# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=182

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 183

---

## [Filebeat Bug: exclude\_lines](https://discuss.elastic.co/t/filebeat-bug-exclude-lines/262611)

<div class="topic-metadata">

**Author:** [@Peter\_Boos](https://discuss.elastic.co/u/Peter_Boos)\
**Replies:** 2\
**Last updated:** [January 29, 2021, 7:39pm UTC](https://discuss.elastic.co/t/filebeat-bug-exclude-lines/262611 "2021-01-29T19:39:49Z")

</div>

BUG report filebeat version : filebeat-7.10.1-2021.01.13-000001 problem : The exclude\_lines option in filebeat.yml does not work. Example item to be filtered out : 2021-01-27T02:08:31.775-0500#011INFO#011log/harvest…

---

## [Is my data just not conforming to the pipeline? Filebeat not processing iptables](https://discuss.elastic.co/t/is-my-data-just-not-conforming-to-the-pipeline-filebeat-not-processing-iptables/262259)

<div class="topic-metadata">

**Author:** [@rfischman](https://discuss.elastic.co/u/rfischman)\
**Replies:** 2\
**Last updated:** [January 29, 2021, 3:54pm UTC](https://discuss.elastic.co/t/is-my-data-just-not-conforming-to-the-pipeline-filebeat-not-processing-iptables/262259 "2021-01-29T15:54:00Z")

</div>

Hopefully the group can help me out here... I've got my network infrastructure (coming out of a unifi controller) sending syslog to a filebeat over UDP/514. The messages are iptables logs. I'm not seeing any of the me…

---

## [Monitor APIC on kubernetes using metricbeat](https://discuss.elastic.co/t/monitor-apic-on-kubernetes-using-metricbeat/261465)

<div class="topic-metadata">

**Author:** [@Sagar\_Naik](https://discuss.elastic.co/u/Sagar_Naik)\
**Replies:** 2\
**Last updated:** [January 29, 2021, 9:10am UTC](https://discuss.elastic.co/t/monitor-apic-on-kubernetes-using-metricbeat/261465 "2021-01-29T09:10:49Z")

</div>

I am getting 400 bad request while trying to configure metricbeat for monitoring kubernetes cluster deployed along with IBM API Connect. System information is displaying , but no kubernetes info , We need to monitor tr…

---

## [Api Key Help](https://discuss.elastic.co/t/api-key-help/262576)

<div class="topic-metadata">

**Author:** [@ukuleleplayer](https://discuss.elastic.co/u/ukuleleplayer)\
**Replies:** 0\
**Last updated:** [January 28, 2021, 10:34pm UTC](https://discuss.elastic.co/t/api-key-help/262576 "2021-01-28T22:34:48Z")

</div>

I apologize in advance, I'm new to auditbeat and could use some help. Basically, I'm trying to get just system logs from machines I'm monitoring. I previously had this working by just putting cloud.id and cloud.auth int…

---

## [CPU thread info metrics](https://discuss.elastic.co/t/cpu-thread-info-metrics/262536)

<div class="topic-metadata">

**Author:** [@Ishaan](https://discuss.elastic.co/u/Ishaan)\
**Replies:** 3\
**Last updated:** [January 28, 2021, 5:42pm UTC](https://discuss.elastic.co/t/cpu-thread-info-metrics/262536 "2021-01-28T17:42:50Z")

</div>

Hello, Is there any metrics that collects CPU thread related information. I couldn't find anything related to thread under cpu metricset fields. Thanks

---

## [Auditbeat service is not starting in Centos](https://discuss.elastic.co/t/auditbeat-service-is-not-starting-in-centos/262531)

<div class="topic-metadata">

**Author:** [@Sivapriya](https://discuss.elastic.co/u/Sivapriya)\
**Replies:** 0\
**Last updated:** [January 28, 2021, 4:25pm UTC](https://discuss.elastic.co/t/auditbeat-service-is-not-starting-in-centos/262531 "2021-01-28T16:25:32Z")

</div>

Host Info: I am running the service as a root user {"system\_info": {"host": {"architecture":"i686","boot\_time":"2020-03-06T07:06:21Z","containerized":false,"name","kernel\_version":"2.6.32-754.27.1.el6.i686","mac":\["00:…

