# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=223

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 224

---

## [Exiting: missing field accessing 'output.elasticsearch.index' (source:'command line flag')](https://discuss.elastic.co/t/exiting-missing-field-accessing-output-elasticsearch-index-source-command-line-flag/243791)

<div class="topic-metadata">

**Author:** [@luado](https://discuss.elastic.co/u/luado)\
**Replies:** 1\
**Last updated:** [August 5, 2020, 6:59pm UTC](https://discuss.elastic.co/t/exiting-missing-field-accessing-output-elasticsearch-index-source-command-line-flag/243791 "2020-08-05T18:59:39Z")

</div>

I have made a custom beat. It runs fine. When I run it from inside a docker container it complains that I'm trying to change the index. My Dockerfile goes like this: FROM ubuntu MAINTAINER Luis Eduardo Pessoa ARG …

---

## [Unable to point metricbeat to monitor elasticsearch instance running on custom port](https://discuss.elastic.co/t/unable-to-point-metricbeat-to-monitor-elasticsearch-instance-running-on-custom-port/243908)

<div class="topic-metadata">

**Author:** [@Vijay\_Gharge](https://discuss.elastic.co/u/Vijay_Gharge)\
**Replies:** 1\
**Last updated:** [August 5, 2020, 6:08pm UTC](https://discuss.elastic.co/t/unable-to-point-metricbeat-to-monitor-elasticsearch-instance-running-on-custom-port/243908 "2020-08-05T18:08:54Z")

</div>

Hi, I am trying to configure metricbeat-oss to monitor ES-OSS instance hosted on custom port i.e. 7077 (which is further forwarded to 9200 in docker instance configured on localhost). However I am unable to monitor as e…

---

## [Filebeat doesn't accept logs with container name](https://discuss.elastic.co/t/filebeat-doesnt-accept-logs-with-container-name/243723)

<div class="topic-metadata">

**Author:** [@mohanr](https://discuss.elastic.co/u/mohanr)\
**Replies:** 3\
**Last updated:** [August 5, 2020, 5:44pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-accept-logs-with-container-name/243723 "2020-08-05T17:44:07Z")

</div>

Hi, We are using Docker to deploy microservice. Every time when we run a new container. Its id will be changed. Default logs path looks like /var/lib/docker/containers/\<container-id\>/\<container-id\>-json.log. We are usin…

---

## [Is there a cross reference available to map file names to modules you should use to process them](https://discuss.elastic.co/t/is-there-a-cross-reference-available-to-map-file-names-to-modules-you-should-use-to-process-them/243907)

<div class="topic-metadata">

**Author:** [@srpine](https://discuss.elastic.co/u/srpine)\
**Replies:** 0\
**Last updated:** [August 5, 2020, 4:55pm UTC](https://discuss.elastic.co/t/is-there-a-cross-reference-available-to-map-file-names-to-modules-you-should-use-to-process-them/243907 "2020-08-05T16:55:47Z")

</div>

I keep struggling trying to work out what modules I need to use for some of the more common log files found in linux. Example: I have yum.log what module should I use to map this to (in short set var.paths for that modu…

---

## [Illegal\_argument\_exception when metricbeat begins new index](https://discuss.elastic.co/t/illegal-argument-exception-when-metricbeat-begins-new-index/243269)

<div class="topic-metadata">

**Author:** [@HeroCC](https://discuss.elastic.co/u/HeroCC)\
**Replies:** 2\
**Last updated:** [August 5, 2020, 2:57pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-when-metricbeat-begins-new-index/243269 "2020-08-05T14:57:28Z")

</div>

Hello! I had a metricbeat instance running 7.8.0, and when I first wired it up to logstash, then to elasticsearch, it generated an index, but whenever I tried to use it things like the Dashboards would not work, citing a…

---

## [How to run metricbeat as background process](https://discuss.elastic.co/t/how-to-run-metricbeat-as-background-process/243865)

<div class="topic-metadata">

**Author:** [@Mahebub\_Sayyed](https://discuss.elastic.co/u/Mahebub_Sayyed)\
**Replies:** 7\
**Last updated:** [August 5, 2020, 2:26pm UTC](https://discuss.elastic.co/t/how-to-run-metricbeat-as-background-process/243865 "2020-08-05T14:26:44Z")

