# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=178

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 179

---

## [FileBeats -\> MSK : SSL handshake failed when TLS is enabled](https://discuss.elastic.co/t/filebeats-msk-ssl-handshake-failed-when-tls-is-enabled/264424)

<div class="topic-metadata">

**Author:** [@Ravi342883](https://discuss.elastic.co/u/Ravi342883)\
**Replies:** 2\
**Last updated:** [February 17, 2021, 11:16am UTC](https://discuss.elastic.co/t/filebeats-msk-ssl-handshake-failed-when-tls-is-enabled/264424 "2021-02-17T11:16:49Z")

</div>

Hi All.. I have created a MSK cluster with 3 brokers and enabled encryption at rest and in transit but disabled TLS authentication. I'm trying to send data from Filebeat (7.10.0) --\> AWS MSK over TLS endpoint (9094). …

---

## [Metricbeat zookeeper module](https://discuss.elastic.co/t/metricbeat-zookeeper-module/264453)

<div class="topic-metadata">

**Author:** [@VictorG](https://discuss.elastic.co/u/VictorG)\
**Replies:** 2\
**Last updated:** [February 17, 2021, 7:26am UTC](https://discuss.elastic.co/t/metricbeat-zookeeper-module/264453 "2021-02-17T07:26:38Z")

</div>

Hello, I have two questions regarding the zookeeper module from metricbeat. Does metricbeat reads from a file or connects directly to zookeeper to query for mntr events? Does the zookeeper dashboard comes with panels …

---

## [Dissect Parsing Error with Sonicwall Module \[Filebeat 7.9.2\]](https://discuss.elastic.co/t/dissect-parsing-error-with-sonicwall-module-filebeat-7-9-2/264011)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 2\
**Last updated:** [February 17, 2021, 6:54am UTC](https://discuss.elastic.co/t/dissect-parsing-error-with-sonicwall-module-filebeat-7-9-2/264011 "2021-02-17T06:54:58Z")

</div>

Hi, everyone I have found some dissect parsing errors by using Sonicwall module module of Filebeat 7.9.2. Here you are some examples: Feb 11 07:31:35 \_gateway id=firewall sn=\<serial-number\> time="2021-02-11 06:31:35 …

---

## [Filebeat invalid CRI log format error](https://discuss.elastic.co/t/filebeat-invalid-cri-log-format-error/263324)

<div class="topic-metadata">

**Author:** [@user2416](https://discuss.elastic.co/u/user2416)\
**Replies:** 4\
**Last updated:** [February 17, 2021, 6:45am UTC](https://discuss.elastic.co/t/filebeat-invalid-cri-log-format-error/263324 "2021-02-17T06:45:27Z")

</div>

Hi, I am frequently seeing invalid CRI log format ERROR with filebeat. We are running filebeat as deamonset on kubernetes nodes to collect container logs. This Error is causing filebeat to stop sending logs to logstash …

---

## [Post incorrectly closed](https://discuss.elastic.co/t/post-incorrectly-closed/264465)

<div class="topic-metadata">

**Author:** [@strophy](https://discuss.elastic.co/u/strophy)\
**Replies:** 0\
**Last updated:** [February 16, 2021, 6:38pm UTC](https://discuss.elastic.co/t/post-incorrectly-closed/264465 "2021-02-16T18:38:37Z")

</div>

@Mario\_Castro closed my post regarding an unmerged PR to release Elastic Beats 7.11.0 on Ansible Galaxy, since the general release was on February 10, 2021. From his comment, he seems to think this is my PR. It's not my …

---

## [Startup Docker race condition](https://discuss.elastic.co/t/startup-docker-race-condition/264365)

<div class="topic-metadata">

**Author:** [@tman5](https://discuss.elastic.co/u/tman5)\
**Replies:** 2\
**Last updated:** [February 16, 2021, 3:27pm UTC](https://discuss.elastic.co/t/startup-docker-race-condition/264365 "2021-02-16T15:27:48Z")

</div>

Facing an issue when a server reboots with Filebeat 7.10 and Docker. Filebeat will start slightly before Docker and not pick up Docker container logs. If you restart Filebeat, it will then pick them up. I could set start…

---

## [Problem Using Filebeat for logging ssh log in](https://discuss.elastic.co/t/problem-using-filebeat-for-logging-ssh-log-in/264412)

