# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=250

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 251

---

## [Exiting: error initializing processors: the processor add\_id doesn't exist](https://discuss.elastic.co/t/exiting-error-initializing-processors-the-processor-add-id-doesnt-exist/231991)

<div class="topic-metadata">

**Author:** [@XFLaura](https://discuss.elastic.co/u/XFLaura)\
**Replies:** 2\
**Last updated:** [May 12, 2020, 3:34am UTC](https://discuss.elastic.co/t/exiting-error-initializing-processors-the-processor-add-id-doesnt-exist/231991 "2020-05-12T03:34:14Z")

</div>

I get the error "Exiting: error initializing processors: the processor add\_id doesn't exist" when I am trying to add processors: - add\_id: ~

---

## [ECS: Converting winglogbeats for Sysmon/Security to Logstash](https://discuss.elastic.co/t/ecs-converting-winglogbeats-for-sysmon-security-to-logstash/231902)

<div class="topic-metadata">

**Author:** [@elkn00b](https://discuss.elastic.co/u/elkn00b)\
**Replies:** 1\
**Last updated:** [May 11, 2020, 11:36pm UTC](https://discuss.elastic.co/t/ecs-converting-winglogbeats-for-sysmon-security-to-logstash/231902 "2020-05-11T23:36:03Z")

</div>

I'm in the process of converting the winlogbeats javascript to Logstash, and I want to be sure I'm correctly interpreting some of the javascript. In the snip below, is the winlogbeats.js template for Sysmon separating t…

---

## [Beats agent support for SLES11 & 15, Solaris 10 & 11, AIX7 and HP-UX. Any suggestions?](https://discuss.elastic.co/t/beats-agent-support-for-sles11-15-solaris-10-11-aix7-and-hp-ux-any-suggestions/232094)

<div class="topic-metadata">

**Author:** [@spoole](https://discuss.elastic.co/u/spoole)\
**Replies:** 1\
**Last updated:** [May 11, 2020, 11:14pm UTC](https://discuss.elastic.co/t/beats-agent-support-for-sles11-15-solaris-10-11-aix7-and-hp-ux-any-suggestions/232094 "2020-05-11T23:14:06Z")

</div>

I cannot find whether Beats supports or can be made to support and of the O/S's mentioned in the title. Are there any updates or has anyone managed to get the agents to work on the platforms? Thanks

---

## [Filebeat connection refused to logstash](https://discuss.elastic.co/t/filebeat-connection-refused-to-logstash/232049)

<div class="topic-metadata">

**Author:** [@Andre\_Martins](https://discuss.elastic.co/u/Andre_Martins)\
**Replies:** 1\
**Last updated:** [May 11, 2020, 7:12pm UTC](https://discuss.elastic.co/t/filebeat-connection-refused-to-logstash/232049 "2020-05-11T19:12:51Z")

</div>

Hi I'm a newbie, so please bare with me. For couple of days I've been trying to figure out why I can't make logstash to listen to the port 5141. At the conf.d I have 15-dns-syslog.conf beats { port =\> …

---

## [Putting add\_host\_metadata per input](https://discuss.elastic.co/t/putting-add-host-metadata-per-input/232098)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [May 11, 2020, 7:02pm UTC](https://discuss.elastic.co/t/putting-add-host-metadata-per-input/232098 "2020-05-11T19:02:17Z")

</div>

Hello, Is it possible to add the add\_host\_metadata processor in filebeat.yml for specific inputs only? This works: filebeat.inputs: - type: log paths: C:\\Windows\\System32\\LogFiles\\Firewall\\\*.log pipeline: filebeat…

---

## [Is add\_kubernetes\_metadata in filebeat enabled by default?](https://discuss.elastic.co/t/is-add-kubernetes-metadata-in-filebeat-enabled-by-default/232064)

<div class="topic-metadata">

**Author:** [@camilisette](https://discuss.elastic.co/u/camilisette)\
**Replies:** 1\
**Last updated:** [May 11, 2020, 6:30pm UTC](https://discuss.elastic.co/t/is-add-kubernetes-metadata-in-filebeat-enabled-by-default/232064 "2020-05-11T18:30:38Z")

