# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=191

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 192

---

## [Error creating connection to Oracle](https://discuss.elastic.co/t/error-creating-connection-to-oracle/257980)

<div class="topic-metadata">

**Author:** [@jenssc](https://discuss.elastic.co/u/jenssc)\
**Replies:** 24\
**Last updated:** [December 15, 2020, 6:24am UTC](https://discuss.elastic.co/t/error-creating-connection-to-oracle/257980 "2020-12-15T06:24:06Z")

</div>

Hi I'm having a lot of problems getting the metricbeat connect to my Oracle database! What ever I'm trying to put in my YML-file I always end up with this error: Error fetching data for metricset oracle.tablespace: er…

---

## [What security roles or rights does functionbeat require for the username in the output.elasticsearch?](https://discuss.elastic.co/t/what-security-roles-or-rights-does-functionbeat-require-for-the-username-in-the-output-elasticsearch/258646)

<div class="topic-metadata">

**Author:** [@Jonathan\_Detert](https://discuss.elastic.co/u/Jonathan_Detert)\
**Replies:** 0\
**Last updated:** [December 14, 2020, 8:52pm UTC](https://discuss.elastic.co/t/what-security-roles-or-rights-does-functionbeat-require-for-the-username-in-the-output-elasticsearch/258646 "2020-12-14T20:52:35Z")

</div>

I want to create an elasticsearch user for function beat to use in the output.elasticsearch section. The documentation doesn't say anything about what rights or roles within elasticsearch the user will need. Can someon…

---

## [No enrollment token for Fleet Agent](https://discuss.elastic.co/t/no-enrollment-token-for-fleet-agent/258453)

<div class="topic-metadata">

**Author:** [@AirJordan](https://discuss.elastic.co/u/AirJordan)\
**Replies:** 2\
**Last updated:** [December 14, 2020, 9:16pm UTC](https://discuss.elastic.co/t/no-enrollment-token-for-fleet-agent/258453 "2020-12-14T21:16:31Z")

</div>

I went to do the wizard for creating a fleet agent user and let it setup everything. When I clicked create user all of a sudden it timed out my web session. I went back in and the user for fleet enrollment is there. The …

---

## [Filebeat Cisco Umbrella module](https://discuss.elastic.co/t/filebeat-cisco-umbrella-module/256811)

<div class="topic-metadata">

**Author:** [@Massimo\_Brogioni](https://discuss.elastic.co/u/Massimo_Brogioni)\
**Replies:** 1\
**Last updated:** [December 14, 2020, 12:30pm UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella-module/256811 "2020-12-14T12:30:31Z")

</div>

Hi, I am trying to configure filebeat to get logs from Cisco Umbrella but something don't work. The logs are in a bucket Cisco managed. If I try to list the bucket I am successful, with: /usr/local/bin/aws s3 ls s3://…

---

## [Index name based on docker-compose service name](https://discuss.elastic.co/t/index-name-based-on-docker-compose-service-name/258468)

<div class="topic-metadata">

**Author:** [@fulkon](https://discuss.elastic.co/u/fulkon)\
**Replies:** 3\
**Last updated:** [December 14, 2020, 11:45am UTC](https://discuss.elastic.co/t/index-name-based-on-docker-compose-service-name/258468 "2020-12-14T11:45:24Z")

</div>

Is there any way to set index name based on docker-compose service name? Corresponding name is in container.labels.com\_docker\_compose\_service field. Tried this in input: - type: container paths: - '/…

---

## [Cannot read property 'split' of undefined \[Winlogbeat\]](https://discuss.elastic.co/t/cannot-read-property-split-of-undefined-winlogbeat/258365)

<div class="topic-metadata">

**Author:** [@ThreatInter](https://discuss.elastic.co/u/ThreatInter)\
**Replies:** 2\
**Last updated:** [December 14, 2020, 11:03am UTC](https://discuss.elastic.co/t/cannot-read-property-split-of-undefined-winlogbeat/258365 "2020-12-14T11:03:23Z")

</div>

Hello, everyone! We have troubles with our winlogbeat agent. Sometimes it writes error message "TypeError: Cannot read property 'split' of undefined at C:\\Program Files\\Winlogbeat/module/security/config/winlogbeat-secur…

