# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=222

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 223

---

## [Decode\_json\_fields with message field](https://discuss.elastic.co/t/decode-json-fields-with-message-field/243943)

<div class="topic-metadata">

**Author:** [@cnb3](https://discuss.elastic.co/u/cnb3)\
**Replies:** 2\
**Last updated:** [August 10, 2020, 6:13pm UTC](https://discuss.elastic.co/t/decode-json-fields-with-message-field/243943 "2020-08-10T18:13:46Z")

</div>

I am running into a problem of trying to process decode\_json\_fields on the message field out of a cloudwatch event. I have this field populated with a json string generated in a lambda function using JSON.stringify(obj) …

---

## [Filebeat queue.mem vs Filebeat Netflow module queue\_size](https://discuss.elastic.co/t/filebeat-queue-mem-vs-filebeat-netflow-module-queue-size/244403)

<div class="topic-metadata">

**Author:** [@tlazarus](https://discuss.elastic.co/u/tlazarus)\
**Replies:** 2\
**Last updated:** [August 10, 2020, 3:32pm UTC](https://discuss.elastic.co/t/filebeat-queue-mem-vs-filebeat-netflow-module-queue-size/244403 "2020-08-10T15:32:28Z")

</div>

When using the Filebeat Netflow Module, there are 2 queue options - one in the primary yaml file (queue.mem) and another in the module yaml (queue\_size). What is the difference between the 2 options? I would assume that …

---

## [AIX "beat like" daemon, written in Python3](https://discuss.elastic.co/t/aix-beat-like-daemon-written-in-python3/244070)

<div class="topic-metadata">

**Author:** [@bhm-ibm](https://discuss.elastic.co/u/bhm-ibm)\
**Replies:** 3\
**Last updated:** [August 10, 2020, 3:37pm UTC](https://discuss.elastic.co/t/aix-beat-like-daemon-written-in-python3/244070 "2020-08-10T15:37:32Z")

</div>

Hello All, I've been ask to write an ELK Metricbeat/Filebeat daemon for AIX , like it is currently existing for Linux and Windows. It is called "Metraixbeat" and I wanted to share it with others ! I created also dozen …

---

## [Getting 401 Unauthorized with Elasticsearch module](https://discuss.elastic.co/t/getting-401-unauthorized-with-elasticsearch-module/243737)

<div class="topic-metadata">

**Author:** [@scriptdb](https://discuss.elastic.co/u/scriptdb)\
**Replies:** 2\
**Last updated:** [August 10, 2020, 3:31pm UTC](https://discuss.elastic.co/t/getting-401-unauthorized-with-elasticsearch-module/243737 "2020-08-10T15:31:25Z")

</div>

Hi, I'm using metricbeat 7.6.2 and trying to get elasticsearch metrics (with module). - module: elasticsearch metricsets: - node period: 10s enabled: true hosts: \["http://internal:8081"\] basepath: "/es/" …

---

## [Zeek Filebeat Module - index is not populated](https://discuss.elastic.co/t/zeek-filebeat-module-index-is-not-populated/244430)

<div class="topic-metadata">

**Author:** [@ommneom](https://discuss.elastic.co/u/ommneom)\
**Replies:** 0\
**Last updated:** [August 10, 2020, 3:20pm UTC](https://discuss.elastic.co/t/zeek-filebeat-module-index-is-not-populated/244430 "2020-08-10T15:20:29Z")

</div>

Hello, I'm having trouble with what seems like a standard scenario and I can't figure out what I'm doing wrong. The setup : I installed Elasticsearch and Kibana (version 7.8.1 for both) on the same server. I kept the c…

---

## [7.4.2 exclude\_files not workinig](https://discuss.elastic.co/t/7-4-2-exclude-files-not-workinig/244416)

<div class="topic-metadata">

**Author:** [@alces](https://discuss.elastic.co/u/alces)\
**Replies:** 1\
**Last updated:** [August 10, 2020, 2:59pm UTC](https://discuss.elastic.co/t/7-4-2-exclude-files-not-workinig/244416 "2020-08-10T14:59:54Z")