</div>

Just a general question I guess since the documentation wasn't very clear to me. When running Filebeat on Kubernetes as instructed here, https://www.elastic.co/guide/en/beats/filebeat/master/running-on-kubernetes.html …

---

## [Another Drop Event](https://discuss.elastic.co/t/another-drop-event/231024)

<div class="topic-metadata">

**Author:** [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Replies:** 4\
**Last updated:** [May 11, 2020, 5:18pm UTC](https://discuss.elastic.co/t/another-drop-event/231024 "2020-05-11T17:18:50Z")

</div>

Winlogbeat 7.6.1. Really easy drop 2 events is failing. I get hundreds of thousands of these events a day. They consist of 95% of the winlog traffic that is sent to the elastic stack. Copy/Paste which from other threads…

---

## [Filebeat Nginx Module + ModSecurity Audit Log to Same ELK Stack](https://discuss.elastic.co/t/filebeat-nginx-module-modsecurity-audit-log-to-same-elk-stack/232018)

<div class="topic-metadata">

**Author:** [@adlp](https://discuss.elastic.co/u/adlp)\
**Replies:** 3\
**Last updated:** [May 11, 2020, 3:14pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module-modsecurity-audit-log-to-same-elk-stack/232018 "2020-05-11T15:14:26Z")

</div>

In this case I am using a droplet to host django web application. I am serving it by Nginx. Also I have integrated ModSecurity WAF with Nginx. Now I have Nginx Access & Error that I am transmitting through filebeat by en…

---

## [NFS Mount for Solaris Server](https://discuss.elastic.co/t/nfs-mount-for-solaris-server/231738)

<div class="topic-metadata">

**Author:** [@kawalec](https://discuss.elastic.co/u/kawalec)\
**Replies:** 5\
**Last updated:** [May 11, 2020, 2:11pm UTC](https://discuss.elastic.co/t/nfs-mount-for-solaris-server/231738 "2020-05-11T14:11:03Z")

</div>

I have loaded up an Ubuntu Server. NFS mounted directory that hold logs of our glassfish application servers that run on solaris. added filebeats and point to the location of the logs. #=========================== Fi…

---

## [Raspberry Pi 4's CPU temperature monitoring](https://discuss.elastic.co/t/raspberry-pi-4s-cpu-temperature-monitoring/227874)

<div class="topic-metadata">

**Author:** [@ralones](https://discuss.elastic.co/u/ralones)\
**Replies:** 1\
**Last updated:** [May 11, 2020, 12:47pm UTC](https://discuss.elastic.co/t/raspberry-pi-4s-cpu-temperature-monitoring/227874 "2020-05-11T12:47:49Z")

</div>

Hello, Is there a metric set or a way to send the Raspberry Pi's CPU temperature to an ES based Grafana platform using Metricbeat?

---

## [Wowza logs =\> filebeat =\> kibana](https://discuss.elastic.co/t/wowza-logs-filebeat-kibana/231698)

<div class="topic-metadata">

**Author:** [@Jozz](https://discuss.elastic.co/u/Jozz)\
**Replies:** 1\
**Last updated:** [May 11, 2020, 12:42pm UTC](https://discuss.elastic.co/t/wowza-logs-filebeat-kibana/231698 "2020-05-11T12:42:08Z")

</div>

I'm looking into getting our wowza logs in kibana. One of my predecessors has set up our ELK stack. I started filebeat, because it wasn't running on the server. I do see exim4 log entry's in kibana, but nothing related t…

---

## [Equivalent of http input plugin of logstash but for filebeat -\> possible?](https://discuss.elastic.co/t/equivalent-of-http-input-plugin-of-logstash-but-for-filebeat-possible/231922)

<div class="topic-metadata">

**Author:** [@jbisson](https://discuss.elastic.co/u/jbisson)\
**Replies:** 2\
**Last updated:** [May 11, 2020, 12:21pm UTC](https://discuss.elastic.co/t/equivalent-of-http-input-plugin-of-logstash-but-for-filebeat-possible/231922 "2020-05-11T12:21:20Z")

