# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=201

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 202

---

## [Parse Apache Error Logs](https://discuss.elastic.co/t/parse-apache-error-logs/253158)

<div class="topic-metadata">

**Author:** [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Replies:** 7\
**Last updated:** [November 2, 2020, 1:36pm UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158 "2020-11-02T13:36:28Z")

</div>

Is there something I'm missing? Currently using Filebeat to send Apache 2.4 logs to Elasticsearch. Access logs get parsed fine (well, mostly, have lots of grok errors) but error\_log always shows grok error and inputs log…

---

## [Unable to push data into multiple indices](https://discuss.elastic.co/t/unable-to-push-data-into-multiple-indices/253685)

<div class="topic-metadata">

**Author:** [@bhaskar\_todi](https://discuss.elastic.co/u/bhaskar_todi)\
**Replies:** 4\
**Last updated:** [November 2, 2020, 6:46am UTC](https://discuss.elastic.co/t/unable-to-push-data-into-multiple-indices/253685 "2020-11-02T06:46:50Z")

</div>

I am trying to push different streams of windows events into different elastic indices based on the event.provider But unfortunately, all my data is pushed into the default index. I am not sure if the filtering is not …

---

## [Installed filebeat on next server, but I can't see any data in Kibana](https://discuss.elastic.co/t/installed-filebeat-on-next-server-but-i-cant-see-any-data-in-kibana/253880)

<div class="topic-metadata">

**Author:** [@oicfar](https://discuss.elastic.co/u/oicfar)\
**Replies:** 1\
**Last updated:** [October 31, 2020, 4:15pm UTC](https://discuss.elastic.co/t/installed-filebeat-on-next-server-but-i-cant-see-any-data-in-kibana/253880 "2020-10-31T16:15:29Z")

</div>

Hi, weeks ago I installed ElasticSearch, Logstash, Kibana and Filebeat on same server. It wors fine. Filebeat I'm using for syslog, nginx and postgresql monitoring. Today installed Filebeat on other server. I don't se…

---

## [Export Sample Dashboard -\> Import it new cluster -\> change index?](https://discuss.elastic.co/t/export-sample-dashboard-import-it-new-cluster-change-index/253824)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 4\
**Last updated:** [October 31, 2020, 8:07am UTC](https://discuss.elastic.co/t/export-sample-dashboard-import-it-new-cluster-change-index/253824 "2020-10-31T08:07:53Z")

</div>

Dear Elastic & Community, I did this: exported the sample dashboards of a beat (auditbeat) from one cluster, imported them (ndson file) in an second cluster. In this second cluster I would like to change in Kibana the i…

---

## [Can't get enrich processor to work with beats](https://discuss.elastic.co/t/cant-get-enrich-processor-to-work-with-beats/253889)

<div class="topic-metadata">

**Author:** [@Hutuleac\_Iulius](https://discuss.elastic.co/u/Hutuleac_Iulius)\
**Replies:** 0\
**Last updated:** [October 31, 2020, 7:07am UTC](https://discuss.elastic.co/t/cant-get-enrich-processor-to-work-with-beats/253889 "2020-10-31T07:07:48Z")

</div>

Version: 7.9.2 ECK 1.5.0 Steps to Reproduce: configure filebeat with enrichment pipeline and start ingestion Hi, I am trying to add an automatic enrichment to a filebeat getting PaloAlto firewall logs but enrichment …

---

## [Non-zero metrics in the last 30s - Filebeat](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s-filebeat/253884)

<div class="topic-metadata">

**Author:** [@shinydeng](https://discuss.elastic.co/u/shinydeng)\
**Replies:** 0\
**Last updated:** [October 31, 2020, 2:33am UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s-filebeat/253884 "2020-10-31T02:33:12Z")

</div>

I'm new to ELK and need to do log forwarding for my mulesoft application logs. my filebeat.yml is below ''' Here is the Filebeat log. It seems there are no errors but I am seeing any metrics on KIBANA. then i tri…

---

## [Failed to publish events caused by: read tcp filebeat:33330-\>logstash:5044: read: connection reset by peer](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-read-tcp-filebeat-33330-logstash-read-connection-reset-by-peer/252615)

<div class="topic-metadata">

**Author:** [@ShadwDrgn](https://discuss.elastic.co/u/ShadwDrgn)\
**Replies:** 4\
**Last updated:** [October 31, 2020, 1:28am UTC](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-read-tcp-filebeat-33330-logstash-read-connection-reset-by-peer/252615 "2020-10-31T01:28:05Z")

