# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=232

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 233

---

## [Metricbeat: System Call Level Is Not Correct](https://discuss.elastic.co/t/metricbeat-system-call-level-is-not-correct/240376)

<div class="topic-metadata">

**Author:** [@Guerreiro\_Sousa](https://discuss.elastic.co/u/Guerreiro_Sousa)\
**Replies:** 0\
**Last updated:** [July 8, 2020, 3:17pm UTC](https://discuss.elastic.co/t/metricbeat-system-call-level-is-not-correct/240376 "2020-07-08T15:17:01Z")

</div>

I'm having trouble using the windows module. When trying to use the module a json with the following error message is returned: The system call level is not correct. My operating system is Windows Server 2003 (32-bit). …

---

## [Using filebeat container with shared volume from another container](https://discuss.elastic.co/t/using-filebeat-container-with-shared-volume-from-another-container/239824)

<div class="topic-metadata">

**Author:** [@mzdev](https://discuss.elastic.co/u/mzdev)\
**Replies:** 4\
**Last updated:** [July 8, 2020, 2:17pm UTC](https://discuss.elastic.co/t/using-filebeat-container-with-shared-volume-from-another-container/239824 "2020-07-08T14:17:19Z")

</div>

Hello there, a quick question, we have an app that is using filebeat to ship logs, currently we're installing the filebeat package on the container itself, but due to a redesign we're toying with the idea of removing the…

---

## [Unable to use mounted elastic-agent.yml if running in elastic-agent container](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202)

<div class="topic-metadata">

**Author:** [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Replies:** 6\
**Last updated:** [July 8, 2020, 1:41pm UTC](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202 "2020-07-08T13:41:21Z")

</div>

Hi, I am using elastic-agent-7.9.0-SNAPSHOT docker image (also tested and encountered the same error with elastic-agent-8.0.0-SNAPSHOT docker image). My docker-compose.yml: version: '3.7' services: elastic-agent: …

---

## [Beats SSL Cert & Key exposure](https://discuss.elastic.co/t/beats-ssl-cert-key-exposure/240061)

<div class="topic-metadata">

**Author:** [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Replies:** 2\
**Last updated:** [July 8, 2020, 1:18pm UTC](https://discuss.elastic.co/t/beats-ssl-cert-key-exposure/240061 "2020-07-08T13:18:04Z")

</div>

In every \*beat.yml file we define the output destination, In my case we use logstash for logs to be ingested from beats. Along the beats config.yml file we supply the logstash and kibana ssl cert and it's key. output.lo…

---

## [Unable to create a proper processor for windows module to filter certain services](https://discuss.elastic.co/t/unable-to-create-a-proper-processor-for-windows-module-to-filter-certain-services/240330)

<div class="topic-metadata">

**Author:** [@yankun0567](https://discuss.elastic.co/u/yankun0567)\
**Replies:** 1\
**Last updated:** [July 8, 2020, 11:34am UTC](https://discuss.elastic.co/t/unable-to-create-a-proper-processor-for-windows-module-to-filter-certain-services/240330 "2020-07-08T11:34:46Z")

</div>

Hi, I'm currently evaluating metricbeat for monitoring our systems. On windows I would like to only monitor services, which are started automatically (or delayed) except a few services which are ok to be stopped, even i…

---

## [CloudFlare X-Forwarded-For Real Source IP](https://discuss.elastic.co/t/cloudflare-x-forwarded-for-real-source-ip/239973)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 4\
**Last updated:** [July 8, 2020, 7:50am UTC](https://discuss.elastic.co/t/cloudflare-x-forwarded-for-real-source-ip/239973 "2020-07-08T07:50:45Z")

</div>

Hi, I'm new to Elastic and need help to find the real IP of nginx site visitor. The environment I have is Nginx module installed in Filebeat and reading the data passed via logstash to elasticsearch and viewed in kiban…

---

## [No data from filebeat cisco module](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402)

<div class="topic-metadata">

**Author:** [@bqy314495](https://discuss.elastic.co/u/bqy314495)\
**Replies:** 8\
**Last updated:** [July 8, 2020, 4:17am UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402 "2020-07-08T04:17:09Z")

