# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=233

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 234

---

## [\[Filebeat\] Using the System module while running Filebeat in docker](https://discuss.elastic.co/t/filebeat-using-the-system-module-while-running-filebeat-in-docker/239700)

<div class="topic-metadata">

**Author:** [@miande](https://discuss.elastic.co/u/miande)\
**Replies:** 0\
**Last updated:** [July 2, 2020, 6:41pm UTC](https://discuss.elastic.co/t/filebeat-using-the-system-module-while-running-filebeat-in-docker/239700 "2020-07-02T18:41:49Z")

</div>

When running Filebeat as a docker container and using the System module in the filebeat.yml it requires access to the host's file system for reading from /var/logs/ (easy enough) but once the System module pulls the logs…

---

## [Metricbeat deamonset no system metrics](https://discuss.elastic.co/t/metricbeat-deamonset-no-system-metrics/239130)

<div class="topic-metadata">

**Author:** [@Bogdan\_Milescu](https://discuss.elastic.co/u/Bogdan_Milescu)\
**Replies:** 1\
**Last updated:** [July 2, 2020, 5:27pm UTC](https://discuss.elastic.co/t/metricbeat-deamonset-no-system-metrics/239130 "2020-07-02T17:27:14Z")

</div>

Hey guys, I have the deployed metricbeat as a daemonset on a k8s cluster. I have added the system module in order to monitor worker nodes metrics but it seems that no system metrics are recorded. The configuration is as…

---

## [Filebeat logs /tmp/filebeat.{host}.root.log.INFO.{date}](https://discuss.elastic.co/t/filebeat-logs-tmp-filebeat-host-root-log-info-date/239607)

<div class="topic-metadata">

**Author:** [@phivos](https://discuss.elastic.co/u/phivos)\
**Replies:** 2\
**Last updated:** [July 2, 2020, 3:31pm UTC](https://discuss.elastic.co/t/filebeat-logs-tmp-filebeat-host-root-log-info-date/239607 "2020-07-02T15:31:37Z")

</div>

Same case with this closed topic Filebeat is deployed on a kubernetes cluster as daemon set, and generates thousands of files under /tmp. This caused extremely high inode usage preventing the system from being able to …

---

## [X-ProxiedEntitiesChain - Has anyone used it in a heartbeat?](https://discuss.elastic.co/t/x-proxiedentitieschain-has-anyone-used-it-in-a-heartbeat/239159)

<div class="topic-metadata">

**Author:** [@soooooobusy](https://discuss.elastic.co/u/soooooobusy)\
**Replies:** 1\
**Last updated:** [July 2, 2020, 3:08pm UTC](https://discuss.elastic.co/t/x-proxiedentitieschain-has-anyone-used-it-in-a-heartbeat/239159 "2020-07-02T15:08:41Z")

</div>

Hi, I'm trying to get a check.request to a RESTful endpoint, using GET and headers of Accept and X-ProxiedEntitiesChain, but I can't seem to pass across the Chain correctly to get authorisation. I'm using - Accept: 'a…

---

## [Winlogbeat Could not index event to Elasticsearch (source.ip: LOCAL)](https://discuss.elastic.co/t/winlogbeat-could-not-index-event-to-elasticsearch-source-ip-local/239658)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 0\
**Last updated:** [July 2, 2020, 2:56pm UTC](https://discuss.elastic.co/t/winlogbeat-could-not-index-event-to-elasticsearch-source-ip-local/239658 "2020-07-02T14:56:18Z")

</div>

I am seeing quite a lot of errors in Logstash for Winlogbeat events failing to index. The error indicates events are coming in with "source.ip: LOCAL" which is not a valid IP address. If for some reason the literal strin…

---

## [Do we loose backpressure-sensitive protocol by inserting Kafka between Filebeat and Elasticsearch](https://discuss.elastic.co/t/do-we-loose-backpressure-sensitive-protocol-by-inserting-kafka-between-filebeat-and-elasticsearch/239644)

<div class="topic-metadata">

**Author:** [@yguubiqube](https://discuss.elastic.co/u/yguubiqube)\
**Replies:** 0\
**Last updated:** [July 2, 2020, 1:34pm UTC](https://discuss.elastic.co/t/do-we-loose-backpressure-sensitive-protocol-by-inserting-kafka-between-filebeat-and-elasticsearch/239644 "2020-07-02T13:34:20Z")