</div>

Hello, I'm running elk and beats at 7.4.2 and I'm having trouble with the "exclude\_files" config: Following are extractions of my filebeat.yml and my system.yml: filebeat.yml: filebeat.inputs: - type: log enabled: …

---

## [Multiline issue with filebeat](https://discuss.elastic.co/t/multiline-issue-with-filebeat/242234)

<div class="topic-metadata">

**Author:** [@bryand](https://discuss.elastic.co/u/bryand)\
**Replies:** 6\
**Last updated:** [August 10, 2020, 12:29pm UTC](https://discuss.elastic.co/t/multiline-issue-with-filebeat/242234 "2020-08-10T12:29:42Z")

</div>

Hi, I'm having issues with trying to aggregate java exceptions into a single message using the filebeat multiline support. From everything I've read this should be very simple, yet, no matter what I try, it doesn't wor…

---

## [Miss the field winlog.keywords in ForwardedEvents event\_logs](https://discuss.elastic.co/t/miss-the-field-winlog-keywords-in-forwardedevents-event-logs/244373)

<div class="topic-metadata">

**Author:** [@Lehugo](https://discuss.elastic.co/u/Lehugo)\
**Replies:** 1\
**Last updated:** [August 10, 2020, 10:11am UTC](https://discuss.elastic.co/t/miss-the-field-winlog-keywords-in-forwardedevents-event-logs/244373 "2020-08-10T10:11:04Z")

</div>

all the security Events have the the field winlog.keywords but ForwardedEvents don't Forward it. How can i configure the winlogbeat.yml file that the ForwardedEvents fordward the field winlog.keywords ? https://www.ela…

---

## [Add User Beats not Create index](https://discuss.elastic.co/t/add-user-beats-not-create-index/244363)

<div class="topic-metadata">

**Author:** [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Replies:** 0\
**Last updated:** [August 10, 2020, 8:13am UTC](https://discuss.elastic.co/t/add-user-beats-not-create-index/244363 "2020-08-10T08:13:49Z")

</div>

hi, i try add user beats with privilage setup and create index but the moment, I privilege winlogbeat indices - \* it can't create indices but if I use indices the user beats can create indices winlogbeat-\* \[\*\] …

---

## [Delete raw text files once file beat forwarded to ELK](https://discuss.elastic.co/t/delete-raw-text-files-once-file-beat-forwarded-to-elk/244332)

<div class="topic-metadata">

**Author:** [@Puneeth\_S\_B\_Gowda1](https://discuss.elastic.co/u/Puneeth_S_B_Gowda1)\
**Replies:** 1\
**Last updated:** [August 10, 2020, 4:17am UTC](https://discuss.elastic.co/t/delete-raw-text-files-once-file-beat-forwarded-to-elk/244332 "2020-08-10T04:17:09Z")

</div>

Yes it's outside file beat function but is there any way or tool to delete these files from window OS server once file beat forward to Elastic search as we don't need these physical files anymore as we have these logs in…

---

## [Access to latest version as a DEB](https://discuss.elastic.co/t/access-to-latest-version-as-a-deb/244168)

<div class="topic-metadata">

**Author:** [@cuttlefishjones](https://discuss.elastic.co/u/cuttlefishjones)\
**Replies:** 1\
**Last updated:** [August 9, 2020, 10:56pm UTC](https://discuss.elastic.co/t/access-to-latest-version-as-a-deb/244168 "2020-08-09T22:56:36Z")

</div>

Hi, is there anywhere I can get access to the latest version of Filebeat as a DEB file. We don't have access to a toolchain on the machines we are working with to compile our own from source.

---

## [Unable to get Suricata dashboards](https://discuss.elastic.co/t/unable-to-get-suricata-dashboards/244326)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 0\
**Last updated:** [August 9, 2020, 10:11pm UTC](https://discuss.elastic.co/t/unable-to-get-suricata-dashboards/244326 "2020-08-09T22:11:21Z")

</div>

Hi there guys. Im new to Elastic and im getting a problem. I have an ELK and suricata on the same machine. I use filebeats to collect the suricata logs directly to elastic. In kibana i can see all the logs in the discove…

---

## [Enable modules.d/suricata.yml module](https://discuss.elastic.co/t/enable-modules-d-suricata-yml-module/244114)

<div class="topic-metadata">

**Author:** [@bn1980](https://discuss.elastic.co/u/bn1980)\
**Replies:** 3\
**Last updated:** [August 9, 2020, 6:10am UTC](https://discuss.elastic.co/t/enable-modules-d-suricata-yml-module/244114 "2020-08-09T06:10:18Z")

</div>

I don't appear to have the suricata.yml module. Am i missing something? Installed ELK on a freebsd11.2 machine.

