# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=227

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 228

---

## [Filebeat getting stopped automatically after sometime](https://discuss.elastic.co/t/filebeat-getting-stopped-automatically-after-sometime/242198)

<div class="topic-metadata">

**Author:** [@HariniGajendran](https://discuss.elastic.co/u/HariniGajendran)\
**Replies:** 1\
**Last updated:** [July 22, 2020, 11:23pm UTC](https://discuss.elastic.co/t/filebeat-getting-stopped-automatically-after-sometime/242198 "2020-07-22T23:23:18Z")

</div>

Hi, I am using 7.4.2 version filebeat. Issue is my filebeat service gets stopped automatically after running for sometime. But whenever I start it will crawl properly and log data into elastic search properly for certai…

---

## [Filebeats Getting Connection reset by peer error](https://discuss.elastic.co/t/filebeats-getting-connection-reset-by-peer-error/242250)

<div class="topic-metadata">

**Author:** [@deep\_sandhu](https://discuss.elastic.co/u/deep_sandhu)\
**Replies:** 0\
**Last updated:** [July 22, 2020, 8:58pm UTC](https://discuss.elastic.co/t/filebeats-getting-connection-reset-by-peer-error/242250 "2020-07-22T20:58:52Z")

</div>

I am trying to send logs from filebeat(from dev host) to logstash (running in kubernetes separate Node), but getting following error \[INFO \] 2020-07-22 20:42:19.309 \[defaultEventExecutorGroup-4-1\] BeatsHandler - \[local:…

---

## [Status=403): {"type":"security\_exception","reason":"action \[indices:data/write/bulk\[s\]](https://discuss.elastic.co/t/status-403-type-security-exception-reason-action-indices-data-write-bulk-s/240299)

<div class="topic-metadata">

**Author:** [@mmk1995](https://discuss.elastic.co/u/mmk1995)\
**Replies:** 8\
**Last updated:** [July 22, 2020, 6:24pm UTC](https://discuss.elastic.co/t/status-403-type-security-exception-reason-action-indices-data-write-bulk-s/240299 "2020-07-22T18:24:34Z")

</div>

Hello, It took me the whole day and I still cant work it out. Please see below what is wrong My Kibana user setting: metricbeat.yml: metricbeat.config.modules: path: ${path.config}/modules.d/\*.yml reload.enab…

---

## [Can @timestamp be renamed when dumped to elasticsearch? (version 7.8)](https://discuss.elastic.co/t/can-timestamp-be-renamed-when-dumped-to-elasticsearch-version-7-8/242225)

<div class="topic-metadata">

**Author:** [@Alex\_Tchhailo](https://discuss.elastic.co/u/Alex_Tchhailo)\
**Replies:** 0\
**Last updated:** [July 22, 2020, 3:31pm UTC](https://discuss.elastic.co/t/can-timestamp-be-renamed-when-dumped-to-elasticsearch-version-7-8/242225 "2020-07-22T15:31:29Z")

</div>

Hello friends! i was hoping to find out if when winlogbeat writes to elasticsearch the field '@timestamp' can be renamed/remapped to something i can get to with javascript when i get the records out. I located such art…

---

## [Problem ingesting vpc flow logs](https://discuss.elastic.co/t/problem-ingesting-vpc-flow-logs/239172)

<div class="topic-metadata">

**Author:** [@andywt123](https://discuss.elastic.co/u/andywt123)\
**Replies:** 4\
**Last updated:** [July 22, 2020, 3:12pm UTC](https://discuss.elastic.co/t/problem-ingesting-vpc-flow-logs/239172 "2020-07-22T15:12:29Z")

</div>

We are using filebeat 7.6.2 to ingest vpc flow logs. IT appears that it is taking longer then 24 hours for the vpc flow logs to be ingested. Everything seems to be working fine for the elb logs. The SQS queue still has …

---

## [Compiling filebeat from source on ppc64le](https://discuss.elastic.co/t/compiling-filebeat-from-source-on-ppc64le/242186)

<div class="topic-metadata">

**Author:** [@seth-priya](https://discuss.elastic.co/u/seth-priya)\
**Replies:** 0\
**Last updated:** [July 22, 2020, 12:18pm UTC](https://discuss.elastic.co/t/compiling-filebeat-from-source-on-ppc64le/242186 "2020-07-22T12:18:40Z")

