# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=187

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 188

---

## [How to send logs to logstash via filebeat](https://discuss.elastic.co/t/how-to-send-logs-to-logstash-via-filebeat/260289)

<div class="topic-metadata">

**Author:** [@knagasri](https://discuss.elastic.co/u/knagasri)\
**Replies:** 2\
**Last updated:** [January 7, 2021, 5:26am UTC](https://discuss.elastic.co/t/how-to-send-logs-to-logstash-via-filebeat/260289 "2021-01-07T05:26:17Z")

</div>

I am using the below code for deploying file beat in GCP: I can see 3 or 4 restarts . After then , it was getting stable. Can anyone know why it is getting 3 or 4 restarts and also by default it is sending logs to …

---

## [Issue with creating new Beat](https://discuss.elastic.co/t/issue-with-creating-new-beat/260339)

<div class="topic-metadata">

**Author:** [@yuv](https://discuss.elastic.co/u/yuv)\
**Replies:** 0\
**Last updated:** [January 6, 2021, 12:30pm UTC](https://discuss.elastic.co/t/issue-with-creating-new-beat/260339 "2021-01-06T12:30:25Z")

</div>

Hi, i've followed the following documentation https://www.elastic.co/guide/en/beats/devguide/7.11/new-beat.html for creating new beat. While i'm trying to build it i got the below issues. What i'm i doing wrong ? how …

---

## [Filebeat is not sending Logs to Logstash](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash/260372)

<div class="topic-metadata">

**Author:** [@Esakkiraj\_Karthi](https://discuss.elastic.co/u/Esakkiraj_Karthi)\
**Replies:** 0\
**Last updated:** [January 6, 2021, 4:44pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash/260372 "2021-01-06T16:44:43Z")

</div>

We have deployed Filebeat as a daemonset on ELK operator in GKE cluster. Our Filebeat is working fine when we want to send logs directly to Elasticsearch but when it comes to send it via Logstash we are getting an issue.…

---

## [How to stop and remove filebeat from kubernetes? (eks)](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957)

<div class="topic-metadata">

**Author:** [@umen](https://discuss.elastic.co/u/umen)\
**Replies:** 13\
**Last updated:** [January 6, 2021, 3:03pm UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957 "2021-01-06T15:03:16Z")

</div>

Hello i installed filebeat from this link : and its working. now i like to remove it from the eks cluster. how can i stop it and remove it ? no info in documents Thanks

---

## [Custom metricbeat index,ilm](https://discuss.elastic.co/t/custom-metricbeat-index-ilm/260249)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [January 6, 2021, 3:00pm UTC](https://discuss.elastic.co/t/custom-metricbeat-index-ilm/260249 "2021-01-06T15:00:33Z")

</div>

I have follwing setting on metricbeat.yml setup.template.enabled: true setup.template.overwrite: true output.elasticsearch.index: "hou\_metricbeat\_insite-%{\[agent.version\]}-%{+yyyy.MM.dd}" setup.template.name: "hou\_me…

---

## [Windows Perfmon (DHCP) Dashboard](https://discuss.elastic.co/t/windows-perfmon-dhcp-dashboard/260263)

<div class="topic-metadata">

**Author:** [@efaile](https://discuss.elastic.co/u/efaile)\
**Replies:** 0\
**Last updated:** [January 6, 2021, 12:26am UTC](https://discuss.elastic.co/t/windows-perfmon-dhcp-dashboard/260263 "2021-01-06T00:26:52Z")

</div>

I'm new to the Elastic Stack - forgive me if this is a "Captain Obvious" question. We want to monitor some key services such as DHCP Declines that can be indicative of trouble. I installed the metricbeat on our Windows…

---

## [How to make the changes in filebeat effective](https://discuss.elastic.co/t/how-to-make-the-changes-in-filebeat-effective/260143)

<div class="topic-metadata">

**Author:** [@aagarwal3](https://discuss.elastic.co/u/aagarwal3)\
**Replies:** 21\
**Last updated:** [January 5, 2021, 8:59pm UTC](https://discuss.elastic.co/t/how-to-make-the-changes-in-filebeat-effective/260143 "2021-01-05T20:59:17Z")

