# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=179

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 180

---

## [Fortinet module processor fail](https://discuss.elastic.co/t/fortinet-module-processor-fail/264003)

<div class="topic-metadata">

**Author:** [@Thomas74](https://discuss.elastic.co/u/Thomas74)\
**Replies:** 0\
**Last updated:** [February 11, 2021, 11:04am UTC](https://discuss.elastic.co/t/fortinet-module-processor-fail/264003 "2021-02-11T11:04:51Z")

</div>

Hi, I'm configuring Fortinet module but processor condition added doesn't work and I don't understand why. Here you have config module : - module: fortinet firewall: enabled: true var.input: udp …

---

## [Filebeat compatibality](https://discuss.elastic.co/t/filebeat-compatibality/263965)

<div class="topic-metadata">

**Author:** [@kvtang](https://discuss.elastic.co/u/kvtang)\
**Replies:** 1\
**Last updated:** [February 11, 2021, 9:10am UTC](https://discuss.elastic.co/t/filebeat-compatibality/263965 "2021-02-11T09:10:25Z")

</div>

Hi all, Can I install and run filebeat on Windows Embedded Standard PC? I think it is 2010 version. Thank you.

---

## [Filebeat performance is low after upgraded to 7.9.3](https://discuss.elastic.co/t/filebeat-performance-is-low-after-upgraded-to-7-9-3/263828)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 4\
**Last updated:** [February 11, 2021, 5:31am UTC](https://discuss.elastic.co/t/filebeat-performance-is-low-after-upgraded-to-7-9-3/263828 "2021-02-11T05:31:02Z")

</div>

Hi, I am using Filebeat to read all the application logs in my openshift cluster. The filebeat sends the logs to the logstash for indexing and then to Elasticsearch and finally visible on Kibana. Using 3 filebeat pods …

---

## [Agent service will not start, failure to authenticate to Kibana when using API key w/Elasticsearch](https://discuss.elastic.co/t/agent-service-will-not-start-failure-to-authenticate-to-kibana-when-using-api-key-w-elasticsearch/263906)

<div class="topic-metadata">

**Author:** [@dvo](https://discuss.elastic.co/u/dvo)\
**Replies:** 3\
**Last updated:** [February 11, 2021, 1:35am UTC](https://discuss.elastic.co/t/agent-service-will-not-start-failure-to-authenticate-to-kibana-when-using-api-key-w-elasticsearch/263906 "2021-02-11T01:35:52Z")

</div>

Hello all, we're doing a POC with Windows servers running \*beat agents sending perf and event log data to a Linux VM running ELK Stack. Everything is latest version. We want to standardize on agents authenticating using …

---

## [How to connect filebeat to azure elasticsearch](https://discuss.elastic.co/t/how-to-connect-filebeat-to-azure-elasticsearch/263833)

<div class="topic-metadata">

**Author:** [@vikramp](https://discuss.elastic.co/u/vikramp)\
**Replies:** 3\
**Last updated:** [February 10, 2021, 9:08pm UTC](https://discuss.elastic.co/t/how-to-connect-filebeat-to-azure-elasticsearch/263833 "2021-02-10T21:08:47Z")

</div>

what will be the elastic search ip/url of azure elastic-search as it contains 3 master node and 3 slave node.

---

## [Filebeat:7.10.0 not publishing/pushing logs to single node elasticsearch cluster deployed in kubernetes cluster](https://discuss.elastic.co/t/filebeat-7-10-0-not-publishing-pushing-logs-to-single-node-elasticsearch-cluster-deployed-in-kubernetes-cluster/263123)

<div class="topic-metadata">

**Author:** [@nirmal\_elastic](https://discuss.elastic.co/u/nirmal_elastic)\
**Replies:** 17\
**Last updated:** [February 10, 2021, 7:15pm UTC](https://discuss.elastic.co/t/filebeat-7-10-0-not-publishing-pushing-logs-to-single-node-elasticsearch-cluster-deployed-in-kubernetes-cluster/263123 "2021-02-10T19:15:18Z")

</div>

I have single node elasticsearch deployed on master node of k8s cluster and it's accessible using nodePort:30339 curl http://xx.xx.xx.xx:30339 { "name" : "elasticsearch-0", "cluster\_name" : "docker-cluster", "cluste…

