# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=220

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 221

---

## [Invalid Yamyl Config Error: "not find expected hexdecimal number"](https://discuss.elastic.co/t/invalid-yamyl-config-error-not-find-expected-hexdecimal-number/245164)

<div class="topic-metadata">

**Author:** [@Koray\_Tugberk\_GUBUR](https://discuss.elastic.co/u/Koray_Tugberk_GUBUR)\
**Replies:** 1\
**Last updated:** [August 18, 2020, 7:27am UTC](https://discuss.elastic.co/t/invalid-yamyl-config-error-not-find-expected-hexdecimal-number/245164 "2020-08-18T07:27:56Z")

</div>

Hello, when I run the ./filebeat setup ./filebeat -e command, I got the error below: Exiting: 1 error: invalid config: yaml: line 10: did not find expected hexdecimal number Do you have any idea? This is the file's l…

---

## [Unable to push multiline events from Filebeat to Logstash](https://discuss.elastic.co/t/unable-to-push-multiline-events-from-filebeat-to-logstash/245343)

<div class="topic-metadata">

**Author:** [@asabhyak](https://discuss.elastic.co/u/asabhyak)\
**Replies:** 0\
**Last updated:** [August 18, 2020, 4:16am UTC](https://discuss.elastic.co/t/unable-to-push-multiline-events-from-filebeat-to-logstash/245343 "2020-08-18T04:16:11Z")

</div>

Hi team, I am doing a PoC on ELK and have come across an issue. I have had a look at many topics on discuss.elastic.co and StackOverflow, but none seems to have helped. I am trying to configure multiline events via Fil…

---

## [Elasticsearch kibana 7.8 give false information ?!](https://discuss.elastic.co/t/elasticsearch-kibana-7-8-give-false-information/245333)

<div class="topic-metadata">

**Author:** [@Feriel\_Mufti](https://discuss.elastic.co/u/Feriel_Mufti)\
**Replies:** 4\
**Last updated:** [August 18, 2020, 4:41am UTC](https://discuss.elastic.co/t/elasticsearch-kibana-7-8-give-false-information/245333 "2020-08-18T04:41:17Z")

</div>

Hello , i am using Elasticsearch ,kibana and beats 7.8 , while i am using winlogbeat i have noticed illogical information , suring the last 15 min ( i didn't even open the machine that is working with winlogbeat , it…

---

## [Metric beat ssl configuration is not working in linux6](https://discuss.elastic.co/t/metric-beat-ssl-configuration-is-not-working-in-linux6/245247)

<div class="topic-metadata">

**Author:** [@manojb1-in.ibm.com](https://discuss.elastic.co/u/manojb1-in.ibm.com)\
**Replies:** 1\
**Last updated:** [August 18, 2020, 1:59am UTC](https://discuss.elastic.co/t/metric-beat-ssl-configuration-is-not-working-in-linux6/245247 "2020-08-18T01:59:18Z")

</div>

Below is metricbeat.yml file etricbeat.config.modules: path: ${path.config}/modules.d/\*.yml reload.enabled: false setup.template.settings: index.number\_of\_shards: 1 index.codec: best\_compression setup.dashboard…

---

## [Connecting WinLogBeat to ElasticSearch - if I ship to LogStash, I get weird index creation. If I ship directly to ES, the connection is refused](https://discuss.elastic.co/t/connecting-winlogbeat-to-elasticsearch-if-i-ship-to-logstash-i-get-weird-index-creation-if-i-ship-directly-to-es-the-connection-is-refused/245318)

<div class="topic-metadata">

**Author:** [@apatton-cnet](https://discuss.elastic.co/u/apatton-cnet)\
**Replies:** 0\
**Last updated:** [August 17, 2020, 9:15pm UTC](https://discuss.elastic.co/t/connecting-winlogbeat-to-elasticsearch-if-i-ship-to-logstash-i-get-weird-index-creation-if-i-ship-directly-to-es-the-connection-is-refused/245318 "2020-08-17T21:15:18Z")

</div>

So I have ElasticSearch already ingesting syslogs from my Sophos-XG firewall. I have a separate logstash filter config for this input, and it all works correctly. The index name is sophos-xg-##-##-#### I wanted to start…

