# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=247

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 248

---

## [Plotting a graph for Elasticsearch Slow Logs](https://discuss.elastic.co/t/plotting-a-graph-for-elasticsearch-slow-logs/233411)

<div class="topic-metadata">

**Author:** [@sachindesai](https://discuss.elastic.co/u/sachindesai)\
**Replies:** 3\
**Last updated:** [May 20, 2020, 8:10am UTC](https://discuss.elastic.co/t/plotting-a-graph-for-elasticsearch-slow-logs/233411 "2020-05-20T08:10:03Z")

</div>

Hi , I am working on to plot my slow logs of elasticsearch on graphs in kibana/grafana. I want to get a graph for "elasticsearch.slowlog.took" (which gives me total time taken for a query to exec) to be on Y axis and Tim…

---

## [Logs not being shipped, I am lost :(](https://discuss.elastic.co/t/logs-not-being-shipped-i-am-lost/233468)

<div class="topic-metadata">

**Author:** [@calanon](https://discuss.elastic.co/u/calanon)\
**Replies:** 0\
**Last updated:** [May 20, 2020, 6:29am UTC](https://discuss.elastic.co/t/logs-not-being-shipped-i-am-lost/233468 "2020-05-20T06:29:25Z")

</div>

I have setup a second instance of Filebeat to test the config on another ELK stack server using this command: /usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat-test.yml -path.data /var/lib/filebeat/tempdat-path…

---

## [Does Auditbeat support RHEL 6](https://discuss.elastic.co/t/does-auditbeat-support-rhel-6/233418)

<div class="topic-metadata">

**Author:** [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Replies:** 2\
**Last updated:** [May 20, 2020, 1:31am UTC](https://discuss.elastic.co/t/does-auditbeat-support-rhel-6/233418 "2020-05-20T01:31:04Z")

</div>

Hello, I saw at elastic.co that Beats support RHEL 8 but does it support RHEL 6 ? Thank you EDIT : For any os compatibility check, take a look at https://www.elastic.co/support/matrix (thanks @warkolm )

---

## [Metricbeat fails to connect to elastisearch and ignores fields in yaml](https://discuss.elastic.co/t/metricbeat-fails-to-connect-to-elastisearch-and-ignores-fields-in-yaml/233409)

<div class="topic-metadata">

**Author:** [@syost](https://discuss.elastic.co/u/syost)\
**Replies:** 1\
**Last updated:** [May 19, 2020, 11:43pm UTC](https://discuss.elastic.co/t/metricbeat-fails-to-connect-to-elastisearch-and-ignores-fields-in-yaml/233409 "2020-05-19T23:43:54Z")

</div>

ENVIRONMENT: Amazon EC2 Instance ELK has been installed XPACK has been enabled Passwords have been set for built-in users metricbeat has been untar'd ISSUE: When I start metricbeat it gives the following output in…

---

## [Can't compile beats since 7.6.2](https://discuss.elastic.co/t/cant-compile-beats-since-7-6-2/232695)

<div class="topic-metadata">

**Author:** [@Aaron\_Abbett](https://discuss.elastic.co/u/Aaron_Abbett)\
**Replies:** 2\
**Last updated:** [May 19, 2020, 8:24pm UTC](https://discuss.elastic.co/t/cant-compile-beats-since-7-6-2/232695 "2020-05-19T20:24:25Z")

</div>

Using the same methods I've been using to compile Beats for Pi since v6, I can no longer compile beats. GOARCH=arm GOOS=linux GO v1.13.10 I clone the repo, checkout the commit for the release (5e69e25), cd to the bea…

---

## [Filebeat's System Module not parsing "message" in syslogs](https://discuss.elastic.co/t/filebeats-system-module-not-parsing-message-in-syslogs/233377)

<div class="topic-metadata">

**Author:** [@artsAmit](https://discuss.elastic.co/u/artsAmit)\
**Replies:** 0\
**Last updated:** [May 19, 2020, 4:54pm UTC](https://discuss.elastic.co/t/filebeats-system-module-not-parsing-message-in-syslogs/233377 "2020-05-19T16:54:08Z")

</div>

I am trying to ship system logs to logstash using filebeat. I have enabled system module and started the log shipping from filebeat to logstash. Logstash is receiving the logs properly but it seems like the system logs a…

