# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=231

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 232

---

## [Help with drop\_event](https://discuss.elastic.co/t/help-with-drop-event/240763)

<div class="topic-metadata">

**Author:** [@nwed](https://discuss.elastic.co/u/nwed)\
**Replies:** 0\
**Last updated:** [July 10, 2020, 9:21pm UTC](https://discuss.elastic.co/t/help-with-drop-event/240763 "2020-07-10T21:21:33Z")

</div>

We are just starting to play around with drop\_event filtering. Auditd rules are not great at filtering so drop\_event is going to serve us well. Right now we are stuck with a nesting example and want to know what is poss…

---

## [Having difficulty having clients send data into dockerized elasticsearch](https://discuss.elastic.co/t/having-difficulty-having-clients-send-data-into-dockerized-elasticsearch/240867)

<div class="topic-metadata">

**Author:** [@timeand](https://discuss.elastic.co/u/timeand)\
**Replies:** 0\
**Last updated:** [July 12, 2020, 10:09pm UTC](https://discuss.elastic.co/t/having-difficulty-having-clients-send-data-into-dockerized-elasticsearch/240867 "2020-07-12T22:09:35Z")

</div>

I am trying to learn the elastic stack at home with a few different systems. What I am ultimately trying to apply/monitor logs for the following: ZFS Disk stats (smartmontools) rclone Docker (nginx, plex, etc - but not…

---

## [What are the ways we can do to reduce the high utilization observe in winlogbeat agent](https://discuss.elastic.co/t/what-are-the-ways-we-can-do-to-reduce-the-high-utilization-observe-in-winlogbeat-agent/234317)

<div class="topic-metadata">

**Author:** [@realyn\_elastic](https://discuss.elastic.co/u/realyn_elastic)\
**Replies:** 1\
**Last updated:** [July 11, 2020, 11:36pm UTC](https://discuss.elastic.co/t/what-are-the-ways-we-can-do-to-reduce-the-high-utilization-observe-in-winlogbeat-agent/234317 "2020-07-11T23:36:47Z")

</div>

what are the ways we can do to reduce the high utilization observe in winlogbeat agent

---

## [SIEM, Winlogbeat and Windows Auditing](https://discuss.elastic.co/t/siem-winlogbeat-and-windows-auditing/234555)

<div class="topic-metadata">

**Author:** [@elvarb](https://discuss.elastic.co/u/elvarb)\
**Replies:** 1\
**Last updated:** [July 11, 2020, 11:31pm UTC](https://discuss.elastic.co/t/siem-winlogbeat-and-windows-auditing/234555 "2020-07-11T23:31:48Z")

</div>

I'm testing the SIEM solution along with Winlogbeat to send event logs and sysmon logs. When viewing the premade alerts, dashboards and more I feel like certain events should be there but do not show. For example starti…

---

## [Auditbeat - 120% CPU?](https://discuss.elastic.co/t/auditbeat-120-cpu/234909)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 29\
**Last updated:** [July 11, 2020, 11:44am UTC](https://discuss.elastic.co/t/auditbeat-120-cpu/234909 "2020-07-11T11:44:14Z")

</div>

The high CPU usage of this process has been an ongoing issue. Recently I created a portal host for remote workers. Just supposed to be a gateway to move to other machines. 2 CPUs, 4Gb RAM, etc. Started getting reports o…

---

## [Error loading config file: yaml: line 38: did not find expected key](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-38-did-not-find-expected-key/240794)

<div class="topic-metadata">

**Author:** [@asagnam](https://discuss.elastic.co/u/asagnam)\
**Replies:** 0\
**Last updated:** [July 11, 2020, 11:11am UTC](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-38-did-not-find-expected-key/240794 "2020-07-11T11:11:57Z")

</div>

when i was testing the winloagbeat config i got error in line 38 couldn't find expected key this is my winlogbeat.yml file kindly help me please to solve this problem thank you ###################### Winlogbeat Conf…

---

## [Processes are not logged in winlogbeat](https://discuss.elastic.co/t/processes-are-not-logged-in-winlogbeat/240471)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 1\
**Last updated:** [July 11, 2020, 7:49am UTC](https://discuss.elastic.co/t/processes-are-not-logged-in-winlogbeat/240471 "2020-07-11T07:49:48Z")

