# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=226

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 227

---

## [Send email alert when filebeat cannot send out log](https://discuss.elastic.co/t/send-email-alert-when-filebeat-cannot-send-out-log/242718)

<div class="topic-metadata">

**Author:** [@iammanmale](https://discuss.elastic.co/u/iammanmale)\
**Replies:** 2\
**Last updated:** [July 27, 2020, 2:28pm UTC](https://discuss.elastic.co/t/send-email-alert-when-filebeat-cannot-send-out-log/242718 "2020-07-27T14:28:00Z")

</div>

we have installed filebeat on aws machines around the world. Sometimes, some machines cannot send out log, is there any want to trigger an email alert when something like that happen?

---

## [Unique File Identifier in Filebeat](https://discuss.elastic.co/t/unique-file-identifier-in-filebeat/242507)

<div class="topic-metadata">

**Author:** [@pulkit007](https://discuss.elastic.co/u/pulkit007)\
**Replies:** 2\
**Last updated:** [July 27, 2020, 8:59am UTC](https://discuss.elastic.co/t/unique-file-identifier-in-filebeat/242507 "2020-07-27T08:59:10Z")

</div>

https://www.elastic.co/guide/en/beats/filebeat/current/how-filebeat-works.html#\_how\_does\_filebeat\_keep\_the\_state\_of\_files The above link tells that "For each file, Filebeat stores unique identifiers to detect whether a …

---

## [Custom index names with an ILM policy](https://discuss.elastic.co/t/custom-index-names-with-an-ilm-policy/241852)

<div class="topic-metadata">

**Author:** [@michielM](https://discuss.elastic.co/u/michielM)\
**Replies:** 4\
**Last updated:** [July 27, 2020, 8:35am UTC](https://discuss.elastic.co/t/custom-index-names-with-an-ilm-policy/241852 "2020-07-27T08:35:36Z")

</div>

Hi all, I am trying to setup my elk stack and beats in a way that I can have an ILM policy in combination with custom index names. For example: I want to have the index name filebeat-department-01/01/2000 and have it …

---

## [Elastic agent support for Windows container](https://discuss.elastic.co/t/elastic-agent-support-for-windows-container/242671)

<div class="topic-metadata">

**Author:** [@ankugarg](https://discuss.elastic.co/u/ankugarg)\
**Replies:** 1\
**Last updated:** [July 27, 2020, 8:12am UTC](https://discuss.elastic.co/t/elastic-agent-support-for-windows-container/242671 "2020-07-27T08:12:50Z")

</div>

Does Elastic Agent (https://www.elastic.co/downloads/elastic-agent) supports monitoring of windows container metrics(like CPU,memory of containers) and windows event logs?

---

## [How to update multiple servers (yml)?](https://discuss.elastic.co/t/how-to-update-multiple-servers-yml/242678)

<div class="topic-metadata">

**Author:** [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Replies:** 1\
**Last updated:** [July 27, 2020, 12:04am UTC](https://discuss.elastic.co/t/how-to-update-multiple-servers-yml/242678 "2020-07-27T00:04:59Z")

</div>

Hello All, A general question. Is there an easy way to update yml file(s) on multiple servers? Assuming the file is identical on all servers, and I just want to update the configuration file(s). Another scenario, is …

---

## [Filebeat putting in thousands of extraneous fields](https://discuss.elastic.co/t/filebeat-putting-in-thousands-of-extraneous-fields/242561)

<div class="topic-metadata">

**Author:** [@hmschreck](https://discuss.elastic.co/u/hmschreck)\
**Replies:** 1\
**Last updated:** [July 26, 2020, 11:52pm UTC](https://discuss.elastic.co/t/filebeat-putting-in-thousands-of-extraneous-fields/242561 "2020-07-26T23:52:42Z")

</div>

I'm trying to use the transform functionality in Elastic Cloud (7.8) and it is complaining that Filebeat has too many index fields (3700+ vs a maximum of 1024). I've tried changing the fields file to send something diff…

