# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=199

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 200

---

## [Custom log file - Kibana](https://discuss.elastic.co/t/custom-log-file-kibana/254866)

<div class="topic-metadata">

**Author:** [@mrdebian](https://discuss.elastic.co/u/mrdebian)\
**Replies:** 1\
**Last updated:** [November 10, 2020, 8:37am UTC](https://discuss.elastic.co/t/custom-log-file-kibana/254866 "2020-11-10T08:37:50Z")

</div>

Hi all, I'm new to ELK setup and trying to figure out what is the problem with one particular log file. When I run filebeat in debug mode it seems that it parses the file fine (see output below) but when I search on Ki…

---

## [Filebeat use default port instead of my port](https://discuss.elastic.co/t/filebeat-use-default-port-instead-of-my-port/254756)

<div class="topic-metadata">

**Author:** [@rony](https://discuss.elastic.co/u/rony)\
**Replies:** 2\
**Last updated:** [November 10, 2020, 8:25am UTC](https://discuss.elastic.co/t/filebeat-use-default-port-instead-of-my-port/254756 "2020-11-10T08:25:11Z")

</div>

my filebeat.yml looks like this: filebeat.inputs: - type: log enabled: true paths: - /var/logs/mylog.log #============================= Filebeat modules =============================== filebeat.config.modules…

---

## [Filebeat Setup error: error loading index pattern: returned 408 to import file](https://discuss.elastic.co/t/filebeat-setup-error-error-loading-index-pattern-returned-408-to-import-file/254855)

<div class="topic-metadata">

**Author:** [@jaydeepk](https://discuss.elastic.co/u/jaydeepk)\
**Replies:** 2\
**Last updated:** [November 10, 2020, 8:03am UTC](https://discuss.elastic.co/t/filebeat-setup-error-error-loading-index-pattern-returned-408-to-import-file/254855 "2020-11-10T08:03:20Z")

</div>

Hi I'm currently using a 14-day free trial of elastic cloud. I was trying to get my local apache logs shipped to the hosted elastic cluster. So I decided to setup a Filebeat on my local machine ( Mac OS Catalina) acc…

---

## [Error retrieving collection totals from Mongo module metric beat](https://discuss.elastic.co/t/error-retrieving-collection-totals-from-mongo-module-metric-beat/254861)

<div class="topic-metadata">

**Author:** [@tarund](https://discuss.elastic.co/u/tarund)\
**Replies:** 0\
**Last updated:** [November 10, 2020, 7:54am UTC](https://discuss.elastic.co/t/error-retrieving-collection-totals-from-mongo-module-metric-beat/254861 "2020-11-10T07:54:34Z")

</div>

Hi, I have configured metric beat on mongodb sending data to Elasticsearch. I am getting data except for collstats. I am 2000+ databases in mongo. So, probably the number of metrics of collstats is large. I am getting …

---

## [How to create Index Template & ILM Policy for Logstash output in Filebeat](https://discuss.elastic.co/t/how-to-create-index-template-ilm-policy-for-logstash-output-in-filebeat/254857)

<div class="topic-metadata">

**Author:** [@ksaha](https://discuss.elastic.co/u/ksaha)\
**Replies:** 0\
**Last updated:** [November 10, 2020, 7:25am UTC](https://discuss.elastic.co/t/how-to-create-index-template-ilm-policy-for-logstash-output-in-filebeat/254857 "2020-11-10T07:25:45Z")

</div>

Hi, If I set the filebeat output to Logstash and give customize name to the index in the output section of Logstash pipeline code, in that case how to create the index template and ILM policy (For Elasticsearch output i…

---

## [Heartbeat monitoring system resources utilization](https://discuss.elastic.co/t/heartbeat-monitoring-system-resources-utilization/254745)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 4\
**Last updated:** [November 10, 2020, 1:13am UTC](https://discuss.elastic.co/t/heartbeat-monitoring-system-resources-utilization/254745 "2020-11-10T01:13:52Z")

