# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=212

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 213

---

## [Filebeat Container Cannot Connect to Docker Daemon](https://discuss.elastic.co/t/filebeat-container-cannot-connect-to-docker-daemon/248876)

<div class="topic-metadata">

**Author:** [@JustinRSE](https://discuss.elastic.co/u/JustinRSE)\
**Replies:** 2\
**Last updated:** [September 17, 2020, 2:25pm UTC](https://discuss.elastic.co/t/filebeat-container-cannot-connect-to-docker-daemon/248876 "2020-09-17T14:25:15Z")

</div>

I'm attempting to configure Filebeat to monitor some log files on one of our machines. I've created a compose file that looks like the following: version: '2.2' services: filebeat: image: docker.elastic.co/beats/fil…

---

## [Will AutoDiscovery work with a Role and RoleBinding in kubernetes](https://discuss.elastic.co/t/will-autodiscovery-work-with-a-role-and-rolebinding-in-kubernetes/248584)

<div class="topic-metadata">

**Author:** [@TejaV](https://discuss.elastic.co/u/TejaV)\
**Replies:** 2\
**Last updated:** [September 17, 2020, 11:28am UTC](https://discuss.elastic.co/t/will-autodiscovery-work-with-a-role-and-rolebinding-in-kubernetes/248584 "2020-09-17T11:28:12Z")

</div>

Hi, I like the autodiscovery feature of filebeat (as a Daemonset) but I was reluctant to use a clusterRole and clusterRoleBinding as part of my kubernetes deployment. Apparently I'm not allowed to use a clusterRoleBindi…

---

## [Filebeat.yml drop event not working](https://discuss.elastic.co/t/filebeat-yml-drop-event-not-working/248761)

<div class="topic-metadata">

**Author:** [@angeloli](https://discuss.elastic.co/u/angeloli)\
**Replies:** 2\
**Last updated:** [September 17, 2020, 9:34am UTC](https://discuss.elastic.co/t/filebeat-yml-drop-event-not-working/248761 "2020-09-17T09:34:53Z")

</div>

I have add these in filebeat.yml, (version is 7.9) I try every kinds of these keywords , but i still receive the process.name = "kibana" event. why ? Please kindly help #======== Drop event processors: - drop\_event…

---

## [If not a root account, the kubernetes metadata is not generated](https://discuss.elastic.co/t/if-not-a-root-account-the-kubernetes-metadata-is-not-generated/248786)

<div class="topic-metadata">

**Author:** [@kyungseok](https://discuss.elastic.co/u/kyungseok)\
**Replies:** 3\
**Last updated:** [September 17, 2020, 7:38am UTC](https://discuss.elastic.co/t/if-not-a-root-account-the-kubernetes-metadata-is-not-generated/248786 "2020-09-17T07:38:01Z")

</div>

Hello, I am trying to run auditbeat on kubernetes cluster But kubernetes metadata are not added to events when I run application with not a root account Below is a debug messages 2020-09-16T04:59:16.435Z DEBUG \[add\_…

---

## [How to add delimiter in functionbeat.yml](https://discuss.elastic.co/t/how-to-add-delimiter-in-functionbeat-yml/248916)

<div class="topic-metadata">

**Author:** [@deepasaju](https://discuss.elastic.co/u/deepasaju)\
**Replies:** 1\
**Last updated:** [September 17, 2020, 7:32am UTC](https://discuss.elastic.co/t/how-to-add-delimiter-in-functionbeat-yml/248916 "2020-09-17T07:32:08Z")

</div>

Team, How to add delimiter in functionbeat.yml file to include the entire loggroups ? ex. If I have multiple logs start with API-Gateway , what is the exact syntax ? /API-Gateway-\* is not working API-Gateway-Executio…

---

## [BIND dns with Beats](https://discuss.elastic.co/t/bind-dns-with-beats/247651)

<div class="topic-metadata">

**Author:** [@Gomeisa](https://discuss.elastic.co/u/Gomeisa)\
**Replies:** 11\
**Last updated:** [September 17, 2020, 12:22am UTC](https://discuss.elastic.co/t/bind-dns-with-beats/247651 "2020-09-17T00:22:44Z")

