# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=249

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 250

---

## [Collect logs for specific containers or namespace in Openshift/Kubernetes](https://discuss.elastic.co/t/collect-logs-for-specific-containers-or-namespace-in-openshift-kubernetes/232417)

<div class="topic-metadata">

**Author:** [@sayeedc](https://discuss.elastic.co/u/sayeedc)\
**Replies:** 1\
**Last updated:** [May 14, 2020, 7:12pm UTC](https://discuss.elastic.co/t/collect-logs-for-specific-containers-or-namespace-in-openshift-kubernetes/232417 "2020-05-14T19:12:29Z")

</div>

Can filebeat daemonsets be configured to: Collect logs for specific pods in a namespace and nothing else. Collect logs for all pods in specific namespaces and nothing else. I want to avoid filebeat picking up all cont…

---

## [Unable to setup dashboard on Kibana from Beats](https://discuss.elastic.co/t/unable-to-setup-dashboard-on-kibana-from-beats/232605)

<div class="topic-metadata">

**Author:** [@Atul\_Gunjal](https://discuss.elastic.co/u/Atul_Gunjal)\
**Replies:** 1\
**Last updated:** [May 14, 2020, 7:00pm UTC](https://discuss.elastic.co/t/unable-to-setup-dashboard-on-kibana-from-beats/232605 "2020-05-14T19:00:17Z")

</div>

Showing error while loading dashboard to kibana using .\\metricbeat.exe setup --dashboards Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://7147ccb65b60479190c4a7918017a4a…

---

## [Integrity issue between Winlogbeat and Logstash (Fingerprint)](https://discuss.elastic.co/t/integrity-issue-between-winlogbeat-and-logstash-fingerprint/232654)

<div class="topic-metadata">

**Author:** [@JeanN](https://discuss.elastic.co/u/JeanN)\
**Replies:** 1\
**Last updated:** [May 14, 2020, 6:57pm UTC](https://discuss.elastic.co/t/integrity-issue-between-winlogbeat-and-logstash-fingerprint/232654 "2020-05-14T18:57:07Z")

</div>

Hi, I'm trying to test the integrity between winlogbeat and logstash with the fingerprint module. But when i saw the log from Kibana those two fingerprint (hash) are different. My logstash configuration: filter { …

---

## [Problem with Auditbeat system host dashboard](https://discuss.elastic.co/t/problem-with-auditbeat-system-host-dashboard/232693)

<div class="topic-metadata">

**Author:** [@andywt123](https://discuss.elastic.co/u/andywt123)\
**Replies:** 2\
**Last updated:** [May 14, 2020, 6:56pm UTC](https://discuss.elastic.co/t/problem-with-auditbeat-system-host-dashboard/232693 "2020-05-14T18:56:14Z")

</div>

I am testing auditbeat on three hosts. The Auditbeat system host dashboard only shows a host count of 1. The host list has all 3 hosts. Why is host count only 1? How do I troubleshoot or investigate further. I am runing…

---

## [Event.Original](https://discuss.elastic.co/t/event-original/232658)

<div class="topic-metadata">

**Author:** [@JeanN](https://discuss.elastic.co/u/JeanN)\
**Replies:** 1\
**Last updated:** [May 14, 2020, 5:25pm UTC](https://discuss.elastic.co/t/event-original/232658 "2020-05-14T17:25:34Z")

</div>

Hi, I'm trying to get "event.original" field from "\_source" field but i don't suceed to get it on the winlogbeat conf. Is someone have a solution to get it ? Thanks.

---

## [Panw Schema Bugs in Bytes Sent/Received and Packets Sent/Received](https://discuss.elastic.co/t/panw-schema-bugs-in-bytes-sent-received-and-packets-sent-received/208090)

<div class="topic-metadata">

**Author:** [@davidhowell.tx](https://discuss.elastic.co/u/davidhowell.tx)\
**Replies:** 2\
**Last updated:** [May 14, 2020, 5:19pm UTC](https://discuss.elastic.co/t/panw-schema-bugs-in-bytes-sent-received-and-packets-sent-received/208090 "2020-05-14T17:19:56Z")

