# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=211

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 212

---

## [Multi index in filbeat Logstash output](https://discuss.elastic.co/t/multi-index-in-filbeat-logstash-output/249412)

<div class="topic-metadata">

**Author:** [@ganta\_chandra\_teja](https://discuss.elastic.co/u/ganta_chandra_teja)\
**Replies:** 0\
**Last updated:** [September 21, 2020, 7:03pm UTC](https://discuss.elastic.co/t/multi-index-in-filbeat-logstash-output/249412 "2020-09-21T19:03:36Z")

</div>

Tried multi index in filebeat 7.5.2 but didn't work. Please suggest. filebeat.inputs: - type: log enabled: true paths: - /app/logs/ldapsync/dnp\_ldap\_interface\_error.log processors: - dissect: tokenize…

---

## [Winlogbeat 7.9 pipeline delay](https://discuss.elastic.co/t/winlogbeat-7-9-pipeline-delay/249405)

<div class="topic-metadata">

**Author:** [@AleksandrN](https://discuss.elastic.co/u/AleksandrN)\
**Replies:** 0\
**Last updated:** [September 21, 2020, 6:12pm UTC](https://discuss.elastic.co/t/winlogbeat-7-9-pipeline-delay/249405 "2020-09-21T18:12:15Z")

</div>

Hello everyone! I have a delay for docs going throught my pipeline and asked about it here https://discuss.elastic.co/t/pipeline-delay-7-9/249148 In conclusion, it turns out that the most suspiciouse point of a pipelin…

---

## [Multiline config for continuation with empty lines interspersed](https://discuss.elastic.co/t/multiline-config-for-continuation-with-empty-lines-interspersed/249365)

<div class="topic-metadata">

**Author:** [@kornexl](https://discuss.elastic.co/u/kornexl)\
**Replies:** 2\
**Last updated:** [September 21, 2020, 2:03pm UTC](https://discuss.elastic.co/t/multiline-config-for-continuation-with-empty-lines-interspersed/249365 "2020-09-21T14:03:21Z")

</div>

I want to use multiline feature for messages in error.log. The error lines to match are mixed with empty lines Error cccccc continuation error line The default multiline pattern ( ^\[\[:space:\]\] ) for this type of cont…

---

## [Autodiscover kubernetes pod with multiple containers](https://discuss.elastic.co/t/autodiscover-kubernetes-pod-with-multiple-containers/248943)

<div class="topic-metadata">

**Author:** [@fridberg](https://discuss.elastic.co/u/fridberg)\
**Replies:** 2\
**Last updated:** [September 21, 2020, 10:54am UTC](https://discuss.elastic.co/t/autodiscover-kubernetes-pod-with-multiple-containers/248943 "2020-09-21T10:54:21Z")

</div>

I have been trying to use the autodiscover kubernetes provider to retrieve metrics from prometheus endpoints on my pods. In each pod there is also a cloudsql-proxy container, which should not be scraped. The problem here…

---

## [Ping remote services for availability and log results to Elasticsearch or send to Logstash](https://discuss.elastic.co/t/ping-remote-services-for-availability-and-log-results-to-elasticsearch-or-send-to-logstash/249273)

<div class="topic-metadata">

**Author:** [@Armen\_Khachikyan](https://discuss.elastic.co/u/Armen_Khachikyan)\
**Replies:** 2\
**Last updated:** [September 21, 2020, 10:09am UTC](https://discuss.elastic.co/t/ping-remote-services-for-availability-and-log-results-to-elasticsearch-or-send-to-logstash/249273 "2020-09-21T10:09:44Z")

</div>

have ELK server, and sending Heartbeats to server. I added an monitor in monitors.d directory, added setup.dashboards.enabled: true line in heartbeat.yml file, but after restarting heartbeat service, service working 2-…

---

## [Filebeat - unknown index name/nginx log formatting](https://discuss.elastic.co/t/filebeat-unknown-index-name-nginx-log-formatting/248828)

<div class="topic-metadata">

**Author:** [@vinci](https://discuss.elastic.co/u/vinci)\
**Replies:** 3\
**Last updated:** [September 21, 2020, 7:28am UTC](https://discuss.elastic.co/t/filebeat-unknown-index-name-nginx-log-formatting/248828 "2020-09-21T07:28:59Z")