<div class="topic-metadata">

**Author:** [@Skriix](https://discuss.elastic.co/u/Skriix)\
**Replies:** 3\
**Last updated:** [February 16, 2021, 1:10pm UTC](https://discuss.elastic.co/t/problem-using-filebeat-for-logging-ssh-log-in/264412 "2021-02-16T13:10:11Z")

</div>

Hi, SSh logs are not being shown in the kibana, I am pushing my logs to the ES Only I am using the following configuration, OS - Ubuntu 20.04 ES - 7.11.0 LogStash - 7.11.0 Kibana - 7.11.0 FileBeat - 7.11.0 The en…

---

## [7.11.0 release forgot to merge ansible-beats](https://discuss.elastic.co/t/7-11-0-release-forgot-to-merge-ansible-beats/264256)

<div class="topic-metadata">

**Author:** [@strophy](https://discuss.elastic.co/u/strophy)\
**Replies:** 1\
**Last updated:** [February 16, 2021, 12:03pm UTC](https://discuss.elastic.co/t/7-11-0-release-forgot-to-merge-ansible-beats/264256 "2021-02-16T12:03:31Z")

</div>

Hello, who is responsible for merging and releasing this? It seems to have been forgotten compared to previous releases, where it was merged on the same day as the rest of Elastic Stack.

---

## [Filebeat setup. fail to create the Kibana loader](https://discuss.elastic.co/t/filebeat-setup-fail-to-create-the-kibana-loader/264394)

<div class="topic-metadata">

**Author:** [@DavidEA](https://discuss.elastic.co/u/DavidEA)\
**Replies:** 1\
**Last updated:** [February 16, 2021, 11:47am UTC](https://discuss.elastic.co/t/filebeat-setup-fail-to-create-the-kibana-loader/264394 "2021-02-16T11:47:48Z")

</div>

Please tell me, I don't know where to look. When installing filebeat, I do: filebeat setup -e -E output.logstash.enabled = false -E output.elasticsearch.hosts = \['remote\_ip: 9200'\] -E setup.kibana.host = remote\_ip: 560…

---

## [Configure dropwizard modules for same services in different namespaces](https://discuss.elastic.co/t/configure-dropwizard-modules-for-same-services-in-different-namespaces/264162)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 1\
**Last updated:** [February 16, 2021, 11:36am UTC](https://discuss.elastic.co/t/configure-dropwizard-modules-for-same-services-in-different-namespaces/264162 "2021-02-16T11:36:41Z")

</div>

Hi we have multiple services exposing metrics using dropwizard running in kubernetes environment. Same services run in multiple kubernetes. namespaces, so I need to configure metricbeat everytime a new namespace is ad…

---

## [Winlogbeat does not properly handle CN's with comma(s) in name](https://discuss.elastic.co/t/winlogbeat-does-not-properly-handle-cns-with-comma-s-in-name/264362)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [February 15, 2021, 9:15pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-properly-handle-cns-with-comma-s-in-name/264362 "2021-02-15T21:15:10Z")

</div>

Hi All, I was looking at some Winlogbeat events, and I noticed that it doesn't seem to be properly handling CN's with comma(s) in them. Example (backslashes present to show escapes): Have a user like so: Admin\\\\, user …

---

## [Filebeat 7.11 is not publishing application log into AWS MSK-2.2.1, getting error kafka: client has run out of available brokers to talk](https://discuss.elastic.co/t/filebeat-7-11-is-not-publishing-application-log-into-aws-msk-2-2-1-getting-error-kafka-client-has-run-out-of-available-brokers-to-talk/264339)

<div class="topic-metadata">

**Author:** [@saroja](https://discuss.elastic.co/u/saroja)\
**Replies:** 0\
**Last updated:** [February 15, 2021, 5:27pm UTC](https://discuss.elastic.co/t/filebeat-7-11-is-not-publishing-application-log-into-aws-msk-2-2-1-getting-error-kafka-client-has-run-out-of-available-brokers-to-talk/264339 "2021-02-15T17:27:55Z")

</div>

Hi All, I am unable to post data from filebeat agent to AWS MSK 2.2.1 . Initially I was used filebeat version 7.10.0.As per the elastic team advice I have upgraded into 7.11.0. I used TLS configuration and please find …

---

## [Everything you Always Wanted to Know about Filebeat \* But Were Afraid to Ask](https://discuss.elastic.co/t/everything-you-always-wanted-to-know-about-filebeat-but-were-afraid-to-ask/264323)

