# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=215

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 216

---

## [Java stack trace - Multiline config](https://discuss.elastic.co/t/java-stack-trace-multiline-config/247889)

<div class="topic-metadata">

**Author:** [@sidiney.crescencio](https://discuss.elastic.co/u/sidiney.crescencio)\
**Replies:** 0\
**Last updated:** [September 8, 2020, 12:22pm UTC](https://discuss.elastic.co/t/java-stack-trace-multiline-config/247889 "2020-09-08T12:22:26Z")

</div>

Hello, I'm trying to configure a multiline pattern to get any exceptions in my application logs, unfortunately I haven't been able yet to find a good pattern. Sample logs 2020-09-08 13:24:13.406 INFO 17739 --- \[ \] c…

---

## [Metricbeat 6.8.12 xpack.enabled for Logstash module](https://discuss.elastic.co/t/metricbeat-6-8-12-xpack-enabled-for-logstash-module/247849)

<div class="topic-metadata">

**Author:** [@Di\_Croatiano](https://discuss.elastic.co/u/Di_Croatiano)\
**Replies:** 0\
**Last updated:** [September 8, 2020, 8:43am UTC](https://discuss.elastic.co/t/metricbeat-6-8-12-xpack-enabled-for-logstash-module/247849 "2020-09-08T08:43:05Z")

</div>

Greetings! I was reading a docs about Metricbeat modules, searching for ELK modules configuration. Finding an option for Elasticsearch and Kibana and how easy is to collect and show metric data in Elastic Stack monitori…

---

## [Multiple inputs for Filebeat](https://discuss.elastic.co/t/multiple-inputs-for-filebeat/247519)

<div class="topic-metadata">

**Author:** [@Sid](https://discuss.elastic.co/u/Sid)\
**Replies:** 2\
**Last updated:** [September 8, 2020, 8:33am UTC](https://discuss.elastic.co/t/multiple-inputs-for-filebeat/247519 "2020-09-08T08:33:47Z")

</div>

Is it possible in Filebeat to have multiple log sources as inputs and indexed into different Elasticsearch indices? Suppose I have apache access logs & mysql logs. How to enable filebeat modules for apache and mysql ava…

---

## [Modify Beats Output](https://discuss.elastic.co/t/modify-beats-output/247841)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 0\
**Last updated:** [September 8, 2020, 8:06am UTC](https://discuss.elastic.co/t/modify-beats-output/247841 "2020-09-08T08:06:36Z")

</div>

Hi There, I have two queries regarding the beats event output If i install winlobeat and auditbeat on the same machine , In the SIEM host table i am getting two hosts as below (one with Just hostname and other with fq…

---

## [Kafka module of metrcbeat field question](https://discuss.elastic.co/t/kafka-module-of-metrcbeat-field-question/247752)

<div class="topic-metadata">

**Author:** [@8wlgns](https://discuss.elastic.co/u/8wlgns)\
**Replies:** 0\
**Last updated:** [September 7, 2020, 10:06am UTC](https://discuss.elastic.co/t/kafka-module-of-metrcbeat-field-question/247752 "2020-09-07T10:06:57Z")

</div>

Hello? I want to get metrics that is newest events of duration(sec) on Kafka. Could I use kafka.broker.messages\_in ? Is it all newest events per duration (second) ? https://www.elastic.co/guide/en/beats/metricbeat/cu…

---

## [Syslog input doesn't seem to work, rsyslog error -2027](https://discuss.elastic.co/t/syslog-input-doesnt-seem-to-work-rsyslog-error-2027/247797)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [September 7, 2020, 9:15pm UTC](https://discuss.elastic.co/t/syslog-input-doesnt-seem-to-work-rsyslog-error-2027/247797 "2020-09-07T21:15:07Z")

</div>

Hey all, I'm having issues getting the Filebeat syslog input plugin to receive remote syslog messages. My filebeat config looks like: filebeat: config: modules: path: ${path.config}/modules.d/\*.yml r…

---

## [Can't Start Filebeat from docker compose](https://discuss.elastic.co/t/cant-start-filebeat-from-docker-compose/247788)

