# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=246

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 247

---

## [Converting type of a field in Elasticsearch Slow Logs scraped by filebeat](https://discuss.elastic.co/t/converting-type-of-a-field-in-elasticsearch-slow-logs-scraped-by-filebeat/233788)

<div class="topic-metadata">

**Author:** [@sachindesai](https://discuss.elastic.co/u/sachindesai)\
**Replies:** 0\
**Last updated:** [May 21, 2020, 6:08pm UTC](https://discuss.elastic.co/t/converting-type-of-a-field-in-elasticsearch-slow-logs-scraped-by-filebeat/233788 "2020-05-21T18:08:20Z")

</div>

Hi team, I am trying to plot some graphs using metrics scraped by filebeat from elasticsearch slow log files on kibana. But by default as the metric "elasticsearch.slowlog.took" is being created as keyword by filebeat ,…

---

## [Filebeat log input not re-scanning at scan\_duration](https://discuss.elastic.co/t/filebeat-log-input-not-re-scanning-at-scan-duration/233604)

<div class="topic-metadata">

**Author:** [@Ben\_Buzbee](https://discuss.elastic.co/u/Ben_Buzbee)\
**Replies:** 1\
**Last updated:** [May 21, 2020, 5:26pm UTC](https://discuss.elastic.co/t/filebeat-log-input-not-re-scanning-at-scan-duration/233604 "2020-05-21T17:26:09Z")

</div>

Short description: I have a log input set to scan every 5 seconds. With full debug logs turned on I see 2020-05-20T19:29:06.606Z DEBUG \[input\] log/input.go:191 Start next scan Which discovers some fil…

---

## [Unmatched response Packetbeat - 6.5.4](https://discuss.elastic.co/t/unmatched-response-packetbeat-6-5-4/233769)

<div class="topic-metadata">

**Author:** [@bruno\_aleixo](https://discuss.elastic.co/u/bruno_aleixo)\
**Replies:** 0\
**Last updated:** [May 21, 2020, 3:55pm UTC](https://discuss.elastic.co/t/unmatched-response-packetbeat-6-5-4/233769 "2020-05-21T15:55:40Z")

</div>

Hi, Please, can help me with a collection error in packetbeat, error in Kibana Error: Unmatched response Configuration in packetbeat packetbeat.interfaces.device: any packetbeat.protocols: type: icmp enabled: …

---

## [How to connect prospector to custom module](https://discuss.elastic.co/t/how-to-connect-prospector-to-custom-module/233768)

<div class="topic-metadata">

**Author:** [@Jonny\_McCullagh](https://discuss.elastic.co/u/Jonny_McCullagh)\
**Replies:** 0\
**Last updated:** [May 21, 2020, 3:38pm UTC](https://discuss.elastic.co/t/how-to-connect-prospector-to-custom-module/233768 "2020-05-21T15:38:34Z")

</div>

I am able to get logs going to elasticsearch using the following: /etc/filebeat/conf.d/lwrp-prospector-airflow.yml --- filebeat: prospectors: - paths: - "/var/log/airflow/\*.log" enabl…

---

## [How to add an alias in filebeat template aliases field without distributing the other alias in aliases](https://discuss.elastic.co/t/how-to-add-an-alias-in-filebeat-template-aliases-field-without-distributing-the-other-alias-in-aliases/233761)

<div class="topic-metadata">

**Author:** [@ramakrushna.sahu](https://discuss.elastic.co/u/ramakrushna.sahu)\
**Replies:** 0\
**Last updated:** [May 21, 2020, 3:01pm UTC](https://discuss.elastic.co/t/how-to-add-an-alias-in-filebeat-template-aliases-field-without-distributing-the-other-alias-in-aliases/233761 "2020-05-21T15:01:37Z")

</div>

How to add an alias in filebeat template aliases field without distributing the other alias in aliases I have existing alias in template aliases. I want to add one/few allies in the existing aliases-filed of the template…

---

## [Custom Output log to elasticsearch](https://discuss.elastic.co/t/custom-output-log-to-elasticsearch/233668)

<div class="topic-metadata">

**Author:** [@Andres\_Felipe\_Vargas](https://discuss.elastic.co/u/Andres_Felipe_Vargas)\
**Replies:** 2\
**Last updated:** [May 21, 2020, 2:32pm UTC](https://discuss.elastic.co/t/custom-output-log-to-elasticsearch/233668 "2020-05-21T14:32:26Z")