</div>

Hi, I want to use elastic siem for my DNS server logs, we are using a BIND DNS server, I don't want to install Packetbeat/Filebeat on the DNS server machine. we use syslog-ng to redirect DNS server logs to UDP port 514…

---

## [How do I change winlogbeat's index name to anything other than winlogbeat?](https://discuss.elastic.co/t/how-do-i-change-winlogbeats-index-name-to-anything-other-than-winlogbeat/248878)

<div class="topic-metadata">

**Author:** [@Sylancer](https://discuss.elastic.co/u/Sylancer)\
**Replies:** 1\
**Last updated:** [September 16, 2020, 8:49pm UTC](https://discuss.elastic.co/t/how-do-i-change-winlogbeats-index-name-to-anything-other-than-winlogbeat/248878 "2020-09-16T20:49:45Z")

</div>

Hi, I can't seem to change the index pattern name for winlogbeat. This is what I'm trying to change: Here's my winlogbeat yml file ###################### Winlogbeat Configuration Example ######################## # T…

---

## [Filebeat Drop field doesnt work for json](https://discuss.elastic.co/t/filebeat-drop-field-doesnt-work-for-json/248432)

<div class="topic-metadata">

**Author:** [@niv](https://discuss.elastic.co/u/niv)\
**Replies:** 7\
**Last updated:** [September 16, 2020, 5:48pm UTC](https://discuss.elastic.co/t/filebeat-drop-field-doesnt-work-for-json/248432 "2020-09-16T17:48:49Z")

</div>

filebeat.inputs: - type: log enabled: true paths: - "\*.json" processors: - drop\_fields: fields: \["value"\] \`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\` That's my filebeat yml file. the drop fields d…

---

## [Apache logs missing SSL Protocol](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070)

<div class="topic-metadata">

**Author:** [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Replies:** 5\
**Last updated:** [September 16, 2020, 3:36pm UTC](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070 "2020-09-16T15:36:38Z")

</div>

Despite SSL Protocol and request time showing in my logformat directive in Apache 2.4 I am not seeing either of them in ES/Kibana. How is this fixed? I am using filebeat and shipping logs directly to ES.

---

## [Wrong event start time with Fortinet module](https://discuss.elastic.co/t/wrong-event-start-time-with-fortinet-module/246599)

<div class="topic-metadata">

**Author:** [@anon56147639](https://discuss.elastic.co/u/anon56147639)\
**Replies:** 6\
**Last updated:** [September 16, 2020, 3:30pm UTC](https://discuss.elastic.co/t/wrong-event-start-time-with-fortinet-module/246599 "2020-09-16T15:30:55Z")

</div>

Hi everyone, I'm using Filebeat with its Fortinet module. In Kibana, I noticed that the fields event.start is completely wrong. It contains values such as "1970-01-19T12:01:51.846Z ". I guess there is some parsing prob…

---

## [Cylance module in filebeat docs are mixed with RSA](https://discuss.elastic.co/t/cylance-module-in-filebeat-docs-are-mixed-with-rsa/248754)

<div class="topic-metadata">

**Author:** [@jessvin.thomas](https://discuss.elastic.co/u/jessvin.thomas)\
**Replies:** 2\
**Last updated:** [September 16, 2020, 1:50pm UTC](https://discuss.elastic.co/t/cylance-module-in-filebeat-docs-are-mixed-with-rsa/248754 "2020-09-16T13:50:07Z")

</div>

The documentation for the cylance module in filebeats looks mixed up with RSA Netwitness. In this documentation: RSA fields are referenced: var.rsa\_fields And the link to exported fields also are mainly RSA fields…

---

## [Error loading yaml file-did not find expected key](https://discuss.elastic.co/t/error-loading-yaml-file-did-not-find-expected-key/248554)

<div class="topic-metadata">

**Author:** [@vsekvsek](https://discuss.elastic.co/u/vsekvsek)\
**Replies:** 6\
**Last updated:** [September 16, 2020, 1:48pm UTC](https://discuss.elastic.co/t/error-loading-yaml-file-did-not-find-expected-key/248554 "2020-09-16T13:48:45Z")

</div>

.\\filebeat.exe modules enable apache Error initializing beat: error loading config file: yaml line 70: did not find expected key This is on line 70 on the filebeat file. path: "C:\\\\Program Files\\\\filebeat\\\\module\\\\apa…

