# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=218

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 219

---

## [Importing dashboards on Elasicsearch](https://discuss.elastic.co/t/importing-dashboards-on-elasicsearch/246431)

<div class="topic-metadata">

**Author:** [@nb03briceno](https://discuss.elastic.co/u/nb03briceno)\
**Replies:** 1\
**Last updated:** [August 26, 2020, 7:32pm UTC](https://discuss.elastic.co/t/importing-dashboards-on-elasicsearch/246431 "2020-08-26T19:32:03Z")

</div>

Hello everyone, i'm just searching for a bit of help regarding on how to import my dashboards through filebeat into ELK running with docker in my computer. When using normal ELk (without docker), I imported my dashboard…

---

## [Input http\_endpoint is not accepted by 7.9.0 or master](https://discuss.elastic.co/t/input-http-endpoint-is-not-accepted-by-7-9-0-or-master/245557)

<div class="topic-metadata">

**Author:** [@KlavsKlavsen](https://discuss.elastic.co/u/KlavsKlavsen)\
**Replies:** 6\
**Last updated:** [August 26, 2020, 3:58pm UTC](https://discuss.elastic.co/t/input-http-endpoint-is-not-accepted-by-7-9-0-or-master/245557 "2020-08-26T15:58:22Z")

</div>

I just tried building docker images (make release) from github on both master and the new 7.9.0 tag. When I then run filebeat with this config: filebeat.inputs: - type: http\_endpoint enabled: true l…

---

## [Filebeat Fortinet module doesn't parse message field](https://discuss.elastic.co/t/filebeat-fortinet-module-doesnt-parse-message-field/246013)

<div class="topic-metadata">

**Author:** [@anon56147639](https://discuss.elastic.co/u/anon56147639)\
**Replies:** 6\
**Last updated:** [August 26, 2020, 3:35pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-doesnt-parse-message-field/246013 "2020-08-26T15:35:27Z")

</div>

Hi everyone, I'm facing issues with the Fortinet module in Filebeat. It stores the whole log in the message field instead of seperate fields. This is an example of my log (I removed some info such as IPs): https://paste…

---

## [Unmatched responses or requests](https://discuss.elastic.co/t/unmatched-responses-or-requests/246455)

<div class="topic-metadata">

**Author:** [@toms130](https://discuss.elastic.co/u/toms130)\
**Replies:** 0\
**Last updated:** [August 26, 2020, 1:18pm UTC](https://discuss.elastic.co/t/unmatched-responses-or-requests/246455 "2020-08-26T13:18:32Z")

</div>

Hi all, I'm using packetbeat to capture http webservices traffic using SOAP , and I'm facing a lot of http requests that are logged as unmatched requests or responses. ( for example, 80k on 470k documents on last 24h ha…

---

## [Custom Metric not Adding Host.geo.country\_name](https://discuss.elastic.co/t/custom-metric-not-adding-host-geo-country-name/246094)

<div class="topic-metadata">

**Author:** [@Hassaan\_mustafa](https://discuss.elastic.co/u/Hassaan_mustafa)\
**Replies:** 2\
**Last updated:** [August 26, 2020, 10:22am UTC](https://discuss.elastic.co/t/custom-metric-not-adding-host-geo-country-name/246094 "2020-08-26T10:22:42Z")

</div>

processors: - add\_host\_metadata: geo: name: server-1 country\_name: PK country\_iso\_code: PK city\_name: Karachi after providing add\_host\_metadata still country\_name is not …

---

## [Question about auditbeat and squid](https://discuss.elastic.co/t/question-about-auditbeat-and-squid/246246)

<div class="topic-metadata">

**Author:** [@ThreatInter](https://discuss.elastic.co/u/ThreatInter)\
**Replies:** 4\
**Last updated:** [August 26, 2020, 9:20am UTC](https://discuss.elastic.co/t/question-about-auditbeat-and-squid/246246 "2020-08-26T09:20:40Z")

</div>

We have squid proxy server, that writes it 's logs in /var/log directory. And we want to monitor it by auditbeat. Is it possible?If yes how we should do it?

