# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=242

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 243

---

## [Error getting list of running units](https://discuss.elastic.co/t/error-getting-list-of-running-units/233544)

<div class="topic-metadata">

**Author:** [@Deny7](https://discuss.elastic.co/u/Deny7)\
**Replies:** 3\
**Last updated:** [June 3, 2020, 11:25am UTC](https://discuss.elastic.co/t/error-getting-list-of-running-units/233544 "2020-06-03T11:25:36Z")

</div>

Hi, I just installed metricbeat-oss-7.6.2-x86\_64.rpm. I configured system.yml but when I run it as service I get errors in logs: 2020-05-20T14:52:44.744+0200 INFO module/wrapper.go:252 Error fetching data for metricset…

---

## [Path to Logs not respected](https://discuss.elastic.co/t/path-to-logs-not-respected/234338)

<div class="topic-metadata">

**Author:** [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Replies:** 2\
**Last updated:** [June 3, 2020, 8:39am UTC](https://discuss.elastic.co/t/path-to-logs-not-respected/234338 "2020-06-03T08:39:22Z")

</div>

Hi, I've upgraded one metricbeat installation to 7.7. Since the upgrade, the logs are written in /var/log/messages and not respecting the -path.logs setting. From the former releases I have customized systemd to this s…

---

## [Filebeat sends same logs to Logstash on every restart](https://discuss.elastic.co/t/filebeat-sends-same-logs-to-logstash-on-every-restart/235376)

<div class="topic-metadata">

**Author:** [@vijayjavaprgmr](https://discuss.elastic.co/u/vijayjavaprgmr)\
**Replies:** 3\
**Last updated:** [June 2, 2020, 6:08pm UTC](https://discuss.elastic.co/t/filebeat-sends-same-logs-to-logstash-on-every-restart/235376 "2020-06-02T18:08:45Z")

</div>

Hi, I am using Filebeat 6.5.8 and deployed it in the openshift. The log & registry file available in the mount location. Filebeat sends same logs to Logstash on every restart and when i checked the registry file, can a…

---

## [Capturing metrics from all nodes in a docker swarm](https://discuss.elastic.co/t/capturing-metrics-from-all-nodes-in-a-docker-swarm/235445)

<div class="topic-metadata">

**Author:** [@robsv](https://discuss.elastic.co/u/robsv)\
**Replies:** 0\
**Last updated:** [June 3, 2020, 2:21am UTC](https://discuss.elastic.co/t/capturing-metrics-from-all-nodes-in-a-docker-swarm/235445 "2020-06-03T02:21:58Z")

</div>

I have a Docker Swarm with a total of 4 nodes (1 leader, 3 workers), and I've been using Metricbeat to capture system metrics (CPU, etc.). Metricbeat is installed on all four nodes, but outside of Docker. Each node sends…

---

## [Filebeat MISP module error](https://discuss.elastic.co/t/filebeat-misp-module-error/233882)

<div class="topic-metadata">

**Author:** [@flxdan](https://discuss.elastic.co/u/flxdan)\
**Replies:** 2\
**Last updated:** [June 2, 2020, 10:57pm UTC](https://discuss.elastic.co/t/filebeat-misp-module-error/233882 "2020-06-02T22:57:35Z")

</div>

Previously had the MISP module working although not used frequently. Recently I've noticed that it seems to be broken, I've updated to Filebeat (7.7) recently. The logs say "key not found". Filebeat logs: May 22 …

---

## [Httpjson input broke in 7.7](https://discuss.elastic.co/t/httpjson-input-broke-in-7-7/234517)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 1\
**Last updated:** [June 2, 2020, 10:53pm UTC](https://discuss.elastic.co/t/httpjson-input-broke-in-7-7/234517 "2020-06-02T22:53:04Z")

</div>

Since 7.7, the httpjson input has issues with the json\_objects\_array option - if that option is set, filebeat faults with ERROR \[httpjson\] httpjson/input.go:123 key not found. I've prepared a docker-compose setup to make…

---

## [Ignore\_order not working in Filebeat](https://discuss.elastic.co/t/ignore-order-not-working-in-filebeat/234420)

<div class="topic-metadata">

**Author:** [@PRODIPTO](https://discuss.elastic.co/u/PRODIPTO)\
**Replies:** 3\
**Last updated:** [June 2, 2020, 8:23pm UTC](https://discuss.elastic.co/t/ignore-order-not-working-in-filebeat/234420 "2020-06-02T20:23:51Z")