</div>

Hi, I have json format strings into the .log files. And I need that filebeat insert that json strings as individual logs into a custom elastic search index. That index needs to have the same structure that the json form…

---

## [Filebeat - Spooling to disk](https://discuss.elastic.co/t/filebeat-spooling-to-disk/232800)

<div class="topic-metadata">

**Author:** [@saket\_gupta](https://discuss.elastic.co/u/saket_gupta)\
**Replies:** 3\
**Last updated:** [May 21, 2020, 2:29pm UTC](https://discuss.elastic.co/t/filebeat-spooling-to-disk/232800 "2020-05-21T14:29:28Z")

</div>

Hi Team, What happens when a filebeat's output like ELastic Search or Logstash is not avalable , however the log files are still written. Will it start consuming memory or will it default to disk. I see that we can con…

---

## [How activate module to parser envoy logs](https://discuss.elastic.co/t/how-activate-module-to-parser-envoy-logs/233337)

<div class="topic-metadata">

**Author:** [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Replies:** 1\
**Last updated:** [May 21, 2020, 1:35pm UTC](https://discuss.elastic.co/t/how-activate-module-to-parser-envoy-logs/233337 "2020-05-21T13:35:08Z")

</div>

Hi! I found this page about envoy module but there isn't instructions to configure on Kubernetes installation. https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-envoyproxy.html My filebeat version…

---

## [How to get the podman container name , cpu and memory usage details using metricbeat](https://discuss.elastic.co/t/how-to-get-the-podman-container-name-cpu-and-memory-usage-details-using-metricbeat/233728)

<div class="topic-metadata">

**Author:** [@balamurugan\_ravi](https://discuss.elastic.co/u/balamurugan_ravi)\
**Replies:** 1\
**Last updated:** [May 21, 2020, 1:34pm UTC](https://discuss.elastic.co/t/how-to-get-the-podman-container-name-cpu-and-memory-usage-details-using-metricbeat/233728 "2020-05-21T13:34:13Z")

</div>

Hi, We are using rootless podman to our containers and would like to monitor the containers performance using metricbeat installed on the host. I have seen this blog post https://www.elastic.co/blog/blog-detail and unde…

---

## [Is Metribeat modules beat-xpack, elasticsearch-xpack and logstash-xpack are free or paid?](https://discuss.elastic.co/t/is-metribeat-modules-beat-xpack-elasticsearch-xpack-and-logstash-xpack-are-free-or-paid/233682)

<div class="topic-metadata">

**Author:** [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Replies:** 2\
**Last updated:** [May 21, 2020, 10:24am UTC](https://discuss.elastic.co/t/is-metribeat-modules-beat-xpack-elasticsearch-xpack-and-logstash-xpack-are-free-or-paid/233682 "2020-05-21T10:24:57Z")

</div>

Is monitoring beats, Elasticsearch, logstash and kibana with Metricbeat using x-pack modules is free or licence ? Simply Monitoring ELK stack with Metricbeat is free or require licence?

---

## [Filebeat deduplication fail to update index](https://discuss.elastic.co/t/filebeat-deduplication-fail-to-update-index/231870)

<div class="topic-metadata">

**Author:** [@mustapha.arakji](https://discuss.elastic.co/u/mustapha.arakji)\
**Replies:** 7\
**Last updated:** [May 21, 2020, 10:03am UTC](https://discuss.elastic.co/t/filebeat-deduplication-fail-to-update-index/231870 "2020-05-21T10:03:53Z")

</div>

Hi, I'm reading this guide: https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-deduplication.html, that discusses the deduplication in both filebeat and logstash, and recommends to set the document id befor…

---

## [How to change Functionbeat index pattern?](https://discuss.elastic.co/t/how-to-change-functionbeat-index-pattern/233635)

<div class="topic-metadata">

**Author:** [@jdcruz](https://discuss.elastic.co/u/jdcruz)\
**Replies:** 1\
**Last updated:** [May 21, 2020, 12:31am UTC](https://discuss.elastic.co/t/how-to-change-functionbeat-index-pattern/233635 "2020-05-21T00:31:04Z")

</div>

Is there anyway to change index name in kibana during functionbeat deployment? Default name is functionbeat-7.6.1-2020.05.14-000001. I would like to change to custom name like e.g functionBeat-dev. One of the goal is to…

