# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=260

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 261

---

## [\[BUG\] Filebeat creates wrong index name on index deletion](https://discuss.elastic.co/t/bug-filebeat-creates-wrong-index-name-on-index-deletion/227100)

<div class="topic-metadata">

**Author:** [@vutkin](https://discuss.elastic.co/u/vutkin)\
**Replies:** 12\
**Last updated:** [April 10, 2020, 6:15pm UTC](https://discuss.elastic.co/t/bug-filebeat-creates-wrong-index-name-on-index-deletion/227100 "2020-04-10T18:15:21Z")

</div>

Hi All, Filebeat affected: 7.6.1/7.6.2, installed via Elastic's helm charts (with default config). ES: 7.5.1 We are running into an issue where setting the ILM policy via filebeat config with the default index pattern…

---

## [Is it possible to obtain a file creation date via Filebeat?](https://discuss.elastic.co/t/is-it-possible-to-obtain-a-file-creation-date-via-filebeat/227124)

<div class="topic-metadata">

**Author:** [@Guerreiro\_Sousa](https://discuss.elastic.co/u/Guerreiro_Sousa)\
**Replies:** 1\
**Last updated:** [April 10, 2020, 6:03pm UTC](https://discuss.elastic.co/t/is-it-possible-to-obtain-a-file-creation-date-via-filebeat/227124 "2020-04-10T18:03:18Z")

</div>

Is it possible to obtain a file creation date via Filebeat? I would like to get this field to include as object of metadata in elastic.

---

## [Implementation question: Central syslog server vs filebeat on each machine](https://discuss.elastic.co/t/implementation-question-central-syslog-server-vs-filebeat-on-each-machine/227517)

<div class="topic-metadata">

**Author:** [@andywt123](https://discuss.elastic.co/u/andywt123)\
**Replies:** 1\
**Last updated:** [April 10, 2020, 5:32pm UTC](https://discuss.elastic.co/t/implementation-question-central-syslog-server-vs-filebeat-on-each-machine/227517 "2020-04-10T17:32:12Z")

</div>

I am new to elasticsearch. We are currently migrating from Splunk to Elastic. When we setup splunk the best practice was to use a central syslog server and ingest all the different servers logs from one point. Does Elas…

---

## [Change loaded index name](https://discuss.elastic.co/t/change-loaded-index-name/227272)

<div class="topic-metadata">

**Author:** [@kickon](https://discuss.elastic.co/u/kickon)\
**Replies:** 6\
**Last updated:** [April 10, 2020, 12:50pm UTC](https://discuss.elastic.co/t/change-loaded-index-name/227272 "2020-04-10T12:50:42Z")

</div>

hello, I cannot anymore change index name loaded by winlogbeat, could someone look at this and indicate where is an issue ? ###################### Winlogbeat Configuration Example ######################## # This file…

---

## [Metricbeat 7.6.1 on Windows fails to start sometimes](https://discuss.elastic.co/t/metricbeat-7-6-1-on-windows-fails-to-start-sometimes/227329)

<div class="topic-metadata">

**Author:** [@jori-be](https://discuss.elastic.co/u/jori-be)\
**Replies:** 2\
**Last updated:** [April 10, 2020, 9:53am UTC](https://discuss.elastic.co/t/metricbeat-7-6-1-on-windows-fails-to-start-sometimes/227329 "2020-04-10T09:53:24Z")

</div>

Hi all, We are running Metricbeat 7.6.1 on Windows 10 1909 and we notice that sometimes (once in 5 times) metricbeat does not start. Note: Metricbeat is started via Windows Service. This is what happens in the logs: 2…

---

## [Fails : sudo filebeat setup --dashboards -e (](https://discuss.elastic.co/t/fails-sudo-filebeat-setup-dashboards-e/227261)

<div class="topic-metadata">

**Author:** [@zero.lim](https://discuss.elastic.co/u/zero.lim)\
**Replies:** 4\
**Last updated:** [April 10, 2020, 8:50am UTC](https://discuss.elastic.co/t/fails-sudo-filebeat-setup-dashboards-e/227261 "2020-04-10T08:50:25Z")

