# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=195

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 196

---

## [Only getting node and node\_stats metricsets from elasticsearch module](https://discuss.elastic.co/t/only-getting-node-and-node-stats-metricsets-from-elasticsearch-module/256585)

<div class="topic-metadata">

**Author:** [@chapterthree](https://discuss.elastic.co/u/chapterthree)\
**Replies:** 2\
**Last updated:** [November 25, 2020, 5:16pm UTC](https://discuss.elastic.co/t/only-getting-node-and-node-stats-metricsets-from-elasticsearch-module/256585 "2020-11-25T17:16:40Z")

</div>

I seem to only be getting the node and node\_stats metricsets when I enable the elasticsearch-xpack.yml module. Any ideas why? I have tried with and without the xpack.enabled: true setting.

---

## [ILM trying to rollover old index](https://discuss.elastic.co/t/ilm-trying-to-rollover-old-index/256573)

<div class="topic-metadata">

**Author:** [@Dennis1](https://discuss.elastic.co/u/Dennis1)\
**Replies:** 2\
**Last updated:** [November 25, 2020, 4:06pm UTC](https://discuss.elastic.co/t/ilm-trying-to-rollover-old-index/256573 "2020-11-25T16:06:42Z")

</div>

Hello, I have a single-node ES setup that's receiving data from Filebeat running on a separate server. Since I have Filebeat shipping data from different log sources, I went through the process of manually creating an i…

---

## [Filebeat drop\_event module input](https://discuss.elastic.co/t/filebeat-drop-event-module-input/238610)

<div class="topic-metadata">

**Author:** [@Mischa\_Diehm](https://discuss.elastic.co/u/Mischa_Diehm)\
**Replies:** 3\
**Last updated:** [November 25, 2020, 1:28pm UTC](https://discuss.elastic.co/t/filebeat-drop-event-module-input/238610 "2020-11-25T13:28:19Z")

</div>

Hi, I try to filter messages in the filebeat module section to parse a single logstream into system and iptables parsed logs. Syslog is received from our linux based (openwrt to be specific) devices over the network an…

---

## [Winlogbeat dashboard incomplete/missing fields](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375)

<div class="topic-metadata">

**Author:** [@bohm](https://discuss.elastic.co/u/bohm)\
**Replies:** 9\
**Last updated:** [November 25, 2020, 11:25am UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375 "2020-11-25T11:25:01Z")

</div>

Hello, Winlogbeat and ELK 7.10.0 Trying to show a college of mine that visualisation is much easier with Kibana then Splunk, I'm trying to build a use case with Active Directory security logging. But is looks like some…

---

## [Elasticsearch output for Elastic Agent - adding an ingest pipeline](https://discuss.elastic.co/t/elasticsearch-output-for-elastic-agent-adding-an-ingest-pipeline/256398)

<div class="topic-metadata">

**Author:** [@bsanderRMG](https://discuss.elastic.co/u/bsanderRMG)\
**Replies:** 4\
**Last updated:** [November 25, 2020, 10:56am UTC](https://discuss.elastic.co/t/elasticsearch-output-for-elastic-agent-adding-an-ingest-pipeline/256398 "2020-11-25T10:56:37Z")

</div>

Hello. Is it possible to assign an ingest pipeline for the Elastic Agent? ideally we'd like to push this out to the entire fleet as well. I've tried below and it does not seem to have any effect. Let me know if you h…

---

## [Error without origin](https://discuss.elastic.co/t/error-without-origin/256630)

<div class="topic-metadata">

**Author:** [@Tim\_Stoop](https://discuss.elastic.co/u/Tim_Stoop)\
**Replies:** 0\
**Last updated:** [November 25, 2020, 9:49am UTC](https://discuss.elastic.co/t/error-without-origin/256630 "2020-11-25T09:49:50Z")

</div>

Hi, We're running ECK and our 7.9.3 Filebeat are logging a lot of messages like these: {"log.level":"error","@timestamp":"2020-11-25T09:43:39.424Z","log.logger":"reader\_json","log.origin":{"file.name":"readjson/json.go…

