# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=196

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 197

---

## [Multiple logs to different index - Filebeat](https://discuss.elastic.co/t/multiple-logs-to-different-index-filebeat/256003)

<div class="topic-metadata">

**Author:** [@Charakterny](https://discuss.elastic.co/u/Charakterny)\
**Replies:** 2\
**Last updated:** [November 20, 2020, 9:09am UTC](https://discuss.elastic.co/t/multiple-logs-to-different-index-filebeat/256003 "2020-11-20T09:09:38Z")

</div>

Hello, I have in one filebeat.yml two paths for two different logs and it works fine but I need to divide to two index. I tried as below: filebeat.inputs: - type: log enabled: true paths: - /var/log/nginx/\*.lo…

---

## [Why metricbeat is not picking up keystore entries?](https://discuss.elastic.co/t/why-metricbeat-is-not-picking-up-keystore-entries/256011)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 2\
**Last updated:** [November 20, 2020, 11:19am UTC](https://discuss.elastic.co/t/why-metricbeat-is-not-picking-up-keystore-entries/256011 "2020-11-20T11:19:10Z")

</div>

Hi, I am using elastic stack 7.9. I have a 3 node cluster and https is I have created certificates using elasticsearch-certutil command, which are generic, and I am using it across all nodes. I have the below files; e…

---

## [Add custom field on IIS log](https://discuss.elastic.co/t/add-custom-field-on-iis-log/256054)

<div class="topic-metadata">

**Author:** [@victortamotsu](https://discuss.elastic.co/u/victortamotsu)\
**Replies:** 0\
**Last updated:** [November 20, 2020, 2:34am UTC](https://discuss.elastic.co/t/add-custom-field-on-iis-log/256054 "2020-11-20T02:34:52Z")

</div>

Hi everybody! I added a custom field on IIS log to register the original client IP (x-forwarded-for). This is necessary because I use a reverse proxy to publish my webserver, so the Client IP Address (c-ip) show only th…

---

## [Metricbeat doesn't communicate with Elasticsearch](https://discuss.elastic.co/t/metricbeat-doesnt-communicate-with-elasticsearch/256035)

<div class="topic-metadata">

**Author:** [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Replies:** 1\
**Last updated:** [November 19, 2020, 11:03pm UTC](https://discuss.elastic.co/t/metricbeat-doesnt-communicate-with-elasticsearch/256035 "2020-11-19T23:03:13Z")

</div>

Hi! I have installed Metricbeat and I have Security feature installed on my ELK! After I make all configurations with certificates and modules I get this error: "service": { "type": "elasticsearch", "address…

---

## [Filebeat httpjason input](https://discuss.elastic.co/t/filebeat-httpjason-input/255813)

<div class="topic-metadata">

**Author:** [@pankaj](https://discuss.elastic.co/u/pankaj)\
**Replies:** 2\
**Last updated:** [November 18, 2020, 4:47pm UTC](https://discuss.elastic.co/t/filebeat-httpjason-input/255813 "2020-11-18T16:47:11Z")

</div>

I tried configure the test httpjson input but that failing filebeat service to start. filebeat.inputs: Fetch your public IP every minute. type: httpjson url: https://api.ipify.org/?format=json interval: 1m processo…

---

## [Filebeat: file output with dynamic filename](https://discuss.elastic.co/t/filebeat-file-output-with-dynamic-filename/256002)

<div class="topic-metadata">

**Author:** [@james\_m](https://discuss.elastic.co/u/james_m)\
**Replies:** 2\
**Last updated:** [November 19, 2020, 2:49pm UTC](https://discuss.elastic.co/t/filebeat-file-output-with-dynamic-filename/256002 "2020-11-19T14:49:29Z")

</div>

Hi, I'm using the file output module to write some container logs to NFS. I can't figure out how to make the output filename dynamic - I'd like the filename to be the container name. I suspect I have two options. S…

---

## [Range of values for system.process.memory.rss.pct and system.process.cpu.total.norm.pct](https://discuss.elastic.co/t/range-of-values-for-system-process-memory-rss-pct-and-system-process-cpu-total-norm-pct/255992)

<div class="topic-metadata">

**Author:** [@musician](https://discuss.elastic.co/u/musician)\
**Replies:** 2\
**Last updated:** [November 19, 2020, 2:06pm UTC](https://discuss.elastic.co/t/range-of-values-for-system-process-memory-rss-pct-and-system-process-cpu-total-norm-pct/255992 "2020-11-19T14:06:18Z")

</div>

Hello, I wanted to find out if the range of values for system.process.memory.rss.pct and system.process.cpu.total.norm.pct if from: 0.0 to 1.0 or 0.0 to 100.0.

