# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=209

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 210

---

## [Heartbeat Auto-discovery not working for AWS ELB](https://discuss.elastic.co/t/heartbeat-auto-discovery-not-working-for-aws-elb/250302)

<div class="topic-metadata">

**Author:** [@Ayush\_Agrahari](https://discuss.elastic.co/u/Ayush_Agrahari)\
**Replies:** 1\
**Last updated:** [September 29, 2020, 4:13pm UTC](https://discuss.elastic.co/t/heartbeat-auto-discovery-not-working-for-aws-elb/250302 "2020-09-29T16:13:20Z")

</div>

We are trying setup for AWS ELB Heartbeats. We got way to do in document https://www.elastic.co/guide/en/beats/heartbeat/current/configuration-autodiscover.html but when we tried the same then not getting any beats from …

---

## [Multiline filter failure](https://discuss.elastic.co/t/multiline-filter-failure/250354)

<div class="topic-metadata">

**Author:** [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Replies:** 2\
**Last updated:** [September 29, 2020, 3:01pm UTC](https://discuss.elastic.co/t/multiline-filter-failure/250354 "2020-09-29T15:01:36Z")

</div>

Hello, I am trying to parse a log file in multiline format and each new linestarts with the date : 28-Sep-2020 18:26:19.982 I tried to configure the config as below : filebeat.inputs: - type: log tags: \["PROD\_CATAL…

---

## [Elastic Agent and Ingest Manager Roadmap](https://discuss.elastic.co/t/elastic-agent-and-ingest-manager-roadmap/250292)

<div class="topic-metadata">

**Author:** [@RichardH](https://discuss.elastic.co/u/RichardH)\
**Replies:** 2\
**Last updated:** [September 29, 2020, 2:32pm UTC](https://discuss.elastic.co/t/elastic-agent-and-ingest-manager-roadmap/250292 "2020-09-29T14:32:52Z")

</div>

Hi All, I'm very excited about the new Elastic agent and Ingest Manager. How would I go about finding out roadmap information such as when they are expected to go GA? when is the functionality from other beats (e.g. Hea…

---

## [Azure Module Metricbeat](https://discuss.elastic.co/t/azure-module-metricbeat/249125)

<div class="topic-metadata">

**Author:** [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Replies:** 7\
**Last updated:** [September 29, 2020, 12:27pm UTC](https://discuss.elastic.co/t/azure-module-metricbeat/249125 "2020-09-29T12:27:21Z")

</div>

Hello, I hope you are doing well! I have ELK stack 7.9 running in an AKS alongside metricbeat (which is running as a daemonset). Among the modules configured for metricbeat, I have the azure module which is configured…

---

## [Logstash output not working and not throwing an error](https://discuss.elastic.co/t/logstash-output-not-working-and-not-throwing-an-error/250259)

<div class="topic-metadata">

**Author:** [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Replies:** 2\
**Last updated:** [September 29, 2020, 11:50am UTC](https://discuss.elastic.co/t/logstash-output-not-working-and-not-throwing-an-error/250259 "2020-09-29T11:50:48Z")

</div>

I have winlogbeat and audit beat working fine for logstash output. I cannot get logstash output from packetbeat (7.9.2 and 7.6.1) and no errors show up in the log. Totally stuck on this and is is a simple config. An…

---

## [Error index management Metricbeat to Logstash](https://discuss.elastic.co/t/error-index-management-metricbeat-to-logstash/249756)

<div class="topic-metadata">

**Author:** [@kennedy](https://discuss.elastic.co/u/kennedy)\
**Replies:** 5\
**Last updated:** [September 29, 2020, 8:59am UTC](https://discuss.elastic.co/t/error-index-management-metricbeat-to-logstash/249756 "2020-09-29T08:59:22Z")

</div>

I have configured metricbeat and feeding the logs to lagstash. But when im trying to use command : metricbeat setup the following error is coming: Exiting: Index management requested but the Elasticsearch output is not…

---

## [Packet beat not loading dashboard](https://discuss.elastic.co/t/packet-beat-not-loading-dashboard/250046)

<div class="topic-metadata">

**Author:** [@pankaj0172](https://discuss.elastic.co/u/pankaj0172)\
**Replies:** 2\
**Last updated:** [September 28, 2020, 5:12pm UTC](https://discuss.elastic.co/t/packet-beat-not-loading-dashboard/250046 "2020-09-28T17:12:24Z")

