# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=204

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 205

---

## [Apache logs missing SSL Protocol v2](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol-v2/252400)

<div class="topic-metadata">

**Author:** [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Replies:** 5\
**Last updated:** [October 21, 2020, 1:26pm UTC](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol-v2/252400 "2020-10-21T13:26:44Z")

</div>

OP: Despite SSL Protocol and request time showing in my log format directive in Apache 2.4 I am not seeing either of them in ES/Kibana. How is this fixed? I am using filebeat and shipping logs directly to ES. Upgraded …

---

## [Filebeat not able to send data to TLS enabled Kafka cluster](https://discuss.elastic.co/t/filebeat-not-able-to-send-data-to-tls-enabled-kafka-cluster/251701)

<div class="topic-metadata">

**Author:** [@Amritanshu\_Pandey](https://discuss.elastic.co/u/Amritanshu_Pandey)\
**Replies:** 1\
**Last updated:** [October 21, 2020, 1:24pm UTC](https://discuss.elastic.co/t/filebeat-not-able-to-send-data-to-tls-enabled-kafka-cluster/251701 "2020-10-21T13:24:08Z")

</div>

Hi Team, We are trying to send some logs from a Windows host using filebeat to a Kafka cluster that uses TLS for encryption and Kerberos for Authentication. Filebeat version: 7.9.2 On the Filebeats logs I get this mes…

---

## [Metricbeat for application connected to NAS drive](https://discuss.elastic.co/t/metricbeat-for-application-connected-to-nas-drive/252020)

<div class="topic-metadata">

**Author:** [@nagabhushan.tr](https://discuss.elastic.co/u/nagabhushan.tr)\
**Replies:** 1\
**Last updated:** [October 21, 2020, 1:18pm UTC](https://discuss.elastic.co/t/metricbeat-for-application-connected-to-nas-drive/252020 "2020-10-21T13:18:36Z")

</div>

We have an application which connects to NetApp NAS drive, the application/users dont have permissions to setup beats on NAS drive. Is there a way we can monitor metrics like disk IO, disk Space just because of the fact…

---

## [How to reduce primary storage size](https://discuss.elastic.co/t/how-to-reduce-primary-storage-size/252518)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 7\
**Last updated:** [October 21, 2020, 12:50pm UTC](https://discuss.elastic.co/t/how-to-reduce-primary-storage-size/252518 "2020-10-21T12:50:56Z")

</div>

hi all, generally, when I use Logstash I like to remove the message field if the filter section doesn't contain any error. I do it to reduce the size of every document. since this time I will not use Logstash, is there…

---

## [Filebeat fills up the disk very quickly and write log repeatedly](https://discuss.elastic.co/t/filebeat-fills-up-the-disk-very-quickly-and-write-log-repeatedly/252404)

<div class="topic-metadata">

**Author:** [@linxianwu](https://discuss.elastic.co/u/linxianwu)\
**Replies:** 4\
**Last updated:** [October 21, 2020, 12:44pm UTC](https://discuss.elastic.co/t/filebeat-fills-up-the-disk-very-quickly-and-write-log-repeatedly/252404 "2020-10-21T12:44:06Z")

</div>

In our environment, filebeat has a lot of this error (file name is replaced): DEBUG \[input\] log/input.go:261 State for file not removed because harvester not finished: /var/log/xxx.log DEBUG \[input\] log/input.go:251 Rem…

---

## [\[Filebeat\] K8s OOM kill causes file corruption](https://discuss.elastic.co/t/filebeat-k8s-oom-kill-causes-file-corruption/252734)

<div class="topic-metadata">

**Author:** [@boernd](https://discuss.elastic.co/u/boernd)\
**Replies:** 1\
**Last updated:** [October 21, 2020, 3:06am UTC](https://discuss.elastic.co/t/filebeat-k8s-oom-kill-causes-file-corruption/252734 "2020-10-21T03:06:49Z")

</div>

Hi, I have the following issue and think it's a bug but wanted to post here before filing a Github issue: A filebeat container gets killed/restarted because of memory limits within K8s. After the container restart the …

