# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=253

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 254

---

## [Disable metricbeat categories](https://discuss.elastic.co/t/disable-metricbeat-categories/230623)

<div class="topic-metadata">

**Author:** [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Replies:** 1\
**Last updated:** [May 4, 2020, 10:50am UTC](https://discuss.elastic.co/t/disable-metricbeat-categories/230623 "2020-05-04T10:50:36Z")

</div>

Hello, We have metricbeat 7.6 on Centos 7 hosts, we are getting all kinds of metrics Is there a way to turn off certain metrics that I dont need for example CouchDB, Apache, AWS, Ceph, Redis, Traefik, etc Im only inte…

---

## [Install Istio beta module in metricbeat docker image?](https://discuss.elastic.co/t/install-istio-beta-module-in-metricbeat-docker-image/230746)

<div class="topic-metadata">

**Author:** [@Jesse\_Bye](https://discuss.elastic.co/u/Jesse_Bye)\
**Replies:** 1\
**Last updated:** [May 4, 2020, 10:31am UTC](https://discuss.elastic.co/t/install-istio-beta-module-in-metricbeat-docker-image/230746 "2020-05-04T10:31:34Z")

</div>

We are using the official 7.6.2 metricbeat docker image, but the Istio beta module isn't present in that image. We'd like to try out that module; what's the best way to add it? Do we need to build a custom docker image?

---

## [Metricbeat error Cannot connect to Docker Daemon](https://discuss.elastic.co/t/metricbeat-error-cannot-connect-to-docker-daemon/230747)

<div class="topic-metadata">

**Author:** [@eemtzc](https://discuss.elastic.co/u/eemtzc)\
**Replies:** 1\
**Last updated:** [May 4, 2020, 10:24am UTC](https://discuss.elastic.co/t/metricbeat-error-cannot-connect-to-docker-daemon/230747 "2020-05-04T10:24:19Z")

</div>

Hello, I have a ES cluster with 4 data nodes and 3 masternodes. I installed metricbeat on datanode 1 and configured the system module. Started metricbeat on this node and everything worked fine with no issues. Attempte…

---

## [Having troubles installing Heartbeat on AKS](https://discuss.elastic.co/t/having-troubles-installing-heartbeat-on-aks/228216)

<div class="topic-metadata">

**Author:** [@nfsouzaj](https://discuss.elastic.co/u/nfsouzaj)\
**Replies:** 7\
**Last updated:** [May 4, 2020, 9:20am UTC](https://discuss.elastic.co/t/having-troubles-installing-heartbeat-on-aks/228216 "2020-05-04T09:20:24Z")

</div>

Hello, I've been trying pretty hard to install heartbeat but so far aint working. All our Elasticsearch stack is being installed through helm charts successfully. Apparently heartbeat doesn't have an official helm char…

---

## [Error while creating custom beat in Windows environment](https://discuss.elastic.co/t/error-while-creating-custom-beat-in-windows-environment/230916)

<div class="topic-metadata">

**Author:** [@PrabhuThav](https://discuss.elastic.co/u/PrabhuThav)\
**Replies:** 0\
**Last updated:** [May 4, 2020, 3:27am UTC](https://discuss.elastic.co/t/error-while-creating-custom-beat-in-windows-environment/230916 "2020-05-04T03:27:57Z")

</div>

Hi, I tried to develop a custom beat following the instruction given in the document https://www.elastic.co/guide/en/beats/devguide/current/new-beat.html mage GenerateCustomBeat is throwing error and not creating the so…

---

## [Automation Anywhere BOTS Logs Visualization using Kibana](https://discuss.elastic.co/t/automation-anywhere-bots-logs-visualization-using-kibana/230911)

<div class="topic-metadata">

**Author:** [@hem\_sai\_chand](https://discuss.elastic.co/u/hem_sai_chand)\
**Replies:** 1\
**Last updated:** [May 4, 2020, 2:53am UTC](https://discuss.elastic.co/t/automation-anywhere-bots-logs-visualization-using-kibana/230911 "2020-05-04T02:53:21Z")

</div>

Hello techies, We would like to visualize our Automation anywehere bots using Kibana. Bots usually generates different types of logs with good amount of information. This could be a great oppurtunity for me disscuss and…

