# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=235

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 236

---

## [Packetbeat not getting data of mongodb?](https://discuss.elastic.co/t/packetbeat-not-getting-data-of-mongodb/238937)

<div class="topic-metadata">

**Author:** [@Sushant\_Sawant](https://discuss.elastic.co/u/Sushant_Sawant)\
**Replies:** 0\
**Last updated:** [June 27, 2020, 9:17am UTC](https://discuss.elastic.co/t/packetbeat-not-getting-data-of-mongodb/238937 "2020-06-27T09:17:23Z")

</div>

I am working on windows 10 machine, I have installed packetbeat. but whenever I am trying to get the data of mongodb on port 27017 it is showing no data in kibana dashboard. can anyone help with this?

---

## [Metricbeat & docker & kibana dashboard](https://discuss.elastic.co/t/metricbeat-docker-kibana-dashboard/238090)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [June 27, 2020, 8:38am UTC](https://discuss.elastic.co/t/metricbeat-docker-kibana-dashboard/238090 "2020-06-27T08:38:41Z")

</div>

Hi there, I have a quite interesting question: I am deplyoing an elastic cluster with docker-compose. The problem I could not solve so far: docker-compose starts all containers, also metricbeat. But metricbeat tries to …

---

## [Namespace labels to kubernetes metadata - ELasticsearch - Metricbeat](https://discuss.elastic.co/t/namespace-labels-to-kubernetes-metadata-elasticsearch-metricbeat/238925)

<div class="topic-metadata">

**Author:** [@abhishek\_acharya](https://discuss.elastic.co/u/abhishek_acharya)\
**Replies:** 0\
**Last updated:** [June 27, 2020, 3:55am UTC](https://discuss.elastic.co/t/namespace-labels-to-kubernetes-metadata-elasticsearch-metricbeat/238925 "2020-06-27T03:55:57Z")

</div>

Hi I am working on an issue where i have assigned labels to my kubernetes namespace externally through kubectl command and wanted to get those kubernetes namespace labels in the metricbeat. I am following this https://…

---

## [Filebeat do not send logs to kafka](https://discuss.elastic.co/t/filebeat-do-not-send-logs-to-kafka/238718)

<div class="topic-metadata">

**Author:** [@ramgold9](https://discuss.elastic.co/u/ramgold9)\
**Replies:** 3\
**Last updated:** [June 26, 2020, 9:47pm UTC](https://discuss.elastic.co/t/filebeat-do-not-send-logs-to-kafka/238718 "2020-06-26T21:47:01Z")

</div>

Hello Everyone, We are trying implement a centralized logging solution filebeats (on eks) -\>kafka -\> elasticsearch(aws). I have tried different versions of filebeat 6.X and 7.X with different valid versions of kafka. F…

---

## [\[Filebeat\] Changing filebeat's path for it's configuration module](https://discuss.elastic.co/t/filebeat-changing-filebeats-path-for-its-configuration-module/236243)

<div class="topic-metadata">

**Author:** [@gonzalo2kx](https://discuss.elastic.co/u/gonzalo2kx)\
**Replies:** 2\
**Last updated:** [June 26, 2020, 7:56pm UTC](https://discuss.elastic.co/t/filebeat-changing-filebeats-path-for-its-configuration-module/236243 "2020-06-26T19:56:22Z")

</div>

Good day, I am currently experiencing a problem to load the system module on filebeat. The system module has been enabled and verified using "filebeat modules list". When I launch filebeat 7.6.2 in publish mode I get th…

---

## [Beats monitoring settings](https://discuss.elastic.co/t/beats-monitoring-settings/238882)

<div class="topic-metadata">

**Author:** [@Ronin](https://discuss.elastic.co/u/Ronin)\
**Replies:** 0\
**Last updated:** [June 26, 2020, 3:37pm UTC](https://discuss.elastic.co/t/beats-monitoring-settings/238882 "2020-06-26T15:37:58Z")

</div>

We are using Elastic Cloud and its unclear from the documentation of what we should put for the monitoring settings. Following this documentation: https://www.elastic.co/guide/en/beats/filebeat/current/monitoring-interna…

---

## [Add\_tags processor in Filebeat panw module](https://discuss.elastic.co/t/add-tags-processor-in-filebeat-panw-module/238745)

