# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=245

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 246

---

## [How to parse @timestamp from Cloudfront logs?](https://discuss.elastic.co/t/how-to-parse-timestamp-from-cloudfront-logs/233620)

<div class="topic-metadata">

**Author:** [@nhnicwaller](https://discuss.elastic.co/u/nhnicwaller)\
**Replies:** 1\
**Last updated:** [May 25, 2020, 6:37pm UTC](https://discuss.elastic.co/t/how-to-parse-timestamp-from-cloudfront-logs/233620 "2020-05-25T18:37:44Z")

</div>

I'm trying to use Filebeat to ship my logs from AWS CloudFront, but I can't figure out how to get the @timestamp field populated correctly. The log format is TSV (tab separated values) and the first two fields are date a…

---

## [Filebeat module custom policy management](https://discuss.elastic.co/t/filebeat-module-custom-policy-management/234183)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 0\
**Last updated:** [May 25, 2020, 4:51pm UTC](https://discuss.elastic.co/t/filebeat-module-custom-policy-management/234183 "2020-05-25T16:51:15Z")

</div>

I want to apply custom ilm\_policy for every index that I create with filebeat. I tried below approach \`#-------------------------- Elasticsearch output ------------------------------ output.elasticsearch: # Array of …

---

## [Filebeat k8s autodiscover and short-living pods](https://discuss.elastic.co/t/filebeat-k8s-autodiscover-and-short-living-pods/234161)

<div class="topic-metadata">

**Author:** [@Opium\_ForPeople](https://discuss.elastic.co/u/Opium_ForPeople)\
**Replies:** 0\
**Last updated:** [May 25, 2020, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-k8s-autodiscover-and-short-living-pods/234161 "2020-05-25T14:04:09Z")

</div>

Hi! I'm trying to get logs from short-living pods such as jobs and cronJobs. For example I have cronJob that starts every minute and produces three lines of output in json format, but the fact is that not all the runs …

---

## [Override multiline configuration in helm is not working](https://discuss.elastic.co/t/override-multiline-configuration-in-helm-is-not-working/232935)

<div class="topic-metadata">

**Author:** [@eyesmoker](https://discuss.elastic.co/u/eyesmoker)\
**Replies:** 3\
**Last updated:** [May 25, 2020, 1:55pm UTC](https://discuss.elastic.co/t/override-multiline-configuration-in-helm-is-not-working/232935 "2020-05-25T13:55:35Z")

</div>

Hello, I am using helm --set command line parameter to override filebeatConfig at run time https://github.com/elastic/helm-charts/blob/master/filebeat/values.yaml Errors I get: Error: template: filebeat/templates/daem…

---

## [Error when running Filebeat in docker: /usr/local/bin/docker-entrypoint: line 8: exec: filebeat: not found](https://discuss.elastic.co/t/error-when-running-filebeat-in-docker-usr-local-bin-docker-entrypoint-line-8-exec-filebeat-not-found/233645)

<div class="topic-metadata">

**Author:** [@david4](https://discuss.elastic.co/u/david4)\
**Replies:** 4\
**Last updated:** [May 25, 2020, 12:55pm UTC](https://discuss.elastic.co/t/error-when-running-filebeat-in-docker-usr-local-bin-docker-entrypoint-line-8-exec-filebeat-not-found/233645 "2020-05-25T12:55:30Z")

</div>

I kept getting this error /usr/local/bin/docker-entrypoint: line 8: exec: filebeat: not found when running export HOST\_UID=1001; export HOST\_GID=1001; docker-compose up Here is my docker-compose.yml file: version: '3.…

---

## [Log insertion with Filebeat](https://discuss.elastic.co/t/log-insertion-with-filebeat/232653)

<div class="topic-metadata">

**Author:** [@JulienN](https://discuss.elastic.co/u/JulienN)\
**Replies:** 4\
**Last updated:** [May 25, 2020, 9:22am UTC](https://discuss.elastic.co/t/log-insertion-with-filebeat/232653 "2020-05-25T09:22:11Z")

</div>

Hi , I use Filebeat to recover my scheduler's log . It's functional but the elasticsearch insertion is not optimal ... it inserts one hit by line on my log. Ideally , i would like to insert the entire log i one hit.. …

