# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=185

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 186

---

## [Redirect or POST to "press the button"](https://discuss.elastic.co/t/redirect-or-post-to-press-the-button/261289)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 2\
**Last updated:** [January 16, 2021, 9:27am UTC](https://discuss.elastic.co/t/redirect-or-post-to-press-the-button/261289 "2021-01-16T09:27:43Z")

</div>

Hi, my heartbeat (7.8.0) is stuck on page asking for "press the button", to redirect further. Is there any way to configure Heartbeat to get past the page? Output which I'm receiving is: \<!DOCTYPE html\> \<html\> \<body o…

---

## [Install on air gap system](https://discuss.elastic.co/t/install-on-air-gap-system/261291)

<div class="topic-metadata">

**Author:** [@Andrew\_McDonald](https://discuss.elastic.co/u/Andrew_McDonald)\
**Replies:** 2\
**Last updated:** [January 15, 2021, 8:32pm UTC](https://discuss.elastic.co/t/install-on-air-gap-system/261291 "2021-01-15T20:32:01Z")

</div>

I work in an air gap aws system and we use puppet for deployment. So usually we make or grab an rpm and install it to the local repo and puppet takes care of the rest. Unfortunately, after adding the filebeats-oss rpm …

---

## [Filebeat not sending logs in real time](https://discuss.elastic.co/t/filebeat-not-sending-logs-in-real-time/260305)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 4\
**Last updated:** [January 15, 2021, 1:02pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-in-real-time/260305 "2021-01-15T13:02:20Z")

</div>

Hello Team, We have upgraded our ELK stack from 6.4 to 6.8 but we are using beats 6.4. Before upgradation all the logs were reaching on kiabna in real time. But we upgraded our ELK from 6.4 to 6.8 and now filebeat is n…

---

## [Elastic-agent (manual mode) + beats specific configurations](https://discuss.elastic.co/t/elastic-agent-manual-mode-beats-specific-configurations/261253)

<div class="topic-metadata">

**Author:** [@mscc](https://discuss.elastic.co/u/mscc)\
**Replies:** 0\
**Last updated:** [January 15, 2021, 11:12am UTC](https://discuss.elastic.co/t/elastic-agent-manual-mode-beats-specific-configurations/261253 "2021-01-15T11:12:32Z")

</div>

I'm using elastic-agent (dockerized) in manual mode. Earlier I used the same setup, just a dockerized filebeat instead of dockerized elastic-agent. To avoid shipping duplicate logs after container restart, we persistet …

---

## [FIlebeat 7.10.1 logging.metrics.enabled: false appears to have no effect](https://discuss.elastic.co/t/filebeat-7-10-1-logging-metrics-enabled-false-appears-to-have-no-effect/261202)

<div class="topic-metadata">

**Author:** [@ernestr](https://discuss.elastic.co/u/ernestr)\
**Replies:** 1\
**Last updated:** [January 15, 2021, 5:53am UTC](https://discuss.elastic.co/t/filebeat-7-10-1-logging-metrics-enabled-false-appears-to-have-no-effect/261202 "2021-01-15T05:53:40Z")

</div>

Hi, I am running the Filebeat deb package on Ubuntu Server 20.04. I noticed that when I set logging.metrics.enabled: false Filebeat still writes monitoring messages to syslog and then forwards them when I have the syste…

---

## [Filebeat:aws:cloudtrail](https://discuss.elastic.co/t/filebeatcloudtrail/261190)

<div class="topic-metadata">

**Author:** [@mdrdannyr](https://discuss.elastic.co/u/mdrdannyr)\
**Replies:** 0\
**Last updated:** [January 14, 2021, 11:13pm UTC](https://discuss.elastic.co/t/filebeatcloudtrail/261190 "2021-01-14T23:13:59Z")

</div>

Hi all, Had a question about the filebeat aws module - specifically the cloudtrail set. I've managed to get this up and running, and as far as i understand, the process used for the above can be broken down into the …

---

## [Handling multiple logstream formats with Functionbeat](https://discuss.elastic.co/t/handling-multiple-logstream-formats-with-functionbeat/261181)

