# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=261

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 262

---

## [Oracle Linux (RedHat) will not open filebeat port](https://discuss.elastic.co/t/oracle-linux-redhat-will-not-open-filebeat-port/226866)

<div class="topic-metadata">

**Author:** [@calanon](https://discuss.elastic.co/u/calanon)\
**Replies:** 1\
**Last updated:** [April 7, 2020, 1:03pm UTC](https://discuss.elastic.co/t/oracle-linux-redhat-will-not-open-filebeat-port/226866 "2020-04-07T13:03:10Z")

</div>

I am running my filebeat on port 2561, when checking netstat there is no port of this type open. I am running filebeat in debug mode and I see nothing in the output.

---

## [Beats index management](https://discuss.elastic.co/t/beats-index-management/226894)

<div class="topic-metadata">

**Author:** [@michielM](https://discuss.elastic.co/u/michielM)\
**Replies:** 0\
**Last updated:** [April 7, 2020, 12:40pm UTC](https://discuss.elastic.co/t/beats-index-management/226894 "2020-04-07T12:40:29Z")

</div>

Hi all, Currently, I,m trying to change the index name in a way that every server I connect is a prefix of the index. For example: currently, I just have auditbeat-7.6.1-2020.03.27-000001 as index name, but I want to ha…

---

## [Filebeat stop after sometimes while reading yarn logs](https://discuss.elastic.co/t/filebeat-stop-after-sometimes-while-reading-yarn-logs/226702)

<div class="topic-metadata">

**Author:** [@ucguy4u](https://discuss.elastic.co/u/ucguy4u)\
**Replies:** 5\
**Last updated:** [April 7, 2020, 10:47am UTC](https://discuss.elastic.co/t/filebeat-stop-after-sometimes-while-reading-yarn-logs/226702 "2020-04-07T10:47:31Z")

</div>

I am using filebeat to ship data of yarn logs of hadoop. I am using is filebeat-7.5.1 \` filebeat.inputs: type: log enabled: true paths: /root/hadoop/userlogs/\*\*/stderr /root/ingest-logs/ingest.log /root/root-log…

---

## [X509: cannot validate certificate for xx.xx.xx.xxbecause it doesn't contain any IP SANs](https://discuss.elastic.co/t/x509-cannot-validate-certificate-for-xx-xx-xx-xxbecause-it-doesnt-contain-any-ip-sans/226706)

<div class="topic-metadata">

**Author:** [@Daud\_Ahmed](https://discuss.elastic.co/u/Daud_Ahmed)\
**Replies:** 5\
**Last updated:** [April 7, 2020, 10:24am UTC](https://discuss.elastic.co/t/x509-cannot-validate-certificate-for-xx-xx-xx-xxbecause-it-doesnt-contain-any-ip-sans/226706 "2020-04-07T10:24:59Z")

</div>

I am able to curl my elasticsearch API successfully curl -k --verbose https://username:password@x.x.x.x:9900 But when i'm trying to connect my filebeat to elasticsearch i'm getting the error x509: cannot validate certi…

---

## [Beats configuration: overlaping between output.elasticsearch and cloud.\*?](https://discuss.elastic.co/t/beats-configuration-overlaping-between-output-elasticsearch-and-cloud/226704)

<div class="topic-metadata">

**Author:** [@ffknob](https://discuss.elastic.co/u/ffknob)\
**Replies:** 3\
**Last updated:** [April 7, 2020, 7:51am UTC](https://discuss.elastic.co/t/beats-configuration-overlaping-between-output-elasticsearch-and-cloud/226704 "2020-04-07T07:51:13Z")

</div>

Hi I'm just curious about the needed settings in a Beat file when the cluster is in the Elastic cloud. Currently my config files looks like this: output.elasticsearch: hosts: \["https://....us-east-1.aws.found.io:...…

---

## [Logging only kubelet logs](https://discuss.elastic.co/t/logging-only-kubelet-logs/226694)

<div class="topic-metadata">

**Author:** [@Mario\_Albo\_Soria](https://discuss.elastic.co/u/Mario_Albo_Soria)\
**Replies:** 2\
**Last updated:** [April 7, 2020, 6:42am UTC](https://discuss.elastic.co/t/logging-only-kubelet-logs/226694 "2020-04-07T06:42:19Z")

