# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=184

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 185

---

## [Cannot ship ssh logs from filebeat to logstash](https://discuss.elastic.co/t/cannot-ship-ssh-logs-from-filebeat-to-logstash/261575)

<div class="topic-metadata">

**Author:** [@john8](https://discuss.elastic.co/u/john8)\
**Replies:** 3\
**Last updated:** [January 21, 2021, 3:44am UTC](https://discuss.elastic.co/t/cannot-ship-ssh-logs-from-filebeat-to-logstash/261575 "2021-01-21T03:44:36Z")

</div>

I sent syslog from filebeat to logstash it appeared in kibana as well then when I changed the path of the log file to /var/logs/auth.log it did not work. My main goal is to visualize the ssh logs. Thanks in advance.

---

## [Elastic-agent fleet apache integration illegal\_argument\_exception](https://discuss.elastic.co/t/elastic-agent-fleet-apache-integration-illegal-argument-exception/261644)

<div class="topic-metadata">

**Author:** [@gregorys](https://discuss.elastic.co/u/gregorys)\
**Replies:** 2\
**Last updated:** [January 20, 2021, 8:35pm UTC](https://discuss.elastic.co/t/elastic-agent-fleet-apache-integration-illegal-argument-exception/261644 "2021-01-20T20:35:52Z")

</div>

Hi, Running on 7.10.2. I have added the "Apache" integration to collect only logfiles, not metrics. When I go to discover to browse the logs-\* index, these errors appear: 1 of 8 shards failed ## illegal\_argument\_exce…

---

## [Unable to limit FileBeat fields](https://discuss.elastic.co/t/unable-to-limit-filebeat-fields/261405)

<div class="topic-metadata">

**Author:** [@ChrisaT](https://discuss.elastic.co/u/ChrisaT)\
**Replies:** 2\
**Last updated:** [January 20, 2021, 5:50pm UTC](https://discuss.elastic.co/t/unable-to-limit-filebeat-fields/261405 "2021-01-20T17:50:27Z")

</div>

Good morning, a housekeeping question We are processing data from a number of API's using Filebeat. The fields we define are working fine but what we have found is that field for all modules are also being added. The in…

---

## [Create custom fields for each host in heartbeat.yml](https://discuss.elastic.co/t/create-custom-fields-for-each-host-in-heartbeat-yml/261410)

<div class="topic-metadata">

**Author:** [@anjana1](https://discuss.elastic.co/u/anjana1)\
**Replies:** 3\
**Last updated:** [January 20, 2021, 3:40am UTC](https://discuss.elastic.co/t/create-custom-fields-for-each-host-in-heartbeat-yml/261410 "2021-01-20T03:40:49Z")

</div>

I am trying to combine my heartbeat visualization with APM visualization in same dashboards. Since the field names are not similar, the filter wont work correctly. So I was thinking of creating similar field names and la…

---

## [Can filebeat be can initialed using initcontiner to forward logs](https://discuss.elastic.co/t/can-filebeat-be-can-initialed-using-initcontiner-to-forward-logs/261649)

<div class="topic-metadata">

**Author:** [@srini54](https://discuss.elastic.co/u/srini54)\
**Replies:** 0\
**Last updated:** [January 20, 2021, 12:54pm UTC](https://discuss.elastic.co/t/can-filebeat-be-can-initialed-using-initcontiner-to-forward-logs/261649 "2021-01-20T12:54:48Z")

</div>

We are exloring options to trigger the filebeat process as part of an initContainer to push the tomcat logs. Is it possible to initialize scirpt to copy tomcat log to another volume and push it to logstash/elastic. Plea…

---

## [Elastic Agent service stops after launching but doesn't throw any error in command line](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547)

<div class="topic-metadata">

**Author:** [@icious](https://discuss.elastic.co/u/icious)\
**Replies:** 9\
**Last updated:** [January 20, 2021, 11:48am UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547 "2021-01-20T11:48:27Z")

</div>

Hi, I set up a Fleet environment and tested multiple integrations of Elastic Agent on Linux and Windows machines without any problem, but there is a specific Windows machine where it does not work, and I couldn't find t…