</div>

Hello, I wanted to ask what is a better approach in setting up for example icmp monitor for 1 minute ping: 1.) Schedule a monitor to start every 24h with wait 1m value? 2.) Schedule monitor every 1 minute with 1 minut…

---

## [How to periodically harvest/read Status-File that changes in content, but not in size?](https://discuss.elastic.co/t/how-to-periodically-harvest-read-status-file-that-changes-in-content-but-not-in-size/254371)

<div class="topic-metadata">

**Author:** [@anriko](https://discuss.elastic.co/u/anriko)\
**Replies:** 2\
**Last updated:** [November 9, 2020, 8:05pm UTC](https://discuss.elastic.co/t/how-to-periodically-harvest-read-status-file-that-changes-in-content-but-not-in-size/254371 "2020-11-09T20:05:37Z")

</div>

Hi, I am having a Status-Logfile, that changes periodically (every minute). The problem is, that mostly only content of the file changes (timestamps, some numbers) and the size of the file stays the same. I am having tr…

---

## [Metricbeat ILM issue](https://discuss.elastic.co/t/metricbeat-ilm-issue/254541)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 2\
**Last updated:** [November 9, 2020, 4:39pm UTC](https://discuss.elastic.co/t/metricbeat-ilm-issue/254541 "2020-11-09T16:39:04Z")

</div>

Hi, \*Note: Running ELK 7.9.2. Beats version matches ELK version. I recently deployed Metricbeat to monitor my MSSQL server. Setup was successfully completed according to the PS console output. Metricbeat index, index t…

---

## [Can filebeat exclude a specific container name from hints-based autodiscover?](https://discuss.elastic.co/t/can-filebeat-exclude-a-specific-container-name-from-hints-based-autodiscover/254577)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [November 9, 2020, 1:54pm UTC](https://discuss.elastic.co/t/can-filebeat-exclude-a-specific-container-name-from-hints-based-autodiscover/254577 "2020-11-09T13:54:20Z")

</div>

In a hints-based autodiscover configuration, can filebeat exclude all instances of a specific container name from discovery, even if co.elastic.logs/enabled: 'true' is set for the pod? My use case is that I have a fileb…

---

## [Elastic agent & fleet](https://discuss.elastic.co/t/elastic-agent-fleet/254691)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [November 9, 2020, 8:46am UTC](https://discuss.elastic.co/t/elastic-agent-fleet/254691 "2020-11-09T08:46:14Z")

</div>

Hi there, instead of different kind of beats we are going to use agent & fleet. Concerning fleet I have a question: How does it work together with Kibana spaces? In a central environment, where different projects share …

---

## [Filebeat failed to insert too much log](https://discuss.elastic.co/t/filebeat-failed-to-insert-too-much-log/254607)

<div class="topic-metadata">

**Author:** [@Mohammad\_Mousavi](https://discuss.elastic.co/u/Mohammad_Mousavi)\
**Replies:** 1\
**Last updated:** [November 9, 2020, 8:28am UTC](https://discuss.elastic.co/t/filebeat-failed-to-insert-too-much-log/254607 "2020-11-09T08:28:04Z")

</div>

Hi, It's look like my filebeats agents are failed to insert some logs into elasticsearch. I have multiple filebeats and 3 logstash and 3 clustered elasticsearch (1 shard , 2 replica). I see some data exists in nginx lo…

---

## [Filebeat using Fortinet module TZ issue](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 11\
**Last updated:** [November 9, 2020, 4:54am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518 "2020-11-09T04:54:51Z")

</div>

Hi, We are using Filebeat with the Fortinet module to ingest our FW logs via Syslog. Our Fortigates do not send timezone information in log entries. The logs all have this format \<189\>date=2020-10-09 time=14:06:56 de…

---

## [Cannot Parse Json response, looking for begining of values](https://discuss.elastic.co/t/cannot-parse-json-response-looking-for-begining-of-values/252632)

