# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=193

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 194

---

## [Stderr log format](https://discuss.elastic.co/t/stderr-log-format/257689)

<div class="topic-metadata">

**Author:** [@Andrii](https://discuss.elastic.co/u/Andrii)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 6:39pm UTC](https://discuss.elastic.co/t/stderr-log-format/257689 "2020-12-04T18:39:46Z")

</div>

Hello, I noticed that filebeat stderr has a different format than stdout. That makes it impossible to parse filebeat logs with the same rule: here is an example: {"log":"{\\"level\\":\\"debug\\",\\"timestamp\\":\\"2020-12-04…

---

## [Error after upgrading filebeat to 7.10](https://discuss.elastic.co/t/error-after-upgrading-filebeat-to-7-10/255402)

<div class="topic-metadata">

**Author:** [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Replies:** 11\
**Last updated:** [December 4, 2020, 4:43pm UTC](https://discuss.elastic.co/t/error-after-upgrading-filebeat-to-7-10/255402 "2020-12-04T16:43:47Z")

</div>

Hi, after I upgraded my stack to 7.10(from 7.9.3), I tried to upgrade my filebeat. But I'm getting this error: Nov 14 14:41:54 XXXXXXX filebeat\[13184\]: 2020-11-14T14:41:54.462+0330 INFO instance/beat.go:46…

---

## [Tracing which privileged user used a local admin account in windows](https://discuss.elastic.co/t/tracing-which-privileged-user-used-a-local-admin-account-in-windows/257473)

<div class="topic-metadata">

**Author:** [@mkanukur](https://discuss.elastic.co/u/mkanukur)\
**Replies:** 3\
**Last updated:** [December 4, 2020, 4:18pm UTC](https://discuss.elastic.co/t/tracing-which-privileged-user-used-a-local-admin-account-in-windows/257473 "2020-12-04T16:18:35Z")

</div>

Hi All, Reaching out to the community to seek a response to find which privileged user has used a local admin account on a windows server from Kibana, can anyone suggest ? Regards,

---

## [\[Help\] How to ship logs from Kubernetes Cluster to Elasticsearch/Kibana](https://discuss.elastic.co/t/help-how-to-ship-logs-from-kubernetes-cluster-to-elasticsearch-kibana/257545)

<div class="topic-metadata">

**Author:** [@kekoks](https://discuss.elastic.co/u/kekoks)\
**Replies:** 0\
**Last updated:** [December 3, 2020, 4:03pm UTC](https://discuss.elastic.co/t/help-how-to-ship-logs-from-kubernetes-cluster-to-elasticsearch-kibana/257545 "2020-12-03T16:03:29Z")

</div>

(topic withdrawn by author, will be automatically deleted in 24 hours unless flagged)

---

## [Filebeat error](https://discuss.elastic.co/t/filebeat-error/257666)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-error/257666 "2020-12-04T14:31:51Z")

</div>

Hi. I am using the ELK with filebeat sending logs to elastic via suricata module. I have all configured but after some time the information on "discover" and "dashboard" just disappears. On the elastic and filebeat logs …

---

## [Filebeat registry not getting updated](https://discuss.elastic.co/t/filebeat-registry-not-getting-updated/257664)

<div class="topic-metadata">

**Author:** [@Ankush\_Goyal](https://discuss.elastic.co/u/Ankush_Goyal)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 2:25pm UTC](https://discuss.elastic.co/t/filebeat-registry-not-getting-updated/257664 "2020-12-04T14:25:59Z")

</div>

Hi There, Issue: Filebeat is not updating the custom filebeat.registry\_file according to the files present in the filebeat.prospector.paths Specs: System spec: 8 core 8GB ram Intel system Filebeat version: 6.2.2 OS: …

---

## [Cisco ASA module Source and Destination IP incorrect](https://discuss.elastic.co/t/cisco-asa-module-source-and-destination-ip-incorrect/257658)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 2:04pm UTC](https://discuss.elastic.co/t/cisco-asa-module-source-and-destination-ip-incorrect/257658 "2020-12-04T14:04:04Z")

