# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=234

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 235

---

## [Timestamping issues with Winlogbeat and Logstash](https://discuss.elastic.co/t/timestamping-issues-with-winlogbeat-and-logstash/239325)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 0\
**Last updated:** [June 30, 2020, 2:39pm UTC](https://discuss.elastic.co/t/timestamping-issues-with-winlogbeat-and-logstash/239325 "2020-06-30T14:39:52Z")

</div>

Hello, Our setup is: Winlogbeat on endpoints which ships data to an API API sends logs to sqs queue Logstash VM picks up from sqs and contextualises logs then forwards them on to another sqs queue Another applicatio…

---

## [Kubernetes module](https://discuss.elastic.co/t/kubernetes-module/239329)

<div class="topic-metadata">

**Author:** [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Replies:** 0\
**Last updated:** [June 30, 2020, 2:53pm UTC](https://discuss.elastic.co/t/kubernetes-module/239329 "2020-06-30T14:53:01Z")

</div>

Hello, I hope you guys are doing well! I am running ELK stack on kubernetes, along with metricbeat. I am using Kubernetes module to get relevant data regarding the pods performance. Everything is working as expected. …

---

## [Configuration for ELK+filebeat with docker-compose](https://discuss.elastic.co/t/configuration-for-elk-filebeat-with-docker-compose/239239)

<div class="topic-metadata">

**Author:** [@Govinda8594](https://discuss.elastic.co/u/Govinda8594)\
**Replies:** 0\
**Last updated:** [June 30, 2020, 7:28am UTC](https://discuss.elastic.co/t/configuration-for-elk-filebeat-with-docker-compose/239239 "2020-06-30T07:28:24Z")

</div>

Hello Team, i am new to ELK and i have problem with setting this configuration ,My filebeat.yml is taking input from docker log (with respective file path) and send this log to logstash for indexing based on log file but…

---

## [Winlogbeat gives unathorized error when using keystore](https://discuss.elastic.co/t/winlogbeat-gives-unathorized-error-when-using-keystore/238891)

<div class="topic-metadata">

**Author:** [@kaushas](https://discuss.elastic.co/u/kaushas)\
**Replies:** 2\
**Last updated:** [June 30, 2020, 1:00pm UTC](https://discuss.elastic.co/t/winlogbeat-gives-unathorized-error-when-using-keystore/238891 "2020-06-30T13:00:28Z")

</div>

When using winlogbeat Keystore for PWD, I get 401 unauthorized error. Just passing elastic password value itself in the config file works. I have looked at few of these issues raised by others already but none of the so…

---

## [Custom logs not appearing in visualization](https://discuss.elastic.co/t/custom-logs-not-appearing-in-visualization/239118)

<div class="topic-metadata">

**Author:** [@TheNmaptomyHeartBeat](https://discuss.elastic.co/u/TheNmaptomyHeartBeat)\
**Replies:** 2\
**Last updated:** [June 30, 2020, 12:56pm UTC](https://discuss.elastic.co/t/custom-logs-not-appearing-in-visualization/239118 "2020-06-30T12:56:43Z")

</div>

Hi all, I created custom logs in NGINX to log for http.response.time and http.response.upstream.time. I updated the grok filter on the NGINX module pipeline for Filebeat. I am receiving the data on the Filebeat-\* inde…

---

## [Beat for RDD files](https://discuss.elastic.co/t/beat-for-rdd-files/239299)

<div class="topic-metadata">

**Author:** [@anikajaninaelfie](https://discuss.elastic.co/u/anikajaninaelfie)\
**Replies:** 0\
**Last updated:** [June 30, 2020, 12:42pm UTC](https://discuss.elastic.co/t/beat-for-rdd-files/239299 "2020-06-30T12:42:26Z")

</div>

Hello there! I want to read RDD Files and transfer them to Kibana. Unfortunately, Filebeat can't manage that. Is there any other solution than to develop a beat for that purpose. I fount this post from 2016: Any prog…

---

## [Winlogbeat not sending logs via logstash on port 5044](https://discuss.elastic.co/t/winlogbeat-not-sending-logs-via-logstash-on-port-5044/237327)

<div class="topic-metadata">

**Author:** [@proxx](https://discuss.elastic.co/u/proxx)\
**Replies:** 1\
**Last updated:** [June 30, 2020, 11:46am UTC](https://discuss.elastic.co/t/winlogbeat-not-sending-logs-via-logstash-on-port-5044/237327 "2020-06-30T11:46:56Z")

