# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=256

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 257

---

## [Multiline txt log files not parsing correctly in ingest pipeline](https://discuss.elastic.co/t/multiline-txt-log-files-not-parsing-correctly-in-ingest-pipeline/229440)

<div class="topic-metadata">

**Author:** [@nigel.piggott](https://discuss.elastic.co/u/nigel.piggott)\
**Replies:** 0\
**Last updated:** [April 23, 2020, 10:39am UTC](https://discuss.elastic.co/t/multiline-txt-log-files-not-parsing-correctly-in-ingest-pipeline/229440 "2020-04-23T10:39:25Z")

</div>

\[on windows\] I have a log file that can contain multiple lines. The filebeat yml is correctly configured for multi line The source appearing in elastic contains "\\n" e.g. source file content " ababasd asfjklasjdflkj…

---

## [Possible to get disk pressure metrics from kubernetes module?](https://discuss.elastic.co/t/possible-to-get-disk-pressure-metrics-from-kubernetes-module/229367)

<div class="topic-metadata">

**Author:** [@Synthetic\_Test](https://discuss.elastic.co/u/Synthetic_Test)\
**Replies:** 0\
**Last updated:** [April 23, 2020, 1:11am UTC](https://discuss.elastic.co/t/possible-to-get-disk-pressure-metrics-from-kubernetes-module/229367 "2020-04-23T01:11:48Z")

</div>

Hi, I have the Kubernetes module configured: https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-module-kubernetes.html I am interested in node metrics, specifically kube\_node\_status\_condition found he…

---

## [Winlogbeat event.action for 4648](https://discuss.elastic.co/t/winlogbeat-event-action-for-4648/227919)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [April 23, 2020, 8:54am UTC](https://discuss.elastic.co/t/winlogbeat-event-action-for-4648/227919 "2020-04-23T08:54:23Z")

</div>

Hello, Using the Winlogbeat 'security ' module I noticed event.code 4648 does not (yet) have an event.action defined: var eventActionTypes = { "4624": "logged-in", "4625": "logon-failed", "4634": "logged-ou…

---

## [Filebeat Registry - Will I get duplicates if I delete](https://discuss.elastic.co/t/filebeat-registry-will-i-get-duplicates-if-i-delete/229060)

<div class="topic-metadata">

**Author:** [@stevesimpson](https://discuss.elastic.co/u/stevesimpson)\
**Replies:** 2\
**Last updated:** [April 23, 2020, 8:41am UTC](https://discuss.elastic.co/t/filebeat-registry-will-i-get-duplicates-if-i-delete/229060 "2020-04-23T08:41:11Z")

</div>

Hi, I've been an idiot. I added a conditional into my Logstash pipelines which, long story short, has caused me to miss around an hour of logging data over about 18 different agents. I've since fixed the issue and data…

---

## [Netflow Performance](https://discuss.elastic.co/t/netflow-performance/229407)

<div class="topic-metadata">

**Author:** [@ksremo](https://discuss.elastic.co/u/ksremo)\
**Replies:** 0\
**Last updated:** [April 23, 2020, 8:10am UTC](https://discuss.elastic.co/t/netflow-performance/229407 "2020-04-23T08:10:05Z")

</div>

Our Architecture looks like Netflow Exporter Appliance -\> Filebeat Netflow Module -\> Logstash -\> Elasticsearch In Kibana there is a gap of 5min. I only see 5min and older Events in Kibana. How to debug this Situation?…

---

## [Beats (metricbeat and filebeat) does't start as windows service](https://discuss.elastic.co/t/beats-metricbeat-and-filebeat-doest-start-as-windows-service/228877)

<div class="topic-metadata">

**Author:** [@Harpello](https://discuss.elastic.co/u/Harpello)\
**Replies:** 4\
**Last updated:** [April 22, 2020, 7:20pm UTC](https://discuss.elastic.co/t/beats-metricbeat-and-filebeat-doest-start-as-windows-service/228877 "2020-04-22T19:20:39Z")

</div>

Behavior: Behaviors for filebeat and metricbeat are exactly the same. Windows services filebeat and metricbeat does not start automatic after reboot. Manual start of service failes with error '1053: The service did no…