---

## [Linux audit trail file to ECS output](https://discuss.elastic.co/t/linux-audit-trail-file-to-ecs-output/245285)

<div class="topic-metadata">

**Author:** [@ToddH](https://discuss.elastic.co/u/ToddH)\
**Replies:** 0\
**Last updated:** [August 17, 2020, 4:42pm UTC](https://discuss.elastic.co/t/linux-audit-trail-file-to-ecs-output/245285 "2020-08-17T16:42:49Z")

</div>

I've successfully configured Auditbeat to collect logs on a Linux system (CentOS 7.7). However, I also have some systems that (for policy reasons) cannot have Auditbeat installed on them. Periodically the audit trail fi…

---

## [Winlogbeat - no winlog.logon.id](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 21\
**Last updated:** [August 17, 2020, 2:29pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524 "2020-08-17T14:29:41Z")

</div>

The winlogbeat 7.7.1 dashboards reference winlog.logon.id.These two threads also mention it and imply it should be in versions \> 7.4. https://discuss.elastic.co/search?q=winlog.logon.id However, I am running 7.6.2 and …

---

## [Custom beat needs to send custom health messages to monitoring cluster](https://discuss.elastic.co/t/custom-beat-needs-to-send-custom-health-messages-to-monitoring-cluster/245032)

<div class="topic-metadata">

**Author:** [@rmauri](https://discuss.elastic.co/u/rmauri)\
**Replies:** 1\
**Last updated:** [August 17, 2020, 2:18pm UTC](https://discuss.elastic.co/t/custom-beat-needs-to-send-custom-health-messages-to-monitoring-cluster/245032 "2020-08-17T14:18:08Z")

</div>

I have a suite of custom beats that are all configured to output to logstash and enable the internal monitoring collection. The monitoring data being collected is currently of two types (as supported out of the box by li…

---

## [Non-zero metrics in the last 30s how to reduce this 30s to 5s?](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s-how-to-reduce-this-30s-to-5s/245239)

<div class="topic-metadata">

**Author:** [@Puneeth\_S\_B\_Gowda1](https://discuss.elastic.co/u/Puneeth_S_B_Gowda1)\
**Replies:** 2\
**Last updated:** [August 17, 2020, 2:12pm UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s-how-to-reduce-this-30s-to-5s/245239 "2020-08-17T14:12:36Z")

</div>

Hi ELK friends, Non-zero metrics in the last 30s how to reduce this 30s to 5s? File beat should send data instantly instead of every 30s how to change this setting?

---

## [Saved "field" parameter is now invalid. Please select a new field](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886)

<div class="topic-metadata">

**Author:** [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Replies:** 6\
**Last updated:** [August 17, 2020, 1:15pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886 "2020-08-17T13:15:31Z")

</div>

hello everybody, I am setting up ILM and I am having an error in kibana dashboards: Saved "field" parameter is now invalid. Please select a new field. here are the steps that I followed: Create ILM policy: PUT \_ilm/p…

---

## [Source raw files purging after shipping to ELK](https://discuss.elastic.co/t/source-raw-files-purging-after-shipping-to-elk/243597)

<div class="topic-metadata">

**Author:** [@Puneeth\_S\_B\_Gowda1](https://discuss.elastic.co/u/Puneeth_S_B_Gowda1)\
**Replies:** 5\
**Last updated:** [August 17, 2020, 1:05pm UTC](https://discuss.elastic.co/t/source-raw-files-purging-after-shipping-to-elk/243597 "2020-08-17T13:05:33Z")

</div>

how to manage physical logs file after moving to ELK if we want to delete text files after moving to ELK how do we do? what tool can i userWe are getting payload logs from GDS channels as response for our request to book…

---

## [Get message information from filebeat](https://discuss.elastic.co/t/get-message-information-from-filebeat/244948)

<div class="topic-metadata">

**Author:** [@jorge\_rivera](https://discuss.elastic.co/u/jorge_rivera)\
**Replies:** 0\
**Last updated:** [August 13, 2020, 9:14pm UTC](https://discuss.elastic.co/t/get-message-information-from-filebeat/244948 "2020-08-13T21:14:44Z")

</div>

Good afternoon. I am starting in ELK issues and I have a question that I hope you will help me solve. I am sending logs from a cisco 5520 controller to a server (udp: 514) but when I receive the log with filebeat I get…