</div>

Hi, this is a design investigation. On many docker containers, we will have Filebeat that reads logs (generated by many services). On one docker container we will have Elasticsearch that receives and indexes the logs. …

---

## [Metricbeat - PostgreSQL authentication method](https://discuss.elastic.co/t/metricbeat-postgresql-authentication-method/239641)

<div class="topic-metadata">

**Author:** [@adminunix](https://discuss.elastic.co/u/adminunix)\
**Replies:** 0\
**Last updated:** [July 2, 2020, 1:17pm UTC](https://discuss.elastic.co/t/metricbeat-postgresql-authentication-method/239641 "2020-07-02T13:17:52Z")

</div>

Hello, I am trying to use postgresql module for metricbeat but I get the following error: error in QueryStats: failed to obtain a connection with the database: pq: Ident authentication failed for user "postgres" My Po…

---

## [Exiting: error loading config file: open filebeat.yml: permission denied](https://discuss.elastic.co/t/exiting-error-loading-config-file-open-filebeat-yml-permission-denied/239490)

<div class="topic-metadata">

**Author:** [@mschindl](https://discuss.elastic.co/u/mschindl)\
**Replies:** 1\
**Last updated:** [July 2, 2020, 1:17pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-open-filebeat-yml-permission-denied/239490 "2020-07-02T13:17:42Z")

</div>

I try to specifiy the config file for filebeat, but all the time I get a permission denied error in the container. User root is set and strict.perms=false too. I'm using following versions: \[root@mschindl-lnx1 config-d…

---

## [Metricbeat reports incorrect (outdated?) kernel version](https://discuss.elastic.co/t/metricbeat-reports-incorrect-outdated-kernel-version/237183)

<div class="topic-metadata">

**Author:** [@archon810](https://discuss.elastic.co/u/archon810)\
**Replies:** 4\
**Last updated:** [July 2, 2020, 9:28am UTC](https://discuss.elastic.co/t/metricbeat-reports-incorrect-outdated-kernel-version/237183 "2020-07-02T09:28:44Z")

</div>

Version: 7.7.1 Operating System: OpenSUSE 15.1 I have several hosts running metricbeat. One of them is currently reporting an incorrect kernel version (5.4.10): In reality, this host is on 5.1.17: uname -a Linux hi…

---

## [To set an index name with filebeat](https://discuss.elastic.co/t/to-set-an-index-name-with-filebeat/239397)

<div class="topic-metadata">

**Author:** [@jang](https://discuss.elastic.co/u/jang)\
**Replies:** 1\
**Last updated:** [July 2, 2020, 5:25am UTC](https://discuss.elastic.co/t/to-set-an-index-name-with-filebeat/239397 "2020-07-02T05:25:43Z")

</div>

hello, I pass the log to logstash via Filebit. I currently collect logs from three path. I'm trying to set index name on the filebit. I want to set an index name for each path. How can I set each index name? now se…

---

## [Auditbeat 7.8.0 socket only send data in 2 minutes](https://discuss.elastic.co/t/auditbeat-7-8-0-socket-only-send-data-in-2-minutes/239199)

<div class="topic-metadata">

**Author:** [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Replies:** 2\
**Last updated:** [July 2, 2020, 5:18am UTC](https://discuss.elastic.co/t/auditbeat-7-8-0-socket-only-send-data-in-2-minutes/239199 "2020-07-02T05:18:33Z")

</div>

Hi all, I have something weird since upgrade to 7.8 of auditbeat, below the log that produce by auditbeat I use Centos 7.6 with kernel Linux sync-02 3.10.0-1062.18.1.el7.x86\_64 #1 SMP Tue Mar 17 23:49:17 UTC 2020 x86\_…

---

## [JSON field expansion](https://discuss.elastic.co/t/json-field-expansion/239544)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 2\
**Last updated:** [July 1, 2020, 11:14pm UTC](https://discuss.elastic.co/t/json-field-expansion/239544 "2020-07-01T23:14:58Z")

</div>

Over the past couple days I've read a bunch of posts here and on some other forums, plus official documentation, but there is something that just isn't "clicking"... Goal: Expand/explode/parse a document field that cont…

---

## [Could not locate that index-pattern-field (id: winlog.login.id)](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-winlog-login-id/239543)

