# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=255

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 256

---

## [Fail2ban module for Filebeat](https://discuss.elastic.co/t/fail2ban-module-for-filebeat/229853)

<div class="topic-metadata">

**Author:** [@rmartinsjr](https://discuss.elastic.co/u/rmartinsjr)\
**Replies:** 1\
**Last updated:** [April 27, 2020, 2:50pm UTC](https://discuss.elastic.co/t/fail2ban-module-for-filebeat/229853 "2020-04-27T14:50:17Z")

</div>

Hello! I've seen some people discussing here and there about shipping Fail2ban logs, but it's always using Logstash, which for my current setup, is overkill. So I was wondering if there's any on-going effort to create …

---

## [Kibana cannot locate index pattern osquery.result\* for the filebeat-osquery combination](https://discuss.elastic.co/t/kibana-cannot-locate-index-pattern-osquery-result-for-the-filebeat-osquery-combination/229770)

<div class="topic-metadata">

**Author:** [@Gernot\_Schmied](https://discuss.elastic.co/u/Gernot_Schmied)\
**Replies:** 1\
**Last updated:** [April 27, 2020, 2:44pm UTC](https://discuss.elastic.co/t/kibana-cannot-locate-index-pattern-osquery-result-for-the-filebeat-osquery-combination/229770 "2020-04-27T14:44:05Z")

</div>

Hi, after filebeat and osquery setup data is present in the log-files and received from the Filebeat osquery module. However, I do not see any osquery.result\* index pattern at all. Just activated the osquery module, no…

---

## [Filbeat is not creating indices according to setup.ilm.pattern](https://discuss.elastic.co/t/filbeat-is-not-creating-indices-according-to-setup-ilm-pattern/229940)

<div class="topic-metadata">

**Author:** [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Replies:** 0\
**Last updated:** [April 27, 2020, 10:28am UTC](https://discuss.elastic.co/t/filbeat-is-not-creating-indices-according-to-setup-ilm-pattern/229940 "2020-04-27T10:28:07Z")

</div>

i set this in my filebeat.yml file and the index was created as per expected setup.ilm.pattern: '{now/m{yyyy.MM.dd.mm}}-000001' but i was expecting that new index will be created every minute but it didn't. The initial…

---

## [Problem creating index](https://discuss.elastic.co/t/problem-creating-index/229454)

<div class="topic-metadata">

**Author:** [@vdelburgo](https://discuss.elastic.co/u/vdelburgo)\
**Replies:** 6\
**Last updated:** [April 27, 2020, 8:01am UTC](https://discuss.elastic.co/t/problem-creating-index/229454 "2020-04-27T08:01:55Z")

</div>

Good morning, I have a filebeat on one server, and I would need you to create a new index, different from what I have configured on other servers, so that when the index is created the Kibana can absorb it under another…

---

## [Filebeat (7.6.2) doesn't send any data to ElasticSearch](https://discuss.elastic.co/t/filebeat-7-6-2-doesnt-send-any-data-to-elasticsearch/229858)

<div class="topic-metadata">

**Author:** [@flavienbwk](https://discuss.elastic.co/u/flavienbwk)\
**Replies:** 1\
**Last updated:** [April 26, 2020, 6:12pm UTC](https://discuss.elastic.co/t/filebeat-7-6-2-doesnt-send-any-data-to-elasticsearch/229858 "2020-04-26T18:12:29Z")

</div>

Hi, My filebeat instance doesn't send any data to ElasticSearch, would you know why ? Service is correctly launched (service filebeat status is green). /srv/docker/gitlab/logs/nginx/\*.log log files are available in c…

---

## [Filebeat does not insert document on the newly created index on rollover but still look for the previous index](https://discuss.elastic.co/t/filebeat-does-not-insert-document-on-the-newly-created-index-on-rollover-but-still-look-for-the-previous-index/229857)

<div class="topic-metadata">

**Author:** [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Replies:** 0\
**Last updated:** [April 26, 2020, 5:08pm UTC](https://discuss.elastic.co/t/filebeat-does-not-insert-document-on-the-newly-created-index-on-rollover-but-still-look-for-the-previous-index/229857 "2020-04-26T17:08:25Z")

</div>

The index got rollover from 000001 to 000002 but no documented inserted on the index with 000002 ...