---

## [Need 6 months of log data in to ELK](https://discuss.elastic.co/t/need-6-months-of-log-data-in-to-elk/242437)

<div class="topic-metadata">

**Author:** [@nikhilesh](https://discuss.elastic.co/u/nikhilesh)\
**Replies:** 1\
**Last updated:** [July 26, 2020, 2:30pm UTC](https://discuss.elastic.co/t/need-6-months-of-log-data-in-to-elk/242437 "2020-07-26T14:30:18Z")

</div>

Hi Team, I have a requirement to fetch the 6 months of log data in to the Elasticsearch , is that possible? for suppose, if i install filebeat now, how many day/months of data will come to elastic search. Please help …

---

## [Can a dissect processor have a condition?](https://discuss.elastic.co/t/can-a-dissect-processor-have-a-condition/242578)

<div class="topic-metadata">

**Author:** [@geoffreyphippsuw](https://discuss.elastic.co/u/geoffreyphippsuw)\
**Replies:** 1\
**Last updated:** [July 25, 2020, 12:44am UTC](https://discuss.elastic.co/t/can-a-dissect-processor-have-a-condition/242578 "2020-07-25T00:44:56Z")

</div>

Our EFK stack is receiving logs from several different kubernetes containers and other sources that use differing log patterns. I have created a dissect processor that can extract certain fields from the message field. B…

---

## [When should I use Kafka?](https://discuss.elastic.co/t/when-should-i-use-kafka/241989)

<div class="topic-metadata">

**Author:** [@falconpurple](https://discuss.elastic.co/u/falconpurple)\
**Replies:** 3\
**Last updated:** [July 24, 2020, 9:56pm UTC](https://discuss.elastic.co/t/when-should-i-use-kafka/241989 "2020-07-24T21:56:34Z")

</div>

Hi, I am capturing logs from filebeat and sending to logstash for filtering.The data is then send to elasticsearch .The results are displayed on kibana. Data captured per day is about 150MB. Should I connect kafka wi…

---

## [Filebeat s3 cannot parse jsonl file who's content-type is set to application/json](https://discuss.elastic.co/t/filebeat-s3-cannot-parse-jsonl-file-whos-content-type-is-set-to-application-json/239374)

<div class="topic-metadata">

**Author:** [@lag13](https://discuss.elastic.co/u/lag13)\
**Replies:** 3\
**Last updated:** [July 24, 2020, 9:24pm UTC](https://discuss.elastic.co/t/filebeat-s3-cannot-parse-jsonl-file-whos-content-type-is-set-to-application-json/239374 "2020-07-24T21:24:42Z")

</div>

Hello! I was hoping y'all could help me out. The essence of my problem is that the filebeat S3 input plugin cannot process an s3 object who's content-type is application/json AND the object content is a separate json ob…

---

## [Filebeat 7.7 panw module sends THREAT, but not TRAFFIC logs](https://discuss.elastic.co/t/filebeat-7-7-panw-module-sends-threat-but-not-traffic-logs/239792)

<div class="topic-metadata">

**Author:** [@nverrill](https://discuss.elastic.co/u/nverrill)\
**Replies:** 7\
**Last updated:** [July 24, 2020, 6:13pm UTC](https://discuss.elastic.co/t/filebeat-7-7-panw-module-sends-threat-but-not-traffic-logs/239792 "2020-07-24T18:13:17Z")

</div>

I am testing Filebeat 7.7 with the panw module, and am receiving THREAT type logs, but not TRAFFIC type logs. Elasticsearch version is also 7.7. filebeat.yml config: filebeat.config.modules: path: ${path.config}/modu…

---

## [Winlogbeat Offline Parsing : Ingesting multiple Event Files for DFIR](https://discuss.elastic.co/t/winlogbeat-offline-parsing-ingesting-multiple-event-files-for-dfir/242549)

<div class="topic-metadata">

**Author:** [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Replies:** 0\
**Last updated:** [July 24, 2020, 5:35pm UTC](https://discuss.elastic.co/t/winlogbeat-offline-parsing-ingesting-multiple-event-files-for-dfir/242549 "2020-07-24T17:35:58Z")

</div>

I was trying to use Elastic Stack for forensics investigation purposes. I can parse 1 evtx file with no problem : But I guess Winlogbeat doesn support multiple files : Is there a built in way to do this because I d…