---

## [Filebeat Hints-based Autodiscovery: how to use copy\_fields or rename processor in Kubernetes annotation?](https://discuss.elastic.co/t/filebeat-hints-based-autodiscovery-how-to-use-copy-fields-or-rename-processor-in-kubernetes-annotation/233476)

<div class="topic-metadata">

**Author:** [@Jan\_Malcomess](https://discuss.elastic.co/u/Jan_Malcomess)\
**Replies:** 8\
**Last updated:** [May 25, 2020, 7:45am UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscovery-how-to-use-copy-fields-or-rename-processor-in-kubernetes-annotation/233476 "2020-05-25T07:45:23Z")

</div>

Hi there, im trying to use hints-based autodiscovery in our Openshift/Kubernetes environment to dissect the logs of our Springboot-based microservices (Filbeat 7.7.0). So far, dissecting the message and parsing the time…

---

## [Filebeat Module: Fortinet 7.8](https://discuss.elastic.co/t/filebeat-module-fortinet-7-8/233803)

<div class="topic-metadata">

**Author:** [@jared](https://discuss.elastic.co/u/jared)\
**Replies:** 1\
**Last updated:** [May 25, 2020, 7:13am UTC](https://discuss.elastic.co/t/filebeat-module-fortinet-7-8/233803 "2020-05-25T07:13:06Z")

</div>

Hello, We are seeing multiple iterations of the following error type in the Filebeat Module for Fortinet v 7.8. When sentbyte=1569241255 + sentpkt=2797855 and rcvdpkt=2166884 + rcvddelta=6625355 are greater than lo…

---

## [Heartbeat.7.5.2 works but no details under 'monitor status'](https://discuss.elastic.co/t/heartbeat-7-5-2-works-but-no-details-under-monitor-status/233456)

<div class="topic-metadata">

**Author:** [@sivaaws](https://discuss.elastic.co/u/sivaaws)\
**Replies:** 9\
**Last updated:** [May 25, 2020, 6:10am UTC](https://discuss.elastic.co/t/heartbeat-7-5-2-works-but-no-details-under-monitor-status/233456 "2020-05-25T06:10:07Z")

</div>

Hello. I'm trying to setup heartbeat.7.5.2 and able to do so; could find the HTTP/ TCP end-points status on Kibana (under 'Uptime'). However, it doesnt show up the name/status/url; despite i've explicitly added 'name & …

---

## [Two filebeat servers setting output to same elasticsearch](https://discuss.elastic.co/t/two-filebeat-servers-setting-output-to-same-elasticsearch/232550)

<div class="topic-metadata">

**Author:** [@sushma\_bm](https://discuss.elastic.co/u/sushma_bm)\
**Replies:** 5\
**Last updated:** [May 25, 2020, 12:36am UTC](https://discuss.elastic.co/t/two-filebeat-servers-setting-output-to-same-elasticsearch/232550 "2020-05-25T00:36:22Z")

</div>

My question is, I have filebeat configured in 2 ec2 instance. In one server I have few tools along with filebeat, in another server also few tools, filebeat and elasticsearch is configured. Can I set output of both fileb…

---

## [Filebeat can't receive log from pfSense](https://discuss.elastic.co/t/filebeat-cant-receive-log-from-pfsense/233859)

<div class="topic-metadata">

**Author:** [@Minh\_Ti\_n\_Tr\_n](https://discuss.elastic.co/u/Minh_Ti_n_Tr_n)\
**Replies:** 6\
**Last updated:** [May 24, 2020, 11:43am UTC](https://discuss.elastic.co/t/filebeat-cant-receive-log-from-pfsense/233859 "2020-05-24T11:43:35Z")

</div>

Hi all, I'm trying to make filebeat receive pfsense syslog. my filebeat.yml input part: filebeat.inputs: - type: syslog protocol.udp: host: "0.0.0.0:9560" fields\_under\_root: true fields: input.type: pfsen…

---

## [Metricbeat HTTP module - request and process headers only](https://discuss.elastic.co/t/metricbeat-http-module-request-and-process-headers-only/233942)

<div class="topic-metadata">

**Author:** [@adilld](https://discuss.elastic.co/u/adilld)\
**Replies:** 1\
**Last updated:** [May 24, 2020, 2:02am UTC](https://discuss.elastic.co/t/metricbeat-http-module-request-and-process-headers-only/233942 "2020-05-24T02:02:51Z")

