# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=194

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 195

---

## [Filebeat for just forwarding Full text log](https://discuss.elastic.co/t/filebeat-for-just-forwarding-full-text-log/256697)

<div class="topic-metadata">

**Author:** [@seddikalaouiismaili](https://discuss.elastic.co/u/seddikalaouiismaili)\
**Replies:** 8\
**Last updated:** [December 1, 2020, 4:49pm UTC](https://discuss.elastic.co/t/filebeat-for-just-forwarding-full-text-log/256697 "2020-12-01T16:49:14Z")

</div>

Hello team, Is there any way using filebat (7.10), for just forwarding logs ? The main goals is : shipping log from differents sources (file log text) forward them to another (file log text), without do any changes i…

---

## [Single Line Logs - No newline character](https://discuss.elastic.co/t/single-line-logs-no-newline-character/254941)

<div class="topic-metadata">

**Author:** [@CWelsh](https://discuss.elastic.co/u/CWelsh)\
**Replies:** 1\
**Last updated:** [December 1, 2020, 11:26am UTC](https://discuss.elastic.co/t/single-line-logs-no-newline-character/254941 "2020-12-01T11:26:07Z")

</div>

Filebeat documentation is very clear that logs not ending in a newline character will not be processed by filebeat: Documentation I do however have a number of logs which are written as single JSON objects, in a single …

---

## [Filebeat Cisco ASA Module failing to parse](https://discuss.elastic.co/t/filebeat-cisco-asa-module-failing-to-parse/254304)

<div class="topic-metadata">

**Author:** [@hueyg](https://discuss.elastic.co/u/hueyg)\
**Replies:** 11\
**Last updated:** [December 1, 2020, 10:18am UTC](https://discuss.elastic.co/t/filebeat-cisco-asa-module-failing-to-parse/254304 "2020-12-01T10:18:01Z")

</div>

I have a Filebeat 7.9.3 shipper confirmed sending logs using two modules panw and cisco, specifically the ASA feature. I am only seeing entries for the panw module, but I know the cisco logs are there somewhere. After …

---

## [Metricbeat using more than expected memory](https://discuss.elastic.co/t/metricbeat-using-more-than-expected-memory/257144)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 6\
**Last updated:** [December 1, 2020, 6:47am UTC](https://discuss.elastic.co/t/metricbeat-using-more-than-expected-memory/257144 "2020-12-01T06:47:39Z")

</div>

I want to use metricbeat to track logstash and have followed the instructions here:https://www.elastic.co/guide/en/logstash/current/monitoring-with-metricbeat.html. Everything worked but metricbeat is using 1.3gb of ram …

---

## [How to collect the network information (data) through metricbeat from windows OS](https://discuss.elastic.co/t/how-to-collect-the-network-information-data-through-metricbeat-from-windows-os/256754)

<div class="topic-metadata">

**Author:** [@naveen\_reddy](https://discuss.elastic.co/u/naveen_reddy)\
**Replies:** 2\
**Last updated:** [December 1, 2020, 6:00am UTC](https://discuss.elastic.co/t/how-to-collect-the-network-information-data-through-metricbeat-from-windows-os/256754 "2020-12-01T06:00:09Z")

</div>

i am not able to collect the process and network related information from metric beats can one help me please...

---

## [ELK stack set up - Filebeat setup failing](https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122)

<div class="topic-metadata">

**Author:** [@Guy\_Goodrick](https://discuss.elastic.co/u/Guy_Goodrick)\
**Replies:** 5\
**Last updated:** [November 30, 2020, 9:54pm UTC](https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122 "2020-11-30T21:54:51Z")

</div>

Hello - I'm new to this, just getting started installing the ELK stack on Ubuntu 20.04. Everything is running on that one server for now (though eventually we will want to look at a production version with a cluster, but…

---

## [Filebeat httpjson with content type plus beat block](https://discuss.elastic.co/t/filebeat-httpjson-with-content-type-plus-beat-block/257131)