---

## [Filebeat AWS Module problem](https://discuss.elastic.co/t/filebeat-aws-module-problem/233141)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 4\
**Last updated:** [May 19, 2020, 4:10pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-problem/233141 "2020-05-19T16:10:14Z")

</div>

Hi I am trying to use the Filebeat AWS module to retrieve data from AWS. My Elastic environment is running v7.7 and I have a single server running Kibana, Elasticsearch, Filebeat and Logstash (Logstash not relevant for…

---

## [Filebeat error while reading multiline json lines log file](https://discuss.elastic.co/t/filebeat-error-while-reading-multiline-json-lines-log-file/233366)

<div class="topic-metadata">

**Author:** [@polaaditya](https://discuss.elastic.co/u/polaaditya)\
**Replies:** 0\
**Last updated:** [May 19, 2020, 3:52pm UTC](https://discuss.elastic.co/t/filebeat-error-while-reading-multiline-json-lines-log-file/233366 "2020-05-19T15:52:20Z")

</div>

I am facing issues while ingesting logs to logstash using filebeat. both of filebeat and logstash versions are 7.5.2 and please find the details below filebeat config filebeat.inputs: - type: log enabled: true enco…

---

## [Panw module network.direction unknown](https://discuss.elastic.co/t/panw-module-network-direction-unknown/232999)

<div class="topic-metadata">

**Author:** [@Garrett\_Gauthier](https://discuss.elastic.co/u/Garrett_Gauthier)\
**Replies:** 2\
**Last updated:** [May 19, 2020, 1:26pm UTC](https://discuss.elastic.co/t/panw-module-network-direction-unknown/232999 "2020-05-19T13:26:17Z")

</div>

The network.direction attribute always states unknown All other attributes seem to be properly populated. Any help. PAN 9.0, syslog in BSD format

---

## [Filebeat process timestamp from JSON](https://discuss.elastic.co/t/filebeat-process-timestamp-from-json/232910)

<div class="topic-metadata">

**Author:** [@nmoham](https://discuss.elastic.co/u/nmoham)\
**Replies:** 1\
**Last updated:** [May 19, 2020, 12:45pm UTC](https://discuss.elastic.co/t/filebeat-process-timestamp-from-json/232910 "2020-05-19T12:45:14Z")

</div>

I am trying to use the filebeat timestamp processor to overwrite the timestamp from logs to @timestamp field before sending data to Elasticsearch . but the timestamp is kibana still shows the ingest timestamp . Not sure…

---

## [Why metricbeat data showing process state as sleeping](https://discuss.elastic.co/t/why-metricbeat-data-showing-process-state-as-sleeping/233093)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 1\
**Last updated:** [May 19, 2020, 10:36am UTC](https://discuss.elastic.co/t/why-metricbeat-data-showing-process-state-as-sleeping/233093 "2020-05-19T10:36:08Z")

</div>

Hi All, I have installed metricbeat 6.8.8 in ubuntu machine and I'm able to see all the system metrics. The problem that I find all processes system.process.state metric, are showing as "Sleeping", Though process like…

---

## [Filebeat Autodiscovery: Different configurations for different Docker containers](https://discuss.elastic.co/t/filebeat-autodiscovery-different-configurations-for-different-docker-containers/232210)

<div class="topic-metadata">

**Author:** [@tomson21](https://discuss.elastic.co/u/tomson21)\
**Replies:** 2\
**Last updated:** [May 19, 2020, 9:02am UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-different-configurations-for-different-docker-containers/232210 "2020-05-19T09:02:37Z")

</div>

Hello , I'm currently drawing logs from around 30 Docker containers with a single input and it works perfectly. However, I have recently discovered that one of these containers exports XML which will need a separate con…

---

## [Missing docker metadata in filebeat](https://discuss.elastic.co/t/missing-docker-metadata-in-filebeat/233095)

<div class="topic-metadata">

**Author:** [@eihkoh](https://discuss.elastic.co/u/eihkoh)\
**Replies:** 4\
**Last updated:** [May 19, 2020, 8:11am UTC](https://discuss.elastic.co/t/missing-docker-metadata-in-filebeat/233095 "2020-05-19T08:11:28Z")

