# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=237

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 238

---

## [Filebeat - o365 module Error, api error:AF20051](https://discuss.elastic.co/t/filebeat-o365-module-error-api-error-af20051/238148)

<div class="topic-metadata">

**Author:** [@zerolife](https://discuss.elastic.co/u/zerolife)\
**Replies:** 0\
**Last updated:** [June 22, 2020, 8:08pm UTC](https://discuss.elastic.co/t/filebeat-o365-module-error-api-error-af20051/238148 "2020-06-22T20:08:51Z")

</div>

Hi, I was hoping someone can help point me in the right direction here. I setup Filebeat and the o365 module. Everything was working fine for 8 days or so. And then for some reason, it stopped being able to connect to…

---

## [Data ingest using curl](https://discuss.elastic.co/t/data-ingest-using-curl/237517)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 3\
**Last updated:** [June 22, 2020, 10:38pm UTC](https://discuss.elastic.co/t/data-ingest-using-curl/237517 "2020-06-22T22:38:59Z")

</div>

Is there a way to pull logs from an external system into Elastic through curl command? If so, what are the recommendations on it's architecture. Here is what I have in mind: Setup a shell script to run curl command -\> …

---

## [Messages escaped in Filebeat](https://discuss.elastic.co/t/messages-escaped-in-filebeat/237125)

<div class="topic-metadata">

**Author:** [@JeanN](https://discuss.elastic.co/u/JeanN)\
**Replies:** 5\
**Last updated:** [June 22, 2020, 8:45pm UTC](https://discuss.elastic.co/t/messages-escaped-in-filebeat/237125 "2020-06-22T20:45:30Z")

</div>

Hi, I have an issue with Filebeat, I have escaping characters that I can't remove from the message value, or I don't know how. I know there already are some topics on that matter but none solved my issue, that's why I'm…

---

## [FIlebeat data not pushed into filebeat-7.8 index](https://discuss.elastic.co/t/filebeat-data-not-pushed-into-filebeat-7-8-index/238114)

<div class="topic-metadata">

**Author:** [@Shadowphax](https://discuss.elastic.co/u/Shadowphax)\
**Replies:** 1\
**Last updated:** [June 22, 2020, 5:10pm UTC](https://discuss.elastic.co/t/filebeat-data-not-pushed-into-filebeat-7-8-index/238114 "2020-06-22T17:10:27Z")

</div>

Hi, Today we upgraded ES, Kibana, and Filebeats from 7.7 to 7.8. Everything went well but unfortunately, it seems like Filebeats is not pushing the cisco fdt module data it receives into ElasticSearch filebeat-7.8 index…

---

## [Kubernetes module vs add\_kubernetes\_metadata](https://discuss.elastic.co/t/kubernetes-module-vs-add-kubernetes-metadata/237489)

<div class="topic-metadata">

**Author:** [@akrzos](https://discuss.elastic.co/u/akrzos)\
**Replies:** 2\
**Last updated:** [June 22, 2020, 3:53pm UTC](https://discuss.elastic.co/t/kubernetes-module-vs-add-kubernetes-metadata/237489 "2020-06-22T15:53:35Z")

</div>

If you are using the kubernetes module is there any reason to use the add\_kubernetes\_metadata processor? What is the difference between these two (module vs processor) and the use cases for each. Thanks

---

## [Okta module in filebeat retrieving an error failed to find message](https://discuss.elastic.co/t/okta-module-in-filebeat-retrieving-an-error-failed-to-find-message/237456)

<div class="topic-metadata">

**Author:** [@Mohan\_vel](https://discuss.elastic.co/u/Mohan_vel)\
**Replies:** 3\
**Last updated:** [June 22, 2020, 1:49pm UTC](https://discuss.elastic.co/t/okta-module-in-filebeat-retrieving-an-error-failed-to-find-message/237456 "2020-06-22T13:49:22Z")

</div>

Hi all, i am using the filebeat to ship the logs from Okta to elasticsearch, connection established successfully and elaticsearch is receiving the event.dataset from okta when i look into the log messages it's showing f…

---

## [Winlogbeat not filtering event more than 21 sources](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740)

<div class="topic-metadata">

**Author:** [@kumarbn](https://discuss.elastic.co/u/kumarbn)\
**Replies:** 7\
**Last updated:** [June 22, 2020, 12:00pm UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740 "2020-06-22T12:00:52Z")

</div>

unable to get alert on kafka if we mention more than 21 event source in winlogbeat yml file .