---

## [Where is the default template.json file for filebeat](https://discuss.elastic.co/t/where-is-the-default-template-json-file-for-filebeat/229761)

<div class="topic-metadata">

**Author:** [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Replies:** 10\
**Last updated:** [April 26, 2020, 1:32pm UTC](https://discuss.elastic.co/t/where-is-the-default-template-json-file-for-filebeat/229761 "2020-04-26T13:32:34Z")

</div>

As you can see in the image the part in red box what i want to know is where is that file for template resides i want to see that configuration as i want to made the custom template for that sake need a help for config…

---

## [Creating indices based on timestamp using date index name processor](https://discuss.elastic.co/t/creating-indices-based-on-timestamp-using-date-index-name-processor/229839)

<div class="topic-metadata">

**Author:** [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Replies:** 0\
**Last updated:** [April 26, 2020, 12:14pm UTC](https://discuss.elastic.co/t/creating-indices-based-on-timestamp-using-date-index-name-processor/229839 "2020-04-26T12:14:43Z")

</div>

This processor is used to create indices { "date\_index\_name": { "field": "timestamp", "date\_rounding": "d", "index\_name\_prefix": "{{fields.index\_prefix}}", "index\_name\_format": "y…

---

## [Measure number of events per pod in k8s](https://discuss.elastic.co/t/measure-number-of-events-per-pod-in-k8s/229413)

<div class="topic-metadata">

**Author:** [@tomeri](https://discuss.elastic.co/u/tomeri)\
**Replies:** 3\
**Last updated:** [April 26, 2020, 7:05am UTC](https://discuss.elastic.co/t/measure-number-of-events-per-pod-in-k8s/229413 "2020-04-26T07:05:11Z")

</div>

Hi, I wonder if there a proper way to measure the number of emitted events per pod/container in Kubernetes, every 1 minute before they being sent to Logstash. I see that Filebeat saves the offset of each harvested file…

---

## [How to use Logs in Logstash format with Filebeat](https://discuss.elastic.co/t/how-to-use-logs-in-logstash-format-with-filebeat/229786)

<div class="topic-metadata">

**Author:** [@BuesBu](https://discuss.elastic.co/u/BuesBu)\
**Replies:** 1\
**Last updated:** [April 25, 2020, 10:27pm UTC](https://discuss.elastic.co/t/how-to-use-logs-in-logstash-format-with-filebeat/229786 "2020-04-25T22:27:55Z")

</div>

Hello guys, I'm at my wit's end and I need your advice. We use Filebeat to send our logs to elastic search (Cloud). All good so far. Nginx and system logs are working fine so far. Now we would like to send our logs …

---

## [Question about setting up beats on multiple hosts](https://discuss.elastic.co/t/question-about-setting-up-beats-on-multiple-hosts/229608)

<div class="topic-metadata">

**Author:** [@archon810](https://discuss.elastic.co/u/archon810)\
**Replies:** 2\
**Last updated:** [April 24, 2020, 11:26pm UTC](https://discuss.elastic.co/t/question-about-setting-up-beats-on-multiple-hosts/229608 "2020-04-24T23:26:16Z")

</div>

Hi, We have a 4-machine ES and Kibana cluster and I'm now setting up various beats. For starters, I set up metricbeat on host1 and enabled nginx metricbeat that grabs metrics from host1, host2, host3, host4. This crea…

---

## [Metricbeat script processor](https://discuss.elastic.co/t/metricbeat-script-processor/229548)

<div class="topic-metadata">

**Author:** [@musician](https://discuss.elastic.co/u/musician)\
**Replies:** 6\
**Last updated:** [April 24, 2020, 11:03pm UTC](https://discuss.elastic.co/t/metricbeat-script-processor/229548 "2020-04-24T23:03:10Z")

</div>

Hello, I am trying to use the script processor in metricbeat. I have the following system.yml: - module: system period: 10s metricsets: - cpu - memory - process processes: …

