# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=229

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 230

---

## [Out-of-the-box fail with metricbeat 7.8](https://discuss.elastic.co/t/out-of-the-box-fail-with-metricbeat-7-8/241499)

<div class="topic-metadata">

**Author:** [@Sushimaster](https://discuss.elastic.co/u/Sushimaster)\
**Replies:** 0\
**Last updated:** [July 16, 2020, 4:03pm UTC](https://discuss.elastic.co/t/out-of-the-box-fail-with-metricbeat-7-8/241499 "2020-07-16T16:03:55Z")

</div>

Hi there, just installed metricbeat 7.8 on a client and just changed ip to elasticsearch server, nothing more. Cannot connect to server: Connection marked as failed because the onConnect callback failed: resource 'met…

---

## [Shipping with FileBeats to Azure Marketplace Offering](https://discuss.elastic.co/t/shipping-with-filebeats-to-azure-marketplace-offering/241195)

<div class="topic-metadata">

**Author:** [@JakeWickLB](https://discuss.elastic.co/u/JakeWickLB)\
**Replies:** 4\
**Last updated:** [July 16, 2020, 3:48pm UTC](https://discuss.elastic.co/t/shipping-with-filebeats-to-azure-marketplace-offering/241195 "2020-07-16T15:48:09Z")

</div>

I have deployed the Azure Marketplace ElasticSearch cluster, and am trying to configure my FileBeat to ship to it. I am confused about how to ship logs to LogStash. My filebeat is on a separate network from the logstash…

---

## [Exiting: error unpacking config data: more than one namespace configured accessing 'output' (source:'filebeat.yml')](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640)

<div class="topic-metadata">

**Author:** [@Bhavin\_Varsur](https://discuss.elastic.co/u/Bhavin_Varsur)\
**Replies:** 7\
**Last updated:** [July 16, 2020, 2:04pm UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640 "2020-07-16T14:04:00Z")

</div>

when i enable elasticsearch output and logstash output in filebeat.yml i get this error. Exiting: error unpacking config data: more than one namespace configured accessing 'output' (source:'filebeat.yml') please give m…

---

## [Parameter is missing in config for application/json content-type file Filebeat S3](https://discuss.elastic.co/t/parameter-is-missing-in-config-for-application-json-content-type-file-filebeat-s3/241427)

<div class="topic-metadata">

**Author:** [@Scrubsboy](https://discuss.elastic.co/u/Scrubsboy)\
**Replies:** 1\
**Last updated:** [July 16, 2020, 1:54pm UTC](https://discuss.elastic.co/t/parameter-is-missing-in-config-for-application-json-content-type-file-filebeat-s3/241427 "2020-07-16T13:54:30Z")

</div>

Hello, I face some issues with Filebeat, I installed it et and configure the Filebeat.yml but when i run filbeat with the command : ./filebeat -e i have this errors and no results are found in Kibana \*\*2020-07-16T11:09…

---

## [Efficiency (Processing Time) of Filebeat and Logstash](https://discuss.elastic.co/t/efficiency-processing-time-of-filebeat-and-logstash/241263)

<div class="topic-metadata">

**Author:** [@pulkit007](https://discuss.elastic.co/u/pulkit007)\
**Replies:** 3\
**Last updated:** [July 16, 2020, 1:06pm UTC](https://discuss.elastic.co/t/efficiency-processing-time-of-filebeat-and-logstash/241263 "2020-07-16T13:06:36Z")

</div>

I have couple of questions regarding Filebeat and Logstash. How can we find the exact time Filebeat takes to process (send logs from Logfile to Logstash) a certain set of logs? How can we find the time which Logsta…

---

## [Multiple concurrent modules](https://discuss.elastic.co/t/multiple-concurrent-modules/241449)

<div class="topic-metadata">

**Author:** [@hazcod](https://discuss.elastic.co/u/hazcod)\
**Replies:** 0\
**Last updated:** [July 16, 2020, 12:10pm UTC](https://discuss.elastic.co/t/multiple-concurrent-modules/241449 "2020-07-16T12:10:46Z")

