# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=181

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 182

---

## [App\_insights data configuration \[AZURE \]](https://discuss.elastic.co/t/app-insights-data-configuration-azure/263166)

<div class="topic-metadata">

**Author:** [@miki\_haiat](https://discuss.elastic.co/u/miki_haiat)\
**Replies:** 0\
**Last updated:** [February 3, 2021, 8:22pm UTC](https://discuss.elastic.co/t/app-insights-data-configuration-azure/263166 "2021-02-03T20:22:42Z")

</div>

Im trying to configure and ingest data from azure to elastic cloud I generated an API key as the docs suggested and setup the metrics list as you can see below. I can see that Azure dashboards have been loaded successf…

---

## [Filebeat keystore permissions](https://discuss.elastic.co/t/filebeat-keystore-permissions/262962)

<div class="topic-metadata">

**Author:** [@Coyz](https://discuss.elastic.co/u/Coyz)\
**Replies:** 0\
**Last updated:** [February 2, 2021, 10:58am UTC](https://discuss.elastic.co/t/filebeat-keystore-permissions/262962 "2021-02-02T10:58:12Z")

</div>

Hello, i'm trying to setup filebeat as non root user. Here the service file ; \[Unit\] Description=Filebeat sends log files to Logstash or directly to Elasticsearch. Documentation=https://www.elastic.co/products/beats/f…

---

## [Recovered from panic while fetching 'azure/app\_insights' for host ''. \[AZURE\]](https://discuss.elastic.co/t/recovered-from-panic-while-fetching-azure-app-insights-for-host-azure/263113)

<div class="topic-metadata">

**Author:** [@miki\_haiat](https://discuss.elastic.co/u/miki_haiat)\
**Replies:** 0\
**Last updated:** [February 3, 2021, 11:19am UTC](https://discuss.elastic.co/t/recovered-from-panic-while-fetching-azure-app-insights-for-host-azure/263113 "2021-02-03T11:19:06Z")

</div>

Hey, I'm trying to send app\_insights metric via metric beat to elastic. I can't see any reference to 'host' in the app\_insight docs Any suggestion on how to solve this panic error I found the cause of the error, wh…

---

## [Incorrect regexp reaction](https://discuss.elastic.co/t/incorrect-regexp-reaction/263001)

<div class="topic-metadata">

**Author:** [@dmalchikov](https://discuss.elastic.co/u/dmalchikov)\
**Replies:** 3\
**Last updated:** [February 3, 2021, 1:17pm UTC](https://discuss.elastic.co/t/incorrect-regexp-reaction/263001 "2021-02-03T13:17:07Z")

</div>

Hi! Using ELK 7.10 Tried different terms but result always go through My winlogbeat.yml: ...... '- name: Windows PowerShell event\_id: 400, 403, 600, 800 processors: - drop\_event.when.or: - regexp.process.command\_l…

---

## [Filebeat o365 module - Parsing o365.audit.data field](https://discuss.elastic.co/t/filebeat-o365-module-parsing-o365-audit-data-field/261591)

<div class="topic-metadata">

**Author:** [@opiedrah](https://discuss.elastic.co/u/opiedrah)\
**Replies:** 4\
**Last updated:** [February 3, 2021, 12:24pm UTC](https://discuss.elastic.co/t/filebeat-o365-module-parsing-o365-audit-data-field/261591 "2021-02-03T12:24:52Z")

</div>

Hi, I have filebeat 7.10 running with module o365 beat. Similar to how extendedproperties filed for azure active directory workload is parsed. How can i parse this o365.audit.data filed. the value in this field looks…

---

## [Pushing different types of (access, application) logs using filebeat-daemonset in Kubernetes](https://discuss.elastic.co/t/pushing-different-types-of-access-application-logs-using-filebeat-daemonset-in-kubernetes/261353)

<div class="topic-metadata">

**Author:** [@JasminShah](https://discuss.elastic.co/u/JasminShah)\
**Replies:** 2\
**Last updated:** [February 3, 2021, 11:43am UTC](https://discuss.elastic.co/t/pushing-different-types-of-access-application-logs-using-filebeat-daemonset-in-kubernetes/261353 "2021-02-03T11:43:54Z")