<div class="topic-metadata">

**Author:** [@Karl\_Falconer](https://discuss.elastic.co/u/Karl_Falconer)\
**Replies:** 0\
**Last updated:** [January 14, 2021, 9:00pm UTC](https://discuss.elastic.co/t/handling-multiple-logstream-formats-with-functionbeat/261181 "2021-01-14T21:00:20Z")

</div>

Hi, I have a working function beat sending logs from Cloudwatch containing mysql slow query data ES and am able to view the log data in Kibana. I am trying to understand a few things regarding various log types. What…

---

## [How to set up Filebeat to send geoip-info to our hosted instance?](https://discuss.elastic.co/t/how-to-set-up-filebeat-to-send-geoip-info-to-our-hosted-instance/260117)

<div class="topic-metadata">

**Author:** [@byoungman](https://discuss.elastic.co/u/byoungman)\
**Replies:** 9\
**Last updated:** [January 14, 2021, 8:39pm UTC](https://discuss.elastic.co/t/how-to-set-up-filebeat-to-send-geoip-info-to-our-hosted-instance/260117 "2021-01-14T20:39:14Z")

</div>

I am in the process of creating a POC presentation for my management team hoping to show the benefits and advantages of this approach as compared to what we are currently using which is a combination of AppDynamics, the …

---

## [Heartbeat with Domain name target is not working](https://discuss.elastic.co/t/heartbeat-with-domain-name-target-is-not-working/260637)

<div class="topic-metadata">

**Author:** [@folderman](https://discuss.elastic.co/u/folderman)\
**Replies:** 5\
**Last updated:** [January 14, 2021, 7:18pm UTC](https://discuss.elastic.co/t/heartbeat-with-domain-name-target-is-not-working/260637 "2021-01-14T19:18:21Z")

</div>

Hi All, I have done a simple test with heartbeat to monitor the up/down of host, however, it is found that if I use IP, it works normal, however, once I change to use domain name, it doesn't work (attached). Do I mis…

---

## [Failed to create tempfile (/.filebeat.new) for writing: open /.filebeat.new: permission denied](https://discuss.elastic.co/t/failed-to-create-tempfile-filebeat-new-for-writing-open-filebeat-new-permission-denied/261132)

<div class="topic-metadata">

**Author:** [@prashant\_Rajenderan](https://discuss.elastic.co/u/prashant_Rajenderan)\
**Replies:** 0\
**Last updated:** [January 14, 2021, 2:08pm UTC](https://discuss.elastic.co/t/failed-to-create-tempfile-filebeat-new-for-writing-open-filebeat-new-permission-denied/261132 "2021-01-14T14:08:34Z")

</div>

I noticed that filebeat agent is not shipping the logs, when I tried restarting the service I found the following error. Also, when I run sudo ./filebeat -e output returns nothing. By looking at the logs "permission deni…

---

## [Add tags in filebeat modules](https://discuss.elastic.co/t/add-tags-in-filebeat-modules/261014)

<div class="topic-metadata">

**Author:** [@vasilev](https://discuss.elastic.co/u/vasilev)\
**Replies:** 1\
**Last updated:** [January 14, 2021, 9:25am UTC](https://discuss.elastic.co/t/add-tags-in-filebeat-modules/261014 "2021-01-14T09:25:01Z")

</div>

Hello, I have read this information: Can I add a tag in ibmmq module ? tried with: errorlog: enabled: true var.paths: \["/var/mqm/qmgrs/\*/errors/\*.json"\] # json.tags: ibmmq # tags: \["ibmmq", json\] and…

---

## [Cannot index event when using output pipeline definition](https://discuss.elastic.co/t/cannot-index-event-when-using-output-pipeline-definition/260822)

<div class="topic-metadata">

**Author:** [@subsonnic](https://discuss.elastic.co/u/subsonnic)\
**Replies:** 4\
**Last updated:** [January 14, 2021, 2:25am UTC](https://discuss.elastic.co/t/cannot-index-event-when-using-output-pipeline-definition/260822 "2021-01-14T02:25:51Z")

</div>

Hi, I am using filebeat/elasticsearch/kibana 7.10.0. My filebeat runs on Kubernetes. When I activate my ingest pipeline in my filebeat output config it runs into errors on client side. But if I test one event in my pi…