<div class="topic-metadata">

**Author:** [@minorsatellite](https://discuss.elastic.co/u/minorsatellite)\
**Replies:** 0\
**Last updated:** [July 1, 2020, 8:22pm UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-winlog-login-id/239543 "2020-07-01T20:22:30Z")

</div>

I am trying to add pre-built Winlogbeat visualizations to my new dashboard but I am encountering errors when events are processed by the Windows Security module. The error is: "Could not locate that index-pattern-field (…

---

## [Multiple Filebeats from multiple sources to multiple pipelines?](https://discuss.elastic.co/t/multiple-filebeats-from-multiple-sources-to-multiple-pipelines/239517)

<div class="topic-metadata">

**Author:** [@Asinus1223](https://discuss.elastic.co/u/Asinus1223)\
**Replies:** 0\
**Last updated:** [July 1, 2020, 3:47pm UTC](https://discuss.elastic.co/t/multiple-filebeats-from-multiple-sources-to-multiple-pipelines/239517 "2020-07-01T15:47:18Z")

</div>

Let me see if I am doing this right. I have two logs from two different servers that I want to process in Logstash then pass on to Elasticsearch. Both files contain different information. I want to use the Filebeats sh…

---

## [Tutorials or webinar links for developing chatbot](https://discuss.elastic.co/t/tutorials-or-webinar-links-for-developing-chatbot/239516)

<div class="topic-metadata">

**Author:** [@Sushant\_Sawant](https://discuss.elastic.co/u/Sushant_Sawant)\
**Replies:** 0\
**Last updated:** [July 1, 2020, 3:44pm UTC](https://discuss.elastic.co/t/tutorials-or-webinar-links-for-developing-chatbot/239516 "2020-07-01T15:44:06Z")

</div>

I have packetbeat and winlogbeat data in elastic search and kibana. Now I have to create the chatbot for querying on the data. If any one know how to create anything like this that would be helpful.

---

## [Kibana - Syslog and Winlogbeat are not visible](https://discuss.elastic.co/t/kibana-syslog-and-winlogbeat-are-not-visible/239457)

<div class="topic-metadata">

**Author:** [@Phillip](https://discuss.elastic.co/u/Phillip)\
**Replies:** 0\
**Last updated:** [July 1, 2020, 10:26am UTC](https://discuss.elastic.co/t/kibana-syslog-and-winlogbeat-are-not-visible/239457 "2020-07-01T10:26:03Z")

</div>

Hey, I configured logstash to get data from beats and syslog like here: input { beats { port =\> 5044 ssl =\> true ssl\_certificate =\> "/etc/pki/tls/certs/logstash.crt" ssl\_key =\> "/etc/pki/tls/private/l…

---

## [Azure Module in Metricbeat : Monitor Metricset](https://discuss.elastic.co/t/azure-module-in-metricbeat-monitor-metricset/236746)

<div class="topic-metadata">

**Author:** [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Replies:** 13\
**Last updated:** [July 1, 2020, 2:07pm UTC](https://discuss.elastic.co/t/azure-module-in-metricbeat-monitor-metricset/236746 "2020-07-01T14:07:00Z")

</div>

Hello, I want to make efficient use of "Monitor" metricset in "Azure" module on metricbeat side. I am looking to get relevant information regarding disk usage, memory availability of my Azure VMs. The issue is that I …

---

## [Empty String on windows.service.start\_type field while using Metricbeat 7.8.0](https://discuss.elastic.co/t/empty-string-on-windows-service-start-type-field-while-using-metricbeat-7-8-0/238056)

<div class="topic-metadata">

**Author:** [@Jamaluddin](https://discuss.elastic.co/u/Jamaluddin)\
**Replies:** 3\
**Last updated:** [July 1, 2020, 1:41pm UTC](https://discuss.elastic.co/t/empty-string-on-windows-service-start-type-field-while-using-metricbeat-7-8-0/238056 "2020-07-01T13:41:17Z")

</div>

Hi Dear Friends and Master of ELK Stack, I want to ask/report about missing value on windows.service.start\_type field while using Metricbeat 7.8.0. While using Metricbeat 7.7.1 the values of windows.service.start\_type …

---

## [Add\_kubernetes\_metadata logs\_path does not use provided value from config](https://discuss.elastic.co/t/add-kubernetes-metadata-logs-path-does-not-use-provided-value-from-config/239482)

