# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=221

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 222

---

## [MSSQL Connection to Server Instance fails due to Connection String parsing](https://discuss.elastic.co/t/mssql-connection-to-server-instance-fails-due-to-connection-string-parsing/244738)

<div class="topic-metadata">

**Author:** [@phebing](https://discuss.elastic.co/u/phebing)\
**Replies:** 2\
**Last updated:** [August 13, 2020, 7:56am UTC](https://discuss.elastic.co/t/mssql-connection-to-server-instance-fails-due-to-connection-string-parsing/244738 "2020-08-13T07:56:51Z")

</div>

I would like to connect the Metricbeat MSSQL to a specific Instance of the sql server. Connecting to another server without an instance works fine, but i can't get it to work with an instance. My yml file looks like th…

---

## [Filebeat - AWS Module with WAF Logs](https://discuss.elastic.co/t/filebeat-aws-module-with-waf-logs/244815)

<div class="topic-metadata">

**Author:** [@robincher](https://discuss.elastic.co/u/robincher)\
**Replies:** 0\
**Last updated:** [August 13, 2020, 7:29am UTC](https://discuss.elastic.co/t/filebeat-aws-module-with-waf-logs/244815 "2020-08-13T07:29:55Z")

</div>

Hi, I am referring to this post , and attempt to set-up something similar on AWS Just a question, and being pretty new in using Elastic's beats, will the current AWS module allow the pulling of AWS WAF logs (or oth…

---

## [How to change timestamp field added by filebeat while sending logs to output plugin](https://discuss.elastic.co/t/how-to-change-timestamp-field-added-by-filebeat-while-sending-logs-to-output-plugin/244812)

<div class="topic-metadata">

**Author:** [@aksshm](https://discuss.elastic.co/u/aksshm)\
**Replies:** 0\
**Last updated:** [August 13, 2020, 7:06am UTC](https://discuss.elastic.co/t/how-to-change-timestamp-field-added-by-filebeat-while-sending-logs-to-output-plugin/244812 "2020-08-13T07:06:13Z")

</div>

Hi, I'm running filebeat where it is fetching logs from kubernetes pods and sending to kafka. While fetching from kafka topic i could see filebeat is adding some fields to the logs. wherein one field @timestamp is com…

---

## [Multiline message appearing as individual event](https://discuss.elastic.co/t/multiline-message-appearing-as-individual-event/243710)

<div class="topic-metadata">

**Author:** [@raj\_elk](https://discuss.elastic.co/u/raj_elk)\
**Replies:** 3\
**Last updated:** [August 13, 2020, 6:19am UTC](https://discuss.elastic.co/t/multiline-message-appearing-as-individual-event/243710 "2020-08-13T06:19:05Z")

</div>

Each line of logs appearing as individual event where as i want it to appear as single. In filebeat config i have set multiline setting as below. multiline.pattern: '^Timestamp' multline.negate : true multiline.match…

---

## [How to populate the data from custom index to the default metric beat index dashboard](https://discuss.elastic.co/t/how-to-populate-the-data-from-custom-index-to-the-default-metric-beat-index-dashboard/244793)

<div class="topic-metadata">

**Author:** [@BSR21](https://discuss.elastic.co/u/BSR21)\
**Replies:** 0\
**Last updated:** [August 13, 2020, 3:06am UTC](https://discuss.elastic.co/t/how-to-populate-the-data-from-custom-index-to-the-default-metric-beat-index-dashboard/244793 "2020-08-13T03:06:58Z")

</div>

Hello All, I am new to ELK stack. So if my question is not clear please ask I will try to elaborate. I am working on ELK 7.8.0. I have a question here. I have installed Metricbeat on the server and got lots of default…

---

## [How to view cloudwatch log in Kibana after deploying via functionbeat](https://discuss.elastic.co/t/how-to-view-cloudwatch-log-in-kibana-after-deploying-via-functionbeat/244473)

<div class="topic-metadata">

**Author:** [@JamaesTiger](https://discuss.elastic.co/u/JamaesTiger)\
**Replies:** 2\
**Last updated:** [August 13, 2020, 1:06am UTC](https://discuss.elastic.co/t/how-to-view-cloudwatch-log-in-kibana-after-deploying-via-functionbeat/244473 "2020-08-13T01:06:38Z")