<div class="topic-metadata">

**Author:** [@Mostafa\_Hamdy](https://discuss.elastic.co/u/Mostafa_Hamdy)\
**Replies:** 0\
**Last updated:** [September 7, 2020, 3:57pm UTC](https://discuss.elastic.co/t/cant-start-filebeat-from-docker-compose/247788 "2020-09-07T15:57:33Z")

</div>

I am trying to start filebeat using docker compose. but i am facing this error /usr/local/bin/docker-entrypoint: line 8: exec: filebeat: not found This is my docker-compose filebeat: image: docker.elasti…

---

## [FileBeat as a service. After rebooting the system it starts automatically](https://discuss.elastic.co/t/filebeat-as-a-service-after-rebooting-the-system-it-starts-automatically/241075)

<div class="topic-metadata">

**Author:** [@TUSHAR\_Sinha](https://discuss.elastic.co/u/TUSHAR_Sinha)\
**Replies:** 12\
**Last updated:** [September 7, 2020, 3:04pm UTC](https://discuss.elastic.co/t/filebeat-as-a-service-after-rebooting-the-system-it-starts-automatically/241075 "2020-09-07T15:04:00Z")

</div>

Hi all, I want to know can we run filebeat as a service. So, whenever someone rebots the system it automatically starts running again. The system in which my filebeat is running, has access to different people sometimes…

---

## [Number of fields and size](https://discuss.elastic.co/t/number-of-fields-and-size/247610)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [September 7, 2020, 2:01am UTC](https://discuss.elastic.co/t/number-of-fields-and-size/247610 "2020-09-07T02:01:27Z")

</div>

if I turn on metricbeat by default it has more then 2000+ field. but if I am only monitoring system matric. will that empthy field that I saw in pattern will use space? removing them is very time consuming exercise.

---

## [Ingest pipeline drops the field as @timestamp while loading Elasticsearch's server and slowlog using filebeat](https://discuss.elastic.co/t/ingest-pipeline-drops-the-field-as-timestamp-while-loading-elasticsearchs-server-and-slowlog-using-filebeat/247031)

<div class="topic-metadata">

**Author:** [@Prashant\_Agrawal](https://discuss.elastic.co/u/Prashant_Agrawal)\
**Replies:** 9\
**Last updated:** [September 6, 2020, 11:08pm UTC](https://discuss.elastic.co/t/ingest-pipeline-drops-the-field-as-timestamp-while-loading-elasticsearchs-server-and-slowlog-using-filebeat/247031 "2020-09-06T23:08:34Z")

</div>

Ingest pipeline drops the field as @timestamp while loading Elasticsearch's server and slowlog using filebeat. "filebeat-7.9.0-elasticsearch-server-pipeline" : { "description" : "Pipeline for parsing elasticsearch ser…

---

## [Metricbeat setup error](https://discuss.elastic.co/t/metricbeat-setup-error/247671)

<div class="topic-metadata">

**Author:** [@hanuman513](https://discuss.elastic.co/u/hanuman513)\
**Replies:** 4\
**Last updated:** [September 6, 2020, 9:29pm UTC](https://discuss.elastic.co/t/metricbeat-setup-error/247671 "2020-09-06T21:29:09Z")

</div>

metricbeat setup --dashboards Loading dashboards (Kibana must be running and reachable) Exiting: fail to create the Kibana loader: Error creating Kibana client: Error creating Kibana client: fail to get the Kibana ver…

---

## [Setup filebeat module](https://discuss.elastic.co/t/setup-filebeat-module/247658)

<div class="topic-metadata">

**Author:** [@headtea](https://discuss.elastic.co/u/headtea)\
**Replies:** 6\
**Last updated:** [September 6, 2020, 11:35am UTC](https://discuss.elastic.co/t/setup-filebeat-module/247658 "2020-09-06T11:35:12Z")

</div>

I'm trying to set up the apache module in filebeat. I output filebeat to logstash. Just for some context I've enabled pipelines with this command: filebeat setup --pipelines --dashboards --modules apache -E output.logst…

