# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=217

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 218

---

## [Is Metricbeat meant to ship hundreds of docs per second?](https://discuss.elastic.co/t/is-metricbeat-meant-to-ship-hundreds-of-docs-per-second/244495)

<div class="topic-metadata">

**Author:** [@di.lu](https://discuss.elastic.co/u/di.lu)\
**Replies:** 5\
**Last updated:** [September 1, 2020, 5:40am UTC](https://discuss.elastic.co/t/is-metricbeat-meant-to-ship-hundreds-of-docs-per-second/244495 "2020-09-01T05:40:38Z")

</div>

Hiii All, I've just started adding Metricbeat to my K8S cluster following this tutorial: https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-kubernetes.html Everything works fine and I was able to see M…

---

## [Exiting: resource 'filebeat-7.9.0' exists, but it is not an alias](https://discuss.elastic.co/t/exiting-resource-filebeat-7-9-0-exists-but-it-is-not-an-alias/245745)

<div class="topic-metadata">

**Author:** [@oicfar](https://discuss.elastic.co/u/oicfar)\
**Replies:** 10\
**Last updated:** [August 31, 2020, 8:38pm UTC](https://discuss.elastic.co/t/exiting-resource-filebeat-7-9-0-exists-but-it-is-not-an-alias/245745 "2020-08-31T20:38:55Z")

</div>

hi, after update to ELK 7.9.0 I deleted the filebeat-7.8.x indexes, templatres and now I see this Exiting: resource 'filebeat-7.9.0' exists, but it is not an alias ERROR in the log. Regards, Rafal

---

## [Metricbeat MongoDB Dashboard - Memory stats issue](https://discuss.elastic.co/t/metricbeat-mongodb-dashboard-memory-stats-issue/246570)

<div class="topic-metadata">

**Author:** [@sandeep3](https://discuss.elastic.co/u/sandeep3)\
**Replies:** 1\
**Last updated:** [August 31, 2020, 5:34pm UTC](https://discuss.elastic.co/t/metricbeat-mongodb-dashboard-memory-stats-issue/246570 "2020-08-31T17:34:04Z")

</div>

Hi , Even after configured the Metricbeat dashboard for MongoDB. The dashboard displaying the number of connections and opcounters but not displaying the memort stats. Here we are using the mongodb cluster and we need t…

---

## [Elastic Agent System Integration](https://discuss.elastic.co/t/elastic-agent-system-integration/246607)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 2\
**Last updated:** [August 31, 2020, 1:59pm UTC](https://discuss.elastic.co/t/elastic-agent-system-integration/246607 "2020-08-31T13:59:13Z")

</div>

The Elastic Agent collects Filebeat logs. Within 'Fleet' I have the system-1 default. This module collects the logs form usual logfiles like /var/log/syslog\* etc. But also the logs from /var/lib/elastic-agent/logs/defau…

---

## [Filebeat not dropping the entire events/log](https://discuss.elastic.co/t/filebeat-not-dropping-the-entire-events-log/246875)

<div class="topic-metadata">

**Author:** [@Kumar\_Shubham](https://discuss.elastic.co/u/Kumar_Shubham)\
**Replies:** 1\
**Last updated:** [August 31, 2020, 12:42pm UTC](https://discuss.elastic.co/t/filebeat-not-dropping-the-entire-events-log/246875 "2020-08-31T12:42:24Z")

</div>

I don't want to collect logs from all containers, so I want to discard a few container logs. In the below case, I don't want to capture logs from logstash and elastic. Actual: In the logs, I see only the "container" f…

---

## [Cannot setup Filebeat, when enable Imperva module - 7.9](https://discuss.elastic.co/t/cannot-setup-filebeat-when-enable-imperva-module-7-9/245719)

<div class="topic-metadata">

**Author:** [@denis.atanasov](https://discuss.elastic.co/u/denis.atanasov)\
**Replies:** 2\
**Last updated:** [August 31, 2020, 12:37pm UTC](https://discuss.elastic.co/t/cannot-setup-filebeat-when-enable-imperva-module-7-9/245719 "2020-08-31T12:37:47Z")

