# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=180

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 181

---

## [S390x support for Beats](https://discuss.elastic.co/t/s390x-support-for-beats/263382)

<div class="topic-metadata">

**Author:** [@VibhutiS](https://discuss.elastic.co/u/VibhutiS)\
**Replies:** 2\
**Last updated:** [February 9, 2021, 5:20am UTC](https://discuss.elastic.co/t/s390x-support-for-beats/263382 "2021-02-09T05:20:46Z")

</div>

Hi We would like to know if support for s390x can be provided in Beats Jenkins CI. We can provide linux/s390x VM if needed so that you can execute the build process and run basic test cases. Also please let us know if a…

---

## [Finding computer in hosts](https://discuss.elastic.co/t/finding-computer-in-hosts/263460)

<div class="topic-metadata">

**Author:** [@ukuleleplayer](https://discuss.elastic.co/u/ukuleleplayer)\
**Replies:** 5\
**Last updated:** [February 8, 2021, 11:48pm UTC](https://discuss.elastic.co/t/finding-computer-in-hosts/263460 "2021-02-08T23:48:35Z")

</div>

I got a computer hooked up to auditbeat, but am unable to find it in the hosts. So, I have two questions. 1.) Is there any setting that might prevent it from showing up? 2.) Is there anyway for me to confirm whether or…

---

## [Need some help configuring an ACK handler for a custom beat](https://discuss.elastic.co/t/need-some-help-configuring-an-ack-handler-for-a-custom-beat/263639)

<div class="topic-metadata">

**Author:** [@luado](https://discuss.elastic.co/u/luado)\
**Replies:** 0\
**Last updated:** [February 8, 2021, 5:12pm UTC](https://discuss.elastic.co/t/need-some-help-configuring-an-ack-handler-for-a-custom-beat/263639 "2021-02-08T17:12:00Z")

</div>

First of, I tried finding on the tags options a "custom beat" tag, but there is not one there, could I suggest adding such a tag? I have created a custom beat based on libbeat v7. I have defined a struct that implement…

---

## [Metricbeat|Failed to parse api response: invalid ch aracter '#' looking for beginning of value"](https://discuss.elastic.co/t/metricbeat-failed-to-parse-api-response-invalid-ch-aracter-looking-for-beginning-of-value/263436)

<div class="topic-metadata">

**Author:** [@sandeepsingh2103](https://discuss.elastic.co/u/sandeepsingh2103)\
**Replies:** 2\
**Last updated:** [February 8, 2021, 5:04pm UTC](https://discuss.elastic.co/t/metricbeat-failed-to-parse-api-response-invalid-ch-aracter-looking-for-beginning-of-value/263436 "2021-02-08T17:04:18Z")

</div>

Metricbeat: "version": "7.10.0" I am trying to use query metricbeat of 'prometheus' module using following config: - module: prometheus period: 10s hosts: \["fluentd:24231"\] metricsets: \["query"\] queries: - n…

---

## [Limiting fields created by Filebeat for Netflow](https://discuss.elastic.co/t/limiting-fields-created-by-filebeat-for-netflow/263371)

<div class="topic-metadata">

**Author:** [@Attila\_Kelenyi](https://discuss.elastic.co/u/Attila_Kelenyi)\
**Replies:** 1\
**Last updated:** [February 8, 2021, 4:13pm UTC](https://discuss.elastic.co/t/limiting-fields-created-by-filebeat-for-netflow/263371 "2021-02-08T16:13:27Z")

</div>

Dear All, I hope you can give me some advice on the best way to reduce the number of fields created. Let me begin with the overview of the design: VMware ESXI hosts are sending Neflow v10 (IPFX) to Filebeat forwardin…

---

## [About filebeat upgrade 7.6.2 to 7.10.2](https://discuss.elastic.co/t/about-filebeat-upgrade-7-6-2-to-7-10-2/263196)

<div class="topic-metadata">

**Author:** [@ZPerling](https://discuss.elastic.co/u/ZPerling)\
**Replies:** 3\
**Last updated:** [February 8, 2021, 2:38pm UTC](https://discuss.elastic.co/t/about-filebeat-upgrade-7-6-2-to-7-10-2/263196 "2021-02-08T14:38:14Z")

