# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=177

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 178

---

## [Metricbeat not showing info on Kibana](https://discuss.elastic.co/t/metricbeat-not-showing-info-on-kibana/264839)

<div class="topic-metadata">

**Author:** [@gpalazov](https://discuss.elastic.co/u/gpalazov)\
**Replies:** 2\
**Last updated:** [February 20, 2021, 7:58am UTC](https://discuss.elastic.co/t/metricbeat-not-showing-info-on-kibana/264839 "2021-02-20T07:58:43Z")

</div>

Hello everyone:), Metricbeat not showing info on Kibana for me. I have Packetbeat configured and everything there is running as it should. Probably i'm missing some info on the conf side of metricbeat. Please tell me wh…

---

## [Metricbeat AWS module error while using credentials\_profile\_name](https://discuss.elastic.co/t/metricbeat-aws-module-error-while-using-credentials-profile-name/264807)

<div class="topic-metadata">

**Author:** [@atharvak](https://discuss.elastic.co/u/atharvak)\
**Replies:** 4\
**Last updated:** [February 20, 2021, 7:45am UTC](https://discuss.elastic.co/t/metricbeat-aws-module-error-while-using-credentials-profile-name/264807 "2021-02-20T07:45:31Z")

</div>

Hello guys, I am trying to configure AWS metrics for multiple AWS accounts of mine. I have already configured the profiles using AWS CLI and they are working. But when the same profile name is put in the modules.d/aws.y…

---

## [Filebeat is not closing files and open\_files count keeps on increasing](https://discuss.elastic.co/t/filebeat-is-not-closing-files-and-open-files-count-keeps-on-increasing/264344)

<div class="topic-metadata">

**Author:** [@abhishekkene](https://discuss.elastic.co/u/abhishekkene)\
**Replies:** 8\
**Last updated:** [February 19, 2021, 9:11pm UTC](https://discuss.elastic.co/t/filebeat-is-not-closing-files-and-open-files-count-keeps-on-increasing/264344 "2021-02-19T21:11:28Z")

</div>

The disk space on server shows full and when I checked the Filebeat logs, it was showing the open\_files as quite big number, it is continously increasing. The logs are rolling continously and new log file is being creat…

---

## [\[heartbeat\]: add feature to support returning multiple metrics for a single http check](https://discuss.elastic.co/t/heartbeat-add-feature-to-support-returning-multiple-metrics-for-a-single-http-check/264331)

<div class="topic-metadata">

**Author:** [@lowry](https://discuss.elastic.co/u/lowry)\
**Replies:** 2\
**Last updated:** [February 19, 2021, 8:47pm UTC](https://discuss.elastic.co/t/heartbeat-add-feature-to-support-returning-multiple-metrics-for-a-single-http-check/264331 "2021-02-19T20:47:57Z")

</div>

Hello Beats friends, Wondering if current Heartbeat supports returning multiple metrics for single http check? What I means here is that, if a single http check returns multiple desired key/value pairs, like the follow…

---

## [Not able to add custom field in heartbeat v6.5.3](https://discuss.elastic.co/t/not-able-to-add-custom-field-in-heartbeat-v6-5-3/263606)

<div class="topic-metadata">

**Author:** [@Kartikey\_Bhatore](https://discuss.elastic.co/u/Kartikey_Bhatore)\
**Replies:** 1\
**Last updated:** [February 19, 2021, 8:44pm UTC](https://discuss.elastic.co/t/not-able-to-add-custom-field-in-heartbeat-v6-5-3/263606 "2021-02-19T20:44:23Z")

</div>

Hello, I am using heartbeat 6.5.3 can you please let me know a way or workaround to add field in my output. Asking coz I am not able to find a way to add a field in this version in the documentation. Thanks …

---

## [Exporting to constant index name with Filebeat](https://discuss.elastic.co/t/exporting-to-constant-index-name-with-filebeat/264906)

<div class="topic-metadata">

**Author:** [@Tim\_Estes](https://discuss.elastic.co/u/Tim_Estes)\
**Replies:** 3\
**Last updated:** [February 19, 2021, 7:30pm UTC](https://discuss.elastic.co/t/exporting-to-constant-index-name-with-filebeat/264906 "2021-02-19T19:30:55Z")