---

## [Filebeat is not sending logs to logstash](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash/255855)

<div class="topic-metadata">

**Author:** [@Jurilz](https://discuss.elastic.co/u/Jurilz)\
**Replies:** 1\
**Last updated:** [November 19, 2020, 12:48pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash/255855 "2020-11-19T12:48:58Z")

</div>

I'm trying to read Tomcat logfiles with filebeat, send them to logstash, format them and forward them to elasticsearch. Problem: I'm pretty sure the logs never reach logstash, because they don't apper at stdout version…

---

## [Metricbeat AWS module metricsets and exported fields](https://discuss.elastic.co/t/metricbeat-aws-module-metricsets-and-exported-fields/255976)

<div class="topic-metadata">

**Author:** [@nickgregz](https://discuss.elastic.co/u/nickgregz)\
**Replies:** 0\
**Last updated:** [November 19, 2020, 11:45am UTC](https://discuss.elastic.co/t/metricbeat-aws-module-metricsets-and-exported-fields/255976 "2020-11-19T11:45:39Z")

</div>

Hello, I have a question regarding exported fields of metricsets for the AWS metricbeat module, specifically if they all include some variation of a unique identifier. For example the RDS module has an exported field a…

---

## [What all credentials should be configured in metricbeat, and how, while working with secure elasticsearch having https and built in user roles?](https://discuss.elastic.co/t/what-all-credentials-should-be-configured-in-metricbeat-and-how-while-working-with-secure-elasticsearch-having-https-and-built-in-user-roles/255947)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 0\
**Last updated:** [November 19, 2020, 8:29am UTC](https://discuss.elastic.co/t/what-all-credentials-should-be-configured-in-metricbeat-and-how-while-working-with-secure-elasticsearch-having-https-and-built-in-user-roles/255947 "2020-11-19T08:29:41Z")

</div>

Hi, I am using elastic stack 7.9. I have a 3 node elasticsearch cluster with https enabled using http.p12 and I have configured kibana as well (but kibana still runs in http). I have set up credenatials for built-in use…

---

## [Elastic-Agent - Custom Log Integration](https://discuss.elastic.co/t/elastic-agent-custom-log-integration/255736)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 3\
**Last updated:** [November 19, 2020, 9:26am UTC](https://discuss.elastic.co/t/elastic-agent-custom-log-integration/255736 "2020-11-19T09:26:20Z")

</div>

Hi I am trying to get a 'Custom Log' working with Elastic-Agent via the GUI. I have managed to get the custom log file being processed but I need to define mappings for it. the format of the file is minimal at this st…

---

## [Filebeat high disk usage when reboot server. How fix it?](https://discuss.elastic.co/t/filebeat-high-disk-usage-when-reboot-server-how-fix-it/255876)

<div class="topic-metadata">

**Author:** [@Andrew\_Foxis](https://discuss.elastic.co/u/Andrew_Foxis)\
**Replies:** 6\
**Last updated:** [November 19, 2020, 9:23am UTC](https://discuss.elastic.co/t/filebeat-high-disk-usage-when-reboot-server-how-fix-it/255876 "2020-11-19T09:23:14Z")

</div>

Hi all! Filebeat on server send many events from logs of exchange (windows) server to logstash. When we reboot server filebeat make high disk usage. Other services can't load for a long time. How can i fix it? Thank y…

---

## [Heartbeat enabled: false kills process with error](https://discuss.elastic.co/t/heartbeat-enabled-false-kills-process-with-error/255900)

<div class="topic-metadata">

**Author:** [@Ben\_Berg1](https://discuss.elastic.co/u/Ben_Berg1)\
**Replies:** 1\
**Last updated:** [November 18, 2020, 11:36pm UTC](https://discuss.elastic.co/t/heartbeat-enabled-false-kills-process-with-error/255900 "2020-11-18T23:36:30Z")