---

## [Problem with big log files](https://discuss.elastic.co/t/problem-with-big-log-files/229325)

<div class="topic-metadata">

**Author:** [@Adryeh](https://discuss.elastic.co/u/Adryeh)\
**Replies:** 0\
**Last updated:** [April 22, 2020, 5:33pm UTC](https://discuss.elastic.co/t/problem-with-big-log-files/229325 "2020-04-22T17:33:27Z")

</div>

Hi to all! I am using filebeat version 6.8.8 and i have a problem. I need to bring deploy logs to kibana. Each file have 1-2k lines and for parsing in Logstash i need whole file content and there is my problem. If i us…

---

## [User.name field for event ID 4104](https://discuss.elastic.co/t/user-name-field-for-event-id-4104/229296)

<div class="topic-metadata">

**Author:** [@\_finack](https://discuss.elastic.co/u/_finack)\
**Replies:** 1\
**Last updated:** [April 22, 2020, 4:06pm UTC](https://discuss.elastic.co/t/user-name-field-for-event-id-4104/229296 "2020-04-22T16:06:08Z")

</div>

I want event ID 4104 (PowerShell scriptblock logging) to populate the username in the user.name field. What is the best way to get the username to populate into the user.name field in Elasticsearch? Event IDs 4688 and 1…

---

## [Auditbeat file integrity doesn't scans shares nor mount points](https://discuss.elastic.co/t/auditbeat-file-integrity-doesnt-scans-shares-nor-mount-points/229291)

<div class="topic-metadata">

**Author:** [@ormaman](https://discuss.elastic.co/u/ormaman)\
**Replies:** 0\
**Last updated:** [April 22, 2020, 3:01pm UTC](https://discuss.elastic.co/t/auditbeat-file-integrity-doesnt-scans-shares-nor-mount-points/229291 "2020-04-22T15:01:54Z")

</div>

auditbeat file integrity doesn't scans shares nor mount points I tried to mount windows share to a windows machine with a auditbeat on it mapped to Z: The auditbeat does not recognizing changes there moreover i tried…

---

## [Filebeat on Windows not indexing into name on yml](https://discuss.elastic.co/t/filebeat-on-windows-not-indexing-into-name-on-yml/225886)

<div class="topic-metadata">

**Author:** [@math1324](https://discuss.elastic.co/u/math1324)\
**Replies:** 1\
**Last updated:** [April 22, 2020, 2:11pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-not-indexing-into-name-on-yml/225886 "2020-04-22T14:11:01Z")

</div>

New to Beats, trying to figure out why Filebeat is sending data to ES in the default file index name filebeat--, when my yml configuration states that I want it to go into logs\_server1: filebeat.inputs: - type: log e…

---

## [WInlogbeats Error after upgrade](https://discuss.elastic.co/t/winlogbeats-error-after-upgrade/227791)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 1\
**Last updated:** [April 22, 2020, 2:06pm UTC](https://discuss.elastic.co/t/winlogbeats-error-after-upgrade/227791 "2020-04-22T14:06:14Z")

</div>

Hi everyone i upgraded from 6.2.4 winlogbeats to 6.8 Same exact configs, same logstash conf file I now get this error any ideas ? \[2020-04-13T11:18:30,467\]\[WARN \]\[logstash.outputs.elasticsearch\] Could not index event…

---

## [Filebeat not shipping Exceptions and Error message logs from my log file?](https://discuss.elastic.co/t/filebeat-not-shipping-exceptions-and-error-message-logs-from-my-log-file/228016)

<div class="topic-metadata">

**Author:** [@Pacha\_Gopi](https://discuss.elastic.co/u/Pacha_Gopi)\
**Replies:** 1\
**Last updated:** [April 22, 2020, 1:54pm UTC](https://discuss.elastic.co/t/filebeat-not-shipping-exceptions-and-error-message-logs-from-my-log-file/228016 "2020-04-22T13:54:52Z")

</div>

Hi i am using filebeat for shipping my logs to logstash,problem that i am facing is filebeat not sending the Exception and Error message from my log file can anyone help me on this my log file logs are mentioned below \[…