</div>

Hi, I have following config for running concurrent checkpoint modules: filebeat.modules: - module: checkpoint firewall: ....port: 9001 - module: checkpoint firewall: ......port: 9002 However I only see por…

---

## [High CPU usage for auditbeat](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430)

<div class="topic-metadata">

**Author:** [@gbmzjy](https://discuss.elastic.co/u/gbmzjy)\
**Replies:** 6\
**Last updated:** [July 16, 2020, 10:40am UTC](https://discuss.elastic.co/t/high-cpu-usage-for-auditbeat/133430 "2020-07-16T10:40:04Z")

</div>

Hi, I am trying to use auditbeat to collect Linux Audit log and send them to our elasticsearch server. In order to compare performance with auditd, I tried the following configuration: auditbeat.modules: -module: audi…

---

## [Parsing Error in Fortinet-Module Pipeline blasts up message log](https://discuss.elastic.co/t/parsing-error-in-fortinet-module-pipeline-blasts-up-message-log/241411)

<div class="topic-metadata">

**Author:** [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Replies:** 1\
**Last updated:** [July 16, 2020, 8:44am UTC](https://discuss.elastic.co/t/parsing-error-in-fortinet-module-pipeline-blasts-up-message-log/241411 "2020-07-16T08:44:10Z")

</div>

Hey guys, First of a few details about my cluster: Cluster of 3 Servers - 1xMaster 2xData Nodes All of them are running ES 7.8 Filebeat 7.8 (ofc Kibana as well on the master node) OS: CentOS 7 (Kernel 3.10.0-957) I …

---

## [Run filebeat, enable module as non-root user](https://discuss.elastic.co/t/run-filebeat-enable-module-as-non-root-user/241407)

<div class="topic-metadata">

**Author:** [@J\_P](https://discuss.elastic.co/u/J_P)\
**Replies:** 1\
**Last updated:** [July 16, 2020, 7:47am UTC](https://discuss.elastic.co/t/run-filebeat-enable-module-as-non-root-user/241407 "2020-07-16T07:47:35Z")

</div>

Hey, I would like to edit configuration files, enable modules, run filebeat as a non-root user. Do you have any template what permissions are required?

---

## [Problems in using auditbeat to collect user commands](https://discuss.elastic.co/t/problems-in-using-auditbeat-to-collect-user-commands/241380)

<div class="topic-metadata">

**Author:** [@lovelysoda](https://discuss.elastic.co/u/lovelysoda)\
**Replies:** 0\
**Last updated:** [July 16, 2020, 3:14am UTC](https://discuss.elastic.co/t/problems-in-using-auditbeat-to-collect-user-commands/241380 "2020-07-16T03:14:30Z")

</div>

HI， About collecting user commands。 I think of two solutions，If there is any misunderstanding, please correct it。 First，we can use pam\_tty\_audit , configure the system-auth PAM configuration file to enable TTY audt…

---

## [Alternative to Filebeat on Solaris 11.3 SPARC](https://discuss.elastic.co/t/alternative-to-filebeat-on-solaris-11-3-sparc/241356)

<div class="topic-metadata">

**Author:** [@dhanshake](https://discuss.elastic.co/u/dhanshake)\
**Replies:** 1\
**Last updated:** [July 15, 2020, 9:08pm UTC](https://discuss.elastic.co/t/alternative-to-filebeat-on-solaris-11-3-sparc/241356 "2020-07-15T21:08:10Z")

</div>

Any alternative to Filebeat to read application logs from Solaris server ( Solaris 11.3 SPARC) ? P.S - logs weren't written to syslog.

---

## [Heartbeat is only detecting physical devices](https://discuss.elastic.co/t/heartbeat-is-only-detecting-physical-devices/241348)

<div class="topic-metadata">

**Author:** [@samspopguy](https://discuss.elastic.co/u/samspopguy)\
**Replies:** 0\
**Last updated:** [July 15, 2020, 6:21pm UTC](https://discuss.elastic.co/t/heartbeat-is-only-detecting-physical-devices/241348 "2020-07-15T18:21:57Z")

</div>

heartbeat detects any physical device as being up fine, but almost anything that's a virtual server its marking it as down. I think 1 of the 12 virtual servers is marked as up. I'm just using the http type for the server …

