# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=257

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 258

---

## [Filebeat syslog input : enable both TCP + UDP on port 514](https://discuss.elastic.co/t/filebeat-syslog-input-enable-both-tcp-udp-on-port-514/228671)

<div class="topic-metadata">

**Author:** [@webfr](https://discuss.elastic.co/u/webfr)\
**Replies:** 2\
**Last updated:** [April 21, 2020, 1:34pm UTC](https://discuss.elastic.co/t/filebeat-syslog-input-enable-both-tcp-udp-on-port-514/228671 "2020-04-21T13:34:32Z")

</div>

Hello guys, I can't enable BOTH protocols on port 514 with settings below in filebeat.yml Does this input only support one protocol at a time? Nothing is written if I enable both protocols, I also tried with different …

---

## [Multi-line configuration with the filebeat](https://discuss.elastic.co/t/multi-line-configuration-with-the-filebeat/227673)

<div class="topic-metadata">

**Author:** [@Ganesh\_Bhosale](https://discuss.elastic.co/u/Ganesh_Bhosale)\
**Replies:** 1\
**Last updated:** [April 21, 2020, 12:24pm UTC](https://discuss.elastic.co/t/multi-line-configuration-with-the-filebeat/227673 "2020-04-21T12:24:42Z")

</div>

Hello, I am having challenges to set up the filebeat to honor multiline configurations so I need your help. I am configuring filebeat to ship the logs from linux servers where large number of docker containers are runni…

---

## [Filebeat Netflow Input to Logstash Elastiflow Pipeline](https://discuss.elastic.co/t/filebeat-netflow-input-to-logstash-elastiflow-pipeline/229020)

<div class="topic-metadata">

**Author:** [@ksremo](https://discuss.elastic.co/u/ksremo)\
**Replies:** 0\
**Last updated:** [April 21, 2020, 10:53am UTC](https://discuss.elastic.co/t/filebeat-netflow-input-to-logstash-elastiflow-pipeline/229020 "2020-04-21T10:53:18Z")

</div>

I installed the elastiflow pipelines/module on my Logstash. The Netflow-Data is ingested in a Filebeat (input netflow) and then forwarded to a Logstash pipeline. In this Pipeline there is a switch/case on the log type. …

---

## [Pipeline definition in filebeat.yml doesn't work](https://discuss.elastic.co/t/pipeline-definition-in-filebeat-yml-doesnt-work/229009)

<div class="topic-metadata">

**Author:** [@Burga](https://discuss.elastic.co/u/Burga)\
**Replies:** 2\
**Last updated:** [April 21, 2020, 10:12am UTC](https://discuss.elastic.co/t/pipeline-definition-in-filebeat-yml-doesnt-work/229009 "2020-04-21T10:12:26Z")

</div>

Hi , trying to configure filebeat to use pipeline , but it doesnt work my filebeat.yml pipeline configuration looks like this filebeat.inputs: - type: log paths: - /var/log/messages # - /var/log/\*.log d…

---

## [Parse json data from log file into Kibana via Filebeat and Logstash](https://discuss.elastic.co/t/parse-json-data-from-log-file-into-kibana-via-filebeat-and-logstash/228627)

<div class="topic-metadata">

**Author:** [@theFatCat](https://discuss.elastic.co/u/theFatCat)\
**Replies:** 9\
**Last updated:** [April 21, 2020, 9:17am UTC](https://discuss.elastic.co/t/parse-json-data-from-log-file-into-kibana-via-filebeat-and-logstash/228627 "2020-04-21T09:17:06Z")

</div>

I am using Filebeat and Logstash for parsing json log file into Kibana. filebeat.inputs: - type: log enabled: true paths: - /home/tiennd/filebeat/logstash/\*.json json.keys\_under\_root: true processors: - add…

---

## [How to implement multiple multiline filters in filebeat using autodiscover](https://discuss.elastic.co/t/how-to-implement-multiple-multiline-filters-in-filebeat-using-autodiscover/228978)

<div class="topic-metadata">

**Author:** [@user2416](https://discuss.elastic.co/u/user2416)\
**Replies:** 0\
**Last updated:** [April 21, 2020, 7:13am UTC](https://discuss.elastic.co/t/how-to-implement-multiple-multiline-filters-in-filebeat-using-autodiscover/228978 "2020-04-21T07:13:30Z")

