# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=239

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 240

---

## [Message.keyword not exist filebeat 7.3](https://discuss.elastic.co/t/message-keyword-not-exist-filebeat-7-3/237259)

<div class="topic-metadata">

**Author:** [@Jaume\_Puigserver](https://discuss.elastic.co/u/Jaume_Puigserver)\
**Replies:** 0\
**Last updated:** [June 16, 2020, 8:52am UTC](https://discuss.elastic.co/t/message-keyword-not-exist-filebeat-7-3/237259 "2020-06-16T08:52:59Z")

</div>

Hi, I'm trying to create a search using message.keyword it works without problems with version 7.7 but I have several indexes with version 7.3.1 and when I execute the query I got "No field found for \[message.keyword\] …

---

## [Winlogbeat, metricbeat not work on winodws xp](https://discuss.elastic.co/t/winlogbeat-metricbeat-not-work-on-winodws-xp/236515)

<div class="topic-metadata">

**Author:** [@manzu](https://discuss.elastic.co/u/manzu)\
**Replies:** 2\
**Last updated:** [June 16, 2020, 8:24am UTC](https://discuss.elastic.co/t/winlogbeat-metricbeat-not-work-on-winodws-xp/236515 "2020-06-16T08:24:54Z")

</div>

i need mornitoring system for many server. so, i 'm setting winlogbeat and metricbeat (7.6.0 v...) two beat works well on win7 but not work on xp ..... I need help. alert error message winodws 1053 error and ".\\winl…

---

## [Looking for advices on how to improve an Elastic architecture](https://discuss.elastic.co/t/looking-for-advices-on-how-to-improve-an-elastic-architecture/235024)

<div class="topic-metadata">

**Author:** [@LomigFR](https://discuss.elastic.co/u/LomigFR)\
**Replies:** 8\
**Last updated:** [June 16, 2020, 7:42am UTC](https://discuss.elastic.co/t/looking-for-advices-on-how-to-improve-an-elastic-architecture/235024 "2020-06-16T07:42:10Z")

</div>

Good evening, During an internship in computer science (so I start with Docker, K8S and the Elastic stack), I'm asked to set up a log retrieval environment using the Elastic stack under ECK. For the moment, I'm trainin…

---

## [Force filebeat to reparse CSV](https://discuss.elastic.co/t/force-filebeat-to-reparse-csv/237082)

<div class="topic-metadata">

**Author:** [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Replies:** 3\
**Last updated:** [June 16, 2020, 7:16am UTC](https://discuss.elastic.co/t/force-filebeat-to-reparse-csv/237082 "2020-06-16T07:16:15Z")

</div>

Hello, I'm using filebeat and Logstash I want to force re-parse the files provided in the path section, but that doesn't seem to work my config filebeat is: filebeat.inputs: - type: log enabled: true paths: …

---

## [Can ELK monitor registry values](https://discuss.elastic.co/t/can-elk-monitor-registry-values/236870)

<div class="topic-metadata">

**Author:** [@Ayesha](https://discuss.elastic.co/u/Ayesha)\
**Replies:** 3\
**Last updated:** [June 16, 2020, 12:57am UTC](https://discuss.elastic.co/t/can-elk-monitor-registry-values/236870 "2020-06-16T00:57:55Z")

</div>

Hi I want to know is there a way ELK can monitor security configurations like check registry value every 24 hours and if it is changed then alert? Like compare security configurations to a baseline every few hours?

---

## [Functionbeat cant send events with warning \[float\] supports only finite values, but got \[Infinity\]](https://discuss.elastic.co/t/functionbeat-cant-send-events-with-warning-float-supports-only-finite-values-but-got-infinity/236916)

<div class="topic-metadata">

**Author:** [@thiago.dantas](https://discuss.elastic.co/u/thiago.dantas)\
**Replies:** 0\
**Last updated:** [June 12, 2020, 3:43pm UTC](https://discuss.elastic.co/t/functionbeat-cant-send-events-with-warning-float-supports-only-finite-values-but-got-infinity/236916 "2020-06-12T15:43:54Z")

</div>

A few of our log group subscriptions seem unable to send events to elasticsearch with the following message 2020-06-12T15:07:36.434Z WARN elasticsearch/client.go:535 Cannot index event publisher.Event{Content:beat.Even…

