# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=240

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 241

---

## [Services internally used by Metricbeat](https://discuss.elastic.co/t/services-internally-used-by-metricbeat/236811)

<div class="topic-metadata">

**Author:** [@sandeep\_reddy1](https://discuss.elastic.co/u/sandeep_reddy1)\
**Replies:** 1\
**Last updated:** [June 12, 2020, 7:34am UTC](https://discuss.elastic.co/t/services-internally-used-by-metricbeat/236811 "2020-06-12T07:34:30Z")

</div>

Hi All, Can we know what the service or applications used by Metric beat to collect the system metrics. I am running metricbeat in windows with windows and system module and on Linux with system module. Can I know what …

---

## [Filebeat did not pass the file to Elasticsearch](https://discuss.elastic.co/t/filebeat-did-not-pass-the-file-to-elasticsearch/236150)

<div class="topic-metadata">

**Author:** [@Taeho\_Oh](https://discuss.elastic.co/u/Taeho_Oh)\
**Replies:** 3\
**Last updated:** [June 12, 2020, 6:53am UTC](https://discuss.elastic.co/t/filebeat-did-not-pass-the-file-to-elasticsearch/236150 "2020-06-12T06:53:20Z")

</div>

Hi, I am trying to pass the log file from the beats to the Elasticsearch. my problem is that even though the beats harvest the log file from the log directory, there is no update in Elasticsearch index management in Ki…

---

## [Filebeat config - USER system env variable](https://discuss.elastic.co/t/filebeat-config-user-system-env-variable/232428)

<div class="topic-metadata">

**Author:** [@Johny](https://discuss.elastic.co/u/Johny)\
**Replies:** 3\
**Last updated:** [June 11, 2020, 9:26pm UTC](https://discuss.elastic.co/t/filebeat-config-user-system-env-variable/232428 "2020-06-11T21:26:12Z")

</div>

Hello, i am trying read logs from currently logged user folder. In filebeat config i have: paths: - /home/${USERNAME}/logs/foo.log, this does not even compile. But it work when i hardcode name like this: paths: - /ho…

---

## [Failed to load suricata dashboard using filebeat](https://discuss.elastic.co/t/failed-to-load-suricata-dashboard-using-filebeat/236026)

<div class="topic-metadata">

**Author:** [@Jun.8](https://discuss.elastic.co/u/Jun.8)\
**Replies:** 0\
**Last updated:** [June 6, 2020, 9:28am UTC](https://discuss.elastic.co/t/failed-to-load-suricata-dashboard-using-filebeat/236026 "2020-06-06T09:28:21Z")

</div>

Hi, I have a trouble with loading suricata dashboard using filebeat.. I followed the steps below and it seems that it is working well... plz check the result message below. ./filebeat setup Overwriting ILM policy i…

---

## [Metricbeat dont create index pattern by itself](https://discuss.elastic.co/t/metricbeat-dont-create-index-pattern-by-itself/235974)

<div class="topic-metadata">

**Author:** [@Alexandros888](https://discuss.elastic.co/u/Alexandros888)\
**Replies:** 0\
**Last updated:** [June 5, 2020, 3:14pm UTC](https://discuss.elastic.co/t/metricbeat-dont-create-index-pattern-by-itself/235974 "2020-06-05T15:14:24Z")

</div>

Hello, I have installed metricbeat version 7.7.1 in my 7.7.0 cluster. the yaml file of metricbeat is like that: ###################### Metricbeat Configuration Example ####################### # This file is an exampl…

---

## [Filebeat always need kibana now?](https://discuss.elastic.co/t/filebeat-always-need-kibana-now/236637)

<div class="topic-metadata">

**Author:** [@azteker](https://discuss.elastic.co/u/azteker)\
**Replies:** 2\
**Last updated:** [June 11, 2020, 5:55pm UTC](https://discuss.elastic.co/t/filebeat-always-need-kibana-now/236637 "2020-06-11T17:55:35Z")

</div>

I don't want to set kibana and only need the filebeat to send data. But now I cannot start my filebeat and get this error: Exiting: Error importing Kibana dashboards: fail to create the Kibana loader: Error creating Kib…