<div class="topic-metadata">

**Author:** [@zombiebrak](https://discuss.elastic.co/u/zombiebrak)\
**Replies:** 2\
**Last updated:** [June 26, 2020, 3:06pm UTC](https://discuss.elastic.co/t/add-tags-processor-in-filebeat-panw-module/238745 "2020-06-26T15:06:42Z")

</div>

I am trying to implement the add\_tags processor within the panw Filebeat module, but Filebeat fails with the error: Exiting: each processor must have exactly one action, but found 2 actions (add\_locale,add\_tags) add\_lo…

---

## [Journalbeat container.image output incompatible with ECS](https://discuss.elastic.co/t/journalbeat-container-image-output-incompatible-with-ecs/236475)

<div class="topic-metadata">

**Author:** [@bbailey](https://discuss.elastic.co/u/bbailey)\
**Replies:** 3\
**Last updated:** [June 26, 2020, 1:31pm UTC](https://discuss.elastic.co/t/journalbeat-container-image-output-incompatible-with-ecs/236475 "2020-06-26T13:31:46Z")

</div>

Using Journalbeat, logstash and elasticsearch version 7.6.0 we are getting bulk indexing errors due to an incompatibility with the ECS schema Journalbeat appears to be outputting container.image as a concrete value wher…

---

## [Setting the User-Agent of heartbeat](https://discuss.elastic.co/t/setting-the-user-agent-of-heartbeat/238806)

<div class="topic-metadata">

**Author:** [@Peter\_Steenbergen](https://discuss.elastic.co/u/Peter_Steenbergen)\
**Replies:** 4\
**Last updated:** [June 26, 2020, 11:12am UTC](https://discuss.elastic.co/t/setting-the-user-agent-of-heartbeat/238806 "2020-06-26T11:12:19Z")

</div>

Is there a way to set override the user-agent of heartbeat? The default one is "Go-http-client/1.1" I want to change that to "heartbeat".

---

## [Filebeat lost lines from docker json log file](https://discuss.elastic.co/t/filebeat-lost-lines-from-docker-json-log-file/238863)

<div class="topic-metadata">

**Author:** [@BBrainBurst](https://discuss.elastic.co/u/BBrainBurst)\
**Replies:** 0\
**Last updated:** [June 26, 2020, 1:05pm UTC](https://discuss.elastic.co/t/filebeat-lost-lines-from-docker-json-log-file/238863 "2020-06-26T13:05:50Z")

</div>

Hi, I'm using Filebeat to process docker json logs and send them into logstash. My Filebeat config: filebeat.inputs: - type: docker containers.ids: '\*' processors: - add\_docker\_metadata: …

---

## [Filebeat dissect tokenizer problem](https://discuss.elastic.co/t/filebeat-dissect-tokenizer-problem/238701)

<div class="topic-metadata">

**Author:** [@elastic\_dave](https://discuss.elastic.co/u/elastic_dave)\
**Replies:** 2\
**Last updated:** [June 26, 2020, 9:57am UTC](https://discuss.elastic.co/t/filebeat-dissect-tokenizer-problem/238701 "2020-06-26T09:57:06Z")

</div>

Hi everyone, having problem with setting up .yml config file and specificaly processors:dissect. i have root filebeat.yml file pointing to several config files. This seems to work, in filebeat log i can see that confi…

---

## [Heartbeat](https://discuss.elastic.co/t/heartbeat/238822)

<div class="topic-metadata">

**Author:** [@Downer](https://discuss.elastic.co/u/Downer)\
**Replies:** 0\
**Last updated:** [June 26, 2020, 9:27am UTC](https://discuss.elastic.co/t/heartbeat/238822 "2020-06-26T09:27:06Z")

</div>

Hello, I'm using heartbeat in docker which ping an url using http method but my firewall DROP the response. What rule I need to add on it please ?