</div>

I want to install metricbeat to monitor server metrics. I dont have internet connection on server so I have manually downloaded "metricbeat-oss-7.3.2-linux-x86\_64.tar.gz" and running it through "./metricbeat -e" when I a…

---

## [I need help! Auditbeat \`file.path\` field does not contain the absolute path](https://discuss.elastic.co/t/i-need-help-auditbeat-file-path-field-does-not-contain-the-absolute-path/243045)

<div class="topic-metadata">

**Author:** [@Simon\_Moller](https://discuss.elastic.co/u/Simon_Moller)\
**Replies:** 8\
**Last updated:** [August 5, 2020, 1:34pm UTC](https://discuss.elastic.co/t/i-need-help-auditbeat-file-path-field-does-not-contain-the-absolute-path/243045 "2020-08-05T13:34:44Z")

</div>

Hi, I am having problems with how auditbeat pushes documents to elasticsearch. I want auditbeat to monitor openat system calls on a directory (or, alternatively on the files within that directory). To that end I have the…

---

## [Filebeat custom patterns](https://discuss.elastic.co/t/filebeat-custom-patterns/243662)

<div class="topic-metadata">

**Author:** [@vladtepes](https://discuss.elastic.co/u/vladtepes)\
**Replies:** 1\
**Last updated:** [August 5, 2020, 1:28pm UTC](https://discuss.elastic.co/t/filebeat-custom-patterns/243662 "2020-08-05T13:28:53Z")

</div>

Greetings friends, I am trying to make this approach work in ingest pipelines, but have stumbled upon a syntax error. The grok pattern is valid from what I have tested: When I try to use it in the ingest pipeline ho…

---

## [Filebeat ingest pipeline Grok pattern](https://discuss.elastic.co/t/filebeat-ingest-pipeline-grok-pattern/243866)

<div class="topic-metadata">

**Author:** [@vladtepes](https://discuss.elastic.co/u/vladtepes)\
**Replies:** 3\
**Last updated:** [August 5, 2020, 12:51pm UTC](https://discuss.elastic.co/t/filebeat-ingest-pipeline-grok-pattern/243866 "2020-08-05T12:51:28Z")

</div>

Must be something really simple, but am struggling to make it work. :confused: The sample log line: 2020-07-29 12:17:16.948 +02:00 \[80000025-0002-ff00-b63f-84710c7967bb\] \[Some.Text.Goes.Here.Controllers.UserController\]…

---

## [Copying field values](https://discuss.elastic.co/t/copying-field-values/242520)

<div class="topic-metadata">

**Author:** [@macg](https://discuss.elastic.co/u/macg)\
**Replies:** 8\
**Last updated:** [August 5, 2020, 12:29pm UTC](https://discuss.elastic.co/t/copying-field-values/242520 "2020-08-05T12:29:53Z")

</div>

I want to copy the value of the host.hostname field to host.name or otherwise ensure that host.name takes this value. I'm collecting syslog and auth data from a number of hosts on a single machine and shipping to Elasti…

---

## [Metricbeat AWS dashboards fails on cloud.region alias](https://discuss.elastic.co/t/metricbeat-aws-dashboards-fails-on-cloud-region-alias/243841)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 0\
**Last updated:** [August 5, 2020, 9:46am UTC](https://discuss.elastic.co/t/metricbeat-aws-dashboards-fails-on-cloud-region-alias/243841 "2020-08-05T09:46:57Z")

</div>

Elasticseach 7.8.1, Kibana 7.8.1, Logstash 7.7.x, Metricbeat 7.8.1 and 7.7.1 on an AWS Kubernetes cluster. All dashboards, searches and visualizations have been updated. The metricbeat index template has also been update…

---

## [Auditbeat and reverse shells. Help required!](https://discuss.elastic.co/t/auditbeat-and-reverse-shells-help-required/243824)

<div class="topic-metadata">

**Author:** [@Simon\_Moller](https://discuss.elastic.co/u/Simon_Moller)\
**Replies:** 0\
**Last updated:** [August 5, 2020, 8:22am UTC](https://discuss.elastic.co/t/auditbeat-and-reverse-shells-help-required/243824 "2020-08-05T08:22:52Z")

