# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=189

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 190

---

## [Can you configure linger.ms in the kafka output?](https://discuss.elastic.co/t/can-you-configure-linger-ms-in-the-kafka-output/259501)

<div class="topic-metadata">

**Author:** [@shayrybak](https://discuss.elastic.co/u/shayrybak)\
**Replies:** 0\
**Last updated:** [December 23, 2020, 3:17pm UTC](https://discuss.elastic.co/t/can-you-configure-linger-ms-in-the-kafka-output/259501 "2020-12-23T15:17:38Z")

</div>

Hi, I've been running filebeat to send log files to kafka for processing, I've noticed that filebeat is lingering before sending the kafka batch for about 1 second. I'm assuming that is the default value in Sarama, howe…

---

## [Filebeat - How to disable "kube-system" namespace logs?](https://discuss.elastic.co/t/filebeat-how-to-disable-kube-system-namespace-logs/259313)

<div class="topic-metadata">

**Author:** [@David\_Fachini](https://discuss.elastic.co/u/David_Fachini)\
**Replies:** 5\
**Last updated:** [December 23, 2020, 3:15pm UTC](https://discuss.elastic.co/t/filebeat-how-to-disable-kube-system-namespace-logs/259313 "2020-12-23T15:15:42Z")

</div>

Hello, I am using Elasticsearch + Filebeat and Kibana. I have two namespaces "datastore" and "logging". I would like only to collect logs from those and avoid to harvest log from "kube-system". Checking in kibana I am a…

---

## [Auditbeat memory leak](https://discuss.elastic.co/t/auditbeat-memory-leak/259137)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 5\
**Last updated:** [December 23, 2020, 1:28pm UTC](https://discuss.elastic.co/t/auditbeat-memory-leak/259137 "2020-12-23T13:28:55Z")

</div>

Hi All, I was wondering if anyone else has noticed a memory leak with the last few version of Auditbeat? Currently running 7.10.0 (and had the issue in 7.8 and 7.9 as well) and I am seeing Auditbeat constantly being OO…

---

## [Create indices dynamically using filebeat by configuring filebeat.yml](https://discuss.elastic.co/t/create-indices-dynamically-using-filebeat-by-configuring-filebeat-yml/259473)

<div class="topic-metadata">

**Author:** [@kibelk22](https://discuss.elastic.co/u/kibelk22)\
**Replies:** 0\
**Last updated:** [December 23, 2020, 11:13am UTC](https://discuss.elastic.co/t/create-indices-dynamically-using-filebeat-by-configuring-filebeat-yml/259473 "2020-12-23T11:13:39Z")

</div>

Hi guys, I would like to create indices dynamically using filebeat and ship it directly to elasticsearch without using logstash (too heavy for my use case) by configuring filebeat.yml. I have one csv file which I woul…

---

## [Filebeat logger didn't work](https://discuss.elastic.co/t/filebeat-logger-didnt-work/259468)

<div class="topic-metadata">

**Author:** [@dukeyang](https://discuss.elastic.co/u/dukeyang)\
**Replies:** 0\
**Last updated:** [December 23, 2020, 10:16am UTC](https://discuss.elastic.co/t/filebeat-logger-didnt-work/259468 "2020-12-23T10:16:37Z")

</div>

I create a new output type (ghttp), and creat a new logger logger = logp.NewLogger("http") I test my logger: 168 logger.Info("got events",events) 169 logp.L().Info("got events",events) my config was: logging.l…

---

## [Winlogbeat 7.10.0 Cannot start service (Error 1068)](https://discuss.elastic.co/t/winlogbeat-7-10-0-cannot-start-service-error-1068/259461)

<div class="topic-metadata">

**Author:** [@flavia\_b](https://discuss.elastic.co/u/flavia_b)\
**Replies:** 0\
**Last updated:** [December 23, 2020, 8:59am UTC](https://discuss.elastic.co/t/winlogbeat-7-10-0-cannot-start-service-error-1068/259461 "2020-12-23T08:59:34Z")

