# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=259

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 260

---

## [ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch(https://\<ES\_URL\>)): 401 Unauthorized](https://discuss.elastic.co/t/error-pipeline-output-go-100-failed-to-connect-to-backoff-elasticsearch-https-es-url-401-unauthorized/227772)

<div class="topic-metadata">

**Author:** [@\_kyllr](https://discuss.elastic.co/u/_kyllr)\
**Replies:** 4\
**Last updated:** [April 14, 2020, 10:30am UTC](https://discuss.elastic.co/t/error-pipeline-output-go-100-failed-to-connect-to-backoff-elasticsearch-https-es-url-401-unauthorized/227772 "2020-04-14T10:30:20Z")

</div>

Hello, AWS Elasticsearch Version: 7.1 aws-es-proxy-0.9-windows-amd64.exe Kibana OSS 7.1.1 Filebeat OSS 7.1.1 This is a production issue on our windows server, we suddenly got this error from filebeat logs: 2020-04…

---

## [Filebeat 6.8.6 - Get kernel version of OS](https://discuss.elastic.co/t/filebeat-6-8-6-get-kernel-version-of-os/227823)

<div class="topic-metadata">

**Author:** [@michael\_sc](https://discuss.elastic.co/u/michael_sc)\
**Replies:** 1\
**Last updated:** [April 14, 2020, 9:13am UTC](https://discuss.elastic.co/t/filebeat-6-8-6-get-kernel-version-of-os/227823 "2020-04-14T09:13:55Z")

</div>

I want to add the kernel version of the host to the filebeat output. Can I do that with this version, and if so, where in the config file do I need to add parameters.

---

## [To Read particular event form text file](https://discuss.elastic.co/t/to-read-particular-event-form-text-file/227861)

<div class="topic-metadata">

**Author:** [@aman97](https://discuss.elastic.co/u/aman97)\
**Replies:** 2\
**Last updated:** [April 14, 2020, 9:10am UTC](https://discuss.elastic.co/t/to-read-particular-event-form-text-file/227861 "2020-04-14T09:10:37Z")

</div>

Hi, I am having a multiline text file with multiple events, I want to read a particular event from a file. First, I want to know how can I read this particular multiline text file in filebeat then after how can i extr…

---

## [\[Auditbeat\] Memory leak in 7.5.2](https://discuss.elastic.co/t/auditbeat-memory-leak-in-7-5-2/218335)

<div class="topic-metadata">

**Author:** [@nickbabkin](https://discuss.elastic.co/u/nickbabkin)\
**Replies:** 17\
**Last updated:** [April 14, 2020, 8:32am UTC](https://discuss.elastic.co/t/auditbeat-memory-leak-in-7-5-2/218335 "2020-04-14T08:32:38Z")

</div>

Hi! It seems like there's a memory leak in latest version of auditbeat (7.5.2) that is running with socket module enabled on high network loaded servers (such as load balancers). We recently upgraded to the newest vers…

---

## [Unexpected state reading from file - stale NFS handle errors](https://discuss.elastic.co/t/unexpected-state-reading-from-file-stale-nfs-handle-errors/227853)

<div class="topic-metadata">

**Author:** [@msunilreddy](https://discuss.elastic.co/u/msunilreddy)\
**Replies:** 3\
**Last updated:** [April 14, 2020, 6:02am UTC](https://discuss.elastic.co/t/unexpected-state-reading-from-file-stale-nfs-handle-errors/227853 "2020-04-14T06:02:37Z")

</div>

Hi Team, We have deployed filebeat as docker container for reading log files by volume mounting of logs files from NFS server. We are getting stale NFS handle errors. Could you please help us how to resolve this issue.…

---

## [Filebeat performing better when reading multiple files rather the a single file](https://discuss.elastic.co/t/filebeat-performing-better-when-reading-multiple-files-rather-the-a-single-file/226800)

<div class="topic-metadata">

**Author:** [@bink](https://discuss.elastic.co/u/bink)\
**Replies:** 2\
**Last updated:** [April 14, 2020, 3:50am UTC](https://discuss.elastic.co/t/filebeat-performing-better-when-reading-multiple-files-rather-the-a-single-file/226800 "2020-04-14T03:50:09Z")

