# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=208

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 209

---

## [Winlogbeat service stopped automaticly](https://discuss.elastic.co/t/winlogbeat-service-stopped-automaticly/249026)

<div class="topic-metadata">

**Author:** [@collideroff](https://discuss.elastic.co/u/collideroff)\
**Replies:** 2\
**Last updated:** [October 4, 2020, 12:08pm UTC](https://discuss.elastic.co/t/winlogbeat-service-stopped-automaticly/249026 "2020-10-04T12:08:56Z")

</div>

Good day! I have installed winlogbeat in WindowsServer 2012R2 on EventCollector. It's was istalled properly, but service automaticly stopped after several time..abou 12 hours on more. winlogbeat.event\_logs: name: Ap…

---

## [How to configure output as webhook for filebeat?](https://discuss.elastic.co/t/how-to-configure-output-as-webhook-for-filebeat/250826)

<div class="topic-metadata">

**Author:** [@abh90](https://discuss.elastic.co/u/abh90)\
**Replies:** 2\
**Last updated:** [October 4, 2020, 10:20am UTC](https://discuss.elastic.co/t/how-to-configure-output-as-webhook-for-filebeat/250826 "2020-10-04T10:20:59Z")

</div>

I went through the output list of filebeat, webhook is not supported is what I can gather. How easy or difficult will it be to add webhook as output param for filebeat? I am already using filebeat to ship logs to elast…

---

## [Non-zero metrics in the last 30s (filebeat with docker)](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s-filebeat-with-docker/250859)

<div class="topic-metadata">

**Author:** [@linhonghui](https://discuss.elastic.co/u/linhonghui)\
**Replies:** 4\
**Last updated:** [October 4, 2020, 9:17am UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s-filebeat-with-docker/250859 "2020-10-04T09:17:03Z")

</div>

I used docker to run filebeat and always got this message "Non-zero metrics in the last 30s". It seems not to work. file docker-compose.yml: version: '2' services: filebeat: image: elastic/filebea…

---

## [How to use logstash parsers in filebeat to parse customer logs](https://discuss.elastic.co/t/how-to-use-logstash-parsers-in-filebeat-to-parse-customer-logs/250856)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 0\
**Last updated:** [October 3, 2020, 3:39am UTC](https://discuss.elastic.co/t/how-to-use-logstash-parsers-in-filebeat-to-parse-customer-logs/250856 "2020-10-03T03:39:17Z")

</div>

Hello, I BIND parsers created with logstash and few others as well. Can someone please guide how do I use those parsers with filebeat to create custom module. TIA

---

## [Filebeat module design](https://discuss.elastic.co/t/filebeat-module-design/250204)

<div class="topic-metadata">

**Author:** [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Replies:** 3\
**Last updated:** [October 2, 2020, 9:23pm UTC](https://discuss.elastic.co/t/filebeat-module-design/250204 "2020-10-02T21:23:10Z")

</div>

In the past, most of the filebeat modules were using elasticsearch ingest pipelines to do the enrichment of documents. This means that they are as lightweight as possible, since the work is done centrally and scales well…

---

## [ELK cluster monitoring with Metricbeat](https://discuss.elastic.co/t/elk-cluster-monitoring-with-metricbeat/249224)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 6\
**Last updated:** [October 2, 2020, 12:53pm UTC](https://discuss.elastic.co/t/elk-cluster-monitoring-with-metricbeat/249224 "2020-10-02T12:53:54Z")

</div>

I am trying to set my cluster with metricbeat monitoring. follow the document. setup everything but all my node just keep changing what am i missing? elasticsearch.yml file on all system xpack.monitoring.collection.e…

---

## [Filebeat 7.9.1 parsing http\_json data](https://discuss.elastic.co/t/filebeat-7-9-1-parsing-http-json-data/250314)

<div class="topic-metadata">

**Author:** [@cdroberts](https://discuss.elastic.co/u/cdroberts)\
**Replies:** 9\
**Last updated:** [October 2, 2020, 10:10am UTC](https://discuss.elastic.co/t/filebeat-7-9-1-parsing-http-json-data/250314 "2020-10-02T10:10:37Z")