</div>

Hello, I have the following configuration file for filebeat: # filebeat.yml for harvesting docker logfiles #=========================== Filebeat inputs ============================= filebeat.inputs: - t…

---

## [Where will I enter from?](https://discuss.elastic.co/t/where-will-i-enter-from/249204)

<div class="topic-metadata">

**Author:** [@falanofilano](https://discuss.elastic.co/u/falanofilano)\
**Replies:** 2\
**Last updated:** [September 20, 2020, 9:26pm UTC](https://discuss.elastic.co/t/where-will-i-enter-from/249204 "2020-09-20T21:26:37Z")

</div>

I installed heartbeat on CentOS 7 with the yum package manager. It is running smoothly now. Where or from which port can I access the administration panel?

---

## [Journalbeat: Environment variable in config crashes service](https://discuss.elastic.co/t/journalbeat-environment-variable-in-config-crashes-service/249091)

<div class="topic-metadata">

**Author:** [@alpi-ua](https://discuss.elastic.co/u/alpi-ua)\
**Replies:** 2\
**Last updated:** [September 20, 2020, 9:20pm UTC](https://discuss.elastic.co/t/journalbeat-environment-variable-in-config-crashes-service/249091 "2020-09-20T21:20:31Z")

</div>

Hello. Please, help with the issue. Following this reference, I've added following to my config: fields\_under\_root: true fields: hwkey: ${HWKEY} And after restarting the service, constantly receiving: systemctl r…

---

## [Heartbeat (webservice response)](https://discuss.elastic.co/t/heartbeat-webservice-response/249271)

<div class="topic-metadata">

**Author:** [@mustafa.husny](https://discuss.elastic.co/u/mustafa.husny)\
**Replies:** 0\
**Last updated:** [September 20, 2020, 6:22pm UTC](https://discuss.elastic.co/t/heartbeat-webservice-response/249271 "2020-09-20T18:22:18Z")

</div>

First my ELK stack version is 7.6.2 My approach is save the heartbeat logs and search in the body.content filed for status code , so i made the following config type: http #SOAP/HTTP id: my-webservice name: my-webs…

---

## [Setting up Filebeats with the IIS module to parse IIS logs](https://discuss.elastic.co/t/setting-up-filebeats-with-the-iis-module-to-parse-iis-logs/248978)

<div class="topic-metadata">

**Author:** [@pheathers](https://discuss.elastic.co/u/pheathers)\
**Replies:** 1\
**Last updated:** [September 18, 2020, 10:05pm UTC](https://discuss.elastic.co/t/setting-up-filebeats-with-the-iis-module-to-parse-iis-logs/248978 "2020-09-18T22:05:31Z")

</div>

Hi. I'm trying to setup the Filebeats IIS module (link) so I can display IIS logs (version 10) in the canned Kibana Dashboards, however I get errors in Logstash when parsing the messages preventing them from display cor…

---

## [Every time read file from beginning when modified](https://discuss.elastic.co/t/every-time-read-file-from-beginning-when-modified/249030)

<div class="topic-metadata">

**Author:** [@xyz2](https://discuss.elastic.co/u/xyz2)\
**Replies:** 2\
**Last updated:** [September 18, 2020, 9:25pm UTC](https://discuss.elastic.co/t/every-time-read-file-from-beginning-when-modified/249030 "2020-09-18T21:25:41Z")

</div>

HI, I have a use case where a file is replaced with additional details periodically. I was using filebeat to do that but I see filebeat maintains an offset and considers it as same file and starts reading from the line …

---

## [Filebeat + squid module GeoIP](https://discuss.elastic.co/t/filebeat-squid-module-geoip/249176)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 0\
**Last updated:** [September 18, 2020, 8:58pm UTC](https://discuss.elastic.co/t/filebeat-squid-module-geoip/249176 "2020-09-18T20:58:44Z")

</div>

Hi there, I´m trying to setup GeoIPs from internal, private IP addresses but no luck. Follow my filebeat.yml processors: - add\_host\_metadata: netinfo.enabled: true Geo: location: -23.499294, -46.…

---

## [Module: kubernetes, metricset: container - is missing exported fields from docs (such as status?)](https://discuss.elastic.co/t/module-kubernetes-metricset-container-is-missing-exported-fields-from-docs-such-as-status/248456)

