# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=236

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 237

---

## [Setup of beat exporter doesn't work](https://discuss.elastic.co/t/setup-of-beat-exporter-doesnt-work/238433)

<div class="topic-metadata">

**Author:** [@vaishno.avi](https://discuss.elastic.co/u/vaishno.avi)\
**Replies:** 0\
**Last updated:** [June 24, 2020, 10:14am UTC](https://discuss.elastic.co/t/setup-of-beat-exporter-doesnt-work/238433 "2020-06-24T10:14:02Z")

</div>

Hello, I wanted to export filebeat metrics via beat exporter. filebeat has a conf that exposes the metrics https://www.elastic.co/guide/en/beats/filebeat/master/http-endpoint.html beat exporter's documentation als…

---

## [Customize filebeat iis log increase x-forwarded-for](https://discuss.elastic.co/t/customize-filebeat-iis-log-increase-x-forwarded-for/238240)

<div class="topic-metadata">

**Author:** [@Fabio\_Scoppetta](https://discuss.elastic.co/u/Fabio_Scoppetta)\
**Replies:** 1\
**Last updated:** [June 24, 2020, 9:28pm UTC](https://discuss.elastic.co/t/customize-filebeat-iis-log-increase-x-forwarded-for/238240 "2020-06-24T21:28:26Z")

</div>

Hello, I am use elk 7.3.2 and metricbeat for monitoring capacity environment Now I am trying to use to log iis with x-forwarded-for but in elasitc and kibana i not was saw the public ip for example log 2020-06-22 12:…

---

## [Discrepancy between source and destination host reported packet count in packetbeat](https://discuss.elastic.co/t/discrepancy-between-source-and-destination-host-reported-packet-count-in-packetbeat/238454)

<div class="topic-metadata">

**Author:** [@mdyson](https://discuss.elastic.co/u/mdyson)\
**Replies:** 0\
**Last updated:** [June 24, 2020, 12:07pm UTC](https://discuss.elastic.co/t/discrepancy-between-source-and-destination-host-reported-packet-count-in-packetbeat/238454 "2020-06-24T12:07:23Z")

</div>

Created a Kibana visualization counting the sum of packets from a source.ip to a destination.ip over time. There are documents from each host.hostname (source and destination) in the data set. When analyzing the counts i…

---

## [Elasticsearch 7.8.0 Metricbeat index conflict](https://discuss.elastic.co/t/elasticsearch-7-8-0-metricbeat-index-conflict/237749)

<div class="topic-metadata">

**Author:** [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Replies:** 2\
**Last updated:** [June 24, 2020, 12:02pm UTC](https://discuss.elastic.co/t/elasticsearch-7-8-0-metricbeat-index-conflict/237749 "2020-06-24T12:02:39Z")

</div>

Hi.. Since the 7.8.0 released, I just tried it and suddenly the metricbeat index have a conflict field. The field that have conflict is kubernetes.service.ingress\_hostname Any workaround to solve this? Regards, F…

---

## [Support for ESXi and vCenter 6.7?](https://discuss.elastic.co/t/support-for-esxi-and-vcenter-6-7/237743)

<div class="topic-metadata">

**Author:** [@rehanp707](https://discuss.elastic.co/u/rehanp707)\
**Replies:** 1\
**Last updated:** [June 24, 2020, 11:04am UTC](https://discuss.elastic.co/t/support-for-esxi-and-vcenter-6-7/237743 "2020-06-24T11:04:50Z")

</div>

As per elastic documentation here, https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-module-vsphere.html#metricbeat-module-vsphere vSphere module library is built for and tested against ESXi and vCente…

---

## [Need help to setup Metricbeat](https://discuss.elastic.co/t/need-help-to-setup-metricbeat/238309)

<div class="topic-metadata">

**Author:** [@Anshumanabhishek](https://discuss.elastic.co/u/Anshumanabhishek)\
**Replies:** 2\
**Last updated:** [June 24, 2020, 10:53am UTC](https://discuss.elastic.co/t/need-help-to-setup-metricbeat/238309 "2020-06-24T10:53:25Z")