---

## [Default ingest pipeline not working](https://discuss.elastic.co/t/default-ingest-pipeline-not-working/247639)

<div class="topic-metadata">

**Author:** [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Replies:** 5\
**Last updated:** [September 6, 2020, 6:26am UTC](https://discuss.elastic.co/t/default-ingest-pipeline-not-working/247639 "2020-09-06T06:26:03Z")

</div>

Hi, I'm pretty new in elastic search so sorry if it's a newbie question. I want to change the ingest pipeline and index for my cisco ios module. I tried changing them in filebeat.yml file. my config so far: filebeat.in…

---

## [Winlogbeat is not accpeting .crt and .key](https://discuss.elastic.co/t/winlogbeat-is-not-accpeting-crt-and-key/247636)

<div class="topic-metadata">

**Author:** [@Rahul\_Dankhara](https://discuss.elastic.co/u/Rahul_Dankhara)\
**Replies:** 0\
**Last updated:** [September 5, 2020, 3:01pm UTC](https://discuss.elastic.co/t/winlogbeat-is-not-accpeting-crt-and-key/247636 "2020-09-05T15:01:46Z")

</div>

I am using .crt and .key for authentication of filebeat with logstash. Which is working perfectly fine. I am using the same certificates for winlogbeat and it is not working as expected. Followed this doc to create .ca…

---

## [A Yocto meta layer for Beats](https://discuss.elastic.co/t/a-yocto-meta-layer-for-beats/247631)

<div class="topic-metadata">

**Author:** [@dimtass](https://discuss.elastic.co/u/dimtass)\
**Replies:** 0\
**Last updated:** [September 5, 2020, 11:04am UTC](https://discuss.elastic.co/t/a-yocto-meta-layer-for-beats/247631 "2020-09-05T11:04:15Z")

</div>

Hi all, I've recently created a Yocto meta layer to add beats in custom images. The meta layer is only software layer with dependencies on poky and meta-openembedded. I've built and tested on a nanopi-k1-plus (allwinner …

---

## [Configuring multiple filebeat instances in Kubernetes](https://discuss.elastic.co/t/configuring-multiple-filebeat-instances-in-kubernetes/247620)

<div class="topic-metadata">

**Author:** [@trondhindenes](https://discuss.elastic.co/u/trondhindenes)\
**Replies:** 0\
**Last updated:** [September 5, 2020, 8:01am UTC](https://discuss.elastic.co/t/configuring-multiple-filebeat-instances-in-kubernetes/247620 "2020-09-05T08:01:47Z")

</div>

Hi, We're currently running a well-working setup for indexing nginx sidecar logs using filebeat. It consists of a filebeat container per node, and in our app deployments we have annotations such as annotations: …

---

## [Perfmon counter: The returned value is not valid](https://discuss.elastic.co/t/perfmon-counter-the-returned-value-is-not-valid/247471)

<div class="topic-metadata">

**Author:** [@sleepy](https://discuss.elastic.co/u/sleepy)\
**Replies:** 2\
**Last updated:** [September 5, 2020, 1:04am UTC](https://discuss.elastic.co/t/perfmon-counter-the-returned-value-is-not-valid/247471 "2020-09-05T01:04:24Z")

</div>

Hai, I am currently using metricbeat 7.9.0 in windows to monitor the cpu usage of it. windows.yml: - module: windows metricsets: \[perfmon\] period: 20s perfmon.ignore\_non\_existent\_counters: true …

---

## [Filebeat in crashing 7.9.0](https://discuss.elastic.co/t/filebeat-in-crashing-7-9-0/247425)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 2\
**Last updated:** [September 5, 2020, 12:53am UTC](https://discuss.elastic.co/t/filebeat-in-crashing-7-9-0/247425 "2020-09-05T00:53:28Z")

</div>

filebeat is crashing, everything works and feeds for 30min then filebeat crashes centos 6.10 filebeat 7.9.0 yum package install increased logging to debug these are the last lines of the filebeat logs 2020-09-03T1…

---

## [Monitor activemq inside a Kubernetes Cluster](https://discuss.elastic.co/t/monitor-activemq-inside-a-kubernetes-cluster/247604)

