# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=213

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 214

---

## [Filebeat Modules and Parsing, with Logstash - Cisco Related](https://discuss.elastic.co/t/filebeat-modules-and-parsing-with-logstash-cisco-related/246027)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 5\
**Last updated:** [September 15, 2020, 10:12am UTC](https://discuss.elastic.co/t/filebeat-modules-and-parsing-with-logstash-cisco-related/246027 "2020-09-15T10:12:13Z")

</div>

From what I can glean from https://www.elastic.co/guide/en/logstash/current/use-ingest-pipelines.html and Problems parsing Cisco ASA logs using filebeat, using the filebeat cisco module with logstash successfully looks l…

---

## [Make Inside libbeat fails](https://discuss.elastic.co/t/make-inside-libbeat-fails/248602)

<div class="topic-metadata">

**Author:** [@Ali\_Tahir](https://discuss.elastic.co/u/Ali_Tahir)\
**Replies:** 4\
**Last updated:** [September 15, 2020, 8:42am UTC](https://discuss.elastic.co/t/make-inside-libbeat-fails/248602 "2020-09-15T08:42:17Z")

</div>

I get the following error on running make inside libbeat go build -ldflags "-X github.com/elastic/beats/libbeat/version.buildTime=2020-09-15T05:09:36Z -X github.com/elastic/beats/libbeat/version.commit=3435fe9f46e53708d…

---

## [Billing metricset in azure module not working](https://discuss.elastic.co/t/billing-metricset-in-azure-module-not-working/245569)

<div class="topic-metadata">

**Author:** [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Replies:** 4\
**Last updated:** [September 15, 2020, 8:21am UTC](https://discuss.elastic.co/t/billing-metricset-in-azure-module-not-working/245569 "2020-09-15T08:21:33Z")

</div>

Hello guys, I hope you are doing well ! I have ELK stack (7.8.1) deployed in kubernetes along with metricbeat (same version). I wanted to exploit the new metricset "billing" in azure module, however it didn't work. -…

---

## [Cannot output to redis](https://discuss.elastic.co/t/cannot-output-to-redis/248446)

<div class="topic-metadata">

**Author:** [@vincentchao](https://discuss.elastic.co/u/vincentchao)\
**Replies:** 2\
**Last updated:** [September 15, 2020, 7:14am UTC](https://discuss.elastic.co/t/cannot-output-to-redis/248446 "2020-09-15T07:14:45Z")

</div>

my config.yml is like this: filebeat.inputs: - type: log enabled: true paths: - 'D:\\1021\\\*.log' #scan\_frequency: '60s' #multiline.pattern: '^\\\[\\d{4}\\-\\d{2}' #multiline.negat…

---

## [Collect directories & sub-directories/files data usage metrics](https://discuss.elastic.co/t/collect-directories-sub-directories-files-data-usage-metrics/248558)

<div class="topic-metadata">

**Author:** [@asmi10](https://discuss.elastic.co/u/asmi10)\
**Replies:** 1\
**Last updated:** [September 15, 2020, 6:56am UTC](https://discuss.elastic.co/t/collect-directories-sub-directories-files-data-usage-metrics/248558 "2020-09-15T06:56:11Z")

</div>

Hello! I have a kubernetes cluster where I am using local path provisioner for creating storage for multiple projects. Basically this provisioner creates subdirecties under already existing root directory on worker nod…

---

## [Error fetching data for metricset kubernetes.node, DNS lookup failed on AKS](https://discuss.elastic.co/t/error-fetching-data-for-metricset-kubernetes-node-dns-lookup-failed-on-aks/248543)

<div class="topic-metadata">

**Author:** [@Franck3](https://discuss.elastic.co/u/Franck3)\
**Replies:** 1\
**Last updated:** [September 15, 2020, 6:51am UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-kubernetes-node-dns-lookup-failed-on-aks/248543 "2020-09-15T06:51:30Z")

</div>

The metricbeat pod are not able to get metrics from the /stats/summary endpoints on the nodes. Running on AKS version 1.16.10. 2020-09-14T13:35:54.081Z WARN \[transport\] transport/tcp.go:52 DNS lookup failure "aks-agen…

