# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=219

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 220

---

## [Struggling with filebeat and elasticsearch ingest pipeline for processing custom log file that has weird date/time format](https://discuss.elastic.co/t/struggling-with-filebeat-and-elasticsearch-ingest-pipeline-for-processing-custom-log-file-that-has-weird-date-time-format/243941)

<div class="topic-metadata">

**Author:** [@jrykowski-huron](https://discuss.elastic.co/u/jrykowski-huron)\
**Replies:** 7\
**Last updated:** [August 21, 2020, 12:29am UTC](https://discuss.elastic.co/t/struggling-with-filebeat-and-elasticsearch-ingest-pipeline-for-processing-custom-log-file-that-has-weird-date-time-format/243941 "2020-08-21T00:29:49Z")

</div>

Struggling with use of elasticsearch ingest pipeline for custom parsing of a unique flatfile log format. Running into problems. Not sure if there's mix of issues here. Here's the scenerio... Format uses multi-line …

---

## [Elastic Agent on Older Windows Disable Driver Signature Enforcement](https://discuss.elastic.co/t/elastic-agent-on-older-windows-disable-driver-signature-enforcement/245667)

<div class="topic-metadata">

**Author:** [@Dallas\_Toth](https://discuss.elastic.co/u/Dallas_Toth)\
**Replies:** 2\
**Last updated:** [August 20, 2020, 9:31pm UTC](https://discuss.elastic.co/t/elastic-agent-on-older-windows-disable-driver-signature-enforcement/245667 "2020-08-20T21:31:51Z")

</div>

In order to have elastic agent install Endpoint on older windows you need to disable Driver Signature Enforcement With CMD as Administrator bcdedit /set testsigning on Then restart windows.

---

## [Add\_kubernetes\_metadata causes KubeAPIErrorsHigh alert](https://discuss.elastic.co/t/add-kubernetes-metadata-causes-kubeapierrorshigh-alert/245806)

<div class="topic-metadata">

**Author:** [@yogeek](https://discuss.elastic.co/u/yogeek)\
**Replies:** 0\
**Last updated:** [August 20, 2020, 5:39pm UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-causes-kubeapierrorshigh-alert/245806 "2020-08-20T17:39:05Z")

</div>

Hi, 2 days ago, we began to regularly receive the "KubeAPIErrorsHigh" alert on our Kubernetes cluster (definition of the alert here). To try to find the cause, we looked at the API server logs and saw the following err…

---

## [Winlogbeats error](https://discuss.elastic.co/t/winlogbeats-error/245803)

<div class="topic-metadata">

**Author:** [@davidbrilliant](https://discuss.elastic.co/u/davidbrilliant)\
**Replies:** 0\
**Last updated:** [August 20, 2020, 5:16pm UTC](https://discuss.elastic.co/t/winlogbeats-error/245803 "2020-08-20T17:16:44Z")

</div>

When running winlogbeat.exe setup, I am getting an error that I cannot solve. "Exiting: 1 error: error loading index pattern: returned 408 to import file: . Response {statusCode:408,error,Request Time-out, message, Requ…

---

## [Ship metricbeat data without logstash or kafka?](https://discuss.elastic.co/t/ship-metricbeat-data-without-logstash-or-kafka/245613)

<div class="topic-metadata">

**Author:** [@FTLJ](https://discuss.elastic.co/u/FTLJ)\
**Replies:** 2\
**Last updated:** [August 20, 2020, 3:30pm UTC](https://discuss.elastic.co/t/ship-metricbeat-data-without-logstash-or-kafka/245613 "2020-08-20T15:30:26Z")

</div>

Hi, I am planning to deploy metricbeat to monitor servers' basic metrics. Is it fine to ship metricbeat data to data node directly (without logstash or kafka) under this situation? Anything I should take into considera…

---

## [Metricbeat system collecting processes differently between servers](https://discuss.elastic.co/t/metricbeat-system-collecting-processes-differently-between-servers/245637)