</div>

From the documentation on changing the name of the index that filebeat writes to: But I was wondering if it would be possible to have filebeat write to an index name that doesn't change: output.elasticsearch.index: "…

---

## [Filebeat processors not dropping events](https://discuss.elastic.co/t/filebeat-processors-not-dropping-events/264875)

<div class="topic-metadata">

**Author:** [@Rahul\_Dankhara](https://discuss.elastic.co/u/Rahul_Dankhara)\
**Replies:** 2\
**Last updated:** [February 19, 2021, 4:41pm UTC](https://discuss.elastic.co/t/filebeat-processors-not-dropping-events/264875 "2021-02-19T16:41:53Z")

</div>

Hi Team, I am using filebeat 7.9.3 to ship events. I do want to drop events that contains any of the below key-value pairs. I am using processors to do the same, but somehow it is not working for me. processors:…

---

## [Beats - Export dashboards to file](https://discuss.elastic.co/t/beats-export-dashboards-to-file/264857)

<div class="topic-metadata">

**Author:** [@siginigin](https://discuss.elastic.co/u/siginigin)\
**Replies:** 3\
**Last updated:** [February 19, 2021, 4:09pm UTC](https://discuss.elastic.co/t/beats-export-dashboards-to-file/264857 "2021-02-19T16:09:12Z")

</div>

Hi, I'm working on automation of beats deployment with ansible. I don't want to give all the beats access to neither kibana nor elasticsearch, just logstash. So I decided to grab all the dashboards delivered with beats …

---

## [Configure filebeat nginx module with ansible role](https://discuss.elastic.co/t/configure-filebeat-nginx-module-with-ansible-role/264661)

<div class="topic-metadata">

**Author:** [@elster](https://discuss.elastic.co/u/elster)\
**Replies:** 3\
**Last updated:** [February 19, 2021, 2:21pm UTC](https://discuss.elastic.co/t/configure-filebeat-nginx-module-with-ansible-role/264661 "2021-02-19T14:21:48Z")

</div>

Dear experts, Can you please lead me into the right direction how I have to customize the GitHub - elastic/ansible-beats: Ansible Beats Role role so that the nginx module is enabled and working? Thanks and br, Elmar

---

## [Monitor file download over 10mb](https://discuss.elastic.co/t/monitor-file-download-over-10mb/264766)

<div class="topic-metadata">

**Author:** [@stravze](https://discuss.elastic.co/u/stravze)\
**Replies:** 4\
**Last updated:** [February 19, 2021, 1:14pm UTC](https://discuss.elastic.co/t/monitor-file-download-over-10mb/264766 "2021-02-19T13:14:56Z")

</div>

i'm totally new to Elastic stack and the beats family. I need to alert on either just files downloaded of files download over 10mb i've installed filebeat and auditbeat and still can't work how you do this Any advice …

---

## [Filebeat not sending logs to logstash (port 5044 )](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-logstash-port-5044/264514)

<div class="topic-metadata">

**Author:** [@syrine\_chelly](https://discuss.elastic.co/u/syrine_chelly)\
**Replies:** 17\
**Last updated:** [February 19, 2021, 12:50pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-logstash-port-5044/264514 "2021-02-19T12:50:58Z")

</div>

My filebeat is reading the log file but it 's not sending anything to logstash Here are my filebeats.yml: filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can use different …

---

## [Kubernetes - Number of deployments not matching reality](https://discuss.elastic.co/t/kubernetes-number-of-deployments-not-matching-reality/264665)

<div class="topic-metadata">

**Author:** [@dantonag](https://discuss.elastic.co/u/dantonag)\
**Replies:** 1\
**Last updated:** [February 19, 2021, 12:38pm UTC](https://discuss.elastic.co/t/kubernetes-number-of-deployments-not-matching-reality/264665 "2021-02-19T12:38:02Z")

</div>

Hello, one of our "clients" has installed metricbeat 7.6.2 on an Openshift cluster, but he's lamenting that the number of deployments he sees through one of the default metricbeat dashboards (the view name is "Deploymen…

---

## [Exiting: error loading config file: yaml: line 29: did not find expected key](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-29-did-not-find-expected-key/264816)