</div>

I am testing how to stream to elastic service cloudwatch log via lambda function. Deployment seem to be fine but i couldn't create(define) index pattern. Please let me know what was problem of my tested configuration(f…

---

## [Filebeat indices for each type of source log](https://discuss.elastic.co/t/filebeat-indices-for-each-type-of-source-log/244410)

<div class="topic-metadata">

**Author:** [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Replies:** 3\
**Last updated:** [August 12, 2020, 7:05pm UTC](https://discuss.elastic.co/t/filebeat-indices-for-each-type-of-source-log/244410 "2020-08-12T19:05:31Z")

</div>

Dear all, I have an ELK 7.8.1 server with syslog and cisco module enabled from Filebeat. At the moment I'm receiving data from: Linux servers (syslog) Cisco ASA (cisco module, asa data set) Cisco IOS (cisco module, io…

---

## [How to remove the specific Icingabeat field names sent to elasticsearch?](https://discuss.elastic.co/t/how-to-remove-the-specific-icingabeat-field-names-sent-to-elasticsearch/244304)

<div class="topic-metadata">

**Author:** [@Pankaj\_Navneet](https://discuss.elastic.co/u/Pankaj_Navneet)\
**Replies:** 2\
**Last updated:** [August 12, 2020, 1:44pm UTC](https://discuss.elastic.co/t/how-to-remove-the-specific-icingabeat-field-names-sent-to-elasticsearch/244304 "2020-08-12T13:44:58Z")

</div>

Hi Team, I have integrated Icinga to my ELK cluster using Icingabeat. Everything is working as expected, but now I don't want to include some of the available fields that are sent to Elasticsearch from Icingabeat. Reas…

---

## [Getting error while configuring metricbeat for Oracle module](https://discuss.elastic.co/t/getting-error-while-configuring-metricbeat-for-oracle-module/244402)

<div class="topic-metadata">

**Author:** [@puja](https://discuss.elastic.co/u/puja)\
**Replies:** 2\
**Last updated:** [August 12, 2020, 12:58pm UTC](https://discuss.elastic.co/t/getting-error-while-configuring-metricbeat-for-oracle-module/244402 "2020-08-12T12:58:47Z")

</div>

I am using 7.7.0 version of ELK stack and trying to configure Oracle module of metricbeat. Below is my oracle.yml - Module: oracle Docs: https://www.elastic.co/guide/en/beats/metricbeat/7.6/metricbeat-module-oracle.htm…

---

## [Winlogbeat error during setup](https://discuss.elastic.co/t/winlogbeat-error-during-setup/244093)

<div class="topic-metadata">

**Author:** [@JohnLyman](https://discuss.elastic.co/u/JohnLyman)\
**Replies:** 8\
**Last updated:** [August 12, 2020, 11:47am UTC](https://discuss.elastic.co/t/winlogbeat-error-during-setup/244093 "2020-08-12T11:47:05Z")

</div>

When running .\\winlogbeat-7.8.1-windows-x86\_64\\winlogbeat.exe export index-pattern I'm getting the following error: Error generating Index Pattern: field \<user.domain\> is duplicated. I verified that this error goes all…

---

## [Packetbeat memory usage](https://discuss.elastic.co/t/packetbeat-memory-usage/244177)

<div class="topic-metadata">

**Author:** [@sidiney.crescencio](https://discuss.elastic.co/u/sidiney.crescencio)\
**Replies:** 1\
**Last updated:** [August 12, 2020, 10:55am UTC](https://discuss.elastic.co/t/packetbeat-memory-usage/244177 "2020-08-12T10:55:40Z")

</div>

Hi there, I have recently deployed the ELK stack and beats to my servers, and for some of them I'm facing an issue with Packetbeat consuming 50-70% memory of the server Beats: 7.8.0 Mongo: 4.0.6 This happens mostly d…

---

## [Filebeat installation on FortiOS](https://discuss.elastic.co/t/filebeat-installation-on-fortios/244435)

<div class="topic-metadata">

**Author:** [@anon56147639](https://discuss.elastic.co/u/anon56147639)\
**Replies:** 2\
**Last updated:** [August 12, 2020, 10:19am UTC](https://discuss.elastic.co/t/filebeat-installation-on-fortios/244435 "2020-08-12T10:19:49Z")

</div>

Hi everyone! I'd like to use the Filebeat Fortinet module to send the firewall log files to my logstash server. However, I can't execute the cURL command mentioned in the Filebeat installation reference. I'm referring …