---

## [\[Elastic Cloud\] Configure Filebeat to use timestamp from LogFile](https://discuss.elastic.co/t/elastic-cloud-configure-filebeat-to-use-timestamp-from-logfile/229711)

<div class="topic-metadata">

**Author:** [@Regis\_Oliveira](https://discuss.elastic.co/u/Regis_Oliveira)\
**Replies:** 1\
**Last updated:** [April 24, 2020, 8:39pm UTC](https://discuss.elastic.co/t/elastic-cloud-configure-filebeat-to-use-timestamp-from-logfile/229711 "2020-04-24T20:39:18Z")

</div>

Hello! I'm evaluating Elastic Cloud and couldn't realize how to configure Filebeat to use the timestamp provided in my log file instead of use the time when the file is being read. Actually, when searching on Kibana, t…

---

## [Filebeat upgrade from 6.8 to 7.6 index issue](https://discuss.elastic.co/t/filebeat-upgrade-from-6-8-to-7-6-index-issue/229625)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 1\
**Last updated:** [April 24, 2020, 5:53pm UTC](https://discuss.elastic.co/t/filebeat-upgrade-from-6-8-to-7-6-index-issue/229625 "2020-04-24T17:53:39Z")

</div>

I am having an issue using my 6.8 yml file with 7.6. The index that I am using in the yml file is not carrying into Elasticsearch as it looks like it is using ILM to specify the index. Do I need to add anything to my Y…

---

## [Can't start packetbeat service on Ubuntu 18.04](https://discuss.elastic.co/t/cant-start-packetbeat-service-on-ubuntu-18-04/229458)

<div class="topic-metadata">

**Author:** [@cezar996](https://discuss.elastic.co/u/cezar996)\
**Replies:** 3\
**Last updated:** [April 24, 2020, 5:17pm UTC](https://discuss.elastic.co/t/cant-start-packetbeat-service-on-ubuntu-18-04/229458 "2020-04-24T17:17:52Z")

</div>

Hi! I can't start packetbeat service in Ubuntu 18.04. It runs perfectly If I start the service exactly after it is installed. But if I stop it or restart it in order to make some changes in packetbeat.yml and then try t…

---

## [Filebeat kubernetes fatal error: concurrent map writes](https://discuss.elastic.co/t/filebeat-kubernetes-fatal-error-concurrent-map-writes/229660)

<div class="topic-metadata">

**Author:** [@SamuelBramm](https://discuss.elastic.co/u/SamuelBramm)\
**Replies:** 2\
**Last updated:** [April 24, 2020, 2:46pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-fatal-error-concurrent-map-writes/229660 "2020-04-24T14:46:47Z")

</div>

Hi, I have run into a problem with the autodiscovery module on kubernetes. Filebeat is being deployed as suggested in the documentation with the addition that I wanted to have additional cloud and host metadata. Therefo…

---

## [Error 1067: The process terminates unexpectedly](https://discuss.elastic.co/t/error-1067-the-process-terminates-unexpectedly/229678)

<div class="topic-metadata">

**Author:** [@dearle](https://discuss.elastic.co/u/dearle)\
**Replies:** 0\
**Last updated:** [April 24, 2020, 2:46pm UTC](https://discuss.elastic.co/t/error-1067-the-process-terminates-unexpectedly/229678 "2020-04-24T14:46:45Z")

</div>

We have a number of servers that run Filebeat as a service and the majority of them are having the same issue upon startup: “Error 1067: The process terminates unexpectedly.” Here's the log file on first run: 2020-…

---

## [Kibana can't find packetbeat index](https://discuss.elastic.co/t/kibana-cant-find-packetbeat-index/229663)

<div class="topic-metadata">

**Author:** [@tbhaxor](https://discuss.elastic.co/u/tbhaxor)\
**Replies:** 0\
**Last updated:** [April 24, 2020, 1:26pm UTC](https://discuss.elastic.co/t/kibana-cant-find-packetbeat-index/229663 "2020-04-24T13:26:27Z")

</div>

I have installed packet beat 7.6.1 and when I loaded dashboard and then started the service, on kibana dashboard I am getting But the index in elasticsearch exists

---

## [Filebeat is not sending logs to logstash and no error in filebeat.log](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-and-no-error-in-filebeat-log/229616)