<div class="topic-metadata">

**Author:** [@luiz.ooliveira](https://discuss.elastic.co/u/luiz.ooliveira)\
**Replies:** 2\
**Last updated:** [August 20, 2020, 2:59pm UTC](https://discuss.elastic.co/t/metricbeat-system-collecting-processes-differently-between-servers/245637 "2020-08-20T14:59:48Z")

</div>

I have metricbeat installed on my Data Nodes collecting system metrics. The case is that all servers are very similar in resources and has the same configs, but processes are being collected differently between them. I…

---

## [Packetbeat does not add kubernetes metadata](https://discuss.elastic.co/t/packetbeat-does-not-add-kubernetes-metadata/245622)

<div class="topic-metadata">

**Author:** [@Tim\_Stoop](https://discuss.elastic.co/u/Tim_Stoop)\
**Replies:** 1\
**Last updated:** [August 20, 2020, 2:21pm UTC](https://discuss.elastic.co/t/packetbeat-does-not-add-kubernetes-metadata/245622 "2020-08-20T14:21:45Z")

</div>

Hi, I've started a minikube (using Kubernetes 1.18.3) to test out ECK and specifically packetbeat. The minikube profile is called "packetbeat" (important, as that's the hostname for the Virtualbox VM as well) and I foll…

---

## [Where do is set setup.ilm.overwrite: true](https://discuss.elastic.co/t/where-do-is-set-setup-ilm-overwrite-true/245565)

<div class="topic-metadata">

**Author:** [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Replies:** 2\
**Last updated:** [August 20, 2020, 12:58pm UTC](https://discuss.elastic.co/t/where-do-is-set-setup-ilm-overwrite-true/245565 "2020-08-20T12:58:04Z")

</div>

Hello, filebeat setup shows me that Overwriting ILM policy is disabled, it also shows me how to enable it, but i do not know where to set it, can anyone point me to the right file? \[root@ELASTIC99004 ~\]# filebeat setup…

---

## [Make only has create-metricset](https://discuss.elastic.co/t/make-only-has-create-metricset/244515)

<div class="topic-metadata">

**Author:** [@rJosef](https://discuss.elastic.co/u/rJosef)\
**Replies:** 5\
**Last updated:** [August 20, 2020, 11:46am UTC](https://discuss.elastic.co/t/make-only-has-create-metricset/244515 "2020-08-20T11:46:10Z")

</div>

Make collect and make don't exist in the makefile of the current version of meticbeat.

---

## [Can I install 2 different version of filebeat on the same machine?](https://discuss.elastic.co/t/can-i-install-2-different-version-of-filebeat-on-the-same-machine/245731)

<div class="topic-metadata">

**Author:** [@aannee](https://discuss.elastic.co/u/aannee)\
**Replies:** 0\
**Last updated:** [August 20, 2020, 8:46am UTC](https://discuss.elastic.co/t/can-i-install-2-different-version-of-filebeat-on-the-same-machine/245731 "2020-08-20T08:46:42Z")

</div>

Hi, I'm planning to install 2 different version of filebeat on the same machine. Is this possible?

---

## [Filebeat with high memory consumption after logrotate](https://discuss.elastic.co/t/filebeat-with-high-memory-consumption-after-logrotate/243497)

<div class="topic-metadata">

**Author:** [@mohanisch](https://discuss.elastic.co/u/mohanisch)\
**Replies:** 6\
**Last updated:** [August 20, 2020, 7:56am UTC](https://discuss.elastic.co/t/filebeat-with-high-memory-consumption-after-logrotate/243497 "2020-08-20T07:56:12Z")

</div>

Hello! We use Filebeat (in Docker, version 7.8) to send logs to Logstash. Every night at 0:01 logrotate runs on the machine where Filebeat is running. It is rotating ~20-25 logfiles. Logrotate is configured with followi…

---

## [Filebeat metric libbeat.output.write.bytes does not change for type elasticsearch](https://discuss.elastic.co/t/filebeat-metric-libbeat-output-write-bytes-does-not-change-for-type-elasticsearch/245563)

<div class="topic-metadata">

**Author:** [@EugRomanchenko](https://discuss.elastic.co/u/EugRomanchenko)\
**Replies:** 0\
**Last updated:** [August 19, 2020, 9:10am UTC](https://discuss.elastic.co/t/filebeat-metric-libbeat-output-write-bytes-does-not-change-for-type-elasticsearch/245563 "2020-08-19T09:10:17Z")

