# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=228

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 229

---

## [Error connecting to Kibana: fail to get the Kibana version](https://discuss.elastic.co/t/error-connecting-to-kibana-fail-to-get-the-kibana-version/241747)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [July 18, 2020, 3:48pm UTC](https://discuss.elastic.co/t/error-connecting-to-kibana-fail-to-get-the-kibana-version/241747 "2020-07-18T15:48:03Z")

</div>

I have elasticsearch and kibana setup in my kubernetes cluster using ECK. I'm also trying to get filebeat setup. Im having trouble with getting filebeat to connect to kibana. in the filebeat logs i can see the following …

---

## [Metricbeat beat module works for metricbeat but not for filebeat](https://discuss.elastic.co/t/metricbeat-beat-module-works-for-metricbeat-but-not-for-filebeat/239376)

<div class="topic-metadata">

**Author:** [@eyesmoker](https://discuss.elastic.co/u/eyesmoker)\
**Replies:** 1\
**Last updated:** [July 19, 2020, 7:16am UTC](https://discuss.elastic.co/t/metricbeat-beat-module-works-for-metricbeat-but-not-for-filebeat/239376 "2020-07-19T07:16:11Z")

</div>

I have this configuration for metricbeat beat module. It shows up absolutely fine on the kibana. metricbeat.autodiscover: providers: - type: kubernetes templates: - condition: …

---

## [Metricbeat failed to connect elastic search & kibana](https://discuss.elastic.co/t/metricbeat-failed-to-connect-elastic-search-kibana/241629)

<div class="topic-metadata">

**Author:** [@pankaj0172](https://discuss.elastic.co/u/pankaj0172)\
**Replies:** 1\
**Last updated:** [July 18, 2020, 12:03pm UTC](https://discuss.elastic.co/t/metricbeat-failed-to-connect-elastic-search-kibana/241629 "2020-07-18T12:03:07Z")

</div>

Hi Team, I'm using ElasticSearch cluster with authentication and I'm able to access Kibana/Elastic search through the web interface but When I'm installing metric or Audit beat on any machine to send logs to elastic sea…

---

## [WEF no hosts showing up in SIEM](https://discuss.elastic.co/t/wef-no-hosts-showing-up-in-siem/241731)

<div class="topic-metadata">

**Author:** [@money1968](https://discuss.elastic.co/u/money1968)\
**Replies:** 0\
**Last updated:** [July 17, 2020, 10:35pm UTC](https://discuss.elastic.co/t/wef-no-hosts-showing-up-in-siem/241731 "2020-07-17T22:35:43Z")

</div>

I'm using WEF and upgraded to 7.8, loaded the new template, followed some suggestions and added host.name function process(event) { event.Put("host.name", event.Get("winlog.computer\_name")); …

---

## [Httpjson crashes when receiving json array at the top level](https://discuss.elastic.co/t/httpjson-crashes-when-receiving-json-array-at-the-top-level/241714)

<div class="topic-metadata">

**Author:** [@Sasha\_Gutfraind](https://discuss.elastic.co/u/Sasha_Gutfraind)\
**Replies:** 1\
**Last updated:** [July 17, 2020, 10:15pm UTC](https://discuss.elastic.co/t/httpjson-crashes-when-receiving-json-array-at-the-top-level/241714 "2020-07-17T22:15:51Z")

</div>

I'm using your excellent https://www.elastic.co/guide/en/beats/filebeat/7.6/filebeat-input-httpjson.html version 7.6.2 I'm calling this API: filebeat.yml has no processors, and is supposed to dump the event into ES …

---

## [Multiline is split from main log message - Any help please](https://discuss.elastic.co/t/multiline-is-split-from-main-log-message-any-help-please/241254)

<div class="topic-metadata">

**Author:** [@calanon](https://discuss.elastic.co/u/calanon)\
**Replies:** 4\
**Last updated:** [July 17, 2020, 8:00pm UTC](https://discuss.elastic.co/t/multiline-is-split-from-main-log-message-any-help-please/241254 "2020-07-17T20:00:43Z")

</div>

Here is a snippet of the raw log output: \[2020-07-15T08:21:58+02:00\] 172.16.35.104 ERROR Exception: \<log:context\>{"exception":"\[object\] (App\\\\Action\\\\Exception\\\\MethodNotAllowedException(code: 405): There is no action d…

---

## [Gpg check winlogbeat download... key file?](https://discuss.elastic.co/t/gpg-check-winlogbeat-download-key-file/241707)

