# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=200

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 201

---

## [Custom Unpack for configuration](https://discuss.elastic.co/t/custom-unpack-for-configuration/254306)

<div class="topic-metadata">

**Author:** [@tomkirk](https://discuss.elastic.co/u/tomkirk)\
**Replies:** 5\
**Last updated:** [November 5, 2020, 11:15am UTC](https://discuss.elastic.co/t/custom-unpack-for-configuration/254306 "2020-11-05T11:15:05Z")

</div>

I'm working on a beat where I have currently in my configuration an array of string like this: fields: - FieldName - AnotherFieldName What I would like is the ability to optionally provide a type tag, like so: fie…

---

## [Problem with sending logs from filebeat to logstash when I add kafka to pipeline](https://discuss.elastic.co/t/problem-with-sending-logs-from-filebeat-to-logstash-when-i-add-kafka-to-pipeline/254285)

<div class="topic-metadata">

**Author:** [@Pavle\_Ilic](https://discuss.elastic.co/u/Pavle_Ilic)\
**Replies:** 2\
**Last updated:** [November 5, 2020, 10:18am UTC](https://discuss.elastic.co/t/problem-with-sending-logs-from-filebeat-to-logstash-when-i-add-kafka-to-pipeline/254285 "2020-11-05T10:18:32Z")

</div>

I seem to be having a problem with sending logs from filebeat to logstash via kafka, and I can't find out why. I can send them directly from filebeat to logstash without a problem, but when I add kafka to the pipeline t…

---

## [Packetbeat capturing responsetime and sending it to Logstash](https://discuss.elastic.co/t/packetbeat-capturing-responsetime-and-sending-it-to-logstash/253155)

<div class="topic-metadata">

**Author:** [@21908](https://discuss.elastic.co/u/21908)\
**Replies:** 2\
**Last updated:** [November 4, 2020, 8:50pm UTC](https://discuss.elastic.co/t/packetbeat-capturing-responsetime-and-sending-it-to-logstash/253155 "2020-11-04T20:50:00Z")

</div>

My goal is to capture and store all queries run against Elasticsearch in Elasticsearch. I am mimicking the scenario discussed at monitoring-the-search-queries. I am using v7.9.2 of Elasticsearch, Logstash, Kibana and P…

---

## [Functionbeat.keystore: permission denied](https://discuss.elastic.co/t/functionbeat-keystore-permission-denied/254329)

<div class="topic-metadata">

**Author:** [@hyochang](https://discuss.elastic.co/u/hyochang)\
**Replies:** 0\
**Last updated:** [November 4, 2020, 8:31pm UTC](https://discuss.elastic.co/t/functionbeat-keystore-permission-denied/254329 "2020-11-04T20:31:44Z")

</div>

Hi, I am preparing a demo to send Cloudwatch log to the Elastic Cloud, and deployed cloudwatch\_log functionbeat lambda. It seems the lambda detecting cloudwatch log changes, but I am getting an error: Exiting: could no…

---

## [How to send application log to a Solace queue](https://discuss.elastic.co/t/how-to-send-application-log-to-a-solace-queue/254291)

<div class="topic-metadata">

**Author:** [@suhelrizvi](https://discuss.elastic.co/u/suhelrizvi)\
**Replies:** 4\
**Last updated:** [November 4, 2020, 4:18pm UTC](https://discuss.elastic.co/t/how-to-send-application-log-to-a-solace-queue/254291 "2020-11-04T16:18:45Z")

</div>

We need to send log file contents on a linux server to a remote queue in Solace. Can we use filebeat to do this and how?

