# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=230

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 231

---

## [Geolocation using packetbeat](https://discuss.elastic.co/t/geolocation-using-packetbeat/241102)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [July 14, 2020, 9:27am UTC](https://discuss.elastic.co/t/geolocation-using-packetbeat/241102 "2020-07-14T09:27:44Z")

</div>

I am using geopoint filter in logstash and i am using packetbeat to send network logs to the elasticsearch through logstash. Here is my logstash config file filter { geoip { source =\> "\[server\]\[ip\]" target =\> "\[ser…

---

## [Problem to update to filebeat 7.7.0 and parser nginx-ingress-controller on Kubernetes](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461)

<div class="topic-metadata">

**Author:** [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Replies:** 5\
**Last updated:** [July 14, 2020, 8:33am UTC](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461 "2020-07-14T08:33:42Z")

</div>

Hi! I was using Kubernetes with this version of Filebeat: docker.elastic.co/beats/filebeat:7.3.2 In order to use the new functionalities to parser nginx-ingress-controller I've update to docker.elastic.co/beats/filebea…

---

## [Beat templates do not stick to ECS?](https://discuss.elastic.co/t/beat-templates-do-not-stick-to-ecs/241064)

<div class="topic-metadata">

**Author:** [@BBQigniter](https://discuss.elastic.co/u/BBQigniter)\
**Replies:** 3\
**Last updated:** [July 14, 2020, 8:10am UTC](https://discuss.elastic.co/t/beat-templates-do-not-stick-to-ecs/241064 "2020-07-14T08:10:20Z")

</div>

Hello, am I seeing this correctly that the Beat-templates sometimes do not stick to the ECS? For example I wanted to prepare a mapping template for our ELK-Stack and so I merged auditbeat, filebeat and winlogbeat mappin…

---

## [Load external configuration files](https://discuss.elastic.co/t/load-external-configuration-files/241046)

<div class="topic-metadata">

**Author:** [@Mrzhuang007](https://discuss.elastic.co/u/Mrzhuang007)\
**Replies:** 1\
**Last updated:** [July 14, 2020, 8:04am UTC](https://discuss.elastic.co/t/load-external-configuration-files/241046 "2020-07-14T08:04:02Z")

</div>

Hi! I can load external config through this config in filebeat.yml filebeat.config.inputs: enabled: true path: configs/\*.yml Do anyone test how many external config I can add, and will it cost to much delay?

---

## [Syslog from network devices to Filebeat](https://discuss.elastic.co/t/syslog-from-network-devices-to-filebeat/240928)

<div class="topic-metadata">

**Author:** [@sera](https://discuss.elastic.co/u/sera)\
**Replies:** 4\
**Last updated:** [July 14, 2020, 7:56am UTC](https://discuss.elastic.co/t/syslog-from-network-devices-to-filebeat/240928 "2020-07-14T07:56:21Z")

</div>

Hi - I can't seem to get Filebeat to collect syslog from ONLY my network devices. It seems to collect everything from /var/log/messages (Filebeat installed on Centos 7) and from my network devices. Here are the input/ou…

---

## [Filebeat registrar to use statestore log.json is never clean](https://discuss.elastic.co/t/filebeat-registrar-to-use-statestore-log-json-is-never-clean/241048)

<div class="topic-metadata">

**Author:** [@JKeita](https://discuss.elastic.co/u/JKeita)\
**Replies:** 0\
**Last updated:** [July 14, 2020, 3:33am UTC](https://discuss.elastic.co/t/filebeat-registrar-to-use-statestore-log-json-is-never-clean/241048 "2020-07-14T03:33:15Z")

</div>

master branch filebeat registrar to use statestore. log.json is never clean old data. filebeat.registry.cleanup\_interval in linux is invalid.