</div>

Hi there, I am struggling with winlogbeat 7.10.0. I installed the service in 68 hosts and everything seems fine (configuration and msi deployed via group policy). But there are a some hosts that fail to start the serv…

---

## [Drop field with dynamic name in filebeat](https://discuss.elastic.co/t/drop-field-with-dynamic-name-in-filebeat/259457)

<div class="topic-metadata">

**Author:** [@malcolm666](https://discuss.elastic.co/u/malcolm666)\
**Replies:** 0\
**Last updated:** [December 23, 2020, 8:15am UTC](https://discuss.elastic.co/t/drop-field-with-dynamic-name-in-filebeat/259457 "2020-12-23T08:15:34Z")

</div>

Hi. I have filebeat (version 7.6.1) deployed in k8s and some application. This application generates a lot of json data that is parsed. I want to drop some json fields from the filebeat output. The problem is that the n…

---

## [Filebeat don't harvest log](https://discuss.elastic.co/t/filebeat-dont-harvest-log/258234)

<div class="topic-metadata">

**Author:** [@W1nter-3Z](https://discuss.elastic.co/u/W1nter-3Z)\
**Replies:** 7\
**Last updated:** [December 23, 2020, 2:08am UTC](https://discuss.elastic.co/t/filebeat-dont-harvest-log/258234 "2020-12-23T02:08:42Z")

</div>

Filebeat can't harvest log after restart I deploy filebeat with docker , but it can't harvest log after restart while log is still appended to the logFile. the log doesn't show the log path I configued in filebeat.yml. …

---

## [Send log records with Filebeat over TCP](https://discuss.elastic.co/t/send-log-records-with-filebeat-over-tcp/259331)

<div class="topic-metadata">

**Author:** [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Replies:** 4\
**Last updated:** [December 23, 2020, 12:19am UTC](https://discuss.elastic.co/t/send-log-records-with-filebeat-over-tcp/259331 "2020-12-23T00:19:46Z")

</div>

Is there a way to send filebeats output to a TCP socket? I have tried using output.logstash As written - The Logstash output sends events directly to Logstash by using the lumberjack protocol, which runs over TCP. But…

---

## [Filebeat - Force filebeat to read custom log from different pod paths](https://discuss.elastic.co/t/filebeat-force-filebeat-to-read-custom-log-from-different-pod-paths/259320)

<div class="topic-metadata">

**Author:** [@David\_Fachini](https://discuss.elastic.co/u/David_Fachini)\
**Replies:** 6\
**Last updated:** [December 22, 2020, 10:41pm UTC](https://discuss.elastic.co/t/filebeat-force-filebeat-to-read-custom-log-from-different-pod-paths/259320 "2020-12-22T22:41:08Z")

</div>

Hello, using Elastic + Filebeat + kibana in kubernetes. I have a lot of products running in cluster (apache kafka, apache druid, postgresql). Checking filebeat behavior it harvest logs from /var/lib/docker/containers/ …

---

## [Error: Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/error-failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/259409)

<div class="topic-metadata">

**Author:** [@Jonathan\_Davis](https://discuss.elastic.co/u/Jonathan_Davis)\
**Replies:** 0\
**Last updated:** [December 22, 2020, 4:35pm UTC](https://discuss.elastic.co/t/error-failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/259409 "2020-12-22T16:35:22Z")

</div>

Good time of the day! I have got a problem with a launch of Filebeat. It doen't want to start. Here is a text of error: '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''…

---

## [Filebeat F5 AFM Module Log Format](https://discuss.elastic.co/t/filebeat-f5-afm-module-log-format/259106)

<div class="topic-metadata">

**Author:** [@cyber\_crab](https://discuss.elastic.co/u/cyber_crab)\
**Replies:** 4\
**Last updated:** [December 22, 2020, 4:15pm UTC](https://discuss.elastic.co/t/filebeat-f5-afm-module-log-format/259106 "2020-12-22T16:15:56Z")

</div>

We're currently trying to get the bigipafm fileset in the F5 module to parse the logs that are incoming from the F5 appliance. The documentation is missing the required log format, as well as the F5 AFM versions that are…

