# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=248

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 249

---

## [Filebeat dont work properly](https://discuss.elastic.co/t/filebeat-dont-work-properly/232046)

<div class="topic-metadata">

**Author:** [@Alexandros888](https://discuss.elastic.co/u/Alexandros888)\
**Replies:** 16\
**Last updated:** [May 18, 2020, 7:14am UTC](https://discuss.elastic.co/t/filebeat-dont-work-properly/232046 "2020-05-18T07:14:52Z")

</div>

Hello, I have installed filebeat version 7.6.2. My elastic cluster nodes also have vesion 7.6.2 in kibana end elastic search. My filebeat yamlfile is the following: ###################### Filebeat Configuration Examp…

---

## [Proper Syntax for filtering forwarded events?](https://discuss.elastic.co/t/proper-syntax-for-filtering-forwarded-events/233025)

<div class="topic-metadata">

**Author:** [@almathden](https://discuss.elastic.co/u/almathden)\
**Replies:** 0\
**Last updated:** [May 18, 2020, 3:04am UTC](https://discuss.elastic.co/t/proper-syntax-for-filtering-forwarded-events/233025 "2020-05-18T03:04:31Z")

</div>

So this is a two-fer, filtering and processing with the security module https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-module-security.html What is the proper syntax for this? The article has this,…

---

## [Filebeat Redis Module 7.6.2 the timestamp is not right](https://discuss.elastic.co/t/filebeat-redis-module-7-6-2-the-timestamp-is-not-right/232969)

<div class="topic-metadata">

**Author:** [@AlanNing](https://discuss.elastic.co/u/AlanNing)\
**Replies:** 1\
**Last updated:** [May 17, 2020, 5:28am UTC](https://discuss.elastic.co/t/filebeat-redis-module-7-6-2-the-timestamp-is-not-right/232969 "2020-05-17T05:28:34Z")

</div>

Filebeat Redis(5.0.8) Module(i use default setting ) 7.6.2 the timestamp is not right. I use filebeat 7.6.2 to es. the event.created is right. how can change @timestamp -8 hours to event.created .

---

## [Heartbeat kibana mongodb](https://discuss.elastic.co/t/heartbeat-kibana-mongodb/232732)

<div class="topic-metadata">

**Author:** [@ElAouane](https://discuss.elastic.co/u/ElAouane)\
**Replies:** 5\
**Last updated:** [May 17, 2020, 4:33am UTC](https://discuss.elastic.co/t/heartbeat-kibana-mongodb/232732 "2020-05-17T04:33:39Z")

</div>

Hello guys. I am working in aws on a project that is structured as follow: app instance (public subnet) -mongodb (3 instances on a private subnet, 1 is primary and the other 2 are replicaset) -kibana instance -elast…

---

## [Auditd module's kibana dashboards do not use keyword fields](https://discuss.elastic.co/t/auditd-modules-kibana-dashboards-do-not-use-keyword-fields/232795)

<div class="topic-metadata">

**Author:** [@kosfar](https://discuss.elastic.co/u/kosfar)\
**Replies:** 2\
**Last updated:** [May 16, 2020, 5:15pm UTC](https://discuss.elastic.co/t/auditd-modules-kibana-dashboards-do-not-use-keyword-fields/232795 "2020-05-16T17:15:18Z")

</div>

Kibana dashboards and visualizations for auditd module do not use keyword fields for aggregation queries in my version 6.8.4. This is the case for latest upstream too though: This led to dashboards not working prope…

---

## [Log/log.go:145 Non-zero metrics in the last 30s](https://discuss.elastic.co/t/log-log-go-145-non-zero-metrics-in-the-last-30s/231873)

<div class="topic-metadata">

**Author:** [@sai\_charan](https://discuss.elastic.co/u/sai_charan)\
**Replies:** 16\
**Last updated:** [May 16, 2020, 11:16am UTC](https://discuss.elastic.co/t/log-log-go-145-non-zero-metrics-in-the-last-30s/231873 "2020-05-16T11:16:23Z")

</div>

Hello, I am new to ELK stack and configured my filebeat in such a way that it directly send logs to elasticsearch itself. Problem here is when i ran the filebeat in debug mode using the below command, i am getting the l…