---

## [Kubernetes metadata not showing (add\_kubernetes\_metadata)](https://discuss.elastic.co/t/kubernetes-metadata-not-showing-add-kubernetes-metadata/255538)

<div class="topic-metadata">

**Author:** [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Replies:** 5\
**Last updated:** [December 14, 2020, 10:24am UTC](https://discuss.elastic.co/t/kubernetes-metadata-not-showing-add-kubernetes-metadata/255538 "2020-12-14T10:24:00Z")

</div>

Hi, Im currently having issues with the add\_kubernetes\_metadata processor. Im adding a simple config and I've configured a service account to have permissions to query the cluster, but I cant get any metadata entry with…

---

## [Bug: Netflow events takes event.created from flow.timestamp](https://discuss.elastic.co/t/bug-netflow-events-takes-event-created-from-flow-timestamp/258487)

<div class="topic-metadata">

**Author:** [@shanavas786](https://discuss.elastic.co/u/shanavas786)\
**Replies:** 0\
**Last updated:** [December 12, 2020, 6:19pm UTC](https://discuss.elastic.co/t/bug-netflow-events-takes-event-created-from-flow-timestamp/258487 "2020-12-12T18:19:58Z")

</div>

As per documentation, event.created is the timestamp at which the event is read by agent/pipeline. Conversely, it is being copied from flow.Timestamp. Shouldn't it be time.Now() ?

---

## [Filebeat folder structured not correct for version 7.10](https://discuss.elastic.co/t/filebeat-folder-structured-not-correct-for-version-7-10/257927)

<div class="topic-metadata">

**Author:** [@kbirhan](https://discuss.elastic.co/u/kbirhan)\
**Replies:** 5\
**Last updated:** [December 12, 2020, 6:18am UTC](https://discuss.elastic.co/t/filebeat-folder-structured-not-correct-for-version-7-10/257927 "2020-12-12T06:18:57Z")

</div>

filebeat bin file location in the service file declared might be in the wrong location for debian platform. after moving the filebeat bin file (located in /usr/ share/filebeat/) to /usr/share/filebeat/bin/ folder everyt…

---

## [Grok Pattern against stdout](https://discuss.elastic.co/t/grok-pattern-against-stdout/258195)

<div class="topic-metadata">

**Author:** [@willis](https://discuss.elastic.co/u/willis)\
**Replies:** 4\
**Last updated:** [December 11, 2020, 9:21pm UTC](https://discuss.elastic.co/t/grok-pattern-against-stdout/258195 "2020-12-11T21:21:48Z")

</div>

I have a custom log format that is being sent to stdout. Filebeat is correctly capturing this output. I would like to apply a grok pattern against these lines and have them parsed/indexed. Is a pipeline, a processor, or …

---

## [Cannot load Filebeat 7.9.0 and higher template in Elasticsearch 6.8.12](https://discuss.elastic.co/t/cannot-load-filebeat-7-9-0-and-higher-template-in-elasticsearch-6-8-12/257663)

<div class="topic-metadata">

**Author:** [@aryon](https://discuss.elastic.co/u/aryon)\
**Replies:** 1\
**Last updated:** [December 11, 2020, 12:24pm UTC](https://discuss.elastic.co/t/cannot-load-filebeat-7-9-0-and-higher-template-in-elasticsearch-6-8-12/257663 "2020-12-11T12:24:11Z")

</div>

Hello, I am running an Elasticsearch 6.8.12 cluster and have Filebeats agent in various versions. I usually install the filebeat template using the export command : filebeat.exe export template --es.version 6.8.12 | Out…

---

## [How to know if logfile is finished harvested on windows for filebeat 7.10](https://discuss.elastic.co/t/how-to-know-if-logfile-is-finished-harvested-on-windows-for-filebeat-7-10/258056)

<div class="topic-metadata">

**Author:** [@eirik](https://discuss.elastic.co/u/eirik)\
**Replies:** 3\
**Last updated:** [December 11, 2020, 10:37am UTC](https://discuss.elastic.co/t/how-to-know-if-logfile-is-finished-harvested-on-windows-for-filebeat-7-10/258056 "2020-12-11T10:37:28Z")

</div>

I am running Filebeat 7.10 sending log events to logstash on Windows server 2016. As filebeat is not cleaning up logfiles I need to write my own script for this, but for this to work I need to know when the harvesting is…