</div>

I have installed filebeat on kubernetes as deamonset to collect all kubernetes logs. we have different log patterns and also have to multiline filters of different kind of logs. I wrote autodiscover configuration matchin…

---

## [Using filebeat modules with custom fields](https://discuss.elastic.co/t/using-filebeat-modules-with-custom-fields/228909)

<div class="topic-metadata">

**Author:** [@Burga](https://discuss.elastic.co/u/Burga)\
**Replies:** 3\
**Last updated:** [April 20, 2020, 11:11pm UTC](https://discuss.elastic.co/t/using-filebeat-modules-with-custom-fields/228909 "2020-04-20T23:11:30Z")

</div>

Hi guys , I'm wondering , can I enable module and use fields in filebeat.yml file? I just configured filebeat input filebeat.inputs: - type: log paths: - /var/log/messages document\_type: syslog fields: …

---

## [Metricbeat AWS Cloudwatch & AWS ELB](https://discuss.elastic.co/t/metricbeat-aws-cloudwatch-aws-elb/226089)

<div class="topic-metadata">

**Author:** [@Anton91](https://discuss.elastic.co/u/Anton91)\
**Replies:** 3\
**Last updated:** [April 20, 2020, 10:21pm UTC](https://discuss.elastic.co/t/metricbeat-aws-cloudwatch-aws-elb/226089 "2020-04-20T22:21:38Z")

</div>

Hello, everybody, unfortunately I do not get any data on AWS Cloudwatch & AWS ELB with Metricbeat. With AWS Cloudwatch I only get the data for EC2 and S3. All other modules work ec2,sqs,rds,ebs The following settings …

---

## [GenerateCustomBeat - logs was keep rooling with mage -debug GenerateCustomBeat](https://discuss.elastic.co/t/generatecustombeat-logs-was-keep-rooling-with-mage-debug-generatecustombeat/228596)

<div class="topic-metadata">

**Author:** [@visasimbu](https://discuss.elastic.co/u/visasimbu)\
**Replies:** 2\
**Last updated:** [April 20, 2020, 8:39pm UTC](https://discuss.elastic.co/t/generatecustombeat-logs-was-keep-rooling-with-mage-debug-generatecustombeat/228596 "2020-04-20T20:39:16Z")

</div>

I have followed below steps to create custom beat and which results me to infinite loop. I was digging for past 2 days. Kindly help me. Go version source editor go version go1.13.10 windows/amd64 Go environment varia…

---

## [Import a lot of wrong data](https://discuss.elastic.co/t/import-a-lot-of-wrong-data/228732)

<div class="topic-metadata">

**Author:** [@zero.lim](https://discuss.elastic.co/u/zero.lim)\
**Replies:** 1\
**Last updated:** [April 20, 2020, 8:32pm UTC](https://discuss.elastic.co/t/import-a-lot-of-wrong-data/228732 "2020-04-20T20:32:46Z")

</div>

Hi all , I want to transfer the data of aws cloudwatch (cloudfront) to elasticsearch But I found that my elasticsearch has a lot of redundant information. Why? I don't want the information in the two pictures I…

---

## [Is it possible to get a template for Kibana that includes only fields related to activated modules?](https://discuss.elastic.co/t/is-it-possible-to-get-a-template-for-kibana-that-includes-only-fields-related-to-activated-modules/228895)

<div class="topic-metadata">

**Author:** [@Karel\_Cech](https://discuss.elastic.co/u/Karel_Cech)\
**Replies:** 2\
**Last updated:** [April 20, 2020, 8:01pm UTC](https://discuss.elastic.co/t/is-it-possible-to-get-a-template-for-kibana-that-includes-only-fields-related-to-activated-modules/228895 "2020-04-20T20:01:08Z")

</div>

Hi, AFAIK, I have only the Apache module enabled. The command filebeat export template outputs a very long list of fields I'll never have in the index. Filebeat does not have access to Kibana, we use Logstash. But I d…

---

## [7.6.2 Requires Restart of Server](https://discuss.elastic.co/t/7-6-2-requires-restart-of-server/228409)

<div class="topic-metadata">

**Author:** [@Nerbelir](https://discuss.elastic.co/u/Nerbelir)\
**Replies:** 3\
**Last updated:** [April 20, 2020, 7:23pm UTC](https://discuss.elastic.co/t/7-6-2-requires-restart-of-server/228409 "2020-04-20T19:23:59Z")