---

## [Filebeat registry data.json is empty](https://discuss.elastic.co/t/filebeat-registry-data-json-is-empty/240709)

<div class="topic-metadata">

**Author:** [@Sai\_Avinash\_Duddupud](https://discuss.elastic.co/u/Sai_Avinash_Duddupud)\
**Replies:** 2\
**Last updated:** [July 14, 2020, 7:36am UTC](https://discuss.elastic.co/t/filebeat-registry-data-json-is-empty/240709 "2020-07-14T07:36:07Z")

</div>

I am trying to setup filebeat, but it not harvesting logs at all from the given log file path. After lot of research, I came to know that data.json in registry folder is empty which is why filebeat is unable to read log…

---

## [Filebeat not receiving logs](https://discuss.elastic.co/t/filebeat-not-receiving-logs/240829)

<div class="topic-metadata">

**Author:** [@Sai\_Avinash\_Duddupud](https://discuss.elastic.co/u/Sai_Avinash_Duddupud)\
**Replies:** 1\
**Last updated:** [July 14, 2020, 7:36am UTC](https://discuss.elastic.co/t/filebeat-not-receiving-logs/240829 "2020-07-14T07:36:05Z")

</div>

Hi all, I have setup filebeat on server, but filebeat is not receiving logs at all. my log file continuously generates logs and the directory where log file is present has drwxr-xr-x+ permission I want to understand if…

---

## [Where is beats 6.8.11?](https://discuss.elastic.co/t/where-is-beats-6-8-11/240963)

<div class="topic-metadata">

**Author:** [@Danie\_de\_Jager](https://discuss.elastic.co/u/Danie_de_Jager)\
**Replies:** 2\
**Last updated:** [July 14, 2020, 5:33am UTC](https://discuss.elastic.co/t/where-is-beats-6-8-11/240963 "2020-07-14T05:33:45Z")

</div>

I see there is a changelog for 6.8.11 and that the build of 6.8.10 has been pulled. When will 6.8.11 be released?

---

## [Filebeat extremely slow startup for large number of files](https://discuss.elastic.co/t/filebeat-extremely-slow-startup-for-large-number-of-files/240746)

<div class="topic-metadata">

**Author:** [@serant](https://discuss.elastic.co/u/serant)\
**Replies:** 0\
**Last updated:** [July 10, 2020, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-extremely-slow-startup-for-large-number-of-files/240746 "2020-07-10T18:52:42Z")

</div>

We use Filebeat to tail hundreds of directories, each containing up to a few thousand log files. Whenever we need to restart Filebeat, it often takes days for Filebeat to being sending logs to Logstash again. I am confi…

---

## [Heartbeat - howto configure body & check.request with password in keystore file](https://discuss.elastic.co/t/heartbeat-howto-configure-body-check-request-with-password-in-keystore-file/240917)

<div class="topic-metadata">

**Author:** [@Samuelg75](https://discuss.elastic.co/u/Samuelg75)\
**Replies:** 0\
**Last updated:** [July 13, 2020, 7:50am UTC](https://discuss.elastic.co/t/heartbeat-howto-configure-body-check-request-with-password-in-keystore-file/240917 "2020-07-13T07:50:05Z")

</div>

Hello everybody, Il use heartbeat to check some web site with check.request. For example : - type: http urls: \[http://localhost:5050/myweb/app\] schedule: '@every 1m' response.include\_body\_max\_bytes: 10240 chec…

---

## [Imphash behavior changes between 7.7.1 and 7.8.0](https://discuss.elastic.co/t/imphash-behavior-changes-between-7-7-1-and-7-8-0/241034)

<div class="topic-metadata">

**Author:** [@j91321](https://discuss.elastic.co/u/j91321)\
**Replies:** 0\
**Last updated:** [July 13, 2020, 7:49pm UTC](https://discuss.elastic.co/t/imphash-behavior-changes-between-7-7-1-and-7-8-0/241034 "2020-07-13T19:49:54Z")

</div>

Hello, I have noticed a change in behavior of hash.imphash field between versions 7.7.1 and 7.8.0. In 7.7.1 when Event log has value IMPHASH=00000000000000000000000000000000 this is used then as a field value. Let's say…

---

## [Stack monitoring shows a subset of all configured beats](https://discuss.elastic.co/t/stack-monitoring-shows-a-subset-of-all-configured-beats/240804)

<div class="topic-metadata">

**Author:** [@tterranigma](https://discuss.elastic.co/u/tterranigma)\
**Replies:** 4\
**Last updated:** [July 13, 2020, 3:52pm UTC](https://discuss.elastic.co/t/stack-monitoring-shows-a-subset-of-all-configured-beats/240804 "2020-07-13T15:52:19Z")

