# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=205

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 206

---

## [Network interfaces statistics @ nodes/logstash/kibana](https://discuss.elastic.co/t/network-interfaces-statistics-nodes-logstash-kibana/252191)

<div class="topic-metadata">

**Author:** [@Waxman](https://discuss.elastic.co/u/Waxman)\
**Replies:** 2\
**Last updated:** [October 16, 2020, 10:03am UTC](https://discuss.elastic.co/t/network-interfaces-statistics-nodes-logstash-kibana/252191 "2020-10-16T10:03:09Z")

</div>

How to stat network interfaces on nodes. We'd like to present network utilization (bitrate) per interface. I'm thinking about metricbeat, which we use actually but there are collection only from the system network. We'd …

---

## [\[Filebeat\] Huge mapping (nearly 5k fields) when ingesting logs](https://discuss.elastic.co/t/filebeat-huge-mapping-nearly-5k-fields-when-ingesting-logs/252185)

<div class="topic-metadata">

**Author:** [@M-O](https://discuss.elastic.co/u/M-O)\
**Replies:** 2\
**Last updated:** [October 16, 2020, 9:08am UTC](https://discuss.elastic.co/t/filebeat-huge-mapping-nearly-5k-fields-when-ingesting-logs/252185 "2020-10-16T09:08:34Z")

</div>

Hello, i am currently experimenting with filebeat and noticed that, when filebeat creates the standard indicies, it comes with a huge count of field mappings. To me it looks like the index-template specifies every …

---

## [\[Filebeat\] Panic in K8s autodiscover](https://discuss.elastic.co/t/filebeat-panic-in-k8s-autodiscover/252144)

<div class="topic-metadata">

**Author:** [@boernd](https://discuss.elastic.co/u/boernd)\
**Replies:** 3\
**Last updated:** [October 16, 2020, 7:25am UTC](https://discuss.elastic.co/t/filebeat-panic-in-k8s-autodiscover/252144 "2020-10-16T07:25:08Z")

</div>

Hi, after upgrading from 7.5.2 to 7.9.2 I observe sporadic container crashes with the following stacktrace: fatal error: concurrent map read and map write goroutine 5766 \[running\]: runtime.throw(0x3d8cd28, 0x21) /usr…

---

## [Kafka output throughput is slow or not fast enough](https://discuss.elastic.co/t/kafka-output-throughput-is-slow-or-not-fast-enough/252117)

<div class="topic-metadata">

**Author:** [@jkyamog](https://discuss.elastic.co/u/jkyamog)\
**Replies:** 1\
**Last updated:** [October 16, 2020, 3:26am UTC](https://discuss.elastic.co/t/kafka-output-throughput-is-slow-or-not-fast-enough/252117 "2020-10-16T03:26:38Z")

</div>

We are ingesting logs of zscaler, we have come up with a bottle neck likely on the filebeat kafka output. Deployment A: \[\[ Zscaler NSS \]\] -- syslog input --\> \[\[ filebeat \]\] -- kafka output --\> \[\[ Event Hub \]\] ... \[\[ El…

---

## [Configuration of logstash for forwarding winlogbeats to a syslog server](https://discuss.elastic.co/t/configuration-of-logstash-for-forwarding-winlogbeats-to-a-syslog-server/252195)

<div class="topic-metadata">

**Author:** [@jjoseph8008](https://discuss.elastic.co/u/jjoseph8008)\
**Replies:** 2\
**Last updated:** [October 16, 2020, 2:54am UTC](https://discuss.elastic.co/t/configuration-of-logstash-for-forwarding-winlogbeats-to-a-syslog-server/252195 "2020-10-16T02:54:07Z")

</div>

I am using winlogbeats to send log files from a windows box to logstash. My logstash is collecting Linux syslogs over port 514,forwarding them to a local NGINX service that will then forward it to our SIEM syslog server …

---

## [How to gather journald logs from coreos hosts in an Openshift cluster?](https://discuss.elastic.co/t/how-to-gather-journald-logs-from-coreos-hosts-in-an-openshift-cluster/247553)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 4\
**Last updated:** [October 15, 2020, 6:51pm UTC](https://discuss.elastic.co/t/how-to-gather-journald-logs-from-coreos-hosts-in-an-openshift-cluster/247553 "2020-10-15T18:51:39Z")

