# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=202

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 203

---

## [Find and replace string in message field](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/253574)

<div class="topic-metadata">

**Author:** [@randoran](https://discuss.elastic.co/u/randoran)\
**Replies:** 1\
**Last updated:** [October 29, 2020, 11:33am UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/253574 "2020-10-29T11:33:04Z")

</div>

Is there a way using filebeat to find and replace a string in the \[message\] field of a log entry before sending to Elasticsearch? (similar to mutate and gsub in logstash)

---

## [Filebeat on Centos 8 doesn't seem to properly parse /var/log/secure](https://discuss.elastic.co/t/filebeat-on-centos-8-doesnt-seem-to-properly-parse-var-log-secure/253590)

<div class="topic-metadata">

**Author:** [@AndersBolager](https://discuss.elastic.co/u/AndersBolager)\
**Replies:** 1\
**Last updated:** [October 29, 2020, 11:28am UTC](https://discuss.elastic.co/t/filebeat-on-centos-8-doesnt-seem-to-properly-parse-var-log-secure/253590 "2020-10-29T11:28:42Z")

</div>

Hi. I have a fresh install of the Elastic Stack 7.9.3, including FileBeat with the system module enabled. I have created the following three test log lines: Oct 28 16:46:54 ELASTIC01 sshd\[17840\]: Invalid user test from…

---

## [Metricbeat without any outputs configured - not allowed?](https://discuss.elastic.co/t/metricbeat-without-any-outputs-configured-not-allowed/253562)

<div class="topic-metadata">

**Author:** [@KlavsKlavsen1](https://discuss.elastic.co/u/KlavsKlavsen1)\
**Replies:** 1\
**Last updated:** [October 29, 2020, 10:57am UTC](https://discuss.elastic.co/t/metricbeat-without-any-outputs-configured-not-allowed/253562 "2020-10-29T10:57:19Z")

</div>

I'm trying to use metricbeat with beat-exporter (exposing metrics from metricbeat to prometheus) - and as such, I just want http.enabled set - and don't want any output. If I don't configure any output - metricbeat won'…

---

## [Filebeat multiple input and multiple output indices](https://discuss.elastic.co/t/filebeat-multiple-input-and-multiple-output-indices/253624)

<div class="topic-metadata">

**Author:** [@Jigar\_Patel1](https://discuss.elastic.co/u/Jigar_Patel1)\
**Replies:** 2\
**Last updated:** [October 28, 2020, 11:31pm UTC](https://discuss.elastic.co/t/filebeat-multiple-input-and-multiple-output-indices/253624 "2020-10-28T23:31:47Z")

</div>

I am getting error with filebeat.yml what am I missing? filebeat test config Exiting: error initializing publisher: missing condition cat filebeat.yml filebeat.inputs: - type: log paths: - /var/log/cloud-init.…

---

## [Metricbeat timeout reading index\_recovery, index\_summary, etc](https://discuss.elastic.co/t/metricbeat-timeout-reading-index-recovery-index-summary-etc/253592)

<div class="topic-metadata">

**Author:** [@zvazquez](https://discuss.elastic.co/u/zvazquez)\
**Replies:** 0\
**Last updated:** [October 28, 2020, 4:35pm UTC](https://discuss.elastic.co/t/metricbeat-timeout-reading-index-recovery-index-summary-etc/253592 "2020-10-28T16:35:13Z")

</div>

Hi, I am experiencing a problem where one of the elasticsearch clusters that I am monitoring within a Kubernetes cluster is having troubles being monitored with metricbeats. The metricbeat agent is having problem with …

---

## [Winlogbeat unable to connect to elasticsearch](https://discuss.elastic.co/t/winlogbeat-unable-to-connect-to-elasticsearch/253612)

<div class="topic-metadata">

**Author:** [@antmar904](https://discuss.elastic.co/u/antmar904)\
**Replies:** 0\
**Last updated:** [October 28, 2020, 7:15pm UTC](https://discuss.elastic.co/t/winlogbeat-unable-to-connect-to-elasticsearch/253612 "2020-10-28T19:15:09Z")