</div>

Hello, i'm using metricbeat / elasticsearch / kibana. My goal is to know if the server is UP : i'm planning to do a request (HEAD request will be perfect) then process the headers (and filtering them maybe in logstash?…

---

## [Error when running Filebeat to send log to Elasticsearch behind a reverse proxy](https://discuss.elastic.co/t/error-when-running-filebeat-to-send-log-to-elasticsearch-behind-a-reverse-proxy/234017)

<div class="topic-metadata">

**Author:** [@aparasxidis](https://discuss.elastic.co/u/aparasxidis)\
**Replies:** 0\
**Last updated:** [May 23, 2020, 8:27pm UTC](https://discuss.elastic.co/t/error-when-running-filebeat-to-send-log-to-elasticsearch-behind-a-reverse-proxy/234017 "2020-05-23T20:27:00Z")

</div>

Hi, I'm running filebeat in docker, when I check the container logs I get: pipeline/output.go:105 Connection to backoff(elasticsearch(http://xxxxx.xxxxx.com:80/elastic)) established Failed to perform any bulk index op…

---

## [Details about "Non-zero metrics in the last 30s" Filebeat Reported](https://discuss.elastic.co/t/details-about-non-zero-metrics-in-the-last-30s-filebeat-reported/233980)

<div class="topic-metadata">

**Author:** [@Madan](https://discuss.elastic.co/u/Madan)\
**Replies:** 0\
**Last updated:** [May 23, 2020, 7:50am UTC](https://discuss.elastic.co/t/details-about-non-zero-metrics-in-the-last-30s-filebeat-reported/233980 "2020-05-23T07:50:44Z")

</div>

Can someone explain me what is each metric about? {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":1390,"time":{"ms":22}},"total":{"ticks":2780,"time":{"ms":42},"value":2780},"user":{"ticks":1390,"time":{"ms…

---

## [How to build custom beat for windows OS using Linux machine](https://discuss.elastic.co/t/how-to-build-custom-beat-for-windows-os-using-linux-machine/231863)

<div class="topic-metadata">

**Author:** [@visasimbu](https://discuss.elastic.co/u/visasimbu)\
**Replies:** 2\
**Last updated:** [May 23, 2020, 5:07am UTC](https://discuss.elastic.co/t/how-to-build-custom-beat-for-windows-os-using-linux-machine/231863 "2020-05-23T05:07:43Z")

</div>

I am able to create custom beat as mentioned in documentation with my custom logic. I have tested same in linux RHEL 7 machine. I have used RHEL7 for build and test. Now I need to create beat exe file for windows machin…

---

## [No data from Filebeat 7.7 - Using Palo Alto module](https://discuss.elastic.co/t/no-data-from-filebeat-7-7-using-palo-alto-module/233634)

<div class="topic-metadata">

**Author:** [@hueyg](https://discuss.elastic.co/u/hueyg)\
**Replies:** 1\
**Last updated:** [May 22, 2020, 6:10pm UTC](https://discuss.elastic.co/t/no-data-from-filebeat-7-7-using-palo-alto-module/233634 "2020-05-22T18:10:57Z")

</div>

Have a working already establish 7.6 cluster processing multiple beats from multiple hosts. Attempting to setup another beat to process Palo Alto file logs, but unlike the others I am using the built in PaloAlto module …

---

## [Host listed twice, one with hostname one with FQDN](https://discuss.elastic.co/t/host-listed-twice-one-with-hostname-one-with-fqdn/233140)

<div class="topic-metadata">

**Author:** [@daveywilks](https://discuss.elastic.co/u/daveywilks)\
**Replies:** 1\
**Last updated:** [May 22, 2020, 5:40pm UTC](https://discuss.elastic.co/t/host-listed-twice-one-with-hostname-one-with-fqdn/233140 "2020-05-22T17:40:29Z")

</div>

Hopefully someone can help with this one! I am just getting started with Elastic Stack (SIEM) and I'm currently using the cloud trial. I have installed Beats on two hosts. One host just has WinLogBeat and MetricBeat. …

---

## [Cant send logs via Filebeat using Reverse proxy endpoint for Elasticsearch server](https://discuss.elastic.co/t/cant-send-logs-via-filebeat-using-reverse-proxy-endpoint-for-elasticsearch-server/233922)