---

## [FQDN for whitelisting in firewall for pulling filebeat docker image](https://discuss.elastic.co/t/fqdn-for-whitelisting-in-firewall-for-pulling-filebeat-docker-image/238069)

<div class="topic-metadata">

**Author:** [@manav](https://discuss.elastic.co/u/manav)\
**Replies:** 0\
**Last updated:** [June 22, 2020, 10:55am UTC](https://discuss.elastic.co/t/fqdn-for-whitelisting-in-firewall-for-pulling-filebeat-docker-image/238069 "2020-06-22T10:55:02Z")

</div>

Hi All, I'm trying to deploy filebeat docker image in an network restricting egress traffic. The outbound traffic of the network is locked down to only allowed domains. I'm going to pull filebeat docker official reposi…

---

## [Problems with FileBeat and FreeBSD](https://discuss.elastic.co/t/problems-with-filebeat-and-freebsd/238067)

<div class="topic-metadata">

**Author:** [@daniel.valle](https://discuss.elastic.co/u/daniel.valle)\
**Replies:** 0\
**Last updated:** [June 22, 2020, 10:44am UTC](https://discuss.elastic.co/t/problems-with-filebeat-and-freebsd/238067 "2020-06-22T10:44:15Z")

</div>

I am encountering a problem in the filebeat setup for our Elastic Cloud system. This is our scenario: We have a FreeBSD server where several applications are installed. Each application generates a set of log files. W…

---

## [Filebeat doesn't bring me all the logs i need](https://discuss.elastic.co/t/filebeat-doesnt-bring-me-all-the-logs-i-need/236698)

<div class="topic-metadata">

**Author:** [@Alexandros888](https://discuss.elastic.co/u/Alexandros888)\
**Replies:** 3\
**Last updated:** [June 22, 2020, 9:37am UTC](https://discuss.elastic.co/t/filebeat-doesnt-bring-me-all-the-logs-i-need/236698 "2020-06-22T09:37:25Z")

</div>

Hello, I have filebeat and ELK version 7.7.0 I successfully enabled the Elasticsearch module of Filebeat and i can see server and gc logs now in kibana. Nevertheless i cant see in kibana my gc, audit and deprecation …

---

## [Filebeat how to autodiscover kubernetes service and fetch pod log?](https://discuss.elastic.co/t/filebeat-how-to-autodiscover-kubernetes-service-and-fetch-pod-log/237997)

<div class="topic-metadata">

**Author:** [@chanjarster](https://discuss.elastic.co/u/chanjarster)\
**Replies:** 3\
**Last updated:** [June 22, 2020, 8:18am UTC](https://discuss.elastic.co/t/filebeat-how-to-autodiscover-kubernetes-service-and-fetch-pod-log/237997 "2020-06-22T08:18:21Z")

</div>

I've deploy filebeat on kubernetes cluster following the doc. And set resource: service in the config file: filebeat.autodiscover: providers: - type: kubernetes resource: service no…

---

## [Get output of executing process](https://discuss.elastic.co/t/get-output-of-executing-process/238030)

<div class="topic-metadata">

**Author:** [@Matt\_Rollo](https://discuss.elastic.co/u/Matt_Rollo)\
**Replies:** 0\
**Last updated:** [June 22, 2020, 7:52am UTC](https://discuss.elastic.co/t/get-output-of-executing-process/238030 "2020-06-22T07:52:26Z")

</div>

Hi Guys, Is there option to grab and log stdout of executing process/application ? Cheers Matt

---

## [Filebeat when started as homebrew service is not harvesting logs](https://discuss.elastic.co/t/filebeat-when-started-as-homebrew-service-is-not-harvesting-logs/238004)

