# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=241

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 242

---

## [Packetbeat appears to be adding DNS packets that were not really sent](https://discuss.elastic.co/t/packetbeat-appears-to-be-adding-dns-packets-that-were-not-really-sent/235886)

<div class="topic-metadata">

**Author:** [@scott\_A](https://discuss.elastic.co/u/scott_A)\
**Replies:** 1\
**Last updated:** [June 8, 2020, 5:30pm UTC](https://discuss.elastic.co/t/packetbeat-appears-to-be-adding-dns-packets-that-were-not-really-sent/235886 "2020-06-08T17:30:50Z")

</div>

Hello, I have an interesting problem with Packetbeat. It is installed on a Windows Server 2012 system. It is the latest version (installed fresh this week from the Elastic download area) and sending data to Elastic v7.7…

---

## [How to use filebeat changes to collect the entire file](https://discuss.elastic.co/t/how-to-use-filebeat-changes-to-collect-the-entire-file/233440)

<div class="topic-metadata">

**Author:** [@lisongtao](https://discuss.elastic.co/u/lisongtao)\
**Replies:** 4\
**Last updated:** [June 8, 2020, 9:49am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-changes-to-collect-the-entire-file/233440 "2020-06-08T09:49:23Z")

</div>

I want to use filbeat to collect configuration files, and when the file content has CRUD operations, the entire file content will be collected

---

## [Filebeat nginx module not working](https://discuss.elastic.co/t/filebeat-nginx-module-not-working/235170)

<div class="topic-metadata">

**Author:** [@karthiknpy](https://discuss.elastic.co/u/karthiknpy)\
**Replies:** 5\
**Last updated:** [June 8, 2020, 6:38am UTC](https://discuss.elastic.co/t/filebeat-nginx-module-not-working/235170 "2020-06-08T06:38:55Z")

</div>

Hi Team, My Log pipeline is as follows Filebeat\_7.6.2-----\> Logstash\_7.6.2--------\>Redis------\>Elastic\_cloud I have enabled filebeat nginx module and have configured the nginx log paths (access and error) filebeat mo…

---

## [Metricbeat activemq & jolokia modules error (using HTTP when HTTPS specified)](https://discuss.elastic.co/t/metricbeat-activemq-jolokia-modules-error-using-http-when-https-specified/235992)

<div class="topic-metadata">

**Author:** [@Don-cloud](https://discuss.elastic.co/u/Don-cloud)\
**Replies:** 7\
**Last updated:** [June 6, 2020, 5:37pm UTC](https://discuss.elastic.co/t/metricbeat-activemq-jolokia-modules-error-using-http-when-https-specified/235992 "2020-06-06T17:37:54Z")

</div>

Hi, I have turned on these two modules in activemq server (version 5.15.9). jolokia is enabled by default on HTTPS port. i am seeing that, even after clearly specifying on activemq.yml and jolokia.yml the value of host…

---

## [Why filebeat input enabled=false not effective?](https://discuss.elastic.co/t/why-filebeat-input-enabled-false-not-effective/234252)

<div class="topic-metadata">

**Author:** [@strong-ge](https://discuss.elastic.co/u/strong-ge)\
**Replies:** 1\
**Last updated:** [June 5, 2020, 11:58pm UTC](https://discuss.elastic.co/t/why-filebeat-input-enabled-false-not-effective/234252 "2020-06-05T23:58:37Z")

</div>

I set the output config enabled flag that is 'false', when start the filebeat, the harvester still exec my log file, my enabled flag is not effective? Here is filebeat.yml: filebeat.config.inputs: path: configs/\*.y…

---

## [Metricbeat 7.7 problem](https://discuss.elastic.co/t/metricbeat-7-7-problem/235704)

<div class="topic-metadata">

**Author:** [@Mario\_Fimiani](https://discuss.elastic.co/u/Mario_Fimiani)\
**Replies:** 3\
**Last updated:** [June 5, 2020, 4:42pm UTC](https://discuss.elastic.co/t/metricbeat-7-7-problem/235704 "2020-06-05T16:42:13Z")

</div>

Hi I have installed metricbeat 7.7 on redhat 6.8 (Red Hat Enterprise Linux Server release 6.8 (Santiago)). After the configuration and restart of the agent, I'm receiving this error : Exiting: 1 error: error finding …

