# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=224

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 225

---

## [Auditbeat encryption and dashboards](https://discuss.elastic.co/t/auditbeat-encryption-and-dashboards/243423)

<div class="topic-metadata">

**Author:** [@elk6](https://discuss.elastic.co/u/elk6)\
**Replies:** 0\
**Last updated:** [August 1, 2020, 12:40pm UTC](https://discuss.elastic.co/t/auditbeat-encryption-and-dashboards/243423 "2020-08-01T12:40:16Z")

</div>

I'm a little overwhelmed and I was hoping someone could help me sort things out. On each machine, I have auditbeat setup. On top of the audit logs, I also use auditbeat for the dashboards it provides in kibana (for fail…

---

## [Event ID missing - winlogbeat](https://discuss.elastic.co/t/event-id-missing-winlogbeat/243479)

<div class="topic-metadata">

**Author:** [@edvrfn](https://discuss.elastic.co/u/edvrfn)\
**Replies:** 0\
**Last updated:** [August 2, 2020, 8:21pm UTC](https://discuss.elastic.co/t/event-id-missing-winlogbeat/243479 "2020-08-02T20:21:18Z")

</div>

I am interested in event-id 3 of sysmon and and i am not getting it in elasticsearch. There are other event IDs but not this one. Blockquote Network connection detected: RuleName: - UtcTime: 2020-08-02 19:46:15.226 …

---

## [Provided Grok expressions do not match field value](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value/243607)

<div class="topic-metadata">

**Author:** [@wolf\_goe](https://discuss.elastic.co/u/wolf_goe)\
**Replies:** 0\
**Last updated:** [August 3, 2020, 5:21pm UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value/243607 "2020-08-03T17:21:41Z")

</div>

I have successfully configured filebeats to ingest iis logfiles from a clients server to my elasticsearch. I can view the entries through discovery, but every message has the following error: Provided Grok expressions d…

---

## [Migrating to ECK](https://discuss.elastic.co/t/migrating-to-eck/243591)

<div class="topic-metadata">

**Author:** [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Replies:** 0\
**Last updated:** [August 3, 2020, 2:40pm UTC](https://discuss.elastic.co/t/migrating-to-eck/243591 "2020-08-03T14:40:20Z")

</div>

Hello, I am running ELK stack on an azure kubernetes cluster. Furthermore, I have filebeat and metricbeat running as daemonsets as well. Now, we are trying to deploy ECK (and get rid of the old ES cluster) and I am loo…

---

## [Filebeat not sending metadata pipeline to logstash for pipeline ingestion](https://discuss.elastic.co/t/filebeat-not-sending-metadata-pipeline-to-logstash-for-pipeline-ingestion/243588)

<div class="topic-metadata">

**Author:** [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Replies:** 0\
**Last updated:** [August 3, 2020, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-metadata-pipeline-to-logstash-for-pipeline-ingestion/243588 "2020-08-03T14:23:24Z")

</div>

Need help. We configured the filebeat apache module and send the data to logstash, then to elasticsearch for pipeline ingestion. It works fine in access logs. But not in the error logs. How could that be? btw ingest pi…

---

## [Windows integration does not add any integration settings in agent configuration](https://discuss.elastic.co/t/windows-integration-does-not-add-any-integration-settings-in-agent-configuration/243465)

<div class="topic-metadata">

**Author:** [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Replies:** 2\
**Last updated:** [August 3, 2020, 11:33am UTC](https://discuss.elastic.co/t/windows-integration-does-not-add-any-integration-settings-in-agent-configuration/243465 "2020-08-03T11:33:39Z")

</div>

Trying out Elastic Agent 7.9.0-SNAPSHOT on Windows. Added windows integration together with system to a new agent configuration. However, there is no configuration related to windows integration can be seen in the agent …

---

## [Filebeat struggles](https://discuss.elastic.co/t/filebeat-struggles/243523)

<div class="topic-metadata">

**Author:** [@vladtepes](https://discuss.elastic.co/u/vladtepes)\
**Replies:** 5\
**Last updated:** [August 3, 2020, 12:24pm UTC](https://discuss.elastic.co/t/filebeat-struggles/243523 "2020-08-03T12:24:04Z")