<div class="topic-metadata">

**Author:** [@ntx-ben](https://discuss.elastic.co/u/ntx-ben)\
**Replies:** 0\
**Last updated:** [July 1, 2020, 12:27pm UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-logs-path-does-not-use-provided-value-from-config/239482 "2020-07-01T12:27:51Z")

</div>

I just deployed filebeat 7.8.0 in Kubernetes. I cannot get the add\_kubernetes\_metadata to work correctly using logs in /var/log/containers folder location. I need to use that location because I am filtering on container …

---

## [Filebeat error using processors on inputs file](https://discuss.elastic.co/t/filebeat-error-using-processors-on-inputs-file/239131)

<div class="topic-metadata">

**Author:** [@willyaranda\_vonage](https://discuss.elastic.co/u/willyaranda_vonage)\
**Replies:** 1\
**Last updated:** [July 1, 2020, 11:23am UTC](https://discuss.elastic.co/t/filebeat-error-using-processors-on-inputs-file/239131 "2020-07-01T11:23:00Z")

</div>

Hi, I have tested filebeat correctly using one single filebeat.yml file and works perfectly with my processors. I have split it into a input yml file and the processor stops working. I have tried a lot of things, and i…

---

## [Filebeat DNS lookup failure after upgrading coreDNS](https://discuss.elastic.co/t/filebeat-dns-lookup-failure-after-upgrading-coredns/238621)

<div class="topic-metadata">

**Author:** [@Tech\_Techie](https://discuss.elastic.co/u/Tech_Techie)\
**Replies:** 1\
**Last updated:** [July 1, 2020, 8:42am UTC](https://discuss.elastic.co/t/filebeat-dns-lookup-failure-after-upgrading-coredns/238621 "2020-07-01T08:42:27Z")

</div>

I was upgrading the EKS version to 1.15 and after I upgrade the coreDNS version to 1.6.6. I got an error log from the filebeat 2020-06-20T20:00:43.298Z WARN transport/tcp.go:53 DNS lookup failure "logstash-collection-he…

---

## [When should I use filebeat instead of logstash](https://discuss.elastic.co/t/when-should-i-use-filebeat-instead-of-logstash/239415)

<div class="topic-metadata">

**Author:** [@Willem\_Jenniskens](https://discuss.elastic.co/u/Willem_Jenniskens)\
**Replies:** 2\
**Last updated:** [July 1, 2020, 7:27am UTC](https://discuss.elastic.co/t/when-should-i-use-filebeat-instead-of-logstash/239415 "2020-07-01T07:27:31Z")

</div>

I have a litte trouble understanding filebeat. What can I do with filebeat that I cannot do with logstash? I use logstash to load a bunch of logfiles into ElasticSearch. This works fine. What problem does filebeat solve?…

---

## [Fail-over strategy and avoid duplication of events for multiple winlogbeat sending same events to elasticsearch using Windows Event Collector](https://discuss.elastic.co/t/fail-over-strategy-and-avoid-duplication-of-events-for-multiple-winlogbeat-sending-same-events-to-elasticsearch-using-windows-event-collector/239095)

<div class="topic-metadata">

**Author:** [@sid159](https://discuss.elastic.co/u/sid159)\
**Replies:** 3\
**Last updated:** [July 1, 2020, 7:08am UTC](https://discuss.elastic.co/t/fail-over-strategy-and-avoid-duplication-of-events-for-multiple-winlogbeat-sending-same-events-to-elasticsearch-using-windows-event-collector/239095 "2020-07-01T07:08:49Z")

</div>

Background (Infrastructure) Events were collected from about thousands of machine on centralize Windows Event Collector (WEC) server. Windows Event Forwarder configure using GPO to collect events of each machine on WEC.…

---

## [Uptime/Metrics interlinked tabs](https://discuss.elastic.co/t/uptime-metrics-interlinked-tabs/239400)

<div class="topic-metadata">

**Author:** [@bevano](https://discuss.elastic.co/u/bevano)\
**Replies:** 0\
**Last updated:** [July 1, 2020, 4:26am UTC](https://discuss.elastic.co/t/uptime-metrics-interlinked-tabs/239400 "2020-07-01T04:26:10Z")

</div>

Hi All, I have started installing Metricbeat across all my servers, with one instance of heartbeat pinging all of them as well. When I select 'Host in Uptime' on the generic metrics tab in kibana it brings me to the ge…