---

## [Parse the log in filebeat](https://discuss.elastic.co/t/parse-the-log-in-filebeat/244993)

<div class="topic-metadata">

**Author:** [@sandeep1-0](https://discuss.elastic.co/u/sandeep1-0)\
**Replies:** 0\
**Last updated:** [August 14, 2020, 10:41am UTC](https://discuss.elastic.co/t/parse-the-log-in-filebeat/244993 "2020-08-14T10:41:57Z")

</div>

Hey my current setup includes filebeat sending data to kafka. So i wanted to have control over data going into partition. So by making use of a unique key we can actually control it. So the question is . Is there a way …

---

## [Use filebeat as a relay?](https://discuss.elastic.co/t/use-filebeat-as-a-relay/245055)

<div class="topic-metadata">

**Author:** [@astateofmind](https://discuss.elastic.co/u/astateofmind)\
**Replies:** 0\
**Last updated:** [August 14, 2020, 6:44pm UTC](https://discuss.elastic.co/t/use-filebeat-as-a-relay/245055 "2020-08-14T18:44:24Z")

</div>

I have a bit more complicated setup. But what I want is something similar to what's below: Host1 -\> Host2 -\> Logstash -\> ES. And i want to ship the metrics and logs from Host1 to ES. Metrics and logs from Host2 are i…

---

## [Filebeat to kafka - monitoring](https://discuss.elastic.co/t/filebeat-to-kafka-monitoring/245148)

<div class="topic-metadata">

**Author:** [@grynhtjnyuk](https://discuss.elastic.co/u/grynhtjnyuk)\
**Replies:** 0\
**Last updated:** [August 16, 2020, 2:36pm UTC](https://discuss.elastic.co/t/filebeat-to-kafka-monitoring/245148 "2020-08-16T14:36:44Z")

</div>

I have filebeat that sends data to kafka. Could you please tell me, how can I monitor this flow and send allert when no new data in kafka longer than 20 minutes for example. do you know some kafka metrics ? could it b…

---

## [Generate automatic index names like "%{\[container.name\]}-%{+yyyy.MM.dd}" with ILM enabled](https://discuss.elastic.co/t/generate-automatic-index-names-like-container-name-yyyy-mm-dd-with-ilm-enabled/244217)

<div class="topic-metadata">

**Author:** [@sholokhov17](https://discuss.elastic.co/u/sholokhov17)\
**Replies:** 4\
**Last updated:** [August 16, 2020, 9:26pm UTC](https://discuss.elastic.co/t/generate-automatic-index-names-like-container-name-yyyy-mm-dd-with-ilm-enabled/244217 "2020-08-16T21:26:34Z")

</div>

Hello, our worked config of filebeat.yml: #===== Filebeat Inputs ====== filebeat.inputs: - type: docker combine\_partial: true containers: path: "/var/lib/docker/containers" ids : - "\*" #===== Filebeat…

---

## [Fortinet log reading error in filebeat fortinet module v7.8.1](https://discuss.elastic.co/t/fortinet-log-reading-error-in-filebeat-fortinet-module-v7-8-1/245149)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 0\
**Last updated:** [August 16, 2020, 3:18pm UTC](https://discuss.elastic.co/t/fortinet-log-reading-error-in-filebeat-fortinet-module-v7-8-1/245149 "2020-08-16T15:18:11Z")

</div>

i am using filebeat version 7.8.1 i got error saying Provided Grok expressions do not match field value: \[date=2020-04-23 time=12:17:45 devname=\\"testswitch1\\" devid=\\"somerouterid\\" logid=\\"0317013312\\" type=\\"utm\\" s…

---

## [Modify filebeat module](https://discuss.elastic.co/t/modify-filebeat-module/245134)

<div class="topic-metadata">

**Author:** [@bornatalebi](https://discuss.elastic.co/u/bornatalebi)\
**Replies:** 0\
**Last updated:** [August 16, 2020, 10:51am UTC](https://discuss.elastic.co/t/modify-filebeat-module/245134 "2020-08-16T10:51:44Z")

</div>

Hi Is there an option to edit what kind of logs a module sends? for example i want winlogbeat not to send authentication failure events. should i use processors?