</div>

Hi, I am trying to build filebeat version 6.8.10 using the below steps on ppc64le, UBI-8 and had a couple of questions #Steps to build (using go.10.2) git clone https://github.com/elastic/beats.git cd beats git chec…

---

## [Filebeat regexp metadata variables](https://discuss.elastic.co/t/filebeat-regexp-metadata-variables/242172)

<div class="topic-metadata">

**Author:** [@gladsheim](https://discuss.elastic.co/u/gladsheim)\
**Replies:** 0\
**Last updated:** [July 22, 2020, 11:01am UTC](https://discuss.elastic.co/t/filebeat-regexp-metadata-variables/242172 "2020-07-22T11:01:49Z")

</div>

Hi i run filebeat on Kubernetes cluster. We use them for send logs to Kafka. Sorry, but I'm rookie on Filebeat :). In our Kubernetes cluster we have a namespace naming convention: - , for example: dev-deathstar. O…

---

## [Filebeat sets the multi-line mode, the unmatched rows are also multi-line, the match result is abnormal](https://discuss.elastic.co/t/filebeat-sets-the-multi-line-mode-the-unmatched-rows-are-also-multi-line-the-match-result-is-abnormal/239090)

<div class="topic-metadata">

**Author:** [@lklkxcxc](https://discuss.elastic.co/u/lklkxcxc)\
**Replies:** 3\
**Last updated:** [July 21, 2020, 10:09am UTC](https://discuss.elastic.co/t/filebeat-sets-the-multi-line-mode-the-unmatched-rows-are-also-multi-line-the-match-result-is-abnormal/239090 "2020-07-21T10:09:33Z")

</div>

set multiline filebeat config: multiline.pattern: '^\[0-9\]{4}-\[0-9\]{2}-\[0-9\]{2}|^\[0-9\]{4}/\[0-9\]{2}/\[0-9\]{2}' multiline.negate: true multiline.match: after As a result, the following log was matched as multiple lines i…

---

## [Group multiple metric to one event](https://discuss.elastic.co/t/group-multiple-metric-to-one-event/241842)

<div class="topic-metadata">

**Author:** [@CHU\_XU](https://discuss.elastic.co/u/CHU_XU)\
**Replies:** 3\
**Last updated:** [July 22, 2020, 7:11am UTC](https://discuss.elastic.co/t/group-multiple-metric-to-one-event/241842 "2020-07-22T07:11:40Z")

</div>

Hi all, I'm using metricbeat to collect some instance metrics with system module. When I set cpu, memory and network in the metricsets, I found that metricbeat actually emit three lines of log repestively. Can I merge t…

---

## [Can metricbeat copy fields from basic fields like event or agent?](https://discuss.elastic.co/t/can-metricbeat-copy-fields-from-basic-fields-like-event-or-agent/242137)

<div class="topic-metadata">

**Author:** [@CHU\_XU](https://discuss.elastic.co/u/CHU_XU)\
**Replies:** 0\
**Last updated:** [July 22, 2020, 5:53am UTC](https://discuss.elastic.co/t/can-metricbeat-copy-fields-from-basic-fields-like-event-or-agent/242137 "2020-07-22T05:53:46Z")

</div>

Hi experts, I'd like to copy the host name to event root when using system module. - copy\_fields: fields: - from: agent.name to: name fail\_on\_error: true ignore\_missing: false Output is: "ec…

---

## [Filebeat on Kubernetes with SSL to remote Elastic server](https://discuss.elastic.co/t/filebeat-on-kubernetes-with-ssl-to-remote-elastic-server/242126)

<div class="topic-metadata">

**Author:** [@rainfarmer](https://discuss.elastic.co/u/rainfarmer)\
**Replies:** 0\
**Last updated:** [July 22, 2020, 2:14am UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes-with-ssl-to-remote-elastic-server/242126 "2020-07-22T02:14:30Z")

</div>

Hello! I'm trying to my filebeat kubernetes daemonset to talk to my remote elastic search server. It works when ssl is off. When ssl is on, it gets cert error. I downloaded the ca.crt from elastic. But I'm not sure h…