</div>

Hello, We are in the process of migrating from Openshift 3.11 to Openshift 4.5. We managed to get the Filebeat daemonset working to ship pod logs, but we also need to index the journalctl logs from the coreos hosts. Wha…

---

## [Mysql data fetching in ELK](https://discuss.elastic.co/t/mysql-data-fetching-in-elk/252192)

<div class="topic-metadata">

**Author:** [@Waxman](https://discuss.elastic.co/u/Waxman)\
**Replies:** 1\
**Last updated:** [October 15, 2020, 12:41pm UTC](https://discuss.elastic.co/t/mysql-data-fetching-in-elk/252192 "2020-10-15T12:41:42Z")

</div>

Hello Folks, we got a database with data that are refreshing every hour. We'd like to fetch this data as it is to the elk (ofcourse with some filtering etc.) Can you suggest what is the best architecture and way to do t…

---

## [Cannot connect metricbeat with an SSL secured Kafka](https://discuss.elastic.co/t/cannot-connect-metricbeat-with-an-ssl-secured-kafka/252060)

<div class="topic-metadata">

**Author:** [@JadeJaber](https://discuss.elastic.co/u/JadeJaber)\
**Replies:** 2\
**Last updated:** [October 15, 2020, 11:48am UTC](https://discuss.elastic.co/t/cannot-connect-metricbeat-with-an-ssl-secured-kafka/252060 "2020-10-15T11:48:25Z")

</div>

Hi, I have set the following configuration on my Kafka Module - module: kafka metricsets: - partition - consumergroup period: 10s hosts: \["centralfeederkafka01.datalakefeeder###.com:9093"\] ssl.enabled: …

---

## [Filebeat opening two harvesters for the same file](https://discuss.elastic.co/t/filebeat-opening-two-harvesters-for-the-same-file/252187)

<div class="topic-metadata">

**Author:** [@jbury](https://discuss.elastic.co/u/jbury)\
**Replies:** 0\
**Last updated:** [October 15, 2020, 11:46am UTC](https://discuss.elastic.co/t/filebeat-opening-two-harvesters-for-the-same-file/252187 "2020-10-15T11:46:11Z")

</div>

Issue: We're seeing occasional data loss in kibana. We'll get several lines from a given log file that filebeat grabs and successfully sends to elasticsearch, and then suddenly (and before we are finished processing th…

---

## [Specifying Filebeat paths with "-"](https://discuss.elastic.co/t/specifying-filebeat-paths-with/252043)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 2\
**Last updated:** [October 15, 2020, 9:26am UTC](https://discuss.elastic.co/t/specifying-filebeat-paths-with/252043 "2020-10-15T09:26:02Z")

</div>

Hello All , I have a filebeat config like this - type: log enabled: true paths: - //XXXXXX/E122\_WWUSA-OPRD-CmpLog/XXXX/XXXXX/\*.log - //XXXXXX/E122\_WWUSA-OPRD-CmpLog/XXXX/XXXXX/\*.log I have the folder wit…

---

## [Filebeat](https://discuss.elastic.co/t/filebeat/252146)

<div class="topic-metadata">

**Author:** [@111387](https://discuss.elastic.co/u/111387)\
**Replies:** 1\
**Last updated:** [October 15, 2020, 9:22am UTC](https://discuss.elastic.co/t/filebeat/252146 "2020-10-15T09:22:26Z")

</div>

receiving CEF format log using filebeat cef module and send to logstash While viewing the parsed results, I could see that there was an error tag. "error": { "message": \[ "malformed value for filePath at pos 168"…

---

## [Grok expressions do not match field value](https://discuss.elastic.co/t/grok-expressions-do-not-match-field-value/251654)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 3\
**Last updated:** [October 15, 2020, 9:10am UTC](https://discuss.elastic.co/t/grok-expressions-do-not-match-field-value/251654 "2020-10-15T09:10:54Z")

</div>

Hello, I am trying to parse posgresql audit logs which is in csv format (sample line below) 2020-10-05 00:23:14.603 GMT,ixq\_dc\_monitor,postgres,11450,10.10.60.83:59536,5f7a6772.2cba,1,authentication,2020-10-05 00:23:14…