<div class="topic-metadata">

**Author:** [@Venkat\_Ram\_Movva](https://discuss.elastic.co/u/Venkat_Ram_Movva)\
**Replies:** 0\
**Last updated:** [June 22, 2020, 5:42am UTC](https://discuss.elastic.co/t/filebeat-when-started-as-homebrew-service-is-not-harvesting-logs/238004 "2020-06-22T05:42:40Z")

</div>

Hi, I installed filebeat-full using the brew command from the documentation. I changed the config file(present at /usr/local/etc/filebeat/filebeat.yml). I started the service using brew services start filebeat-full. But…

---

## [Finding a public IP for geotagging](https://discuss.elastic.co/t/finding-a-public-ip-for-geotagging/237979)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 0\
**Last updated:** [June 21, 2020, 10:38pm UTC](https://discuss.elastic.co/t/finding-a-public-ip-for-geotagging/237979 "2020-06-21T22:38:59Z")

</div>

The scenario is enhancing my metricbeat data to help track a dozen laptops. I thought adding geo data to their low frequency uptime response would be a cheap way to do this. A custom pipeline that all metricbeats data go…

---

## [Winlogbeat queuing when Logstash offline](https://discuss.elastic.co/t/winlogbeat-queuing-when-logstash-offline/237968)

<div class="topic-metadata">

**Author:** [@sera](https://discuss.elastic.co/u/sera)\
**Replies:** 0\
**Last updated:** [June 21, 2020, 4:00pm UTC](https://discuss.elastic.co/t/winlogbeat-queuing-when-logstash-offline/237968 "2020-06-21T16:00:55Z")

</div>

Apologies if this has been asked before, but I have hunted around and can't find anything specific. I'm sending domain controller logs to Logstash with Winlogbeat. Windows Performance Monitor shows Winlogbeat process usi…

---

## [FileBeat for parsing](https://discuss.elastic.co/t/filebeat-for-parsing/237964)

<div class="topic-metadata">

**Author:** [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Replies:** 0\
**Last updated:** [June 21, 2020, 2:12pm UTC](https://discuss.elastic.co/t/filebeat-for-parsing/237964 "2020-06-21T14:12:05Z")

</div>

I know that FileBeat was not built for parsing data, rather for filtering and shipping specific data! However, looking at the current landing page of processors, I realized that if the data is not too complicated, we co…

---

## [Add namespace labels to kubernetes metadata](https://discuss.elastic.co/t/add-namespace-labels-to-kubernetes-metadata/237922)

<div class="topic-metadata">

**Author:** [@abhishek\_acharya](https://discuss.elastic.co/u/abhishek_acharya)\
**Replies:** 0\
**Last updated:** [June 20, 2020, 3:44pm UTC](https://discuss.elastic.co/t/add-namespace-labels-to-kubernetes-metadata/237922 "2020-06-20T15:44:07Z")

</div>

Hi there I have assigned labels to my kubernetes namespace and I want these labels in my kibana. I am getting only my namespace field in kibana as kubernetes.namespace: "my-namespace". What changes i have to do in my …

---

## [Any way to maintain a long list of hearbeat.monitors.urls?](https://discuss.elastic.co/t/any-way-to-maintain-a-long-list-of-hearbeat-monitors-urls/236906)

<div class="topic-metadata">

**Author:** [@zongzw](https://discuss.elastic.co/u/zongzw)\
**Replies:** 6\
**Last updated:** [June 20, 2020, 2:32pm UTC](https://discuss.elastic.co/t/any-way-to-maintain-a-long-list-of-hearbeat-monitors-urls/236906 "2020-06-20T14:32:38Z")

</div>

Hi, My list in heartbeat.monitors.urls is long, is there any way to maintain it in a separate file. I mean I want to it to be: heartbeat.yml: # Configure monitors inline heartbeat.monitors: - type: http # List or …

---

## [Module test, how do i create the test.log-expected.json file?](https://discuss.elastic.co/t/module-test-how-do-i-create-the-test-log-expected-json-file/237914)