</div>

my filebeat constantly (1-3 times a second) can't seem to connect to logstash and do it's thing. I'm on the docker images for 7.9.2 Steps i've already taken: confirmed host is resolving. confirmed I can ping logstash …

---

## [Filebeat cisco module missing logs](https://discuss.elastic.co/t/filebeat-cisco-module-missing-logs/253873)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 0\
**Last updated:** [October 30, 2020, 10:45pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-missing-logs/253873 "2020-10-30T22:45:43Z")

</div>

Hello, I noticed that logs for one of my asa divices are not visible inside elastic around period of time when load on the device is rising above some level. Logs are harvested from file. Harverst log level is set to 5. …

---

## [Different index for new filebeat module "bind9"](https://discuss.elastic.co/t/different-index-for-new-filebeat-module-bind9/253250)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 6\
**Last updated:** [October 30, 2020, 8:05pm UTC](https://discuss.elastic.co/t/different-index-for-new-filebeat-module-bind9/253250 "2020-10-30T20:05:16Z")

</div>

Dear All, My environment: ELK stack 7.9.2 on Debian buster I wrote a new module called "bind9" which picks up the bind query logs from a DNS server. This is writing its data to the filebeat index. I would like to have …

---

## [Winlogbeat missing winlog.event\_data.IpAddress](https://discuss.elastic.co/t/winlogbeat-missing-winlog-event-data-ipaddress/253745)

<div class="topic-metadata">

**Author:** [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Replies:** 1\
**Last updated:** [October 30, 2020, 6:41pm UTC](https://discuss.elastic.co/t/winlogbeat-missing-winlog-event-data-ipaddress/253745 "2020-10-30T18:41:23Z")

</div>

Hi, I have a windows machine with Active Directory and winlogbeat (7.3) and in the generated info i have a field winlog.event\_data.IpAddress but on a differente scenario with winlogbeat (7.4.2) that field is not present…

---

## [Filebeat Auto discover config check failed for config - stopped harvesting data](https://discuss.elastic.co/t/filebeat-auto-discover-config-check-failed-for-config-stopped-harvesting-data/253675)

<div class="topic-metadata">

**Author:** [@dorinand](https://discuss.elastic.co/u/dorinand)\
**Replies:** 3\
**Last updated:** [October 30, 2020, 2:51pm UTC](https://discuss.elastic.co/t/filebeat-auto-discover-config-check-failed-for-config-stopped-harvesting-data/253675 "2020-10-30T14:51:19Z")

</div>

I harvest logs from gitlab runners created in kubernetes namespace. I implement the opciton to store elastic index in pod annotation. So all my gitlab runners has elastic.index: runner-jobs annotation. This is my autods…

---

## [Docker Filebeat 7.9.3 cannot collect metrics from http from outside the container](https://discuss.elastic.co/t/docker-filebeat-7-9-3-cannot-collect-metrics-from-http-from-outside-the-container/253792)

<div class="topic-metadata">

**Author:** [@Tisi](https://discuss.elastic.co/u/Tisi)\
**Replies:** 9\
**Last updated:** [October 30, 2020, 2:37pm UTC](https://discuss.elastic.co/t/docker-filebeat-7-9-3-cannot-collect-metrics-from-http-from-outside-the-container/253792 "2020-10-30T14:37:55Z")

</div>

Hello Elastic Staff I am not able to collect metrics from filebeat from the defined http port. I can get the metrics from within the filebeat container with curl -XGET localhost:5066/stats. When I want to collect the…

---

## [Filebeat.yml - Environnement variable on UBUNTU](https://discuss.elastic.co/t/filebeat-yml-environnement-variable-on-ubuntu/253733)

<div class="topic-metadata">

**Author:** [@ASRLO](https://discuss.elastic.co/u/ASRLO)\
**Replies:** 3\
**Last updated:** [October 30, 2020, 2:13pm UTC](https://discuss.elastic.co/t/filebeat-yml-environnement-variable-on-ubuntu/253733 "2020-10-30T14:13:16Z")

</div>

Hello everybody , I want to use an environment variable on my path but it doesn't work. When I run the filebeat service it works but fails when sending logs to logstash I have set my environment variable in /etc/bash.b…

