# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=198

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 199

---

## [Auditbeat 7.8.0 stuck: process running but no data sent to Elasticsearch](https://discuss.elastic.co/t/auditbeat-7-8-0-stuck-process-running-but-no-data-sent-to-elasticsearch/255323)

<div class="topic-metadata">

**Author:** [@sonickenbaker](https://discuss.elastic.co/u/sonickenbaker)\
**Replies:** 0\
**Last updated:** [November 13, 2020, 10:22am UTC](https://discuss.elastic.co/t/auditbeat-7-8-0-stuck-process-running-but-no-data-sent-to-elasticsearch/255323 "2020-11-13T10:22:19Z")

</div>

Hello, I have auditbeat v7.8.0 installed on a Ubuntu 18.04.5 LTS VM that is currently in a weird state. Process is up and running but no data is sent to Elasticsearch. According to systemd the process is fine (and it i…

---

## [Logstash or straight?](https://discuss.elastic.co/t/logstash-or-straight/253722)

<div class="topic-metadata">

**Author:** [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Replies:** 2\
**Last updated:** [November 13, 2020, 7:57am UTC](https://discuss.elastic.co/t/logstash-or-straight/253722 "2020-11-13T07:57:51Z")

</div>

Hi, Simpel question, What would be the (dis)advantage of sending metrics via logstash to ES instead of directly? Cheers,

---

## [Filebeat stop to send logs to Elastic after cluster\_block\_exception occurs](https://discuss.elastic.co/t/filebeat-stop-to-send-logs-to-elastic-after-cluster-block-exception-occurs/255301)

<div class="topic-metadata">

**Author:** [@mattia\_galati](https://discuss.elastic.co/u/mattia_galati)\
**Replies:** 0\
**Last updated:** [November 13, 2020, 7:41am UTC](https://discuss.elastic.co/t/filebeat-stop-to-send-logs-to-elastic-after-cluster-block-exception-occurs/255301 "2020-11-13T07:41:20Z")

</div>

I'm containerizing a monolith application and in each current VM there is a Logstash process which harvests the logs that are being rotating by the application itself, through the python's RotatingFileHandler. In the cu…

---

## [Kubernetes monitoring using metricbeat and ELK](https://discuss.elastic.co/t/kubernetes-monitoring-using-metricbeat-and-elk/255297)

<div class="topic-metadata">

**Author:** [@ruthvicsakre](https://discuss.elastic.co/u/ruthvicsakre)\
**Replies:** 0\
**Last updated:** [November 13, 2020, 7:06am UTC](https://discuss.elastic.co/t/kubernetes-monitoring-using-metricbeat-and-elk/255297 "2020-11-13T07:06:18Z")

</div>

Hi, We are using metricbeat to monitor kubernetes which is on AKS. We have installed Kube-state-metrics which is prerequisite for metricbeat and also metricbeat using the values.yaml present in below. But, in the default…

---

## [Metricbeat 7.8 | aws.rds | cpu intermittently missing from multiple events](https://discuss.elastic.co/t/metricbeat-7-8-aws-rds-cpu-intermittently-missing-from-multiple-events/255271)

<div class="topic-metadata">

**Author:** [@william.shipman](https://discuss.elastic.co/u/william.shipman)\
**Replies:** 0\
**Last updated:** [November 12, 2020, 11:56pm UTC](https://discuss.elastic.co/t/metricbeat-7-8-aws-rds-cpu-intermittently-missing-from-multiple-events/255271 "2020-11-12T23:56:35Z")

</div>

I'm using metricbeat's AWS module to scrape rds data from cloudwatch for multiple aurora databases. I'm currently seeing events missing cpu data at the same time, across multiple database instances, even while the events…

---

## [Cisco IOS Filebeat Indexing Error](https://discuss.elastic.co/t/cisco-ios-filebeat-indexing-error/255260)

<div class="topic-metadata">

**Author:** [@savethebyte](https://discuss.elastic.co/u/savethebyte)\
**Replies:** 2\
**Last updated:** [November 12, 2020, 10:28pm UTC](https://discuss.elastic.co/t/cisco-ios-filebeat-indexing-error/255260 "2020-11-12T22:28:15Z")

</div>

I am saving logs to a file via syslog-ng (for other reasons). Filebeat is using that file as a source for cisco-ios logs. I am using the official Cisco module but when I am loading cisco-ios logs, I am getting a parsing …

