# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=216

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 217

---

## [Approaches to run metricbeat](https://discuss.elastic.co/t/approaches-to-run-metricbeat/247435)

<div class="topic-metadata">

**Author:** [@nan140114](https://discuss.elastic.co/u/nan140114)\
**Replies:** 1\
**Last updated:** [September 4, 2020, 8:43am UTC](https://discuss.elastic.co/t/approaches-to-run-metricbeat/247435 "2020-09-04T08:43:17Z")

</div>

Hello. I'm trying to set up metricbeat to monitor metrics from cloudwatch. I mean, I wanna send some metrics (ec2, rds, s3 ) from cloudwatch to ELK. I take a look to functionbeat but it's just for CW logs. So, the right …

---

## [Error Collecting in Instrumentation of Beat Pipeline](https://discuss.elastic.co/t/error-collecting-in-instrumentation-of-beat-pipeline/247489)

<div class="topic-metadata">

**Author:** [@Byungjin\_Park](https://discuss.elastic.co/u/Byungjin_Park)\
**Replies:** 0\
**Last updated:** [September 4, 2020, 7:02am UTC](https://discuss.elastic.co/t/error-collecting-in-instrumentation-of-beat-pipeline/247489 "2020-09-04T07:02:20Z")

</div>

There is a new feature which instruments the Beat Pipeline using APM Server. However, I just see no errors in Kibana APM Error page of Beats, although there are some error logs actually. Is there error collection featu…

---

## [Advanced Configuring- Filebeat Loadbalance](https://discuss.elastic.co/t/advanced-configuring-filebeat-loadbalance/247414)

<div class="topic-metadata">

**Author:** [@ofer.h](https://discuss.elastic.co/u/ofer.h)\
**Replies:** 2\
**Last updated:** [September 4, 2020, 6:07am UTC](https://discuss.elastic.co/t/advanced-configuring-filebeat-loadbalance/247414 "2020-09-04T06:07:50Z")

</div>

Hi, I'm trying to send events from Filebeat to Logstash instances on a couple of different servers. Is there an option to configure Filebeat Loadbalance logic? I'm trying to solve these 2 problems: Split traffic dif…

---

## [Not seeing all my hosts in Kibana Infrastructure UI](https://discuss.elastic.co/t/not-seeing-all-my-hosts-in-kibana-infrastructure-ui/247122)

<div class="topic-metadata">

**Author:** [@Delep](https://discuss.elastic.co/u/Delep)\
**Replies:** 0\
**Last updated:** [September 1, 2020, 3:39pm UTC](https://discuss.elastic.co/t/not-seeing-all-my-hosts-in-kibana-infrastructure-ui/247122 "2020-09-01T15:39:05Z")

</div>

Hi, I'm using the elk suite (all in 6.8.6). I've installed metricbeat on all my hosts (more than 250). Config is identical on all hosts: #========================== Modules configuration ============================ …

---

## [ILM for each module fileset](https://discuss.elastic.co/t/ilm-for-each-module-fileset/245812)

<div class="topic-metadata">

**Author:** [@mweissha](https://discuss.elastic.co/u/mweissha)\
**Replies:** 2\
**Last updated:** [September 4, 2020, 12:34am UTC](https://discuss.elastic.co/t/ilm-for-each-module-fileset/245812 "2020-09-04T00:34:41Z")

</div>

Hey all, I'm currently in the process of porting from another logging system over to elasticsearch/kibana using filebeat as the shipper and ingest pipelines on the cloud to parse the data. What I want to accomplish is to…

---

## [Index rollover not working for custom indices](https://discuss.elastic.co/t/index-rollover-not-working-for-custom-indices/245853)

<div class="topic-metadata">

**Author:** [@jijo.john](https://discuss.elastic.co/u/jijo.john)\
**Replies:** 1\
**Last updated:** [September 3, 2020, 11:51pm UTC](https://discuss.elastic.co/t/index-rollover-not-working-for-custom-indices/245853 "2020-09-03T23:51:57Z")

</div>

Hi Team, Kindly help us with the below error , we are having a custom index created and rollover is not working. Below is the error i am getting. illegal\_argument\_exception: index.lifecycle.rollover\_alias \[ciscobeat-7.…

