# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=186

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 187

---

## [Filebeat Azure module](https://discuss.elastic.co/t/filebeat-azure-module/256771)

<div class="topic-metadata">

**Author:** [@Marco0101](https://discuss.elastic.co/u/Marco0101)\
**Replies:** 1\
**Last updated:** [January 11, 2021, 1:05pm UTC](https://discuss.elastic.co/t/filebeat-azure-module/256771 "2021-01-11T13:05:41Z")

</div>

Hi, i would like to know if the activitylogs - auditlogs can only be used for Azure AD audit events or that it is also possible to use it for keyvault audit logging also. Because we built an eventhub and pass the keyvaul…

---

## [Suricata module with remote syslog input](https://discuss.elastic.co/t/suricata-module-with-remote-syslog-input/260707)

<div class="topic-metadata">

**Author:** [@kostiik](https://discuss.elastic.co/u/kostiik)\
**Replies:** 0\
**Last updated:** [January 11, 2021, 11:16am UTC](https://discuss.elastic.co/t/suricata-module-with-remote-syslog-input/260707 "2021-01-11T11:16:58Z")

</div>

Hello, I am unable to configure suricata.yml in filebeat/modules.d to receive suricata logs remotely from syslog instead a local log file. This post: https://discuss.elastic.co/t/using-the-filebeat-suricata-module-for-…

---

## [Disable x-pack on Auditbeat and Metricbeat clients 7.9 (AWS Elasticsearch service) using OSS version](https://discuss.elastic.co/t/disable-x-pack-on-auditbeat-and-metricbeat-clients-7-9-aws-elasticsearch-service-using-oss-version/258924)

<div class="topic-metadata">

**Author:** [@francisca.munhoz](https://discuss.elastic.co/u/francisca.munhoz)\
**Replies:** 5\
**Last updated:** [January 11, 2021, 11:11am UTC](https://discuss.elastic.co/t/disable-x-pack-on-auditbeat-and-metricbeat-clients-7-9-aws-elasticsearch-service-using-oss-version/258924 "2021-01-11T11:11:10Z")

</div>

Hi all, I'm using AWS Elasticsearch service (7.9) and I have installed metricbeat and auditbeat clients (oss) 7.9.1 on a linux node: Beats client source: However somehow x-pack check is enabled, so I'm getting …

---

## [Heartbeat in dotnet core 3.1 services](https://discuss.elastic.co/t/heartbeat-in-dotnet-core-3-1-services/260274)

<div class="topic-metadata">

**Author:** [@Bilal\_Malik](https://discuss.elastic.co/u/Bilal_Malik)\
**Replies:** 1\
**Last updated:** [January 11, 2021, 10:43am UTC](https://discuss.elastic.co/t/heartbeat-in-dotnet-core-3-1-services/260274 "2021-01-11T10:43:12Z")

</div>

i have configured logging in Elasticsearch, it is working perfectly. Now I am looking for statuses of my microservices that are running or which one is down. How can i figure out using Elasticsearch? Every microservices …

---

## [Endpoint Agent two host showing in logs-\* per host](https://discuss.elastic.co/t/endpoint-agent-two-host-showing-in-logs-per-host/260700)

<div class="topic-metadata">

**Author:** [@The1WhoPrtNocks](https://discuss.elastic.co/u/The1WhoPrtNocks)\
**Replies:** 0\
**Last updated:** [January 11, 2021, 10:36am UTC](https://discuss.elastic.co/t/endpoint-agent-two-host-showing-in-logs-per-host/260700 "2021-01-11T10:36:01Z")

</div>

Hi, I have recently been rolling out the Endpoint agent to some host for testing. Within the fleet agents tab, there is a single entry for each host in the format "hostname". However within the logs-\* index there are …

---

## [Filebeat not collection logs of elastic pods](https://discuss.elastic.co/t/filebeat-not-collection-logs-of-elastic-pods/259719)

<div class="topic-metadata">

**Author:** [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Replies:** 9\
**Last updated:** [January 11, 2021, 7:47am UTC](https://discuss.elastic.co/t/filebeat-not-collection-logs-of-elastic-pods/259719 "2021-01-11T07:47:12Z")

</div>

I am not sure since when this is happening, but my filebeat has stopped collecting the logs of elastic pods that I have deployed using eck. In total I do have these 3 pods: elastic-es-masterdata-100-0 elastic-es-master…