</div>

Hello all, I am trying to use the filebeat.yml file for the first time. Since, the logs are being logged in a different country and sometimes I see an abrupt jump in the logs visibility. It might be (not sure) because p…

---

## [PostgreSQL Replication Data Metricbeat](https://discuss.elastic.co/t/postgresql-replication-data-metricbeat/260251)

<div class="topic-metadata">

**Author:** [@willis](https://discuss.elastic.co/u/willis)\
**Replies:** 0\
**Last updated:** [January 5, 2021, 7:57pm UTC](https://discuss.elastic.co/t/postgresql-replication-data-metricbeat/260251 "2021-01-05T19:57:09Z")

</div>

According to https://github.com/elastic/beats/issues/11234 the Metricbeat PostgreSQL module does not support pulling replication data. Is there a workaround to get important metrics like Replication Lag from PostgreSQL …

---

## [Filebeat stopped sending the log entries](https://discuss.elastic.co/t/filebeat-stopped-sending-the-log-entries/260217)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 1\
**Last updated:** [January 5, 2021, 2:13pm UTC](https://discuss.elastic.co/t/filebeat-stopped-sending-the-log-entries/260217 "2021-01-05T14:13:48Z")

</div>

Hello , We have a typical issue here. Filebeat suddenly stopped sending the log entries and i can see the below message in the log. 2021-01-05T14:58:50.314+0100 INFO \[monitoring\] log/log.go:144 Non-zero metr…

---

## [Simultaneous Filebeats to handle high load](https://discuss.elastic.co/t/simultaneous-filebeats-to-handle-high-load/260108)

<div class="topic-metadata">

**Author:** [@talsh87](https://discuss.elastic.co/u/talsh87)\
**Replies:** 2\
**Last updated:** [January 5, 2021, 7:32am UTC](https://discuss.elastic.co/t/simultaneous-filebeats-to-handle-high-load/260108 "2021-01-05T07:32:49Z")

</div>

I'd like to leverage Filebeat so it'd fetch our o365\\azure\\aws logs using the various modules . How would it handle very high volumes? Is there any benchmark for example events\\MBs per second? Is there any way to maint…

---

## [DNS lookup failure "my-cluster-es-http": lookup my-cluster-es-http on 1xx.xx.xx.xx:53: no such host](https://discuss.elastic.co/t/dns-lookup-failure-my-cluster-es-http-lookup-my-cluster-es-http-on-1xx-xx-xx-xx-no-such-host/260172)

<div class="topic-metadata">

**Author:** [@umen](https://discuss.elastic.co/u/umen)\
**Replies:** 0\
**Last updated:** [January 5, 2021, 7:30am UTC](https://discuss.elastic.co/t/dns-lookup-failure-my-cluster-es-http-lookup-my-cluster-es-http-on-1xx-xx-xx-xx-no-such-host/260172 "2021-01-05T07:30:27Z")

</div>

Hey i followed the quickstart tutorial to setup elasticsearch on Kubernetes . installed it on pre created namespace not default . apiVersion: elasticsearch.k8s.elastic.co/v1 kind: Elasticsearch metadata: name: my-cl…

---

## [ERROR	pipeline/output.go:100	Failed to connect to backoff(async(tcp://0.0.0.0:5044)): dial tcp 0.0.0.0:5044: connect: connection refused](https://discuss.elastic.co/t/error-pipeline-output-go-100-failed-to-connect-to-backoff-async-tcp-0-0-0-0-5044-dial-tcp-0-0-0-0-connect-connection-refused/260121)

<div class="topic-metadata">

**Author:** [@UjjwalBera](https://discuss.elastic.co/u/UjjwalBera)\
**Replies:** 6\
**Last updated:** [January 5, 2021, 7:30am UTC](https://discuss.elastic.co/t/error-pipeline-output-go-100-failed-to-connect-to-backoff-async-tcp-0-0-0-0-5044-dial-tcp-0-0-0-0-connect-connection-refused/260121 "2021-01-05T07:30:11Z")

</div>

Here below filebeat.yml output configuration output.logstash: enabled: true hosts: \["0.0.0.0:5044"\] timeout: 86400\`\` logstash.conf input configuration input { beats { port =\> 5044 …