---

## [How to segregate cloudwatch logs using functionbeat?](https://discuss.elastic.co/t/how-to-segregate-cloudwatch-logs-using-functionbeat/233631)

<div class="topic-metadata">

**Author:** [@marksantosph](https://discuss.elastic.co/u/marksantosph)\
**Replies:** 0\
**Last updated:** [May 20, 2020, 11:38pm UTC](https://discuss.elastic.co/t/how-to-segregate-cloudwatch-logs-using-functionbeat/233631 "2020-05-20T23:38:59Z")

</div>

I am trying to segregate cloudwatch logs using functionbeat. I deployed two lambda functions having different log group name, function name and deploy bucket. The goal is to get logs from two different environments and v…

---

## [Overwriting @timestamp in module](https://discuss.elastic.co/t/overwriting-timestamp-in-module/233463)

<div class="topic-metadata">

**Author:** [@mcardlesam](https://discuss.elastic.co/u/mcardlesam)\
**Replies:** 5\
**Last updated:** [May 20, 2020, 11:46pm UTC](https://discuss.elastic.co/t/overwriting-timestamp-in-module/233463 "2020-05-20T23:46:17Z")

</div>

I have written a module for filebeat to parse a log from a application I have written The pipeline mostly works, except in kibana i get the error "Text '19/May/2020 15:25:17' could not be parsed at index 12" for each re…

---

## [Filebeat is filling up Filesystem](https://discuss.elastic.co/t/filebeat-is-filling-up-filesystem/233629)

<div class="topic-metadata">

**Author:** [@snakhuda](https://discuss.elastic.co/u/snakhuda)\
**Replies:** 1\
**Last updated:** [May 20, 2020, 11:26pm UTC](https://discuss.elastic.co/t/filebeat-is-filling-up-filesystem/233629 "2020-05-20T23:26:34Z")

</div>

We are monitoring a log file which is approx. 300mb in size. Log file is on /data FileSystem of 68GB. Once I start filebeat service, it fills up /data FS. Any ideas what could be the cause of this issue? \[root@IST000219…

---

## [Filebeat Multiline field not importing correctly](https://discuss.elastic.co/t/filebeat-multiline-field-not-importing-correctly/233435)

<div class="topic-metadata">

**Author:** [@ckunkel](https://discuss.elastic.co/u/ckunkel)\
**Replies:** 2\
**Last updated:** [May 20, 2020, 9:54pm UTC](https://discuss.elastic.co/t/filebeat-multiline-field-not-importing-correctly/233435 "2020-05-20T21:54:41Z")

</div>

I'm having trouble getting the correct output in Kabana from my log files ingested by filebeats. I'm pretty sure the issue is with filebeats though so I'm posting it here. My log files have the following format: \[dat…

---

## [Updated filebeat (from 6.2.4 to 7.6 ) drops all log.\*](https://discuss.elastic.co/t/updated-filebeat-from-6-2-4-to-7-6-drops-all-log/232724)

<div class="topic-metadata">

**Author:** [@mishat-realityi](https://discuss.elastic.co/u/mishat-realityi)\
**Replies:** 2\
**Last updated:** [May 20, 2020, 7:03pm UTC](https://discuss.elastic.co/t/updated-filebeat-from-6-2-4-to-7-6-drops-all-log/232724 "2020-05-20T19:03:52Z")

</div>

Hi everyone, I have a stack filebeat \> logstash \> elasticsearch Here is my config of filebeat. filebeat.inputs: - type: log enabled: true paths: - C:\\folder\\\* json.keys\_under\_root: true …

---

## [Filebeat Kafka topic mappings](https://discuss.elastic.co/t/filebeat-kafka-topic-mappings/233584)

<div class="topic-metadata">

**Author:** [@Darshan\_B\_M](https://discuss.elastic.co/u/Darshan_B_M)\
**Replies:** 0\
**Last updated:** [May 20, 2020, 5:53pm UTC](https://discuss.elastic.co/t/filebeat-kafka-topic-mappings/233584 "2020-05-20T17:53:48Z")

</div>

Hi I am trying to setup filebeat to send events to Kafka and have a requirement that I will need to send events from different apps to a different topic. I tried to set the configs as mentioned in the documentation(http…

---

## [\[httpjson\] Process another repeated request](https://discuss.elastic.co/t/httpjson-process-another-repeated-request/233578)