---

## [Winlogbeat doesn't create custom index-patterns but Elasticsearch does create custom index names, so everything is broken](https://discuss.elastic.co/t/winlogbeat-doesnt-create-custom-index-patterns-but-elasticsearch-does-create-custom-index-names-so-everything-is-broken/248555)

<div class="topic-metadata">

**Author:** [@syunusic](https://discuss.elastic.co/u/syunusic)\
**Replies:** 2\
**Last updated:** [September 15, 2020, 2:50am UTC](https://discuss.elastic.co/t/winlogbeat-doesnt-create-custom-index-patterns-but-elasticsearch-does-create-custom-index-names-so-everything-is-broken/248555 "2020-09-15T02:50:43Z")

</div>

Let’s say I want to have winlogbeat and metricbeat in windows machines for two areas of my company… so I created two spaces in Kibana: “foo” and “bar”. I want to have different indices for each space.. so, instead of wi…

---

## [Custom field format doesn't get applied, some field types get changed](https://discuss.elastic.co/t/custom-field-format-doesnt-get-applied-some-field-types-get-changed/248396)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 2\
**Last updated:** [September 15, 2020, 12:51am UTC](https://discuss.elastic.co/t/custom-field-format-doesnt-get-applied-some-field-types-get-changed/248396 "2020-09-15T00:51:04Z")

</div>

I am editing the mybeat/\_meta/fields.yml file to include a section like: fields: - name: resulturl type: text format: url required: true description: \> PLEASE UPDATE DOCUMENTATION …

---

## [Metricbeat - system network - how does it work?](https://discuss.elastic.co/t/metricbeat-system-network-how-does-it-work/248507)

<div class="topic-metadata">

**Author:** [@nitzan.karni](https://discuss.elastic.co/u/nitzan.karni)\
**Replies:** 1\
**Last updated:** [September 14, 2020, 8:46pm UTC](https://discuss.elastic.co/t/metricbeat-system-network-how-does-it-work/248507 "2020-09-14T20:46:02Z")

</div>

Hi, In the background of metricbeat once I configure it to collect system.network metrics with period of 15 minutes, what does it do? More specificaly what is exactly the value mentioned in system.network.out.bytes/sys…

---

## [Winlogbeat API Key Permissions](https://discuss.elastic.co/t/winlogbeat-api-key-permissions/248382)

<div class="topic-metadata">

**Author:** [@Coinology](https://discuss.elastic.co/u/Coinology)\
**Replies:** 4\
**Last updated:** [September 14, 2020, 6:53pm UTC](https://discuss.elastic.co/t/winlogbeat-api-key-permissions/248382 "2020-09-14T18:53:04Z")

</div>

All, I'm hoping someone can help. I used to output data from Winlogbeat to Logstash and index from there, everything worked fine. With 7.9 I attempted to use Elasticsearch output and received the below: WARN \[elasticse…

---

## [Cisco asa module Drop events - help required](https://discuss.elastic.co/t/cisco-asa-module-drop-events-help-required/248442)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 2\
**Last updated:** [September 14, 2020, 6:39pm UTC](https://discuss.elastic.co/t/cisco-asa-module-drop-events-help-required/248442 "2020-09-14T18:39:02Z")

</div>

Hi Team , We are currently using Cisco asa module for capturing firewall logs. Is there any option in Cisco asa module to capture only logs with specific severity (eg: log.level: informational) and drop all other events…

---

## [Escape character for SQL module](https://discuss.elastic.co/t/escape-character-for-sql-module/248352)

<div class="topic-metadata">

**Author:** [@Prashant\_Achari](https://discuss.elastic.co/u/Prashant_Achari)\
**Replies:** 3\
**Last updated:** [September 14, 2020, 1:46pm UTC](https://discuss.elastic.co/t/escape-character-for-sql-module/248352 "2020-09-14T13:46:58Z")

</div>

I am using SQL module and user password has "#". I gave "" prior to hash but the same is not working. Can you pl help error :oracle://GTXXX:July": invalid port ":July" after host