</div>

In the filebeat.yml file we have ignore\_order : 24h , still when filebeat was started for first time it picked up log events from all files which were present in the directory and matched with the naming pattern , some …

---

## [Metricbeat w/ aws module says failed to list account aliases and failed to get caller identity](https://discuss.elastic.co/t/metricbeat-w-aws-module-says-failed-to-list-account-aliases-and-failed-to-get-caller-identity/234638)

<div class="topic-metadata">

**Author:** [@syost](https://discuss.elastic.co/u/syost)\
**Replies:** 3\
**Last updated:** [June 2, 2020, 7:14pm UTC](https://discuss.elastic.co/t/metricbeat-w-aws-module-says-failed-to-list-account-aliases-and-failed-to-get-caller-identity/234638 "2020-06-02T19:14:39Z")

</div>

I've enabled the metricbeat module called aws. When starting metricbeat I receive the following errors... 2020-05-27T23:59:07.253Z INFO \[monitoring\] log/log.go:118 Starting metrics logging every 30s 2020-05-27T23:59:07.…

---

## [Filebeat 7.7.0 @timestamp not UTC](https://discuss.elastic.co/t/filebeat-7-7-0-timestamp-not-utc/235396)

<div class="topic-metadata">

**Author:** [@tzeappa](https://discuss.elastic.co/u/tzeappa)\
**Replies:** 0\
**Last updated:** [June 2, 2020, 6:50pm UTC](https://discuss.elastic.co/t/filebeat-7-7-0-timestamp-not-utc/235396 "2020-06-02T18:50:46Z")

</div>

Hello, Since upgrading to Filebeat 7.7.0 it seems that the @timestamp is no longer UTC for type: log and it just parses the OS date without any timezone filtering. I have made sure that the event.timezone is added prop…

---

## [Winlogbeat to write output to a file](https://discuss.elastic.co/t/winlogbeat-to-write-output-to-a-file/234525)

<div class="topic-metadata">

**Author:** [@guruprasadh4](https://discuss.elastic.co/u/guruprasadh4)\
**Replies:** 2\
**Last updated:** [June 2, 2020, 4:54pm UTC](https://discuss.elastic.co/t/winlogbeat-to-write-output-to-a-file/234525 "2020-06-02T16:54:36Z")

</div>

Team, Is there a way we can have filename dynamically picks the host.name while writing to a file ? Something like below. output.file: path: "/tmp/winlogbeat" filename: \*\*\*${host.name}\*\*\*

---

## [Filebeat metadata docker](https://discuss.elastic.co/t/filebeat-metadata-docker/235368)

<div class="topic-metadata">

**Author:** [@yassine](https://discuss.elastic.co/u/yassine)\
**Replies:** 2\
**Last updated:** [June 2, 2020, 4:16pm UTC](https://discuss.elastic.co/t/filebeat-metadata-docker/235368 "2020-06-02T16:16:52Z")

</div>

I wanted to know if there was a way for filebeat to send specific metada from the node because right now i am getting a nod id for each event which is a random long id created by docker and the hostname that is sending i…

---

## [Filebeat multiline patern loglevel match](https://discuss.elastic.co/t/filebeat-multiline-patern-loglevel-match/235362)

<div class="topic-metadata">

**Author:** [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Replies:** 1\
**Last updated:** [June 2, 2020, 3:56pm UTC](https://discuss.elastic.co/t/filebeat-multiline-patern-loglevel-match/235362 "2020-06-02T15:56:54Z")

</div>

The log has the following view: \[WARNING\] \[HOSTNAME\] \[Servicename.Web.Node2\] \[https://google.com/application/WebModules/AdminTools/UsersSessionInfo/UsersSessionInfo.aspx\] \[12/26/2019 15:34:27.569\] \[DOMAIN\\USER\] \[CLUSTER…

---

## [Filebeat output failed](https://discuss.elastic.co/t/filebeat-output-failed/235294)

<div class="topic-metadata">

**Author:** [@stanwang](https://discuss.elastic.co/u/stanwang)\
**Replies:** 1\
**Last updated:** [June 2, 2020, 3:48pm UTC](https://discuss.elastic.co/t/filebeat-output-failed/235294 "2020-06-02T15:48:17Z")