---

## [Kubernetes\_metadata does not work on Kubernetes Windows](https://discuss.elastic.co/t/kubernetes-metadata-does-not-work-on-kubernetes-windows/245617)

<div class="topic-metadata">

**Author:** [@iusergii](https://discuss.elastic.co/u/iusergii)\
**Replies:** 2\
**Last updated:** [August 26, 2020, 6:25am UTC](https://discuss.elastic.co/t/kubernetes-metadata-does-not-work-on-kubernetes-windows/245617 "2020-08-26T06:25:12Z")

</div>

Hi Team, I'm evaluating moving our Windows workloads to Kubernetes and would like to use filebeat for logs shipment. I've created DaemonSet where I mounted hostPathes: /var/log /ProgramData/docker/containers My file…

---

## [Auditbeat or Filebeat](https://discuss.elastic.co/t/auditbeat-or-filebeat/246287)

<div class="topic-metadata">

**Author:** [@Burga](https://discuss.elastic.co/u/Burga)\
**Replies:** 3\
**Last updated:** [August 26, 2020, 5:22am UTC](https://discuss.elastic.co/t/auditbeat-or-filebeat/246287 "2020-08-26T05:22:35Z")

</div>

Hi I just wondering what Auditbeat can audit what filebeat can't by logging /var/log/audit/audit.log ? we planned to install both auditbeat and filebeat on the same host but from my undersating filebeat also can get …

---

## [Keystore Not Finding auditbeat.yml and Non-Zero Issue](https://discuss.elastic.co/t/keystore-not-finding-auditbeat-yml-and-non-zero-issue/246354)

<div class="topic-metadata">

**Author:** [@teej](https://discuss.elastic.co/u/teej)\
**Replies:** 0\
**Last updated:** [August 25, 2020, 7:56pm UTC](https://discuss.elastic.co/t/keystore-not-finding-auditbeat-yml-and-non-zero-issue/246354 "2020-08-25T19:56:45Z")

</div>

Hi, I am basically just getting beats going so I apologize for what may be stupid questions but.... I have just installed auditbeat on a number of servers and all appears to be functioning - meaning systemctl says its …

---

## [MetricBeat Binary Signed](https://discuss.elastic.co/t/metricbeat-binary-signed/246349)

<div class="topic-metadata">

**Author:** [@Questions](https://discuss.elastic.co/u/Questions)\
**Replies:** 0\
**Last updated:** [August 25, 2020, 7:08pm UTC](https://discuss.elastic.co/t/metricbeat-binary-signed/246349 "2020-08-25T19:08:40Z")

</div>

On investigating the MetricBeat client binary, I noticed that it was not properly signed with the Elastic publisher certificate (the Endgame sensor binary is signed). Am I missing something or is there a reason why Metri…

---

## [Filebeat error with helm3](https://discuss.elastic.co/t/filebeat-error-with-helm3/246181)

<div class="topic-metadata">

**Author:** [@Raman\_Sawhney](https://discuss.elastic.co/u/Raman_Sawhney)\
**Replies:** 2\
**Last updated:** [August 25, 2020, 6:28pm UTC](https://discuss.elastic.co/t/filebeat-error-with-helm3/246181 "2020-08-25T18:28:19Z")

</div>

I am getting error while deploying autodiscover in our environment Error: Exiting: error in autodiscover provider settings: error setting up kubernetes autodiscover provider: missing field accessing 'filebeat.autodiscov…

---

## [Multiple Winlogbeat Agents on WEF Collectors](https://discuss.elastic.co/t/multiple-winlogbeat-agents-on-wef-collectors/245424)

<div class="topic-metadata">

**Author:** [@stranjer](https://discuss.elastic.co/u/stranjer)\
**Replies:** 4\
**Last updated:** [August 25, 2020, 5:48pm UTC](https://discuss.elastic.co/t/multiple-winlogbeat-agents-on-wef-collectors/245424 "2020-08-25T17:48:32Z")

</div>

I have an environment that has pretty high Windows EPS and am looking at best how to alleviate bottlenecks in processing Windows Event Logs. Overall, I'm getting around 100k EPS Windows events sustained on average, with …