---

## [Freebsd 12.1 system.memory: VMStat error](https://discuss.elastic.co/t/freebsd-12-1-system-memory-vmstat-error/248342)

<div class="topic-metadata">

**Author:** [@THetherington](https://discuss.elastic.co/u/THetherington)\
**Replies:** 1\
**Last updated:** [September 14, 2020, 1:37pm UTC](https://discuss.elastic.co/t/freebsd-12-1-system-memory-vmstat-error/248342 "2020-09-14T13:37:00Z")

</div>

Hi. is there a compatibility problem with FreeBSD 12.1 and Metricbeat 7.9.1? I'm not seeing the memory metricset working. below is the log: INFO module/wrapper.go:259 Error fetching data for metricset system.memor…

---

## [Filebeat output file permission](https://discuss.elastic.co/t/filebeat-output-file-permission/247793)

<div class="topic-metadata">

**Author:** [@Mostafa\_Hamdy](https://discuss.elastic.co/u/Mostafa_Hamdy)\
**Replies:** 3\
**Last updated:** [September 14, 2020, 12:46pm UTC](https://discuss.elastic.co/t/filebeat-output-file-permission/247793 "2020-09-14T12:46:35Z")

</div>

These are my configuration for filebeat output.file: path: "/var/lib/filebeat-logs" filename: filebeat permissions: 0664 This is the permission is see when i use ls -l -rw-r----- 1 root root 269219 Sep 7 17:01…

---

## [Functionbeat deployment to s3 bucket fails](https://discuss.elastic.co/t/functionbeat-deployment-to-s3-bucket-fails/248111)

<div class="topic-metadata">

**Author:** [@kristofvb](https://discuss.elastic.co/u/kristofvb)\
**Replies:** 1\
**Last updated:** [September 14, 2020, 12:02pm UTC](https://discuss.elastic.co/t/functionbeat-deployment-to-s3-bucket-fails/248111 "2020-09-14T12:02:22Z")

</div>

It looks like the issue reported in https://discuss.elastic.co/t/unable-to-deploy-functionbeat-to-s3-bucket/171371 and https://discuss.elastic.co/t/function-could-not-deploy-error-bucket-abc-already-exist-and-you-dont-ha…

---

## [Winlogbeat filtering problem](https://discuss.elastic.co/t/winlogbeat-filtering-problem/248297)

<div class="topic-metadata">

**Author:** [@jpeyton](https://discuss.elastic.co/u/jpeyton)\
**Replies:** 2\
**Last updated:** [September 14, 2020, 8:30am UTC](https://discuss.elastic.co/t/winlogbeat-filtering-problem/248297 "2020-09-14T08:30:20Z")

</div>

Hi, What I want to do achieve is to send all events from the Security log except event id 4672 and 4627. This works well, but what I can't find out how to do, is make a rule that send event id 4627 only if it does not h…

---

## [Metricbeat tar vs rpm](https://discuss.elastic.co/t/metricbeat-tar-vs-rpm/248468)

<div class="topic-metadata">

**Author:** [@karthikeyanajendran1](https://discuss.elastic.co/u/karthikeyanajendran1)\
**Replies:** 4\
**Last updated:** [September 14, 2020, 5:06am UTC](https://discuss.elastic.co/t/metricbeat-tar-vs-rpm/248468 "2020-09-14T05:06:02Z")

</div>

Hi Experts, We are using metricbeat in our project to capture and monitor host and oracle modules statistics. We have plan to have automation script which download the metricbeat package , setup the metricbeat configur…

---

## [Setting version number for custom beat](https://discuss.elastic.co/t/setting-version-number-for-custom-beat/248393)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 0\
**Last updated:** [September 12, 2020, 12:43am UTC](https://discuss.elastic.co/t/setting-version-number-for-custom-beat/248393 "2020-09-12T00:43:35Z")

</div>

I found various forum posts about using commands like make set\_version or editing a version.yml but neither seem to work. Every time I build my beat, it just keeps setting itself to version beat name-8.0.0, which makes …