</div>

I have installed Elasticsearch and Kibana on EC2 server with docker compose. Its version is 7.6. When I try the metricbeat on the Minikube on my localmachine, it working fine and get all the data. But issue arise when …

---

## [Filebeat Netflow module doesn't load](https://discuss.elastic.co/t/filebeat-netflow-module-doesnt-load/237267)

<div class="topic-metadata">

**Author:** [@ahiyaz](https://discuss.elastic.co/u/ahiyaz)\
**Replies:** 13\
**Last updated:** [June 24, 2020, 10:09am UTC](https://discuss.elastic.co/t/filebeat-netflow-module-doesnt-load/237267 "2020-06-24T10:09:25Z")

</div>

hi ive installed filebeat ver 7.7.0 using arm repository. udp input and logstash output work fine. only when im configuring netflow input filebeat fail to start. appreciate your help. bellow is the out put of debug: …

---

## [Unable to convert winlogbeat output data format from json to inflex](https://discuss.elastic.co/t/unable-to-convert-winlogbeat-output-data-format-from-json-to-inflex/238423)

<div class="topic-metadata">

**Author:** [@kumarbn](https://discuss.elastic.co/u/kumarbn)\
**Replies:** 1\
**Last updated:** [June 24, 2020, 9:47am UTC](https://discuss.elastic.co/t/unable-to-convert-winlogbeat-output-data-format-from-json-to-inflex/238423 "2020-06-24T09:47:28Z")

</div>

unable to convert winlogbeat output data format from json to inflex

---

## [Using filebeat modules in conditions](https://discuss.elastic.co/t/using-filebeat-modules-in-conditions/238388)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 1\
**Last updated:** [June 24, 2020, 9:06am UTC](https://discuss.elastic.co/t/using-filebeat-modules-in-conditions/238388 "2020-06-24T09:06:13Z")

</div>

Assume i have 3 different systems sending different syslog formats to my server on port 514. Using filebeat, i want to use modules in conditionals. eg. When a message field contains "pa" use the PANW module, but if the…

---

## [Dynamic filebeat index naming](https://discuss.elastic.co/t/dynamic-filebeat-index-naming/238387)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 1\
**Last updated:** [June 24, 2020, 9:04am UTC](https://discuss.elastic.co/t/dynamic-filebeat-index-naming/238387 "2020-06-24T09:04:26Z")

</div>

Hi - I am using the new(er) Okta and PANW filebeat modules. How do i say "send the okta logs to the okta index and the panw logs to the panw index" I have tried this to create an index based of the fields.event.module …

---

## [Customized decode\_csv\_fields in filebeat](https://discuss.elastic.co/t/customized-decode-csv-fields-in-filebeat/238410)

<div class="topic-metadata">

**Author:** [@job52](https://discuss.elastic.co/u/job52)\
**Replies:** 0\
**Last updated:** [June 24, 2020, 9:03am UTC](https://discuss.elastic.co/t/customized-decode-csv-fields-in-filebeat/238410 "2020-06-24T09:03:51Z")

</div>

Hello everyone, I started using filebeat to send logs in csv format to elasticsearch, but I didn't find any way to configure filebeat to tell it where to take the headers of csv files, and I don't want to pass through I…

---

## [GeoIP Enrichment for private IPs in CIDR form whilst using IIS logs input in filebeat](https://discuss.elastic.co/t/geoip-enrichment-for-private-ips-in-cidr-form-whilst-using-iis-logs-input-in-filebeat/238076)

<div class="topic-metadata">

**Author:** [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Replies:** 4\
**Last updated:** [June 24, 2020, 6:57am UTC](https://discuss.elastic.co/t/geoip-enrichment-for-private-ips-in-cidr-form-whilst-using-iis-logs-input-in-filebeat/238076 "2020-06-24T06:57:14Z")

</div>

Hi, This is a weird problem I am facing. I am using the IIS logs input for filebeat, which creates an ingest-pipeline in ES, thus I can see that the data leaving filebeat is an unmodified string. I created some add\_fie…

---

## [Have to export the log file ending with \_debug (log file name)](https://discuss.elastic.co/t/have-to-export-the-log-file-ending-with-debug-log-file-name/238300)