</div>

Hi all , My problem is ... Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://kibana.nextlink.technology:5601/app/kibana/api/status fails: fail to execute the HTTP GET requ…

---

## [Under special log rolling strategy, filebeat repeatedly collects logs](https://discuss.elastic.co/t/under-special-log-rolling-strategy-filebeat-repeatedly-collects-logs/223036)

<div class="topic-metadata">

**Author:** [@xiongjunkun](https://discuss.elastic.co/u/xiongjunkun)\
**Replies:** 6\
**Last updated:** [April 10, 2020, 3:38am UTC](https://discuss.elastic.co/t/under-special-log-rolling-strategy-filebeat-repeatedly-collects-logs/223036 "2020-04-10T03:38:21Z")

</div>

I have a special log rolling strategy. The application keeps writing logs to file f. When file f reaches the rolling threshold, f is renamed to f1, the original f1 is renamed to f2, and so on. Recently, we found There ar…

---

## [Filebeat Stats and Metrics](https://discuss.elastic.co/t/filebeat-stats-and-metrics/227408)

<div class="topic-metadata">

**Author:** [@Emily\_Hontoria](https://discuss.elastic.co/u/Emily_Hontoria)\
**Replies:** 1\
**Last updated:** [April 9, 2020, 11:16pm UTC](https://discuss.elastic.co/t/filebeat-stats-and-metrics/227408 "2020-04-09T23:16:14Z")

</div>

Hi folks, I am trying to better understand the metrics I am currently seeing from the filebeat /stats call. Specifically looking to understand exactly what these metrics are: u'filebeat': {u'events': {u'active': 12…

---

## [Winlogbeat MSI create service](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267)

<div class="topic-metadata">

**Author:** [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Replies:** 6\
**Last updated:** [April 9, 2020, 3:19pm UTC](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267 "2020-04-09T15:19:36Z")

</div>

I have installed Winlogbeat 7.6.2 with the new MSI installer. The installer works very well and simplifies installation and maintenance of beats on Windows hosts. The only problem is that the installer does not contain a…

---

## [Filebeat sending all data from file not just new line added](https://discuss.elastic.co/t/filebeat-sending-all-data-from-file-not-just-new-line-added/227215)

<div class="topic-metadata">

**Author:** [@NetRajan](https://discuss.elastic.co/u/NetRajan)\
**Replies:** 2\
**Last updated:** [April 9, 2020, 1:56pm UTC](https://discuss.elastic.co/t/filebeat-sending-all-data-from-file-not-just-new-line-added/227215 "2020-04-09T13:56:41Z")

</div>

I am bit puzzled why Filebeat is sending all file data when only one line is added. I am expecting to behave like tail -f and send only one newly added file

---

## [Metricbeat Redis Module Connection to Digitalocean DB Failure](https://discuss.elastic.co/t/metricbeat-redis-module-connection-to-digitalocean-db-failure/227133)

<div class="topic-metadata">

**Author:** [@Henco](https://discuss.elastic.co/u/Henco)\
**Replies:** 2\
**Last updated:** [April 9, 2020, 1:08pm UTC](https://discuss.elastic.co/t/metricbeat-redis-module-connection-to-digitalocean-db-failure/227133 "2020-04-09T13:08:36Z")

</div>

Hi, I am trying to connect the redis module of metricbeat to a digitalocean hosted redis database; but EOF errors are thrown. Is there an alternate approach I should use to connect to a redis server over TLS as apposed …

---

## [Redis module](https://discuss.elastic.co/t/redis-module/227299)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 1\
**Last updated:** [April 9, 2020, 11:24am UTC](https://discuss.elastic.co/t/redis-module/227299 "2020-04-09T11:24:21Z")

</div>

Hi, in my current scenario I have 2 different Redis instances running on the same server. I have installed Metricbeat and enabled its module; is there a way to collect data from both instances? should I just put them i…