---

## [Log entries gathered by filebeat in EKS are occasionally joined](https://discuss.elastic.co/t/log-entries-gathered-by-filebeat-in-eks-are-occasionally-joined/244074)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 1\
**Last updated:** [August 25, 2020, 2:57pm UTC](https://discuss.elastic.co/t/log-entries-gathered-by-filebeat-in-eks-are-occasionally-joined/244074 "2020-08-25T14:57:47Z")

</div>

TL;DR Some messages are merging when using filebeat container input. Issue When I'm using the filebeat container input, some log messages occasionally merge into a single message. I am running the filebeat in EKS, deplo…

---

## [Problem with fields mqobject\_ and mq\_ They are not displayed in Elasticsearch from Prometheus](https://discuss.elastic.co/t/problem-with-fields-mqobject-and-mq-they-are-not-displayed-in-elasticsearch-from-prometheus/245959)

<div class="topic-metadata">

**Author:** [@amateur](https://discuss.elastic.co/u/amateur)\
**Replies:** 3\
**Last updated:** [August 25, 2020, 2:34pm UTC](https://discuss.elastic.co/t/problem-with-fields-mqobject-and-mq-they-are-not-displayed-in-elasticsearch-from-prometheus/245959 "2020-08-25T14:34:53Z")

</div>

Hi, We already have MQ monitoring running in Prometehus, but we are trying to bring the metrics to ElasticSearch, we made the integration between Prometehus and Metricbeat, but they do not arrive, all the fields related…

---

## [Username and password-based enrollment - "environment variable VAR\_NAME does not exist"](https://discuss.elastic.co/t/username-and-password-based-enrollment-environment-variable-var-name-does-not-exist/245879)

<div class="topic-metadata">

**Author:** [@gohovd](https://discuss.elastic.co/u/gohovd)\
**Replies:** 2\
**Last updated:** [August 25, 2020, 10:43am UTC](https://discuss.elastic.co/t/username-and-password-based-enrollment-environment-variable-var-name-does-not-exist/245879 "2020-08-25T10:43:24Z")

</div>

I am working on an automated deployment of filebeat, and one of the steps is to enroll the beat. As per the documentation, to have this process scripted, I need to use 'Username and password-based enrollment', where the…

---

## [Journalbeat can't open a log file](https://discuss.elastic.co/t/journalbeat-cant-open-a-log-file/246116)

<div class="topic-metadata">

**Author:** [@DenProg](https://discuss.elastic.co/u/DenProg)\
**Replies:** 3\
**Last updated:** [August 25, 2020, 10:42am UTC](https://discuss.elastic.co/t/journalbeat-cant-open-a-log-file/246116 "2020-08-25T10:42:50Z")

</div>

Hi. I describe specific log file in the config as it's written in the docs: journalbeat.inputs: - paths: - "/var/log/syslog" This file is present, but Journalbeat can't open it for some reason: авг 24 15:53:29 com…

---

## [Metricbeat ILM rollover issue](https://discuss.elastic.co/t/metricbeat-ilm-rollover-issue/246063)

<div class="topic-metadata">

**Author:** [@ragmenon](https://discuss.elastic.co/u/ragmenon)\
**Replies:** 3\
**Last updated:** [August 25, 2020, 4:52am UTC](https://discuss.elastic.co/t/metricbeat-ilm-rollover-issue/246063 "2020-08-25T04:52:27Z")

</div>

Hi, My metric dashboard in kibana crashed every now and then in 2 days with error Error Internal Server Error (500) URL https://kibana.integ.tvld.tech/api/metrics/snapshot i suspect this might an issue with metric bea…

---

## [Packetbeats mechanism for capturing network flow data](https://discuss.elastic.co/t/packetbeats-mechanism-for-capturing-network-flow-data/246208)

<div class="topic-metadata">

**Author:** [@opentree](https://discuss.elastic.co/u/opentree)\
**Replies:** 0\
**Last updated:** [August 25, 2020, 2:40am UTC](https://discuss.elastic.co/t/packetbeats-mechanism-for-capturing-network-flow-data/246208 "2020-08-25T02:40:55Z")

</div>

I was wondering if someone could share how packetbeat captures network flow data. I tried to piece together from the documentation, but I was still unclear on a few things. The documentation refers to the use of pcap or…