</div>

I have several pods running spring-boot applications, writing application-logs to stdout, which is then picked up by filebeat-daemonset and then pushed to elasticsearch. (standard logging architecture for kubernetes) No…

---

## [Packetbeat handle error when exec show databases](https://discuss.elastic.co/t/packetbeat-handle-error-when-exec-show-databases/262469)

<div class="topic-metadata">

**Author:** [@282857484](https://discuss.elastic.co/u/282857484)\
**Replies:** 3\
**Last updated:** [February 3, 2021, 10:28am UTC](https://discuss.elastic.co/t/packetbeat-handle-error-when-exec-show-databases/262469 "2021-02-03T10:28:22Z")

</div>

Version: master(newest) Operating System: macos 11.1 Steps to Reproduce: env:mysql5.7,mysql8.0 packetbeat when exec "show databases" then the program will never recovery. because the var complete return false,and…

---

## [MetricBeat error](https://discuss.elastic.co/t/metricbeat-error/262153)

<div class="topic-metadata">

**Author:** [@cloudenv](https://discuss.elastic.co/u/cloudenv)\
**Replies:** 7\
**Last updated:** [January 28, 2021, 3:52pm UTC](https://discuss.elastic.co/t/metricbeat-error/262153 "2021-01-28T15:52:46Z")

</div>

Ok will try to be civil here, but 'd be hard as Im furious. Have spent all f\* day tryting to setup Kibana ( cloud / self ) Am trying to configure metricbeat using this. Im getting Anyone? PS: why all texts here are…

---

## [Filebeat not starting](https://discuss.elastic.co/t/filebeat-not-starting/263076)

<div class="topic-metadata">

**Author:** [@Kaushal\_Kishore1](https://discuss.elastic.co/u/Kaushal_Kishore1)\
**Replies:** 0\
**Last updated:** [February 3, 2021, 6:45am UTC](https://discuss.elastic.co/t/filebeat-not-starting/263076 "2021-02-03T06:45:20Z")

</div>

my filebeat.yaml filebeat.inputs: - type: log paths: - /var/log/apache2/whatfix\_access.log tags: \["apache"\] - type: log paths: - /usr/lib/quickonutch/logs/quickoapi.20\* tags: \["api"\] multiline.pattern: '^…

---

## [Filebeat hint based autodiscover on Openshift/Kubernetes](https://discuss.elastic.co/t/filebeat-hint-based-autodiscover-on-openshift-kubernetes/263019)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 0\
**Last updated:** [February 2, 2021, 5:50pm UTC](https://discuss.elastic.co/t/filebeat-hint-based-autodiscover-on-openshift-kubernetes/263019 "2021-02-02T17:50:03Z")

</div>

Hi folks, I am using following filebeat configuration (7.10). Filebeat is running on openshift: filebeat.autodiscover: providers: - type: kubernetes node: ${NODE\_NAME} hints.enabled: true hints.…

---

## [Status/progress API for filebeat](https://discuss.elastic.co/t/status-progress-api-for-filebeat/262994)

<div class="topic-metadata">

**Author:** [@jnc943](https://discuss.elastic.co/u/jnc943)\
**Replies:** 1\
**Last updated:** [February 2, 2021, 6:56pm UTC](https://discuss.elastic.co/t/status-progress-api-for-filebeat/262994 "2021-02-02T18:56:50Z")

</div>

Hi, I am familiar with https://www.elastic.co/guide/en/beats/filebeat/current/http-endpoint.html but it is too low level for my use case. I would like to be able to drop a bundle of files in a directory that is watched …

---

## [Filebeat Microsoft Module support for Microsoft Defender for Office 365?](https://discuss.elastic.co/t/filebeat-microsoft-module-support-for-microsoft-defender-for-office-365/263018)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [February 2, 2021, 5:46pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-support-for-microsoft-defender-for-office-365/263018 "2021-02-02T17:46:08Z")

