# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=214

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 215

---

## [How to add all log groups in functionbeat.yml](https://discuss.elastic.co/t/how-to-add-all-log-groups-in-functionbeat-yml/248181)

<div class="topic-metadata">

**Author:** [@deepasaju](https://discuss.elastic.co/u/deepasaju)\
**Replies:** 0\
**Last updated:** [September 10, 2020, 1:43pm UTC](https://discuss.elastic.co/t/how-to-add-all-log-groups-in-functionbeat-yml/248181 "2020-09-10T13:43:41Z")

</div>

Team, How to add delimiter in functionbeat.yml file to include the entire log groups of a service ? ex. If I have multiple logs start with API-Gateway , what is the exact syntax to include them? /API-Gateway-\* is …

---

## [Winlogbeat - only new logs?](https://discuss.elastic.co/t/winlogbeat-only-new-logs/248174)

<div class="topic-metadata">

**Author:** [@Shawn\_Keslar](https://discuss.elastic.co/u/Shawn_Keslar)\
**Replies:** 2\
**Last updated:** [September 10, 2020, 1:38pm UTC](https://discuss.elastic.co/t/winlogbeat-only-new-logs/248174 "2020-09-10T13:38:04Z")

</div>

How do I configure Winlogbeat to only read new data? I'm adding my DC's to our SIEM, and it's reading all of the audit data on the box. Taking a lot to process it. I'd like to avoid this issue as I add new servers. TIA.

---

## [Gpu beats for metricbeat](https://discuss.elastic.co/t/gpu-beats-for-metricbeat/248036)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [September 10, 2020, 1:31pm UTC](https://discuss.elastic.co/t/gpu-beats-for-metricbeat/248036 "2020-09-10T13:31:02Z")

</div>

Is there a beats to monitor GPU stats ?

---

## [Unable to configure filebeat to send to logstash or elasticsearch](https://discuss.elastic.co/t/unable-to-configure-filebeat-to-send-to-logstash-or-elasticsearch/248106)

<div class="topic-metadata">

**Author:** [@muru1](https://discuss.elastic.co/u/muru1)\
**Replies:** 0\
**Last updated:** [September 10, 2020, 5:05am UTC](https://discuss.elastic.co/t/unable-to-configure-filebeat-to-send-to-logstash-or-elasticsearch/248106 "2020-09-10T05:05:13Z")

</div>

I am trying to setup elk stack with filebeat and unable to send any logs to elasticsearch or logstash using filebeat . I am not sure if I am missing something simple - if I use gelf input (ie myapp is shipped to elastic…

---

## [Manually appending log lines to log file, filebeat is not sending the appended logs](https://discuss.elastic.co/t/manually-appending-log-lines-to-log-file-filebeat-is-not-sending-the-appended-logs/248158)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 0\
**Last updated:** [September 10, 2020, 11:39am UTC](https://discuss.elastic.co/t/manually-appending-log-lines-to-log-file-filebeat-is-not-sending-the-appended-logs/248158 "2020-09-10T11:39:39Z")

</div>

I manually appended the lines to a file using echo "2020-09-09T11:07:56,826 DEBUG test log file , send to logstash" \>\>test.log in powershell. restarted filebeat service. It's no luck. Tried to check the publish messa…

---

## [Elasticsearch stops after running for a week](https://discuss.elastic.co/t/elasticsearch-stops-after-running-for-a-week/248137)

<div class="topic-metadata">

**Author:** [@Mason](https://discuss.elastic.co/u/Mason)\
**Replies:** 3\
**Last updated:** [September 10, 2020, 9:22am UTC](https://discuss.elastic.co/t/elasticsearch-stops-after-running-for-a-week/248137 "2020-09-10T09:22:43Z")

</div>

I am using ELK stack (Elasticsearch and Kibana ) in a docker setup to monitor one of our application which is running in docker. This is a dedicated machine. I use filebeats to send logs to the ELK. Filebeats also run in…

---

## [Filebeat Module for Sonicwall gives Dissect parse error](https://discuss.elastic.co/t/filebeat-module-for-sonicwall-gives-dissect-parse-error/245602)