---

## [Ingest pipe line csv parser with multiline message failing](https://discuss.elastic.co/t/ingest-pipe-line-csv-parser-with-multiline-message-failing/260666)

<div class="topic-metadata">

**Author:** [@Bo\_Koralage](https://discuss.elastic.co/u/Bo_Koralage)\
**Replies:** 0\
**Last updated:** [January 11, 2021, 4:18am UTC](https://discuss.elastic.co/t/ingest-pipe-line-csv-parser-with-multiline-message-failing/260666 "2021-01-11T04:18:00Z")

</div>

I am using a csv processor and \\t as the separator ingest pipeline to push logs from filebeat. This works great but fails when the message (logmessage) portion has a new line character. I added the following to the fileb…

---

## [Vsphere metric in windows trying to connect on localhost address](https://discuss.elastic.co/t/vsphere-metric-in-windows-trying-to-connect-on-localhost-address/260277)

<div class="topic-metadata">

**Author:** [@rohan0018](https://discuss.elastic.co/u/rohan0018)\
**Replies:** 2\
**Last updated:** [January 11, 2021, 3:34am UTC](https://discuss.elastic.co/t/vsphere-metric-in-windows-trying-to-connect-on-localhost-address/260277 "2021-01-11T03:34:49Z")

</div>

Hi!!! I have installed and enabled vsphere metricbeat module on my vcenter server. I have configured vsphere.yml as below. '''''metricbeat.modules: module: vsphere enabled: true metricsets: \["datastore", "host", …

---

## [How to find which node, with an old version of metricbeat, is the data coming from?](https://discuss.elastic.co/t/how-to-find-which-node-with-an-old-version-of-metricbeat-is-the-data-coming-from/260389)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 8\
**Last updated:** [January 11, 2021, 1:51am UTC](https://discuss.elastic.co/t/how-to-find-which-node-with-an-old-version-of-metricbeat-is-the-data-coming-from/260389 "2021-01-11T01:51:53Z")

</div>

We've upgraded to elastic v7.5 a few months ago, and upgraded most of the known servers metricbeat to the same version. However, looks like there might be a few servers which still have v6.6 metricbeat running and so we …

---

## [Running journalbeat as non-privileged user](https://discuss.elastic.co/t/running-journalbeat-as-non-privileged-user/260552)

<div class="topic-metadata">

**Author:** [@jmcclelland](https://discuss.elastic.co/u/jmcclelland)\
**Replies:** 0\
**Last updated:** [January 8, 2021, 2:04pm UTC](https://discuss.elastic.co/t/running-journalbeat-as-non-privileged-user/260552 "2021-01-08T14:04:56Z")

</div>

Hi all - I am sharing this for anyone else interested in running journalbeat as a non-root user. I'm grateful for the attention to security of the elasticsearch team but I think the solar winds compromise is making us al…

---

## [Capturing clear text beats traffic with wireshark](https://discuss.elastic.co/t/capturing-clear-text-beats-traffic-with-wireshark/260590)

<div class="topic-metadata">

**Author:** [@qbui](https://discuss.elastic.co/u/qbui)\
**Replies:** 1\
**Last updated:** [January 10, 2021, 10:00pm UTC](https://discuss.elastic.co/t/capturing-clear-text-beats-traffic-with-wireshark/260590 "2021-01-10T22:00:23Z")

</div>

Hello, Has anyone tried to capture and analyze the "clear text" beats traffic (FileBeat, Winlogbeats, etc.) as it is being sent to Logstash or Elasticsearch? In its default configuration, the traffic is being sent unenc…

---

## [Using the iptables dashboard](https://discuss.elastic.co/t/using-the-iptables-dashboard/259908)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 3\
**Last updated:** [January 9, 2021, 3:15pm UTC](https://discuss.elastic.co/t/using-the-iptables-dashboard/259908 "2021-01-09T15:15:52Z")

</div>

I am running iptables on my server. I enable the module, configure the .yml file for the file /var/log/kern.log. I do a filebeat -E setup.kibana.host= setup --dashboards. I restart kibana on the server, and go to vie…

---

## [Filebeat output to elasticsearch (open kerberos), publisher\_pipeline\_output WWW-Authenticate Negotiate 401 No processing](https://discuss.elastic.co/t/filebeat-output-to-elasticsearch-open-kerberos-publisher-pipeline-output-www-authenticate-negotiate-401-no-processing/260539)

