# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=225

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 226

---

## [How to remove certain fields from filebeat index](https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597)

<div class="topic-metadata">

**Author:** [@jijo.john](https://discuss.elastic.co/u/jijo.john)\
**Replies:** 5\
**Last updated:** [July 30, 2020, 10:16am UTC](https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597 "2020-07-30T10:16:04Z")

</div>

Hi Team, I am new to Elasticsearch and we are running a POC on Elasticsearch. We would like to remove few fields from the index documents which are not relevant. Please help us to remove this from newly creating index …

---

## [Filebeat not creating index daily](https://discuss.elastic.co/t/filebeat-not-creating-index-daily/243181)

<div class="topic-metadata">

**Author:** [@daniel\_fablius](https://discuss.elastic.co/u/daniel_fablius)\
**Replies:** 5\
**Last updated:** [July 30, 2020, 9:37am UTC](https://discuss.elastic.co/t/filebeat-not-creating-index-daily/243181 "2020-07-30T09:37:29Z")

</div>

Hi, so i use filebeat to send logs to Elasticsearch and i see an index is created with name "filebeat-7.7.1-2020.07.29-000002" i assume that filebeat will keep creating a new index based on the datetime of the data eve…

---

## [Filebeat resent all events of a logfile - every day](https://discuss.elastic.co/t/filebeat-resent-all-events-of-a-logfile-every-day/242478)

<div class="topic-metadata">

**Author:** [@scheffler](https://discuss.elastic.co/u/scheffler)\
**Replies:** 9\
**Last updated:** [July 30, 2020, 8:57am UTC](https://discuss.elastic.co/t/filebeat-resent-all-events-of-a-logfile-every-day/242478 "2020-07-30T08:57:43Z")

</div>

Hi The logfile has always the same name, but a housekeeping job copy and zip the file every night, with the side effect that the file gets a new inode. I guess that the inode is harvesters primary key in the registry an…

---

## [Giving up on filebeat/elastic soon.. dashboards broken when rolling over index](https://discuss.elastic.co/t/giving-up-on-filebeat-elastic-soon-dashboards-broken-when-rolling-over-index/242869)

<div class="topic-metadata">

**Author:** [@Martin\_Norrsken](https://discuss.elastic.co/u/Martin_Norrsken)\
**Replies:** 9\
**Last updated:** [July 30, 2020, 8:04am UTC](https://discuss.elastic.co/t/giving-up-on-filebeat-elastic-soon-dashboards-broken-when-rolling-over-index/242869 "2020-07-30T08:04:29Z")

</div>

I've set up elastic stack (7.8.0 now 7.8.1) in kubernetes and filebeat on my nodes. Everty time an index rolls over i get a lot of broken stuff. Every time i try to customize anything it breaks... Its so much that i susp…

---

## [Configuración de FileBeat](https://discuss.elastic.co/t/configuracion-de-filebeat/243138)

<div class="topic-metadata">

**Author:** [@jimmy.baldeond](https://discuss.elastic.co/u/jimmy.baldeond)\
**Replies:** 1\
**Last updated:** [July 30, 2020, 7:05am UTC](https://discuss.elastic.co/t/configuracion-de-filebeat/243138 "2020-07-30T07:05:23Z")

</div>

Hola, he instalado el Filebeat en el cluster de Kubernetes, sin embargo no visualizo los logs en el Kibana. Adicionalmente, les comento que los logs si llegan de los servidores normales. Sin embargo no funciona en Kubern…

---

## [Filebeat Multiline Not Working At All, Please Help](https://discuss.elastic.co/t/filebeat-multiline-not-working-at-all-please-help/242537)

<div class="topic-metadata">

**Author:** [@gratefulted](https://discuss.elastic.co/u/gratefulted)\
**Replies:** 1\
**Last updated:** [July 30, 2020, 6:39am UTC](https://discuss.elastic.co/t/filebeat-multiline-not-working-at-all-please-help/242537 "2020-07-30T06:39:46Z")

</div>

Hi all, I'm fairly new to ELK stack and am helping a client with an issue they are having getting multiline logs formatted in kibana. Here is my filebeat.yml: #=========================== Filebeat inputs ==============…