</div>

I'm just getting around to setting up WinlogBeat. It appears if I used the msi installer or the traditional method, I only get the server to start when the server starts up. If I stop the service to make any changes to t…

---

## [Filebeat - Uppercase log file path](https://discuss.elastic.co/t/filebeat-uppercase-log-file-path/228552)

<div class="topic-metadata">

**Author:** [@VSP](https://discuss.elastic.co/u/VSP)\
**Replies:** 2\
**Last updated:** [April 20, 2020, 6:41pm UTC](https://discuss.elastic.co/t/filebeat-uppercase-log-file-path/228552 "2020-04-20T18:41:23Z")

</div>

Hi , new to filebeat. Been trying to send different types of logs through filebeat to Logstash -\> Elasticsearch. While filebeat is able to read the path of a log file which is in lowercase, it failed to harvest an upperc…

---

## [Is there way to pull logs from remote Linux server instead of installing filebeat on the server and it pushes logs to logstash?](https://discuss.elastic.co/t/is-there-way-to-pull-logs-from-remote-linux-server-instead-of-installing-filebeat-on-the-server-and-it-pushes-logs-to-logstash/228868)

<div class="topic-metadata">

**Author:** [@bhagirath\_h](https://discuss.elastic.co/u/bhagirath_h)\
**Replies:** 1\
**Last updated:** [April 20, 2020, 3:09pm UTC](https://discuss.elastic.co/t/is-there-way-to-pull-logs-from-remote-linux-server-instead-of-installing-filebeat-on-the-server-and-it-pushes-logs-to-logstash/228868 "2020-04-20T15:09:23Z")

</div>

Rather than installing filebeat on each linux server and pushing the logs to logstash, I need some way to pull the logs from all linux servers having no need to install filebeat or any other plugin on the linux servers

---

## [Metricbeat-7.6.2-linux fails to start when activemq module is enabled](https://discuss.elastic.co/t/metricbeat-7-6-2-linux-fails-to-start-when-activemq-module-is-enabled/228546)

<div class="topic-metadata">

**Author:** [@sm12356](https://discuss.elastic.co/u/sm12356)\
**Replies:** 1\
**Last updated:** [April 20, 2020, 2:59pm UTC](https://discuss.elastic.co/t/metricbeat-7-6-2-linux-fails-to-start-when-activemq-module-is-enabled/228546 "2020-04-20T14:59:47Z")

</div>

I am trying to enable the activemq module on metricbeat-7.6.2 on Linux but I keep getting the below error when I start metricbeat. 2020-04-17T16:00:26.399Z INFO instance/beat.go:445 metricbeat stopped. 2020…

---

## [Filebeat not creating new index in Elastic search?](https://discuss.elastic.co/t/filebeat-not-creating-new-index-in-elastic-search/228644)

<div class="topic-metadata">

**Author:** [@pracks1982](https://discuss.elastic.co/u/pracks1982)\
**Replies:** 1\
**Last updated:** [April 20, 2020, 2:56pm UTC](https://discuss.elastic.co/t/filebeat-not-creating-new-index-in-elastic-search/228644 "2020-04-20T14:56:24Z")

</div>

I have a microservice users-ws for which i want to see logs getting pulled by filebeat and send to elasticsearch and logstash for searching and filtering. I have a problem that with the configuration below its not crea…

---

## [Beats status at Kibana or API](https://discuss.elastic.co/t/beats-status-at-kibana-or-api/228167)

<div class="topic-metadata">

**Author:** [@adminunix](https://discuss.elastic.co/u/adminunix)\
**Replies:** 3\
**Last updated:** [April 20, 2020, 2:04pm UTC](https://discuss.elastic.co/t/beats-status-at-kibana-or-api/228167 "2020-04-20T14:04:27Z")

</div>

Hi, Is it possible to know the connection status of the beats in Kibana? Stack Monitoring include statistics and the active beats, but not malfunctioning beats. Example Active Beats: Stack Monitoring --\> Cluster --\> Be…

---

## [Logstash Pipelines for Parsing Questions - No fileset in output](https://discuss.elastic.co/t/logstash-pipelines-for-parsing-questions-no-fileset-in-output/228519)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 10\
**Last updated:** [April 20, 2020, 11:48am UTC](https://discuss.elastic.co/t/logstash-pipelines-for-parsing-questions-no-fileset-in-output/228519 "2020-04-20T11:48:43Z")

