# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=243

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 244

---

## [CEF module parsing, agent.name and agent.hostname are incorrectly set](https://discuss.elastic.co/t/cef-module-parsing-agent-name-and-agent-hostname-are-incorrectly-set/234084)

<div class="topic-metadata">

**Author:** [@undelete](https://discuss.elastic.co/u/undelete)\
**Replies:** 3\
**Last updated:** [June 1, 2020, 10:51am UTC](https://discuss.elastic.co/t/cef-module-parsing-agent-name-and-agent-hostname-are-incorrectly-set/234084 "2020-06-01T10:51:54Z")

</div>

Hi, Im using the Filebeat 7.6.0 to parse CEF logs from our ArcSight SmartConnector. I've noticed that agent.hostname and agent.name is incorrectly set. Agent.name should not be the hostname of the host where the SmartCon…

---

## [Filebeat not starting Error creating input: string value is not set accessing 'url'](https://discuss.elastic.co/t/filebeat-not-starting-error-creating-input-string-value-is-not-set-accessing-url/235107)

<div class="topic-metadata">

**Author:** [@Mangolinux](https://discuss.elastic.co/u/Mangolinux)\
**Replies:** 0\
**Last updated:** [June 1, 2020, 4:08am UTC](https://discuss.elastic.co/t/filebeat-not-starting-error-creating-input-string-value-is-not-set-accessing-url/235107 "2020-06-01T04:08:52Z")

</div>

I am trying to start filebeat and I get these errors WARN \[cfgwarn\] syslog/input.go:111 EXPERIMENTAL: Syslog input type is used ERROR fileset/factory.go:106 Error creating input: stri…

---

## [Metricbeat postgresql (with statement on) module generating too many docs](https://discuss.elastic.co/t/metricbeat-postgresql-with-statement-on-module-generating-too-many-docs/235095)

<div class="topic-metadata">

**Author:** [@Rodrigo\_Jimenez](https://discuss.elastic.co/u/Rodrigo_Jimenez)\
**Replies:** 0\
**Last updated:** [May 31, 2020, 9:48pm UTC](https://discuss.elastic.co/t/metricbeat-postgresql-with-statement-on-module-generating-too-many-docs/235095 "2020-05-31T21:48:03Z")

</div>

Hi!, I'm trying the statement feature of postgres module in metricbeat (metricbeat v.7.7) I generates data all right, but it filled my cluster's capacity overnight. I'm getting more than 5000 docs/min and I don't know …

---

## [Recommended way of storing credentials in Beats configuration file?](https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081)

<div class="topic-metadata">

**Author:** [@curiousmind](https://discuss.elastic.co/u/curiousmind)\
**Replies:** 1\
**Last updated:** [May 31, 2020, 9:23pm UTC](https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081 "2020-05-31T21:23:29Z")

</div>

What is the recommended way of storing the credentials like username and passwords in the beats configuration file? Our deployment is via terraform and ansible, which essentially stores the credentials in the environmen…

---

## [Filebeat v7.3 or above for FreeBSD to collect Bro/Zeek Log](https://discuss.elastic.co/t/filebeat-v7-3-or-above-for-freebsd-to-collect-bro-zeek-log/233226)

<div class="topic-metadata">

**Author:** [@Minh\_Ti\_n\_Tr\_n](https://discuss.elastic.co/u/Minh_Ti_n_Tr_n)\
**Replies:** 1\
**Last updated:** [May 30, 2020, 6:58pm UTC](https://discuss.elastic.co/t/filebeat-v7-3-or-above-for-freebsd-to-collect-bro-zeek-log/233226 "2020-05-30T18:58:05Z")

</div>

Anyone know how to install the lastest version v7.6.0 on freeBSD? I have a pfsense 2.4.5 with zeek log installed on it and want to ship log to ES Siem I tried the instruction: https://blog.securitybits.io/2019/12/beats…

---

## [Calling metricbeat Makefile issues](https://discuss.elastic.co/t/calling-metricbeat-makefile-issues/233949)

<div class="topic-metadata">

**Author:** [@ruhlowr](https://discuss.elastic.co/u/ruhlowr)\
**Replies:** 2\
**Last updated:** [May 29, 2020, 9:56pm UTC](https://discuss.elastic.co/t/calling-metricbeat-makefile-issues/233949 "2020-05-29T21:56:39Z")