<div class="topic-metadata">

**Author:** [@imran](https://discuss.elastic.co/u/imran)\
**Replies:** 1\
**Last updated:** [September 10, 2020, 11:33am UTC](https://discuss.elastic.co/t/filebeat-module-for-sonicwall-gives-dissect-parse-error/245602 "2020-09-10T11:33:39Z")

</div>

Dear support, I have deployed the latest version 7.9 filebeat to include sonicwall syslog logs, i have enabled the sonicwall module, however the events in discover keep throwing the dissect\_parsing\_error. Below are som…

---

## [Cisco Filebeat module loading 4286 fields](https://discuss.elastic.co/t/cisco-filebeat-module-loading-4286-fields/248032)

<div class="topic-metadata">

**Author:** [@ebaena](https://discuss.elastic.co/u/ebaena)\
**Replies:** 3\
**Last updated:** [September 10, 2020, 11:31am UTC](https://discuss.elastic.co/t/cisco-filebeat-module-loading-4286-fields/248032 "2020-09-10T11:31:49Z")

</div>

Hello community, I’m using the latest stable Elasticsearch and Filebeat version 7.9.1 and enabled the cisco module to analyse the logs. I know there is an open issue about the module not showing the message fields on th…

---

## [Manual manage agent binary version](https://discuss.elastic.co/t/manual-manage-agent-binary-version/248009)

<div class="topic-metadata">

**Author:** [@mladen](https://discuss.elastic.co/u/mladen)\
**Replies:** 3\
**Last updated:** [September 10, 2020, 11:04am UTC](https://discuss.elastic.co/t/manual-manage-agent-binary-version/248009 "2020-09-10T11:04:42Z")

</div>

Hi, in Ingest manager I can't select: Manually manage agent binary versions. Requires gold license. This is very strange because I have platinum licences :grinning:. So my question is someone have the same problem? …

---

## [Unable to build custom beat](https://discuss.elastic.co/t/unable-to-build-custom-beat/244915)

<div class="topic-metadata">

**Author:** [@sdndude](https://discuss.elastic.co/u/sdndude)\
**Replies:** 4\
**Last updated:** [September 10, 2020, 10:49am UTC](https://discuss.elastic.co/t/unable-to-build-custom-beat/244915 "2020-09-10T10:49:05Z")

</div>

I am trying to follow the instructions building the countbeat example here on Ubuntu 18.04 but am not having much luck. After figuring out that the mage instructions are wrong, I was able to get past that by building it…

---

## [Winlogbeat - multiple output](https://discuss.elastic.co/t/winlogbeat-multiple-output/248120)

<div class="topic-metadata">

**Author:** [@iccMe](https://discuss.elastic.co/u/iccMe)\
**Replies:** 1\
**Last updated:** [September 10, 2020, 9:30am UTC](https://discuss.elastic.co/t/winlogbeat-multiple-output/248120 "2020-09-10T09:30:50Z")

</div>

Hi, I am wondering if it is possible to have a winlogbeat output to multiple events? So ideally I would like it to ship to my elasticsearch cluster but also output to a file (ideally a flat file) if anyone knows if that…

---

## [Filebeat Zeek and date parsing with SMTP broken](https://discuss.elastic.co/t/filebeat-zeek-and-date-parsing-with-smtp-broken/248103)

<div class="topic-metadata">

**Author:** [@rossw](https://discuss.elastic.co/u/rossw)\
**Replies:** 1\
**Last updated:** [September 10, 2020, 9:20am UTC](https://discuss.elastic.co/t/filebeat-zeek-and-date-parsing-with-smtp-broken/248103 "2020-09-10T09:20:25Z")

</div>

Hiya I've upgraded to filebeat 7.9.0 and using the zeek (bro) module with its associated pipeline. I noticed a few entries in the dead letter queue, and a quick examination showed a parsing error on the date field of t…

---

## [Filebeat log ingestion and scan frequency](https://discuss.elastic.co/t/filebeat-log-ingestion-and-scan-frequency/248113)

