# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=210

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 211

---

## [Filebeat output to Kafka cluster with LDAP Authentication](https://discuss.elastic.co/t/filebeat-output-to-kafka-cluster-with-ldap-authentication/249682)

<div class="topic-metadata">

**Author:** [@agiorgi](https://discuss.elastic.co/u/agiorgi)\
**Replies:** 1\
**Last updated:** [September 25, 2020, 2:13pm UTC](https://discuss.elastic.co/t/filebeat-output-to-kafka-cluster-with-ldap-authentication/249682 "2020-09-25T14:13:32Z")

</div>

Hi there! this might look like a silly question but i'd like to be sure... I'm looking into configuring Filebeat to output to a Kafka cluster which is using SASL LDAP (AD) as authentication mode... I can't understand …

---

## [Filebeat Fortinet module not working](https://discuss.elastic.co/t/filebeat-fortinet-module-not-working/247063)

<div class="topic-metadata">

**Author:** [@bornatalebi](https://discuss.elastic.co/u/bornatalebi)\
**Replies:** 3\
**Last updated:** [September 1, 2020, 9:51am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-not-working/247063 "2020-09-01T09:51:15Z")

</div>

I have a FortiGate 200E firewall and I can see the logs reaching the filebeat machine (using tcpdump listening on port 9004). but filebeat doesn't process them ( no logs in discover tab the output of journalctl -xeu file…

---

## [Unexpected format of ES document generated by FileBeats](https://discuss.elastic.co/t/unexpected-format-of-es-document-generated-by-filebeats/249834)

<div class="topic-metadata">

**Author:** [@Pablo\_Albertengo](https://discuss.elastic.co/u/Pablo_Albertengo)\
**Replies:** 1\
**Last updated:** [September 25, 2020, 12:36pm UTC](https://discuss.elastic.co/t/unexpected-format-of-es-document-generated-by-filebeats/249834 "2020-09-25T12:36:36Z")

</div>

Hi guys! I'm starting to test with FileBeats and I can't generate documents in ElasticSearch that suit what I want. This is my scenario. I want to send some audit information to ElasticSearch from my Java application. …

---

## [Minimum Privilege Required for Beats](https://discuss.elastic.co/t/minimum-privilege-required-for-beats/247729)

<div class="topic-metadata">

**Author:** [@hpicass0](https://discuss.elastic.co/u/hpicass0)\
**Replies:** 6\
**Last updated:** [September 25, 2020, 8:37am UTC](https://discuss.elastic.co/t/minimum-privilege-required-for-beats/247729 "2020-09-25T08:37:40Z")

</div>

Hi, Given than I need to set the API key or username/password pair in the beats config (and they might get exposed). I need to set the privilege to the absolute minimum for the relevant account I've went over the roles…

---

## [Problem about using modules parsing log files while having JSON files](https://discuss.elastic.co/t/problem-about-using-modules-parsing-log-files-while-having-json-files/249050)

<div class="topic-metadata">

**Author:** [@sougou](https://discuss.elastic.co/u/sougou)\
**Replies:** 3\
**Last updated:** [September 24, 2020, 10:28am UTC](https://discuss.elastic.co/t/problem-about-using-modules-parsing-log-files-while-having-json-files/249050 "2020-09-24T10:28:05Z")

</div>

Hi, My architecture is as follows: Filebeat -\> Logstash -\> Elasticsearch I passed a number of files to filebeat. Some of which uses some modules. These modules have been given unique var.paths in their module configur…

---

## [Metricbeat kubernetes module collection 401](https://discuss.elastic.co/t/metricbeat-kubernetes-module-collection-401/246904)

<div class="topic-metadata">

**Author:** [@ZMMWMY](https://discuss.elastic.co/u/ZMMWMY)\
**Replies:** 3\
**Last updated:** [September 25, 2020, 4:28am UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-module-collection-401/246904 "2020-09-25T04:28:01Z")

</div>

I can collect node data, but k8s can't the configuration - module: kubernetes metricsets: - node - system - pod - container - volume period: 10s host: ${NODE\_NAME} hosts: \["https://${NODE\_IP…