---

## [MS SQL monitoring with Filebeat?](https://discuss.elastic.co/t/ms-sql-monitoring-with-filebeat/252392)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 10\
**Last updated:** [October 20, 2020, 8:10pm UTC](https://discuss.elastic.co/t/ms-sql-monitoring-with-filebeat/252392 "2020-10-20T20:10:21Z")

</div>

Hi, Note: - Using ELK 7.9.2 in Debian 10 - MS SQL Server 2016 SP2 Standard in Windows Server 2012 I want to start monitoring my MS SQL Server with Elasticsearch and visualize the data in Kibana. After some research I…

---

## [Shards issue when trying to add a filter](https://discuss.elastic.co/t/shards-issue-when-trying-to-add-a-filter/252585)

<div class="topic-metadata">

**Author:** [@leostereo](https://discuss.elastic.co/u/leostereo)\
**Replies:** 2\
**Last updated:** [October 20, 2020, 5:24pm UTC](https://discuss.elastic.co/t/shards-issue-when-trying-to-add-a-filter/252585 "2020-10-20T17:24:55Z")

</div>

Hi guys. My elk platform was working very nice. I was running filebeat with netflow module. I also created default dashboard for kibana. Everything was ok , until tryed to add a filter. After adding a filter on the…

---

## [Filebeat invalid template id](https://discuss.elastic.co/t/filebeat-invalid-template-id/252534)

<div class="topic-metadata">

**Author:** [@111401](https://discuss.elastic.co/u/111401)\
**Replies:** 2\
**Last updated:** [October 20, 2020, 3:11pm UTC](https://discuss.elastic.co/t/filebeat-invalid-template-id/252534 "2020-10-20T15:11:29Z")

</div>

Hi, I have some issue in filebeat. I had sent nProbe netflow v9 to filebeat but when I start filebeat it comes the problem below. elklab@localhost filebeat\]$ sudo filebeat -e \[sudo\] password for elklab: 2020-10-19T17…

---

## [Logfile from restarted docker container is not scanned and written to registry](https://discuss.elastic.co/t/logfile-from-restarted-docker-container-is-not-scanned-and-written-to-registry/248177)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 1\
**Last updated:** [October 20, 2020, 3:05pm UTC](https://discuss.elastic.co/t/logfile-from-restarted-docker-container-is-not-scanned-and-written-to-registry/248177 "2020-10-20T15:05:15Z")

</div>

Hello Team Problem We have an issue, where logfile from a restarted docker container is not scanned, registered and processed by a filebeat. We were using docker input module without problems, until we have spotted a …

---

## [Filebeat Autodiscover appenders - configuration not applied](https://discuss.elastic.co/t/filebeat-autodiscover-appenders-configuration-not-applied/252588)

<div class="topic-metadata">

**Author:** [@solarwinds](https://discuss.elastic.co/u/solarwinds)\
**Replies:** 4\
**Last updated:** [October 20, 2020, 10:53am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-appenders-configuration-not-applied/252588 "2020-10-20T10:53:33Z")

</div>

Hi everyone, before opening an issue on Github, I will try here. As subject states, Filebeat Autodiscover appenders are not working as expected - configuration is not being applied. If I configure add\_docker\_metadata as …

---

## [Metricbeat - filesystem metrics does not include remote network drives](https://discuss.elastic.co/t/metricbeat-filesystem-metrics-does-not-include-remote-network-drives/252346)

<div class="topic-metadata">

**Author:** [@qwinkler](https://discuss.elastic.co/u/qwinkler)\
**Replies:** 4\
**Last updated:** [October 20, 2020, 6:01am UTC](https://discuss.elastic.co/t/metricbeat-filesystem-metrics-does-not-include-remote-network-drives/252346 "2020-10-20T06:01:09Z")

</div>

Hello! I attached a few S3 buckets via TntDrive (https://tntdrive.com/) as a network device. They have a "remote" type in the old metricbeat: { "\_index": "metricbeat-6.3.0-2020.10", "\_type": "\_doc", "\_id": "k-8OM…