</div>

Hello guys, Yesterday on my ELK stack I upgraded the Filebeat version from 7.8 to 7.9. The reason is because of new modules included, especialy the Imperva module for receiving Syslog messages. I am successfully enabli…

---

## [Metricbeat HTTP module digest authentication configuration](https://discuss.elastic.co/t/metricbeat-http-module-digest-authentication-configuration/246939)

<div class="topic-metadata">

**Author:** [@Olga\_Pilipets](https://discuss.elastic.co/u/Olga_Pilipets)\
**Replies:** 2\
**Last updated:** [August 31, 2020, 12:35pm UTC](https://discuss.elastic.co/t/metricbeat-http-module-digest-authentication-configuration/246939 "2020-08-31T12:35:50Z")

</div>

Is it possible to call arbitrary HTTP endpoint with digest authentication using metricbeat HTTP module? If yes, how digest authentication type should be configured?

---

## [Cannot run tests for new module](https://discuss.elastic.co/t/cannot-run-tests-for-new-module/246911)

<div class="topic-metadata">

**Author:** [@hazcod](https://discuss.elastic.co/u/hazcod)\
**Replies:** 0\
**Last updated:** [August 31, 2020, 7:06am UTC](https://discuss.elastic.co/t/cannot-run-tests-for-new-module/246911 "2020-08-31T07:06:31Z")

</div>

Hi, I am having issues running tests for a new filebeat module I'm developing. I followed the public docs on developing a new module, can you see something out of the ordinary? Module is located here: https://github.co…

---

## [Metricbeat AWS module on Kubernetes error](https://discuss.elastic.co/t/metricbeat-aws-module-on-kubernetes-error/246685)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 2\
**Last updated:** [August 30, 2020, 9:04am UTC](https://discuss.elastic.co/t/metricbeat-aws-module-on-kubernetes-error/246685 "2020-08-30T09:04:14Z")

</div>

Hello, We have enabled the AWS module on a metricbeat on Kubernetes. The beat starts, but fails with the error message 2020-08-27T18:50:39.511Z ERROR instance/beat.go:958 Exiting: 1 error: metricset 'aws/ec2' not found. …

---

## [Grabbing UDP data stream with Beats?](https://discuss.elastic.co/t/grabbing-udp-data-stream-with-beats/246756)

<div class="topic-metadata">

**Author:** [@dewell](https://discuss.elastic.co/u/dewell)\
**Replies:** 1\
**Last updated:** [August 29, 2020, 3:43pm UTC](https://discuss.elastic.co/t/grabbing-udp-data-stream-with-beats/246756 "2020-08-29T15:43:24Z")

</div>

Hello, I read now a lot about logstash and beats and I'm still insecure what's the easiest way to get my data into elasticsearch. It seems filebeat supports UDP so I started with that. Intuitively I assumed packetbeat wo…

---

## [Filebeat Multiline Config Help](https://discuss.elastic.co/t/filebeat-multiline-config-help/246667)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 1\
**Last updated:** [August 29, 2020, 3:34pm UTC](https://discuss.elastic.co/t/filebeat-multiline-config-help/246667 "2020-08-29T15:34:48Z")

</div>

Log start: Aug 24 03:32:21 Filebeat Multiline: multiline.pattern: ^\[\[A-Z\]\[a-z\]{3} \[0-9\]{2} \[0-9\]{2}:\[0-9\]{2}:\[0-9\]{2} Logstash date filter: "MMM dd HH:mm:ss" For some reason, my Filebeat multiline pattern does n…

---

## [Redis slowlog monitoring with ECK (Elastic on Kubernetes)?](https://discuss.elastic.co/t/redis-slowlog-monitoring-with-eck-elastic-on-kubernetes/246377)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 5\
**Last updated:** [August 29, 2020, 2:02am UTC](https://discuss.elastic.co/t/redis-slowlog-monitoring-with-eck-elastic-on-kubernetes/246377 "2020-08-29T02:02:45Z")

</div>

Hi thanks for the wonderful elastic stack! I am trying to monitor the SLOWLOG of Redis in elastic, and I am on Kubernetes (using ECK). The doc says Redis filebeat for slowlog needs to specify a list of hosts. However, in…