<div class="topic-metadata">

**Author:** [@nikhilesh](https://discuss.elastic.co/u/nikhilesh)\
**Replies:** 1\
**Last updated:** [June 24, 2020, 1:34am UTC](https://discuss.elastic.co/t/have-to-export-the-log-file-ending-with-debug-log-file-name/238300 "2020-06-24T01:34:49Z")

</div>

Hi Team, Can you please help on this requirement. I have a log files with naming "date\_action" and "date\_debug" , so in file beat input configuration we have to include "date\_debug" log file and to exclude "date\_acti…

---

## [Couldn't connect to any of the configured Elasticsearch hosts](https://discuss.elastic.co/t/couldnt-connect-to-any-of-the-configured-elasticsearch-hosts/238166)

<div class="topic-metadata">

**Author:** [@ibadawe](https://discuss.elastic.co/u/ibadawe)\
**Replies:** 5\
**Last updated:** [June 24, 2020, 1:06am UTC](https://discuss.elastic.co/t/couldnt-connect-to-any-of-the-configured-elasticsearch-hosts/238166 "2020-06-24T01:06:16Z")

</div>

Hello, i have configured all settings in configuration file at winlogbeat.yml, to send logs to Elastic. but unfortunately i couldn't receive any logs at Elastic and when i run the below command in Powershell ".\\winlogb…

---

## [Winlogbeat missing events](https://discuss.elastic.co/t/winlogbeat-missing-events/237961)

<div class="topic-metadata">

**Author:** [@craigothy](https://discuss.elastic.co/u/craigothy)\
**Replies:** 2\
**Last updated:** [June 23, 2020, 9:04pm UTC](https://discuss.elastic.co/t/winlogbeat-missing-events/237961 "2020-06-23T21:04:36Z")

</div>

Can someone tell me the best way to troubleshoot missing windows events from winlogbeat in elastic. We are using WEC to get events to a central collector. That collector is running winlogbeat to send to logstash and then…

---

## [Filebeat's default index mapping causes Kibana to display many empty date fields](https://discuss.elastic.co/t/filebeats-default-index-mapping-causes-kibana-to-display-many-empty-date-fields/238324)

<div class="topic-metadata">

**Author:** [@temp4746](https://discuss.elastic.co/u/temp4746)\
**Replies:** 2\
**Last updated:** [June 23, 2020, 8:42pm UTC](https://discuss.elastic.co/t/filebeats-default-index-mapping-causes-kibana-to-display-many-empty-date-fields/238324 "2020-06-23T20:42:32Z")

</div>

I tried a default dev setup of the ELK stack with Filebeat reading from some Docker container outputting Elastic Common Schema JSON. It looks like the default index mapping that Filebeat sets up causes Kibana to show man…

---

## [Send all routers, switches and access points logs to ELK server](https://discuss.elastic.co/t/send-all-routers-switches-and-access-points-logs-to-elk-server/238289)

<div class="topic-metadata">

**Author:** [@jelocabral](https://discuss.elastic.co/u/jelocabral)\
**Replies:** 3\
**Last updated:** [June 23, 2020, 5:30pm UTC](https://discuss.elastic.co/t/send-all-routers-switches-and-access-points-logs-to-elk-server/238289 "2020-06-23T17:30:18Z")

</div>

Hi people, I have several routers, switches and acces points in my network and I want to send all their logs to a syslog service implemented in my ELK server. Is this possible to implement a syslog server listening on …

---

## [Filebeat 7.8 Azure module issue](https://discuss.elastic.co/t/filebeat-7-8-azure-module-issue/237727)

<div class="topic-metadata">

**Author:** [@sera123k](https://discuss.elastic.co/u/sera123k)\
**Replies:** 4\
**Last updated:** [June 23, 2020, 3:24pm UTC](https://discuss.elastic.co/t/filebeat-7-8-azure-module-issue/237727 "2020-06-23T15:24:03Z")

</div>

Testing out the Azure module and leveraging the exact same configuration from a working 7.7 install generates the following error: 2020-06-18T23:19:14.508-0500 INFO cfgfile/reload.go:224 Loading of config files complete…

---

## [Detecting anomalies in metricbeats data](https://discuss.elastic.co/t/detecting-anomalies-in-metricbeats-data/237846)