---

## [Filebeat timestamp processor handle timezone abbreviation incorrectly](https://discuss.elastic.co/t/filebeat-timestamp-processor-handle-timezone-abbreviation-incorrectly/238729)

<div class="topic-metadata">

**Author:** [@hatifnatt](https://discuss.elastic.co/u/hatifnatt)\
**Replies:** 1\
**Last updated:** [June 26, 2020, 9:09am UTC](https://discuss.elastic.co/t/filebeat-timestamp-processor-handle-timezone-abbreviation-incorrectly/238729 "2020-06-26T09:09:48Z")

</div>

Hi. I have log with timestamp in format like this 2020-06-25 19:24:46.676 MSK 2020-06-25 19:24:46.676 MSK 2020-06-25 19:24:46.678 MSK 2020-06-25 19:24:46.712 MSK My filebeat config (part of it) filebeat.inputs: - ty…

---

## [Beginner - metricbeat system dashboard with basic logstash output set](https://discuss.elastic.co/t/beginner-metricbeat-system-dashboard-with-basic-logstash-output-set/238635)

<div class="topic-metadata">

**Author:** [@NeitoFR](https://discuss.elastic.co/u/NeitoFR)\
**Replies:** 5\
**Last updated:** [June 26, 2020, 9:08am UTC](https://discuss.elastic.co/t/beginner-metricbeat-system-dashboard-with-basic-logstash-output-set/238635 "2020-06-26T09:08:29Z")

</div>

Hi everyone, I'm using ELK 7.5.2 with basic metricbeat modules (system, docker) I managed to load the Kibana dashboard to Kibana correctly. But now I'm making the logs pass through logstash (without any filter) and the …

---

## [Need help in sending Geo Ip data from beats through logstash](https://discuss.elastic.co/t/need-help-in-sending-geo-ip-data-from-beats-through-logstash/238817)

<div class="topic-metadata">

**Author:** [@Bryce\_Fernandes](https://discuss.elastic.co/u/Bryce_Fernandes)\
**Replies:** 0\
**Last updated:** [June 26, 2020, 8:52am UTC](https://discuss.elastic.co/t/need-help-in-sending-geo-ip-data-from-beats-through-logstash/238817 "2020-06-26T08:52:11Z")

</div>

Hi, I have a centralised logstash server and configured beats for sending data to elasticsearch through logstash. i have filebeat apache and iis module and auditbeat installed. Data is parsed properly and reflecting i…

---

## [Wrapping Multiline log on filebeat for the below logs](https://discuss.elastic.co/t/wrapping-multiline-log-on-filebeat-for-the-below-logs/238804)

<div class="topic-metadata">

**Author:** [@shekharkhatri](https://discuss.elastic.co/u/shekharkhatri)\
**Replies:** 0\
**Last updated:** [June 26, 2020, 7:30am UTC](https://discuss.elastic.co/t/wrapping-multiline-log-on-filebeat-for-the-below-logs/238804 "2020-06-26T07:30:39Z")

</div>

Hello everyone! I am trying to ingest a log that looks something like this: \*144\*04:30:19 SOME EVENT 06:17:52 -\> TRANSACTION START 06:17:52 .... LOG DATA 06:18:49 \<- TRANSACTION END 06:17:52 -\> TRANSACTION START 06:17:…

---

## [Pq: SSL is not enabled on the server in Metricbeat log](https://discuss.elastic.co/t/pq-ssl-is-not-enabled-on-the-server-in-metricbeat-log/238785)

<div class="topic-metadata">

**Author:** [@himalc](https://discuss.elastic.co/u/himalc)\
**Replies:** 0\
**Last updated:** [June 26, 2020, 5:27am UTC](https://discuss.elastic.co/t/pq-ssl-is-not-enabled-on-the-server-in-metricbeat-log/238785 "2020-06-26T05:27:40Z")

</div>

Hi, I have below issue when connecting to the postgresql database from Metricbeat postgres module. 2020-06-24T05:25:33 INFO module/wrapper.go:252 Error fetching data for metricset postgresql.activity: error in QuerySta…

---

## [Java Stack Trace logs not displaying with multiline](https://discuss.elastic.co/t/java-stack-trace-logs-not-displaying-with-multiline/238750)

<div class="topic-metadata">

**Author:** [@Archie\_Crawford](https://discuss.elastic.co/u/Archie_Crawford)\
**Replies:** 0\
**Last updated:** [June 25, 2020, 7:18pm UTC](https://discuss.elastic.co/t/java-stack-trace-logs-not-displaying-with-multiline/238750 "2020-06-25T19:18:56Z")

</div>

For some reason multiline is not working, its will not display the multiline stack trace in kibana filebeat.inputs: - type: log enabled: true paths: - /var/log/\*.log - /var/log/\*messages\* - /var/lo…