---

## [Trouble selecting beats inputs](https://discuss.elastic.co/t/trouble-selecting-beats-inputs/235830)

<div class="topic-metadata">

**Author:** [@Maria\_Daniel](https://discuss.elastic.co/u/Maria_Daniel)\
**Replies:** 1\
**Last updated:** [June 5, 2020, 3:17pm UTC](https://discuss.elastic.co/t/trouble-selecting-beats-inputs/235830 "2020-06-05T15:17:24Z")

</div>

Hello! So, i'm trying to select two different types of input files from the same directory. I add a different tag depending on the type of file so that I can later use different grok patterns to process the logs, based …

---

## [Please tell me why my filebeat multi-line pattern is not applicable](https://discuss.elastic.co/t/please-tell-me-why-my-filebeat-multi-line-pattern-is-not-applicable/235721)

<div class="topic-metadata">

**Author:** [@111349](https://discuss.elastic.co/u/111349)\
**Replies:** 2\
**Last updated:** [June 5, 2020, 12:55am UTC](https://discuss.elastic.co/t/please-tell-me-why-my-filebeat-multi-line-pattern-is-not-applicable/235721 "2020-06-05T00:55:57Z")

</div>

This is the harvester part of my file beat (version6.8) I intend so that the multi-line pattern is applied if the beginning of the log is not an 8-digit number. And if you encounter a log that starts with an 8-digit nu…

---

## [Need help with custom Filebeat modules, no input data in real tests but local dev test yes](https://discuss.elastic.co/t/need-help-with-custom-filebeat-modules-no-input-data-in-real-tests-but-local-dev-test-yes/235374)

<div class="topic-metadata">

**Author:** [@Stefan\_Sabolowitsch](https://discuss.elastic.co/u/Stefan_Sabolowitsch)\
**Replies:** 4\
**Last updated:** [June 4, 2020, 7:19pm UTC](https://discuss.elastic.co/t/need-help-with-custom-filebeat-modules-no-input-data-in-real-tests-but-local-dev-test-yes/235374 "2020-06-04T19:19:49Z")

</div>

Hi there, i created my own filebeat module, "filebeat-modules-devguide" served as the basis. All tests had been successful and now wanted to test them in real. The index and the ingest pipelines are created successful…

---

## [Oracle Modules](https://discuss.elastic.co/t/oracle-modules/230345)

<div class="topic-metadata">

**Author:** [@Mario\_Fimiani](https://discuss.elastic.co/u/Mario_Fimiani)\
**Replies:** 7\
**Last updated:** [June 4, 2020, 3:39pm UTC](https://discuss.elastic.co/t/oracle-modules/230345 "2020-06-04T15:39:18Z")

</div>

Hi we are testing this module for metricbeat (v7.5.0) that work with standard OCI driver. We installed/tested the following : enable the module instant client (as per doc) modify the systemd script to load the ENV va…

---

## [Multiline stderr logs mixed with stout logs](https://discuss.elastic.co/t/multiline-stderr-logs-mixed-with-stout-logs/233571)

<div class="topic-metadata">

**Author:** [@elia.oggian](https://discuss.elastic.co/u/elia.oggian)\
**Replies:** 3\
**Last updated:** [June 4, 2020, 2:01pm UTC](https://discuss.elastic.co/t/multiline-stderr-logs-mixed-with-stout-logs/233571 "2020-06-04T14:01:07Z")

</div>

I am having an issue collecting docker containers logs. The issue is that, for example, when a Java Stacktrace gets logged on multiple lines on stderr stream, it could be that other logs of the stdout stream are logged …

---

## [Just one unknown field - Filebeat json parsing](https://discuss.elastic.co/t/just-one-unknown-field-filebeat-json-parsing/234738)

<div class="topic-metadata">

**Author:** [@vdelcampo](https://discuss.elastic.co/u/vdelcampo)\
**Replies:** 4\
**Last updated:** [June 4, 2020, 2:00pm UTC](https://discuss.elastic.co/t/just-one-unknown-field-filebeat-json-parsing/234738 "2020-06-04T14:00:46Z")

</div>

Hi. Im using filebeat to send to Elasticsearch a preformatted json logfile. The files are parsing fine, but i have an unknown field and i don´t know why: Any ideas? Thanks in advance Víctor