<div class="topic-metadata">

**Author:** [@Shereef\_Adekunle](https://discuss.elastic.co/u/Shereef_Adekunle)\
**Replies:** 0\
**Last updated:** [September 4, 2020, 10:00pm UTC](https://discuss.elastic.co/t/monitor-activemq-inside-a-kubernetes-cluster/247604 "2020-09-04T22:00:49Z")

</div>

Hello, I am currently trying to have my Elastic Cloud monitor an activemq broker running in a Kubernetes pod. I know on VMs you would just enable the activemq module to monitor it, but how can I install metricbeat within…

---

## [Missing index pattern heartbeat-\*](https://discuss.elastic.co/t/missing-index-pattern-heartbeat/247394)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 6\
**Last updated:** [September 4, 2020, 9:08pm UTC](https://discuss.elastic.co/t/missing-index-pattern-heartbeat/247394 "2020-09-04T21:08:40Z")

</div>

Hi, I am using ELK 7.9. I have installed and confirmed working fine Winlogbeat, Packetbeat and Auditbeat. But regarding Heartbeat, apparently is working fine, as is communicating with Elasticsearch, but is the only beat…

---

## [Winlogbeat registry file issues](https://discuss.elastic.co/t/winlogbeat-registry-file-issues/247567)

<div class="topic-metadata">

**Author:** [@jlwingo](https://discuss.elastic.co/u/jlwingo)\
**Replies:** 0\
**Last updated:** [September 4, 2020, 3:22pm UTC](https://discuss.elastic.co/t/winlogbeat-registry-file-issues/247567 "2020-09-04T15:22:22Z")

</div>

I am new to winlogbeat and just trying to get it rolled out across all of our windows servers. I just pushed out Winlogbeat to our devtest environment. I had no issues with sandbox environment or any issues when test i…

---

## [Filebeat processor](https://discuss.elastic.co/t/filebeat-processor/247585)

<div class="topic-metadata">

**Author:** [@Jockj](https://discuss.elastic.co/u/Jockj)\
**Replies:** 0\
**Last updated:** [September 4, 2020, 6:54pm UTC](https://discuss.elastic.co/t/filebeat-processor/247585 "2020-09-04T18:54:45Z")

</div>

Is there any document for create one filebeat processor? how the filebeat call the processor?

---

## [How to Run Metricbeat in Docker with Modules to Monitor Other Containers](https://discuss.elastic.co/t/how-to-run-metricbeat-in-docker-with-modules-to-monitor-other-containers/247112)

<div class="topic-metadata">

**Author:** [@chancewwr](https://discuss.elastic.co/u/chancewwr)\
**Replies:** 8\
**Last updated:** [September 4, 2020, 6:26pm UTC](https://discuss.elastic.co/t/how-to-run-metricbeat-in-docker-with-modules-to-monitor-other-containers/247112 "2020-09-04T18:26:09Z")

</div>

Hello all, I'm trying to use Metricbeat to monitor my elasticstack. Logstash, Elasticsearch, Kibana, and some Beats are all running inside of docker containers. I am wondering what is the best way to use Metricbeat to mo…

---

## [Heartbeat not able to connect the HTTP Endpoint via Proxy](https://discuss.elastic.co/t/heartbeat-not-able-to-connect-the-http-endpoint-via-proxy/246393)

<div class="topic-metadata">

**Author:** [@rakesh15](https://discuss.elastic.co/u/rakesh15)\
**Replies:** 3\
**Last updated:** [September 4, 2020, 3:59pm UTC](https://discuss.elastic.co/t/heartbeat-not-able-to-connect-the-http-endpoint-via-proxy/246393 "2020-09-04T15:59:43Z")

</div>

Hi All, Im try to configure the heartbeat to monitor the up time for endpoint. Below is the configuration for the same. - type: http name: JocataHealthCheck schedule: '@every 60s' urls: \["https://SomeURL/rest/joc…

---

## [Filebeat process not running after upgrade from 7.6.2 to 7.8.1](https://discuss.elastic.co/t/filebeat-process-not-running-after-upgrade-from-7-6-2-to-7-8-1/247459)