---

## [Ingesting Crowdstrike events](https://discuss.elastic.co/t/ingesting-crowdstrike-events/252583)

<div class="topic-metadata">

**Author:** [@darkbeatz](https://discuss.elastic.co/u/darkbeatz)\
**Replies:** 0\
**Last updated:** [October 19, 2020, 4:48pm UTC](https://discuss.elastic.co/t/ingesting-crowdstrike-events/252583 "2020-10-19T16:48:43Z")

</div>

Hi All, If I want to bring in events from crowdstrike falcon to elastic siem, is there guidance you can give me to help me plan for storage requirements on elastic? Thanks

---

## [\[IPV6 Only\]: FileBeat Integration to Push Logs on KAFKA Topic](https://discuss.elastic.co/t/ipv6-only-filebeat-integration-to-push-logs-on-kafka-topic/252504)

<div class="topic-metadata">

**Author:** [@PatelRudra](https://discuss.elastic.co/u/PatelRudra)\
**Replies:** 1\
**Last updated:** [October 19, 2020, 2:29pm UTC](https://discuss.elastic.co/t/ipv6-only-filebeat-integration-to-push-logs-on-kafka-topic/252504 "2020-10-19T14:29:32Z")

</div>

Hello Community, Hope you are doing good in this pandemic. I want to integrate FileBeat with Kafka, only on IPV6 K8S Cluster. But I am getting the error " Failed to connect to broker http://\[240b:x:x:x:x:x:x:5001\]:323…

---

## [Linux Disk IOPS](https://discuss.elastic.co/t/linux-disk-iops/252529)

<div class="topic-metadata">

**Author:** [@fabiansc](https://discuss.elastic.co/u/fabiansc)\
**Replies:** 1\
**Last updated:** [October 19, 2020, 2:09pm UTC](https://discuss.elastic.co/t/linux-disk-iops/252529 "2020-10-19T14:09:51Z")

</div>

Hello! I am looking for gathering IOPS information for Azure VMs using Elastics Metricsbeats. We are currently running on metricbeat 7.7 per user (optional: per process). Is there any possibility to gather this kind of…

---

## [Filebeat processor help](https://discuss.elastic.co/t/filebeat-processor-help/252516)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 1\
**Last updated:** [October 19, 2020, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-processor-help/252516 "2020-10-19T14:04:01Z")

</div>

Hey i need some help with filebeat processors. I want to decode\_json\_fields if the kubernetes.container.name is equal to 1 or more values. processors: - add\_cloud\_metadata: - add\_host\_metadata: - de…

---

## [Filebeat scan frequency](https://discuss.elastic.co/t/filebeat-scan-frequency/251138)

<div class="topic-metadata">

**Author:** [@gizem](https://discuss.elastic.co/u/gizem)\
**Replies:** 3\
**Last updated:** [October 19, 2020, 12:11pm UTC](https://discuss.elastic.co/t/filebeat-scan-frequency/251138 "2020-10-19T12:11:09Z")

</div>

Hi, In filebeat configuration file, there is scan\_frequency option. But I am confused about is scan frequency define the scanning new files in the path or scanning updates(new lines) in a file. If the scan frequency ch…

---

## [Illegal\_argument\_exception at index filebeat-7.4.0](https://discuss.elastic.co/t/illegal-argument-exception-at-index-filebeat-7-4-0/252513)

<div class="topic-metadata">

**Author:** [@deniss.stepanov](https://discuss.elastic.co/u/deniss.stepanov)\
**Replies:** 1\
**Last updated:** [October 19, 2020, 9:10am UTC](https://discuss.elastic.co/t/illegal-argument-exception-at-index-filebeat-7-4-0/252513 "2020-10-19T09:10:42Z")

</div>

Hello everyone, After the last update to version 7.9.1 my ELK cluster and beats version in Kibana under Visuals tab, I start to receive such notifications. Easy google is nothing gave to me, so I am here. And this is a…

---

## [Elastic-agent and winlogbeat](https://discuss.elastic.co/t/elastic-agent-and-winlogbeat/252446)

<div class="topic-metadata">

**Author:** [@fdaa](https://discuss.elastic.co/u/fdaa)\
**Replies:** 1\
**Last updated:** [October 19, 2020, 8:34am UTC](https://discuss.elastic.co/t/elastic-agent-and-winlogbeat/252446 "2020-10-19T08:34:30Z")

</div>

Will elastic-agent include winlogbeat when it's released for production?