---

## [Metricbeat 7.4 index not created daily](https://discuss.elastic.co/t/metricbeat-7-4-index-not-created-daily/226728)

<div class="topic-metadata">

**Author:** [@Kawther](https://discuss.elastic.co/u/Kawther)\
**Replies:** 4\
**Last updated:** [April 9, 2020, 11:15am UTC](https://discuss.elastic.co/t/metricbeat-7-4-index-not-created-daily/226728 "2020-04-09T11:15:23Z")

</div>

Hello, I upgraded metricbeat from 6 to 7.4 . I have this problem , I realized that the index is only created with the date you started the service I want to use the old format \<beat-type\>-\<hostname\>-\<date\> GET \_ca…

---

## [Wilnlogbeat 7.6 Elasticsearch TLS Handshake failure](https://discuss.elastic.co/t/wilnlogbeat-7-6-elasticsearch-tls-handshake-failure/227259)

<div class="topic-metadata">

**Author:** [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Replies:** 1\
**Last updated:** [April 9, 2020, 9:28am UTC](https://discuss.elastic.co/t/wilnlogbeat-7-6-elasticsearch-tls-handshake-failure/227259 "2020-04-09T09:28:13Z")

</div>

After upgrade of Winlogbeat from 7.4.2 to 7.6.1 or 7.6.2, communication to elasitcsearch (7.6.1) was broken. The logs point to a TLS Handshake problem. Removing of TLSv1.3 from ssl.supported\_protocols solved the problem…

---

## [Add module for an exterior service in metricbeat.yml error](https://discuss.elastic.co/t/add-module-for-an-exterior-service-in-metricbeat-yml-error/227042)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 2\
**Last updated:** [April 9, 2020, 8:22am UTC](https://discuss.elastic.co/t/add-module-for-an-exterior-service-in-metricbeat-yml-error/227042 "2020-04-09T08:22:21Z")

</div>

I have a service running called OB-Mail Agent in windows and I want to add that in my metricbeat.yml file. What will be the value of metricbeat and module? it runs as expected when no new modules are added as below met…

---

## [Why has reserved space on ext4 uid of filebeat?](https://discuss.elastic.co/t/why-has-reserved-space-on-ext4-uid-of-filebeat/227157)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [April 9, 2020, 7:28am UTC](https://discuss.elastic.co/t/why-has-reserved-space-on-ext4-uid-of-filebeat/227157 "2020-04-09T07:28:24Z")

</div>

Hi, Version: 7.5.2 Filebeat is running as unprivileged user filebeat as systemd service. we noticed the following on our servers: sudo tune2fs -l -u filebeat /dev/mapper/vg\_root-root | grep -i reserved Setting reserv…

---

## [Management audibet](https://discuss.elastic.co/t/management-audibet/224551)

<div class="topic-metadata">

**Author:** [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Replies:** 3\
**Last updated:** [April 8, 2020, 2:33pm UTC](https://discuss.elastic.co/t/management-audibet/224551 "2020-04-08T14:33:18Z")

</div>

hi, How do I make the configuration auditbeat done automatically, for example on the kibana server I prepare one master file audibeat.yml then I push it to all agents, is that possible? please advace? thanks, hambali …

---

## [Loss of performance with Cisco module](https://discuss.elastic.co/t/loss-of-performance-with-cisco-module/226397)

<div class="topic-metadata">

**Author:** [@frbcr](https://discuss.elastic.co/u/frbcr)\
**Replies:** 6\
**Last updated:** [April 8, 2020, 1:43pm UTC](https://discuss.elastic.co/t/loss-of-performance-with-cisco-module/226397 "2020-04-08T13:43:17Z")

</div>

Hello, We have being trying to import our logs coming from a Cisco ASA into the ElasticSearch using Filebeat. The Cisco ASA is sending an average of 8,000 events/seconds. At first we were importing them as syslog liste…

---

## [We want to increase backoff time from 1s to 3s, apart from delay in logs, does this have any other affects on CPU/Memory/Network of filebeat process](https://discuss.elastic.co/t/we-want-to-increase-backoff-time-from-1s-to-3s-apart-from-delay-in-logs-does-this-have-any-other-affects-on-cpu-memory-network-of-filebeat-process/227132)