---

## [Error fetching data for metricset kafka.partition](https://discuss.elastic.co/t/error-fetching-data-for-metricset-kafka-partition/237946)

<div class="topic-metadata">

**Author:** [@eyesmoker](https://discuss.elastic.co/u/eyesmoker)\
**Replies:** 4\
**Last updated:** [June 25, 2020, 11:12pm UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-kafka-partition/237946 "2020-06-25T23:12:56Z")

</div>

Hi, I am running kafka and elk on kubernetes. I am trying to send kafka metrics to elk to view Metricbeat Kafka dashboard. Metricbeat is running as daemonset. Here is my metricbeat config: module: kafka enabled: tru…

---

## [Confused about central management](https://discuss.elastic.co/t/confused-about-central-management/238676)

<div class="topic-metadata">

**Author:** [@DonHansDampf](https://discuss.elastic.co/u/DonHansDampf)\
**Replies:** 2\
**Last updated:** [June 25, 2020, 2:05pm UTC](https://discuss.elastic.co/t/confused-about-central-management/238676 "2020-06-25T14:05:54Z")

</div>

Hey there, just started out with the Elastic Stack as main logging "technology". We set up our cluster, attached Kibana, deployed two Logstash Servers for traditional syslogging, aaaand discovered Beats: The "faster/bet…

---

## [Getting error while connecting to metricbeat on AWS Elasticsearch](https://discuss.elastic.co/t/getting-error-while-connecting-to-metricbeat-on-aws-elasticsearch/238673)

<div class="topic-metadata">

**Author:** [@Anshumanabhishek](https://discuss.elastic.co/u/Anshumanabhishek)\
**Replies:** 1\
**Last updated:** [June 25, 2020, 1:59pm UTC](https://discuss.elastic.co/t/getting-error-while-connecting-to-metricbeat-on-aws-elasticsearch/238673 "2020-06-25T13:59:07Z")

</div>

Hi, I am running metricbeat on kubernetes and try to connect AWS Elasticsearch service and getting this error pipeline/output.go:155 Failed to connect to backoff(elasticsearch(https://xxx-hat333wclpfnnkdkuuigwsti5a.us-…

---

## [\[filebeat panw module\] set timezone when hostname field contains keyword](https://discuss.elastic.co/t/filebeat-panw-module-set-timezone-when-hostname-field-contains-keyword/238634)

<div class="topic-metadata">

**Author:** [@gadelkareem](https://discuss.elastic.co/u/gadelkareem)\
**Replies:** 0\
**Last updated:** [June 25, 2020, 9:53am UTC](https://discuss.elastic.co/t/filebeat-panw-module-set-timezone-when-hostname-field-contains-keyword/238634 "2020-06-25T09:53:48Z")

</div>

How can I set timezone to ex EST when hostname field contains us-east-1? I tried something like this but it does not work: - date: if: "observer.hostname.toLowerCase().contains('useast') " field: "\_temp\_.…

---

## [Auditbeat Log all command not just \`sudo \<cmd\>\`](https://discuss.elastic.co/t/auditbeat-log-all-command-not-just-sudo-cmd/238640)

<div class="topic-metadata">

**Author:** [@esseti](https://discuss.elastic.co/u/esseti)\
**Replies:** 0\
**Last updated:** [June 25, 2020, 10:21am UTC](https://discuss.elastic.co/t/auditbeat-log-all-command-not-just-sudo-cmd/238640 "2020-06-25T10:21:44Z")

</div>

Hello, I've setup the audit beat and it intercepts the commands that have sudo in front. however, it does not log the command from normal users and neither for root user. so that, if I do sudo su there's no log of comm…

---

## [Filebeat extract\_array for panw module for config and system logs](https://discuss.elastic.co/t/filebeat-extract-array-for-panw-module-for-config-and-system-logs/238512)

<div class="topic-metadata">

**Author:** [@gadelkareem](https://discuss.elastic.co/u/gadelkareem)\
**Replies:** 2\
**Last updated:** [June 25, 2020, 9:40am UTC](https://discuss.elastic.co/t/filebeat-extract-array-for-panw-module-for-config-and-system-logs/238512 "2020-06-25T09:40:30Z")