---

## [Duplicated Logs - Filebeats - Logstash](https://discuss.elastic.co/t/duplicated-logs-filebeats-logstash/236901)

<div class="topic-metadata">

**Author:** [@rechena](https://discuss.elastic.co/u/rechena)\
**Replies:** 0\
**Last updated:** [June 12, 2020, 1:07pm UTC](https://discuss.elastic.co/t/duplicated-logs-filebeats-logstash/236901 "2020-06-12T13:07:03Z")

</div>

I think I know what it is, but I wanted to see if anyone tried this and found a solution. I run a website in a shared hosting and because I can't install filebeat but I have ssh access for log checking, I've implemented…

---

## [Enable docker logs with filebeat](https://discuss.elastic.co/t/enable-docker-logs-with-filebeat/237178)

<div class="topic-metadata">

**Author:** [@devwinner](https://discuss.elastic.co/u/devwinner)\
**Replies:** 0\
**Last updated:** [June 15, 2020, 6:17pm UTC](https://discuss.elastic.co/t/enable-docker-logs-with-filebeat/237178 "2020-06-15T18:17:16Z")

</div>

Informations about Elk Stack : Version of Kibana : 7.7.1 Version of Elasticsearch : 7.7.1 Version de Metricbeat : 7.7.1 Version de Filebeat : 7.7.1 I have enabled docker module in metricbeat, but i can't see docker …

---

## [Filebeat System Module - Multi-line Log Generating One Log Per Line](https://discuss.elastic.co/t/filebeat-system-module-multi-line-log-generating-one-log-per-line/236410)

<div class="topic-metadata">

**Author:** [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Replies:** 6\
**Last updated:** [June 15, 2020, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-system-module-multi-line-log-generating-one-log-per-line/236410 "2020-06-15T21:06:02Z")

</div>

I'm enabling the system module of filebeat for the first time on a Ubuntu server. I can see the logs but it's taking what looks like it's taking multiline logs and placing them into single logs per line. Some logs only h…

---

## [Excessive plans generated by #MetricBeat](https://discuss.elastic.co/t/excessive-plans-generated-by-metricbeat/236830)

<div class="topic-metadata">

**Author:** [@Brett\_Shearer](https://discuss.elastic.co/u/Brett_Shearer)\
**Replies:** 2\
**Last updated:** [June 15, 2020, 8:35pm UTC](https://discuss.elastic.co/t/excessive-plans-generated-by-metricbeat/236830 "2020-06-15T20:35:32Z")

</div>

Hi - I am monitoring queries generated by metric beat and can see that it iterates databases frequently, and then checks log usage on each database. This is done in a way that causes plan cache pollution USE CW-RefDb-E…

---

## [Unable to connect local filebeat to distant logstash](https://discuss.elastic.co/t/unable-to-connect-local-filebeat-to-distant-logstash/233498)

<div class="topic-metadata">

**Author:** [@dyl](https://discuss.elastic.co/u/dyl)\
**Replies:** 4\
**Last updated:** [June 15, 2020, 7:36pm UTC](https://discuss.elastic.co/t/unable-to-connect-local-filebeat-to-distant-logstash/233498 "2020-06-15T19:36:54Z")

</div>

Hey everyone, I've got an issue when i try to send some logs from A server filebeat to B server ELK. Telnet test : \[root@A:/etc/ansible\]# telnet B 5044 Trying B... Connected to B. Escape character is '^\]'. (same netw…

---

## [I am not able to add filebeat index pattern](https://discuss.elastic.co/t/i-am-not-able-to-add-filebeat-index-pattern/236687)

<div class="topic-metadata">

**Author:** [@Sesha\_Sai\_Suhash\_Des](https://discuss.elastic.co/u/Sesha_Sai_Suhash_Des)\
**Replies:** 1\
**Last updated:** [June 15, 2020, 3:48pm UTC](https://discuss.elastic.co/t/i-am-not-able-to-add-filebeat-index-pattern/236687 "2020-06-15T15:48:57Z")