<div class="topic-metadata">

**Author:** [@Clyton](https://discuss.elastic.co/u/Clyton)\
**Replies:** 1\
**Last updated:** [February 19, 2021, 10:54am UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-29-did-not-find-expected-key/264816 "2021-02-19T10:54:46Z")

</div>

Hi All, I'm trying to configure kafka output based on two input location conditions, wherein I'm encountering the below error. Please advise !! # ============================== Filebeat inputs =========================…

---

## [Multiline kernel panic log parsing by filebeat](https://discuss.elastic.co/t/multiline-kernel-panic-log-parsing-by-filebeat/264824)

<div class="topic-metadata">

**Author:** [@Kuo\_Hugo](https://discuss.elastic.co/u/Kuo_Hugo)\
**Replies:** 0\
**Last updated:** [February 19, 2021, 9:21am UTC](https://discuss.elastic.co/t/multiline-kernel-panic-log-parsing-by-filebeat/264824 "2021-02-19T09:21:51Z")

</div>

I have hard time to index the kernel panic logs by filebeat as below example. Do you have suggestion about the best option to index Linux kernel logs? I don't see an option to handle the multiline logs as the kernel pa…

---

## [Send logs from filebeat to 2 graylog instances](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-graylog-instances/264701)

<div class="topic-metadata">

**Author:** [@shresthomniit](https://discuss.elastic.co/u/shresthomniit)\
**Replies:** 2\
**Last updated:** [February 19, 2021, 8:45am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-graylog-instances/264701 "2021-02-19T08:45:34Z")

</div>

Hello Everyone, I want to send logs from server-1 to server-2 and server-3. Server-1 has filebeat configured. Server-2 has 1 graylog instance running. (let say it has IP-1) Server-3 has another graylog instance runni…

---

## [How to delete .monitoring\*mb\* indices automatically after period of time?](https://discuss.elastic.co/t/how-to-delete-monitoring-mb-indices-automatically-after-period-of-time/264647)

<div class="topic-metadata">

**Author:** [@dabo](https://discuss.elastic.co/u/dabo)\
**Replies:** 7\
**Last updated:** [February 19, 2021, 6:41am UTC](https://discuss.elastic.co/t/how-to-delete-monitoring-mb-indices-automatically-after-period-of-time/264647 "2021-02-19T06:41:33Z")

</div>

Hi, We are using Cloud Platinum subscription. We enabled Metricbeat monitoring on 21st of January. Seems like .monitoring indices (old and new) are deleted only after 1 month or not deleted at all. Can we control ret…

---

## [Beats Certificate verification with ElasticSearch/Kibana](https://discuss.elastic.co/t/beats-certificate-verification-with-elasticsearch-kibana/264689)

<div class="topic-metadata">

**Author:** [@radu990](https://discuss.elastic.co/u/radu990)\
**Replies:** 0\
**Last updated:** [February 18, 2021, 10:39am UTC](https://discuss.elastic.co/t/beats-certificate-verification-with-elasticsearch-kibana/264689 "2021-02-18T10:39:16Z")

</div>

Hello, I have configured SSL on both Elasticsearch and Kibana, and I can connect ok to it via browser. However when trying to configure Beats (Winlogbeat, Filebeat) to work with certificates, I see the following under t…

---

## [How change index name in Heartbeat](https://discuss.elastic.co/t/how-change-index-name-in-heartbeat/264630)

<div class="topic-metadata">

**Author:** [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Replies:** 10\
**Last updated:** [February 18, 2021, 2:36pm UTC](https://discuss.elastic.co/t/how-change-index-name-in-heartbeat/264630 "2021-02-18T14:36:25Z")

</div>

Hi there guys i need help with a problem i have in heartbeat.yml look what I need is to change the name of the index of heartbeat, ie mapping to index it in kibana with another name other than heartbeat-7-10-2-2021-000…

---

## [Metric Beats installation 408 Error Import File](https://discuss.elastic.co/t/metric-beats-installation-408-error-import-file/264601)

<div class="topic-metadata">

**Author:** [@jamesm1](https://discuss.elastic.co/u/jamesm1)\
**Replies:** 3\
**Last updated:** [February 18, 2021, 11:38am UTC](https://discuss.elastic.co/t/metric-beats-installation-408-error-import-file/264601 "2021-02-18T11:38:57Z")

