# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=207

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 208

---

## [Beat multiline on XML does not send full event and tears up into individual lines](https://discuss.elastic.co/t/beat-multiline-on-xml-does-not-send-full-event-and-tears-up-into-individual-lines/251020)

<div class="topic-metadata">

**Author:** [@thdesy](https://discuss.elastic.co/u/thdesy)\
**Replies:** 1\
**Last updated:** [October 7, 2020, 1:46pm UTC](https://discuss.elastic.co/t/beat-multiline-on-xml-does-not-send-full-event-and-tears-up-into-individual-lines/251020 "2020-10-07T13:46:54Z")

</div>

Hi, I have put a prospector onto a logfile \[1\], that is written as XML. An events is wrapped in tags, so I defined a multiline for the beat multiline: type: pattern pattern: '\<c\>' negate: true match:…

---

## [Multi line pattern in filebeat](https://discuss.elastic.co/t/multi-line-pattern-in-filebeat/250901)

<div class="topic-metadata">

**Author:** [@billy1](https://discuss.elastic.co/u/billy1)\
**Replies:** 2\
**Last updated:** [October 7, 2020, 8:45am UTC](https://discuss.elastic.co/t/multi-line-pattern-in-filebeat/250901 "2020-10-07T08:45:04Z")

</div>

Dears what will be the multiline pattern for below message in the file beat config , i tried all the way but its not getting correct output from filebeat to logstash tried with space filter but its not sending closing …

---

## [Metricbeat stopping or getting killed 7.9.1](https://discuss.elastic.co/t/metricbeat-stopping-or-getting-killed-7-9-1/251099)

<div class="topic-metadata">

**Author:** [@Prashant\_Achari](https://discuss.elastic.co/u/Prashant_Achari)\
**Replies:** 3\
**Last updated:** [October 7, 2020, 6:53am UTC](https://discuss.elastic.co/t/metricbeat-stopping-or-getting-killed-7-9-1/251099 "2020-10-07T06:53:01Z")

</div>

Hi Metric beat stops sending the metrics to elastic. Looks like it is getting killed internally. Logs as below 2020-10-06T08:02:36.529+0100 INFO \[monitoring\] log/log.go:145 Non-zero metrics in the last 30s …

---

## [Powermax2000 monitoring](https://discuss.elastic.co/t/powermax2000-monitoring/251152)

<div class="topic-metadata">

**Author:** [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Replies:** 2\
**Last updated:** [October 7, 2020, 6:18am UTC](https://discuss.elastic.co/t/powermax2000-monitoring/251152 "2020-10-07T06:18:18Z")

</div>

Hello, is there anyway to get metrics and logs of a powermax2000 into elasticsearch. It seems that the powermaxbeat is not working. Kind regards Boris

---

## [Auditbeat and Filebeat ERROR instance/beat.go:951 Exiting: data path already locked by another beat](https://discuss.elastic.co/t/auditbeat-and-filebeat-error-instance-beat-go-951-exiting-data-path-already-locked-by-another-beat/251201)

<div class="topic-metadata">

**Author:** [@bilal\_abudan](https://discuss.elastic.co/u/bilal_abudan)\
**Replies:** 0\
**Last updated:** [October 7, 2020, 2:16am UTC](https://discuss.elastic.co/t/auditbeat-and-filebeat-error-instance-beat-go-951-exiting-data-path-already-locked-by-another-beat/251201 "2020-10-07T02:16:07Z")

</div>

Can someone help please...???? I am using Filebeat and Auditbeat, but when i start the services there's an error : ERROR instance/beat.go:951 Exiting: data path already locked by another beat. Please make sure tha…

---

## [RabbitMQ Module of Metricbeat giving 503 Service Unavailable Error](https://discuss.elastic.co/t/rabbitmq-module-of-metricbeat-giving-503-service-unavailable-error/251130)

<div class="topic-metadata">

**Author:** [@Ayush\_Agrahari](https://discuss.elastic.co/u/Ayush_Agrahari)\
**Replies:** 1\
**Last updated:** [October 6, 2020, 11:37pm UTC](https://discuss.elastic.co/t/rabbitmq-module-of-metricbeat-giving-503-service-unavailable-error/251130 "2020-10-06T23:37:39Z")