</div>

Hello, I am running heartbeat in a docker container. I would like to conditionally enable specific monitors using the enabled configuration option on a monitor by monitor basis. It appears enabled: false results in 202…

---

## [Metricbeat 7.9.2 service doesn't start on windows 2019, but fine on linux](https://discuss.elastic.co/t/metricbeat-7-9-2-service-doesnt-start-on-windows-2019-but-fine-on-linux/253054)

<div class="topic-metadata">

**Author:** [@jmacnett](https://discuss.elastic.co/u/jmacnett)\
**Replies:** 18\
**Last updated:** [November 18, 2020, 5:14pm UTC](https://discuss.elastic.co/t/metricbeat-7-9-2-service-doesnt-start-on-windows-2019-but-fine-on-linux/253054 "2020-11-18T17:14:18Z")

</div>

Attempting a new setup of Metricbeat on a fresh windows 2019 server, and getting error 1067 ("The process terminated unsuccessfully) from services.msc. Powershell startup is essentially the same result. Setup: The fi…

---

## [\[Logstash\] Insufficient memory for the Java Runtime Environment to continue](https://discuss.elastic.co/t/logstash-insufficient-memory-for-the-java-runtime-environment-to-continue/255084)

<div class="topic-metadata">

**Author:** [@Albertoares](https://discuss.elastic.co/u/Albertoares)\
**Replies:** 3\
**Last updated:** [November 18, 2020, 3:53pm UTC](https://discuss.elastic.co/t/logstash-insufficient-memory-for-the-java-runtime-environment-to-continue/255084 "2020-11-18T15:53:06Z")

</div>

Hi everyone, I have a hard time with logstash service. My server was set up to send filebeat to a kafka server and everything was fine until yesterday where I had the following error when debugging logstash: \` OpenJDK …

---

## [ES 7.10 shows an error when using aws module in filebeat](https://discuss.elastic.co/t/es-7-10-shows-an-error-when-using-aws-module-in-filebeat/255647)

<div class="topic-metadata">

**Author:** [@Edwin.v](https://discuss.elastic.co/u/Edwin.v)\
**Replies:** 2\
**Last updated:** [November 18, 2020, 3:36pm UTC](https://discuss.elastic.co/t/es-7-10-shows-an-error-when-using-aws-module-in-filebeat/255647 "2020-11-18T15:36:48Z")

</div>

Elasticsearch 7.9.3 was working fine when I updated to version 7.10 . It is showing an error cfgfile/list.go:99 Error creating runner from config: Error getting config for fileset aws/s3access: Error interpreting…

---

## [Error 1053: “The service did not respond in a timely fashion” when attempting to start winlogbeat service with MSI package](https://discuss.elastic.co/t/error-1053-the-service-did-not-respond-in-a-timely-fashion-when-attempting-to-start-winlogbeat-service-with-msi-package/255802)

<div class="topic-metadata">

**Author:** [@mackov83](https://discuss.elastic.co/u/mackov83)\
**Replies:** 4\
**Last updated:** [November 18, 2020, 3:08pm UTC](https://discuss.elastic.co/t/error-1053-the-service-did-not-respond-in-a-timely-fashion-when-attempting-to-start-winlogbeat-service-with-msi-package/255802 "2020-11-18T15:08:05Z")

</div>

I have just started working with Winlogbeat as a forwarder to Graylog (Logstash). I was able to get this working perfectly fine with the .zip file. In order to simplify the deployment, I wanted to use the .msi file, and…

---

## [How to increase the Heartbeat I/O Timeout value](https://discuss.elastic.co/t/how-to-increase-the-heartbeat-i-o-timeout-value/255719)

<div class="topic-metadata">

**Author:** [@mdamera](https://discuss.elastic.co/u/mdamera)\
**Replies:** 1\
**Last updated:** [November 17, 2020, 7:12pm UTC](https://discuss.elastic.co/t/how-to-increase-the-heartbeat-i-o-timeout-value/255719 "2020-11-17T19:12:30Z")

</div>

Team, we are getting below DOwn alert for one of the uptime monitor we configured, actually the site is not down ,however we got these Get http://xxxxxxxx:5006/aaaaaa\_bbbbb\_ccccc: http: request timed out while waiting …