---

## [Error running input: error receiving slowlog data: ERR unknown command \`SLOWLOG\`, with args beginning with: \`GET\`](https://discuss.elastic.co/t/error-running-input-error-receiving-slowlog-data-err-unknown-command-slowlog-with-args-beginning-with-get/246826)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 1\
**Last updated:** [August 28, 2020, 11:52pm UTC](https://discuss.elastic.co/t/error-running-input-error-receiving-slowlog-data-err-unknown-command-slowlog-with-args-beginning-with-get/246826 "2020-08-28T23:52:05Z")

</div>

Hi I am using redis filebeat with the following config. However the error Error running input: error receiving slowlog data: ERR unknown command SLOWLOG, with args beginning with: GET occurs very frequently. Thanks for …

---

## [Condition to compare if two fields are equal](https://discuss.elastic.co/t/condition-to-compare-if-two-fields-are-equal/246825)

<div class="topic-metadata">

**Author:** [@mathiascg](https://discuss.elastic.co/u/mathiascg)\
**Replies:** 0\
**Last updated:** [August 28, 2020, 11:03pm UTC](https://discuss.elastic.co/t/condition-to-compare-if-two-fields-are-equal/246825 "2020-08-28T23:03:19Z")

</div>

In the processor pipeline, is it possible to compare two exported fields to check for equality? A condition like: fields\_equal: - field\_1 - field\_2 Which would return true/false. From what I understand from the doc…

---

## [Packetbeat duplicated HTTP events in Kubernetes Cluster](https://discuss.elastic.co/t/packetbeat-duplicated-http-events-in-kubernetes-cluster/246374)

<div class="topic-metadata">

**Author:** [@mathiascg](https://discuss.elastic.co/u/mathiascg)\
**Replies:** 4\
**Last updated:** [August 28, 2020, 10:53pm UTC](https://discuss.elastic.co/t/packetbeat-duplicated-http-events-in-kubernetes-cluster/246374 "2020-08-28T22:53:28Z")

</div>

Hi, we are experiencing a similar issue as in this post. Configuration: packetbeat.ignore\_outgoing: true setup.dashboards.enabled: true setup.template.enabled: true setup.template.name: "packetbeat" setup.template.p…

---

## [Winlogbeat secure connection](https://discuss.elastic.co/t/winlogbeat-secure-connection/246803)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 2\
**Last updated:** [August 28, 2020, 9:06pm UTC](https://discuss.elastic.co/t/winlogbeat-secure-connection/246803 "2020-08-28T21:06:03Z")

</div>

Hi, \*I am using ELK 7.9 I am trying use Winlogbeat to ship data to an Elasticsearch node, which has secure connection settings enabled: xpack.security.enabled: true xpack.security.transport.ssl.enabled: true xpack.sec…

---

## [7.8 doesn't parse apache access logs](https://discuss.elastic.co/t/7-8-doesnt-parse-apache-access-logs/242342)

<div class="topic-metadata">

**Author:** [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Replies:** 15\
**Last updated:** [August 28, 2020, 6:07pm UTC](https://discuss.elastic.co/t/7-8-doesnt-parse-apache-access-logs/242342 "2020-08-28T18:07:39Z")

</div>

I had an old 6.x stack setup a while ago but had to shut it down. I'm back to try another round and hopefully its permanent this time. I need to have my Apache 2.4 logs parsed so I can create custom dashboards. All serv…

---

## [Logs parsing error post upgrading filebeat from 5.x to 7.x](https://discuss.elastic.co/t/logs-parsing-error-post-upgrading-filebeat-from-5-x-to-7-x/246808)

<div class="topic-metadata">

**Author:** [@latif.siddiqui](https://discuss.elastic.co/u/latif.siddiqui)\
**Replies:** 0\
**Last updated:** [August 28, 2020, 6:02pm UTC](https://discuss.elastic.co/t/logs-parsing-error-post-upgrading-filebeat-from-5-x-to-7-x/246808 "2020-08-28T18:02:10Z")

</div>

We recently updated the filebeat to 7.9.0 for ECS Clusters but after updating it stopped parsing the logs and sending file path in the log field. sample log: log": { "file": { "path": "/var/lib/docker/con…