</div>

We have a cluster configured with 5 logstash servers and 30 ES servers. A single host is exporting logs from a single file across the 5 logstash servers in a load balanced configuration using the filebeat logstash output…

---

## [Config for Monitoring Windows Services by heartbeat error](https://discuss.elastic.co/t/config-for-monitoring-windows-services-by-heartbeat-error/226999)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 2\
**Last updated:** [April 14, 2020, 2:08am UTC](https://discuss.elastic.co/t/config-for-monitoring-windows-services-by-heartbeat-error/226999 "2020-04-14T02:08:08Z")

</div>

I have my elasticsearch, logstash, kibana running inside docker. The files filebeat ships are from another server. Firstly, I just want to see if up/down status is provided for windows services. Can I install heartbeat…

---

## [Heartbeat keeps getting restarted](https://discuss.elastic.co/t/heartbeat-keeps-getting-restarted/226446)

<div class="topic-metadata">

**Author:** [@hanjukim](https://discuss.elastic.co/u/hanjukim)\
**Replies:** 1\
**Last updated:** [April 14, 2020, 1:47am UTC](https://discuss.elastic.co/t/heartbeat-keeps-getting-restarted/226446 "2020-04-14T01:47:41Z")

</div>

I am using docker image elastic/heartbeat:6.8.8, and container keeps getting restarted. Full log https://pastebin.com/raw/Aag5Q3eL Configuration ############################# Heartbeat ###############################…

---

## [How to add real host name to heartbeat for metricbeat integration of website url\\ip](https://discuss.elastic.co/t/how-to-add-real-host-name-to-heartbeat-for-metricbeat-integration-of-website-url-ip/226288)

<div class="topic-metadata">

**Author:** [@shayvilk](https://discuss.elastic.co/u/shayvilk)\
**Replies:** 1\
**Last updated:** [April 14, 2020, 1:45am UTC](https://discuss.elastic.co/t/how-to-add-real-host-name-to-heartbeat-for-metricbeat-integration-of-website-url-ip/226288 "2020-04-14T01:45:07Z")

</div>

hi there... I'm trying to create a monitoring integration for our web sites. I'm using the heartbeat (standalone docker) for uptime with the external\\public URL and on the sites hosting servers, I've add filebeats and …

---

## [AWS vpcflow errors - count not find region configuration, context deadline exceeded](https://discuss.elastic.co/t/aws-vpcflow-errors-count-not-find-region-configuration-context-deadline-exceeded/225471)

<div class="topic-metadata">

**Author:** [@swisscheese](https://discuss.elastic.co/u/swisscheese)\
**Replies:** 6\
**Last updated:** [April 13, 2020, 9:18pm UTC](https://discuss.elastic.co/t/aws-vpcflow-errors-count-not-find-region-configuration-context-deadline-exceeded/225471 "2020-04-13T21:18:54Z")

</div>

I have vpc flow logs going to an S3 bucket and an SQS notification for any object creation event. I actually much preferred the logstash method of polling the bucket, for several reasons - mainly the ability to re-index…

---

## [Preconfigured Dashboards for ELB and Billing in ElasticSearch](https://discuss.elastic.co/t/preconfigured-dashboards-for-elb-and-billing-in-elasticsearch/227217)

<div class="topic-metadata">

**Author:** [@vennemp](https://discuss.elastic.co/u/vennemp)\
**Replies:** 9\
**Last updated:** [April 13, 2020, 9:13pm UTC](https://discuss.elastic.co/t/preconfigured-dashboards-for-elb-and-billing-in-elasticsearch/227217 "2020-04-13T21:13:38Z")

</div>

Hey guys, I just started using your product to get AWS metrics in to ELK and love the preconfigured EC2 dashboard. However, I was having some problems with getting the ELB and Billing dashboards to appear. I am using AWS…

---

## [Metric beat unable to detect all metricset from cloudwatch](https://discuss.elastic.co/t/metric-beat-unable-to-detect-all-metricset-from-cloudwatch/227402)

<div class="topic-metadata">

**Author:** [@Abhishek\_Tanwar](https://discuss.elastic.co/u/Abhishek_Tanwar)\
**Replies:** 7\
**Last updated:** [April 13, 2020, 7:24pm UTC](https://discuss.elastic.co/t/metric-beat-unable-to-detect-all-metricset-from-cloudwatch/227402 "2020-04-13T19:24:53Z")