---

## [Not able to connect to AWS monitor instance thru proxy](https://discuss.elastic.co/t/not-able-to-connect-to-aws-monitor-instance-thru-proxy/232721)

<div class="topic-metadata">

**Author:** [@Roberto\_Chacon](https://discuss.elastic.co/u/Roberto_Chacon)\
**Replies:** 6\
**Last updated:** [May 15, 2020, 10:01pm UTC](https://discuss.elastic.co/t/not-able-to-connect-to-aws-monitor-instance-thru-proxy/232721 "2020-05-15T22:01:01Z")

</div>

I'm trying to connect to AWS instance for monitoring using metricbeat but getting an error "proxyconnect tcp: tls: first record does not look like a TLS handshake". When trying to test it with curl seems that is working. …

---

## [Runtime: out of memory Multiline filebeats](https://discuss.elastic.co/t/runtime-out-of-memory-multiline-filebeats/232848)

<div class="topic-metadata">

**Author:** [@Thiago\_Paiva](https://discuss.elastic.co/u/Thiago_Paiva)\
**Replies:** 1\
**Last updated:** [May 15, 2020, 7:45pm UTC](https://discuss.elastic.co/t/runtime-out-of-memory-multiline-filebeats/232848 "2020-05-15T19:45:02Z")

</div>

Hi folks, I need help to solve an Out of memory filebeat multiline trouble, following my info about configuration and error. Thanks you for your availability. Version: 7.4.0 Server: Windows Server 2008 Memory: 64 GB …

---

## [ILM filebeat create index by kubernetes namespace](https://discuss.elastic.co/t/ilm-filebeat-create-index-by-kubernetes-namespace/232852)

<div class="topic-metadata">

**Author:** [@melchiormoulin](https://discuss.elastic.co/u/melchiormoulin)\
**Replies:** 0\
**Last updated:** [May 15, 2020, 4:50pm UTC](https://discuss.elastic.co/t/ilm-filebeat-create-index-by-kubernetes-namespace/232852 "2020-05-15T16:50:30Z")

</div>

Hello, What is the best practice to create index by kubernetes namespace with filebeat ILM please ? As it is not possible to put non static variable in setup.ilm.rollover\_alias

---

## [Monitor mupltiple clients](https://discuss.elastic.co/t/monitor-mupltiple-clients/232839)

<div class="topic-metadata">

**Author:** [@stefan-cplanet](https://discuss.elastic.co/u/stefan-cplanet)\
**Replies:** 3\
**Last updated:** [May 15, 2020, 4:02pm UTC](https://discuss.elastic.co/t/monitor-mupltiple-clients/232839 "2020-05-15T16:02:55Z")

</div>

Hello, I am new to Elastic and I got deployment ina network where I have: 1 elastic server ( elastic,kibana,metricbeat... , all on a single instance) 15 LAMP servers. Idea is to monitor them using kibana on the elasti…

---

## [Filebeat field changed type](https://discuss.elastic.co/t/filebeat-field-changed-type/232273)

<div class="topic-metadata">

**Author:** [@KWBrandenWagner](https://discuss.elastic.co/u/KWBrandenWagner)\
**Replies:** 1\
**Last updated:** [May 15, 2020, 3:03pm UTC](https://discuss.elastic.co/t/filebeat-field-changed-type/232273 "2020-05-15T15:03:59Z")

</div>

{"type":"mapper\_parsing\_exception","reason":"Could not dynamically add mapping for field \[id.orig\_p\]. Existing mapping for \[zeek.x509.id\] must be of type object but found \[keyword\]."} Looking at the raw log the entry is…

---

## [Heartbeat tcp port ranges](https://discuss.elastic.co/t/heartbeat-tcp-port-ranges/232377)

<div class="topic-metadata">

**Author:** [@pszemesy](https://discuss.elastic.co/u/pszemesy)\
**Replies:** 1\
**Last updated:** [May 15, 2020, 12:55pm UTC](https://discuss.elastic.co/t/heartbeat-tcp-port-ranges/232377 "2020-05-15T12:55:00Z")