---

## [Endpoint Agent two host showing in logs-\* per host](https://discuss.elastic.co/t/endpoint-agent-two-host-showing-in-logs-per-host/261551)

<div class="topic-metadata">

**Author:** [@The1WhoPrtNocks](https://discuss.elastic.co/u/The1WhoPrtNocks)\
**Replies:** 2\
**Last updated:** [January 20, 2021, 10:58am UTC](https://discuss.elastic.co/t/endpoint-agent-two-host-showing-in-logs-per-host/261551 "2021-01-20T10:58:51Z")

</div>

Re-created with elastic-agent tag for better visibility. Hi, I have recently been rolling out the Endpoint agent to some host for testing. Within the fleet agents tab, there is a single entry for each host in the form…

---

## [Filbeat not publishing logs to logstash](https://discuss.elastic.co/t/filbeat-not-publishing-logs-to-logstash/261578)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 1\
**Last updated:** [January 20, 2021, 9:13am UTC](https://discuss.elastic.co/t/filbeat-not-publishing-logs-to-logstash/261578 "2021-01-20T09:13:06Z")

</div>

filebeat logs 2021-01-19T17:07:14.953Z INFO \[publisher\_pipeline\_output\] pipeline/output.go:151 Connection to backoff(async(tcp://logsrv.example-elk.local:5044)) established 2021-01-19T17:07:14.978Z …

---

## [I/o timeout filebeat when send data to logstash](https://discuss.elastic.co/t/i-o-timeout-filebeat-when-send-data-to-logstash/261412)

<div class="topic-metadata">

**Author:** [@Eti\_Huri](https://discuss.elastic.co/u/Eti_Huri)\
**Replies:** 4\
**Last updated:** [January 20, 2021, 7:49am UTC](https://discuss.elastic.co/t/i-o-timeout-filebeat-when-send-data-to-logstash/261412 "2021-01-20T07:49:27Z")

</div>

Hi all:) I have my logstash vm and my application vm, they don't run in the same subnet I am trying send logs from my vm application to logstash vm this is my filebeat.yml filebeat.inputs: - type: log p…

---

## [Metricbeat prometheus module collector metricset escaping](https://discuss.elastic.co/t/metricbeat-prometheus-module-collector-metricset-escaping/261100)

<div class="topic-metadata">

**Author:** [@4orty](https://discuss.elastic.co/u/4orty)\
**Replies:** 4\
**Last updated:** [January 20, 2021, 5:09am UTC](https://discuss.elastic.co/t/metricbeat-prometheus-module-collector-metricset-escaping/261100 "2021-01-20T05:09:29Z")

</div>

Hi, i'm using metricbeat 7.10.1 and i want to get data with prometheus module(golang prometheus client) and send data to kafka output. Here's my yaml file. metricbeat.yml: |- metricbeat.autodiscover: provid…

---

## [Metricbeat/K8s: "error getting group status: open /proc/\<PID\>/cgroup"](https://discuss.elastic.co/t/metricbeat-k8s-error-getting-group-status-open-proc-pid-cgroup/255371)

<div class="topic-metadata">

**Author:** [@jwhitehead](https://discuss.elastic.co/u/jwhitehead)\
**Replies:** 9\
**Last updated:** [January 20, 2021, 1:17am UTC](https://discuss.elastic.co/t/metricbeat-k8s-error-getting-group-status-open-proc-pid-cgroup/255371 "2021-01-20T01:17:18Z")

</div>

Running Metricbeat on AKS v1.16.3, seeing the following error in logs: instance/metrics.go:285 error getting group status: open /proc/\<PID\>/cgroup: no such file or directory" I'm new to beats and, after several hours o…

---

## [Is that possible to replace @timestamp during parse data via Filebeat](https://discuss.elastic.co/t/is-that-possible-to-replace-timestamp-during-parse-data-via-filebeat/261500)

<div class="topic-metadata">

**Author:** [@GL\_Choong](https://discuss.elastic.co/u/GL_Choong)\
**Replies:** 2\
**Last updated:** [January 19, 2021, 11:57pm UTC](https://discuss.elastic.co/t/is-that-possible-to-replace-timestamp-during-parse-data-via-filebeat/261500 "2021-01-19T23:57:03Z")

