# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=192

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 193

---

## [Filebeat Processors drop\_event](https://discuss.elastic.co/t/filebeat-processors-drop-event/257856)

<div class="topic-metadata">

**Author:** [@erezhazan1](https://discuss.elastic.co/u/erezhazan1)\
**Replies:** 2\
**Last updated:** [December 9, 2020, 12:50pm UTC](https://discuss.elastic.co/t/filebeat-processors-drop-event/257856 "2020-12-09T12:50:54Z")

</div>

Hey all! I need your help with the following, I'm trying to get this condition to work: If not (message: '^.dstintf="aaaa".' OR message: '^.dstintf="bbb".') AND NOT (message: '^.action="ccc".' AND message: '^.action=…

---

## [Netflow summarization of duplicate events](https://discuss.elastic.co/t/netflow-summarization-of-duplicate-events/258112)

<div class="topic-metadata">

**Author:** [@Srikanth\_Suresh](https://discuss.elastic.co/u/Srikanth_Suresh)\
**Replies:** 0\
**Last updated:** [December 9, 2020, 11:04am UTC](https://discuss.elastic.co/t/netflow-summarization-of-duplicate-events/258112 "2020-12-09T11:04:07Z")

</div>

Hello all! I am currently using Filebeat to send Netflow events into Elasticsearch. At certain time stamps I can observe 100,000 to 3 million events per second. Several of these events have the same data fields such a…

---

## [I am unable to Start Auditbeat service](https://discuss.elastic.co/t/i-am-unable-to-start-auditbeat-service/257814)

<div class="topic-metadata">

**Author:** [@shaiksubhan](https://discuss.elastic.co/u/shaiksubhan)\
**Replies:** 19\
**Last updated:** [December 9, 2020, 9:37am UTC](https://discuss.elastic.co/t/i-am-unable-to-start-auditbeat-service/257814 "2020-12-09T09:37:33Z")

</div>

HI Team, I am unable to install Auditbeat In my Linux version. I am getting this error: Exiting: 2 errors: 1 error: failed to create audit client: failed to get audit status: operation not permitted; 1 error: unable t…

---

## [Filebeat doesn\`t collect logs from Kubernetes cronjobs](https://discuss.elastic.co/t/filebeat-doesn-t-collect-logs-from-kubernetes-cronjobs/257859)

<div class="topic-metadata">

**Author:** [@malcolm666](https://discuss.elastic.co/u/malcolm666)\
**Replies:** 2\
**Last updated:** [December 9, 2020, 7:06am UTC](https://discuss.elastic.co/t/filebeat-doesn-t-collect-logs-from-kubernetes-cronjobs/257859 "2020-12-09T07:06:06Z")

</div>

Hi. I use filebeat 7.6.1 and k8s autodiscovery that works good for each pod. Example: filebeat.autodiscover: providers: - type: kubernetes templates: - condition: …

---

## [Filebeat MISP module refresh](https://discuss.elastic.co/t/filebeat-misp-module-refresh/256281)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 11\
**Last updated:** [December 9, 2020, 1:33am UTC](https://discuss.elastic.co/t/filebeat-misp-module-refresh/256281 "2020-12-09T01:33:26Z")

</div>

Is there a way to get the filebeat misp module to delete & re-create the index that stores the misp data in? I'm wanting to refresh this data hourly?

---

## [Elastic-agent 7.10.0 install error](https://discuss.elastic.co/t/elastic-agent-7-10-0-install-error/255368)

<div class="topic-metadata">

**Author:** [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Replies:** 6\
**Last updated:** [December 8, 2020, 10:02pm UTC](https://discuss.elastic.co/t/elastic-agent-7-10-0-install-error/255368 "2020-12-08T22:02:38Z")

</div>

I have tried this on a couple different GCP instances with the same error below ffoti@ep-test-gcp-debian:~$ sudo rpm -vi elastic-agent-7.10.0-x86\_64.rpm sudo: rpm: command not found ffoti@ep-test-gcp-debian:~$ curl -L …