<div class="topic-metadata">

**Author:** [@riferrei](https://discuss.elastic.co/u/riferrei)\
**Replies:** 0\
**Last updated:** [February 15, 2021, 2:32pm UTC](https://discuss.elastic.co/t/everything-you-always-wanted-to-know-about-filebeat-but-were-afraid-to-ask/264323 "2021-02-15T14:32:57Z")

</div>

I just published in the community channel from Elastic an video that introduces Filebeat. If you want to understand more about this Beat and get yourself hands-on with this technology then it may be a 1 hour very well sp…

---

## [How to convert field with "null" string value to 0 integer](https://discuss.elastic.co/t/how-to-convert-field-with-null-string-value-to-0-integer/264216)

<div class="topic-metadata">

**Author:** [@Die\_Meester](https://discuss.elastic.co/u/Die_Meester)\
**Replies:** 1\
**Last updated:** [February 14, 2021, 2:53am UTC](https://discuss.elastic.co/t/how-to-convert-field-with-null-string-value-to-0-integer/264216 "2021-02-14T02:53:36Z")

</div>

Hi, I am receiving the below error whilst trying to use filebeat to read log. I know that I can explicitly exclude the field %{processID} by appending ? %{?processID}, but sometimes the processID is valid integer and p…

---

## [Filebeat processrs revers dns only for private network](https://discuss.elastic.co/t/filebeat-processrs-revers-dns-only-for-private-network/264232)

<div class="topic-metadata">

**Author:** [@tellus83](https://discuss.elastic.co/u/tellus83)\
**Replies:** 0\
**Last updated:** [February 14, 2021, 1:24am UTC](https://discuss.elastic.co/t/filebeat-processrs-revers-dns-only-for-private-network/264232 "2021-02-14T01:24:07Z")

</div>

I'm using filbeate to resolve reverse DNS lookup - dns: type: reverse fields: source.ip: source.hostname destination.ip: destination.hostname success\_cache: capacity.initial:…

---

## [Save metricbeat data locally preferably in csv](https://discuss.elastic.co/t/save-metricbeat-data-locally-preferably-in-csv/264206)

<div class="topic-metadata">

**Author:** [@rsgupta0110](https://discuss.elastic.co/u/rsgupta0110)\
**Replies:** 2\
**Last updated:** [February 13, 2021, 3:22pm UTC](https://discuss.elastic.co/t/save-metricbeat-data-locally-preferably-in-csv/264206 "2021-02-13T15:22:34Z")

</div>

Is it possible to save the metricbeat data locally preferably in csv format ? We are experiencing intermittent connectivity problems between metricbeat and logstash and loosing the data when this happens so we would like…

---

## [BackPressure (?) while using Kafka](https://discuss.elastic.co/t/backpressure-while-using-kafka/264209)

<div class="topic-metadata">

**Author:** [@janoonan](https://discuss.elastic.co/u/janoonan)\
**Replies:** 0\
**Last updated:** [February 13, 2021, 10:57am UTC](https://discuss.elastic.co/t/backpressure-while-using-kafka/264209 "2021-02-13T10:57:12Z")

</div>

We have a busy production set-up generating many 1000's of logs, which are forwarded by beats to kafka before hitting logstash and elastic. Our server paged us last week at the end of the business day (when load subside…

---

## [Windows could not start the filebeat service on Local Computer. Error 1053: The service did not respond to the start or control request in a timely fashion](https://discuss.elastic.co/t/windows-could-not-start-the-filebeat-service-on-local-computer-error-1053-the-service-did-not-respond-to-the-start-or-control-request-in-a-timely-fashion/264191)

<div class="topic-metadata">

**Author:** [@Grativol](https://discuss.elastic.co/u/Grativol)\
**Replies:** 1\
**Last updated:** [February 13, 2021, 2:50am UTC](https://discuss.elastic.co/t/windows-could-not-start-the-filebeat-service-on-local-computer-error-1053-the-service-did-not-respond-to-the-start-or-control-request-in-a-timely-fashion/264191 "2021-02-13T02:50:07Z")

</div>

Fala galera blz? Estou tentando startar o servico do Filebeat em services.msc do server 2016, porem da erro: Windows could not start the filebeat service on Local Computer. Error 1053: The service did not respond to the…