<div class="topic-metadata">

**Author:** [@Arsalan\_Shahid](https://discuss.elastic.co/u/Arsalan_Shahid)\
**Replies:** 6\
**Last updated:** [November 7, 2020, 6:05am UTC](https://discuss.elastic.co/t/cannot-parse-json-response-looking-for-begining-of-values/252632 "2020-11-07T06:05:51Z")

</div>

i am having a problem. i followed all instructions from elastic.co to install ELK Stack but when i run filebeat setup -e is show error: Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[er…

---

## [Ingesting files from host with filebeat](https://discuss.elastic.co/t/ingesting-files-from-host-with-filebeat/254448)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 2\
**Last updated:** [November 6, 2020, 9:58pm UTC](https://discuss.elastic.co/t/ingesting-files-from-host-with-filebeat/254448 "2020-11-06T21:58:39Z")

</div>

I am following this tutorial here: https://kifarunix.com/install-and-configure-elastic-auditbeat-on-ubuntu-18-04/. Upon running this command: curl -XGET 192.168.0.106:9200/\_cat/indices?v I do not see auditbeat listed.…

---

## [Can filebeat.autodiscover load external configuration files, like inputs and modules can?](https://discuss.elastic.co/t/can-filebeat-autodiscover-load-external-configuration-files-like-inputs-and-modules-can/254546)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [November 6, 2020, 5:12pm UTC](https://discuss.elastic.co/t/can-filebeat-autodiscover-load-external-configuration-files-like-inputs-and-modules-can/254546 "2020-11-06T17:12:40Z")

</div>

Title says it all. Filebeat has the capability to load external configuration files for inputs and modules, which is documented here. Does this capability also exist for autodiscover configurations? I suspect the answe…

---

## [Kubernetes metadata missing with add\_kubernetes\_metadata enabled](https://discuss.elastic.co/t/kubernetes-metadata-missing-with-add-kubernetes-metadata-enabled/254314)

<div class="topic-metadata">

**Author:** [@xsb](https://discuss.elastic.co/u/xsb)\
**Replies:** 6\
**Last updated:** [November 6, 2020, 4:48pm UTC](https://discuss.elastic.co/t/kubernetes-metadata-missing-with-add-kubernetes-metadata-enabled/254314 "2020-11-06T16:48:12Z")

</div>

Hello, I am trying to enable add\_kubernetes\_metadata to an ECK setup with no luck. My ECK has a Beats resource that manages a filebeat DaemonSet, it's all pretty standard as I've been mostly copying the config from the…

---

## [Filebeat- syntax for regex file exclusion](https://discuss.elastic.co/t/filebeat-syntax-for-regex-file-exclusion/254452)

<div class="topic-metadata">

**Author:** [@txmrlevine](https://discuss.elastic.co/u/txmrlevine)\
**Replies:** 1\
**Last updated:** [November 6, 2020, 4:46pm UTC](https://discuss.elastic.co/t/filebeat-syntax-for-regex-file-exclusion/254452 "2020-11-06T16:46:27Z")

</div>

I am having issues figuring out the syntax for excluding a list of files in a directory. They all come or none come. Here is the file listing in the directory I am pushing. total 232676 drwxr-xr-x 6 deploy deploy …

---

## [Filebeat fields](https://discuss.elastic.co/t/filebeat-fields/254507)

<div class="topic-metadata">

**Author:** [@alfredo.deluca](https://discuss.elastic.co/u/alfredo.deluca)\
**Replies:** 1\
**Last updated:** [November 6, 2020, 2:30pm UTC](https://discuss.elastic.co/t/filebeat-fields/254507 "2020-11-06T14:30:07Z")

</div>

Hi all. I am testing filebeat on a minikube where I have a few pods and I send the logs to a local logstah and its job is to forward the logs to Elastic/kibana node on AWS. I can see some fields in the logs like host.i…