---

## [Kibana Dashboards not getting loaded using setup.dashboards.file option](https://discuss.elastic.co/t/kibana-dashboards-not-getting-loaded-using-setup-dashboards-file-option/244210)

<div class="topic-metadata">

**Author:** [@Rakesh\_Katakam](https://discuss.elastic.co/u/Rakesh_Katakam)\
**Replies:** 1\
**Last updated:** [August 7, 2020, 6:33pm UTC](https://discuss.elastic.co/t/kibana-dashboards-not-getting-loaded-using-setup-dashboards-file-option/244210 "2020-08-07T18:33:37Z")

</div>

Hi , Instead of loading all dashboards to Kibana, I want to load only kafka specific dashboards . so I zipped below two json file and placed on my local drive. Metricbeat-kafka-overview.json Metricbeat-zookeeper-over…

---

## [Seeing both 7.7 and 7.8 indices for all beats](https://discuss.elastic.co/t/seeing-both-7-7-and-7-8-indices-for-all-beats/243906)

<div class="topic-metadata">

**Author:** [@srpine](https://discuss.elastic.co/u/srpine)\
**Replies:** 2\
**Last updated:** [August 7, 2020, 5:27pm UTC](https://discuss.elastic.co/t/seeing-both-7-7-and-7-8-indices-for-all-beats/243906 "2020-08-07T17:27:08Z")

</div>

I recently upgraded to 7.8 and after that it started creating 7.8.0 indices and I thought that it would close out the existing 7.7.0 indices at some point but here I am days later and indices for 7.7.0 and 7.8.0 are stil…

---

## [Beat processor for mapping your network](https://discuss.elastic.co/t/beat-processor-for-mapping-your-network/244208)

<div class="topic-metadata">

**Author:** [@jasonwomack](https://discuss.elastic.co/u/jasonwomack)\
**Replies:** 0\
**Last updated:** [August 7, 2020, 5:19pm UTC](https://discuss.elastic.co/t/beat-processor-for-mapping-your-network/244208 "2020-08-07T17:19:59Z")

</div>

I think I've read every geoip and map network post I can find and I have one thing I need clarified. To clarify I'm trying to configure the yml of a beat agent, not Logstash. We have right around 50 facilities with dif…

---

## [Error on filebeat to monitor systemlogs](https://discuss.elastic.co/t/error-on-filebeat-to-monitor-systemlogs/244196)

<div class="topic-metadata">

**Author:** [@javig12](https://discuss.elastic.co/u/javig12)\
**Replies:** 0\
**Last updated:** [August 7, 2020, 4:10pm UTC](https://discuss.elastic.co/t/error-on-filebeat-to-monitor-systemlogs/244196 "2020-08-07T16:10:32Z")

</div>

Hello community, Recently I've installed filebeat to monitore systemlogs on linux server, and have this error: 2020-08-07T11:57:14.546-0400 INFO instance/beat.go:280 Setup Beat: filebeat; Version: 6.8.11 2020-08-07T11…

---

## [Auditbeat IP metadata missing](https://discuss.elastic.co/t/auditbeat-ip-metadata-missing/244162)

<div class="topic-metadata">

**Author:** [@mozam](https://discuss.elastic.co/u/mozam)\
**Replies:** 0\
**Last updated:** [August 7, 2020, 11:22am UTC](https://discuss.elastic.co/t/auditbeat-ip-metadata-missing/244162 "2020-08-07T11:22:18Z")

</div>

Hello, I'm using the below pipeline to index data to Elasticsearch (Elastic 7.8.0 is used). Auditbeat -\> Logstash -\> Elasticsearch Using the below mutate filter I'm able to copy the IP address from metadata to a new f…

