# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=188

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 189

---

## [VPC Flow Logs Lagging](https://discuss.elastic.co/t/vpc-flow-logs-lagging/259855)

<div class="topic-metadata">

**Author:** [@jhanvi](https://discuss.elastic.co/u/jhanvi)\
**Replies:** 2\
**Last updated:** [December 30, 2020, 7:10am UTC](https://discuss.elastic.co/t/vpc-flow-logs-lagging/259855 "2020-12-30T07:10:49Z")

</div>

Hi, I am trying to take vpc flow logs. They are getting ingested but there is a lag in the logs flowing i.e. for today, logs of yesterday are still being ingested. What could possibly be the reason for the same and how…

---

## [Packet Beat does not send any data to elastic search](https://discuss.elastic.co/t/packet-beat-does-not-send-any-data-to-elastic-search/259690)

<div class="topic-metadata">

**Author:** [@bucco1958](https://discuss.elastic.co/u/bucco1958)\
**Replies:** 2\
**Last updated:** [December 29, 2020, 4:23pm UTC](https://discuss.elastic.co/t/packet-beat-does-not-send-any-data-to-elastic-search/259690 "2020-12-29T16:23:58Z")

</div>

Hi there I'm running elastic search version 7.8.0 and Kibana 7.8.0 on Win10. I have installed metricbeat and filebeat - both are running fine. I have installed packetbeat and runned packetbeat -setup The index has b…

---

## [Metricbeat AWS module](https://discuss.elastic.co/t/metricbeat-aws-module/259696)

<div class="topic-metadata">

**Author:** [@Jurilz](https://discuss.elastic.co/u/Jurilz)\
**Replies:** 3\
**Last updated:** [December 29, 2020, 12:42pm UTC](https://discuss.elastic.co/t/metricbeat-aws-module/259696 "2020-12-29T12:42:23Z")

</div>

Kibana version : 7.10.0 Elasticsearch version : 7.10.0 Metricbeat version : 7.10.1 Good day, I'm trying to collect monitoring metrics from AWS with metricbeat. In particular, I am interested in the metrics of the 5 E…

---

## [How does Winlogbeat parsing happen?](https://discuss.elastic.co/t/how-does-winlogbeat-parsing-happen/259727)

<div class="topic-metadata">

**Author:** [@Travis](https://discuss.elastic.co/u/Travis)\
**Replies:** 3\
**Last updated:** [December 29, 2020, 9:25am UTC](https://discuss.elastic.co/t/how-does-winlogbeat-parsing-happen/259727 "2020-12-29T09:25:01Z")

</div>

Hello there ! Probably dumb question, but : I'm asking how Winlogbeat parsing happen as I didn't use any logstash processing (grok,kv...) and didn't explicitely specify any pipeline to use How does it works ? My setu…

---

## [FileBeat - awscloudwatch input config](https://discuss.elastic.co/t/filebeat-awscloudwatch-input-config/259761)

<div class="topic-metadata">

**Author:** [@Zorkmid](https://discuss.elastic.co/u/Zorkmid)\
**Replies:** 0\
**Last updated:** [December 28, 2020, 10:07pm UTC](https://discuss.elastic.co/t/filebeat-awscloudwatch-input-config/259761 "2020-12-28T22:07:04Z")

</div>

Hello Everyone, I have attempted to use the awscloudwatch input type in my FileBeat setup as follows but the appropriate ARN for the account I'm dealing with. The AWS credentials file has the correct ID keys and these …

---

## [Search\_phase\_execution\_exception filebeat all shards failed](https://discuss.elastic.co/t/search-phase-execution-exception-filebeat-all-shards-failed/259755)

<div class="topic-metadata">

**Author:** [@whosecode](https://discuss.elastic.co/u/whosecode)\
**Replies:** 1\
**Last updated:** [December 29, 2020, 1:11am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-filebeat-all-shards-failed/259755 "2020-12-29T01:11:42Z")

</div>

Hi! My ealstic cluster overview panel shows health yellow as shards are missing, and I get below reponses whenever I try to produce some visualization, or dashboard search\_phase\_execution\_exception all shards failed E…