</div>

I want to detect AWS/SES metric set from cloud watch or basically monitor SES metrics via elastic. I tried to configure "\*" namespace but still, it doesn't query all of the namespaces. I am have tested with 7.5.1 and 7.…

---

## ["A new process has been created" appears from only half the network computers](https://discuss.elastic.co/t/a-new-process-has-been-created-appears-from-only-half-the-network-computers/227809)

<div class="topic-metadata">

**Author:** [@jacobr91](https://discuss.elastic.co/u/jacobr91)\
**Replies:** 0\
**Last updated:** [April 13, 2020, 6:07pm UTC](https://discuss.elastic.co/t/a-new-process-has-been-created-appears-from-only-half-the-network-computers/227809 "2020-04-13T18:07:07Z")

</div>

My company's network PCs all have winlogbeats now which feeds into Kibana thatI manage for the network. Every computer has the same config file, but only about half push out the hit when a new process has been created an…

---

## [Send only some fields of processor 'add\_host\_metadata'](https://discuss.elastic.co/t/send-only-some-fields-of-processor-add-host-metadata/227778)

<div class="topic-metadata">

**Author:** [@felixbarbeira](https://discuss.elastic.co/u/felixbarbeira)\
**Replies:** 1\
**Last updated:** [April 13, 2020, 5:27pm UTC](https://discuss.elastic.co/t/send-only-some-fields-of-processor-add-host-metadata/227778 "2020-04-13T17:27:05Z")

</div>

I'm using filebeat and I only need a couple of fields from the processor "add\_host\_metadata". The only way I found to send those events is the following: processors: - add\_host\_metadata: ~ And then on Elasticsearch i…

---

## [Use ingest pipelines with output.kafka specified](https://discuss.elastic.co/t/use-ingest-pipelines-with-output-kafka-specified/227762)

<div class="topic-metadata">

**Author:** [@romanfurst](https://discuss.elastic.co/u/romanfurst)\
**Replies:** 2\
**Last updated:** [April 13, 2020, 4:30pm UTC](https://discuss.elastic.co/t/use-ingest-pipelines-with-output-kafka-specified/227762 "2020-04-13T16:30:38Z")

</div>

Hello there, is it possible use ingest pipeline in filebeat without direct connection to logstash (or elastic) ? I mean in our scenario we have specified ouput.kafka (filebeat -\> kafka -\> logstash -\> elastic), however we…

---

## [Filebeat takes days to start outputting events to Logstash after a restart](https://discuss.elastic.co/t/filebeat-takes-days-to-start-outputting-events-to-logstash-after-a-restart/226954)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 2\
**Last updated:** [April 13, 2020, 12:21pm UTC](https://discuss.elastic.co/t/filebeat-takes-days-to-start-outputting-events-to-logstash-after-a-restart/226954 "2020-04-13T12:21:09Z")

</div>

Hello everyone , Can any one please help me on this serious issue please . We have installed filebeat on PROD server and we have around 50K log files in it. If I restart Filebeat , it takes days to start outputting eve…

---

## [HeartBeat ICMP question](https://discuss.elastic.co/t/heartbeat-icmp-question/224097)

<div class="topic-metadata">

**Author:** [@rguptarg](https://discuss.elastic.co/u/rguptarg)\
**Replies:** 2\
**Last updated:** [April 13, 2020, 10:30am UTC](https://discuss.elastic.co/t/heartbeat-icmp-question/224097 "2020-04-13T10:30:11Z")

</div>

Hi Team, I am new in Heartbeat/ELKStack, can you please help me to understand below points:- Can we use Heartbeat as an opensource? IS there any limitation to configure IP/host for ICMP Monitoring, I have 3000+ se…

---

## [Consistent data blackouts followed by data restoration](https://discuss.elastic.co/t/consistent-data-blackouts-followed-by-data-restoration/227389)

<div class="topic-metadata">

**Author:** [@anda](https://discuss.elastic.co/u/anda)\
**Replies:** 1\
**Last updated:** [April 13, 2020, 8:08am UTC](https://discuss.elastic.co/t/consistent-data-blackouts-followed-by-data-restoration/227389 "2020-04-13T08:08:14Z")