---

## [Stat metricbeat.yml: no such file or directory](https://discuss.elastic.co/t/stat-metricbeat-yml-no-such-file-or-directory/246303)

<div class="topic-metadata">

**Author:** [@teej](https://discuss.elastic.co/u/teej)\
**Replies:** 4\
**Last updated:** [August 28, 2020, 1:39pm UTC](https://discuss.elastic.co/t/stat-metricbeat-yml-no-such-file-or-directory/246303 "2020-08-28T13:39:16Z")

</div>

Hi, I am new with the Beats. I did a yum install of metricbeat and followed the instructions on Elastic site for setting up a keystore but oddly when I try to do: /usr/share/metricbeat/bin/metricbeat keystore create I…

---

## [Pushing logs to ElasticSearch in another AWS account: Timeout errors](https://discuss.elastic.co/t/pushing-logs-to-elasticsearch-in-another-aws-account-timeout-errors/246718)

<div class="topic-metadata">

**Author:** [@ltrod](https://discuss.elastic.co/u/ltrod)\
**Replies:** 0\
**Last updated:** [August 28, 2020, 6:14am UTC](https://discuss.elastic.co/t/pushing-logs-to-elasticsearch-in-another-aws-account-timeout-errors/246718 "2020-08-28T06:14:07Z")

</div>

I'm running Filebeat on Kubernetes in a EKS Cluster in AWS and send the logs to ElasticSearch in another AWS account. The logs reach the ElasticSearch and I can see the logs in Kibana. But I get these errors sometimes: E…

---

## [Some kubernetes metadata fields aren't populated in Filebeat 7.9.0](https://discuss.elastic.co/t/some-kubernetes-metadata-fields-arent-populated-in-filebeat-7-9-0/246680)

<div class="topic-metadata">

**Author:** [@delphi](https://discuss.elastic.co/u/delphi)\
**Replies:** 0\
**Last updated:** [August 27, 2020, 7:36pm UTC](https://discuss.elastic.co/t/some-kubernetes-metadata-fields-arent-populated-in-filebeat-7-9-0/246680 "2020-08-27T19:36:45Z")

</div>

In Filebeat 7.6.2 or higher (I'm using 7.9.0) the field kubernetes.deployment.name isn't populated, even using add\_kubernetes\_metadata + autodiscover. I'm getting only the higher level kubernetes.replicaset.name. There…

---

## [Auditbeat 'process.title' gone](https://discuss.elastic.co/t/auditbeat-process-title-gone/246652)

<div class="topic-metadata">

**Author:** [@headtea](https://discuss.elastic.co/u/headtea)\
**Replies:** 0\
**Last updated:** [August 27, 2020, 3:14pm UTC](https://discuss.elastic.co/t/auditbeat-process-title-gone/246652 "2020-08-27T15:14:18Z")

</div>

Before deploying in production, I've made a demo deployment of elk and used auditbeat (7.8.0) to log actions on the system. In kibana, I was able to put it into a dashboard with using the process.title field. I've now d…

---

## [ELMAH, xml and winlogbeat](https://discuss.elastic.co/t/elmah-xml-and-winlogbeat/246473)

<div class="topic-metadata">

**Author:** [@kawalec](https://discuss.elastic.co/u/kawalec)\
**Replies:** 3\
**Last updated:** [August 27, 2020, 3:02pm UTC](https://discuss.elastic.co/t/elmah-xml-and-winlogbeat/246473 "2020-08-27T15:02:24Z")

</div>

We are using ELMAH for logging and it writes an xml file for every error. Is there a way to use Winlogbeat to get these files into kibana? Thanks

---

## [Filebeat timestamp processor parsing incorrectly](https://discuss.elastic.co/t/filebeat-timestamp-processor-parsing-incorrectly/246586)

<div class="topic-metadata">

**Author:** [@anandd4](https://discuss.elastic.co/u/anandd4)\
**Replies:** 4\
**Last updated:** [August 27, 2020, 11:09am UTC](https://discuss.elastic.co/t/filebeat-timestamp-processor-parsing-incorrectly/246586 "2020-08-27T11:09:56Z")