---

## [Filebeat Fortinet have error message](https://discuss.elastic.co/t/filebeat-fortinet-have-error-message/258261)

<div class="topic-metadata">

**Author:** [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Replies:** 7\
**Last updated:** [December 22, 2020, 2:34pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-have-error-message/258261 "2020-12-22T14:34:04Z")

</div>

Hi @P1llus, I saw you're the person that give more comment on Filebeat Fortinet module, so I directly ask for help. I just send my fortinet log into my rsyslog server and save it into the file then I enabled the fortin…

---

## [\[Filebeat\] Redis Cluster support](https://discuss.elastic.co/t/filebeat-redis-cluster-support/259107)

<div class="topic-metadata">

**Author:** [@Henrikaya](https://discuss.elastic.co/u/Henrikaya)\
**Replies:** 1\
**Last updated:** [December 22, 2020, 10:42am UTC](https://discuss.elastic.co/t/filebeat-redis-cluster-support/259107 "2020-12-22T10:42:04Z")

</div>

Hi Beats team, My company is planning to move from Redis "classic" (single instance) to Redis Cluster very soon, which is used in our platform for business usages, but also for logging purposes with Filebeat. When tryi…

---

## [My cluster stopped ingesting due to low disk space but beats did not seem to recover all missed events](https://discuss.elastic.co/t/my-cluster-stopped-ingesting-due-to-low-disk-space-but-beats-did-not-seem-to-recover-all-missed-events/258210)

<div class="topic-metadata">

**Author:** [@netfire](https://discuss.elastic.co/u/netfire)\
**Replies:** 1\
**Last updated:** [December 22, 2020, 6:52am UTC](https://discuss.elastic.co/t/my-cluster-stopped-ingesting-due-to-low-disk-space-but-beats-did-not-seem-to-recover-all-missed-events/258210 "2020-12-22T06:52:51Z")

</div>

Newbie here. I had an event the other day due to not minding my index lifecycle policies. The cluster went yellow as there were unallocated shards (seemed like shards had moved completely off the first node to hit the di…

---

## [Filebeat IBMMQ module logs](https://discuss.elastic.co/t/filebeat-ibmmq-module-logs/257499)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 6\
**Last updated:** [December 22, 2020, 6:28am UTC](https://discuss.elastic.co/t/filebeat-ibmmq-module-logs/257499 "2020-12-22T06:28:49Z")

</div>

Hi Team, We are trying to integrate IBMMQ logs to elasticsearch using filebeat and its default ibmmq module. We are able to see the logs getting send to the elasticsearch from the filebeat debug logs. But we are unable…

---

## [Filebeat Event Hub Beat - Stuck on Blob already exists](https://discuss.elastic.co/t/filebeat-event-hub-beat-stuck-on-blob-already-exists/259307)

<div class="topic-metadata">

**Author:** [@jkaufmanlr](https://discuss.elastic.co/u/jkaufmanlr)\
**Replies:** 2\
**Last updated:** [December 21, 2020, 10:58pm UTC](https://discuss.elastic.co/t/filebeat-event-hub-beat-stuck-on-blob-already-exists/259307 "2020-12-21T22:58:14Z")

</div>

I know I have another topic open but this I am kind of stuck on: PUT https://storageName.blob.core.windows.net/hubName/0?timeout=61 Authorization: REDACTED RESPONSE Status: 409 The specified blob already exists. ERRO…

---

## [Filebeats issue](https://discuss.elastic.co/t/filebeats-issue/258255)

<div class="topic-metadata">

**Author:** [@egS](https://discuss.elastic.co/u/egS)\
**Replies:** 1\
**Last updated:** [December 21, 2020, 10:38pm UTC](https://discuss.elastic.co/t/filebeats-issue/258255 "2020-12-21T22:38:45Z")

</div>

Trying to get IBM MQ logs. Have success with the following commands and actions: curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.10.1-x86\_64.rpm sudo rpm -vi filebeat-7.10.1-x86\_64.rpm Modif…