</div>

I must say, that I am confident it is something simple, but am struggling to make the iis module work in filebeat. :confused: After you enable the iis module and set a custom path, it is throwing an error that Blockqu…

---

## [Filebeat configmap change reload](https://discuss.elastic.co/t/filebeat-configmap-change-reload/243548)

<div class="topic-metadata">

**Author:** [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Replies:** 0\
**Last updated:** [August 3, 2020, 11:46am UTC](https://discuss.elastic.co/t/filebeat-configmap-change-reload/243548 "2020-08-03T11:46:53Z")

</div>

Hi guys, I would be interesting in how you perform an update on filebeat. From what I have seen the live config reloading is not supported for the filebeat.yml. This means currently that after every change to that fil…

---

## [Filebeat does not create index template](https://discuss.elastic.co/t/filebeat-does-not-create-index-template/243083)

<div class="topic-metadata">

**Author:** [@snolfi](https://discuss.elastic.co/u/snolfi)\
**Replies:** 10\
**Last updated:** [August 3, 2020, 10:36am UTC](https://discuss.elastic.co/t/filebeat-does-not-create-index-template/243083 "2020-08-03T10:36:39Z")

</div>

Hello, as said in the object, i'm using filebeat but for some reason its index template wasn't created on ES, the strange thing is that with the same configuration metricbeat's template was created. I report settings…

---

## [Filebeat error](https://discuss.elastic.co/t/filebeat-error/243385)

<div class="topic-metadata">

**Author:** [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Replies:** 3\
**Last updated:** [August 3, 2020, 6:42am UTC](https://discuss.elastic.co/t/filebeat-error/243385 "2020-08-03T06:42:44Z")

</div>

I am using nginx as a frontend for Kibana. I am trying to load the logs onto kibana using a Filebeat module. This is how Kibana portion of filebeat.yml file looks like # =================================== Kibana =====…

---

## [The node name cannot be resolved using fieldPath: spec.nodeName, is there any solution?](https://discuss.elastic.co/t/the-node-name-cannot-be-resolved-using-fieldpath-spec-nodename-is-there-any-solution/243489)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 0\
**Last updated:** [August 3, 2020, 2:21am UTC](https://discuss.elastic.co/t/the-node-name-cannot-be-resolved-using-fieldpath-spec-nodename-is-there-any-solution/243489 "2020-08-03T02:21:59Z")

</div>

metricbeat should be able to obtain kube-status-metric information, but cannot connect to metric-server (DNS lookup failure "k8s-dev-node02.lonsid.cn": lookup k8s-dev-node02.lonsid.cn: no such host ), I see most people u…

---

## [Auditbeat consuming almost 90% cpu some times](https://discuss.elastic.co/t/auditbeat-consuming-almost-90-cpu-some-times/242872)

<div class="topic-metadata">

**Author:** [@Khasim\_Soudagar](https://discuss.elastic.co/u/Khasim_Soudagar)\
**Replies:** 2\
**Last updated:** [August 3, 2020, 12:15am UTC](https://discuss.elastic.co/t/auditbeat-consuming-almost-90-cpu-some-times/242872 "2020-08-03T00:15:52Z")

</div>

HI i'm using auditbeat:7.7.1-OSS as part of SIEM, following is the configuration we are following. \`audit\_rules: | -a always,exit -F arch=b64 -S execve,execveat -k exec -a always,exit -F arch=b64 -S accept,bind,conne…

---

## [Can't retrieve Nginx logs with Elastic Stask on ECK](https://discuss.elastic.co/t/cant-retrieve-nginx-logs-with-elastic-stask-on-eck/242921)

<div class="topic-metadata">

**Author:** [@LomigFR](https://discuss.elastic.co/u/LomigFR)\
**Replies:** 5\
**Last updated:** [August 2, 2020, 4:08pm UTC](https://discuss.elastic.co/t/cant-retrieve-nginx-logs-with-elastic-stask-on-eck/242921 "2020-08-02T16:08:53Z")

</div>

Hello, As a test, I want to retrieve access.log and error.log from a Nginx server with : Filebeat ==\> Logstash ==\> Elasticsearch ==\> Kibana Here's the situation: Windows 10 PRO with WSL1/Ubuntu18.04/Terminator and …