</div>

Hello, I was wondering if the following Filebeat module also works for Microsoft Defender for Office 365 (https://www.microsoft.com/en/microsoft-365/security/office-365-defender)? Best regards, Willem

---

## [Metric output to elasticsearch via filebeat](https://discuss.elastic.co/t/metric-output-to-elasticsearch-via-filebeat/262560)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 3\
**Last updated:** [February 2, 2021, 4:58pm UTC](https://discuss.elastic.co/t/metric-output-to-elasticsearch-via-filebeat/262560 "2021-02-02T16:58:01Z")

</div>

I have a question related to metrics collection. The application writes metric data into a file. Can filebeat pickup this information say using log or filestream input and send it to elasticsearch ? What would be the d…

---

## [FileBeat Gsuite module deprecated?](https://discuss.elastic.co/t/filebeat-gsuite-module-deprecated/262939)

<div class="topic-metadata">

**Author:** [@ido](https://discuss.elastic.co/u/ido)\
**Replies:** 2\
**Last updated:** [February 2, 2021, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-gsuite-module-deprecated/262939 "2021-02-02T14:04:44Z")

</div>

TL;DR - gsuite module does not send logs although it seems that I've done everything right (more details in the post). I looked at the source code and there was a comment saying "Gsuite module is deprecated... use Google…

---

## [Filebeat - support for API keys in Logstash outputs](https://discuss.elastic.co/t/filebeat-support-for-api-keys-in-logstash-outputs/262981)

<div class="topic-metadata">

**Author:** [@vigneshr35](https://discuss.elastic.co/u/vigneshr35)\
**Replies:** 0\
**Last updated:** [February 2, 2021, 1:16pm UTC](https://discuss.elastic.co/t/filebeat-support-for-api-keys-in-logstash-outputs/262981 "2021-02-02T13:16:50Z")

</div>

Hi, I see that support for API keys in Elasticsearch outputs was provided starting from release 7.6.0. Do we have similar support added for API keys in Logstash outputs? I don't see it in the documentation. So, my unde…

---

## [Unable to create pipeline for nginx](https://discuss.elastic.co/t/unable-to-create-pipeline-for-nginx/262858)

<div class="topic-metadata">

**Author:** [@yukpun](https://discuss.elastic.co/u/yukpun)\
**Replies:** 3\
**Last updated:** [February 2, 2021, 9:38am UTC](https://discuss.elastic.co/t/unable-to-create-pipeline-for-nginx/262858 "2021-02-02T09:38:50Z")

</div>

For some reason, nginx logs stopped going to elastick stack. I checked status, and I see this: ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 Failed to connect to backoff(elasticsearch(http://elastic-server:92…

---

## [Unable to have data in kibana from filebeat](https://discuss.elastic.co/t/unable-to-have-data-in-kibana-from-filebeat/262534)

<div class="topic-metadata">

**Author:** [@Jean-P](https://discuss.elastic.co/u/Jean-P)\
**Replies:** 2\
**Last updated:** [February 2, 2021, 9:29am UTC](https://discuss.elastic.co/t/unable-to-have-data-in-kibana-from-filebeat/262534 "2021-02-02T09:29:50Z")

</div>

Hello, Actually, I tried to use Filebeat to transmit my logs to elastcisearch to have data in kibana. But I receive no data in Kibana. Here is my config file for Filebeat: filebeat.yml: filebeat.inputs: type: log …

---

## [Filebeat System module not sending process name when using Logstash as a output](https://discuss.elastic.co/t/filebeat-system-module-not-sending-process-name-when-using-logstash-as-a-output/262844)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 5\
**Last updated:** [February 2, 2021, 8:13am UTC](https://discuss.elastic.co/t/filebeat-system-module-not-sending-process-name-when-using-logstash-as-a-output/262844 "2021-02-02T08:13:40Z")

</div>

I am using filebeat system module to send syslog data to Elasticsearch and it is working fine, even the default dashboard is also working fine. However, while I use Logstash as the output, it is not sending few fields su…