---

## [Configure filebeat to ship elasticsearch logs to monitoring cluster in kubernetes](https://discuss.elastic.co/t/configure-filebeat-to-ship-elasticsearch-logs-to-monitoring-cluster-in-kubernetes/264161)

<div class="topic-metadata">

**Author:** [@itsron](https://discuss.elastic.co/u/itsron)\
**Replies:** 0\
**Last updated:** [February 12, 2021, 5:54pm UTC](https://discuss.elastic.co/t/configure-filebeat-to-ship-elasticsearch-logs-to-monitoring-cluster-in-kubernetes/264161 "2021-02-12T17:54:04Z")

</div>

I've 2 clusters (7.10) running on Kubernetes - 1 prod and 1 monitoring. I've successfully set up metricbeat to ship elasticsearch metrics to my monitoring cluster. Now I want to ship elasticsearch logs using filebeat to …

---

## [Multiple filebeats to a server ELK in docker](https://discuss.elastic.co/t/multiple-filebeats-to-a-server-elk-in-docker/263836)

<div class="topic-metadata">

**Author:** [@Martin\_perez](https://discuss.elastic.co/u/Martin_perez)\
**Replies:** 13\
**Last updated:** [February 12, 2021, 10:17am UTC](https://discuss.elastic.co/t/multiple-filebeats-to-a-server-elk-in-docker/263836 "2021-02-12T10:17:26Z")

</div>

I'm new to elk and i want to and I want to connect my elk stack with filebeat in docker, which I already have created in docker and it is creating the records for me, because I can see them in kibana. Now what I want is…

---

## [Auditbeat 7.11 on Ubuntu doesn't read /var/log/btmp](https://discuss.elastic.co/t/auditbeat-7-11-on-ubuntu-doesnt-read-var-log-btmp/264092)

<div class="topic-metadata">

**Author:** [@Supp0rt](https://discuss.elastic.co/u/Supp0rt)\
**Replies:** 0\
**Last updated:** [February 12, 2021, 8:26am UTC](https://discuss.elastic.co/t/auditbeat-7-11-on-ubuntu-doesnt-read-var-log-btmp/264092 "2021-02-12T08:26:50Z")

</div>

Hi, I installed auditbeat 7.11.2 on Ubuntu 16.04 and Centos 7 to read login from file /var/log/wtmp and /var/log/btmp . On Centos 7 all registers are read correctly. On Ubuntu, only login and logout are collected. No…

---

## [Filebeat configuration (o365 module) is not working](https://discuss.elastic.co/t/filebeat-configuration-o365-module-is-not-working/264089)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 0\
**Last updated:** [February 12, 2021, 7:59am UTC](https://discuss.elastic.co/t/filebeat-configuration-o365-module-is-not-working/264089 "2021-02-12T07:59:22Z")

</div>

Hello Im trying to configure the 0365 module with this: # List of content-types to fetch. By default all known content-types # are retrieved: var.content\_type: - "Audit.AzureActiveDirectory" # - "Audit.Exchange" …

---

## [Filebeat to ingest raw cloudtrail logs](https://discuss.elastic.co/t/filebeat-to-ingest-raw-cloudtrail-logs/264086)

<div class="topic-metadata">

**Author:** [@p1k4chu](https://discuss.elastic.co/u/p1k4chu)\
**Replies:** 0\
**Last updated:** [February 12, 2021, 7:36am UTC](https://discuss.elastic.co/t/filebeat-to-ingest-raw-cloudtrail-logs/264086 "2021-02-12T07:36:02Z")

</div>

Hello, I have raw cloudtrail logs in archives stored on a disk. How can I ingest them to elasticsearch instead of S3 input or direct cloudtrail input.

---

## [Need to setup cpu,memory,disk dashboards in kibana](https://discuss.elastic.co/t/need-to-setup-cpu-memory-disk-dashboards-in-kibana/263295)

<div class="topic-metadata">

**Author:** [@charanteja](https://discuss.elastic.co/u/charanteja)\
**Replies:** 6\
**Last updated:** [February 12, 2021, 6:17am UTC](https://discuss.elastic.co/t/need-to-setup-cpu-memory-disk-dashboards-in-kibana/263295 "2021-02-12T06:17:29Z")

</div>

I am fairly new to ELK and going thru dis portal is kind of helping me a little bit. I saw you are active and knowledgable in ELK. Could you help me in setting my visualization so I could set up the dashboards for my ne…