</div>

Hello, Can you help me here as I'm not able to load packet beat dashboard as below. any suggestions

---

## [Can't get text on a START\_OBJECT](https://discuss.elastic.co/t/cant-get-text-on-a-start-object/250010)

<div class="topic-metadata">

**Author:** [@jhansibalu](https://discuss.elastic.co/u/jhansibalu)\
**Replies:** 2\
**Last updated:** [September 28, 2020, 4:02pm UTC](https://discuss.elastic.co/t/cant-get-text-on-a-start-object/250010 "2020-09-28T16:02:23Z")

</div>

Hi I am sending logs to kibana using filebeat ,and I am facing below error while sending logs .Some of the events doesn't have host in raw data facinf error for that events. \[2020-09-24T09:20:40,591\]\[WARN \]\[logstash.out…

---

## [Kibana is not getting any logs](https://discuss.elastic.co/t/kibana-is-not-getting-any-logs/249803)

<div class="topic-metadata">

**Author:** [@Lusca\_lusca](https://discuss.elastic.co/u/Lusca_lusca)\
**Replies:** 2\
**Last updated:** [September 28, 2020, 2:24pm UTC](https://discuss.elastic.co/t/kibana-is-not-getting-any-logs/249803 "2020-09-28T14:24:41Z")

</div>

I am knew in ELK and I have not beeing able to see any logs in kibana. I need to get logs from PFSENSE firewall. I am getting the following error that might be the issue. nettec@Ubuntu-ELK:~$ sudo filebeat -e -d "\*"? 2…

---

## [Keep or restore message](https://discuss.elastic.co/t/keep-or-restore-message/250203)

<div class="topic-metadata">

**Author:** [@szandala](https://discuss.elastic.co/u/szandala)\
**Replies:** 0\
**Last updated:** [September 28, 2020, 2:06pm UTC](https://discuss.elastic.co/t/keep-or-restore-message/250203 "2020-09-28T14:06:30Z")

</div>

Greetings, I have in filebeat.yml filebeat.modules: - module: nginx access: var.paths: \["/var/log/nginx/access.log"\] error: var.paths: \["/var/log/nginx/error.log"\] - module: system syslog: var.paths: …

---

## [Packetbeat - Bug parsing http method](https://discuss.elastic.co/t/packetbeat-bug-parsing-http-method/250095)

<div class="topic-metadata">

**Author:** [@ebanashka](https://discuss.elastic.co/u/ebanashka)\
**Replies:** 0\
**Last updated:** [September 27, 2020, 4:29pm UTC](https://discuss.elastic.co/t/packetbeat-bug-parsing-http-method/250095 "2020-09-27T16:29:46Z")

</div>

Hi, I've stumbled upon a weird bug with http protocol method parsing. Upon feeding the following PCAP file https://drive.google.com/file/d/11DN4ZXbWE-W83VdwSRfJA04jBbOLMzs3/view?usp=sharing to the latest packetbeat one …

---

## [Filebeat aws readStringAndTrimDelimiter failed: context deadline exceeded in logs](https://discuss.elastic.co/t/filebeat-aws-readstringandtrimdelimiter-failed-context-deadline-exceeded-in-logs/249787)

<div class="topic-metadata">

**Author:** [@buzzdeee](https://discuss.elastic.co/u/buzzdeee)\
**Replies:** 2\
**Last updated:** [September 28, 2020, 12:54pm UTC](https://discuss.elastic.co/t/filebeat-aws-readstringandtrimdelimiter-failed-context-deadline-exceeded-in-logs/249787 "2020-09-28T12:54:29Z")

</div>

Hi, I'm running filebeat 7.9.0, sending logs to logstash 7.9.0 before they are handed over to ES 7.9.0. For filbeat, I have the AWS module configured to retrieve elblogs. It took me a while to get it setup properly, i.…

---

## [Extend Kafka Metricbeat module to add mbean missing](https://discuss.elastic.co/t/extend-kafka-metricbeat-module-to-add-mbean-missing/249779)