---

## [Simple Observability of Metrics from Apache Spark](https://discuss.elastic.co/t/simple-observability-of-metrics-from-apache-spark/259760)

<div class="topic-metadata">

**Author:** [@bplies](https://discuss.elastic.co/u/bplies)\
**Replies:** 0\
**Last updated:** [December 28, 2020, 9:31pm UTC](https://discuss.elastic.co/t/simple-observability-of-metrics-from-apache-spark/259760 "2020-12-28T21:31:48Z")

</div>

We're trying to collect basic metrics from Apache Spark. We realize there are Hadoop Metrics provided by ES-Hadoop but it seems just so heavy-handed for what we want. We are not trying to tie in full featured interacti…

---

## [Filebeat multiline config doesn't work with S3 input](https://discuss.elastic.co/t/filebeat-multiline-config-doesnt-work-with-s3-input/259756)

<div class="topic-metadata">

**Author:** [@bplies](https://discuss.elastic.co/u/bplies)\
**Replies:** 0\
**Last updated:** [December 28, 2020, 7:03pm UTC](https://discuss.elastic.co/t/filebeat-multiline-config-doesnt-work-with-s3-input/259756 "2020-12-28T19:03:47Z")

</div>

Elastic Cloud hosting Elasticsearch 7.10.0 Filebeat 7.10.1 We've been unable to get files from S3 input to successfully apply the configured multiline options on that input. Despite our best efforts, lines that shoul…

---

## [Can't get filebeat Netflow Module to work](https://discuss.elastic.co/t/cant-get-filebeat-netflow-module-to-work/258459)

<div class="topic-metadata">

**Author:** [@Gambit22](https://discuss.elastic.co/u/Gambit22)\
**Replies:** 4\
**Last updated:** [December 28, 2020, 6:36pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-netflow-module-to-work/258459 "2020-12-28T18:36:14Z")

</div>

Hello Everyone, I've been pulling my hair out trying to understand why Filebeat's net flow module keeps causing filebeats to end. Heres the error it keeps outputting: 2020-12-11T17:42:22.025-0700 ERROR instance/be…

---

## [Filebeat code=exited, status=1/FAILURE](https://discuss.elastic.co/t/filebeat-code-exited-status-1-failure/258926)

<div class="topic-metadata">

**Author:** [@dave.mc](https://discuss.elastic.co/u/dave.mc)\
**Replies:** 23\
**Last updated:** [December 28, 2020, 6:11pm UTC](https://discuss.elastic.co/t/filebeat-code-exited-status-1-failure/258926 "2020-12-28T18:11:57Z")

</div>

Newbie here, so think basic. :slightly\_smiling\_face: Filebeat service won't start (on Debian), fails with code=exited, status=1/FAILURE. If I run filebeat -v -e -d "\*", I get: Exiting: error loading config file: yaml…

---

## [Don't drop event postgresql.activity.query](https://discuss.elastic.co/t/dont-drop-event-postgresql-activity-query/259749)

<div class="topic-metadata">

**Author:** [@Guto\_Ribeiro](https://discuss.elastic.co/u/Guto_Ribeiro)\
**Replies:** 0\
**Last updated:** [December 28, 2020, 5:25pm UTC](https://discuss.elastic.co/t/dont-drop-event-postgresql-activity-query/259749 "2020-12-28T17:25:50Z")

</div>

Hello guys, I'm using metricbeat to collect metrics from postgresql, via the postgresql module. I need to drop events with: postgresql.activity.query: "COMMIT" postgresql.activity.query: "" In the metrcibeat configu…

---

## [7.10.1 upgrade and GrokProcessor Error](https://discuss.elastic.co/t/7-10-1-upgrade-and-grokprocessor-error/259647)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [December 28, 2020, 5:26pm UTC](https://discuss.elastic.co/t/7-10-1-upgrade-and-grokprocessor-error/259647 "2020-12-28T17:26:23Z")

</div>

After I upgraded to 7.10.1 I am started getting following error. more investigation turn up following links to fix it. https://github.com/elastic/beats/issues/15840 https://discuss.elastic.co/t/es-7-6-regular-express…