<div class="topic-metadata">

**Author:** [@jing](https://discuss.elastic.co/u/jing)\
**Replies:** 1\
**Last updated:** [January 9, 2021, 8:21am UTC](https://discuss.elastic.co/t/filebeat-output-to-elasticsearch-open-kerberos-publisher-pipeline-output-www-authenticate-negotiate-401-no-processing/260539 "2021-01-09T08:21:16Z")

</div>

Connect to elasticsearch(open kerberos )，The authentication fails, when elasticsearch responds with 401(Negotiate), nothing happens,Normal logic should go to kdc to request processing Why doesn't filebeat request kerber…

---

## [Having Issue Starting Winlogbeat As A Windows Service](https://discuss.elastic.co/t/having-issue-starting-winlogbeat-as-a-windows-service/260574)

<div class="topic-metadata">

**Author:** [@qcjacobo](https://discuss.elastic.co/u/qcjacobo)\
**Replies:** 1\
**Last updated:** [January 8, 2021, 8:22pm UTC](https://discuss.elastic.co/t/having-issue-starting-winlogbeat-as-a-windows-service/260574 "2021-01-08T20:22:18Z")

</div>

I am having issues getting winlogbeat to start as a Windows service on my Windows 10 (1909) system. As you can see below, I am not getting any obvious errors when trying to install and start the Windows service. Just t…

---

## [Functionbeat package command creates zip archive with credentials visible in plaintext](https://discuss.elastic.co/t/functionbeat-package-command-creates-zip-archive-with-credentials-visible-in-plaintext/260569)

<div class="topic-metadata">

**Author:** [@ashort](https://discuss.elastic.co/u/ashort)\
**Replies:** 0\
**Last updated:** [January 8, 2021, 5:30pm UTC](https://discuss.elastic.co/t/functionbeat-package-command-creates-zip-archive-with-credentials-visible-in-plaintext/260569 "2021-01-08T17:30:50Z")

</div>

Hi, When I use the Functionbeat manager to package up Functionbeat and the Yaml file into a zip archive for use with AWS Lambda the zip archive is generated with the password for the Elasticsearch user in plaintext in t…

---

## [Addition of response time into Apache access fileset](https://discuss.elastic.co/t/addition-of-response-time-into-apache-access-fileset/260548)

<div class="topic-metadata">

**Author:** [@jberanek](https://discuss.elastic.co/u/jberanek)\
**Replies:** 1\
**Last updated:** [January 8, 2021, 2:01pm UTC](https://discuss.elastic.co/t/addition-of-response-time-into-apache-access-fileset/260548 "2021-01-08T14:01:54Z")

</div>

So, I'm not sure how specific this is to our environment, but our Apache logs have response time added onto the end of one of filebeat's 'apache' module's standard formats, like: 2s 2123456 micro-seconds So, I modified…

---

## [Filebeat disk queue messing up encoding](https://discuss.elastic.co/t/filebeat-disk-queue-messing-up-encoding/260546)

<div class="topic-metadata">

**Author:** [@Valker](https://discuss.elastic.co/u/Valker)\
**Replies:** 0\
**Last updated:** [January 8, 2021, 1:00pm UTC](https://discuss.elastic.co/t/filebeat-disk-queue-messing-up-encoding/260546 "2021-01-08T13:00:25Z")

</div>

Hello, I believe I have found a misbehavior in the disk queue mechanism in the filebeat. When I’m adding a UTF-8 encoded json with a polish characters, on the output I am getting messed up value. Example: ^^^^^^^^^^^^…

---

## [Customize ingest pipelines in Fleet / Elastic Agent](https://discuss.elastic.co/t/customize-ingest-pipelines-in-fleet-elastic-agent/260236)

<div class="topic-metadata">

**Author:** [@icious](https://discuss.elastic.co/u/icious)\
**Replies:** 2\
**Last updated:** [January 8, 2021, 12:35pm UTC](https://discuss.elastic.co/t/customize-ingest-pipelines-in-fleet-elastic-agent/260236 "2021-01-08T12:35:06Z")

</div>

Hello, I was fiddling around with Elastic Agent and Fleet to integrate multiple log sources in the same agent, and I am getting "Provided Grok expressions do not match field value" error with Fortinet integration. Usin…

