# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=197

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 198

---

## [Kubernetes.container.memory.usage.bytes doesn't match pmap](https://discuss.elastic.co/t/kubernetes-container-memory-usage-bytes-doesnt-match-pmap/255748)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [November 17, 2020, 6:48pm UTC](https://discuss.elastic.co/t/kubernetes-container-memory-usage-bytes-doesnt-match-pmap/255748 "2020-11-17T18:48:20Z")

</div>

None of the metric sets listed above closely match: pmap \<pid\> which is the size of the process. I have tried working set, rss and usage.bytes, and none seem to match this. What is the correct metric to use for memor…

---

## [Elastic Agent Linux Install Directory](https://discuss.elastic.co/t/elastic-agent-linux-install-directory/255595)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 4\
**Last updated:** [November 17, 2020, 6:10pm UTC](https://discuss.elastic.co/t/elastic-agent-linux-install-directory/255595 "2020-11-17T18:10:12Z")

</div>

Hi all, I installed Elastic Agent from /tmp/elastic-agent-7.10.0-linux-x86\_64. I now see a metricbeat running from /tmp/elastic-agent-7.10.0-linux-x86\_64/data/elastic-agent-1428d5. Is this intended? Why are downloaded …

---

## [Filebeat fortinet module not indexing after upgrading it and kibana to 7.10.0,](https://discuss.elastic.co/t/filebeat-fortinet-module-not-indexing-after-upgrading-it-and-kibana-to-7-10-0/255739)

<div class="topic-metadata">

**Author:** [@jonjon](https://discuss.elastic.co/u/jonjon)\
**Replies:** 0\
**Last updated:** [November 17, 2020, 5:32pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-not-indexing-after-upgrading-it-and-kibana-to-7-10-0/255739 "2020-11-17T17:32:09Z")

</div>

I upgraded Kibana and filebeat to 7.10.0 and my Fortinet logs aren't being indexed anymore. Looking at the logs, it looks like I am filebeat is connected to Kibana but I am getting several of these messages below and log…

---

## [Get system.process.cpu.user.ticks](https://discuss.elastic.co/t/get-system-process-cpu-user-ticks/255584)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [November 17, 2020, 4:59pm UTC](https://discuss.elastic.co/t/get-system-process-cpu-user-ticks/255584 "2020-11-17T16:59:16Z")

</div>

I am trying to located system.process.cpu.user.ticks but I can't find it on my output. do I have to enable something in my system.module file? I only have following for system.process "cpu" =\> { …

---

## [FileBeat apache module log issue](https://discuss.elastic.co/t/filebeat-apache-module-log-issue/255718)

<div class="topic-metadata">

**Author:** [@psganeshk](https://discuss.elastic.co/u/psganeshk)\
**Replies:** 0\
**Last updated:** [November 17, 2020, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-log-issue/255718 "2020-11-17T14:44:18Z")

</div>

apache module configuration file Module: apache Docs: https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-apache.html module: apache Access logs access: enabled: true Set custom paths for the log fi…

---

## [Filebeat i/o timeout on output to Redis](https://discuss.elastic.co/t/filebeat-i-o-timeout-on-output-to-redis/255677)

<div class="topic-metadata">

**Author:** [@ushaopusnet](https://discuss.elastic.co/u/ushaopusnet)\
**Replies:** 0\
**Last updated:** [November 17, 2020, 11:32am UTC](https://discuss.elastic.co/t/filebeat-i-o-timeout-on-output-to-redis/255677 "2020-11-17T11:32:55Z")

</div>

Hi, I've a simple setup using filebeat (v7.8.0) pushing logs to redis v4.0.9 and seeing the following error in logs. Please help troubleshoot. redis/client.go:239 Failed to RPUSH to redis list with: write…

---

## [Rx packet errors metricbeat stat doesn't match netstat output](https://discuss.elastic.co/t/rx-packet-errors-metricbeat-stat-doesnt-match-netstat-output/255583)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [November 16, 2020, 6:00pm UTC](https://discuss.elastic.co/t/rx-packet-errors-metricbeat-stat-doesnt-match-netstat-output/255583 "2020-11-16T18:00:19Z")