<div class="topic-metadata">

**Author:** [@Manojbvn\_Barthipudi](https://discuss.elastic.co/u/Manojbvn_Barthipudi)\
**Replies:** 0\
**Last updated:** [April 8, 2020, 1:13pm UTC](https://discuss.elastic.co/t/we-want-to-increase-backoff-time-from-1s-to-3s-apart-from-delay-in-logs-does-this-have-any-other-affects-on-cpu-memory-network-of-filebeat-process/227132 "2020-04-08T13:13:22Z")

</div>

Also, we have scan\_frequency:30s close\_inactive: 5m max\_backoff: 10s backoff\_factor: 2 what does harvester does after max\_backoff? does it close the handler?

---

## [Count total files](https://discuss.elastic.co/t/count-total-files/227125)

<div class="topic-metadata">

**Author:** [@Guerreiro\_Sousa](https://discuss.elastic.co/u/Guerreiro_Sousa)\
**Replies:** 0\
**Last updated:** [April 8, 2020, 12:39pm UTC](https://discuss.elastic.co/t/count-total-files/227125 "2020-04-08T12:39:25Z")

</div>

I have to count the total number of "xpto \* .log" files in a given directory, I imagine Filebeat does not do that. Alternatively, can I just look at new files and not modified files? What are my alternatives to solve th…

---

## [Which nodes to include in output.host in filebeat.yml?](https://discuss.elastic.co/t/which-nodes-to-include-in-output-host-in-filebeat-yml/227117)

<div class="topic-metadata">

**Author:** [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Replies:** 4\
**Last updated:** [April 8, 2020, 12:16pm UTC](https://discuss.elastic.co/t/which-nodes-to-include-in-output-host-in-filebeat-yml/227117 "2020-04-08T12:16:20Z")

</div>

I have like 5 elastic nodes in total. One node ingest and coordinating node while two are dedicated master nodes and the other two are dedicated data nodes. I have elasticsearch install on all my five nodes with respect…

---

## [Filebeat doesnt exclude rotated files](https://discuss.elastic.co/t/filebeat-doesnt-exclude-rotated-files/226191)

<div class="topic-metadata">

**Author:** [@Neropointer](https://discuss.elastic.co/u/Neropointer)\
**Replies:** 1\
**Last updated:** [April 8, 2020, 11:58am UTC](https://discuss.elastic.co/t/filebeat-doesnt-exclude-rotated-files/226191 "2020-04-08T11:58:34Z")

</div>

I try to grab the log files that only end in .log but Filebeat grabs the rotated logfiles .log.2020-03-11too. I dont understand why he does that. -type: log enabled: true paths: - /opt/service/\*\*/service-\*.log ex…

---

## [Tailf new file system( not constant) to logstash](https://discuss.elastic.co/t/tailf-new-file-system-not-constant-to-logstash/226658)

<div class="topic-metadata">

**Author:** [@Dawood](https://discuss.elastic.co/u/Dawood)\
**Replies:** 7\
**Last updated:** [April 8, 2020, 10:27am UTC](https://discuss.elastic.co/t/tailf-new-file-system-not-constant-to-logstash/226658 "2020-04-08T10:27:23Z")

</div>

Hi, Using python infrastructure: I am already familiar of putting data into logstash via python module " logstash\_async". It works excellent. My need now as part of test process on several nodes ( machines) is to give …

---

## [Filebeat not logging to /var/log/filebeat](https://discuss.elastic.co/t/filebeat-not-logging-to-var-log-filebeat/227001)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 1\
**Last updated:** [April 8, 2020, 2:39am UTC](https://discuss.elastic.co/t/filebeat-not-logging-to-var-log-filebeat/227001 "2020-04-08T02:39:14Z")

</div>

I read this reference: https://discuss.elastic.co/t/filebeat-refuses-to-log-to-file-7-0-1/181846 I am on Ubuntu 18.04 Installed filebeat from the package: root@chris-Standard-PC-Q35-ICH9-2009:/etc# apt list filebeat …