---

## [AWS Elasticsearch service and filebeat](https://discuss.elastic.co/t/aws-elasticsearch-service-and-filebeat/253700)

<div class="topic-metadata">

**Author:** [@alfredo.deluca](https://discuss.elastic.co/u/alfredo.deluca)\
**Replies:** 2\
**Last updated:** [October 30, 2020, 2:00pm UTC](https://discuss.elastic.co/t/aws-elasticsearch-service-and-filebeat/253700 "2020-10-30T14:00:38Z")

</div>

Hi all. For testing purposes, I ve installed AWS Elasticsearch service in my account and I have access to kibana. I tried also to send some data with CURL and it's all ok. Now I was trying to setup filebeat on my lapto…

---

## [Metricbeat: \[logstash.node\] node/node.go:79 could not fetch node pipelines: HTTP error 405 in : 405 Method Not Allowed](https://discuss.elastic.co/t/metricbeat-logstash-node-node-node-go-79-could-not-fetch-node-pipelines-http-error-405-in-405-method-not-allowed/253786)

<div class="topic-metadata">

**Author:** [@Yuy\_Heero](https://discuss.elastic.co/u/Yuy_Heero)\
**Replies:** 2\
**Last updated:** [October 30, 2020, 12:52pm UTC](https://discuss.elastic.co/t/metricbeat-logstash-node-node-node-go-79-could-not-fetch-node-pipelines-http-error-405-in-405-method-not-allowed/253786 "2020-10-30T12:52:10Z")

</div>

I created one-node elasticsearch(7.9.3) and one-node logstash(7.9.3). Logstash can transfer logs via https without problem. I want to use metricbeat to monitor logstash. After I installed metricbeat in logstash node. M…

---

## [Metricbeat: Sql Module: Oracle Driver: Sql Query Error :ERROR error opening connection: opening connection: sql: unknown driver "oracle" (forgotten import?)](https://discuss.elastic.co/t/metricbeat-sql-module-oracle-driver-sql-query-error-error-error-opening-connection-opening-connection-sql-unknown-driver-oracle-forgotten-import/253387)

<div class="topic-metadata">

**Author:** [@Sunil18](https://discuss.elastic.co/u/Sunil18)\
**Replies:** 4\
**Last updated:** [October 30, 2020, 11:13am UTC](https://discuss.elastic.co/t/metricbeat-sql-module-oracle-driver-sql-query-error-error-error-opening-connection-opening-connection-sql-unknown-driver-oracle-forgotten-import/253387 "2020-10-30T11:13:06Z")

</div>

I have configured Metricbeat Oracle Module(For Default Metrices/Dashboard ) & I am using Sql Module for customized queries to fetch the data from Oracle DB. Oracle Module is working perfectly but for Sql module I am g…

---

## [\[QUESTION/HELP\] Metricbeat kubernetes state\_node labels](https://discuss.elastic.co/t/question-help-metricbeat-kubernetes-state-node-labels/253784)

<div class="topic-metadata">

**Author:** [@rayanebel](https://discuss.elastic.co/u/rayanebel)\
**Replies:** 1\
**Last updated:** [October 30, 2020, 10:05am UTC](https://discuss.elastic.co/t/question-help-metricbeat-kubernetes-state-node-labels/253784 "2020-10-30T10:05:55Z")

</div>

Hello, I'm using metricbeat (7.x) and the kubernetes module to fetch kubernetes metrics from api-server and kube-state-metrics. I have a question about the metricset state\_node. This metricset will fetch the metrics rel…

---

## [Metricbeat oracle module](https://discuss.elastic.co/t/metricbeat-oracle-module/253563)

<div class="topic-metadata">

**Author:** [@dmeijboom](https://discuss.elastic.co/u/dmeijboom)\
**Replies:** 3\
**Last updated:** [October 30, 2020, 10:01am UTC](https://discuss.elastic.co/t/metricbeat-oracle-module/253563 "2020-10-30T10:01:35Z")

</div>

We are trying to connect the oracle module in metricbeat if we use hosts: \["oraclemonitor/apassword@//host:1521/TESTDV"\] it works but then we see the password in plain text in the kibana message And if we use this(in…

---

## [Metricbeat getting error on illegal\_argument\_exception: index.lifecycle.rollover\_alias](https://discuss.elastic.co/t/metricbeat-getting-error-on-illegal-argument-exception-index-lifecycle-rollover-alias/253206)