---

## [Winlogbeat: Problem to get fields from nested winevent message](https://discuss.elastic.co/t/winlogbeat-problem-to-get-fields-from-nested-winevent-message/249712)

<div class="topic-metadata">

**Author:** [@Pedro\_77](https://discuss.elastic.co/u/Pedro_77)\
**Replies:** 4\
**Last updated:** [September 24, 2020, 10:47pm UTC](https://discuss.elastic.co/t/winlogbeat-problem-to-get-fields-from-nested-winevent-message/249712 "2020-09-24T22:47:00Z")

</div>

Hello I have problem with winlogbeat (7.9.1) I'm trying to get fields which are "nested" in message field: for example: "message": Endpoint: xxxyy211\\n Endpoint IP: 10.1.1.x\\n …

---

## [CPU utilization showing differently in Dashboard](https://discuss.elastic.co/t/cpu-utilization-showing-differently-in-dashboard/248958)

<div class="topic-metadata">

**Author:** [@pankaj0172](https://discuss.elastic.co/u/pankaj0172)\
**Replies:** 0\
**Last updated:** [September 17, 2020, 10:11am UTC](https://discuss.elastic.co/t/cpu-utilization-showing-differently-in-dashboard/248958 "2020-09-17T10:11:22Z")

</div>

Hi, In Metricbeat dashboard, Top10 cpu utilization showing different as below.. But when I click the host overview it's showing and host overview showing only 50% but disk utilization showing also in red, is it cou…

---

## [Winlogbeat doesnt send windows defender events](https://discuss.elastic.co/t/winlogbeat-doesnt-send-windows-defender-events/249689)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 2\
**Last updated:** [September 24, 2020, 4:54pm UTC](https://discuss.elastic.co/t/winlogbeat-doesnt-send-windows-defender-events/249689 "2020-09-24T16:54:40Z")

</div>

is there any way I can ship windows defender even to Elasticsearch ? I cannot see any Windows defender related events in Elasticsearch. Can anyone help me on this ?

---

## [Filebeat to Logstash split message log to different tables](https://discuss.elastic.co/t/filebeat-to-logstash-split-message-log-to-different-tables/249840)

<div class="topic-metadata">

**Author:** [@cedrikson](https://discuss.elastic.co/u/cedrikson)\
**Replies:** 0\
**Last updated:** [September 24, 2020, 2:55pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-split-message-log-to-different-tables/249840 "2020-09-24T14:55:54Z")

</div>

Hello guys! Please can someone help me..... I look for a solution that i get my filebeat logs in a perfekt readable log..... This is how my log look like....but i like different columns (Ip,User) here everything stand…

---

## [Filebeat googlecloud module not loading service account](https://discuss.elastic.co/t/filebeat-googlecloud-module-not-loading-service-account/248736)

<div class="topic-metadata">

**Author:** [@David\_Hurley](https://discuss.elastic.co/u/David_Hurley)\
**Replies:** 4\
**Last updated:** [September 24, 2020, 2:19pm UTC](https://discuss.elastic.co/t/filebeat-googlecloud-module-not-loading-service-account/248736 "2020-09-24T14:19:42Z")

</div>

I am running into an issue where filebeat is unable to load my gcp service account keyfile. This is my googlecloud config file - - module: googlecloud audit: enabled: true var.project\_id: my-proj…

---

## [Docker logs in metrics](https://discuss.elastic.co/t/docker-logs-in-metrics/249556)

<div class="topic-metadata">

**Author:** [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Replies:** 2\
**Last updated:** [September 24, 2020, 12:25pm UTC](https://discuss.elastic.co/t/docker-logs-in-metrics/249556 "2020-09-24T12:25:29Z")

</div>

Hi there. I set up Metricbeat in my Rancher environment. I set it up with module docker so far. In tab metrics in kibana I can see metrics on docker containers but can not see logs, only this: docker.memory failed t…

---

## [Old evtx-File with winlogbeat read in](https://discuss.elastic.co/t/old-evtx-file-with-winlogbeat-read-in/249636)

<div class="topic-metadata">

**Author:** [@PatNae](https://discuss.elastic.co/u/PatNae)\
**Replies:** 2\
**Last updated:** [September 24, 2020, 9:44am UTC](https://discuss.elastic.co/t/old-evtx-file-with-winlogbeat-read-in/249636 "2020-09-24T09:44:43Z")