</div>

I want to fix bug with filebeat kubernetes auto discover, so upgrade filbeat from 7.6.2 to 7.10.2, but I found some problem, the log events output to kafka speed is very slower at the new version, I do not know how to fi…

---

## [Packetbeat - Cannot add kubernetes metadata](https://discuss.elastic.co/t/packetbeat-cannot-add-kubernetes-metadata/263615)

<div class="topic-metadata">

**Author:** [@Francisco\_Peralta\_Gu](https://discuss.elastic.co/u/Francisco_Peralta_Gu)\
**Replies:** 0\
**Last updated:** [February 8, 2021, 2:36pm UTC](https://discuss.elastic.co/t/packetbeat-cannot-add-kubernetes-metadata/263615 "2021-02-08T14:36:36Z")

</div>

Hi. I am trying to configure packetbeat 1.10.1 in order to get kubernetes metadata in a kubernetes cluster v. 1.18.3 but I am not able to get it. This is the configuration that I have applied: - add\_cloud\_meta…

---

## [Add\_resource\_metadata.namespace.include\_annotations doesn't work anymore in 7.10.x?](https://discuss.elastic.co/t/add-resource-metadata-namespace-include-annotations-doesnt-work-anymore-in-7-10-x/261878)

<div class="topic-metadata">

**Author:** [@lobachpavel](https://discuss.elastic.co/u/lobachpavel)\
**Replies:** 1\
**Last updated:** [February 8, 2021, 11:59am UTC](https://discuss.elastic.co/t/add-resource-metadata-namespace-include-annotations-doesnt-work-anymore-in-7-10-x/261878 "2021-02-08T11:59:14Z")

</div>

While migrating from filebeat 7.6.0 to 7.10.x we discovered that we can not pull kubernetes namespace annotations into events anymore , here is the minimal example config: filebeat.yml: | filebeat.autodisc…

---

## [Harvester not harvesting Autodiscover](https://discuss.elastic.co/t/harvester-not-harvesting-autodiscover/263392)

<div class="topic-metadata">

**Author:** [@Alexis\_Oviedo](https://discuss.elastic.co/u/Alexis_Oviedo)\
**Replies:** 4\
**Last updated:** [February 8, 2021, 11:10am UTC](https://discuss.elastic.co/t/harvester-not-harvesting-autodiscover/263392 "2021-02-08T11:10:24Z")

</div>

I'm trying to use filebeat docker but it's not harvesting files. Autodiscover seems to work because found the logs I want but it's not harvesting them. This is my filebeat.yml: filebeat.autodiscover: providers: - t…

---

## [Beats Developer Guide \[master\] is out of date, creating new beat fails](https://discuss.elastic.co/t/beats-developer-guide-master-is-out-of-date-creating-new-beat-fails/263156)

<div class="topic-metadata">

**Author:** [@jackemuk-es](https://discuss.elastic.co/u/jackemuk-es)\
**Replies:** 5\
**Last updated:** [February 8, 2021, 10:10am UTC](https://discuss.elastic.co/t/beats-developer-guide-master-is-out-of-date-creating-new-beat-fails/263156 "2021-02-08T10:10:23Z")

</div>

There are errors in the documentation to get started with creating your own beats. If you search in the history, they have been around for some time and haven't been updated. This makes it extremely difficult to create a…

---

## [Filebeat only operating at 10%-15% of expected Performance](https://discuss.elastic.co/t/filebeat-only-operating-at-10-15-of-expected-performance/262865)

<div class="topic-metadata">

**Author:** [@svbernem](https://discuss.elastic.co/u/svbernem)\
**Replies:** 3\
**Last updated:** [February 8, 2021, 6:56am UTC](https://discuss.elastic.co/t/filebeat-only-operating-at-10-15-of-expected-performance/262865 "2021-02-08T06:56:34Z")

</div>

Hi, I have invested quite some time profiling configurations of filebeat (7.6.2) in the past few days, since it is currently running very slow. My test dataset consists of ~2GB ndjson files, at 10 MB per file, with ~6 m…

---

## [Force Read few files from start when filebeat restarts](https://discuss.elastic.co/t/force-read-few-files-from-start-when-filebeat-restarts/263362)

<div class="topic-metadata">

**Author:** [@rsgupta0110](https://discuss.elastic.co/u/rsgupta0110)\
**Replies:** 2\
**Last updated:** [February 7, 2021, 1:49pm UTC](https://discuss.elastic.co/t/force-read-few-files-from-start-when-filebeat-restarts/263362 "2021-02-07T13:49:48Z")