---

## [Filebeat dashboards are not loaded in kibana---filebeat version 7.10](https://discuss.elastic.co/t/filebeat-dashboards-are-not-loaded-in-kibana-filebeat-version-7-10/257933)

<div class="topic-metadata">

**Author:** [@prakash22](https://discuss.elastic.co/u/prakash22)\
**Replies:** 4\
**Last updated:** [December 8, 2020, 8:11pm UTC](https://discuss.elastic.co/t/filebeat-dashboards-are-not-loaded-in-kibana-filebeat-version-7-10/257933 "2020-12-08T20:11:49Z")

</div>

2020-12-08T09:58:34.256+0530 INFO instance/beat.go:299 Setup Beat: filebeat; Version: 7.10.0 2020-12-08T09:58:34.256+0530 DEBUG \[beat\] instance/beat.go:325 Initializing output plugins 2020-12-08T09:58…

---

## [Filebeat redis module not working](https://discuss.elastic.co/t/filebeat-redis-module-not-working/257806)

<div class="topic-metadata">

**Author:** [@Amy\_Peng](https://discuss.elastic.co/u/Amy_Peng)\
**Replies:** 1\
**Last updated:** [December 8, 2020, 6:48pm UTC](https://discuss.elastic.co/t/filebeat-redis-module-not-working/257806 "2020-12-08T18:48:27Z")

</div>

Hi all, I'm using filebeat 7.6.2 and my redis version is 6.0.3. From this reference below, I supposed my redis log would be parsed automatically and easily get all the useful fields. But redis module isn't working…

---

## [How to install multiple filebeat services in same host (Windows Server)?](https://discuss.elastic.co/t/how-to-install-multiple-filebeat-services-in-same-host-windows-server/257879)

<div class="topic-metadata">

**Author:** [@noobman2logstash](https://discuss.elastic.co/u/noobman2logstash)\
**Replies:** 1\
**Last updated:** [December 8, 2020, 6:39pm UTC](https://discuss.elastic.co/t/how-to-install-multiple-filebeat-services-in-same-host-windows-server/257879 "2020-12-08T18:39:34Z")

</div>

Hi i need help figuring out this issue as i want to run two filebeat services that points to two deferent directories in the c drive. we currently have a team using filebeat pointing to redis and now i want to install a …

---

## [How do I add a Custom Field to FileBeat with a Module?](https://discuss.elastic.co/t/how-do-i-add-a-custom-field-to-filebeat-with-a-module/257909)

<div class="topic-metadata">

**Author:** [@mstacy](https://discuss.elastic.co/u/mstacy)\
**Replies:** 1\
**Last updated:** [December 8, 2020, 6:34pm UTC](https://discuss.elastic.co/t/how-do-i-add-a-custom-field-to-filebeat-with-a-module/257909 "2020-12-08T18:34:23Z")

</div>

Below is the top portion of my filebeat yaml. This configuration works adequately. However I would like to append additional data to the events in order to better distinguish the source of the logs. I have gone throug…

---

## [Filebeat isn\`t collecting logs of short living containers like cronjobs](https://discuss.elastic.co/t/filebeat-isn-t-collecting-logs-of-short-living-containers-like-cronjobs/254984)

<div class="topic-metadata">

**Author:** [@Patrick\_Erber](https://discuss.elastic.co/u/Patrick_Erber)\
**Replies:** 6\
**Last updated:** [December 8, 2020, 6:12pm UTC](https://discuss.elastic.co/t/filebeat-isn-t-collecting-logs-of-short-living-containers-like-cronjobs/254984 "2020-12-08T18:12:31Z")

</div>

Hello, Filebeat isn\`t collecting logs of short living containers like cronjobs. We are using filebeat version 7.9.3 and also kubernetes autodiscovery. I've created a cronjob which prints just one line and exits afterw…

---

## [Parse dotnet logs to filebeat](https://discuss.elastic.co/t/parse-dotnet-logs-to-filebeat/257968)

<div class="topic-metadata">

**Author:** [@walter.franssen](https://discuss.elastic.co/u/walter.franssen)\
**Replies:** 0\
**Last updated:** [December 8, 2020, 10:32am UTC](https://discuss.elastic.co/t/parse-dotnet-logs-to-filebeat/257968 "2020-12-08T10:32:18Z")