---

## [JWT Support in Beats](https://discuss.elastic.co/t/jwt-support-in-beats/254825)

<div class="topic-metadata">

**Author:** [@cchandak](https://discuss.elastic.co/u/cchandak)\
**Replies:** 2\
**Last updated:** [November 12, 2020, 9:38pm UTC](https://discuss.elastic.co/t/jwt-support-in-beats/254825 "2020-11-12T21:38:32Z")

</div>

I would like to scrape logs using Beats (either Filebeat, Metricbeat, etc.) and send them to Logstash or Kafka depending on my use case. Currently, I am leveraging the SSL support, but I would like to use JSON Web Token …

---

## [Filebeat running as root, but not ingesting all logs](https://discuss.elastic.co/t/filebeat-running-as-root-but-not-ingesting-all-logs/254583)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 3\
**Last updated:** [November 12, 2020, 9:20pm UTC](https://discuss.elastic.co/t/filebeat-running-as-root-but-not-ingesting-all-logs/254583 "2020-11-12T21:20:15Z")

</div>

I am running Ubuntu, and I noticed in Kibana, it is only monitoring two files: kern.log and auth.log. Here are what the file permissions look like: -rw-r----- 1 syslog adm. Doing a ps aux, I get this: root 17888…

---

## [Drop event for Apache Module](https://discuss.elastic.co/t/drop-event-for-apache-module/254913)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 2\
**Last updated:** [November 12, 2020, 1:03pm UTC](https://discuss.elastic.co/t/drop-event-for-apache-module/254913 "2020-11-12T13:03:21Z")

</div>

Hi Team, I am trying drop a specific event from filebeat apache module , i have tried below drop event processor and its not working. Event to be dropped if the url.original field contains refresh as the text url.orig…

---

## [Mutiple beats on multiple servers sending logs to logstash through one pipeline](https://discuss.elastic.co/t/mutiple-beats-on-multiple-servers-sending-logs-to-logstash-through-one-pipeline/255205)

<div class="topic-metadata">

**Author:** [@prajwalgmpp](https://discuss.elastic.co/u/prajwalgmpp)\
**Replies:** 1\
**Last updated:** [November 12, 2020, 12:18pm UTC](https://discuss.elastic.co/t/mutiple-beats-on-multiple-servers-sending-logs-to-logstash-through-one-pipeline/255205 "2020-11-12T12:18:10Z")

</div>

Hi. I have a requirement where I am supposed to enable log monitoring of NOI (Netcool Omnibus Impact) components through Elastic stack. We have decided to install filebeats on all the components and send logs to logstas…

---

## [WinLogBeat as Daemonset](https://discuss.elastic.co/t/winlogbeat-as-daemonset/255199)

<div class="topic-metadata">

**Author:** [@geek876](https://discuss.elastic.co/u/geek876)\
**Replies:** 0\
**Last updated:** [November 12, 2020, 10:49am UTC](https://discuss.elastic.co/t/winlogbeat-as-daemonset/255199 "2020-11-12T10:49:39Z")

</div>

Dear Members, Has anyone successfully configured 'WinLogBeat' as DaemonSet on 'Windows Docker Host' for Kubernetes ? Or is that possible at all ? If not, what are alternative approaches ? Ours is a hybrid K8s Cluster ( …

---

## [Filebeat is unable to send data to Logstash, and very high CPU utilization on filebeat](https://discuss.elastic.co/t/filebeat-is-unable-to-send-data-to-logstash-and-very-high-cpu-utilization-on-filebeat/255161)

<div class="topic-metadata">

**Author:** [@Utkarsh\_Jain](https://discuss.elastic.co/u/Utkarsh_Jain)\
**Replies:** 2\
**Last updated:** [November 12, 2020, 9:52am UTC](https://discuss.elastic.co/t/filebeat-is-unable-to-send-data-to-logstash-and-very-high-cpu-utilization-on-filebeat/255161 "2020-11-12T09:52:25Z")

</div>

Hello, Everything was working fine for us but after a security patch update, the CPU utilization is very high on filebeat server and logstash is not recieving data from filebeat. Here are the logs from logstash server. …

---

## [AWS ELK and metricbeat issue](https://discuss.elastic.co/t/aws-elk-and-metricbeat-issue/255179)

<div class="topic-metadata">

**Author:** [@alfredo.deluca](https://discuss.elastic.co/u/alfredo.deluca)\
**Replies:** 0\
**Last updated:** [November 12, 2020, 9:31am UTC](https://discuss.elastic.co/t/aws-elk-and-metricbeat-issue/255179 "2020-11-12T09:31:49Z")