---

## [Renaming log file in filebeat and passing index name](https://discuss.elastic.co/t/renaming-log-file-in-filebeat-and-passing-index-name/260519)

<div class="topic-metadata">

**Author:** [@navin1093](https://discuss.elastic.co/u/navin1093)\
**Replies:** 0\
**Last updated:** [January 8, 2021, 9:11am UTC](https://discuss.elastic.co/t/renaming-log-file-in-filebeat-and-passing-index-name/260519 "2021-01-08T09:11:33Z")

</div>

hi can i knowif wish to renmae the log before sending to logstash. Besides that, I also wish to set index name based on respective paths. How can this be done in filebeat. I saw we have something called fields but fiel…

---

## [Get node hostname/ip on which the container is hosted](https://discuss.elastic.co/t/get-node-hostname-ip-on-which-the-container-is-hosted/260493)

<div class="topic-metadata">

**Author:** [@astrovj](https://discuss.elastic.co/u/astrovj)\
**Replies:** 0\
**Last updated:** [January 8, 2021, 3:41am UTC](https://discuss.elastic.co/t/get-node-hostname-ip-on-which-the-container-is-hosted/260493 "2021-01-08T03:41:09Z")

</div>

Is there a way to get node hostname/ip on which the container is hosted using filebeat dynamically, as a field in the ES index. Right now it gives the container id/ip as hostname/ip ? I am not using logstash.

---

## [PanW module issues](https://discuss.elastic.co/t/panw-module-issues/260487)

<div class="topic-metadata">

**Author:** [@S3l3ct3d](https://discuss.elastic.co/u/S3l3ct3d)\
**Replies:** 0\
**Last updated:** [January 7, 2021, 8:34pm UTC](https://discuss.elastic.co/t/panw-module-issues/260487 "2021-01-07T20:34:47Z")

</div>

I have the panw module enabled in filebeat along with other modules enabled as well. For the panw module I have configured it as shown below - module: panw panos: enabled: true # Set which input to use betwee…

---

## [Kubernetes autodiscover fails if filebeat cannot determine its node name](https://discuss.elastic.co/t/kubernetes-autodiscover-fails-if-filebeat-cannot-determine-its-node-name/260375)

<div class="topic-metadata">

**Author:** [@smacl](https://discuss.elastic.co/u/smacl)\
**Replies:** 2\
**Last updated:** [January 7, 2021, 5:29pm UTC](https://discuss.elastic.co/t/kubernetes-autodiscover-fails-if-filebeat-cannot-determine-its-node-name/260375 "2021-01-07T17:29:37Z")

</div>

Hi, We are (rarely) seeing an issue using the k8s autodiscover feature in filebeat 7.9.1. If the API server is unavailable when filebeat tries to determine which node it's running on, filebeat might report an error lik…

---

## [Provided Grok expressions do not match field value:](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value/260472)

<div class="topic-metadata">

**Author:** [@millie](https://discuss.elastic.co/u/millie)\
**Replies:** 0\
**Last updated:** [January 7, 2021, 5:24pm UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value/260472 "2021-01-07T17:24:29Z")

</div>

Hi, I am successfully running filebeats with the logstash module to push serial port logs to elasticsearch/kibana. However, I get the error "Provided Grok expressions do not match field value:" but haven't set up any g…

---

## [How to parse first line in all the next lines](https://discuss.elastic.co/t/how-to-parse-first-line-in-all-the-next-lines/260459)

<div class="topic-metadata">

**Author:** [@kevin\_urbina](https://discuss.elastic.co/u/kevin_urbina)\
**Replies:** 0\
**Last updated:** [January 7, 2021, 3:49pm UTC](https://discuss.elastic.co/t/how-to-parse-first-line-in-all-the-next-lines/260459 "2021-01-07T15:49:23Z")

</div>

Hello everyone, I am having the following log : Sun Dec 20 00:40:05 CST 2020: Starting docker, stream=prod, version=latest, pwd=PATH Processing... SERVER oc: Successfully processed 23 TSM servers. Failed: 23 Detail…

---

## [Data path already locked by another beat ,how to configure path.data in running on kubernetes filebeat-kubernetes.yaml](https://discuss.elastic.co/t/data-path-already-locked-by-another-beat-how-to-configure-path-data-in-running-on-kubernetes-filebeat-kubernetes-yaml/260036)