---

## [MSSQL metric in windows](https://discuss.elastic.co/t/mssql-metric-in-windows/260197)

<div class="topic-metadata">

**Author:** [@rohan0018](https://discuss.elastic.co/u/rohan0018)\
**Replies:** 8\
**Last updated:** [January 28, 2021, 3:25pm UTC](https://discuss.elastic.co/t/mssql-metric-in-windows/260197 "2021-01-28T15:25:16Z")

</div>

I have installed metricbeat MSSQL module in windows, but when I enable MSSQL module metricbeat service auto stop. Metricbeat service worksonly if MSSQL module is disabled. Please help

---

## [Filebeat 7.10.1 cannot write to /var/log/filebeat](https://discuss.elastic.co/t/filebeat-7-10-1-cannot-write-to-var-log-filebeat/262419)

<div class="topic-metadata">

**Author:** [@matG](https://discuss.elastic.co/u/matG)\
**Replies:** 1\
**Last updated:** [January 28, 2021, 3:12pm UTC](https://discuss.elastic.co/t/filebeat-7-10-1-cannot-write-to-var-log-filebeat/262419 "2021-01-28T15:12:34Z")

</div>

Hi :slight\_smile: I am currently having an issue with filebeat. It is running and can connect to the kafka host although it is not creating /var/log/filebeat nor writing to it. Which I believe is key to then send the be…

---

## [Send to different indices with filebeat modules and ILM enabled](https://discuss.elastic.co/t/send-to-different-indices-with-filebeat-modules-and-ilm-enabled/262507)

<div class="topic-metadata">

**Author:** [@nber](https://discuss.elastic.co/u/nber)\
**Replies:** 0\
**Last updated:** [January 28, 2021, 1:43pm UTC](https://discuss.elastic.co/t/send-to-different-indices-with-filebeat-modules-and-ilm-enabled/262507 "2021-01-28T13:43:36Z")

</div>

Hey there, I'd like to collect logs on a device with different modules and send them to different indices. The question itself is answered in: Though, as far as I understand, this only works when ILM is disabled. Yet…

---

## [Problem with syslog in Fleet-Elastic agent-System Integration](https://discuss.elastic.co/t/problem-with-syslog-in-fleet-elastic-agent-system-integration/262464)

<div class="topic-metadata">

**Author:** [@bjarnej](https://discuss.elastic.co/u/bjarnej)\
**Replies:** 0\
**Last updated:** [January 28, 2021, 8:41am UTC](https://discuss.elastic.co/t/problem-with-syslog-in-fleet-elastic-agent-system-integration/262464 "2021-01-28T08:41:06Z")

</div>

I deployed an Elastic Agent 7.10.2 on Debian Linux using Fleet and the "System Integration", all metric logs disabled. Default the System integration will look in: /var/log/auth.log\* and /var/log/secure\* for "System au…

---

## ["failed parsing time field" + "failed using layout"](https://discuss.elastic.co/t/failed-parsing-time-field-failed-using-layout/262433)

<div class="topic-metadata">

**Author:** [@6NMgfDwZ3](https://discuss.elastic.co/u/6NMgfDwZ3)\
**Replies:** 0\
**Last updated:** [January 28, 2021, 12:23am UTC](https://discuss.elastic.co/t/failed-parsing-time-field-failed-using-layout/262433 "2021-01-28T00:23:08Z")

</div>

Hello, I am trying to convert a microseconds precision time field to @timestamp but I got error messages. A part of the Filebeat config lines, related to the issue: processors: - decode\_json\_fields: fields: \["…

---

## [All documents via Cylance module are failing to extract fields](https://discuss.elastic.co/t/all-documents-via-cylance-module-are-failing-to-extract-fields/262437)

<div class="topic-metadata">

**Author:** [@10FoyfBqA](https://discuss.elastic.co/u/10FoyfBqA)\
**Replies:** 0\
**Last updated:** [January 28, 2021, 1:54am UTC](https://discuss.elastic.co/t/all-documents-via-cylance-module-are-failing-to-extract-fields/262437 "2021-01-28T01:54:59Z")