---

## [Beats minimum requirements](https://discuss.elastic.co/t/beats-minimum-requirements/248373)

<div class="topic-metadata">

**Author:** [@Adam\_Fink](https://discuss.elastic.co/u/Adam_Fink)\
**Replies:** 0\
**Last updated:** [September 11, 2020, 6:51pm UTC](https://discuss.elastic.co/t/beats-minimum-requirements/248373 "2020-09-11T18:51:06Z")

</div>

Howdy folks! Is there somewhere I can the minimum system requirements for each Beat? I have checked the online docs, readme files, release notes, and github but I can't find any minimum requirements. Specifically fil…

---

## [Filebeat - input not enabled when using external config load](https://discuss.elastic.co/t/filebeat-input-not-enabled-when-using-external-config-load/245365)

<div class="topic-metadata">

**Author:** [@eMDee](https://discuss.elastic.co/u/eMDee)\
**Replies:** 5\
**Last updated:** [September 11, 2020, 4:02pm UTC](https://discuss.elastic.co/t/filebeat-input-not-enabled-when-using-external-config-load/245365 "2020-09-11T16:02:44Z")

</div>

Hi There, I'm trying to use filebeat to import logs from custom locations. In configuration I have: filebeat: config.inputs: enabled: true path: "/etc/filebeat/conf.d/\*.yml" output.logstash: …

---

## [Filebeats: Fortinet Module not processing data as it should](https://discuss.elastic.co/t/filebeats-fortinet-module-not-processing-data-as-it-should/241890)

<div class="topic-metadata">

**Author:** [@Khaled3500](https://discuss.elastic.co/u/Khaled3500)\
**Replies:** 4\
**Last updated:** [September 11, 2020, 11:26am UTC](https://discuss.elastic.co/t/filebeats-fortinet-module-not-processing-data-as-it-should/241890 "2020-09-11T11:26:15Z")

</div>

Hello, I'm trying to use fortinet module to parse and make logs presentable before it ships to logstash here is my filebeats configuration file: # ============================== Filebeat inputs ======================…

---

## [Filebeat Setup isn't working after update to 7.9.0](https://discuss.elastic.co/t/filebeat-setup-isnt-working-after-update-to-7-9-0/245564)

<div class="topic-metadata">

**Author:** [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Replies:** 6\
**Last updated:** [September 11, 2020, 7:46am UTC](https://discuss.elastic.co/t/filebeat-setup-isnt-working-after-update-to-7-9-0/245564 "2020-09-11T07:46:49Z")

</div>

Hello there, we just upgraded our testsite (elastic, kibana, metricbeat, auditbeat and filebeat) to version 7.9.0. After the update filebeat setup fails with the following message: \[root@ELASTIC99004 ~\]# filebeat setup…

---

## [Filebeat not sending output](https://discuss.elastic.co/t/filebeat-not-sending-output/248190)

<div class="topic-metadata">

**Author:** [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Replies:** 2\
**Last updated:** [September 11, 2020, 7:30am UTC](https://discuss.elastic.co/t/filebeat-not-sending-output/248190 "2020-09-11T07:30:16Z")

</div>

I was trying to debug why my filebeat is not sending output to kafka but after debuging I'd change it to file output to see if my config is ok, but Im not getting any output also This is my config file cat filebeat.yml…

---

## [Filebeat not respecting ingest pipeline in output settings when using syslog inputs](https://discuss.elastic.co/t/filebeat-not-respecting-ingest-pipeline-in-output-settings-when-using-syslog-inputs/248060)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 3\
**Last updated:** [September 11, 2020, 7:21am UTC](https://discuss.elastic.co/t/filebeat-not-respecting-ingest-pipeline-in-output-settings-when-using-syslog-inputs/248060 "2020-09-11T07:21:43Z")

</div>

Hi, I'm having issues using ingest pipelines with Filebeat. Filebeat is supposed to collect any syslog messages and send them to the ingest pipeline "syslog\_distributor". However, the incoming documents are not passed t…

---

## [Filebeat is not sending logs to ELastic search](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-elastic-search/247745)