---

## [What's the proper way to set the op\_type metadata field?](https://discuss.elastic.co/t/whats-the-proper-way-to-set-the-op-type-metadata-field/258323)

<div class="topic-metadata">

**Author:** [@jdmcalee](https://discuss.elastic.co/u/jdmcalee)\
**Replies:** 1\
**Last updated:** [December 28, 2020, 2:36pm UTC](https://discuss.elastic.co/t/whats-the-proper-way-to-set-the-op-type-metadata-field/258323 "2020-12-28T14:36:55Z")

</div>

I am trying to have filebeat use the index operation rather than create, and after digging through the beats source code, I came to this pull request where support was added to set the @metadata.op\_type field to index, c…

---

## [Elastic Agent and other Beats not run](https://discuss.elastic.co/t/elastic-agent-and-other-beats-not-run/259730)

<div class="topic-metadata">

**Author:** [@Minh\_Ti\_n\_Tr\_n](https://discuss.elastic.co/u/Minh_Ti_n_Tr_n)\
**Replies:** 0\
**Last updated:** [December 28, 2020, 12:20pm UTC](https://discuss.elastic.co/t/elastic-agent-and-other-beats-not-run/259730 "2020-12-28T12:20:16Z")

</div>

I install ELK in single-node mode with following configuration Host IP: 192.168.87.47 Elasticsearch.yml network.host: 0.0.0.0 node.name: elasticsearch cluster.initial\_master\_nodes: elasticsearch # Transport layer xpa…

---

## [Cisco core switch integration](https://discuss.elastic.co/t/cisco-core-switch-integration/259711)

<div class="topic-metadata">

**Author:** [@sbathla](https://discuss.elastic.co/u/sbathla)\
**Replies:** 3\
**Last updated:** [December 28, 2020, 9:18am UTC](https://discuss.elastic.co/t/cisco-core-switch-integration/259711 "2020-12-28T09:18:09Z")

</div>

Hi All, I am trying to integrate elasticsearch with cisco core switch.I have done the required configuration in filebeat file and cisco module file. But while sending logs from core switch on port 9506, getting error t…

---

## [Can we use datastreams with Filebeat?659+](https://discuss.elastic.co/t/can-we-use-datastreams-with-filebeat-659/259693)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [December 27, 2020, 6:26pm UTC](https://discuss.elastic.co/t/can-we-use-datastreams-with-filebeat-659/259693 "2020-12-27T18:26:12Z")

</div>

Hello, So "Can we use datastreams with Filebeat?" And more importantly, can we mix multiple inputs, where some use legacy ilm and some use datastreams? This is in a test 7.10.1 setup without Logstash. For example until…

---

## [Fail to parse HTTP parameters: parse "response\\"}}\\nPOST /\_bulk": net/url: invalid control character in](https://discuss.elastic.co/t/fail-to-parse-http-parameters-parse-response-npost-bulk-net-url-invalid-control-character-in/259652)

<div class="topic-metadata">

**Author:** [@Alir3z4](https://discuss.elastic.co/u/Alir3z4)\
**Replies:** 0\
**Last updated:** [December 25, 2020, 11:18pm UTC](https://discuss.elastic.co/t/fail-to-parse-http-parameters-parse-response-npost-bulk-net-url-invalid-control-character-in/259652 "2020-12-25T23:18:40Z")

</div>

I'm running packetbeat version 7.10.1; Looking at its logs I see 2020-12-25T23:08:29.956Z WARN http/http.go:545 Fail to parse HTTP parameters: parse "response\\"}}\\nPOST /\_bulk": net/url: invalid contro…

---

## [Journalbeat no connection event](https://discuss.elastic.co/t/journalbeat-no-connection-event/259633)

<div class="topic-metadata">

**Author:** [@Catherine](https://discuss.elastic.co/u/Catherine)\
**Replies:** 0\
**Last updated:** [December 25, 2020, 12:46pm UTC](https://discuss.elastic.co/t/journalbeat-no-connection-event/259633 "2020-12-25T12:46:17Z")