<div class="topic-metadata">

**Author:** [@money1968](https://discuss.elastic.co/u/money1968)\
**Replies:** 1\
**Last updated:** [July 17, 2020, 7:59pm UTC](https://discuss.elastic.co/t/gpg-check-winlogbeat-download-key-file/241707 "2020-07-17T19:59:21Z")

</div>

Sorry for what I guess is a basic question... Is there any instructions anywhere for verifying the winlogbeats download? I downloaded the asc and the file buuut isn't there supposed to be a key somewhere? Thought I ne…

---

## [CrowdStrike Module unable to convert value \[\]: value is not a valid IP address](https://discuss.elastic.co/t/crowdstrike-module-unable-to-convert-value-value-is-not-a-valid-ip-address/239187)

<div class="topic-metadata">

**Author:** [@James\_Cribbs](https://discuss.elastic.co/u/James_Cribbs)\
**Replies:** 4\
**Last updated:** [July 17, 2020, 7:48pm UTC](https://discuss.elastic.co/t/crowdstrike-module-unable-to-convert-value-value-is-not-a-valid-ip-address/239187 "2020-07-17T19:48:46Z")

</div>

The CrowdStrike Filebeat (version 7.8) module appears to have two issues. Null / non-existent values in event.UserIP field causing parse errors during ingest. Parsing of UTCTimestamp to crowdstrike.event.UTCTimestamp (…

---

## [Filebeat favors single logstash node after significant backpressure](https://discuss.elastic.co/t/filebeat-favors-single-logstash-node-after-significant-backpressure/241716)

<div class="topic-metadata">

**Author:** [@Derek\_Gallo](https://discuss.elastic.co/u/Derek_Gallo)\
**Replies:** 0\
**Last updated:** [July 17, 2020, 7:36pm UTC](https://discuss.elastic.co/t/filebeat-favors-single-logstash-node-after-significant-backpressure/241716 "2020-07-17T19:36:53Z")

</div>

We are running Filebeat via a daemonset in Kubernetes. We are running logstash as a statefulset with persistent queues and 12 nodes. Filebeat is configured with the hostname to each logstash node and loadbalance is set…

---

## [Mapper\_parsing\_exception error](https://discuss.elastic.co/t/mapper-parsing-exception-error/241703)

<div class="topic-metadata">

**Author:** [@AjitR](https://discuss.elastic.co/u/AjitR)\
**Replies:** 0\
**Last updated:** [July 17, 2020, 5:53pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-error/241703 "2020-07-17T17:53:16Z")

</div>

Hi All, I an getting error in Kibana as, Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0x38baf060, ext:63730582410, loc:(\*time.Location)(nil)}, Meta:common.MapStr(nil), Fields:common.Ma…

---

## [SASL GSSAPI mechanism added in Beats 7.8?](https://discuss.elastic.co/t/sasl-gssapi-mechanism-added-in-beats-7-8/241692)

<div class="topic-metadata">

**Author:** [@savvy](https://discuss.elastic.co/u/savvy)\
**Replies:** 0\
**Last updated:** [July 17, 2020, 4:02pm UTC](https://discuss.elastic.co/t/sasl-gssapi-mechanism-added-in-beats-7-8/241692 "2020-07-17T16:02:26Z")

</div>

Hi, Is SASL GSSAPI mechanism to produce data to kafka added in latest Beats 7.8? If no, what is the ETA for this?

---

## [Filebeat vs Winlogbeat with ingest pipelines](https://discuss.elastic.co/t/filebeat-vs-winlogbeat-with-ingest-pipelines/241329)

<div class="topic-metadata">

**Author:** [@sera](https://discuss.elastic.co/u/sera)\
**Replies:** 1\
**Last updated:** [July 17, 2020, 3:06pm UTC](https://discuss.elastic.co/t/filebeat-vs-winlogbeat-with-ingest-pipelines/241329 "2020-07-17T15:06:54Z")

</div>

I understand the Filebeat and its sample dashboards do not function properly without ingest pipelines. Is this also the case with Winlogbeat? I have Winlogbeat working well, and the sample dashboard is populating nicely,…

---

## [No logs in filebeat index even though it has docs](https://discuss.elastic.co/t/no-logs-in-filebeat-index-even-though-it-has-docs/241675)