</div>

Hi, I've winlogbeat sending data to logstash then to elasticsearc and kibana. If I run cmd.exe or calc.exe or any process on the beat machine, the process.name in kibana doesn't have any values for them. It only shows…

---

## [Beats reporting on Kibana as Standalone Cluster](https://discuss.elastic.co/t/beats-reporting-on-kibana-as-standalone-cluster/240711)

<div class="topic-metadata">

**Author:** [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Replies:** 1\
**Last updated:** [July 10, 2020, 2:33pm UTC](https://discuss.elastic.co/t/beats-reporting-on-kibana-as-standalone-cluster/240711 "2020-07-10T14:33:38Z")

</div>

ELK-Stack: 7.8 Beats -\> Logstash -\> ES in my cluster: I'm ingesting both data logs and monitoring stats to same cluster. Installed and configured Filebeat 7.8 on a linux server with the below configuration. Once star…

---

## [Filebeat 7.3.2 using high CPU (50~60%)](https://discuss.elastic.co/t/filebeat-7-3-2-using-high-cpu-50-60/240251)

<div class="topic-metadata">

**Author:** [@tandav](https://discuss.elastic.co/u/tandav)\
**Replies:** 1\
**Last updated:** [July 10, 2020, 2:28pm UTC](https://discuss.elastic.co/t/filebeat-7-3-2-using-high-cpu-50-60/240251 "2020-07-10T14:28:55Z")

</div>

Hello community. I've been tweaking the filebeat.yml for several hours now, and cannot get filebeat to use less CPU than 50~60%. I have tried various combinations of: filebeat.inputs: - type: log enab…

---

## [Pass AWS tags to resources created by Functionbeat](https://discuss.elastic.co/t/pass-aws-tags-to-resources-created-by-functionbeat/240575)

<div class="topic-metadata">

**Author:** [@svenky](https://discuss.elastic.co/u/svenky)\
**Replies:** 1\
**Last updated:** [July 10, 2020, 2:14pm UTC](https://discuss.elastic.co/t/pass-aws-tags-to-resources-created-by-functionbeat/240575 "2020-07-10T14:14:48Z")

</div>

I am using Functionbeat 7.6.2 and I wanted to inject a few tags to all the AWS resources that get created as part of functionbeat deploy cloudwatch . Is there a way to do this today? I do not see documentation or exampl…

---

## [Filebeat Reverse DNS](https://discuss.elastic.co/t/filebeat-reverse-dns/240552)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 2\
**Last updated:** [July 10, 2020, 11:40am UTC](https://discuss.elastic.co/t/filebeat-reverse-dns/240552 "2020-07-10T11:40:40Z")

</div>

Hi there, Can anyone tell what I´m doing wrong with this configuration? processors: - dns: type: reverse action: replace fields: source.ip: source.ip destination.ip: destination.ip Keep receivi…

---

## [Filebeat data path already locked](https://discuss.elastic.co/t/filebeat-data-path-already-locked/240559)

<div class="topic-metadata">

**Author:** [@Imad\_Bouchakour](https://discuss.elastic.co/u/Imad_Bouchakour)\
**Replies:** 2\
**Last updated:** [July 10, 2020, 7:16am UTC](https://discuss.elastic.co/t/filebeat-data-path-already-locked/240559 "2020-07-10T07:16:08Z")

</div>

Hi, how to fix ? ERROR instance/beat.go:958 Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data). Exiting: data path already locked by …

---

## [Metricbeat not using name in http monitoring](https://discuss.elastic.co/t/metricbeat-not-using-name-in-http-monitoring/240368)

<div class="topic-metadata">

**Author:** [@Tasmanien](https://discuss.elastic.co/u/Tasmanien)\
**Replies:** 3\
**Last updated:** [July 10, 2020, 6:17am UTC](https://discuss.elastic.co/t/metricbeat-not-using-name-in-http-monitoring/240368 "2020-07-10T06:17:44Z")