---

## [Filebeat PaloAlto Modules for virtual system field](https://discuss.elastic.co/t/filebeat-paloalto-modules-for-virtual-system-field/255987)

<div class="topic-metadata">

**Author:** [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Replies:** 2\
**Last updated:** [November 25, 2020, 9:00am UTC](https://discuss.elastic.co/t/filebeat-paloalto-modules-for-virtual-system-field/255987 "2020-11-25T09:00:39Z")

</div>

This is my little modification to get the paloalto vsys field. In the file /usr/share/filebeat/module/panw/panos/config/input.yml i add 2 lines to make vsys visible in the index, as follow: {{ if eq .input "syslog" }}…

---

## [Panic: runtime error: index out of range goroutine 1 \[running\]: while running metricbeat setup](https://discuss.elastic.co/t/panic-runtime-error-index-out-of-range-goroutine-1-running-while-running-metricbeat-setup/256220)

<div class="topic-metadata">

**Author:** [@prat](https://discuss.elastic.co/u/prat)\
**Replies:** 11\
**Last updated:** [November 25, 2020, 8:48am UTC](https://discuss.elastic.co/t/panic-runtime-error-index-out-of-range-goroutine-1-running-while-running-metricbeat-setup/256220 "2020-11-25T08:48:37Z")

</div>

running metricbeat setup command through ansible but getting below error. Can someone please sugesst where to check to fix this issue. After 2nd playbook run can see this host is skipped or ignored (may be due to when co…

---

## [Metricbeat-IIS](https://discuss.elastic.co/t/metricbeat-iis/256596)

<div class="topic-metadata">

**Author:** [@reza\_naipospos](https://discuss.elastic.co/u/reza_naipospos)\
**Replies:** 2\
**Last updated:** [November 25, 2020, 5:39am UTC](https://discuss.elastic.co/t/metricbeat-iis/256596 "2020-11-25T05:39:27Z")

</div>

I install metricbeat on windows server, system overview is working fine and show statistic data, but i enable iis module is not send any data about iis, this is my iis.yml # Docs: https://www.elastic.co/guide/en/bea…

---

## [Cisco.yml missing from filebeat](https://discuss.elastic.co/t/cisco-yml-missing-from-filebeat/256561)

<div class="topic-metadata">

**Author:** [@dave.mc](https://discuss.elastic.co/u/dave.mc)\
**Replies:** 3\
**Last updated:** [November 25, 2020, 5:27am UTC](https://discuss.elastic.co/t/cisco-yml-missing-from-filebeat/256561 "2020-11-25T05:27:06Z")

</div>

Attempting to set up a Cisco switch to send logs to Elastic, but Cisco.yml is missing from /etc/filebeat/modules.d folder. I'm asssuming I did something wrong in the setup, but I'm so new to ELK I don't know where to ev…

---

## [Filebeat - Overwrite hostname from decoded json](https://discuss.elastic.co/t/filebeat-overwrite-hostname-from-decoded-json/256537)

<div class="topic-metadata">

**Author:** [@Ajay\_Singh2](https://discuss.elastic.co/u/Ajay_Singh2)\
**Replies:** 1\
**Last updated:** [November 25, 2020, 2:41am UTC](https://discuss.elastic.co/t/filebeat-overwrite-hostname-from-decoded-json/256537 "2020-11-25T02:41:54Z")

</div>

Hi, I am trying to ingest a json file using filebeat, here are few logs from the file: {"iso.gov.dd.internet.public.enterprises.7.0.1.3.0":23,"@timestamp":"2020-11-24T09:09:09.875Z","host":"1.2.3.4","@version":"1"} {"i…

---

## [How to skip docker related package when make beats](https://discuss.elastic.co/t/how-to-skip-docker-related-package-when-make-beats/256324)

<div class="topic-metadata">

**Author:** [@CHU\_XU](https://discuss.elastic.co/u/CHU_XU)\
**Replies:** 2\
**Last updated:** [November 25, 2020, 2:11am UTC](https://discuss.elastic.co/t/how-to-skip-docker-related-package-when-make-beats/256324 "2020-11-25T02:11:16Z")