<div class="topic-metadata">

**Author:** [@Jaskaran123](https://discuss.elastic.co/u/Jaskaran123)\
**Replies:** 1\
**Last updated:** [June 22, 2020, 2:16pm UTC](https://discuss.elastic.co/t/detecting-anomalies-in-metricbeats-data/237846 "2020-06-22T14:16:57Z")

</div>

Hello, I am pretty new to ES ML and metric beats, so please excuse if my question seems a bit unusual. So I setup a a job to detect anomalies in the field "system.cpu.user.pct", I am successfully able to detect anomali…

---

## [Metricbeat Host Not Showing On Dashboard](https://discuss.elastic.co/t/metricbeat-host-not-showing-on-dashboard/238287)

<div class="topic-metadata">

**Author:** [@vps-eric](https://discuss.elastic.co/u/vps-eric)\
**Replies:** 0\
**Last updated:** [June 23, 2020, 2:46pm UTC](https://discuss.elastic.co/t/metricbeat-host-not-showing-on-dashboard/238287 "2020-06-23T14:46:15Z")

</div>

I am using the latest Metricbeat from GitHub, cross compiled for use on aarch64. I have a device that was submitting default system statistics to Elastic just fine on Friday. Monday, it was not showing on the System Over…

---

## [Doubt about System Module \[Filebeat\]](https://discuss.elastic.co/t/doubt-about-system-module-filebeat/238078)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 3\
**Last updated:** [June 23, 2020, 12:02pm UTC](https://discuss.elastic.co/t/doubt-about-system-module-filebeat/238078 "2020-06-23T12:02:00Z")

</div>

Hi, everyone I would like to know over which logs Module System is able to parse. In Filebeat Doc, it shows an example with auth.log and syslog. Is it possible to do it with logs as secure, messages, etc? From my poin…

---

## [Failed to obtain a connection with the database Metricbeat](https://discuss.elastic.co/t/failed-to-obtain-a-connection-with-the-database-metricbeat/238249)

<div class="topic-metadata">

**Author:** [@himalc](https://discuss.elastic.co/u/himalc)\
**Replies:** 0\
**Last updated:** [June 23, 2020, 11:47am UTC](https://discuss.elastic.co/t/failed-to-obtain-a-connection-with-the-database-metricbeat/238249 "2020-06-23T11:47:06Z")

</div>

Hi, I have below issue on metricbeat logs. I have using all applications are in docker containers (metricbeat, postgresql, elasticsearch, kibana). Any help on this? Error from metricbeat: (1) Error INFO module/wrappe…

---

## [Filebeat stop working after upgrade from 7.6.0 to 7.7.1 (kubernetes)](https://discuss.elastic.co/t/filebeat-stop-working-after-upgrade-from-7-6-0-to-7-7-1-kubernetes/238190)

<div class="topic-metadata">

**Author:** [@Johanes\_Anggara](https://discuss.elastic.co/u/Johanes_Anggara)\
**Replies:** 2\
**Last updated:** [June 23, 2020, 9:23am UTC](https://discuss.elastic.co/t/filebeat-stop-working-after-upgrade-from-7-6-0-to-7-7-1-kubernetes/238190 "2020-06-23T09:23:42Z")

</div>

I have filebeat running as daemonset in k8s cluster, while apps storing file which mounted in host disk, this path also mounted by filebeat containers. Previously on 7.6 its working but after upgrading to 7.7.1 its stop…

---

## [Unable to start metricbeat using service command](https://discuss.elastic.co/t/unable-to-start-metricbeat-using-service-command/238122)

<div class="topic-metadata">

**Author:** [@prakash\_a](https://discuss.elastic.co/u/prakash_a)\
**Replies:** 1\
**Last updated:** [June 23, 2020, 9:09am UTC](https://discuss.elastic.co/t/unable-to-start-metricbeat-using-service-command/238122 "2020-06-23T09:09:51Z")

</div>

We are unable to start/stop/ manage metricbeat on Oracle Linux 6.5 version. We have to manually start service using metricbeat -e -c /etc/metricbeat/metricbeat.yml Below is what we see when we start metricbeat using se…