---

## [Problem processing multiline json](https://discuss.elastic.co/t/problem-processing-multiline-json/250446)

<div class="topic-metadata">

**Author:** [@niv](https://discuss.elastic.co/u/niv)\
**Replies:** 3\
**Last updated:** [October 18, 2020, 10:34am UTC](https://discuss.elastic.co/t/problem-processing-multiline-json/250446 "2020-10-18T10:34:22Z")

</div>

MY INPUT FILE : \[ { "value": "drrrrrrrrrrrrropfields\_NTNT10", "Id": "drrrrrrrrrropfields\_10", "PSShowComputerName": "dropfields\_10" }, { "value": "dropfields\_nT8", "P…

---

## [Monitoring of remote server's CPU utilization](https://discuss.elastic.co/t/monitoring-of-remote-servers-cpu-utilization/252360)

<div class="topic-metadata">

**Author:** [@Martin\_qa](https://discuss.elastic.co/u/Martin_qa)\
**Replies:** 2\
**Last updated:** [October 18, 2020, 8:28am UTC](https://discuss.elastic.co/t/monitoring-of-remote-servers-cpu-utilization/252360 "2020-10-18T08:28:52Z")

</div>

Hi guys, I am looking for the best solution for measure CPU utilization on the remote server where is running performance testing. Please can you give me some hint on which plugins or beats do I need to use, I am at th…

---

## [Filebeat netflow cant parse netstream from huawei](https://discuss.elastic.co/t/filebeat-netflow-cant-parse-netstream-from-huawei/251534)

<div class="topic-metadata">

**Author:** [@ar4](https://discuss.elastic.co/u/ar4)\
**Replies:** 5\
**Last updated:** [October 17, 2020, 11:47pm UTC](https://discuss.elastic.co/t/filebeat-netflow-cant-parse-netstream-from-huawei/251534 "2020-10-17T23:47:03Z")

</div>

Hi, We using filebeat for collect netflow from Mikrotik. Also its work perfect. Now we need to collect netstream from Huawei AR2240 and it's don't work, flows no seen in kibana. Then i run filebeat at debug mode i see…

---

## [Drop all system event](https://discuss.elastic.co/t/drop-all-system-event/252366)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 6\
**Last updated:** [October 16, 2020, 7:53pm UTC](https://discuss.elastic.co/t/drop-all-system-event/252366 "2020-10-16T19:53:21Z")

</div>

I just want to monitor user processed using metricbeat currently it is giving me all the system process as well like kworker, systemd etc... how do I drop them? I think drop\_event in system.yml file needs to be set. bu…

---

## [GeoIP mapping returns wrong results](https://discuss.elastic.co/t/geoip-mapping-returns-wrong-results/251871)

<div class="topic-metadata">

**Author:** [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Replies:** 3\
**Last updated:** [October 16, 2020, 6:54pm UTC](https://discuss.elastic.co/t/geoip-mapping-returns-wrong-results/251871 "2020-10-16T18:54:49Z")

</div>

I use the geoip processor to enhance packetbeat documents. The ingest pipeline looks like this: { "geoip-info" : { "description" : "Add geoip info", "processors" : \[ { "geoip" : { "fiel…

---

## [How make filebeat harvest not end of file](https://discuss.elastic.co/t/how-make-filebeat-harvest-not-end-of-file/252369)