</div>

Hi. I downloaded and installed SOF-ELK, imported it into VMware, powered it up then installed the winlogbeat on my Windows 10 laptop. I changed the following in the winlogbeat.yml file: Under the "Kibana" section I ed…

---

## [Filebeat Azure Activity Logs Ingest Pipeline; Error parsing fields with $-characters](https://discuss.elastic.co/t/filebeat-azure-activity-logs-ingest-pipeline-error-parsing-fields-with-characters/253571)

<div class="topic-metadata">

**Author:** [@C0FFEEC0FFEE](https://discuss.elastic.co/u/C0FFEEC0FFEE)\
**Replies:** 0\
**Last updated:** [October 28, 2020, 1:58pm UTC](https://discuss.elastic.co/t/filebeat-azure-activity-logs-ingest-pipeline-error-parsing-fields-with-characters/253571 "2020-10-28T13:58:08Z")

</div>

I'm trying to enhance the filebeat-7.9.3-azure-activitylogs-pipeline to parse the information about vulnerability scans (Azure Security Center / Qualys) into ECS. I'm stuck with the problem that some of the fields have …

---

## [Custom Index for Functionbeat](https://discuss.elastic.co/t/custom-index-for-functionbeat/248664)

<div class="topic-metadata">

**Author:** [@sainath](https://discuss.elastic.co/u/sainath)\
**Replies:** 4\
**Last updated:** [October 28, 2020, 1:12pm UTC](https://discuss.elastic.co/t/custom-index-for-functionbeat/248664 "2020-10-28T13:12:24Z")

</div>

Hi Team, I am trying to deploy function beat to read AWS logs which i am succesfully able to do. However, i require different index to be created in Elasticsearch for different log groups.Below id the elasticsearch outp…

---

## [Filebeat custom modules on macOS](https://discuss.elastic.co/t/filebeat-custom-modules-on-macos/251783)

<div class="topic-metadata">

**Author:** [@gerard1](https://discuss.elastic.co/u/gerard1)\
**Replies:** 1\
**Last updated:** [October 28, 2020, 10:06am UTC](https://discuss.elastic.co/t/filebeat-custom-modules-on-macos/251783 "2020-10-28T10:06:21Z")

</div>

I'm wondering where should custom modules be stored in macOS, after installing Filebeat with brew. In Linux, the default path is "/usr/share/filebeat/module/", but I can't find it in macOS.

---

## [Filebeat not starting properly after host start](https://discuss.elastic.co/t/filebeat-not-starting-properly-after-host-start/253410)

<div class="topic-metadata">

**Author:** [@adsr](https://discuss.elastic.co/u/adsr)\
**Replies:** 4\
**Last updated:** [October 28, 2020, 7:58am UTC](https://discuss.elastic.co/t/filebeat-not-starting-properly-after-host-start/253410 "2020-10-28T07:58:08Z")

</div>

Hi everyone, I am running filebeat 7.5.0 on centos with systemd and everything works fine except when I restart the host (the filebeat service is enabled). According to systemd the service is running fine, yet it does n…

---

## [Unable to start Filebeat 7.9.2 , Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/unable-to-start-filebeat-7-9-2-failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/252928)

<div class="topic-metadata">

**Author:** [@a\_ssuresh](https://discuss.elastic.co/u/a_ssuresh)\
**Replies:** 10\
**Last updated:** [October 28, 2020, 6:58am UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-7-9-2-failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/252928 "2020-10-28T06:58:59Z")

</div>

Hi , I just installed ELK on a server, filebeat agent (ver 7.9.2) on another, OS- CentOS 7 Started elastic, logstash & kibana on a server, but unable to start filebeat agent from another server, where im trying to s…

---

## [Filebeat Cisco Module to Logstash not working as expected](https://discuss.elastic.co/t/filebeat-cisco-module-to-logstash-not-working-as-expected/249885)

<div class="topic-metadata">

**Author:** [@asaravanan](https://discuss.elastic.co/u/asaravanan)\
**Replies:** 4\
**Last updated:** [October 27, 2020, 10:35pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-to-logstash-not-working-as-expected/249885 "2020-10-27T22:35:15Z")