</div>

how can i read an old logfile with winlogbeat. I have seen the following: winlogbeat.event\_logs: name: ${EVTX\_FILE} no\_more\_events: stop But what exactly do I have to write in name/path? Where must my file be locate…

---

## [Filebeat pipeline for elasticsearch slowlog not indexing/parsing slowlog\_took (slowlog.duration)](https://discuss.elastic.co/t/filebeat-pipeline-for-elasticsearch-slowlog-not-indexing-parsing-slowlog-took-slowlog-duration/249777)

<div class="topic-metadata">

**Author:** [@Jiri\_Petak](https://discuss.elastic.co/u/Jiri_Petak)\
**Replies:** 0\
**Last updated:** [September 24, 2020, 8:57am UTC](https://discuss.elastic.co/t/filebeat-pipeline-for-elasticsearch-slowlog-not-indexing-parsing-slowlog-took-slowlog-duration/249777 "2020-09-24T08:57:57Z")

</div>

Hi, i have a question about filebeat elasticsearch module and it’s slowlog pipeline part. I found that in filebeat-7.7.0-elasticsearch-slowlog-pipeline-json which is default pipeline in fb 7.7.0 version, there is parse…

---

## [Unable to authenticate user for REST request](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/249118)

<div class="topic-metadata">

**Author:** [@bhavikdhoot](https://discuss.elastic.co/u/bhavikdhoot)\
**Replies:** 4\
**Last updated:** [September 24, 2020, 5:56am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/249118 "2020-09-24T05:56:15Z")

</div>

Hi, I'm trying to connect to Elasticsearch through FileBeats using the following config in my filebeat.yml. output.elasticsearch: Array of hosts to connect to. #hosts: \["localhost:9200"\] hosts: \["server1:9600","serve…

---

## [Fliebeats + apache files](https://discuss.elastic.co/t/fliebeats-apache-files/249583)

<div class="topic-metadata">

**Author:** [@vsekvsek](https://discuss.elastic.co/u/vsekvsek)\
**Replies:** 2\
**Last updated:** [September 23, 2020, 8:18pm UTC](https://discuss.elastic.co/t/fliebeats-apache-files/249583 "2020-09-23T20:18:00Z")

</div>

I am trying to load some local log files into filebeat and get this error. .\\filebeat.exe setup -e 2020-09-22T13:28:52.813-0700 ERROR \[esclientleg\] eslegclient/connection.go:261 error connecting to Elasticsear…

---

## [Log message encoding of \\n for multiline output](https://discuss.elastic.co/t/log-message-encoding-of-n-for-multiline-output/249687)

<div class="topic-metadata">

**Author:** [@kbrisso](https://discuss.elastic.co/u/kbrisso)\
**Replies:** 0\
**Last updated:** [September 23, 2020, 5:35pm UTC](https://discuss.elastic.co/t/log-message-encoding-of-n-for-multiline-output/249687 "2020-09-23T17:35:21Z")

</div>

Hello All- In my messages, some of the log messages actually have \\n in the log output itself along with other random characters like XML tags. Is there a way to encode \\n in file beat before shipping to log stash so th…

---

## [ERROR Index management Winlogbeat 7.9.0](https://discuss.elastic.co/t/error-index-management-winlogbeat-7-9-0/249229)

<div class="topic-metadata">

**Author:** [@zombietek](https://discuss.elastic.co/u/zombietek)\
**Replies:** 9\
**Last updated:** [September 23, 2020, 4:10pm UTC](https://discuss.elastic.co/t/error-index-management-winlogbeat-7-9-0/249229 "2020-09-23T16:10:16Z")

</div>

Hi, I saw this old thread(https://discuss.elastic.co/t/error-index-management-filebeat-to-logstash/218849) though it was for filebeat and my issue is for winlogbeat, I'll give it a try. I have winlogbeat version 7.9.0 …

---

## [Metricbeat couchdb module crash with CouchDB 3.x](https://discuss.elastic.co/t/metricbeat-couchdb-module-crash-with-couchdb-3-x/247789)