<div class="topic-metadata">

**Author:** [@jpnorenam](https://discuss.elastic.co/u/jpnorenam)\
**Replies:** 0\
**Last updated:** [May 20, 2020, 5:00pm UTC](https://discuss.elastic.co/t/httpjson-process-another-repeated-request/233578 "2020-05-20T17:00:41Z")

</div>

Hello, I am trying to set up a Enrolled Beat in Kibana's Beats Central Management, although its running it doesn't create any index with the data. The configuration block Type: Filebeat Input Path: /home/vagrant/foo.…

---

## [I’m seeing Centos7 OS reported as wrong OS RHEL (not surprising) but is that expected Beat behavior?](https://discuss.elastic.co/t/i-m-seeing-centos7-os-reported-as-wrong-os-rhel-not-surprising-but-is-that-expected-beat-behavior/233206)

<div class="topic-metadata">

**Author:** [@EricDavisX](https://discuss.elastic.co/u/EricDavisX)\
**Replies:** 2\
**Last updated:** [May 20, 2020, 5:02pm UTC](https://discuss.elastic.co/t/i-m-seeing-centos7-os-reported-as-wrong-os-rhel-not-surprising-but-is-that-expected-beat-behavior/233206 "2020-05-20T17:02:42Z")

</div>

I'm seeing this with the MetricBeat and FileBeat deploys that come with the 7.8 Alpha Elastic Agent. I didn't see any 'wrong os' Agent discussions immediately so I'm asking.

---

## [Turning Monitor with Metricbeat on (Metricbeat -\> ElasticSearch)](https://discuss.elastic.co/t/turning-monitor-with-metricbeat-on-metricbeat-elasticsearch/229632)

<div class="topic-metadata">

**Author:** [@tjmartins](https://discuss.elastic.co/u/tjmartins)\
**Replies:** 2\
**Last updated:** [May 20, 2020, 4:59pm UTC](https://discuss.elastic.co/t/turning-monitor-with-metricbeat-on-metricbeat-elasticsearch/229632 "2020-05-20T16:59:34Z")

</div>

Hi all, I'm trying to turning my "Monitor with Metricbeat" on but i'm getting the following errors: - From Metricbeat log: Apr 24 12:06:40 l-qa-bes48 metricbeat\[47280\]: 2020-04-24T12:06:40.332+0100 INFO …

---

## [Find the Slowest Filebeat](https://discuss.elastic.co/t/find-the-slowest-filebeat/233405)

<div class="topic-metadata">

**Author:** [@ssarpotdar](https://discuss.elastic.co/u/ssarpotdar)\
**Replies:** 0\
**Last updated:** [May 19, 2020, 8:38pm UTC](https://discuss.elastic.co/t/find-the-slowest-filebeat/233405 "2020-05-19T20:38:26Z")

</div>

Hello, I am new to ELK stack. I have several Filebeats configured to send the logs to Logstash and also enabled Filebeat to send the monitoring data to Elastic search. I have a downstream process that needs to process t…

---

## [Error trying to import dashboards to kibana with filebeat](https://discuss.elastic.co/t/error-trying-to-import-dashboards-to-kibana-with-filebeat/232261)

<div class="topic-metadata">

**Author:** [@nb03briceno](https://discuss.elastic.co/u/nb03briceno)\
**Replies:** 4\
**Last updated:** [May 20, 2020, 2:45pm UTC](https://discuss.elastic.co/t/error-trying-to-import-dashboards-to-kibana-with-filebeat/232261 "2020-05-20T14:45:45Z")

</div>

Hello everyone, I would like to ask if somebody know how I could import my dashboards directly with filebeat. When I do the procedure manually within the kibana page with import/export It works fine, yet when I set (set…

---

## [Setup.dashboard.url - functionning (In filebeat.yml)](https://discuss.elastic.co/t/setup-dashboard-url-functionning-in-filebeat-yml/233557)

<div class="topic-metadata">

**Author:** [@nb03briceno](https://discuss.elastic.co/u/nb03briceno)\
**Replies:** 0\
**Last updated:** [May 20, 2020, 2:31pm UTC](https://discuss.elastic.co/t/setup-dashboard-url-functionning-in-filebeat-yml/233557 "2020-05-20T14:31:28Z")