<div class="topic-metadata">

**Author:** [@Beng\_Hui\_Ong](https://discuss.elastic.co/u/Beng_Hui_Ong)\
**Replies:** 5\
**Last updated:** [October 30, 2020, 9:16am UTC](https://discuss.elastic.co/t/metricbeat-getting-error-on-illegal-argument-exception-index-lifecycle-rollover-alias/253206 "2020-10-30T09:16:27Z")

</div>

Hi folks, I keep getting this error on my metricbeat setup, and despite me shutting down and recreate all the index and policies, it will still pop up. illegal\_argument\_exception: index.lifecycle.rollover\_alias \[metricb…

---

## [User.id Not Populated by Powershell Module](https://discuss.elastic.co/t/user-id-not-populated-by-powershell-module/253478)

<div class="topic-metadata">

**Author:** [@variable](https://discuss.elastic.co/u/variable)\
**Replies:** 5\
**Last updated:** [October 30, 2020, 8:33am UTC](https://discuss.elastic.co/t/user-id-not-populated-by-powershell-module/253478 "2020-10-30T08:33:12Z")

</div>

It doesn't appear that the powershell module for Winlogbeat 7.9.2 is recording the user.id or the user.name. Is this intended or a bug? One example: { "\_index": "winlogbeat-7.9.2-2020.10.14-000001", "\_type": "\_d…

---

## [How would you index this type of data?](https://discuss.elastic.co/t/how-would-you-index-this-type-of-data/253754)

<div class="topic-metadata">

**Author:** [@Toontje](https://discuss.elastic.co/u/Toontje)\
**Replies:** 2\
**Last updated:** [October 30, 2020, 8:10am UTC](https://discuss.elastic.co/t/how-would-you-index-this-type-of-data/253754 "2020-10-30T08:10:41Z")

</div>

{"windowNumber": 1830323, "timestamp": "2020-09-24T01:26:31.673097Z", "tagData": {"103040840050DDABCD10028300003B93": {"inIntensity": "2542", "inCount": 2}, "103040840004FCA60A64028108F4C764": {"outIntensity": "760", "o…

---

## [How to monitor windows's GPU Utilization?](https://discuss.elastic.co/t/how-to-monitor-windowss-gpu-utilization/253766)

<div class="topic-metadata">

**Author:** [@Weicloud9527](https://discuss.elastic.co/u/Weicloud9527)\
**Replies:** 1\
**Last updated:** [October 30, 2020, 8:10am UTC](https://discuss.elastic.co/t/how-to-monitor-windowss-gpu-utilization/253766 "2020-10-30T08:10:04Z")

</div>

hi I have server run for machine learning OS:windows 10 gpu:NVIDIA RTX8000 how do I monitor GPU Utilization can any beats support ?

---

## [Filebeat Cisco module can't parse 305011, 302015, 302013, or 722015 message types](https://discuss.elastic.co/t/filebeat-cisco-module-cant-parse-305011-302015-302013-or-722015-message-types/250882)

<div class="topic-metadata">

**Author:** [@rthielen](https://discuss.elastic.co/u/rthielen)\
**Replies:** 11\
**Last updated:** [October 30, 2020, 5:13am UTC](https://discuss.elastic.co/t/filebeat-cisco-module-cant-parse-305011-302015-302013-or-722015-message-types/250882 "2020-10-30T05:13:31Z")

</div>

Version 7.9.2 Debian 10 Problematic file: /usr/share/filebeat/module/cisco/shared/ingest/asa-ftd-pipeline.yml 305011 parse pattern doesn't account for presence of source.user.name pattern: "Built %{} %{network.transp…

---

## [Metricsets being created two times at the start of the beat](https://discuss.elastic.co/t/metricsets-being-created-two-times-at-the-start-of-the-beat/253621)

<div class="topic-metadata">

**Author:** [@Thiago\_Ruiz](https://discuss.elastic.co/u/Thiago_Ruiz)\
**Replies:** 2\
**Last updated:** [October 29, 2020, 6:43pm UTC](https://discuss.elastic.co/t/metricsets-being-created-two-times-at-the-start-of-the-beat/253621 "2020-10-29T18:43:40Z")

</div>

Hello there! I'm creating some new modules and metricsets and saw something odd, maybe a bug, or at least a possibility of an improvement :slight\_smile: The possible problem: When we use the config "reload.enabled: fal…