---

## [Cisco Umbrella selfhosted s3 the queue is not processing](https://discuss.elastic.co/t/cisco-umbrella-selfhosted-s3-the-queue-is-not-processing/263152)

<div class="topic-metadata">

**Author:** [@YegorKovylyayev](https://discuss.elastic.co/u/YegorKovylyayev)\
**Replies:** 8\
**Last updated:** [February 10, 2021, 6:52pm UTC](https://discuss.elastic.co/t/cisco-umbrella-selfhosted-s3-the-queue-is-not-processing/263152 "2021-02-10T18:52:46Z")

</div>

Hello, can not connect Cisco Umbrella from self hosted s3 to filebeat on cisco.yml is have: - module: cisco umbrella: enabled: true var.input: s3 var.queue\_url: https://sqs.eu-west-1.amazonaws.com/111111111…

---

## [How to configure Auditbeat to panic the kernel if auditing fails](https://discuss.elastic.co/t/how-to-configure-auditbeat-to-panic-the-kernel-if-auditing-fails/263919)

<div class="topic-metadata">

**Author:** [@RLPowellJr](https://discuss.elastic.co/u/RLPowellJr)\
**Replies:** 0\
**Last updated:** [February 10, 2021, 6:34pm UTC](https://discuss.elastic.co/t/how-to-configure-auditbeat-to-panic-the-kernel-if-auditing-fails/263919 "2021-02-10T18:34:30Z")

</div>

Greetings all! We have a small Elastic Stack used for security-relevant event collection in a standalone Red Hat Enterprise Linux 7.4 & 7.6 modeling & simulation enclave. The Stack is just four Elasticsearch nodes, a K…

---

## [AWS Cloudwatch Metricset module and Cloudwatch Input Plugin - logstash](https://discuss.elastic.co/t/aws-cloudwatch-metricset-module-and-cloudwatch-input-plugin-logstash/263877)

<div class="topic-metadata">

**Author:** [@Priyank07](https://discuss.elastic.co/u/Priyank07)\
**Replies:** 2\
**Last updated:** [February 10, 2021, 4:34pm UTC](https://discuss.elastic.co/t/aws-cloudwatch-metricset-module-and-cloudwatch-input-plugin-logstash/263877 "2021-02-10T16:34:52Z")

</div>

Hi, I want to get metric from aws cloudwatch for this we have two options: 1 . cloudwatch input plugin - logstash 2 . aws cloudwatch metricset module - metricbeat So here is my question: Which one is more reliable? @js…

---

## [Oracle Driver on Metricbeat Pod](https://discuss.elastic.co/t/oracle-driver-on-metricbeat-pod/263786)

<div class="topic-metadata">

**Author:** [@ssurenr](https://discuss.elastic.co/u/ssurenr)\
**Replies:** 3\
**Last updated:** [February 10, 2021, 3:40pm UTC](https://discuss.elastic.co/t/oracle-driver-on-metricbeat-pod/263786 "2021-02-10T15:40:21Z")

</div>

Hi, I am trying to collect metrics from an Oracle Database Query. I am getting the following error upon configuring the 'query' metricset from sql module. 2021-02-09T16:57:35.337Z INFO module/wrapper.go:266 E…

---

## [Filesetup is not working](https://discuss.elastic.co/t/filesetup-is-not-working/262775)

<div class="topic-metadata">

**Author:** [@lielar](https://discuss.elastic.co/u/lielar)\
**Replies:** 12\
**Last updated:** [February 10, 2021, 2:26pm UTC](https://discuss.elastic.co/t/filesetup-is-not-working/262775 "2021-02-10T14:26:05Z")

</div>

I am currently in the Observability Fundamentals lab. While running the command ./filebeat setup, it brings up the following error Overwriting ILM policy is disabled. Set \`setup.ilm.overwrite: true\` for enabling. Inde…

---

## [Multiple interface sniffing with packetbeat & output to 1 file](https://discuss.elastic.co/t/multiple-interface-sniffing-with-packetbeat-output-to-1-file/263883)