---

## [Any way to set defaults to all filebeat modules?](https://discuss.elastic.co/t/any-way-to-set-defaults-to-all-filebeat-modules/236747)

<div class="topic-metadata">

**Author:** [@arcade](https://discuss.elastic.co/u/arcade)\
**Replies:** 0\
**Last updated:** [June 11, 2020, 4:25pm UTC](https://discuss.elastic.co/t/any-way-to-set-defaults-to-all-filebeat-modules/236747 "2020-06-11T16:25:57Z")

</div>

Hello. I'm collecting a number of logs, and some of them are rotated through logrotate with delaycompress option (file is renamed but sits there for 24h). Those files are collected and opened by filebeat, but it never c…

---

## [Winlogbeat configuration - exact selection](https://discuss.elastic.co/t/winlogbeat-configuration-exact-selection/235895)

<div class="topic-metadata">

**Author:** [@RRadim](https://discuss.elastic.co/u/RRadim)\
**Replies:** 10\
**Last updated:** [June 11, 2020, 2:09pm UTC](https://discuss.elastic.co/t/winlogbeat-configuration-exact-selection/235895 "2020-06-11T14:09:25Z")

</div>

Hello :slight\_smile: Hope someone could help me :wink: I want to collect ALL events of level Critical, Error and Warning + from level Information JUST events id 1074, 6005, 6006, 6008. (Due to monitoring restart/shutdo…

---

## [Correlation between auditd and system module](https://discuss.elastic.co/t/correlation-between-auditd-and-system-module/236691)

<div class="topic-metadata">

**Author:** [@marcus\_lhisp](https://discuss.elastic.co/u/marcus_lhisp)\
**Replies:** 0\
**Last updated:** [June 11, 2020, 11:42am UTC](https://discuss.elastic.co/t/correlation-between-auditd-and-system-module/236691 "2020-06-11T11:42:45Z")

</div>

Hey folks, I began asking myself if the system module which handles stuff like login, packages, etc. actually obsoletes some of my auditd rules? Or do they only the same thing but in a different manner? My rules that I…

---

## [Filtering not working](https://discuss.elastic.co/t/filtering-not-working/234397)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 7\
**Last updated:** [June 11, 2020, 8:36am UTC](https://discuss.elastic.co/t/filtering-not-working/234397 "2020-06-11T08:36:05Z")

</div>

Hi, Running ELK 6.8.9 on premises Output in Winlogbeat config file is Eslasticsearch (not Logstash) I am trying to add some processing on the client side to filter only the Win events I need before sending the data t…

---

## [Filebeat to kafka: Failed to connect to broker](https://discuss.elastic.co/t/filebeat-to-kafka-failed-to-connect-to-broker/236440)

<div class="topic-metadata">

**Author:** [@charles97](https://discuss.elastic.co/u/charles97)\
**Replies:** 4\
**Last updated:** [June 11, 2020, 3:29am UTC](https://discuss.elastic.co/t/filebeat-to-kafka-failed-to-connect-to-broker/236440 "2020-06-11T03:29:28Z")

</div>

environment : kafka 2.11 (installed via ambari) filebeat 7.4.2 (windows) according this source since it was installed via ambari i should use port 6667 here is my filebeat.conf filebeat.inputs: - type: log p…

---

## [Filebeat收集多种编码日志](https://discuss.elastic.co/t/filebeat/236601)

<div class="topic-metadata">

**Author:** [@rockyu](https://discuss.elastic.co/u/rockyu)\
**Replies:** 0\
**Last updated:** [June 11, 2020, 2:51am UTC](https://discuss.elastic.co/t/filebeat/236601 "2020-06-11T02:51:26Z")

</div>

filebeat收集一台机器上的多个应用日志，有的日志编码是UTF8，有的编码是GBK，如何能解决乱码问题，目前是使用设置两个input的，设置两个encoding，但是机器和应用多了，操作就不方便

---

## [Creating new index with an already existing index pattern](https://discuss.elastic.co/t/creating-new-index-with-an-already-existing-index-pattern/236560)