---

## [IIS Custom Fields logging in Elasticsearch with Filebeat](https://discuss.elastic.co/t/iis-custom-fields-logging-in-elasticsearch-with-filebeat/242525)

<div class="topic-metadata">

**Author:** [@Kunjan\_Sanghavi](https://discuss.elastic.co/u/Kunjan_Sanghavi)\
**Replies:** 1\
**Last updated:** [July 24, 2020, 2:55pm UTC](https://discuss.elastic.co/t/iis-custom-fields-logging-in-elasticsearch-with-filebeat/242525 "2020-07-24T14:55:31Z")

</div>

I am using Filebeat to ship my IIS logs to Elasticsearch. I enables the IIS module and its successfully shipping the logs. I have few custom fields which I am writing in IIS logs files. I am seeing the correct value of …

---

## [Trouble with log in UCS-2 LE BOM encoding](https://discuss.elastic.co/t/trouble-with-log-in-ucs-2-le-bom-encoding/198487)

<div class="topic-metadata">

**Author:** [@\_finack](https://discuss.elastic.co/u/_finack)\
**Replies:** 2\
**Last updated:** [July 24, 2020, 7:12am UTC](https://discuss.elastic.co/t/trouble-with-log-in-ucs-2-le-bom-encoding/198487 "2020-07-24T07:12:28Z")

</div>

I'm new to filebeat. I have a log file in UCS-2 LE BOM encoding. Log entries are each their own valid JSON object, one per line. Filebeat does not seem to like the UCS-2 LE BOM encoding. I'm seeing the following in the …

---

## [Suggestion for field name](https://discuss.elastic.co/t/suggestion-for-field-name/242105)

<div class="topic-metadata">

**Author:** [@opoplawski](https://discuss.elastic.co/u/opoplawski)\
**Replies:** 5\
**Last updated:** [July 24, 2020, 3:50am UTC](https://discuss.elastic.co/t/suggestion-for-field-name/242105 "2020-07-24T03:50:22Z")

</div>

I'm parsing logs from e2guardian - a web filter. One of the fields is basically "why" a request was block. For e.g.: 2020.04.06 12:21:37 - 10.11.2.22 https://stats.g.doubleclick.net/r/collect?v=1&aip=…

---

## [Issues with additional event logs enabled](https://discuss.elastic.co/t/issues-with-additional-event-logs-enabled/242416)

<div class="topic-metadata">

**Author:** [@rmoat](https://discuss.elastic.co/u/rmoat)\
**Replies:** 0\
**Last updated:** [July 23, 2020, 10:38pm UTC](https://discuss.elastic.co/t/issues-with-additional-event-logs-enabled/242416 "2020-07-23T22:38:44Z")

</div>

Hello, I am trying to get events from two separate logs on our domain controllers, and just realized today that the entire Security log was not being sent to Kibana by winlogbeat after I tried to send events from a seco…

---

## [Removing "winlog" prefix in winlogbeat](https://discuss.elastic.co/t/removing-winlog-prefix-in-winlogbeat/242344)

<div class="topic-metadata">

**Author:** [@ssiws](https://discuss.elastic.co/u/ssiws)\
**Replies:** 0\
**Last updated:** [July 23, 2020, 1:31pm UTC](https://discuss.elastic.co/t/removing-winlog-prefix-in-winlogbeat/242344 "2020-07-23T13:31:34Z")

</div>

Hello, I'm upgrading winlogbeat 5.4.1 to 7.8.0. I saw that some fields are now prefixed by "winlog" (example: event\_id became winlog\_event\_id). Is there a setting, or is it possible to add rule to remove this prefix ? …

---

## [Metricbeat 7.8 only listing one drive](https://discuss.elastic.co/t/metricbeat-7-8-only-listing-one-drive/242360)

<div class="topic-metadata">

**Author:** [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Replies:** 0\
**Last updated:** [July 23, 2020, 2:56pm UTC](https://discuss.elastic.co/t/metricbeat-7-8-only-listing-one-drive/242360 "2020-07-23T14:56:20Z")