---

## [Filter events by source using REGEXP](https://discuss.elastic.co/t/filter-events-by-source-using-regexp/262918)

<div class="topic-metadata">

**Author:** [@NadyLeez123](https://discuss.elastic.co/u/NadyLeez123)\
**Replies:** 0\
**Last updated:** [February 2, 2021, 1:20am UTC](https://discuss.elastic.co/t/filter-events-by-source-using-regexp/262918 "2021-02-02T01:20:52Z")

</div>

Hello, I'm working on a winlogbeat.yml. I want to filter event by events providers. I am using the REGEXP property so that all the events that would not begin as specified , would just be dropped. I'm so new to ELK. He…

---

## [Winlogbeat Filtering Issue](https://discuss.elastic.co/t/winlogbeat-filtering-issue/261695)

<div class="topic-metadata">

**Author:** [@jcor](https://discuss.elastic.co/u/jcor)\
**Replies:** 3\
**Last updated:** [February 2, 2021, 1:51am UTC](https://discuss.elastic.co/t/winlogbeat-filtering-issue/261695 "2021-02-02T01:51:01Z")

</div>

Hi folks, I've run into a weird issue. I have two separate clusters. One is my personal lab and the other is a dev lab. I'm trying to drop a specific winlogevent id as sysmon is very noisey and not required for what I a…

---

## [ES Cannot Index Monitoring Indices](https://discuss.elastic.co/t/es-cannot-index-monitoring-indices/262695)

<div class="topic-metadata">

**Author:** [@lnorman](https://discuss.elastic.co/u/lnorman)\
**Replies:** 4\
**Last updated:** [February 1, 2021, 8:57pm UTC](https://discuss.elastic.co/t/es-cannot-index-monitoring-indices/262695 "2021-02-01T20:57:48Z")

</div>

I am trying to turn on stack monitoring, however, metricbeat keeps logging something that starts like this: WARN \[elasticsearch\] elasticsearch/client.go:408 Cannot index event publisher.Event and in…

---

## [Elastic SIEM alerts + auditbeats - only few are working fine](https://discuss.elastic.co/t/elastic-siem-alerts-auditbeats-only-few-are-working-fine/262810)

<div class="topic-metadata">

**Author:** [@Orion](https://discuss.elastic.co/u/Orion)\
**Replies:** 2\
**Last updated:** [February 1, 2021, 8:16pm UTC](https://discuss.elastic.co/t/elastic-siem-alerts-auditbeats-only-few-are-working-fine/262810 "2021-02-01T20:16:21Z")

</div>

Hello, first post in the forum, since using free Elastic licence, would like to seek for some support in the discussion board. Currently I'm experimenting on SIEM \> Detections module, have Elastic stack installed on one…

---

## [How to custom the fetch metrics by docker containers?](https://discuss.elastic.co/t/how-to-custom-the-fetch-metrics-by-docker-containers/262836)

<div class="topic-metadata">

**Author:** [@MatteoM](https://discuss.elastic.co/u/MatteoM)\
**Replies:** 1\
**Last updated:** [February 1, 2021, 7:31pm UTC](https://discuss.elastic.co/t/how-to-custom-the-fetch-metrics-by-docker-containers/262836 "2021-02-01T19:31:14Z")

</div>

Hi to everyone! I'm new to kibana and elasticsearch. I've seen that in kibana is possible to fetch metrics by docker containers. How can i custum this metric to fetch the consumption disk space of a container ? And i…

---

## [Filebeat to GCP PubSub](https://discuss.elastic.co/t/filebeat-to-gcp-pubsub/262859)

<div class="topic-metadata">

**Author:** [@MMH](https://discuss.elastic.co/u/MMH)\
**Replies:** 0\
**Last updated:** [February 1, 2021, 4:08pm UTC](https://discuss.elastic.co/t/filebeat-to-gcp-pubsub/262859 "2021-02-01T16:08:20Z")