</div>

I'm trying to configure the Cylance module in Filebeat, but it is not extracting any fields from log messages, and all documents have the value dissect\_parsing\_error in the log.flags. I have setup a filebeat collector l…

---

## [Jolokia agent id and name](https://discuss.elastic.co/t/jolokia-agent-id-and-name/262430)

<div class="topic-metadata">

**Author:** [@bucks](https://discuss.elastic.co/u/bucks)\
**Replies:** 0\
**Last updated:** [January 27, 2021, 11:40pm UTC](https://discuss.elastic.co/t/jolokia-agent-id-and-name/262430 "2021-01-27T23:40:05Z")

</div>

Hello All - We are trying Jolokia for capturing JVM metrics. When we configure Jolokia to receive data from multiple JVMs it is hard to identify the which JVM is sending the data. Jolokia documentation says that we hav…

---

## [Regular Expression on Env Var](https://discuss.elastic.co/t/regular-expression-on-env-var/262295)

<div class="topic-metadata">

**Author:** [@hQWeedEater](https://discuss.elastic.co/u/hQWeedEater)\
**Replies:** 1\
**Last updated:** [January 27, 2021, 5:08pm UTC](https://discuss.elastic.co/t/regular-expression-on-env-var/262295 "2021-01-27T17:08:17Z")

</div>

processors: - add\_fields: fields: custom\_value: "${COMPUTERNAME}" Is it possible to use regex on {COMPUTERNAME} to only return the first X characters or last X characters? I tried adding the above process…

---

## [Upper limits on Filebeat harvesting](https://discuss.elastic.co/t/upper-limits-on-filebeat-harvesting/262389)

<div class="topic-metadata">

**Author:** [@beirtipol](https://discuss.elastic.co/u/beirtipol)\
**Replies:** 0\
**Last updated:** [January 27, 2021, 3:38pm UTC](https://discuss.elastic.co/t/upper-limits-on-filebeat-harvesting/262389 "2021-01-27T15:38:31Z")

</div>

I have a system which produces separate log files of all RMI calls and SQL executions. This is very useful for tracing of client requests. The loggers are set to roll the file every 10mb, which equals 36,000 lines on ave…

---

## [Filebeat ships only the first path mentioned from filebeat.yml](https://discuss.elastic.co/t/filebeat-ships-only-the-first-path-mentioned-from-filebeat-yml/262388)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 0\
**Last updated:** [January 27, 2021, 3:35pm UTC](https://discuss.elastic.co/t/filebeat-ships-only-the-first-path-mentioned-from-filebeat-yml/262388 "2021-01-27T15:35:48Z")

</div>

Please find my filebeat conf. ################### Filebeat Configuration Example ################### # filebeat config for dco project # ############################# Filebeat ########…

---

## [Beat me if i'm wrong harvester info 302 and 333 has no use, how to turn off](https://discuss.elastic.co/t/beat-me-if-im-wrong-harvester-info-302-and-333-has-no-use-how-to-turn-off/262337)

<div class="topic-metadata">

**Author:** [@Peter\_Boos](https://discuss.elastic.co/u/Peter_Boos)\
**Replies:** 0\
**Last updated:** [January 27, 2021, 8:33am UTC](https://discuss.elastic.co/t/beat-me-if-im-wrong-harvester-info-302-and-333-has-no-use-how-to-turn-off/262337 "2021-01-27T08:33:35Z")

</div>

I test deployed ELK and installed filebeat. To see if there are interesting things mentioned in log files and manage it centrally. I already disabled the 30s update about filebeat state to much clutter imo. Another o…

---

## [Winlogbeat no longer logging to Logstash](https://discuss.elastic.co/t/winlogbeat-no-longer-logging-to-logstash/261267)

<div class="topic-metadata">

**Author:** [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Replies:** 2\
**Last updated:** [January 27, 2021, 8:50am UTC](https://discuss.elastic.co/t/winlogbeat-no-longer-logging-to-logstash/261267 "2021-01-27T08:50:11Z")