<div class="topic-metadata">

**Author:** [@stevizik](https://discuss.elastic.co/u/stevizik)\
**Replies:** 1\
**Last updated:** [September 28, 2020, 11:56am UTC](https://discuss.elastic.co/t/extend-kafka-metricbeat-module-to-add-mbean-missing/249779 "2020-09-28T11:56:08Z")

</div>

Hi community, i am using Kafka metricbeat module to get metrics from a Kafka cluster. Furthermore i have enabled Jolokia (JMX - HTTP Connector) to fetch metrics also from broker, consumer and producer. The solution wor…

---

## [Unable to send log files where newline character is not present](https://discuss.elastic.co/t/unable-to-send-log-files-where-newline-character-is-not-present/249871)

<div class="topic-metadata">

**Author:** [@anirbansaha](https://discuss.elastic.co/u/anirbansaha)\
**Replies:** 2\
**Last updated:** [September 28, 2020, 9:13am UTC](https://discuss.elastic.co/t/unable-to-send-log-files-where-newline-character-is-not-present/249871 "2020-09-28T09:13:18Z")

</div>

The log data which I am trying to send is a single line in file similar to the following \[{"empid" : "1", "empname": "anirban", "location":"India"}\] It is not having newline at the end. How to work for this? If this t…

---

## [Metricbeat AzureStack](https://discuss.elastic.co/t/metricbeat-azurestack/250149)

<div class="topic-metadata">

**Author:** [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Replies:** 0\
**Last updated:** [September 28, 2020, 8:51am UTC](https://discuss.elastic.co/t/metricbeat-azurestack/250149 "2020-09-28T08:51:19Z")

</div>

I tried to configure the metricbeat add module azure but the azure that I am monitoring the azure stack can?

---

## [Filebeat monitoring metrics sent bytes and throughput shown as 0](https://discuss.elastic.co/t/filebeat-monitoring-metrics-sent-bytes-and-throughput-shown-as-0/246215)

<div class="topic-metadata">

**Author:** [@daniel\_fablius](https://discuss.elastic.co/u/daniel_fablius)\
**Replies:** 5\
**Last updated:** [September 28, 2020, 8:04am UTC](https://discuss.elastic.co/t/filebeat-monitoring-metrics-sent-bytes-and-throughput-shown-as-0/246215 "2020-09-28T08:04:53Z")

</div>

Hi, when i loadtest and monitoring filebeat, i found out that the throughput (/s) and sent bytest shown as 0, while the Event (/s) showing some value and also the logs data is shown in Kibana. which then i assume, the co…

---

## [Filebeat.exe allocates too much memory on Windows server 2016](https://discuss.elastic.co/t/filebeat-exe-allocates-too-much-memory-on-windows-server-2016/249887)

<div class="topic-metadata">

**Author:** [@petertw6235](https://discuss.elastic.co/u/petertw6235)\
**Replies:** 1\
**Last updated:** [September 28, 2020, 3:46am UTC](https://discuss.elastic.co/t/filebeat-exe-allocates-too-much-memory-on-windows-server-2016/249887 "2020-09-28T03:46:57Z")

</div>

Dear Sir: We use filebeat to parse our log and send the data to kafka -\> logstash -\> elasticsearch. But we found the memory consumed by filebeat.exe was over 1.6Gb. We also check the filebeat log. {"monitoring": {"…

---

## [How can we get list of programs/softwares installed in a Windows server/endpoint?](https://discuss.elastic.co/t/how-can-we-get-list-of-programs-softwares-installed-in-a-windows-server-endpoint/249904)

<div class="topic-metadata">

**Author:** [@kelk](https://discuss.elastic.co/u/kelk)\
**Replies:** 0\
**Last updated:** [September 25, 2020, 5:16am UTC](https://discuss.elastic.co/t/how-can-we-get-list-of-programs-softwares-installed-in-a-windows-server-endpoint/249904 "2020-09-25T05:16:55Z")

</div>

After doing some basic tests, I couldn't find if the Windows client would put list of softwares into the Windows EventLog. Is there an option to run a script or execution in any of the beats on the target client? it co…

---

## [Please Help Newbie with default auditbeat YML did not find expected key?](https://discuss.elastic.co/t/please-help-newbie-with-default-auditbeat-yml-did-not-find-expected-key/250101)