<div class="topic-metadata">

**Author:** [@karthik\_kiccha](https://discuss.elastic.co/u/karthik_kiccha)\
**Replies:** 0\
**Last updated:** [April 24, 2020, 10:13am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-and-no-error-in-filebeat-log/229616 "2020-04-24T10:13:00Z")

</div>

Hello Team, We are using filbeat version 1.3.1 and logstash, i'm unable to send the logs from filebeat to logstash. perhaps it is very slow there is a lag of more than 10 mins. here is my filebeat.yaml file. --- fileb…

---

## [Connecting Merticbeat to AWS](https://discuss.elastic.co/t/connecting-merticbeat-to-aws/229551)

<div class="topic-metadata">

**Author:** [@spike83](https://discuss.elastic.co/u/spike83)\
**Replies:** 1\
**Last updated:** [April 24, 2020, 9:32am UTC](https://discuss.elastic.co/t/connecting-merticbeat-to-aws/229551 "2020-04-24T09:32:53Z")

</div>

Hi, I'm having trouble connecting Merticbeat to AWS. I have setup user with a policy assigned with the required access level, generated keys for the user to connect. Loaded the credentials I to the Aws yml file both di…

---

## [Single build template for multiple beats (for example: Filebeat + MetricBeat + AuditBeat into single package)](https://discuss.elastic.co/t/single-build-template-for-multiple-beats-for-example-filebeat-metricbeat-auditbeat-into-single-package/229533)

<div class="topic-metadata">

**Author:** [@kelk](https://discuss.elastic.co/u/kelk)\
**Replies:** 3\
**Last updated:** [April 24, 2020, 8:40am UTC](https://discuss.elastic.co/t/single-build-template-for-multiple-beats-for-example-filebeat-metricbeat-auditbeat-into-single-package/229533 "2020-04-24T08:40:04Z")

</div>

We have been looking into vast estate of Linux clients and the project scope is looking for data for Operational data (filebeat) and (metrics-beat) && Security/complicance (Auditbeat) etc. The original plan was to instal…

---

## [Filebeat - Date processor - Log file content without date](https://discuss.elastic.co/t/filebeat-date-processor-log-file-content-without-date/229489)

<div class="topic-metadata">

**Author:** [@pjo](https://discuss.elastic.co/u/pjo)\
**Replies:** 2\
**Last updated:** [April 24, 2020, 7:49am UTC](https://discuss.elastic.co/t/filebeat-date-processor-log-file-content-without-date/229489 "2020-04-24T07:49:32Z")

</div>

Hello there, I'm new on this product. here is my question I use filebeat to crawl log file and send content to logstash frontend. Usually my logs files contains on each row a full date format. File is able to read to…

---

## [Secure access to logstash](https://discuss.elastic.co/t/secure-access-to-logstash/229585)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 0\
**Last updated:** [April 24, 2020, 7:01am UTC](https://discuss.elastic.co/t/secure-access-to-logstash/229585 "2020-04-24T07:01:33Z")

</div>

Hi, We currently use winlogbeats on a WEF server, logstash behind a firewall with allow rules for the source of the WEF server, using SSL on top of that. We need to plan for a more mobile workforce without vpn back to …

---

## [Unable to get data by using postgresql module of metricbeat 7.6.2](https://discuss.elastic.co/t/unable-to-get-data-by-using-postgresql-module-of-metricbeat-7-6-2/229422)

<div class="topic-metadata">

**Author:** [@akELK081](https://discuss.elastic.co/u/akELK081)\
**Replies:** 3\
**Last updated:** [April 24, 2020, 6:27am UTC](https://discuss.elastic.co/t/unable-to-get-data-by-using-postgresql-module-of-metricbeat-7-6-2/229422 "2020-04-24T06:27:59Z")

</div>

I have installed postgresql in RHEL, and created one sample database for postgres owner. With the following configuration of postgresql.yml: Preformatted text# Module: postgresql Docs: https://www.elastic.co/guide/en/…