<div class="topic-metadata">

**Author:** [@Nicolas\_Perez1](https://discuss.elastic.co/u/Nicolas_Perez1)\
**Replies:** 2\
**Last updated:** [October 16, 2020, 6:33pm UTC](https://discuss.elastic.co/t/how-make-filebeat-harvest-not-end-of-file/252369 "2020-10-16T18:33:58Z")

</div>

hi, i have a application what write in the last line information incomplete and i need how make filebeat read one line before the end of file. this is a problem the application re write the last line

---

## [Append logs using filebeat](https://discuss.elastic.co/t/append-logs-using-filebeat/252322)

<div class="topic-metadata">

**Author:** [@Abhishek\_Sharma](https://discuss.elastic.co/u/Abhishek_Sharma)\
**Replies:** 1\
**Last updated:** [October 16, 2020, 5:55pm UTC](https://discuss.elastic.co/t/append-logs-using-filebeat/252322 "2020-10-16T17:55:39Z")

</div>

My logs produce some content that I can see only when appended using (-A 20) or (- A 200). For Ex: While seeing a log from a docker container, I do : docker logs \[container\_id\] | grep "something" -A 20 Now i have imple…

---

## [Repeatedly dashboard importing is needed for same beats in multiple machines?](https://discuss.elastic.co/t/repeatedly-dashboard-importing-is-needed-for-same-beats-in-multiple-machines/251434)

<div class="topic-metadata">

**Author:** [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Replies:** 3\
**Last updated:** [October 16, 2020, 5:25pm UTC](https://discuss.elastic.co/t/repeatedly-dashboard-importing-is-needed-for-same-beats-in-multiple-machines/251434 "2020-10-16T17:25:55Z")

</div>

Hi All , Dashboard importing is needed for same beat agents in multiple machines ? For Example I am planning to install metricbeat in 10 Linux machines . Is there dashboard importing is needed in all 10 Linux machin…

---

## [Filebeat for Openshift and Kubernetes audit logs](https://discuss.elastic.co/t/filebeat-for-openshift-and-kubernetes-audit-logs/249287)

<div class="topic-metadata">

**Author:** [@sayeedc](https://discuss.elastic.co/u/sayeedc)\
**Replies:** 3\
**Last updated:** [October 16, 2020, 2:58pm UTC](https://discuss.elastic.co/t/filebeat-for-openshift-and-kubernetes-audit-logs/249287 "2020-10-16T14:58:21Z")

</div>

Hi, What’s the best way to collect Openshift and Kubernetes audit logs with Filebeats? Auditbeat doesn’t seem to have any options to inspect Kube or OCP audit log files. Thanks, Sayeed

---

## [Heartbeat activemq monitor without error in activemq.log](https://discuss.elastic.co/t/heartbeat-activemq-monitor-without-error-in-activemq-log/249351)

<div class="topic-metadata">

**Author:** [@rino](https://discuss.elastic.co/u/rino)\
**Replies:** 4\
**Last updated:** [October 16, 2020, 1:03pm UTC](https://discuss.elastic.co/t/heartbeat-activemq-monitor-without-error-in-activemq-log/249351 "2020-10-16T13:03:08Z")

</div>

Hi, We're monitoring the uptime of our activemq servers (specificly the openwire port our queue is using). The problem is, with the below tcp monitor, it leaves behind some ugly logging in the activemq log. i wonder if …

---

## [Filebeat 6.5.4 is truncating some records - multibyte character issue?](https://discuss.elastic.co/t/filebeat-6-5-4-is-truncating-some-records-multibyte-character-issue/252343)

<div class="topic-metadata">

**Author:** [@Tim\_Baverstock](https://discuss.elastic.co/u/Tim_Baverstock)\
**Replies:** 0\
**Last updated:** [October 16, 2020, 11:52am UTC](https://discuss.elastic.co/t/filebeat-6-5-4-is-truncating-some-records-multibyte-character-issue/252343 "2020-10-16T11:52:56Z")

</div>

On each host, a few Docker 18.09.6 containers use a shared volume to create low-load logfiles (a few entries a minute each). Each test-run takes under an hour, and each test run starts a new logfile. We delete files olde…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=203)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=205)