---

## [Filebeat too quick on recovering data](https://discuss.elastic.co/t/filebeat-too-quick-on-recovering-data/241133)

<div class="topic-metadata">

**Author:** [@Bader](https://discuss.elastic.co/u/Bader)\
**Replies:** 2\
**Last updated:** [July 15, 2020, 11:12am UTC](https://discuss.elastic.co/t/filebeat-too-quick-on-recovering-data/241133 "2020-07-15T11:12:49Z")

</div>

Hello. I am running ELK 6.6 on a CentOS 7 box. I have filebeat configured on a Windows machine to forward specific logs to Logstash. The problem I have is that my Logstash filter has a throttling mechanism setup as to …

---

## [Pfsense logs to ELK cloud](https://discuss.elastic.co/t/pfsense-logs-to-elk-cloud/241333)

<div class="topic-metadata">

**Author:** [@jhaycraft](https://discuss.elastic.co/u/jhaycraft)\
**Replies:** 1\
**Last updated:** [July 15, 2020, 4:28pm UTC](https://discuss.elastic.co/t/pfsense-logs-to-elk-cloud/241333 "2020-07-15T16:28:44Z")

</div>

Is there a good way to get PFsense logs straight from the firewall to the Elk hosted stack without a go between ( graylog, logstash etc)? Thanks,

---

## [Filebeat - Non-zero metrics in the last 30s](https://discuss.elastic.co/t/filebeat-non-zero-metrics-in-the-last-30s/241216)

<div class="topic-metadata">

**Author:** [@saravananveera](https://discuss.elastic.co/u/saravananveera)\
**Replies:** 2\
**Last updated:** [July 15, 2020, 11:14am UTC](https://discuss.elastic.co/t/filebeat-non-zero-metrics-in-the-last-30s/241216 "2020-07-15T11:14:16Z")

</div>

Apparently logs are transferred from Filebeat to logstash, however the filebeat logs continiously show this message: 2020-07-15T01:18:20.789Z INFO \[monitoring\] log/log.go:124 Non-zero metrics in the last 30s {"monitorin…

---

## [Rsyslog and Filebeats](https://discuss.elastic.co/t/rsyslog-and-filebeats/240982)

<div class="topic-metadata">

**Author:** [@srpine](https://discuss.elastic.co/u/srpine)\
**Replies:** 1\
**Last updated:** [July 15, 2020, 8:31am UTC](https://discuss.elastic.co/t/rsyslog-and-filebeats/240982 "2020-07-15T08:31:00Z")

</div>

I am collecting logs from other serves to a syslog server using rsyslog. The result is a directory path with sub-directories under it that have the IP address of the server from where the logs came from. I have filebea…

---

## [Beats Digital Signature](https://discuss.elastic.co/t/beats-digital-signature/241186)

<div class="topic-metadata">

**Author:** [@tacomaster](https://discuss.elastic.co/u/tacomaster)\
**Replies:** 1\
**Last updated:** [July 15, 2020, 8:22am UTC](https://discuss.elastic.co/t/beats-digital-signature/241186 "2020-07-15T08:22:13Z")

</div>

Hi, I was wondering if there are any plans on digitally signing the executables in beats on Windows?

---

## [ELK Stack on Kubernetes Architecture](https://discuss.elastic.co/t/elk-stack-on-kubernetes-architecture/241170)

<div class="topic-metadata">

**Author:** [@pulkit007](https://discuss.elastic.co/u/pulkit007)\
**Replies:** 1\
**Last updated:** [July 15, 2020, 8:19am UTC](https://discuss.elastic.co/t/elk-stack-on-kubernetes-architecture/241170 "2020-07-15T08:19:20Z")

</div>

I want to deploy ELK stack on Kubernetes for monitoring logs stored in Persistant Volume in the Kubernetes namespace. Logs are generating from different nodes, but are stored at the same place in Persistant Volume. What …

---

## [How to ensure Lifecycle Policy is applied when redeploying Metricbeat in Kubernetes?](https://discuss.elastic.co/t/how-to-ensure-lifecycle-policy-is-applied-when-redeploying-metricbeat-in-kubernetes/241106)