</div>

I have configured Filebeat with Cisco Module enabled as per https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-installation-configuration.html & https://www.elastic.co/guide/en/logstash/7.9/use-ingest-pipelines.…

---

## [Filebeat module with logstash not parsing with IDFW enabled](https://discuss.elastic.co/t/filebeat-module-with-logstash-not-parsing-with-idfw-enabled/249896)

<div class="topic-metadata">

**Author:** [@asaravanan](https://discuss.elastic.co/u/asaravanan)\
**Replies:** 4\
**Last updated:** [October 27, 2020, 10:34pm UTC](https://discuss.elastic.co/t/filebeat-module-with-logstash-not-parsing-with-idfw-enabled/249896 "2020-10-27T22:34:56Z")

</div>

I am not getting any "Built" message ID "302013" with Identity Firewall enabled on Cisco ASA. I think pipeline configuration doesnt have this field to parse it and sending it to Elastic. Error Message \[2020-09-25T02:07…

---

## [List server hostname and disk usage](https://discuss.elastic.co/t/list-server-hostname-and-disk-usage/253451)

<div class="topic-metadata">

**Author:** [@plegault](https://discuss.elastic.co/u/plegault)\
**Replies:** 2\
**Last updated:** [October 27, 2020, 6:19pm UTC](https://discuss.elastic.co/t/list-server-hostname-and-disk-usage/253451 "2020-10-27T18:19:47Z")

</div>

There is a Host overview page for each host that I have the system monitor enabled on. On each Host overview page there are all the system graphs etc. I want to be able to take the host name and Disk Usage graph and crea…

---

## [How add field using apache module in filebeat](https://discuss.elastic.co/t/how-add-field-using-apache-module-in-filebeat/253477)

<div class="topic-metadata">

**Author:** [@randoran](https://discuss.elastic.co/u/randoran)\
**Replies:** 1\
**Last updated:** [October 27, 2020, 7:35pm UTC](https://discuss.elastic.co/t/how-add-field-using-apache-module-in-filebeat/253477 "2020-10-27T19:35:42Z")

</div>

I am using the apache module in filebeat to send logs to elasticsearch. How can I add a field to what gets sent? When I was using type: log I did something like this to get a field added but not sure how to do it when us…

---

## [Is winlogbeat able to ingore events before specific time?](https://discuss.elastic.co/t/is-winlogbeat-able-to-ingore-events-before-specific-time/253486)

<div class="topic-metadata">

**Author:** [@Louis\_Zhang](https://discuss.elastic.co/u/Louis_Zhang)\
**Replies:** 0\
**Last updated:** [October 27, 2020, 7:19pm UTC](https://discuss.elastic.co/t/is-winlogbeat-able-to-ingore-events-before-specific-time/253486 "2020-10-27T19:19:16Z")

</div>

I found winlogbeat is able to configured to ignore events older since now. winlogbeat.event\_logs: - name: Application ignore\_older: 72h - name: Security - name: System Woundering if it's possible to configure…

---

## [Non-zero metrics in the last 30s- Filebeat](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s-filebeat/253482)

<div class="topic-metadata">

**Author:** [@Mauricio\_Alejandro\_V](https://discuss.elastic.co/u/Mauricio_Alejandro_V)\
**Replies:** 1\
**Last updated:** [October 27, 2020, 6:53pm UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s-filebeat/253482 "2020-10-27T18:53:19Z")

</div>

hello, I am trying to pass some logs to logstash using filebeat, however the filebeat logs continiously show this message: Help Loaded: loaded (/usr/lib/systemd/system/filebeat.service; enabled; vendor preset: disable…

---

## [Filebeat adds drive letter to path](https://discuss.elastic.co/t/filebeat-adds-drive-letter-to-path/253470)

<div class="topic-metadata">

**Author:** [@jimmyvalmer19](https://discuss.elastic.co/u/jimmyvalmer19)\
**Replies:** 0\
**Last updated:** [October 27, 2020, 4:23pm UTC](https://discuss.elastic.co/t/filebeat-adds-drive-letter-to-path/253470 "2020-10-27T16:23:26Z")