</div>

We are trying to setup RabbitMQ module in metricbeat to pull metrics. Please find metricbeat configuration details below - type: kubernetes node: ${NODE\_NAME} scope: cluster templat…

---

## [Using processors with modules in Filebeat](https://discuss.elastic.co/t/using-processors-with-modules-in-filebeat/251001)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 5\
**Last updated:** [October 6, 2020, 6:15pm UTC](https://discuss.elastic.co/t/using-processors-with-modules-in-filebeat/251001 "2020-10-06T18:15:19Z")

</div>

TL;DR How do I add fields (or any processors) to the config for a preexisting module without editing the module source? Issue I'm attempting to add some fields to logs ingested via the system module. This is my modules.…

---

## [Filebeat not showing container logs](https://discuss.elastic.co/t/filebeat-not-showing-container-logs/251059)

<div class="topic-metadata">

**Author:** [@masber](https://discuss.elastic.co/u/masber)\
**Replies:** 0\
**Last updated:** [October 6, 2020, 12:05am UTC](https://discuss.elastic.co/t/filebeat-not-showing-container-logs/251059 "2020-10-06T00:05:34Z")

</div>

Hi, I have a Kubernetes test cluster with Filebeat running as Daemonset and a Redis container I want to monitor. Filebeat log shows it can find the container because the logs path (/var/log/containers/\*-20845e0aa57813e…

---

## [FIlebeat XML Parsing in Logstash](https://discuss.elastic.co/t/filebeat-xml-parsing-in-logstash/251165)

<div class="topic-metadata">

**Author:** [@teej](https://discuss.elastic.co/u/teej)\
**Replies:** 0\
**Last updated:** [October 6, 2020, 4:55pm UTC](https://discuss.elastic.co/t/filebeat-xml-parsing-in-logstash/251165 "2020-10-06T16:55:20Z")

</div>

I was running the following code to get xml parsed from a local file into an elastic index and it appears to work fine: input { file { path =\> "/tmp/test2.xml" sincedb\_path =\> "/dev/null" start\_position =\> …

---

## [Json parsing / containers / kubernetes](https://discuss.elastic.co/t/json-parsing-containers-kubernetes/251161)

<div class="topic-metadata">

**Author:** [@Michael\_Eaton](https://discuss.elastic.co/u/Michael_Eaton)\
**Replies:** 0\
**Last updated:** [October 6, 2020, 4:15pm UTC](https://discuss.elastic.co/t/json-parsing-containers-kubernetes/251161 "2020-10-06T16:15:29Z")

</div>

Hi I have a nodejs application that is running in Kubernetes, and i have filebeat setup as a DaemonSet - all working pretty well, i'm trying to get the logs from my nodejs app which uses the Winston logger and logs in j…

---

## [Metricbeat index without version number](https://discuss.elastic.co/t/metricbeat-index-without-version-number/251141)

<div class="topic-metadata">

**Author:** [@graimato](https://discuss.elastic.co/u/graimato)\
**Replies:** 0\
**Last updated:** [October 6, 2020, 1:52pm UTC](https://discuss.elastic.co/t/metricbeat-index-without-version-number/251141 "2020-10-06T13:52:30Z")

</div>

Dear all, I have many metricbeat and filebeat that are sending data on kibana. I set up my lifecycle policy eg. 50GB and 30d, but each metricbeat uses as index metricbeat-{version} and I have every time update lifecycle…

---

## [FileBeat harvester doesn't work on the defined path with 777 permission](https://discuss.elastic.co/t/filebeat-harvester-doesnt-work-on-the-defined-path-with-777-permission/251133)

<div class="topic-metadata">

**Author:** [@BTH.S3](https://discuss.elastic.co/u/BTH.S3)\
**Replies:** 1\
**Last updated:** [October 6, 2020, 1:42pm UTC](https://discuss.elastic.co/t/filebeat-harvester-doesnt-work-on-the-defined-path-with-777-permission/251133 "2020-10-06T13:42:42Z")