---

## [System process informamtion logged wrong?](https://discuss.elastic.co/t/system-process-informamtion-logged-wrong/228676)

<div class="topic-metadata">

**Author:** [@suikast42](https://discuss.elastic.co/u/suikast42)\
**Replies:** 1\
**Last updated:** [April 22, 2020, 1:45pm UTC](https://discuss.elastic.co/t/system-process-informamtion-logged-wrong/228676 "2020-04-22T13:45:26Z")

</div>

The docu says that process name is exported under the field system.process.name But in the metricbeat index it under process.name I am running on V 7.6.2

---

## [Jolokia Module Exec Operation](https://discuss.elastic.co/t/jolokia-module-exec-operation/229139)

<div class="topic-metadata">

**Author:** [@jason\_0](https://discuss.elastic.co/u/jason_0)\
**Replies:** 1\
**Last updated:** [April 22, 2020, 1:15pm UTC](https://discuss.elastic.co/t/jolokia-module-exec-operation/229139 "2020-04-22T13:15:08Z")

</div>

Hi Team, Our developers are using Jolokia to perform various actions. One of which is an exec operation that returns some application telemetry we want to ingest into elasticsearch via metricbeat Jolokia module. The URL…

---

## [Failed to list \*v1beta1.ReplicaSet](https://discuss.elastic.co/t/failed-to-list-v1beta1-replicaset/229179)

<div class="topic-metadata">

**Author:** [@rajputvishwas](https://discuss.elastic.co/u/rajputvishwas)\
**Replies:** 0\
**Last updated:** [April 22, 2020, 5:59am UTC](https://discuss.elastic.co/t/failed-to-list-v1beta1-replicaset/229179 "2020-04-22T05:59:21Z")

</div>

I have setup metricbeat-7.5.2 on kubernetes using the instructions available @ kauri. my pod is up and running fine and I am also able to view metrics in kibana. When I was going through the pod logs I found an error, …

---

## [Creating a beat based on metric beat](https://discuss.elastic.co/t/creating-a-beat-based-on-metric-beat/229253)

<div class="topic-metadata">

**Author:** [@nabeel\_ahmed](https://discuss.elastic.co/u/nabeel_ahmed)\
**Replies:** 0\
**Last updated:** [April 22, 2020, 12:05pm UTC](https://discuss.elastic.co/t/creating-a-beat-based-on-metric-beat/229253 "2020-04-22T12:05:31Z")

</div>

Hi, i am creating a beat based on metric and follow this documentation https://www.elastic.co/guide/en/beats/devguide/current/creating-beat-from-metricbeat.html But it gave me Kibana dashboards error: vendor/githu…

---

## [Filebeat refuse connect to Logstash port- "Connection timed out error"](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803)

<div class="topic-metadata">

**Author:** [@pash123](https://discuss.elastic.co/u/pash123)\
**Replies:** 6\
**Last updated:** [April 22, 2020, 9:38am UTC](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803 "2020-04-22T09:38:55Z")

</div>

Hi all, I have installed FB on Linux server and LG on my local server. (ES and Kibana installed on local server as well) \*\*LG configuration:\*\* input{ beats{ port =\> 5044 } } output { elasticsearch { hosts…

---

## [Why is filebeat reading log files over and over again](https://discuss.elastic.co/t/why-is-filebeat-reading-log-files-over-and-over-again/224654)

<div class="topic-metadata">

**Author:** [@SjonnieW](https://discuss.elastic.co/u/SjonnieW)\
**Replies:** 6\
**Last updated:** [April 22, 2020, 6:37am UTC](https://discuss.elastic.co/t/why-is-filebeat-reading-log-files-over-and-over-again/224654 "2020-04-22T06:37:52Z")

</div>

Hello all I know this was posted before, only i never read a satifying answer\\solution. I was advised by my user succes manager to post the problem here Using a windows10 environment (also tried on Linux) I am using …

---

## [Heartbeat when reload.enabled: true](https://discuss.elastic.co/t/heartbeat-when-reload-enabled-true/227619)

<div class="topic-metadata">

**Author:** [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Replies:** 5\
**Last updated:** [April 22, 2020, 1:21am UTC](https://discuss.elastic.co/t/heartbeat-when-reload-enabled-true/227619 "2020-04-22T01:21:55Z")