</div>

Hi there, I'm trying to build metricbeat from source code. The build process needs some docker info with running docker cmds. But I'm building it in a image and I don't want to install docker in it. Also I just want a …

---

## [Filebeat support rotating or renaming log files of another service?](https://discuss.elastic.co/t/filebeat-support-rotating-or-renaming-log-files-of-another-service/256543)

<div class="topic-metadata">

**Author:** [@FREDDIE2020](https://discuss.elastic.co/u/FREDDIE2020)\
**Replies:** 1\
**Last updated:** [November 25, 2020, 1:59am UTC](https://discuss.elastic.co/t/filebeat-support-rotating-or-renaming-log-files-of-another-service/256543 "2020-11-25T01:59:54Z")

</div>

Hello, Does Filebeat support rotating / renaming log files of an other service? Meaning can Filebeat be used as a replacement for logrotate or other similar tools? Thanks, FREDDIE

---

## [Filebeat two diffrent input - one logstash](https://discuss.elastic.co/t/filebeat-two-diffrent-input-one-logstash/256353)

<div class="topic-metadata">

**Author:** [@langol93](https://discuss.elastic.co/u/langol93)\
**Replies:** 2\
**Last updated:** [November 24, 2020, 8:21am UTC](https://discuss.elastic.co/t/filebeat-two-diffrent-input-one-logstash/256353 "2020-11-24T08:21:40Z")

</div>

Good Morning I have a little problem with filebeat configuration. I tried use two diffrent inputs in filebeat config file: mqtt and httpjson and pass the results to one logstash instance. This solution isn't work for m…

---

## [Filebeat not reading 1st log in a file](https://discuss.elastic.co/t/filebeat-not-reading-1st-log-in-a-file/256076)

<div class="topic-metadata">

**Author:** [@Ameer\_Mukadam](https://discuss.elastic.co/u/Ameer_Mukadam)\
**Replies:** 6\
**Last updated:** [November 24, 2020, 5:08am UTC](https://discuss.elastic.co/t/filebeat-not-reading-1st-log-in-a-file/256076 "2020-11-24T05:08:56Z")

</div>

I am pulling mimecast email logs using a python script and saving it to a folder the logs are in json and each file only has 1 log, I have configured my filebeat to read logs from the directory where the logs are stored …

---

## [Configure Packetbeat prior to building MacOS pkg](https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204)

<div class="topic-metadata">

**Author:** [@AaronWF](https://discuss.elastic.co/u/AaronWF)\
**Replies:** 5\
**Last updated:** [November 24, 2020, 2:57am UTC](https://discuss.elastic.co/t/configure-packetbeat-prior-to-building-macos-pkg/256204 "2020-11-24T02:57:39Z")

</div>

I am building beats on MacOS for the native integration feature, I have successfully built & deployed auditbeat, and during the build process I was able to find the file which the build was using in the template. File l…

---

## [Packetbeat not sending the data to kafka multi node](https://discuss.elastic.co/t/packetbeat-not-sending-the-data-to-kafka-multi-node/256364)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [November 23, 2020, 2:03pm UTC](https://discuss.elastic.co/t/packetbeat-not-sending-the-data-to-kafka-multi-node/256364 "2020-11-23T14:03:53Z")

</div>

Packetbeat version 7.9 and kafka version is 2.5 #----------------------------- Kafka output -------------------------------- output.kafka: hosts: \["kafka1:9092","kafka2:9092","kafka3:9092"\] topic: "packetbeat" …

---

## [Filebeat - Netflow - Add flows set id to document](https://discuss.elastic.co/t/filebeat-netflow-add-flows-set-id-to-document/256357)

<div class="topic-metadata">

**Author:** [@rvd](https://discuss.elastic.co/u/rvd)\
**Replies:** 0\
**Last updated:** [November 23, 2020, 1:02pm UTC](https://discuss.elastic.co/t/filebeat-netflow-add-flows-set-id-to-document/256357 "2020-11-23T13:02:53Z")

</div>

Hi I'm using FILEBEAT as IPFIX decoder . I would like to add automatically the flow set id coming from IPFIX template ID to the produced document in ELS. Is there a way to do that ? thx RV