<div class="topic-metadata">

**Author:** [@Ilai\_Fallach](https://discuss.elastic.co/u/Ilai_Fallach)\
**Replies:** 2\
**Last updated:** [September 18, 2020, 4:29pm UTC](https://discuss.elastic.co/t/module-kubernetes-metricset-container-is-missing-exported-fields-from-docs-such-as-status/248456 "2020-09-18T16:29:44Z")

</div>

Hey there, I'm trying to get the status of a pod to alert for Crashloop Backoffs and other non Ready states. To achieve that I've tried the docs: https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fiel…

---

## [Filebeat+auditd module not parsed through logstash](https://discuss.elastic.co/t/filebeat-auditd-module-not-parsed-through-logstash/249126)

<div class="topic-metadata">

**Author:** [@pereyrdi](https://discuss.elastic.co/u/pereyrdi)\
**Replies:** 0\
**Last updated:** [September 18, 2020, 3:42pm UTC](https://discuss.elastic.co/t/filebeat-auditd-module-not-parsed-through-logstash/249126 "2020-09-18T15:42:26Z")

</div>

Hello! Im using filebeat with audit module enable to monitoring the audit.log, I have try configure as output directy to elasticsearch and the message field was parsed with all audit's fields correctly. But when I conf…

---

## [Kubernetes.container.memory.usage.bytes looks incorrect for redis container](https://discuss.elastic.co/t/kubernetes-container-memory-usage-bytes-looks-incorrect-for-redis-container/249110)

<div class="topic-metadata">

**Author:** [@willis](https://discuss.elastic.co/u/willis)\
**Replies:** 0\
**Last updated:** [September 18, 2020, 1:44pm UTC](https://discuss.elastic.co/t/kubernetes-container-memory-usage-bytes-looks-incorrect-for-redis-container/249110 "2020-09-18T13:44:10Z")

</div>

I have a redis pod with container limits of 6GB. Metricbeat (7.6.2) data from the container shows: kubernetes.container.memory.usage.bytes: 5.9GB kubernetes.container.memory.usage.limit.pct: 99.9% kubernetes.container.m…

---

## [How to customize a filebeat to parse a log?](https://discuss.elastic.co/t/how-to-customize-a-filebeat-to-parse-a-log/249049)

<div class="topic-metadata">

**Author:** [@icaruswu](https://discuss.elastic.co/u/icaruswu)\
**Replies:** 2\
**Last updated:** [September 18, 2020, 10:45am UTC](https://discuss.elastic.co/t/how-to-customize-a-filebeat-to-parse-a-log/249049 "2020-09-18T10:45:51Z")

</div>

I read a the formal docs and wanna build my own filebeat module to parse my log. But there's little essays which could be helpful to me. For example, my log is : 2020-09-17T15:48:56.998+0800 INFO chain chain/sync.go:70…

---

## [Filebeat stops until log rotated](https://discuss.elastic.co/t/filebeat-stops-until-log-rotated/249083)

<div class="topic-metadata">

**Author:** [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Replies:** 0\
**Last updated:** [September 18, 2020, 10:02am UTC](https://discuss.elastic.co/t/filebeat-stops-until-log-rotated/249083 "2020-09-18T10:02:03Z")

</div>

Hi, Have a filebeat 7.9.1 running on several CentOS 7 servers watching 1 log. This log is growing ca 150.000 to 200.000 bytes per second (12 to 15 GB a day at the moment). This log is copytruncated. This issue is that …

---

## [I want to send json formated logs via filebeat to elasticsearch](https://discuss.elastic.co/t/i-want-to-send-json-formated-logs-via-filebeat-to-elasticsearch/249069)

<div class="topic-metadata">

**Author:** [@aakash41](https://discuss.elastic.co/u/aakash41)\
**Replies:** 1\
**Last updated:** [September 18, 2020, 9:43am UTC](https://discuss.elastic.co/t/i-want-to-send-json-formated-logs-via-filebeat-to-elasticsearch/249069 "2020-09-18T09:43:33Z")

</div>

Can someone please let me know, if below config is correct. The content of logs in JSON but extension is .log. type: log paths: /opt/Application.log json.keys\_under\_root: true json.add\_error\_key: true Below is t…