---

## [Missing field](https://discuss.elastic.co/t/missing-field/230760)

<div class="topic-metadata">

**Author:** [@edvrfn](https://discuss.elastic.co/u/edvrfn)\
**Replies:** 0\
**Last updated:** [May 1, 2020, 7:47pm UTC](https://discuss.elastic.co/t/missing-field/230760 "2020-05-01T19:47:09Z")

</div>

I am using filebeats panos module. In the index i don't see the source.geo.name or destination.geo.name if i select the event.category as network\_traffic. Although it shows as country ISO\_code but not by name. Actual sys…

---

## [Why dont beats support keystore and truststore?](https://discuss.elastic.co/t/why-dont-beats-support-keystore-and-truststore/230908)

<div class="topic-metadata">

**Author:** [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Replies:** 1\
**Last updated:** [May 4, 2020, 1:34am UTC](https://discuss.elastic.co/t/why-dont-beats-support-keystore-and-truststore/230908 "2020-05-04T01:34:38Z")

</div>

Is there any option like "xpack.security.transport.ssl.keystore.path:" in elasticsearch ? Is there any another option to hide private key in Windows servers?

---

## [\[Metricbeat\] Incorrect percentages when a process uses multiple cores on the kibana dashboard](https://discuss.elastic.co/t/metricbeat-incorrect-percentages-when-a-process-uses-multiple-cores-on-the-kibana-dashboard/228919)

<div class="topic-metadata">

**Author:** [@premierpsp](https://discuss.elastic.co/u/premierpsp)\
**Replies:** 4\
**Last updated:** [May 4, 2020, 12:49am UTC](https://discuss.elastic.co/t/metricbeat-incorrect-percentages-when-a-process-uses-multiple-cores-on-the-kibana-dashboard/228919 "2020-05-04T00:49:23Z")

</div>

Hi, When i have a process using multiples cores the percentage values ​​are wrong in Top Processes By CPU module. Top Output: Kibana dashboard (Top Processes By CPU module): I also cannot set the conditions for t…

---

## [Metricbeat showing Zero\_Percent CPU utilization](https://discuss.elastic.co/t/metricbeat-showing-zero-percent-cpu-utilization/223768)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 2\
**Last updated:** [May 3, 2020, 5:27pm UTC](https://discuss.elastic.co/t/metricbeat-showing-zero-percent-cpu-utilization/223768 "2020-05-03T17:27:31Z")

</div>

Hello All , I have recently changed the period from 10s to 3m for system module in metricbeat.yml (system.yml) . Earlier when it was 10s i was able to see the CPU data in Host system dashboard. Now i don't see the data …

---

## [Metricbeat connectivity issue to Elasticsearch](https://discuss.elastic.co/t/metricbeat-connectivity-issue-to-elasticsearch/227114)

<div class="topic-metadata">

**Author:** [@DeepakBishi](https://discuss.elastic.co/u/DeepakBishi)\
**Replies:** 2\
**Last updated:** [May 3, 2020, 5:25pm UTC](https://discuss.elastic.co/t/metricbeat-connectivity-issue-to-elasticsearch/227114 "2020-05-03T17:25:27Z")

</div>

I am facing an issue of metricbeat not able to connect to elaticsearch. I have installed metricbeat in a remote host and trying to send the data to elasticsearch which is hosted on another host. While starting metricbea…

---

## [Winlogbeat read DNS Server events](https://discuss.elastic.co/t/winlogbeat-read-dns-server-events/230868)

<div class="topic-metadata">

**Author:** [@sundar\_elk](https://discuss.elastic.co/u/sundar_elk)\
**Replies:** 1\
**Last updated:** [May 3, 2020, 1:37pm UTC](https://discuss.elastic.co/t/winlogbeat-read-dns-server-events/230868 "2020-05-03T13:37:36Z")

</div>

Hi Team, I can read all channel events i.e Application, Security, PowerShell and etc but not able to read DNS Server events. configuration is winlogbeat.event\_logs: - name: DNS Server ignore\_older: 4h logging…

---

## [AWS module - ELB Tags - 7.6.2](https://discuss.elastic.co/t/aws-module-elb-tags-7-6-2/228531)

<div class="topic-metadata">

**Author:** [@kungl](https://discuss.elastic.co/u/kungl)\
**Replies:** 2\
**Last updated:** [May 2, 2020, 9:36pm UTC](https://discuss.elastic.co/t/aws-module-elb-tags-7-6-2/228531 "2020-05-02T21:36:43Z")