</div>

Hi, We had an instance where the disk space caused logging to stop over xmas which has now since been resolved. However, since then, 2 servers which are Server 2019 are no longer logging to Logstash \> Elastic. Winlogbe…

---

## [Filebeat is running but not sending logs to logstash](https://discuss.elastic.co/t/filebeat-is-running-but-not-sending-logs-to-logstash/262283)

<div class="topic-metadata">

**Author:** [@ats](https://discuss.elastic.co/u/ats)\
**Replies:** 1\
**Last updated:** [January 26, 2021, 11:09pm UTC](https://discuss.elastic.co/t/filebeat-is-running-but-not-sending-logs-to-logstash/262283 "2021-01-26T23:09:00Z")

</div>

Hi folks, I configured filebeat on a ubuntu instance in aws and sending logs to Logstash but it's not sending to Logstash. Here is my filebeat yml file # ---------------------------- Elasticsearch Output -------------…

---

## [Metricbeat AWS module endpoint not working correctly](https://discuss.elastic.co/t/metricbeat-aws-module-endpoint-not-working-correctly/261589)

<div class="topic-metadata">

**Author:** [@cjm3625](https://discuss.elastic.co/u/cjm3625)\
**Replies:** 8\
**Last updated:** [January 26, 2021, 8:43pm UTC](https://discuss.elastic.co/t/metricbeat-aws-module-endpoint-not-working-correctly/261589 "2021-01-26T20:43:56Z")

</div>

aws.yml is as follows regions: us-iso-east-1 endpoint: us-iso-east-1.c2s.ic.gov period: 5m metricsets: - ec2 The error is ListMetricsRequest failed: send request failed. followed by a proxy error driven by …

---

## [OAuth authentication](https://discuss.elastic.co/t/oauth-authentication/262081)

<div class="topic-metadata">

**Author:** [@atira](https://discuss.elastic.co/u/atira)\
**Replies:** 2\
**Last updated:** [January 26, 2021, 5:49pm UTC](https://discuss.elastic.co/t/oauth-authentication/262081 "2021-01-26T17:49:03Z")

</div>

Hi, Is it somehow possible to use 2-legged OAuth authentication, specifically client\_credentials and password type, with Heartbeat? The goal is to request a token by a single request to the oauth server, extract the to…

---

## [Filebeat error: Exiting: Error in initing input: the processor dissect doesn't exist](https://discuss.elastic.co/t/filebeat-error-exiting-error-in-initing-input-the-processor-dissect-doesnt-exist/262255)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [January 26, 2021, 4:16pm UTC](https://discuss.elastic.co/t/filebeat-error-exiting-error-in-initing-input-the-processor-dissect-doesnt-exist/262255 "2021-01-26T16:16:08Z")

</div>

I am getting this error when I start the filebeat container in kubernetes: 2021-01-26T15:59:47.358Z INFO input/input.go:88 Starting input of type: log; ID: 11352026245999945754 2021-01-26T15:59…

---

## [Unable to set custom index name in metricbeat taml file](https://discuss.elastic.co/t/unable-to-set-custom-index-name-in-metricbeat-taml-file/262252)

<div class="topic-metadata">

**Author:** [@navin1093](https://discuss.elastic.co/u/navin1093)\
**Replies:** 0\
**Last updated:** [January 26, 2021, 3:51pm UTC](https://discuss.elastic.co/t/unable-to-set-custom-index-name-in-metricbeat-taml-file/262252 "2021-01-26T15:51:11Z")

</div>

I tried to set custom index name however it was not working. below are my config setup.ilm.enabled: false output.elasticsearch.index: "%{\[metricset.name\]}-=-%{\[event.module\]}%{+yyyy.MM.dd}" setup.template.name: "%{…

---

## [How to filter out IP from auth.log](https://discuss.elastic.co/t/how-to-filter-out-ip-from-auth-log/262231)

<div class="topic-metadata">

**Author:** [@john8](https://discuss.elastic.co/u/john8)\
**Replies:** 0\
**Last updated:** [January 26, 2021, 1:23pm UTC](https://discuss.elastic.co/t/how-to-filter-out-ip-from-auth-log/262231 "2021-01-26T13:23:56Z")