<div class="topic-metadata">

**Author:** [@jkaufmanlr](https://discuss.elastic.co/u/jkaufmanlr)\
**Replies:** 0\
**Last updated:** [November 30, 2020, 9:48pm UTC](https://discuss.elastic.co/t/filebeat-httpjson-with-content-type-plus-beat-block/257131 "2020-11-30T21:48:30Z")

</div>

okay I am at a loss, I have a POST api call that has a body and absolutely requires content-type: "application/json" without the content-type I can get the api to make the call but the json response isn't what I was exp…

---

## [Having an issue enabling proper multiline options for container logs](https://discuss.elastic.co/t/having-an-issue-enabling-proper-multiline-options-for-container-logs/256916)

<div class="topic-metadata">

**Author:** [@sloney](https://discuss.elastic.co/u/sloney)\
**Replies:** 1\
**Last updated:** [November 30, 2020, 12:36pm UTC](https://discuss.elastic.co/t/having-an-issue-enabling-proper-multiline-options-for-container-logs/256916 "2020-11-30T12:36:06Z")

</div>

Currently have these settings enabled, hoping to make all logs that start with a date like: 2020-11-27 to be in their own entry, including java stack traces. multiline.type: pattern multiline.pattern: '^\[0-9\]{4}-\[0-9\]{…

---

## [Error trying to setup filebeat](https://discuss.elastic.co/t/error-trying-to-setup-filebeat/257011)

<div class="topic-metadata">

**Author:** [@ffknob](https://discuss.elastic.co/u/ffknob)\
**Replies:** 1\
**Last updated:** [November 30, 2020, 12:26pm UTC](https://discuss.elastic.co/t/error-trying-to-setup-filebeat/257011 "2020-11-30T12:26:26Z")

</div>

i'm geting this error trying to setup Filebeat 7.10 on a 7.10 Elasticsearch cluster: ➜ filebeat ./filebeat setup Overwriting ILM policy is disabled. Set \`setup.ilm.overwrite: true…

---

## [Monitoring Logstash with metricbeat: Error connection refused](https://discuss.elastic.co/t/monitoring-logstash-with-metricbeat-error-connection-refused/256760)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 2\
**Last updated:** [November 30, 2020, 8:28am UTC](https://discuss.elastic.co/t/monitoring-logstash-with-metricbeat-error-connection-refused/256760 "2020-11-30T08:28:28Z")

</div>

Hello, I am trying to monitor my Logstash node using metricbeat, but I am getting these errors: Error fetching data for metricset logstash.node: error making http request: Get "https://X.X.X.X:9600/\_node": dial tcp X.X.…

---

## [Export ingest pipeline in Beats \[7.x\]](https://discuss.elastic.co/t/export-ingest-pipeline-in-beats-7-x/256757)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 1\
**Last updated:** [November 30, 2020, 3:15am UTC](https://discuss.elastic.co/t/export-ingest-pipeline-in-beats-7-x/256757 "2020-11-30T03:15:59Z")

</div>

Hi, everyone I would like to know if there is a method like export template but for ingest pipelines, that is: filebeat export ingest module system \> system-ingest-pipeline.json The purpose of this is because sometime…

---

## [How can FileBeat access Kibana over SSL?](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420)

<div class="topic-metadata">

**Author:** [@houmie](https://discuss.elastic.co/u/houmie)\
**Replies:** 6\
**Last updated:** [November 30, 2020, 3:03am UTC](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420 "2020-11-30T03:03:06Z")

</div>

Hello, filebeat.inputs: - type: log paths: - /var/log/app-uwsgi/app.json json.keys\_under\_root: true json.add\_error\_key: true filebeat.config.modules: path: ${path.config}/modules.d/\*.yml reload.enabled: tr…

---

## [Metricbeat prometheus autodiscover metrics not appearing in ES indices](https://discuss.elastic.co/t/metricbeat-prometheus-autodiscover-metrics-not-appearing-in-es-indices/256950)