---

## [Notify slack when hosts are up](https://discuss.elastic.co/t/notify-slack-when-hosts-are-up/258942)

<div class="topic-metadata">

**Author:** [@minu.ajith](https://discuss.elastic.co/u/minu.ajith)\
**Replies:** 3\
**Last updated:** [January 5, 2021, 12:37am UTC](https://discuss.elastic.co/t/notify-slack-when-hosts-are-up/258942 "2021-01-05T00:37:26Z")

</div>

Hi team, Is there a way to get alerts in slack and auto-resolve pagerduty alerts when the hosts come back online ? Regards, Minu

---

## [Checkpoint Firewall Logs](https://discuss.elastic.co/t/checkpoint-firewall-logs/260133)

<div class="topic-metadata">

**Author:** [@somerandomitperson](https://discuss.elastic.co/u/somerandomitperson)\
**Replies:** 5\
**Last updated:** [January 5, 2021, 12:07am UTC](https://discuss.elastic.co/t/checkpoint-firewall-logs/260133 "2021-01-05T00:07:42Z")

</div>

This is my first experience with Elastic. I am trying to set up a Kibana dashboard and create dashboards for my Checkpoint firewall. The built in checkpoint module does not parse logs from my firewall. I have looked into…

---

## [Filebeats and xpack modules - Confusion about licensing](https://discuss.elastic.co/t/filebeats-and-xpack-modules-confusion-about-licensing/260106)

<div class="topic-metadata">

**Author:** [@talsh87](https://discuss.elastic.co/u/talsh87)\
**Replies:** 1\
**Last updated:** [January 4, 2021, 9:16pm UTC](https://discuss.elastic.co/t/filebeats-and-xpack-modules-confusion-about-licensing/260106 "2021-01-04T21:16:12Z")

</div>

In case I'd just like to leverage Filebeats including x-pack modules (such as Office365) and Logstash as part of a backend infrastructure - Is a license needed? The ingestion process (and Filebeats\\Logstash inside) isn'…

---

## [Filebeat 7.3.0 High CPU](https://discuss.elastic.co/t/filebeat-7-3-0-high-cpu/260130)

<div class="topic-metadata">

**Author:** [@tarpanpathak](https://discuss.elastic.co/u/tarpanpathak)\
**Replies:** 0\
**Last updated:** [January 4, 2021, 8:47pm UTC](https://discuss.elastic.co/t/filebeat-7-3-0-high-cpu/260130 "2021-01-04T20:47:55Z")

</div>

Hi, I am not sure if this is the best place to discuss this but one of our compute nodes in Kubernetes is constantly alerting on high CPU. After digging a bit deeper, we see that the Filebeat process on the node is trig…

---

## [Trying to setup beats](https://discuss.elastic.co/t/trying-to-setup-beats/257794)

<div class="topic-metadata">

**Author:** [@knagasri](https://discuss.elastic.co/u/knagasri)\
**Replies:** 6\
**Last updated:** [January 4, 2021, 5:22pm UTC](https://discuss.elastic.co/t/trying-to-setup-beats/257794 "2021-01-04T17:22:47Z")

</div>

I had deployed Elasticsearch cluster along with kibana in GCP. I was trying to deploy beats as well. I had used the beats yaml files which are in the following link: I just changed the elastic and kibana references…

---

## [Hostname and timestamp gets overwritten when using archived event logs using winlogbeat](https://discuss.elastic.co/t/hostname-and-timestamp-gets-overwritten-when-using-archived-event-logs-using-winlogbeat/257739)

<div class="topic-metadata">

**Author:** [@p1k4chu](https://discuss.elastic.co/u/p1k4chu)\
**Replies:** 1\
**Last updated:** [January 4, 2021, 4:00pm UTC](https://discuss.elastic.co/t/hostname-and-timestamp-gets-overwritten-when-using-archived-event-logs-using-winlogbeat/257739 "2021-01-04T16:00:45Z")

</div>

Version : Winlogbeat 7.9.2 Platform: Windows 10 Reproduction Instructions: Use winlogbeat to upload an event log file (.evtx file using -E option) and use the default config file. I used this script to upload bulk fil…