</div>

Hi, I'm using http monitoring on my metricbeat, so I can see it in Kibana Monitoring. I've setup like this: metricbeat.yml: http.enabled: true http.port: 5067 name: NAME-I-PICKED beat-xpack.yml: module: beat me…

---

## [Filebeat and Logstash without ingest pipelines](https://discuss.elastic.co/t/filebeat-and-logstash-without-ingest-pipelines/240595)

<div class="topic-metadata">

**Author:** [@sera](https://discuss.elastic.co/u/sera)\
**Replies:** 2\
**Last updated:** [July 9, 2020, 8:02pm UTC](https://discuss.elastic.co/t/filebeat-and-logstash-without-ingest-pipelines/240595 "2020-07-09T20:02:23Z")

</div>

I am building an environment as follows: server1 = logstash & filebeat (with Cisco module enabled) server2 = kibana server3 = elasticsearch I want to use this to monitor Cisco ASA firewalls. The ASA's will send logs …

---

## [Beats behavior when output host is unreachable](https://discuss.elastic.co/t/beats-behavior-when-output-host-is-unreachable/240481)

<div class="topic-metadata">

**Author:** [@nitzan.karni](https://discuss.elastic.co/u/nitzan.karni)\
**Replies:** 2\
**Last updated:** [July 9, 2020, 7:28pm UTC](https://discuss.elastic.co/t/beats-behavior-when-output-host-is-unreachable/240481 "2020-07-09T19:28:01Z")

</div>

Hi, I Wanted to know the filebeat and metricbeat behavior when all hosts specified on ouput.logstash / output.elastic are unreachable. Does the beat saves data it collected over the course of time the hosts were unreac…

---

## [Ignore\_older is not pushing the latest logs](https://discuss.elastic.co/t/ignore-older-is-not-pushing-the-latest-logs/239632)

<div class="topic-metadata">

**Author:** [@aolvikash](https://discuss.elastic.co/u/aolvikash)\
**Replies:** 5\
**Last updated:** [July 9, 2020, 6:51pm UTC](https://discuss.elastic.co/t/ignore-older-is-not-pushing-the-latest-logs/239632 "2020-07-09T18:51:30Z")

</div>

Hi All, I have configured ignore\_older into filebeat \[version 6.6\] so that only new logs should push into ELK, here is the ignore\_older and other related configs: ignore\_older: 1h close\_older: 24h close\_inactive: 30…

---

## [S3 Filebeat Input Cloudfront Logs - handleSQSMessage failed: json unmarshal sqs message body failed](https://discuss.elastic.co/t/s3-filebeat-input-cloudfront-logs-handlesqsmessage-failed-json-unmarshal-sqs-message-body-failed/239716)

<div class="topic-metadata">

**Author:** [@AddChickpeas](https://discuss.elastic.co/u/AddChickpeas)\
**Replies:** 2\
**Last updated:** [July 9, 2020, 4:24pm UTC](https://discuss.elastic.co/t/s3-filebeat-input-cloudfront-logs-handlesqsmessage-failed-json-unmarshal-sqs-message-body-failed/239716 "2020-07-09T16:24:18Z")

</div>

Hello, I'm trying to get the S3 input configured to ingest Cloudfront logs. Problem is, regardless of what settings I use, it runs into a log in can't process and gives me: handleSQSMessage failed: json unmarshal sqs m…

---

## [Filebeat with ssl error on windows server 2008](https://discuss.elastic.co/t/filebeat-with-ssl-error-on-windows-server-2008/240555)

<div class="topic-metadata">

**Author:** [@mibfb23](https://discuss.elastic.co/u/mibfb23)\
**Replies:** 0\
**Last updated:** [July 9, 2020, 3:34pm UTC](https://discuss.elastic.co/t/filebeat-with-ssl-error-on-windows-server-2008/240555 "2020-07-09T15:34:01Z")

</div>

Hello, I installed filebeat 7.7.0 on a windows 2008 server with the following settings: ###################### Filebeat Configuration Example ######################### # This file is an example configuration file hig…

---

## [Filebeat multiple sources netflow module](https://discuss.elastic.co/t/filebeat-multiple-sources-netflow-module/240421)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 2\
**Last updated:** [July 9, 2020, 3:20pm UTC](https://discuss.elastic.co/t/filebeat-multiple-sources-netflow-module/240421 "2020-07-09T15:20:14Z")