</div>

Every day at the same time, all data stops being coming into my cluster for a few hours. When I check again in the morning, all the data is there and there is no gap. When checking /var/log/filebeat I see this error re…

---

## [Docker Autodiscover of ElasticSearch container](https://discuss.elastic.co/t/docker-autodiscover-of-elasticsearch-container/227628)

<div class="topic-metadata">

**Author:** [@LenaSikirin](https://discuss.elastic.co/u/LenaSikirin)\
**Replies:** 1\
**Last updated:** [April 13, 2020, 12:18am UTC](https://discuss.elastic.co/t/docker-autodiscover-of-elasticsearch-container/227628 "2020-04-13T00:18:06Z")

</div>

Hi, I'm trying to ship elasticsearch logs using filebeat's autodiscover feature + container input, but don't know how to split different types of es logs properly. For nginx - I can split log easily just by using strea…

---

## [Filebeat and Minimal Server Install](https://discuss.elastic.co/t/filebeat-and-minimal-server-install/227707)

<div class="topic-metadata">

**Author:** [@mrogowski](https://discuss.elastic.co/u/mrogowski)\
**Replies:** 3\
**Last updated:** [April 12, 2020, 11:24pm UTC](https://discuss.elastic.co/t/filebeat-and-minimal-server-install/227707 "2020-04-12T23:24:57Z")

</div>

Hi folks, new user here. I just spent the last two days bashing my head against the wall trying to determine why a minimal server setup (Centos 8) would not send beat info to a remote logstash system. So after exhausti…

---

## [ARM64/aarch64 suppport (Debian Linux) for filebeat, metricbeat](https://discuss.elastic.co/t/arm64-aarch64-suppport-debian-linux-for-filebeat-metricbeat/227419)

<div class="topic-metadata">

**Author:** [@siva-eh](https://discuss.elastic.co/u/siva-eh)\
**Replies:** 5\
**Last updated:** [April 12, 2020, 9:55pm UTC](https://discuss.elastic.co/t/arm64-aarch64-suppport-debian-linux-for-filebeat-metricbeat/227419 "2020-04-12T21:55:26Z")

</div>

I have been using rsyslogd as the log forwarder, but I would prefer to use filebeat (and metricbeat). However, arm64/aarch64 is not being built as a standard platform. I installed go, and downloaded v7.6 of beats, but I'…

---

## [Filebeat-error](https://discuss.elastic.co/t/filebeat-error/227700)

<div class="topic-metadata">

**Author:** [@jatinder10884](https://discuss.elastic.co/u/jatinder10884)\
**Replies:** 1\
**Last updated:** [April 12, 2020, 8:25pm UTC](https://discuss.elastic.co/t/filebeat-error/227700 "2020-04-12T20:25:29Z")

</div>

Hi All, I am facing the below error while running filebeat docker ERROR instance/beat.go:933 Exiting: Error while initializing input: No paths were defined for input accessing 'filebeat.inputs.0' (source:'filebeat.yml'…

---

## [Logstash and kafka and order of messages](https://discuss.elastic.co/t/logstash-and-kafka-and-order-of-messages/227651)

<div class="topic-metadata">

**Author:** [@arp220](https://discuss.elastic.co/u/arp220)\
**Replies:** 0\
**Last updated:** [April 12, 2020, 8:32am UTC](https://discuss.elastic.co/t/logstash-and-kafka-and-order-of-messages/227651 "2020-04-12T08:32:29Z")

</div>

Hi. We have an application with the event log, our application send event log to Kafka with JSON format. our topic in Kafka has one partition because we need to read order message, also we use Logstash for consuming even…

---

## [Error creating new beat](https://discuss.elastic.co/t/error-creating-new-beat/227567)

<div class="topic-metadata">

**Author:** [@whatgeorgemade](https://discuss.elastic.co/u/whatgeorgemade)\
**Replies:** 1\
**Last updated:** [April 11, 2020, 10:26pm UTC](https://discuss.elastic.co/t/error-creating-new-beat/227567 "2020-04-11T22:26:02Z")

</div>

I've created beats in the past using the old method by invoking Python. This is the first time I've tried generating one using mage GenerateCustomBeat. I have the beats repo checked out in the right place and pulled lat…