</div>

Hi, I have a Win10 for client and Ubuntu20 for ELK server. Previously, I have built Winlogbeat on my client, and it run successfully that the event can be shown on Kibana. Then, I build Filebeat on the same client, and …

---

## [Metricbeat ILM enabled with OSS ES Cluster when using auto](https://discuss.elastic.co/t/metricbeat-ilm-enabled-with-oss-es-cluster-when-using-auto/235293)

<div class="topic-metadata">

**Author:** [@TheNom](https://discuss.elastic.co/u/TheNom)\
**Replies:** 1\
**Last updated:** [June 2, 2020, 3:23pm UTC](https://discuss.elastic.co/t/metricbeat-ilm-enabled-with-oss-es-cluster-when-using-auto/235293 "2020-06-02T15:23:22Z")

</div>

Hi, I have an issue with Metricbeat OSS v7.6.1 enabling the ILM feature when the output is an OSS\\OD cluster. Jun 01 10:44:38 ip-10-100-129-179.eu-west-1.compute.internal metricbeat\[3654\]: 2020-06-01T10:44:38.720Z …

---

## [Cant see data from Windows module in kibana](https://discuss.elastic.co/t/cant-see-data-from-windows-module-in-kibana/235203)

<div class="topic-metadata">

**Author:** [@Deny7](https://discuss.elastic.co/u/Deny7)\
**Replies:** 3\
**Last updated:** [June 2, 2020, 3:06pm UTC](https://discuss.elastic.co/t/cant-see-data-from-windows-module-in-kibana/235203 "2020-06-02T15:06:05Z")

</div>

Hi, I just installed metricbeat-7.6.2-windows-x86\_64-OSS on Windows Server 2008 R2 Enterprise. I have already in kibana metricbeat\* index where I monitor Linux servers. I disabled system.yml and enabled windows.yml mod…

---

## [Filebeat touches my @timestamp even I've explicitly said don't do this!](https://discuss.elastic.co/t/filebeat-touches-my-timestamp-even-ive-explicitly-said-dont-do-this/235127)

<div class="topic-metadata">

**Author:** [@alchy](https://discuss.elastic.co/u/alchy)\
**Replies:** 4\
**Last updated:** [June 2, 2020, 2:21pm UTC](https://discuss.elastic.co/t/filebeat-touches-my-timestamp-even-ive-explicitly-said-dont-do-this/235127 "2020-06-02T14:21:05Z")

</div>

Hi, thank you for reading, the story goes: generated event in file {"@timestamp": "20200601T070018-0100", "src\_type": ""...} ... ... ... all the lines with in the same @timestamp format filebeat 7.7 grabs file on…

---

## [Failed to log events to logstash](https://discuss.elastic.co/t/failed-to-log-events-to-logstash/234305)

<div class="topic-metadata">

**Author:** [@pchar](https://discuss.elastic.co/u/pchar)\
**Replies:** 9\
**Last updated:** [June 2, 2020, 12:50pm UTC](https://discuss.elastic.co/t/failed-to-log-events-to-logstash/234305 "2020-06-02T12:50:57Z")

</div>

Hello, I just configured ELK stack on a server and winlogbeat with sysmon on a windows 10 computer. The objective is to forward windows logs to logstash. Unfortunately, I have an issue because no logs are forwarded to…

---

## [Error: bucket '\<bucketname\>' already exist and you don't have permission to access it](https://discuss.elastic.co/t/error-bucket-bucketname-already-exist-and-you-dont-have-permission-to-access-it/235232)

<div class="topic-metadata">

**Author:** [@sunilb1](https://discuss.elastic.co/u/sunilb1)\
**Replies:** 0\
**Last updated:** [June 1, 2020, 8:53pm UTC](https://discuss.elastic.co/t/error-bucket-bucketname-already-exist-and-you-dont-have-permission-to-access-it/235232 "2020-06-01T20:53:46Z")

</div>

Hi, While deploy Function Beat using standard method , getting permission error for S3 bucket. I am able to access the same bucket from CLI . Kindly advise. /functionbeat -v -e -d "\*" deploy cloudwatchecs 2020-06-01…