---

## [Purpose of pipeline.js in filebeat module](https://discuss.elastic.co/t/purpose-of-pipeline-js-in-filebeat-module/245077)

<div class="topic-metadata">

**Author:** [@bornatalebi](https://discuss.elastic.co/u/bornatalebi)\
**Replies:** 0\
**Last updated:** [August 15, 2020, 7:18am UTC](https://discuss.elastic.co/t/purpose-of-pipeline-js-in-filebeat-module/245077 "2020-08-15T07:18:17Z")

</div>

Hi, I want to edit the cisco filebeat module to read more types of ios logs ( e.g., ssh login attemps). There is a pipeline.js file that does most of the job. I know it's used for Script processor. but i couldn't find a…

---

## [FILEBEAT - GOOGLE CLOUD MODULE - PUB/SUB](https://discuss.elastic.co/t/filebeat-google-cloud-module-pub-sub/244804)

<div class="topic-metadata">

**Author:** [@juaromu](https://discuss.elastic.co/u/juaromu)\
**Replies:** 6\
**Last updated:** [August 14, 2020, 9:49pm UTC](https://discuss.elastic.co/t/filebeat-google-cloud-module-pub-sub/244804 "2020-08-14T21:49:49Z")

</div>

Hi there: Running Filebeat, 7.8.1 and using the Google Cloud Module, PUB/SUB, to pull out VPC Firewall Logs. Getting an error (I believe JSON related) when Filebeat starts: ERROR \[google.pubsub\] googlepu…

---

## [Adopting beats/v7 v7.8.1 - custom beat no longer compiles, refactoring help needed](https://discuss.elastic.co/t/adopting-beats-v7-v7-8-1-custom-beat-no-longer-compiles-refactoring-help-needed/244200)

<div class="topic-metadata">

**Author:** [@rmauri](https://discuss.elastic.co/u/rmauri)\
**Replies:** 2\
**Last updated:** [August 14, 2020, 2:03pm UTC](https://discuss.elastic.co/t/adopting-beats-v7-v7-8-1-custom-beat-no-longer-compiles-refactoring-help-needed/244200 "2020-08-14T14:03:22Z")

</div>

I have several custom beats that I am now refactoring to adopt the beats/v7 and go modules. The trivial main.go no longer compile as there are breaking changes and the new API replacement is unclear how to use it. The …

---

## [Grokking of the request of an apache logfile is to optimistic](https://discuss.elastic.co/t/grokking-of-the-request-of-an-apache-logfile-is-to-optimistic/245002)

<div class="topic-metadata">

**Author:** [@guequierre](https://discuss.elastic.co/u/guequierre)\
**Replies:** 0\
**Last updated:** [August 14, 2020, 11:37am UTC](https://discuss.elastic.co/t/grokking-of-the-request-of-an-apache-logfile-is-to-optimistic/245002 "2020-08-14T11:37:17Z")

</div>

Right now it expects the request always to be in a valid form of "method url version". But in practice i do see a lot of invalid requests which i actually from a siem point of view i want to know about. As these are pote…

---

## [Filebeat not able to get k8s namespace annotations](https://discuss.elastic.co/t/filebeat-not-able-to-get-k8s-namespace-annotations/245000)

<div class="topic-metadata">

**Author:** [@tocw](https://discuss.elastic.co/u/tocw)\
**Replies:** 0\
**Last updated:** [August 14, 2020, 11:30am UTC](https://discuss.elastic.co/t/filebeat-not-able-to-get-k8s-namespace-annotations/245000 "2020-08-14T11:30:41Z")

</div>

Hello, I noticed a potential issue with filebeat. I'm trying to add some annotations to the log messages and I noticed that filebeat is not able to get namespace annotations from kubernetes cluster. Pod annotations are …

---

## [Load Balancing Elasticsearch Nodes](https://discuss.elastic.co/t/load-balancing-elasticsearch-nodes/244933)

<div class="topic-metadata">

**Author:** [@jijo.john](https://discuss.elastic.co/u/jijo.john)\
**Replies:** 2\
**Last updated:** [August 14, 2020, 9:15am UTC](https://discuss.elastic.co/t/load-balancing-elasticsearch-nodes/244933 "2020-08-14T09:15:48Z")