---

## [How to drop events only from specific module](https://discuss.elastic.co/t/how-to-drop-events-only-from-specific-module/254175)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 8\
**Last updated:** [November 4, 2020, 4:04pm UTC](https://discuss.elastic.co/t/how-to-drop-events-only-from-specific-module/254175 "2020-11-04T16:04:41Z")

</div>

Hello, I want to drop all events that filebeat was unable to parse. I tried a few things my last attempt looks like this. processors: - drop\_event: when: and: - equals.event.module: cisco…

---

## [Metricbeat memory usage](https://discuss.elastic.co/t/metricbeat-memory-usage/254217)

<div class="topic-metadata">

**Author:** [@tarophin403](https://discuss.elastic.co/u/tarophin403)\
**Replies:** 1\
**Last updated:** [November 4, 2020, 3:43pm UTC](https://discuss.elastic.co/t/metricbeat-memory-usage/254217 "2020-11-04T15:43:04Z")

</div>

Is it normal for a metricbeat process thats runnning as a docker container to record "docker.memory.usage.pct" (one of the data fields collected by metricbeat) with values higher than 100%(1.00067, 1.00044...)? metricbe…

---

## [Unable to harvest log files with glob](https://discuss.elastic.co/t/unable-to-harvest-log-files-with-glob/253849)

<div class="topic-metadata">

**Author:** [@Arvind\_Ks](https://discuss.elastic.co/u/Arvind_Ks)\
**Replies:** 2\
**Last updated:** [November 4, 2020, 3:28pm UTC](https://discuss.elastic.co/t/unable-to-harvest-log-files-with-glob/253849 "2020-11-04T15:28:10Z")

</div>

Hi Team, I am trying to parse jenkins build logs using filebeat. There are several subdirectories that it needs to traverse to. I can also see in the filebeat log what all locations filebeat is checking. However when i …

---

## [Kubernetes autodiscovery for ephemeral containers](https://discuss.elastic.co/t/kubernetes-autodiscovery-for-ephemeral-containers/253840)

<div class="topic-metadata">

**Author:** [@marqc](https://discuss.elastic.co/u/marqc)\
**Replies:** 1\
**Last updated:** [November 4, 2020, 1:57pm UTC](https://discuss.elastic.co/t/kubernetes-autodiscovery-for-ephemeral-containers/253840 "2020-11-04T13:57:53Z")

</div>

Quick question for maintainers. How do you think filebeat should consider ephemeral containers. Should they be scrapped by default? Optionally when some additional autodiscovery flag is set? Or should they never be scrap…

---

## [Filebeat does not correctly merge multiline events](https://discuss.elastic.co/t/filebeat-does-not-correctly-merge-multiline-events/253907)

<div class="topic-metadata">

**Author:** [@Sebastian\_Kenter](https://discuss.elastic.co/u/Sebastian_Kenter)\
**Replies:** 3\
**Last updated:** [November 4, 2020, 11:09am UTC](https://discuss.elastic.co/t/filebeat-does-not-correctly-merge-multiline-events/253907 "2020-11-04T11:09:44Z")

</div>

I have the following problem: This is my logfile 11:30:00,909 9=DEB BswTcpTskComSrv::passTele() 11:30:00,909 12=EVT | TELEGRAMM SEND comsrv-\>TskEvm: |TskBrm|TskEvm|TeleDb| 11:30:00,909 12=EVT | BswTcpTskComSrv::send…

---

## [Filebeat kafka output with SCRAM authentication](https://discuss.elastic.co/t/filebeat-kafka-output-with-scram-authentication/254233)

<div class="topic-metadata">

**Author:** [@Darshan\_Parab](https://discuss.elastic.co/u/Darshan_Parab)\
**Replies:** 0\
**Last updated:** [November 4, 2020, 9:27am UTC](https://discuss.elastic.co/t/filebeat-kafka-output-with-scram-authentication/254233 "2020-11-04T09:27:46Z")

</div>

Hi People, I'm trying to configure a Kafka output for filebeat. The kafka broker is configure to listend on TLS and supports SCRAM authentication. I configured Kafka output successfully. However Published goes in retry …

---

## [Adding conditional tags or fields](https://discuss.elastic.co/t/adding-conditional-tags-or-fields/253890)

<div class="topic-metadata">

**Author:** [@zoulja](https://discuss.elastic.co/u/zoulja)\
**Replies:** 2\
**Last updated:** [November 4, 2020, 9:25am UTC](https://discuss.elastic.co/t/adding-conditional-tags-or-fields/253890 "2020-11-04T09:25:45Z")