</div>

I am attempting to install the Metric Beats V 7.10.2 (I have also tried 7.11.0 aswell) module against my Elastic Cloud instance. I have followed the guide for installing: However I am getting an error message as follo…

---

## [GenerateCustomBeats hangs](https://discuss.elastic.co/t/generatecustombeats-hangs/264682)

<div class="topic-metadata">

**Author:** [@Dev-Flo](https://discuss.elastic.co/u/Dev-Flo)\
**Replies:** 0\
**Last updated:** [February 18, 2021, 10:12am UTC](https://discuss.elastic.co/t/generatecustombeats-hangs/264682 "2021-02-18T10:12:43Z")

</div>

Hi all, I'm attempting to create a new custom beat but get stuck when using the mage GenerateCustomBeat command. Enter the beat name \[examplebeat\]: examplebeat Enter your github name \[your-github-name\]: Enter the beat …

---

## [Logstash stuck in \[2021-02-17T12:32:52,208\]\[DEBUG\]\[org.logstash.execution.PeriodicFlush\]\[main\] Pushing flush onto pipeline](https://discuss.elastic.co/t/logstash-stuck-in-2021-02-17t1252-208-debug-org-logstash-execution-periodicflush-main-pushing-flush-onto-pipeline/264559)

<div class="topic-metadata">

**Author:** [@syrine\_chelly](https://discuss.elastic.co/u/syrine_chelly)\
**Replies:** 3\
**Last updated:** [February 18, 2021, 9:20am UTC](https://discuss.elastic.co/t/logstash-stuck-in-2021-02-17t1252-208-debug-org-logstash-execution-periodicflush-main-pushing-flush-onto-pipeline/264559 "2021-02-18T09:20:59Z")

</div>

i see this message in logs of logstash \[2021-02-17T12:27:27,747\]\[DEBUG\]\[io.netty.util.internal.PlatformDependent0\]\[main\]\[f24f5a6935ca56387219d3b2bfdc6097466486c907605f8a15f69f812d2d4269\] direct buffer constructor: unava…

---

## [Unable to sends data to AWS MSK, Error Message: Kafka publish failed with: circuit breaker is open](https://discuss.elastic.co/t/unable-to-sends-data-to-aws-msk-error-message-kafka-publish-failed-with-circuit-breaker-is-open/263785)

<div class="topic-metadata">

**Author:** [@saroja](https://discuss.elastic.co/u/saroja)\
**Replies:** 3\
**Last updated:** [February 17, 2021, 3:50pm UTC](https://discuss.elastic.co/t/unable-to-sends-data-to-aws-msk-error-message-kafka-publish-failed-with-circuit-breaker-is-open/263785 "2021-02-17T15:50:00Z")

</div>

Hello, I have configured a pipeline, that will read the application logs and sends the log messages to individual kafka topic. I have installed filebeat -7.10.0 and configured AWS msk -2.2.1. After starting the filebe…

---

## [Filebeat - 7.10.2 - Flooding Syslog with CIFS Errors](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587)

<div class="topic-metadata">

**Author:** [@scott\_stash](https://discuss.elastic.co/u/scott_stash)\
**Replies:** 6\
**Last updated:** [February 18, 2021, 2:27am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587 "2021-02-18T02:27:19Z")

</div>

Previously I was running Filebeat 7.5 on Ubuntu 18.04. I have installed Filebeat 7.10.2 on Ubuntu 20, and now my syslog is flooded with this message while filebeat is running: CIFS VFS: Close unmatched open The config…

---

## [Filebeat Cisco Umbrella Fileset](https://discuss.elastic.co/t/filebeat-cisco-umbrella-fileset/262731)

<div class="topic-metadata">

**Author:** [@InnerJoin](https://discuss.elastic.co/u/InnerJoin)\
**Replies:** 6\
**Last updated:** [February 18, 2021, 1:36am UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella-fileset/262731 "2021-02-18T01:36:05Z")

</div>

Hi. I'm trying to set up the Filebeat Cisco module with the Umbrella fileset. I understand that they do not yet support Cisco managed S3 instances but I see that you can set the input to be file. I can't find anything ab…

---

## [Issues filtering Elasticsearch logs in Docker with Modules](https://discuss.elastic.co/t/issues-filtering-elasticsearch-logs-in-docker-with-modules/263314)