</div>

I am using the following query: The stat I am trying to monitor is: kubernetes.pod.network.rx.errors. If I log onto one of the pods which has metricbeat running and my application and do netstat -s -u (-u for udp pa…

---

## [Logs nicely parsed but not showing in dashboards for nginx module in kubernetes](https://discuss.elastic.co/t/logs-nicely-parsed-but-not-showing-in-dashboards-for-nginx-module-in-kubernetes/255443)

<div class="topic-metadata">

**Author:** [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Replies:** 2\
**Last updated:** [November 16, 2020, 8:48pm UTC](https://discuss.elastic.co/t/logs-nicely-parsed-but-not-showing-in-dashboards-for-nginx-module-in-kubernetes/255443 "2020-11-16T20:48:42Z")

</div>

Hello, I am running my nginx container in kubernetes and using nginx module I am able to parse logs and show them nicely in kibana discover. I also see ingest pipelines for nginx in kibana. My setup is: Filebeat daemon…

---

## [Metricbeat gives me certificate issue](https://discuss.elastic.co/t/metricbeat-gives-me-certificate-issue/255590)

<div class="topic-metadata">

**Author:** [@adityak248](https://discuss.elastic.co/u/adityak248)\
**Replies:** 0\
**Last updated:** [November 16, 2020, 8:15pm UTC](https://discuss.elastic.co/t/metricbeat-gives-me-certificate-issue/255590 "2020-11-16T20:15:39Z")

</div>

Hello Team, I have been trying to configure the metricbeat over SSL and i keep getting the following error metricbeat\_1 | Exiting: error initializing publisher: 2 errors: open $CERTS\_DIR/elk/elk.crt: no such file or d…

---

## [Filebeat module to see system logins](https://discuss.elastic.co/t/filebeat-module-to-see-system-logins/255519)

<div class="topic-metadata">

**Author:** [@headtea](https://discuss.elastic.co/u/headtea)\
**Replies:** 4\
**Last updated:** [November 16, 2020, 12:21pm UTC](https://discuss.elastic.co/t/filebeat-module-to-see-system-logins/255519 "2020-11-16T12:21:16Z")

</div>

I have to keep track of system logins with filebeat. Filebeat has a default dashboard called \[Filebeat System\] SSH login attempts ECS which seems perfect. So to use that, I went to one of the machines, stopped filebeat, …

---

## [Apache module custom index is ignored](https://discuss.elastic.co/t/apache-module-custom-index-is-ignored/255560)

<div class="topic-metadata">

**Author:** [@JohanT](https://discuss.elastic.co/u/JohanT)\
**Replies:** 0\
**Last updated:** [November 16, 2020, 2:57pm UTC](https://discuss.elastic.co/t/apache-module-custom-index-is-ignored/255560 "2020-11-16T14:57:14Z")

</div>

Hi there, We've upgraded from filebeats 6.8.2 to 7.9.2, and all our logs are getting to ElasticSearch, yet the Apache logs are getting through with the default index (filebeat-version-date type setup) instead of the cus…

---

## [Filebeat-\* status of 413 "cannot read property 'get' of undefined"](https://discuss.elastic.co/t/filebeat-status-of-413-cannot-read-property-get-of-undefined/254939)

<div class="topic-metadata">

**Author:** [@datawrangler](https://discuss.elastic.co/u/datawrangler)\
**Replies:** 2\
**Last updated:** [November 16, 2020, 3:04pm UTC](https://discuss.elastic.co/t/filebeat-status-of-413-cannot-read-property-get-of-undefined/254939 "2020-11-16T15:04:29Z")

</div>

Hello All, I have a very strange issue where I can't even go to: http://:5601/app/management/kibana/indexPatterns/patterns/filebeat-\* ... the screen is blank and when I press F12 I get the error messages in the subjec…

---

## [CPU and Load Average high after enabling filebeat Apache module](https://discuss.elastic.co/t/cpu-and-load-average-high-after-enabling-filebeat-apache-module/254651)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 1\
**Last updated:** [November 16, 2020, 2:45pm UTC](https://discuss.elastic.co/t/cpu-and-load-average-high-after-enabling-filebeat-apache-module/254651 "2020-11-16T14:45:54Z")