</div>

Hello. I need Filebeat 7.9.2 to add tags based on content. What I've tried: - add\_tags: when: contains: request:"/image/" tags: \[image\] - add\_tags: when: cont…

---

## [FIlebeat dashboard creation](https://discuss.elastic.co/t/filebeat-dashboard-creation/254216)

<div class="topic-metadata">

**Author:** [@A\_Ravi\_Prashant](https://discuss.elastic.co/u/A_Ravi_Prashant)\
**Replies:** 3\
**Last updated:** [November 4, 2020, 7:24am UTC](https://discuss.elastic.co/t/filebeat-dashboard-creation/254216 "2020-11-04T07:24:11Z")

</div>

Hi team I have 12 EC2 instances my requirement is to create dashboard for all the server I have configure Elk stack with docker compose in one ec2 instance To create dashboard we use command filebeat setup so my ques…

---

## [Elastic Agent init script calls unavailable test command](https://discuss.elastic.co/t/elastic-agent-init-script-calls-unavailable-test-command/253811)

<div class="topic-metadata">

**Author:** [@SergeyD](https://discuss.elastic.co/u/SergeyD)\
**Replies:** 3\
**Last updated:** [November 4, 2020, 6:34am UTC](https://discuss.elastic.co/t/elastic-agent-init-script-calls-unavailable-test-command/253811 "2020-11-04T06:34:52Z")

</div>

Elastic Agent service is unable to start via init script due to call of unavailable "test" command. Environment: Ubuntu 14.04 + Agent 7.9.3 Steps to reproduce: curl -L -O https://artifacts.elastic.co/downloads/beats/…

---

## [Elastic Agent - OSS version](https://discuss.elastic.co/t/elastic-agent-oss-version/254182)

<div class="topic-metadata">

**Author:** [@micas](https://discuss.elastic.co/u/micas)\
**Replies:** 0\
**Last updated:** [November 3, 2020, 5:32pm UTC](https://discuss.elastic.co/t/elastic-agent-oss-version/254182 "2020-11-03T17:32:48Z")

</div>

Are there any plans to make an OSS version of the new "Elastic Agent"? ( https://www.elastic.co/downloads/elastic-agent ) or is it something that will never happen? We are creating a product that heavily relies on Beats…

---

## [Filebeat cannot connect to Logstash \[Logstash/Filebeat 7.9.x\]](https://discuss.elastic.co/t/filebeat-cannot-connect-to-logstash-logstash-filebeat-7-9-x/254189)

<div class="topic-metadata">

**Author:** [@fraballi](https://discuss.elastic.co/u/fraballi)\
**Replies:** 0\
**Last updated:** [November 3, 2020, 10:36pm UTC](https://discuss.elastic.co/t/filebeat-cannot-connect-to-logstash-logstash-filebeat-7-9-x/254189 "2020-11-03T22:36:02Z")

</div>

Dear colleagues, Version: 7.9.x I have two instances of Filebeat (docker, rpm in localhost), none can connect to Logstash (docker). I searched on similar topics and tried solutions, but still cannot reach safe port. T…

---

## [Process.name incomplete](https://discuss.elastic.co/t/process-name-incomplete/250804)

<div class="topic-metadata">

**Author:** [@wifi](https://discuss.elastic.co/u/wifi)\
**Replies:** 5\
**Last updated:** [November 3, 2020, 8:13pm UTC](https://discuss.elastic.co/t/process-name-incomplete/250804 "2020-11-03T20:13:06Z")

</div>

Somehow the process name gets cut off and i end up with process.name like "ansible-playboo" instead of "ansible-playbook" It seems tat the name is cut off after the 15th character I checked the mapping for process.name…