</div>

I am having troubles working with Auditbeat under certain conditions. My team is using Auditbeat and Elasticsearch to monitor students while they are performing a project that involves hacking networks that are set up on…

---

## [Elasticsearch + Filebeat + CrowdStrike](https://discuss.elastic.co/t/elasticsearch-filebeat-crowdstrike/243798)

<div class="topic-metadata">

**Author:** [@spinoz4](https://discuss.elastic.co/u/spinoz4)\
**Replies:** 0\
**Last updated:** [August 5, 2020, 1:06am UTC](https://discuss.elastic.co/t/elasticsearch-filebeat-crowdstrike/243798 "2020-08-05T01:06:20Z")

</div>

Hi folks. I did install the following scenario: Elasticsearh + Kibana + Filebeat + Crowdstrike Falcon's SIEM conector + Single CID it work flawless however in the multiple CIDs scenario, which involves multiple log fi…

---

## [Filebeat processing with external Javascript modules](https://discuss.elastic.co/t/filebeat-processing-with-external-javascript-modules/243775)

<div class="topic-metadata">

**Author:** [@Clippy](https://discuss.elastic.co/u/Clippy)\
**Replies:** 0\
**Last updated:** [August 4, 2020, 7:22pm UTC](https://discuss.elastic.co/t/filebeat-processing-with-external-javascript-modules/243775 "2020-08-04T19:22:21Z")

</div>

Does anybody know if it is possible to run a Filebeat processor using external modules. The logs are telling me that it isn't allowed natively but I would love to be able to use the File System (fs) module with my proces…

---

## [What version of gosigar does Metricbeat 6.4.3 pull in?](https://discuss.elastic.co/t/what-version-of-gosigar-does-metricbeat-6-4-3-pull-in/243757)

<div class="topic-metadata">

**Author:** [@mehagar](https://discuss.elastic.co/u/mehagar)\
**Replies:** 0\
**Last updated:** [August 4, 2020, 5:31pm UTC](https://discuss.elastic.co/t/what-version-of-gosigar-does-metricbeat-6-4-3-pull-in/243757 "2020-08-04T17:31:58Z")

</div>

I'm trying to figure out if this PR: https://github.com/elastic/gosigar/pull/71/files Has been incorporated into the 6.4.3 release of Metricbeat, which is what we are using. This might help explain the discrepancy betwe…

---

## [Filebeat O365 Module, API proxy support](https://discuss.elastic.co/t/filebeat-o365-module-api-proxy-support/242368)

<div class="topic-metadata">

**Author:** [@robertnixon](https://discuss.elastic.co/u/robertnixon)\
**Replies:** 1\
**Last updated:** [August 4, 2020, 3:10pm UTC](https://discuss.elastic.co/t/filebeat-o365-module-api-proxy-support/242368 "2020-08-04T15:10:49Z")

</div>

Is there a way to tell Filebeat to use a proxy when attempting to connect to the Microsoft API when pulling down O365 Audit logs? Here are some errors. Jul 23 14:45:57 \<redacted\> filebeat\[22797\]: 2020-07-23T14:45:57.12…

---

## [2 instance filebeat reading the same file](https://discuss.elastic.co/t/2-instance-filebeat-reading-the-same-file/243704)

<div class="topic-metadata">

**Author:** [@zeO](https://discuss.elastic.co/u/zeO)\
**Replies:** 3\
**Last updated:** [August 4, 2020, 3:07pm UTC](https://discuss.elastic.co/t/2-instance-filebeat-reading-the-same-file/243704 "2020-08-04T15:07:42Z")

</div>

Hi, I am using Elastic Kibana and filebeat to read and monitor my docker container (docker stack) logs. for compagnie policy reason I need to send the logs at 2 elasticsearch locations (the project instance and the compa…

---

## [Auditbeat module system dataset login: error reading wtmp](https://discuss.elastic.co/t/auditbeat-module-system-dataset-login-error-reading-wtmp/243732)

<div class="topic-metadata">

**Author:** [@pauleccm](https://discuss.elastic.co/u/pauleccm)\
**Replies:** 0\
**Last updated:** [August 4, 2020, 2:40pm UTC](https://discuss.elastic.co/t/auditbeat-module-system-dataset-login-error-reading-wtmp/243732 "2020-08-04T14:40:25Z")