---

## [Help with 'dissect\_parsing\_error' on 'log file path'](https://discuss.elastic.co/t/help-with-dissect-parsing-error-on-log-file-path/243451)

<div class="topic-metadata">

**Author:** [@Yirmio](https://discuss.elastic.co/u/Yirmio)\
**Replies:** 1\
**Last updated:** [August 2, 2020, 2:21pm UTC](https://discuss.elastic.co/t/help-with-dissect-parsing-error-on-log-file-path/243451 "2020-08-02T14:21:17Z")

</div>

Hi I'm collecting logs from a central location, where each machine keep the log in separate folder, each folder name represents the machine name. In Filebeat, I want to put the folder name as field 'HOSTNAME', below i…

---

## [How to monitor docker swarm status with beats](https://discuss.elastic.co/t/how-to-monitor-docker-swarm-status-with-beats/243394)

<div class="topic-metadata">

**Author:** [@jlvrhee](https://discuss.elastic.co/u/jlvrhee)\
**Replies:** 0\
**Last updated:** [July 31, 2020, 7:59pm UTC](https://discuss.elastic.co/t/how-to-monitor-docker-swarm-status-with-beats/243394 "2020-07-31T19:59:03Z")

</div>

Is there a way to monitor the status of docker nodes in a docker swarm? I didn't find any topic about this. We had a problem today that one of your docker nodes was down and we would like to monitor this so we can also d…

---

## [Auditbeat sends unencrypted data](https://discuss.elastic.co/t/auditbeat-sends-unencrypted-data/243366)

<div class="topic-metadata">

**Author:** [@elk6](https://discuss.elastic.co/u/elk6)\
**Replies:** 0\
**Last updated:** [July 31, 2020, 2:56pm UTC](https://discuss.elastic.co/t/auditbeat-sends-unencrypted-data/243366 "2020-07-31T14:56:03Z")

</div>

I have two beats on each server. Filebeat and auditbeat. I set up filebeat output to logstash and auditbeat output to elasticsearch. Filebeat encryption works fine. Now I'm setting up auditbeat's encryption. I have copi…

---

## [Each login/logout and failure event is populated 14 times in auditbeat index / dashboard](https://discuss.elastic.co/t/each-login-logout-and-failure-event-is-populated-14-times-in-auditbeat-index-dashboard/243388)

<div class="topic-metadata">

**Author:** [@himanshu.mainali](https://discuss.elastic.co/u/himanshu.mainali)\
**Replies:** 1\
**Last updated:** [July 31, 2020, 7:08pm UTC](https://discuss.elastic.co/t/each-login-logout-and-failure-event-is-populated-14-times-in-auditbeat-index-dashboard/243388 "2020-07-31T19:08:07Z")

</div>

Time host.hostname user.name event.outcome message Jul 31, 2020 @ 23:27:13.465 - mainalih - Logout by user mainalih (UID: 832203832) on pts/1 (PID: 17481) from 1x.2xx.xx.xx (IP: 1x.2xx.xx.xx) Jul 31, 2020 @ 23:27:1…

---

## [Metricbeat scrapping dead containers for prometheus metrics](https://discuss.elastic.co/t/metricbeat-scrapping-dead-containers-for-prometheus-metrics/242945)

<div class="topic-metadata">

**Author:** [@Suman\_M](https://discuss.elastic.co/u/Suman_M)\
**Replies:** 2\
**Last updated:** [July 31, 2020, 5:08pm UTC](https://discuss.elastic.co/t/metricbeat-scrapping-dead-containers-for-prometheus-metrics/242945 "2020-07-31T17:08:39Z")

</div>

We are running metricbeat in ecs. We have the prometheus module enabled for docker autodiscovery in the metricbeat configuration. We are running metricbeat version 7.6.2 on Amazon Linux 2. This is the relevant section in…

---

## [Problem loading root cert filebeat on openshift](https://discuss.elastic.co/t/problem-loading-root-cert-filebeat-on-openshift/243364)