<div class="topic-metadata">

**Author:** [@tonysue](https://discuss.elastic.co/u/tonysue)\
**Replies:** 5\
**Last updated:** [September 28, 2020, 1:11am UTC](https://discuss.elastic.co/t/please-help-newbie-with-default-auditbeat-yml-did-not-find-expected-key/250101 "2020-09-28T01:11:19Z")

</div>

Default auditbeat YML has the following error prevented from setup and execute. PS C:\\Program Files\\auditbeat\> ./auditbeat setup ./auditbeat -e ./auditbeat : Exiting: error loading config file: yaml: line 102: did not…

---

## [Httpjson Crawler is not compatible with the --once option](https://discuss.elastic.co/t/httpjson-crawler-is-not-compatible-with-the-once-option/250077)

<div class="topic-metadata">

**Author:** [@XhstormR](https://discuss.elastic.co/u/XhstormR)\
**Replies:** 0\
**Last updated:** [September 27, 2020, 10:31am UTC](https://discuss.elastic.co/t/httpjson-crawler-is-not-compatible-with-the-once-option/250077 "2020-09-27T10:31:24Z")

</div>

I use filebeat's httpjson inputs to export elasticsearch index data, D:\\Download\\filebeat-7.9.2-windows-x86\_64\>filebeat.exe run -e -c 2.yml 2020-09-27T18:24:01.195+0800 INFO \[httpjson\] httpjson/input.go:471 …

---

## [Beats direction: ingest pipeline vs. local input modifications](https://discuss.elastic.co/t/beats-direction-ingest-pipeline-vs-local-input-modifications/250063)

<div class="topic-metadata">

**Author:** [@jessvin.thomas](https://discuss.elastic.co/u/jessvin.thomas)\
**Replies:** 0\
**Last updated:** [September 26, 2020, 4:35pm UTC](https://discuss.elastic.co/t/beats-direction-ingest-pipeline-vs-local-input-modifications/250063 "2020-09-26T16:35:06Z")

</div>

When using a filebeat module, some data manipulations seem to be done in two places: In an ingest pipeline in filebeat at input using filebeat/module/\[modulename\]/\[module-sub\]/config/...yml. This seems to be opposite …

---

## [Unable to run python tests - No module named beat.beat](https://discuss.elastic.co/t/unable-to-run-python-tests-no-module-named-beat-beat/249949)

<div class="topic-metadata">

**Author:** [@ebanashka](https://discuss.elastic.co/u/ebanashka)\
**Replies:** 3\
**Last updated:** [September 26, 2020, 9:54am UTC](https://discuss.elastic.co/t/unable-to-run-python-tests-no-module-named-beat-beat/249949 "2020-09-26T09:54:51Z")

</div>

I am unable to run python tests for packetbeat or any other beats. Here's what I've done: in the packetbeat dir i ran make python-dev then navigated to the tests/system folder and ran nosetests -x -v. Getting the fol…

---

## [Monitoring network connectivity by ping](https://discuss.elastic.co/t/monitoring-network-connectivity-by-ping/250038)

<div class="topic-metadata">

**Author:** [@pankaj0172](https://discuss.elastic.co/u/pankaj0172)\
**Replies:** 1\
**Last updated:** [September 26, 2020, 6:00am UTC](https://discuss.elastic.co/t/monitoring-network-connectivity-by-ping/250038 "2020-09-26T06:00:06Z")

</div>

Hi, Can we monitor network connectivity through any beat if yes then which one should I use for it. Basically I'm trying to find at what time my machine dropped network or ping or network drop packets..

---

## [Can we see how many users are active on the terminal server through Metricbeat](https://discuss.elastic.co/t/can-we-see-how-many-users-are-active-on-the-terminal-server-through-metricbeat/249453)

<div class="topic-metadata">

**Author:** [@pankaj0172](https://discuss.elastic.co/u/pankaj0172)\
**Replies:** 2\
**Last updated:** [September 25, 2020, 4:10pm UTC](https://discuss.elastic.co/t/can-we-see-how-many-users-are-active-on-the-terminal-server-through-metricbeat/249453 "2020-09-25T16:10:23Z")

</div>

Hi, Can someone please let me know what does meant by user in Cpu usage graph? Can we see how many users are active on terminal server through metricbeat or other beats?