</div>

Hi There, Our elasticsearch (Ver 7.9) consist of 4 Nodes (2 Hot and 2 Warm ) . We are using auditbeat ,winlogbeat and filebeat for sending data to the nodes. We recently started integrating apache access and error logs …

---

## [Fleet integration Suggestions](https://discuss.elastic.co/t/fleet-integration-suggestions/255270)

<div class="topic-metadata">

**Author:** [@pixelsquared](https://discuss.elastic.co/u/pixelsquared)\
**Replies:** 1\
**Last updated:** [November 16, 2020, 12:56pm UTC](https://discuss.elastic.co/t/fleet-integration-suggestions/255270 "2020-11-16T12:56:42Z")

</div>

Hi, I have some Ideas for fleet integrations: Winlogbeat Heartbeat OSquery Docker AuditBeat OPNsense Firewall Logs Thanks

---

## [Filebeat missing container k8 metadata](https://discuss.elastic.co/t/filebeat-missing-container-k8-metadata/255530)

<div class="topic-metadata">

**Author:** [@mo\_ct](https://discuss.elastic.co/u/mo_ct)\
**Replies:** 0\
**Last updated:** [November 16, 2020, 12:52pm UTC](https://discuss.elastic.co/t/filebeat-missing-container-k8-metadata/255530 "2020-11-16T12:52:42Z")

</div>

When running batch of short-lived containers (which are same docker images), on some (random) occasions k8 metadata tags are missing from some of them Also there are no errors on the Filebeat service itself when filebea…

---

## [Heartbeat url monitor](https://discuss.elastic.co/t/heartbeat-url-monitor/255524)

<div class="topic-metadata">

**Author:** [@psganeshk](https://discuss.elastic.co/u/psganeshk)\
**Replies:** 1\
**Last updated:** [November 16, 2020, 12:39pm UTC](https://discuss.elastic.co/t/heartbeat-url-monitor/255524 "2020-11-16T12:39:33Z")

</div>

Error 401 Unauthorized Response Body Body size is 381B. {"error":{"root\_cause":\[{"type":"security\_exception","reason":"missing authentication credentials for REST request \[/\]","header":{"WWW-Authenticate":"Basic real…

---

## [Why Filebeat is not picking up multiline ISO timestamp pattern but picking when pattern is defined manually?](https://discuss.elastic.co/t/why-filebeat-is-not-picking-up-multiline-iso-timestamp-pattern-but-picking-when-pattern-is-defined-manually/255036)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 2\
**Last updated:** [November 16, 2020, 12:17pm UTC](https://discuss.elastic.co/t/why-filebeat-is-not-picking-up-multiline-iso-timestamp-pattern-but-picking-when-pattern-is-defined-manually/255036 "2020-11-16T12:17:24Z")

</div>

Hi, I have log lines like below; \[2020-11-11T11:19:00+05:30\] \[INFO\] \[msg1\] \[msg2\] \[msg3\] \[msg4\] \[msg5\] \[msg6\] \[msg7\] \[msg8\] \[msg9\] The msg9 attribute may contain multi-line message, so I have decided to configure mult…

---

## [eTLD+1 seems to be eTLD+2 in some cases](https://discuss.elastic.co/t/etld-1-seems-to-be-etld-2-in-some-cases/250532)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [November 16, 2020, 10:45am UTC](https://discuss.elastic.co/t/etld-1-seems-to-be-etld-2-in-some-cases/250532 "2020-11-16T10:45:14Z")

</div>

Hello, Noticed in the packetbeat\_dns\_tunneling ml job that some etld+1's seem incorrect: The third column is dns.question.etld\_plus\_one Afaik an etld+1 should consist of 2 parts and 1 dot? For example dns.question.…

---

## [32-BIT Metricbeat (7.8.0) return abnormal value for system.network.in.bytes](https://discuss.elastic.co/t/32-bit-metricbeat-7-8-0-return-abnormal-value-for-system-network-in-bytes/254369)