</div>

Hi, I am having an issue parsing http\_json data with Filebeat. In the logs I can see the events come through fine. 2020-09-29T18:16:19.606+1000 DEBUG \[processors\] processing/processors.go:187 Publish event: { "@times…

---

## [How to parse functionbeat cloudwatch logs](https://discuss.elastic.co/t/how-to-parse-functionbeat-cloudwatch-logs/250765)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [October 2, 2020, 8:57am UTC](https://discuss.elastic.co/t/how-to-parse-functionbeat-cloudwatch-logs/250765 "2020-10-02T08:57:34Z")

</div>

I have recently setup functionbeat to ship aws cloudwatch logs to elasticsearch. How do i format the message into multiple fields; timestamp, log\_id, log\_level and the actual message. I want to parse the message fields…

---

## [Filebeat timestamp processsor doesn't parse microseconds part](https://discuss.elastic.co/t/filebeat-timestamp-processsor-doesnt-parse-microseconds-part/248591)

<div class="topic-metadata">

**Author:** [@6NMgfDwZ3](https://discuss.elastic.co/u/6NMgfDwZ3)\
**Replies:** 3\
**Last updated:** [October 2, 2020, 7:58am UTC](https://discuss.elastic.co/t/filebeat-timestamp-processsor-doesnt-parse-microseconds-part/248591 "2020-10-02T07:58:21Z")

</div>

Hi, this is the first part of my filebeat.xml filebeat.inputs: - type: tcp enabled: true host: "localhost:9000" processors: - decode\_json\_fields: fields: \["message"\] process\_array: true t…

---

## [Send k8s logs with Filebeat to separate indices](https://discuss.elastic.co/t/send-k8s-logs-with-filebeat-to-separate-indices/250632)

<div class="topic-metadata">

**Author:** [@karol\_k](https://discuss.elastic.co/u/karol_k)\
**Replies:** 1\
**Last updated:** [October 2, 2020, 7:02am UTC](https://discuss.elastic.co/t/send-k8s-logs-with-filebeat-to-separate-indices/250632 "2020-10-02T07:02:02Z")

</div>

Hi :slight\_smile: Currently I'm using self-hosted elastic stack but evaluating elastic cloud. I collect all the logs from multiple k8s clusters in a standard way with filebeat kubernetes module. There are application an…

---

## [In Filebeat config fields.type not getting picked up in index!](https://discuss.elastic.co/t/in-filebeat-config-fields-type-not-getting-picked-up-in-index/250658)

<div class="topic-metadata">

**Author:** [@jaraws](https://discuss.elastic.co/u/jaraws)\
**Replies:** 0\
**Last updated:** [October 1, 2020, 11:23am UTC](https://discuss.elastic.co/t/in-filebeat-config-fields-type-not-getting-picked-up-in-index/250658 "2020-10-01T11:23:10Z")

</div>

I am trying to add fields.type of a pipeline to my index but for some reason is not resolving and data is going in against one single index i.e. index-other. filebeat.inputs: - type: log enabled: true paths: …

---

## [Heartbeats configure using AWS Elasticsearch kibana 7.4.2](https://discuss.elastic.co/t/heartbeats-configure-using-aws-elasticsearch-kibana-7-4-2/250315)

<div class="topic-metadata">

**Author:** [@A\_Ravi\_Prashant](https://discuss.elastic.co/u/A_Ravi_Prashant)\
**Replies:** 3\
**Last updated:** [October 1, 2020, 9:06pm UTC](https://discuss.elastic.co/t/heartbeats-configure-using-aws-elasticsearch-kibana-7-4-2/250315 "2020-10-01T21:06:08Z")

</div>

Hi Team, I am using aws elasticsearch kibana 7.4.2 and i have configured filebeats, metricbeats, and hearbeats and sent it to logstash and logstash is sending data logs, metrics etc to aws elasticsearch. and configured …

---

## [FIlebeat httpjson support for proxy connection](https://discuss.elastic.co/t/filebeat-httpjson-support-for-proxy-connection/250731)