</div>

I was deployed ELK on local host and filebeat on remote host in order to fetch log from remote to local by using docker-compose for ELK and docker run for filebeat. The flow will be like Filebeat(remote) -\> Logstash (lo…

---

## [Exiting: 2 errors: metricset 'system/load' not found; error connecting to dbus: dial tcp 127.0.0.1:12434: connectex: No connection could be made because the target machine actively refused it](https://discuss.elastic.co/t/exiting-2-errors-metricset-system-load-not-found-error-connecting-to-dbus-dial-tcp-127-0-0-1-connectex-no-connection-could-be-made-because-the-target-machine-actively-refused-it/248781)

<div class="topic-metadata">

**Author:** [@Shriram\_Wasule](https://discuss.elastic.co/u/Shriram_Wasule)\
**Replies:** 3\
**Last updated:** [October 6, 2020, 11:24am UTC](https://discuss.elastic.co/t/exiting-2-errors-metricset-system-load-not-found-error-connecting-to-dbus-dial-tcp-127-0-0-1-connectex-no-connection-could-be-made-because-the-target-machine-actively-refused-it/248781 "2020-10-06T11:24:43Z")

</div>

I am getting above error when i am trying to start metricbeat. please help to resolve this issue

---

## [Packetbeat- Duplicated flow records even intermediate report is disabled](https://discuss.elastic.co/t/packetbeat-duplicated-flow-records-even-intermediate-report-is-disabled/251107)

<div class="topic-metadata">

**Author:** [@wphromma](https://discuss.elastic.co/u/wphromma)\
**Replies:** 0\
**Last updated:** [October 6, 2020, 11:12am UTC](https://discuss.elastic.co/t/packetbeat-duplicated-flow-records-even-intermediate-report-is-disabled/251107 "2020-10-06T11:12:19Z")

</div>

Hi, I am just curious why we are getting duplicated logs of a flow. As I understand, the flow id should be uniqued and when flow.final is to true, doesn't that mean there should be no more data for this flow? This i…

---

## [Getting external IP from gke node](https://discuss.elastic.co/t/getting-external-ip-from-gke-node/250832)

<div class="topic-metadata">

**Author:** [@Roman\_Kournjaev](https://discuss.elastic.co/u/Roman_Kournjaev)\
**Replies:** 2\
**Last updated:** [October 6, 2020, 3:47am UTC](https://discuss.elastic.co/t/getting-external-ip-from-gke-node/250832 "2020-10-06T03:47:06Z")

</div>

Hi I am running beats on GKE and wondering whether its possible to get the external IP of the node that i am running on with the processors: - add\_host\_metadata: what i am getting now is the internal google ip whic…

---

## [High CPU usage on warms caused by metricbeat](https://discuss.elastic.co/t/high-cpu-usage-on-warms-caused-by-metricbeat/251054)

<div class="topic-metadata">

**Author:** [@Jesbourne](https://discuss.elastic.co/u/Jesbourne)\
**Replies:** 1\
**Last updated:** [October 5, 2020, 10:29pm UTC](https://discuss.elastic.co/t/high-cpu-usage-on-warms-caused-by-metricbeat/251054 "2020-10-05T22:29:56Z")

</div>

We've been troubleshooting an issue for several months that seems to be related to metricbeat. This weekend, within a few hours of starting metricbeat on our warms, hots, percolators and clients (we do not run it on the …

---

## [Configure pfsense to ELK](https://discuss.elastic.co/t/configure-pfsense-to-elk/249360)

<div class="topic-metadata">

**Author:** [@Lusca\_lusca](https://discuss.elastic.co/u/Lusca_lusca)\
**Replies:** 11\
**Last updated:** [October 5, 2020, 6:29pm UTC](https://discuss.elastic.co/t/configure-pfsense-to-elk/249360 "2020-10-05T18:29:26Z")

</div>

Hi I am an intern at an IT company and I have to set up ELK to get logs from pfsense firewall, I am doing it all by myself but I don't have much knowledge about the topic. I am using an Azure server that I acess with my…