---

## [Right way to make ingest pipeline work](https://discuss.elastic.co/t/right-way-to-make-ingest-pipeline-work/249055)

<div class="topic-metadata">

**Author:** [@fxx](https://discuss.elastic.co/u/fxx)\
**Replies:** 0\
**Last updated:** [September 18, 2020, 4:53am UTC](https://discuss.elastic.co/t/right-way-to-make-ingest-pipeline-work/249055 "2020-09-18T04:53:27Z")

</div>

create a ingest pipeline in kibana test with kibana.dev-tool.grok .... ok test with kibana.ingest.test-pipeline ... ok test with POST index/?pipeline=xxx ... ok call by filebeat.yml filebeat.yml output.elastics…

---

## [Filebeat getting after few hours of starting](https://discuss.elastic.co/t/filebeat-getting-after-few-hours-of-starting/248990)

<div class="topic-metadata">

**Author:** [@Shefali](https://discuss.elastic.co/u/Shefali)\
**Replies:** 4\
**Last updated:** [September 18, 2020, 8:05am UTC](https://discuss.elastic.co/t/filebeat-getting-after-few-hours-of-starting/248990 "2020-09-18T08:05:15Z")

</div>

Having this issue on production. We have installed filebeat using tar file. After starting, in few hours it's stopping without any error. On our other lower environment we have installed using rpm and never seen this is…

---

## [Uptime monitoring of HTTPS URLs using Heartbeat](https://discuss.elastic.co/t/uptime-monitoring-of-https-urls-using-heartbeat/248931)

<div class="topic-metadata">

**Author:** [@ksaha](https://discuss.elastic.co/u/ksaha)\
**Replies:** 2\
**Last updated:** [September 18, 2020, 5:51am UTC](https://discuss.elastic.co/t/uptime-monitoring-of-https-urls-using-heartbeat/248931 "2020-09-18T05:51:43Z")

</div>

Hi Team, Can we monitor uptime of HTTPS URLs using heartbeat ? And can heartbeat monitor uptime of URLs with DNS ? Any help will be appreciated. Thanks.

---

## [Filebeat nginx access logs not loading with required fields in kibana dashboard](https://discuss.elastic.co/t/filebeat-nginx-access-logs-not-loading-with-required-fields-in-kibana-dashboard/248944)

<div class="topic-metadata">

**Author:** [@pratap1991](https://discuss.elastic.co/u/pratap1991)\
**Replies:** 2\
**Last updated:** [September 18, 2020, 5:12am UTC](https://discuss.elastic.co/t/filebeat-nginx-access-logs-not-loading-with-required-fields-in-kibana-dashboard/248944 "2020-09-18T05:12:44Z")

</div>

filebeat nginx access logs not loading with required fields in kibana dashboard i am using below logstash filter for to get access logs fields but i am not able get required fields ( access.message and other fields) #…

---

## [Not able to start metricbeat](https://discuss.elastic.co/t/not-able-to-start-metricbeat/248963)

<div class="topic-metadata">

**Author:** [@Shriram\_Wasule](https://discuss.elastic.co/u/Shriram_Wasule)\
**Replies:** 2\
**Last updated:** [September 18, 2020, 3:25am UTC](https://discuss.elastic.co/t/not-able-to-start-metricbeat/248963 "2020-09-18T03:25:27Z")

</div>

i am getting this error while i am trying to start metricbeat on one of my hosts write error: failed to rotate backups: failed to rotate backups: rename C:\\metricbeat\\logs\\metricbeat C:\\metricbeat\\logs\\metricbeat.1: Acc…

---

## [Beat-xpack module doesn't work on localhost 5066 port](https://discuss.elastic.co/t/beat-xpack-module-doesnt-work-on-localhost-5066-port/248896)

<div class="topic-metadata">

**Author:** [@xpacker](https://discuss.elastic.co/u/xpacker)\
**Replies:** 1\
**Last updated:** [September 17, 2020, 10:25pm UTC](https://discuss.elastic.co/t/beat-xpack-module-doesnt-work-on-localhost-5066-port/248896 "2020-09-17T22:25:40Z")

</div>

\[root@xyz modules.d\]# cat beat-xpack.yml # Module: beat # Docs: https://www.elastic.co/guide/en/beats/metricbeat/7.6/metricbeat-module-beat.html - module: beat metricsets: - stats - state period: 10s http.…