</div>

There are some inconsistencies in the way the bytes sent/received and packets sent/received are being mapped in the panw module for filebeat. According to ECS the traditional "bytes\_sent" would be mapped to "client.bytes…

---

## [Elastic SIEM No Failed Authentications](https://discuss.elastic.co/t/elastic-siem-no-failed-authentications/231344)

<div class="topic-metadata">

**Author:** [@wilfyboyGG](https://discuss.elastic.co/u/wilfyboyGG)\
**Replies:** 6\
**Last updated:** [May 14, 2020, 1:42pm UTC](https://discuss.elastic.co/t/elastic-siem-no-failed-authentications/231344 "2020-05-14T13:42:00Z")

</div>

Hello Community! I'm Exploring ELK as a SIEM. As a beginner I have Winlogbea installed on a virtual machine that's subscribed to forwarded events from Domain Controller. I've made subsequent changes to the YML file and …

---

## [Issue with auditbeat 7.6.2 Dashboards](https://discuss.elastic.co/t/issue-with-auditbeat-7-6-2-dashboards/231377)

<div class="topic-metadata">

**Author:** [@karthiknpy](https://discuss.elastic.co/u/karthiknpy)\
**Replies:** 6\
**Last updated:** [May 14, 2020, 12:56pm UTC](https://discuss.elastic.co/t/issue-with-auditbeat-7-6-2-dashboards/231377 "2020-05-14T12:56:15Z")

</div>

I have an elastic cloud instance, I'm trying to setup auditbeat for some threat hunting purposes I have installed auditbeat on a Linux server Enabled the below datasets hosts login package process socket user s…

---

## [Need to use the function of filebeat output to syslog](https://discuss.elastic.co/t/need-to-use-the-function-of-filebeat-output-to-syslog/232562)

<div class="topic-metadata">

**Author:** [@changgq](https://discuss.elastic.co/u/changgq)\
**Replies:** 0\
**Last updated:** [May 14, 2020, 6:51am UTC](https://discuss.elastic.co/t/need-to-use-the-function-of-filebeat-output-to-syslog/232562 "2020-05-14T06:51:31Z")

</div>

I hope to use filebeat to output logs to the syslog system. Currently, filebeat still does not support this output method. I have implemented this feature, but every new version has to be recompiled, and I hope to contri…

---

## [Duplicate entries with Winlogbeat with WEF](https://discuss.elastic.co/t/duplicate-entries-with-winlogbeat-with-wef/231909)

<div class="topic-metadata">

**Author:** [@NightSpark](https://discuss.elastic.co/u/NightSpark)\
**Replies:** 3\
**Last updated:** [May 13, 2020, 10:42pm UTC](https://discuss.elastic.co/t/duplicate-entries-with-winlogbeat-with-wef/231909 "2020-05-13T22:42:35Z")

</div>

Hi New to elasticsearch and have just setup Winlogbeat on a central Windows 2008 R2 server which is collecting windows events from machines using Windows Event Forwarding I am using V 7.6.2 of elasticsearch and winlogb…

---

## [I want to run two multiline pattern using filebeat](https://discuss.elastic.co/t/i-want-to-run-two-multiline-pattern-using-filebeat/232467)

<div class="topic-metadata">

**Author:** [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)\
**Replies:** 0\
**Last updated:** [May 13, 2020, 3:15pm UTC](https://discuss.elastic.co/t/i-want-to-run-two-multiline-pattern-using-filebeat/232467 "2020-05-13T15:15:27Z")

</div>

Hi, I have an application log, I am reading logs from filebeat and forwarding it to logstash. But I have log in 2 different type of multiline patterns. One is for request begin - to - response end, and in between it ha…

---

## [Try to take only log from on application](https://discuss.elastic.co/t/try-to-take-only-log-from-on-application/232256)

<div class="topic-metadata">

**Author:** [@Roms](https://discuss.elastic.co/u/Roms)\
**Replies:** 3\
**Last updated:** [May 13, 2020, 11:44am UTC](https://discuss.elastic.co/t/try-to-take-only-log-from-on-application/232256 "2020-05-13T11:44:24Z")