---

## [Can't load modules](https://discuss.elastic.co/t/cant-load-modules/247382)

<div class="topic-metadata">

**Author:** [@headtea](https://discuss.elastic.co/u/headtea)\
**Replies:** 2\
**Last updated:** [September 3, 2020, 10:29pm UTC](https://discuss.elastic.co/t/cant-load-modules/247382 "2020-09-03T22:29:27Z")

</div>

I have a website that is hosted with apache. I can't seem to get the apache module working. I think this is happening because filebeat output is directed to logstash (not elasticsearch). If I just a regular filebeat se…

---

## [What is the unit of measure for rtt times in heartbeat](https://discuss.elastic.co/t/what-is-the-unit-of-measure-for-rtt-times-in-heartbeat/247455)

<div class="topic-metadata">

**Author:** [@aviationfan](https://discuss.elastic.co/u/aviationfan)\
**Replies:** 2\
**Last updated:** [September 3, 2020, 10:18pm UTC](https://discuss.elastic.co/t/what-is-the-unit-of-measure-for-rtt-times-in-heartbeat/247455 "2020-09-03T22:18:49Z")

</div>

I have a sample showing the following json snippet "tcp": { "rtt": { "connect": { "us": 79589 } } }, Is that 79,589 nanoseconds?

---

## [Setting up beat.hostname in Metricbeat](https://discuss.elastic.co/t/setting-up-beat-hostname-in-metricbeat/247442)

<div class="topic-metadata">

**Author:** [@YemaneZewdu](https://discuss.elastic.co/u/YemaneZewdu)\
**Replies:** 4\
**Last updated:** [September 3, 2020, 9:24pm UTC](https://discuss.elastic.co/t/setting-up-beat-hostname-in-metricbeat/247442 "2020-09-03T21:24:50Z")

</div>

0 I am super new to these concepts, I apologize if this is a silly thing. I am trying to visualize Metricbeat data on Grafana with Elasticsearch data source, all running locally, but unable to find where "beat.hostname"…

---

## [Multiline not working properly when used along with exclude\_lines](https://discuss.elastic.co/t/multiline-not-working-properly-when-used-along-with-exclude-lines/247422)

<div class="topic-metadata">

**Author:** [@MANI\_M](https://discuss.elastic.co/u/MANI_M)\
**Replies:** 0\
**Last updated:** [September 3, 2020, 4:24pm UTC](https://discuss.elastic.co/t/multiline-not-working-properly-when-used-along-with-exclude-lines/247422 "2020-09-03T16:24:37Z")

</div>

We were trying to combine all the logs into a single event after excluding lines with a specific pattern. But it seems filebeat is appending the excluded lines in multiline and misses out other data leading to misbehavio…

---

## [Error running Metricbeat 7.6 on AKS K8S cluster](https://discuss.elastic.co/t/error-running-metricbeat-7-6-on-aks-k8s-cluster/246608)

<div class="topic-metadata">

**Author:** [@mirii1994](https://discuss.elastic.co/u/mirii1994)\
**Replies:** 5\
**Last updated:** [September 3, 2020, 2:38pm UTC](https://discuss.elastic.co/t/error-running-metricbeat-7-6-on-aks-k8s-cluster/246608 "2020-09-03T14:38:03Z")

</div>

I'm trying to run metricbeat 7.6.2 on my AKS cluster (k8s version 1.16), And getting the following errors: 2020-08-27T11:00:03.417Z INFO module/wrapper.go:252 Error fetching data for metricset kubernetes.volume: error …

---

## [Winlogbeat drop specific system events](https://discuss.elastic.co/t/winlogbeat-drop-specific-system-events/247275)

<div class="topic-metadata">

**Author:** [@StlAR](https://discuss.elastic.co/u/StlAR)\
**Replies:** 1\
**Last updated:** [September 3, 2020, 1:30pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-specific-system-events/247275 "2020-09-03T13:30:28Z")

</div>

I'm looking to collect specific System events. I would like all error and warning events. Only 36880 information events. And finally ignore older than 72 hours. This code checks out but still including information eve…