---

## [Filebeat output elasticsearch pipeline not working](https://discuss.elastic.co/t/filebeat-output-elasticsearch-pipeline-not-working/240167)

<div class="topic-metadata">

**Author:** [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Replies:** 5\
**Last updated:** [July 30, 2020, 12:08am UTC](https://discuss.elastic.co/t/filebeat-output-elasticsearch-pipeline-not-working/240167 "2020-07-30T00:08:09Z")

</div>

Hi, I am stuck on configuring filebeat to use a custom elasticsearch ingest pipeline. For some reasons the pipeline is now applied for logs shipped by filebeat. If a document is indexed manually, everything works as e…

---

## [Dns log parsing and display in Kibana](https://discuss.elastic.co/t/dns-log-parsing-and-display-in-kibana/242989)

<div class="topic-metadata">

**Author:** [@rossw](https://discuss.elastic.co/u/rossw)\
**Replies:** 2\
**Last updated:** [July 29, 2020, 9:00pm UTC](https://discuss.elastic.co/t/dns-log-parsing-and-display-in-kibana/242989 "2020-07-29T21:00:55Z")

</div>

I think there is an error in the way that Packetbeat (7.8) parses DNS logs, and/or the way that Kibana displays them. If I have a host 1.1.1.1 that sends a dns request for microsoft.com to the DNS server 2.2.2.2, and pa…

---

## [Ssl.verification\_mode options for Filebeat 5.6](https://discuss.elastic.co/t/ssl-verification-mode-options-for-filebeat-5-6/242978)

<div class="topic-metadata">

**Author:** [@alarka](https://discuss.elastic.co/u/alarka)\
**Replies:** 9\
**Last updated:** [July 29, 2020, 7:44pm UTC](https://discuss.elastic.co/t/ssl-verification-mode-options-for-filebeat-5-6/242978 "2020-07-29T19:44:22Z")

</div>

As per Filebeat 7.8, https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html ssl.verification\_mode has 3 options: "full", "certificate" and "none". For Filebeat 5.6, I do not see the opti…

---

## [Logstash - filebeat](https://discuss.elastic.co/t/logstash-filebeat/242216)

<div class="topic-metadata">

**Author:** [@Arezki76](https://discuss.elastic.co/u/Arezki76)\
**Replies:** 2\
**Last updated:** [July 29, 2020, 5:32pm UTC](https://discuss.elastic.co/t/logstash-filebeat/242216 "2020-07-29T17:32:38Z")

</div>

Hi, I'm new in ELK and I'm trying to parse log file as follow: 2019 Nov 12 14:58:01:211 GMT -0500 BW.ypg\_bis\_ful\_campaignservice\_bw-ypg-bis-ful-campaignservice-bw Info \[BW-User\] UPSTREAM\_REQUEST Job-1000 \[ESBCore/Log/S…

---

## [Multi line logs Javastack trace not showing up correctly](https://discuss.elastic.co/t/multi-line-logs-javastack-trace-not-showing-up-correctly/242903)

<div class="topic-metadata">

**Author:** [@Archie\_Crawford](https://discuss.elastic.co/u/Archie_Crawford)\
**Replies:** 11\
**Last updated:** [July 29, 2020, 1:51pm UTC](https://discuss.elastic.co/t/multi-line-logs-javastack-trace-not-showing-up-correctly/242903 "2020-07-29T13:51:16Z")

</div>

The java stack trace logs are not coming in as multi-lines they are still coming in as separate lines Filebeat Config - /var/\*\*\*/catalina\* - /var/\*\*\*/\*.log multiline.pattern: '^\[\[:space:\]\]' multiline.negate:…

---

## [Process to upgrade windows auditbeat install?](https://discuss.elastic.co/t/process-to-upgrade-windows-auditbeat-install/243043)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 1\
**Last updated:** [July 29, 2020, 1:16pm UTC](https://discuss.elastic.co/t/process-to-upgrade-windows-auditbeat-install/243043 "2020-07-29T13:16:16Z")

</div>

Any special steps to take? Does the existing service need to be removed somehow beforehand? 7.7.0 -\> 7.8.1