</div>

version: auditbeat version 7.8.0 (arm64), libbeat 7.8.0 \[f79387d32717d79f689d94fda1ec80b2cf285d30 built 2020-06-14 18:12:56 +0000 UTC\] Debian 10 Aug 04 16:37:51 scw-optimistic-austin auditbeat\[11004\]: 2020-08-04T16:37…

---

## [Azure.resource.name field is missing in Metricbeat 7.7](https://discuss.elastic.co/t/azure-resource-name-field-is-missing-in-metricbeat-7-7/243696)

<div class="topic-metadata">

**Author:** [@Abir\_Mahfoudhi](https://discuss.elastic.co/u/Abir_Mahfoudhi)\
**Replies:** 2\
**Last updated:** [August 4, 2020, 2:17pm UTC](https://discuss.elastic.co/t/azure-resource-name-field-is-missing-in-metricbeat-7-7/243696 "2020-08-04T14:17:56Z")

</div>

We are using metricbeat 7.7 to fetch data from azure using azure module and we use the data to build some monitoring dashboards . Everything was working fine until we discovered a missing field in metricbeat which is azu…

---

## [Cluster\_stats not sent to monitoring cluster](https://discuss.elastic.co/t/cluster-stats-not-sent-to-monitoring-cluster/243402)

<div class="topic-metadata">

**Author:** [@souravsahoo](https://discuss.elastic.co/u/souravsahoo)\
**Replies:** 1\
**Last updated:** [August 4, 2020, 1:42pm UTC](https://discuss.elastic.co/t/cluster-stats-not-sent-to-monitoring-cluster/243402 "2020-08-04T13:42:08Z")

</div>

Hi all, I am facing an issue, where the production cluster/sending cluster is sending the monitoring data to the monitoring cluster. However, I am not able to view it on the stack monitoring page. On further analysis, I…

---

## [Filebeat output setting on modules](https://discuss.elastic.co/t/filebeat-output-setting-on-modules/243669)

<div class="topic-metadata">

**Author:** [@esseti](https://discuss.elastic.co/u/esseti)\
**Replies:** 1\
**Last updated:** [August 4, 2020, 11:33am UTC](https://discuss.elastic.co/t/filebeat-output-setting-on-modules/243669 "2020-08-04T11:33:24Z")

</div>

Hello all, I've two system one ELK for monitoring (Monitoring) and an ELK for auditing (Auditing) On a machine, i've setup filebeat to send the output to Monitoring. that's fine. Now,I 've to setup a filebaeat conf th…

---

## [How to restrict nodes while indexing to elastic search](https://discuss.elastic.co/t/how-to-restrict-nodes-while-indexing-to-elastic-search/243695)

<div class="topic-metadata">

**Author:** [@Rakesh\_Katakam](https://discuss.elastic.co/u/Rakesh_Katakam)\
**Replies:** 0\
**Last updated:** [August 4, 2020, 11:21am UTC](https://discuss.elastic.co/t/how-to-restrict-nodes-while-indexing-to-elastic-search/243695 "2020-08-04T11:21:34Z")

</div>

Hi, I am trying to index application logs to elastic search using file beats. Here I observed in elastic search, it created for each document hosts,agent..etc nodes, but I am interested only in message field Node. s…

---

## [Metricbeat 7.8 IIS Module Malformed Events Emitted from application\_pool metricset](https://discuss.elastic.co/t/metricbeat-7-8-iis-module-malformed-events-emitted-from-application-pool-metricset/241538)

<div class="topic-metadata">

**Author:** [@william.shipman](https://discuss.elastic.co/u/william.shipman)\
**Replies:** 2\
**Last updated:** [August 4, 2020, 11:18am UTC](https://discuss.elastic.co/t/metricbeat-7-8-iis-module-malformed-events-emitted-from-application-pool-metricset/241538 "2020-08-04T11:18:59Z")

</div>

Good afternoon, I'm currently seeing lots of missing data from the IIS module, specifically the application\_pool metricset: I believe there are a couple of different things going on here, including the same errors me…

---

## [Beats environment variable not working](https://discuss.elastic.co/t/beats-environment-variable-not-working/243660)

<div class="topic-metadata">

**Author:** [@mozam](https://discuss.elastic.co/u/mozam)\
**Replies:** 1\
**Last updated:** [August 4, 2020, 10:49am UTC](https://discuss.elastic.co/t/beats-environment-variable-not-working/243660 "2020-08-04T10:49:11Z")