</div>

Filebeat maintains the registry and just uploads new logs between filebeat restarts. Is there a way to specify to read few log files from beginning everytime filebeat restarts while maintaining the registry for other fil…

---

## [How to monitor a file for its version, code signature etc](https://discuss.elastic.co/t/how-to-monitor-a-file-for-its-version-code-signature-etc/263178)

<div class="topic-metadata">

**Author:** [@rsgupta0110](https://discuss.elastic.co/u/rsgupta0110)\
**Replies:** 2\
**Last updated:** [February 7, 2021, 1:29pm UTC](https://discuss.elastic.co/t/how-to-monitor-a-file-for-its-version-code-signature-etc/263178 "2021-02-07T13:29:15Z")

</div>

I would like to monitor files inside a directory for the file description like version, code signature etc. without uploading the files to Elastic Search. I found this File fields but not sure how to add these fields in…

---

## [Combine two fields into one via add\_fields](https://discuss.elastic.co/t/combine-two-fields-into-one-via-add-fields/263468)

<div class="topic-metadata">

**Author:** [@bascht](https://discuss.elastic.co/u/bascht)\
**Replies:** 2\
**Last updated:** [February 6, 2021, 12:48pm UTC](https://discuss.elastic.co/t/combine-two-fields-into-one-via-add-fields/263468 "2021-02-06T12:48:07Z")

</div>

Hey everyone. I am trying to achieve something seemingly simple but cannot get this to work with the latest Filebeat 7.10: I want to combine the two fields foo.bar and foo.baz into a single new field that just joins th…

---

## [Using processor in Filebeat Nginx module](https://discuss.elastic.co/t/using-processor-in-filebeat-nginx-module/263368)

<div class="topic-metadata">

**Author:** [@jz1603](https://discuss.elastic.co/u/jz1603)\
**Replies:** 2\
**Last updated:** [February 5, 2021, 7:47pm UTC](https://discuss.elastic.co/t/using-processor-in-filebeat-nginx-module/263368 "2021-02-05T19:47:02Z")

</div>

I am trying to drop some fields on the indices ingested by the filebeat Nginx module. I followed the instructions on the thread https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/3, bu…

---

## [Metricbeat MSSQL module connecting to only localhost](https://discuss.elastic.co/t/metricbeat-mssql-module-connecting-to-only-localhost/261674)

<div class="topic-metadata">

**Author:** [@phani\_akkina](https://discuss.elastic.co/u/phani_akkina)\
**Replies:** 13\
**Last updated:** [February 5, 2021, 3:32pm UTC](https://discuss.elastic.co/t/metricbeat-mssql-module-connecting-to-only-localhost/261674 "2021-02-05T15:32:23Z")

</div>

I am trying to monitor MSSQL using metricbeat but I found some strange errors. I am trying to monitor SQL Cluster with IP and SQL instance name. But I see whenever I use the correct SQL server details then it's connecti…

---

## [Filebeat IIS module - only good for the first part of a second](https://discuss.elastic.co/t/filebeat-iis-module-only-good-for-the-first-part-of-a-second/263311)

<div class="topic-metadata">

**Author:** [@Gary\_Griffith](https://discuss.elastic.co/u/Gary_Griffith)\
**Replies:** 0\
**Last updated:** [February 4, 2021, 11:06pm UTC](https://discuss.elastic.co/t/filebeat-iis-module-only-good-for-the-first-part-of-a-second/263311 "2021-02-04T23:06:05Z")

</div>

So, we installed filebeat v7.10.1 and enables the IIS System module in a pretty standard way. Under heavy load, we get a batch of IIS access logs nicely parsed into the IIS fields: method, user\_agents, geolocation, etc.…

---

## [Filebeat's Data not showing in Kibana Dashboard](https://discuss.elastic.co/t/filebeats-data-not-showing-in-kibana-dashboard/263115)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 3\
**Last updated:** [February 4, 2021, 10:47pm UTC](https://discuss.elastic.co/t/filebeats-data-not-showing-in-kibana-dashboard/263115 "2021-02-04T22:47:54Z")