---

## [Cant see my Beats list in ES version 7.8.0](https://discuss.elastic.co/t/cant-see-my-beats-list-in-es-version-7-8-0/244181)

<div class="topic-metadata">

**Author:** [@Alexandros888](https://discuss.elastic.co/u/Alexandros888)\
**Replies:** 1\
**Last updated:** [August 11, 2020, 2:24pm UTC](https://discuss.elastic.co/t/cant-see-my-beats-list-in-es-version-7-8-0/244181 "2020-08-11T14:24:47Z")

</div>

Hello, After updating to ES version 7.8.0 i cant see my Beats list in Beat management What can i do to see them as i did before the update? Important note: Despite the fact that i dont see them in the beats manage…

---

## [Metricbeat jolokia autodiscover question](https://discuss.elastic.co/t/metricbeat-jolokia-autodiscover-question/243736)

<div class="topic-metadata">

**Author:** [@ZMMWMY](https://discuss.elastic.co/u/ZMMWMY)\
**Replies:** 8\
**Last updated:** [August 12, 2020, 2:45am UTC](https://discuss.elastic.co/t/metricbeat-jolokia-autodiscover-question/243736 "2020-08-12T02:45:43Z")

</div>

this is my config , no jvm data sent to es ,so what goes wrong with this config version : 7.6.0 metricbeat.yml metricbeat.config.modules: # Mounted \`metricbeat-daemonset-modules\` configmap: path: ${path.config}/mo…

---

## [Event outcome and winlog.keywords - Possible Bug](https://discuss.elastic.co/t/event-outcome-and-winlog-keywords-possible-bug/242353)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 1\
**Last updated:** [August 11, 2020, 8:07pm UTC](https://discuss.elastic.co/t/event-outcome-and-winlog-keywords-possible-bug/242353 "2020-08-11T20:07:29Z")

</div>

Hi, I'm using winlogbeat in DC that are in different languages (English and Spanish). Looking at the event.outcome I realized that was missing in the events coming from the DC with Spanish set. That is because the eve…

---

## [Beats log capture limitation using filebeat, matricbeat and winlogbeat](https://discuss.elastic.co/t/beats-log-capture-limitation-using-filebeat-matricbeat-and-winlogbeat/244542)

<div class="topic-metadata">

**Author:** [@japarka2](https://discuss.elastic.co/u/japarka2)\
**Replies:** 2\
**Last updated:** [August 11, 2020, 5:59pm UTC](https://discuss.elastic.co/t/beats-log-capture-limitation-using-filebeat-matricbeat-and-winlogbeat/244542 "2020-08-11T17:59:35Z")

</div>

Hi Team, Since I am new to Beats and ElasticSearch, I have few query before perfromaing POC on Beats and Elasticsearch for windows and Linux monitoring. Is possible to capature the log on endpoint and send the capture…

---

## [Choosing the apropriate beats to import MySQL-DB](https://discuss.elastic.co/t/choosing-the-apropriate-beats-to-import-mysql-db/244602)

<div class="topic-metadata">

**Author:** [@S.Schlaak](https://discuss.elastic.co/u/S.Schlaak)\
**Replies:** 1\
**Last updated:** [August 11, 2020, 5:24pm UTC](https://discuss.elastic.co/t/choosing-the-apropriate-beats-to-import-mysql-db/244602 "2020-08-11T17:24:51Z")

</div>

Hi, i am new to working with the elastic solutions and currently tasked to import a variety of data from MySQL Databases into Kibana / elastic. So i found some solutions promising that metricbeats and filebeat can impo…

---

## [Report disk failures](https://discuss.elastic.co/t/report-disk-failures/243605)

<div class="topic-metadata">

**Author:** [@jmcclelland](https://discuss.elastic.co/u/jmcclelland)\
**Replies:** 2\
**Last updated:** [August 11, 2020, 4:21pm UTC](https://discuss.elastic.co/t/report-disk-failures/243605 "2020-08-11T16:21:14Z")

</div>

The journald log is reporting: Jul 22 09:39:26 zora kernel: sd 3:0:0:0: \[sdd\] tag#14 FAILED Result: hostbyte=DID\_OK driverbyte=DRIVER\_SENSE Jul 22 09:39:26 zora kernel: sd 3:0:0:0: \[sdd\] tag#14 Sense Key : Medium Error …