---

## [Metricbeat SSL to Elastic Setup](https://discuss.elastic.co/t/metricbeat-ssl-to-elastic-setup/244024)

<div class="topic-metadata">

**Author:** [@PiperMp3](https://discuss.elastic.co/u/PiperMp3)\
**Replies:** 1\
**Last updated:** [August 7, 2020, 11:15am UTC](https://discuss.elastic.co/t/metricbeat-ssl-to-elastic-setup/244024 "2020-08-07T11:15:52Z")

</div>

Hello, I'm about to lose my mind and scratch ELK all together due to this problem. Let me start with explaining the goal. There are 3 VMs. 2 are public VPS' and 1 is a local VM. All are Ubuntu 20.04. I will call th…

---

## [Help required! Auditbeat fails to push correct \`process.args\` field when using reverse shells](https://discuss.elastic.co/t/help-required-auditbeat-fails-to-push-correct-process-args-field-when-using-reverse-shells/244132)

<div class="topic-metadata">

**Author:** [@Simon\_Moller](https://discuss.elastic.co/u/Simon_Moller)\
**Replies:** 0\
**Last updated:** [August 7, 2020, 7:49am UTC](https://discuss.elastic.co/t/help-required-auditbeat-fails-to-push-correct-process-args-field-when-using-reverse-shells/244132 "2020-08-07T07:49:20Z")

</div>

Hi, I am having problems with the process.args and process.title field that Auditbeat pushes when using a reverse shell. E.g. let's say that I add the following auditd rule to the /etc/auditbeat/audit.rules.d/blueprint-e…

---

## [Send AIX logs to ELK](https://discuss.elastic.co/t/send-aix-logs-to-elk/243061)

<div class="topic-metadata">

**Author:** [@hmillares](https://discuss.elastic.co/u/hmillares)\
**Replies:** 3\
**Last updated:** [August 6, 2020, 4:42pm UTC](https://discuss.elastic.co/t/send-aix-logs-to-elk/243061 "2020-08-06T16:42:53Z")

</div>

Hi Guys, I´m using AIX machine on my environment and I want to know how is the best way to send logs to the ELK. I know that filebeat is not supported on AIX Can you help me with this problem? Thanks in advance. Rega…

---

## [Its possible activate the parser a json format for specific pod?](https://discuss.elastic.co/t/its-possible-activate-the-parser-a-json-format-for-specific-pod/243325)

<div class="topic-metadata">

**Author:** [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Replies:** 2\
**Last updated:** [August 6, 2020, 3:23pm UTC](https://discuss.elastic.co/t/its-possible-activate-the-parser-a-json-format-for-specific-pod/243325 "2020-08-06T15:23:38Z")

</div>

I'm using filebeat 7.8.0 inside my kubernetes cluster. With that configuration --- apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: logging labels: k8s-app: filebeat data: filebeat.…

---

## [Elastic agent does not send data](https://discuss.elastic.co/t/elastic-agent-does-not-send-data/239190)

<div class="topic-metadata">

**Author:** [@Pavel\_Penka](https://discuss.elastic.co/u/Pavel_Penka)\
**Replies:** 5\
**Last updated:** [August 6, 2020, 1:36pm UTC](https://discuss.elastic.co/t/elastic-agent-does-not-send-data/239190 "2020-08-06T13:36:45Z")

</div>

Hello, I am trying to use ingest management and elastic agent on Windows Server 2012 against elastic cloud instance. Unfortunately, I am ending with the error bellow and no data is sent to elastic. Can someone please h…

---

## [Metricbeat IIS Module - There is more data to return than will fit in the supplied buffer](https://discuss.elastic.co/t/metricbeat-iis-module-there-is-more-data-to-return-than-will-fit-in-the-supplied-buffer/240442)

<div class="topic-metadata">

**Author:** [@kagoadvs](https://discuss.elastic.co/u/kagoadvs)\
**Replies:** 4\
**Last updated:** [August 6, 2020, 9:52am UTC](https://discuss.elastic.co/t/metricbeat-iis-module-there-is-more-data-to-return-than-will-fit-in-the-supplied-buffer/240442 "2020-08-06T09:52:24Z")