---

## [Filebeat on kubernetes not pulling logs from all pods](https://discuss.elastic.co/t/filebeat-on-kubernetes-not-pulling-logs-from-all-pods/239379)

<div class="topic-metadata">

**Author:** [@eyesmoker](https://discuss.elastic.co/u/eyesmoker)\
**Replies:** 0\
**Last updated:** [June 30, 2020, 11:24pm UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes-not-pulling-logs-from-all-pods/239379 "2020-06-30T23:24:52Z")

</div>

Hi, I am running file beat as daemonset on the k8s. It is pulling logs from few pods and not all. Here is the simple config used. filebeat.autodiscover: providers: - type: kubernetes node: ${NOD…

---

## [Winlogbeat Starts then Stops - Server 2016](https://discuss.elastic.co/t/winlogbeat-starts-then-stops-server-2016/239062)

<div class="topic-metadata">

**Author:** [@minorsatellite](https://discuss.elastic.co/u/minorsatellite)\
**Replies:** 7\
**Last updated:** [June 30, 2020, 11:24pm UTC](https://discuss.elastic.co/t/winlogbeat-starts-then-stops-server-2016/239062 "2020-06-30T23:24:49Z")

</div>

In the log is the following error message: 2020-06-28T22:46:03.550-0700 INFO \[monitoring\] log/log.go:131 Stopping metrics logging. 2020-06-28T22:46:03.550-0700 INFO instance/beat.go:460 winlogbeat stopped. 2020-06-28T…

---

## [Why processors need inode/fileid in the event (why is file.StateOS under Private?)](https://discuss.elastic.co/t/why-processors-need-inode-fileid-in-the-event-why-is-file-stateos-under-private/239307)

<div class="topic-metadata">

**Author:** [@rmauri](https://discuss.elastic.co/u/rmauri)\
**Replies:** 0\
**Last updated:** [June 30, 2020, 1:01pm UTC](https://discuss.elastic.co/t/why-processors-need-inode-fileid-in-the-event-why-is-file-stateos-under-private/239307 "2020-06-30T13:01:40Z")

</div>

I have filebeat, built with a custom regexprocessor, that processes events from input log files that have no date, only time, in the log messages. The regexprocessor constructs the @timestamp using the time from the log…

---

## [How does the Beats load balancing option work?](https://discuss.elastic.co/t/how-does-the-beats-load-balancing-option-work/239358)

<div class="topic-metadata">

**Author:** [@Guerreiro\_Sousa](https://discuss.elastic.co/u/Guerreiro_Sousa)\
**Replies:** 0\
**Last updated:** [June 30, 2020, 6:12pm UTC](https://discuss.elastic.co/t/how-does-the-beats-load-balancing-option-work/239358 "2020-06-30T18:12:42Z")

</div>

How does balancing work? Does Beat monitor server availability and distribute events among available machines?

---

## [Filebeat modules doesn' follow symlinks](https://discuss.elastic.co/t/filebeat-modules-doesn-follow-symlinks/239357)

<div class="topic-metadata">

**Author:** [@Elbanby](https://discuss.elastic.co/u/Elbanby)\
**Replies:** 0\
**Last updated:** [June 30, 2020, 6:11pm UTC](https://discuss.elastic.co/t/filebeat-modules-doesn-follow-symlinks/239357 "2020-06-30T18:11:09Z")

</div>

Hi folks, I am running into a problem where I can't seem to get the Nginx module (ingress-controller) to follow symlinks. Is there is a way to accomplish that? If not, what is the recommended approach to do so? There i…

---

## [Unable to send input log to Elastic search via filebeat docker installation](https://discuss.elastic.co/t/unable-to-send-input-log-to-elastic-search-via-filebeat-docker-installation/237973)

<div class="topic-metadata">

**Author:** [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Replies:** 2\
**Last updated:** [June 30, 2020, 4:50pm UTC](https://discuss.elastic.co/t/unable-to-send-input-log-to-elastic-search-via-filebeat-docker-installation/237973 "2020-06-30T16:50:37Z")

</div>

Hello, I have installed ELK in 3 different containers. All are working fine. Pulled docker image and Installed Filebeat in docker container with below command: docker run -d --name=filebeat --user=root --volume="…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=232)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=234)