</div>

My Logstash is running on port 5044, however when i started my Winlogbeat service on my windows server, which it show running, checking my Kibana i couldn't find the indices to index Here is my Logstash result \[root@o…

---

## [Filebeat and Logstash are running but no output on logstash](https://discuss.elastic.co/t/filebeat-and-logstash-are-running-but-no-output-on-logstash/239255)

<div class="topic-metadata">

**Author:** [@falconpurple](https://discuss.elastic.co/u/falconpurple)\
**Replies:** 1\
**Last updated:** [June 30, 2020, 11:42am UTC](https://discuss.elastic.co/t/filebeat-and-logstash-are-running-but-no-output-on-logstash/239255 "2020-06-30T11:42:31Z")

</div>

I have configured elk stack with filebeat. I am standing logs from filebeat to logstash but it's not running. The configuration in filebeat.yml : filebeat.inputs: - type: log enabled: true -C:/Users/mohnadik/…

---

## [Metricbeat service don't start (Win2019)](https://discuss.elastic.co/t/metricbeat-service-dont-start-win2019/237972)

<div class="topic-metadata">

**Author:** [@DucretJe](https://discuss.elastic.co/u/DucretJe)\
**Replies:** 1\
**Last updated:** [June 30, 2020, 11:31am UTC](https://discuss.elastic.co/t/metricbeat-service-dont-start-win2019/237972 "2020-06-30T11:31:42Z")

</div>

Hello, I'm trying to install metricbeat on a Windows Server 2019. I'm using Elastic Metricbeat 7.8.0 installed with the .msi package. I begin with: .\\metricbeat.exe setup Overwritng ILM policy is disabled. Set \`setup…

---

## [Winlogbeat Failed to publish events caused by: lumberjack protocol error](https://discuss.elastic.co/t/winlogbeat-failed-to-publish-events-caused-by-lumberjack-protocol-error/238469)

<div class="topic-metadata">

**Author:** [@Phillip](https://discuss.elastic.co/u/Phillip)\
**Replies:** 1\
**Last updated:** [June 30, 2020, 11:14am UTC](https://discuss.elastic.co/t/winlogbeat-failed-to-publish-events-caused-by-lumberjack-protocol-error/238469 "2020-06-30T11:14:20Z")

</div>

Hi, I wanted to install winloagbeat on an Windows Server to get his informations. I forwarded the logs to lagstash, but after starting the service, the following problems are appearing: 2020-06-24T14:41:32.573+0200 ERR…

---

## [So seriously, what permissions do beats need?](https://discuss.elastic.co/t/so-seriously-what-permissions-do-beats-need/238958)

<div class="topic-metadata">

**Author:** [@sej7278](https://discuss.elastic.co/u/sej7278)\
**Replies:** 8\
**Last updated:** [June 30, 2020, 10:31am UTC](https://discuss.elastic.co/t/so-seriously-what-permissions-do-beats-need/238958 "2020-06-30T10:31:42Z")

</div>

So contrary to the docs even this lot doesn't work: POST /\_security/api\_key { "name": "{beat\_default\_index\_prefix}\_localhost", "role\_descriptors": { "{beat\_default\_index\_prefix}\_writer": { "cluster": \["mon…

---

## [Beat doesn't take in count index template configuration](https://discuss.elastic.co/t/beat-doesnt-take-in-count-index-template-configuration/239258)

<div class="topic-metadata">

**Author:** [@NeitoFR](https://discuss.elastic.co/u/NeitoFR)\
**Replies:** 0\
**Last updated:** [June 30, 2020, 9:04am UTC](https://discuss.elastic.co/t/beat-doesnt-take-in-count-index-template-configuration/239258 "2020-06-30T09:04:15Z")

</div>

I'm using the ELK Stack in version 7.5.2 in Docker container on a CentOS7 AWS Machine. My goal is to load filebeat Kibana dashboards with custom index pattern set (to replace the filebeat-\* default). Here is the beginn…

---

## [Configuring Packetbeat with Logstash and GeoIP](https://discuss.elastic.co/t/configuring-packetbeat-with-logstash-and-geoip/239208)