<div class="topic-metadata">

**Author:** [@leosunmo](https://discuss.elastic.co/u/leosunmo)\
**Replies:** 1\
**Last updated:** [February 18, 2021, 12:02am UTC](https://discuss.elastic.co/t/issues-filtering-elasticsearch-logs-in-docker-with-modules/263314 "2021-02-18T00:02:54Z")

</div>

Hey there, I'm running in to some matching issues when I'm trying to use the Elasticsearch Module with the Docker provider. I've followed this blog post on how to make it play nicely together somewhat. My issue is tha…

---

## [Filebeat on ECK with AWS Module Fails Due To Metadata Error](https://discuss.elastic.co/t/filebeat-on-eck-with-aws-module-fails-due-to-metadata-error/264616)

<div class="topic-metadata">

**Author:** [@jgriffiths](https://discuss.elastic.co/u/jgriffiths)\
**Replies:** 0\
**Last updated:** [February 17, 2021, 9:21pm UTC](https://discuss.elastic.co/t/filebeat-on-eck-with-aws-module-fails-due-to-metadata-error/264616 "2021-02-17T21:21:41Z")

</div>

We are running an Elastic Stack with ECK in EKS (7.8). We noticed that our filebeat daemonset and the AWS module were not processing logs from S3 and our SQS queues backing up. Looking at the logs on our FileBeat conta…

---

## [High disk usage while docker container is recreating](https://discuss.elastic.co/t/high-disk-usage-while-docker-container-is-recreating/264533)

<div class="topic-metadata">

**Author:** [@homa\_inc](https://discuss.elastic.co/u/homa_inc)\
**Replies:** 1\
**Last updated:** [February 17, 2021, 7:29pm UTC](https://discuss.elastic.co/t/high-disk-usage-while-docker-container-is-recreating/264533 "2021-02-17T19:29:09Z")

</div>

Hi there. I have Filebeat container that configured to scan redis logs from redis container. There is configuration (filebeat.yml): filebeat.registry.flush: 2s output.elasticsearch: hosts: \['${ELASTICSEARCH\_HOST…

---

## [Metricbeat getResources failed AccessDeniedException](https://discuss.elastic.co/t/metricbeat-getresources-failed-accessdeniedexception/264556)

<div class="topic-metadata">

**Author:** [@atharvak](https://discuss.elastic.co/u/atharvak)\
**Replies:** 1\
**Last updated:** [February 17, 2021, 7:21pm UTC](https://discuss.elastic.co/t/metricbeat-getresources-failed-accessdeniedexception/264556 "2021-02-17T19:21:14Z")

</div>

Hello guys, I am trying to setup Metricbeat for my AWS account. I have already created an IAM user with full access to EC2, S3, Cloudwatch, etc. Following is my configuration #- module: aws # period: 1m # metricsets:…

---

## [Best Practice for Deploying Custom Metricset for Metricbeat](https://discuss.elastic.co/t/best-practice-for-deploying-custom-metricset-for-metricbeat/263811)

<div class="topic-metadata">

**Author:** [@traw1234](https://discuss.elastic.co/u/traw1234)\
**Replies:** 3\
**Last updated:** [February 16, 2021, 11:35pm UTC](https://discuss.elastic.co/t/best-practice-for-deploying-custom-metricset-for-metricbeat/263811 "2021-02-16T23:35:14Z")

</div>

I've created my own custom module to run in Metricbeat. My process locally (following this guide) was: clone https://github.com/elastic/beats run make create-metricset write the code in the metricset run mage update …

---

## [Filebeat + logstash infinite loop](https://discuss.elastic.co/t/filebeat-logstash-infinite-loop/264595)

<div class="topic-metadata">

**Author:** [@Edi1](https://discuss.elastic.co/u/Edi1)\
**Replies:** 0\
**Last updated:** [February 17, 2021, 3:39pm UTC](https://discuss.elastic.co/t/filebeat-logstash-infinite-loop/264595 "2021-02-17T15:39:41Z")

</div>

Hello. I am new to elasticsearch and I am trying to send json data with filebeat to logstash -\> elasticsearch. #filebeat.yml filebeat.inputs: - type: log enabled: true paths: - /var/log/json-data2.log json.me…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=176)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=178)