</div>

Hello everyone, I can catch every log from the computer but I just want the log from one application. I try to make that with the processors on Winlogbeat. It's is possible ? Did I have to do that with a filter on Log…

---

## [Filebeat deal json logs](https://discuss.elastic.co/t/filebeat-deal-json-logs/232412)

<div class="topic-metadata">

**Author:** [@loveyang2012](https://discuss.elastic.co/u/loveyang2012)\
**Replies:** 0\
**Last updated:** [May 13, 2020, 10:14am UTC](https://discuss.elastic.co/t/filebeat-deal-json-logs/232412 "2020-05-13T10:14:08Z")

</div>

I have a log like this: {"log":"13/May/2020:10:09:34 +0000 10.244.5.1 GET /storeback/companyInfo/getCompanyInfoAndQualificationToInfo HTTP/1.1 200 9349 0.043","stream":"stdout","time":"2020-05-13T10:09:34.921821872Z"} …

---

## [Could not get host ID](https://discuss.elastic.co/t/could-not-get-host-id/232401)

<div class="topic-metadata">

**Author:** [@mr-who](https://discuss.elastic.co/u/mr-who)\
**Replies:** 0\
**Last updated:** [May 13, 2020, 9:28am UTC](https://discuss.elastic.co/t/could-not-get-host-id/232401 "2020-05-13T09:28:48Z")

</div>

On some systems with CentOS 6.10 i got warning message WARN \[system\] system/system.go:64 Could not get host ID, will not fill entity\_id fields. Error: \<nil\> Have no idea why it tells so.

---

## [GitLab tracking User-Authetications](https://discuss.elastic.co/t/gitlab-tracking-user-authetications/231316)

<div class="topic-metadata">

**Author:** [@nkellner](https://discuss.elastic.co/u/nkellner)\
**Replies:** 4\
**Last updated:** [May 13, 2020, 9:17am UTC](https://discuss.elastic.co/t/gitlab-tracking-user-authetications/231316 "2020-05-13T09:17:13Z")

</div>

we are using FlieBeat to get teh GitLab-LogFiles. In this Logs the User-Action is given. Do you have any idea how we can handle it in a right way? What we need is only the state of Userlogins (acepted or denied). Tha…

---

## [Metricset mongodb.replstatus only work on primary server](https://discuss.elastic.co/t/metricset-mongodb-replstatus-only-work-on-primary-server/232045)

<div class="topic-metadata">

**Author:** [@dbargo](https://discuss.elastic.co/u/dbargo)\
**Replies:** 1\
**Last updated:** [May 13, 2020, 9:15am UTC](https://discuss.elastic.co/t/metricset-mongodb-replstatus-only-work-on-primary-server/232045 "2020-05-13T09:15:06Z")

</div>

We deploy metricbeat on 3 mongo servers ( 1 primary, 2 secondary ) While metricbeat run on secondary server we get the following error: Error fetching data for metricset mongodb.replstatus: error getting replication in…

---

## [Filebeat Multiple input filter and send to multiple indexes](https://discuss.elastic.co/t/filebeat-multiple-input-filter-and-send-to-multiple-indexes/232394)

<div class="topic-metadata">

**Author:** [@Gokul\_Kandasamy](https://discuss.elastic.co/u/Gokul_Kandasamy)\
**Replies:** 0\
**Last updated:** [May 13, 2020, 8:44am UTC](https://discuss.elastic.co/t/filebeat-multiple-input-filter-and-send-to-multiple-indexes/232394 "2020-05-13T08:44:55Z")

</div>

Hi All, I Have multiple types of all log in a file {z: "a", "id: "x", "name": "Y", "source": "app-name"} {log: "a", "id: "x", "name": "Y", "amt": 100} I want to filter the logs and send them to different elastic sear…

---

## [Does heartbeat have the ability to capture response headers directly?](https://discuss.elastic.co/t/does-heartbeat-have-the-ability-to-capture-response-headers-directly/231337)

<div class="topic-metadata">

**Author:** [@tholfie](https://discuss.elastic.co/u/tholfie)\
**Replies:** 2\
**Last updated:** [May 13, 2020, 7:22am UTC](https://discuss.elastic.co/t/does-heartbeat-have-the-ability-to-capture-response-headers-directly/231337 "2020-05-13T07:22:49Z")