<div class="topic-metadata">

**Author:** [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Replies:** 1\
**Last updated:** [June 10, 2020, 8:23pm UTC](https://discuss.elastic.co/t/creating-new-index-with-an-already-existing-index-pattern/236560 "2020-06-10T20:23:06Z")

</div>

Hello, Actually, I have by mistakenly deleted an index "filebeat-2020-06-05". My index gets generated on daily basis. Now, I am trying create an index manually with older date, and trying to restore older data, but tha…

---

## [Winlogbeat event file system logstash](https://discuss.elastic.co/t/winlogbeat-event-file-system-logstash/236512)

<div class="topic-metadata">

**Author:** [@Renato\_Santos](https://discuss.elastic.co/u/Renato_Santos)\
**Replies:** 0\
**Last updated:** [June 10, 2020, 12:56pm UTC](https://discuss.elastic.co/t/winlogbeat-event-file-system-logstash/236512 "2020-06-10T12:56:03Z")

</div>

Hi guys, I have a question about winlogbeat along with logstash where I need to use the translate for hexadecimal codes. KQL example winlog.event\_data.AccessMask: "0x10080" and event.code: "4656" returns me that the ev…

---

## [Offline log storage when ingest through elasticsearch/logstash is not avaialble](https://discuss.elastic.co/t/offline-log-storage-when-ingest-through-elasticsearch-logstash-is-not-avaialble/236503)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 0\
**Last updated:** [June 10, 2020, 11:38am UTC](https://discuss.elastic.co/t/offline-log-storage-when-ingest-through-elasticsearch-logstash-is-not-avaialble/236503 "2020-06-10T11:38:45Z")

</div>

Hi, is there a way to configure packetbeat to verify availability of elasticsearch or logstash ingest pipeline on regular basis and if found unavailable store the logs locally, before sending them (again)? An alternativ…

---

## [Monitoring NUMA with metricbeats](https://discuss.elastic.co/t/monitoring-numa-with-metricbeats/234548)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 2\
**Last updated:** [June 10, 2020, 9:48am UTC](https://discuss.elastic.co/t/monitoring-numa-with-metricbeats/234548 "2020-06-10T09:48:35Z")

</div>

Hello ever one, All operation systems has a new feature named NUMA which provide opportunity to join some CPU cores in a group, I want to monitor processors performance by each NUMA in my servers, however I could not fi…

---

## [Filebeat keystore using empty password](https://discuss.elastic.co/t/filebeat-keystore-using-empty-password/236336)

<div class="topic-metadata">

**Author:** [@yuqingz](https://discuss.elastic.co/u/yuqingz)\
**Replies:** 1\
**Last updated:** [June 10, 2020, 8:38am UTC](https://discuss.elastic.co/t/filebeat-keystore-using-empty-password/236336 "2020-06-10T08:38:20Z")

</div>

HI all: Based on the source code of filebeat, an empty string is used as the password to generate keysotres(see https://github.com/elastic/beats/blob/c825c727948c1f87eb36e5d4bd982de06c42cfbf/libbeat/keystore/file\_keysto…

---

## [RKE/Rancker 2.0 and Filebeat not sending logs](https://discuss.elastic.co/t/rke-rancker-2-0-and-filebeat-not-sending-logs/235406)

<div class="topic-metadata">

**Author:** [@wrender](https://discuss.elastic.co/u/wrender)\
**Replies:** 2\
**Last updated:** [June 10, 2020, 6:57am UTC](https://discuss.elastic.co/t/rke-rancker-2-0-and-filebeat-not-sending-logs/235406 "2020-06-10T06:57:08Z")

</div>

I have a single server RKE cluster, with Rancher on top for testing. I then deployed elasticsearch and kibana using the helm charts to a namespace called elasticsearch. I then install filebeat using the official elastic…