---

## [Make Beats listen on localhost AND external IPs?](https://discuss.elastic.co/t/make-beats-listen-on-localhost-and-external-ips/259278)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 2\
**Last updated:** [December 21, 2020, 10:01pm UTC](https://discuss.elastic.co/t/make-beats-listen-on-localhost-and-external-ips/259278 "2020-12-21T22:01:43Z")

</div>

Hello I want to able to make Beats all listen on the localhost AND on the external IP (or at least bind it to a IP) All I see is creating a reverse proxy with Nginx and its something I rather avoid. How can I do this? …

---

## [Run two winlogbeat instances on the same machine](https://discuss.elastic.co/t/run-two-winlogbeat-instances-on-the-same-machine/259238)

<div class="topic-metadata">

**Author:** [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Replies:** 3\
**Last updated:** [December 21, 2020, 9:58pm UTC](https://discuss.elastic.co/t/run-two-winlogbeat-instances-on-the-same-machine/259238 "2020-12-21T21:58:56Z")

</div>

Hi, I want to send my winlogbeat data to two different ES clusters. As far as I know, winlogbeat can't have several outputs. Is there a way to run two winlogbeat instances with different configs on the same machine?

---

## [Filebeat data extra Fields not populating in raw logs](https://discuss.elastic.co/t/filebeat-data-extra-fields-not-populating-in-raw-logs/259033)

<div class="topic-metadata">

**Author:** [@jkaufmanlr](https://discuss.elastic.co/u/jkaufmanlr)\
**Replies:** 2\
**Last updated:** [December 21, 2020, 5:50pm UTC](https://discuss.elastic.co/t/filebeat-data-extra-fields-not-populating-in-raw-logs/259033 "2020-12-21T17:50:04Z")

</div>

There are some additional log variables that I want ingesting into my logstash. I have the logs ingesting and can see the Event Hub Beats just fine. But these specific values that I will be able to spot within event hub …

---

## [Filebeat not reading .out file from filebeat.inputs path](https://discuss.elastic.co/t/filebeat-not-reading-out-file-from-filebeat-inputs-path/258413)

<div class="topic-metadata">

**Author:** [@arjun\_gowda](https://discuss.elastic.co/u/arjun_gowda)\
**Replies:** 3\
**Last updated:** [December 21, 2020, 12:05pm UTC](https://discuss.elastic.co/t/filebeat-not-reading-out-file-from-filebeat-inputs-path/258413 "2020-12-21T12:05:56Z")

</div>

Filebeat is not reading .out file from filebeat.inputs path. I want to read the nohup.out files in the log folder. Please help me with the configuration Here's the filebeat.yml. filebeat.inputs: type: log Change to t…

---

## [JournalBeat Stopped Shipping Logs](https://discuss.elastic.co/t/journalbeat-stopped-shipping-logs/259195)

<div class="topic-metadata">

**Author:** [@vamshisiddarth](https://discuss.elastic.co/u/vamshisiddarth)\
**Replies:** 2\
**Last updated:** [December 21, 2020, 10:22am UTC](https://discuss.elastic.co/t/journalbeat-stopped-shipping-logs/259195 "2020-12-21T10:22:22Z")

</div>

JournalBeat stopped shipping logs on all environments for us from 19th Dec, 2020. We configured our beats services to ship logs from aws instance to elasticsearch through logstash. Our filebeat and metricbeat logs are be…

---

## [How to config filebeat to collect containerd logs file in K8S?](https://discuss.elastic.co/t/how-to-config-filebeat-to-collect-containerd-logs-file-in-k8s/259237)

<div class="topic-metadata">

**Author:** [@hillbun](https://discuss.elastic.co/u/hillbun)\
**Replies:** 0\
**Last updated:** [December 21, 2020, 9:53am UTC](https://discuss.elastic.co/t/how-to-config-filebeat-to-collect-containerd-logs-file-in-k8s/259237 "2020-12-21T09:53:36Z")

</div>

apiVersion: v1 kind: ConfigMap metadata: name: filebeat-inputs namespace: kube-system labels: k8s-app: filebeat data: kubernetes.yml: |- - type: container symlinks: true paths: - '/var/log/containers/\*.log' …