</div>

Dear Team, We are currently ingesting Cisco ASA logs to our elasticsearch cluster using cisco asa module \[ECS\] which comes with filebeat. After verifying the logs in elasticsearch we could understand that Source.address…

---

## [\[Filebeat\] HAProxy module in combination with autodiscover](https://discuss.elastic.co/t/filebeat-haproxy-module-in-combination-with-autodiscover/257539)

<div class="topic-metadata">

**Author:** [@dacamposol](https://discuss.elastic.co/u/dacamposol)\
**Replies:** 0\
**Last updated:** [December 3, 2020, 3:51pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-in-combination-with-autodiscover/257539 "2020-12-03T15:51:20Z")

</div>

Good afternoon everyone, I have a server where are running one instance of haproxy and one instance of filebeat in different containers. In order to have the output of haproxy accesible by docker logs, I have configure…

---

## [Filebeat stops harvesting files after logrotate](https://discuss.elastic.co/t/filebeat-stops-harvesting-files-after-logrotate/257013)

<div class="topic-metadata">

**Author:** [@\_Sree](https://discuss.elastic.co/u/_Sree)\
**Replies:** 3\
**Last updated:** [December 4, 2020, 9:50am UTC](https://discuss.elastic.co/t/filebeat-stops-harvesting-files-after-logrotate/257013 "2020-12-04T09:50:30Z")

</div>

I'm using wazuh kibana plugin and using filebeat to ship alerts to elasticsearch. Filebeat stop indexing data to wazuh-alerts index daily at midnight. I will be able to see new data only after restarting filebeat and it …

---

## [Does Filebeat Module fortinet support TLS/SSL](https://discuss.elastic.co/t/does-filebeat-module-fortinet-support-tls-ssl/257639)

<div class="topic-metadata">

**Author:** [@AndWe](https://discuss.elastic.co/u/AndWe)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 9:30am UTC](https://discuss.elastic.co/t/does-filebeat-module-fortinet-support-tls-ssl/257639 "2020-12-04T09:30:45Z")

</div>

Hi All Does the fortinet module for filebeat support TLS/SSL? According to documentation it doesn't. But for input its using the tcp input. And this input is supporting TLS/SSL. Any chance to implement TLS/SSL for for…

---

## [Filebeat ingestion pipeline for ElasticSearch slow logs](https://discuss.elastic.co/t/filebeat-ingestion-pipeline-for-elasticsearch-slow-logs/257133)

<div class="topic-metadata">

**Author:** [@libbkmz](https://discuss.elastic.co/u/libbkmz)\
**Replies:** 2\
**Last updated:** [December 4, 2020, 8:15am UTC](https://discuss.elastic.co/t/filebeat-ingestion-pipeline-for-elasticsearch-slow-logs/257133 "2020-12-04T08:15:28Z")

</div>

Hello, I've found and possibly created a bug fix when ElasticSearch ingestion pipelines do not capture data from the regex groups in the grok processor. My setup - ES, Kibana, and Filebeat with version 7.6.2. I have th…

---

## [Field not match error with default apache access logs](https://discuss.elastic.co/t/field-not-match-error-with-default-apache-access-logs/257608)

<div class="topic-metadata">

**Author:** [@ravindra2](https://discuss.elastic.co/u/ravindra2)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 4:46am UTC](https://discuss.elastic.co/t/field-not-match-error-with-default-apache-access-logs/257608 "2020-12-04T04:46:14Z")

</div>

Hi, I am using file-beat default apache access pipeline. And I am facing field not match error while parsing my log events. and for same logs it is parsing correctly in kibana dev console while passing my log data wi…

---

## [Heartbeat-Elastic unable to get data](https://discuss.elastic.co/t/heartbeat-elastic-unable-to-get-data/256463)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 13\
**Last updated:** [December 4, 2020, 2:22am UTC](https://discuss.elastic.co/t/heartbeat-elastic-unable-to-get-data/256463 "2020-12-04T02:22:23Z")