<div class="topic-metadata">

**Author:** [@Mattness](https://discuss.elastic.co/u/Mattness)\
**Replies:** 1\
**Last updated:** [July 15, 2020, 7:54am UTC](https://discuss.elastic.co/t/how-to-ensure-lifecycle-policy-is-applied-when-redeploying-metricbeat-in-kubernetes/241106 "2020-07-15T07:54:41Z")

</div>

Hello, I had a problem where my Metricbeat index would not update according to the Lifecycle Policy I had set in the config. As it turns out there was a default "metricbeat" Lifecycle Policy active which overrode my con…

---

## [Metricbeat service starts then stop when trying to use the MSSQL](https://discuss.elastic.co/t/metricbeat-service-starts-then-stop-when-trying-to-use-the-mssql/240545)

<div class="topic-metadata">

**Author:** [@jhaycraft](https://discuss.elastic.co/u/jhaycraft)\
**Replies:** 5\
**Last updated:** [July 15, 2020, 7:43am UTC](https://discuss.elastic.co/t/metricbeat-service-starts-then-stop-when-trying-to-use-the-mssql/240545 "2020-07-15T07:43:53Z")

</div>

I'm trying to log some metrics from Microsoft MSSQL and the Metricbeat service starts then stop. I'm thinking that I have something wrong in the mssql.yaml file that is causing this. Windows errors logs have not been m…

---

## [Installing two heartbeat services in the same host](https://discuss.elastic.co/t/installing-two-heartbeat-services-in-the-same-host/241118)

<div class="topic-metadata">

**Author:** [@Randima\_Somathilaka](https://discuss.elastic.co/u/Randima_Somathilaka)\
**Replies:** 2\
**Last updated:** [July 15, 2020, 5:31am UTC](https://discuss.elastic.co/t/installing-two-heartbeat-services-in-the-same-host/241118 "2020-07-15T05:31:16Z")

</div>

Hi, Is there a specific guide to install two heartbeat services inside the same host machine. These heartbeat instances are pointed to two different elastic cloud stacks.

---

## [Missing events when shipping Cloudtrail logs with Filebeat and the AWS module](https://discuss.elastic.co/t/missing-events-when-shipping-cloudtrail-logs-with-filebeat-and-the-aws-module/239838)

<div class="topic-metadata">

**Author:** [@m1kel](https://discuss.elastic.co/u/m1kel)\
**Replies:** 8\
**Last updated:** [July 15, 2020, 1:40am UTC](https://discuss.elastic.co/t/missing-events-when-shipping-cloudtrail-logs-with-filebeat-and-the-aws-module/239838 "2020-07-15T01:40:45Z")

</div>

I've configured a POC of Filebeat ingestion of Cloudtrail logs into our Elastic Cloud. I see the events and can see that the SQS queue is being processed. However, when looking closely, I can spot that not all of the ev…

---

## [Metricbeat extra fields](https://discuss.elastic.co/t/metricbeat-extra-fields/241168)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [July 14, 2020, 7:07pm UTC](https://discuss.elastic.co/t/metricbeat-extra-fields/241168 "2020-07-14T19:07:42Z")

</div>

I have just enable metricbeat. using very simple config. metricbeat.config.modules: path: ${path.config}/modules.d/\*.yml reload.enabled: false setup.template.settings: index.number\_of\_shards: 1 index.codec: be…

---

## [Metricbeat 7.8 AWS/RDS | Events missing db\_instance.identifier, cluster\_identifier, etc](https://discuss.elastic.co/t/metricbeat-7-8-aws-rds-events-missing-db-instance-identifier-cluster-identifier-etc/240769)

<div class="topic-metadata">

**Author:** [@william.shipman](https://discuss.elastic.co/u/william.shipman)\
**Replies:** 2\
**Last updated:** [July 14, 2020, 4:21pm UTC](https://discuss.elastic.co/t/metricbeat-7-8-aws-rds-events-missing-db-instance-identifier-cluster-identifier-etc/240769 "2020-07-14T16:21:55Z")

</div>

The events I'm receiving from AWS/RDS do not match the shape I expect after reviewing the docs, so I'm requesting some clarification about the expected behavior. In particular, is it expected that some events will be gen…