---

## [Filebeat puts all logs in only one index](https://discuss.elastic.co/t/filebeat-puts-all-logs-in-only-one-index/254386)

<div class="topic-metadata">

**Author:** [@yukpun](https://discuss.elastic.co/u/yukpun)\
**Replies:** 2\
**Last updated:** [November 6, 2020, 2:12pm UTC](https://discuss.elastic.co/t/filebeat-puts-all-logs-in-only-one-index/254386 "2020-11-06T14:12:51Z")

</div>

I have server with nginx running on. I'm trying to make filebeat installed on this server to send logs to elasticsearch directly. It sends logs, but however puts in "common" index filebeat-7.9.3-2020.11.04-000001 Here i…

---

## [Metricbeat MSSQL DB connection](https://discuss.elastic.co/t/metricbeat-mssql-db-connection/252519)

<div class="topic-metadata">

**Author:** [@kavi\_anand](https://discuss.elastic.co/u/kavi_anand)\
**Replies:** 2\
**Last updated:** [November 6, 2020, 12:25pm UTC](https://discuss.elastic.co/t/metricbeat-mssql-db-connection/252519 "2020-11-06T12:25:18Z")

</div>

I need to monitor particular a DB in MSSQL server, Is there any way to specify the DB name in MSSQL module itself

---

## [Build Custom RPM and DEB packages](https://discuss.elastic.co/t/build-custom-rpm-and-deb-packages/254275)

<div class="topic-metadata">

**Author:** [@Domenico](https://discuss.elastic.co/u/Domenico)\
**Replies:** 5\
**Last updated:** [November 6, 2020, 10:39am UTC](https://discuss.elastic.co/t/build-custom-rpm-and-deb-packages/254275 "2020-11-06T10:39:27Z")

</div>

Hi, we need to build rpm and deb packages with custom binary and service names. I have searched for a way to build from source code but most of the posts/topics are related to old versions and have broken link to github. …

---

## [Metricbeat setup overwrite Elastic Agent built in UI (Dashboard and Visualization)](https://discuss.elastic.co/t/metricbeat-setup-overwrite-elastic-agent-built-in-ui-dashboard-and-visualization/254235)

<div class="topic-metadata">

**Author:** [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Replies:** 5\
**Last updated:** [November 6, 2020, 8:11am UTC](https://discuss.elastic.co/t/metricbeat-setup-overwrite-elastic-agent-built-in-ui-dashboard-and-visualization/254235 "2020-11-06T08:11:09Z")

</div>

Hi all, I have an issue during elastic agent evaluation in Elastic Cloud 7.9.3 (Managed EC). I can successfully setup agent on several machines (Windows and Linux) with system and endpoint-security integrations. Data is…

---

## [Gsuite module in Filebeat not generating logs](https://discuss.elastic.co/t/gsuite-module-in-filebeat-not-generating-logs/254288)

<div class="topic-metadata">

**Author:** [@Edwin.v](https://discuss.elastic.co/u/Edwin.v)\
**Replies:** 13\
**Last updated:** [November 6, 2020, 7:55am UTC](https://discuss.elastic.co/t/gsuite-module-in-filebeat-not-generating-logs/254288 "2020-11-06T07:55:01Z")

</div>

Gsuite module in Filebeat not pushing the logs to Elasticsearch. I have configured the service account and domain wide delegation and setup the proper scope required. Still it throws back a error code 401 which says cann…

---

## [Why I am getting one huge metricbeat index instead of daily indices?](https://discuss.elastic.co/t/why-i-am-getting-one-huge-metricbeat-index-instead-of-daily-indices/252789)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 7\
**Last updated:** [November 6, 2020, 7:15am UTC](https://discuss.elastic.co/t/why-i-am-getting-one-huge-metricbeat-index-instead-of-daily-indices/252789 "2020-11-06T07:15:19Z")

</div>

Hi, I am using elastic stack 7.9.2. I have set up metricbeat and it is exporting to elasticsearch. I haven't modified the index name setting in metricbeat.yml and is taking the default setting index: "metricbeat-%{\[agen…