---

## [Metricbeat data flow problem with Kibana](https://discuss.elastic.co/t/metricbeat-data-flow-problem-with-kibana/256247)

<div class="topic-metadata">

**Author:** [@yattaes](https://discuss.elastic.co/u/yattaes)\
**Replies:** 3\
**Last updated:** [November 23, 2020, 10:15am UTC](https://discuss.elastic.co/t/metricbeat-data-flow-problem-with-kibana/256247 "2020-11-23T10:15:38Z")

</div>

Hi! I recently deployed Elasticsearch with Kibana on Azure Kubernetes environment. After that I deployed Metricbeat and it seems fine, all pods are running without problem. But I can not see any data flow to Kibana fro…

---

## [Setup metricbeat to monitor docker containers](https://discuss.elastic.co/t/setup-metricbeat-to-monitor-docker-containers/255985)

<div class="topic-metadata">

**Author:** [@Sauerbrei](https://discuss.elastic.co/u/Sauerbrei)\
**Replies:** 2\
**Last updated:** [November 23, 2020, 9:21am UTC](https://discuss.elastic.co/t/setup-metricbeat-to-monitor-docker-containers/255985 "2020-11-23T09:21:21Z")

</div>

Hi there, I am trying to setup metricbeat inside a local docker environment to write the collected data into an AWS Elastic Search Service. The Service runs and authentication is available via Basic Authentication. Here…

---

## [Filebeat MSSQL ECS](https://discuss.elastic.co/t/filebeat-mssql-ecs/256308)

<div class="topic-metadata">

**Author:** [@bering](https://discuss.elastic.co/u/bering)\
**Replies:** 0\
**Last updated:** [November 23, 2020, 6:52am UTC](https://discuss.elastic.co/t/filebeat-mssql-ecs/256308 "2020-11-23T06:52:26Z")

</div>

I would like to improve the MSSQL module in filebeats so that that the multiline messages in the SQL log maps into an ECS structure. The multiline messages that I am looking at always has 'Error:' in the messsage. What…

---

## [Metricbeat MSSQL User Role required](https://discuss.elastic.co/t/metricbeat-mssql-user-role-required/256159)

<div class="topic-metadata">

**Author:** [@kotha](https://discuss.elastic.co/u/kotha)\
**Replies:** 1\
**Last updated:** [November 23, 2020, 6:33am UTC](https://discuss.elastic.co/t/metricbeat-mssql-user-role-required/256159 "2020-11-23T06:33:40Z")

</div>

what is the minimum role required to gather stats for Metric MSSQL beat. Right now we are using sysadmin role, but there is a push back from the DBA in using that role for the user that collects the metrics for MSSQL

---

## [Filebeat 7.10 doesn't follow log while log rotation occur](https://discuss.elastic.co/t/filebeat-7-10-doesnt-follow-log-while-log-rotation-occur/256034)

<div class="topic-metadata">

**Author:** [@Mahoni](https://discuss.elastic.co/u/Mahoni)\
**Replies:** 1\
**Last updated:** [November 23, 2020, 12:33am UTC](https://discuss.elastic.co/t/filebeat-7-10-doesnt-follow-log-while-log-rotation-occur/256034 "2020-11-23T00:33:46Z")

</div>

filebeat 7.10 doesn't follow log while log rotation occur, log files inode number is changing but filebeat doesn't follow the log file; # ls -ltr /logs/user-app.tomcat/applicationLogs/tra\*.log\* -rw-r--r-- 1 use…

---

## [Can't start auditbeat](https://discuss.elastic.co/t/cant-start-auditbeat/255097)

<div class="topic-metadata">

**Author:** [@headtea](https://discuss.elastic.co/u/headtea)\
**Replies:** 24\
**Last updated:** [November 22, 2020, 10:18am UTC](https://discuss.elastic.co/t/cant-start-auditbeat/255097 "2020-11-22T10:18:32Z")

</div>

I have installed auditbeat (latest version). This is my config file (I hid the output.logstash/kibana part as it's irrelevant and has sensitive data. Also, it doesn't even have audit rules - it didn't work before so I r…

---

## [Why does Beat need to connect to Kibana?](https://discuss.elastic.co/t/why-does-beat-need-to-connect-to-kibana/255417)