</div>

Hi I have upgraded my Heartbeat-elastic to 7.9.1. But later on all the data are not coming in. Below are the ELSK version I am having: Kibana - 7.7.0 Filebeat - 7.7.0 Logstash - 7.9.1 Please advise how can I debug a…

---

## [Simultaneous Filebeats to handle high load](https://discuss.elastic.co/t/simultaneous-filebeats-to-handle-high-load/257498)

<div class="topic-metadata">

**Author:** [@talsh87](https://discuss.elastic.co/u/talsh87)\
**Replies:** 1\
**Last updated:** [December 4, 2020, 1:59am UTC](https://discuss.elastic.co/t/simultaneous-filebeats-to-handle-high-load/257498 "2020-12-04T01:59:10Z")

</div>

I'd like to leverage Filebeat so it'd fetch our o365\\azure\\aws logs using the various modules. I'd like to understand how would it handle with very high volumes? Any way to maintain a cluster of Filebeat clusters? Did…

---

## [How to read logs from docker containers running in a docker swarm cluster](https://discuss.elastic.co/t/how-to-read-logs-from-docker-containers-running-in-a-docker-swarm-cluster/257564)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 2\
**Last updated:** [December 3, 2020, 9:28pm UTC](https://discuss.elastic.co/t/how-to-read-logs-from-docker-containers-running-in-a-docker-swarm-cluster/257564 "2020-12-03T21:28:33Z")

</div>

Hello, I have several java applications that are running as different services in a docker swarm cluster. I would like filebeat to be able to read the logs of the containers and I can see that it has a docker input but …

---

## [Cisco Module/Meraki not properly parsing date on all events](https://discuss.elastic.co/t/cisco-module-meraki-not-properly-parsing-date-on-all-events/257584)

<div class="topic-metadata">

**Author:** [@justinainsworth](https://discuss.elastic.co/u/justinainsworth)\
**Replies:** 0\
**Last updated:** [December 3, 2020, 8:29pm UTC](https://discuss.elastic.co/t/cisco-module-meraki-not-properly-parsing-date-on-all-events/257584 "2020-12-03T20:29:49Z")

</div>

I've been playing around with the new Meraki fileset in the Cisco module, and have noticed that for some event types, the date is not properly parsed, and i get a @timestamp of '1970-01-01T00:00:03.000Z'. Here is a samp…

---

## [No logs found for filebeat](https://discuss.elastic.co/t/no-logs-found-for-filebeat/257519)

<div class="topic-metadata">

**Author:** [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Replies:** 8\
**Last updated:** [December 3, 2020, 4:55pm UTC](https://discuss.elastic.co/t/no-logs-found-for-filebeat/257519 "2020-12-03T16:55:08Z")

</div>

Hello, I am using filebeat 7.10 on Debian machine and I configured it to send data to /var/log/filebeat : logging.level: info logging.to\_file: true logging.files: path: /var/log/filebeat name: filebeat keepfiles…

---

## [Error creating input: Can only start an input when all related states are finished](https://discuss.elastic.co/t/error-creating-input-can-only-start-an-input-when-all-related-states-are-finished/257527)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 0\
**Last updated:** [December 3, 2020, 2:54pm UTC](https://discuss.elastic.co/t/error-creating-input-can-only-start-an-input-when-all-related-states-are-finished/257527 "2020-12-03T14:54:49Z")

</div>

I am using Filebeat 7.10 to send elasticsearch audit file to my cluster and I am having this error: Error creating input: Can only start an input when all related states are finished in filebeat.yml I disabled all the …

---

## [Data type of fields created in ingest pipeline with KV processor](https://discuss.elastic.co/t/data-type-of-fields-created-in-ingest-pipeline-with-kv-processor/257512)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 0\
**Last updated:** [December 3, 2020, 1:21pm UTC](https://discuss.elastic.co/t/data-type-of-fields-created-in-ingest-pipeline-with-kv-processor/257512 "2020-12-03T13:21:06Z")