</div>

Hello, I'm currently wondering if Heartbeat has the ability to capture response headers instead of just checking for them, i.e. the event of heartbeat checking an url and then parsing the response headers to elastic. I…

---

## [Logs with time difference only in seconds not ordered properly](https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734)

<div class="topic-metadata">

**Author:** [@haneefh](https://discuss.elastic.co/u/haneefh)\
**Replies:** 5\
**Last updated:** [May 13, 2020, 7:11am UTC](https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734 "2020-05-13T07:11:34Z")

</div>

I am using filebeats to send logs. When log events with time differnce only in seconds do not appear properly in kibana. Below is my filbeat configuration. The latest logs appear first as of now in kibana, but for logs w…

---

## [Functionbeat lambda timeout on aws elasticsearch connection](https://discuss.elastic.co/t/functionbeat-lambda-timeout-on-aws-elasticsearch-connection/230269)

<div class="topic-metadata">

**Author:** [@mnlth](https://discuss.elastic.co/u/mnlth)\
**Replies:** 10\
**Last updated:** [May 12, 2020, 10:30pm UTC](https://discuss.elastic.co/t/functionbeat-lambda-timeout-on-aws-elasticsearch-connection/230269 "2020-05-12T22:30:53Z")

</div>

I have functionbeat lambda deployed with cloudwatch triggers which works fine. When lambda streams logs to elasticsearch, I get Connecting to backoff(elasticsearch( https://escluster.es.amazonaws.com:9200 )) using htt…

---

## [Log file missing](https://discuss.elastic.co/t/log-file-missing/232296)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 1\
**Last updated:** [May 12, 2020, 8:25pm UTC](https://discuss.elastic.co/t/log-file-missing/232296 "2020-05-12T20:25:47Z")

</div>

I've noticed that a file is missing from my Kibana dashboard - /var/log/tallylog. How can I figure out why this file is not being populated into my dashboard?

---

## [AWS through Proxy](https://discuss.elastic.co/t/aws-through-proxy/232022)

<div class="topic-metadata">

**Author:** [@spike83](https://discuss.elastic.co/u/spike83)\
**Replies:** 7\
**Last updated:** [May 12, 2020, 1:18pm UTC](https://discuss.elastic.co/t/aws-through-proxy/232022 "2020-05-12T13:18:28Z")

</div>

Hi, How can I add a proxy setting the the AWS module to get to the outside world? I appear to run into issues using the system variable https\_proxy when outputting to elastic internally, I can either get to AWS and not …

---

## [Configuring metricbeat to collect Kubernetes metrics](https://discuss.elastic.co/t/configuring-metricbeat-to-collect-kubernetes-metrics/232221)

<div class="topic-metadata">

**Author:** [@aman97](https://discuss.elastic.co/u/aman97)\
**Replies:** 0\
**Last updated:** [May 12, 2020, 11:49am UTC](https://discuss.elastic.co/t/configuring-metricbeat-to-collect-kubernetes-metrics/232221 "2020-05-12T11:49:53Z")

</div>

Hi Everyone I am configuring metric beat to collect Kubernetes logs , I am using below config apiVersion: v1 kind: ConfigMap metadata: name: metricbeat-config namespace: kube-system labels: app: metricbeat data: …

---

## [\[Filebeat 7.6.2\] Could not locate that index-pattern-field (id: source.geo.location)](https://discuss.elastic.co/t/filebeat-7-6-2-could-not-locate-that-index-pattern-field-id-source-geo-location/232207)

<div class="topic-metadata">

**Author:** [@statiksof](https://discuss.elastic.co/u/statiksof)\
**Replies:** 0\
**Last updated:** [May 12, 2020, 10:54am UTC](https://discuss.elastic.co/t/filebeat-7-6-2-could-not-locate-that-index-pattern-field-id-source-geo-location/232207 "2020-05-12T10:54:48Z")

</div>

Hi, I am using the Apache module (Filebeat 7.6.2) with a customized index name. After some modifications, almost all visualizations are working except the "Unique IPs map \[Filebeat Apache\] ECS". It returns: Could not l…