</div>

hello newbie here I am running ELK on VMWare16 I need a little bit of help I have enabled the filebeat module called system but I am unable to get the clientip from there it falls under the message category Filebeat.y…

---

## [XML Logs in single-line challenge](https://discuss.elastic.co/t/xml-logs-in-single-line-challenge/262249)

<div class="topic-metadata">

**Author:** [@Igor\_Teresco](https://discuss.elastic.co/u/Igor_Teresco)\
**Replies:** 0\
**Last updated:** [January 26, 2021, 3:39pm UTC](https://discuss.elastic.co/t/xml-logs-in-single-line-challenge/262249 "2021-01-26T15:39:12Z")

</div>

Have some applications writing their logs as a single line XML files, no LF, no CR... Is there a way to get them uploaded by FileBeat to LogStash?

---

## [Dissect on a multiline message field](https://discuss.elastic.co/t/dissect-on-a-multiline-message-field/262122)

<div class="topic-metadata">

**Author:** [@abev](https://discuss.elastic.co/u/abev)\
**Replies:** 1\
**Last updated:** [January 26, 2021, 2:50pm UTC](https://discuss.elastic.co/t/dissect-on-a-multiline-message-field/262122 "2021-01-26T14:50:13Z")

</div>

I have a multiline message field and I have to extract a field with tokenizer from a starting point to the end of the line. How can I select as ending point the new line?

---

## [Setting up Metricbeat to pull Exchange Perfmon](https://discuss.elastic.co/t/setting-up-metricbeat-to-pull-exchange-perfmon/261845)

<div class="topic-metadata">

**Author:** [@zachswill](https://discuss.elastic.co/u/zachswill)\
**Replies:** 2\
**Last updated:** [January 26, 2021, 1:44pm UTC](https://discuss.elastic.co/t/setting-up-metricbeat-to-pull-exchange-perfmon/261845 "2021-01-26T13:44:07Z")

</div>

Trying to get Metricbeat to collect the exchange perfmon counters. Here is my current config. Any thoughts? I am getting counter not found. module: windows metricsets: \[perfmon\] period: 30s perfmon.ignore\_non\_existe…

---

## [Agents are running properly but no data in Data Stream](https://discuss.elastic.co/t/agents-are-running-properly-but-no-data-in-data-stream/260111)

<div class="topic-metadata">

**Author:** [@nomoneynoproblems](https://discuss.elastic.co/u/nomoneynoproblems)\
**Replies:** 16\
**Last updated:** [January 26, 2021, 1:35pm UTC](https://discuss.elastic.co/t/agents-are-running-properly-but-no-data-in-data-stream/260111 "2021-01-26T13:35:23Z")

</div>

Using Elastic Cloud I'm not seeing any data in the data stream section even though a test "Rails Prod" server is showing "Online".

---

## [Filebeat multiline.pattern set up](https://discuss.elastic.co/t/filebeat-multiline-pattern-set-up/262229)

<div class="topic-metadata">

**Author:** [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Replies:** 0\
**Last updated:** [January 26, 2021, 12:45pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-set-up/262229 "2021-01-26T12:45:18Z")

</div>

I have to ingest a text file with multilines running filebeat 7.1.1. But the format is different from anything I've had so far. Here below is an example. Each line starts with timestamp+loglevel+"\[stderr\]"+ "(componen…

---

## [On startup run filebeat restart upon fail](https://discuss.elastic.co/t/on-startup-run-filebeat-restart-upon-fail/262204)

<div class="topic-metadata">

**Author:** [@Peter\_Boos](https://discuss.elastic.co/u/Peter_Boos)\
**Replies:** 6\
**Last updated:** [January 26, 2021, 10:51am UTC](https://discuss.elastic.co/t/on-startup-run-filebeat-restart-upon-fail/262204 "2021-01-26T10:51:21Z")

</div>

On a test machine with Debian 10 with a desktop, filebeat did not startup after a hard VM reset. I would like to be sure that on Debian systems with a desktop and headless systems this service restart it self upon failu…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=181)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=183)