---

## [Journalbeat message format](https://discuss.elastic.co/t/journalbeat-message-format/247289)

<div class="topic-metadata">

**Author:** [@cartesian-theatrics](https://discuss.elastic.co/u/cartesian-theatrics)\
**Replies:** 3\
**Last updated:** [September 3, 2020, 1:15pm UTC](https://discuss.elastic.co/t/journalbeat-message-format/247289 "2020-09-03T13:15:43Z")

</div>

Hello, I'm looking for documentation on the journalbeat message format? I need to understand what I can about the format in order to understand the tradeoffs related to batching. Thanks, John

---

## [\[Filebeat\] Range:%20990%0AX-SA-ID:%20778 to multiple fields](https://discuss.elastic.co/t/filebeat-range-20990-0ax-sa-id-20778-to-multiple-fields/247346)

<div class="topic-metadata">

**Author:** [@Kuo\_Hugo](https://discuss.elastic.co/u/Kuo_Hugo)\
**Replies:** 1\
**Last updated:** [September 3, 2020, 10:17am UTC](https://discuss.elastic.co/t/filebeat-range-20990-0ax-sa-id-20778-to-multiple-fields/247346 "2020-09-03T10:17:04Z")

</div>

Hi, May I know if there's a way to split the string into multiple fields? Range:%20990%0AX-SA-ID:%20778 This is encoded. The decoded string is Range: 990\\nX-SA-ID: 778 My goal is to split it into multiple field and …

---

## [Filebeat: How to differentiate data from different types sources on same port?](https://discuss.elastic.co/t/filebeat-how-to-differentiate-data-from-different-types-sources-on-same-port/247175)

<div class="topic-metadata">

**Author:** [@denis.atanasov](https://discuss.elastic.co/u/denis.atanasov)\
**Replies:** 3\
**Last updated:** [September 2, 2020, 9:12pm UTC](https://discuss.elastic.co/t/filebeat-how-to-differentiate-data-from-different-types-sources-on-same-port/247175 "2020-09-02T21:12:35Z")

</div>

Hello guys, I setup a Filebeat (7.9) on my ELK(7.9) and started receiving syslog messages. So far so good, everything is parsed and visualized successfully. However I am facing problems, when I enable 2 different modul…

---

## [How I can fetch the apache and node logs through filebeat](https://discuss.elastic.co/t/how-i-can-fetch-the-apache-and-node-logs-through-filebeat/246926)

<div class="topic-metadata">

**Author:** [@Priya\_Kapoor](https://discuss.elastic.co/u/Priya_Kapoor)\
**Replies:** 7\
**Last updated:** [September 2, 2020, 9:02pm UTC](https://discuss.elastic.co/t/how-i-can-fetch-the-apache-and-node-logs-through-filebeat/246926 "2020-09-02T21:02:24Z")

</div>

Both the logs are on same server. I am using filebeat 7.8.0 and want both the apache and node logs on different index.

---

## [Any of metricbeat modules require JDK?](https://discuss.elastic.co/t/any-of-metricbeat-modules-require-jdk/247246)

<div class="topic-metadata">

**Author:** [@Prashant\_Achari](https://discuss.elastic.co/u/Prashant_Achari)\
**Replies:** 1\
**Last updated:** [September 2, 2020, 2:17pm UTC](https://discuss.elastic.co/t/any-of-metricbeat-modules-require-jdk/247246 "2020-09-02T14:17:38Z")

</div>

I need to install metricbeat with modules ( MQ,Jolokia,apache,oracle) on multiple servers is jdk mandatory before we install beat ?

---

## [Ingesting CloudTrail logs from multiple AWS accounts](https://discuss.elastic.co/t/ingesting-cloudtrail-logs-from-multiple-aws-accounts/246999)

<div class="topic-metadata">

**Author:** [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Replies:** 3\
**Last updated:** [September 2, 2020, 1:43pm UTC](https://discuss.elastic.co/t/ingesting-cloudtrail-logs-from-multiple-aws-accounts/246999 "2020-09-02T13:43:49Z")

</div>

Brief: We do have multiple AWS accounts and we would prefer to ingest cloudtrail logs from all our accounts via Filebeat's AWS Module. (filebeat from same/single server & single agent) ELK-Stack: 7.8.0 Filebeat: 7.8.0 …