</div>

hi, guys i'm new to this platform and want to do some cisco device monitoring , in my lab i've setted netflow and syslog on asa firewall , and now i can see data from netflow and make dashboards on kibana. which now p…

---

## [Metricbeat http http.json: invalid character '\<' looking for beginning of value error](https://discuss.elastic.co/t/metricbeat-http-http-json-invalid-character-looking-for-beginning-of-value-error/240147)

<div class="topic-metadata">

**Author:** [@Faten](https://discuss.elastic.co/u/Faten)\
**Replies:** 2\
**Last updated:** [July 7, 2020, 11:52pm UTC](https://discuss.elastic.co/t/metricbeat-http-http-json-invalid-character-looking-for-beginning-of-value-error/240147 "2020-07-07T23:52:35Z")

</div>

Hi, I configured in metricbeat the http module as below example, but I am getting the following error : http.json: invalid character '\<' looking for beginning of value. # Module: http # Docs: https://www.elastic.co/gui…

---

## [Metricbeat for docker - filesystem metrics](https://discuss.elastic.co/t/metricbeat-for-docker-filesystem-metrics/240236)

<div class="topic-metadata">

**Author:** [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Replies:** 0\
**Last updated:** [July 7, 2020, 11:45pm UTC](https://discuss.elastic.co/t/metricbeat-for-docker-filesystem-metrics/240236 "2020-07-07T23:45:53Z")

</div>

Hello, I am interested in monitoring the filesystem capacity inside a docker container (df -h results). The container(s) runs postgresSQL cluster. Especially, want metrics for size, used, available, percentage. Is th…

---

## [How to add client ip address in winlogbeat](https://discuss.elastic.co/t/how-to-add-client-ip-address-in-winlogbeat/240195)

<div class="topic-metadata">

**Author:** [@tiencong283](https://discuss.elastic.co/u/tiencong283)\
**Replies:** 0\
**Last updated:** [July 7, 2020, 4:27pm UTC](https://discuss.elastic.co/t/how-to-add-client-ip-address-in-winlogbeat/240195 "2020-07-07T16:27:35Z")

</div>

As the question implies, I know there's a processor that enrich client host information "add\_host\_metadata" but it just lists all network interfaces including the one really communicating with the output like: "ip": \["1…

---

## [Trouble ingesting through Filebeat](https://discuss.elastic.co/t/trouble-ingesting-through-filebeat/240016)

<div class="topic-metadata">

**Author:** [@tom.p](https://discuss.elastic.co/u/tom.p)\
**Replies:** 6\
**Last updated:** [July 7, 2020, 6:21pm UTC](https://discuss.elastic.co/t/trouble-ingesting-through-filebeat/240016 "2020-07-07T18:21:35Z")

</div>

Hello all, I'm trying to ingest data from a "data" directory into Elasticsearch using Filebeat. When I manually upload these data files through Filebeat I have no problems. If I use that same mapping for my .conf file …

---

## [MongoDB module error](https://discuss.elastic.co/t/mongodb-module-error/240065)

<div class="topic-metadata">

**Author:** [@szaharici](https://discuss.elastic.co/u/szaharici)\
**Replies:** 1\
**Last updated:** [July 7, 2020, 3:55pm UTC](https://discuss.elastic.co/t/mongodb-module-error/240065 "2020-07-07T15:55:33Z")

</div>

Hey guys, I am trying to use the mongodb filebeat module to parse the logs from mongodb instances running under kubernetes. Filebeat is deployed with the elastic-stack helm chart, here is the configuration: filebeat: …

---

## [./filebeat generate fields with pipeline.yml](https://discuss.elastic.co/t/filebeat-generate-fields-with-pipeline-yml/239790)

<div class="topic-metadata">

**Author:** [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Replies:** 2\
**Last updated:** [July 7, 2020, 2:14pm UTC](https://discuss.elastic.co/t/filebeat-generate-fields-with-pipeline-yml/239790 "2020-07-07T14:14:43Z")