</div>

Dear developers, Elasticsearch 7.6.2 I have issue in the heartbeat when reload.enabled change to true. The condition as follow: I have around 120 monitor yml file I created around 40 new monitor yml file Before the …

---

## [Heartbeat using Docker hints](https://discuss.elastic.co/t/heartbeat-using-docker-hints/227768)

<div class="topic-metadata">

**Author:** [@nedim](https://discuss.elastic.co/u/nedim)\
**Replies:** 7\
**Last updated:** [April 22, 2020, 1:21am UTC](https://discuss.elastic.co/t/heartbeat-using-docker-hints/227768 "2020-04-22T01:21:44Z")

</div>

I am trying to setup heartbeat using hints/labels and I am getting the following error \`\`\` 2020-04-11T06:02:38.483Z WARN \[hints.builder\] hints/monitors.go:195 unable to frame a host from input host: %shost.my.domain.io …

---

## [HeartBeat - Envio de alerta de UPTIME por email](https://discuss.elastic.co/t/heartbeat-envio-de-alerta-de-uptime-por-email/226745)

<div class="topic-metadata">

**Author:** [@thiago7azevedo](https://discuss.elastic.co/u/thiago7azevedo)\
**Replies:** 1\
**Last updated:** [April 22, 2020, 1:18am UTC](https://discuss.elastic.co/t/heartbeat-envio-de-alerta-de-uptime-por-email/226745 "2020-04-22T01:18:28Z")

</div>

Olá a todos! É uma grande satisfação fazer parte deste fórum. Configurei o heartbeat com a imagem docker.elastic.co/beats/heartbeat:7.5.1 rodando em um container em docker, onde verifico o UPTIME de algumas URLs. Somen…

---

## [Metricbeat's dashboard doesn't show the CentOS cpu, memory info and network traffic](https://discuss.elastic.co/t/metricbeats-dashboard-doesnt-show-the-centos-cpu-memory-info-and-network-traffic/228952)

<div class="topic-metadata">

**Author:** [@Mudboyzh](https://discuss.elastic.co/u/Mudboyzh)\
**Replies:** 0\
**Last updated:** [April 21, 2020, 4:01am UTC](https://discuss.elastic.co/t/metricbeats-dashboard-doesnt-show-the-centos-cpu-memory-info-and-network-traffic/228952 "2020-04-21T04:01:43Z")

</div>

I used Metricbeat to collect servers system status, but I found something strange. There are two OSs in my servers. The Window Servers work fine, but the one of CentOS Servers seems to lost cpu, memory info and network …

---

## [AWS metricbeat ELB not working](https://discuss.elastic.co/t/aws-metricbeat-elb-not-working/229064)

<div class="topic-metadata">

**Author:** [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Replies:** 1\
**Last updated:** [April 21, 2020, 7:28pm UTC](https://discuss.elastic.co/t/aws-metricbeat-elb-not-working/229064 "2020-04-21T19:28:34Z")

</div>

I am working on the latest version of Metricbeat. I have configured the AWS module to work in one of my AWS accounts. It seems there are a few issues with some of the dashboards. ELB dashboard doesn't generate data. Wh…

---

## [Tracking SQL Queries](https://discuss.elastic.co/t/tracking-sql-queries/229055)

<div class="topic-metadata">

**Author:** [@Ray\_Rondini](https://discuss.elastic.co/u/Ray_Rondini)\
**Replies:** 2\
**Last updated:** [April 21, 2020, 7:24pm UTC](https://discuss.elastic.co/t/tracking-sql-queries/229055 "2020-04-21T19:24:28Z")

</div>

Super noob here, who barely knows what he's asking. We'd like to somehow keep track of who executed queries in SQL, preferably with at least 30 days history. Possible?