---

## [Multiline breaking in blank line](https://discuss.elastic.co/t/multiline-breaking-in-blank-line/258359)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 1\
**Last updated:** [December 11, 2020, 3:42am UTC](https://discuss.elastic.co/t/multiline-breaking-in-blank-line/258359 "2020-12-11T03:42:04Z")

</div>

This has been reports a few times but I can not put the answer together. I would like these lines to arrive as one multiline. But they arrive as 5 lines. Which is odd because the pattern clearly only matches the first…

---

## [Filebeat / kubernetes / data loss](https://discuss.elastic.co/t/filebeat-kubernetes-data-loss/258322)

<div class="topic-metadata">

**Author:** [@elastic\_user1](https://discuss.elastic.co/u/elastic_user1)\
**Replies:** 1\
**Last updated:** [December 10, 2020, 7:20pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-data-loss/258322 "2020-12-10T19:20:15Z")

</div>

I am using following config https://raw.githubusercontent.com/elastic/beats/master/deploy/kubernetes/filebeat-kubernetes.yaml plus settings symlinks: true I have container'd containers with rotated logs by default. 5 lo…

---

## [Filebeat not loading env variables](https://discuss.elastic.co/t/filebeat-not-loading-env-variables/258328)

<div class="topic-metadata">

**Author:** [@francom1](https://discuss.elastic.co/u/francom1)\
**Replies:** 0\
**Last updated:** [December 10, 2020, 7:17pm UTC](https://discuss.elastic.co/t/filebeat-not-loading-env-variables/258328 "2020-12-10T19:17:48Z")

</div>

Hello everyone! I'm using this filebeats installation script in my deploys to ec2. files: "/etc/filebeat/filebeat.yml": mode: "000755" owner: root group: root content: | …

---

## [Metricbeat - resource 'metricbeat-7.10.0' exists, but it is not an alias](https://discuss.elastic.co/t/metricbeat-resource-metricbeat-7-10-0-exists-but-it-is-not-an-alias/258311)

<div class="topic-metadata">

**Author:** [@madhan0618](https://discuss.elastic.co/u/madhan0618)\
**Replies:** 1\
**Last updated:** [December 10, 2020, 6:20pm UTC](https://discuss.elastic.co/t/metricbeat-resource-metricbeat-7-10-0-exists-but-it-is-not-an-alias/258311 "2020-12-10T18:20:34Z")

</div>

Please help me understand this error message. I have metricbeat with kafka module running on each of my three kafka cluster nodes this is my metricbeat.yml file # =========================== Modules configuration ===…

---

## [Auditbeat: Prefix syscall arguments value with '0x' so that they can be handled by "convert" processor](https://discuss.elastic.co/t/auditbeat-prefix-syscall-arguments-value-with-0x-so-that-they-can-be-handled-by-convert-processor/258308)

<div class="topic-metadata">

**Author:** [@docteur\_saoul](https://discuss.elastic.co/u/docteur_saoul)\
**Replies:** 0\
**Last updated:** [December 10, 2020, 5:00pm UTC](https://discuss.elastic.co/t/auditbeat-prefix-syscall-arguments-value-with-0x-so-that-they-can-be-handled-by-convert-processor/258308 "2020-12-10T17:00:58Z")

</div>

Hi, I'm looking for a way to add the traced process metadata for ptrace events on linux. This could be done using the add\_process\_metadata and the PID (second argument of ptrace syscall). However, auditd.data.aX fields …

---

## [Filebeat "Provided Grok expressions do not match field value"](https://discuss.elastic.co/t/filebeat-provided-grok-expressions-do-not-match-field-value/258288)

<div class="topic-metadata">

**Author:** [@Taufik\_Maulana](https://discuss.elastic.co/u/Taufik_Maulana)\
**Replies:** 0\
**Last updated:** [December 10, 2020, 2:24pm UTC](https://discuss.elastic.co/t/filebeat-provided-grok-expressions-do-not-match-field-value/258288 "2020-12-10T14:24:02Z")

</div>

Hello everyone, i'm having issue where Filebeat cant extract (idk if its the right word) data from apache2 log. So, i have my ES and Grafana in the same server, then Filebeat on the other server. I didn't use Logstash a…