---

## [No filebeat index in Elasticsearch after running setup](https://discuss.elastic.co/t/no-filebeat-index-in-elasticsearch-after-running-setup/249017)

<div class="topic-metadata">

**Author:** [@stor314](https://discuss.elastic.co/u/stor314)\
**Replies:** 2\
**Last updated:** [September 17, 2020, 10:21pm UTC](https://discuss.elastic.co/t/no-filebeat-index-in-elasticsearch-after-running-setup/249017 "2020-09-17T22:21:26Z")

</div>

New to filebeat, trying to get an index up and running in elasticsearch. I followed this guide: https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation-configuration.html but for some reason even af…

---

## [Remote Filebeat cannot ship logs to elastic ERROR \[publisher\_pipeline\_output\]](https://discuss.elastic.co/t/remote-filebeat-cannot-ship-logs-to-elastic-error-publisher-pipeline-output/248893)

<div class="topic-metadata">

**Author:** [@Team\_K](https://discuss.elastic.co/u/Team_K)\
**Replies:** 5\
**Last updated:** [September 17, 2020, 7:00pm UTC](https://discuss.elastic.co/t/remote-filebeat-cannot-ship-logs-to-elastic-error-publisher-pipeline-output/248893 "2020-09-17T19:00:46Z")

</div>

I have been trying to ship logs from a remote server to my elk. Below is my conf file. I tested my conf file using filebeat -c filebeat.yml test output everything seems fine. Could you please help. Thank you ela…

---

## [Filebeat for binary files?](https://discuss.elastic.co/t/filebeat-for-binary-files/46479)

<div class="topic-metadata">

**Author:** [@rahin88](https://discuss.elastic.co/u/rahin88)\
**Replies:** 9\
**Last updated:** [September 17, 2020, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-for-binary-files/46479 "2020-09-17T18:52:34Z")

</div>

Hello Folks, I am new to whole Logstash/ELK. But I am wondering if I can use filebeat for streaming binary data to network ? Here is what I am trying to do. Multiple processes (in hundreds) have lib in them to encod…

---

## [Metricbeat data not showing on kibana](https://discuss.elastic.co/t/metricbeat-data-not-showing-on-kibana/248907)

<div class="topic-metadata">

**Author:** [@Roberto\_Chacon](https://discuss.elastic.co/u/Roberto_Chacon)\
**Replies:** 2\
**Last updated:** [September 17, 2020, 5:49pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-showing-on-kibana/248907 "2020-09-17T17:49:03Z")

</div>

Trying to setup metricbeat to monitor the ES cluster. It was running fine on an AWS instance that was removed and now going to be self monitored on the sale ES cluster. So far got all the metricbeat configuration update…

---

## [Large number of files causing IO Spike](https://discuss.elastic.co/t/large-number-of-files-causing-io-spike/249008)

<div class="topic-metadata">

**Author:** [@mahadevaprasadap](https://discuss.elastic.co/u/mahadevaprasadap)\
**Replies:** 1\
**Last updated:** [September 17, 2020, 5:04pm UTC](https://discuss.elastic.co/t/large-number-of-files-causing-io-spike/249008 "2020-09-17T17:04:04Z")

</div>

Hello, There are \>300 inputs files needs to monitored by filebeat. We are facing IO spike. We are not in the position to tweak harvest\_limit or scan frequency as this would delay the detection of file change. Please le…

---

## [I am unable to see system metrics of more than one host](https://discuss.elastic.co/t/i-am-unable-to-see-system-metrics-of-more-than-one-host/248962)

<div class="topic-metadata">

**Author:** [@Shriram\_Wasule](https://discuss.elastic.co/u/Shriram_Wasule)\
**Replies:** 2\
**Last updated:** [September 17, 2020, 3:53pm UTC](https://discuss.elastic.co/t/i-am-unable-to-see-system-metrics-of-more-than-one-host/248962 "2020-09-17T15:53:11Z")

</div>

Hello, i have configured 2 metricbeat on 2 dfferent hosts, and i am sending the metrics to one central host where kibana and elasticsearch is running. but when i tried to monitor system data from 2 hosts i am only able …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=210)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=212)