---

## [Filebeat dissect](https://discuss.elastic.co/t/filebeat-dissect/261062)

<div class="topic-metadata">

**Author:** [@Benoit\_Martin](https://discuss.elastic.co/u/Benoit_Martin)\
**Replies:** 0\
**Last updated:** [January 13, 2021, 11:03pm UTC](https://discuss.elastic.co/t/filebeat-dissect/261062 "2021-01-13T23:03:38Z")

</div>

Hi, I'm trying to parse that type of line via dissect. I know that I can do pipeline/logstash grok but I want to find a way to do it with dissect directly on filebeat side :slight\_smile: filebeat.yml ##################…

---

## [Filebeats not sending log file to ingest pipeline for my custom module](https://discuss.elastic.co/t/filebeats-not-sending-log-file-to-ingest-pipeline-for-my-custom-module/261027)

<div class="topic-metadata">

**Author:** [@oultimocoder](https://discuss.elastic.co/u/oultimocoder)\
**Replies:** 0\
**Last updated:** [January 13, 2021, 4:58pm UTC](https://discuss.elastic.co/t/filebeats-not-sending-log-file-to-ingest-pipeline-for-my-custom-module/261027 "2021-01-13T16:58:10Z")

</div>

I am using the official elastic helm charts for file beats. My config looks like: filebeatConfig: filebeat.yml: | setup.kibana.host: "http://kibana-kibana:80" setup.dashboards.enabled: true filebeat.modul…

---

## [Failed to cleanup /run/elastic-agent.sock](https://discuss.elastic.co/t/failed-to-cleanup-run-elastic-agent-sock/259809)

<div class="topic-metadata">

**Author:** [@mostlyjason](https://discuss.elastic.co/u/mostlyjason)\
**Replies:** 2\
**Last updated:** [January 13, 2021, 2:19pm UTC](https://discuss.elastic.co/t/failed-to-cleanup-run-elastic-agent-sock/259809 "2021-01-13T14:19:15Z")

</div>

I'm getting an error after installing Elastic Agent that says: 2020-12-29T15:16:12.945Z INFO application/application.go:58 Detecting execution mode 2020-12-29T15:16:12.945Z INFO application/applica…

---

## [Create a new metric for metricbeat](https://discuss.elastic.co/t/create-a-new-metric-for-metricbeat/260977)

<div class="topic-metadata">

**Author:** [@MatteoM](https://discuss.elastic.co/u/MatteoM)\
**Replies:** 0\
**Last updated:** [January 13, 2021, 10:48am UTC](https://discuss.elastic.co/t/create-a-new-metric-for-metricbeat/260977 "2021-01-13T10:48:50Z")

</div>

Hi there! I'm new in the forum and even to elasticsearch and kibana. For an university project I have to monitor several docker container created with marathon. Initially I've used zabbix to get the docker metrics for…

---

## [Auditbeat socket dataset doesn't correlate process info](https://discuss.elastic.co/t/auditbeat-socket-dataset-doesnt-correlate-process-info/260844)

<div class="topic-metadata">

**Author:** [@bolemebrige](https://discuss.elastic.co/u/bolemebrige)\
**Replies:** 4\
**Last updated:** [January 13, 2021, 10:08am UTC](https://discuss.elastic.co/t/auditbeat-socket-dataset-doesnt-correlate-process-info/260844 "2021-01-13T10:08:49Z")

</div>

Why are some events in my socket dataset missing process info?

---

## [Filebeat docker container with python 3. How to?](https://discuss.elastic.co/t/filebeat-docker-container-with-python-3-how-to/260946)

<div class="topic-metadata">

**Author:** [@Sreekanth\_Mannari](https://discuss.elastic.co/u/Sreekanth_Mannari)\
**Replies:** 0\
**Last updated:** [January 13, 2021, 7:42am UTC](https://discuss.elastic.co/t/filebeat-docker-container-with-python-3-how-to/260946 "2021-01-13T07:42:26Z")

</div>

docker run docker.elastic.co/beats/filebeat:7.10.1 When I exec into above container and check Python version it is 2.7.5 How can I upgrade the python version within container to use 3.x Or is there any other image wit…