</div>

I am running version 7.8 of everything. I have a cluster of 3 instances, each running logstash and elasticsearch. On a 4th instance I run kibana with metricbeat and with a separate monitoring cluster. These are located i…

---

## [Filebeat system module: multiline events not merged?](https://discuss.elastic.co/t/filebeat-system-module-multiline-events-not-merged/240998)

<div class="topic-metadata">

**Author:** [@pauleccm](https://discuss.elastic.co/u/pauleccm)\
**Replies:** 0\
**Last updated:** [July 13, 2020, 2:30pm UTC](https://discuss.elastic.co/t/filebeat-system-module-multiline-events-not-merged/240998 "2020-07-13T14:30:49Z")

</div>

I have enabled the system module and loaded the ingest pipeline using the filebeat setup command. The resulting events se\]eem a bit odd to me and I wonder if this is current normal behaviour of the module, or abnormal b…

---

## [Logs in discovery update very rarely](https://discuss.elastic.co/t/logs-in-discovery-update-very-rarely/240843)

<div class="topic-metadata">

**Author:** [@vinci](https://discuss.elastic.co/u/vinci)\
**Replies:** 2\
**Last updated:** [July 13, 2020, 1:46pm UTC](https://discuss.elastic.co/t/logs-in-discovery-update-very-rarely/240843 "2020-07-13T13:46:33Z")

</div>

Hello, First of all I should say that I'm very new to elasticsearch/kibana and I'm still really struggling to wrap my head around the whole thing. I've got a weird issue with elasticsearch not updating the information …

---

## [\[Filebeat\] Setup of pipelines is not working correctly](https://discuss.elastic.co/t/filebeat-setup-of-pipelines-is-not-working-correctly/240477)

<div class="topic-metadata">

**Author:** [@miande](https://discuss.elastic.co/u/miande)\
**Replies:** 2\
**Last updated:** [July 13, 2020, 1:19pm UTC](https://discuss.elastic.co/t/filebeat-setup-of-pipelines-is-not-working-correctly/240477 "2020-07-13T13:19:48Z")

</div>

IPs are masked. When I run the following command: filebeat setup --pipelines logstash,kibana,elasticsearch -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=\["X.X.X.X:9200"\]' I do not see the pipelines i…

---

## [Override index name while using the inbuilt filebeat modules](https://discuss.elastic.co/t/override-index-name-while-using-the-inbuilt-filebeat-modules/240855)

<div class="topic-metadata">

**Author:** [@kelk](https://discuss.elastic.co/u/kelk)\
**Replies:** 5\
**Last updated:** [July 13, 2020, 12:31pm UTC](https://discuss.elastic.co/t/override-index-name-while-using-the-inbuilt-filebeat-modules/240855 "2020-07-13T12:31:14Z")

</div>

We are in process of standardising index names to ensure permissions are given correctly (eg my\_os\_windows\_yyyy-mm-dd, my\_os\_linux\_yyyy-mm-dd, my\_network\_cisco\_yyyy-mm-dd etc..) rather than the default "filebeat\*" form…

---

## [FileBeat decode\_json\_fields processor max\_depth option not working](https://discuss.elastic.co/t/filebeat-decode-json-fields-processor-max-depth-option-not-working/240948)

<div class="topic-metadata">

**Author:** [@Vitaliy\_Kravchenko](https://discuss.elastic.co/u/Vitaliy_Kravchenko)\
**Replies:** 2\
**Last updated:** [July 13, 2020, 12:14pm UTC](https://discuss.elastic.co/t/filebeat-decode-json-fields-processor-max-depth-option-not-working/240948 "2020-07-13T12:14:44Z")

</div>

decode\_json\_fields -\> max\_depth option not working or documentation misunderstanding. To prevent creating tons of document fields in an Elasticsearch log index I want to control nested JSON parsing depth. Filebeat vers…

---

## [Filebeat stopped harvesting logs](https://discuss.elastic.co/t/filebeat-stopped-harvesting-logs/240863)

<div class="topic-metadata">

**Author:** [@Sai\_Avinash\_Duddupud](https://discuss.elastic.co/u/Sai_Avinash_Duddupud)\
**Replies:** 2\
**Last updated:** [July 13, 2020, 9:04am UTC](https://discuss.elastic.co/t/filebeat-stopped-harvesting-logs/240863 "2020-07-13T09:04:20Z")