<div class="topic-metadata">

**Author:** [@luciferdude](https://discuss.elastic.co/u/luciferdude)\
**Replies:** 0\
**Last updated:** [February 10, 2021, 2:13pm UTC](https://discuss.elastic.co/t/multiple-interface-sniffing-with-packetbeat-output-to-1-file/263883 "2021-02-10T14:13:21Z")

</div>

Hello - I have packetbeat version 7.10 installed on Linux (RHEL Centos 7) server. I've configured packetbeat to listen on two interfaces. I was able to calculate this by using the command packetbeat devices command. Ever…

---

## [Filebeat and Logstash](https://discuss.elastic.co/t/filebeat-and-logstash/263873)

<div class="topic-metadata">

**Author:** [@Sunflower](https://discuss.elastic.co/u/Sunflower)\
**Replies:** 4\
**Last updated:** [February 10, 2021, 1:20pm UTC](https://discuss.elastic.co/t/filebeat-and-logstash/263873 "2021-02-10T13:20:34Z")

</div>

Hi, I'd like to install Filebeat and send the Filebeat output to logstash, Is this documentation is relevant also to the latest version? https://www.elastic.co/guide/en/beats/filebeat/6.8/config-filebeat-logstash.htm…

---

## [Filebeat Apache Log fields (remote\_ip, geo etc)](https://discuss.elastic.co/t/filebeat-apache-log-fields-remote-ip-geo-etc/263760)

<div class="topic-metadata">

**Author:** [@radu990](https://discuss.elastic.co/u/radu990)\
**Replies:** 3\
**Last updated:** [February 10, 2021, 1:04pm UTC](https://discuss.elastic.co/t/filebeat-apache-log-fields-remote-ip-geo-etc/263760 "2021-02-10T13:04:08Z")

</div>

Hello, Sorry for bothering. I'm a new user for ELK. I have managed to enable Apache module for Filebeat and I'm seeing the Apache logs coming in Discover Section in Kibana. However the remote\_ip and other fields from Ap…

---

## [Filebeat Pod not working properly](https://discuss.elastic.co/t/filebeat-pod-not-working-properly/263641)

<div class="topic-metadata">

**Author:** [@yimengael](https://discuss.elastic.co/u/yimengael)\
**Replies:** 3\
**Last updated:** [February 10, 2021, 11:28am UTC](https://discuss.elastic.co/t/filebeat-pod-not-working-properly/263641 "2021-02-10T11:28:33Z")

</div>

Hi Filebeat experts, I deployed Filebeat on my Kubernetes cluster using deamon set. I have many nodes in my cluster. In each node of my cluster, I have a Filebeat pods that is running and collecting all the pods logs on…

---

## [When I restart the pod and move the worker node, filebeat does not start collecting logs](https://discuss.elastic.co/t/when-i-restart-the-pod-and-move-the-worker-node-filebeat-does-not-start-collecting-logs/263490)

<div class="topic-metadata">

**Author:** [@Negi700](https://discuss.elastic.co/u/Negi700)\
**Replies:** 3\
**Last updated:** [February 10, 2021, 11:17am UTC](https://discuss.elastic.co/t/when-i-restart-the-pod-and-move-the-worker-node-filebeat-does-not-start-collecting-logs/263490 "2021-02-10T11:17:53Z")

</div>

The log of the pod of azure kubernetes system is collected from the worker node. Log collection does not start when the pod reboots and moves the worker node. Is there any good workaround?

---

## [Filebeat: failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-temporary-bulk-send-failure/263515)

<div class="topic-metadata">

**Author:** [@samiusan](https://discuss.elastic.co/u/samiusan)\
**Replies:** 2\
**Last updated:** [February 10, 2021, 10:07am UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-temporary-bulk-send-failure/263515 "2021-02-10T10:07:08Z")

</div>

Hi, I have setup a few hosts at home & and am slowly teaching myself elastic. Problem at the moment is filebeat 7.10.2 are having trouble sending to my elasticsearch instance. Below is the snippet I'm seeing from one o…

---

## [Trying to drop event if mount\_point is /](https://discuss.elastic.co/t/trying-to-drop-event-if-mount-point-is/263798)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 0\
**Last updated:** [February 9, 2021, 7:32pm UTC](https://discuss.elastic.co/t/trying-to-drop-event-if-mount-point-is/263798 "2021-02-09T19:32:50Z")