</div>

"Your index pattern doesn't match any indices, but you have 1 index which looks similar." This is what it shows when I try to add filebeat-\* as an index. I have filebeat running on my machine. Can someone help me fin…

---

## [Elastic searchguard auditbeat](https://discuss.elastic.co/t/elastic-searchguard-auditbeat/237127)

<div class="topic-metadata">

**Author:** [@Slava\_Gavrilov](https://discuss.elastic.co/u/Slava_Gavrilov)\
**Replies:** 6\
**Last updated:** [June 15, 2020, 3:15pm UTC](https://discuss.elastic.co/t/elastic-searchguard-auditbeat/237127 "2020-06-15T15:15:45Z")

</div>

Hi. I've installed yet another instance of auditbeat for my SIEM. The configurations is same as other. But it can't connect to elastic because of not enough permissions (monitor/xpack/license/get). Failed to connect to …

---

## [Send Auditbeat output to 2 seperate elasticsearch clusters](https://discuss.elastic.co/t/send-auditbeat-output-to-2-seperate-elasticsearch-clusters/237152)

<div class="topic-metadata">

**Author:** [@stenbot](https://discuss.elastic.co/u/stenbot)\
**Replies:** 2\
**Last updated:** [June 15, 2020, 2:46pm UTC](https://discuss.elastic.co/t/send-auditbeat-output-to-2-seperate-elasticsearch-clusters/237152 "2020-06-15T14:46:31Z")

</div>

Hello, we currently have Auditbeats installed on multiple servers in our environment feeding an Elasticsearch cluster that does not have TLS enabled. My question is, is it possible to output Auditbeats to a separate clus…

---

## [Filbeat exclude and multiline configuration](https://discuss.elastic.co/t/filbeat-exclude-and-multiline-configuration/237042)

<div class="topic-metadata">

**Author:** [@nmoham](https://discuss.elastic.co/u/nmoham)\
**Replies:** 1\
**Last updated:** [June 15, 2020, 8:45am UTC](https://discuss.elastic.co/t/filbeat-exclude-and-multiline-configuration/237042 "2020-06-15T08:45:08Z")

</div>

Example Events - time,thread,logger,level,message 2020-06-11 09:46:50.3836,7,Logs.Shared.ServiceBehaviors.ServiceExceptionHandlerBehavior,Debug,applying ServiceExceptionHandler to UsersService time,thread,logger,level,m…

---

## [Filebeat Netflow not getting to Kibana](https://discuss.elastic.co/t/filebeat-netflow-not-getting-to-kibana/237044)

<div class="topic-metadata">

**Author:** [@Pradeepan](https://discuss.elastic.co/u/Pradeepan)\
**Replies:** 3\
**Last updated:** [June 15, 2020, 8:39am UTC](https://discuss.elastic.co/t/filebeat-netflow-not-getting-to-kibana/237044 "2020-06-15T08:39:50Z")

</div>

Hi Techs Filebeat not getting the Netflow logs from Cisco. Not sure where to check. Using Filebeat 7.7.1 ELK also 7.7.1.Filebat , Kibana , Logstash and Elasticserach are running without errors. Cisco Netflow config is …

---

## [Is there a goroutine leak in libbeat?](https://discuss.elastic.co/t/is-there-a-goroutine-leak-in-libbeat/236822)

<div class="topic-metadata">

**Author:** [@erenming](https://discuss.elastic.co/u/erenming)\
**Replies:** 3\
**Last updated:** [June 15, 2020, 7:21am UTC](https://discuss.elastic.co/t/is-there-a-goroutine-leak-in-libbeat/236822 "2020-06-15T07:21:11Z")

</div>

I'm doing a pressure test for our beats like filebeat use libbeat package，But I found github.com/elastic/beats/libbeat/reader/readfile.(\*TimeoutReader).Next.func1 is continuous growing。 The presure test condition is de…

---

## [Kibana doesn't show anything from elasticsearch](https://discuss.elastic.co/t/kibana-doesnt-show-anything-from-elasticsearch/236847)

<div class="topic-metadata">

**Author:** [@teooood](https://discuss.elastic.co/u/teooood)\
**Replies:** 1\
**Last updated:** [June 15, 2020, 6:14am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-anything-from-elasticsearch/236847 "2020-06-15T06:14:53Z")