---

## [Filebeat 5.6.16 to 7.8.1 breaking](https://discuss.elastic.co/t/filebeat-5-6-16-to-7-8-1-breaking/244422)

<div class="topic-metadata">

**Author:** [@kopacko](https://discuss.elastic.co/u/kopacko)\
**Replies:** 2\
**Last updated:** [August 25, 2020, 1:35am UTC](https://discuss.elastic.co/t/filebeat-5-6-16-to-7-8-1-breaking/244422 "2020-08-25T01:35:51Z")

</div>

I attempted a migration on one of my Windows servers from filebeats 5.6.16 to 7.8.1. And got no service errors but was no longer receiving any file logs. I noticed in the logs that connections to the Elasticsearch clust…

---

## [Filebeat processor for single line logs?](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812)

<div class="topic-metadata">

**Author:** [@t3fsx](https://discuss.elastic.co/u/t3fsx)\
**Replies:** 6\
**Last updated:** [August 24, 2020, 4:24pm UTC](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812 "2020-08-24T16:24:15Z")

</div>

I ran into this threat in Github so I just copy-paste: Steps to Reproduce: Enable Apache module in Filebeat and use the DNS processor; configuration example below: - dns: type: reverse action: append field…

---

## [Beats manual index template loading instructions (alternate method) is missing index alias step](https://discuss.elastic.co/t/beats-manual-index-template-loading-instructions-alternate-method-is-missing-index-alias-step/245991)

<div class="topic-metadata">

**Author:** [@alhazred](https://discuss.elastic.co/u/alhazred)\
**Replies:** 1\
**Last updated:** [August 23, 2020, 1:49pm UTC](https://discuss.elastic.co/t/beats-manual-index-template-loading-instructions-alternate-method-is-missing-index-alias-step/245991 "2020-08-23T13:49:50Z")

</div>

All the beats documentation provide instructions on loading the template index manually through an alternate method if your beat shipper doesn't have access to elasticsearch (for example: https://www.elastic.co/guide/en/…

---

## [Filebeat Log Message Parsing](https://discuss.elastic.co/t/filebeat-log-message-parsing/245967)

<div class="topic-metadata">

**Author:** [@batninja24601](https://discuss.elastic.co/u/batninja24601)\
**Replies:** 0\
**Last updated:** [August 22, 2020, 12:01am UTC](https://discuss.elastic.co/t/filebeat-log-message-parsing/245967 "2020-08-22T00:01:16Z")

</div>

Hello all. I've been reading the Filebeat docs. I need to confirm my understanding. I am using FileBeat to parse some custom local log text files using the log input type. I would to parse the message out and rename f…

---

## [How to get node exporters metrics from Prometheus database without connecting to exporters explicitly](https://discuss.elastic.co/t/how-to-get-node-exporters-metrics-from-prometheus-database-without-connecting-to-exporters-explicitly/245911)

<div class="topic-metadata">

**Author:** [@mish](https://discuss.elastic.co/u/mish)\
**Replies:** 0\
**Last updated:** [August 21, 2020, 11:15am UTC](https://discuss.elastic.co/t/how-to-get-node-exporters-metrics-from-prometheus-database-without-connecting-to-exporters-explicitly/245911 "2020-08-21T11:15:02Z")

</div>

Hello experts- Requirement is to create a Kibana dashboards of OS related metrics by reusing Prometheus Server setup. I am having a Prometheus server and multiple node exporters (30) already set up in AWS. Installed …

---

## [Metricbeat does not find any application\_pool](https://discuss.elastic.co/t/metricbeat-does-not-find-any-application-pool/244761)

<div class="topic-metadata">

**Author:** [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Replies:** 2\
**Last updated:** [August 21, 2020, 10:39am UTC](https://discuss.elastic.co/t/metricbeat-does-not-find-any-application-pool/244761 "2020-08-21T10:39:52Z")

</div>

Hellow All, I have installed metricbeat-7.8.1, IIS module is enabled with bellow module: iis metricsets: webserver website application\_pool enabled: true period: 10s but in the Log i am keep seeing bellow 2020-…

---

## [Metricbeat is running but do not provide metrics](https://discuss.elastic.co/t/metricbeat-is-running-but-do-not-provide-metrics/245864)