<div class="topic-metadata">

**Author:** [@houmie](https://discuss.elastic.co/u/houmie)\
**Replies:** 4\
**Last updated:** [November 22, 2020, 1:11am UTC](https://discuss.elastic.co/t/why-does-beat-need-to-connect-to-kibana/255417 "2020-11-22T01:11:54Z")

</div>

In filebeat.yml there is this line Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API. But filebeat either connects to logstash or directly to Elasticsearch. Elastic search then in return…

---

## [WinlogBeat shipping custom event log to ES, Parsing woes](https://discuss.elastic.co/t/winlogbeat-shipping-custom-event-log-to-es-parsing-woes/256186)

<div class="topic-metadata">

**Author:** [@SigmazGFX](https://discuss.elastic.co/u/SigmazGFX)\
**Replies:** 0\
**Last updated:** [November 20, 2020, 7:58pm UTC](https://discuss.elastic.co/t/winlogbeat-shipping-custom-event-log-to-es-parsing-woes/256186 "2020-11-20T19:58:46Z")

</div>

Hey gang.. Some of our devs have been working on Application API's and are using windows events to store errors and audits and the like. I have winlogbeat picking up these events and shipping them into the winlogbeat-\* …

---

## [MetricBeat Logstash Monitoring Error](https://discuss.elastic.co/t/metricbeat-logstash-monitoring-error/256048)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 4\
**Last updated:** [November 20, 2020, 8:21pm UTC](https://discuss.elastic.co/t/metricbeat-logstash-monitoring-error/256048 "2020-11-20T20:21:15Z")

</div>

Running Elastic Stack 7.10.0 and am trying to modernize the monitoring by implementing Metricbeat. Elasticsearch and Kibana run on one server and logstash is running on a different server. I've got both Elasticsearch a…

---

## [Filebeat connect with Kafka Kerberos(SASL\_SSL) not working](https://discuss.elastic.co/t/filebeat-connect-with-kafka-kerberos-sasl-ssl-not-working/256175)

<div class="topic-metadata">

**Author:** [@Jockj](https://discuss.elastic.co/u/Jockj)\
**Replies:** 2\
**Last updated:** [November 20, 2020, 6:46pm UTC](https://discuss.elastic.co/t/filebeat-connect-with-kafka-kerberos-sasl-ssl-not-working/256175 "2020-11-20T18:46:28Z")

</div>

Continuing the discussion from \[Filebeat connect with Kafka Kerberos(SASL\_SSL) not working\](https://discuss.elastic.co/t/filebeat-connect-with-kafka-kerberos-sasl-ssl-not-working/246160/10): @ascherbakov686, can you ple…

---

## [Parsing Windows DHCP Logs with Filebeat Microsoft Module](https://discuss.elastic.co/t/parsing-windows-dhcp-logs-with-filebeat-microsoft-module/254814)

<div class="topic-metadata">

**Author:** [@kkojouri](https://discuss.elastic.co/u/kkojouri)\
**Replies:** 5\
**Last updated:** [November 20, 2020, 3:22pm UTC](https://discuss.elastic.co/t/parsing-windows-dhcp-logs-with-filebeat-microsoft-module/254814 "2020-11-20T15:22:33Z")

</div>

Hello, We're trying to use the new microsoft.yml module in Filebeat 7.9.0 to ingest and parse Windows DHCP logs. The configuration seems pretty straightfoward, we just pointed it to the default C:\\Windows\\System32\\dhcp\\…

---

## [Filebeat removed, but still logging](https://discuss.elastic.co/t/filebeat-removed-but-still-logging/255956)

<div class="topic-metadata">

**Author:** [@Elitlogik](https://discuss.elastic.co/u/Elitlogik)\
**Replies:** 2\
**Last updated:** [November 20, 2020, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-removed-but-still-logging/255956 "2020-11-20T15:18:53Z")

</div>

I wanted to uninstall Filebeat (since I'm not there yet), so I did sudo yum remove filebeat. Successful. However, there are still logs generted as below. How come filebeat generate logs when it's uninstalled? 2020-11-1…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=194)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=196)