</div>

Hi everyone. I am using the Filebeat service, and I have a problem. I can't see the logs in Kibana. I am on a Windows machine. I tried to config Filebeat to get data from Elasticsearch. This is my config file: #====…

---

## [Failed to publish events caused by: write tcp X.X.X.X:36524-\>X.X.X.X:5044: write: connection reset by peer error in filebeat](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-write-tcp-x-x-x-x-36524-x-x-x-x-write-connection-reset-by-peer-error-in-filebeat/237031)

<div class="topic-metadata">

**Author:** [@Aqel](https://discuss.elastic.co/u/Aqel)\
**Replies:** 2\
**Last updated:** [June 15, 2020, 1:50am UTC](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-write-tcp-x-x-x-x-36524-x-x-x-x-write-connection-reset-by-peer-error-in-filebeat/237031 "2020-06-15T01:50:30Z")

</div>

I am getting this error while trying to push logs using filebeat to logstash. |filebeat | 2020-06-14T16:45:36.660318702Z 2020-06-14T16:45:36.660Z|ERROR|logstash/async.go:256|Failed to publish events caused by: wri…

---

## [Filebeat panic in Windows nano server container](https://discuss.elastic.co/t/filebeat-panic-in-windows-nano-server-container/236838)

<div class="topic-metadata">

**Author:** [@zhiweiv](https://discuss.elastic.co/u/zhiweiv)\
**Replies:** 2\
**Last updated:** [June 15, 2020, 1:49am UTC](https://discuss.elastic.co/t/filebeat-panic-in-windows-nano-server-container/236838 "2020-06-15T01:49:18Z")

</div>

Filebeat 7.7 panic in Windows nano server container, however 7.3 works. Found a useful link: https://github.com/golang/go/issues/21867, latest klog fixed it: https://github.com/kubernetes/klog/blob/master/klog\_file.go#L…

---

## [Auditbeat config - What about this config makes the CPU so high?](https://discuss.elastic.co/t/auditbeat-config-what-about-this-config-makes-the-cpu-so-high/235988)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 3\
**Last updated:** [June 14, 2020, 7:59pm UTC](https://discuss.elastic.co/t/auditbeat-config-what-about-this-config-makes-the-cpu-so-high/235988 "2020-06-14T19:59:24Z")

</div>

Below is my auditbeat config. What about this is so CPU taxing? \` ###################### Auditbeat Configuration Example ######################### # This is an example configuration file highlighting only the most c…

---

## [Sending Alerts to different slack Webhook](https://discuss.elastic.co/t/sending-alerts-to-different-slack-webhook/236963)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 0\
**Last updated:** [June 13, 2020, 6:28am UTC](https://discuss.elastic.co/t/sending-alerts-to-different-slack-webhook/236963 "2020-06-13T06:28:35Z")

</div>

Hello everybody I have an ELK server that gets information from so many beats like Filebeat, Metricbeat, and ... , also I am using Slack webhook to send my alerts by Elastalert, However, I have a problem sending differ…

---

## [SSH Access Rule](https://discuss.elastic.co/t/ssh-access-rule/235647)

<div class="topic-metadata">

**Author:** [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Replies:** 3\
**Last updated:** [June 13, 2020, 3:28am UTC](https://discuss.elastic.co/t/ssh-access-rule/235647 "2020-06-13T03:28:34Z")

</div>

To detect SSH access, I'm using the rule below: ## External access (warning: these can be expensive to audit). -a always,exit -F arch=b64 -S accept,bind,connect -F key=external-access This is generating a lot of events…

---

## [Authentication using apikey failed - Illegal base64 character 3a After Upgrading to 7.7.0](https://discuss.elastic.co/t/authentication-using-apikey-failed-illegal-base64-character-3a-after-upgrading-to-7-7-0/235190)

<div class="topic-metadata">

**Author:** [@btnrsec](https://discuss.elastic.co/u/btnrsec)\
**Replies:** 3\
**Last updated:** [June 12, 2020, 6:00pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-illegal-base64-character-3a-after-upgrading-to-7-7-0/235190 "2020-06-12T18:00:04Z")