---

## [How to make input processor process all data?](https://discuss.elastic.co/t/how-to-make-input-processor-process-all-data/259067)

<div class="topic-metadata">

**Author:** [@dukeyang](https://discuss.elastic.co/u/dukeyang)\
**Replies:** 2\
**Last updated:** [December 19, 2020, 6:56am UTC](https://discuss.elastic.co/t/how-to-make-input-processor-process-all-data/259067 "2020-12-19T06:56:59Z")

</div>

In my application, there are multiple logs that need to process, I want every log has its own processors. BUT processors under specific input only process data collected by this input; - type: log paths: - ./data…

---

## [Correct way to setup the beats index patterns?](https://discuss.elastic.co/t/correct-way-to-setup-the-beats-index-patterns/258360)

<div class="topic-metadata">

**Author:** [@jclemons7](https://discuss.elastic.co/u/jclemons7)\
**Replies:** 5\
**Last updated:** [December 18, 2020, 8:12pm UTC](https://discuss.elastic.co/t/correct-way-to-setup-the-beats-index-patterns/258360 "2020-12-18T20:12:41Z")

</div>

Hello and thanks in advance for the guidance. I've been trying to figure this out on my own for a while, but I'm not having any luck so I thought I'd just finally ask. What is the CORRECT way to setup the indexes for t…

---

## [Startup Type missing data](https://discuss.elastic.co/t/startup-type-missing-data/258049)

<div class="topic-metadata">

**Author:** [@mjsteckiel](https://discuss.elastic.co/u/mjsteckiel)\
**Replies:** 6\
**Last updated:** [December 18, 2020, 8:02pm UTC](https://discuss.elastic.co/t/startup-type-missing-data/258049 "2020-12-18T20:02:17Z")

</div>

Hey all, We have been looking into the Windows Service metricset, and have found that none of the services are coming through with Startup Type data. We are following the metricset configuration - and there doesn't even…

---

## [Metricbeat don't get all mounting points for filesystems](https://discuss.elastic.co/t/metricbeat-dont-get-all-mounting-points-for-filesystems/259098)

<div class="topic-metadata">

**Author:** [@Vinicius\_Maia](https://discuss.elastic.co/u/Vinicius_Maia)\
**Replies:** 2\
**Last updated:** [December 18, 2020, 5:31pm UTC](https://discuss.elastic.co/t/metricbeat-dont-get-all-mounting-points-for-filesystems/259098 "2020-12-18T17:31:58Z")

</div>

Hello all, I need some help with a problem about my metricbeat setup. I'm trying to monitor my elasticsearch server disks with metricbeat. In the elasticsearch servers I created a LVM and mounted it in /var/lib/elasti…

---

## [Metricbeat AWS Module Issues](https://discuss.elastic.co/t/metricbeat-aws-module-issues/257976)

<div class="topic-metadata">

**Author:** [@Ganesh999](https://discuss.elastic.co/u/Ganesh999)\
**Replies:** 7\
**Last updated:** [December 18, 2020, 3:08pm UTC](https://discuss.elastic.co/t/metricbeat-aws-module-issues/257976 "2020-12-18T15:08:44Z")

</div>

Hi All, Have been trying to use the aws module in metrcibeat and have included all the related credentials required for authentication but it fails and gives the following error But the same credentials when used in…

---

## [Can't filebeat use multiple input/output config files in one instance?](https://discuss.elastic.co/t/cant-filebeat-use-multiple-input-output-config-files-in-one-instance/259095)

<div class="topic-metadata">

**Author:** [@iooi](https://discuss.elastic.co/u/iooi)\
**Replies:** 2\
**Last updated:** [December 18, 2020, 1:33pm UTC](https://discuss.elastic.co/t/cant-filebeat-use-multiple-input-output-config-files-in-one-instance/259095 "2020-12-18T13:33:30Z")

</div>

Want to deploy filebeat with 3 log definations together. Send to different output targets. --- apiVersion: apps/v1 kind: DaemonSet metadata: name: filebeat labels: k8s-app: filebeat spec: selector: matchLa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=188)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=190)