<div class="topic-metadata">

**Author:** [@vmwiz](https://discuss.elastic.co/u/vmwiz)\
**Replies:** 1\
**Last updated:** [September 23, 2020, 9:41am UTC](https://discuss.elastic.co/t/metricbeat-couchdb-module-crash-with-couchdb-3-x/247789 "2020-09-23T09:41:30Z")

</div>

The metricbeat module for CouchDB crash when targetting CouchDB 3.1 Metricbeat version: 7.8.1 CouchDB version: 3.1.0 (6 nodes cluster) OS: RedHat 7.8 # /etc/metricbeat/modules.d/couchdb.yaml - module: couchdb metri…

---

## [Want to enable NGINX module in our filebeat to get the kubernetes nginx/ingress\_controller logs](https://discuss.elastic.co/t/want-to-enable-nginx-module-in-our-filebeat-to-get-the-kubernetes-nginx-ingress-controller-logs/248945)

<div class="topic-metadata">

**Author:** [@rahulsrivastava71](https://discuss.elastic.co/u/rahulsrivastava71)\
**Replies:** 2\
**Last updated:** [September 23, 2020, 8:04am UTC](https://discuss.elastic.co/t/want-to-enable-nginx-module-in-our-filebeat-to-get-the-kubernetes-nginx-ingress-controller-logs/248945 "2020-09-23T08:04:21Z")

</div>

we are using filebeat as our log shipper and running it as a docker image , we want to enable the NGINX module so that we can get the logs in proper format as currently we get the logs in the form as a bunch of lines, an…

---

## [Winlogbeat 7.9 removed a field?](https://discuss.elastic.co/t/winlogbeat-7-9-removed-a-field/249588)

<div class="topic-metadata">

**Author:** [@ted1621](https://discuss.elastic.co/u/ted1621)\
**Replies:** 1\
**Last updated:** [September 22, 2020, 11:11pm UTC](https://discuss.elastic.co/t/winlogbeat-7-9-removed-a-field/249588 "2020-09-22T23:11:33Z")

</div>

I just completed upgrading my winlogbeat versions to 7.9.1. As part of this upgrade it now appears that my winlogbeat agent is no longer parsing this particular event type? This event type is part a sysmon job that i…

---

## [Winlogbeat processor for powershell module](https://discuss.elastic.co/t/winlogbeat-processor-for-powershell-module/249390)

<div class="topic-metadata">

**Author:** [@v.n](https://discuss.elastic.co/u/v.n)\
**Replies:** 2\
**Last updated:** [September 22, 2020, 8:03pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-for-powershell-module/249390 "2020-09-22T20:03:18Z")

</div>

This page shows how to enable modules for security and sysmon but nothing for powershell. winlogbeat.event\_logs: name: ForwardedEvents tags: \[forwarded\] processors: script: when.equals.winlog.channel: Security l…

---

## [Latest released version (v7.9.1) python environment fails](https://discuss.elastic.co/t/latest-released-version-v7-9-1-python-environment-fails/249568)

<div class="topic-metadata">

**Author:** [@Sean\_Houghton](https://discuss.elastic.co/u/Sean_Houghton)\
**Replies:** 1\
**Last updated:** [September 22, 2020, 6:00pm UTC](https://discuss.elastic.co/t/latest-released-version-v7-9-1-python-environment-fails/249568 "2020-09-22T18:00:47Z")

</div>

When using the latest pinned version (as everyone should be doing in production) the python-dev makefile target fails with setuptools errors ImportError: cannot import name 'Feature' from 'setuptools' (/private/tmp/…

---

## [Yum install filebeat oss version fails](https://discuss.elastic.co/t/yum-install-filebeat-oss-version-fails/249529)

<div class="topic-metadata">

**Author:** [@xachman](https://discuss.elastic.co/u/xachman)\
**Replies:** 1\
**Last updated:** [September 22, 2020, 1:29pm UTC](https://discuss.elastic.co/t/yum-install-filebeat-oss-version-fails/249529 "2020-09-22T13:29:08Z")