</div>

I want to setup the environment similar to this: but to use GCP PubSub instead of Kafka. I know, that Filebeat does not have a PubSub output. What is the easiest way to achieve this? I know, that Logstash can be use…

---

## [How to collect \`dmesg\` outputs - or those logs are useless?](https://discuss.elastic.co/t/how-to-collect-dmesg-outputs-or-those-logs-are-useless/262714)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 2\
**Last updated:** [February 1, 2021, 2:08pm UTC](https://discuss.elastic.co/t/how-to-collect-dmesg-outputs-or-those-logs-are-useless/262714 "2021-02-01T14:08:54Z")

</div>

Hi thanks for the lib! I wonder (1) whether I should collect dmesg outputs? Are they useful or useless? In addition, I wonder how can I collect them using Filebeat? Thanks!

---

## [How to let Functionbeat write to multiple indices](https://discuss.elastic.co/t/how-to-let-functionbeat-write-to-multiple-indices/262614)

<div class="topic-metadata">

**Author:** [@yahya92](https://discuss.elastic.co/u/yahya92)\
**Replies:** 2\
**Last updated:** [February 1, 2021, 1:11pm UTC](https://discuss.elastic.co/t/how-to-let-functionbeat-write-to-multiple-indices/262614 "2021-02-01T13:11:43Z")

</div>

Hello Is there a way to let Functionbeat write to multiple indices? I have seen that it can write to only one of many indices according to defined rules. Example: output.elasticsearch: indices: - index: "index-firs…

---

## [How to get only one field from elasticsearch in the output](https://discuss.elastic.co/t/how-to-get-only-one-field-from-elasticsearch-in-the-output/261379)

<div class="topic-metadata">

**Author:** [@devil\_hacks](https://discuss.elastic.co/u/devil_hacks)\
**Replies:** 2\
**Last updated:** [January 30, 2021, 6:18pm UTC](https://discuss.elastic.co/t/how-to-get-only-one-field-from-elasticsearch-in-the-output/261379 "2021-01-30T18:18:41Z")

</div>

I am having my log data pushed into elasticssearch looks like given below: { "took": 5, "timed\_out": false, "\_shards": { "total": 1, "successful": 1, "skipped": 0, "failed": 0 }…

---

## [Metricbeat/mysql module data not showing](https://discuss.elastic.co/t/metricbeat-mysql-module-data-not-showing/262648)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 2\
**Last updated:** [January 30, 2021, 1:15pm UTC](https://discuss.elastic.co/t/metricbeat-mysql-module-data-not-showing/262648 "2021-01-30T13:15:32Z")

</div>

I have the mysql module enabled on a number of mysql hosts. I see this appearing in the logs: "metricbeat":{"mysql":{"status":{"events":7,"success":7}}} When I go to kibana and search for mysql I don't see any values i…

---

## [vSphere module fields](https://discuss.elastic.co/t/vsphere-module-fields/262692)

<div class="topic-metadata">

**Author:** [@Ishaan](https://discuss.elastic.co/u/Ishaan)\
**Replies:** 2\
**Last updated:** [January 29, 2021, 10:34pm UTC](https://discuss.elastic.co/t/vsphere-module-fields/262692 "2021-01-29T22:34:34Z")

</div>

I read somewhere that the vSphere module is in beta version. Is that true? Is there a plan to collect more metrics in vSphere module as the current fields are very limited?

---

## [Is it possible to add to @metadata in Filebeat?](https://discuss.elastic.co/t/is-it-possible-to-add-to-metadata-in-filebeat/262561)

<div class="topic-metadata">

**Author:** [@Alex\_Nelson](https://discuss.elastic.co/u/Alex_Nelson)\
**Replies:** 6\
**Last updated:** [January 29, 2021, 9:21pm UTC](https://discuss.elastic.co/t/is-it-possible-to-add-to-metadata-in-filebeat/262561 "2021-01-29T21:21:05Z")

</div>

I have the following processors: - add\_fields: target: '@metadata' fields: index\_prefix: 'flow\_metadata\_event' which gives me the following using output.console (note there are 2 object …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=180)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=182)