---

## [Filebeat Fortinet Module + Kibana SIEM](https://discuss.elastic.co/t/filebeat-fortinet-module-kibana-siem/236457)

<div class="topic-metadata">

**Author:** [@tjfred](https://discuss.elastic.co/u/tjfred)\
**Replies:** 10\
**Last updated:** [July 14, 2020, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-kibana-siem/236457 "2020-07-14T14:31:14Z")

</div>

Hello, I'm using the Fortinet module with Filebeat on Linux, logs are flowing and making their way into Elastic. Is there something I need to do to have these show in SIEM? The Fortinet module docs https://www.elastic.c…

---

## [Filebeat Fortinet Default Ingest Pipeline fails](https://discuss.elastic.co/t/filebeat-fortinet-default-ingest-pipeline-fails/238893)

<div class="topic-metadata">

**Author:** [@Mercwri](https://discuss.elastic.co/u/Mercwri)\
**Replies:** 5\
**Last updated:** [July 14, 2020, 2:28pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-default-ingest-pipeline-fails/238893 "2020-07-14T14:28:45Z")

</div>

I have multiple Fortinet devices pushing logs to a collector running Filebeat 7.8.0 with the Fortinet module enabled. All of the logs are being ingested but the pipeline fails at decoding/normalizing the timestamps. I g…

---

## [Internal metric collection ends up in "Standalone Cluster" regardless cluster\_uuid setting](https://discuss.elastic.co/t/internal-metric-collection-ends-up-in-standalone-cluster-regardless-cluster-uuid-setting/240320)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 12\
**Last updated:** [July 14, 2020, 1:17pm UTC](https://discuss.elastic.co/t/internal-metric-collection-ends-up-in-standalone-cluster-regardless-cluster-uuid-setting/240320 "2020-07-14T13:17:32Z")

</div>

Hi, ES, APM version: 7.2.1 I've seen this before with Filebeat but it wasn't important at the time but now that I added an APM server to the cluster it's frustrating. ES, Kibana, and Logstash are correctly grouped so I…

---

## [Client certificate selection by metricbeat](https://discuss.elastic.co/t/client-certificate-selection-by-metricbeat/241123)

<div class="topic-metadata">

**Author:** [@goromorotolo](https://discuss.elastic.co/u/goromorotolo)\
**Replies:** 0\
**Last updated:** [July 14, 2020, 11:49am UTC](https://discuss.elastic.co/t/client-certificate-selection-by-metricbeat/241123 "2020-07-14T11:49:50Z")

</div>

Hi, I have configured elasticsearch to request a client certificate from clients. This has been configured in addition to username and password. The truststore configured in elasticsearch only holds one "server certifi…

---

## [Filebeat ignore log entries with certain size](https://discuss.elastic.co/t/filebeat-ignore-log-entries-with-certain-size/241009)

<div class="topic-metadata">

**Author:** [@sfenman](https://discuss.elastic.co/u/sfenman)\
**Replies:** 2\
**Last updated:** [July 14, 2020, 11:45am UTC](https://discuss.elastic.co/t/filebeat-ignore-log-entries-with-certain-size/241009 "2020-07-14T11:45:08Z")

</div>

Hello, I am using filebeat to parse logs from my server directly to Elastic cloud. Sometimes there are some inconsistent logs entries with hundreds of log lines which I don't want to harvest them. Is there any way I can…

---

## [Filebeat getting stop without giving any error](https://discuss.elastic.co/t/filebeat-getting-stop-without-giving-any-error/241094)

<div class="topic-metadata">

**Author:** [@Rashid\_Ali](https://discuss.elastic.co/u/Rashid_Ali)\
**Replies:** 2\
**Last updated:** [July 14, 2020, 11:26am UTC](https://discuss.elastic.co/t/filebeat-getting-stop-without-giving-any-error/241094 "2020-07-14T11:26:23Z")

</div>

Hi everybody, I have a situation where filebeat automatically gets toped without giving any error in the log file. I am attaching all the logs of the filebeat. I am reading multiple files from the same path. Data in fil…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=228)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=230)