<div class="topic-metadata">

**Author:** [@aparasxidis](https://discuss.elastic.co/u/aparasxidis)\
**Replies:** 0\
**Last updated:** [May 22, 2020, 3:18pm UTC](https://discuss.elastic.co/t/cant-send-logs-via-filebeat-using-reverse-proxy-endpoint-for-elasticsearch-server/233922 "2020-05-22T15:18:44Z")

</div>

Hi, I'm running Filebeat on a EC2 machine as a docker container and configured to get logs from a Jenkins container, the Elasticsearch server is on another EC2 machine behind a reverse proxy (nginx), I can curl to the El…

---

## [Filebeat installation is deleted from the file system](https://discuss.elastic.co/t/filebeat-installation-is-deleted-from-the-file-system/233757)

<div class="topic-metadata">

**Author:** [@suresh123](https://discuss.elastic.co/u/suresh123)\
**Replies:** 3\
**Last updated:** [May 22, 2020, 4:39pm UTC](https://discuss.elastic.co/t/filebeat-installation-is-deleted-from-the-file-system/233757 "2020-05-22T16:39:22Z")

</div>

Hi, I have installed filebeat on client machine, after some hours, file beat installation is deleted and saved as filebeat.rmv file and modules.d/ remained. I have installed it through yum Can someone please look into…

---

## [Filebeat.yml is deleting frequently](https://discuss.elastic.co/t/filebeat-yml-is-deleting-frequently/233662)

<div class="topic-metadata">

**Author:** [@suresh123](https://discuss.elastic.co/u/suresh123)\
**Replies:** 3\
**Last updated:** [May 22, 2020, 4:37pm UTC](https://discuss.elastic.co/t/filebeat-yml-is-deleting-frequently/233662 "2020-05-22T16:37:42Z")

</div>

Filebeat.yml is deleting frequently on client(machine) file system. Can anyone please suggest and your help is appreciated.

---

## [Setup vs writer role for Filebeat](https://discuss.elastic.co/t/setup-vs-writer-role-for-filebeat/233923)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 0\
**Last updated:** [May 22, 2020, 3:22pm UTC](https://discuss.elastic.co/t/setup-vs-writer-role-for-filebeat/233923 "2020-05-22T15:22:06Z")

</div>

Hi, from the documentation I see a sort of role seperation between setting up filebeat and shipping data using filebeat: https://www.elastic.co/guide/en/beats/filebeat/master/feature-roles.html (setup role and writer ro…

---

## [Kafka output module](https://discuss.elastic.co/t/kafka-output-module/230030)

<div class="topic-metadata">

**Author:** [@suikast42](https://discuss.elastic.co/u/suikast42)\
**Replies:** 0\
**Last updated:** [April 27, 2020, 8:55pm UTC](https://discuss.elastic.co/t/kafka-output-module/230030 "2020-04-27T20:55:06Z")

</div>

I installed metricbeat on 3 machines with key partition strategy. The key is the ecs host.hostname. So far so good. The partitioning works. But there is a little problem. Every three instances chooses the same partition.…

---

## [Unable to overwrite module input](https://discuss.elastic.co/t/unable-to-overwrite-module-input/233907)

<div class="topic-metadata">

**Author:** [@hazcod](https://discuss.elastic.co/u/hazcod)\
**Replies:** 0\
**Last updated:** [May 22, 2020, 1:40pm UTC](https://discuss.elastic.co/t/unable-to-overwrite-module-input/233907 "2020-05-22T13:40:33Z")

</div>

Hi, I am trying to disable a module input and specify my own. As seen in https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/checkpoint/firewall/config/firewall.yml , if we specify 'false' for input.var …

---

## [Problems with Filebeat's auditd module](https://discuss.elastic.co/t/problems-with-filebeats-auditd-module/233520)

<div class="topic-metadata">

**Author:** [@mrlhansen](https://discuss.elastic.co/u/mrlhansen)\
**Replies:** 1\
**Last updated:** [May 22, 2020, 11:51am UTC](https://discuss.elastic.co/t/problems-with-filebeats-auditd-module/233520 "2020-05-22T11:51:40Z")

</div>

Hi, We are currently using filebeat+logstash to send our log files to Elasticsearch, and it works fine. However, we would like to send the files directly from filebeat in the future, but we are getting tons of errors li…