<div class="topic-metadata">

**Author:** [@Stefan\_Sabolowitsch](https://discuss.elastic.co/u/Stefan_Sabolowitsch)\
**Replies:** 0\
**Last updated:** [June 20, 2020, 12:52pm UTC](https://discuss.elastic.co/t/module-test-how-do-i-create-the-test-log-expected-json-file/237914 "2020-06-20T12:52:39Z")

</div>

Hi there, how do i create the "test.log-expected.json" with elastic / kibana, search ? Search command needed, so that i get the same format / content as in the sample file. thanks for any help here. StefanS

---

## [Heartbeat problem in 7.7.x](https://discuss.elastic.co/t/heartbeat-problem-in-7-7-x/237250)

<div class="topic-metadata">

**Author:** [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Replies:** 4\
**Last updated:** [June 20, 2020, 4:02am UTC](https://discuss.elastic.co/t/heartbeat-problem-in-7-7-x/237250 "2020-06-20T04:02:29Z")

</div>

Dear Experts, I have problem with Heartbeat version when upgrade to 7.7. In 7.6.2 I have icmp monitor, and the result in the index for rtt was rtt.us, then in 7.7, the rtt.us was missing and change to icmp.rtt.us, this…

---

## [Filebeat to send application logs to elasticsearch](https://discuss.elastic.co/t/filebeat-to-send-application-logs-to-elasticsearch/237507)

<div class="topic-metadata">

**Author:** [@jacobzh](https://discuss.elastic.co/u/jacobzh)\
**Replies:** 10\
**Last updated:** [June 19, 2020, 4:08pm UTC](https://discuss.elastic.co/t/filebeat-to-send-application-logs-to-elasticsearch/237507 "2020-06-19T16:08:07Z")

</div>

Hi, I want to use filebeat to ship developers application logs to elasticsearch running in a developers servers. Developers application generates a log file in a particular folder. Whenever the log file reaches a config…

---

## [.net logs from filebeat to logstash multiline proper format](https://discuss.elastic.co/t/net-logs-from-filebeat-to-logstash-multiline-proper-format/237757)

<div class="topic-metadata">

**Author:** [@catadetest](https://discuss.elastic.co/u/catadetest)\
**Replies:** 1\
**Last updated:** [June 19, 2020, 1:14pm UTC](https://discuss.elastic.co/t/net-logs-from-filebeat-to-logstash-multiline-proper-format/237757 "2020-06-19T13:14:53Z")

</div>

I'm trying to ingest logs from a .net application. I have filebeat installed on a node which pushes the logs to a logstash server. logfile: 2020-06-19 00:00:16.421 +02:00 \[Error\] \[Band.Account.HealthCheckService\] \[2HB0…

---

## [Non standard log](https://discuss.elastic.co/t/non-standard-log/237800)

<div class="topic-metadata">

**Author:** [@AngeloM](https://discuss.elastic.co/u/AngeloM)\
**Replies:** 0\
**Last updated:** [June 19, 2020, 11:57am UTC](https://discuss.elastic.co/t/non-standard-log/237800 "2020-06-19T11:57:36Z")

</div>

2018-06-13 13:45:04 DEBUG JAXBGenericUtils:33 - JAXBContext.newInstance(au.bdau.fasci.generated) 2018-06-13 13:45:04 DEBUG JAXBGenericUtils:169 - \*\*\* getObjectXML(String sa, JAXBContext jcpaut) \*\*\* 2018-06-13 13:45:04 …

---

## [Auditbeat Bug? - Include\_files not limiting to just those files](https://discuss.elastic.co/t/auditbeat-bug-include-files-not-limiting-to-just-those-files/237798)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [June 19, 2020, 11:35am UTC](https://discuss.elastic.co/t/auditbeat-bug-include-files-not-limiting-to-just-those-files/237798 "2020-06-19T11:35:05Z")

</div>

The auditbeat reference documentation and common sense would imply that doing something like module: file\_integrity paths: C:/windows/system32 include\_files: \[ '(?i).dll$', '(?i).exe$' \] would monitor ONLY .dll a…