</div>

Hello there, My ELK Stack is composed by: Elasticsearch Kibana Filebeat My question is, how can I accomplish multiple sources (firewall) to send same port 2055 netflow module? Is possible? Or not? Thanks in advance…

---

## [Errors in filebeat i/o timeout, reconnecting](https://discuss.elastic.co/t/errors-in-filebeat-i-o-timeout-reconnecting/240026)

<div class="topic-metadata">

**Author:** [@George\_Wainwright](https://discuss.elastic.co/u/George_Wainwright)\
**Replies:** 3\
**Last updated:** [July 9, 2020, 2:34pm UTC](https://discuss.elastic.co/t/errors-in-filebeat-i-o-timeout-reconnecting/240026 "2020-07-09T14:34:30Z")

</div>

Hi, from time to time I see periodic errors in filebeat logs: 2020-07-06T09:00:12.479-0500 ERROR logstash/sync.go:96 error closing connection to logstash host test-logstash:5044: write tcp 10.120.248.89:48856-\>10.120.24…

---

## [Not skipping the folders and files sending from filebeat to elaticsearch](https://discuss.elastic.co/t/not-skipping-the-folders-and-files-sending-from-filebeat-to-elaticsearch/240267)

<div class="topic-metadata">

**Author:** [@sukku77](https://discuss.elastic.co/u/sukku77)\
**Replies:** 1\
**Last updated:** [July 9, 2020, 2:33pm UTC](https://discuss.elastic.co/t/not-skipping-the-folders-and-files-sending-from-filebeat-to-elaticsearch/240267 "2020-07-09T14:33:31Z")

</div>

Hi , I am using filebeat version 7.3.1. There is an issue with the below sample filebeat configuration. I need to skip all the folders named "ignore" as mentioned in paths. I used the exclude\_files pattern, But those l…

---

## [NGINX - restructure logging to match nginx module](https://discuss.elastic.co/t/nginx-restructure-logging-to-match-nginx-module/240415)

<div class="topic-metadata">

**Author:** [@Mikki](https://discuss.elastic.co/u/Mikki)\
**Replies:** 1\
**Last updated:** [July 9, 2020, 2:27pm UTC](https://discuss.elastic.co/t/nginx-restructure-logging-to-match-nginx-module/240415 "2020-07-09T14:27:44Z")

</div>

Im trying to ingest a custom logformat from nginx log\_format main '$remote\_addr - $http\_x\_forwarded\_for - $http\_true\_client\_ip - $remote\_user \[$time\_local\] "$host" "$request" ' '$status $body\_bytes\_sent "$http\_referer" …

---

## [Metricbeat mssql performance module does not record data from named instance](https://discuss.elastic.co/t/metricbeat-mssql-performance-module-does-not-record-data-from-named-instance/240536)

<div class="topic-metadata">

**Author:** [@Dominik\_Skiba](https://discuss.elastic.co/u/Dominik_Skiba)\
**Replies:** 2\
**Last updated:** [July 9, 2020, 1:54pm UTC](https://discuss.elastic.co/t/metricbeat-mssql-performance-module-does-not-record-data-from-named-instance/240536 "2020-07-09T13:54:04Z")

</div>

Hello, I'd like to re-raise an issue exactly as described in this post Reason I'm doing this is because original post was automatically closed and I couldn't find such bug recorded. Counter query should take named ins…

---

## [\[Filebeat\] "Configured paths: ... " log printed twice every time](https://discuss.elastic.co/t/filebeat-configured-paths-log-printed-twice-every-time/240518)

<div class="topic-metadata">

**Author:** [@wflyer](https://discuss.elastic.co/u/wflyer)\
**Replies:** 0\
**Last updated:** [July 9, 2020, 11:35am UTC](https://discuss.elastic.co/t/filebeat-configured-paths-log-printed-twice-every-time/240518 "2020-07-09T11:35:39Z")

</div>

Hello, I'm trying to upgrade filebeat daemonsets in my kubernetes cluster from 7.5.0 to 7.8.0 to fix some bugs. While evaluating new version, I found an issue in the filebeat log. 2020-07-09T11:15:26.303Z INFO …