<div class="topic-metadata">

**Author:** [@misheck](https://discuss.elastic.co/u/misheck)\
**Replies:** 0\
**Last updated:** [July 17, 2020, 2:50pm UTC](https://discuss.elastic.co/t/no-logs-in-filebeat-index-even-though-it-has-docs/241675 "2020-07-17T14:50:41Z")

</div>

I am using filebeat docker image with syslog enabled. When I run a search under discover I am not getting any results even though I know there is logs because if I run a search in Dev Tools I can see some of the log mess…

---

## [Can't ship logs with filebeat to logstash](https://discuss.elastic.co/t/cant-ship-logs-with-filebeat-to-logstash/241608)

<div class="topic-metadata">

**Author:** [@elk6](https://discuss.elastic.co/u/elk6)\
**Replies:** 10\
**Last updated:** [July 17, 2020, 1:43pm UTC](https://discuss.elastic.co/t/cant-ship-logs-with-filebeat-to-logstash/241608 "2020-07-17T13:43:39Z")

</div>

I'm trying to make filebeat send log to logstash on another machine and I just can't get it to work. This is the filebeat.yml configuration: https://pastebin.com/8a2RtGBa (Using pastebin because of character limit) Thi…

---

## [Auditbeat - Triggering file integrity event.action:updated when hash.sha1 is unchanged](https://discuss.elastic.co/t/auditbeat-triggering-file-integrity-event-action-updated-when-hash-sha1-is-unchanged/241656)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [July 17, 2020, 2:03pm UTC](https://discuss.elastic.co/t/auditbeat-triggering-file-integrity-event-action-updated-when-hash-sha1-is-unchanged/241656 "2020-07-17T14:03:57Z")

</div>

I think this is a submitted bug but it's 4 months old and no one has addressed it and it's pretty damn important. https://github.com/elastic/beats/issues/17347 auditbeat seems to be identifying file integrity changes wh…

---

## [Metricbeat-7.2.0-windows-x86\_64 turn off with code exception in windows server 2016](https://discuss.elastic.co/t/metricbeat-7-2-0-windows-x86-64-turn-off-with-code-exception-in-windows-server-2016/239939)

<div class="topic-metadata">

**Author:** [@peter-wang-wsl](https://discuss.elastic.co/u/peter-wang-wsl)\
**Replies:** 2\
**Last updated:** [July 17, 2020, 1:27pm UTC](https://discuss.elastic.co/t/metricbeat-7-2-0-windows-x86-64-turn-off-with-code-exception-in-windows-server-2016/239939 "2020-07-17T13:27:43Z")

</div>

I run metricbeat with admin privilage, after a few hours metric beat turn off with code exception. Please help figrue out the problem, thanks a lot. For the limit I can not post all debug log 2020-07-04T18:31:48.591+08…

---

## [Filebeat is not processing the logs which suppose to be sending to LogStash hosted in same Machine](https://discuss.elastic.co/t/filebeat-is-not-processing-the-logs-which-suppose-to-be-sending-to-logstash-hosted-in-same-machine/241637)

<div class="topic-metadata">

**Author:** [@ramkumar.J](https://discuss.elastic.co/u/ramkumar.J)\
**Replies:** 5\
**Last updated:** [July 17, 2020, 1:05pm UTC](https://discuss.elastic.co/t/filebeat-is-not-processing-the-logs-which-suppose-to-be-sending-to-logstash-hosted-in-same-machine/241637 "2020-07-17T13:05:10Z")

</div>

My filebeat configuration has been working fine. But it suddenly stopped working now. I am confirming this by seeing the filebeat logs, there is no harvester logs. But I used to see the harvester logs before. When i r…

---

## [Metricbeat Prometheus Collector Metricset](https://discuss.elastic.co/t/metricbeat-prometheus-collector-metricset/241614)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 1\
**Last updated:** [July 17, 2020, 11:47am UTC](https://discuss.elastic.co/t/metricbeat-prometheus-collector-metricset/241614 "2020-07-17T11:47:05Z")

</div>

Hi, everyone I have a doubt about feature Histograms and Types. I have been working with it in order to collect metrics of CoreDNS and Weave (Kubernetes Tools). I would like to use use\_types: true and rate\_counters: t…

---

## [Filebeat, Kibana and ElasticSearch are configured, but not reading log files](https://discuss.elastic.co/t/filebeat-kibana-and-elasticsearch-are-configured-but-not-reading-log-files/241344)