---

## [Data from Metricbeat AWS module](https://discuss.elastic.co/t/data-from-metricbeat-aws-module/260725)

<div class="topic-metadata">

**Author:** [@Jurilz](https://discuss.elastic.co/u/Jurilz)\
**Replies:** 0\
**Last updated:** [January 11, 2021, 1:13pm UTC](https://discuss.elastic.co/t/data-from-metricbeat-aws-module/260725 "2021-01-11T13:13:36Z")

</div>

metricbeat version 7.10.0 (amd64), libbeat 7.10.0 elasticsearch version: 7.10.0 kibana version: 7.10.0 Good day, I'm still trying to collect and display the AWS metrics, especially EC2-metrics and billing information…

---

## [Filebeat Fortinet Module does't parse message fields when using tcp protocol](https://discuss.elastic.co/t/filebeat-fortinet-module-doest-parse-message-fields-when-using-tcp-protocol/260913)

<div class="topic-metadata">

**Author:** [@luigius](https://discuss.elastic.co/u/luigius)\
**Replies:** 0\
**Last updated:** [January 12, 2021, 10:01pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-doest-parse-message-fields-when-using-tcp-protocol/260913 "2021-01-12T22:01:29Z")

</div>

Hi everyone, I have filebeat with Fortinet module working fine if I use UDP, but when I switch to TCP stops to parse the records as Fortinet log adds at the beginning the priority (usually \<189\> or \<190\>) Any idea on ho…

---

## [Defining fields for metricsets](https://discuss.elastic.co/t/defining-fields-for-metricsets/260720)

<div class="topic-metadata">

**Author:** [@efftee](https://discuss.elastic.co/u/efftee)\
**Replies:** 8\
**Last updated:** [January 12, 2021, 9:31pm UTC](https://discuss.elastic.co/t/defining-fields-for-metricsets/260720 "2021-01-12T21:31:29Z")

</div>

Hi there, Using a single metricbeat agent to finetune settings before a larger deployment to 3000+ hosts, and trying to contain the number of fields to only those required, I seem to hit a wall at the "metricsets" level…

---

## [Should I store ES GC logs in my stack? And is there a way to condense them?](https://discuss.elastic.co/t/should-i-store-es-gc-logs-in-my-stack-and-is-there-a-way-to-condense-them/260887)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 1\
**Last updated:** [January 12, 2021, 8:48pm UTC](https://discuss.elastic.co/t/should-i-store-es-gc-logs-in-my-stack-and-is-there-a-way-to-condense-them/260887 "2021-01-12T20:48:24Z")

</div>

While poking around looking for ways to save space, I noticed that Elasticsearch .gc logs were 80% of my Filebeat logs. I turned them off yesterday afternoon. This morning I did a comparison of how many hits I got yeste…

---

## [Need assistance on combined processors within metricbeat module](https://discuss.elastic.co/t/need-assistance-on-combined-processors-within-metricbeat-module/260416)

<div class="topic-metadata">

**Author:** [@J\_Weeda](https://discuss.elastic.co/u/J_Weeda)\
**Replies:** 1\
**Last updated:** [January 12, 2021, 7:41pm UTC](https://discuss.elastic.co/t/need-assistance-on-combined-processors-within-metricbeat-module/260416 "2021-01-12T19:41:27Z")

</div>

Hello, I need assistance on getting a combined processor up and running. Situation: I'm running metricbeat 7.9.1. I would like to set up the metricbeat to monitor windows services when: windows.service.display\_name …

---

## [Functionbeat deploy fails, citing issue with s3 bucket](https://discuss.elastic.co/t/functionbeat-deploy-fails-citing-issue-with-s3-bucket/260767)

<div class="topic-metadata">

**Author:** [@Jonathan\_Detert](https://discuss.elastic.co/u/Jonathan_Detert)\
**Replies:** 3\
**Last updated:** [January 12, 2021, 7:36pm UTC](https://discuss.elastic.co/t/functionbeat-deploy-fails-citing-issue-with-s3-bucket/260767 "2021-01-12T19:36:59Z")