</div>

Hi everybody! I have a Kubernets cluster deployed with RKE. When you deploy using RKE, the kubelet is not deployed as a pod, but it is deployed as a Docker container. I want to collect logs from kubelet container and i…

---

## [Multiline for Logline starting with "STATUS" or "INFO"](https://discuss.elastic.co/t/multiline-for-logline-starting-with-status-or-info/226761)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 1\
**Last updated:** [April 7, 2020, 3:57am UTC](https://discuss.elastic.co/t/multiline-for-logline-starting-with-status-or-info/226761 "2020-04-07T03:57:40Z")

</div>

I have some logs whose one word starts with "STATUS" or "INFO" and in my multline pattern, I want to identify these words as starting point. WHat will be the multiline? I tried multiline.pattern: '^%{WORD}' Sample Log…

---

## [Can i run metricbeat, packetbeat etc.. inside a docker on windows?](https://discuss.elastic.co/t/can-i-run-metricbeat-packetbeat-etc-inside-a-docker-on-windows/226782)

<div class="topic-metadata">

**Author:** [@micas](https://discuss.elastic.co/u/micas)\
**Replies:** 0\
**Last updated:** [April 6, 2020, 9:36pm UTC](https://discuss.elastic.co/t/can-i-run-metricbeat-packetbeat-etc-inside-a-docker-on-windows/226782 "2020-04-06T21:36:50Z")

</div>

Can i run metricbeat, packetbeat etc.. inside a docker on windows? I have managed to do so and they run fine however i cant get any windows related data other than packetbeat. Do the other beats NEED to be installed di…

---

## [Custom Index Name for Apache Module, but using ILM as well](https://discuss.elastic.co/t/custom-index-name-for-apache-module-but-using-ilm-as-well/226284)

<div class="topic-metadata">

**Author:** [@dsdameron](https://discuss.elastic.co/u/dsdameron)\
**Replies:** 2\
**Last updated:** [April 6, 2020, 9:03pm UTC](https://discuss.elastic.co/t/custom-index-name-for-apache-module-but-using-ilm-as-well/226284 "2020-04-06T21:03:46Z")

</div>

I need to setup a Linux system running Apache to send logs into Elastic Search via Filebeat, but have the Apache module send to a different index. This custom index name needs to use the Filebeat/apache module mappings,…

---

## [Multiline parsing issue](https://discuss.elastic.co/t/multiline-parsing-issue/226545)

<div class="topic-metadata">

**Author:** [@rosseba](https://discuss.elastic.co/u/rosseba)\
**Replies:** 2\
**Last updated:** [April 6, 2020, 7:16pm UTC](https://discuss.elastic.co/t/multiline-parsing-issue/226545 "2020-04-06T19:16:05Z")

</div>

Hi all, filebeat newbie here. I'm trying to reduce this log: \[2020-04-05T00:20:00\] /usr/bin/rsnapshot -c /etc/rsnapshot\_nuc.conf alpha: started \[2020-04-05T00:20:00\] echo 2123427 \> /var/run/rsnapshot\_nuc.pid \[2020-04-…

---

## [Metricbeat MSSQL - keystore](https://discuss.elastic.co/t/metricbeat-mssql-keystore/222933)

<div class="topic-metadata">

**Author:** [@shortcommand](https://discuss.elastic.co/u/shortcommand)\
**Replies:** 1\
**Last updated:** [April 6, 2020, 6:52pm UTC](https://discuss.elastic.co/t/metricbeat-mssql-keystore/222933 "2020-04-06T18:52:14Z")

</div>

Hi, I've a problem with using keystore to store passwords for DB connection in the MSSQL module. I've created a keystore and and added a key called SA\_PW. I can see this key in the keystore when I list all keys in the …

---

## [Return Group1 from regex not fullmatch](https://discuss.elastic.co/t/return-group1-from-regex-not-fullmatch/224420)

<div class="topic-metadata">

**Author:** [@quixter](https://discuss.elastic.co/u/quixter)\
**Replies:** 4\
**Last updated:** [April 6, 2020, 1:48pm UTC](https://discuss.elastic.co/t/return-group1-from-regex-not-fullmatch/224420 "2020-04-06T13:48:25Z")

