# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=244

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 245

---

## [7.7: broken filebeat pipeline for Nginx access logs](https://discuss.elastic.co/t/7-7-broken-filebeat-pipeline-for-nginx-access-logs/232519)

<div class="topic-metadata">

**Author:** [@Slavik\_Fursov](https://discuss.elastic.co/u/Slavik_Fursov)\
**Replies:** 3\
**Last updated:** [May 28, 2020, 1:45pm UTC](https://discuss.elastic.co/t/7-7-broken-filebeat-pipeline-for-nginx-access-logs/232519 "2020-05-28T13:45:01Z")

</div>

I just upgraded my stack to 7.7 Now, I see that I have 2 pipelines for nginx access logs: filebeat-7.7.0-nginx-access-default description: "Pipeline for parsing Nginx access logs. Requires the geoip and user\_agent p…

---

## [Filtering nested xml tag using Filebeat](https://discuss.elastic.co/t/filtering-nested-xml-tag-using-filebeat/234733)

<div class="topic-metadata">

**Author:** [@joshua.stanley](https://discuss.elastic.co/u/joshua.stanley)\
**Replies:** 0\
**Last updated:** [May 28, 2020, 11:32am UTC](https://discuss.elastic.co/t/filtering-nested-xml-tag-using-filebeat/234733 "2020-05-28T11:32:58Z")

</div>

Hello, I am very new to ELK , need your guidance in my below usecase development. We have lot of XML files generated from source server(around 55GB per day )..but, from each file, we need only very few lines, as shown …

---

## [Filebeat unable to access logs under “/var/lib/docker/containers” path due to "Permission Denied" issue](https://discuss.elastic.co/t/filebeat-unable-to-access-logs-under-var-lib-docker-containers-path-due-to-permission-denied-issue/234696)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 0\
**Last updated:** [May 28, 2020, 9:04am UTC](https://discuss.elastic.co/t/filebeat-unable-to-access-logs-under-var-lib-docker-containers-path-due-to-permission-denied-issue/234696 "2020-05-28T09:04:45Z")

</div>

I am trying to deploy ELK stack with Filebeat in Openshift environment. Filebeat is trying to read the log files under "/var/lib/docker/containers" path of a pod but it failed with "Permission Denied" error. I am using…

---

## [Failed to connect to backoff(async(tcp://IP:5044)): dial tcp IP:5044: i/o timeout](https://discuss.elastic.co/t/failed-to-connect-to-backoff-async-tcp-ip-5044-dial-tcp-ip-i-o-timeout/234686)

<div class="topic-metadata">

**Author:** [@Fent](https://discuss.elastic.co/u/Fent)\
**Replies:** 0\
**Last updated:** [May 28, 2020, 7:59am UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-async-tcp-ip-5044-dial-tcp-ip-i-o-timeout/234686 "2020-05-28T07:59:46Z")

</div>

HI, I run filebeat on machineA to send log data to Logstash Server, but show " Failed to connect to backoff(async(tcp://IP:5044)): dial tcp IP:5044: i/o timeout" machine A "ping" Logstash Server ok, the same config …

---

## [Filebeat connect to Elasticsearch failed](https://discuss.elastic.co/t/filebeat-connect-to-elasticsearch-failed/234251)

<div class="topic-metadata">

**Author:** [@stanwang](https://discuss.elastic.co/u/stanwang)\
**Replies:** 3\
**Last updated:** [May 28, 2020, 6:01am UTC](https://discuss.elastic.co/t/filebeat-connect-to-elasticsearch-failed/234251 "2020-05-28T06:01:51Z")

</div>

Hi, I have a Win10 for client and ELK ubuntu for server. I have installed "Winlogbeat" and "Filebeat" on the client simultaneously. And, I have make sure the connect between "Winlogbeat" and "Elasticsearch" is correct …

---

## [Create Field Winlogbeat](https://discuss.elastic.co/t/create-field-winlogbeat/233563)

<div class="topic-metadata">

**Author:** [@JeanN](https://discuss.elastic.co/u/JeanN)\
**Replies:** 4\
**Last updated:** [May 28, 2020, 5:55am UTC](https://discuss.elastic.co/t/create-field-winlogbeat/233563 "2020-05-28T05:55:34Z")