</div>

I am new to ealsticsearch and metricbeat, and GO/MAGE. I've successfully compiled filebeat and am working on metricbeat on a Power9 ppc64le system. The following make commands work successfully: make check make fmt W…

---

## [Metricbeat WARN Cannot index event](https://discuss.elastic.co/t/metricbeat-warn-cannot-index-event/234212)

<div class="topic-metadata">

**Author:** [@lrabbade](https://discuss.elastic.co/u/lrabbade)\
**Replies:** 1\
**Last updated:** [May 29, 2020, 8:16pm UTC](https://discuss.elastic.co/t/metricbeat-warn-cannot-index-event/234212 "2020-05-29T20:16:56Z")

</div>

I've seen a few posts like this, but none of them solved my problem, so: I created a elastic cluster following this tutorial: https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-tls-docker.html I…

---

## [How to install Metricbeat in Docker?](https://discuss.elastic.co/t/how-to-install-metricbeat-in-docker/234225)

<div class="topic-metadata">

**Author:** [@grantcurell](https://discuss.elastic.co/u/grantcurell)\
**Replies:** 1\
**Last updated:** [May 29, 2020, 6:48pm UTC](https://discuss.elastic.co/t/how-to-install-metricbeat-in-docker/234225 "2020-05-29T18:48:01Z")

</div>

Playing around with the UI and I go to install Metricbeat under monitoring, just click the out of the box button "Install Metricbeat" and it comes back with: Setup mode is not available You do not have the necessary p…

---

## [Limiting Filebeat Autodiscover to Namespace](https://discuss.elastic.co/t/limiting-filebeat-autodiscover-to-namespace/234803)

<div class="topic-metadata">

**Author:** [@jvirgo](https://discuss.elastic.co/u/jvirgo)\
**Replies:** 1\
**Last updated:** [May 29, 2020, 6:00pm UTC](https://discuss.elastic.co/t/limiting-filebeat-autodiscover-to-namespace/234803 "2020-05-29T18:00:40Z")

</div>

I am hoping I can get some guidance on an issue I am having with my filebeat.yml and my kubernetes environment. I am new to elastic so hopefully I am providing the relevant info. I am running a filebeat daemonset and fro…

---

## [Metricbeat swap usage per process](https://discuss.elastic.co/t/metricbeat-swap-usage-per-process/234920)

<div class="topic-metadata">

**Author:** [@Jo\_De\_Troy](https://discuss.elastic.co/u/Jo_De_Troy)\
**Replies:** 1\
**Last updated:** [May 29, 2020, 5:57pm UTC](https://discuss.elastic.co/t/metricbeat-swap-usage-per-process/234920 "2020-05-29T17:57:12Z")

</div>

Hello, I've got a request to see the swap usage of individual processes. I've looked around in the metricbeat docs and field list and it seem like currently that's not captured. Is there any other way to capture this? A…

---

## [How to delete/drop the fields while the value matches a specific pattern?](https://discuss.elastic.co/t/how-to-delete-drop-the-fields-while-the-value-matches-a-specific-pattern/234937)

<div class="topic-metadata">

**Author:** [@Kuo\_Hugo](https://discuss.elastic.co/u/Kuo_Hugo)\
**Replies:** 0\
**Last updated:** [May 29, 2020, 2:29pm UTC](https://discuss.elastic.co/t/how-to-delete-drop-the-fields-while-the-value-matches-a-specific-pattern/234937 "2020-05-29T14:29:26Z")

</div>

I'm using dissect plugin to parse logs. The log looks like this: a b c d - f - h The dissect is %{f1} %{f2} %{f3} %{f4} %{f5} %{f6} %{f7} So the "f4": - I'm looking for a way to drop the field with dash (-) from th…

---

## [Autoindex seems like doesn't work](https://discuss.elastic.co/t/autoindex-seems-like-doesnt-work/234278)

<div class="topic-metadata">

**Author:** [@john\_peterson](https://discuss.elastic.co/u/john_peterson)\
**Replies:** 7\
**Last updated:** [May 29, 2020, 12:54pm UTC](https://discuss.elastic.co/t/autoindex-seems-like-doesnt-work/234278 "2020-05-29T12:54:13Z")