---

## [Docker logs not parsed](https://discuss.elastic.co/t/docker-logs-not-parsed/229075)

<div class="topic-metadata">

**Author:** [@cjack03](https://discuss.elastic.co/u/cjack03)\
**Replies:** 2\
**Last updated:** [April 21, 2020, 5:44pm UTC](https://discuss.elastic.co/t/docker-logs-not-parsed/229075 "2020-04-21T17:44:33Z")

</div>

I'm pulling my hair out, please help!! I have a very basic setup: Filebeat (7.6.2) sending docker logs to elasticsearch (7.6.2) everything is working exactly as expected EXCEPT the actual docker logs are not being deco…

---

## [Is there a Go API to read output.logstash yml settings from a custom libbeat](https://discuss.elastic.co/t/is-there-a-go-api-to-read-output-logstash-yml-settings-from-a-custom-libbeat/229072)

<div class="topic-metadata">

**Author:** [@rmauri](https://discuss.elastic.co/u/rmauri)\
**Replies:** 0\
**Last updated:** [April 21, 2020, 2:41pm UTC](https://discuss.elastic.co/t/is-there-a-go-api-to-read-output-logstash-yml-settings-from-a-custom-libbeat/229072 "2020-04-21T14:41:52Z")

</div>

I have a custom beat based on libbeat, that parses log files and adds fields and their value to the beat event to be output to logstash. The log files contain json that get unmarshaled by go and then translated from a go…

---

## [AMQP dump writes incorrect body](https://discuss.elastic.co/t/amqp-dump-writes-incorrect-body/229067)

<div class="topic-metadata">

**Author:** [@\_yumi](https://discuss.elastic.co/u/_yumi)\
**Replies:** 0\
**Last updated:** [April 21, 2020, 2:22pm UTC](https://discuss.elastic.co/t/amqp-dump-writes-incorrect-body/229067 "2020-04-21T14:22:45Z")

</div>

Hello! I'm using packetbeat to capture AMQP traffic with send\_response option enabled. Messages are in JSON. Sometimes it shows me valid JSON that was expected, but sometimes response looks like list of a numbers (I'll …

---

## [Filebeats(7.6.2) duplicates logs entries on idle minikube instance](https://discuss.elastic.co/t/filebeats-7-6-2-duplicates-logs-entries-on-idle-minikube-instance/229063)

<div class="topic-metadata">

**Author:** [@nickytd](https://discuss.elastic.co/u/nickytd)\
**Replies:** 0\
**Last updated:** [April 21, 2020, 1:56pm UTC](https://discuss.elastic.co/t/filebeats-7-6-2-duplicates-logs-entries-on-idle-minikube-instance/229063 "2020-04-21T13:56:11Z")

</div>

Hi here is a helm chart that installs filebeat, journalbeat, kibana and ES instance on a minikube. Upon start the log entries are seen to be duplicated by the Filebeat Same origin (file path and offset) Can you ple…

---

## [Filebeat (7.6.2) crashes on fingerprint](https://discuss.elastic.co/t/filebeat-7-6-2-crashes-on-fingerprint/228805)

<div class="topic-metadata">

**Author:** [@nickytd](https://discuss.elastic.co/u/nickytd)\
**Replies:** 2\
**Last updated:** [April 21, 2020, 1:49pm UTC](https://discuss.elastic.co/t/filebeat-7-6-2-crashes-on-fingerprint/228805 "2020-04-21T13:49:34Z")

</div>

filebeat crashes when adding fingerprint Can you please take a look and confirm? Thanks. Here is the stack trace: ... panic: d.nx != 0 goroutine 113 \[running\]: crypto/sha256.(\*digest).checkSum(0xc000c0f950, 0x0, 0x0…

---

## [AWS metricbeat config, Access Denied](https://discuss.elastic.co/t/aws-metricbeat-config-access-denied/228548)

<div class="topic-metadata">

**Author:** [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Replies:** 15\
**Last updated:** [April 21, 2020, 1:48pm UTC](https://discuss.elastic.co/t/aws-metricbeat-config-access-denied/228548 "2020-04-21T13:48:23Z")

</div>

Hello, I am trying to configure Metricbeat to collect AWS metrics. I have tried configuring it to use credential profile and even explicity setting the access keys inside the yml. It keeps saying I dont have enough perm…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=255)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=257)