</div>

We use the HTTP Endpoint functionality to monitor the internal statistics of Filebeat agents. We have configured Elasticsearch output and write our logs into AWS Elasticsearch index. And we are monitoring the indicator l…

---

## [Metricbeat kubernetes module](https://discuss.elastic.co/t/metricbeat-kubernetes-module/245704)

<div class="topic-metadata">

**Author:** [@ZMMWMY](https://discuss.elastic.co/u/ZMMWMY)\
**Replies:** 0\
**Last updated:** [August 20, 2020, 5:15am UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-module/245704 "2020-08-20T05:15:43Z")

</div>

I try to get jvm information through jolokia, Through the debug log, I see that the return value is obtained, but it is not written into the index. uptime information can be written Configuration logging.level: debug…

---

## [Elastic Cloud - Not able to vizualize data from filebeats](https://discuss.elastic.co/t/elastic-cloud-not-able-to-vizualize-data-from-filebeats/245441)

<div class="topic-metadata">

**Author:** [@Eduardo\_Iglesias](https://discuss.elastic.co/u/Eduardo_Iglesias)\
**Replies:** 2\
**Last updated:** [August 19, 2020, 11:05pm UTC](https://discuss.elastic.co/t/elastic-cloud-not-able-to-vizualize-data-from-filebeats/245441 "2020-08-19T23:05:25Z")

</div>

Hello team, I'm not able to visualize any data coming from filebeat. I'm new on Elastic. I setup an Elastic Cloud based instance and I would like to send logs from my computer (using filebeat). FIlebeat.yml config file…

---

## [Failed build Metricbeat 7.9.0 from source](https://discuss.elastic.co/t/failed-build-metricbeat-7-9-0-from-source/245675)

<div class="topic-metadata">

**Author:** [@mladen](https://discuss.elastic.co/u/mladen)\
**Replies:** 0\
**Last updated:** [August 19, 2020, 8:50pm UTC](https://discuss.elastic.co/t/failed-build-metricbeat-7-9-0-from-source/245675 "2020-08-19T20:50:37Z")

</div>

Hello, for some time I build metricbeat agent because I have a lot of custom fields. Process is the following: make make update make release Everything was working fine until version 7.9.0. When I try to run make …

---

## [Secured connection from FIlebeat to Logstash (remote error: tls: handshake failure)](https://discuss.elastic.co/t/secured-connection-from-filebeat-to-logstash-remote-error-tls-handshake-failure/245652)

<div class="topic-metadata">

**Author:** [@ofer.h](https://discuss.elastic.co/u/ofer.h)\
**Replies:** 0\
**Last updated:** [August 19, 2020, 4:37pm UTC](https://discuss.elastic.co/t/secured-connection-from-filebeat-to-logstash-remote-error-tls-handshake-failure/245652 "2020-08-19T16:37:33Z")

</div>

Hi, I'm trying to configure tls for logstash and I'm getting the following error: 2020-08-19T11:56:29.340-0400 ERROR \[publisher\_pipeline\_output\] pipeline/output.go:106 Failed to connect to backoff(async(tcp:/…

---

## [New module in Filebeat for custom logs analysis](https://discuss.elastic.co/t/new-module-in-filebeat-for-custom-logs-analysis/245598)

<div class="topic-metadata">

**Author:** [@Damecharla\_Tharun](https://discuss.elastic.co/u/Damecharla_Tharun)\
**Replies:** 0\
**Last updated:** [August 19, 2020, 12:22pm UTC](https://discuss.elastic.co/t/new-module-in-filebeat-for-custom-logs-analysis/245598 "2020-08-19T12:22:40Z")

</div>

Hi All, I want to create a new module in filebeat for data patterns for logs will be different. Need a help what are the pre requistes to create custom modul in order to develop one of our client to analyze IBM Webspher…

---

## [Filebeats only sends logs when I have filebeat -e running](https://discuss.elastic.co/t/filebeats-only-sends-logs-when-i-have-filebeat-e-running/245088)