---

## [Custom filebeat processor](https://discuss.elastic.co/t/custom-filebeat-processor/248029)

<div class="topic-metadata">

**Author:** [@yoklmn](https://discuss.elastic.co/u/yoklmn)\
**Replies:** 1\
**Last updated:** [October 5, 2020, 4:01pm UTC](https://discuss.elastic.co/t/custom-filebeat-processor/248029 "2020-10-05T16:01:40Z")

</div>

Hello. I hard trying create my own plugin of filebeat's processor. I use filebeat v7.9.1 from official repository on machine B, CentOS 7.6.1810, CPU Intel Xeon E-2176G: filebeat version 7.9.1 (amd64), libbeat 7.9.1 \[ad8…

---

## [Journalbeat -multiline](https://discuss.elastic.co/t/journalbeat-multiline/251013)

<div class="topic-metadata">

**Author:** [@sidhesh\_kumar](https://discuss.elastic.co/u/sidhesh_kumar)\
**Replies:** 0\
**Last updated:** [October 5, 2020, 3:04pm UTC](https://discuss.elastic.co/t/journalbeat-multiline/251013 "2020-10-05T15:04:20Z")

</div>

Hi.. Is there multiline support avaialble for journalbeat . I am using 7.9

---

## [Packet beat in stopped stae](https://discuss.elastic.co/t/packet-beat-in-stopped-stae/250960)

<div class="topic-metadata">

**Author:** [@ashwinvijay](https://discuss.elastic.co/u/ashwinvijay)\
**Replies:** 1\
**Last updated:** [October 5, 2020, 3:00pm UTC](https://discuss.elastic.co/t/packet-beat-in-stopped-stae/250960 "2020-10-05T15:00:06Z")

</div>

Installed packet beat and started service for packet beat. Not showing any error. But when checking the service status, it shows packet beat is stopped. Any way to fix this.

---

## [Parsing Sysmon Logs to filter on Event.Code](https://discuss.elastic.co/t/parsing-sysmon-logs-to-filter-on-event-code/250834)

<div class="topic-metadata">

**Author:** [@Lee\_Archinal](https://discuss.elastic.co/u/Lee_Archinal)\
**Replies:** 1\
**Last updated:** [October 5, 2020, 2:45pm UTC](https://discuss.elastic.co/t/parsing-sysmon-logs-to-filter-on-event-code/250834 "2020-10-05T14:45:37Z")

</div>

Good afternoon everyone, I recently blew away my old ELK stack and built a new one. I still maintained the same log sources, Sysmon, Windows events, and Powershell, (using the configuration that came with winlogbeat) bu…

---

## [Metricbeat Dashboard only some stats working](https://discuss.elastic.co/t/metricbeat-dashboard-only-some-stats-working/248929)

<div class="topic-metadata">

**Author:** [@rplus](https://discuss.elastic.co/u/rplus)\
**Replies:** 3\
**Last updated:** [October 5, 2020, 2:27pm UTC](https://discuss.elastic.co/t/metricbeat-dashboard-only-some-stats-working/248929 "2020-10-05T14:27:23Z")

</div>

Hi, I've setup metricbeat on a windows server. It currently ships it's logs to logstash and then elastic. For some reason the deafult metric dashboard only shows some stats: (Dont worry about the filtering, I only h…

---

## [Filebeat Azure Module with Intune Diagnostics?](https://discuss.elastic.co/t/filebeat-azure-module-with-intune-diagnostics/248635)

<div class="topic-metadata">

**Author:** [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Replies:** 2\
**Last updated:** [October 5, 2020, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-with-intune-diagnostics/248635 "2020-10-05T14:23:41Z")

</div>

Hi, We're interested in trying out the Azure module for Filebeat in order to fetch logs from an Azure event hub. The event hub will be fed diagnostics logs from Intune. If we look at the documentation for the Azure mod…

---

## [\[Filebeat\] AWS module & ELB fileset, not parsing message](https://discuss.elastic.co/t/filebeat-aws-module-elb-fileset-not-parsing-message/250690)