</div>

Hi all, I have started filebeat today with the following config and filbeat read logs till 2days ago and now it stopped receiving logs. I have tried restarting the filebeat by deleted the registry folder too, but the re…

---

## [Auditd rules to save terminal output](https://discuss.elastic.co/t/auditd-rules-to-save-terminal-output/240930)

<div class="topic-metadata">

**Author:** [@Matt\_Rollo](https://discuss.elastic.co/u/Matt_Rollo)\
**Replies:** 0\
**Last updated:** [July 13, 2020, 9:03am UTC](https://discuss.elastic.co/t/auditd-rules-to-save-terminal-output/240930 "2020-07-13T09:03:29Z")

</div>

Thanks to autidbeat I'm able to logging on ELK command execution with flags, but I also need to save output from terminal of that command call. Is there any way to do that by auditbeat ? Maybe some rules to record kernel…

---

## [Sending logs to external SIEM via syslog using filebeat](https://discuss.elastic.co/t/sending-logs-to-external-siem-via-syslog-using-filebeat/240816)

<div class="topic-metadata">

**Author:** [@JitenM](https://discuss.elastic.co/u/JitenM)\
**Replies:** 2\
**Last updated:** [July 13, 2020, 8:25am UTC](https://discuss.elastic.co/t/sending-logs-to-external-siem-via-syslog-using-filebeat/240816 "2020-07-13T08:25:35Z")

</div>

Hello All, Is it possible to send the logs to a external SIEM server through syslog configuration using filebeat? If yes could you please give me a reference link because i am not able to find a output type as syslog in…

---

## [ElasticSearch, Filebeat SSL authentication](https://discuss.elastic.co/t/elasticsearch-filebeat-ssl-authentication/240657)

<div class="topic-metadata">

**Author:** [@taseer94](https://discuss.elastic.co/u/taseer94)\
**Replies:** 1\
**Last updated:** [July 13, 2020, 8:01am UTC](https://discuss.elastic.co/t/elasticsearch-filebeat-ssl-authentication/240657 "2020-07-13T08:01:45Z")

</div>

Hi all, I am trying to secure elasticsearch with SSL certificates. I have configured SSL in ingress pointing to elastic, and then added the root and intermediate certificates in the filebeats image. However, when I conf…

---

## [MetricBeat not computing rate counters while using 'rate\_counters: true' , and 'use\_types: true'-new](https://discuss.elastic.co/t/metricbeat-not-computing-rate-counters-while-using-rate-counters-true-and-use-types-true-new/239707)

<div class="topic-metadata">

**Author:** [@akraj](https://discuss.elastic.co/u/akraj)\
**Replies:** 1\
**Last updated:** [July 13, 2020, 7:34am UTC](https://discuss.elastic.co/t/metricbeat-not-computing-rate-counters-while-using-rate-counters-true-and-use-types-true-new/239707 "2020-07-13T07:34:10Z")

</div>

Hi, In my setup, wanted to ingest data from Prometheus into Elasticsearch using MetricBeat. Below are the versions: Prometheus: 2.7.1 MetricBeat: 7.7 Elasticsearch/Kibana: 7.7.1 Prometheus is receiving cumulative co…

---

## [Metricbeat 7.7.1 : Failed to publish events caused by: unsupported float value: NaN](https://discuss.elastic.co/t/metricbeat-7-7-1-failed-to-publish-events-caused-by-unsupported-float-value-nan/240400)

<div class="topic-metadata">

**Author:** [@jlvrhee](https://discuss.elastic.co/u/jlvrhee)\
**Replies:** 1\
**Last updated:** [July 13, 2020, 7:27am UTC](https://discuss.elastic.co/t/metricbeat-7-7-1-failed-to-publish-events-caused-by-unsupported-float-value-nan/240400 "2020-07-13T07:27:19Z")

</div>

Metricbeat version: 7.7.1 OS version : Flatcar 2303.4.0 and RHEL 7.4 Docker : Docker version 18.06.3-ce, build d7080c1 We also configured docker swarm on these nodes Config: #-------------------------------- Syst…

---

## [Metricbeat is not sending cluster\_stats for elasticsearch module](https://discuss.elastic.co/t/metricbeat-is-not-sending-cluster-stats-for-elasticsearch-module/240688)

