2021, 4:43pm UTC](https://discuss.elastic.co/t/heartbeat-http-monitor-get-with-json-body-and-response/262168 "2021-02-22T16:43:12Z")

</div>

Hello! I'm trying to get heartbeat to perform an HTTP GET , while combining a JSON body with the GET request to the page. My goal is to query an elastic index, take the fields and analyze for up/down accordingly. In t…

---

## [Kafka keeps syslog timestamp in the message](https://discuss.elastic.co/t/kafka-keeps-syslog-timestamp-in-the-message/264902)

<div class="topic-metadata">

**Author:** [@ywsong2](https://discuss.elastic.co/u/ywsong2)\
**Replies:** 1\
**Last updated:** [February 22, 2021, 4:04pm UTC](https://discuss.elastic.co/t/kafka-keeps-syslog-timestamp-in-the-message/264902 "2021-02-22T16:04:12Z")

</div>

Hi, I am having an issue with syslog timestamp when the Filebeat sends system module logs (/var/log/messages and /var/log/secure) through Kafka output. If I send logs straight to Elasticsearch, the default Filebeat's da…

---

## [Metricbeat configuration file from package repository is always detected as changed and stops auto upgrade process](https://discuss.elastic.co/t/metricbeat-configuration-file-from-package-repository-is-always-detected-as-changed-and-stops-auto-upgrade-process/265077)

<div class="topic-metadata">

**Author:** [@Jorge\_Correa](https://discuss.elastic.co/u/Jorge_Correa)\
**Replies:** 0\
**Last updated:** [February 22, 2021, 2:17pm UTC](https://discuss.elastic.co/t/metricbeat-configuration-file-from-package-repository-is-always-detected-as-changed-and-stops-auto-upgrade-process/265077 "2021-02-22T14:17:23Z")

</div>

I'm using metricbeat installed from APT repository in Ubuntu. I've all hosts configured to auto upgrade packages (for example, with rules in unattended-upgrades). However, on every upgrade of metricbeat, even though mino…

---

## [Windows Events with evtx](https://discuss.elastic.co/t/windows-events-with-evtx/264565)

<div class="topic-metadata">

**Author:** [@Christer\_Palmen](https://discuss.elastic.co/u/Christer_Palmen)\
**Replies:** 2\
**Last updated:** [February 22, 2021, 10:28am UTC](https://discuss.elastic.co/t/windows-events-with-evtx/264565 "2021-02-22T10:28:47Z")

</div>

Hello. I am trying to setup an PoC with Ingesting Windows Evenst to Elastic. Because of company policies I can´t install Winlogbeat in any host, but the host where I have installed Elasticstack I have access to install a…

---

## [Metricbeat DNS error in kubernetes Cluster](https://discuss.elastic.co/t/metricbeat-dns-error-in-kubernetes-cluster/263303)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 8\
**Last updated:** [February 22, 2021, 8:47am UTC](https://discuss.elastic.co/t/metricbeat-dns-error-in-kubernetes-cluster/263303 "2021-02-22T08:47:37Z")

</div>

I have installed metric beat using helm chart and I am getting following DNS error. 2021-02-04T21:27:38.074Z WARN \[transport\] transport/tcp.go:52 DNS lookup failure "k8s-rke-cluster1-node2": lookup k8s-rke-cluster1-node…

---

## [Filebeat 2 log sources](https://discuss.elastic.co/t/filebeat-2-log-sources/264827)

<div class="topic-metadata">

**Author:** [@grazia0912](https://discuss.elastic.co/u/grazia0912)\
**Replies:** 3\
**Last updated:** [February 22, 2021, 8:40am UTC](https://discuss.elastic.co/t/filebeat-2-log-sources/264827 "2021-02-22T08:40:11Z")

</div>

Hi, i'm currently working with Filebeat and i would like to know if there is a way Filebeat gets logs from 1 remote Windows server then if the the server is down it will get logs automatically from a different server. I …

---

## [JSON file input to Filebeat sending data to Logstash and then to Azure Data Explorer](https://discuss.elastic.co/t/json-file-input-to-filebeat-sending-data-to-logstash-and-then-to-azure-data-explorer/264800)

<div class="topic-metadata">

**Author:** [@omkarg81](https://discuss.elastic.co/u/omkarg81)\
**Replies:** 6\
**Last updated:** [February 22, 2021, 7:39am UTC](https://discuss.elastic.co/t/json-file-input-to-filebeat-sending-data-to-logstash-and-then-to-azure-data-explorer/264800 "2021-02-22T07:39:39Z")

</div>

I'm trying to send a single line JSON input file to Filebeat which should read and send in the data over to Logstash which should then forward or dump it to Azure Data Explorer cluster-table. Somehow, when the Filebeat …