</div>

I have try all different kind of options but nothing seems to work. anyone has doe this before. how do I do this? processors: - drop\_event.when.equals: system.filesystem.mount\_point: '/' processors: - drop\_event.wh…

---

## [Filebeat HTTP JSON with epochtime](https://discuss.elastic.co/t/filebeat-http-json-with-epochtime/263318)

<div class="topic-metadata">

**Author:** [@seefor](https://discuss.elastic.co/u/seefor)\
**Replies:** 4\
**Last updated:** [February 9, 2021, 7:06pm UTC](https://discuss.elastic.co/t/filebeat-http-json-with-epochtime/263318 "2021-02-09T19:06:21Z")

</div>

Can filebeat be configured to pass epoch time every 15 minutes? filebeat.inputs: type: httpjson url: https://api.ipify.org/?format=json&t0=epochtime-15minutes&t1=epochtimenow

---

## [Packetbeat is not sending data to elasticsearch](https://discuss.elastic.co/t/packetbeat-is-not-sending-data-to-elasticsearch/263790)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 1\
**Last updated:** [February 9, 2021, 5:50pm UTC](https://discuss.elastic.co/t/packetbeat-is-not-sending-data-to-elasticsearch/263790 "2021-02-09T17:50:15Z")

</div>

Hi Guys, I have installed Packetbeat in many servers and it works fine in all of them but i tried use packetbeat in a F5 Load Balancer and it is not working. Packetbeat is not sending http requests (over 10110 port) to…

---

## [Uninstall Filebeat on Ubuntu](https://discuss.elastic.co/t/uninstall-filebeat-on-ubuntu/263746)

<div class="topic-metadata">

**Author:** [@Liora](https://discuss.elastic.co/u/Liora)\
**Replies:** 4\
**Last updated:** [February 9, 2021, 4:57pm UTC](https://discuss.elastic.co/t/uninstall-filebeat-on-ubuntu/263746 "2021-02-09T16:57:57Z")

</div>

Hi Team, please how can i uninstall Filebeat from my Ubuntu Server? Thank you for the reply

---

## [Filebeat K8S pod keeps restarting and Logs stop getting to Kibana](https://discuss.elastic.co/t/filebeat-k8s-pod-keeps-restarting-and-logs-stop-getting-to-kibana/263476)

<div class="topic-metadata">

**Author:** [@yimengael](https://discuss.elastic.co/u/yimengael)\
**Replies:** 3\
**Last updated:** [February 9, 2021, 4:41pm UTC](https://discuss.elastic.co/t/filebeat-k8s-pod-keeps-restarting-and-logs-stop-getting-to-kibana/263476 "2021-02-09T16:41:37Z")

</div>

Hello, I have configured Filebeat on my Kubernetes cluster and it is running in a kubernetes pod. Sometimes I noticed that Filebeat stopped collecting logs and the pods where filebeat is installed keeps restarting. I i…

---

## [Convert from dynamodb json to regular json on ingest](https://discuss.elastic.co/t/convert-from-dynamodb-json-to-regular-json-on-ingest/263298)

<div class="topic-metadata">

**Author:** [@ryantomaselli](https://discuss.elastic.co/u/ryantomaselli)\
**Replies:** 1\
**Last updated:** [February 9, 2021, 3:48pm UTC](https://discuss.elastic.co/t/convert-from-dynamodb-json-to-regular-json-on-ingest/263298 "2021-02-09T15:48:52Z")

</div>

Hey guys; I'm ingesting DynamoDB stream data into Elastic using a function beat. Thing is the data ingested is all DynamoDB JSON rather than regular JSON. The AWS SDK has a method to do the conversion (see https://doc…

---

## [Providing document\_id in function beat for decode\_json\_fields results in effectively no updates to any records](https://discuss.elastic.co/t/providing-document-id-in-function-beat-for-decode-json-fields-results-in-effectively-no-updates-to-any-records/263434)

<div class="topic-metadata">

**Author:** [@ryantomaselli](https://discuss.elastic.co/u/ryantomaselli)\
**Replies:** 3\
**Last updated:** [February 9, 2021, 3:46pm UTC](https://discuss.elastic.co/t/providing-document-id-in-function-beat-for-decode-json-fields-results-in-effectively-no-updates-to-any-records/263434 "2021-02-09T15:46:49Z")