<div class="topic-metadata">

**Author:** [@Yousaf\_Syed](https://discuss.elastic.co/u/Yousaf_Syed)\
**Replies:** 1\
**Last updated:** [July 13, 2020, 7:23am UTC](https://discuss.elastic.co/t/metricbeat-is-not-sending-cluster-stats-for-elasticsearch-module/240688 "2020-07-13T07:23:45Z")

</div>

Hello, I am trying to monitor our elastic search cluster 2.x with metricbeat 7.7.1. Metricbeat is sending over the data for shards, indicex, node, node\_stats but for some reason its not sending over cluster\_stats metric…

---

## [Can we restrict Prometheus Metrics at Metricbeat?](https://discuss.elastic.co/t/can-we-restrict-prometheus-metrics-at-metricbeat/240499)

<div class="topic-metadata">

**Author:** [@Jalpesh1](https://discuss.elastic.co/u/Jalpesh1)\
**Replies:** 1\
**Last updated:** [July 13, 2020, 7:17am UTC](https://discuss.elastic.co/t/can-we-restrict-prometheus-metrics-at-metricbeat/240499 "2020-07-13T07:17:16Z")

</div>

Hi Team, Currently we have configured Metricbeat to integrate Prometheus with ElasticSearch .We are getting around 1,50,000 metrics per minute frequency . Currently we don't need all metrics so can we restrict Promethe…

---

## [How to avoid sending duplicate events when Winlogbeat is processing duplicate events](https://discuss.elastic.co/t/how-to-avoid-sending-duplicate-events-when-winlogbeat-is-processing-duplicate-events/240883)

<div class="topic-metadata">

**Author:** [@aixic](https://discuss.elastic.co/u/aixic)\
**Replies:** 0\
**Last updated:** [July 13, 2020, 2:22am UTC](https://discuss.elastic.co/t/how-to-avoid-sending-duplicate-events-when-winlogbeat-is-processing-duplicate-events/240883 "2020-07-13T02:22:49Z")

</div>

我是一个新手开发者，我想了解Winlogbeat是如何避免出现发送重复的日志。我通过复现beats/winlogbeat/beater/eventlogger.go 中的 for \_, lr := range records { client.Publish(lr.ToEvent()) } 会出现同一日志一直刷新created进行输出

---

## [Filebeat decode json processor](https://discuss.elastic.co/t/filebeat-decode-json-processor/236770)

<div class="topic-metadata">

**Author:** [@venkat9731](https://discuss.elastic.co/u/venkat9731)\
**Replies:** 0\
**Last updated:** [June 11, 2020, 6:20pm UTC](https://discuss.elastic.co/t/filebeat-decode-json-processor/236770 "2020-06-11T18:20:34Z")

</div>

I am having an issue with my filebeat config Exiting: Error while initializing input: When using the JSON decoder and multiline together, you need to specify a message\_key value accessing filebeat.yml file filebeat.in…

---

## [Remove JSON formatting?](https://discuss.elastic.co/t/remove-json-formatting/236869)

<div class="topic-metadata">

**Author:** [@cogz0qj](https://discuss.elastic.co/u/cogz0qj)\
**Replies:** 0\
**Last updated:** [June 12, 2020, 10:27am UTC](https://discuss.elastic.co/t/remove-json-formatting/236869 "2020-06-12T10:27:28Z")

</div>

FileBeat reads JSON logfile and sends logs to Elasticsearch, but in Kibana discover (selected field full\_log) events are visually unreadable, because of JSON formatting. Is there any idea please, how to remove JSON form…

---

## [Heartbeat Monitoring on individual host](https://discuss.elastic.co/t/heartbeat-monitoring-on-individual-host/236894)

<div class="topic-metadata">

**Author:** [@quixter](https://discuss.elastic.co/u/quixter)\
**Replies:** 0\
**Last updated:** [June 12, 2020, 12:48pm UTC](https://discuss.elastic.co/t/heartbeat-monitoring-on-individual-host/236894 "2020-06-12T12:48:28Z")

</div>

WE currently use heartbeat from a single source that verifies a UL is up. It worksgreat but we want to know also if there is an issue with a single web server in a webfarm has an issue connecting to that url. I was think…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=229)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=231)