</div>

Hi, I would like to get only those ELBs which belongs to specific tags from my AWS infrastructure (Stage=production). I can't find any example of this on ELB specific site, but I get "tags\_filter" on ec2 documentation, …

---

## [Uptime dashboard - Error: \[illegal\_argument\_exception\] Text fields are not optimised for operations that require per-document field data](https://discuss.elastic.co/t/uptime-dashboard-error-illegal-argument-exception-text-fields-are-not-optimised-for-operations-that-require-per-document-field-data/230429)

<div class="topic-metadata">

**Author:** [@almathden](https://discuss.elastic.co/u/almathden)\
**Replies:** 6\
**Last updated:** [May 2, 2020, 5:44am UTC](https://discuss.elastic.co/t/uptime-dashboard-error-illegal-argument-exception-text-fields-are-not-optimised-for-operations-that-require-per-document-field-data/230429 "2020-05-02T05:44:31Z")

</div>

Hey Team. Just getting started using heartbeat. Here's the full error I'm getting. This shows up under the 'Monitor Status' section of the /app/uptime area: Error: \[illegal\_argument\_exception\] Text fields are not opti…

---

## [Save field parameter is not valid](https://discuss.elastic.co/t/save-field-parameter-is-not-valid/227849)

<div class="topic-metadata">

**Author:** [@vijay\_kaali](https://discuss.elastic.co/u/vijay_kaali)\
**Replies:** 2\
**Last updated:** [May 1, 2020, 6:24am UTC](https://discuss.elastic.co/t/save-field-parameter-is-not-valid/227849 "2020-05-01T06:24:57Z")

</div>

I am using elk 6.3 i have downloaded dashboard to test environment and i get save field parameter is not valid throws . I checked the individual visualization and actual field name is not listed. issue is in index…

---

## [Issue with Filebeat and JSON to Kibana](https://discuss.elastic.co/t/issue-with-filebeat-and-json-to-kibana/230587)

<div class="topic-metadata">

**Author:** [@EmilioIgn](https://discuss.elastic.co/u/EmilioIgn)\
**Replies:** 2\
**Last updated:** [April 30, 2020, 4:29pm UTC](https://discuss.elastic.co/t/issue-with-filebeat-and-json-to-kibana/230587 "2020-04-30T16:29:44Z")

</div>

Hello experts, I am new to this world of ELK and I have already read the documentation but I still do not find the problem ... I am very horrible to write problems, but here I go: Case: I have a JSON report (a Behave T…

---

## [Want to parse multiline json logs using filebeat and logstash except non-josn logs without any failure](https://discuss.elastic.co/t/want-to-parse-multiline-json-logs-using-filebeat-and-logstash-except-non-josn-logs-without-any-failure/230665)

<div class="topic-metadata">

**Author:** [@Dragon9](https://discuss.elastic.co/u/Dragon9)\
**Replies:** 0\
**Last updated:** [May 1, 2020, 5:41am UTC](https://discuss.elastic.co/t/want-to-parse-multiline-json-logs-using-filebeat-and-logstash-except-non-josn-logs-without-any-failure/230665 "2020-05-01T05:41:20Z")

</div>

my json log file { "a":{ "se":"NA", "event":"158", "sys":"NA", "Id":"149", "ma":"o", "ab":"Pod", "source": "Application", "eq":"NA", "pr":"NA", "sev":"CRIT" }, "b":{ "total\_memory":"10GB", "memory\_usage":"8GB", "memory\_…

---

## [Filebeat to Elasticsearch vs Filebeat to Logstash](https://discuss.elastic.co/t/filebeat-to-elasticsearch-vs-filebeat-to-logstash/230583)

<div class="topic-metadata">

**Author:** [@anur](https://discuss.elastic.co/u/anur)\
**Replies:** 0\
**Last updated:** [April 30, 2020, 3:25pm UTC](https://discuss.elastic.co/t/filebeat-to-elasticsearch-vs-filebeat-to-logstash/230583 "2020-04-30T15:25:30Z")

</div>

Hi , I need to configure ELK for a big ecossystem which consists of 500 servers. Which architecture provides good performance.There is no Parsing is required. ThankYou