</div>

Hi, My Rasberry Pi’s are sending some information via a Syslog server to Elastic (with the Elastic Agent/Filebeat). The event looks like this: "Dec 3 14:00:01 PiMirror piinfo: gpu\_temp=50.1| cpu\_temp=49.1| model=4" I …

---

## [Filebeat, ECS and fieds.\* namespace](https://discuss.elastic.co/t/filebeat-ecs-and-fieds-namespace/255062)

<div class="topic-metadata">

**Author:** [@A\_B](https://discuss.elastic.co/u/A_B)\
**Replies:** 2\
**Last updated:** [December 3, 2020, 12:05pm UTC](https://discuss.elastic.co/t/filebeat-ecs-and-fieds-namespace/255062 "2020-12-03T12:05:36Z")

</div>

Hello all, I'm looking for some suggestions for the following situation. Some context I'm trying to convince our developers to adopt ECS as their log format for container logs. We run our containers in Kubernetes and…

---

## [90k files amount - cleaning registry too slow?](https://discuss.elastic.co/t/90k-files-amount-cleaning-registry-too-slow/255573)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 2\
**Last updated:** [December 3, 2020, 11:15am UTC](https://discuss.elastic.co/t/90k-files-amount-cleaning-registry-too-slow/255573 "2020-12-03T11:15:32Z")

</div>

Hi, It's bit frustrating to understand what is Filebeat doing during startup. My situation is, I needed to ingest about 90k files from fs, which were simple xml logs. It happend quite fast. No problems at all. Afterwar…

---

## [Specify extra fields in modules (e.g Elasticsearch)](https://discuss.elastic.co/t/specify-extra-fields-in-modules-e-g-elasticsearch/255948)

<div class="topic-metadata">

**Author:** [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Replies:** 2\
**Last updated:** [December 3, 2020, 9:09am UTC](https://discuss.elastic.co/t/specify-extra-fields-in-modules-e-g-elasticsearch/255948 "2020-12-03T09:09:48Z")

</div>

I have several log type inputs in Filebeat, these specify one or more extra fields. E.g. a.yml for logs from app 'A', b.yml for logs from app 'B'. The extra field 'index' is set to 'index\_A' and index\_B' respectively. L…

---

## [Find logs location](https://discuss.elastic.co/t/find-logs-location/257355)

<div class="topic-metadata">

**Author:** [@Mohith\_Vegi](https://discuss.elastic.co/u/Mohith_Vegi)\
**Replies:** 5\
**Last updated:** [December 3, 2020, 5:21am UTC](https://discuss.elastic.co/t/find-logs-location/257355 "2020-12-03T05:21:16Z")

</div>

Hi, Where can I find the file path of the filebeats logs. Please help me with this... Thanks!

---

## [Setting hostname for specific log files being shipped with filebeat](https://discuss.elastic.co/t/setting-hostname-for-specific-log-files-being-shipped-with-filebeat/257431)

<div class="topic-metadata">

**Author:** [@afc](https://discuss.elastic.co/u/afc)\
**Replies:** 0\
**Last updated:** [December 3, 2020, 12:04am UTC](https://discuss.elastic.co/t/setting-hostname-for-specific-log-files-being-shipped-with-filebeat/257431 "2020-12-03T00:04:24Z")

</div>

Greetings! I've been setting up a centralized log server to collect data from our servers, switches, access points etc. I have a folder on the log server that contains apache log files from a remote machine (/var/log/pr…

---

## [Specify strict\_date\_optional\_time\_nanos format for date data type](https://discuss.elastic.co/t/specify-strict-date-optional-time-nanos-format-for-date-data-type/256246)