</div>

Filebeat timestamp processor is unable to parse timestamp as expected. Log file - 26/Aug/2020:08:00:30 +0100 26/Aug/2020:08:02:30 +0100 Filebeat config - filebeat.inputs: - type: log paths: …

---

## [Filebeat stopped sending logs continuously](https://discuss.elastic.co/t/filebeat-stopped-sending-logs-continuously/246595)

<div class="topic-metadata">

**Author:** [@Silvium](https://discuss.elastic.co/u/Silvium)\
**Replies:** 0\
**Last updated:** [August 27, 2020, 10:15am UTC](https://discuss.elastic.co/t/filebeat-stopped-sending-logs-continuously/246595 "2020-08-27T10:15:10Z")

</div>

Filebeat has started to have gaps in sending logs from a file written by rsyslog from a docker instance. Below the visualisation of count of documents from specific host The path logs take to Kibana is: Docker-\> rsys…

---

## [Filebeat make update fails for new custom module](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/246070)

<div class="topic-metadata">

**Author:** [@cpohl](https://discuss.elastic.co/u/cpohl)\
**Replies:** 3\
**Last updated:** [August 27, 2020, 9:57am UTC](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/246070 "2020-08-27T09:57:22Z")

</div>

I have followed the instructions: https://www.elastic.co/guide/en/beats/devguide/7.8/filebeat-modules-devguide.html create-module, create-fileset and create-fields all work correctly with no errors. But the make updat…

---

## [Start auditbeat](https://discuss.elastic.co/t/start-auditbeat/246267)

<div class="topic-metadata">

**Author:** [@headtea](https://discuss.elastic.co/u/headtea)\
**Replies:** 2\
**Last updated:** [August 27, 2020, 7:05am UTC](https://discuss.elastic.co/t/start-auditbeat/246267 "2020-08-27T07:05:01Z")

</div>

I'm starting auditbeat on one of the machines and I'm getting the following message when running auditbeat: ERROR instance/beat.go:951 Exiting: 1 error: system/socket dataset setup failed: tracefs/debugfs is not mo…

---

## [Filebeat/Logstash Log\_Type issue](https://discuss.elastic.co/t/filebeat-logstash-log-type-issue/246529)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 0\
**Last updated:** [August 27, 2020, 1:55am UTC](https://discuss.elastic.co/t/filebeat-logstash-log-type-issue/246529 "2020-08-27T01:55:35Z")

</div>

Hi, my current Filebeat configuration is below: - type: log enabled: true paths: - /DATAPATH/log\* fields: {log\_type: JLogs} multiline.pattern: \*pattern\* multiline.negate: true multiline.match: after M…

---

## [Nginx-ingress grok expression does not handle multiple upstreams](https://discuss.elastic.co/t/nginx-ingress-grok-expression-does-not-handle-multiple-upstreams/246046)

<div class="topic-metadata">

**Author:** [@chendo](https://discuss.elastic.co/u/chendo)\
**Replies:** 2\
**Last updated:** [August 27, 2020, 12:29am UTC](https://discuss.elastic.co/t/nginx-ingress-grok-expression-does-not-handle-multiple-upstreams/246046 "2020-08-27T00:29:43Z")

</div>

If nginx-ingress retries multiple upstreams, the grok expression does not parse it correctly and manifested as missing data when we knew errors were happening. This is on filebeat 7.8.0, but issue does not appear to be …

---

## [Filebeat unable obtain kubernetes metadata](https://discuss.elastic.co/t/filebeat-unable-obtain-kubernetes-metadata/245741)

<div class="topic-metadata">

**Author:** [@dorinand](https://discuss.elastic.co/u/dorinand)\
**Replies:** 1\
**Last updated:** [August 26, 2020, 8:50pm UTC](https://discuss.elastic.co/t/filebeat-unable-obtain-kubernetes-metadata/245741 "2020-08-26T20:50:11Z")

</div>

I am running filebeat in my kubernetes cluster. I used this helm chart to deploy filebeat, logstash and elasticsearch. This is my filebeat configuration: filebeatConfig: filebeat.yml: | filebeat.inputs: - type…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=216)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=218)