</div>

Hi, I'm pretty new to both ELK and Filebeat. I'm trying to get a custom field built using a regex value. I'm having to use javascript which seems to be complicating things. I have the following regex .com/(\[A-Za-z0-9\]+…

---

## [One cluster to monitor them all](https://discuss.elastic.co/t/one-cluster-to-monitor-them-all/226598)

<div class="topic-metadata">

**Author:** [@ffknob](https://discuss.elastic.co/u/ffknob)\
**Replies:** 3\
**Last updated:** [April 6, 2020, 1:03pm UTC](https://discuss.elastic.co/t/one-cluster-to-monitor-them-all/226598 "2020-04-06T13:03:46Z")

</div>

Hi there So I'm planning to deploy a single cluster to centralize logs and metrics from a group of different clients. The scope of this would be metrics from hosts and services (Metricbeat), log files (Filebeat), networ…

---

## [Suricata Module missing mapping for tenant\_id](https://discuss.elastic.co/t/suricata-module-missing-mapping-for-tenant-id/226708)

<div class="topic-metadata">

**Author:** [@stormrider959](https://discuss.elastic.co/u/stormrider959)\
**Replies:** 0\
**Last updated:** [April 6, 2020, 12:27pm UTC](https://discuss.elastic.co/t/suricata-module-missing-mapping-for-tenant-id/226708 "2020-04-06T12:27:16Z")

</div>

Hello everybody I'm posting this here because the contributing guidelines on GitHub state that issues should be posted here before opening one on GitHub. The Suricata Filebeat Module is missing a mapping for the field …

---

## [Filebeat Azure Module Error](https://discuss.elastic.co/t/filebeat-azure-module-error/225757)

<div class="topic-metadata">

**Author:** [@craigothy](https://discuss.elastic.co/u/craigothy)\
**Replies:** 7\
**Last updated:** [April 6, 2020, 9:47am UTC](https://discuss.elastic.co/t/filebeat-azure-module-error/225757 "2020-04-06T09:47:13Z")

</div>

When starting filebeat after enabling an configuring the azure module in 7.6.1 I get the following error: ERROR \[azure-eventhub input\] azureeventhub/input.go:116 illegal base64 data at input byte 0 {"conne…

---

## [Specify port range of http protocol](https://discuss.elastic.co/t/specify-port-range-of-http-protocol/226060)

<div class="topic-metadata">

**Author:** [@e997cd7e8d9915436150](https://discuss.elastic.co/u/e997cd7e8d9915436150)\
**Replies:** 2\
**Last updated:** [April 5, 2020, 9:49am UTC](https://discuss.elastic.co/t/specify-port-range-of-http-protocol/226060 "2020-04-05T09:49:30Z")

</div>

Hello, I want to specify port range of http protocol like \[80-65000\]. Is it impossible? Any advice is much appreciated.:slight\_smile:

---

## [Multiple Filebeat Inputs to different Logstash ports](https://discuss.elastic.co/t/multiple-filebeat-inputs-to-different-logstash-ports/226273)

<div class="topic-metadata">

**Author:** [@radd](https://discuss.elastic.co/u/radd)\
**Replies:** 2\
**Last updated:** [April 4, 2020, 10:20am UTC](https://discuss.elastic.co/t/multiple-filebeat-inputs-to-different-logstash-ports/226273 "2020-04-04T10:20:36Z")

</div>

Hi, I am trying to send 3 total different logs from server A using filebeat, to server B running logstash on 3 different ports, based on different pipelines. Server A,filebeat, file\_1.log ---------\> Server B, logstash…

---

## [Filebeat: wrong multiline merging](https://discuss.elastic.co/t/filebeat-wrong-multiline-merging/225881)

<div class="topic-metadata">

**Author:** [@agapoff](https://discuss.elastic.co/u/agapoff)\
**Replies:** 3\
**Last updated:** [April 4, 2020, 10:14am UTC](https://discuss.elastic.co/t/filebeat-wrong-multiline-merging/225881 "2020-04-04T10:14:47Z")

</div>

I am trying to run filebeat daemonset in Kubernetes cluster. It is expected to honor the multiline log entries and also parse json log entries. This is the config snippet: filebeat.autodiscover: providers: …