<div class="topic-metadata">

**Author:** [@mladen](https://discuss.elastic.co/u/mladen)\
**Replies:** 0\
**Last updated:** [July 31, 2020, 2:43pm UTC](https://discuss.elastic.co/t/problem-loading-root-cert-filebeat-on-openshift/243364 "2020-07-31T14:43:18Z")

</div>

Hello, I am trying to install filebeat on my three openshift worker nodes. Following docs I manged to install filebeat agents. In log I see the following error: 2020-07-31T14:05:31.350Z ERROR tlscommon/tls.go:145 Fail…

---

## [Filebeat not send logs to elasticsearch directly](https://discuss.elastic.co/t/filebeat-not-send-logs-to-elasticsearch-directly/238437)

<div class="topic-metadata">

**Author:** [@Andrew31](https://discuss.elastic.co/u/Andrew31)\
**Replies:** 4\
**Last updated:** [July 31, 2020, 12:12pm UTC](https://discuss.elastic.co/t/filebeat-not-send-logs-to-elasticsearch-directly/238437 "2020-07-31T12:12:24Z")

</div>

Hi I have install filebeat in a centos 7, not send to elasticsearch installed in other machine. Ports 9200 and 5601 is opened. The configs are this.

---

## [Error fetching fields for index pattern metricbeat-\* (ID: metricbeat-\*) Request Timeout](https://discuss.elastic.co/t/error-fetching-fields-for-index-pattern-metricbeat-id-metricbeat-request-timeout/241313)

<div class="topic-metadata">

**Author:** [@Peter\_Kasper](https://discuss.elastic.co/u/Peter_Kasper)\
**Replies:** 1\
**Last updated:** [July 31, 2020, 9:01am UTC](https://discuss.elastic.co/t/error-fetching-fields-for-index-pattern-metricbeat-id-metricbeat-request-timeout/241313 "2020-07-31T09:01:52Z")

</div>

Kibana, Elastic are 7.8, using Centos 7.7 and sending VM is Centos is 8.0, non secure single node. Whenever I run metricbeat setup, it loads the items but when i view the index pattern i get the error. It seems to load …

---

## [Metricbeat / Filebeat blocked by Gatekeeper on macOS Catalina](https://discuss.elastic.co/t/metricbeat-filebeat-blocked-by-gatekeeper-on-macos-catalina/243279)

<div class="topic-metadata">

**Author:** [@djune](https://discuss.elastic.co/u/djune)\
**Replies:** 0\
**Last updated:** [July 30, 2020, 8:01pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat-blocked-by-gatekeeper-on-macos-catalina/243279 "2020-07-30T20:01:34Z")

</div>

Attempting to upgrade from 7.6.2 to 7.8.0 (or 7.8.1) and running into issues with Gatekeeper blocking metricbeat and filebeat from loading on boot. Both are able to launch manually with ./metricbeat -e and ./filebeat -e …

---

## [Filebeat not sending Apache logs to Logstash](https://discuss.elastic.co/t/filebeat-not-sending-apache-logs-to-logstash/243118)

<div class="topic-metadata">

**Author:** [@Kevin\_f](https://discuss.elastic.co/u/Kevin_f)\
**Replies:** 4\
**Last updated:** [July 30, 2020, 7:53pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-apache-logs-to-logstash/243118 "2020-07-30T19:53:08Z")

</div>

Hello, All, I have an issue where I have filebeat installed on my apache server with the following config: filebeat: prospectors: - enabled: true backoff: 1s backoff\_factor: 2 clean\_inactive: 0 …

---

## [Can Filebeat creating multiple logging files](https://discuss.elastic.co/t/can-filebeat-creating-multiple-logging-files/242460)

<div class="topic-metadata">

**Author:** [@vijayjavaprgmr](https://discuss.elastic.co/u/vijayjavaprgmr)\
**Replies:** 2\
**Last updated:** [July 30, 2020, 4:52pm UTC](https://discuss.elastic.co/t/can-filebeat-creating-multiple-logging-files/242460 "2020-07-30T16:52:50Z")

</div>

Hi Team, I am currently using Filebeat 7.6.2. could like to monitor the filebeat logging logs and want to write if any error during filebeat process then error logs need to writes in separate log file ex. \[filebeat\_erro…