<div class="topic-metadata">

**Author:** [@Raman\_Sawhney](https://discuss.elastic.co/u/Raman_Sawhney)\
**Replies:** 8\
**Last updated:** [September 10, 2020, 10:44pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-elastic-search/247745 "2020-09-10T22:44:02Z")

</div>

Hello Team, We have an issue where filebeat is not sending some logs to elasticsearch so we can see it on kibana. The error we have received for the same is as below. Entity Too Large\\u003c/title\\u003e\\u003c/head\\u003…

---

## [CloudTrail log is different between elasticsearch output and logstash output in Filebeat](https://discuss.elastic.co/t/cloudtrail-log-is-different-between-elasticsearch-output-and-logstash-output-in-filebeat/246075)

<div class="topic-metadata">

**Author:** [@TuongBma](https://discuss.elastic.co/u/TuongBma)\
**Replies:** 1\
**Last updated:** [September 10, 2020, 10:06pm UTC](https://discuss.elastic.co/t/cloudtrail-log-is-different-between-elasticsearch-output-and-logstash-output-in-filebeat/246075 "2020-09-10T22:06:40Z")

</div>

I try to get cloudtrail log from AWS by filebeat. Scenario 1: I use elastic search output in filebeat, there are many enrichment fields such as geo, ... in the cloudtrail index. Scenario 2: I use log stash output in fi…

---

## [Filebeat apache module: Provided Grok expressions do not match field value](https://discuss.elastic.co/t/filebeat-apache-module-provided-grok-expressions-do-not-match-field-value/248214)

<div class="topic-metadata">

**Author:** [@gnumoksha](https://discuss.elastic.co/u/gnumoksha)\
**Replies:** 0\
**Last updated:** [September 10, 2020, 5:43pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-provided-grok-expressions-do-not-match-field-value/248214 "2020-09-10T17:43:43Z")

</div>

Hello. Filebeat is unable to parse any entry from the Apache access log. Here is a complete document which demonstrates the error: { "\_index": "filebeat-7.7.1-2020.08.29-000002", "\_type": "\_doc", "\_id": "ZV4cdHQB…

---

## [Filebeat Kubernetes Pod Publishing Behind For Only Some Files in Container Path Input](https://discuss.elastic.co/t/filebeat-kubernetes-pod-publishing-behind-for-only-some-files-in-container-path-input/248207)

<div class="topic-metadata">

**Author:** [@stockhausenj](https://discuss.elastic.co/u/stockhausenj)\
**Replies:** 0\
**Last updated:** [September 10, 2020, 4:52pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-pod-publishing-behind-for-only-some-files-in-container-path-input/248207 "2020-09-10T16:52:13Z")

</div>

Greetings! I have deployed the Filebeat Daemonset to collect container logs. Kubernetes YAML: apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: filebeat data: filebeat.yml: |- filebea…

---

## [Docker.elastic.co/r/beats down?](https://discuss.elastic.co/t/docker-elastic-co-r-beats-down/248203)

<div class="topic-metadata">

**Author:** [@ldavis2](https://discuss.elastic.co/u/ldavis2)\
**Replies:** 0\
**Last updated:** [September 10, 2020, 4:17pm UTC](https://discuss.elastic.co/t/docker-elastic-co-r-beats-down/248203 "2020-09-10T16:17:13Z")

</div>

As mentioned in title, when visiting www.docker.elastic.co and navigating to the beats namespace, an internal server error occurs. This prevents deploying images from the beats namespace. For backup purposes, are the im…

---

## [Heartbeat high network utilization](https://discuss.elastic.co/t/heartbeat-high-network-utilization/248184)

<div class="topic-metadata">

**Author:** [@ehausig1](https://discuss.elastic.co/u/ehausig1)\
**Replies:** 0\
**Last updated:** [September 10, 2020, 1:50pm UTC](https://discuss.elastic.co/t/heartbeat-high-network-utilization/248184 "2020-09-10T13:50:30Z")

</div>

I'm trying to figure out why Heartbeat seems to be using so much network bandwidth: I have a single http monitor for an Elasticsearch endpoint that is scheduled every 10s. The endpoint returns about a 600 byte response …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=212)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=214)