---

## [Cfgfile - is not read after first failed attempt](https://discuss.elastic.co/t/cfgfile-is-not-read-after-first-failed-attempt/227041)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 0\
**Last updated:** [April 8, 2020, 2:19am UTC](https://discuss.elastic.co/t/cfgfile-is-not-read-after-first-failed-attempt/227041 "2020-04-08T02:19:07Z")

</div>

I thought it was interesting observation that the changed cfgfile was not re-read after the first attempt failed, until I restarted filebeat. Maybe there is an option I am missing to re-read failed config files. filebe…

---

## [Zeek error unpacking configuration](https://discuss.elastic.co/t/zeek-error-unpacking-configuration/226983)

<div class="topic-metadata">

**Author:** [@Mangolinux](https://discuss.elastic.co/u/Mangolinux)\
**Replies:** 1\
**Last updated:** [April 7, 2020, 8:01pm UTC](https://discuss.elastic.co/t/zeek-error-unpacking-configuration/226983 "2020-04-07T20:01:51Z")

</div>

I am trying to configure the seek module and keep getting this error when I run sudo filebeat setup Exiting: 1 error: error unpacking module config: error creating config from fileset zeek/rfb: error unpacking configur…

---

## [Can't get filebeat dashboard on kibana](https://discuss.elastic.co/t/cant-get-filebeat-dashboard-on-kibana/226984)

<div class="topic-metadata">

**Author:** [@oumy](https://discuss.elastic.co/u/oumy)\
**Replies:** 0\
**Last updated:** [April 7, 2020, 6:40pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-dashboard-on-kibana/226984 "2020-04-07T18:40:09Z")

</div>

hello there, i am trying to connect two machines, one master that has elasticsearch kibana and logstash, and a minion that has beats. trying to e/get the dashboard of file beat to the "IPaddress: 5601", yet it keeps se…

---

## [Filebeat: Cannot parse certain FTD messages, bug?](https://discuss.elastic.co/t/filebeat-cannot-parse-certain-ftd-messages-bug/226969)

<div class="topic-metadata">

**Author:** [@SjoerdFurth](https://discuss.elastic.co/u/SjoerdFurth)\
**Replies:** 0\
**Last updated:** [April 7, 2020, 5:50pm UTC](https://discuss.elastic.co/t/filebeat-cannot-parse-certain-ftd-messages-bug/226969 "2020-04-07T17:50:55Z")

</div>

At work we wanted to monitor our Cisco FTD using Elasticsearch and try the SIEM option. After setting this up with version 7.5.2 and 7.6.1 (when it released), I noticed some of the syslog messages not to be parsed corre…

---

## [Fields.yml not packaged?](https://discuss.elastic.co/t/fields-yml-not-packaged/226968)

<div class="topic-metadata">

**Author:** [@Matt\_Howard](https://discuss.elastic.co/u/Matt_Howard)\
**Replies:** 0\
**Last updated:** [April 7, 2020, 5:44pm UTC](https://discuss.elastic.co/t/fields-yml-not-packaged/226968 "2020-04-07T17:44:21Z")

</div>

Should the fields.yml be deployed along with the lambda (I'm on AWS)? I added some custom fields to fields.yml and noticed they weren't added to the index mapping. I tried to explicitly set setup.template.fields=fields.y…

---

## [Problem when sending info from Filebeat -\> logstash -\> Elasticsearch -\>kibana in windows](https://discuss.elastic.co/t/problem-when-sending-info-from-filebeat-logstash-elasticsearch-kibana-in-windows/226732)

<div class="topic-metadata">

**Author:** [@nb03briceno](https://discuss.elastic.co/u/nb03briceno)\
**Replies:** 2\
**Last updated:** [April 7, 2020, 1:36pm UTC](https://discuss.elastic.co/t/problem-when-sending-info-from-filebeat-logstash-elasticsearch-kibana-in-windows/226732 "2020-04-07T13:36:14Z")

</div>

Hello everyone, I hope somebody could help me. Recently, I'm learning how to use filebeat and I'm trying to use it for making the streaming of a log in the most basic way in Windows. I have a the log file located in the…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=259)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=261)