<div class="topic-metadata">

**Author:** [@byc-art](https://discuss.elastic.co/u/byc-art)\
**Replies:** 5\
**Last updated:** [July 17, 2020, 11:30am UTC](https://discuss.elastic.co/t/filebeat-kibana-and-elasticsearch-are-configured-but-not-reading-log-files/241344 "2020-07-17T11:30:08Z")

</div>

Hi there, I'm setting up filebeats to read log files from Ubuntu machine and send them to ElasticSearch/ Kibana. I made a few changes to .yml settings after reading through previous posts https://github.com/elastic/beat…

---

## [Will metricbeat send redundant metrics if deploy to each elasticsearch node](https://discuss.elastic.co/t/will-metricbeat-send-redundant-metrics-if-deploy-to-each-elasticsearch-node/241627)

<div class="topic-metadata">

**Author:** [@CHU\_XU](https://discuss.elastic.co/u/CHU_XU)\
**Replies:** 1\
**Last updated:** [July 17, 2020, 10:09am UTC](https://discuss.elastic.co/t/will-metricbeat-send-redundant-metrics-if-deploy-to-each-elasticsearch-node/241627 "2020-07-17T10:09:47Z")

</div>

Hi there, As described in the graphic metricbeat is deployed to each es node. For some cluster info like "status", will all these metricbeat get cluster status and send to endpoint? If I have a large es cluster, ther…

---

## [Filebeat is not processing the logs which suppose to be sending to LogStash hosted in same Machine](https://discuss.elastic.co/t/filebeat-is-not-processing-the-logs-which-suppose-to-be-sending-to-logstash-hosted-in-same-machine/241620)

<div class="topic-metadata">

**Author:** [@ramkumar.J](https://discuss.elastic.co/u/ramkumar.J)\
**Replies:** 0\
**Last updated:** [July 17, 2020, 9:10am UTC](https://discuss.elastic.co/t/filebeat-is-not-processing-the-logs-which-suppose-to-be-sending-to-logstash-hosted-in-same-machine/241620 "2020-07-17T09:10:53Z")

</div>

My filebeat configuration has been working fine. But it suddenly stopped working now. I am confirming this by seeing the filebeat logs, there is no harvester logs. But I used to see the harvester logs before. This is …

---

## [Problem Loading packetbeat index from different instances](https://discuss.elastic.co/t/problem-loading-packetbeat-index-from-different-instances/241466)

<div class="topic-metadata">

**Author:** [@elkoussaimi\_ayoub](https://discuss.elastic.co/u/elkoussaimi_ayoub)\
**Replies:** 0\
**Last updated:** [July 16, 2020, 1:10pm UTC](https://discuss.elastic.co/t/problem-loading-packetbeat-index-from-different-instances/241466 "2020-07-16T13:10:40Z")

</div>

Hi Guys, For now, I successfully deploy the elk stack and I've loaded the packetbeat index for a machine that I've got on AWS ec2 service, but when I want to load the same index to elasticsearch, it gets replaced every …

---

## [Trying to use filebeat postgresql conf.d to push logs to kibana](https://discuss.elastic.co/t/trying-to-use-filebeat-postgresql-conf-d-to-push-logs-to-kibana/240550)

<div class="topic-metadata">

**Author:** [@Andrew\_Freitas](https://discuss.elastic.co/u/Andrew_Freitas)\
**Replies:** 10\
**Last updated:** [July 17, 2020, 8:50am UTC](https://discuss.elastic.co/t/trying-to-use-filebeat-postgresql-conf-d-to-push-logs-to-kibana/240550 "2020-07-17T08:50:49Z")

</div>

Hey guys, I'm trying to configure filebeat output to logstash, the full pipeline is as follows: filebeat \> redis cache \> logstash \> elastic \> kibana Below is a screenshot of what I get in kibana About two logs com…

---

## [Collecting from syslog data-lake](https://discuss.elastic.co/t/collecting-from-syslog-data-lake/241363)

<div class="topic-metadata">

**Author:** [@kelk](https://discuss.elastic.co/u/kelk)\
**Replies:** 5\
**Last updated:** [July 17, 2020, 7:27am UTC](https://discuss.elastic.co/t/collecting-from-syslog-data-lake/241363 "2020-07-17T07:27:32Z")

</div>

hi we got a datalake from syslog datasets and the devices/endpoints are logging in format of /data/\<collect\_port\>/\<ip\_address\>/\<severity\>.\<facility\>.log eg /data/514/172.128.4.2/auth.info.log And within the datasets…