</div>

I have install ELK on ubuntu18.04 for monitoring remote server logs. On remote server i have installed Filebeat to send data to logstash. Remote server's logs are showing in Kibana--\>observability--\>logs. But in dashboad…

---

## [High CPU and Harvester Errors with 20000 log files](https://discuss.elastic.co/t/high-cpu-and-harvester-errors-with-20000-log-files/263290)

<div class="topic-metadata">

**Author:** [@jbudin](https://discuss.elastic.co/u/jbudin)\
**Replies:** 2\
**Last updated:** [February 4, 2021, 10:06pm UTC](https://discuss.elastic.co/t/high-cpu-and-harvester-errors-with-20000-log-files/263290 "2021-02-04T22:06:16Z")

</div>

Hi Elastic Community, We have a bottleneck on CPU using filebeat. The service takes anywhere from 10-80% of CPU at all times. After excluding certain paths, the CPU no longer spikes. In each of the path subdirectories …

---

## [Metricbeat showing values as 1000% in dashboard](https://discuss.elastic.co/t/metricbeat-showing-values-as-1000-in-dashboard/263216)

<div class="topic-metadata">

**Author:** [@vinod\_kumar](https://discuss.elastic.co/u/vinod_kumar)\
**Replies:** 1\
**Last updated:** [February 4, 2021, 7:00pm UTC](https://discuss.elastic.co/t/metricbeat-showing-values-as-1000-in-dashboard/263216 "2021-02-04T19:00:07Z")

</div>

I have configured Metricbeat but showing values as 1000% instead of 100%. How this can be resolved

---

## [Parsing Windows DHCP Logs with Filebeat Microsoft Module](https://discuss.elastic.co/t/parsing-windows-dhcp-logs-with-filebeat-microsoft-module/260849)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 3\
**Last updated:** [February 4, 2021, 5:17pm UTC](https://discuss.elastic.co/t/parsing-windows-dhcp-logs-with-filebeat-microsoft-module/260849 "2021-02-04T17:17:22Z")

</div>

I somehow lost track of the previous thread regarding this issue, and it ended up closing due to inactivity. I am still seeing this same problem now on 7.10.1. Related thread: Has this been looked into any more?

---

## [\[ES 7.6\] regular expression has redundant nested repeat operator](https://discuss.elastic.co/t/es-7-6-regular-expression-has-redundant-nested-repeat-operator/220835)

<div class="topic-metadata">

**Author:** [@yurgers](https://discuss.elastic.co/u/yurgers)\
**Replies:** 8\
**Last updated:** [February 4, 2021, 2:54pm UTC](https://discuss.elastic.co/t/es-7-6-regular-expression-has-redundant-nested-repeat-operator/220835 "2021-02-04T14:54:03Z")

</div>

good day! I'm new to ELK Noticed that after updating ES to 7.6 a large number of messages started appearing in /var/log/messages Feb 25 13:55:01 elasticsearch elasticsearch\[23298\]: regular expression has redundant ne…

---

## [JDBC connection string](https://discuss.elastic.co/t/jdbc-connection-string/263165)

<div class="topic-metadata">

**Author:** [@525125](https://discuss.elastic.co/u/525125)\
**Replies:** 3\
**Last updated:** [February 4, 2021, 1:41pm UTC](https://discuss.elastic.co/t/jdbc-connection-string/263165 "2021-02-04T13:41:20Z")

</div>

Hi Team , We want to ingest oracle db (jdbc connection string ) filebeat -\>logstash --\>elk--\>kibana. Could help us what are prerequisites for achieve this.

---

## [How to Filebeat and logstash working with a JSON file](https://discuss.elastic.co/t/how-to-filebeat-and-logstash-working-with-a-json-file/263227)

<div class="topic-metadata">

**Author:** [@thewasta](https://discuss.elastic.co/u/thewasta)\
**Replies:** 0\
**Last updated:** [February 4, 2021, 10:02am UTC](https://discuss.elastic.co/t/how-to-filebeat-and-logstash-working-with-a-json-file/263227 "2021-02-04T10:02:25Z")

</div>

Filebeat, Logstash version: 7.10 Given this json { "killStreakData": { "12344412441": { "Name": "nickName", "highestKS": 2 }, "53134441634": { "Name": "nickName2", "highestKS": 3…