</div>

I've tried following https://www.elastic.co/guide/en/logstash/7.6/logstash-config-for-filebeat-modules.html, and create logstash pipelines to parse the filebeat data. However, even the examples provided in that link don…

---

## [Filebat signals](https://discuss.elastic.co/t/filebat-signals/228670)

<div class="topic-metadata">

**Author:** [@elastic\_user1](https://discuss.elastic.co/u/elastic_user1)\
**Replies:** 0\
**Last updated:** [April 18, 2020, 6:06pm UTC](https://discuss.elastic.co/t/filebat-signals/228670 "2020-04-18T18:06:26Z")

</div>

I noticed following in my log when i could not connect to Logstash logs: NFO pipeline/output.go:93 Attempting to reconnect to backoff(async()) with 3 reconnect attempt(s) NFO \[publisher\] …

---

## [Failed to hash executable /usr/sbin/agetty](https://discuss.elastic.co/t/failed-to-hash-executable-usr-sbin-agetty/228283)

<div class="topic-metadata">

**Author:** [@StefanDE](https://discuss.elastic.co/u/StefanDE)\
**Replies:** 1\
**Last updated:** [April 20, 2020, 7:51am UTC](https://discuss.elastic.co/t/failed-to-hash-executable-usr-sbin-agetty/228283 "2020-04-20T07:51:35Z")

</div>

On RHEL when starting auditbeat I get this errormessage via journalctl -u auditbeat: WARN \[process\] process/process.go:234 failed to hash executable /usr/sbin/agetty;5e46b406 (deleted) for PID 1140…

---

## [Filebeat + Netflow error: "bind: cannot assign requested address"](https://discuss.elastic.co/t/filebeat-netflow-error-bind-cannot-assign-requested-address/228479)

<div class="topic-metadata">

**Author:** [@Minh\_Ti\_n\_Tr\_n](https://discuss.elastic.co/u/Minh_Ti_n_Tr_n)\
**Replies:** 3\
**Last updated:** [April 20, 2020, 2:53am UTC](https://discuss.elastic.co/t/filebeat-netflow-error-bind-cannot-assign-requested-address/228479 "2020-04-20T02:53:03Z")

</div>

Dear all, I config filebeat and netflow ( softflowd on pfsense ) but I got issue. Any solution for that? Thanks systemctl status filebeat -l ● filebeat.service - Filebeat sends log files to Logstash or directly to Ela…

---

## [Filebeat EKS - sidecar container](https://discuss.elastic.co/t/filebeat-eks-sidecar-container/228741)

<div class="topic-metadata">

**Author:** [@samaresh\_kirtania](https://discuss.elastic.co/u/samaresh_kirtania)\
**Replies:** 0\
**Last updated:** [April 19, 2020, 3:38pm UTC](https://discuss.elastic.co/t/filebeat-eks-sidecar-container/228741 "2020-04-19T15:38:26Z")

</div>

Hi, I have a 3rd party image deployed in EKS, and it writes a lot of logs in different files. Now I have to push the logs from different files generated by the product into ES and viewed through Kibana I am using sidec…

---

## [Multiline not working properly](https://discuss.elastic.co/t/multiline-not-working-properly/228636)

<div class="topic-metadata">

**Author:** [@haneefh](https://discuss.elastic.co/u/haneefh)\
**Replies:** 0\
**Last updated:** [April 18, 2020, 11:35am UTC](https://discuss.elastic.co/t/multiline-not-working-properly/228636 "2020-04-18T11:35:11Z")

</div>

I am using filebeats to send Atlassian catalina Logs. Below is a snippet filebeat configuration - /opt/atlassian/jira/logs/catalina.out fields: log\_type: catalina log\_application: atlassian\_jira multiline.pattern: '…

---

## [Pull Request](https://discuss.elastic.co/t/pull-request/228624)

<div class="topic-metadata">

**Author:** [@saw.wn](https://discuss.elastic.co/u/saw.wn)\
**Replies:** 0\
**Last updated:** [April 18, 2020, 7:42am UTC](https://discuss.elastic.co/t/pull-request/228624 "2020-04-18T07:42:14Z")

</div>

Our team has created filebeat module. I request PR but elastic didn't reply anything. Please guide me.