---

## [O365 get tenant authen token through proxy](https://discuss.elastic.co/t/o365-get-tenant-authen-token-through-proxy/239289)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 3\
**Last updated:** [July 22, 2020, 1:30am UTC](https://discuss.elastic.co/t/o365-get-tenant-authen-token-through-proxy/239289 "2020-07-22T01:30:28Z")

</div>

Hi all. I have been trying to get o365 log using filebeat and there is apear to be a problems, the current filebeat that i am ussing need to get the authentication token but our serrver are put behind a proxy, is there…

---

## [Metricbeat reporting incorrect system.diskio.iostat.queue.avg\_size values](https://discuss.elastic.co/t/metricbeat-reporting-incorrect-system-diskio-iostat-queue-avg-size-values/242107)

<div class="topic-metadata">

**Author:** [@mferreira22](https://discuss.elastic.co/u/mferreira22)\
**Replies:** 0\
**Last updated:** [July 21, 2020, 10:27pm UTC](https://discuss.elastic.co/t/metricbeat-reporting-incorrect-system-diskio-iostat-queue-avg-size-values/242107 "2020-07-21T22:27:14Z")

</div>

I'm using Elastic's machine learning to detect anomalies in system usage data, one of the fields being system.diskio.iostat.queue.avg\_size. The data we are receiving occasionally reports anomalies in the disk IO average…

---

## [Can winlogbeat push direct to http?](https://discuss.elastic.co/t/can-winlogbeat-push-direct-to-http/242081)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 1\
**Last updated:** [July 21, 2020, 7:37pm UTC](https://discuss.elastic.co/t/can-winlogbeat-push-direct-to-http/242081 "2020-07-21T19:37:50Z")

</div>

Hi, Is there any out of the box functionality for Winlogbeat to push direct to a http endpoint? (our personal API) Thanks

---

## [Metricbeat-Filebeat Install & Run as Docker Container](https://discuss.elastic.co/t/metricbeat-filebeat-install-run-as-docker-container/241919)

<div class="topic-metadata">

**Author:** [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Replies:** 2\
**Last updated:** [July 21, 2020, 6:02pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat-install-run-as-docker-container/241919 "2020-07-21T18:02:35Z")

</div>

Task Objective: using aws module (metricbeat + filebeat), I would like to pull logs and metrics from multiple aws accounts from one server. Thus reducing the server cost of running beats in each aws account. To achieve…

---

## [AWS Cost and Usage Details with Metricbeat](https://discuss.elastic.co/t/aws-cost-and-usage-details-with-metricbeat/241930)

<div class="topic-metadata">

**Author:** [@stevewritescode](https://discuss.elastic.co/u/stevewritescode)\
**Replies:** 2\
**Last updated:** [July 21, 2020, 2:23pm UTC](https://discuss.elastic.co/t/aws-cost-and-usage-details-with-metricbeat/241930 "2020-07-21T14:23:05Z")

</div>

Hi Beats pros! Is there any recommended way to pull and index AWS cost and usage report data into Elastic? I've been using the built-in AWS Billing Metricbeat module to pull in billing data from AWS. From what I can te…

---

## [Incoming logs from Cisco switches don't appear in filebeat-\* indexes](https://discuss.elastic.co/t/incoming-logs-from-cisco-switches-dont-appear-in-filebeat-indexes/241679)

<div class="topic-metadata">

**Author:** [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Replies:** 2\
**Last updated:** [July 21, 2020, 12:43pm UTC](https://discuss.elastic.co/t/incoming-logs-from-cisco-switches-dont-appear-in-filebeat-indexes/241679 "2020-07-21T12:43:11Z")

</div>

Dear all, I have ELK 7.8.0 and I've configured cisco asa module from Filebeat 7.8.0 in order to receive incoming logs from Cisco switches. Here it is the /etc/filebeat/modules.d/cisco.yml below module.cisco line: ios: …

---

## [Filebeat Event Hub - 409 The specified blob already exists](https://discuss.elastic.co/t/filebeat-event-hub-409-the-specified-blob-already-exists/241942)

<div class="topic-metadata">

**Author:** [@CSelastic](https://discuss.elastic.co/u/CSelastic)\
**Replies:** 1\
**Last updated:** [July 21, 2020, 11:03am UTC](https://discuss.elastic.co/t/filebeat-event-hub-409-the-specified-blob-already-exists/241942 "2020-07-21T11:03:13Z")