</div>

I am running Metricbeat 7.8 on CentOS 7. Only one drive is showing in Kibana. \[centos@server9 modules.d\]$ df -h Filesystem Size Used Avail Use% Mounted on /dev/xvda1 …

---

## [Download new version of filebeat](https://discuss.elastic.co/t/download-new-version-of-filebeat/241607)

<div class="topic-metadata">

**Author:** [@JoseSaborido](https://discuss.elastic.co/u/JoseSaborido)\
**Replies:** 8\
**Last updated:** [July 23, 2020, 1:25pm UTC](https://discuss.elastic.co/t/download-new-version-of-filebeat/241607 "2020-07-23T13:25:04Z")

</div>

Hi! I've been trying to configure filebeat to create an index every day but it seems to be impossible. I have seen this issue https://github.com/elastic/beats/issues/11595 So I have been trying to download the version …

---

## [Found encoding issue with Filebeat MS SQL module](https://discuss.elastic.co/t/found-encoding-issue-with-filebeat-ms-sql-module/242336)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 0\
**Last updated:** [July 23, 2020, 11:39am UTC](https://discuss.elastic.co/t/found-encoding-issue-with-filebeat-ms-sql-module/242336 "2020-07-23T11:39:25Z")

</div>

Filebeat MS SQL module has a encoding issue ERRORLOG files in SQL folder is a utf-16le-bom encoded files but that is not specified in the config.yml file of the filebeat mssql module folder please add encoding: utf…

---

## [Issue with output kafka multiple topics](https://discuss.elastic.co/t/issue-with-output-kafka-multiple-topics/242316)

<div class="topic-metadata">

**Author:** [@svasilyev](https://discuss.elastic.co/u/svasilyev)\
**Replies:** 0\
**Last updated:** [July 23, 2020, 9:55am UTC](https://discuss.elastic.co/t/issue-with-output-kafka-multiple-topics/242316 "2020-07-23T09:55:13Z")

</div>

i use filebeat 7.8.0 in Docker-Compose OS rhel 7 When I try to write logs for multiple topics in kafka, the logs are added to kafka (always one topic (containerlogs) with no selection) logs are received at the time of…

---

## [Parsing for syslog in Filebeat](https://discuss.elastic.co/t/parsing-for-syslog-in-filebeat/242314)

<div class="topic-metadata">

**Author:** [@misheck](https://discuss.elastic.co/u/misheck)\
**Replies:** 0\
**Last updated:** [July 23, 2020, 9:44am UTC](https://discuss.elastic.co/t/parsing-for-syslog-in-filebeat/242314 "2020-07-23T09:44:39Z")

</div>

I have filebeat installed on a Centos vm to collect local logs via flat file and also receive syslog on Port 9000 from a remote Centos Machine. I am collecting logs from computers but I have noticed that the Filebeat EC…

---

## [Correct way to remove unnecessary fields from filebeat](https://discuss.elastic.co/t/correct-way-to-remove-unnecessary-fields-from-filebeat/239443)

<div class="topic-metadata">

**Author:** [@sfenman](https://discuss.elastic.co/u/sfenman)\
**Replies:** 1\
**Last updated:** [July 23, 2020, 7:19am UTC](https://discuss.elastic.co/t/correct-way-to-remove-unnecessary-fields-from-filebeat/239443 "2020-07-23T07:19:14Z")

</div>

Hello, I send different types of logs from filebeat directly to ES and I have noticed in kibana discover tab that my some logs have empty fields which they are used by other log entries. For example, my production log e…

---

## [Metricbeat for IBM MQ](https://discuss.elastic.co/t/metricbeat-for-ibm-mq/242276)

<div class="topic-metadata">

**Author:** [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Replies:** 2\
**Last updated:** [July 23, 2020, 5:33am UTC](https://discuss.elastic.co/t/metricbeat-for-ibm-mq/242276 "2020-07-23T05:33:52Z")

</div>

Hi All, I am trying to use metricbeat for IBM MQ but I am getting below error No data has been received from this module yet Can someone please suggest what changes , do I need to make in below file 'modules.d/ibmmq.…