<div class="topic-metadata">

**Author:** [@Scott\_Harris](https://discuss.elastic.co/u/Scott_Harris)\
**Replies:** 0\
**Last updated:** [October 1, 2020, 7:03pm UTC](https://discuss.elastic.co/t/filebeat-httpjson-support-for-proxy-connection/250731 "2020-10-01T19:03:25Z")

</div>

I am attempting to configure filebeat 7.9.2 (running from docker image) to use the httpjson input. It works fine with an internally available URL but times outs on an external URL. I have verified and tried multiple comb…

---

## [Filebeat lagging behind raw logs](https://discuss.elastic.co/t/filebeat-lagging-behind-raw-logs/250697)

<div class="topic-metadata">

**Author:** [@jhaugh](https://discuss.elastic.co/u/jhaugh)\
**Replies:** 0\
**Last updated:** [October 1, 2020, 2:34pm UTC](https://discuss.elastic.co/t/filebeat-lagging-behind-raw-logs/250697 "2020-10-01T14:34:51Z")

</div>

Hey Everyone, Recently primary ingest node for network devices syslogs, (unifi APs, cisco switches, sonicwalls, etc) has been lagging behind the raw logs. In my setup I'm using rsyslog to write the initial logs to file …

---

## [Connection Filebeat to Logstash SSL: certificate specifies an incompatible key usage](https://discuss.elastic.co/t/connection-filebeat-to-logstash-ssl-certificate-specifies-an-incompatible-key-usage/250684)

<div class="topic-metadata">

**Author:** [@peterol](https://discuss.elastic.co/u/peterol)\
**Replies:** 0\
**Last updated:** [October 1, 2020, 1:37pm UTC](https://discuss.elastic.co/t/connection-filebeat-to-logstash-ssl-certificate-specifies-an-incompatible-key-usage/250684 "2020-10-01T13:37:31Z")

</div>

Hey everyone, I want to establish a connection with SSL between Filebeat and Logstash according to this. Filebeat runs natively whereas Logstash is running in a Docker container. I converted my keys to the PKCS8 format,…

---

## [Increasing The Frequency of Receiving UDP Data of Filebeat](https://discuss.elastic.co/t/increasing-the-frequency-of-receiving-udp-data-of-filebeat/250683)

<div class="topic-metadata">

**Author:** [@gizem](https://discuss.elastic.co/u/gizem)\
**Replies:** 0\
**Last updated:** [October 1, 2020, 1:07pm UTC](https://discuss.elastic.co/t/increasing-the-frequency-of-receiving-udp-data-of-filebeat/250683 "2020-10-01T13:07:30Z")

</div>

Hi, I listen a udp port with filebeat, and the data comes from the port is sended to elasticsearch directly. Then I check it from kibana. The problem is the duration is very long between the data incoming and sending t…

---

## [Harvester could not be started on new file: /usr/share/apps/logs/sample.log](https://discuss.elastic.co/t/harvester-could-not-be-started-on-new-file-usr-share-apps-logs-sample-log/250648)

<div class="topic-metadata">

**Author:** [@jaraws](https://discuss.elastic.co/u/jaraws)\
**Replies:** 0\
**Last updated:** [October 1, 2020, 10:32am UTC](https://discuss.elastic.co/t/harvester-could-not-be-started-on-new-file-usr-share-apps-logs-sample-log/250648 "2020-10-01T10:32:21Z")

</div>

I am getting following error while starting Filebeat container. 2020-10-01 ERROR log/input.go:519 Harvester could not be started on new file: /usr/share/apps/logs/sample.log, Err: registry already stopped …

---

## [Multiline stack traces (.net) with whitespace](https://discuss.elastic.co/t/multiline-stack-traces-net-with-whitespace/249954)

<div class="topic-metadata">

**Author:** [@Raman\_Sawhney](https://discuss.elastic.co/u/Raman_Sawhney)\
**Replies:** 3\
**Last updated:** [October 1, 2020, 12:23pm UTC](https://discuss.elastic.co/t/multiline-stack-traces-net-with-whitespace/249954 "2020-10-01T12:23:58Z")