</div>

Would like to get advise from all expert. Currently I\`m working on a project. But having issue on @Timestamp that generated by Kibana is event\_timestamp which expected the timestamp grab from log which example as below …

---

## [Message looks like it is binary when using inputs.d](https://discuss.elastic.co/t/message-looks-like-it-is-binary-when-using-inputs-d/261559)

<div class="topic-metadata">

**Author:** [@gungazoo](https://discuss.elastic.co/u/gungazoo)\
**Replies:** 1\
**Last updated:** [January 19, 2021, 4:57pm UTC](https://discuss.elastic.co/t/message-looks-like-it-is-binary-when-using-inputs-d/261559 "2021-01-19T16:57:44Z")

</div>

If I have filebeat.yml file follow a file and send it to Elasticsearch it seems to work fine but if I use the inputs.d format then the message looks like it is binary. It could just be a font problem. I don't understan…

---

## [Filebeat is not reading the log file in real time](https://discuss.elastic.co/t/filebeat-is-not-reading-the-log-file-in-real-time/261270)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 13\
**Last updated:** [January 19, 2021, 4:00pm UTC](https://discuss.elastic.co/t/filebeat-is-not-reading-the-log-file-in-real-time/261270 "2021-01-19T16:00:40Z")

</div>

Hello Team, We setup new elasticsearch cluster with version 7.10 and beats version is also 7.10. When we setup the cluster it was working fine and we were getting the logs on kibana dashboard in real time. But now we …

---

## [\[Winlogbeat 7.10.1 dashboards\]: could not locate some index pattern fields](https://discuss.elastic.co/t/winlogbeat-7-10-1-dashboards-could-not-locate-some-index-pattern-fields/259961)

<div class="topic-metadata">

**Author:** [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Replies:** 5\
**Last updated:** [January 19, 2021, 3:28pm UTC](https://discuss.elastic.co/t/winlogbeat-7-10-1-dashboards-could-not-locate-some-index-pattern-fields/259961 "2021-01-19T15:28:17Z")

</div>

Hello, I am using Elasticsearch, kibana and winlogbeat, all version 7.10.1 I configured winlogbeat and run: .\\winlogbeat.exe setup -e and I had no error in my winlogbeat logs, but in kibana there are some dashboards wo…

---

## [Add\_kubernetes\_metadata with input type log](https://discuss.elastic.co/t/add-kubernetes-metadata-with-input-type-log/261448)

<div class="topic-metadata">

**Author:** [@Vladimir\_Rimar](https://discuss.elastic.co/u/Vladimir_Rimar)\
**Replies:** 4\
**Last updated:** [January 19, 2021, 1:32pm UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-with-input-type-log/261448 "2021-01-19T13:32:12Z")

</div>

I'm using filebeat as a side-car container, having input type log. I have also configured: processors: - add\_kubernetes\_metadata: in\_cluster: true but I'm not getting any metadata like pod, name…

---

## [Filebeat doesn't send logs to Elasticsearch](https://discuss.elastic.co/t/filebeat-doesnt-send-logs-to-elasticsearch/259228)

<div class="topic-metadata">

**Author:** [@Pawel\_Skadorwa](https://discuss.elastic.co/u/Pawel_Skadorwa)\
**Replies:** 7\
**Last updated:** [January 19, 2021, 10:21am UTC](https://discuss.elastic.co/t/filebeat-doesnt-send-logs-to-elasticsearch/259228 "2021-01-19T10:21:15Z")

</div>

Hi, I decided to talk to you because I have no idea how to resolve the problem with the logging stack. On kubernetes 1.19 I installed elasticsearch 7.10.1, kibana, metricbeat and filebeat in the same version. Connection…

---

## [Ingressing Palo Alto logs thru syslog](https://discuss.elastic.co/t/ingressing-palo-alto-logs-thru-syslog/261456)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 2\
**Last updated:** [January 19, 2021, 10:01am UTC](https://discuss.elastic.co/t/ingressing-palo-alto-logs-thru-syslog/261456 "2021-01-19T10:01:00Z")

</div>

Hello I am trying to ingress Palo Alto logs using the module but I cannot get it to work. I have the pipeline enabled as I go to http://elasticsearchserver:9200/\_ingest/pipeline and I see Pipeline for Palo Alto Network…