---

## [Foreign "fields" in JSON document in Kibana Discover](https://discuss.elastic.co/t/foreign-fields-in-json-document-in-kibana-discover/265024)

<div class="topic-metadata">

**Author:** [@thesn](https://discuss.elastic.co/u/thesn)\
**Replies:** 2\
**Last updated:** [February 22, 2021, 6:44am UTC](https://discuss.elastic.co/t/foreign-fields-in-json-document-in-kibana-discover/265024 "2021-02-22T06:44:46Z")

</div>

Hi, my setup: .log file --\> filebeat --\> logstash --\> elasticsearch \<-- kibana sample of .log file content: { "@timestamp":"2021-02-22T09:40:32.533+07:00", "@version":"1", "message":"mappingReloadDTreeEr…

---

## [\[Heartbeat\]: add retry logic into http/tcp check](https://discuss.elastic.co/t/heartbeat-add-retry-logic-into-http-tcp-check/264328)

<div class="topic-metadata">

**Author:** [@lowry](https://discuss.elastic.co/u/lowry)\
**Replies:** 4\
**Last updated:** [February 22, 2021, 6:25am UTC](https://discuss.elastic.co/t/heartbeat-add-retry-logic-into-http-tcp-check/264328 "2021-02-22T06:25:51Z")

</div>

Hello Beats friends, Wondering if current heartbeat supports retry in http/tcp check? Current Heartbeat ails me since looks like there's no retry logic in http/tcp check. As far as I can find, only icmp support retry …

---

## [Can it be supported to be configured by user that dropping @timestamp and @metadata fields of filebeat event before sent to kafka?](https://discuss.elastic.co/t/can-it-be-supported-to-be-configured-by-user-that-dropping-timestamp-and-metadata-fields-of-filebeat-event-before-sent-to-kafka/264849)

<div class="topic-metadata">

**Author:** [@mover](https://discuss.elastic.co/u/mover)\
**Replies:** 1\
**Last updated:** [February 22, 2021, 5:17am UTC](https://discuss.elastic.co/t/can-it-be-supported-to-be-configured-by-user-that-dropping-timestamp-and-metadata-fields-of-filebeat-event-before-sent-to-kafka/264849 "2021-02-22T05:17:37Z")

</div>

currently, the @timestamp and @metadata fields of filebeat event can not be dropped before sending to kafka. why? dropping or retainning these fields before sent to kafka can be controlled by user?

---

## [Reduce metricbeat storage data](https://discuss.elastic.co/t/reduce-metricbeat-storage-data/262125)

<div class="topic-metadata">

**Author:** [@tvander](https://discuss.elastic.co/u/tvander)\
**Replies:** 1\
**Last updated:** [February 22, 2021, 5:02am UTC](https://discuss.elastic.co/t/reduce-metricbeat-storage-data/262125 "2021-02-22T05:02:05Z")

</div>

Hi, I'm collecting 2 days of metricbeat data on my servers, its 20go per day, i let the default configuration and i need it this way to get precise real time information, But i also want to get information on my last 6…

---

## [Metricbeat on 200 PCs](https://discuss.elastic.co/t/metricbeat-on-200-pcs/265025)

<div class="topic-metadata">

**Author:** [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Replies:** 4\
**Last updated:** [February 22, 2021, 4:32am UTC](https://discuss.elastic.co/t/metricbeat-on-200-pcs/265025 "2021-02-22T04:32:25Z")

</div>

With default settings (like sending data every 10s), 200 PCs with Metricbeat, how much data is going to be sent and how many GBs per day do you think will be collected? Will my network traffic become slow since a lot of …

---

## [Exiting: 1 error: error loading config file: invalid config: yaml: line 91: did not find expected '-' indicator](https://discuss.elastic.co/t/exiting-1-error-error-loading-config-file-invalid-config-yaml-line-91-did-not-find-expected-indicator/264996)

<div class="topic-metadata">

**Author:** [@Wahyu\_Nugroho](https://discuss.elastic.co/u/Wahyu_Nugroho)\
**Replies:** 1\
**Last updated:** [February 22, 2021, 4:30am UTC](https://discuss.elastic.co/t/exiting-1-error-error-loading-config-file-invalid-config-yaml-line-91-did-not-find-expected-indicator/264996 "2021-02-22T04:30:33Z")

</div>

Please help me. This is my filebeat.yml : ###################### Filebeat Configuration Example ######################### # This file is an example configuration file highlighting only the most common # options. The…

---

## [Agent support for OS windows server and red hat](https://discuss.elastic.co/t/agent-support-for-os-windows-server-and-red-hat/262276)

<div class="topic-metadata">

**Author:** [@javig12](https://discuss.elastic.co/u/javig12)\
**Replies:** 3\
**Last updated:** [February 22, 2021, 3:59am UTC](https://discuss.elastic.co/t/agent-support-for-os-windows-server-and-red-hat/262276 "2021-02-22T03:59:54Z")

</div>

Hello Community, what about support agents on these servers: Windows Server 2012 R2, Windows Server 2012, Windows Server 2008 R2, Linux Redhat desde 5.11 and 6.8 hope your comments, Regards.