</div>

Hello, I want to create a Field with the value that i want like in Logstash. For example in my Logstash configuration i set in the fingerprint module: add\_field =\> {"key" =\> "123" } On the log (In Kibana), I saw this…

---

## [Monitor Windows Logons win Winlogbeat](https://discuss.elastic.co/t/monitor-windows-logons-win-winlogbeat/234634)

<div class="topic-metadata">

**Author:** [@Ayesha](https://discuss.elastic.co/u/Ayesha)\
**Replies:** 1\
**Last updated:** [May 28, 2020, 5:20am UTC](https://discuss.elastic.co/t/monitor-windows-logons-win-winlogbeat/234634 "2020-05-28T05:20:54Z")

</div>

Hi, I am shipping logs from my DC to Logstash and then to Elasticsearch. I am trying to visualize domain user logins to all domain joined servers. But It is not showing me the name of server on which user logs in. It a…

---

## [Filebeat module vs filebeat output plugin?](https://discuss.elastic.co/t/filebeat-module-vs-filebeat-output-plugin/234143)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 3\
**Last updated:** [May 28, 2020, 12:24am UTC](https://discuss.elastic.co/t/filebeat-module-vs-filebeat-output-plugin/234143 "2020-05-28T00:24:00Z")

</div>

Hi, what is the difference between so called filebeat module and output plugin like: output.elasticsearch:

---

## [How to add geo information in Heartbeat?](https://discuss.elastic.co/t/how-to-add-geo-information-in-heartbeat/234386)

<div class="topic-metadata">

**Author:** [@ozonshak](https://discuss.elastic.co/u/ozonshak)\
**Replies:** 5\
**Last updated:** [May 27, 2020, 8:36pm UTC](https://discuss.elastic.co/t/how-to-add-geo-information-in-heartbeat/234386 "2020-05-27T20:36:56Z")

</div>

Hello. I'm attempting to set up Heartbeat for the first time. I believe I have this setup and I'm doing some basic pings against some web sites. I've noticed that when you click into a heartbeat, it says "geo informat…

---

## [Heartbeat data roll-up](https://discuss.elastic.co/t/heartbeat-data-roll-up/228254)

<div class="topic-metadata">

**Author:** [@sderungs](https://discuss.elastic.co/u/sderungs)\
**Replies:** 1\
**Last updated:** [May 27, 2020, 4:16pm UTC](https://discuss.elastic.co/t/heartbeat-data-roll-up/228254 "2020-05-27T16:16:42Z")

</div>

Hi I was wondering if there are any good practices around roll-up for data in Elasticsearch coming from Heartbeat or if anyone has experience with it. Some background: We're collecting uptime data from multiple system…

---

## [Metricbeat as unprivilleged user with init.d](https://discuss.elastic.co/t/metricbeat-as-unprivilleged-user-with-init-d/234524)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [May 27, 2020, 2:32pm UTC](https://discuss.elastic.co/t/metricbeat-as-unprivilleged-user-with-init-d/234524 "2020-05-27T14:32:02Z")

</div>

Hi, In the past I always installed metricbeat and filebeat with centos 7+ which uses systemd. There I managed to run both beats as unprivileged user. I am much familar with init.d, but I need to install the beats on ce…

---

## [Filebeat sending logs issue](https://discuss.elastic.co/t/filebeat-sending-logs-issue/234507)

<div class="topic-metadata">

**Author:** [@PierreR](https://discuss.elastic.co/u/PierreR)\
**Replies:** 2\
**Last updated:** [May 27, 2020, 12:04pm UTC](https://discuss.elastic.co/t/filebeat-sending-logs-issue/234507 "2020-05-27T12:04:39Z")

</div>

Hello everyone, I have a problem with the Filebeat inputs. I installed and configured Filebeat on a CentOS 7 with Prelude SIEM installed. I am using Filebeat to transmit the logs from Prelude to ELK. For the moment the …

---

## [Remove Ec2IAM Role and change use Aws configure credentials ,filebeat will not work!](https://discuss.elastic.co/t/remove-ec2iam-role-and-change-use-aws-configure-credentials-filebeat-will-not-work/234522)