</div>

Hi all. I have AWS Elasticsearch 7.8 and also, for testing purposes, I have a minikube kubernetes where I installed through Helm, metricbeat. When I do metricbeat test config it seems to be ok and test output parse ur…

---

## [Filebeat pipeline Apache log pattern including response time](https://discuss.elastic.co/t/filebeat-pipeline-apache-log-pattern-including-response-time/255090)

<div class="topic-metadata">

**Author:** [@ChrisTB](https://discuss.elastic.co/u/ChrisTB)\
**Replies:** 1\
**Last updated:** [November 12, 2020, 9:31am UTC](https://discuss.elastic.co/t/filebeat-pipeline-apache-log-pattern-including-response-time/255090 "2020-11-12T09:31:25Z")

</div>

Hi, In our apache logs we also log response time with the %D parameter. We would also like to add this field to the filebeat logs so we can analyse it in Kibana. I can manage to add an updated grok pattern to the fileb…

---

## [Can EA replace all beats?](https://discuss.elastic.co/t/can-ea-replace-all-beats/253723)

<div class="topic-metadata">

**Author:** [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Replies:** 4\
**Last updated:** [November 12, 2020, 9:17am UTC](https://discuss.elastic.co/t/can-ea-replace-all-beats/253723 "2020-11-12T09:17:55Z")

</div>

Hi, Topic title says it all. At this moment I am buidling up a new platform based on 7.9.3 . I still need to install filebeat/metricbeat on dozens of servers and am wondering: would Elastic-agent eventually replace tho…

---

## [Removing of \\\\\\\\ via filebeat while parsing logs to elastic search](https://discuss.elastic.co/t/removing-of-via-filebeat-while-parsing-logs-to-elastic-search/254589)

<div class="topic-metadata">

**Author:** [@525125](https://discuss.elastic.co/u/525125)\
**Replies:** 2\
**Last updated:** [November 12, 2020, 7:15am UTC](https://discuss.elastic.co/t/removing-of-via-filebeat-while-parsing-logs-to-elastic-search/254589 "2020-11-12T07:15:08Z")

</div>

log line: {"log":"{\\"time\\":\\"2019-11-04 18:06:07.+00:00\\",\\"severity\\":\\"Information\\",\\"name\\":\\"\\"45632dc\\"\\",\\"class\\":\\"\\"Middleware\\"\\",\\"mcr\\":\\"\\"\_\_3\\"\\",\\"msg\\":\\"###Request: http url ###Response: 200: {\\\\n \[\\…

---

## [Write ip4 0.0.0.0-\>10.X.X.X: sendto: no buffer space available](https://discuss.elastic.co/t/write-ip4-0-0-0-0-10-x-x-x-sendto-no-buffer-space-available/255050)

<div class="topic-metadata">

**Author:** [@rguptarg](https://discuss.elastic.co/u/rguptarg)\
**Replies:** 2\
**Last updated:** [November 12, 2020, 5:09am UTC](https://discuss.elastic.co/t/write-ip4-0-0-0-0-10-x-x-x-sendto-no-buffer-space-available/255050 "2020-11-12T05:09:40Z")

</div>

HI, I am new in heartbeat, I have configured heartbeat-elastic-7.9.3-1.x86\_64 with default configuration. Currently I am using only ICMP monitoring and configured 8K IP's. But I am getting "sendto: no buffer space avai…

---

## [Heartbeat schedule not work when has large number of hosts](https://discuss.elastic.co/t/heartbeat-schedule-not-work-when-has-large-number-of-hosts/253522)

<div class="topic-metadata">

**Author:** [@luckyclue](https://discuss.elastic.co/u/luckyclue)\
**Replies:** 1\
**Last updated:** [November 12, 2020, 2:27am UTC](https://discuss.elastic.co/t/heartbeat-schedule-not-work-when-has-large-number-of-hosts/253522 "2020-11-12T02:27:39Z")

</div>

heartbeat icmp monitor not work with large number of hosts with config schedule: '1 \* \* \* \* \* \*' It did not show any error but cannot create index at elasticsearch . not work (under 4096 hosts it is normal) schedule: …

---

## [Packetbeat, fail to set up index lifecyle policy](https://discuss.elastic.co/t/packetbeat-fail-to-set-up-index-lifecyle-policy/255139)