</div>

Hi, We running dotnet applications in k8s and I see that the log from our dotnet application are parse on a single line instead adding more lines to one line of log. What is the best solution for getting multiply lines…

---

## [Can't send logs by filebeat to logstash in Kubernetes](https://discuss.elastic.co/t/cant-send-logs-by-filebeat-to-logstash-in-kubernetes/257851)

<div class="topic-metadata">

**Author:** [@iooi](https://discuss.elastic.co/u/iooi)\
**Replies:** 0\
**Last updated:** [December 7, 2020, 12:55pm UTC](https://discuss.elastic.co/t/cant-send-logs-by-filebeat-to-logstash-in-kubernetes/257851 "2020-12-07T12:55:20Z")

</div>

Configuration nginx.yaml --- apiVersion: v1 kind: Namespace metadata: name: beats --- apiVersion: apps/v1 kind: Deployment metadata: namespace: beats name: nginx spec: replicas: 1 selector: matchLabels: …

---

## [Rsyslog vs filebeat](https://discuss.elastic.co/t/rsyslog-vs-filebeat/257904)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 1\
**Last updated:** [December 7, 2020, 10:07pm UTC](https://discuss.elastic.co/t/rsyslog-vs-filebeat/257904 "2020-12-07T22:07:01Z")

</div>

What is the best way to monitor my hosts? Should I stand up a rsyslog server, and then have clients send logs there, then forward to logstash, or should the clients just send them right to logstash?

---

## [Cisco FTD module does not appear to be processing any events](https://discuss.elastic.co/t/cisco-ftd-module-does-not-appear-to-be-processing-any-events/257896)

<div class="topic-metadata">

**Author:** [@ThePVD](https://discuss.elastic.co/u/ThePVD)\
**Replies:** 0\
**Last updated:** [December 7, 2020, 7:00pm UTC](https://discuss.elastic.co/t/cisco-ftd-module-does-not-appear-to-be-processing-any-events/257896 "2020-12-07T19:00:47Z")

</div>

Helllo! I am currently troubleshooting sending FTD syslog output to a filebeat listener. I'm able to sniff traffic and see packets arriving, but filebeat does not seem to do ANYTHING with the event. I've experimented …

---

## [Trying to forward multiple filebeats via a filebeat relay](https://discuss.elastic.co/t/trying-to-forward-multiple-filebeats-via-a-filebeat-relay/257886)

<div class="topic-metadata">

**Author:** [@dorj1234](https://discuss.elastic.co/u/dorj1234)\
**Replies:** 0\
**Last updated:** [December 7, 2020, 6:17pm UTC](https://discuss.elastic.co/t/trying-to-forward-multiple-filebeats-via-a-filebeat-relay/257886 "2020-12-07T18:17:11Z")

</div>

Hello, I have multiple machines running filebeat and a logstash host in my cloud environment. To minimize firewall impact, I created a single VM to be a relay, and forward everything from the other filebeats to the out…

---

## [Error in events Elastic agent 7.10](https://discuss.elastic.co/t/error-in-events-elastic-agent-7-10/256607)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 6\
**Last updated:** [December 7, 2020, 1:21pm UTC](https://discuss.elastic.co/t/error-in-events-elastic-agent-7-10/256607 "2020-12-07T13:21:43Z")

</div>

Hi, I installed the new agent 7.10 on my windows machines. Among normaal events I see a lot of these: Nov 25, 2020 @ 07:54:06.033 Surface7 error making http request: Get "http://npipe/state": open \\default-endpoint…

---

## [Filebeat data.json missing after minor upgrade](https://discuss.elastic.co/t/filebeat-data-json-missing-after-minor-upgrade/250518)

<div class="topic-metadata">

**Author:** [@CWelsh](https://discuss.elastic.co/u/CWelsh)\
**Replies:** 6\
**Last updated:** [December 7, 2020, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-data-json-missing-after-minor-upgrade/250518 "2020-12-07T12:56:33Z")