---

## [Functionbeat Get Data From All Log Groups](https://discuss.elastic.co/t/functionbeat-get-data-from-all-log-groups/248796)

<div class="topic-metadata">

**Author:** [@sainath](https://discuss.elastic.co/u/sainath)\
**Replies:** 2\
**Last updated:** [September 16, 2020, 12:17pm UTC](https://discuss.elastic.co/t/functionbeat-get-data-from-all-log-groups/248796 "2020-09-16T12:17:30Z")

</div>

I am using functionbeat 7.9 to integrate with AWS lambda logs and I am currently providing multiple log group names to fetch data from each of them. - log\_group\_name: /aws/lambda/Summary - log\_group\_name: /a…

---

## [How to convert bytes in MB/GB data in Metribeat system module](https://discuss.elastic.co/t/how-to-convert-bytes-in-mb-gb-data-in-metribeat-system-module/248755)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 2\
**Last updated:** [September 16, 2020, 10:29am UTC](https://discuss.elastic.co/t/how-to-convert-bytes-in-mb-gb-data-in-metribeat-system-module/248755 "2020-09-16T10:29:06Z")

</div>

I enable the system module but the data come into the format of the byte. Can anyone helps how to convert it or any config need to change in metricbeat?

---

## [Filebeat fails to parse GuardDuty json logs](https://discuss.elastic.co/t/filebeat-fails-to-parse-guardduty-json-logs/248696)

<div class="topic-metadata">

**Author:** [@Ameer\_Mukadam](https://discuss.elastic.co/u/Ameer_Mukadam)\
**Replies:** 5\
**Last updated:** [September 16, 2020, 10:25am UTC](https://discuss.elastic.co/t/filebeat-fails-to-parse-guardduty-json-logs/248696 "2020-09-16T10:25:25Z")

</div>

So I am trying to ingest Guarduty logs from S3 to elasticsearch using filebeats s3 input. The logs are getting indexed but they are not getting parsed, everything goes under message field and all the logs are in json for…

---

## [reason:'None' is not an IP string literal](https://discuss.elastic.co/t/reason-none-is-not-an-ip-string-literal/248753)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 2\
**Last updated:** [September 16, 2020, 9:57am UTC](https://discuss.elastic.co/t/reason-none-is-not-an-ip-string-literal/248753 "2020-09-16T09:57:27Z")

</div>

2020-09-16T01:04:38.158Z INFO instance/beat.go:640 Home path: \[/usr/share/metricbeat\] Config path: \[/usr/share/metricbeat\] Data path: \[/usr/share/metricbeat/data\] Logs path: \[/usr/share/metricbeat/logs\] 2020-09-16T01:0…

---

## [Filebeat Autodiscover Configuration](https://discuss.elastic.co/t/filebeat-autodiscover-configuration/248740)

<div class="topic-metadata">

**Author:** [@Paul\_B](https://discuss.elastic.co/u/Paul_B)\
**Replies:** 2\
**Last updated:** [September 16, 2020, 9:51am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-configuration/248740 "2020-09-16T09:51:13Z")

</div>

Can anyone shed some light on where exactly in the YAML config the configuration property "cleanup\_timeout" is supposed to sit? We're using Filebeat Autodiscover for Kubernetes and unfortunately the documentation around…

---

## [Overwrite metricbeat time period](https://discuss.elastic.co/t/overwrite-metricbeat-time-period/248809)

<div class="topic-metadata">

**Author:** [@sandeep1-0](https://discuss.elastic.co/u/sandeep1-0)\
**Replies:** 0\
**Last updated:** [September 16, 2020, 9:49am UTC](https://discuss.elastic.co/t/overwrite-metricbeat-time-period/248809 "2020-09-16T09:49:51Z")

</div>

Hi I have new module which collect url health. I need to overwrite the default time period with multiple values which is taken through user input. For first url let say time interval is 30 seconds and second url 60 secon…

---

## [Write error: failed to rotate backups: failed to rotate backups](https://discuss.elastic.co/t/write-error-failed-to-rotate-backups-failed-to-rotate-backups/248778)