</div>

I have implemented Filebeat and Auditbeat with ElasticSearch output functionally in 7.6.0 to 7.6.2 without issue. I upgraded a host and ELK Server to version 7.7.0 and am not able to authenticate with the API key in the …

---

## [Adding Host fields to configuration](https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510)

<div class="topic-metadata">

**Author:** [@nick1](https://discuss.elastic.co/u/nick1)\
**Replies:** 5\
**Last updated:** [June 12, 2020, 3:17pm UTC](https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510 "2020-06-12T15:17:41Z")

</div>

Hi, I'm trying to configure filebeat, winlogbeat and metricbeat to send details on their host type (OS type mainly) so I can use this field in Graylog to filter. Host doesn't seem to be a module and the fields document…

---

## [Filebeat to AWS ES \_xpack](https://discuss.elastic.co/t/filebeat-to-aws-es-xpack/236913)

<div class="topic-metadata">

**Author:** [@Jonny\_McCullagh](https://discuss.elastic.co/u/Jonny_McCullagh)\
**Replies:** 1\
**Last updated:** [June 12, 2020, 2:58pm UTC](https://discuss.elastic.co/t/filebeat-to-aws-es-xpack/236913 "2020-06-12T14:58:23Z")

</div>

I appreciate that ES does not support the AWS implementation, so let me know if this question would be better on stackoverflow. When running filebeat setup I get: Exiting: request checking for ILM availability failed: …

---

## [Filebeat creates too many handlers](https://discuss.elastic.co/t/filebeat-creates-too-many-handlers/234793)

<div class="topic-metadata">

**Author:** [@Merlin\_Nunez](https://discuss.elastic.co/u/Merlin_Nunez)\
**Replies:** 1\
**Last updated:** [June 12, 2020, 1:06pm UTC](https://discuss.elastic.co/t/filebeat-creates-too-many-handlers/234793 "2020-06-12T13:06:35Z")

</div>

I have this production cluster that is running dockerized versions of ELK applications. One VM hosts the entire stack except for filebeat instances that run one in each VM where other applications run. Sometimes the con…

---

## [How to handle overlapping logs with filebeat?](https://discuss.elastic.co/t/how-to-handle-overlapping-logs-with-filebeat/236678)

<div class="topic-metadata">

**Author:** [@Amine\_Maalfi](https://discuss.elastic.co/u/Amine_Maalfi)\
**Replies:** 1\
**Last updated:** [June 12, 2020, 8:00am UTC](https://discuss.elastic.co/t/how-to-handle-overlapping-logs-with-filebeat/236678 "2020-06-12T08:00:47Z")

</div>

Hi everyone is there a way to handle overlapping logs with filebeat? here's a sample of what i have: \[17/02/2020 07:53:27:748\] 00000 I \>\> message1 (start of event) \[17/02/2020 07:53:27:751\] 00000 I @ message2 \[17/02/20…

---

## [How to configure Filebeat to recognize ECS data](https://discuss.elastic.co/t/how-to-configure-filebeat-to-recognize-ecs-data/236550)

<div class="topic-metadata">

**Author:** [@Noxis](https://discuss.elastic.co/u/Noxis)\
**Replies:** 3\
**Last updated:** [June 12, 2020, 8:57am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-recognize-ecs-data/236550 "2020-06-12T08:57:44Z")

</div>

Hello I have an Kibana Elastic Filebeat docker stack and I want to monitor the logs of some NodeJS microservices (that run in docker too). I discovered yesterday ecs-morgan-format and it seems to work well with morgan. …

---

## [How to increase the throughput of filebeat?](https://discuss.elastic.co/t/how-to-increase-the-throughput-of-filebeat/236708)

<div class="topic-metadata">

**Author:** [@iammanmale](https://discuss.elastic.co/u/iammanmale)\
**Replies:** 1\
**Last updated:** [June 12, 2020, 7:56am UTC](https://discuss.elastic.co/t/how-to-increase-the-throughput-of-filebeat/236708 "2020-06-12T07:56:36Z")

</div>

Although I have many GBs log waiting to be harvested and I have not configured any limitation(e.g max\_proc or something like that ) in the filebeat.yml but the throughput of the filebeat is just 1XX KB or slower. Is it …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=238)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=240)