---

## [Issues configuring AWS Module for MetricBeat](https://discuss.elastic.co/t/issues-configuring-aws-module-for-metricbeat/235355)

<div class="topic-metadata">

**Author:** [@ozonshak](https://discuss.elastic.co/u/ozonshak)\
**Replies:** 4\
**Last updated:** [June 4, 2020, 1:30pm UTC](https://discuss.elastic.co/t/issues-configuring-aws-module-for-metricbeat/235355 "2020-06-04T13:30:02Z")

</div>

Hello. I'm attempting to set up the AWS module for the first time with MetricBeat. I've got the module enabled, got past the authentication errors I was seeing (created an AWS user with full "ReadOnlyPolicy"), and upda…

---

## [HeartBeat issue with matching on response body string](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931)

<div class="topic-metadata">

**Author:** [@ozonshak](https://discuss.elastic.co/u/ozonshak)\
**Replies:** 16\
**Last updated:** [June 4, 2020, 12:55pm UTC](https://discuss.elastic.co/t/heartbeat-issue-with-matching-on-response-body-string/233931 "2020-06-04T12:55:23Z")

</div>

Hello. I'm installing HeartBeat for the first time. I've got the basic ping uptime check working. However, I would love to match on a keyword on the page. I keep coming across articles saying this will only match on …

---

## [Field \[winlog.event\_data.ProcessCreationTime\] of type \[keyword\] does not support custom formats](https://discuss.elastic.co/t/field-winlog-event-data-processcreationtime-of-type-keyword-does-not-support-custom-formats/235489)

<div class="topic-metadata">

**Author:** [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Replies:** 4\
**Last updated:** [June 4, 2020, 12:44pm UTC](https://discuss.elastic.co/t/field-winlog-event-data-processcreationtime-of-type-keyword-does-not-support-custom-formats/235489 "2020-06-04T12:44:11Z")

</div>

Hi, I have winlogbeat sending data via logstash to elasticsearch from a Windows 10 box. In Kibana I get Type illegal\_argument\_exception Reason Field \[winlog.event\_data.ProcessCreationTime\] of type \[keyword\] does not…

---

## [Filebeat on windows generating data much different than it is ingesting](https://discuss.elastic.co/t/filebeat-on-windows-generating-data-much-different-than-it-is-ingesting/235655)

<div class="topic-metadata">

**Author:** [@scott\_A](https://discuss.elastic.co/u/scott_A)\
**Replies:** 1\
**Last updated:** [June 4, 2020, 11:38am UTC](https://discuss.elastic.co/t/filebeat-on-windows-generating-data-much-different-than-it-is-ingesting/235655 "2020-06-04T11:38:25Z")

</div>

I configured filebeat to run on one of our Windows Server 2012 servers. It appears to be performing the ingest function on the log file I configured for it to use in the filebeat.yml file. It also appears to be parsing t…

---

## [On what all platforms/server/FTPs, i can configure filebeats in realtime application project, which platform is the best?](https://discuss.elastic.co/t/on-what-all-platforms-server-ftps-i-can-configure-filebeats-in-realtime-application-project-which-platform-is-the-best/235729)

<div class="topic-metadata">

**Author:** [@jagadish1](https://discuss.elastic.co/u/jagadish1)\
**Replies:** 0\
**Last updated:** [June 4, 2020, 10:19am UTC](https://discuss.elastic.co/t/on-what-all-platforms-server-ftps-i-can-configure-filebeats-in-realtime-application-project-which-platform-is-the-best/235729 "2020-06-04T10:19:21Z")

</div>

Hello, I want to use the filebeats for shipping logs of my application and send to kafka cluster(log ingestion). So, where can i host the filebeat in project realtime, is it either on vm/webserver/containers/ftp ? and …

---

## [Does beats capture dates of last patch applied and date](https://discuss.elastic.co/t/does-beats-capture-dates-of-last-patch-applied-and-date/233701)

<div class="topic-metadata">

**Author:** [@yasin\_mohammed](https://discuss.elastic.co/u/yasin_mohammed)\
**Replies:** 2\
**Last updated:** [June 4, 2020, 10:04am UTC](https://discuss.elastic.co/t/does-beats-capture-dates-of-last-patch-applied-and-date/233701 "2020-06-04T10:04:19Z")