<div class="topic-metadata">

**Author:** [@Shriram\_Wasule](https://discuss.elastic.co/u/Shriram_Wasule)\
**Replies:** 0\
**Last updated:** [September 16, 2020, 7:06am UTC](https://discuss.elastic.co/t/write-error-failed-to-rotate-backups-failed-to-rotate-backups/248778 "2020-09-16T07:06:53Z")

</div>

I am trying to start metricbeat from powershell ut after running i am getting above error. Also i am not able to receive any data in kibana. i can just see disk usage. rest visualization is not visible to me. even i tr…

---

## [Filebeat Cisco FTD](https://discuss.elastic.co/t/filebeat-cisco-ftd/248797)

<div class="topic-metadata">

**Author:** [@Shadowphax](https://discuss.elastic.co/u/Shadowphax)\
**Replies:** 0\
**Last updated:** [September 16, 2020, 9:08am UTC](https://discuss.elastic.co/t/filebeat-cisco-ftd/248797 "2020-09-16T09:08:45Z")

</div>

Hi All, I have Cisco FTD enabled and it is ingesting lots of data into ES. Great. However, after looking at the various data in ES I noticed a few entries missing which I see in the syslog on the default port 9003 using…

---

## [In Packetloss dropping packets](https://discuss.elastic.co/t/in-packetloss-dropping-packets/248680)

<div class="topic-metadata">

**Author:** [@pankaj0172](https://discuss.elastic.co/u/pankaj0172)\
**Replies:** 5\
**Last updated:** [September 16, 2020, 4:55am UTC](https://discuss.elastic.co/t/in-packetloss-dropping-packets/248680 "2020-09-16T04:55:50Z")

</div>

Hi, Can we see time period like at what time "In Packet loss" drop the packets?

---

## [Heartbeat monitor auto reloading does now work](https://discuss.elastic.co/t/heartbeat-monitor-auto-reloading-does-now-work/248306)

<div class="topic-metadata">

**Author:** [@tterranigma](https://discuss.elastic.co/u/tterranigma)\
**Replies:** 4\
**Last updated:** [September 16, 2020, 1:22am UTC](https://discuss.elastic.co/t/heartbeat-monitor-auto-reloading-does-now-work/248306 "2020-09-16T01:22:19Z")

</div>

According to heartbeat documentation, heartbeat supports automatically reloading the monitor files periodically. In my installation of heartbeat, I have enabled this: heartbeat: config: monitors: path: /etc/…

---

## [Filebeat is running fine but no data showing in dashboard](https://discuss.elastic.co/t/filebeat-is-running-fine-but-no-data-showing-in-dashboard/248670)

<div class="topic-metadata">

**Author:** [@pankaj0172](https://discuss.elastic.co/u/pankaj0172)\
**Replies:** 1\
**Last updated:** [September 15, 2020, 7:23pm UTC](https://discuss.elastic.co/t/filebeat-is-running-fine-but-no-data-showing-in-dashboard/248670 "2020-09-15T19:23:36Z")

</div>

Hi Team, I have installed file beat service on the machine and I'm able to connect elastic search & kibana. Service is running fine but no data is coming & showing in Kibana dashboard, Can someone please help me here. A…

---

## [Fail to unpack the dns configuration: requires duration \< 1 accessing 'processors.0.dns.min\_ttl'](https://discuss.elastic.co/t/fail-to-unpack-the-dns-configuration-requires-duration-1-accessing-processors-0-dns-min-ttl/248453)

<div class="topic-metadata">

**Author:** [@dddpaul](https://discuss.elastic.co/u/dddpaul)\
**Replies:** 4\
**Last updated:** [September 15, 2020, 6:03pm UTC](https://discuss.elastic.co/t/fail-to-unpack-the-dns-configuration-requires-duration-1-accessing-processors-0-dns-min-ttl/248453 "2020-09-15T18:03:29Z")

</div>

Hi. Trying Packetbeat 7.x branch with enabled DNS processor and default config fails with fail to unpack the dns configuration: requires duration \< 1 accessing 'processors.0.dns.min\_ttl' Steps to reproduce: Config f…

---

## [Metricbeat - Windows Module - Perfmon Instances truncated with parenthesis](https://discuss.elastic.co/t/metricbeat-windows-module-perfmon-instances-truncated-with-parenthesis/248422)