---

## [Index data conflict with another](https://discuss.elastic.co/t/index-data-conflict-with-another/254271)

<div class="topic-metadata">

**Author:** [@mustafa.husny](https://discuss.elastic.co/u/mustafa.husny)\
**Replies:** 12\
**Last updated:** [November 5, 2020, 11:55pm UTC](https://discuss.elastic.co/t/index-data-conflict-with-another/254271 "2020-11-05T23:55:18Z")

</div>

Hi All, I installed Heartbeat and changed the pipeline to be (Heartbeat ==\> Logstash ===\> Elasticsearch) and I loaded the heartbeat dashboards, Also I have its logs, and logs forwarded from (IBM Qradar), My issue is t…

---

## [Metricbeat elasticsearch-xpack errors](https://discuss.elastic.co/t/metricbeat-elasticsearch-xpack-errors/253758)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 3\
**Last updated:** [November 5, 2020, 9:42pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-xpack-errors/253758 "2020-11-05T21:42:01Z")

</div>

After 7.9.2 upgrade I've lost monitoring data on the "indexes" tab. I've found errors like this on metricbeat on the active master node: Error fetching data for metricset elasticsearch.index\_summary: HTTP error 400 in…

---

## [Filebeat for zip files](https://discuss.elastic.co/t/filebeat-for-zip-files/254385)

<div class="topic-metadata">

**Author:** [@kvtang](https://discuss.elastic.co/u/kvtang)\
**Replies:** 1\
**Last updated:** [November 5, 2020, 6:23pm UTC](https://discuss.elastic.co/t/filebeat-for-zip-files/254385 "2020-11-05T18:23:55Z")

</div>

Hi all, Is there any way to read a zipped file directly using filebeat? Thank you.

---

## [How can we see the full output /result of a query in Metrcibeat Sql module](https://discuss.elastic.co/t/how-can-we-see-the-full-output-result-of-a-query-in-metrcibeat-sql-module/254239)

<div class="topic-metadata">

**Author:** [@Sunil18](https://discuss.elastic.co/u/Sunil18)\
**Replies:** 1\
**Last updated:** [November 5, 2020, 5:44pm UTC](https://discuss.elastic.co/t/how-can-we-see-the-full-output-result-of-a-query-in-metrcibeat-sql-module/254239 "2020-11-05T17:44:26Z")

</div>

I have configured the sql module to get custom metrices using for custom queries from Oracle ,MySQL and PostgreSQL databases. When I check the output using " metrciebat test modules sql " it does not show me full outpu…

---

## [Using Filebeat or Logstash](https://discuss.elastic.co/t/using-filebeat-or-logstash/254332)

<div class="topic-metadata">

**Author:** [@Falikou1](https://discuss.elastic.co/u/Falikou1)\
**Replies:** 10\
**Last updated:** [November 5, 2020, 4:34pm UTC](https://discuss.elastic.co/t/using-filebeat-or-logstash/254332 "2020-11-05T16:34:20Z")

</div>

What is the benefit of using Filebeat alone? What is the advantage of using Logstash alone? What is the advantage of using Filebeat and Logstash?

---

## [Ingest Manager - Custom Files not being uploaded](https://discuss.elastic.co/t/ingest-manager-custom-files-not-being-uploaded/253397)

<div class="topic-metadata">

**Author:** [@\_Meir](https://discuss.elastic.co/u/_Meir)\
**Replies:** 8\
**Last updated:** [November 5, 2020, 3:31pm UTC](https://discuss.elastic.co/t/ingest-manager-custom-files-not-being-uploaded/253397 "2020-11-05T15:31:00Z")

</div>

I'm trying to get custom logs uploaded from my server to my elastic cloud . I'm using the Ingest Manager via fleet deployment. I've added Windows, System and Custom Logs integrations. I'm only seeing logs from MetricB…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=198)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=200)