</div>

I have issues with Multiline stack traces (.net) with whitespace. logs are getting split and we are not able to troubleshoot the things its more time consuming. I tried the fix from ES-stack website but after apply…

---

## [Why include\_lines is not working?](https://discuss.elastic.co/t/why-include-lines-is-not-working/250606)

<div class="topic-metadata">

**Author:** [@jaraws](https://discuss.elastic.co/u/jaraws)\
**Replies:** 0\
**Last updated:** [October 1, 2020, 6:58am UTC](https://discuss.elastic.co/t/why-include-lines-is-not-working/250606 "2020-10-01T06:58:11Z")

</div>

I have the following file yaml configuration to pick certain lines with string expressions, but filebeat doesnt seems to be prpagating messages to elastic search: filebeat.inputs: - type: log enabled: true paths:…

---

## [AWS Cloudwatch](https://discuss.elastic.co/t/aws-cloudwatch/250578)

<div class="topic-metadata">

**Author:** [@nan140114](https://discuss.elastic.co/u/nan140114)\
**Replies:** 9\
**Last updated:** [October 1, 2020, 1:14am UTC](https://discuss.elastic.co/t/aws-cloudwatch/250578 "2020-10-01T01:14:38Z")

</div>

SO: Ubuntu 20.04 LTS metricbeat: metricbeat version 7.9.2 (amd64), libbeat 7.9.2 \[2ab907f built 2020-09-22 23:25:17 +0000 UTC\] Hello there. I hope you're doing well. I'm trying to set up a metricbeat agent. It will be…

---

## [Filebeat not picking up /var/log/containers/\*.log k8s](https://discuss.elastic.co/t/filebeat-not-picking-up-var-log-containers-log-k8s/250576)

<div class="topic-metadata">

**Author:** [@dsuma](https://discuss.elastic.co/u/dsuma)\
**Replies:** 0\
**Last updated:** [September 30, 2020, 11:25pm UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-var-log-containers-log-k8s/250576 "2020-09-30T23:25:42Z")

</div>

I have filebeats deployed onto my kube cluster through the elastic helm chart. The pod is privileged. Filebeats is picking up the new log that I create on the node. touch /var/log/containers/mylog.log and then I add stu…

---

## [Is it reasonable to use multiple instances of Filebeat (Windows) on a production system?](https://discuss.elastic.co/t/is-it-reasonable-to-use-multiple-instances-of-filebeat-windows-on-a-production-system/250457)

<div class="topic-metadata">

**Author:** [@ruben.crespo.cano](https://discuss.elastic.co/u/ruben.crespo.cano)\
**Replies:** 4\
**Last updated:** [September 30, 2020, 10:02pm UTC](https://discuss.elastic.co/t/is-it-reasonable-to-use-multiple-instances-of-filebeat-windows-on-a-production-system/250457 "2020-09-30T22:02:51Z")

</div>

To whom it may concern, Background: Currently in our windows servers we have different applications that belong to different clients. Therefore, we want to create different indexes with different ILM policies since each…

---

## [How tell metricbeat to create custom indices?](https://discuss.elastic.co/t/how-tell-metricbeat-to-create-custom-indices/250297)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 11\
**Last updated:** [September 30, 2020, 12:35pm UTC](https://discuss.elastic.co/t/how-tell-metricbeat-to-create-custom-indices/250297 "2020-09-30T12:35:27Z")

</div>

Hi there, how can I tell metricbeat to direct the ingested data into a custom index? What I tried so far did not work. cheers Ste

---

## [Kubernetes metrics](https://discuss.elastic.co/t/kubernetes-metrics/250486)

<div class="topic-metadata">

**Author:** [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Replies:** 0\
**Last updated:** [September 30, 2020, 10:53am UTC](https://discuss.elastic.co/t/kubernetes-metrics/250486 "2020-09-30T10:53:35Z")

</div>

Hello, I hope you are doing well! I am running ELK stack alongside metricbeat (version 7.9) on an Azure kubernetes cluster. Metricbeat is running as a daemonset. I was trying to fetch scheduler and controllermanger m…

---

## [FileBeat not harvesting new logs in the provided path](https://discuss.elastic.co/t/filebeat-not-harvesting-new-logs-in-the-provided-path/250485)