<div class="topic-metadata">

**Author:** [@zero.lim](https://discuss.elastic.co/u/zero.lim)\
**Replies:** 0\
**Last updated:** [May 27, 2020, 10:32am UTC](https://discuss.elastic.co/t/remove-ec2iam-role-and-change-use-aws-configure-credentials-filebeat-will-not-work/234522 "2020-05-27T10:32:37Z")

</div>

Hi Everyone , When I remove the IAM Role on EC2 and use Aws Configure, Filebeat will not work. error ~/.aws/credentials \[default\] aws\_access\_key\_id = aaa aws\_secret\_access\_key = aaa \[aaa\] aws\_access\_key\_id = aa…

---

## [Disable automatic creation of daily indexes](https://discuss.elastic.co/t/disable-automatic-creation-of-daily-indexes/234293)

<div class="topic-metadata">

**Author:** [@michielM](https://discuss.elastic.co/u/michielM)\
**Replies:** 4\
**Last updated:** [May 27, 2020, 10:11am UTC](https://discuss.elastic.co/t/disable-automatic-creation-of-daily-indexes/234293 "2020-05-27T10:11:06Z")

</div>

Hey all, I recently created custom index names because I needed spaces for customers, and each customer needed an index to link to the space. So that's what I did. I have these indexes now. auditbeat-customer1-01/01…

---

## [Forward custom nginx header](https://discuss.elastic.co/t/forward-custom-nginx-header/234485)

<div class="topic-metadata">

**Author:** [@maiera](https://discuss.elastic.co/u/maiera)\
**Replies:** 0\
**Last updated:** [May 27, 2020, 8:13am UTC](https://discuss.elastic.co/t/forward-custom-nginx-header/234485 "2020-05-27T08:13:01Z")

</div>

Hey there, I am using the nginx module in filebeat to get the access and error logs into elasticsearch. I've added a custom header (X-Request\_Id) to my log output and would like also have that recognized. I've seen the…

---

## [Live reloading filebeat is not working](https://discuss.elastic.co/t/live-reloading-filebeat-is-not-working/232485)

<div class="topic-metadata">

**Author:** [@anjilinga](https://discuss.elastic.co/u/anjilinga)\
**Replies:** 1\
**Last updated:** [May 27, 2020, 7:48am UTC](https://discuss.elastic.co/t/live-reloading-filebeat-is-not-working/232485 "2020-05-27T07:48:45Z")

</div>

Hi i have given the below file beat configuration for live reloading filebeat.config.inputs: enabled: true path: config/\*.yml reload.enabled: true reload.period: 10s under config folder i have created test.yml fi…

---

## [Kubernetes add\_kubernetes\_metadata not able to send](https://discuss.elastic.co/t/kubernetes-add-kubernetes-metadata-not-able-to-send/232842)

<div class="topic-metadata">

**Author:** [@vasu\_devan](https://discuss.elastic.co/u/vasu_devan)\
**Replies:** 4\
**Last updated:** [May 27, 2020, 6:25am UTC](https://discuss.elastic.co/t/kubernetes-add-kubernetes-metadata-not-able-to-send/232842 "2020-05-27T06:25:19Z")

</div>

Hi Team, I am planning to send custom path logs(example: /var/log/nginx/\*logs) with cloud and kubernetes metadata. sample App deployed: kind: Deployment metadata: name: nginx-deployment-test namespace: vasu labe…

---

## [How do you run multiple functionbeats?](https://discuss.elastic.co/t/how-do-you-run-multiple-functionbeats/234458)

<div class="topic-metadata">

**Author:** [@syost](https://discuss.elastic.co/u/syost)\
**Replies:** 0\
**Last updated:** [May 27, 2020, 5:23am UTC](https://discuss.elastic.co/t/how-do-you-run-multiple-functionbeats/234458 "2020-05-27T05:23:25Z")

</div>

\> Environment: Hosting our own ELK on a EC2 \> OS: RedHat EC2 \> License: As of now just a trial BACKGROUND: Our team will want to run multiple functionbeats for cloudwatch logs mainly because will have different struc…