</div>

Hi... I would like to know if beats capture the date and patch no for OS patches applied on the system

---

## [Single line files - no newline](https://discuss.elastic.co/t/single-line-files-no-newline/235205)

<div class="topic-metadata">

**Author:** [@sjsadowski](https://discuss.elastic.co/u/sjsadowski)\
**Replies:** 0\
**Last updated:** [June 1, 2020, 4:28pm UTC](https://discuss.elastic.co/t/single-line-files-no-newline/235205 "2020-06-01T16:28:45Z")

</div>

I have a single line logfile with no newline character that is not being shipped. I am aware that this is problematic from both searches here on the forums and some trial and error. With that being said, I don't have th…

---

## [How to add source ip (device ip) of host to log](https://discuss.elastic.co/t/how-to-add-source-ip-device-ip-of-host-to-log/235603)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 0\
**Last updated:** [June 3, 2020, 4:26pm UTC](https://discuss.elastic.co/t/how-to-add-source-ip-device-ip-of-host-to-log/235603 "2020-06-03T16:26:00Z")

</div>

Hi, We have winlogbeat installed on our host machines and are trying to get the IP address of them. On a previous version of winlogbeat 6.x? We were getting a field value \[beat\]\[ip\] which we were then able to use later…

---

## [Enquiry of the priority of 1 or more prospectors in filebeat](https://discuss.elastic.co/t/enquiry-of-the-priority-of-1-or-more-prospectors-in-filebeat/235488)

<div class="topic-metadata">

**Author:** [@iammanmale](https://discuss.elastic.co/u/iammanmale)\
**Replies:** 2\
**Last updated:** [June 4, 2020, 1:59am UTC](https://discuss.elastic.co/t/enquiry-of-the-priority-of-1-or-more-prospectors-in-filebeat/235488 "2020-06-04T01:59:45Z")

</div>

I have configured different prospectors to collect different kind of log on the same machine. As the urgency of each logs are different, is it possible to make the filebeat to collect certain kind of log first before ot…

---

## [Packet on window](https://discuss.elastic.co/t/packet-on-window/234177)

<div class="topic-metadata">

**Author:** [@Guddu\_Prasad](https://discuss.elastic.co/u/Guddu_Prasad)\
**Replies:** 1\
**Last updated:** [June 4, 2020, 12:42am UTC](https://discuss.elastic.co/t/packet-on-window/234177 "2020-06-04T00:42:23Z")

</div>

Hi Team, I trying to use Packetbeat on a windows machine. I have placed the Packetbeat folder in c:/program file and when I start the service using the command I can see the Packetbeat service get started however I do …

---

## [Journalbeat processor logical operators fail with expanded notation](https://discuss.elastic.co/t/journalbeat-processor-logical-operators-fail-with-expanded-notation/233813)

<div class="topic-metadata">

**Author:** [@Disconn3ct](https://discuss.elastic.co/u/Disconn3ct)\
**Replies:** 3\
**Last updated:** [June 3, 2020, 11:54pm UTC](https://discuss.elastic.co/t/journalbeat-processor-logical-operators-fail-with-expanded-notation/233813 "2020-06-03T23:54:48Z")

</div>

Version: 7.6.1 Operating System: Ubuntu 16.04 Creating a journalbeat configuration using logical operators according to the documentation causes failures: processors: - drop\_event: when: or: …

---

## [Pass full original timestamp from Zeek log to Elasticsearch](https://discuss.elastic.co/t/pass-full-original-timestamp-from-zeek-log-to-elasticsearch/233944)

<div class="topic-metadata">

**Author:** [@matthewerobison](https://discuss.elastic.co/u/matthewerobison)\
**Replies:** 3\
**Last updated:** [June 3, 2020, 11:37pm UTC](https://discuss.elastic.co/t/pass-full-original-timestamp-from-zeek-log-to-elasticsearch/233944 "2020-06-03T23:37:55Z")

</div>

I have an Elastic cluster setup with a server hosting Zeek and Filebeat. We are manually running PCAP files through Zeek, Filebeat is picking up the logs, and data is being parsed/indexed by Elastic and we can see all t…