<div class="topic-metadata">

**Author:** [@Nerbelir](https://discuss.elastic.co/u/Nerbelir)\
**Replies:** 1\
**Last updated:** [September 15, 2020, 12:53pm UTC](https://discuss.elastic.co/t/metricbeat-windows-module-perfmon-instances-truncated-with-parenthesis/248422 "2020-09-15T12:53:11Z")

</div>

Using 7.9.0 and 7.9.1 (I can't confirm this for earlier versions) it seems there is something off with how it will read instance names to elasticsearch output. If the perfmon instance's name contains parenthesis such as …

---

## [Beats pipeline.json not received correctly in elastisearch/kibana](https://discuss.elastic.co/t/beats-pipeline-json-not-received-correctly-in-elastisearch-kibana/248624)

<div class="topic-metadata">

**Author:** [@schultz](https://discuss.elastic.co/u/schultz)\
**Replies:** 2\
**Last updated:** [September 15, 2020, 12:45pm UTC](https://discuss.elastic.co/t/beats-pipeline-json-not-received-correctly-in-elastisearch-kibana/248624 "2020-09-15T12:45:14Z")

</div>

Versions: Filebeat v7.9.1 Elastisearch v 7.9.1 Kibana v7.9.1 On windows. I have a pipeline.json file that describes the ingest part of my module { "description": "Pipeline for parsing aaa server logs.", "processors"…

---

## [Error Messages in Logstash Logfile io.netty.channel](https://discuss.elastic.co/t/error-messages-in-logstash-logfile-io-netty-channel/248660)

<div class="topic-metadata">

**Author:** [@bateskevin](https://discuss.elastic.co/u/bateskevin)\
**Replies:** 2\
**Last updated:** [September 15, 2020, 11:41am UTC](https://discuss.elastic.co/t/error-messages-in-logstash-logfile-io-netty-channel/248660 "2020-09-15T11:41:23Z")

</div>

Hi, I am recieving the following errors in my logstash log file on the instance on a regular basis: \[2020-09-15T02:00:17,587\]\[WARN \]\[io.netty.channel.DefaultChannelPipeline\]\[main\]\[localinstance\] An exceptionCaught() ev…

---

## [Journalbeat does not support globbing?](https://discuss.elastic.co/t/journalbeat-does-not-support-globbing/248666)

<div class="topic-metadata">

**Author:** [@kbaf](https://discuss.elastic.co/u/kbaf)\
**Replies:** 0\
**Last updated:** [September 15, 2020, 11:28am UTC](https://discuss.elastic.co/t/journalbeat-does-not-support-globbing/248666 "2020-09-15T11:28:29Z")

</div>

I have several directories with different journals I'd like to collect with globbing: - paths: - "/var/log/journal" - "/openstack/log/\*/journal/\*/system.journal" This is documented behaviour for filebea…

---

## [Auditbeat consuming lot of CPU](https://discuss.elastic.co/t/auditbeat-consuming-lot-of-cpu/248629)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 1\
**Last updated:** [September 15, 2020, 11:28am UTC](https://discuss.elastic.co/t/auditbeat-consuming-lot-of-cpu/248629 "2020-09-15T11:28:09Z")

</div>

Hello Team, We are using ELK with architecture Beat-\>Logstsh-\>Elasticsaerch-\>Kibana version 6.4. Elasticsaerch, Kibana, Logstash and all beats version is 6.4. Yesterday we installed auditbeat version 6.4 on our one ser…

---

## [GPO to start Beats not working](https://discuss.elastic.co/t/gpo-to-start-beats-not-working/248626)

<div class="topic-metadata">

**Author:** [@Thelmo\_Henrique\_Sant](https://discuss.elastic.co/u/Thelmo_Henrique_Sant)\
**Replies:** 5\
**Last updated:** [September 15, 2020, 10:18am UTC](https://discuss.elastic.co/t/gpo-to-start-beats-not-working/248626 "2020-09-15T10:18:58Z")

</div>

Hi buddies, I am trying to start beat services (filebeat, metricbeat, heartbeat, winlogbeat, auditbeat) using a GPO but I don't know why,it's not working. In Group Policy Management, under "Computer Configuration" I di…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=211)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=213)