---

## [Autodiscover issue in kubernetes](https://discuss.elastic.co/t/autodiscover-issue-in-kubernetes/234930)

<div class="topic-metadata">

**Author:** [@malcolm666](https://discuss.elastic.co/u/malcolm666)\
**Replies:** 6\
**Last updated:** [June 9, 2020, 10:34pm UTC](https://discuss.elastic.co/t/autodiscover-issue-in-kubernetes/234930 "2020-06-09T22:34:46Z")

</div>

Hi! I have an issue with autodiscover in kubernetes. I have such yaml file: apiVersion: v1 kind: ConfigMap metadata: namespace: kube-logging name: filebeat-config labels: app: filebeat data: filebeat.yml: …

---

## [Office 365 Module - not an IP string literal](https://discuss.elastic.co/t/office-365-module-not-an-ip-string-literal/232727)

<div class="topic-metadata">

**Author:** [@ericbarnes](https://discuss.elastic.co/u/ericbarnes)\
**Replies:** 10\
**Last updated:** [June 9, 2020, 4:27pm UTC](https://discuss.elastic.co/t/office-365-module-not-an-ip-string-literal/232727 "2020-06-09T16:27:14Z")

</div>

Getting the following error with default o365 module setup. Casual glance seems to say this is mostly happening on Exchange related audit data but not enough to know yet. May 14 16:51:23 ainfcp1esl00001 filebeat: 2020-…

---

## [Azure Module Metricbeat](https://discuss.elastic.co/t/azure-module-metricbeat/236346)

<div class="topic-metadata">

**Author:** [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Replies:** 0\
**Last updated:** [June 9, 2020, 1:35pm UTC](https://discuss.elastic.co/t/azure-module-metricbeat/236346 "2020-06-09T13:35:44Z")

</div>

Hello, I want to make efficient use of "Monitor" metricset in "Azure" module on metricbeat side. I am looking to get relevant information regarding disk usage, memory availability of my Azure VMs. The issue is that I …

---

## [Error establishing direct connection to mongo node at \[ip:port\]. Error output: no reachable servers](https://discuss.elastic.co/t/error-establishing-direct-connection-to-mongo-node-at-ip-port-error-output-no-reachable-servers/233995)

<div class="topic-metadata">

**Author:** [@chandu5565](https://discuss.elastic.co/u/chandu5565)\
**Replies:** 19\
**Last updated:** [June 9, 2020, 12:48pm UTC](https://discuss.elastic.co/t/error-establishing-direct-connection-to-mongo-node-at-ip-port-error-output-no-reachable-servers/233995 "2020-06-09T12:48:46Z")

</div>

Hi, I am using mongodb with replicaset and ssl enabled. When I am trying to create metricbeat mongodb module am not sure How to give URL. I have only CA file. I don't undestand how to solve it. hosts: \["mongodb://rspel…

---

## [Cannot create a file when that file already exists](https://discuss.elastic.co/t/cannot-create-a-file-when-that-file-already-exists/235303)

<div class="topic-metadata">

**Author:** [@bob88](https://discuss.elastic.co/u/bob88)\
**Replies:** 4\
**Last updated:** [June 9, 2020, 11:15am UTC](https://discuss.elastic.co/t/cannot-create-a-file-when-that-file-already-exists/235303 "2020-06-09T11:15:20Z")

</div>

Hello, i have a problem with winlogbeat 7.6 on windows 2008r2: "ERROR instance/beat.go:933 Exiting: rename C:\\ProgramData\\winlogbeat.winlogbeat.yml.new C:\\ProgramData\\winlogbeat.winlogbeat.yml: Cannot create a file w…

---

## [What are all IAM permissions needed for Metricbeat AWS module?](https://discuss.elastic.co/t/what-are-all-iam-permissions-needed-for-metricbeat-aws-module/236196)

<div class="topic-metadata">

**Author:** [@gnumoksha](https://discuss.elastic.co/u/gnumoksha)\
**Replies:** 2\
**Last updated:** [June 8, 2020, 8:07pm UTC](https://discuss.elastic.co/t/what-are-all-iam-permissions-needed-for-metricbeat-aws-module/236196 "2020-06-08T20:07:34Z")

</div>

What are all IAM permissions needed for Metricbeat AWS module?