---

## [Perfmon metrics on Windows](https://discuss.elastic.co/t/perfmon-metrics-on-windows/230539)

<div class="topic-metadata">

**Author:** [@Volodymyr\_Shypyguzov](https://discuss.elastic.co/u/Volodymyr_Shypyguzov)\
**Replies:** 1\
**Last updated:** [April 30, 2020, 12:46pm UTC](https://discuss.elastic.co/t/perfmon-metrics-on-windows/230539 "2020-04-30T12:46:19Z")

</div>

Hi there, we started using metricbeat for monitoring our windows machines including MSMQ perfmon counters. When using metricbeat 7.6.2 it starts reading them just fine, but after an hour or so it compains that it cannot …

---

## [SQL output to Log File](https://discuss.elastic.co/t/sql-output-to-log-file/230516)

<div class="topic-metadata">

**Author:** [@spike83](https://discuss.elastic.co/u/spike83)\
**Replies:** 1\
**Last updated:** [April 30, 2020, 12:07pm UTC](https://discuss.elastic.co/t/sql-output-to-log-file/230516 "2020-04-30T12:07:43Z")

</div>

Hi, I have a pgsql script that outputs a value from a select count(\*) script to a log file. I have configured filebeat to grab this log and push the data into Elasticsearch with a pipeline that converts the message fil…

---

## [Multiple log files per index -- need to create one index per one log file](https://discuss.elastic.co/t/multiple-log-files-per-index-need-to-create-one-index-per-one-log-file/230505)

<div class="topic-metadata">

**Author:** [@Hung\_M\_Le](https://discuss.elastic.co/u/Hung_M_Le)\
**Replies:** 1\
**Last updated:** [April 30, 2020, 11:42am UTC](https://discuss.elastic.co/t/multiple-log-files-per-index-need-to-create-one-index-per-one-log-file/230505 "2020-04-30T11:42:34Z")

</div>

Hi My current setting is filebeat -\> Elasticsearch -\> Kibana. Current behavior: Send one file to the work directory to be ingested by filebeat and send to the Elasticsearch log output is sent to Elasticsearch without…

---

## [After redirect connection reset by peer](https://discuss.elastic.co/t/after-redirect-connection-reset-by-peer/230323)

<div class="topic-metadata">

**Author:** [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Replies:** 2\
**Last updated:** [April 30, 2020, 10:53am UTC](https://discuss.elastic.co/t/after-redirect-connection-reset-by-peer/230323 "2020-04-30T10:53:57Z")

</div>

Hi, I use heartbeat to monitor an URL, that is redirected to another. The configuration is: - type: http urls: \["https://www.123-usability.de"\] max\_redirects: 20 ssl.verification\_mode: none …

---

## [Meetricbeat 7.6.2 on Openshift 4.3](https://discuss.elastic.co/t/meetricbeat-7-6-2-on-openshift-4-3/230513)

<div class="topic-metadata">

**Author:** [@doyoungim999](https://discuss.elastic.co/u/doyoungim999)\
**Replies:** 0\
**Last updated:** [April 30, 2020, 9:49am UTC](https://discuss.elastic.co/t/meetricbeat-7-6-2-on-openshift-4-3/230513 "2020-04-30T09:49:16Z")

</div>

Hi, I deployed successfully metricbeat7.6.2 on openshift4.3 without problem like ; $oc new-app -e output.elasticsearch.hosts="http://elasticsearch-emsproject.apps-crc.testing/" docker.elastic.co/beats/metricbeat:7.6.…

---

## [Ingestion of several double lines in elastic research](https://discuss.elastic.co/t/ingestion-of-several-double-lines-in-elastic-research/229682)

<div class="topic-metadata">

**Author:** [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Replies:** 2\
**Last updated:** [April 30, 2020, 9:39am UTC](https://discuss.elastic.co/t/ingestion-of-several-double-lines-in-elastic-research/229682 "2020-04-30T09:39:13Z")

</div>

I use file beat and logstsh for ingest csv in elastic i have this problem ingestion of several double lines in elastic research can you help me please? I use this config in filebeat filebeat.inputs: - type: log …

---

## [Filebeat seems truncated message in single line\[Filebeat 7.6\]](https://discuss.elastic.co/t/filebeat-seems-truncated-message-in-single-line-filebeat-7-6/230124)