</div>

Hi all, Somebody experiencing the same problem that filebeat doesn't send any docker metadata for the docker container logging? Symptom: Since docker version 19.x you need to configure "type=container" as filebeat.inp…

---

## [How to read metricbeats data for filebeat (looking for Event rates(/s) Throughput(/s))?](https://discuss.elastic.co/t/how-to-read-metricbeats-data-for-filebeat-looking-for-event-rates-s-throughput-s/233128)

<div class="topic-metadata">

**Author:** [@johnprakashgithub](https://discuss.elastic.co/u/johnprakashgithub)\
**Replies:** 2\
**Last updated:** [May 19, 2020, 8:00am UTC](https://discuss.elastic.co/t/how-to-read-metricbeats-data-for-filebeat-looking-for-event-rates-s-throughput-s/233128 "2020-05-19T08:00:33Z")

</div>

Tried to find out a way to interpret the metricdata to occur from filebeat. Especially following Events rates per sec Throughput per sec {"beat":{"cpu":{"system":{"ticks":106810,"time":{"ms":106818}},"total":{"ticks":…

---

## [FileBeat make update fails for new custom module](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/233264)

<div class="topic-metadata">

**Author:** [@seshagiriSriram](https://discuss.elastic.co/u/seshagiriSriram)\
**Replies:** 0\
**Last updated:** [May 19, 2020, 7:53am UTC](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/233264 "2020-05-19T07:53:52Z")

</div>

I have followed the instructions here: https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html create-module, create-fileset and create-fields all work correctly with no errors. make update…

---

## [Filebeat multiple input log files with condition](https://discuss.elastic.co/t/filebeat-multiple-input-log-files-with-condition/233251)

<div class="topic-metadata">

**Author:** [@Mohammad\_Mousavi](https://discuss.elastic.co/u/Mohammad_Mousavi)\
**Replies:** 1\
**Last updated:** [May 19, 2020, 7:46am UTC](https://discuss.elastic.co/t/filebeat-multiple-input-log-files-with-condition/233251 "2020-05-19T07:46:39Z")

</div>

Hi, I have 2 input files. access and error nginx log files. in one of them I need just specific lines. I thought this might work but it doesn't. paths: - /var/log/nginx/myapp-access.log fields: {log\_type: myapp-med…

---

## [Filebeat module not in OSS licensed version](https://discuss.elastic.co/t/filebeat-module-not-in-oss-licensed-version/233243)

<div class="topic-metadata">

**Author:** [@mcardlesam](https://discuss.elastic.co/u/mcardlesam)\
**Replies:** 1\
**Last updated:** [May 19, 2020, 5:14am UTC](https://discuss.elastic.co/t/filebeat-module-not-in-oss-licensed-version/233243 "2020-05-19T05:14:16Z")

</div>

I am wanting to use the OSS version of filebeat to send log data to the AWS Elasticsearch service One of the log producers I have is rabbitmq - The rabbitmq module is not included in the OSS version of filebeat. Why is…

---

## [/etc/rc.d/init.d/filebeat for pfSense - freeBSD 13](https://discuss.elastic.co/t/etc-rc-d-init-d-filebeat-for-pfsense-freebsd-13/233084)

<div class="topic-metadata">

**Author:** [@Minh\_Ti\_n\_Tr\_n](https://discuss.elastic.co/u/Minh_Ti_n_Tr_n)\
**Replies:** 3\
**Last updated:** [May 19, 2020, 2:38am UTC](https://discuss.elastic.co/t/etc-rc-d-init-d-filebeat-for-pfsense-freebsd-13/233084 "2020-05-19T02:38:58Z")

</div>

Hi, I just install filebeat v6.8.7 on my pfSense 2.4.5 box. But when I start with command service filebeat start it throws the error start does not exist in /etc/rc.d or the local startup directories (/usr/local/etc/r…

---

## [When use variables in output.kakfa ,it doesn't work](https://discuss.elastic.co/t/when-use-variables-in-output-kakfa-it-doesnt-work/233086)