</div>

Hi there. After upgrading from filebeat v7.7.0 to v7.9.2 on a windows 2012 server I no longer have a data.json file in my registry folder. This has been replaced with a file named 'X.json' where X is an almost continuou…

---

## [Filebeat not properly recognising truncated file](https://discuss.elastic.co/t/filebeat-not-properly-recognising-truncated-file/257849)

<div class="topic-metadata">

**Author:** [@mutt13y](https://discuss.elastic.co/u/mutt13y)\
**Replies:** 0\
**Last updated:** [December 7, 2020, 12:41pm UTC](https://discuss.elastic.co/t/filebeat-not-properly-recognising-truncated-file/257849 "2020-12-07T12:41:43Z")

</div>

in this post https://discuss.elastic.co/t/filebeat-and-truncated-files/63054 @ruflin states that filebeat will detect when a file is truncated and start reading again. I am on beats7.10 and centos 7 We are going to mo…

---

## [Fortinet rsa fields](https://discuss.elastic.co/t/fortinet-rsa-fields/257538)

<div class="topic-metadata">

**Author:** [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Replies:** 2\
**Last updated:** [December 7, 2020, 12:37pm UTC](https://discuss.elastic.co/t/fortinet-rsa-fields/257538 "2020-12-07T12:37:35Z")

</div>

Hi, I have just seen at https://www.elastic.co/guide/en/beats/filebeat/7.x/exported-fields-fortinet.html that a lot of rsa fields are now exported. What information do they provide which are not part of fortinet or ECE …

---

## [Non-zero metrics in the last 30s](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/257268)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 3\
**Last updated:** [December 7, 2020, 11:22am UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/257268 "2020-12-07T11:22:23Z")

</div>

I am receiving this message. I noticed that my syslog file is being spammed with it, and I am not sure why they are being produced, and not sure how to stop them. It looks like it is json format of localhost statistics…

---

## [Multiline log in elastic agent](https://discuss.elastic.co/t/multiline-log-in-elastic-agent/257698)

<div class="topic-metadata">

**Author:** [@FenixSec](https://discuss.elastic.co/u/FenixSec)\
**Replies:** 1\
**Last updated:** [December 7, 2020, 9:44am UTC](https://discuss.elastic.co/t/multiline-log-in-elastic-agent/257698 "2020-12-07T09:44:45Z")

</div>

Hi, i have a filebeat that picks up a file in the log directory and parses it with the multiline options in the filebeath.yml file: Multiline options multiline.type: pattern multiline.pattern: '\[0-9\]{4}-\[0-9\]{2}-\[0-9\]{…

---

## [How to enable the suricata moudle in the filebeat](https://discuss.elastic.co/t/how-to-enable-the-suricata-moudle-in-the-filebeat/257810)

<div class="topic-metadata">

**Author:** [@zero2](https://discuss.elastic.co/u/zero2)\
**Replies:** 0\
**Last updated:** [December 7, 2020, 7:35am UTC](https://discuss.elastic.co/t/how-to-enable-the-suricata-moudle-in-the-filebeat/257810 "2020-12-07T07:35:38Z")

</div>

when i use the command :./filebeat enable modules suricata, there's a error message: \[root@localhost filebeat\]# ./filebeat modules enable suricata Error in modules manager: modules management requires 'filebeat.config.…

---

## [Metricbeat don't show "\[Metricbeat Windows\] Services"](https://discuss.elastic.co/t/metricbeat-dont-show-metricbeat-windows-services/257807)

<div class="topic-metadata">

**Author:** [@aloalo2242](https://discuss.elastic.co/u/aloalo2242)\
**Replies:** 0\
**Last updated:** [December 7, 2020, 7:12am UTC](https://discuss.elastic.co/t/metricbeat-dont-show-metricbeat-windows-services/257807 "2020-12-07T07:12:31Z")

</div>

Hi, I installed Metricbeat and enable Window module but the template Dashboard ( \[Metricbeat Windows\] Services ECS ) do not show any infomation (No results found). When I run this cmd with powershell: .\\metricbeat.exe -…