---

## [Auditbeat 7.8 file integrity module](https://discuss.elastic.co/t/auditbeat-7-8-file-integrity-module/253823)

<div class="topic-metadata">

**Author:** [@Mohammad\_Etemad](https://discuss.elastic.co/u/Mohammad_Etemad)\
**Replies:** 3\
**Last updated:** [November 3, 2020, 5:15pm UTC](https://discuss.elastic.co/t/auditbeat-7-8-file-integrity-module/253823 "2020-11-03T17:15:17Z")

</div>

Hello, I am using auditbeat to track file changes via the file integrity module. This works for a couple of minutes and logs the changes to files, but then stops working and no changes are detected anymore. Is this a kn…

---

## [Filebeat Sementation Fault on Centos8](https://discuss.elastic.co/t/filebeat-sementation-fault-on-centos8/254162)

<div class="topic-metadata">

**Author:** [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Replies:** 1\
**Last updated:** [November 3, 2020, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-sementation-fault-on-centos8/254162 "2020-11-03T14:04:58Z")

</div>

Hello there, I get a segmentation fault when trying to start Filebeat. Tried v6.8.13 and 7.9.3 What I do : Download Filebeat : https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.9.3-linux-x86\_64.tar.g…

---

## [ES ingest node per input](https://discuss.elastic.co/t/es-ingest-node-per-input/253816)

<div class="topic-metadata">

**Author:** [@ccmsi](https://discuss.elastic.co/u/ccmsi)\
**Replies:** 1\
**Last updated:** [November 3, 2020, 1:13pm UTC](https://discuss.elastic.co/t/es-ingest-node-per-input/253816 "2020-11-03T13:13:42Z")

</div>

Greetings. Filebeat modules come with matching ES ingest node configuration. Filebeat routes module specific input through that matching ingest node on ES. I would like to do the same for normal inputs, defining with t…

---

## [Setup Filebeat with UDP input .. several questions](https://discuss.elastic.co/t/setup-filebeat-with-udp-input-several-questions/252522)

<div class="topic-metadata">

**Author:** [@dewell](https://discuss.elastic.co/u/dewell)\
**Replies:** 6\
**Last updated:** [November 3, 2020, 11:27am UTC](https://discuss.elastic.co/t/setup-filebeat-with-udp-input-several-questions/252522 "2020-11-03T11:27:58Z")

</div>

Hi, I'm trying to grab a udp stream of double values (8 bytes) via udp input plugin of filebeat. The connection is between two servers in the same subnet, there shouldn't be any issue. I changed the filebeat.yml like t…

---

## [Creating dashboards for custom pattern from filebeat not working?](https://discuss.elastic.co/t/creating-dashboards-for-custom-pattern-from-filebeat-not-working/253615)

<div class="topic-metadata">

**Author:** [@Karel\_Cech](https://discuss.elastic.co/u/Karel_Cech)\
**Replies:** 5\
**Last updated:** [November 3, 2020, 10:07am UTC](https://discuss.elastic.co/t/creating-dashboards-for-custom-pattern-from-filebeat-not-working/253615 "2020-11-03T10:07:29Z")

</div>

Hi, I am unable to use a not-default index naming for filebeat. According to the documentation, I have these settings in my filebeat.yml: setup.template.name: "customname" setup.template.pattern: "customname-\*" setup.d…

---

## [Filebeat not sending logs to elastic from fortinet module](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elastic-from-fortinet-module/254000)

<div class="topic-metadata">

**Author:** [@mn0o7](https://discuss.elastic.co/u/mn0o7)\
**Replies:** 1\
**Last updated:** [November 3, 2020, 8:15am UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elastic-from-fortinet-module/254000 "2020-11-03T08:15:35Z")

</div>

Hi Everyone, I have enabled the fortinet/firewall module all looks great i see traffic being received at in the filebeat logs but never forwarded to elastic, can someone please point me in the right direction ? filebea…

---

## [Beats\_system role](https://discuss.elastic.co/t/beats-system-role/253391)

<div class="topic-metadata">

**Author:** [@gquintana](https://discuss.elastic.co/u/gquintana)\
**Replies:** 6\
**Last updated:** [November 3, 2020, 5:07am UTC](https://discuss.elastic.co/t/beats-system-role/253391 "2020-11-03T05:07:18Z")