</div>

Hi All, Are there any possibilities to add port ranges in the heartbeat.yml configfile at the tcp section for ports tag? Thanks, Peter

---

## [Custom ingest alongside with IIS module](https://discuss.elastic.co/t/custom-ingest-alongside-with-iis-module/232682)

<div class="topic-metadata">

**Author:** [@Jujule](https://discuss.elastic.co/u/Jujule)\
**Replies:** 4\
**Last updated:** [May 15, 2020, 12:50pm UTC](https://discuss.elastic.co/t/custom-ingest-alongside-with-iis-module/232682 "2020-05-15T12:50:51Z")

</div>

Hi, warning: those are probably some newbie questions. Context: wanting to filebeat some files to ES with ingest pipelines, and IIS logs, from differents files on the same machine. Are the main configuration from file…

---

## [Filebeat - Cisco Module doesn't accept logs from other sources that itsself](https://discuss.elastic.co/t/filebeat-cisco-module-doesnt-accept-logs-from-other-sources-that-itsself/232779)

<div class="topic-metadata">

**Author:** [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Replies:** 0\
**Last updated:** [May 15, 2020, 9:21am UTC](https://discuss.elastic.co/t/filebeat-cisco-module-doesnt-accept-logs-from-other-sources-that-itsself/232779 "2020-05-15T09:21:14Z")

</div>

Hey Guys, i've installed Filebeat on the 2 Data-Nodes in my Elk-Cluster. Some Information on my Cluster: Cluster Version: 7.6 Filebeat Version: 7.7 Hosts: CentOS 7 Now i want to send logs from Cisco Switches to thi…

---

## [Filebeat system module to kafka topic](https://discuss.elastic.co/t/filebeat-system-module-to-kafka-topic/232666)

<div class="topic-metadata">

**Author:** [@ismyhairnice](https://discuss.elastic.co/u/ismyhairnice)\
**Replies:** 4\
**Last updated:** [May 15, 2020, 12:37pm UTC](https://discuss.elastic.co/t/filebeat-system-module-to-kafka-topic/232666 "2020-05-15T12:37:03Z")

</div>

Hi all I have a setup currently sends snort logs to kafka topic and to logstash for ingest. Just wondering if is possible to send Filebeat System module logs to kafka topic ? Regards Yu Feng

---

## [Filebeat GeoIP not working with dotted field](https://discuss.elastic.co/t/filebeat-geoip-not-working-with-dotted-field/232817)

<div class="topic-metadata">

**Author:** [@Bryserker](https://discuss.elastic.co/u/Bryserker)\
**Replies:** 0\
**Last updated:** [May 15, 2020, 12:28pm UTC](https://discuss.elastic.co/t/filebeat-geoip-not-working-with-dotted-field/232817 "2020-05-15T12:28:57Z")

</div>

I'm trying to ingest Windows IIS logs with the Filebeat IIS module. The pipeline that Filebeat has automatically defined for this includes GeoIP lookups, e.g.: "geoip" : { "field" : "source.ip", "target\_f…

---

## [Metricbeat Beat failed to connect es (xpack enabled)](https://discuss.elastic.co/t/metricbeat-beat-failed-to-connect-es-xpack-enabled/230500)

<div class="topic-metadata">

**Author:** [@Paul\_20](https://discuss.elastic.co/u/Paul_20)\
**Replies:** 2\
**Last updated:** [May 15, 2020, 12:25pm UTC](https://discuss.elastic.co/t/metricbeat-beat-failed-to-connect-es-xpack-enabled/230500 "2020-05-15T12:25:33Z")

</div>

Hello Experts, Issue : Unable to connect to elasticsearch, deployed configmap does not contain username: and password input. Background : I have installed Elastic search (XPACK enabled ) and kibana, this combination …

---

## [What is the correct way to handle logs by httpcode?](https://discuss.elastic.co/t/what-is-the-correct-way-to-handle-logs-by-httpcode/231985)

<div class="topic-metadata">

**Author:** [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Replies:** 6\
**Last updated:** [May 15, 2020, 12:06pm UTC](https://discuss.elastic.co/t/what-is-the-correct-way-to-handle-logs-by-httpcode/231985 "2020-05-15T12:06:17Z")