---

## [Filebeat sending only few log entries to Logstash](https://discuss.elastic.co/t/filebeat-sending-only-few-log-entries-to-logstash/244180)

<div class="topic-metadata">

**Author:** [@eth](https://discuss.elastic.co/u/eth)\
**Replies:** 1\
**Last updated:** [August 11, 2020, 2:25pm UTC](https://discuss.elastic.co/t/filebeat-sending-only-few-log-entries-to-logstash/244180 "2020-08-11T14:25:44Z")

</div>

I am trying to send kubernetes pod log of 100 MB to logstash via filebeat. pod log - filebeat- logstash -syslog I observed that filebeat stopped reading after sending some MB data. I could see the file getting created …

---

## [Too many field in metricbeat](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 8\
**Last updated:** [August 11, 2020, 12:55pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572 "2020-08-11T12:55:03Z")

</div>

When I start the metricbeat it loads about 3000 field. I know it is loading default template. even when I have only one module.d/system.yml file. how do I only load system template?

---

## [Filebeat didn't drop some of the fields like agent.\*, ecs.\* etc](https://discuss.elastic.co/t/filebeat-didnt-drop-some-of-the-fields-like-agent-ecs-etc/243911)

<div class="topic-metadata">

**Author:** [@mohanr](https://discuss.elastic.co/u/mohanr)\
**Replies:** 2\
**Last updated:** [August 11, 2020, 11:52am UTC](https://discuss.elastic.co/t/filebeat-didnt-drop-some-of-the-fields-like-agent-ecs-etc/243911 "2020-08-11T11:52:53Z")

</div>

Hi, I am using filebeat with a docker processor. Filebeat generate some fields like agent, ecs etc. I am trying to remove these fields using drop\_fields processor. filebeat.inputs: - type: docker containers.ids: …

---

## [Monitor elasticsearch with metricbeat, cannot get "index" metricset](https://discuss.elastic.co/t/monitor-elasticsearch-with-metricbeat-cannot-get-index-metricset/243816)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 7\
**Last updated:** [August 11, 2020, 9:11am UTC](https://discuss.elastic.co/t/monitor-elasticsearch-with-metricbeat-cannot-get-index-metricset/243816 "2020-08-11T09:11:09Z")

</div>

I am running on kubernetes, with elastic Helm, 3 master nodes and 3 data nodes. Metricbeat elastic Helm to run metricbeat. I configure metricbeat to monitor my 6 nodes ES cluster, and give it as elasticsearch host the m…

---

## [Exiting: resource 'metricbeat-7.8.0' exists, but it is not an alias](https://discuss.elastic.co/t/exiting-resource-metricbeat-7-8-0-exists-but-it-is-not-an-alias/244507)

<div class="topic-metadata">

**Author:** [@elastic8](https://discuss.elastic.co/u/elastic8)\
**Replies:** 0\
**Last updated:** [August 11, 2020, 8:10am UTC](https://discuss.elastic.co/t/exiting-resource-metricbeat-7-8-0-exists-but-it-is-not-an-alias/244507 "2020-08-11T08:10:45Z")

</div>

we have more than 50 server running and we installed metricbeat 7.6.2 and in some server 7.8.0 but whenver we are tying to setup (metricbeat setup) cmd it show below error Exiting: resource 'metricbeat-7.8.0' exists, bu…

---

## [Tomcat dashboard](https://discuss.elastic.co/t/tomcat-dashboard/244505)

<div class="topic-metadata">

**Author:** [@tomang](https://discuss.elastic.co/u/tomang)\
**Replies:** 0\
**Last updated:** [August 11, 2020, 7:57am UTC](https://discuss.elastic.co/t/tomcat-dashboard/244505 "2020-08-11T07:57:31Z")

</div>

Hello, I am using metricbeat 7.8.1. I notice that under $METRICBEAT\_HOME/kibana/7/dashboard, there is no the default tomcat dashboard ( Metricbeat-Tomcat-overview.json ). But the json is available on github, that I copi…

---

## [Filebeat AWS Module Errors and Missing Logs](https://discuss.elastic.co/t/filebeat-aws-module-errors-and-missing-logs/244503)

<div class="topic-metadata">

**Author:** [@johnnywalker](https://discuss.elastic.co/u/johnnywalker)\
**Replies:** 0\
**Last updated:** [August 11, 2020, 7:36am UTC](https://discuss.elastic.co/t/filebeat-aws-module-errors-and-missing-logs/244503 "2020-08-11T07:36:17Z")