<div class="topic-metadata">

**Author:** [@BTH.S3](https://discuss.elastic.co/u/BTH.S3)\
**Replies:** 0\
**Last updated:** [September 30, 2020, 10:49am UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-new-logs-in-the-provided-path/250485 "2020-09-30T10:49:50Z")

</div>

FileBeat has been running as a docker container started by docker-compose file and already mapped the volume for filebeat.yml. I've updated the configuration in filebeat.yml by setting input and output as Elasticsearch. …

---

## [Logs sent repeatedly to Elastic Search when updated from host machine of filebeat container!](https://discuss.elastic.co/t/logs-sent-repeatedly-to-elastic-search-when-updated-from-host-machine-of-filebeat-container/250409)

<div class="topic-metadata">

**Author:** [@jaraws](https://discuss.elastic.co/u/jaraws)\
**Replies:** 1\
**Last updated:** [September 30, 2020, 9:42am UTC](https://discuss.elastic.co/t/logs-sent-repeatedly-to-elastic-search-when-updated-from-host-machine-of-filebeat-container/250409 "2020-09-30T09:42:41Z")

</div>

Hi, I am running filebeat container using the following command: docker run -d \\ --name=filebeat \\ --user=root \\ --volume="$(pwd)/filebeat-file.yml:/usr/share/filebeat/filebeat.yml:ro" \\ --volume="$(pwd)/apps/l…

---

## [Failed to hash executable](https://discuss.elastic.co/t/failed-to-hash-executable/250469)

<div class="topic-metadata">

**Author:** [@Burga](https://discuss.elastic.co/u/Burga)\
**Replies:** 0\
**Last updated:** [September 30, 2020, 8:36am UTC](https://discuss.elastic.co/t/failed-to-hash-executable/250469 "2020-09-30T08:36:32Z")

</div>

Hi , I installed auditbeat where oracle DB is existing, now I'm getting a warning message : failed to hash executable /oracle/12.2/home/bin/oracle for PID 32167: failed to hash file /oracle/12.2/home/bin/oracle: hashe…

---

## [Dissect string in filebeat](https://discuss.elastic.co/t/dissect-string-in-filebeat/250445)

<div class="topic-metadata">

**Author:** [@niv](https://discuss.elastic.co/u/niv)\
**Replies:** 0\
**Last updated:** [September 30, 2020, 4:54am UTC](https://discuss.elastic.co/t/dissect-string-in-filebeat/250445 "2020-09-30T04:54:33Z")

</div>

Hi I want to dissect the particular field . Original filed Value: "\\t{\\n \\"value\\": \\"dropfields\_nT8\\",\\n \\"PSN\\": \\"dropfields\_8\\",\\n \\"Id\\": \\"dropfields\_8\\",\\n \\"PSShowComputerName\\": …

---

## [Filbeat.yml process a csv header?](https://discuss.elastic.co/t/filbeat-yml-process-a-csv-header/250422)

<div class="topic-metadata">

**Author:** [@niv](https://discuss.elastic.co/u/niv)\
**Replies:** 1\
**Last updated:** [September 29, 2020, 11:41pm UTC](https://discuss.elastic.co/t/filbeat-yml-process-a-csv-header/250422 "2020-09-29T23:41:06Z")

</div>

Are there any configurations in filebeat.yml to process csv header? eg: header1,header2,header3 value1,value2,value3

---

## [Multiline Codec Pattern Match if String Exists](https://discuss.elastic.co/t/multiline-codec-pattern-match-if-string-exists/250225)

<div class="topic-metadata">

**Author:** [@NomadicCodeGuy](https://discuss.elastic.co/u/NomadicCodeGuy)\
**Replies:** 1\
**Last updated:** [September 29, 2020, 4:49pm UTC](https://discuss.elastic.co/t/multiline-codec-pattern-match-if-string-exists/250225 "2020-09-29T16:49:23Z")

</div>

Is it possible to configure the multiline codec to match a pattern if a message contains a certain string? If yes, what would this pattern look like? For example, if a message contains the string "Finished scenario" I wo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=207)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=209)