</div>

Hi! In my kubernetes cluster I receive logs of some applications that have this format (specifically ambassador). But I receive these logs inside the "message" field in my Elastic and I cannot easily filter later the m…

---

## [Nginx logs when filebeat and nginx both are running in containers](https://discuss.elastic.co/t/nginx-logs-when-filebeat-and-nginx-both-are-running-in-containers/232810)

<div class="topic-metadata">

**Author:** [@Arun\_Mittal](https://discuss.elastic.co/u/Arun_Mittal)\
**Replies:** 0\
**Last updated:** [May 15, 2020, 11:54am UTC](https://discuss.elastic.co/t/nginx-logs-when-filebeat-and-nginx-both-are-running-in-containers/232810 "2020-05-15T11:54:35Z")

</div>

I am running filebeat and nginx in different containers. nginx is writing logs in a custom path within the container: /config/log/nginx/access.log My compose and filebeat configs: filebeat is not able to read log…

---

## [Filebeat how to get content of field](https://discuss.elastic.co/t/filebeat-how-to-get-content-of-field/232621)

<div class="topic-metadata">

**Author:** [@Lukolas](https://discuss.elastic.co/u/Lukolas)\
**Replies:** 2\
**Last updated:** [May 15, 2020, 11:37am UTC](https://discuss.elastic.co/t/filebeat-how-to-get-content-of-field/232621 "2020-05-15T11:37:14Z")

</div>

Hello I have got a flow from openshift where filebeat get logs from applications and send it to logstash. In logstash i can read value of app name and send logs to dedicated kafka topic. I'm using "%{\[kubernetes\]\[labe…

---

## [Processor add\_kubernetes\_metadata not working](https://discuss.elastic.co/t/processor-add-kubernetes-metadata-not-working/232544)

<div class="topic-metadata">

**Author:** [@iulian7](https://discuss.elastic.co/u/iulian7)\
**Replies:** 3\
**Last updated:** [May 15, 2020, 10:17am UTC](https://discuss.elastic.co/t/processor-add-kubernetes-metadata-not-working/232544 "2020-05-15T10:17:13Z")

</div>

Using Metricbeat 7.7.0 as a sidecar to scrape Prometheus metrics in a Kubernetes (GKE) pod. The configuration is very simple: metricbeat.modules: - module: prometheus period: ${PERIOD} host: ${NODE\_NAME} h…

---

## [Multiple monitoring cycles after recreating docker image](https://discuss.elastic.co/t/multiple-monitoring-cycles-after-recreating-docker-image/231565)

<div class="topic-metadata">

**Author:** [@MichaelM](https://discuss.elastic.co/u/MichaelM)\
**Replies:** 9\
**Last updated:** [May 15, 2020, 9:26am UTC](https://discuss.elastic.co/t/multiple-monitoring-cycles-after-recreating-docker-image/231565 "2020-05-15T09:26:36Z")

</div>

Hi, I am currently monitoring a dockerized service with metricbeat using autodiscover, which works fine so far. The problem: when I deploy a newer version of the service, metricbeat starts an additional monitoring cycl…

---

## [Auditbeat output.file ignores permissions](https://discuss.elastic.co/t/auditbeat-output-file-ignores-permissions/232637)

<div class="topic-metadata">

**Author:** [@vaclav](https://discuss.elastic.co/u/vaclav)\
**Replies:** 2\
**Last updated:** [May 15, 2020, 7:38am UTC](https://discuss.elastic.co/t/auditbeat-output-file-ignores-permissions/232637 "2020-05-15T07:38:00Z")

</div>

Hello, I found in latest auditbeat version 7.7.0 that auditbeat output file is created with permission 640 even if I set output file permission to 644. I have this configuration in auditbeat.yml output.file: path: "…

---

## [Filebeat Multi line file read with Logstash](https://discuss.elastic.co/t/filebeat-multi-line-file-read-with-logstash/232761)

<div class="topic-metadata">

**Author:** [@vaibhav\_morye](https://discuss.elastic.co/u/vaibhav_morye)\
**Replies:** 0\
**Last updated:** [May 15, 2020, 6:30am UTC](https://discuss.elastic.co/t/filebeat-multi-line-file-read-with-logstash/232761 "2020-05-15T06:30:25Z")