---

## [Filebeat versions from 7.0 - 7.8 fail to create alias field mappings for majority of modules](https://discuss.elastic.co/t/filebeat-versions-from-7-0-7-8-fail-to-create-alias-field-mappings-for-majority-of-modules/242874)

<div class="topic-metadata">

**Author:** [@b0le](https://discuss.elastic.co/u/b0le)\
**Replies:** 4\
**Last updated:** [July 29, 2020, 9:32am UTC](https://discuss.elastic.co/t/filebeat-versions-from-7-0-7-8-fail-to-create-alias-field-mappings-for-majority-of-modules/242874 "2020-07-29T09:32:26Z")

</div>

Summary: When running Filebeat's 7.8.0 setup command the field mappings for the majority of modules which define mappings of type alias never get created. The alias mappings are missing from export template output as wel…

---

## [Which beat to use?](https://discuss.elastic.co/t/which-beat-to-use/243003)

<div class="topic-metadata">

**Author:** [@Murango](https://discuss.elastic.co/u/Murango)\
**Replies:** 1\
**Last updated:** [July 29, 2020, 8:51am UTC](https://discuss.elastic.co/t/which-beat-to-use/243003 "2020-07-29T08:51:51Z")

</div>

Hello, Does anyone know which beat to use for monitoring: File attributes on windows - I have already checked auditbeat but there is no such option for Windows File shifts between folders on windows - Here auditbeat o…

---

## [How can I sort the fields order of json output](https://discuss.elastic.co/t/how-can-i-sort-the-fields-order-of-json-output/242987)

<div class="topic-metadata">

**Author:** [@CHU\_XU](https://discuss.elastic.co/u/CHU_XU)\
**Replies:** 1\
**Last updated:** [July 29, 2020, 7:58am UTC](https://discuss.elastic.co/t/how-can-i-sort-the-fields-order-of-json-output/242987 "2020-07-29T07:58:32Z")

</div>

Hi there, Found that the fields in json output have a random order even in the same event. For some reason, I need the fields sorted. The 'codec.format' acutally does but it's too complicated. Is there any configs ma…

---

## [Logs from Cisco SFR (IPS) to Elasticsearch](https://discuss.elastic.co/t/logs-from-cisco-sfr-ips-to-elasticsearch/242909)

<div class="topic-metadata">

**Author:** [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Replies:** 0\
**Last updated:** [July 28, 2020, 1:03pm UTC](https://discuss.elastic.co/t/logs-from-cisco-sfr-ips-to-elasticsearch/242909 "2020-07-28T13:03:48Z")

</div>

Dear all, I have an ELK 7.8.0 server with Filebeat. I've enabled cisco module from Filebeat and I have these different syslog listeners: syslog configured from filebeat.yml file: logging of Linux hosts asa fileset con…

---

## [Connect to ElasticSearch with HTTPS](https://discuss.elastic.co/t/connect-to-elasticsearch-with-https/242923)

<div class="topic-metadata">

**Author:** [@julianksanchez](https://discuss.elastic.co/u/julianksanchez)\
**Replies:** 1\
**Last updated:** [July 28, 2020, 3:26pm UTC](https://discuss.elastic.co/t/connect-to-elasticsearch-with-https/242923 "2020-07-28T15:26:07Z")

</div>

Hello guys, We are using HTTPS for connection to Elasticsearch. However We are trying to configurate metricbeat in Windows10 and we cant connect to elastic. We have the next configuracion en metricbeat.yml: ==========…

---

## [Unable to Process VPC Flow Logs using filebeat 7.8.0](https://discuss.elastic.co/t/unable-to-process-vpc-flow-logs-using-filebeat-7-8-0/242229)

<div class="topic-metadata">

**Author:** [@nikhilv](https://discuss.elastic.co/u/nikhilv)\
**Replies:** 4\
**Last updated:** [July 28, 2020, 3:08pm UTC](https://discuss.elastic.co/t/unable-to-process-vpc-flow-logs-using-filebeat-7-8-0/242229 "2020-07-28T15:08:44Z")

</div>

Hello Team, I'm using filebeat 8.0 and deployed on AWS EKS to ship aws logs to ECK for analysis. I'm using AWS module in filebeat and i didn't face any issues with cloudtrail&elb logs but only facing issues with vpc flo…