---

## [How to send Json logs to Elastic Search using File Beats without extra fields](https://discuss.elastic.co/t/how-to-send-json-logs-to-elastic-search-using-file-beats-without-extra-fields/239972)

<div class="topic-metadata">

**Author:** [@Ashish\_kapoor](https://discuss.elastic.co/u/Ashish_kapoor)\
**Replies:** 4\
**Last updated:** [July 9, 2020, 4:50am UTC](https://discuss.elastic.co/t/how-to-send-json-logs-to-elastic-search-using-file-beats-without-extra-fields/239972 "2020-07-09T04:50:16Z")

</div>

Hi there, I am trying to send JSON logs to Elastic Search using file beats. My logs file looks like this {"timestamp":1581386084780,"message":"User 'Test' connected","eventId":107,"metadata":{"userID":"Test","serviceID…

---

## [The docker module seems missing](https://discuss.elastic.co/t/the-docker-module-seems-missing/240393)

<div class="topic-metadata">

**Author:** [@lyrixx](https://discuss.elastic.co/u/lyrixx)\
**Replies:** 1\
**Last updated:** [July 8, 2020, 8:23pm UTC](https://discuss.elastic.co/t/the-docker-module-seems-missing/240393 "2020-07-08T20:23:33Z")

</div>

Hello, I saw this announcement https://www.elastic.co/fr/blog/brewing-in-beats-new-sample-dashboards-for-docker-and-redis so I wanted to try But I can not find the docker dashboard in kibana So I look at the code, and …

---

## [Dissect combined with multiline pattern gives errors](https://discuss.elastic.co/t/dissect-combined-with-multiline-pattern-gives-errors/239728)

<div class="topic-metadata">

**Author:** [@kainazzzo](https://discuss.elastic.co/u/kainazzzo)\
**Replies:** 5\
**Last updated:** [July 8, 2020, 7:40pm UTC](https://discuss.elastic.co/t/dissect-combined-with-multiline-pattern-gives-errors/239728 "2020-07-08T19:40:19Z")

</div>

I have log files being picked up and dissected fine when they are single line. I even have a multi line pattern ensuring that the message attribute contains all the lines I want. What I can't seem to figure out is how t…

---

## [Firewall cisco ASA and beats](https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612)

<div class="topic-metadata">

**Author:** [@Feriel\_Mufti](https://discuss.elastic.co/u/Feriel_Mufti)\
**Replies:** 5\
**Last updated:** [July 8, 2020, 4:28pm UTC](https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612 "2020-07-08T16:28:51Z")

</div>

Hello , i am using elasticsearch and kibana on server centos 7 , i have configured beats directly sent to elasticsearch ( without need to configure logstash) and it works perfectly from both centos agents and windows age…

---

## [Netinfo data not added to events using add\_host\_metadata processor](https://discuss.elastic.co/t/netinfo-data-not-added-to-events-using-add-host-metadata-processor/240387)

<div class="topic-metadata">

**Author:** [@ricalo](https://discuss.elastic.co/u/ricalo)\
**Replies:** 0\
**Last updated:** [July 8, 2020, 3:57pm UTC](https://discuss.elastic.co/t/netinfo-data-not-added-to-events-using-add-host-metadata-processor/240387 "2020-07-08T15:57:25Z")

</div>

I'm trying to add host.ip and host.mac fields to filebeat events, but the fields are not showing up in Kibana. I'm using the following related configuration in filebeat.yml: processors: - add\_host\_metadata: net…

---

## [Ip to internal dns netflow module filebeat](https://discuss.elastic.co/t/ip-to-internal-dns-netflow-module-filebeat/240377)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 0\
**Last updated:** [July 8, 2020, 3:17pm UTC](https://discuss.elastic.co/t/ip-to-internal-dns-netflow-module-filebeat/240377 "2020-07-08T15:17:18Z")

</div>

Hi there, I would like to know if is possible to translate private and public ip to dns using internal dns server? When was using elastiflow, we had something called iptodns which we could point the internal DNS to auto…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=230)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=232)