<div class="topic-metadata">

**Author:** [@Razby](https://discuss.elastic.co/u/Razby)\
**Replies:** 4\
**Last updated:** [November 16, 2020, 10:00am UTC](https://discuss.elastic.co/t/32-bit-metricbeat-7-8-0-return-abnormal-value-for-system-network-in-bytes/254369 "2020-11-16T10:00:35Z")

</div>

Hi, 32-BIT Metricbeat (7.8.0) return abnormal high value for system.network.in.bytes such as "6,424,932,420,939,677,696". :worried: With 64-BIT version I got acceptable value such as "3,652,142,427" I really don’t kno…

---

## [Assigning ILM for metricbeat](https://discuss.elastic.co/t/assigning-ilm-for-metricbeat/253160)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 5\
**Last updated:** [November 16, 2020, 9:49am UTC](https://discuss.elastic.co/t/assigning-ilm-for-metricbeat/253160 "2020-11-16T09:49:08Z")

</div>

I have started metricbeat used custome field.yml file to load template. I have following in metricbeat.yml setup.template.fields: "fields.yml" setup.ilm.enabled: auto setup.template.overwrite: true now I started met…

---

## [On Windows system.memory.swap.total shows 2GB although there is no swap](https://discuss.elastic.co/t/on-windows-system-memory-swap-total-shows-2gb-although-there-is-no-swap/254663)

<div class="topic-metadata">

**Author:** [@goodmirek5849](https://discuss.elastic.co/u/goodmirek5849)\
**Replies:** 4\
**Last updated:** [November 16, 2020, 9:29am UTC](https://discuss.elastic.co/t/on-windows-system-memory-swap-total-shows-2gb-although-there-is-no-swap/254663 "2020-11-16T09:29:13Z")

</div>

We run metricbeat-oss-7.9.2-windows-x86\_64.zip on Windows Server 2016 and send data to Kafka. From Kafka, we consume data with Logstash and send them to ElasticCloud. We observe an issue with system.memory.swap.\* metric…

---

## [Ship login history](https://discuss.elastic.co/t/ship-login-history/255437)

<div class="topic-metadata">

**Author:** [@headtea](https://discuss.elastic.co/u/headtea)\
**Replies:** 1\
**Last updated:** [November 15, 2020, 2:57pm UTC](https://discuss.elastic.co/t/ship-login-history/255437 "2020-11-15T14:57:22Z")

</div>

On all servers, I use Filebeat and Auditbeat. While I use filebeat for all sorts of things - I only use auditbeat to ship system logins (who attempted to log-on, from where, successful or not). It comes with Auditbeat's …

---

## [Stack monitoring issues on single node cluster](https://discuss.elastic.co/t/stack-monitoring-issues-on-single-node-cluster/255355)

<div class="topic-metadata">

**Author:** [@DanLS](https://discuss.elastic.co/u/DanLS)\
**Replies:** 3\
**Last updated:** [November 16, 2020, 12:02am UTC](https://discuss.elastic.co/t/stack-monitoring-issues-on-single-node-cluster/255355 "2020-11-16T00:02:18Z")

</div>

Hi, trying to set up node monitoring with metricbeat on a single node cluster (i know its best practise to have a monitoring node but this is just for testing etc) i've followed the install and looking at the logs it ap…

---

## [Filebeat Nginx ingress\_controller doesn't parse message properly](https://discuss.elastic.co/t/filebeat-nginx-ingress-controller-doesnt-parse-message-properly/255423)

<div class="topic-metadata">

**Author:** [@zbioe](https://discuss.elastic.co/u/zbioe)\
**Replies:** 0\
**Last updated:** [November 15, 2020, 5:25am UTC](https://discuss.elastic.co/t/filebeat-nginx-ingress-controller-doesnt-parse-message-properly/255423 "2020-11-15T05:25:36Z")

</div>

We setted the pipeline for filebeat to get the logs from ingress-nginx inside kubernetes. In output it appears with event.dataset: "nginx.ingress\_controller", but it don't parse properlly. We can't see any dashboard, a…

---

## [Does Filebeat have to use 'beats\_system' or 'elastic' to connect to ElasticSearch?](https://discuss.elastic.co/t/does-filebeat-have-to-use-beats-system-or-elastic-to-connect-to-elasticsearch/255434)