<div class="topic-metadata">

**Author:** [@k077](https://discuss.elastic.co/u/k077)\
**Replies:** 1\
**Last updated:** [November 29, 2020, 11:08pm UTC](https://discuss.elastic.co/t/metricbeat-prometheus-autodiscover-metrics-not-appearing-in-es-indices/256950 "2020-11-29T23:08:42Z")

</div>

Hi es community, I have deployed ES on kube using the operator as well as metricbeat and everything is working as expected except for metricbeats autodiscover prometheus. After enabling debugging, I can see metricbeat …

---

## [Parsing multiline log options](https://discuss.elastic.co/t/parsing-multiline-log-options/256441)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 2\
**Last updated:** [November 29, 2020, 8:34am UTC](https://discuss.elastic.co/t/parsing-multiline-log-options/256441 "2020-11-29T08:34:01Z")

</div>

I would like to ingest this multiline event and capture some fields; Is it best to capture the fields at the host? or with logstash as part of a filter? how would I set up regex to catch TTC\_UID KVP and TCCRON …

---

## [Elastic-agent is parsing syslog events different (than Filebeat)](https://discuss.elastic.co/t/elastic-agent-is-parsing-syslog-events-different-than-filebeat/256895)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 1\
**Last updated:** [November 28, 2020, 12:02am UTC](https://discuss.elastic.co/t/elastic-agent-is-parsing-syslog-events-different-than-filebeat/256895 "2020-11-28T00:02:13Z")

</div>

Hi, I switched from the ‘classic’ Filebeat to Elastic-Agent. Very handy, but there is a difference how events are being parsed. My Syslog events from devices and Raspberry Pies are routed via a central syslog server. A…

---

## [Metricbeat data flow problem](https://discuss.elastic.co/t/metricbeat-data-flow-problem/256416)

<div class="topic-metadata">

**Author:** [@yattaes](https://discuss.elastic.co/u/yattaes)\
**Replies:** 1\
**Last updated:** [November 23, 2020, 10:59pm UTC](https://discuss.elastic.co/t/metricbeat-data-flow-problem/256416 "2020-11-23T22:59:08Z")

</div>

Hi, I recently deployed Elasticsearch with Kibana on Azure Kubernetes environment. My env's is like below; \> PS C:\\Users\\user\\Desktop\\ES\_YAML\\2\> kubectl get pods --all-namespaces -o wide \> NAMESPACE NAME…

---

## [Specify Module Pipeline in Kubernetes Annotation](https://discuss.elastic.co/t/specify-module-pipeline-in-kubernetes-annotation/256802)

<div class="topic-metadata">

**Author:** [@Paul\_B](https://discuss.elastic.co/u/Paul_B)\
**Replies:** 0\
**Last updated:** [November 26, 2020, 5:13pm UTC](https://discuss.elastic.co/t/specify-module-pipeline-in-kubernetes-annotation/256802 "2020-11-26T17:13:35Z")

</div>

Is it possible to specify a custom pipeline for a module using hints-based autodiscover? An Elastic team member pointed me to the documentation here - https://www.elastic.co/guide/en/beats/filebeat/master/advanced-setti…

---

## [Request for Filebeat AWS CloudTrail Documentation/Configuration Options for s3prefix, etc](https://discuss.elastic.co/t/request-for-filebeat-aws-cloudtrail-documentation-configuration-options-for-s3prefix-etc/256801)

<div class="topic-metadata">

**Author:** [@Adam\_Krieger](https://discuss.elastic.co/u/Adam_Krieger)\
**Replies:** 0\
**Last updated:** [November 26, 2020, 4:49pm UTC](https://discuss.elastic.co/t/request-for-filebeat-aws-cloudtrail-documentation-configuration-options-for-s3prefix-etc/256801 "2020-11-26T16:49:52Z")

</div>

Regarding CloudTrail setup in filebeat for delivery via SQS Message and S3 Object Get: Current setup only allows read if the CloudTrail is pointed to the root of the S3 bucket. Could a 'var.s3prefix' option be added t…

---

## [Metricbeat view on syn\_recv tcp\_connections](https://discuss.elastic.co/t/metricbeat-view-on-syn-recv-tcp-connections/256781)