</div>

Hi -- I'm running filebeat 7.6.2 and am encountering an issue with the Azure Event Hub input plugin. I believe this was caused due to unclean shutdown. I'm seeing the following errors, and messages are not pulled in from…

---

## [Filebeat add docker metada fail](https://discuss.elastic.co/t/filebeat-add-docker-metada-fail/241958)

<div class="topic-metadata">

**Author:** [@tungpzostar](https://discuss.elastic.co/u/tungpzostar)\
**Replies:** 1\
**Last updated:** [July 21, 2020, 10:57am UTC](https://discuss.elastic.co/t/filebeat-add-docker-metada-fail/241958 "2020-07-21T10:57:49Z")

</div>

Hello everybody, I'm having this issue when try to get docker metada. This is myconfiguration: filebeat.inputs: - type: docker combine\_partial: true containers: path: "/usr/share/dockerlogs/data" stream: "al…

---

## [Before Mapping](https://discuss.elastic.co/t/before-mapping/241837)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 3\
**Last updated:** [July 21, 2020, 10:52am UTC](https://discuss.elastic.co/t/before-mapping/241837 "2020-07-21T10:52:29Z")

</div>

I am using filebeat and i would like to know that to create a mapping do i need to know the field name or should i start the filebeat and analyse that these the fields are coming i can see in kibana discover and after th…

---

## [Is metricbeat version related to elasticsearch?](https://discuss.elastic.co/t/is-metricbeat-version-related-to-elasticsearch/241965)

<div class="topic-metadata">

**Author:** [@CHU\_XU](https://discuss.elastic.co/u/CHU_XU)\
**Replies:** 1\
**Last updated:** [July 21, 2020, 5:07am UTC](https://discuss.elastic.co/t/is-metricbeat-version-related-to-elasticsearch/241965 "2020-07-21T05:07:36Z")

</div>

Hi there, If I use metricbeat to monitor elasticsearch, do I need ensure they are the same version or not? For example I'm using es 7.5.2, how should I choose metricbeat version, the master or also 7.5.2? Thanks C.

---

## [Metricbeat-oss missing aws module](https://discuss.elastic.co/t/metricbeat-oss-missing-aws-module/241750)

<div class="topic-metadata">

**Author:** [@rishabh](https://discuss.elastic.co/u/rishabh)\
**Replies:** 2\
**Last updated:** [July 21, 2020, 2:51am UTC](https://discuss.elastic.co/t/metricbeat-oss-missing-aws-module/241750 "2020-07-21T02:51:59Z")

</div>

Hi, I am using metricbeat-oss 7.8. but aws module is missing. Can some please help how I can monitor AWS Infrastruture like aws cloudwatch do. I want to monitor service of aws like ec2, vpc, rds, s3. Please help in t…

---

## [Filebeat cannot send data to logstash](https://discuss.elastic.co/t/filebeat-cannot-send-data-to-logstash/241463)

<div class="topic-metadata">

**Author:** [@binschlag](https://discuss.elastic.co/u/binschlag)\
**Replies:** 1\
**Last updated:** [July 21, 2020, 1:25am UTC](https://discuss.elastic.co/t/filebeat-cannot-send-data-to-logstash/241463 "2020-07-21T01:25:56Z")

</div>

My filebeat - agents cannot send data to logstash anymore. In logstash.log i can see failed to parse field \[agent\] of type \[text\] in document with id whole message: \[2020-07-16T15:04:41,302\]\[WARN \]\[logstash.outputs.e…

---

## [FileBeat fails to process large log files of some MBs](https://discuss.elastic.co/t/filebeat-fails-to-process-large-log-files-of-some-mbs/240122)

<div class="topic-metadata">

**Author:** [@shwethaN](https://discuss.elastic.co/u/shwethaN)\
**Replies:** 9\
**Last updated:** [July 20, 2020, 11:05am UTC](https://discuss.elastic.co/t/filebeat-fails-to-process-large-log-files-of-some-mbs/240122 "2020-07-20T11:05:35Z")

</div>

Hi, I am new to ELK stack. Done the setup of elastic, Kibana , Logstash and filebeat to process the files. If i configure path of log file which in some KBs(2-3KB) then i am able to process file successfully. I would l…