</div>

env:centos 8 x64 with firewalld selinux disabled filebeat 7.7.0 es 7.7.0 was just enabled xpack feature in es,and now I cannot see any log in es from filebeat.before xpack enabled it works perfect. and the error in s…

---

## [Message "failed to find message" event.dataset "cisco.asa"](https://discuss.elastic.co/t/message-failed-to-find-message-event-dataset-cisco-asa/232690)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 11\
**Last updated:** [May 29, 2020, 10:09am UTC](https://discuss.elastic.co/t/message-failed-to-find-message-event-dataset-cisco-asa/232690 "2020-05-29T10:09:09Z")

</div>

Hello, I have a problem with displaying parsed logs inside Kibana. I am using Filebeat Cisco module to inser logs from file to Elasticsearch I can see index of Filebeat My Filebeat Cisco module configuration config…

---

## [Filebeat output resilience/scalability](https://discuss.elastic.co/t/filebeat-output-resilience-scalability/234893)

<div class="topic-metadata">

**Author:** [@corentin.savineau](https://discuss.elastic.co/u/corentin.savineau)\
**Replies:** 0\
**Last updated:** [May 29, 2020, 9:49am UTC](https://discuss.elastic.co/t/filebeat-output-resilience-scalability/234893 "2020-05-29T09:49:51Z")

</div>

Hi there, I've been working on a cluster Elastic stack cluster. Everything works fine but I would like to push the resilience/scalability further. Regarding filebeat, I understood that I can put a "list" of ES nodes in…

---

## [Filebeat harvester cannot collect logs across files](https://discuss.elastic.co/t/filebeat-harvester-cannot-collect-logs-across-files/234888)

<div class="topic-metadata">

**Author:** [@suoititcif](https://discuss.elastic.co/u/suoititcif)\
**Replies:** 0\
**Last updated:** [May 29, 2020, 9:13am UTC](https://discuss.elastic.co/t/filebeat-harvester-cannot-collect-logs-across-files/234888 "2020-05-29T09:13:13Z")

</div>

docker json log. if a message length exceeds 16K, it will be split if rolling the logs file, one log will be stored in two files steps to reproduce: docker log driver setting max-size 200k, then generate over 200k siz…

---

## [Okta Module Crashing Constantly](https://discuss.elastic.co/t/okta-module-crashing-constantly/233351)

<div class="topic-metadata">

**Author:** [@sean\_wills](https://discuss.elastic.co/u/sean_wills)\
**Replies:** 2\
**Last updated:** [May 29, 2020, 7:12am UTC](https://discuss.elastic.co/t/okta-module-crashing-constantly/233351 "2020-05-29T07:12:04Z")

</div>

Hello, I'm using Elastic 7.7 and wanted to try out the newly-released Okta module. I can get it running for about a minute at a time, during which I can see that it's sending logs to Elasticsearch as expected, but it al…

---

## [Beats 7.7.0 wont run on some of our Windows clients](https://discuss.elastic.co/t/beats-7-7-0-wont-run-on-some-of-our-windows-clients/234319)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 12\
**Last updated:** [May 29, 2020, 7:04am UTC](https://discuss.elastic.co/t/beats-7-7-0-wont-run-on-some-of-our-windows-clients/234319 "2020-05-29T07:04:24Z")

</div>

trying to update our beats v.7.6.2 to 7.7.0, but for some reasons it seems that ~25-30% of them fails to launch the service after installing. v.7.6.2 was running just fine. Debug log from an launch attempt of AuditBeat …

---

## [Filebeat AWS module not parsing all log files](https://discuss.elastic.co/t/filebeat-aws-module-not-parsing-all-log-files/233976)

<div class="topic-metadata">

**Author:** [@bivaswap](https://discuss.elastic.co/u/bivaswap)\
**Replies:** 1\
**Last updated:** [May 29, 2020, 7:00am UTC](https://discuss.elastic.co/t/filebeat-aws-module-not-parsing-all-log-files/233976 "2020-05-29T07:00:42Z")