---

## [Fortinet message field not being parsed correctly](https://discuss.elastic.co/t/fortinet-message-field-not-being-parsed-correctly/247236)

<div class="topic-metadata">

**Author:** [@tocheeba](https://discuss.elastic.co/u/tocheeba)\
**Replies:** 0\
**Last updated:** [September 2, 2020, 1:05pm UTC](https://discuss.elastic.co/t/fortinet-message-field-not-being-parsed-correctly/247236 "2020-09-02T13:05:04Z")

</div>

I've been trying to get this working for the past 3 weeks, and have read literally every forum post, reddit post, etc., on this. I'm spinning my wheels and can't figure out what is going wrong. I've tried using Filebeat…

---

## [Beats return conflicting mapping](https://discuss.elastic.co/t/beats-return-conflicting-mapping/247227)

<div class="topic-metadata">

**Author:** [@a\_maze](https://discuss.elastic.co/u/a_maze)\
**Replies:** 0\
**Last updated:** [September 2, 2020, 11:59am UTC](https://discuss.elastic.co/t/beats-return-conflicting-mapping/247227 "2020-09-02T11:59:25Z")

</div>

Hello, I am struggling to get a very basic ElasticStack / filebeat setup running. Everything was ok while I was using 7.8.1, but since I upgraded to 7.9.0 the Beats have been creating conflicts in my indexes. It's onl…

---

## [Create metricset failed](https://discuss.elastic.co/t/create-metricset-failed/247162)

<div class="topic-metadata">

**Author:** [@icaruswu](https://discuss.elastic.co/u/icaruswu)\
**Replies:** 3\
**Last updated:** [September 2, 2020, 11:46am UTC](https://discuss.elastic.co/t/create-metricset-failed/247162 "2020-09-02T11:46:32Z")

</div>

Help!! I git clone the beats source codes, and cd into the metricbeat to execute 'make create-metricset', then failed: icaruswu@icaruswu-B460MDS3H:~/go/src/beats/metricbeat$ make create-metricset mage createMetricset …

---

## [Multiple instance of Filebeat](https://discuss.elastic.co/t/multiple-instance-of-filebeat/247164)

<div class="topic-metadata">

**Author:** [@Priya\_Kapoor](https://discuss.elastic.co/u/Priya_Kapoor)\
**Replies:** 7\
**Last updated:** [September 2, 2020, 5:29am UTC](https://discuss.elastic.co/t/multiple-instance-of-filebeat/247164 "2020-09-02T05:29:12Z")

</div>

How I can create multiple instance for filebeat 7.4.2. I am new to ELK kindly help.

---

## [How can I load my new metricbeat module to ES and Kibana?](https://discuss.elastic.co/t/how-can-i-load-my-new-metricbeat-module-to-es-and-kibana/246233)

<div class="topic-metadata">

**Author:** [@icaruswu](https://discuss.elastic.co/u/icaruswu)\
**Replies:** 3\
**Last updated:** [September 2, 2020, 4:49am UTC](https://discuss.elastic.co/t/how-can-i-load-my-new-metricbeat-module-to-es-and-kibana/246233 "2020-09-02T04:49:50Z")

</div>

I create a new metricbeat module and succeed in getting data, and how can I load this new module to the Elasticsearch and Kibana? I used the localhost:5601 dashboard to check my new module, but did not get the new module…

---

## [Fetch application logs running on kubernetes using filebeat](https://discuss.elastic.co/t/fetch-application-logs-running-on-kubernetes-using-filebeat/247075)

<div class="topic-metadata">

**Author:** [@Shefali](https://discuss.elastic.co/u/Shefali)\
**Replies:** 1\
**Last updated:** [September 2, 2020, 1:59am UTC](https://discuss.elastic.co/t/fetch-application-logs-running-on-kubernetes-using-filebeat/247075 "2020-09-02T01:59:17Z")

</div>

I am trying to find proper solution but haven't got any. My java application is running on kubernetes and creating logs inside the pod. I have to fetch those logs from filebeat to elasticsearch (running on the server). …