<div class="topic-metadata">

**Author:** [@Moksha20](https://discuss.elastic.co/u/Moksha20)\
**Replies:** 0\
**Last updated:** [September 10, 2020, 6:14am UTC](https://discuss.elastic.co/t/filebeat-log-ingestion-and-scan-frequency/248113 "2020-09-10T06:14:22Z")

</div>

Hi Expert and Team, Could you please help me with the log ingestion from filebeat.There are two scenarios 1)My logs are created in 15 minutes frequency in the same name and replace the older one.what should my .yml fil…

---

## [Setup included dashboards with custom pattern](https://discuss.elastic.co/t/setup-included-dashboards-with-custom-pattern/248088)

<div class="topic-metadata">

**Author:** [@bevano](https://discuss.elastic.co/u/bevano)\
**Replies:** 0\
**Last updated:** [September 10, 2020, 1:02am UTC](https://discuss.elastic.co/t/setup-included-dashboards-with-custom-pattern/248088 "2020-09-10T01:02:39Z")

</div>

Hi All We have setup filebeat to create a different index based on the module used. We plan on using multiple modules, like netflow, checkpoint and many more. I have configured the ILM within the filebeat.yml using this…

---

## [Using the Filebeat Suricata Module for EVE-Logs in Syslog messages](https://discuss.elastic.co/t/using-the-filebeat-suricata-module-for-eve-logs-in-syslog-messages/248064)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 0\
**Last updated:** [September 9, 2020, 8:15pm UTC](https://discuss.elastic.co/t/using-the-filebeat-suricata-module-for-eve-logs-in-syslog-messages/248064 "2020-09-09T20:15:51Z")

</div>

Hey, Filebeat supports extensive Suricata EVE log parsing through the "suricata" module. The assumption of the module is that these logs are present in a file on disk. In my case, they arrive via Syslog. Also, that Sysl…

---

## [Filebeat Cisco Module Trouble](https://discuss.elastic.co/t/filebeat-cisco-module-trouble/248028)

<div class="topic-metadata">

**Author:** [@aparkinson\_merrimac](https://discuss.elastic.co/u/aparkinson_merrimac)\
**Replies:** 0\
**Last updated:** [September 9, 2020, 2:34pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-trouble/248028 "2020-09-09T14:34:06Z")

</div>

I am struggling to get the filebeat cisco module to report correctly. The pipeline appears to be broken, but I am not proficient enough to discover the problem. What can I provide other than the below to assist in discov…

---

## [Decode Array and Extract](https://discuss.elastic.co/t/decode-array-and-extract/247802)

<div class="topic-metadata">

**Author:** [@Milos](https://discuss.elastic.co/u/Milos)\
**Replies:** 2\
**Last updated:** [September 9, 2020, 1:33pm UTC](https://discuss.elastic.co/t/decode-array-and-extract/247802 "2020-09-09T13:33:36Z")

</div>

Hi to All, last few weeks I am getting up to speed with Filebeat and ES, experience is up to now great!! Currently i believe that i am stuck with a small issue: Namely, if i decode array from json, is it possible to ex…

---

## [Mapping Internal Network for SIEM Network Map - Not showing](https://discuss.elastic.co/t/mapping-internal-network-for-siem-network-map-not-showing/247295)

<div class="topic-metadata">

**Author:** [@teej](https://discuss.elastic.co/u/teej)\
**Replies:** 2\
**Last updated:** [September 9, 2020, 1:16pm UTC](https://discuss.elastic.co/t/mapping-internal-network-for-siem-network-map-not-showing/247295 "2020-09-09T13:16:30Z")

</div>

I am not sure I am making the correct assumption but I thought that if I added processors: - add\_host\_metadata: - add\_cloud\_metadata: ~ - add\_fields: when.network.source.ip: 10.10.10.10/24 fiel…

---

## [Heartbeat Use json with secret store in check.request.body](https://discuss.elastic.co/t/heartbeat-use-json-with-secret-store-in-check-request-body/247869)