</div>

Hello, I am trying to parse AWS vpcflowlogs. After configuring AWS module with vpcflow fileset, logs started flowing. With my current traffic condition, AWS generating around 6 million lines of log per 6 hours. Each …

---

## [Filebeat netflow module application-table](https://discuss.elastic.co/t/filebeat-netflow-module-application-table/234862)

<div class="topic-metadata">

**Author:** [@adilias3](https://discuss.elastic.co/u/adilias3)\
**Replies:** 0\
**Last updated:** [May 29, 2020, 5:51am UTC](https://discuss.elastic.co/t/filebeat-netflow-module-application-table/234862 "2020-05-29T05:51:09Z")

</div>

Hi All, I'm sending flexible netflow with nbar application recognition from a cisco ios router to filebeat netflow module, which stores direct to elasticsearch (not via logstash) The netflow data arrives something like…

---

## [Does windows filebeat work with rest of elastic stack on linux](https://discuss.elastic.co/t/does-windows-filebeat-work-with-rest-of-elastic-stack-on-linux/234728)

<div class="topic-metadata">

**Author:** [@kunal16](https://discuss.elastic.co/u/kunal16)\
**Replies:** 2\
**Last updated:** [May 29, 2020, 2:16am UTC](https://discuss.elastic.co/t/does-windows-filebeat-work-with-rest-of-elastic-stack-on-linux/234728 "2020-05-29T02:16:14Z")

</div>

Hi I have installed filebeat (5.2.2) in my windows server and sending logs to logstash (5,.2.2.) which is installed on linux server. I am unable to view logs in the Kibana dashboard. Cant see any error either in logsta…

---

## [Winlogbeat filter not working](https://discuss.elastic.co/t/winlogbeat-filter-not-working/234670)

<div class="topic-metadata">

**Author:** [@Krishna\_MS](https://discuss.elastic.co/u/Krishna_MS)\
**Replies:** 2\
**Last updated:** [May 29, 2020, 2:11am UTC](https://discuss.elastic.co/t/winlogbeat-filter-not-working/234670 "2020-05-29T02:11:36Z")

</div>

Hi, I have installed Winlogbeat 7.6.2 and configured the following filter. winlogbeat.event\_logs: name: Application event\_id: 1000,1002,1001 ignore\_older: 72h level: critical, error, warning name: System even…

---

## [Metricbeat HTTP module - custom request and fetch headers only](https://discuss.elastic.co/t/metricbeat-http-module-custom-request-and-fetch-headers-only/233912)

<div class="topic-metadata">

**Author:** [@adilld](https://discuss.elastic.co/u/adilld)\
**Replies:** 1\
**Last updated:** [May 29, 2020, 12:34am UTC](https://discuss.elastic.co/t/metricbeat-http-module-custom-request-and-fetch-headers-only/233912 "2020-05-29T00:34:01Z")

</div>

Hello, i'm using metricbeat / elasticsearch / kibana. My goal is to know if the server is UP : i'm planning to do a request (HEAD request will be perfect) then process the headers (and filtering them maybe in logstash?…

---

## [Error with Cisco module for filebeat](https://discuss.elastic.co/t/error-with-cisco-module-for-filebeat/233920)

<div class="topic-metadata">

**Author:** [@Nazarenko](https://discuss.elastic.co/u/Nazarenko)\
**Replies:** 1\
**Last updated:** [May 29, 2020, 12:12am UTC](https://discuss.elastic.co/t/error-with-cisco-module-for-filebeat/233920 "2020-05-29T00:12:38Z")

</div>

Hello everyone, i have problem with module cisco for filebeat. I get message from cisco devices, but in kibana i see this message: error.message GoError: could not find delimiter: : in remaining: User 'user1' authenti…

---

## [Metricbeat - Add processor config through "central management"](https://discuss.elastic.co/t/metricbeat-add-processor-config-through-central-management/188850)

<div class="topic-metadata">

**Author:** [@nitzan.karni](https://discuss.elastic.co/u/nitzan.karni)\
**Replies:** 1\
**Last updated:** [May 28, 2020, 11:55pm UTC](https://discuss.elastic.co/t/metricbeat-add-processor-config-through-central-management/188850 "2020-05-28T23:55:18Z")