</div>

I am developing a new filebeat module for sophos firewall logs. Now I got stuck on the ./filebeat generate fields command. It returns with the following error: cannot read pipeline: open module/sophos/secureweb/ingest…

---

## [Prometheus data in ElasticSearch via Metricbeats](https://discuss.elastic.co/t/prometheus-data-in-elasticsearch-via-metricbeats/239768)

<div class="topic-metadata">

**Author:** [@Jalpesh1](https://discuss.elastic.co/u/Jalpesh1)\
**Replies:** 2\
**Last updated:** [July 7, 2020, 1:44pm UTC](https://discuss.elastic.co/t/prometheus-data-in-elasticsearch-via-metricbeats/239768 "2020-07-07T13:44:55Z")

</div>

Hi Team, We are scaling Prometheus data in Elastic via Metricbeats . But there are lot of metrics exposed in Prometheus . We want only few metrics in Elastic , is there any filtering possible to restrict metrics? Cur…

---

## [Monitoring beats hosts who send data to logstash?](https://discuss.elastic.co/t/monitoring-beats-hosts-who-send-data-to-logstash/240135)

<div class="topic-metadata">

**Author:** [@Andrew\_Foxis](https://discuss.elastic.co/u/Andrew_Foxis)\
**Replies:** 1\
**Last updated:** [July 7, 2020, 12:53pm UTC](https://discuss.elastic.co/t/monitoring-beats-hosts-who-send-data-to-logstash/240135 "2020-07-07T12:53:24Z")

</div>

Hi all! Is it possible to monitoring beats hosts who send data to logstash? I want monitoring hostname and last time data. Thank you advanced

---

## [Elastic agent RPM doesn't work, neither does Fleet anymore](https://discuss.elastic.co/t/elastic-agent-rpm-doesnt-work-neither-does-fleet-anymore/239679)

<div class="topic-metadata">

**Author:** [@sej7278](https://discuss.elastic.co/u/sej7278)\
**Replies:** 1\
**Last updated:** [July 6, 2020, 11:22pm UTC](https://discuss.elastic.co/t/elastic-agent-rpm-doesnt-work-neither-does-fleet-anymore/239679 "2020-07-06T23:22:13Z")

</div>

elastic-agent-7.8.0-x86\_64.rpm on centos 8.2 seems to be corrupt, it installs ok, but when you try to enroll it it seems to be looking in the bin directory for the config and all sorts: $ elastic-agent enroll https://el…

---

## [GeoIP resolve query in O365 logs](https://discuss.elastic.co/t/geoip-resolve-query-in-o365-logs/239754)

<div class="topic-metadata">

**Author:** [@Ravy](https://discuss.elastic.co/u/Ravy)\
**Replies:** 0\
**Last updated:** [July 3, 2020, 8:27am UTC](https://discuss.elastic.co/t/geoip-resolve-query-in-o365-logs/239754 "2020-07-03T08:27:43Z")

</div>

How to fix GeoIP resolve query in O365 logs Error o365, beats\_input\_raw\_event, \_geoip\_lookup\_failure

---

## [\[FileBeat\] Unable to get X-Pack Monitoring to work](https://discuss.elastic.co/t/filebeat-unable-to-get-x-pack-monitoring-to-work/239721)

<div class="topic-metadata">

**Author:** [@vcc](https://discuss.elastic.co/u/vcc)\
**Replies:** 0\
**Last updated:** [July 3, 2020, 1:41am UTC](https://discuss.elastic.co/t/filebeat-unable-to-get-x-pack-monitoring-to-work/239721 "2020-07-03T01:41:38Z")

</div>

Hi All, I'm running into an issue getting X-Pack Monitoring to work with file beat. The setup we have is as follows: Elasticsearch Nodes have security enabled (using self signed certificates via elasticsearch-certutil…

---

## [Unable to compile auditbeat - failing on librpm-dev:arm64](https://discuss.elastic.co/t/unable-to-compile-auditbeat-failing-on-librpm-dev-arm64/240015)