---

## [Proxyconnect tcp: tls: first record does not look like a TLS handshake metricbeat monitoring elasticsearch](https://discuss.elastic.co/t/proxyconnect-tcp-tls-first-record-does-not-look-like-a-tls-handshake-metricbeat-monitoring-elasticsearch/253567)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 3\
**Last updated:** [October 29, 2020, 5:54pm UTC](https://discuss.elastic.co/t/proxyconnect-tcp-tls-first-record-does-not-look-like-a-tls-handshake-metricbeat-monitoring-elasticsearch/253567 "2020-10-29T17:54:34Z")

</div>

Hello, I wanted to set up beats monitoring for my enviroment. But it does not work and I see this error in the logs. 2020-10-28T14:25:23.636+0100 INFO \[monitoring\] elasticsearch/elasticsearch.go:245 Failed to connect t…

---

## [Issue with Weird spaces with Filebeat in windows Log](https://discuss.elastic.co/t/issue-with-weird-spaces-with-filebeat-in-windows-log/253415)

<div class="topic-metadata">

**Author:** [@enrique.villar](https://discuss.elastic.co/u/enrique.villar)\
**Replies:** 5\
**Last updated:** [October 29, 2020, 2:36pm UTC](https://discuss.elastic.co/t/issue-with-weird-spaces-with-filebeat-in-windows-log/253415 "2020-10-29T14:36:31Z")

</div>

Good day. I try to index some windows (MSSQL) logs. This logs are in plain text. Some logs are multiline So, in Filebeat is configure: - type: log enabled: true paths: - D:\\logs\\\*.log #example path multi…

---

## [Remote WinlogBeat](https://discuss.elastic.co/t/remote-winlogbeat/253668)

<div class="topic-metadata">

**Author:** [@Eon](https://discuss.elastic.co/u/Eon)\
**Replies:** 2\
**Last updated:** [October 29, 2020, 2:11pm UTC](https://discuss.elastic.co/t/remote-winlogbeat/253668 "2020-10-29T14:11:16Z")

</div>

Hi All, I would like to know, would it be possible to setup a winlogbeat to collect WEF events on a remote WEF server? I know you can install the winlogbeat on a WEF server and grab the forwarded events, but we have a r…

---

## [Filebeat autodiscover doesn't pick-up inputs](https://discuss.elastic.co/t/filebeat-autodiscover-doesnt-pick-up-inputs/253341)

<div class="topic-metadata">

**Author:** [@CatalinM](https://discuss.elastic.co/u/CatalinM)\
**Replies:** 7\
**Last updated:** [October 29, 2020, 1:58pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-doesnt-pick-up-inputs/253341 "2020-10-29T13:58:10Z")

</div>

Hi there! I've deployed Filebeat in the "observability" namespace (with all roles, bindings being set to observability - not sure if this is ok). It starts without issues, but it doesn't discover any inputs. This is my…

---

## [Data loss in Filebeat to Kafka pipeline](https://discuss.elastic.co/t/data-loss-in-filebeat-to-kafka-pipeline/253704)

<div class="topic-metadata">

**Author:** [@Hreidar\_Joelsson](https://discuss.elastic.co/u/Hreidar_Joelsson)\
**Replies:** 0\
**Last updated:** [October 29, 2020, 1:51pm UTC](https://discuss.elastic.co/t/data-loss-in-filebeat-to-kafka-pipeline/253704 "2020-10-29T13:51:00Z")

</div>

Hi, I've been running a data pipeline for a few weeks now which uses Filebeat (V7.9.2) as a log harvester and publishes the data into Kafka. This new pipeline is a replacement for an older one based on Filebeat and Logst…

---

## [I want to pseudonymize a specific field with a beat](https://discuss.elastic.co/t/i-want-to-pseudonymize-a-specific-field-with-a-beat/253671)

<div class="topic-metadata">

**Author:** [@elk51211](https://discuss.elastic.co/u/elk51211)\
**Replies:** 2\
**Last updated:** [October 29, 2020, 12:02pm UTC](https://discuss.elastic.co/t/i-want-to-pseudonymize-a-specific-field-with-a-beat/253671 "2020-10-29T12:02:39Z")

</div>

What is the recommended approach to deal with logs to be as GDPR compliant as possible? I need to pseudonymize user data. The only resource I found is dated back to march of 2018 in this blog post: https://www.elastic.c…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=200)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=202)