---

## [Unable to send newly updated events form filebeat to logstash](https://discuss.elastic.co/t/unable-to-send-newly-updated-events-form-filebeat-to-logstash/233881)

<div class="topic-metadata">

**Author:** [@Charan\_Adabala](https://discuss.elastic.co/u/Charan_Adabala)\
**Replies:** 0\
**Last updated:** [May 22, 2020, 10:22am UTC](https://discuss.elastic.co/t/unable-to-send-newly-updated-events-form-filebeat-to-logstash/233881 "2020-05-22T10:22:52Z")

</div>

\------------------------ filebeat config ----------------------------------- filebeat.inputs: - type: log # Change to true to enable this input configuration. enabled: true # Paths that should be crawled and fe…

---

## [Filebeat Misp Module Ceritifcate Problem](https://discuss.elastic.co/t/filebeat-misp-module-ceritifcate-problem/231077)

<div class="topic-metadata">

**Author:** [@Jsof](https://discuss.elastic.co/u/Jsof)\
**Replies:** 1\
**Last updated:** [May 22, 2020, 9:47am UTC](https://discuss.elastic.co/t/filebeat-misp-module-ceritifcate-problem/231077 "2020-05-22T09:47:05Z")

</div>

Hi all, I am trying to get data from MISP using filebeat but i am having trouble making filebeat work because it doesn't want to establish connection to MISP due to it being self signed. Things i have tried: In Filebe…

---

## [Why the meta in registry file is always null?](https://discuss.elastic.co/t/why-the-meta-in-registry-file-is-always-null/233876)

<div class="topic-metadata">

**Author:** [@yanghuifeng](https://discuss.elastic.co/u/yanghuifeng)\
**Replies:** 0\
**Last updated:** [May 22, 2020, 9:36am UTC](https://discuss.elastic.co/t/why-the-meta-in-registry-file-is-always-null/233876 "2020-05-22T09:36:21Z")

</div>

I'm using a log input for my filebeat6.7, i get the registry file like this: \[ { "source": "/opt/log/test.log", "offset": 916, "timestamp": "2020-05-22T08:58:13.876693008Z", "ttl":…

---

## [How to monitoring JBoss EAP using Jolokia Module?](https://discuss.elastic.co/t/how-to-monitoring-jboss-eap-using-jolokia-module/233860)

<div class="topic-metadata">

**Author:** [@akELK081](https://discuss.elastic.co/u/akELK081)\
**Replies:** 0\
**Last updated:** [May 22, 2020, 7:47am UTC](https://discuss.elastic.co/t/how-to-monitoring-jboss-eap-using-jolokia-module/233860 "2020-05-22T07:47:57Z")

</div>

I am trying to establish jolokia module of metricbeat to monitor Jboss EAP and I am able to monitor JVM related metrices like CPU, memory threads, gc etc. Can any one suggest me relevant fields/attributes along with mbea…

---

## [GZIP invalid header with Filebeat S3 input and GuardDuty logs](https://discuss.elastic.co/t/gzip-invalid-header-with-filebeat-s3-input-and-guardduty-logs/233626)

<div class="topic-metadata">

**Author:** [@nhnicwaller](https://discuss.elastic.co/u/nhnicwaller)\
**Replies:** 5\
**Last updated:** [May 21, 2020, 8:09pm UTC](https://discuss.elastic.co/t/gzip-invalid-header-with-filebeat-s3-input-and-guardduty-logs/233626 "2020-05-21T20:09:34Z")

</div>

I'm trying to ingest logs from AWS GuardDuty using Filebeat, but I'm getting ERROR messages when trying to run the ingest with Filebeat. 2020-05-20T22:42:27.973Z ERROR \[s3\] s3/input.go:447 gzip.NewReader failed: gzip: i…

---

## [Winlogbeat massive deployment](https://discuss.elastic.co/t/winlogbeat-massive-deployment/233804)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 0\
**Last updated:** [May 21, 2020, 7:59pm UTC](https://discuss.elastic.co/t/winlogbeat-massive-deployment/233804 "2020-05-21T19:59:55Z")

</div>

Hi, I may need to deploy/install Winlogbeat in about 100 PCs and I am looking for the most efficient way to do it. So far I only know how to install the beat on each PC one by one, but if there is a way to massively dep…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=244)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=246)