---

## [EVTX Windows logs to ES](https://discuss.elastic.co/t/evtx-windows-logs-to-es/228997)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 4\
**Last updated:** [April 23, 2020, 10:28pm UTC](https://discuss.elastic.co/t/evtx-windows-logs-to-es/228997 "2020-04-23T22:28:12Z")

</div>

Hi, what is most easy way to load static EVTX files to ES for forensics pourposes? Is there maybe some done setup for that? I just have dir with subdirectories for each system and in this subdirectories are evtx logs. Ju…

---

## [Metricbeat Kibana dashboard not loading](https://discuss.elastic.co/t/metricbeat-kibana-dashboard-not-loading/229348)

<div class="topic-metadata">

**Author:** [@Keevin\_Ace\_Viray](https://discuss.elastic.co/u/Keevin_Ace_Viray)\
**Replies:** 8\
**Last updated:** [April 23, 2020, 7:33pm UTC](https://discuss.elastic.co/t/metricbeat-kibana-dashboard-not-loading/229348 "2020-04-23T19:33:02Z")

</div>

Hi, I have setup Metricbeat(System module) -\> Kafka -\> Logstash -\> Elasticsearch -\> Kibana on our Linux local environment. I can see from the Discovery tab in Kibana that there is a lot of hits coming from Metricbeat, b…

---

## [Unable to setup filebeat dashboard for Kibana](https://discuss.elastic.co/t/unable-to-setup-filebeat-dashboard-for-kibana/228410)

<div class="topic-metadata">

**Author:** [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Replies:** 8\
**Last updated:** [April 17, 2020, 6:21pm UTC](https://discuss.elastic.co/t/unable-to-setup-filebeat-dashboard-for-kibana/228410 "2020-04-17T18:21:57Z")

</div>

I have set up elasticsearch , kibana and filebeat on the same CentOS VM. Both elasticsearch and kibana are running. Hostname of the CentOS VM is js-168-192.jetstream-cloud.org I am getting the below error when I run --\>…

---

## [Filebeat does not insert data into elasticsearch using ILM (node default index)](https://discuss.elastic.co/t/filebeat-does-not-insert-data-into-elasticsearch-using-ilm-node-default-index/229288)

<div class="topic-metadata">

**Author:** [@Alon\_Eldi](https://discuss.elastic.co/u/Alon_Eldi)\
**Replies:** 3\
**Last updated:** [April 23, 2020, 6:49pm UTC](https://discuss.elastic.co/t/filebeat-does-not-insert-data-into-elasticsearch-using-ilm-node-default-index/229288 "2020-04-23T18:49:00Z")

</div>

Hi , We have filebeat agents which write data directly into elasticsearch cloud service. For some reason the filebeat is not writing the data into the index The filbeat use ILM policy : setup.ilm.enabled: auto setup.…

---

## [Filebeat multiline pattern from 'abbbc' to 'ac'](https://discuss.elastic.co/t/filebeat-multiline-pattern-from-abbbc-to-ac/229267)

<div class="topic-metadata">

**Author:** [@CorneM](https://discuss.elastic.co/u/CorneM)\
**Replies:** 3\
**Last updated:** [April 23, 2020, 2:18pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-from-abbbc-to-ac/229267 "2020-04-23T14:18:19Z")

</div>

Hello all, The last few days I have been struggling with a multiline pattern. My multiline log messages have a pattern like 'abbbc'. I don't need the b-parts to be send to LogStash. So basically what I want to accomplis…

---

## [Importing IIS logs and matching it with GROK and adding additional fields](https://discuss.elastic.co/t/importing-iis-logs-and-matching-it-with-grok-and-adding-additional-fields/229426)

<div class="topic-metadata">

**Author:** [@W.Almansoori](https://discuss.elastic.co/u/W.Almansoori)\
**Replies:** 2\
**Last updated:** [April 23, 2020, 12:48pm UTC](https://discuss.elastic.co/t/importing-iis-logs-and-matching-it-with-grok-and-adding-additional-fields/229426 "2020-04-23T12:48:56Z")

</div>

Hello there. I've been trying to import some logs from an IIS server. I configured the filebeat.yml, enabled inputs and set the path. I've enabled the IIS module as well and configured the path of the access logs. Sta…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=254)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=256)