<div class="topic-metadata">

**Author:** [@plegault](https://discuss.elastic.co/u/plegault)\
**Replies:** 10\
**Last updated:** [August 19, 2020, 11:58am UTC](https://discuss.elastic.co/t/filebeats-only-sends-logs-when-i-have-filebeat-e-running/245088 "2020-08-19T11:58:57Z")

</div>

I'm new to configuring ELK stack. I had it setup without ssl and with ssl and back to without ssl. I did this because I was not able to get apache and mysql to send logs to the elk stack. I tried to send it to output.ela…

---

## [Api key & error](https://discuss.elastic.co/t/api-key-error/243873)

<div class="topic-metadata">

**Author:** [@maxxitutti](https://discuss.elastic.co/u/maxxitutti)\
**Replies:** 5\
**Last updated:** [August 19, 2020, 11:11am UTC](https://discuss.elastic.co/t/api-key-error/243873 "2020-08-19T11:11:48Z")

</div>

Hello . i am new with elk sollution co forgive me :). i want to run my first beat on my remote machine ... from the begining i want to deploy api-key for my auditbeat. according to documentation https://www.elastic.co…

---

## [Filebeat Module won't process incomming syslogs](https://discuss.elastic.co/t/filebeat-module-wont-process-incomming-syslogs/245442)

<div class="topic-metadata">

**Author:** [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Replies:** 2\
**Last updated:** [August 19, 2020, 7:27am UTC](https://discuss.elastic.co/t/filebeat-module-wont-process-incomming-syslogs/245442 "2020-08-19T07:27:17Z")

</div>

Hi guys, so i i'm using filebeat modules (asa,cisco,fortinet and palo alto) to parse the syslogs of different firewalls. Everything is working fine, expect for the pan module: I enabled the module - and configured the…

---

## [How to filter the scan scope of containers.paths](https://discuss.elastic.co/t/how-to-filter-the-scan-scope-of-containers-paths/245518)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 0\
**Last updated:** [August 19, 2020, 3:15am UTC](https://discuss.elastic.co/t/how-to-filter-the-scan-scope-of-containers-paths/245518 "2020-08-19T03:15:54Z")

</div>

I only want to collect the directories at the beginning of back and front, how should I set the filter? filebeat.inputs: type: container paths: "/var/log/pods///\*.log" stream: "all" processors: add\_host\_me…

---

## [Filebeat relay](https://discuss.elastic.co/t/filebeat-relay/245504)

<div class="topic-metadata">

**Author:** [@astateofmind](https://discuss.elastic.co/u/astateofmind)\
**Replies:** 0\
**Last updated:** [August 18, 2020, 11:12pm UTC](https://discuss.elastic.co/t/filebeat-relay/245504 "2020-08-18T23:12:40Z")

</div>

So, i'm trying to do something ... weird. Filebeat01 - \> filebeat02-\> logstash. On filebeat01 i enabled logstash output with filbeat02 as target and on filebeat02 tcp input. The json from the first filebat is encapulta…

---

## [Filebeat multiline with hints enabled](https://discuss.elastic.co/t/filebeat-multiline-with-hints-enabled/245472)

<div class="topic-metadata">

**Author:** [@clarkritchie](https://discuss.elastic.co/u/clarkritchie)\
**Replies:** 0\
**Last updated:** [August 18, 2020, 5:24pm UTC](https://discuss.elastic.co/t/filebeat-multiline-with-hints-enabled/245472 "2020-08-18T17:24:09Z")

</div>

I've read the multiline documentation so many times now, I am seeing triple. Our logs are in JSON format and stack traces appear like the example below. When using hints based autodiscovery, is this the correct syntax …

---

## [Custom beat not working flag redefined: strict.perms](https://discuss.elastic.co/t/custom-beat-not-working-flag-redefined-strict-perms/245478)

<div class="topic-metadata">

**Author:** [@dowdyph0](https://discuss.elastic.co/u/dowdyph0)\
**Replies:** 0\
**Last updated:** [August 18, 2020, 6:26pm UTC](https://discuss.elastic.co/t/custom-beat-not-working-flag-redefined-strict-perms/245478 "2020-08-18T18:26:27Z")