</div>

Hi, since I always get help here, i try next one. This may be something very obvious, but i spent already few hours on this. It's about filebeat (7.3.0) running on Windows server I'm using shared drive in my Filebeat …

---

## [Issue Creating a Custom Metricset](https://discuss.elastic.co/t/issue-creating-a-custom-metricset/253358)

<div class="topic-metadata">

**Author:** [@traw1234](https://discuss.elastic.co/u/traw1234)\
**Replies:** 3\
**Last updated:** [October 27, 2020, 3:29pm UTC](https://discuss.elastic.co/t/issue-creating-a-custom-metricset/253358 "2020-10-27T15:29:28Z")

</div>

I am working to create a custom metricset for Metricbeat but am having difficulty with the documentation. I am following the guide here, have installed go, mage, ran go get for the beats repo, am writing the module withi…

---

## [\[FIlebeat\] How to get logs default paths for modules?](https://discuss.elastic.co/t/filebeat-how-to-get-logs-default-paths-for-modules/252648)

<div class="topic-metadata">

**Author:** [@Travis](https://discuss.elastic.co/u/Travis)\
**Replies:** 3\
**Last updated:** [October 27, 2020, 1:53pm UTC](https://discuss.elastic.co/t/filebeat-how-to-get-logs-default-paths-for-modules/252648 "2020-10-27T13:53:34Z")

</div>

Hello ! I'm using Filebeat (7.8) and module system. For the var.paths of the syslog fileset, documentation says : "If this setting is left empty, Filebeat will choose log paths based on your operating system." How can…

---

## [Metricbeat --setup dashboards throws error for keystore not created](https://discuss.elastic.co/t/metricbeat-setup-dashboards-throws-error-for-keystore-not-created/253403)

<div class="topic-metadata">

**Author:** [@karthikeyanajendran1](https://discuss.elastic.co/u/karthikeyanajendran1)\
**Replies:** 7\
**Last updated:** [October 27, 2020, 11:05am UTC](https://discuss.elastic.co/t/metricbeat-setup-dashboards-throws-error-for-keystore-not-created/253403 "2020-10-27T11:05:27Z")

</div>

Hi Experts, We are developing automation script to setup metricbeat before start the metricbeat. Our automation script does the following: Download and untar the metricbeat package (7.6.1) from elastic site. Enable s…

---

## [Cant filter out events?](https://discuss.elastic.co/t/cant-filter-out-events/253174)

<div class="topic-metadata">

**Author:** [@jcor](https://discuss.elastic.co/u/jcor)\
**Replies:** 14\
**Last updated:** [October 27, 2020, 10:03am UTC](https://discuss.elastic.co/t/cant-filter-out-events/253174 "2020-10-27T10:03:07Z")

</div>

Hi all, We're trying to configure winlog beats to drop info level logs but seem to be missing something. Ive found a post that is trying to do the same thing as we are but their config isnt working. So I'm guessing my l…

---

## [Does the Metricbeat oracle module works for oracle 11.2 standard edition](https://discuss.elastic.co/t/does-the-metricbeat-oracle-module-works-for-oracle-11-2-standard-edition/251985)

<div class="topic-metadata">

**Author:** [@Sunil18](https://discuss.elastic.co/u/Sunil18)\
**Replies:** 2\
**Last updated:** [October 27, 2020, 5:39am UTC](https://discuss.elastic.co/t/does-the-metricbeat-oracle-module-works-for-oracle-11-2-standard-edition/251985 "2020-10-27T05:39:43Z")

</div>

Does the Metricbeat module works for oracle 11.2 standard version ?