</div>

I've set up an Elastic Stack 7.9.2 and enabled basic security. Metricbeat can not use to Elasticsearch user beats\_system because of a lack of permissions. The documentation Built-in users | Elasticsearch Guide \[8.11\] |…

---

## [\[Metricbeat\] Kafka Module SASL\_SSL](https://discuss.elastic.co/t/metricbeat-kafka-module-sasl-ssl/254085)

<div class="topic-metadata">

**Author:** [@tomerse](https://discuss.elastic.co/u/tomerse)\
**Replies:** 0\
**Last updated:** [November 3, 2020, 12:19am UTC](https://discuss.elastic.co/t/metricbeat-kafka-module-sasl-ssl/254085 "2020-11-03T00:19:28Z")

</div>

Hi, It seems like I'm the only one who uses SASL\_SSL with open-source Kafka in the market as i couldn't find anything related to my issue except from some unclear threads over the internet, I'm trying to get Metricbeat…

---

## [Beat can't to create daily index although ilm.enabled=false](https://discuss.elastic.co/t/beat-cant-to-create-daily-index-although-ilm-enabled-false/253887)

<div class="topic-metadata">

**Author:** [@shinydeng](https://discuss.elastic.co/u/shinydeng)\
**Replies:** 1\
**Last updated:** [November 2, 2020, 11:36pm UTC](https://discuss.elastic.co/t/beat-cant-to-create-daily-index-although-ilm-enabled-false/253887 "2020-11-02T23:36:32Z")

</div>

HI , i'm new fro ELK , tried to intergret my mulesoft application to ELK. i found beat can't to create daily index although ilm.enabled=false. it always to create filebeat-version-timestamp indices in ELK . Here is my…

---

## [PacketBeat](https://discuss.elastic.co/t/packetbeat/253678)

<div class="topic-metadata">

**Author:** [@nirav.gshah](https://discuss.elastic.co/u/nirav.gshah)\
**Replies:** 2\
**Last updated:** [November 2, 2020, 11:20pm UTC](https://discuss.elastic.co/t/packetbeat/253678 "2020-11-02T23:20:14Z")

</div>

Hi Team, I am trying to use processors to limit data but drop fields and events not working together. processors: drop events: regexp: system.process.name: "svchost\*" drop\_fields: fields: \["\_id", "\_index", "\_s…

---

## [Filebeat zscaler module](https://discuss.elastic.co/t/filebeat-zscaler-module/254049)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 0\
**Last updated:** [November 2, 2020, 3:57pm UTC](https://discuss.elastic.co/t/filebeat-zscaler-module/254049 "2020-11-02T15:57:36Z")

</div>

Has anyone got this to work ? I am not getting any data from my zscaler module , everything is default I have it enabled in the module.d Folder First tried the default route with the syslog then tried to change the mod…

---

## [Metricbeat not getting diskio](https://discuss.elastic.co/t/metricbeat-not-getting-diskio/251606)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 12\
**Last updated:** [November 2, 2020, 6:24pm UTC](https://discuss.elastic.co/t/metricbeat-not-getting-diskio/251606 "2020-11-02T18:24:20Z")

</div>

where can I see diskio for process and network traffic use by process? I did load default template, running 7.9.1 here is config file - module: system period: 1m metricsets: - cpu - load - memory -…

---

## [\`Provided Grok expressions do not match field value\` Apache Filebeat](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-apache-filebeat/254027)

<div class="topic-metadata">

**Author:** [@willis](https://discuss.elastic.co/u/willis)\
**Replies:** 0\
**Last updated:** [November 2, 2020, 1:42pm UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-apache-filebeat/254027 "2020-11-02T13:42:51Z")

</div>

Filebeat: 7.9.2 We are using a custom log format for Apache. The filebeat apache module (i.e. /usr/share/filebeat/module/apache/access/ingest/pipeline.yml) is updated with a single Grok expression that matches our custo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=199)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=201)