</div>

Hello I have a problem with no attempt to connect from journalbeat to logstash, even no errors (nothing at all). How to troubleshoot this problem? 2020-12-25T12:38:28.195Z INFO instance/beat.go:299 Setup …

---

## [Filebeat-logstash issue](https://discuss.elastic.co/t/filebeat-logstash-issue/259576)

<div class="topic-metadata">

**Author:** [@mustafa.husny](https://discuss.elastic.co/u/mustafa.husny)\
**Replies:** 2\
**Last updated:** [December 24, 2020, 12:55pm UTC](https://discuss.elastic.co/t/filebeat-logstash-issue/259576 "2020-12-24T12:55:57Z")

</div>

I am using ELK 7.6.2 I have three piplines first for the heartbeat second for the tcp to forward logs from QRadar Third is for filebeat I am receiving logs from heartbeat and qradar, but when I installed filebeat on…

---

## [Filter logstash with grok not work](https://discuss.elastic.co/t/filter-logstash-with-grok-not-work/259324)

<div class="topic-metadata">

**Author:** [@eebor](https://discuss.elastic.co/u/eebor)\
**Replies:** 5\
**Last updated:** [December 24, 2020, 12:31pm UTC](https://discuss.elastic.co/t/filter-logstash-with-grok-not-work/259324 "2020-12-24T12:31:10Z")

</div>

anyone can help, i want to filter my log this is my log {Level:info Time:2020-12-03 12:14:28.203517503 +0700 WIB m=+18300.336235694 LoggerName: somefield Message://app/snmaterialdetail/4550554942/V222FAK-BA341T Caller:…

---

## [Enrich documents with another json file](https://discuss.elastic.co/t/enrich-documents-with-another-json-file/259004)

<div class="topic-metadata">

**Author:** [@anon42972578](https://discuss.elastic.co/u/anon42972578)\
**Replies:** 1\
**Last updated:** [December 24, 2020, 10:47am UTC](https://discuss.elastic.co/t/enrich-documents-with-another-json-file/259004 "2020-12-24T10:47:57Z")

</div>

Hello, we have a server with logfiles in directories: /xxx/log1/ - test-1.log - test-2.log - enrich-log1.json /xxx/log2/ - test-1.log - test-2.log - enrich-log2.json and so on.... the json file "enrich-log\*.json" ha…

---

## [Winlogbeat unable to keep up with AD security logs](https://discuss.elastic.co/t/winlogbeat-unable-to-keep-up-with-ad-security-logs/259582)

<div class="topic-metadata">

**Author:** [@zhumphries](https://discuss.elastic.co/u/zhumphries)\
**Replies:** 0\
**Last updated:** [December 24, 2020, 10:39am UTC](https://discuss.elastic.co/t/winlogbeat-unable-to-keep-up-with-ad-security-logs/259582 "2020-12-24T10:39:49Z")

</div>

Hello. We have recently started using winlogbeat to collect security logs from the Domain Controllers but winlogbeat is struggling to keep up with the required ingest rate. The server in question is generating approx 30…

---

## [Error while using ssl with basic authorization](https://discuss.elastic.co/t/error-while-using-ssl-with-basic-authorization/258839)

<div class="topic-metadata">

**Author:** [@loker](https://discuss.elastic.co/u/loker)\
**Replies:** 4\
**Last updated:** [December 24, 2020, 9:19am UTC](https://discuss.elastic.co/t/error-while-using-ssl-with-basic-authorization/258839 "2020-12-24T09:19:58Z")

</div>

Hello, Here is my config: - module: couchdb metricsets: \["server"\] period: 10s hosts: \["https://xxx.xxxx.xxx.xxx:6984/\_node/\_local/\_stats"\] ssl.verification\_mode: "none" username: xxxxx password: xxxxx I w…

---

## [Filebeat Fortinet module can't run](https://discuss.elastic.co/t/filebeat-fortinet-module-cant-run/258541)

<div class="topic-metadata">

**Author:** [@aloalo2242](https://discuss.elastic.co/u/aloalo2242)\
**Replies:** 5\
**Last updated:** [December 24, 2020, 9:10am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-cant-run/258541 "2020-12-24T09:10:34Z")