<div class="topic-metadata">

**Author:** [@kn\_finfort](https://discuss.elastic.co/u/kn_finfort)\
**Replies:** 0\
**Last updated:** [August 21, 2020, 7:05am UTC](https://discuss.elastic.co/t/metricbeat-is-running-but-do-not-provide-metrics/245864 "2020-08-21T07:05:09Z")

</div>

Hellow everyone, I have an Elastic Stack running in a swarm of docker: ELK 7.7.0 + Filebeat + Metricbeat. After an Metricbeat service restart (maybe not and I missed something) it stopped to provide metrics. The servi…

---

## [Metrices for Openshift via mtericbeat is not coming in elasticsearch](https://discuss.elastic.co/t/metrices-for-openshift-via-mtericbeat-is-not-coming-in-elasticsearch/245229)

<div class="topic-metadata">

**Author:** [@Harshi1](https://discuss.elastic.co/u/Harshi1)\
**Replies:** 1\
**Last updated:** [August 21, 2020, 5:53am UTC](https://discuss.elastic.co/t/metrices-for-openshift-via-mtericbeat-is-not-coming-in-elasticsearch/245229 "2020-08-21T05:53:14Z")

</div>

Kibana version : 7.7.0 Elasticsearch version : 7.7.0 Metricbeat version : 7.7 Browser version : Chrome 84.0 Original install method (e.g. download page, yum, deb, from source, etc.) and version : RPM from download pa…

---

## [Filebeat intermittent auto discovery states issue](https://discuss.elastic.co/t/filebeat-intermittent-auto-discovery-states-issue/243590)

<div class="topic-metadata">

**Author:** [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Replies:** 3\
**Last updated:** [August 21, 2020, 5:45am UTC](https://discuss.elastic.co/t/filebeat-intermittent-auto-discovery-states-issue/243590 "2020-08-21T05:45:35Z")

</div>

I just switched from fluentd to filebeat and am seeing the following issues for some logs now. Does anyone have an idea where the issue could reside? 2020-08-03T14:26:23.349Z ERROR \[autodiscover\] autodiscover…

---

## [Heartbeat: make http check.response.body get negative result based on the match](https://discuss.elastic.co/t/heartbeat-make-http-check-response-body-get-negative-result-based-on-the-match/245332)

<div class="topic-metadata">

**Author:** [@lowry](https://discuss.elastic.co/u/lowry)\
**Replies:** 2\
**Last updated:** [August 21, 2020, 2:49am UTC](https://discuss.elastic.co/t/heartbeat-make-http-check-response-body-get-negative-result-based-on-the-match/245332 "2020-08-21T02:49:35Z")

</div>

Hello everyone, Wondering if there's solution for this case: We want to do http check over an endpoint: http://localhost:8080/health, it returns 3 kinds of response(not json, plain text. just for example) “status”: “…

---

## [Monitoring linux processes with heartbeat](https://discuss.elastic.co/t/monitoring-linux-processes-with-heartbeat/237871)

<div class="topic-metadata">

**Author:** [@igorid70](https://discuss.elastic.co/u/igorid70)\
**Replies:** 1\
**Last updated:** [August 21, 2020, 1:23am UTC](https://discuss.elastic.co/t/monitoring-linux-processes-with-heartbeat/237871 "2020-08-21T01:23:24Z")

</div>

I have a long and successful implementation of Elastic stack and recently we want to add application processes monitoring using hearbeat. It works like a charm with most of them, however some processes are just regular L…

---

## [Beats on Heroku (rails)](https://discuss.elastic.co/t/beats-on-heroku-rails/244780)

<div class="topic-metadata">

**Author:** [@weilandia](https://discuss.elastic.co/u/weilandia)\
**Replies:** 1\
**Last updated:** [August 21, 2020, 1:22am UTC](https://discuss.elastic.co/t/beats-on-heroku-rails/244780 "2020-08-21T01:22:04Z")

</div>

Is there a good way to setup Elastic beats (filebeat, heartbeat, etc.) on Heroku (rails app)? All the setup instructions have you download the packages and run the beat servers. Doing this for each Heroku dyno everytime…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=217)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=219)