---

## [Collect disk IO and network metrics from ESXi and AIX OS](https://discuss.elastic.co/t/collect-disk-io-and-network-metrics-from-esxi-and-aix-os/262173)

<div class="topic-metadata">

**Author:** [@Ishaan](https://discuss.elastic.co/u/Ishaan)\
**Replies:** 1\
**Last updated:** [February 22, 2021, 3:53am UTC](https://discuss.elastic.co/t/collect-disk-io-and-network-metrics-from-esxi-and-aix-os/262173 "2021-02-22T03:53:21Z")

</div>

Hello, Is there a way to collect disk IO and network metrics from ESX and AIX OS just like we have diskio and network metricset available in the metricbeat system module? Any workaround available? Thanks

---

## [FileBeat Setup Error : error loading index pattern: returned 413 to import file: \<nil\>. Response: {"statusCode":413,"error":"Request Entity Too Large","message":"Payload content length greater than maximum allowed: 1048576"](https://discuss.elastic.co/t/filebeat-setup-error-error-loading-index-pattern-returned-413-to-import-file-nil-response-statuscode-413-error-request-entity-too-large-message-payload-content-length-greater-than-maximum-allowed-1048576/264845)

<div class="topic-metadata">

**Author:** [@Biswabhusan\_Dash](https://discuss.elastic.co/u/Biswabhusan_Dash)\
**Replies:** 1\
**Last updated:** [February 22, 2021, 12:51am UTC](https://discuss.elastic.co/t/filebeat-setup-error-error-loading-index-pattern-returned-413-to-import-file-nil-response-statuscode-413-error-request-entity-too-large-message-payload-content-length-greater-than-maximum-allowed-1048576/264845 "2021-02-22T00:51:37Z")

</div>

We are working to capture logs from server to elasticsearch by filebeat. We are getting below issue, while setup the filebeat. Response: {"statusCode":413,"error":"Request Entity Too Large","message":"Payload content le…

---

## [How to monitor inodes using metricbeat?](https://discuss.elastic.co/t/how-to-monitor-inodes-using-metricbeat/263818)

<div class="topic-metadata">

**Author:** [@premierpsp](https://discuss.elastic.co/u/premierpsp)\
**Replies:** 1\
**Last updated:** [February 21, 2021, 8:52pm UTC](https://discuss.elastic.co/t/how-to-monitor-inodes-using-metricbeat/263818 "2021-02-21T20:52:12Z")

</div>

Hi, is there any option to monitor linux inodes with metricbeat? Thank you

---

## [AuditBeat and PacketBeat generated data size for elasticsearch sizing](https://discuss.elastic.co/t/auditbeat-and-packetbeat-generated-data-size-for-elasticsearch-sizing/265000)

<div class="topic-metadata">

**Author:** [@0x90](https://discuss.elastic.co/u/0x90)\
**Replies:** 1\
**Last updated:** [February 21, 2021, 8:22pm UTC](https://discuss.elastic.co/t/auditbeat-and-packetbeat-generated-data-size-for-elasticsearch-sizing/265000 "2021-02-21T20:22:25Z")

</div>

In order for me to plan my elasticsearch cluster volume size needs I calculated EPS and EDS values for filebeat , and winlogbeat by checking the number of lines in the logs. But I can't seem to find a way to calculate ho…

---

## [Filebeat 7.11.1 registry log.json growing wild](https://discuss.elastic.co/t/filebeat-7-11-1-registry-log-json-growing-wild/264982)

<div class="topic-metadata">

**Author:** [@thesn](https://discuss.elastic.co/u/thesn)\
**Replies:** 0\
**Last updated:** [February 21, 2021, 12:27pm UTC](https://discuss.elastic.co/t/filebeat-7-11-1-registry-log-json-growing-wild/264982 "2021-02-21T12:27:31Z")

</div>

Hi, I just migrate from filebeat 7.8 (installed in host os) to filebeat 7.11 (installed in docker). I bind the volume in docker-compose for the registry and log files to be processed: version: "2.2" services: fi…

---

## [Filebeat in a docker container](https://discuss.elastic.co/t/filebeat-in-a-docker-container/264864)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [February 20, 2021, 8:42am UTC](https://discuss.elastic.co/t/filebeat-in-a-docker-container/264864 "2021-02-20T08:42:31Z")

</div>

Dear community, I have a server on openstack. This target I can reach from everywhere else beside from inside the filebeat docker on my laptop. If I make an ip add on my laptop I get a bunch of IPs. All these IPs I can…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=175)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=177)