---

## [Metricbeat service metricset doesn't work on Centos/RedHat 8.x](https://discuss.elastic.co/t/metricbeat-service-metricset-doesnt-work-on-centos-redhat-8-x/255346)

<div class="topic-metadata">

**Author:** [@iorfix](https://discuss.elastic.co/u/iorfix)\
**Replies:** 2\
**Last updated:** [November 18, 2020, 9:46am UTC](https://discuss.elastic.co/t/metricbeat-service-metricset-doesnt-work-on-centos-redhat-8-x/255346 "2020-11-18T09:46:03Z")

</div>

I deployed a metricbeat 7.10.0 on a Centos 8.0 VM and on RedHat 8.2 VM. I defined a metricbeat system module as follows: #module system, metriceset service - module: system metricsets: - service period: 30s s…

---

## [How to add additional fields on filebeat](https://discuss.elastic.co/t/how-to-add-additional-fields-on-filebeat/255489)

<div class="topic-metadata">

**Author:** [@elkrocks](https://discuss.elastic.co/u/elkrocks)\
**Replies:** 2\
**Last updated:** [November 18, 2020, 7:09am UTC](https://discuss.elastic.co/t/how-to-add-additional-fields-on-filebeat/255489 "2020-11-18T07:09:32Z")

</div>

I want to add additional field on filebeat.yml. I want to name it as instancename and the value is the instance name of my aws ec2 instance. How can I add it to the filebeat config?

---

## [Packetbeat nfs resulting in heavy memory usage](https://discuss.elastic.co/t/packetbeat-nfs-resulting-in-heavy-memory-usage/254514)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [November 18, 2020, 7:05am UTC](https://discuss.elastic.co/t/packetbeat-nfs-resulting-in-heavy-memory-usage/254514 "2020-11-18T07:05:13Z")

</div>

Hello, We are noticing heavy memory usage by Packetbeat, which seems to be related to the nfs protocol. The server on which this is happening is an ftp server and runs jobs at night where incoming ftp is moved to nfs sh…

---

## [Create pipeline for module](https://discuss.elastic.co/t/create-pipeline-for-module/255651)

<div class="topic-metadata">

**Author:** [@headtea](https://discuss.elastic.co/u/headtea)\
**Replies:** 2\
**Last updated:** [November 18, 2020, 6:52am UTC](https://discuss.elastic.co/t/create-pipeline-for-module/255651 "2020-11-18T06:52:33Z")

</div>

I've enabled the filebeat system module: filebeat modules enable system filebeat setup --pipelines --modules system filebeat setup --dashboards systemctl restart filebeat This is what logstash has to say pipeline with…

---

## [Filebeat OSS 7.7.0 not able to connect AWS Elasticsearch Service 7.7.0](https://discuss.elastic.co/t/filebeat-oss-7-7-0-not-able-to-connect-aws-elasticsearch-service-7-7-0/252275)

<div class="topic-metadata">

**Author:** [@Jigar\_Patel1](https://discuss.elastic.co/u/Jigar_Patel1)\
**Replies:** 5\
**Last updated:** [November 18, 2020, 6:30am UTC](https://discuss.elastic.co/t/filebeat-oss-7-7-0-not-able-to-connect-aws-elasticsearch-service-7-7-0/252275 "2020-11-18T06:30:54Z")

</div>

I am using EC2 VM to send logs to AWS Elasticsearch Service 7.7.0. EC2 instance and Elastic Service can communicate via same VPC. But, filebeat OSS 7.7.0 not able to connect to Elasticsearch service 7.7.0. Any suggestin…

---

## [Need to recreate/reindex when upgrading beats?](https://discuss.elastic.co/t/need-to-recreate-reindex-when-upgrading-beats/255783)

<div class="topic-metadata">

**Author:** [@rgeisman](https://discuss.elastic.co/u/rgeisman)\
**Replies:** 2\
**Last updated:** [November 18, 2020, 6:29am UTC](https://discuss.elastic.co/t/need-to-recreate-reindex-when-upgrading-beats/255783 "2020-11-18T06:29:46Z")

</div>

Greetings all. I have some questions in general about when beats upgrade. We have ELK running on a cluster where an orchestration platform upgrades the beats automatically. So using Logstash of course when I first use…