---

## [Filebeat too many open files error](https://discuss.elastic.co/t/filebeat-too-many-open-files-error/253289)

<div class="topic-metadata">

**Author:** [@gizem](https://discuss.elastic.co/u/gizem)\
**Replies:** 0\
**Last updated:** [October 26, 2020, 10:43am UTC](https://discuss.elastic.co/t/filebeat-too-many-open-files-error/253289 "2020-10-26T10:43:22Z")

</div>

Hi, I get the error when I start the filebeat 2 \> 020-10-26T13:26:14.132+0300 ERROR \[registrar\] registrar/registrar.go:205 Error writing registrar state to statestore: failed in store/get operation on store 'filebeat'…

---

## [Filebeat starting error](https://discuss.elastic.co/t/filebeat-starting-error/253208)

<div class="topic-metadata">

**Author:** [@gizem](https://discuss.elastic.co/u/gizem)\
**Replies:** 1\
**Last updated:** [October 26, 2020, 9:33am UTC](https://discuss.elastic.co/t/filebeat-starting-error/253208 "2020-10-26T09:33:24Z")

</div>

Hi, I get the error when I start the filebeat. How can I solve this? ERROR instance/beat.go:951 Exiting: Failed to start crawler: starting input failed: Error while initializing input: Can only start an input when all…

---

## [Filebeat Multiline Messages Ingest Pipeline](https://discuss.elastic.co/t/filebeat-multiline-messages-ingest-pipeline/253235)

<div class="topic-metadata">

**Author:** [@Paul\_B](https://discuss.elastic.co/u/Paul_B)\
**Replies:** 0\
**Last updated:** [October 25, 2020, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-multiline-messages-ingest-pipeline/253235 "2020-10-25T12:56:38Z")

</div>

I need some help getting a multiline message from Filebeat Autodiscover ingested into ElasticSearch via an Ingest Pipeline. The messages are not correctly rendering in Kibana Discover, example: The raw message (taken…

---

## [Index creating problem](https://discuss.elastic.co/t/index-creating-problem/253205)

<div class="topic-metadata">

**Author:** [@gizem](https://discuss.elastic.co/u/gizem)\
**Replies:** 2\
**Last updated:** [October 24, 2020, 3:57pm UTC](https://discuss.elastic.co/t/index-creating-problem/253205 "2020-10-24T15:57:44Z")

</div>

Hello, I create index with the filebeat (v 7.9.2) configuration below: setup.ilm.enabled: auto setup.ilm.rollover\_alias: "filebeat-%{\[agent.version\]}" setup.ilm.pattern: "{now/w{yyyy.ww}}-000001" Firstly index cre…

---

## [Heartbeat kibana http check not working](https://discuss.elastic.co/t/heartbeat-kibana-http-check-not-working/253136)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 2\
**Last updated:** [October 23, 2020, 3:31pm UTC](https://discuss.elastic.co/t/heartbeat-kibana-http-check-not-working/253136 "2020-10-23T15:31:21Z")

</div>

I have setup heartbeat to monitor kibana instance running in the same namespace (kubernetes) with following config - type: http enabled: true name: "kibana" tags: \["kibana"\] fields: e…

---

## [File intergrity Do Not Show Who Changed File Share](https://discuss.elastic.co/t/file-intergrity-do-not-show-who-changed-file-share/252577)

<div class="topic-metadata">

**Author:** [@chumphieubac](https://discuss.elastic.co/u/chumphieubac)\
**Replies:** 2\
**Last updated:** [October 23, 2020, 3:16pm UTC](https://discuss.elastic.co/t/file-intergrity-do-not-show-who-changed-file-share/252577 "2020-10-23T15:16:48Z")

</div>

Hi There, I installed Auditbeat to monitor who is changed or deleted file share, It works well if I login window and change or delete the files and shows who delete these files. but the Aauditbeat message doesn't show w…

---

## [Filebeat.yml config setup for individual log and processing of different docker containers](https://discuss.elastic.co/t/filebeat-yml-config-setup-for-individual-log-and-processing-of-different-docker-containers/252876)

<div class="topic-metadata">

**Author:** [@sschoepff](https://discuss.elastic.co/u/sschoepff)\
**Replies:** 2\
**Last updated:** [October 23, 2020, 2:02pm UTC](https://discuss.elastic.co/t/filebeat-yml-config-setup-for-individual-log-and-processing-of-different-docker-containers/252876 "2020-10-23T14:02:46Z")

</div>

hello, im having problems with setting up a working filebeat log shipper for docker instances with different input config files for different containers. my goal is to collect an process docker logs individually from di…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=201)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=203)