---

## [Docker Autodiscover AWS ECS](https://discuss.elastic.co/t/docker-autodiscover-aws-ecs/232179)

<div class="topic-metadata">

**Author:** [@Gavin\_Hardy](https://discuss.elastic.co/u/Gavin_Hardy)\
**Replies:** 0\
**Last updated:** [May 12, 2020, 9:35am UTC](https://discuss.elastic.co/t/docker-autodiscover-aws-ecs/232179 "2020-05-12T09:35:06Z")

</div>

Hello, I am trying to setup autodiscover in docker, to only push locks from containers with a specified label. However, it appears to still be pushing all container logs. here is my filebeat.yml providers: - type…

---

## [Filebeat white/black list for container logs in kubernetes](https://discuss.elastic.co/t/filebeat-white-black-list-for-container-logs-in-kubernetes/230854)

<div class="topic-metadata">

**Author:** [@Vahid\_Mouasvi](https://discuss.elastic.co/u/Vahid_Mouasvi)\
**Replies:** 7\
**Last updated:** [May 12, 2020, 8:58am UTC](https://discuss.elastic.co/t/filebeat-white-black-list-for-container-logs-in-kubernetes/230854 "2020-05-12T08:58:42Z")

</div>

Hi, I have a kubernetes cluster with 3 nodes and I installed and uped filebeat 7.6 for shipping logs from our containers from the cluster with this link configuration. I wanna exclude some containers or pods from loggin…

---

## [Filebeat and ECS](https://discuss.elastic.co/t/filebeat-and-ecs/231429)

<div class="topic-metadata">

**Author:** [@edmond.qiu](https://discuss.elastic.co/u/edmond.qiu)\
**Replies:** 7\
**Last updated:** [May 12, 2020, 8:50am UTC](https://discuss.elastic.co/t/filebeat-and-ecs/231429 "2020-05-12T08:50:42Z")

</div>

Hey guys, We currently have filebeat running parallel with other ecs tasks in our ecs cluster. Each filebeat logs data from /var/lib/dockers/containers//.log and sends them to our elasticsearch and ultimately shows up i…

---

## [Socket\_summary and linux user namespace](https://discuss.elastic.co/t/socket-summary-and-linux-user-namespace/232160)

<div class="topic-metadata">

**Author:** [@Mads\_Jon\_Nielsen](https://discuss.elastic.co/u/Mads_Jon_Nielsen)\
**Replies:** 0\
**Last updated:** [May 12, 2020, 7:59am UTC](https://discuss.elastic.co/t/socket-summary-and-linux-user-namespace/232160 "2020-05-12T07:59:58Z")

</div>

Hey there. I'm running a docker swarm stack in production, and was having some issues with too many sockets being created back and forth and sockets hanging in TIME\_WAIT etc. etc. I thought that socket\_summary included …

---

## [Filebeat loss log data](https://discuss.elastic.co/t/filebeat-loss-log-data/232158)

<div class="topic-metadata">

**Author:** [@yuqibin](https://discuss.elastic.co/u/yuqibin)\
**Replies:** 0\
**Last updated:** [May 12, 2020, 7:54am UTC](https://discuss.elastic.co/t/filebeat-loss-log-data/232158 "2020-05-12T07:54:59Z")

</div>

Filebeat not collect file which has being marked inactived. But the file is always update intime. We use filebeat to collect application's log to logstash. config: filebeat.inputs: - type: log enable…

---

## [Creating watcher on windows event id 4625 with multiple conditions](https://discuss.elastic.co/t/creating-watcher-on-windows-event-id-4625-with-multiple-conditions/231851)

<div class="topic-metadata">

**Author:** [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)\
**Replies:** 3\
**Last updated:** [May 12, 2020, 7:11am UTC](https://discuss.elastic.co/t/creating-watcher-on-windows-event-id-4625-with-multiple-conditions/231851 "2020-05-12T07:11:26Z")

</div>

Hi, I want to create alert for Windows Security Event Log and when the event matches EventID (custom) is any of 4625 and when at least 3 events are seen with the same Username in 24 hour(s). Here is my watcher. { …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=248)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=250)