---

## [How to calculate the query per second from the existing metrics?](https://discuss.elastic.co/t/how-to-calculate-the-query-per-second-from-the-existing-metrics/255775)

<div class="topic-metadata">

**Author:** [@Izek\_Chen](https://discuss.elastic.co/u/Izek_Chen)\
**Replies:** 0\
**Last updated:** [November 18, 2020, 2:39am UTC](https://discuss.elastic.co/t/how-to-calculate-the-query-per-second-from-the-existing-metrics/255775 "2020-11-18T02:39:30Z")

</div>

As per title, I check the export field document and seems like the "mongodb.collstats.queries.time.us" is the right one. the problem I see is that since the metrics gathered are cumulative those values do not represent …

---

## [Filebeat reporting stops after index errors](https://discuss.elastic.co/t/filebeat-reporting-stops-after-index-errors/255485)

<div class="topic-metadata">

**Author:** [@CatalinM](https://discuss.elastic.co/u/CatalinM)\
**Replies:** 0\
**Last updated:** [November 16, 2020, 9:44am UTC](https://discuss.elastic.co/t/filebeat-reporting-stops-after-index-errors/255485 "2020-11-16T09:44:29Z")

</div>

I've noticed Filebeat stopped sending logs to ES after awhile (seems like some pods are restarting - might be the Jaeger agent with the cleanup jobs start around midnight). It's always caused by an empty index name due t…

---

## [Field "process.command\_line" not popluated even though I can see it in the message field](https://discuss.elastic.co/t/field-process-command-line-not-popluated-even-though-i-can-see-it-in-the-message-field/255589)

<div class="topic-metadata">

**Author:** [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Replies:** 1\
**Last updated:** [November 17, 2020, 9:53pm UTC](https://discuss.elastic.co/t/field-process-command-line-not-popluated-even-though-i-can-see-it-in-the-message-field/255589 "2020-11-17T21:53:12Z")

</div>

Hello, I need some orientation with my issue : Description : I have an ELK stack version 7.6 that collects event logs from different log sources via logstash. All endpoints (windows ends linux) send logs to logstash t…

---

## [Winlogbeat Deployment with SCCM](https://discuss.elastic.co/t/winlogbeat-deployment-with-sccm/255760)

<div class="topic-metadata">

**Author:** [@atomiczombie79](https://discuss.elastic.co/u/atomiczombie79)\
**Replies:** 0\
**Last updated:** [November 17, 2020, 8:59pm UTC](https://discuss.elastic.co/t/winlogbeat-deployment-with-sccm/255760 "2020-11-17T20:59:08Z")

</div>

Does anyone have any experience building out an SCCM package for Winlogbeat? Our Security team would like to use Winlogbeat and Sysmon to monitor the environment and I would like to be able to deploy using SCCM. I curr…

---

## [Filebeat doesn't work with AWS ES domain](https://discuss.elastic.co/t/filebeat-doesnt-work-with-aws-es-domain/255683)

<div class="topic-metadata">

**Author:** [@hairongGao](https://discuss.elastic.co/u/hairongGao)\
**Replies:** 3\
**Last updated:** [November 17, 2020, 8:12pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-work-with-aws-es-domain/255683 "2020-11-17T20:12:09Z")

</div>

Hi Team, I've been trying to make filebeat working with AWS ES domain , but I keep getting this error: 2020-11-17T11:42:25.740Z ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 Failed to connect to backoff(ela…

---

## [Elasticsearch winlogbeat field host.ip value issue](https://discuss.elastic.co/t/elasticsearch-winlogbeat-field-host-ip-value-issue/255660)

<div class="topic-metadata">

**Author:** [@abu.sayeed](https://discuss.elastic.co/u/abu.sayeed)\
**Replies:** 1\
**Last updated:** [November 17, 2020, 8:09pm UTC](https://discuss.elastic.co/t/elasticsearch-winlogbeat-field-host-ip-value-issue/255660 "2020-11-17T20:09:28Z")

</div>

winlogbeat version 7.2.0 host.ip : 10.33.55.5 But winlogbeat version 7.10.0 host.ip field show: fe80::95f4:40d4:80a3:8cd, 10.33.55.5, fe80::399f:e9ad:5f5a:9511, 169.254.149.17, fe80::dc91:96a:a1b8:82e3, 169.254.130.22…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=195)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=197)