---

## [Unable to send data to AWS MSK, getting error message: Kafka publish failed with: circuit breaker is open](https://discuss.elastic.co/t/unable-to-send-data-to-aws-msk-getting-error-message-kafka-publish-failed-with-circuit-breaker-is-open/264045)

<div class="topic-metadata">

**Author:** [@saroja](https://discuss.elastic.co/u/saroja)\
**Replies:** 0\
**Last updated:** [February 11, 2021, 6:44pm UTC](https://discuss.elastic.co/t/unable-to-send-data-to-aws-msk-getting-error-message-kafka-publish-failed-with-circuit-breaker-is-open/264045 "2021-02-11T18:44:51Z")

</div>

Dear Team, I am using filebeat agent 7.10.0 and AWS msk in my pipeline. I am getting error : Kafka publish failed with: circuit breaker is open and retryer: send unwait signal to consumer. Please suggest if anyone f…

---

## [Filebeat low throughput and many old files under harvesting](https://discuss.elastic.co/t/filebeat-low-throughput-and-many-old-files-under-harvesting/263093)

<div class="topic-metadata">

**Author:** [@aksadvance](https://discuss.elastic.co/u/aksadvance)\
**Replies:** 3\
**Last updated:** [February 11, 2021, 5:09pm UTC](https://discuss.elastic.co/t/filebeat-low-throughput-and-many-old-files-under-harvesting/263093 "2021-02-11T17:09:25Z")

</div>

Hi, I am noticing this weird problem on filebeat side. Using filebeat version=7.1 I follow this setup , Filebeat -\> Logstash -\> ES. Logstash servers have been setup with persisted queue of 20GB. filebeat is reading…

---

## [Metricbeat AWS Module - billing metricset](https://discuss.elastic.co/t/metricbeat-aws-module-billing-metricset/263223)

<div class="topic-metadata">

**Author:** [@Jurilz](https://discuss.elastic.co/u/Jurilz)\
**Replies:** 10\
**Last updated:** [February 11, 2021, 12:27pm UTC](https://discuss.elastic.co/t/metricbeat-aws-module-billing-metricset/263223 "2021-02-11T12:27:42Z")

</div>

Good day, I'm currently trying to collect billing information from AWS by using the billing metricset of the Metricbeat AWS module, but the received data does not contain any billing information. my metricbeat.yml: me…

---

## [Beats monitoring](https://discuss.elastic.co/t/beats-monitoring/264034)

<div class="topic-metadata">

**Author:** [@bolemebrige](https://discuss.elastic.co/u/bolemebrige)\
**Replies:** 0\
**Last updated:** [February 11, 2021, 4:02pm UTC](https://discuss.elastic.co/t/beats-monitoring/264034 "2021-02-11T16:02:38Z")

</div>

Is there a way to send beats monitoring data (over interanal montiroing or metricbeat) to logstash and than to elasticsearch, so not with direct connection to elasticsearch?

---

## [Filebeat Auditd module: Failed to Parse field \[error\] of type \[keyword\]](https://discuss.elastic.co/t/filebeat-auditd-module-failed-to-parse-field-error-of-type-keyword/263579)

<div class="topic-metadata">

**Author:** [@ven67](https://discuss.elastic.co/u/ven67)\
**Replies:** 7\
**Last updated:** [February 11, 2021, 2:25pm UTC](https://discuss.elastic.co/t/filebeat-auditd-module-failed-to-parse-field-error-of-type-keyword/263579 "2021-02-11T14:25:33Z")

</div>

Hello! I have filebeat running in kubernetes with audtid module as such: Loading and configuring auditd module filebeat.modules: - module: auditd log: enabled: true var.paths: \["/var/lo…

---

## [Filebeat Pipelines](https://discuss.elastic.co/t/filebeat-pipelines/264005)

<div class="topic-metadata">

**Author:** [@st1988](https://discuss.elastic.co/u/st1988)\
**Replies:** 0\
**Last updated:** [February 11, 2021, 11:14am UTC](https://discuss.elastic.co/t/filebeat-pipelines/264005 "2021-02-11T11:14:01Z")

</div>

Hi, I have generated some filebeat configurations using the Machine learning in Kibana which has been amazing. This has given me several configuration files that I can add to Filebeat. The issue I have is that all the i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=177)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=179)