<div class="topic-metadata">

**Author:** [@XFLaura](https://discuss.elastic.co/u/XFLaura)\
**Replies:** 2\
**Last updated:** [May 19, 2020, 2:12am UTC](https://discuss.elastic.co/t/when-use-variables-in-output-kakfa-it-doesnt-work/233086 "2020-05-19T02:12:06Z")

</div>

my filebeat version is 7.6.2 and I config the input.fields.log\_topic , but when I use the same variable in output.kafka as a topic ,it doesn't work output.kafka: enabled: true hosts: \["192.168.2.21:9092","192.168.2.…

---

## [\[Bug\] Output/Kafka Can't use topics with uppercase letters anymore](https://discuss.elastic.co/t/bug-output-kafka-cant-use-topics-with-uppercase-letters-anymore/233194)

<div class="topic-metadata">

**Author:** [@theoo](https://discuss.elastic.co/u/theoo)\
**Replies:** 0\
**Last updated:** [May 18, 2020, 8:05pm UTC](https://discuss.elastic.co/t/bug-output-kafka-cant-use-topics-with-uppercase-letters-anymore/233194 "2020-05-18T20:05:58Z")

</div>

Hi there, I wanted to upgrade my winlogbeat from 7.2.0 to 7.7.0 today but had to realize that the kafka output is broken. In newer versions, the config option topic from output.kafka goes through a constSelectorExpr a…

---

## [Lowering Metricbeat Output Doc Count](https://discuss.elastic.co/t/lowering-metricbeat-output-doc-count/232961)

<div class="topic-metadata">

**Author:** [@Ad3t0](https://discuss.elastic.co/u/Ad3t0)\
**Replies:** 2\
**Last updated:** [May 18, 2020, 7:32pm UTC](https://discuss.elastic.co/t/lowering-metricbeat-output-doc-count/232961 "2020-05-18T19:32:01Z")

</div>

I have Metricbeat configured with default settings and it sends somewhere near 20 docs every 10 seconds. Is there a way to lower this amount ? All I want to use it for is metrics on the entire system not individual proce…

---

## [Can't get text on a START\_OBJECT at](https://discuss.elastic.co/t/cant-get-text-on-a-start-object-at/233183)

<div class="topic-metadata">

**Author:** [@Michael\_Tsikerdekis](https://discuss.elastic.co/u/Michael_Tsikerdekis)\
**Replies:** 0\
**Last updated:** [May 18, 2020, 7:11pm UTC](https://discuss.elastic.co/t/cant-get-text-on-a-start-object-at/233183 "2020-05-18T19:11:43Z")

</div>

I can see that the field tls.server.ja3s cannot be parsed as it send by eve.json. What are my options in this case? Drop it? I am using 7.7.0 and suricata is 5.0.3. May 18 19:08:30 mrkilo filebeat\[16036\]: 2020-05-18T19…

---

## [Filebeat unable to send data to elastic search. ( Failed to publish events: Post + Client.Timeout exceeded while awaiting headers )](https://discuss.elastic.co/t/filebeat-unable-to-send-data-to-elastic-search-failed-to-publish-events-post-client-timeout-exceeded-while-awaiting-headers/233171)

<div class="topic-metadata">

**Author:** [@ramakrushna.sahu](https://discuss.elastic.co/u/ramakrushna.sahu)\
**Replies:** 1\
**Last updated:** [May 18, 2020, 6:35pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-send-data-to-elastic-search-failed-to-publish-events-post-client-timeout-exceeded-while-awaiting-headers/233171 "2020-05-18T18:35:21Z")

</div>

Filebeat unable to send data to elastic search and shows error as below. May 18 23:37:03 filebeat\_host filebeat\[18405\]: 2020-05-18T23:37:03.595+0530 ERROR pipeline/output.go:121 Failed to publish ev…

---

## [Failed to get docker stats: request returned Not Found for API route and version](https://discuss.elastic.co/t/failed-to-get-docker-stats-request-returned-not-found-for-api-route-and-version/230720)

<div class="topic-metadata">

**Author:** [@daz1761](https://discuss.elastic.co/u/daz1761)\
**Replies:** 8\
**Last updated:** [May 18, 2020, 3:52pm UTC](https://discuss.elastic.co/t/failed-to-get-docker-stats-request-returned-not-found-for-api-route-and-version/230720 "2020-05-18T15:52:06Z")