<div class="topic-metadata">

**Author:** [@chris\_pacb](https://discuss.elastic.co/u/chris_pacb)\
**Replies:** 1\
**Last updated:** [December 2, 2020, 9:18pm UTC](https://discuss.elastic.co/t/specify-strict-date-optional-time-nanos-format-for-date-data-type/256246 "2020-12-02T21:18:07Z")

</div>

Hi all! I'm using "setup.template.append\_fields" in filebeat to specify extra fields. I can specify a "type" where I'm using "date" as the data type. How would I specify the "strict\_date\_optional\_time\_nanos" format. Th…

---

## [Filebeat HA servers](https://discuss.elastic.co/t/filebeat-ha-servers/256703)

<div class="topic-metadata">

**Author:** [@madhan0618](https://discuss.elastic.co/u/madhan0618)\
**Replies:** 4\
**Last updated:** [December 2, 2020, 6:17pm UTC](https://discuss.elastic.co/t/filebeat-ha-servers/256703 "2020-12-02T18:17:51Z")

</div>

I have a requirement where the log file that I am trying to pull can be on 1 of 4 servers at any given time. It is for my application that is in a HA cluster on 4 servers. Can i install filebeat on all 4 servers and make…

---

## [Filebeat AWS Module & ELB fileset, got error in parsing NLB log](https://discuss.elastic.co/t/filebeat-aws-module-elb-fileset-got-error-in-parsing-nlb-log/257281)

<div class="topic-metadata">

**Author:** [@pingz](https://discuss.elastic.co/u/pingz)\
**Replies:** 0\
**Last updated:** [December 1, 2020, 10:08pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-elb-fileset-got-error-in-parsing-nlb-log/257281 "2020-12-01T22:08:54Z")

</div>

Hi there: I am using filebeat 7.9.3 with aws module and elb fileset enabled, running inside k8s. It is able to parse ALB log, but failed in paring Network load balancer log. The error message I got is error.message …

---

## [Custom Beat creation was not successful on windows10 machine](https://discuss.elastic.co/t/custom-beat-creation-was-not-successful-on-windows10-machine/257159)

<div class="topic-metadata">

**Author:** [@pradeep.kumarsk](https://discuss.elastic.co/u/pradeep.kumarsk)\
**Replies:** 0\
**Last updated:** [December 1, 2020, 6:08am UTC](https://discuss.elastic.co/t/custom-beat-creation-was-not-successful-on-windows10-machine/257159 "2020-12-01T06:08:29Z")

</div>

Tried to create the custom beats following the officlial documentation on Windows 10 machine we were facing issue $mage GenerateCustomBeat ends in throwing the out of memory error error seems to be at $make update

---

## [Can we use filebeat to send data to AWS elasticsearch service?](https://discuss.elastic.co/t/can-we-use-filebeat-to-send-data-to-aws-elasticsearch-service/257166)

<div class="topic-metadata">

**Author:** [@Ashok4512](https://discuss.elastic.co/u/Ashok4512)\
**Replies:** 4\
**Last updated:** [December 1, 2020, 5:49pm UTC](https://discuss.elastic.co/t/can-we-use-filebeat-to-send-data-to-aws-elasticsearch-service/257166 "2020-12-01T17:49:52Z")

</div>

I am trying to send log data of my nginx server to AWS elasticsearch service. i am done with the changes in filebeat.yml file and then run the command "filebeat setup" but then i got the error like " Overwriting ILM poli…

---

## [Filebeats holding handles on rotated logs](https://discuss.elastic.co/t/filebeats-holding-handles-on-rotated-logs/256538)

<div class="topic-metadata">

**Author:** [@txmrlevine](https://discuss.elastic.co/u/txmrlevine)\
**Replies:** 3\
**Last updated:** [December 1, 2020, 5:20pm UTC](https://discuss.elastic.co/t/filebeats-holding-handles-on-rotated-logs/256538 "2020-12-01T17:20:53Z")

</div>

I am looking into why my disks are getting full and I found that filebeat is holding handles on logs that are rotated. I read some discussions on the topic and I did not see a definitive answer and all requests were rat…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=192)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=194)