<div class="topic-metadata">

**Author:** [@Yanyan\_Liang](https://discuss.elastic.co/u/Yanyan_Liang)\
**Replies:** 0\
**Last updated:** [November 12, 2020, 12:04am UTC](https://discuss.elastic.co/t/packetbeat-fail-to-set-up-index-lifecyle-policy/255139 "2020-11-12T00:04:38Z")

</div>

Hi Community, I have tried to set up packetbeat index for 2 days, then rollover to delete phrase for 1 day. I have 1 node, for practice only. This was my configuration in packetbeat.yml where I made changes, others rem…

---

## [Libclntsh.so: cannot open shared object file](https://discuss.elastic.co/t/libclntsh-so-cannot-open-shared-object-file/255126)

<div class="topic-metadata">

**Author:** [@glitz](https://discuss.elastic.co/u/glitz)\
**Replies:** 0\
**Last updated:** [November 11, 2020, 9:00pm UTC](https://discuss.elastic.co/t/libclntsh-so-cannot-open-shared-object-file/255126 "2020-11-11T21:00:45Z")

</div>

Hello, I'm trying to configure Metricbeat with Oracle module but I got this error: module/wrapper.go:266 Error fetching data for metricset oracle.performance: error creating connection to Oracle: error doing ping to da…

---

## [Authentication in us-gov-west-1 with Metricbeat AWS module](https://discuss.elastic.co/t/authentication-in-us-gov-west-1-with-metricbeat-aws-module/254951)

<div class="topic-metadata">

**Author:** [@jstein\_presidio](https://discuss.elastic.co/u/jstein_presidio)\
**Replies:** 2\
**Last updated:** [November 11, 2020, 6:13pm UTC](https://discuss.elastic.co/t/authentication-in-us-gov-west-1-with-metricbeat-aws-module/254951 "2020-11-11T18:13:52Z")

</div>

aws.yml is as follows regions: us-gov-west-1 shared\_credential\_file: /mnt/home/metricbeat/.aws\_creds aws\_partition: aws-us-gov #endpoint: us-gov-west-1.amazonaws.com period: 5m metricsets: - ec2 2020-11…

---

## [Not able to collect TTY logs using AuditBeat in Kubernetes (AWS EKS)](https://discuss.elastic.co/t/not-able-to-collect-tty-logs-using-auditbeat-in-kubernetes-aws-eks/254006)

<div class="topic-metadata">

**Author:** [@benyitzhaki](https://discuss.elastic.co/u/benyitzhaki)\
**Replies:** 1\
**Last updated:** [November 11, 2020, 12:24pm UTC](https://discuss.elastic.co/t/not-able-to-collect-tty-logs-using-auditbeat-in-kubernetes-aws-eks/254006 "2020-11-11T12:24:41Z")

</div>

I would like to audit users shell activity using AuditBeat and the auditd module integration, by looking at TTY logs. I have followed every possible doc and can't get it up and running. I can see executions, but can't s…

---

## [Filebeat Cisco IOS problem](https://discuss.elastic.co/t/filebeat-cisco-ios-problem/254995)

<div class="topic-metadata">

**Author:** [@Fikrat\_Karimli](https://discuss.elastic.co/u/Fikrat_Karimli)\
**Replies:** 1\
**Last updated:** [November 11, 2020, 6:14am UTC](https://discuss.elastic.co/t/filebeat-cisco-ios-problem/254995 "2020-11-11T06:14:06Z")

</div>

Hi, We are having such trouble with Cisco IOS logs. We enabled cisco ios module but it has parsing error 2020-11-11T01:03:27.650Z DEBUG \[processors\] processing/processors.go:112 Fail to apply processor client{add\_local…

---

## [Nginx field disappeared after filebeat upgrade](https://discuss.elastic.co/t/nginx-field-disappeared-after-filebeat-upgrade/254774)

<div class="topic-metadata">

**Author:** [@yukpun](https://discuss.elastic.co/u/yukpun)\
**Replies:** 2\
**Last updated:** [November 11, 2020, 5:17am UTC](https://discuss.elastic.co/t/nginx-field-disappeared-after-filebeat-upgrade/254774 "2020-11-11T05:17:45Z")

</div>

Hi all. I upgraded Elastic Stack (Elasticsearch + Kibana + Filebeat) from 6.6 to 7.9.3 version. Previously I used to filter logs by nginx.access.host field. After upgrade - this field disappeared. And I don't see any n…

---

## [Functionbeat does not update documents with existing \_id](https://discuss.elastic.co/t/functionbeat-does-not-update-documents-with-existing-id/252901)