</div>

I have a bit of an unconventional log system from some legacy codebase where the log is in a multiline format. Example : Sat May 9 00:00:02 2020 key = value key1 = value1 key2 = value2 key2 = value2 key3 = value…

---

## [Breaking json array into granular events using filebeat script processor](https://discuss.elastic.co/t/breaking-json-array-into-granular-events-using-filebeat-script-processor/232686)

<div class="topic-metadata">

**Author:** [@karthiknpy](https://discuss.elastic.co/u/karthiknpy)\
**Replies:** 2\
**Last updated:** [May 15, 2020, 6:23am UTC](https://discuss.elastic.co/t/breaking-json-array-into-granular-events-using-filebeat-script-processor/232686 "2020-05-15T06:23:59Z")

</div>

Hi Team, I got a crazy thought to split JSON array which filebeat read from redis list input. Then filebeat script processor splits it into granular events and writes to elastic. I know I should be using logstash json…

---

## [GROK pattern troubles](https://discuss.elastic.co/t/grok-pattern-troubles/232747)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 1\
**Last updated:** [May 15, 2020, 6:08am UTC](https://discuss.elastic.co/t/grok-pattern-troubles/232747 "2020-05-15T06:08:09Z")

</div>

I cant seem to find a pattern for this custom log file: CDR|N|05:01:2020 12:00:00:991|TEL|20010|blue02|16285|34|TEL\_InitiateCall|AA\_Rr\_Tenant|blue02-PORT34-0501202011595810:SC:AA\_Rr\_Tenant:7667320521:17663223511:0501202…

---

## [Forever growing registry file](https://discuss.elastic.co/t/forever-growing-registry-file/232736)

<div class="topic-metadata">

**Author:** [@silenceper](https://discuss.elastic.co/u/silenceper)\
**Replies:** 2\
**Last updated:** [May 15, 2020, 4:01am UTC](https://discuss.elastic.co/t/forever-growing-registry-file/232736 "2020-05-15T04:01:18Z")

</div>

filebeat.config.inputs: enabled: true path: configs/\*.yml reload.enabled: true reload.period: 10s After deleting the yaml file from the configs directory, the monitored logs in the registry are not deleted.

---

## [How to delete log states from registry](https://discuss.elastic.co/t/how-to-delete-log-states-from-registry/232737)

<div class="topic-metadata">

**Author:** [@silenceper](https://discuss.elastic.co/u/silenceper)\
**Replies:** 0\
**Last updated:** [May 15, 2020, 3:06am UTC](https://discuss.elastic.co/t/how-to-delete-log-states-from-registry/232737 "2020-05-15T03:06:52Z")

</div>

How to delete log states from the registry file, I found that when filebeat is still running, if you go to an external program to modify the contents of the registry, it will be overwritten by filebeat.

---

## [PANW schema bugs take 2](https://discuss.elastic.co/t/panw-schema-bugs-take-2/232388)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [May 14, 2020, 7:58pm UTC](https://discuss.elastic.co/t/panw-schema-bugs-take-2/232388 "2020-05-14T19:58:38Z")

</div>

Hello, Could someone please take a look at: And confirm this is a bug? This is generating confusion.... As source.bytes and destination.bytes are quite important field in a very important dataset, this should be han…

---

## [MetricBeats || Apache ActiveMq|| Origin null is not allowed](https://discuss.elastic.co/t/metricbeats-apache-activemq-origin-null-is-not-allowed/232191)

<div class="topic-metadata">

**Author:** [@faiz0210](https://discuss.elastic.co/u/faiz0210)\
**Replies:** 4\
**Last updated:** [May 14, 2020, 7:44pm UTC](https://discuss.elastic.co/t/metricbeats-apache-activemq-origin-null-is-not-allowed/232191 "2020-05-14T19:44:21Z")

</div>

Hi Team, Trying to setup metricbeat for ActiveMq, whole installation and configuration process went smooth, but couldn't see any data on Kibana. On further diagnosis, found below information in /var/log/messages. metr…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=247)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=249)