---

## [Filebeat processing file the rsynced file always from the beginning](https://discuss.elastic.co/t/filebeat-processing-file-the-rsynced-file-always-from-the-beginning/233758)

<div class="topic-metadata">

**Author:** [@Manjula\_Piyumal](https://discuss.elastic.co/u/Manjula_Piyumal)\
**Replies:** 1\
**Last updated:** [May 27, 2020, 4:59am UTC](https://discuss.elastic.co/t/filebeat-processing-file-the-rsynced-file-always-from-the-beginning/233758 "2020-05-27T04:59:17Z")

</div>

Hi, I have a log file which will be rsynced from another server(source server) using a different user ID (user 1). In the current sever(destination server) I'm running filebeat agen as a different user(user 2) User 2 an…

---

## [IAM permissions required for Functionbeat](https://discuss.elastic.co/t/iam-permissions-required-for-functionbeat/234435)

<div class="topic-metadata">

**Author:** [@mudricd](https://discuss.elastic.co/u/mudricd)\
**Replies:** 0\
**Last updated:** [May 27, 2020, 12:51am UTC](https://discuss.elastic.co/t/iam-permissions-required-for-functionbeat/234435 "2020-05-27T00:51:16Z")

</div>

Hi, I followed Functionbeat reference to deploy a function that collects events from CloudWatch Logs and forwards the events to Elasticsearch. I am aware of IAM permissions required for Functionbeat deployment but I am…

---

## [How to set up name for default template](https://discuss.elastic.co/t/how-to-set-up-name-for-default-template/234361)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 0\
**Last updated:** [May 26, 2020, 2:59pm UTC](https://discuss.elastic.co/t/how-to-set-up-name-for-default-template/234361 "2020-05-26T14:59:18Z")

</div>

I have a configuration as shown below #-------------------------- Elasticsearch output ------------------------------ output.elasticsearch: # Array of hosts to connect to. hosts: \["IP:9200"\] username: "elastic" …

---

## [Filebeat input problem](https://discuss.elastic.co/t/filebeat-input-problem/232996)

<div class="topic-metadata">

**Author:** [@Rasoul\_Ahmadi](https://discuss.elastic.co/u/Rasoul_Ahmadi)\
**Replies:** 2\
**Last updated:** [May 26, 2020, 6:31pm UTC](https://discuss.elastic.co/t/filebeat-input-problem/232996 "2020-05-26T18:31:37Z")

</div>

hi I have a scenario that my servers will send all their logs to rsyslog server and I want to import them by filebeat to logstash ... i have done this but it does not show hostanmes correctly and only shows my syslogse…

---

## [Issue with filebeat multiline patterns](https://discuss.elastic.co/t/issue-with-filebeat-multiline-patterns/234321)

<div class="topic-metadata">

**Author:** [@sfenman](https://discuss.elastic.co/u/sfenman)\
**Replies:** 1\
**Last updated:** [May 26, 2020, 1:47pm UTC](https://discuss.elastic.co/t/issue-with-filebeat-multiline-patterns/234321 "2020-05-26T13:47:13Z")

</div>

Hello, I am trying to setup filebeat for some multiline application logs directly to ES. So a log entry is always starting with the word "Started" or with the word "Queued" and has different number of lines each time. My…

---

## [\[filebeat\] INTEGRATION\_TESTS with more than four ingest pipeline don't work](https://discuss.elastic.co/t/filebeat-integration-tests-with-more-than-four-ingest-pipeline-dont-work/234313)

<div class="topic-metadata">

**Author:** [@Stefan\_Sabolowitsch](https://discuss.elastic.co/u/Stefan_Sabolowitsch)\
**Replies:** 0\
**Last updated:** [May 26, 2020, 11:16am UTC](https://discuss.elastic.co/t/filebeat-integration-tests-with-more-than-four-ingest-pipeline-dont-work/234313 "2020-05-26T11:16:57Z")

</div>

Hi there, i am creating a new filebeat module, INTEGRATION\_TESTS worked without problems until the fourth ingest pipeline. From the fifth ingest pipeline, the INTEGRATION\_TESTS gets stuck in an endless loop, only a CTRL…