---

## [How to update log msg with FileBeat](https://discuss.elastic.co/t/how-to-update-log-msg-with-filebeat/235237)

<div class="topic-metadata">

**Author:** [@samyesz](https://discuss.elastic.co/u/samyesz)\
**Replies:** 0\
**Last updated:** [June 1, 2020, 9:46pm UTC](https://discuss.elastic.co/t/how-to-update-log-msg-with-filebeat/235237 "2020-06-01T21:46:16Z")

</div>

I am new to FileBeat and I checked the document, yet seems can't find a way to update the log message from input log file to output log file. It seems to be I should be using one of the processors yet I tried some and s…

---

## [Oracle Module](https://discuss.elastic.co/t/oracle-module/234736)

<div class="topic-metadata">

**Author:** [@Sayed\_Eldawy](https://discuss.elastic.co/u/Sayed_Eldawy)\
**Replies:** 1\
**Last updated:** [June 1, 2020, 10:21pm UTC](https://discuss.elastic.co/t/oracle-module/234736 "2020-06-01T22:21:34Z")

</div>

Hello All, we have Oracle Release 12.1.0.2.0 running over RHEL 6.2 and need to use metricbeat 7.7 oracle module, But as per the module compatibility it is tested with Docker based on ARCH. is anyone tried with RHEL and…

---

## [Can't setup kibana dashboards](https://discuss.elastic.co/t/cant-setup-kibana-dashboards/225286)

<div class="topic-metadata">

**Author:** [@chimeno](https://discuss.elastic.co/u/chimeno)\
**Replies:** 1\
**Last updated:** [June 1, 2020, 10:16pm UTC](https://discuss.elastic.co/t/cant-setup-kibana-dashboards/225286 "2020-06-01T22:16:45Z")

</div>

Debian 10 journalbeat 7.6.1 installed with apt when configured with: setup.dashboards.enabled: true journalbeat says: Error importing Kibana dashboards: fail to import the dashboards in Kibana: Error importing dire…

---

## [Filebeat \_all field functionality](https://discuss.elastic.co/t/filebeat-all-field-functionality/232422)

<div class="topic-metadata">

**Author:** [@Richard\_Neely](https://discuss.elastic.co/u/Richard_Neely)\
**Replies:** 1\
**Last updated:** [June 1, 2020, 9:33pm UTC](https://discuss.elastic.co/t/filebeat-all-field-functionality/232422 "2020-06-01T21:33:13Z")

</div>

When we were using version 5.6 of everything filebeat sent the raw unparsed json to logstash, which in turn parsed all the fields but also had a \_all/\_source field that had the entire document in there as a string that y…

---

## [Auditbeat 7.7.0 fails to start on Kubuntu](https://discuss.elastic.co/t/auditbeat-7-7-0-fails-to-start-on-kubuntu/235004)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 3\
**Last updated:** [June 1, 2020, 9:14pm UTC](https://discuss.elastic.co/t/auditbeat-7-7-0-fails-to-start-on-kubuntu/235004 "2020-06-01T21:14:56Z")

</div>

I am trying to run auditbeat on Kubuntu (20.04 LTS), however it keeps crashing. There is no configuration inside audit.rules.d/. However crash reason seems to be something else: May 30 13:13:01 HOSTNAME auditbeat\[1…

---

## [Metricbeats dashboards for Kubernetes controller manager](https://discuss.elastic.co/t/metricbeats-dashboards-for-kubernetes-controller-manager/233402)

<div class="topic-metadata">

**Author:** [@camilisette](https://discuss.elastic.co/u/camilisette)\
**Replies:** 6\
**Last updated:** [June 1, 2020, 8:49pm UTC](https://discuss.elastic.co/t/metricbeats-dashboards-for-kubernetes-controller-manager/233402 "2020-06-01T20:49:37Z")

</div>

For some reason the visualizations of "\[Metricbeat Kubernetes\] Controller Manager" are corrupted. I'm not getting any data on the dashboard, so I drilled down to the panels and saw that the fields on the visualizations …

---

## [Auditbeat 7.7.0 fails to start on Fedora 32 VM: system/socket guess timeout](https://discuss.elastic.co/t/auditbeat-7-7-0-fails-to-start-on-fedora-32-vm-system-socket-guess-timeout/233160)