---

## [RabbitMq Metricbeat error in logs](https://discuss.elastic.co/t/rabbitmq-metricbeat-error-in-logs/241503)

<div class="topic-metadata">

**Author:** [@mdymel](https://discuss.elastic.co/u/mdymel)\
**Replies:** 1\
**Last updated:** [July 17, 2020, 7:14am UTC](https://discuss.elastic.co/t/rabbitmq-metricbeat-error-in-logs/241503 "2020-07-17T07:14:55Z")

</div>

With Metricbeat 7.8 and RabbitMq 3.8.1 I am getting errors in metricbeat.log: 2020-07-16T13:46:46.712+0200 ERROR \[rabbitmq.queue\] queue/data.go:97 error in mapping: error applying schema: 6 errors: key messages\_unacknow…

---

## [RabbitMQ MetricBeat messages totals](https://discuss.elastic.co/t/rabbitmq-metricbeat-messages-totals/241446)

<div class="topic-metadata">

**Author:** [@mdymel](https://discuss.elastic.co/u/mdymel)\
**Replies:** 2\
**Last updated:** [July 17, 2020, 5:38am UTC](https://discuss.elastic.co/t/rabbitmq-metricbeat-messages-totals/241446 "2020-07-17T05:38:11Z")

</div>

Is it possible to visualize total message counts in Kibana when using RabbitMQ MetricBeat? The RMQ Management Plugin displays it at the top of the overview: But I can't find this information in the node metrics.

---

## [How to check filebeat log delivery rate](https://discuss.elastic.co/t/how-to-check-filebeat-log-delivery-rate/241458)

<div class="topic-metadata">

**Author:** [@mahi7](https://discuss.elastic.co/u/mahi7)\
**Replies:** 2\
**Last updated:** [July 17, 2020, 5:30am UTC](https://discuss.elastic.co/t/how-to-check-filebeat-log-delivery-rate/241458 "2020-07-17T05:30:57Z")

</div>

Hello , I have started using filebeat recently , How can i check on what rate my filebeat is sending data to my logstash server. This is my filebeat.yml file filebeat: prospectors: - paths: - /hom…

---

## [Heartbeat to Logstash disappears in Elasticsearch (Indices)](https://discuss.elastic.co/t/heartbeat-to-logstash-disappears-in-elasticsearch-indices/241359)

<div class="topic-metadata">

**Author:** [@Asinus1223](https://discuss.elastic.co/u/Asinus1223)\
**Replies:** 3\
**Last updated:** [July 16, 2020, 10:38pm UTC](https://discuss.elastic.co/t/heartbeat-to-logstash-disappears-in-elasticsearch-indices/241359 "2020-07-16T22:38:55Z")

</div>

How can I get Heartbeat to output to Logstash where I can manipulate it some? Right now the only way I can anything to appear in Elasticsearch/Kibana is to output directly to Elasticsearch and keep the default index nam…

---

## [Filebeat, Cisco ASA and ECS fields](https://discuss.elastic.co/t/filebeat-cisco-asa-and-ecs-fields/238381)

<div class="topic-metadata">

**Author:** [@rossw](https://discuss.elastic.co/u/rossw)\
**Replies:** 5\
**Last updated:** [July 16, 2020, 7:40pm UTC](https://discuss.elastic.co/t/filebeat-cisco-asa-and-ecs-fields/238381 "2020-07-16T19:40:38Z")

</div>

Filebeat 7.7, Cisco ASA logs ASA syslog -\> logstash for filtering -\> filebeat (as original raw syslog) -\> cisco module/asa -\> logstash -\> ES According to the recommendations from Elastic, the firewall should be the "ob…

---

## [Decode\_json\_fields not processing nested array?](https://discuss.elastic.co/t/decode-json-fields-not-processing-nested-array/241367)

<div class="topic-metadata">

**Author:** [@adamparmelee](https://discuss.elastic.co/u/adamparmelee)\
**Replies:** 2\
**Last updated:** [July 16, 2020, 4:22pm UTC](https://discuss.elastic.co/t/decode-json-fields-not-processing-nested-array/241367 "2020-07-16T16:22:42Z")

</div>

Hi. I've been struggling with this for a bit now. Nothing I've tried from forum scouring has done the trick. here's a log entry: {"transaction":{"client\_ip":"x.x.x.x","time\_stamp":"Wed Jul 15 19:08:29 2020","server\_id"…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=227)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=229)