---

## [Metricbeat error unable to send metrics on elastic](https://discuss.elastic.co/t/metricbeat-error-unable-to-send-metrics-on-elastic/242333)

<div class="topic-metadata">

**Author:** [@karunakarsingh](https://discuss.elastic.co/u/karunakarsingh)\
**Replies:** 9\
**Last updated:** [July 28, 2020, 10:54am UTC](https://discuss.elastic.co/t/metricbeat-error-unable-to-send-metrics-on-elastic/242333 "2020-07-28T10:54:18Z")

</div>

Hi Team, kindly help I am not able to export metrics on Elasticsearch. Getting this error. WARN elasticsearch/client.go:539 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0xbfbe3c…

---

## [Issue with sending logs in secure Kafka](https://discuss.elastic.co/t/issue-with-sending-logs-in-secure-kafka/242707)

<div class="topic-metadata">

**Author:** [@svasilyev](https://discuss.elastic.co/u/svasilyev)\
**Replies:** 4\
**Last updated:** [July 28, 2020, 8:45am UTC](https://discuss.elastic.co/t/issue-with-sending-logs-in-secure-kafka/242707 "2020-07-28T08:45:35Z")

</div>

my problem looks the same https://discuss.elastic.co/t/issue-with-sending-to-kafka-0-10-2-1-over-tls/111252 but my version work however my logs are written for some time (different on several servers) and then they sto…

---

## [Issue: Adds all available datetime fields from index template with empty value, when add date\_index\_name processor in pipeline of filebeat fortinet module](https://discuss.elastic.co/t/issue-adds-all-available-datetime-fields-from-index-template-with-empty-value-when-add-date-index-name-processor-in-pipeline-of-filebeat-fortinet-module/240680)

<div class="topic-metadata">

**Author:** [@umeshnagori](https://discuss.elastic.co/u/umeshnagori)\
**Replies:** 4\
**Last updated:** [July 28, 2020, 8:31am UTC](https://discuss.elastic.co/t/issue-adds-all-available-datetime-fields-from-index-template-with-empty-value-when-add-date-index-name-processor-in-pipeline-of-filebeat-fortinet-module/240680 "2020-07-28T08:31:32Z")

</div>

ISSUE Adds all available datetime fields from index template with empty value (even those fields those are otherwise used by disabled modules and disabled) , when add date\_index\_name processor in pipeline of filebeat fo…

---

## [Configuration for ELK+filebeat with docker](https://discuss.elastic.co/t/configuration-for-elk-filebeat-with-docker/239227)

<div class="topic-metadata">

**Author:** [@Govinda8594](https://discuss.elastic.co/u/Govinda8594)\
**Replies:** 0\
**Last updated:** [June 30, 2020, 6:16am UTC](https://discuss.elastic.co/t/configuration-for-elk-filebeat-with-docker/239227 "2020-06-30T06:16:07Z")

</div>

(topic withdrawn by author, will be automatically deleted in 24 hours unless flagged)

---

## [MetricBeat on Openshift](https://discuss.elastic.co/t/metricbeat-on-openshift/242795)

<div class="topic-metadata">

**Author:** [@jaikunwar](https://discuss.elastic.co/u/jaikunwar)\
**Replies:** 1\
**Last updated:** [July 28, 2020, 8:07am UTC](https://discuss.elastic.co/t/metricbeat-on-openshift/242795 "2020-07-28T08:07:09Z")

</div>

I am trying to run metricbeat on openshift using docker file: #Docker file: FROM docker-secure-com/metricbeat/metricbeat:latest COPY metricbeat.yml /etc/metricbeat/config/metricbeat.yml COPY metricbeat.yml /etc/metri…

---

## [How push beats agents to multiple machines ( Avoid Manual installation )](https://discuss.elastic.co/t/how-push-beats-agents-to-multiple-machines-avoid-manual-installation/242842)

<div class="topic-metadata">

**Author:** [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Replies:** 2\
**Last updated:** [July 28, 2020, 7:49am UTC](https://discuss.elastic.co/t/how-push-beats-agents-to-multiple-machines-avoid-manual-installation/242842 "2020-07-28T07:49:13Z")