---

## [Renaming the user agent "Elastic-Heartbeat/7.x.x" in Heartbeat (http monitor type)](https://discuss.elastic.co/t/renaming-the-user-agent-elastic-heartbeat-7-x-x-in-heartbeat-http-monitor-type/260017)

<div class="topic-metadata">

**Author:** [@Rysiu](https://discuss.elastic.co/u/Rysiu)\
**Replies:** 1\
**Last updated:** [January 4, 2021, 3:25pm UTC](https://discuss.elastic.co/t/renaming-the-user-agent-elastic-heartbeat-7-x-x-in-heartbeat-http-monitor-type/260017 "2021-01-04T15:25:51Z")

</div>

Hello, Is it possible to change the name the user agent "Elastic-Heartbeat/7.x.x" in Heartbeat (http monitor type)? Is such modification relatively easy to implement? I do not see the appropriate option in the configu…

---

## [Metricbeat Kubernetes Module has JSON marshal error](https://discuss.elastic.co/t/metricbeat-kubernetes-module-has-json-marshal-error/259900)

<div class="topic-metadata">

**Author:** [@matthew-mcdermott](https://discuss.elastic.co/u/matthew-mcdermott)\
**Replies:** 2\
**Last updated:** [January 4, 2021, 2:48pm UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-module-has-json-marshal-error/259900 "2021-01-04T14:48:27Z")

</div>

I am using metricbeat's kubernetes module and have come across what I believe is a bug. It is related to this issue: https://github.com/elastic/beats/issues/19475. I am not a Go developer, but seems like a fix might be …

---

## [Consolidate log lines sa one depending on the threadID information](https://discuss.elastic.co/t/consolidate-log-lines-sa-one-depending-on-the-threadid-information/257978)

<div class="topic-metadata">

**Author:** [@secintic](https://discuss.elastic.co/u/secintic)\
**Replies:** 1\
**Last updated:** [January 4, 2021, 1:54pm UTC](https://discuss.elastic.co/t/consolidate-log-lines-sa-one-depending-on-the-threadid-information/257978 "2021-01-04T13:54:27Z")

</div>

We have a syserr messages from one of our WebApplication servers it is writing each line with timestamp we want to group these lines depending on their threadID you can see the example log file below. The challenging thi…

---

## [Grokk Patterning output to respective indexes based on \[agent.type\] (or any conditionals) not working](https://discuss.elastic.co/t/grokk-patterning-output-to-respective-indexes-based-on-agent-type-or-any-conditionals-not-working/259602)

<div class="topic-metadata">

**Author:** [@Rohan-boogeyman](https://discuss.elastic.co/u/Rohan-boogeyman)\
**Replies:** 1\
**Last updated:** [January 4, 2021, 8:40am UTC](https://discuss.elastic.co/t/grokk-patterning-output-to-respective-indexes-based-on-agent-type-or-any-conditionals-not-working/259602 "2021-01-04T08:40:32Z")

</div>

Hello, Sorry but i've got a question as I have searched alot for an answer but could not find anything. My winlogbeat and filebeat are all sent to logstash on 5044. I want logstash to filter using Grokk and output them…

---

## [What is the release date of Beats 7.11?](https://discuss.elastic.co/t/what-is-the-release-date-of-beats-7-11/260062)

<div class="topic-metadata">

**Author:** [@cy-zheng](https://discuss.elastic.co/u/cy-zheng)\
**Replies:** 1\
**Last updated:** [January 4, 2021, 7:20am UTC](https://discuss.elastic.co/t/what-is-the-release-date-of-beats-7-11/260062 "2021-01-04T07:20:45Z")

</div>

I found it has some exciting new features and can’t wait to use it.

---

## [Auditbeat-\* No results match your search criteria](https://discuss.elastic.co/t/auditbeat-no-results-match-your-search-criteria/259980)

<div class="topic-metadata">

**Author:** [@Vigilox](https://discuss.elastic.co/u/Vigilox)\
**Replies:** 3\
**Last updated:** [January 4, 2021, 2:37am UTC](https://discuss.elastic.co/t/auditbeat-no-results-match-your-search-criteria/259980 "2021-01-04T02:37:29Z")

</div>

Fresh ElasticStack 7.10 deployment on Azure. Elastic Agents have been deployed. The indices for packetbeat-\* and auditbeat-\* are not found. Date range expanded to a YEAR. Here are the installed Integrations. N…