---

## [Metricbeat not working when It is upgraded from 7.4.0 to 7.8.0](https://discuss.elastic.co/t/metricbeat-not-working-when-it-is-upgraded-from-7-4-0-to-7-8-0/238042)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 1\
**Last updated:** [June 23, 2020, 9:09am UTC](https://discuss.elastic.co/t/metricbeat-not-working-when-it-is-upgraded-from-7-4-0-to-7-8-0/238042 "2020-06-23T09:09:15Z")

</div>

Hello Metricbeat not working when It is upgraded from 7.4.0 to 7.8.0 and I can not find relating indices in Kibana. Metricbeat had been working before upgrading the Metricbeat. My metricbeat config file contains follow…

---

## [Metric using too much disk space -need optimization help](https://discuss.elastic.co/t/metric-using-too-much-disk-space-need-optimization-help/238177)

<div class="topic-metadata">

**Author:** [@cbeprem](https://discuss.elastic.co/u/cbeprem)\
**Replies:** 1\
**Last updated:** [June 23, 2020, 8:58am UTC](https://discuss.elastic.co/t/metric-using-too-much-disk-space-need-optimization-help/238177 "2020-06-23T08:58:03Z")

</div>

Hi Team , I am using metricbeat for a couple of days for monitor system metrics, like CPU, ram, disk and network. It is working fine. I am monitoring for 10 Linux system. I have enabled only the default system modul…

---

## [Getting PacketBeat Raw TCP Payloads 2](https://discuss.elastic.co/t/getting-packetbeat-raw-tcp-payloads-2/238198)

<div class="topic-metadata">

**Author:** [@alpayk](https://discuss.elastic.co/u/alpayk)\
**Replies:** 1\
**Last updated:** [June 23, 2020, 8:45am UTC](https://discuss.elastic.co/t/getting-packetbeat-raw-tcp-payloads-2/238198 "2020-06-23T08:45:29Z")

</div>

I am asking this question again because my first attempt was left unanswered Is it possible to extract and send the network traffic to logstash as a byte array using PacketBeat? I want to post-process the raw network tr…

---

## [Dockerize Custom Beat](https://discuss.elastic.co/t/dockerize-custom-beat/237021)

<div class="topic-metadata">

**Author:** [@Dev-Flo](https://discuss.elastic.co/u/Dev-Flo)\
**Replies:** 9\
**Last updated:** [June 23, 2020, 7:32am UTC](https://discuss.elastic.co/t/dockerize-custom-beat/237021 "2020-06-23T07:32:27Z")

</div>

Hi :smiley: I created a custom beat thanks to your Developer Guide , and would like to package it into a Docker Image. However, I did not find any information regarding that. Are there any instructions on how to do th…

---

## [\[CheckPoint\] \[Filebeat 7.8\] Provided Grok expressions do not match field value](https://discuss.elastic.co/t/checkpoint-filebeat-7-8-provided-grok-expressions-do-not-match-field-value/238186)

<div class="topic-metadata">

**Author:** [@julianksanchez](https://discuss.elastic.co/u/julianksanchez)\
**Replies:** 0\
**Last updated:** [June 23, 2020, 5:29am UTC](https://discuss.elastic.co/t/checkpoint-filebeat-7-8-provided-grok-expressions-do-not-match-field-value/238186 "2020-06-23T05:29:00Z")

</div>

Hello all, I want to send logs directly to Elastic from my CheckPoint Management. This is my checkpoint.yml configuration : module: checkpoint firewall: enabled: true var.syslog\_host: 10.10.10.1 var.syslog\_port: 514 o…

---

## [Setup dashboards](https://discuss.elastic.co/t/setup-dashboards/238028)

<div class="topic-metadata">

**Author:** [@dobby](https://discuss.elastic.co/u/dobby)\
**Replies:** 0\
**Last updated:** [June 22, 2020, 7:51am UTC](https://discuss.elastic.co/t/setup-dashboards/238028 "2020-06-22T07:51:42Z")

</div>

When trying to set up dashboards for winlogbeat i get "Failed to import dashboard" The error doesnt come if i never change the password for the users. So if i try with default "elastic" and "changeme" it works. But af…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=235)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=237)