---

## [Filebeat harvester open file count increasing when Logstash output to Elasticsearch Fails](https://discuss.elastic.co/t/filebeat-harvester-open-file-count-increasing-when-logstash-output-to-elasticsearch-fails/249892)

<div class="topic-metadata">

**Author:** [@arijitb](https://discuss.elastic.co/u/arijitb)\
**Replies:** 2\
**Last updated:** [September 25, 2020, 3:34pm UTC](https://discuss.elastic.co/t/filebeat-harvester-open-file-count-increasing-when-logstash-output-to-elasticsearch-fails/249892 "2020-09-25T15:34:38Z")

</div>

We have a log streaming pipeline setup with filebeat -\> logstash -\> Elasticsearch. Recently, our ES cluster started throwing 429 exceptions for all traffic and we observed that eventually logs stopped streaming to Logst…

---

## [Filebeat with syslog - error index](https://discuss.elastic.co/t/filebeat-with-syslog-error-index/249419)

<div class="topic-metadata">

**Author:** [@Paulogbr](https://discuss.elastic.co/u/Paulogbr)\
**Replies:** 3\
**Last updated:** [September 25, 2020, 3:26pm UTC](https://discuss.elastic.co/t/filebeat-with-syslog-error-index/249419 "2020-09-25T15:26:03Z")

</div>

Hello Team, I was using Logstash in my lab to input data from syslog UDP 5140. Now I tried Filebeat, but the data don't index. I follow this example: My filebeat.yml : filebeat.inputs: type: syslog enabled: t…

---

## [\[FILEBEAT\] Insert timestamp inside of logfile name](https://discuss.elastic.co/t/filebeat-insert-timestamp-inside-of-logfile-name/249843)

<div class="topic-metadata">

**Author:** [@mstojanovic](https://discuss.elastic.co/u/mstojanovic)\
**Replies:** 2\
**Last updated:** [September 25, 2020, 3:15pm UTC](https://discuss.elastic.co/t/filebeat-insert-timestamp-inside-of-logfile-name/249843 "2020-09-25T15:15:50Z")

</div>

Hello, I want to gather logs from a specific location. As the log's name is changed each day, I would like to insert timestamp in log file name. By doing so, each new day, the correct log name will be parsed by filebeat…

---

## [MetricBeat visulization not showing all data(Need urgent help)](https://discuss.elastic.co/t/metricbeat-visulization-not-showing-all-data-need-urgent-help/249895)

<div class="topic-metadata">

**Author:** [@Cute\_Baby\_Inayat\_jar](https://discuss.elastic.co/u/Cute_Baby_Inayat_jar)\
**Replies:** 1\
**Last updated:** [September 25, 2020, 3:13pm UTC](https://discuss.elastic.co/t/metricbeat-visulization-not-showing-all-data-need-urgent-help/249895 "2020-09-25T15:13:30Z")

</div>

Hi ALl, I am new in metricbeat. In my project we are sending metricbeat data to kafka topic and then from logstash pipeline we are sending to index metricbeat-\* in elasticsearch. In index data is coming properly for fil…

---

## [Filebeat.yml inputs vs module](https://discuss.elastic.co/t/filebeat-yml-inputs-vs-module/249768)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 1\
**Last updated:** [September 25, 2020, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-yml-inputs-vs-module/249768 "2020-09-25T14:31:09Z")

</div>

Hi, for sending elasticsearch logs to elasticsearch i am using filebeat with enabled module "elasticsearch". As far as I understod while using a module I do not need to configure the paths in the inputs inside filebeat…

---

## [Filebeat IIS Module](https://discuss.elastic.co/t/filebeat-iis-module/249717)

<div class="topic-metadata">

**Author:** [@MoeAly](https://discuss.elastic.co/u/MoeAly)\
**Replies:** 1\
**Last updated:** [September 25, 2020, 2:27pm UTC](https://discuss.elastic.co/t/filebeat-iis-module/249717 "2020-09-25T14:27:48Z")

</div>

Hello Everyone, I'm using Filebeat's iis module to ingest IIS logs into ES. All is going well and I'm able to successfully ingest my logs into ES. However, there is an iis data field called x-forwarded-for that is not…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=208)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=210)