<div class="topic-metadata">

**Author:** [@Jo\_De\_Troy](https://discuss.elastic.co/u/Jo_De_Troy)\
**Replies:** 0\
**Last updated:** [November 26, 2020, 2:30pm UTC](https://discuss.elastic.co/t/metricbeat-view-on-syn-recv-tcp-connections/256781 "2020-11-26T14:30:38Z")

</div>

Hello, I have metricbeat collecting the socket\_summary metricset of the system module. I see on github \[socket\_summary\](https://github.com/elastic/beats/blob/master/metricbeat/module/system/socket\_summary/socket\_summa…

---

## [No event collected from Sysmon (winlogbeat)](https://discuss.elastic.co/t/no-event-collected-from-sysmon-winlogbeat/256775)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 0\
**Last updated:** [November 26, 2020, 1:51pm UTC](https://discuss.elastic.co/t/no-event-collected-from-sysmon-winlogbeat/256775 "2020-11-26T13:51:56Z")

</div>

Hello, I have installed sysmon in a Windows machine using the command: sysmon.exe -i -accepteula -h md5,sha256,imphash -l -n And then restart winlogbeat. In winlogbeat log everything is working well, and i have logs l…

---

## [Filebeat исключить kubernetes namespace](https://discuss.elastic.co/t/filebeat-kubernetes-namespace/256499)

<div class="topic-metadata">

**Author:** [@Nurlan199206](https://discuss.elastic.co/u/Nurlan199206)\
**Replies:** 2\
**Last updated:** [November 25, 2020, 7:54am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-namespace/256499 "2020-11-25T07:54:12Z")

</div>

Filebeat работает как DaemonSet в kubernetes. Пытаюсь исключить некоторые namespace, такие как "kube-system" и "calico-system". ConfigMap: filebeat.yml выглядит следующим образом. Что я делаю не так? С таким конфигом во…

---

## [Kibana error 500 when viewing metrics](https://discuss.elastic.co/t/kibana-error-500-when-viewing-metrics/256429)

<div class="topic-metadata">

**Author:** [@daq](https://discuss.elastic.co/u/daq)\
**Replies:** 0\
**Last updated:** [November 24, 2020, 1:59am UTC](https://discuss.elastic.co/t/kibana-error-500-when-viewing-metrics/256429 "2020-11-24T01:59:26Z")

</div>

I'm having a problem viewing metrics in Kibana. My issue seems identical to this bug report. except the workaround there doesn't solve the problem for me. Every time I open metrics tab I get the following error: \[illeg…

---

## [Timestamps for archived event logs are overwritten with current time](https://discuss.elastic.co/t/timestamps-for-archived-event-logs-are-overwritten-with-current-time/256756)

<div class="topic-metadata">

**Author:** [@p1k4chu](https://discuss.elastic.co/u/p1k4chu)\
**Replies:** 0\
**Last updated:** [November 26, 2020, 10:46am UTC](https://discuss.elastic.co/t/timestamps-for-archived-event-logs-are-overwritten-with-current-time/256756 "2020-11-26T10:46:46Z")

</div>

I've used the latest winlogbeat to ingest an archived evtx (sample taken from: GitHub - sbousseaden/EVTX-ATTACK-SAMPLES: Windows Events Attack Samples). The timestamp I see in Kibana when ingested via Logstash (without a…

---

## [Missing elastic-agent.yml](https://discuss.elastic.co/t/missing-elastic-agent-yml/256739)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 0\
**Last updated:** [November 26, 2020, 8:33am UTC](https://discuss.elastic.co/t/missing-elastic-agent-yml/256739 "2020-11-26T08:33:31Z")

</div>

Hi, For installing Elastic Agent it is recommended now to use the tarball (Linux) version instead of the deb version. So I did on my Ubuntu server. But when running the install command to enroll to Fleet I am getting t…

---

## [How do I set number of replica to zero in metricbeat?](https://discuss.elastic.co/t/how-do-i-set-number-of-replica-to-zero-in-metricbeat/256618)