---

## [Heartbeat autodiscover not working: protocol not available](https://discuss.elastic.co/t/heartbeat-autodiscover-not-working-protocol-not-available/262780)

<div class="topic-metadata">

**Author:** [@jeffrey008](https://discuss.elastic.co/u/jeffrey008)\
**Replies:** 4\
**Last updated:** [February 4, 2021, 7:37am UTC](https://discuss.elastic.co/t/heartbeat-autodiscover-not-working-protocol-not-available/262780 "2021-02-04T07:37:00Z")

</div>

I was trying Heartbeat autodiscover on my Windows. Here is my heartbeast.yml: heartbeat.autodiscover: providers: - type: docker templates: - condition: contains: docker.cont…

---

## [\[Filebeat\] Azure Module - Additional Azure AD Log Sources](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026)

<div class="topic-metadata">

**Author:** [@Matthew\_Lubbers](https://discuss.elastic.co/u/Matthew_Lubbers)\
**Replies:** 5\
**Last updated:** [February 4, 2021, 3:22am UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026 "2021-02-04T03:22:03Z")

</div>

Recently Microsoft Azure has added 4 new Azure AD log sources to be consumed by Azure Monitor Diagnostic Settings. When would be able to receive support for these new log sources for the Azure module? New Log Sources N…

---

## [How to get a function beat (configured to listen to kinesis stream) to push data into Elasticsearch](https://discuss.elastic.co/t/how-to-get-a-function-beat-configured-to-listen-to-kinesis-stream-to-push-data-into-elasticsearch/263171)

<div class="topic-metadata">

**Author:** [@ryantomaselli](https://discuss.elastic.co/u/ryantomaselli)\
**Replies:** 1\
**Last updated:** [February 3, 2021, 11:56pm UTC](https://discuss.elastic.co/t/how-to-get-a-function-beat-configured-to-listen-to-kinesis-stream-to-push-data-into-elasticsearch/263171 "2021-02-03T23:56:50Z")

</div>

Hi everyone... I'm wet behind the ears on the Elasticsearch product so bear with me. My goal is to stream data from AWS DynamoDB (via a AWS Kinesis stream) to my hosted Elasticsearch instance. I'm using the functionbea…

---

## [Filebeats not sending logs to Logstash to be viewed in stdout](https://discuss.elastic.co/t/filebeats-not-sending-logs-to-logstash-to-be-viewed-in-stdout/263051)

<div class="topic-metadata">

**Author:** [@Juunis](https://discuss.elastic.co/u/Juunis)\
**Replies:** 7\
**Last updated:** [February 3, 2021, 9:31pm UTC](https://discuss.elastic.co/t/filebeats-not-sending-logs-to-logstash-to-be-viewed-in-stdout/263051 "2021-02-03T21:31:48Z")

</div>

Hi guys I'm new to the Elastic stack and I'm currently trying to setup a quick and easy pipeline between Logstash and Filebeats where filebeat will send a test log file and logstash will display it on stdout. Currently n…

---

## [Socket, REST, or WebSocket API into Elastic?](https://discuss.elastic.co/t/socket-rest-or-websocket-api-into-elastic/263167)

<div class="topic-metadata">

**Author:** [@kmiklas](https://discuss.elastic.co/u/kmiklas)\
**Replies:** 1\
**Last updated:** [February 3, 2021, 8:58pm UTC](https://discuss.elastic.co/t/socket-rest-or-websocket-api-into-elastic/263167 "2021-02-03T20:58:08Z")

</div>

Hello All, Is there a way to push logs/metrics directly into Elastic without FB and LS? Imagine a process where I have a metric called "Price" for a NASDAQ security. I want to push the {"ticker": "MSFT", "price", 250.6…

---

## [Microsoft Graph Security API integration](https://discuss.elastic.co/t/microsoft-graph-security-api-integration/263074)

<div class="topic-metadata">

**Author:** [@opiedrah](https://discuss.elastic.co/u/opiedrah)\
**Replies:** 0\
**Last updated:** [February 3, 2021, 6:35am UTC](https://discuss.elastic.co/t/microsoft-graph-security-api-integration/263074 "2021-02-03T06:35:33Z")

</div>

Filebeat has an o365 module that connects to the Microsoft Management API. Does anyone if there are working or is there a connector available for the Microsoft Graph Security API Microsoft Graph Security API overview - …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=179)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=181)