---

## [Regexp Not Evaluating as Expected](https://discuss.elastic.co/t/regexp-not-evaluating-as-expected/251954)

<div class="topic-metadata">

**Author:** [@eafrost.cissp](https://discuss.elastic.co/u/eafrost.cissp)\
**Replies:** 2\
**Last updated:** [October 15, 2020, 6:56am UTC](https://discuss.elastic.co/t/regexp-not-evaluating-as-expected/251954 "2020-10-15T06:56:54Z")

</div>

I'm trying to drop events for which the winlog.event\_data.TargetUserName ends with $ but keep the event when winlog.event\_data.TargetUserName has $ not as the end character. Using the regular expressions 101 tester (http…

---

## [Problems with AND in drop\_events.when.or](https://discuss.elastic.co/t/problems-with-and-in-drop-events-when-or/252066)

<div class="topic-metadata">

**Author:** [@Matthew\_Smith](https://discuss.elastic.co/u/Matthew_Smith)\
**Replies:** 2\
**Last updated:** [October 14, 2020, 5:37pm UTC](https://discuss.elastic.co/t/problems-with-and-in-drop-events-when-or/252066 "2020-10-14T17:37:07Z")

</div>

I'm trying to drop a particular event id (4624 or 4627) when the TargetUserName is SYSTEM and then also just always drop event id 5379. What am I doing wrong here? # Needed for Graylog fields\_under\_root: true fields.c…

---

## [Dynamic index name not working with Filebeat](https://discuss.elastic.co/t/dynamic-index-name-not-working-with-filebeat/251284)

<div class="topic-metadata">

**Author:** [@Pablo\_Albertengo](https://discuss.elastic.co/u/Pablo_Albertengo)\
**Replies:** 3\
**Last updated:** [October 14, 2020, 4:45pm UTC](https://discuss.elastic.co/t/dynamic-index-name-not-working-with-filebeat/251284 "2020-10-14T16:45:03Z")

</div>

Hi guys! I am not being able to get Filebeat to write documents to indices based on a field. This is my configuration: filebeat.inputs: - type: log # Change to true to enable this input configuration. enabled: tr…

---

## [Heartbeat URL changing after POST](https://discuss.elastic.co/t/heartbeat-url-changing-after-post/251934)

<div class="topic-metadata">

**Author:** [@OracleDBA](https://discuss.elastic.co/u/OracleDBA)\
**Replies:** 6\
**Last updated:** [October 14, 2020, 12:27pm UTC](https://discuss.elastic.co/t/heartbeat-url-changing-after-post/251934 "2020-10-14T12:27:15Z")

</div>

Hello, I have a heartbeat configuration such as: - type: http name: CHECK-A id: CHECK-A schedule: '@every: 10s' urls: \["https://website/check/checkRequest.html"\] check.request: method: POST response.inclu…

---

## [Functionbeat Disable ilm Policy](https://discuss.elastic.co/t/functionbeat-disable-ilm-policy/248829)

<div class="topic-metadata">

**Author:** [@sainath](https://discuss.elastic.co/u/sainath)\
**Replies:** 5\
**Last updated:** [October 14, 2020, 11:23am UTC](https://discuss.elastic.co/t/functionbeat-disable-ilm-policy/248829 "2020-10-14T11:23:59Z")

</div>

Hi Team, I am trying to enable custom index in functionbeat using the below configuration. output.elasticsearch: hosts: \["10.10.10.10:9200"\] output.elasticsearch.index: "customname-%{\[agent.version\]}-%{+yyyy.M…

---

## [Filebeat multiline configuration consolidate all logs line to one event](https://discuss.elastic.co/t/filebeat-multiline-configuration-consolidate-all-logs-line-to-one-event/251993)

<div class="topic-metadata">

**Author:** [@HadarPeeran](https://discuss.elastic.co/u/HadarPeeran)\
**Replies:** 0\
**Last updated:** [October 14, 2020, 6:07am UTC](https://discuss.elastic.co/t/filebeat-multiline-configuration-consolidate-all-logs-line-to-one-event/251993 "2020-10-14T06:07:05Z")

</div>

I have the following setting: Filebeat =\> Logstash In order to support java stack trace I added multiline configuration in filebeat.yml multiline.pattern: '^\\\[\[0-9\]{2}-\[0-9\]{2}-\[0-9\]{2}' multiline.negate: true mu…