---

## [No stdout and logs from Packetbeat](https://discuss.elastic.co/t/no-stdout-and-logs-from-packetbeat/261517)

<div class="topic-metadata">

**Author:** [@GabrielJuilien](https://discuss.elastic.co/u/GabrielJuilien)\
**Replies:** 0\
**Last updated:** [January 19, 2021, 9:21am UTC](https://discuss.elastic.co/t/no-stdout-and-logs-from-packetbeat/261517 "2021-01-19T09:21:57Z")

</div>

Hi everyone, I am having trouble to setup Packetbeat on my client Windows. I already have som other Beats running and working as intended. The thing is I am getting no sdtout output in PowerShell when trying to run pac…

---

## [Is it possible set multiple pipeline a ingest pipeline](https://discuss.elastic.co/t/is-it-possible-set-multiple-pipeline-a-ingest-pipeline/261484)

<div class="topic-metadata">

**Author:** [@sungjin.kim](https://discuss.elastic.co/u/sungjin.kim)\
**Replies:** 3\
**Last updated:** [January 19, 2021, 6:03am UTC](https://discuss.elastic.co/t/is-it-possible-set-multiple-pipeline-a-ingest-pipeline/261484 "2021-01-19T06:03:59Z")

</div>

Hi friendly folks, I am planning to send various formatted logs to elastic cloud through ingest pipeline. I read many references regarding configuring filebeat.yml. it's likely that only one pipeline's possible. I…

---

## [Exiting: error loading config file: yaml: line 95: did not find expected '-' indicator](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-95-did-not-find-expected-indicator/261430)

<div class="topic-metadata">

**Author:** [@Ana\_11](https://discuss.elastic.co/u/Ana_11)\
**Replies:** 2\
**Last updated:** [January 19, 2021, 5:27am UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-95-did-not-find-expected-indicator/261430 "2021-01-19T05:27:51Z")

</div>

Hi I have installed filebeat on rsyslog server and have enabled system module. while running filebeat setup -e im getting the below error i have reffered other posts also but unable to find my mistake please help. "Exi…

---

## [For a day network traffic issue](https://discuss.elastic.co/t/for-a-day-network-traffic-issue/261394)

<div class="topic-metadata">

**Author:** [@daemon](https://discuss.elastic.co/u/daemon)\
**Replies:** 4\
**Last updated:** [January 19, 2021, 4:55am UTC](https://discuss.elastic.co/t/for-a-day-network-traffic-issue/261394 "2021-01-19T04:55:20Z")

</div>

0 1 \* \* \* time sync crontab metricbeat -\> network traffic to be weird

---

## [Docker logs to elastic by filebeat](https://discuss.elastic.co/t/docker-logs-to-elastic-by-filebeat/261372)

<div class="topic-metadata">

**Author:** [@sungjin.kim](https://discuss.elastic.co/u/sungjin.kim)\
**Replies:** 2\
**Last updated:** [January 19, 2021, 2:03am UTC](https://discuss.elastic.co/t/docker-logs-to-elastic-by-filebeat/261372 "2021-01-19T02:03:30Z")

</div>

Hi, This is docker logs I tried to send docker logs to elasticsearch by using filebeat however, in elasticsearch, I can't find docker logs. Please let me know how to load stdout load of docker Regards, Sungji…

---

## [Filebeat Cloudtrail metricset breaks and stops returning "s3 log info" when upgrading past 7.9.1](https://discuss.elastic.co/t/filebeat-cloudtrail-metricset-breaks-and-stops-returning-s3-log-info-when-upgrading-past-7-9-1/261302)

<div class="topic-metadata">

**Author:** [@AddChickpeas](https://discuss.elastic.co/u/AddChickpeas)\
**Replies:** 2\
**Last updated:** [January 19, 2021, 12:23am UTC](https://discuss.elastic.co/t/filebeat-cloudtrail-metricset-breaks-and-stops-returning-s3-log-info-when-upgrading-past-7-9-1/261302 "2021-01-19T00:23:51Z")

</div>

I was attempting to upgrade filebeat to the latest release from 7.9.0, but am unable to get any version past 7.9.1 to work. Starting with 7.9.2, debug shows filebeat receiving the SQS message, but it doesn't return any …