</div>

I would like to have the exact same functionality of the http input plugin offered by logstash. I would like to send data through a Rest API. I've tried to use the tcp input of filebeat but didn't get too much success.…

---

## [Droping winlog.event\_data.LogonType: "3"](https://discuss.elastic.co/t/droping-winlog-event-data-logontype-3/231883)

<div class="topic-metadata">

**Author:** [@kubekpk](https://discuss.elastic.co/u/kubekpk)\
**Replies:** 2\
**Last updated:** [May 11, 2020, 11:27am UTC](https://discuss.elastic.co/t/droping-winlog-event-data-logontype-3/231883 "2020-05-11T11:27:49Z")

</div>

Hello, Starting with ELK ,I'm trying to drop the following event without success winlog.event\_data.LogonType: "3" Can someone help? - name: Security ignore\_older: 24h event\_id: 4624, 4625, 7045, 4758, 4743, 4734, 4…

---

## [Apache module and var.paths not working](https://discuss.elastic.co/t/apache-module-and-var-paths-not-working/231725)

<div class="topic-metadata">

**Author:** [@Hausmeister](https://discuss.elastic.co/u/Hausmeister)\
**Replies:** 3\
**Last updated:** [May 11, 2020, 5:48am UTC](https://discuss.elastic.co/t/apache-module-and-var-paths-not-working/231725 "2020-05-11T05:48:11Z")

</div>

All, I'm facing an issue with the apache module paths variable. When enabling the module without any customization, filebeat starts as expected sending the default access-log and error.log files to a logstash/eleastic …

---

## [Can't rename index](https://discuss.elastic.co/t/cant-rename-index/229448)

<div class="topic-metadata">

**Author:** [@My\_Google\_Account](https://discuss.elastic.co/u/My_Google_Account)\
**Replies:** 5\
**Last updated:** [May 10, 2020, 3:39pm UTC](https://discuss.elastic.co/t/cant-rename-index/229448 "2020-05-10T15:39:08Z")

</div>

Good day! i using elasticsearch & kibana & filebeat agent latest versions, and i can't setup index name, every time the index call "filebeat-7.6.2" and i don't understand why... i tried setup my agent from the documentat…

---

## [Create an index with log.file.path field](https://discuss.elastic.co/t/create-an-index-with-log-file-path-field/231789)

<div class="topic-metadata">

**Author:** [@Burak\_Cayir](https://discuss.elastic.co/u/Burak_Cayir)\
**Replies:** 2\
**Last updated:** [May 10, 2020, 1:34pm UTC](https://discuss.elastic.co/t/create-an-index-with-log-file-path-field/231789 "2020-05-10T13:34:23Z")

</div>

Hello , Is it possible to create an index in Filebeat ? My example config doesn't work : output.elasticsearch: hosts: \["https://localhost:9200"\] index: "%{\[log.file.path\]}"

---

## [Unable to drop field from aws module](https://discuss.elastic.co/t/unable-to-drop-field-from-aws-module/231845)

<div class="topic-metadata">

**Author:** [@Ronin](https://discuss.elastic.co/u/Ronin)\
**Replies:** 1\
**Last updated:** [May 10, 2020, 1:26pm UTC](https://discuss.elastic.co/t/unable-to-drop-field-from-aws-module/231845 "2020-05-10T13:26:51Z")

</div>

I have the following config: filebeat.modules: - module: aws cloudtrail: enabled: true var.queue\_url: https://sqs.us-east-1.amazonaws.com/xxxxxxx/yyyyyyyyy cloudwatch: enabled: false ec2: enabled: …

---

## [Winlogbeat data is not parsing properly](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820)

<div class="topic-metadata">

**Author:** [@sundar\_elk](https://discuss.elastic.co/u/sundar_elk)\
**Replies:** 8\
**Last updated:** [May 10, 2020, 7:03am UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820 "2020-05-10T07:03:17Z")

</div>

Hi Team, I'm using winlogbeat for pushing all windows events to elasticsearch. Parsing is not happening properly. One of the examples is under “Message” there is “Properties” which when parsed in winlog.event\_data.Pro…