---

## [No connection could be made because the target machine actively refused it](https://discuss.elastic.co/t/no-connection-could-be-made-because-the-target-machine-actively-refused-it/251961)

<div class="topic-metadata">

**Author:** [@jdehnert](https://discuss.elastic.co/u/jdehnert)\
**Replies:** 3\
**Last updated:** [October 13, 2020, 10:31pm UTC](https://discuss.elastic.co/t/no-connection-could-be-made-because-the-target-machine-actively-refused-it/251961 "2020-10-13T22:31:21Z")

</div>

I have searched all the other posts on this topic, but none of the other answers seemed to help resolve my problem. My configuration is pretty simple. It's basically straight out of the documentation. I have Elasticse…

---

## [AWS metrics shipping intervals are unstable and not matching the configuration of 1minute](https://discuss.elastic.co/t/aws-metrics-shipping-intervals-are-unstable-and-not-matching-the-configuration-of-1minute/251159)

<div class="topic-metadata">

**Author:** [@Yotamloe](https://discuss.elastic.co/u/Yotamloe)\
**Replies:** 9\
**Last updated:** [October 13, 2020, 5:28pm UTC](https://discuss.elastic.co/t/aws-metrics-shipping-intervals-are-unstable-and-not-matching-the-configuration-of-1minute/251159 "2020-10-13T17:28:13Z")

</div>

Hey everyone. I'm facing an issue when using AWS module (cloudwatch metricset) with metricbeat 7.5.2, I'm trying to send metrics data to elasticsearch every 1 minute and I receive the data from the AWS/NetworkELB service…

---

## [Why do I see the winlogbeat fields in Filebeat indexes after creating the winlogbeat index?](https://discuss.elastic.co/t/why-do-i-see-the-winlogbeat-fields-in-filebeat-indexes-after-creating-the-winlogbeat-index/251637)

<div class="topic-metadata">

**Author:** [@zargaran](https://discuss.elastic.co/u/zargaran)\
**Replies:** 2\
**Last updated:** [October 13, 2020, 3:40pm UTC](https://discuss.elastic.co/t/why-do-i-see-the-winlogbeat-fields-in-filebeat-indexes-after-creating-the-winlogbeat-index/251637 "2020-10-13T15:40:10Z")

</div>

I have a filebeat index which worked very carefully. Now I send Windows logs to logstash via winlogbeat and from there I send it to Elasticsearch. A strange thing happens to me over and over again, and that is that afte…

---

## [Filebeat o365 module - Load balancing](https://discuss.elastic.co/t/filebeat-o365-module-load-balancing/251728)

<div class="topic-metadata">

**Author:** [@srilumpa](https://discuss.elastic.co/u/srilumpa)\
**Replies:** 2\
**Last updated:** [October 13, 2020, 3:31pm UTC](https://discuss.elastic.co/t/filebeat-o365-module-load-balancing/251728 "2020-10-13T15:31:03Z")

</div>

Hi, We are looking to use the o365 module from filebeat to gather logs from the Office365 API and we have one question that is not adressed in the documentation (or I haven't find mention about it). In order to deal wi…

---

## [Managing beats and template versions](https://discuss.elastic.co/t/managing-beats-and-template-versions/251829)

<div class="topic-metadata">

**Author:** [@jreichman](https://discuss.elastic.co/u/jreichman)\
**Replies:** 2\
**Last updated:** [October 13, 2020, 3:04pm UTC](https://discuss.elastic.co/t/managing-beats-and-template-versions/251829 "2020-10-13T15:04:24Z")

</div>

Hi, I'm trying to work out the best way to manage differing versions of beats for an elastic search instance. If I output from filebeat to logstash, then to elastic search, I miss out on automatic index template creati…

---

## [Heartbeat returns wrong x.509 information (tls.server.x509)](https://discuss.elastic.co/t/heartbeat-returns-wrong-x-509-information-tls-server-x509/251484)

<div class="topic-metadata">

**Author:** [@fik](https://discuss.elastic.co/u/fik)\
**Replies:** 3\
**Last updated:** [October 13, 2020, 9:25am UTC](https://discuss.elastic.co/t/heartbeat-returns-wrong-x-509-information-tls-server-x509/251484 "2020-10-13T09:25:52Z")

</div>

We have bunch of apps monitored via HTTP endpoints. However, for one of them, heartbeat writes wrong to data to elasticsearch. Data in tls.server.x509 contains old outdated certificate, however it was changed many month…