</div>

Hi, I've created a custom protocol beat using the python script scripts/create\_tcp\_protocol.py. I've tweaked some things that we're not ok in the code like (\*common.IPPortTuple) entries in trans.go So, i've managed to…

---

## [Filebeat autodiscover not working with hints & namespace](https://discuss.elastic.co/t/filebeat-autodiscover-not-working-with-hints-namespace/243876)

<div class="topic-metadata">

**Author:** [@mirii1994](https://discuss.elastic.co/u/mirii1994)\
**Replies:** 2\
**Last updated:** [August 18, 2020, 3:25pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-not-working-with-hints-namespace/243876 "2020-08-18T15:25:11Z")

</div>

I'd like to configure filebeat to use autodiscover with hints enabled. Problem is, when I set a config for a certain namespace, it cancels the annotations in the pods under that namespace (meaning I get the multiline lo…

---

## [How to define Filebeat writer role?](https://discuss.elastic.co/t/how-to-define-filebeat-writer-role/245450)

<div class="topic-metadata">

**Author:** [@illopssec](https://discuss.elastic.co/u/illopssec)\
**Replies:** 0\
**Last updated:** [August 18, 2020, 2:48pm UTC](https://discuss.elastic.co/t/how-to-define-filebeat-writer-role/245450 "2020-08-18T14:48:13Z")

</div>

Good morning, We are using the hosted elasticsearch service version 7.8 as well as Filebeat 7.8.0. I'm trying to set up the writer role for filebeat instances that will only publish data. In the docs,(https://www.elasti…

---

## [Okta Filebeat Stops Pulling Logs](https://discuss.elastic.co/t/okta-filebeat-stops-pulling-logs/245434)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [August 18, 2020, 1:48pm UTC](https://discuss.elastic.co/t/okta-filebeat-stops-pulling-logs/245434 "2020-08-18T13:48:39Z")

</div>

Has anyone else noticed Filebeat Okta module stops pulling in logs after sometime (I don't have an exact duration). I've been running two Filebeats running the Okta module that pulls from 2 different Okta environments. …

---

## [Metricbeat: Filtering processes based on Command Line parameters](https://discuss.elastic.co/t/metricbeat-filtering-processes-based-on-command-line-parameters/245433)

<div class="topic-metadata">

**Author:** [@musician](https://discuss.elastic.co/u/musician)\
**Replies:** 0\
**Last updated:** [August 18, 2020, 1:47pm UTC](https://discuss.elastic.co/t/metricbeat-filtering-processes-based-on-command-line-parameters/245433 "2020-08-18T13:47:02Z")

</div>

Hello, I have two questions: We have multiple java processes that we would like to connect metrics for. Each of these processes has a custom name as a part of the command line. Since the process name for each of them …

---

## [CEF module and decode\_cef processor](https://discuss.elastic.co/t/cef-module-and-decode-cef-processor/245430)

<div class="topic-metadata">

**Author:** [@anon56147639](https://discuss.elastic.co/u/anon56147639)\
**Replies:** 0\
**Last updated:** [August 18, 2020, 1:41pm UTC](https://discuss.elastic.co/t/cef-module-and-decode-cef-processor/245430 "2020-08-18T13:41:56Z")

</div>

Hi everyone, I have a question about the CEF module in Filebeat. Can it only be used to listen to incoming syslog traffic or can the module also read from locally stored files? I'm asking this because there is no defin…

---

## [Indices based on field value](https://discuss.elastic.co/t/indices-based-on-field-value/244891)

<div class="topic-metadata">

**Author:** [@jijo.john](https://discuss.elastic.co/u/jijo.john)\
**Replies:** 10\
**Last updated:** [August 18, 2020, 1:36pm UTC](https://discuss.elastic.co/t/indices-based-on-field-value/244891 "2020-08-18T13:36:38Z")

</div>

Hi There, I am doing a POC on elasticsearch, currently all the cisco asa logs are captured using filebeat cisco module. We would like to create a separate indice when a specific condition is met. Basically we need creat…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=218)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=220)