---

## [Filebeat encryption error](https://discuss.elastic.co/t/filebeat-encryption-error/243227)

<div class="topic-metadata">

**Author:** [@elk6](https://discuss.elastic.co/u/elk6)\
**Replies:** 4\
**Last updated:** [July 30, 2020, 4:32pm UTC](https://discuss.elastic.co/t/filebeat-encryption-error/243227 "2020-07-30T16:32:32Z")

</div>

I'm trying to get filebeat to send encrypted data to logstash. In filebeat.yml, this is my output.logstash: output.logstash: hosts: \["91.242.11.220:5044"\] # Not the real IP ssl.enabled: true ssl.certificate\_autho…

---

## [Duplicate Entries in Filebeat Registry File For Kubernetes Pod Restart](https://discuss.elastic.co/t/duplicate-entries-in-filebeat-registry-file-for-kubernetes-pod-restart/242564)

<div class="topic-metadata">

**Author:** [@pulkit007](https://discuss.elastic.co/u/pulkit007)\
**Replies:** 5\
**Last updated:** [July 30, 2020, 3:23pm UTC](https://discuss.elastic.co/t/duplicate-entries-in-filebeat-registry-file-for-kubernetes-pod-restart/242564 "2020-07-30T15:23:07Z")

</div>

Hi, I am running filebeat in a Docker Container on Kubernetes Cluster for Processing Logs of our Application and send them to Logstash. Our Log Data is stored in PV, so I ran only one pod of filebeat that takes logs fro…

---

## [Secure filebeat to logstash](https://discuss.elastic.co/t/secure-filebeat-to-logstash/242899)

<div class="topic-metadata">

**Author:** [@elk6](https://discuss.elastic.co/u/elk6)\
**Replies:** 21\
**Last updated:** [July 30, 2020, 3:06pm UTC](https://discuss.elastic.co/t/secure-filebeat-to-logstash/242899 "2020-07-30T15:06:31Z")

</div>

I was tasked to secure the whole elastic flow and was able to secure the logstash-elasticsearch-kibana flow. I'm now having some trouble encrypting filebeat to logstash (It's the last step). According to the "secure fil…

---

## [Filebeat Index Template from Modules](https://discuss.elastic.co/t/filebeat-index-template-from-modules/242660)

<div class="topic-metadata">

**Author:** [@tactics](https://discuss.elastic.co/u/tactics)\
**Replies:** 5\
**Last updated:** [July 30, 2020, 2:21pm UTC](https://discuss.elastic.co/t/filebeat-index-template-from-modules/242660 "2020-07-30T14:21:16Z")

</div>

Hi, Not sure if I am overcomplicating things and bothering unnecessarily... I have finally got apache logs importing nicely using Filebeat and the Apache module. I am simply using the fields.yml and therefore the inde…

---

## [Kubernetes - Packetbeat implitation](https://discuss.elastic.co/t/kubernetes-packetbeat-implitation/243230)

<div class="topic-metadata">

**Author:** [@chopper20](https://discuss.elastic.co/u/chopper20)\
**Replies:** 0\
**Last updated:** [July 30, 2020, 1:46pm UTC](https://discuss.elastic.co/t/kubernetes-packetbeat-implitation/243230 "2020-07-30T13:46:17Z")

</div>

I am trying to implement packetbeat for specific services in Kubernetes (EKS cluster) but I am unable to get proper metrics. Issues: Unable to get desired index name. the default index is packetbeat-7.8.1-2020.07.30…

---

## [Filebeat directly to Elastic ingest node](https://discuss.elastic.co/t/filebeat-directly-to-elastic-ingest-node/243194)

<div class="topic-metadata">

**Author:** [@Axellurcher](https://discuss.elastic.co/u/Axellurcher)\
**Replies:** 1\
**Last updated:** [July 30, 2020, 11:34am UTC](https://discuss.elastic.co/t/filebeat-directly-to-elastic-ingest-node/243194 "2020-07-30T11:34:00Z")

</div>

I am pretty new to ELK so some actions and questions could be simple. We are sending logs directly from Filebeats to Elasticsearch without Logstash. Logs can contain JSON in different fields that also need to be parsed…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=223)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=225)