<div class="topic-metadata">

**Author:** [@chancewwr](https://discuss.elastic.co/u/chancewwr)\
**Replies:** 3\
**Last updated:** [June 30, 2020, 8:29am UTC](https://discuss.elastic.co/t/configuring-packetbeat-with-logstash-and-geoip/239208 "2020-06-30T08:29:53Z")

</div>

First, hello all! I am a bit new to the elastic stack as a whole but am learning quickly thanks to the great documentation available. One piece of documentation I've found lacking is how exactly to configure packetbeat t…

---

## [Is it possible to suppress gc logs in filebeat elasticsearch module?](https://discuss.elastic.co/t/is-it-possible-to-suppress-gc-logs-in-filebeat-elasticsearch-module/239066)

<div class="topic-metadata">

**Author:** [@Webtrend\_Inc](https://discuss.elastic.co/u/Webtrend_Inc)\
**Replies:** 1\
**Last updated:** [June 30, 2020, 2:48am UTC](https://discuss.elastic.co/t/is-it-possible-to-suppress-gc-logs-in-filebeat-elasticsearch-module/239066 "2020-06-30T02:48:56Z")

</div>

I tried editing the elasticsearch.yml file in modules.d folder but it does not seem to be working I tried both commenting out gc section and tried gc.enabled: false but none of them seem to be working. When this module…

---

## [AuditBeat failed to create audit client: protocol not supported](https://discuss.elastic.co/t/auditbeat-failed-to-create-audit-client-protocol-not-supported/138601)

<div class="topic-metadata">

**Author:** [@Nicholas\_Amon](https://discuss.elastic.co/u/Nicholas_Amon)\
**Replies:** 5\
**Last updated:** [June 29, 2020, 9:21pm UTC](https://discuss.elastic.co/t/auditbeat-failed-to-create-audit-client-protocol-not-supported/138601 "2020-06-29T21:21:13Z")

</div>

Auditbeat is failing to start successfully with the error message: 2018-07-04T18:01:32.410Z ERROR instance/beat.go:691 Exiting: 1 error: 1 error: failed to create audit client: failed to create audit client: protocol no…

---

## [Auditbeat reliance on auditd](https://discuss.elastic.co/t/auditbeat-reliance-on-auditd/239193)

<div class="topic-metadata">

**Author:** [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Replies:** 0\
**Last updated:** [June 29, 2020, 8:49pm UTC](https://discuss.elastic.co/t/auditbeat-reliance-on-auditd/239193 "2020-06-29T20:49:22Z")

</div>

Hello, question, on my Centos7 servers, if I install auditbeat, do I need to have auditd process running or is auditbeat able to pick up all audit events by itself? Should I run both auditd and auditbeat services, or o…

---

## [Metrics from structured logfile](https://discuss.elastic.co/t/metrics-from-structured-logfile/239167)

<div class="topic-metadata">

**Author:** [@Marcel27](https://discuss.elastic.co/u/Marcel27)\
**Replies:** 0\
**Last updated:** [June 29, 2020, 6:19pm UTC](https://discuss.elastic.co/t/metrics-from-structured-logfile/239167 "2020-06-29T18:19:46Z")

</div>

I have an application which logs periodicly to a file like: {"field1": 21, "field2": 45, "utctime": "2020-06-26 13:48:36,", "event": "test1"} {"field1": 62, "field2": 15, "utctime": "2020-06-26 13:53:36,", "event": "tes…

---

## [ERROR instance/beat.go:932 Exiting: No outputs are defined. Please define one under the output section](https://discuss.elastic.co/t/error-instance-beat-go-932-exiting-no-outputs-are-defined-please-define-one-under-the-output-section/239153)

<div class="topic-metadata">

**Author:** [@Lin2020](https://discuss.elastic.co/u/Lin2020)\
**Replies:** 0\
**Last updated:** [June 29, 2020, 3:57pm UTC](https://discuss.elastic.co/t/error-instance-beat-go-932-exiting-no-outputs-are-defined-please-define-one-under-the-output-section/239153 "2020-06-29T15:57:20Z")

</div>

"Hi, I am very new to ELK stack, kindly support me. I am currently configuring elasticsearch, Logstash, beats and kibana v7.7.1 to collect logs from windows server, Linux server, network devices and application logs in…

---

## [Why doesn’t change file name of source in ~/data/registry/filebeat/data.json?](https://discuss.elastic.co/t/why-doesn-t-change-file-name-of-source-in-data-registry-filebeat-data-json/239077)