<div class="topic-metadata">

**Author:** [@bo\_bo](https://discuss.elastic.co/u/bo_bo)\
**Replies:** 2\
**Last updated:** [April 30, 2020, 2:17am UTC](https://discuss.elastic.co/t/filebeat-seems-truncated-message-in-single-line-filebeat-7-6/230124 "2020-04-30T02:17:08Z")

</div>

filebeat truncated log file line accidentally, so when parsing the next line, error happend Filebeat error log 2020-04-28T16:50:37.642+0800 ERROR readjson/json.go:52 Error decoding JSON: invalid character 'e'…

---

## [Send monitoring data Filebeat to HTTPS](https://discuss.elastic.co/t/send-monitoring-data-filebeat-to-https/230442)

<div class="topic-metadata">

**Author:** [@v.n](https://discuss.elastic.co/u/v.n)\
**Replies:** 1\
**Last updated:** [April 29, 2020, 9:45pm UTC](https://discuss.elastic.co/t/send-monitoring-data-filebeat-to-https/230442 "2020-04-29T21:45:38Z")

</div>

Hi, I want to make more secure sending monitoring data from filebeat to ES. Earlier it was secured just by login/password which were sent by HTTP that was detected by our internal IDS. So I implemented NGINX on port 920…

---

## [Filebeat-0SS throwing error while connecting with AWS ES](https://discuss.elastic.co/t/filebeat-0ss-throwing-error-while-connecting-with-aws-es/230402)

<div class="topic-metadata">

**Author:** [@Rakesh\_Joshi3107](https://discuss.elastic.co/u/Rakesh_Joshi3107)\
**Replies:** 7\
**Last updated:** [April 29, 2020, 7:14pm UTC](https://discuss.elastic.co/t/filebeat-0ss-throwing-error-while-connecting-with-aws-es/230402 "2020-04-29T19:14:45Z")

</div>

Hi, I'm trying to use Filebeat-OSS with AWS ES to ingest AWS ECS Container logs, I'm getting that Filebeat is not able to connect with ES. "2020-04-29T15:40:54.266Z ERROR pipeline/output.go:100 Failed to connect to bac…

---

## [Beats & Logstash - What happens if logstash goes offline?](https://discuss.elastic.co/t/beats-logstash-what-happens-if-logstash-goes-offline/230423)

<div class="topic-metadata">

**Author:** [@Ric878](https://discuss.elastic.co/u/Ric878)\
**Replies:** 2\
**Last updated:** [April 29, 2020, 7:10pm UTC](https://discuss.elastic.co/t/beats-logstash-what-happens-if-logstash-goes-offline/230423 "2020-04-29T19:10:33Z")

</div>

I've setup an elasticsearch cluster with 3 Elasticsearch nodes, 1 Kibana, 1 Logstash. Everything is working as expected with one exception. I currently have my Beats (metric, file, etc.) sending log data to my Logstash …

---

## [Unable to rename Index!](https://discuss.elastic.co/t/unable-to-rename-index/230205)

<div class="topic-metadata">

**Author:** [@JulienN](https://discuss.elastic.co/u/JulienN)\
**Replies:** 2\
**Last updated:** [April 29, 2020, 1:47pm UTC](https://discuss.elastic.co/t/unable-to-rename-index/230205 "2020-04-29T13:47:55Z")

</div>

Hi all , i'm French and i'm a new user of ELK Stack . Actually i discover the ELK stack , and one of my principal use is to aggregate some logs from my Servers to Elastic , and to consult it in Kibana. I've a problem…

---

## [CloudWatch logs for functionbeat are currently being sent but Kibana doesn't show them on the "Logs" tab?!?!](https://discuss.elastic.co/t/cloudwatch-logs-for-functionbeat-are-currently-being-sent-but-kibana-doesnt-show-them-on-the-logs-tab/229140)

<div class="topic-metadata">

**Author:** [@syost](https://discuss.elastic.co/u/syost)\
**Replies:** 15\
**Last updated:** [April 29, 2020, 6:58am UTC](https://discuss.elastic.co/t/cloudwatch-logs-for-functionbeat-are-currently-being-sent-but-kibana-doesnt-show-them-on-the-logs-tab/229140 "2020-04-29T06:58:02Z")

</div>

It appears that my Elasticseach + Kibana + Functionbeat + CloudWatch is setup correctly as far as the connections are working. However, when I generate logs into CloudWatch I never see them in the "Logs" page of Kibana. …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=252)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=254)