</div>

Are there any examples of extract\_array for palo alto firewalls for config and system logs? ref: https://github.com/elastic/beats/blob/e99074029172a9c6d01f953005c3cdc2b58d6cb2/x-pack/filebeat/module/panw/panos/config/in…

---

## [Metricbeat Jolokia Module Not Publishing Custom MBean Data](https://discuss.elastic.co/t/metricbeat-jolokia-module-not-publishing-custom-mbean-data/238337)

<div class="topic-metadata">

**Author:** [@ronjonsilver](https://discuss.elastic.co/u/ronjonsilver)\
**Replies:** 3\
**Last updated:** [June 25, 2020, 7:44am UTC](https://discuss.elastic.co/t/metricbeat-jolokia-module-not-publishing-custom-mbean-data/238337 "2020-06-25T07:44:47Z")

</div>

Hello, I have been trying to get a field from a custom bean published to Kibana but it seems like jolokia is ignoring the jmx mapping for the custom bean field. Here is my metricbeat.yml: metricbeat.modules: …

---

## [How to filter for queries?](https://discuss.elastic.co/t/how-to-filter-for-queries/238592)

<div class="topic-metadata">

**Author:** [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Replies:** 0\
**Last updated:** [June 25, 2020, 3:53am UTC](https://discuss.elastic.co/t/how-to-filter-for-queries/238592 "2020-06-25T03:53:53Z")

</div>

Hello, I followed this knowledge article - https://www.elastic.co/blog/monitoring-the-search-queries Not using logstash filtering, and I am getting all records from packetbeat. How can I recognise the query records? T…

---

## [Exiting: data path already locked by another beat (packetbeat)](https://discuss.elastic.co/t/exiting-data-path-already-locked-by-another-beat-packetbeat/238368)

<div class="topic-metadata">

**Author:** [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Replies:** 4\
**Last updated:** [June 25, 2020, 3:40am UTC](https://discuss.elastic.co/t/exiting-data-path-already-locked-by-another-beat-packetbeat/238368 "2020-06-25T03:40:48Z")

</div>

Hello Just installed and configured packetbeat (7.6.2) on the elastic server (7.6.2). filebeat and metricbeat also run on the same server(s), and of course elasticsearch. packetbeat is not sending any data, so I wante…

---

## [How to build Beats for ArchLinux ARM](https://discuss.elastic.co/t/how-to-build-beats-for-archlinux-arm/238588)

<div class="topic-metadata">

**Author:** [@bloke](https://discuss.elastic.co/u/bloke)\
**Replies:** 1\
**Last updated:** [June 25, 2020, 2:53am UTC](https://discuss.elastic.co/t/how-to-build-beats-for-archlinux-arm/238588 "2020-06-25T02:53:13Z")

</div>

Hi, If you know how to use ALARM (ArchLinux ARM) this will help you build beats for the distro. For technical reasons the package seems excluded on the distro. I have also done some reading on the discuss site and mostl…

---

## [Struggling with Drop\_Event Processor Syntax and Structure](https://discuss.elastic.co/t/struggling-with-drop-event-processor-syntax-and-structure/238530)

<div class="topic-metadata">

**Author:** [@eafrost.cissp](https://discuss.elastic.co/u/eafrost.cissp)\
**Replies:** 1\
**Last updated:** [June 25, 2020, 1:06am UTC](https://discuss.elastic.co/t/struggling-with-drop-event-processor-syntax-and-structure/238530 "2020-06-25T01:06:24Z")

</div>

I'm struggling to get the proper syntax and structure for the following criteria for dropping a specific security log event in Winlogbeat. I can create something that passes the configuration check but it doesn't produce…

---

## [Filebeat with netflow module: independent index problem](https://discuss.elastic.co/t/filebeat-with-netflow-module-independent-index-problem/238571)

<div class="topic-metadata">

**Author:** [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Replies:** 1\
**Last updated:** [June 25, 2020, 12:52am UTC](https://discuss.elastic.co/t/filebeat-with-netflow-module-independent-index-problem/238571 "2020-06-25T00:52:36Z")

</div>

Hi people, I enable netflow module in filebeat, and in filebeat.yml file I put this lines: output.elasticsearch: hosts: \["siemtest.provincianet.com.ar:9200"\] protocol: "http" username: "elastic" password: "xxx" ind…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=234)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=236)