<div class="topic-metadata">

**Author:** [@seungdols](https://discuss.elastic.co/u/seungdols)\
**Replies:** 0\
**Last updated:** [June 29, 2020, 8:48am UTC](https://discuss.elastic.co/t/why-doesn-t-change-file-name-of-source-in-data-registry-filebeat-data-json/239077 "2020-06-29T08:48:14Z")

</div>

Hello. There are a few questions about filebeat 7.6.0. While writing the filebeat, the file bit pattern is used as shown below. -/seungdols/logs/node/server/server.log -/seungdols/logs/node/server/server.log.\* And wh…

---

## [Filebeat putting too much load on the system. Seems to be related to gc.log](https://discuss.elastic.co/t/filebeat-putting-too-much-load-on-the-system-seems-to-be-related-to-gc-log/238966)

<div class="topic-metadata">

**Author:** [@Webtrend\_Inc](https://discuss.elastic.co/u/Webtrend_Inc)\
**Replies:** 2\
**Last updated:** [June 29, 2020, 7:46am UTC](https://discuss.elastic.co/t/filebeat-putting-too-much-load-on-the-system-seems-to-be-related-to-gc-log/238966 "2020-06-29T07:46:20Z")

</div>

On our elastic 7.7.1 stack, when we enabled our elastic log ingestion via filebeat, we saw a significant load on our data and ingestion nodes. Our log path parameter was defined as /var/log/elasticsearch/\*.json and all …

---

## [Failed to get audit status before adding rules](https://discuss.elastic.co/t/failed-to-get-audit-status-before-adding-rules/239060)

<div class="topic-metadata">

**Author:** [@martin.ellis](https://discuss.elastic.co/u/martin.ellis)\
**Replies:** 1\
**Last updated:** [June 29, 2020, 7:37am UTC](https://discuss.elastic.co/t/failed-to-get-audit-status-before-adding-rules/239060 "2020-06-29T07:37:22Z")

</div>

When I start auditbeat I get this error message 2020-06-29T14:49:06.560+1000 ERROR \[auditd\] auditd/audit\_linux.go:148 Failure adding audit rules {"error": "failed to get audit status before adding…

---

## [Grok pattern is working if the "input" is a file, but not if the "input" is beats](https://discuss.elastic.co/t/grok-pattern-is-working-if-the-input-is-a-file-but-not-if-the-input-is-beats/238935)

<div class="topic-metadata">

**Author:** [@Aj\_t](https://discuss.elastic.co/u/Aj_t)\
**Replies:** 2\
**Last updated:** [June 27, 2020, 6:37pm UTC](https://discuss.elastic.co/t/grok-pattern-is-working-if-the-input-is-a-file-but-not-if-the-input-is-beats/238935 "2020-06-27T18:37:24Z")

</div>

Sorry about the long post. I have a multi-line CAS log I am shipping via filebeats to logstash running on a different server. Here's a sample of the original multi-line log: 2020-06-21 00:24:00,833 INFO \[org.apereo.ins…

---

## [How to change output data format in winlogbeat as influx](https://discuss.elastic.co/t/how-to-change-output-data-format-in-winlogbeat-as-influx/239053)

<div class="topic-metadata">

**Author:** [@kumarbn](https://discuss.elastic.co/u/kumarbn)\
**Replies:** 0\
**Last updated:** [June 29, 2020, 5:07am UTC](https://discuss.elastic.co/t/how-to-change-output-data-format-in-winlogbeat-as-influx/239053 "2020-06-29T05:07:25Z")

</div>

unable to change output data format as influx . currently getting alert in json format on kafka server ..please provide suggestions

---

## [Metricbeats only ships node\_stats, but not cluster\_stats to x-pack monitoring](https://discuss.elastic.co/t/metricbeats-only-ships-node-stats-but-not-cluster-stats-to-x-pack-monitoring/238948)

<div class="topic-metadata">

**Author:** [@souravsahoo](https://discuss.elastic.co/u/souravsahoo)\
**Replies:** 1\
**Last updated:** [June 28, 2020, 6:47pm UTC](https://discuss.elastic.co/t/metricbeats-only-ships-node-stats-but-not-cluster-stats-to-x-pack-monitoring/238948 "2020-06-28T18:47:10Z")

</div>

Hi, I have a 3 master, multiple data node architecture. Metricbeat's elasticsearch-xpack module is configured to ship elasticsearch metrics to a separate monitoring cluster. However, I see only node\_stats are sent and no…