<div class="topic-metadata">

**Author:** [@roysjosh](https://discuss.elastic.co/u/roysjosh)\
**Replies:** 2\
**Last updated:** [June 1, 2020, 8:29pm UTC](https://discuss.elastic.co/t/auditbeat-7-7-0-fails-to-start-on-fedora-32-vm-system-socket-guess-timeout/233160 "2020-06-01T20:29:16Z")

</div>

Hello, auditbeat 7.7.0 is failing to start on a fresh Fedora 32 VM. Here is a partial debug log: auditbeat\[879\]: 2020-05-18T03:43:54.446Z INFO \[socket\] guess/guess.go:258 Running 17 guesses …

---

## [Docker memory metrics seems to be incorrect](https://discuss.elastic.co/t/docker-memory-metrics-seems-to-be-incorrect/235120)

<div class="topic-metadata">

**Author:** [@Slavik\_Fursov](https://discuss.elastic.co/u/Slavik_Fursov)\
**Replies:** 4\
**Last updated:** [June 1, 2020, 8:10pm UTC](https://discuss.elastic.co/t/docker-memory-metrics-seems-to-be-incorrect/235120 "2020-06-01T20:10:55Z")

</div>

I installed metricbeat on my Ubuntu 20.04 VM, which has Docker 19.03.9 running. By looking at the \[Metricbeat Docker\] Overview ECS dashboar, it looks like one of the container's memory usage is growing / leaking: Bu…

---

## [Target specific pod in kubernetes filbeat](https://discuss.elastic.co/t/target-specific-pod-in-kubernetes-filbeat/234337)

<div class="topic-metadata">

**Author:** [@recordable542](https://discuss.elastic.co/u/recordable542)\
**Replies:** 3\
**Last updated:** [June 1, 2020, 5:03pm UTC](https://discuss.elastic.co/t/target-specific-pod-in-kubernetes-filbeat/234337 "2020-06-01T17:03:27Z")

</div>

I'm using this yaml to deploy filebeat to my GKE cluster: it works like charm, but I want to push only container named "sy-prod" so, I changed the configMap like below. filebeat.autodiscover: providers: - ty…

---

## [Failed to publish events: temporary bulk send failure for custom ES index](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure-for-custom-es-index/234387)

<div class="topic-metadata">

**Author:** [@robsv](https://discuss.elastic.co/u/robsv)\
**Replies:** 3\
**Last updated:** [June 1, 2020, 4:34pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure-for-custom-es-index/234387 "2020-06-01T16:34:05Z")

</div>

I am trying to set up a custom index name for Metricbeat to use in ES (so I can have more than one server send to the same ES). When I start metricbeat with systemctl, it gets in a loop and constantly throws a "Failed to…

---

## [Preprocessor decode\_json\_fields does not include error key when add\_error\_key true](https://discuss.elastic.co/t/preprocessor-decode-json-fields-does-not-include-error-key-when-add-error-key-true/235192)

<div class="topic-metadata">

**Author:** [@dorinand](https://discuss.elastic.co/u/dorinand)\
**Replies:** 0\
**Last updated:** [June 1, 2020, 3:01pm UTC](https://discuss.elastic.co/t/preprocessor-decode-json-fields-does-not-include-error-key-when-add-error-key-true/235192 "2020-06-01T15:01:56Z")

</div>

I have connected filebeat to logstash and process logs from my docker app. Filebeat, logstash, elsticsearch and kibana are dockerized. I would like to harvest docker logs so I implement python app, that generate this log…

---

## [From filebeat sending json not able to retrive data using lucene query from grafana, how to configure json in filebeat](https://discuss.elastic.co/t/from-filebeat-sending-json-not-able-to-retrive-data-using-lucene-query-from-grafana-how-to-configure-json-in-filebeat/235145)

<div class="topic-metadata">

**Author:** [@shanthi](https://discuss.elastic.co/u/shanthi)\
**Replies:** 0\
**Last updated:** [June 1, 2020, 10:52am UTC](https://discuss.elastic.co/t/from-filebeat-sending-json-not-able-to-retrive-data-using-lucene-query-from-grafana-how-to-configure-json-in-filebeat/235145 "2020-06-01T10:52:07Z")

</div>

from filebeat sending json not able to retrive data using lucene query from grafana, how to configure json in filebeat.yml and sample file if possible. Can someone can help on the same.

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=241)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=243)