</div>

Hello guys, In the project in which I'm working, we are trying to use filebeat to import directly the dashboards we create in Kibana. We already have a gitlab repository in which we save our documents to easy manage all…

---

## [Tailing /var/log/secure](https://discuss.elastic.co/t/tailing-var-log-secure/233540)

<div class="topic-metadata">

**Author:** [@Mohammad\_Etemad](https://discuss.elastic.co/u/Mohammad_Etemad)\
**Replies:** 0\
**Last updated:** [May 20, 2020, 1:18pm UTC](https://discuss.elastic.co/t/tailing-var-log-secure/233540 "2020-05-20T13:18:11Z")

</div>

Hi all, Is there a way for auditbeat to tail /var/log/secure logs in Centos? I am using cockpit and would like to see failed login attempts on my OAM side in Kibana. Is that possible? I know this can be done by filebea…

---

## [Add grok patterns on system auth ssh module](https://discuss.elastic.co/t/add-grok-patterns-on-system-auth-ssh-module/231703)

<div class="topic-metadata">

**Author:** [@flyme](https://discuss.elastic.co/u/flyme)\
**Replies:** 1\
**Last updated:** [May 20, 2020, 12:36pm UTC](https://discuss.elastic.co/t/add-grok-patterns-on-system-auth-ssh-module/231703 "2020-05-20T12:36:02Z")

</div>

I use filebeat to send my logs to logstash. I have these logs : So I'm trying to change the grok patterns of the system.auth module in this file in order to have "source.ip" field like this : I modified this fil…

---

## [Custom filebeat module timezone conversion issue](https://discuss.elastic.co/t/custom-filebeat-module-timezone-conversion-issue/233428)

<div class="topic-metadata">

**Author:** [@nmoham](https://discuss.elastic.co/u/nmoham)\
**Replies:** 0\
**Last updated:** [May 20, 2020, 12:52am UTC](https://discuss.elastic.co/t/custom-filebeat-module-timezone-conversion-issue/233428 "2020-05-20T00:52:22Z")

</div>

We build a custom module for parsing F5 Load Balancer logs, all the patterns are working fine. But the timezone is set to UTC -8 hours for the event ingested and showing up in Kibana. We're currently in PT timezone. …

---

## [\[Metricbeat - elastic module\] Can't monitor more than 10 elastic nodes](https://discuss.elastic.co/t/metricbeat-elastic-module-cant-monitor-more-than-10-elastic-nodes/233496)

<div class="topic-metadata">

**Author:** [@aaleman](https://discuss.elastic.co/u/aaleman)\
**Replies:** 3\
**Last updated:** [May 20, 2020, 12:10pm UTC](https://discuss.elastic.co/t/metricbeat-elastic-module-cant-monitor-more-than-10-elastic-nodes/233496 "2020-05-20T12:10:35Z")

</div>

Hello, something weird is happens in my new cluster dockerized in swarm. When I add 10 machine on: \` metricbeat.modules: - module: elasticsearch metricsets: - ccr - cluster\_stats - enrich - index …

---

## [Filebeat unable to send info to elastic cloud with non elastic user](https://discuss.elastic.co/t/filebeat-unable-to-send-info-to-elastic-cloud-with-non-elastic-user/233530)

<div class="topic-metadata">

**Author:** [@jlopezzarza](https://discuss.elastic.co/u/jlopezzarza)\
**Replies:** 0\
**Last updated:** [May 20, 2020, 12:01pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-send-info-to-elastic-cloud-with-non-elastic-user/233530 "2020-05-20T12:01:43Z")

</div>

Hello! I'm setting up elastic cloud with GKE, sending the event using filebeat. I've configured it with the initial elastic user and now I want to demote the privileges of the filebeat user. Now the events are not sent …

---

## [Filebeat 7.7 collection size](https://discuss.elastic.co/t/filebeat-7-7-collection-size/233525)

<div class="topic-metadata">

**Author:** [@tsbayne](https://discuss.elastic.co/u/tsbayne)\
**Replies:** 0\
**Last updated:** [May 20, 2020, 11:43am UTC](https://discuss.elastic.co/t/filebeat-7-7-collection-size/233525 "2020-05-20T11:43:15Z")

</div>

After updating our ECK stack, filebeat indices grow out of control and eventually fill up the storage and crash the stack within a matter of hours. I literally only bumped up the version numbers and redeployed the stack…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=245)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=247)