<div class="topic-metadata">

**Author:** [@Salim\_B](https://discuss.elastic.co/u/Salim_B)\
**Replies:** 8\
**Last updated:** [October 5, 2020, 2:05pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-elb-fileset-not-parsing-message/250690 "2020-10-05T14:05:34Z")

</div>

Hi there ! I've been setting the aws module and the ELB fileset with it, and got it mostly working. It reads the SQS Queue, then get the matching log on S3 side, but it doesn't parse the Access Log message at all. Im …

---

## [Issue with decode\_json\_fields processor](https://discuss.elastic.co/t/issue-with-decode-json-fields-processor/250965)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 8\
**Last updated:** [October 5, 2020, 11:59am UTC](https://discuss.elastic.co/t/issue-with-decode-json-fields-processor/250965 "2020-10-05T11:59:21Z")

</div>

Hi, Im shipping aws logs to elastic with the use of functionbeat. I have recently added the following processor to my configuration, so that im able decode the json that is usually in the message field. processors…

---

## [Metricbeat module with Kubernetes cluster v1.19.2](https://discuss.elastic.co/t/metricbeat-module-with-kubernetes-cluster-v1-19-2/250964)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 0\
**Last updated:** [October 5, 2020, 9:47am UTC](https://discuss.elastic.co/t/metricbeat-module-with-kubernetes-cluster-v1-19-2/250964 "2020-10-05T09:47:47Z")

</div>

hi all, do you have any news about the compatibility between Metricbeat and Kubernetes version 1.19.x? I saw that starting from K8s 1.19, the components controller-manager and scheduler have been deprecated. I mean, c…

---

## [Multiline filter failure in filebeat](https://discuss.elastic.co/t/multiline-filter-failure-in-filebeat/250599)

<div class="topic-metadata">

**Author:** [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Replies:** 1\
**Last updated:** [October 5, 2020, 7:08am UTC](https://discuss.elastic.co/t/multiline-filter-failure-in-filebeat/250599 "2020-10-05T07:08:38Z")

</div>

Hello, I am trying to parse a log file in multiline format and each new linestarts with the date : 28-Sep-2020 18:26:19.982 I tried to configure the config as below filebeat.inputs: - type: log tags: \["PROD\_CATALIN…

---

## [Glob based paths in Filebeat](https://discuss.elastic.co/t/glob-based-paths-in-filebeat/250906)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 1\
**Last updated:** [October 5, 2020, 1:18am UTC](https://discuss.elastic.co/t/glob-based-paths-in-filebeat/250906 "2020-10-05T01:18:18Z")

</div>

Hi Team, I am trying to find out an easy way to give the Glob based path in filebeat. Below is a sample path which we need to configure in filebeat.yml . - /oraadr/XHPROD/adump/\*.aud - /projects/oraxhph2/orabase/ad…

---

## [Auditd events are not captured for centos](https://discuss.elastic.co/t/auditd-events-are-not-captured-for-centos/247215)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 5\
**Last updated:** [October 4, 2020, 5:52pm UTC](https://discuss.elastic.co/t/auditd-events-are-not-captured-for-centos/247215 "2020-10-04T17:52:00Z")

</div>

Hi There, We are running latest version of elastic stack 7.9. One issues we observed is auditd events are not captured for Centos 7 operating systems. Audit rules are already enabled and we see the events getting captur…

---

## [Index template setting overwrite](https://discuss.elastic.co/t/index-template-setting-overwrite/250528)

<div class="topic-metadata">

**Author:** [@jijo.john](https://discuss.elastic.co/u/jijo.john)\
**Replies:** 4\
**Last updated:** [October 4, 2020, 5:44pm UTC](https://discuss.elastic.co/t/index-template-setting-overwrite/250528 "2020-10-04T17:44:26Z")

</div>

Hi Team, I have a problem with the elasticsearch index template setting. below is a custom config i have updated in the index template setting to keep the index in hot nodes, "routing": { "allocation": { "require…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=206)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=208)