<div class="topic-metadata">

**Author:** [@wls](https://discuss.elastic.co/u/wls)\
**Replies:** 0\
**Last updated:** [July 6, 2020, 1:54pm UTC](https://discuss.elastic.co/t/unable-to-compile-auditbeat-failing-on-librpm-dev-arm64/240015 "2020-07-06T13:54:33Z")

</div>

Greetings, I've compiled metricbeat and filebeat successfully. But, on auditbeat, I'm getting this output with 7.8.0. Wonder if anyone else has seen it, and if there are any suggested work-arounds? user@foo:~/go/…

---

## [Docker filebeat autodiscover not detecting nginx logs](https://discuss.elastic.co/t/docker-filebeat-autodiscover-not-detecting-nginx-logs/239849)

<div class="topic-metadata">

**Author:** [@Fachtna\_Simi](https://discuss.elastic.co/u/Fachtna_Simi)\
**Replies:** 1\
**Last updated:** [July 6, 2020, 6:05pm UTC](https://discuss.elastic.co/t/docker-filebeat-autodiscover-not-detecting-nginx-logs/239849 "2020-07-06T18:05:16Z")

</div>

On my mac I am running nginx in a docker file and filebeat in a docker file. docker run -p 80:80 nginx The above command successfully runs nginx which I can visit in the browser and the output is printed to the console…

---

## [Filebeat setup kibana dashboard: limit to enabled modules](https://discuss.elastic.co/t/filebeat-setup-kibana-dashboard-limit-to-enabled-modules/239763)

<div class="topic-metadata">

**Author:** [@pauleccm](https://discuss.elastic.co/u/pauleccm)\
**Replies:** 1\
**Last updated:** [July 6, 2020, 3:24pm UTC](https://discuss.elastic.co/t/filebeat-setup-kibana-dashboard-limit-to-enabled-modules/239763 "2020-07-06T15:24:25Z")

</div>

When I enable a module https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-modules.html like this, and run the filebeat setup command, the kibana dashboards for ALL default modules are created, …

---

## [Monitoring using metricbeat](https://discuss.elastic.co/t/monitoring-using-metricbeat/236727)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 8\
**Last updated:** [July 6, 2020, 3:18pm UTC](https://discuss.elastic.co/t/monitoring-using-metricbeat/236727 "2020-07-06T15:18:14Z")

</div>

I turned on self-monitoring that I want to roll-back and migrate to metricbeat based monitoring for the cluster. I clicked on set self-monitoring which led to the following: I searched elasticsearch.yml but could no…

---

## [How to sends logs from remote machine to Logstash or Elastic Search](https://discuss.elastic.co/t/how-to-sends-logs-from-remote-machine-to-logstash-or-elastic-search/239791)

<div class="topic-metadata">

**Author:** [@pankaj0172](https://discuss.elastic.co/u/pankaj0172)\
**Replies:** 5\
**Last updated:** [July 6, 2020, 7:23am UTC](https://discuss.elastic.co/t/how-to-sends-logs-from-remote-machine-to-logstash-or-elastic-search/239791 "2020-07-06T07:23:13Z")

</div>

Hi There, I have installed Elasticsearch, Logstash, and Kibana (Elastic Stack) on Ubuntu 18.04 as suggested in the below article and everything configured correctly.. But I have installed metric beat on the remote wi…

---

## [Filebeat Suddenly duplicating events more than 4 entries per log](https://discuss.elastic.co/t/filebeat-suddenly-duplicating-events-more-than-4-entries-per-log/239878)

<div class="topic-metadata">

**Author:** [@uchenebed](https://discuss.elastic.co/u/uchenebed)\
**Replies:** 0\
**Last updated:** [July 4, 2020, 8:56am UTC](https://discuss.elastic.co/t/filebeat-suddenly-duplicating-events-more-than-4-entries-per-log/239878 "2020-07-04T08:56:17Z")

</div>

Hi All, I have ben using filebeat 7.5.2 to forward custom application logs to logstash, recently i noticed a sharp rise in number of events being received by logstash and also realised that i was now getting duplicate lo…