<div class="topic-metadata">

**Author:** [@new11](https://discuss.elastic.co/u/new11)\
**Replies:** 4\
**Last updated:** [September 4, 2020, 3:08pm UTC](https://discuss.elastic.co/t/filebeat-process-not-running-after-upgrade-from-7-6-2-to-7-8-1/247459 "2020-09-04T15:08:19Z")

</div>

Hi all, One of the instance is having beat error after upgrade from 7.6.2 to 7.8.1. as below, ERROR instance/beat.go:933 Exiting: data path already locked by another beat out of 2 instances one instance upgrade had be…

---

## [Metricbeat dashboards changed after kibana update](https://discuss.elastic.co/t/metricbeat-dashboards-changed-after-kibana-update/247413)

<div class="topic-metadata">

**Author:** [@kibit86](https://discuss.elastic.co/u/kibit86)\
**Replies:** 2\
**Last updated:** [September 4, 2020, 2:31pm UTC](https://discuss.elastic.co/t/metricbeat-dashboards-changed-after-kibana-update/247413 "2020-09-04T14:31:45Z")

</div>

Hi all, I have a 3 nodes cluster that was on version 7.1.1 until yesterday. I updated the cluster performing small steps (7.2-7.3-7.6-7.9) in order to start playing with the new alerting framework. I use beats to send…

---

## [Redis slowlog module + Kubernetes secrets =\> error :/](https://discuss.elastic.co/t/redis-slowlog-module-kubernetes-secrets-error/246827)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 6\
**Last updated:** [September 4, 2020, 1:32pm UTC](https://discuss.elastic.co/t/redis-slowlog-module-kubernetes-secrets-error/246827 "2020-09-04T13:32:40Z")

</div>

Hi thanks for the beautiful elastic stack! I am using Redis slowlog module + k8s secrets but then it fails. EDIT: My guess - maybe the var.password do not understand k8s secrets? (just a naive guess) The yaml # ref: h…

---

## [Metricbeat is not loading fields.yml](https://discuss.elastic.co/t/metricbeat-is-not-loading-fields-yml/247390)

<div class="topic-metadata">

**Author:** [@vamsikrishna\_medeti](https://discuss.elastic.co/u/vamsikrishna_medeti)\
**Replies:** 2\
**Last updated:** [September 4, 2020, 9:25am UTC](https://discuss.elastic.co/t/metricbeat-is-not-loading-fields-yml/247390 "2020-09-04T09:25:58Z")

</div>

Hi, I am using metricbeat 7.9.0 daemonset on k8s environment to export the metrics to ELK stack. But I am getting the errors like " Fielddata is disabled on text fields by default. Set fielddata=true on \[cloud.account.…

---

## [Metricbeat and Zookeeper security](https://discuss.elastic.co/t/metricbeat-and-zookeeper-security/247491)

<div class="topic-metadata">

**Author:** [@gquintana](https://discuss.elastic.co/u/gquintana)\
**Replies:** 0\
**Last updated:** [September 4, 2020, 7:20am UTC](https://discuss.elastic.co/t/metricbeat-and-zookeeper-security/247491 "2020-09-04T07:20:50Z")

</div>

Is it possible to use a secure connection between Metricbeat Zookeeper module and Zookeeper. I mean is it possible to enable SASL authentication on Zookeeper side https://docs.confluent.io/current/security/zk-security…

---

## [The container data collected by metricbeat is inconsistent with the computer top command](https://discuss.elastic.co/t/the-container-data-collected-by-metricbeat-is-inconsistent-with-the-computer-top-command/247470)

<div class="topic-metadata">

**Author:** [@ZenSwordzhang](https://discuss.elastic.co/u/ZenSwordzhang)\
**Replies:** 1\
**Last updated:** [September 4, 2020, 8:48am UTC](https://discuss.elastic.co/t/the-container-data-collected-by-metricbeat-is-inconsistent-with-the-computer-top-command/247470 "2020-09-04T08:48:54Z")

</div>

This is the collected es container indicator data This is the computer data seen by the top command Why is this?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=214)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=216)