</div>

Hey guys; I'm processing records from DynamoDB via a function beat and it's working great, if I specify the source record as the "document\_id" for the "decode\_json\_fields" process Elastic correctly uses this as the ID f…

---

## [How to run metricbeat in background?](https://discuss.elastic.co/t/how-to-run-metricbeat-in-background/263595)

<div class="topic-metadata">

**Author:** [@shaiksubhan](https://discuss.elastic.co/u/shaiksubhan)\
**Replies:** 11\
**Last updated:** [February 9, 2021, 3:17pm UTC](https://discuss.elastic.co/t/how-to-run-metricbeat-in-background/263595 "2021-02-09T15:17:17Z")

</div>

Hi Team, I am trying to install Metricbeat 7.10.1 Linux version on my Linux machine but I am unable to run the metricbeat in the Background. Can any one help me on this so that i can run this beat in background itself …

---

## [Filebeat autodiscover+kubernetes module or add\_kubernetes\_metadata processor?](https://discuss.elastic.co/t/filebeat-autodiscover-kubernetes-module-or-add-kubernetes-metadata-processor/263662)

<div class="topic-metadata">

**Author:** [@offero](https://discuss.elastic.co/u/offero)\
**Replies:** 1\
**Last updated:** [February 9, 2021, 2:32pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-kubernetes-module-or-add-kubernetes-metadata-processor/263662 "2021-02-09T14:32:40Z")

</div>

I just set up a new helm chart to use add\_kubernetes\_metadata processor, which seemed to be the way to get k8s annotations based on my googling. But, in the process of trying to figure out which fields are being added, I…

---

## [How to kill filebeat (docker) process?](https://discuss.elastic.co/t/how-to-kill-filebeat-docker-process/263561)

<div class="topic-metadata">

**Author:** [@skime](https://discuss.elastic.co/u/skime)\
**Replies:** 5\
**Last updated:** [February 9, 2021, 1:36pm UTC](https://discuss.elastic.co/t/how-to-kill-filebeat-docker-process/263561 "2021-02-09T13:36:54Z")

</div>

Hello, how can I kill filebeat process that was started on docker? Linux situation by "top" command: I have restarted docker daemon, and it don't want to start - probably because of the filebeat, last log from docker …

---

## [Heartbeat timeout](https://discuss.elastic.co/t/heartbeat-timeout/262509)

<div class="topic-metadata">

**Author:** [@rckvanwijk](https://discuss.elastic.co/u/rckvanwijk)\
**Replies:** 5\
**Last updated:** [February 9, 2021, 1:18pm UTC](https://discuss.elastic.co/t/heartbeat-timeout/262509 "2021-02-09T13:18:14Z")

</div>

Hi there, we've got several heartbeats running for the uptime monitoring aspect. Usually it works fine but sometimes the uptime says the applications are down (while our second tool and our manual tests say they are not…

---

## [Heartbeat monitoring](https://discuss.elastic.co/t/heartbeat-monitoring/263329)

<div class="topic-metadata">

**Author:** [@tech](https://discuss.elastic.co/u/tech)\
**Replies:** 1\
**Last updated:** [February 9, 2021, 11:44am UTC](https://discuss.elastic.co/t/heartbeat-monitoring/263329 "2021-02-09T11:44:04Z")

</div>

Hi, Is there a way to monitor up time for spot instances

---

## [Filebeat Listening on IPV6](https://discuss.elastic.co/t/filebeat-listening-on-ipv6/263690)

<div class="topic-metadata">

**Author:** [@jasonkasih](https://discuss.elastic.co/u/jasonkasih)\
**Replies:** 0\
**Last updated:** [February 9, 2021, 7:32am UTC](https://discuss.elastic.co/t/filebeat-listening-on-ipv6/263690 "2021-02-09T07:32:53Z")

</div>

Good Day, This is my first post in Elastic forum. Apologise for any mistake in formatting. I'm encountering an issue around my filebeat listener only listening in ipv6 instead of ipv4. I understand it has something to …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=178)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=180)