---

## [Filebeat Data transfer speed and size](https://discuss.elastic.co/t/filebeat-data-transfer-speed-and-size/242274)

<div class="topic-metadata">

**Author:** [@gangireddy\_l](https://discuss.elastic.co/u/gangireddy_l)\
**Replies:** 0\
**Last updated:** [July 23, 2020, 4:59am UTC](https://discuss.elastic.co/t/filebeat-data-transfer-speed-and-size/242274 "2020-07-23T04:59:59Z")

</div>

Hi Team How to find file-beat data transfer speed and data sent per hour or day..? Regards, Gangi Reddy

---

## [Little confuse about registry file](https://discuss.elastic.co/t/little-confuse-about-registry-file/242031)

<div class="topic-metadata">

**Author:** [@Mrzhuang007](https://discuss.elastic.co/u/Mrzhuang007)\
**Replies:** 0\
**Last updated:** [July 21, 2020, 1:07pm UTC](https://discuss.elastic.co/t/little-confuse-about-registry-file/242031 "2020-07-21T13:07:35Z")

</div>

I add some config like below filebeat.config: inputs: enabled: true path: /etc/filebeat/filebeat-2/\*.yml reload.enabled: true reload.period: 1s It enable me to add runtime yml configs. But when I remo…

---

## [Filebeate can not remove the state of log in registry file](https://discuss.elastic.co/t/filebeate-can-not-remove-the-state-of-log-in-registry-file/242268)

<div class="topic-metadata">

**Author:** [@Mrzhuang007](https://discuss.elastic.co/u/Mrzhuang007)\
**Replies:** 0\
**Last updated:** [July 23, 2020, 3:23am UTC](https://discuss.elastic.co/t/filebeate-can-not-remove-the-state-of-log-in-registry-file/242268 "2020-07-23T03:23:20Z")

</div>

The Filebeat Version I used is 6.8.6. Running in Linux. The filebeat.yml I used is as fllow: #========================= Filebeat global options ============================ filebeat.config: inputs: enabled: true …

---

## [PaloAlto ingest pipeline and geoip lookup](https://discuss.elastic.co/t/paloalto-ingest-pipeline-and-geoip-lookup/240869)

<div class="topic-metadata">

**Author:** [@rossw](https://discuss.elastic.co/u/rossw)\
**Replies:** 3\
**Last updated:** [July 23, 2020, 2:12am UTC](https://discuss.elastic.co/t/paloalto-ingest-pipeline-and-geoip-lookup/240869 "2020-07-23T02:12:57Z")

</div>

Hi there We are running Filebeat 7.8.0, and utilising the Palo Alto module to ingest firewalls using ECS. When I go to display the source or destination IP addresses on on a map, I get a failure and no data points. Ac…

---

## [Metricbeat capturing performance monitor terminal services](https://discuss.elastic.co/t/metricbeat-capturing-performance-monitor-terminal-services/242087)

<div class="topic-metadata">

**Author:** [@dklinkaz](https://discuss.elastic.co/u/dklinkaz)\
**Replies:** 0\
**Last updated:** [July 21, 2020, 6:58pm UTC](https://discuss.elastic.co/t/metricbeat-capturing-performance-monitor-terminal-services/242087 "2020-07-21T18:58:26Z")

</div>

I am trying to capture the WVD session host information, I am currently using the performance monitor terminal services to capture the information. I am having issues getting the windows module to properly run and send t…

---

## [Metricbeat from 6.5.2 to 7.8.0](https://discuss.elastic.co/t/metricbeat-from-6-5-2-to-7-8-0/242194)

<div class="topic-metadata">

**Author:** [@salvo](https://discuss.elastic.co/u/salvo)\
**Replies:** 1\
**Last updated:** [July 22, 2020, 11:23pm UTC](https://discuss.elastic.co/t/metricbeat-from-6-5-2-to-7-8-0/242194 "2020-07-22T23:23:53Z")

</div>

I recently migrated metricbeat from 6.5.2 to 7.8.0 but for some reason, after I created the dashboard by running: metricbeat setup --dashboards and by navigating to the Kafka dashboard I am facing a strange error: Err…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=225)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=227)