</div>

After enabling the IIS Module in Metricbeat 7.8 (Windows Server 2019 Standard), I am continuously getting errors in the Metricbeat log file: |2020-07-08T20:35:20.831-0700|ERROR|\[website\]|application\_pool/reader.go:94|Th…

---

## [Filebeat Sincedb may not cleanup complete](https://discuss.elastic.co/t/filebeat-sincedb-may-not-cleanup-complete/243989)

<div class="topic-metadata">

**Author:** [@HuanFeng](https://discuss.elastic.co/u/HuanFeng)\
**Replies:** 0\
**Last updated:** [August 6, 2020, 9:23am UTC](https://discuss.elastic.co/t/filebeat-sincedb-may-not-cleanup-complete/243989 "2020-08-06T09:23:50Z")

</div>

Hi, everyone I'm testing filebeat for our project, and I found that the sincedb is not completly cleanup. the below step is the mock situation for our project, and the 3-4 steps is moking the filebeat was down and conf…

---

## [Debugging ingest pipelines](https://discuss.elastic.co/t/debugging-ingest-pipelines/243977)

<div class="topic-metadata">

**Author:** [@trigger-unhappy](https://discuss.elastic.co/u/trigger-unhappy)\
**Replies:** 0\
**Last updated:** [August 6, 2020, 8:16am UTC](https://discuss.elastic.co/t/debugging-ingest-pipelines/243977 "2020-08-06T08:16:38Z")

</div>

Since I'm using custom apache log format and had issues with apache module extracting the correct source ip I wrote my own ingest pipeline for apache access logs and disabled the module. That part works fine, but now I a…

---

## [Converting a multiline mysql query into a single line query](https://discuss.elastic.co/t/converting-a-multiline-mysql-query-into-a-single-line-query/243956)

<div class="topic-metadata">

**Author:** [@gonzalo2kx](https://discuss.elastic.co/u/gonzalo2kx)\
**Replies:** 1\
**Last updated:** [August 6, 2020, 5:55am UTC](https://discuss.elastic.co/t/converting-a-multiline-mysql-query-into-a-single-line-query/243956 "2020-08-06T05:55:24Z")

</div>

Good day, I am looking for a solution to trim multiple white spaces, removing new lines, and a special character "^M" (in my case) from a multiline mysql query (Not multiline mysql-slow.log) in order to get the mysql qu…

---

## [Unable to decode response from prometheus endpoint](https://discuss.elastic.co/t/unable-to-decode-response-from-prometheus-endpoint/243949)

<div class="topic-metadata">

**Author:** [@jaikunwar](https://discuss.elastic.co/u/jaikunwar)\
**Replies:** 0\
**Last updated:** [August 6, 2020, 2:50am UTC](https://discuss.elastic.co/t/unable-to-decode-response-from-prometheus-endpoint/243949 "2020-08-06T02:50:12Z")

</div>

I am using metricbeat but getting error like: Error fetching data prometheus.collector: unable to decode response from prometheus endpoint: error making http request Get http://testserver:9104/metrics: net:/http: reques…

---

## [Community Beats - Unitybeat creation of binary](https://discuss.elastic.co/t/community-beats-unitybeat-creation-of-binary/243218)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 12\
**Last updated:** [August 6, 2020, 2:11am UTC](https://discuss.elastic.co/t/community-beats-unitybeat-creation-of-binary/243218 "2020-08-06T02:11:44Z")

</div>

Testing/Running this on a Windows 10 machine so that I can install it on a Dell EMC server. I'm trying to utilize the Community Beat, Unitybeat, and I've installed Go and tested it out with the instruction from here, ht…

---

## [Using packetbeat with pf\_ring](https://discuss.elastic.co/t/using-packetbeat-with-pf-ring/243925)

<div class="topic-metadata">

**Author:** [@luciferdude](https://discuss.elastic.co/u/luciferdude)\
**Replies:** 0\
**Last updated:** [August 5, 2020, 7:58pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-pf-ring/243925 "2020-08-05T19:58:59Z")

</div>

Hello, Testing packetbeat with af\_packet and pcap. getting an error when testing with pf\_ring. I have 10 GB NIC and trying to capture DNS traffic over that nic. ERROR instance/beat.go:906 Exiting: Unknown sniffer type:…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=221)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=223)