---

## [Change Index name with enabled ILM](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 8\
**Last updated:** [May 26, 2020, 10:28am UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930 "2020-05-26T10:28:17Z")

</div>

Hi guys, from this documentation: Configure the Elasticsearch output | Filebeat Reference \[7.4\] | Elastic i learned: The index setting is ignored when index lifecycle management is enabled. If you’re sending events …

---

## [Winlogbeat: Error loading config file:Type "String" is not supported on top level of config](https://discuss.elastic.co/t/winlogbeat-error-loading-config-file-type-string-is-not-supported-on-top-level-of-config/231860)

<div class="topic-metadata">

**Author:** [@Vi\_Hung\_Tr\_n](https://discuss.elastic.co/u/Vi_Hung_Tr_n)\
**Replies:** 4\
**Last updated:** [May 26, 2020, 8:27am UTC](https://discuss.elastic.co/t/winlogbeat-error-loading-config-file-type-string-is-not-supported-on-top-level-of-config/231860 "2020-05-26T08:27:31Z")

</div>

Hi Guys, i had a problems while config the winlogbeat.yml file in Winlogbeat folder to make it send log to Logstash but it came back with the above errors, so i hop someone that have the similar problem to me can sol…

---

## [How to configure Filebeat to consume logs in JSON format that are already in ECS format](https://discuss.elastic.co/t/how-to-configure-filebeat-to-consume-logs-in-json-format-that-are-already-in-ecs-format/234269)

<div class="topic-metadata">

**Author:** [@xprzemekw](https://discuss.elastic.co/u/xprzemekw)\
**Replies:** 0\
**Last updated:** [May 26, 2020, 8:07am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-consume-logs-in-json-format-that-are-already-in-ecs-format/234269 "2020-05-26T08:07:55Z")

</div>

Hi, I am new to Elastic and struggling with configuring Filebeat to read logs in JSON that are already in the Elastic Common Schema format. I was inspired by the https://github.com/elastic/ecs-dotnet/tree/master/src/El…

---

## [Can filebeat read the log file that under like ’yyyy/mm/dd‘ dynamic folder？](https://discuss.elastic.co/t/can-filebeat-read-the-log-file-that-under-like-yyyy-mm-dd-dynamic-folder/234232)

<div class="topic-metadata">

**Author:** [@strong-ge](https://discuss.elastic.co/u/strong-ge)\
**Replies:** 4\
**Last updated:** [May 26, 2020, 5:56am UTC](https://discuss.elastic.co/t/can-filebeat-read-the-log-file-that-under-like-yyyy-mm-dd-dynamic-folder/234232 "2020-05-26T05:56:14Z")

</div>

can filebeat read the log file that under like ’yyyy/mm/dd‘ dynamic folder？

---

## [Filebeat inptu container rotation json parser error](https://discuss.elastic.co/t/filebeat-inptu-container-rotation-json-parser-error/233713)

<div class="topic-metadata">

**Author:** [@suoititcif](https://discuss.elastic.co/u/suoititcif)\
**Replies:** 5\
**Last updated:** [May 26, 2020, 2:42am UTC](https://discuss.elastic.co/t/filebeat-inptu-container-rotation-json-parser-error/233713 "2020-05-26T02:42:26Z")

</div>

docker json-file 16K stream buffer split When log exceeded 16K and log rotation, json parser error --- apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: kube-system labels: k8s-app: …

---

## [Issues with Index Pattern Search - Kibana/Filebeat Pre Loaded Dashboards](https://discuss.elastic.co/t/issues-with-index-pattern-search-kibana-filebeat-pre-loaded-dashboards/234211)

<div class="topic-metadata">

**Author:** [@Nastriboy](https://discuss.elastic.co/u/Nastriboy)\
**Replies:** 1\
**Last updated:** [May 26, 2020, 12:19am UTC](https://discuss.elastic.co/t/issues-with-index-pattern-search-kibana-filebeat-pre-loaded-dashboards/234211 "2020-05-26T00:19:21Z")

</div>

Hello guys, Good afternoon. This is the first time I worked with the ELK platform in terms of analysing input data from different sources and generate different vizualization patterns. I've been working with the follo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=243)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=245)