---

## [Beats to create daily index](https://discuss.elastic.co/t/beats-to-create-daily-index/247096)

<div class="topic-metadata">

**Author:** [@headtea](https://discuss.elastic.co/u/headtea)\
**Replies:** 2\
**Last updated:** [September 2, 2020, 12:31am UTC](https://discuss.elastic.co/t/beats-to-create-daily-index/247096 "2020-09-02T00:31:43Z")

</div>

Auditbeat is configured to send data to Elasticsearch directly. I'm trying to get auditbeat to create a new index every day. Right now this is the index that beats uses: auditbeat-7.9.0-2020.08.24-000001, even though to…

---

## [Filebeat + netflow module , there is nothing to visualize on kibana](https://discuss.elastic.co/t/filebeat-netflow-module-there-is-nothing-to-visualize-on-kibana/246849)

<div class="topic-metadata">

**Author:** [@leostereo](https://discuss.elastic.co/u/leostereo)\
**Replies:** 13\
**Last updated:** [September 1, 2020, 8:55pm UTC](https://discuss.elastic.co/t/filebeat-netflow-module-there-is-nothing-to-visualize-on-kibana/246849 "2020-09-01T20:55:49Z")

</div>

Hi guys , im very exited about watching netflow data on elk. My elk is already working, I added metricbeat and can see nice graphics. Then with similar methods , installed filebeat and enable netflow module following t…

---

## [Heartbeat 7.9.0 Http Send Request Headers not working](https://discuss.elastic.co/t/heartbeat-7-9-0-http-send-request-headers-not-working/246157)

<div class="topic-metadata">

**Author:** [@simonowusu](https://discuss.elastic.co/u/simonowusu)\
**Replies:** 3\
**Last updated:** [September 1, 2020, 3:52pm UTC](https://discuss.elastic.co/t/heartbeat-7-9-0-http-send-request-headers-not-working/246157 "2020-09-01T15:52:36Z")

</div>

Trying to send the user information which is required as part of the Header Http Monitor # Request settings: check.request: # Configure HTTP method to use. Only 'HEAD', 'GET' and 'POST' methods are allowed. m…

---

## [Index Management](https://discuss.elastic.co/t/index-management/246979)

<div class="topic-metadata">

**Author:** [@Pierrelaurent](https://discuss.elastic.co/u/Pierrelaurent)\
**Replies:** 8\
**Last updated:** [September 1, 2020, 1:16pm UTC](https://discuss.elastic.co/t/index-management/246979 "2020-09-01T13:16:46Z")

</div>

Hi There I keep getting this error when i try to start metricbeat. I have got the newest version of Logstash Elasticsearch and Kibana running on centos 7 ERROR instance/beat.go:951 Exiting: Index management requested b…

---

## [Tracer in libbeat is always enabled](https://discuss.elastic.co/t/tracer-in-libbeat-is-always-enabled/245742)

<div class="topic-metadata">

**Author:** [@newly](https://discuss.elastic.co/u/newly)\
**Replies:** 5\
**Last updated:** [September 1, 2020, 9:32am UTC](https://discuss.elastic.co/t/tracer-in-libbeat-is-always-enabled/245742 "2020-09-01T09:32:06Z")

</div>

here the tracer will always be given apm.DefaultTracer, hence these statements are always reached, and apm.DefaultTracer seems not to be fully disabled. while we don't have apm server setup/configured, StartTransaction …

---

## [Elastic Agent - Windows logs + Tagging](https://discuss.elastic.co/t/elastic-agent-windows-logs-tagging/247032)

<div class="topic-metadata">

**Author:** [@danielsnelling](https://discuss.elastic.co/u/danielsnelling)\
**Replies:** 4\
**Last updated:** [September 1, 2020, 7:21am UTC](https://discuss.elastic.co/t/elastic-agent-windows-logs-tagging/247032 "2020-09-01T07:21:39Z")

</div>

Hi, does anyone know if the Elastic Agent/Ingest Manager will be getting a Winlogbeat integration module? Currently we are deploying Auditbeat/Filebeat/Metricbeat/Winlogbeat + Sysmon in a MSI bundle, as well as a separa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=215)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=217)