---

## [Properly Setup Metricbeat with Statsd](https://discuss.elastic.co/t/properly-setup-metricbeat-with-statsd/251792)

<div class="topic-metadata">

**Author:** [@traw1234](https://discuss.elastic.co/u/traw1234)\
**Replies:** 3\
**Last updated:** [October 13, 2020, 2:08pm UTC](https://discuss.elastic.co/t/properly-setup-metricbeat-with-statsd/251792 "2020-10-13T14:08:06Z")

</div>

I'm using Metricbeat to send to a 3rd party logstash, and it's working well with system but there seems to be some trouble with statsd (running on localhost:8125). My current metricbeat.yml looks like this (with some oth…

---

## [Timezone in metricbeat](https://discuss.elastic.co/t/timezone-in-metricbeat/251547)

<div class="topic-metadata">

**Author:** [@vijay\_kaali](https://discuss.elastic.co/u/vijay_kaali)\
**Replies:** 2\
**Last updated:** [October 13, 2020, 11:36am UTC](https://discuss.elastic.co/t/timezone-in-metricbeat/251547 "2020-10-13T11:36:01Z")

</div>

Hi I have installed metricbeat , on all my servers . servers are in different timezone . How do i browse based on timezone ? as timestamp get converted to UTC or Can i have another field servertime with timezone ? …

---

## [User file access metrics using metricbeat and its visualization in kibana](https://discuss.elastic.co/t/user-file-access-metrics-using-metricbeat-and-its-visualization-in-kibana/251890)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 0\
**Last updated:** [October 13, 2020, 10:48am UTC](https://discuss.elastic.co/t/user-file-access-metrics-using-metricbeat-and-its-visualization-in-kibana/251890 "2020-10-13T10:48:08Z")

</div>

Hi there, my use case is the following: I want to see read write operations per user on a file on a linux vm. I am shipping the metrics using metricbeat so I should have all required data alrady. I am just struggeling …

---

## [Can run Filebeat from HTML page or Javascript?](https://discuss.elastic.co/t/can-run-filebeat-from-html-page-or-javascript/251886)

<div class="topic-metadata">

**Author:** [@pducduy99](https://discuss.elastic.co/u/pducduy99)\
**Replies:** 0\
**Last updated:** [October 13, 2020, 10:08am UTC](https://discuss.elastic.co/t/can-run-filebeat-from-html-page-or-javascript/251886 "2020-10-13T10:08:09Z")

</div>

Hi all, now i am doing task make a button in web page will be ship log at local to server remote immediate and once time when button clicked. I was try to run batch file from html pages but doesn't work, not allow. Can y…

---

## [Is it possible to reload the javascript files in filebeat script processor without restarting filebeat](https://discuss.elastic.co/t/is-it-possible-to-reload-the-javascript-files-in-filebeat-script-processor-without-restarting-filebeat/251821)

<div class="topic-metadata">

**Author:** [@kiterunner](https://discuss.elastic.co/u/kiterunner)\
**Replies:** 1\
**Last updated:** [October 13, 2020, 6:02am UTC](https://discuss.elastic.co/t/is-it-possible-to-reload-the-javascript-files-in-filebeat-script-processor-without-restarting-filebeat/251821 "2020-10-13T06:02:40Z")

</div>

I am trying to process some ips using filebeat script processor. I have created the code that can pick the ip and translate the ip to a device name from the event and send the event with a new field to elasticsearch. Th…

---

## [Possible to Control Order that Beats Processes and Ships Files/Log Lines?](https://discuss.elastic.co/t/possible-to-control-order-that-beats-processes-and-ships-files-log-lines/251764)

<div class="topic-metadata">

**Author:** [@NomadicCodeGuy](https://discuss.elastic.co/u/NomadicCodeGuy)\
**Replies:** 3\
**Last updated:** [October 13, 2020, 4:59am UTC](https://discuss.elastic.co/t/possible-to-control-order-that-beats-processes-and-ships-files-log-lines/251764 "2020-10-13T04:59:07Z")

</div>

I am using Beats to ship entries from log files to Logstash. I have aggregations in Logstash that are order dependent. I cannot seem to find a way to control the order that Beats processes my log files or the individual …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=204)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=206)