<div class="topic-metadata">

**Author:** [@pawarrchetan](https://discuss.elastic.co/u/pawarrchetan)\
**Replies:** 3\
**Last updated:** [September 9, 2020, 11:24am UTC](https://discuss.elastic.co/t/heartbeat-use-json-with-secret-store-in-check-request-body/247869 "2020-09-09T11:24:46Z")

</div>

I need help to figure out the correct json payload for my http monitor to test an authenticated endpoint. Monitor YAML : name: test-xyz-abc-io enabled: true schedule: '@every 1m' # every 10 minutes from start of…

---

## [Cant read metric from apache artemis?](https://discuss.elastic.co/t/cant-read-metric-from-apache-artemis/246609)

<div class="topic-metadata">

**Author:** [@Kiran\_Aher](https://discuss.elastic.co/u/Kiran_Aher)\
**Replies:** 1\
**Last updated:** [September 9, 2020, 11:26am UTC](https://discuss.elastic.co/t/cant-read-metric-from-apache-artemis/246609 "2020-09-09T11:26:40Z")

</div>

Apologize if this is asked already but Im not able to find enough information on either setup document and elastic.co forum as well. We have apache artemis 2.6 running with one broker and trying to get it's metric data …

---

## [Filebeat stops at a certain time](https://discuss.elastic.co/t/filebeat-stops-at-a-certain-time/247979)

<div class="topic-metadata">

**Author:** [@bornatalebi](https://discuss.elastic.co/u/bornatalebi)\
**Replies:** 0\
**Last updated:** [September 9, 2020, 8:47am UTC](https://discuss.elastic.co/t/filebeat-stops-at-a-certain-time/247979 "2020-09-09T08:47:12Z")

</div>

Hi, I have a filebeat with custom index for cisco logs. Here is my filebeat.yaml config: filebeat.inputs: - type: log enabled: true paths: - /var/log/\*.log #- c:\\programdata\\elastic…

---

## [After deleted metric beat index not able to get data from metric beat agent](https://discuss.elastic.co/t/after-deleted-metric-beat-index-not-able-to-get-data-from-metric-beat-agent/247571)

<div class="topic-metadata">

**Author:** [@pankaj0172](https://discuss.elastic.co/u/pankaj0172)\
**Replies:** 2\
**Last updated:** [September 9, 2020, 8:45am UTC](https://discuss.elastic.co/t/after-deleted-metric-beat-index-not-able-to-get-data-from-metric-beat-agent/247571 "2020-09-09T08:45:59Z")

</div>

Hi Team, Can someone please help with the below error message as I deleted the metricbeat index from elastichsearch through Kibana and now I'm not able to get data from metricbeat agent..

---

## [Filebeat with xlsx source](https://discuss.elastic.co/t/filebeat-with-xlsx-source/247969)

<div class="topic-metadata">

**Author:** [@garryrobertson](https://discuss.elastic.co/u/garryrobertson)\
**Replies:** 0\
**Last updated:** [September 9, 2020, 7:36am UTC](https://discuss.elastic.co/t/filebeat-with-xlsx-source/247969 "2020-09-09T07:36:19Z")

</div>

Is it possible to use any of the Beats shippers to send data from an xlsx file from Excel into Elasticsearch? It is straightforward enough with a csv, but how about Excel?

---

## [Heartbeat monitor: use of heartbeat secret store](https://discuss.elastic.co/t/heartbeat-monitor-use-of-heartbeat-secret-store/247770)

<div class="topic-metadata">

**Author:** [@pawarrchetan](https://discuss.elastic.co/u/pawarrchetan)\
**Replies:** 2\
**Last updated:** [September 9, 2020, 6:19am UTC](https://discuss.elastic.co/t/heartbeat-monitor-use-of-heartbeat-secret-store/247770 "2020-09-09T06:19:04Z")

</div>

I would like to use the heartbeat secret store to specify passwords for my https request. I tried testing this option with the username and password fields in the monitor configuration. However the Uptime is reported a…

---

## [Packet beat is not showing the status of down if the port is down](https://discuss.elastic.co/t/packet-beat-is-not-showing-the-status-of-down-if-the-port-is-down/247952)