---

## [Separate process setup and write winlogbeat](https://discuss.elastic.co/t/separate-process-setup-and-write-winlogbeat/231733)

<div class="topic-metadata">

**Author:** [@orsa](https://discuss.elastic.co/u/orsa)\
**Replies:** 1\
**Last updated:** [May 9, 2020, 9:57pm UTC](https://discuss.elastic.co/t/separate-process-setup-and-write-winlogbeat/231733 "2020-05-09T21:57:09Z")

</div>

Hi I probably do not understand correctly what parameters should be in the configuration files when separating the installation process and writing data. Please help me understand how it works correctly my setup YML f…

---

## [Beats on Raspberry Pi 4/4g](https://discuss.elastic.co/t/beats-on-raspberry-pi-4-4g/231814)

<div class="topic-metadata">

**Author:** [@Rainbird](https://discuss.elastic.co/u/Rainbird)\
**Replies:** 2\
**Last updated:** [May 9, 2020, 4:36pm UTC](https://discuss.elastic.co/t/beats-on-raspberry-pi-4-4g/231814 "2020-05-09T16:36:00Z")

</div>

It has been a few months since this topic has come up. I thought I would ask here before starting what looks like will be a difficult slog. I would like to run filebeats on a Raspberry Pi to take in data from a bunch o…

---

## [Make: \*\*\* No rule to make target \`setup'. Stop.- Custom beat](https://discuss.elastic.co/t/make-no-rule-to-make-target-setup-stop-custom-beat/229231)

<div class="topic-metadata">

**Author:** [@visasimbu](https://discuss.elastic.co/u/visasimbu)\
**Replies:** 2\
**Last updated:** [May 5, 2020, 8:51pm UTC](https://discuss.elastic.co/t/make-no-rule-to-make-target-setup-stop-custom-beat/229231 "2020-05-05T20:51:29Z")

</div>

I am able to create custom beat and build (mage build) as per the documentation. But I am getting below error while executing make setup. Documentation is here. \[user@machineName test3\]$ make setup make: \*\*\* No rule to …

---

## [Macro for Beats version?](https://discuss.elastic.co/t/macro-for-beats-version/231822)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [May 9, 2020, 7:47am UTC](https://discuss.elastic.co/t/macro-for-beats-version/231822 "2020-05-09T07:47:37Z")

</div>

Hello, As I'm putting some stuff, such as dashboards in directories containing the version, it would be useful if I could use some sort of macro for this. For this a Beat would need to be aware of it's own version. The…

---

## [Kibana is showing only the first line of the txt log file](https://discuss.elastic.co/t/kibana-is-showing-only-the-first-line-of-the-txt-log-file/231542)

<div class="topic-metadata">

**Author:** [@meniem](https://discuss.elastic.co/u/meniem)\
**Replies:** 2\
**Last updated:** [May 8, 2020, 10:39pm UTC](https://discuss.elastic.co/t/kibana-is-showing-only-the-first-line-of-the-txt-log-file/231542 "2020-05-08T22:39:30Z")

</div>

I need to ship logs from 2 apps into ElasticSearch/Kibana, one of them is a Symfony app that generates logs in /var/www/html/logs/\*.log and they are displayed in the correct format on ES/Kibana. While the other is a Node…

---

## [How to use filebeat copy\_fields processor with data computed later (netflow received data and geo computed data)?](https://discuss.elastic.co/t/how-to-use-filebeat-copy-fields-processor-with-data-computed-later-netflow-received-data-and-geo-computed-data/231799)

<div class="topic-metadata">

**Author:** [@Jorge\_Correa](https://discuss.elastic.co/u/Jorge_Correa)\
**Replies:** 0\
**Last updated:** [May 8, 2020, 8:33pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-copy-fields-processor-with-data-computed-later-netflow-received-data-and-geo-computed-data/231799 "2020-05-08T20:33:57Z")

</div>

I'm using filebeat with netflow module, so I'm receiving netflow data and inserting in elasticsearch. All netflow fields are described here: https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-netflow…

---

## [Metricbeat authentication](https://discuss.elastic.co/t/metricbeat-authentication/228055)

<div class="topic-metadata">

**Author:** [@ranjan300](https://discuss.elastic.co/u/ranjan300)\
**Replies:** 6\
**Last updated:** [May 8, 2020, 5:41pm UTC](https://discuss.elastic.co/t/metricbeat-authentication/228055 "2020-05-08T17:41:05Z")

</div>

is it possible to use aws iam roles instead of aws credentials (access key and secret key) for authentication. Can anyone please help me.