---

## [Unable to see winlogbeat events](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671)

<div class="topic-metadata">

**Author:** [@nkrshna](https://discuss.elastic.co/u/nkrshna)\
**Replies:** 7\
**Last updated:** [July 3, 2020, 5:35pm UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-events/234671 "2020-07-03T17:35:32Z")

</div>

Hi, I'm new to Elasticsearch and configured 7 version running on CentOS 7. Trying to configure windows server to send event logs to ESS server but I'm not able to see any events under winlogbeat index pattern. Below is…

---

## [Filebeat log Not Coming to Logstash](https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608)

<div class="topic-metadata">

**Author:** [@sumitsahay](https://discuss.elastic.co/u/sumitsahay)\
**Replies:** 5\
**Last updated:** [July 3, 2020, 10:09am UTC](https://discuss.elastic.co/t/filebeat-log-not-coming-to-logstash/239608 "2020-07-03T10:09:19Z")

</div>

Hi All, I am having fliebeat install on my client machine and elk masternode on different vm. I Configured everything though logs are not coming to Kibana index and index is not getting created.

---

## [Filebeat as Datasource for Elastic SIEM](https://discuss.elastic.co/t/filebeat-as-datasource-for-elastic-siem/239756)

<div class="topic-metadata">

**Author:** [@robincher](https://discuss.elastic.co/u/robincher)\
**Replies:** 0\
**Last updated:** [July 3, 2020, 8:42am UTC](https://discuss.elastic.co/t/filebeat-as-datasource-for-elastic-siem/239756 "2020-07-03T08:42:23Z")

</div>

Hi , I am looking at piping logs for MS Azure AD to SIEM, specifically for investigating attempted logins and related activity with authentication data gathered by Auditbeat and the Filebeat system modules. From Kibana…

---

## [I am facing some issues while trying to parse XML from some host by using port without XML,](https://discuss.elastic.co/t/i-am-facing-some-issues-while-trying-to-parse-xml-from-some-host-by-using-port-without-xml/239733)

<div class="topic-metadata">

**Author:** [@Radha](https://discuss.elastic.co/u/Radha)\
**Replies:** 1\
**Last updated:** [July 3, 2020, 7:58am UTC](https://discuss.elastic.co/t/i-am-facing-some-issues-while-trying-to-parse-xml-from-some-host-by-using-port-without-xml/239733 "2020-07-03T07:58:17Z")

</div>

filbeat yml file created: type: log paths: O:\\path\\sample.xml fields: Branch: ${BRANCH} Major\_Minor: ${MAJOR\_MINOR} Build\_Time: ${BUILD\_TIME} multiline.pattern: '^\<?xml.\*?\>' multiline.negate: true multiline.…

---

## [Crypto/rsa: verification error - using heartbeat](https://discuss.elastic.co/t/crypto-rsa-verification-error-using-heartbeat/239427)

<div class="topic-metadata">

**Author:** [@Peter\_Steenbergen](https://discuss.elastic.co/u/Peter_Steenbergen)\
**Replies:** 6\
**Last updated:** [July 3, 2020, 7:21am UTC](https://discuss.elastic.co/t/crypto-rsa-verification-error-using-heartbeat/239427 "2020-07-03T07:21:31Z")

</div>

Hi, I am getting a crypto/rsa error: verification error with heartbeat version 7.4.2. The website is using LetsEncrypt and the SSL was verified with ssllabs with a grade of A. What can be the issue here? - type: http…

---

## [Filebeat encrypted communication to Logstash](https://discuss.elastic.co/t/filebeat-encrypted-communication-to-logstash/239739)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 2\
**Last updated:** [July 3, 2020, 7:10am UTC](https://discuss.elastic.co/t/filebeat-encrypted-communication-to-logstash/239739 "2020-07-03T07:10:50Z")

</div>

Dears, I have to enable SSL/TLS in Filebeat configuration to encrypt communication to Logstash. Right now my ELK cluster use SSL/TLS configuration between nodes with self-signed certificates. Logstash is started on ea…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=231)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=233)