---

## [Cannot start filebeat because of instance/beat.go error](https://discuss.elastic.co/t/cannot-start-filebeat-because-of-instance-beat-go-error/261472)

<div class="topic-metadata">

**Author:** [@jfasajr](https://discuss.elastic.co/u/jfasajr)\
**Replies:** 9\
**Last updated:** [January 18, 2021, 11:32pm UTC](https://discuss.elastic.co/t/cannot-start-filebeat-because-of-instance-beat-go-error/261472 "2021-01-18T23:32:56Z")

</div>

When I run filebeat setup -e It runs through and it is able to get through to the point of installing dashboard for kibana, but then fails due to an error, below: Index setup finished. Loading dashboards (Kibana must b…

---

## [Need help figuring out AWS role for functionbeat](https://discuss.elastic.co/t/need-help-figuring-out-aws-role-for-functionbeat/261297)

<div class="topic-metadata">

**Author:** [@Jonathan\_Detert](https://discuss.elastic.co/u/Jonathan_Detert)\
**Replies:** 2\
**Last updated:** [January 18, 2021, 9:16pm UTC](https://discuss.elastic.co/t/need-help-figuring-out-aws-role-for-functionbeat/261297 "2021-01-18T21:16:41Z")

</div>

https://www.elastic.co/guide/en/beats/functionbeat/7.x/configuration-functionbeat-options.html#functionbeat-role says that I can add a parameter named role to my functionbeat config. Where to add it? I'm guessing it's…

---

## [System.cpu.total.norm.pct different of the sum system.process.cpu.total.norm.pct](https://discuss.elastic.co/t/system-cpu-total-norm-pct-different-of-the-sum-system-process-cpu-total-norm-pct/261130)

<div class="topic-metadata">

**Author:** [@Altamir\_Dias](https://discuss.elastic.co/u/Altamir_Dias)\
**Replies:** 3\
**Last updated:** [January 18, 2021, 1:44pm UTC](https://discuss.elastic.co/t/system-cpu-total-norm-pct-different-of-the-sum-system-process-cpu-total-norm-pct/261130 "2021-01-18T13:44:23Z")

</div>

Hello Guys, I using a ELK STACK with version 7.7.1 and I'm testing metricbeat to enviroment observability, but when I need view data about CPU process the calcule not close. Why system.cpu.total.norm.pct its not the …

---

## [Make create-metricset error 127](https://discuss.elastic.co/t/make-create-metricset-error-127/261298)

<div class="topic-metadata">

**Author:** [@MatteoM](https://discuss.elastic.co/u/MatteoM)\
**Replies:** 1\
**Last updated:** [January 18, 2021, 9:02am UTC](https://discuss.elastic.co/t/make-create-metricset-error-127/261298 "2021-01-18T09:02:08Z")

</div>

Hi there, I'm trying to create a new metric beat and to do this I followed the official guide for dev Creating a Metricset | Beats Developer Guide \[7.16\] | Elastic I cloneed the beat repository with git and moved out i…

---

## [Elastic Templates:](https://discuss.elastic.co/t/elastic-templates/261328)

<div class="topic-metadata">

**Author:** [@charleseblack126](https://discuss.elastic.co/u/charleseblack126)\
**Replies:** 4\
**Last updated:** [January 17, 2021, 3:20am UTC](https://discuss.elastic.co/t/elastic-templates/261328 "2021-01-17T03:20:19Z")

</div>

I have installed Winlogbeats and have created an elastic template using a PowerShell statement. I wish to install it on a version elastic in my Ubuntu installation. The PowerShell statement does not allow transfer of tha…

---

## [Metricbeat Index Lifecycle Error](https://discuss.elastic.co/t/metricbeat-index-lifecycle-error/261071)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 3\
**Last updated:** [January 16, 2021, 3:21pm UTC](https://discuss.elastic.co/t/metricbeat-index-lifecycle-error/261071 "2021-01-16T15:21:50Z")

</div>

i am not using user remote\_monitoring\_user i've created user called test as superuser but after an hour it show me unauthorized user remote\_monitoring\_user.I am using metricbeat for ELK i have not used user remote\_mon…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=183)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=185)