---

## [Installing Beats (Filebeat, Auditbeat, etc) on remote host](https://discuss.elastic.co/t/installing-beats-filebeat-auditbeat-etc-on-remote-host/228590)

<div class="topic-metadata">

**Author:** [@mokotoy](https://discuss.elastic.co/u/mokotoy)\
**Replies:** 0\
**Last updated:** [April 17, 2020, 9:54pm UTC](https://discuss.elastic.co/t/installing-beats-filebeat-auditbeat-etc-on-remote-host/228590 "2020-04-17T21:54:32Z")

</div>

I have an ELK stack install on a RockNSM 2.5 machine with Elastic version 7.6 I have the server running and I want to install beats on other hosts in my network. I'm running into issues running the beats setup as it kee…

---

## [Exclude lines not working with multiline](https://discuss.elastic.co/t/exclude-lines-not-working-with-multiline/228411)

<div class="topic-metadata">

**Author:** [@EliWallic](https://discuss.elastic.co/u/EliWallic)\
**Replies:** 3\
**Last updated:** [April 17, 2020, 9:03pm UTC](https://discuss.elastic.co/t/exclude-lines-not-working-with-multiline/228411 "2020-04-17T21:03:00Z")

</div>

Hello, I am trying to import some logs and configured it with an exclusion line and multiline. If I configure just the exclusion its working for this but if I also configure multiline in addition it seems to be ignored…

---

## [Creating new filebeat image by adding custom plugins](https://discuss.elastic.co/t/creating-new-filebeat-image-by-adding-custom-plugins/228329)

<div class="topic-metadata">

**Author:** [@jaks](https://discuss.elastic.co/u/jaks)\
**Replies:** 1\
**Last updated:** [April 17, 2020, 5:58pm UTC](https://discuss.elastic.co/t/creating-new-filebeat-image-by-adding-custom-plugins/228329 "2020-04-17T17:58:04Z")

</div>

I am using filbeat 7.6.2 in Kubernetes. I need to add custom processors like beats-processor-fingerprint to this. I can find instructions to run filebeat in standalone mode with custom plugins, but not on where to add wh…

---

## [Extract some fields from json and assing to a root](https://discuss.elastic.co/t/extract-some-fields-from-json-and-assing-to-a-root/228289)

<div class="topic-metadata">

**Author:** [@esseti](https://discuss.elastic.co/u/esseti)\
**Replies:** 1\
**Last updated:** [April 17, 2020, 5:56pm UTC](https://discuss.elastic.co/t/extract-some-fields-from-json-and-assing-to-a-root/228289 "2020-04-17T17:56:13Z")

</div>

Hi all, i've in a log file a series of JSON that i want to parse not to extarct all the fields but only some. This is my log { "call\_type": "Example", "begin\_time": "2020-04-15T15:05:32.982520+00:…

---

## [Using timestamp processor fails](https://discuss.elastic.co/t/using-timestamp-processor-fails/228348)

<div class="topic-metadata">

**Author:** [@willyaranda\_vonage](https://discuss.elastic.co/u/willyaranda_vonage)\
**Replies:** 1\
**Last updated:** [April 17, 2020, 12:56pm UTC](https://discuss.elastic.co/t/using-timestamp-processor-fails/228348 "2020-04-17T12:56:49Z")

</div>

Hi, I have logs that are JSON, and I'm trying to set the @timestamp field based on that. The format is: 2020-04-16 05:45:51,913 with timezone as 'America/Los\_Angeles' I have set this configuration processors: - tim…

---

## [Filebeat loading index template JSON not working](https://discuss.elastic.co/t/filebeat-loading-index-template-json-not-working/228508)

<div class="topic-metadata">

**Author:** [@Kupauw](https://discuss.elastic.co/u/Kupauw)\
**Replies:** 0\
**Last updated:** [April 17, 2020, 12:08pm UTC](https://discuss.elastic.co/t/filebeat-loading-index-template-json-not-working/228508 "2020-04-17T12:08:43Z")

</div>

Hi, I'm trying to load a custom index template as JSON. This is the filebeat configuration im using: setup.template.json.enable: true setup.template.json.path: "index\_template\_perimeter.json" setup.template.json.name: …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=256)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=258)