</div>

Hi, I want to add to my beats configuration processor section for example: processors: - dns: type: reverse fields: source.ip: source.hostname destination.ip: destination.hostname the main problem…

---

## [Elastic Stack Rest API for Loggin](https://discuss.elastic.co/t/elastic-stack-rest-api-for-loggin/234773)

<div class="topic-metadata">

**Author:** [@svvss\_svvss](https://discuss.elastic.co/u/svvss_svvss)\
**Replies:** 1\
**Last updated:** [May 28, 2020, 11:43pm UTC](https://discuss.elastic.co/t/elastic-stack-rest-api-for-loggin/234773 "2020-05-28T23:43:47Z")

</div>

Hi, Our requirement is to log data from different applications like one php application and another is .net application. in order to use it we started exploring beats. But we need to install beats in servers if we use b…

---

## [Filebeat and AWS Module unable to get CloudTrail logs](https://discuss.elastic.co/t/filebeat-and-aws-module-unable-to-get-cloudtrail-logs/230670)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 1\
**Last updated:** [May 28, 2020, 11:05pm UTC](https://discuss.elastic.co/t/filebeat-and-aws-module-unable-to-get-cloudtrail-logs/230670 "2020-05-28T23:05:45Z")

</div>

Hi I am having troubles getting the Filebeat AWS module to work with CloudTrail logs. I believe I have followed everything correctly as per the documentation but can't seem to get it working. All components are runnin…

---

## [Log lines are clumped even after correct grok and multine pattern added](https://discuss.elastic.co/t/log-lines-are-clumped-even-after-correct-grok-and-multine-pattern-added/234452)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 3\
**Last updated:** [May 28, 2020, 8:01pm UTC](https://discuss.elastic.co/t/log-lines-are-clumped-even-after-correct-grok-and-multine-pattern-added/234452 "2020-05-28T20:01:35Z")

</div>

I have tested both my grok pattern and multiline pattern for this log file but in Kibana, some log files are getting combined and not able to separate. Looks like this May 26th should be considered as start of log li…

---

## [Winlogbeat 7.7.0 Keystore Broken?](https://discuss.elastic.co/t/winlogbeat-7-7-0-keystore-broken/233829)

<div class="topic-metadata">

**Author:** [@Coinology](https://discuss.elastic.co/u/Coinology)\
**Replies:** 2\
**Last updated:** [May 28, 2020, 4:44pm UTC](https://discuss.elastic.co/t/winlogbeat-7-7-0-keystore-broken/233829 "2020-05-28T16:44:16Z")

</div>

Adding keys to the keystore in Winlogbeat 7.7.0 seems to be broken. The prompt doesn't respond to any input. I've tested this on three separate machines. To reproduce: Download fresh copy of Winlogbeat 7.7.0 Execute w…

---

## [Is it possible to adding fields to beats monitoring data?](https://discuss.elastic.co/t/is-it-possible-to-adding-fields-to-beats-monitoring-data/234779)

<div class="topic-metadata">

**Author:** [@Bingu\_Shim](https://discuss.elastic.co/u/Bingu_Shim)\
**Replies:** 0\
**Last updated:** [May 28, 2020, 4:29pm UTC](https://discuss.elastic.co/t/is-it-possible-to-adding-fields-to-beats-monitoring-data/234779 "2020-05-28T16:29:31Z")

</div>

Hello Currently I'm operating about 1,000 beats, and It will grow soon. So, I'm trying to make few Dashboards for managing and monitoring beats status. I found these setting, and I was able to gathering the beats stat…

---

## [Fails Filebeat Input format data](https://discuss.elastic.co/t/fails-filebeat-input-format-data/234741)

<div class="topic-metadata">

**Author:** [@zero.lim](https://discuss.elastic.co/u/zero.lim)\
**Replies:** 2\
**Last updated:** [May 28, 2020, 2:07pm UTC](https://discuss.elastic.co/t/fails-filebeat-input-format-data/234741 "2020-05-28T14:07:20Z")

</div>

Hi Everyone, I used Filebeat to input the data of Aws Elb to Elk, but the input format was not what I wanted. He saved all the data to message field. . . Is there any change to disassemble the information in the messag…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=242)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=244)