---

## [Auditbeat 6.8.10 / Windows / File intergrity / kafka output / changing file attrubutes info](https://discuss.elastic.co/t/auditbeat-6-8-10-windows-file-intergrity-kafka-output-changing-file-attrubutes-info/240166)

<div class="topic-metadata">

**Author:** [@MaGu](https://discuss.elastic.co/u/MaGu)\
**Replies:** 1\
**Last updated:** [July 20, 2020, 10:53am UTC](https://discuss.elastic.co/t/auditbeat-6-8-10-windows-file-intergrity-kafka-output-changing-file-attrubutes-info/240166 "2020-07-20T10:53:15Z")

</div>

Hi guys I have auditbeat (v6.8.10) installed and configured on a windows host to send data to kafka (kafka output). I noticed that changing file attributes triggers an event which is sent to kafka but I do not see any s…

---

## [Getting a value in each document based on other fields calculation](https://discuss.elastic.co/t/getting-a-value-in-each-document-based-on-other-fields-calculation/241799)

<div class="topic-metadata">

**Author:** [@igorid70](https://discuss.elastic.co/u/igorid70)\
**Replies:** 1\
**Last updated:** [July 20, 2020, 9:31am UTC](https://discuss.elastic.co/t/getting-a-value-in-each-document-based-on-other-fields-calculation/241799 "2020-07-20T09:31:29Z")

</div>

Hi I need to get a value in each document which is a calculation based on some other metricbeat feilds. The problem is that I can't use scripted fields because I don't need it for visualization/Kibana but accessing thos…

---

## [Custom Metricbeat metricsets](https://discuss.elastic.co/t/custom-metricbeat-metricsets/241822)

<div class="topic-metadata">

**Author:** [@chathsuom](https://discuss.elastic.co/u/chathsuom)\
**Replies:** 1\
**Last updated:** [July 20, 2020, 9:30am UTC](https://discuss.elastic.co/t/custom-metricbeat-metricsets/241822 "2020-07-20T09:30:04Z")

</div>

Creating a custom metricset according to the document is not working in 7.8. It looks either documentation needs an update or something wrong with the Makefile https://www.elastic.co/guide/en/beats/devguide/7.8/creating…

---

## [HTTP error 403 in pod - Metricbeat in Openshift](https://discuss.elastic.co/t/http-error-403-in-pod-metricbeat-in-openshift/241631)

<div class="topic-metadata">

**Author:** [@alexloz93](https://discuss.elastic.co/u/alexloz93)\
**Replies:** 2\
**Last updated:** [July 20, 2020, 8:09am UTC](https://discuss.elastic.co/t/http-error-403-in-pod-metricbeat-in-openshift/241631 "2020-07-20T08:09:25Z")

</div>

Hi. I'm trying to run the Kubernetes module in the Openshift metricbeat configuration. When I consult in kibana, it shows me the following error: "key": "HTTP error 403 in volume: 403 Forbidden", "doc\_count…

---

## [Can Metricbeat collect elasticsearch shard size?](https://discuss.elastic.co/t/can-metricbeat-collect-elasticsearch-shard-size/241579)

<div class="topic-metadata">

**Author:** [@CHU\_XU](https://discuss.elastic.co/u/CHU_XU)\
**Replies:** 5\
**Last updated:** [July 20, 2020, 7:55am UTC](https://discuss.elastic.co/t/can-metricbeat-collect-elasticsearch-shard-size/241579 "2020-07-20T07:55:49Z")

</div>

Hi experts, I'm considering use metricbeat to monitor my es cluster and for some reason I care about the shard size of our indices. Seems that Elasticsearch module of metricbeat does not collect such info. Any idea how …

---

## [Can I pass application logs to filebeat?](https://discuss.elastic.co/t/can-i-pass-application-logs-to-filebeat/241574)

<div class="topic-metadata">

**Author:** [@Bhavin\_Varsur](https://discuss.elastic.co/u/Bhavin_Varsur)\
**Replies:** 7\
**Last updated:** [July 20, 2020, 7:27am UTC](https://discuss.elastic.co/t/can-i-pass-application-logs-to-filebeat/241574 "2020-07-20T07:27:04Z")

</div>

I want to pass application logs to filebeat . Can I pass ? if yes then how should I pass?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=226)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=228)