---

## [Auditbeat: monitoring of single files fails with 'recursive: true'](https://discuss.elastic.co/t/auditbeat-monitoring-of-single-files-fails-with-recursive-true/258287)

<div class="topic-metadata">

**Author:** [@matletix](https://discuss.elastic.co/u/matletix)\
**Replies:** 0\
**Last updated:** [December 10, 2020, 2:23pm UTC](https://discuss.elastic.co/t/auditbeat-monitoring-of-single-files-fails-with-recursive-true/258287 "2020-12-10T14:23:40Z")

</div>

Let's say I want to monitor the /watch\_me.txt file with auditbeat file\_integrity module. The following configuration do work and send events on modifications of this file : - module: file\_integrity enabled: true pat…

---

## [New filebeat instance does not add docker metadata to logs in elastic](https://discuss.elastic.co/t/new-filebeat-instance-does-not-add-docker-metadata-to-logs-in-elastic/256147)

<div class="topic-metadata">

**Author:** [@LudoNew](https://discuss.elastic.co/u/LudoNew)\
**Replies:** 5\
**Last updated:** [December 10, 2020, 1:57pm UTC](https://discuss.elastic.co/t/new-filebeat-instance-does-not-add-docker-metadata-to-logs-in-elastic/256147 "2020-12-10T13:57:24Z")

</div>

Hi there elastic community! This is my first post here, I hope it is according to standards. Recently, I've stumbled into a mysterious issue whose solution I cannot find. It is about docker metadata not being added to …

---

## [Heartbeat not starting](https://discuss.elastic.co/t/heartbeat-not-starting/256994)

<div class="topic-metadata">

**Author:** [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Replies:** 2\
**Last updated:** [December 10, 2020, 11:50am UTC](https://discuss.elastic.co/t/heartbeat-not-starting/256994 "2020-12-10T11:50:39Z")

</div>

Heartbeat not starting. Throwing below log. Please help me? Heartbeat version is 7.10 2020-11-29T07:52:16.218-0800 ERROR instance/beat.go:956 Exiting: could not create monitor: Monitor not loaded, plugin is dis…

---

## [Synthetic Monitoring](https://discuss.elastic.co/t/synthetic-monitoring/257829)

<div class="topic-metadata">

**Author:** [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Replies:** 1\
**Last updated:** [December 10, 2020, 10:51am UTC](https://discuss.elastic.co/t/synthetic-monitoring/257829 "2020-12-10T10:51:53Z")

</div>

Hi, I've been trying to use elastic synthetic monitoring for testing. when i tried to validate the heartbeat.docker.yml file, it failed. The script is causing this. I wasnt able to run the docker image because yaml is…

---

## [My packetbeat memory is growing continuously](https://discuss.elastic.co/t/my-packetbeat-memory-is-growing-continuously/258221)

<div class="topic-metadata">

**Author:** [@mysqldba](https://discuss.elastic.co/u/mysqldba)\
**Replies:** 3\
**Last updated:** [December 10, 2020, 7:38am UTC](https://discuss.elastic.co/t/my-packetbeat-memory-is-growing-continuously/258221 "2020-12-10T07:38:57Z")

</div>

could anyone help me on this problem? thanks in advance.

---

## [Fields count in elasticsearch indice](https://discuss.elastic.co/t/fields-count-in-elasticsearch-indice/258138)

<div class="topic-metadata">

**Author:** [@malcolm666](https://discuss.elastic.co/u/malcolm666)\
**Replies:** 9\
**Last updated:** [December 10, 2020, 6:42am UTC](https://discuss.elastic.co/t/fields-count-in-elasticsearch-indice/258138 "2020-12-10T06:42:52Z")

</div>

Hi. I have elasticsearch, Grafana and some beats deployed in k8s. Version is 7.6.1. There are some fields from my configuration: # env values - env: - name: cluster.name value: k8s-logs …

---

## [Winlogbeat ssl to elasticsearch](https://discuss.elastic.co/t/winlogbeat-ssl-to-elasticsearch/258039)

<div class="topic-metadata">

**Author:** [@ChrisDaniels](https://discuss.elastic.co/u/ChrisDaniels)\
**Replies:** 2\
**Last updated:** [December 10, 2020, 12:59am UTC](https://discuss.elastic.co/t/winlogbeat-ssl-to-elasticsearch/258039 "2020-12-10T00:59:48Z")