---

## [Filebeat - Suricata drop\_event not working](https://discuss.elastic.co/t/filebeat-suricata-drop-event-not-working/227597)

<div class="topic-metadata">

**Author:** [@lw24](https://discuss.elastic.co/u/lw24)\
**Replies:** 0\
**Last updated:** [April 11, 2020, 10:55am UTC](https://discuss.elastic.co/t/filebeat-suricata-drop-event-not-working/227597 "2020-04-11T10:55:15Z")

</div>

Hi, I'm trying to add a drop\_event condition to drop events with Suricata alert severity below a threshold. Currently I have modified /filebeat/module/suricata/eve/config/eve.yml to contain: drop\_event: when: equals…

---

## [Metricbeat: Kibana Dashboard with (almost) no data](https://discuss.elastic.co/t/metricbeat-kibana-dashboard-with-almost-no-data/226760)

<div class="topic-metadata">

**Author:** [@ffknob](https://discuss.elastic.co/u/ffknob)\
**Replies:** 6\
**Last updated:** [April 10, 2020, 11:10pm UTC](https://discuss.elastic.co/t/metricbeat-kibana-dashboard-with-almost-no-data/226760 "2020-04-10T23:10:41Z")

</div>

Hi I have a group of Metricbeats collecting metrics every 1m. When I try to view those metrics in the Dashboard / \[Metricbeat System\] Host overview ECS I get something like this: Not much being showed and some visual…

---

## [AWS SNS not getting metrics, return a weird error](https://discuss.elastic.co/t/aws-sns-not-getting-metrics-return-a-weird-error/220771)

<div class="topic-metadata">

**Author:** [@odirionyeo](https://discuss.elastic.co/u/odirionyeo)\
**Replies:** 3\
**Last updated:** [April 10, 2020, 8:13pm UTC](https://discuss.elastic.co/t/aws-sns-not-getting-metrics-return-a-weird-error/220771 "2020-04-10T20:13:34Z")

</div>

Hello, I deployed the ELK stack on Kubernetes. I have configured all the metrics for AWS SNS, SQS, Cloudwatch, etc. All the metrics setup on metricbeat works but SNS metric set returns a weird error. Here is my config: …

---

## [\[Filebeat\] Timestamp with nanosecond precision](https://discuss.elastic.co/t/filebeat-timestamp-with-nanosecond-precision/227554)

<div class="topic-metadata">

**Author:** [@bmalecki4](https://discuss.elastic.co/u/bmalecki4)\
**Replies:** 0\
**Last updated:** [April 10, 2020, 7:31pm UTC](https://discuss.elastic.co/t/filebeat-timestamp-with-nanosecond-precision/227554 "2020-04-10T19:31:42Z")

</div>

My configuration: filebeat + logstash + elasticsearch + kibana (with logtrail) - all in version 7.6.1 I have a mule.log file which contains information without the timestamp field that I could extract to enforce pro…

---

## [Filebeat reading logs from S3](https://discuss.elastic.co/t/filebeat-reading-logs-from-s3/226065)

<div class="topic-metadata">

**Author:** [@Nithya](https://discuss.elastic.co/u/Nithya)\
**Replies:** 10\
**Last updated:** [April 10, 2020, 6:33pm UTC](https://discuss.elastic.co/t/filebeat-reading-logs-from-s3/226065 "2020-04-10T18:33:57Z")

</div>

Hi, I'm trying to get the AWS Logs which is stored in the centralised S3 bucket. I configured the SQS to get the file and push it to the Elastic Cloud index. I'm facing the below problems: When I see the logs, each l…

---

## [Getting intermittent parsing of JSON logs in Kibana](https://discuss.elastic.co/t/getting-intermittent-parsing-of-json-logs-in-kibana/227146)

<div class="topic-metadata">

**Author:** [@VictorS](https://discuss.elastic.co/u/VictorS)\
**Replies:** 2\
**Last updated:** [April 10, 2020, 6:18pm UTC](https://discuss.elastic.co/t/getting-intermittent-parsing-of-json-logs-in-kibana/227146 "2020-04-10T18:18:25Z")

</div>

Hi, I'm trying to do a shift of the current log setup we have in place from text to JSON so that we can accommodate MDC and get more info from our logs. The current setup is pretty basic with no real changes from the s…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=258)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=260)