---

## [How to packetbeat for captuer traffic switch cisco SPAN port](https://discuss.elastic.co/t/how-to-packetbeat-for-captuer-traffic-switch-cisco-span-port/239028)

<div class="topic-metadata">

**Author:** [@jam\_mahmoudi](https://discuss.elastic.co/u/jam_mahmoudi)\
**Replies:** 0\
**Last updated:** [June 28, 2020, 6:37pm UTC](https://discuss.elastic.co/t/how-to-packetbeat-for-captuer-traffic-switch-cisco-span-port/239028 "2020-06-28T18:37:16Z")

</div>

Hi guys how to packetbeat for capture traffic switch cisco SPAN port ؟ I didn't find anything in the packetbeat document .! Thank you for your help

---

## [CheckPoint logs error with filebeat](https://discuss.elastic.co/t/checkpoint-logs-error-with-filebeat/239024)

<div class="topic-metadata">

**Author:** [@julianksanchez](https://discuss.elastic.co/u/julianksanchez)\
**Replies:** 0\
**Last updated:** [June 28, 2020, 3:58pm UTC](https://discuss.elastic.co/t/checkpoint-logs-error-with-filebeat/239024 "2020-06-28T15:58:40Z")

</div>

Hello, I am trying to obtain firewall logs from syslog. I configurate checkpoint module of filebeat. I dont know if anyone did yet, because I have problems I can see the logs of filebeat and I see it message in var/lo/s…

---

## [Can't get text on a START\_OBJECT at 1:708](https://discuss.elastic.co/t/cant-get-text-on-a-start-object-at-1-708/238965)

<div class="topic-metadata">

**Author:** [@mastersmit](https://discuss.elastic.co/u/mastersmit)\
**Replies:** 1\
**Last updated:** [June 28, 2020, 4:21am UTC](https://discuss.elastic.co/t/cant-get-text-on-a-start-object-at-1-708/238965 "2020-06-28T04:21:51Z")

</div>

I am trying to configure SpringBoot \<\> FileBeat \<\> LogStash \<\> ElasticSearch \<\> Kibana. But I am getting error at LogStash, here is my code snippets: filebeat.yml: filebeat: inputs: - type: log paths: …

---

## [Runtime: VirtualAlloc of 1056768 bytes failed with errno=1455](https://discuss.elastic.co/t/runtime-virtualalloc-of-1056768-bytes-failed-with-errno-1455/238983)

<div class="topic-metadata">

**Author:** [@bevano](https://discuss.elastic.co/u/bevano)\
**Replies:** 0\
**Last updated:** [June 28, 2020, 3:03am UTC](https://discuss.elastic.co/t/runtime-virtualalloc-of-1056768-bytes-failed-with-errno-1455/238983 "2020-06-28T03:03:48Z")

</div>

Hi All, Wondering whether any one can help me understand what happened. Been running filebeat for the past 6 months, and have been upgrading accordingly to our logstash. Currently on version 7.7 Never has it crashed ou…

---

## [How to create a filebeat processor?](https://discuss.elastic.co/t/how-to-create-a-filebeat-processor/238417)

<div class="topic-metadata">

**Author:** [@xvdy](https://discuss.elastic.co/u/xvdy)\
**Replies:** 2\
**Last updated:** [June 28, 2020, 2:59am UTC](https://discuss.elastic.co/t/how-to-create-a-filebeat-processor/238417 "2020-06-28T02:59:47Z")

</div>

We want to use filebeat to gather mysql slow log. I want to create a filebeat processor to convert mysql slow log to json format and add a sql fingerprint field. I find a related issue here: https://github.com/elastic/b…

---

## [Filebeat can't get the older iis files](https://discuss.elastic.co/t/filebeat-cant-get-the-older-iis-files/238981)

<div class="topic-metadata">

**Author:** [@chairxiao](https://discuss.elastic.co/u/chairxiao)\
**Replies:** 0\
**Last updated:** [June 28, 2020, 1:50am UTC](https://discuss.elastic.co/t/filebeat-cant-get-the-older-iis-files/238981 "2020-06-28T01:50:20Z")

</div>

Hello, I use es+kibana+filebeat to analyze the iis logs.filebeat.yml use the default setting except the ip of the es and kibana. But I can only get one week logs. I want to get all the logs in the path.the version is 7.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=233)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=235)