</div>

Prior to our 7.8 migration, we used our own cloudtrail worker(golang + logstash) but wanted to adopt the aws filebeat module for ECS conversion. Upon doing so I notice a significant drop in log volume(500GB -\> 30GB), mi…

---

## [Help, Cannot get multiline to work correctly](https://discuss.elastic.co/t/help-cannot-get-multiline-to-work-correctly/244161)

<div class="topic-metadata">

**Author:** [@calanon](https://discuss.elastic.co/u/calanon)\
**Replies:** 5\
**Last updated:** [August 11, 2020, 7:36am UTC](https://discuss.elastic.co/t/help-cannot-get-multiline-to-work-correctly/244161 "2020-08-11T07:36:20Z")

</div>

I have this raw log output: \[2020-08-07T12:45:33+02:00\] 10.8.0.84 ERROR Exception: \<log:context\>{"exception":"\[object\] (UnexpectedValueException(code: 0): This is to simulate uncaught exceptions at /home/app1/products/s…

---

## [Beats Multiline Pattern Error](https://discuss.elastic.co/t/beats-multiline-pattern-error/244458)

<div class="topic-metadata">

**Author:** [@ben\_men](https://discuss.elastic.co/u/ben_men)\
**Replies:** 4\
**Last updated:** [August 11, 2020, 1:59am UTC](https://discuss.elastic.co/t/beats-multiline-pattern-error/244458 "2020-08-11T01:59:05Z")

</div>

I am trying to ingest multiline log event with filebeat and using Multiline Pattern but it is not working out as expected. Here is one of the multiline event I have: 03 Aug 2020 02:39:53,456 DEBUG \[sometext\] \[sometext\]…

---

## [Failed to create the stack. AWS Lambda Stack event CREATE\_FAILED, ResourceStatusReason: The specified log group does not exist](https://discuss.elastic.co/t/failed-to-create-the-stack-aws-lambda-stack-event-create-failed-resourcestatusreason-the-specified-log-group-does-not-exist/244115)

<div class="topic-metadata">

**Author:** [@JamaesTiger](https://discuss.elastic.co/u/JamaesTiger)\
**Replies:** 2\
**Last updated:** [August 11, 2020, 12:36am UTC](https://discuss.elastic.co/t/failed-to-create-the-stack-aws-lambda-stack-event-create-failed-resourcestatusreason-the-specified-log-group-does-not-exist/244115 "2020-08-11T00:36:20Z")

</div>

I have tested how to use functionbeat for AWS cloudwatch via lambda function. But when i deploy funtionbeat, stack creating is failed after the following error generating. # ./functionbeat -v -e -d "\*" deploy cloudwatc…

---

## [Filebeat version 6.4.0 unable to send logs to Kafka directly . Filebeat not starting](https://discuss.elastic.co/t/filebeat-version-6-4-0-unable-to-send-logs-to-kafka-directly-filebeat-not-starting/244350)

<div class="topic-metadata">

**Author:** [@Dibyendu\_Dutta](https://discuss.elastic.co/u/Dibyendu_Dutta)\
**Replies:** 8\
**Last updated:** [August 10, 2020, 9:09pm UTC](https://discuss.elastic.co/t/filebeat-version-6-4-0-unable-to-send-logs-to-kafka-directly-filebeat-not-starting/244350 "2020-08-10T21:09:30Z")

</div>

I want to send filebeat (logs) data to kafka directly. I have commented logstash/elasticsearch output and set the kafka output like below. But after that my filebeat instance is not starting . Getting error message Fail…

---

## [Auditbeat Not Sending -k tags](https://discuss.elastic.co/t/auditbeat-not-sending-k-tags/244439)

<div class="topic-metadata">

**Author:** [@MikeHarness](https://discuss.elastic.co/u/MikeHarness)\
**Replies:** 1\
**Last updated:** [August 10, 2020, 7:22pm UTC](https://discuss.elastic.co/t/auditbeat-not-sending-k-tags/244439 "2020-08-10T19:22:39Z")

</div>

I've just set up auditbeat on a RHEL8 box to log various commands. In the 'audit.rules.d' directory I've added a new file with entries such as: -a always,exit -F path=/usr/bin/wget -F perm=x -k external\_call Running a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=220)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=222)