</div>

Hi There, We are new to elasticsearch and running a POC and nodes are hosted as EC2 instance in aws. We have a query for elasticsearch node redundancy. How do we configure multiple elasticsearch nodes in auditbeat/fileb…

---

## [Problem to send data from filebeat autodiscover container to elastic search on kubernetes](https://discuss.elastic.co/t/problem-to-send-data-from-filebeat-autodiscover-container-to-elastic-search-on-kubernetes/244795)

<div class="topic-metadata">

**Author:** [@MrZycred](https://discuss.elastic.co/u/MrZycred)\
**Replies:** 1\
**Last updated:** [August 13, 2020, 8:12pm UTC](https://discuss.elastic.co/t/problem-to-send-data-from-filebeat-autodiscover-container-to-elastic-search-on-kubernetes/244795 "2020-08-13T20:12:56Z")

</div>

I'm trying to properly configure Filebeat autodiscover on my kubernetes cluster to send log data from a specific namespace to a VM containing the elasticsearch installed. I couldn't identify the problem, because apparent…

---

## [Monitor Acitve MQ server](https://discuss.elastic.co/t/monitor-acitve-mq-server/244923)

<div class="topic-metadata">

**Author:** [@amritesh\_mishra](https://discuss.elastic.co/u/amritesh_mishra)\
**Replies:** 1\
**Last updated:** [August 13, 2020, 5:02pm UTC](https://discuss.elastic.co/t/monitor-acitve-mq-server/244923 "2020-08-13T17:02:58Z")

</div>

Hi Team, What are configuration we have to do to monitor the active mq sever and also see what are the messgages are getting consumed by the consumers through metricbeat. Regards, Amritesh Mishra

---

## [\[Question\] Can I distribute filebeat ZIP binaries?](https://discuss.elastic.co/t/question-can-i-distribute-filebeat-zip-binaries/244901)

<div class="topic-metadata">

**Author:** [@joaovperin](https://discuss.elastic.co/u/joaovperin)\
**Replies:** 0\
**Last updated:** [August 13, 2020, 2:53pm UTC](https://discuss.elastic.co/t/question-can-i-distribute-filebeat-zip-binaries/244901 "2020-08-13T14:53:12Z")

</div>

I have a distributed Spring application running on Windows. I'm using Filebeat to ship data to a server where I have Elastic Search, Logstash and Kibana running. Internally, I've installed Filebeat using the msi install…

---

## [Error message when creating a custom beat](https://discuss.elastic.co/t/error-message-when-creating-a-custom-beat/244868)

<div class="topic-metadata">

**Author:** [@grobd](https://discuss.elastic.co/u/grobd)\
**Replies:** 0\
**Last updated:** [August 13, 2020, 11:19am UTC](https://discuss.elastic.co/t/error-message-when-creating-a-custom-beat/244868 "2020-08-13T11:19:09Z")

</div>

Hi, i just wanted to create a new community beat by sending the number of open files to Elasticsearch using the command lsof | wc -l. I have also checked the documentation in the beats section and followed it very caref…

---

## [FileBeat updatable log](https://discuss.elastic.co/t/filebeat-updatable-log/243565)

<div class="topic-metadata">

**Author:** [@vdmitrief](https://discuss.elastic.co/u/vdmitrief)\
**Replies:** 2\
**Last updated:** [August 13, 2020, 11:15am UTC](https://discuss.elastic.co/t/filebeat-updatable-log/243565 "2020-08-13T11:15:28Z")

</div>

Need help configuring filebit ... One of my applications writes rotated logs to a file with a specified number of lines. If the file contains only 3 lines, then the log at the first moment of time will look like this: …

---

## [Rotated log files have incorrect permissions](https://discuss.elastic.co/t/rotated-log-files-have-incorrect-permissions/244623)

<div class="topic-metadata">

**Author:** [@drjan](https://discuss.elastic.co/u/drjan)\
**Replies:** 3\
**Last updated:** [August 13, 2020, 10:40am UTC](https://discuss.elastic.co/t/rotated-log-files-have-incorrect-permissions/244623 "2020-08-13T10:40:01Z")

</div>

When log files are rotated by metricbeat, the files created do not have the permissions specified in the metricbeat.yml file. Here's part of metricbeat.yml: logging.to\_files: true logging.files: path: /var/log/metric…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=219)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=221)