<div class="topic-metadata">

**Author:** [@amiPorat](https://discuss.elastic.co/u/amiPorat)\
**Replies:** 4\
**Last updated:** [November 11, 2020, 4:52am UTC](https://discuss.elastic.co/t/functionbeat-does-not-update-documents-with-existing-id/252901 "2020-11-11T04:52:44Z")

</div>

Hello, I am currently deploying Functionbeat configured to accept events from an SQS queue. The goal is to use a processor/ingest pipeline to extract and set \_id from fields in the incoming messages. Documents with exis…

---

## [Should filebeat's cisco module export ecs fields when outputting to non-elasticsearch](https://discuss.elastic.co/t/should-filebeats-cisco-module-export-ecs-fields-when-outputting-to-non-elasticsearch/254801)

<div class="topic-metadata">

**Author:** [@justinainsworth](https://discuss.elastic.co/u/justinainsworth)\
**Replies:** 4\
**Last updated:** [November 10, 2020, 11:42pm UTC](https://discuss.elastic.co/t/should-filebeats-cisco-module-export-ecs-fields-when-outputting-to-non-elasticsearch/254801 "2020-11-10T23:42:55Z")

</div>

I'm new to filebeat, and I am trying to understand what data it should be exporting when sending to logstash. I have setup filebeat to read cisco asa log files, and output to logstash. I guess I expected it to parse mo…

---

## [Functionbeat - kinesis seems not ingesting data stream](https://discuss.elastic.co/t/functionbeat-kinesis-seems-not-ingesting-data-stream/254921)

<div class="topic-metadata">

**Author:** [@hyochang](https://discuss.elastic.co/u/hyochang)\
**Replies:** 2\
**Last updated:** [November 10, 2020, 11:21pm UTC](https://discuss.elastic.co/t/functionbeat-kinesis-seems-not-ingesting-data-stream/254921 "2020-11-10T23:21:31Z")

</div>

Hi With functionbeat-kinesis, I have been trying to steam AWS Kinese Data stream to my locally deployed Elastic. All set-up seems okay. the functionbeat lambda deployed and I don't see any error from the functionbeat l…

---

## [Forward beats logs from site A to B using a single server as a proxy](https://discuss.elastic.co/t/forward-beats-logs-from-site-a-to-b-using-a-single-server-as-a-proxy/254614)

<div class="topic-metadata">

**Author:** [@Shankars](https://discuss.elastic.co/u/Shankars)\
**Replies:** 3\
**Last updated:** [November 10, 2020, 5:22pm UTC](https://discuss.elastic.co/t/forward-beats-logs-from-site-a-to-b-using-a-single-server-as-a-proxy/254614 "2020-11-10T17:22:49Z")

</div>

Hello, I searched a way to ship logs from one site to another using a single point of contact (a server using a VPN to connect to site B), let's see it this way : Differents endpoints using Beats to ship logs to the se…

---

## [Filebeat high disk usage when reboot server. How fix it?](https://discuss.elastic.co/t/filebeat-high-disk-usage-when-reboot-server-how-fix-it/254884)

<div class="topic-metadata">

**Author:** [@Andrew\_Foxis](https://discuss.elastic.co/u/Andrew_Foxis)\
**Replies:** 0\
**Last updated:** [November 10, 2020, 9:25am UTC](https://discuss.elastic.co/t/filebeat-high-disk-usage-when-reboot-server-how-fix-it/254884 "2020-11-10T09:25:13Z")

</div>

Hi all! Filebeat on server send csv logs of exchange (windows) server to logstash. When we reboot server filebeat make high disk usage. Other services can't load for a long time. How can i fix it? Thank you

---

## [Filebeat is not send enough log to elasticsearch](https://discuss.elastic.co/t/filebeat-is-not-send-enough-log-to-elasticsearch/254196)

<div class="topic-metadata">

**Author:** [@AkatsukiPain](https://discuss.elastic.co/u/AkatsukiPain)\
**Replies:** 8\
**Last updated:** [November 10, 2020, 9:17am UTC](https://discuss.elastic.co/t/filebeat-is-not-send-enough-log-to-elasticsearch/254196 "2020-11-10T09:17:08Z")

</div>

My filebeat sending not enough logs to elasticsearch. Graph suddenly went down This is filebeat.yml filebeat.inputs: #============================= Filebeat modules =============================== filebeat.conf…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=197)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=199)