</div>

Hi, I'm trying to ship Fortigate300E Log to my Elasticstack with topo: Fortigate syslog port 514 -\> Filebeat (fortinet module) -\> Elasticsearch -\> Kibana. I have 2 question: First, is it possible? And when I run fileb…

---

## [Filebeat O365 Module Through proxy](https://discuss.elastic.co/t/filebeat-o365-module-through-proxy/259570)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 0\
**Last updated:** [December 24, 2020, 9:10am UTC](https://discuss.elastic.co/t/filebeat-o365-module-through-proxy/259570 "2020-12-24T09:10:20Z")

</div>

Hi all I have a problems with using the o365 module in filebeat. In our network in order to reach internet we need to go through a proxy server, and it is because of that the filebeat module cannot connect to the o365 …

---

## [Systemd version conflict / bug on journalbeat](https://discuss.elastic.co/t/systemd-version-conflict-bug-on-journalbeat/259569)

<div class="topic-metadata">

**Author:** [@DenizParlak](https://discuss.elastic.co/u/DenizParlak)\
**Replies:** 0\
**Last updated:** [December 24, 2020, 9:06am UTC](https://discuss.elastic.co/t/systemd-version-conflict-bug-on-journalbeat/259569 "2020-12-24T09:06:16Z")

</div>

Hi all, Our journalbeat deployed on the Kubernetes cluster and stopped shipping logs to the elasticsearch via logstash suddenly. We got this error message first: /var/log/journal/ec28d502b342fad1a4d44d3a101845cf/system…

---

## [Multiple auditbeat file\_integrity module configurations](https://discuss.elastic.co/t/multiple-auditbeat-file-integrity-module-configurations/259540)

<div class="topic-metadata">

**Author:** [@p\_ansell](https://discuss.elastic.co/u/p_ansell)\
**Replies:** 0\
**Last updated:** [December 24, 2020, 1:14am UTC](https://discuss.elastic.co/t/multiple-auditbeat-file-integrity-module-configurations/259540 "2020-12-24T01:14:02Z")

</div>

I have had issues in the past with the flexibility of the auditbeat file\_integrity module configuration. On one hand I want to monitor most changes under /etc and similar directories, but on another hand I also want to m…

---

## [Why are the arm64 builds hidden?](https://discuss.elastic.co/t/why-are-the-arm64-builds-hidden/258860)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 1\
**Last updated:** [December 23, 2020, 10:43pm UTC](https://discuss.elastic.co/t/why-are-the-arm64-builds-hidden/258860 "2020-12-23T22:43:38Z")

</div>

A few weeks ago ARM64 builds for most beats were available on the download page - now they are hidden but still on artifacts, i.e: https://artifacts.elastic.co/downloads/beats/packetbeat/packetbeat-7.9.0-arm64.deb Can …

---

## [Zeek - Filebeat module and Processors for DNS Lookups](https://discuss.elastic.co/t/zeek-filebeat-module-and-processors-for-dns-lookups/259163)

<div class="topic-metadata">

**Author:** [@thinkagain](https://discuss.elastic.co/u/thinkagain)\
**Replies:** 5\
**Last updated:** [December 23, 2020, 9:30pm UTC](https://discuss.elastic.co/t/zeek-filebeat-module-and-processors-for-dns-lookups/259163 "2020-12-23T21:30:56Z")

</div>

hi everyone, I'm trying to get acquainted with the ELK platform and trying to understand how the different modules interact with each other. Besides the (internal) ip addresses I would like the result of a dns lookup i…

---

## [Winlogbeat not dropping multicast traffic using drop\_event.when.or](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428)

<div class="topic-metadata">

**Author:** [@jtillman2020](https://discuss.elastic.co/u/jtillman2020)\
**Replies:** 6\
**Last updated:** [December 23, 2020, 5:58pm UTC](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428 "2020-12-23T17:58:40Z")

</div>

Using drop\_event.when.or I've attempted to exclude multicast traffic logs from being sent over as well as logs containing the keyword "zabbix". However, I am still receiving these events. winlogbeat.event\_logs: - name…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=187)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=189)