</div>

I'm trying to use functionbeat for my first time, with a single function, of type kinesis, using functionbeat v6.8.13. When I run 'functionbeat deploy kinesis' (where 'kinesis' is the name i chose for the function name)…

---

## [StatsD: metricset 'statsd/server' is not registered, module not found](https://discuss.elastic.co/t/statsd-metricset-statsd-server-is-not-registered-module-not-found/260641)

<div class="topic-metadata">

**Author:** [@shugydw](https://discuss.elastic.co/u/shugydw)\
**Replies:** 1\
**Last updated:** [January 12, 2021, 7:20pm UTC](https://discuss.elastic.co/t/statsd-metricset-statsd-server-is-not-registered-module-not-found/260641 "2021-01-12T19:20:54Z")

</div>

Hello. I am encountering an error with StatsD module. Please help! Exiting: 1 error: 1 error: metricset 'statsd/server' is not registered, module not found Here is the confirguration module: statsd period: 10s met…

---

## [Metricbeat AWS module not sending data](https://discuss.elastic.co/t/metricbeat-aws-module-not-sending-data/260200)

<div class="topic-metadata">

**Author:** [@Jurilz](https://discuss.elastic.co/u/Jurilz)\
**Replies:** 17\
**Last updated:** [January 11, 2021, 11:45am UTC](https://discuss.elastic.co/t/metricbeat-aws-module-not-sending-data/260200 "2021-01-11T11:45:46Z")

</div>

Good day, I'm currently trying to collect AWS metrics with the Metricbeat AWS module. And although the status of metricbeat looks fine, elasticsearch doesn't seem to receive any data. my metricbeat.yml: metricbeat.con…

---

## [Can't get my host to talk to the kibana server](https://discuss.elastic.co/t/cant-get-my-host-to-talk-to-the-kibana-server/260660)

<div class="topic-metadata">

**Author:** [@Minx](https://discuss.elastic.co/u/Minx)\
**Replies:** 1\
**Last updated:** [January 12, 2021, 7:21am UTC](https://discuss.elastic.co/t/cant-get-my-host-to-talk-to-the-kibana-server/260660 "2021-01-12T07:21:20Z")

</div>

I'm not sure why but all I seem to get it this error message, I'm using a server 2016 with Elastic search, kibana, file beat and winlog beat, it can see the windows log from itself but this message is from a Win 10 ho…

---

## [Memory usage for a particular directory](https://discuss.elastic.co/t/memory-usage-for-a-particular-directory/260553)

<div class="topic-metadata">

**Author:** [@akhileshtapdiya](https://discuss.elastic.co/u/akhileshtapdiya)\
**Replies:** 3\
**Last updated:** [January 11, 2021, 9:10pm UTC](https://discuss.elastic.co/t/memory-usage-for-a-particular-directory/260553 "2021-01-11T21:10:23Z")

</div>

Hi I am tyring to get memory usage information for a particular directory on my server. Is there any way to get this in kibana? Current system.memory.act.pct give me overall memory at os level and I am interested in me…

---

## [Beats Denial of Service issue (ESA-2020-16)](https://discuss.elastic.co/t/beats-denial-of-service-issue-esa-2020-16/260759)

<div class="topic-metadata">

**Author:** [@Anandh\_Kumar](https://discuss.elastic.co/u/Anandh_Kumar)\
**Replies:** 0\
**Last updated:** [January 11, 2021, 7:35pm UTC](https://discuss.elastic.co/t/beats-denial-of-service-issue-esa-2020-16/260759 "2021-01-11T19:35:53Z")

</div>

Does the denial of service issue apply to filebeat connections made to logstash over ssl? We have filebeat running in one linux machine streaming via SSL TCP to a logstash output setup in another linux machine.

---

## [Index patterns health status yellow](https://discuss.elastic.co/t/index-patterns-health-status-yellow/260749)

<div class="topic-metadata">

**Author:** [@Grant1999](https://discuss.elastic.co/u/Grant1999)\
**Replies:** 1\
**Last updated:** [January 11, 2021, 6:16pm UTC](https://discuss.elastic.co/t/index-patterns-health-status-yellow/260749 "2021-01-11T18:16:06Z")

</div>

Any idea what it means about health status being yellow?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=184)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=186)