---

## [Not able to change filebeat index name running on Kubernetes](https://discuss.elastic.co/t/not-able-to-change-filebeat-index-name-running-on-kubernetes/236009)

<div class="topic-metadata">

**Author:** [@Vinicius\_Maia](https://discuss.elastic.co/u/Vinicius_Maia)\
**Replies:** 2\
**Last updated:** [June 8, 2020, 7:59pm UTC](https://discuss.elastic.co/t/not-able-to-change-filebeat-index-name-running-on-kubernetes/236009 "2020-06-08T19:59:50Z")

</div>

Hello guys, I'm not able to change my index name in filebeat running on kubernetes. I found a lot of information about it, but my setup isnt' working. I'll really appreciate for any help. My objective is send my log f…

---

## [Filebeat Azure Module Pipeline Functions](https://discuss.elastic.co/t/filebeat-azure-module-pipeline-functions/236062)

<div class="topic-metadata">

**Author:** [@craigothy](https://discuss.elastic.co/u/craigothy)\
**Replies:** 1\
**Last updated:** [June 8, 2020, 7:35pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-pipeline-functions/236062 "2020-06-08T19:35:57Z")

</div>

Could someone tell me what the difference is between the different azure module pipelines are? For example, I see: filebeat-7.6.2-azure-activitylogs-pipleline AND filebeat-7.6.2-azure-activitylogs-azure-shared-pipelin…

---

## [Import yaml pipeline](https://discuss.elastic.co/t/import-yaml-pipeline/236184)

<div class="topic-metadata">

**Author:** [@rverchere](https://discuss.elastic.co/u/rverchere)\
**Replies:** 2\
**Last updated:** [June 8, 2020, 7:18pm UTC](https://discuss.elastic.co/t/import-yaml-pipeline/236184 "2020-06-08T19:18:55Z")

</div>

Hello, I'd like to manually insert ingest pipelines defined in filebeat, which is not yet released. In filebeat, these ingest pipelines are in yaml format, but are defined in json format in elasticsearch. How can I ea…

---

## [Extract message to additional fields](https://discuss.elastic.co/t/extract-message-to-additional-fields/236198)

<div class="topic-metadata">

**Author:** [@Sivakumar\_K](https://discuss.elastic.co/u/Sivakumar_K)\
**Replies:** 1\
**Last updated:** [June 8, 2020, 6:35pm UTC](https://discuss.elastic.co/t/extract-message-to-additional-fields/236198 "2020-06-08T18:35:36Z")

</div>

Hi All, I am looking for some help, I have configured filebeat to collect the CISCO syslogs and push to elasticsearch, it's working fine. I am looking for extracting the data from log.original and messages to addition …

---

## [How hard is it to add a custom module?](https://discuss.elastic.co/t/how-hard-is-it-to-add-a-custom-module/234046)

<div class="topic-metadata">

**Author:** [@Jonny\_McCullagh](https://discuss.elastic.co/u/Jonny_McCullagh)\
**Replies:** 3\
**Last updated:** [June 8, 2020, 6:12pm UTC](https://discuss.elastic.co/t/how-hard-is-it-to-add-a-custom-module/234046 "2020-06-08T18:12:54Z")

</div>

I've been battling with this for days, I can't believe it can be this hard to process a custom log format. My log lines mainly look like : \[2020-05-24 13:40:06,414\] {{jobs.py:1725}} WARNING - No viable dags retrieved f…

---

## [Added new line in my log and cannot get the output correctly in filbeat (need to remove new line)](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123)

<div class="topic-metadata">

**Author:** [@himalc](https://discuss.elastic.co/u/himalc)\
**Replies:** 6\
**Last updated:** [June 8, 2020, 6:11pm UTC](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123 "2020-06-08T18:11:27Z")

</div>

How to remove newline using multiline config in filebeat Log file: 2020-06-01T07:44:31.300103 H 80 DHandler.cpp:953 stdlog sql\_execute 11201 9 handcrafted admin 431-856b {"query","client","execution\_time","total\_time"}…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=239)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=241)