<div class="topic-metadata">

**Author:** [@umen](https://discuss.elastic.co/u/umen)\
**Replies:** 6\
**Last updated:** [January 7, 2021, 3:25pm UTC](https://discuss.elastic.co/t/data-path-already-locked-by-another-beat-how-to-configure-path-data-in-running-on-kubernetes-filebeat-kubernetes-yaml/260036 "2021-01-07T15:25:57Z")

</div>

Hey i installed filebeat using this link : right away i got the error : \[root@ip-10-xx-x-x filebeat\]# filebeat -e -d "publish" 2021-01-03T09:12:11.438Z INFO instance/beat.go:645 Home path: \[/usr/share/fi…

---

## [Filebeat TCP Input Max Connections](https://discuss.elastic.co/t/filebeat-tcp-input-max-connections/260296)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [January 7, 2021, 3:22pm UTC](https://discuss.elastic.co/t/filebeat-tcp-input-max-connections/260296 "2021-01-07T15:22:25Z")

</div>

Hello, The documentation of the Filebeat tcp input mentions max\_connections. But it does not state what's the default value? So what is the default value? Grtz Willem

---

## [Metricbeat/K8s connect directly to elasticsearch or logstash what is best practices here?](https://discuss.elastic.co/t/metricbeat-k8s-connect-directly-to-elasticsearch-or-logstash-what-is-best-practices-here/260450)

<div class="topic-metadata">

**Author:** [@Kiril\_Churilov](https://discuss.elastic.co/u/Kiril_Churilov)\
**Replies:** 1\
**Last updated:** [January 7, 2021, 2:59pm UTC](https://discuss.elastic.co/t/metricbeat-k8s-connect-directly-to-elasticsearch-or-logstash-what-is-best-practices-here/260450 "2021-01-07T14:59:23Z")

</div>

Hello I'm new to ELK stack and beats technology. I managed to build and install Elasticseach 3 nodes cluster and kibana on kubernetes in google cloud (GKE) and plan to use it in production environment. I installed lo…

---

## [Index.lifecycle.rollover\_alias \[metricbeat\] does not point to index \[metricbeat-XXX\]](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-metricbeat-does-not-point-to-index-metricbeat-xxx/260187)

<div class="topic-metadata">

**Author:** [@graimato](https://discuss.elastic.co/u/graimato)\
**Replies:** 3\
**Last updated:** [January 7, 2021, 9:50am UTC](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-metricbeat-does-not-point-to-index-metricbeat-xxx/260187 "2021-01-07T09:50:10Z")

</div>

Dear all, I have a problem with a rollover for a metric beat index. I created a ILM Policy I setup metric beat to send data as follow: setup.ilm.check\_exists: false setup.ilm.overwrite: true setup.ilm.enabled…

---

## [\[Need help\] Error when installing winlogbeat on Windows Server 2012 R2](https://discuss.elastic.co/t/need-help-error-when-installing-winlogbeat-on-windows-server-2012-r2/259351)

<div class="topic-metadata">

**Author:** [@lachezar.uzunov](https://discuss.elastic.co/u/lachezar.uzunov)\
**Replies:** 5\
**Last updated:** [January 7, 2021, 7:00am UTC](https://discuss.elastic.co/t/need-help-error-when-installing-winlogbeat-on-windows-server-2012-r2/259351 "2021-01-07T07:00:45Z")

</div>

Hello everyone I need help debugging what is actually going on. I am installing winlogbeat as mentioned in the documentation (www.elastic.co/guide/en/beats/winlogbeat/7.10/winlogbeat-installation-configuration.html). T…

---

## [\[HELP\] Cannot receive data from winlogbeat on Windows Server 2012 R2](https://discuss.elastic.co/t/help-cannot-receive-data-from-winlogbeat-on-windows-server-2012-r2/260092)

<div class="topic-metadata">

**Author:** [@lachezar.uzunov](https://discuss.elastic.co/u/lachezar.uzunov)\
**Replies:** 5\
**Last updated:** [January 7, 2021, 6:59am UTC](https://discuss.elastic.co/t/help-cannot-receive-data-from-winlogbeat-on-windows-server-2012-r2/260092 "2021-01-07T06:59:00Z")

</div>

Hello everyone, I am struggling at receiving logs from winlogbeat on Windows Server 2012 R2. Things to mention: On Windows Server 2016+ its working completely fine. On Windows 10 PC (Pro/Home) is working completely fi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=185)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=187)