---

## [Office365 Signin Logs event.outcome seems incorrect sometimes](https://discuss.elastic.co/t/office365-signin-logs-event-outcome-seems-incorrect-sometimes/258832)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [January 3, 2021, 11:22am UTC](https://discuss.elastic.co/t/office365-signin-logs-event-outcome-seems-incorrect-sometimes/258832 "2021-01-03T11:22:59Z")

</div>

Hello, (Elastic 7.9.2) We noticed something weird in the Office365 Signin logs. This a screenshot from the Azure Portal itself: As you can see the user had 1 failed login followed by a successful login. In the o365 …

---

## [New Community Beat to Apache Pulsar](https://discuss.elastic.co/t/new-community-beat-to-apache-pulsar/259968)

<div class="topic-metadata">

**Author:** [@Pinar\_Zaimoglu](https://discuss.elastic.co/u/Pinar_Zaimoglu)\
**Replies:** 2\
**Last updated:** [January 2, 2021, 9:17pm UTC](https://discuss.elastic.co/t/new-community-beat-to-apache-pulsar/259968 "2021-01-02T21:17:04Z")

</div>

Hi everyone! I wanted to share with you that I'm creating a new community beat based on Metricbeat called "pulsar beat". If you have any advice, please let me know. Thank you in advance.

---

## [Transaction metrics](https://discuss.elastic.co/t/transaction-metrics/259959)

<div class="topic-metadata">

**Author:** [@Jose\_Campos](https://discuss.elastic.co/u/Jose_Campos)\
**Replies:** 0\
**Last updated:** [December 31, 2020, 1:20pm UTC](https://discuss.elastic.co/t/transaction-metrics/259959 "2020-12-31T13:20:30Z")

</div>

hello everyone I have been working with metricbeat version 7.9.10, for windows server 2016 with MSSQL module. The problem I am having is that a day goes by and I stop receiving transaction metrics from the database but…

---

## [I made some multi-arch filebeat alpine images](https://discuss.elastic.co/t/i-made-some-multi-arch-filebeat-alpine-images/259920)

<div class="topic-metadata">

**Author:** [@Martin\_Norrsken](https://discuss.elastic.co/u/Martin_Norrsken)\
**Replies:** 0\
**Last updated:** [December 30, 2020, 9:17pm UTC](https://discuss.elastic.co/t/i-made-some-multi-arch-filebeat-alpine-images/259920 "2020-12-30T21:17:48Z")

</div>

I've been building filebeat for alpine to run as a sidecar to other containers (specifically for shipping traefik access logs) and I have to say that the build process is overcomplicated with dependencies all over the pl…

---

## [Filebeat index is getting created but with 0 documents](https://discuss.elastic.co/t/filebeat-index-is-getting-created-but-with-0-documents/259667)

<div class="topic-metadata">

**Author:** [@anujaggarwal](https://discuss.elastic.co/u/anujaggarwal)\
**Replies:** 2\
**Last updated:** [December 30, 2020, 4:49pm UTC](https://discuss.elastic.co/t/filebeat-index-is-getting-created-but-with-0-documents/259667 "2020-12-30T16:49:57Z")

</div>

Hi I am trying to index my custom log file using filebeat. I am successfully running filebeat with pre-built modules like mysql, nginx etc. But when I actually try to use it with my application specific log file, index …

---

## [Why does filebeat register a new broker when inserting data into topic of kafka?](https://discuss.elastic.co/t/why-does-filebeat-register-a-new-broker-when-inserting-data-into-topic-of-kafka/259850)

<div class="topic-metadata">

**Author:** [@bae\_park](https://discuss.elastic.co/u/bae_park)\
**Replies:** 0\
**Last updated:** [December 30, 2020, 5:43am UTC](https://discuss.elastic.co/t/why-does-filebeat-register-a-new-broker-when-inserting-data-into-topic-of-kafka/259850 "2020-12-30T05:43:53Z")

</div>

I tried to insert data into the cta\_test topic of kafka using filebeat. However, the topic of cta\_test had no data. So I checked the filebeat log and found a new broker registration part there. I intended to access ka…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=186)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=188)