</div>

Followed the encrypting communications between nodes in a cluster and elasticsearch is running but now elasticsearch is not accepting connections from winlogbeat. When I run winlogbeat.exe test config-c winlogbeat.yml I…

---

## [Metricbeat: Error 1054: Unknown column 'quantile\_95' in 'field list'](https://discuss.elastic.co/t/metricbeat-error-1054-unknown-column-quantile-95-in-field-list/258190)

<div class="topic-metadata">

**Author:** [@gnumoksha](https://discuss.elastic.co/u/gnumoksha)\
**Replies:** 0\
**Last updated:** [December 9, 2020, 9:32pm UTC](https://discuss.elastic.co/t/metricbeat-error-1054-unknown-column-quantile-95-in-field-list/258190 "2020-12-09T21:32:50Z")

</div>

Version: metricbeat 7.10.0 Operating System: Linux agent01.monitoring.tflux.local 4.19.0-13-cloud-amd64 #1 SMP Debian 4.19.160-2 (2020-11-28) x86\_64 GNU/Linux Steps to Reproduce: /etc/metricbeat/modules.d/mysql.yml …

---

## [Any work arounds for this? - issue 21232](https://discuss.elastic.co/t/any-work-arounds-for-this-issue-21232/258173)

<div class="topic-metadata">

**Author:** [@madhan0618](https://discuss.elastic.co/u/madhan0618)\
**Replies:** 0\
**Last updated:** [December 9, 2020, 6:38pm UTC](https://discuss.elastic.co/t/any-work-arounds-for-this-issue-21232/258173 "2020-12-09T18:38:21Z")

</div>

I am running into this issue, I create custom indexes and when trying to import metricbeat dashboards for kafka, it is not working correctly. i have tried to edit the JSON and edit every reference of metricbeat-\* with…

---

## [Not getting indices log data from Elasticsearch/Filebeat in Kibana](https://discuss.elastic.co/t/not-getting-indices-log-data-from-elasticsearch-filebeat-in-kibana/258057)

<div class="topic-metadata">

**Author:** [@FREDDIE2020](https://discuss.elastic.co/u/FREDDIE2020)\
**Replies:** 3\
**Last updated:** [December 9, 2020, 9:17pm UTC](https://discuss.elastic.co/t/not-getting-indices-log-data-from-elasticsearch-filebeat-in-kibana/258057 "2020-12-09T21:17:32Z")

</div>

Hello, I am Not getting indices log data from Elasticsearch/Filebeat in Kibana to create my indexes any longer. How can I rectify this issue or what do I need to look at to try and find out the issues? Filebeat is dep…

---

## [Problem metricbeat with ssl](https://discuss.elastic.co/t/problem-metricbeat-with-ssl/258118)

<div class="topic-metadata">

**Author:** [@arp220](https://discuss.elastic.co/u/arp220)\
**Replies:** 1\
**Last updated:** [December 9, 2020, 7:02pm UTC](https://discuss.elastic.co/t/problem-metricbeat-with-ssl/258118 "2020-12-09T19:02:37Z")

</div>

Hi. I enable ssl for elasticsearch, elasticsearch config is : cluster.name: es-cluster path.data: /es-data/elasticsearch path.logs: /var/log/elasticsearch http.host: 0.0.0.0 network.host: 0 cluster.initial\_master\_nodes:…

---

## [How to index json attributes on ES from a json multiline log](https://discuss.elastic.co/t/how-to-index-json-attributes-on-es-from-a-json-multiline-log/258130)

<div class="topic-metadata">

**Author:** [@Luca\_P](https://discuss.elastic.co/u/Luca_P)\
**Replies:** 0\
**Last updated:** [December 9, 2020, 1:38pm UTC](https://discuss.elastic.co/t/how-to-index-json-attributes-on-es-from-a-json-multiline-log/258130 "2020-12-09T13:38:53Z")

</div>

Hi All, I need some advice here, I don't want to reinvent the wheel. With Filebeat 6.7.0 I'm picking up logs in typical docker format, , i.e. json strings with "log", "stream" and "time" attributes. In the logs, each …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=190)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=192)