---

## [Setting different ilm policy based on index name](https://discuss.elastic.co/t/setting-different-ilm-policy-based-on-index-name/234497)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 11\
**Last updated:** [June 3, 2020, 6:16pm UTC](https://discuss.elastic.co/t/setting-different-ilm-policy-based-on-index-name/234497 "2020-06-03T18:16:06Z")

</div>

I use "indices" syntax to create a different indexes based on a module name. I want to apply different ilm policy based on index name? How can I achieve that? indices: - index: "filebeat-netflow-%{+yyyy.MM.dd}" …

---

## [Couchbase module throws json parse exception on basicStats.opsPerSec](https://discuss.elastic.co/t/couchbase-module-throws-json-parse-exception-on-basicstats-opspersec/235455)

<div class="topic-metadata">

**Author:** [@amrishraje](https://discuss.elastic.co/u/amrishraje)\
**Replies:** 1\
**Last updated:** [June 3, 2020, 4:40pm UTC](https://discuss.elastic.co/t/couchbase-module-throws-json-parse-exception-on-basicstats-opspersec/235455 "2020-06-03T16:40:09Z")

</div>

I am trying to use Metricbeats couchbase module. I keep getting the below error Error: %!(EXTRA \*json.UnmarshalTypeError=json: cannot unmarshal number 790.2097902097902 into Go struct field BucketBasicStats.opsPerSec of…

---

## [Configure file beat to multiple output](https://discuss.elastic.co/t/configure-file-beat-to-multiple-output/235471)

<div class="topic-metadata">

**Author:** [@user524](https://discuss.elastic.co/u/user524)\
**Replies:** 1\
**Last updated:** [June 3, 2020, 4:36pm UTC](https://discuss.elastic.co/t/configure-file-beat-to-multiple-output/235471 "2020-06-03T16:36:33Z")

</div>

Hi Team, We have a requirement where we are sending logs from the db using filebeat to elasticsearch cluster and Kafka cluster based on the type of the log. For Example: If the log type is INFO we need to send it to El…

---

## [Offset mssql logs](https://discuss.elastic.co/t/offset-mssql-logs/235542)

<div class="topic-metadata">

**Author:** [@GedeoN](https://discuss.elastic.co/u/GedeoN)\
**Replies:** 1\
**Last updated:** [June 3, 2020, 4:19pm UTC](https://discuss.elastic.co/t/offset-mssql-logs/235542 "2020-06-03T16:19:05Z")

</div>

Hi, I'm working on a solution to send mssql logs to Elasticsearch. The global solution is working, but i don't have solution to only send the difference. In thirst time, I copy and encoding mssql logs files in an othe…

---

## [Filebeat json file transfer](https://discuss.elastic.co/t/filebeat-json-file-transfer/235574)

<div class="topic-metadata">

**Author:** [@jshi](https://discuss.elastic.co/u/jshi)\
**Replies:** 1\
**Last updated:** [June 3, 2020, 4:07pm UTC](https://discuss.elastic.co/t/filebeat-json-file-transfer/235574 "2020-06-03T16:07:54Z")

</div>

Hi, I'm wondering if I have filebeat configured correctly to ship a json file from a local directory to elasticsearch. I'm running filebeat and the elastic stack on a ubuntu AWS VM server and the local json file is sto…

---

## [Upgrade from 7.6.2 to 7.7.0 stops filebeat logging to /var/log/filebeat on Debian 8](https://discuss.elastic.co/t/upgrade-from-7-6-2-to-7-7-0-stops-filebeat-logging-to-var-log-filebeat-on-debian-8/235349)

<div class="topic-metadata">

**Author:** [@fairfx](https://discuss.elastic.co/u/fairfx)\
**Replies:** 2\
**Last updated:** [June 3, 2020, 1:28pm UTC](https://discuss.elastic.co/t/upgrade-from-7-6-2-to-7-7-0-stops-filebeat-logging-to-var-log-filebeat-on-debian-8/235349 "2020-06-03T13:28:34Z")

</div>

I have used filebeat for nearly a year. Awesome product. I have it running on a number of servers running Debian 7 and Debian 8. The upgrade to 7.7.0 I did this morning on Debian 7 worked exactly as expected, but on t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=240)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=242)