<div class="topic-metadata">

**Author:** [@jerin](https://discuss.elastic.co/u/jerin)\
**Replies:** 2\
**Last updated:** [September 9, 2020, 5:44am UTC](https://discuss.elastic.co/t/packet-beat-is-not-showing-the-status-of-down-if-the-port-is-down/247952 "2020-09-09T05:44:29Z")

</div>

Hello , I have started to use packetbeat for port monitoring in kibana . These are the current issues when I kill the process (http) , its not showing the exact status of port in elastic search . Even if it's down , …

---

## [How to harvest YAML files using Filebeat and process them in Logstash](https://discuss.elastic.co/t/how-to-harvest-yaml-files-using-filebeat-and-process-them-in-logstash/247910)

<div class="topic-metadata">

**Author:** [@abregman](https://discuss.elastic.co/u/abregman)\
**Replies:** 0\
**Last updated:** [September 8, 2020, 4:07pm UTC](https://discuss.elastic.co/t/how-to-harvest-yaml-files-using-filebeat-and-process-them-in-logstash/247910 "2020-09-08T16:07:55Z")

</div>

I have a YAML file similar to this: --- install: boot: mode: bios build: None buildmods: pin ceph: cluster: name: ceph hci: memreserve: false How can I configure filebeat to collect it a…

---

## [Using exclude\_lines with json logs](https://discuss.elastic.co/t/using-exclude-lines-with-json-logs/247913)

<div class="topic-metadata">

**Author:** [@fabrizio73](https://discuss.elastic.co/u/fabrizio73)\
**Replies:** 0\
**Last updated:** [September 8, 2020, 4:32pm UTC](https://discuss.elastic.co/t/using-exclude-lines-with-json-logs/247913 "2020-09-08T16:32:52Z")

</div>

Hi, we are trying to exclude some line from our PDC Linux server, logging accesses in json format with filebeat . We just need to log real users accesses, without any log related to workstations accounts. For what we r…

---

## [Metric Beats Question](https://discuss.elastic.co/t/metric-beats-question/246664)

<div class="topic-metadata">

**Author:** [@bigbobolue](https://discuss.elastic.co/u/bigbobolue)\
**Replies:** 3\
**Last updated:** [September 8, 2020, 2:48pm UTC](https://discuss.elastic.co/t/metric-beats-question/246664 "2020-09-08T14:48:12Z")

</div>

Should Beats agents that I monitor with metricbeats be displayed in the Stack monitoring?

---

## [Force Filebeat to re process a file](https://discuss.elastic.co/t/force-filebeat-to-re-process-a-file/247901)

<div class="topic-metadata">

**Author:** [@Jackson](https://discuss.elastic.co/u/Jackson)\
**Replies:** 0\
**Last updated:** [September 8, 2020, 1:59pm UTC](https://discuss.elastic.co/t/force-filebeat-to-re-process-a-file/247901 "2020-09-08T13:59:08Z")

</div>

Hello, I added a new file on the filebeat.yml. It went into elastic but some of the fields were not parsed correctly. This file is only updated once per day at 9AM. I modified the filebeat.yml to properly parse the fil…

---

## [Meteicbeat socket\_summary metricset not reult syn\_sent, fin\_wait](https://discuss.elastic.co/t/meteicbeat-socket-summary-metricset-not-reult-syn-sent-fin-wait/247892)

<div class="topic-metadata">

**Author:** [@ryanda\_pratama](https://discuss.elastic.co/u/ryanda_pratama)\
**Replies:** 0\
**Last updated:** [September 8, 2020, 12:32pm UTC](https://discuss.elastic.co/t/meteicbeat-socket-summary-metricset-not-reult-syn-sent-fin-wait/247892 "2020-09-08T12:32:38Z")

</div>

Hello, How to get more result of tcp state connection with metricbeat. Now the result just listen, established, close\_wait, time\_wait. As i see on github, the socket summary.go able to get syn\_sent, fin\_wait etc. Thank…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=213)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=215)