---

## [What is the log ship agent for network device](https://discuss.elastic.co/t/what-is-the-log-ship-agent-for-network-device/236844)

<div class="topic-metadata">

**Author:** [@NISHANT\_KHARAT](https://discuss.elastic.co/u/NISHANT_KHARAT)\
**Replies:** 4\
**Last updated:** [June 19, 2020, 10:50am UTC](https://discuss.elastic.co/t/what-is-the-log-ship-agent-for-network-device/236844 "2020-06-19T10:50:00Z")

</div>

How we can send logs of network device to Elasticsearch any sample configuration Thanks

---

## [Elasticsearch.slowlog.took\_millis not being indexed](https://discuss.elastic.co/t/elasticsearch-slowlog-took-millis-not-being-indexed/237361)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 1\
**Last updated:** [June 18, 2020, 9:44am UTC](https://discuss.elastic.co/t/elasticsearch-slowlog-took-millis-not-being-indexed/237361 "2020-06-18T09:44:46Z")

</div>

I've installed filebeat on my es boxes to ship es slowlogs to a separate elasticsearch cluster. I installed it from deb package (v7.6.0 to match my es version), activated the elasticsearch plugin, ran the setup and star…

---

## [Filebeat Cisco-FTD: Too many dynamic script compilations](https://discuss.elastic.co/t/filebeat-cisco-ftd-too-many-dynamic-script-compilations/237434)

<div class="topic-metadata">

**Author:** [@xoh](https://discuss.elastic.co/u/xoh)\
**Replies:** 1\
**Last updated:** [June 19, 2020, 9:47am UTC](https://discuss.elastic.co/t/filebeat-cisco-ftd-too-many-dynamic-script-compilations/237434 "2020-06-19T09:47:53Z")

</div>

I want to ingest the logs of Cisco Firepowers for use within the SIEM App and custom alerting, but with just one FTD added (out of roughly 30), I'm already receiving the following error: \[script\] Too many dynamic script…

---

## [Filebeat not logging to files](https://discuss.elastic.co/t/filebeat-not-logging-to-files/237777)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 0\
**Last updated:** [June 19, 2020, 9:38am UTC](https://discuss.elastic.co/t/filebeat-not-logging-to-files/237777 "2020-06-19T09:38:48Z")

</div>

My filebeat (v7.6.0) config has the following: logging.level: debug logging.to\_files: true logging.files: path: /var/log/filebeat name: filebeat keepfiles: 7 permissions: 0755 It doesn't create the files, nor d…

---

## [Logs geeting stored in default filebeat 7.7.1 index and custom index not getting created](https://discuss.elastic.co/t/logs-geeting-stored-in-default-filebeat-7-7-1-index-and-custom-index-not-getting-created/236953)

<div class="topic-metadata">

**Author:** [@Avinash\_sanapala](https://discuss.elastic.co/u/Avinash_sanapala)\
**Replies:** 2\
**Last updated:** [June 19, 2020, 9:11am UTC](https://discuss.elastic.co/t/logs-geeting-stored-in-default-filebeat-7-7-1-index-and-custom-index-not-getting-created/236953 "2020-06-19T09:11:43Z")

</div>

Hi all, I am trying to send my log data from filebeat to Elasticsearch directly in .log format.It is not going to the custom index I created and getting stored under the default indice filebeat 7.7.1 . Also I could not …

---

## [Aws network loadblancer metrics not captured](https://discuss.elastic.co/t/aws-network-loadblancer-metrics-not-captured/237698)

<div class="topic-metadata">

**Author:** [@Abhishek\_Tanwar](https://discuss.elastic.co/u/Abhishek_Tanwar)\
**Replies:** 1\
**Last updated:** [June 19, 2020, 8:34am UTC](https://discuss.elastic.co/t/aws-network-loadblancer-metrics-not-captured/237698 "2020-06-19T08:34:40Z")

</div>

I am using metricbeat 7.8, elasticsearch 7.8 and kibana 7.8. module: aws period: 1m regions: eu-central-1 metricsets: elb With the above configuration, only application load balancers are getting captured. Netwo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=236)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=238)