<div class="topic-metadata">

**Author:** [@Webtrend\_Inc](https://discuss.elastic.co/u/Webtrend_Inc)\
**Replies:** 1\
**Last updated:** [November 26, 2020, 5:52am UTC](https://discuss.elastic.co/t/how-do-i-set-number-of-replica-to-zero-in-metricbeat/256618 "2020-11-26T05:52:05Z")

</div>

I have only 1 node cluster and hence I need only 1 shard and 0 replica for all my indices. I cannot set the number of replica to 0 for metricbeat index. My yml file looks like this: setup.template.name: "metricbeat"…

---

## [Auditbeat chroot jail support](https://discuss.elastic.co/t/auditbeat-chroot-jail-support/256677)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 1\
**Last updated:** [November 26, 2020, 5:45am UTC](https://discuss.elastic.co/t/auditbeat-chroot-jail-support/256677 "2020-11-26T05:45:23Z")

</div>

Hi All, I was wondering if there is any documentation on getting Auditbeat to collect information from chroot jails? Based on how chroot jails work, it doesn't seem like there is a straight forward way of getting Auditb…

---

## [Upgrade to 7.10 new beats writing to former indices/index patterns?](https://discuss.elastic.co/t/upgrade-to-7-10-new-beats-writing-to-former-indices-index-patterns/256719)

<div class="topic-metadata">

**Author:** [@rgeisman](https://discuss.elastic.co/u/rgeisman)\
**Replies:** 0\
**Last updated:** [November 26, 2020, 12:10am UTC](https://discuss.elastic.co/t/upgrade-to-7-10-new-beats-writing-to-former-indices-index-patterns/256719 "2020-11-26T00:10:18Z")

</div>

Hello all. I just upgraded the Elastic stack we have across the board to 7.10. Logstash and 5 Elastic nodes with auditbeat, metricbeat, and filebeat. After upgrade I took the necessary steps and stopped the output to …

---

## [Stopping automatic update of beats via public elasticsearch reop](https://discuss.elastic.co/t/stopping-automatic-update-of-beats-via-public-elasticsearch-reop/255908)

<div class="topic-metadata">

**Author:** [@rgeisman](https://discuss.elastic.co/u/rgeisman)\
**Replies:** 2\
**Last updated:** [November 26, 2020, 12:03am UTC](https://discuss.elastic.co/t/stopping-automatic-update-of-beats-via-public-elasticsearch-reop/255908 "2020-11-26T00:03:08Z")

</div>

Hello all. When we first installed ELK on our series of boxes the external Elasticsearch repo was used for Linux and installed. Unfortunately we are seeing that the beats on this box (Metricbeat, etc) are updating ON T…

---

## [Filebeat 7.10 is not harvesting](https://discuss.elastic.co/t/filebeat-7-10-is-not-harvesting/256182)

<div class="topic-metadata">

**Author:** [@elkwhat](https://discuss.elastic.co/u/elkwhat)\
**Replies:** 16\
**Last updated:** [November 25, 2020, 6:50pm UTC](https://discuss.elastic.co/t/filebeat-7-10-is-not-harvesting/256182 "2020-11-25T18:50:24Z")

</div>

Hi, I got a weird problem that i would like to share. I have one filebeat instance trying to harvest a particular file and its just doing nothing. Here's my filebeat config - # ============================== Filebea…

---

## [Issues with Elastic Agent](https://discuss.elastic.co/t/issues-with-elastic-agent/256578)

<div class="topic-metadata">

**Author:** [@abdeslam.mazouz](https://discuss.elastic.co/u/abdeslam.mazouz)\
**Replies:** 2\
**Last updated:** [November 25, 2020, 6:29pm UTC](https://discuss.elastic.co/t/issues-with-elastic-agent/256578 "2020-11-25T18:29:40Z")

</div>

What do you think about this; Elastic agent shows up in SIEM under administration for some servers but not all. Even if they are suing the same config and managed from Fleet. The agent piece working but the endpoint secu…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=193)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=195)