</div>

I am using metricbeat in conjunction with Docker to get metrics from a given container via hints autodiscovery. I don't think its working properly as I am getting an error, in the error message key: failed to get docke…

---

## [Host metadata in beats](https://discuss.elastic.co/t/host-metadata-in-beats/233104)

<div class="topic-metadata">

**Author:** [@ParashB](https://discuss.elastic.co/u/ParashB)\
**Replies:** 0\
**Last updated:** [May 18, 2020, 12:21pm UTC](https://discuss.elastic.co/t/host-metadata-in-beats/233104 "2020-05-18T12:21:25Z")

</div>

How does the add\_host\_metadata fetch the host metadata fields. I am particularly concerned about the below fields in RHEL OS. I want to fetch the same fields using fluent-bit in my application. { "host":{ "arch…

---

## [Any Netflow Dashboard beside the default one?](https://discuss.elastic.co/t/any-netflow-dashboard-beside-the-default-one/229630)

<div class="topic-metadata">

**Author:** [@Minh\_Ti\_n\_Tr\_n](https://discuss.elastic.co/u/Minh_Ti_n_Tr_n)\
**Replies:** 1\
**Last updated:** [May 18, 2020, 10:58am UTC](https://discuss.elastic.co/t/any-netflow-dashboard-beside-the-default-one/229630 "2020-05-18T10:58:52Z")

</div>

Hi, I just config Netflow for Elastic Siem. With the auditbeat we will have some template for auditbeat in Dashboard field. Do we have template for Netflow using Filebeat? Thanks

---

## [Filebeat logs not visible in kibana dashboards](https://discuss.elastic.co/t/filebeat-logs-not-visible-in-kibana-dashboards/232405)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 3\
**Last updated:** [May 18, 2020, 10:23am UTC](https://discuss.elastic.co/t/filebeat-logs-not-visible-in-kibana-dashboards/232405 "2020-05-18T10:23:37Z")

</div>

Hi, After a long back and forth with my issue on this link: I've been forwarded to here. My question is that I'm receiving logs in the kibana: But still the tables don't show anything neither events from SEIM. …

---

## [How to add a new filebeat.input tag in filebeat go code repo](https://discuss.elastic.co/t/how-to-add-a-new-filebeat-input-tag-in-filebeat-go-code-repo/233002)

<div class="topic-metadata">

**Author:** [@rushabhwadkar](https://discuss.elastic.co/u/rushabhwadkar)\
**Replies:** 4\
**Last updated:** [May 18, 2020, 8:13am UTC](https://discuss.elastic.co/t/how-to-add-a-new-filebeat-input-tag-in-filebeat-go-code-repo/233002 "2020-05-18T08:13:05Z")

</div>

These are the steps I followed - I cloned and copied the log folder (https://github.com/elastic/beats/tree/master/filebeat/input), renamed it to newlog and placed it into that folder only. I changed the package name to…

---

## [If filebeat finish to harvest is it mean that logstash finished to process?](https://discuss.elastic.co/t/if-filebeat-finish-to-harvest-is-it-mean-that-logstash-finished-to-process/231365)

<div class="topic-metadata">

**Author:** [@111320](https://discuss.elastic.co/u/111320)\
**Replies:** 3\
**Last updated:** [May 18, 2020, 7:44am UTC](https://discuss.elastic.co/t/if-filebeat-finish-to-harvest-is-it-mean-that-logstash-finished-to-process/231365 "2020-05-18T07:44:57Z")

</div>

I can see from the "offset" field in the registry file of filebeat that it finish to harvest some file. Is it mean that logstash finish to process the file and send it to elasticsearch?

---

## [Importing data (json) from API](https://discuss.elastic.co/t/importing-data-json-from-api/232979)

<div class="topic-metadata">

**Author:** [@josete242](https://discuss.elastic.co/u/josete242)\
**Replies:** 1\
**Last updated:** [May 18, 2020, 7:18am UTC](https://discuss.elastic.co/t/importing-data-json-from-api/232979 "2020-05-18T07:18:47Z")

</div>

Hi all. I need to import data via API to to analyze and create reports in elasticsearch. These data are collected in JSON format. I have seen that with metricbeat using the http module I could do it, but I have some do…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=246)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=248)