</div>

Hi , If we have large number of Linux and Windows machines in our infrastructure ( Suppose 100+ windows and Linux machines ) . Manual installation takes large amount of time . How we can automate beat remote installat…

---

## [Weblogic log message data extraction](https://discuss.elastic.co/t/weblogic-log-message-data-extraction/242797)

<div class="topic-metadata">

**Author:** [@tommparekh](https://discuss.elastic.co/u/tommparekh)\
**Replies:** 1\
**Last updated:** [July 27, 2020, 10:40pm UTC](https://discuss.elastic.co/t/weblogic-log-message-data-extraction/242797 "2020-07-27T22:40:54Z")

</div>

Hi, I am new to ELK and trying to setup log file monitoring for my weblogic servers. So far, I have setup filebeat on the linux server to send log details to ES/Kibana. This functionality is working. However, the log e…

---

## [Where is metricbeat saving docs?](https://discuss.elastic.co/t/where-is-metricbeat-saving-docs/242810)

<div class="topic-metadata">

**Author:** [@tterranigma](https://discuss.elastic.co/u/tterranigma)\
**Replies:** 1\
**Last updated:** [July 27, 2020, 9:35pm UTC](https://discuss.elastic.co/t/where-is-metricbeat-saving-docs/242810 "2020-07-27T21:35:33Z")

</div>

I have setup metricbeat to connect to beats I have on my productions servers. I can see in Kibana's stack monitoring page useful stats about my beats. I also monitor my elasticsearch nodes. My question is where does met…

---

## [Bash: make: command not found while trying to run make create-metricset](https://discuss.elastic.co/t/bash-make-command-not-found-while-trying-to-run-make-create-metricset/242809)

<div class="topic-metadata">

**Author:** [@Venkat\_Raj](https://discuss.elastic.co/u/Venkat_Raj)\
**Replies:** 0\
**Last updated:** [July 27, 2020, 9:06pm UTC](https://discuss.elastic.co/t/bash-make-command-not-found-while-trying-to-run-make-create-metricset/242809 "2020-07-27T21:06:33Z")

</div>

I am trying to create a new metricset inside the metricbeat folder and I am getting error while trying to run the command "make create-metricset". bash: make: command not found I have few proxy issues on the linux serv…

---

## [Metricbeat 7.8 elasticsearch monitoring permissions Issue](https://discuss.elastic.co/t/metricbeat-7-8-elasticsearch-monitoring-permissions-issue/242807)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 1\
**Last updated:** [July 27, 2020, 8:40pm UTC](https://discuss.elastic.co/t/metricbeat-7-8-elasticsearch-monitoring-permissions-issue/242807 "2020-07-27T20:40:35Z")

</div>

I am having monitoring data permissions issue using metricbeat to send monitoring data The current Roles / Privlages are as below. when i make the account a superuser , Elasticsearch monitoring data goes to the monitori…

---

## [Filebeat Haproxy module configuration](https://discuss.elastic.co/t/filebeat-haproxy-module-configuration/240011)

<div class="topic-metadata">

**Author:** [@ndg](https://discuss.elastic.co/u/ndg)\
**Replies:** 5\
**Last updated:** [July 27, 2020, 6:22pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-configuration/240011 "2020-07-27T18:22:08Z")

</div>

Hi! I want to configure the haproxy module on filebeat. I did it and i am getting some fileds but others are empty. Here is my filebeat configuration # Module: haproxy # Docs: https://www.elastic.co/guide/en/beats/file…

---

## [Filebeat module for SharePoint](https://discuss.elastic.co/t/filebeat-module-for-sharepoint/242766)

<div class="topic-metadata">

**Author:** [@vladtepes](https://discuss.elastic.co/u/vladtepes)\
**Replies:** 1\
**Last updated:** [July 27, 2020, 3:24pm UTC](https://discuss.elastic.co/t/filebeat-module-for-sharepoint/242766 "2020-07-27T15:24:45Z")

</div>

Hi, There is now this new concept of using ingest pipelines instead of Logstash pipelines, but the Filebeat would be fantastic, if there was a module for SharePoint ULS logs. There a quite a few farms out there, which w…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=224)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=226)