<div class="topic-metadata">

**Author:** [@houmie](https://discuss.elastic.co/u/houmie)\
**Replies:** 1\
**Last updated:** [November 15, 2020, 3:14pm UTC](https://discuss.elastic.co/t/does-filebeat-have-to-use-beats-system-or-elastic-to-connect-to-elasticsearch/255434 "2020-11-15T15:14:19Z")

</div>

Sorry, which one is the best practice? Because when we run elasticsearch-setup-passwords auto it generates passwords for beats\_system and elastic for us. output.elasticsearch: hosts: \["localhost:9200"\] protocol: "ht…

---

## [Question about log rotation and log order](https://discuss.elastic.co/t/question-about-log-rotation-and-log-order/255427)

<div class="topic-metadata">

**Author:** [@Guohao\_Yi](https://discuss.elastic.co/u/Guohao_Yi)\
**Replies:** 0\
**Last updated:** [November 15, 2020, 7:21am UTC](https://discuss.elastic.co/t/question-about-log-rotation-and-log-order/255427 "2020-11-15T07:21:13Z")

</div>

I have learned that filebeat can be configured properly to handle log rotation correctly. However, I am not sure if the following situation I am going to mention is possibile to configure or not. We want to collect logs…

---

## [How to get multiline JSON parsing configured?](https://discuss.elastic.co/t/how-to-get-multiline-json-parsing-configured/255409)

<div class="topic-metadata">

**Author:** [@houmie](https://discuss.elastic.co/u/houmie)\
**Replies:** 1\
**Last updated:** [November 14, 2020, 5:39pm UTC](https://discuss.elastic.co/t/how-to-get-multiline-json-parsing-configured/255409 "2020-11-14T17:39:45Z")

</div>

Hello, When I try to activate multiline JSON parsing directly I get this error message:: Exiting: Failed to start crawler: starting input failed: Error while initializing input: When using the JSON decoder and multili…

---

## [How to remove all the Host&Cloud fields added to Filebeats/Elasticsearch index?](https://discuss.elastic.co/t/how-to-remove-all-the-host-cloud-fields-added-to-filebeats-elasticsearch-index/255399)

<div class="topic-metadata">

**Author:** [@houmie](https://discuss.elastic.co/u/houmie)\
**Replies:** 2\
**Last updated:** [November 14, 2020, 5:12pm UTC](https://discuss.elastic.co/t/how-to-remove-all-the-host-cloud-fields-added-to-filebeats-elasticsearch-index/255399 "2020-11-14T17:12:50Z")

</div>

Hello, I finally got Filebeats/Elasticsearch/Kibana working. However the stack seems to have injected a lot of cloud tags (e.g. cloud.account.id) and host tags (host.os.kernel) that has inflated the data and makes it h…

---

## [Different modules?](https://discuss.elastic.co/t/different-modules/255345)

<div class="topic-metadata">

**Author:** [@MichaelJ](https://discuss.elastic.co/u/MichaelJ)\
**Replies:** 3\
**Last updated:** [November 13, 2020, 2:48pm UTC](https://discuss.elastic.co/t/different-modules/255345 "2020-11-13T14:48:15Z")

</div>

We're using filebeat to ingest all kinds of logfiles: application logs, apache, nginx, whatever. For specifix log files, like apache, we want to parse the message into different fields. The apache module with its ingest…

---

## [Filebeat logs not making it to Logstash](https://discuss.elastic.co/t/filebeat-logs-not-making-it-to-logstash/252941)

<div class="topic-metadata">

**Author:** [@allieg](https://discuss.elastic.co/u/allieg)\
**Replies:** 4\
**Last updated:** [November 13, 2020, 1:43pm UTC](https://discuss.elastic.co/t/filebeat-logs-not-making-it-to-logstash/252941 "2020-11-13T13:43:37Z")

</div>

Hi, for some reason remote server that has Filebeat setup on it is not being able to successfully send logs to my elk server that has logstash running on it. I ran filebeat -e -d "publish,logstash and got the following w…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=196)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=198)