---

## [Filebeat unable to send data to logstash which results in empty data in elastic & kibana](https://discuss.elastic.co/t/filebeat-unable-to-send-data-to-logstash-which-results-in-empty-data-in-elastic-kibana/230918)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 5\
**Last updated:** [May 8, 2020, 3:03pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-send-data-to-logstash-which-results-in-empty-data-in-elastic-kibana/230918 "2020-05-08T15:03:27Z")

</div>

I am trying to deploy ELK stack in openshift platform (OKD - v3.11) and using filebeat to automatically detect the logs. ELK stack versions: FIlebeat - 6.4.1 Logstash - 6.3.1 elastic - 6.5.4 & kibana - 6.5.4 Please…

---

## [Unable to get logs from filebeats to logstash](https://discuss.elastic.co/t/unable-to-get-logs-from-filebeats-to-logstash/231726)

<div class="topic-metadata">

**Author:** [@gkvganesh](https://discuss.elastic.co/u/gkvganesh)\
**Replies:** 1\
**Last updated:** [May 8, 2020, 1:05pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-from-filebeats-to-logstash/231726 "2020-05-08T13:05:25Z")

</div>

I have installed Filebeat in server A (linux server) to send logs to server B (CentOS server). Server B has Elastic, logstash and kibana installed. I followed the steps to configure logstash output in filebeat.yml from t…

---

## [Adding to security module the parse of event.id equals to 4663](https://discuss.elastic.co/t/adding-to-security-module-the-parse-of-event-id-equals-to-4663/231488)

<div class="topic-metadata">

**Author:** [@Aleix\_Abrie\_Prat](https://discuss.elastic.co/u/Aleix_Abrie_Prat)\
**Replies:** 2\
**Last updated:** [May 8, 2020, 11:03am UTC](https://discuss.elastic.co/t/adding-to-security-module-the-parse-of-event-id-equals-to-4663/231488 "2020-05-08T11:03:42Z")

</div>

Hello everyone, I want to have control of file access using Winlogbeat with parsing event with id 4663... I am modifying the "security" module so that it can read the events with that id. I have seen that there is a va…

---

## [Palo Alto Leef type logs (panw)](https://discuss.elastic.co/t/palo-alto-leef-type-logs-panw/231664)

<div class="topic-metadata">

**Author:** [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)\
**Replies:** 2\
**Last updated:** [May 8, 2020, 10:43am UTC](https://discuss.elastic.co/t/palo-alto-leef-type-logs-panw/231664 "2020-05-08T10:43:45Z")

</div>

Hi, I am getting logs of palo alto in leef format on a udp port. I tried to parsed the data with default module in filebeat panw and also tried with cef module, but couldn't able to parse it. Is there any other way fr…

---

## [The packet bit allows MySQL to recognize some requests from Spring Boot](https://discuss.elastic.co/t/the-packet-bit-allows-mysql-to-recognize-some-requests-from-spring-boot/231690)

<div class="topic-metadata">

**Author:** [@111332](https://discuss.elastic.co/u/111332)\
**Replies:** 0\
**Last updated:** [May 8, 2020, 9:26am UTC](https://discuss.elastic.co/t/the-packet-bit-allows-mysql-to-recognize-some-requests-from-spring-boot/231690 "2020-05-08T09:26:57Z")

</div>

Hi, I am Sorry, My English is not good， Please understand。 My settings My PC: WEB Browser Server1: Packetbeat, Spring Boot Server Server2: Mysql Server Server3: Elastic search, Kibana I set it as above. When a web…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=249)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=251)