</div>

When installing filebeat oss version I get the error. The non oss version installed fine. filebeat-7.9.1-x86\_64.rpm FAILED https://artifacts.elastic.co/packages/oss-7.x/yum/7.9.1/filebeat-7.9.1-x86\_64.rpm: \[Errno …

---

## [Creating New Indices using Functionbeat](https://discuss.elastic.co/t/creating-new-indices-using-functionbeat/246177)

<div class="topic-metadata">

**Author:** [@joabrb22](https://discuss.elastic.co/u/joabrb22)\
**Replies:** 3\
**Last updated:** [September 22, 2020, 12:39pm UTC](https://discuss.elastic.co/t/creating-new-indices-using-functionbeat/246177 "2020-09-22T12:39:52Z")

</div>

I have searched across the internet after having read the documentation, but I cannot seem to find the answer to my question. I want to create multiple new indicesfor Functionbeat, besides the default. I created a new i…

---

## [How to push winlogbeat logs to the kibana manually](https://discuss.elastic.co/t/how-to-push-winlogbeat-logs-to-the-kibana-manually/249467)

<div class="topic-metadata">

**Author:** [@neelu\_patel](https://discuss.elastic.co/u/neelu_patel)\
**Replies:** 1\
**Last updated:** [September 22, 2020, 12:36pm UTC](https://discuss.elastic.co/t/how-to-push-winlogbeat-logs-to-the-kibana-manually/249467 "2020-09-22T12:36:03Z")

</div>

is anyone know about , how to push winlogbeat logs to the kibana manually?

---

## [Beats stopped working after enabled TLS/SSL on Elasticsearch and Kibana](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 6\
**Last updated:** [September 22, 2020, 10:30am UTC](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354 "2020-09-22T10:30:16Z")

</div>

Winlogbeat,packetbeat,auditbeat stopped working right after enabling TLS/SSL between Elasticsearch and Kibana. Attached image is my configuration for winlogbeat.yml. I tried putting https also but it is not working. Do I…

---

## [Filebeat custom module pipeline failed](https://discuss.elastic.co/t/filebeat-custom-module-pipeline-failed/249297)

<div class="topic-metadata">

**Author:** [@icaruswu](https://discuss.elastic.co/u/icaruswu)\
**Replies:** 4\
**Last updated:** [September 22, 2020, 6:51am UTC](https://discuss.elastic.co/t/filebeat-custom-module-pipeline-failed/249297 "2020-09-22T06:51:07Z")

</div>

I build my own filebeat and I created a 'pipeline.yml' in the ingest directory. And I'm surely changed the ingest\_pipeline PATH in the mainfest.yml. But when I executed the filebeat but the pipeline processors not worke…

---

## [From Logstash to Filebeat (Suricata module) - Substring Search No Longer Works](https://discuss.elastic.co/t/from-logstash-to-filebeat-suricata-module-substring-search-no-longer-works/249448)

<div class="topic-metadata">

**Author:** [@jason26](https://discuss.elastic.co/u/jason26)\
**Replies:** 0\
**Last updated:** [September 22, 2020, 5:25am UTC](https://discuss.elastic.co/t/from-logstash-to-filebeat-suricata-module-substring-search-no-longer-works/249448 "2020-09-22T05:25:19Z")

</div>

I'm testing a move from Logstash to Filebeat with the Suricata plugin and I'm noticing that substring searching no longer works. For example, when I used Logstash (no custom template, just defaults, but JSON codec), I c…

---

## [Problem searching Filebeat netflow module logs](https://discuss.elastic.co/t/problem-searching-filebeat-netflow-module-logs/249166)

<div class="topic-metadata">

**Author:** [@Sylancer](https://discuss.elastic.co/u/Sylancer)\
**Replies:** 14\
**Last updated:** [September 22, 2020, 4:19am UTC](https://discuss.elastic.co/t/problem-searching-filebeat-netflow-module-logs/249166 "2020-09-22T04:19:07Z")

</div>

I'm really sorry if this isn't the right tag for this, I'm just not sure where to start. I recently installed Filebeat, enabled the netflow module and pointed my Edgerouter X to my machine running the Elastic stack. I'm…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=209)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=211)