</div>

Hello, I'm using Auditbeat 7.8.0, trying to pass value to configuration using environment variables under the processors - add\_host\_metadata. I have exported the variable in my shell using the command export CITY\_NAME=…

---

## [Auditbeat not getting the host's public address](https://discuss.elastic.co/t/auditbeat-not-getting-the-hosts-public-address/243200)

<div class="topic-metadata">

**Author:** [@curiousmind](https://discuss.elastic.co/u/curiousmind)\
**Replies:** 3\
**Last updated:** [August 4, 2020, 9:44am UTC](https://discuss.elastic.co/t/auditbeat-not-getting-the-hosts-public-address/243200 "2020-08-04T09:44:37Z")

</div>

Beats and Elasticsearch Version 7.8.0 We have 50+ sources in which auditbeat version 7.8.0 is installed. The OS used is predominantly Windows in all these sources. These 50+ sources are sending the logs directly to a 2…

---

## [Why filebeat collected multi pod log to single row？](https://discuss.elastic.co/t/why-filebeat-collected-multi-pod-log-to-single-row/243641)

<div class="topic-metadata">

**Author:** [@lklkxcxc](https://discuss.elastic.co/u/lklkxcxc)\
**Replies:** 0\
**Last updated:** [August 4, 2020, 3:09am UTC](https://discuss.elastic.co/t/why-filebeat-collected-multi-pod-log-to-single-row/243641 "2020-08-04T03:09:00Z")

</div>

There are three containers in single row ，please check ” kubernetes.container.name “

---

## [Heartbeat log file is not created](https://discuss.elastic.co/t/heartbeat-log-file-is-not-created/243310)

<div class="topic-metadata">

**Author:** [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Replies:** 5\
**Last updated:** [August 4, 2020, 12:04am UTC](https://discuss.elastic.co/t/heartbeat-log-file-is-not-created/243310 "2020-08-04T00:04:41Z")

</div>

Very basic, but... The log file is not created. Any ideas? logging.level: debug logging.to\_files: true logging.files: path: /var/log/heartbeat name: heartbeat.log keepfiles: 3 permissions: 0644 Copied from - h…

---

## [Check Point Filebeat module clarification](https://discuss.elastic.co/t/check-point-filebeat-module-clarification/243360)

<div class="topic-metadata">

**Author:** [@jasonwomack](https://discuss.elastic.co/u/jasonwomack)\
**Replies:** 0\
**Last updated:** [July 31, 2020, 1:52pm UTC](https://discuss.elastic.co/t/check-point-filebeat-module-clarification/243360 "2020-07-31T13:52:51Z")

</div>

I’m hoping someone can clarify how Filebeat is supposed to be setup when being used to process logs from a Check Point firewall (as covered here: https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-chec…

---

## [Secure auditbeat output](https://discuss.elastic.co/t/secure-auditbeat-output/243448)

<div class="topic-metadata">

**Author:** [@elk6](https://discuss.elastic.co/u/elk6)\
**Replies:** 1\
**Last updated:** [August 3, 2020, 10:22pm UTC](https://discuss.elastic.co/t/secure-auditbeat-output/243448 "2020-08-03T22:22:46Z")

</div>

I have logstash listening for encrypted data. If I set auditbeat output to logstash with ssl, I won't find the data later in elasticsearch. If I set auditbeat output to elasticsearch, I can't get it to encrypt data. Thi…

---

## [Exabeam integration with winlogbeat](https://discuss.elastic.co/t/exabeam-integration-with-winlogbeat/243395)

<div class="topic-metadata">

**Author:** [@elastic.newb](https://discuss.elastic.co/u/elastic.newb)\
**Replies:** 1\
**Last updated:** [August 3, 2020, 10:20pm UTC](https://discuss.elastic.co/t/exabeam-integration-with-winlogbeat/243395 "2020-08-03T22:20:37Z")

</div>

I am realatively new to the elastic environment and I am hoping that someone might be able to point me to a walkthrough or steps on collecting events for windows and sending them to exabeam. Thanks!

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=222)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=224)