---

## [How to monitor %free disk space via metricbeat on windows server](https://discuss.elastic.co/t/how-to-monitor-free-disk-space-via-metricbeat-on-windows-server/257062)

<div class="topic-metadata">

**Author:** [@hunter\_puu](https://discuss.elastic.co/u/hunter_puu)\
**Replies:** 5\
**Last updated:** [December 7, 2020, 7:03am UTC](https://discuss.elastic.co/t/how-to-monitor-free-disk-space-via-metricbeat-on-windows-server/257062 "2020-12-07T07:03:56Z")

</div>

I am newbie on ELK. i want to monitor %free disk space on windows server via metric beat. Anybody can show parameter on windows.yml for solve this issue. Thank you.

---

## [Monitor Java 11 apps with metricbeat?](https://discuss.elastic.co/t/monitor-java-11-apps-with-metricbeat/257750)

<div class="topic-metadata">

**Author:** [@stevedwray](https://discuss.elastic.co/u/stevedwray)\
**Replies:** 1\
**Last updated:** [December 7, 2020, 6:08am UTC](https://discuss.elastic.co/t/monitor-java-11-apps-with-metricbeat/257750 "2020-12-07T06:08:21Z")

</div>

The Metricbeat java monitoring seems to require Jolokia. Jolokia does not support Java 11. We have an application that requires Java 11 and which we'd like to monitor for performance and behavior. Can anyone please su…

---

## [Heartbeat-Elastic 7.10 unable to display details \[search\_phase\_execution\_exception\]](https://discuss.elastic.co/t/heartbeat-elastic-7-10-unable-to-display-details-search-phase-execution-exception/257481)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 10\
**Last updated:** [December 7, 2020, 3:12am UTC](https://discuss.elastic.co/t/heartbeat-elastic-7-10-unable-to-display-details-search-phase-execution-exception/257481 "2020-12-07T03:12:15Z")

</div>

Versions Kibana: 7.7.0 APM Server: (if relevant) Elasticsearch: 7.10.0 Heartbeat: 7.10 After I have upgraded to version 7.10 (Heartbeat-Elastic) the table below is not showing up. Below is my heartbeat.yml, please…

---

## [Metricbeat not sending data after recreating index](https://discuss.elastic.co/t/metricbeat-not-sending-data-after-recreating-index/257694)

<div class="topic-metadata">

**Author:** [@StilgarBF](https://discuss.elastic.co/u/StilgarBF)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 7:37pm UTC](https://discuss.elastic.co/t/metricbeat-not-sending-data-after-recreating-index/257694 "2020-12-04T19:37:58Z")

</div>

Hi, tldr: I had metricbeats running but after deleting and recreating template and index, I see no data comming in. I Have a remote host running elasticsearch and kibana in docker. Metricbeat with only module system w…

---

## [Filebeat does not harvest inactive files](https://discuss.elastic.co/t/filebeat-does-not-harvest-inactive-files/257700)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-does-not-harvest-inactive-files/257700 "2020-12-04T21:06:18Z")

</div>

Hi All, I am using filebeat 7.6.2. On starting up, it does not harvest a file which has time stamp of today but not actively being written into. Is there some parameter that I could introduce in filebeat.yml to make i…

---

## [Filebeat cisco/asa module not working](https://discuss.elastic.co/t/filebeat-cisco-asa-module-not-working/257088)

<div class="topic-metadata">

**Author:** [@Rafal\_Radziejewski](https://discuss.elastic.co/u/Rafal_Radziejewski)\
**Replies:** 7\
**Last updated:** [December 4, 2020, 8:10pm UTC](https://discuss.elastic.co/t/filebeat-cisco-asa-module-not-working/257088 "2020-12-04T20:10:41Z")

</div>

Elasticsearch 7.9.2 Filebeat 7.10 Running command: sudo filebeat setup -e --dashboards --pipelines --template Produces: 2020-11-30T16:04:16.488+0100 ERROR \[load\] cfgfile/list.go:99 Error creating runner from config:…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=191)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=193)