---

## [Unable to Get user name in Audit beat File Integrity](https://discuss.elastic.co/t/unable-to-get-user-name-in-audit-beat-file-integrity/224524)

<div class="topic-metadata">

**Author:** [@8Bit\_System](https://discuss.elastic.co/u/8Bit_System)\
**Replies:** 1\
**Last updated:** [April 4, 2020, 9:03am UTC](https://discuss.elastic.co/t/unable-to-get-user-name-in-audit-beat-file-integrity/224524 "2020-04-04T09:03:32Z")

</div>

Hello Team I want not to check my filesystem in Linux, if any user delete/update/create/move this action with user detail know the user. name who perform an action

---

## [How to automatically change the file name output by Auditbeat.yml](https://discuss.elastic.co/t/how-to-automatically-change-the-file-name-output-by-auditbeat-yml/225529)

<div class="topic-metadata">

**Author:** [@Ryo\_Takeuchi](https://discuss.elastic.co/u/Ryo_Takeuchi)\
**Replies:** 1\
**Last updated:** [April 4, 2020, 8:55am UTC](https://discuss.elastic.co/t/how-to-automatically-change-the-file-name-output-by-auditbeat-yml/225529 "2020-04-04T08:55:00Z")

</div>

Is it possible to set variable information (date information etc ...) in the file name with the File option of Configure the output? For example, filename\_yyyymmdd\_hhmmss.log etc ... Or is there any other way to change …

---

## [않은 waldheim33.com/yes/ - 샌즈카지노](https://discuss.elastic.co/t/waldheim33-com-yes/226500)

<div class="topic-metadata">

**Author:** [@moondrew3w](https://discuss.elastic.co/u/moondrew3w)\
**Replies:** 0\
**Last updated:** [April 4, 2020, 8:31am UTC](https://discuss.elastic.co/t/waldheim33-com-yes/226500 "2020-04-04T08:31:56Z")

</div>

뭔가 좋지 않은 https://waldheim33.com/yes/ - 샌즈카지노기분을 더나인카지노느낀 코인카지노기현이 퍼스트카지노움찔하며 더킹카지노한영의 우리카지노등뒤로 물러섰다. 한영과 함께 온 유택천의 패거리도 왠지 모를 기선에 뒤로 물러났다. 민형

---

## [Filebeat stops in docker container](https://discuss.elastic.co/t/filebeat-stops-in-docker-container/226323)

<div class="topic-metadata">

**Author:** [@fdbatista](https://discuss.elastic.co/u/fdbatista)\
**Replies:** 2\
**Last updated:** [April 3, 2020, 8:33pm UTC](https://discuss.elastic.co/t/filebeat-stops-in-docker-container/226323 "2020-04-03T20:33:00Z")

</div>

Hello everyone. I am trying to feed Logstash via Filebeat using docker containers, and it works fine, except for the fact that Filebeat container stops after reading the files contents. I want Filebeat to constantly wa…

---

## [Build filebeat x-pack modules from source fails](https://discuss.elastic.co/t/build-filebeat-x-pack-modules-from-source-fails/226128)

<div class="topic-metadata">

**Author:** [@Mike\_Ware](https://discuss.elastic.co/u/Mike_Ware)\
**Replies:** 11\
**Last updated:** [April 3, 2020, 7:58pm UTC](https://discuss.elastic.co/t/build-filebeat-x-pack-modules-from-source-fails/226128 "2020-04-03T19:58:00Z")

</div>

I have managed to build file beat and base modules from source found at https://github.com/elastic/beats . When I try to build the modules in beats/x-pack/filebeat I receive the following error with build launched at src…

---

## [Changes of hostname or ip addresses does not updates host metadata until metricbeat restart on nodes](https://discuss.elastic.co/t/changes-of-hostname-or-ip-addresses-does-not-updates-host-metadata-until-metricbeat-restart-on-nodes/226403)

<div class="topic-metadata">

**Author:** [@mmelyp](https://discuss.elastic.co/u/mmelyp)\
**Replies:** 3\
**Last updated:** [April 3, 2020, 3:53pm UTC](https://discuss.elastic.co/t/changes-of-hostname-or-ip-addresses-does-not-updates-host-metadata-until-metricbeat-restart-on-nodes/226403 "2020-04-03T15:53:24Z")

</div>

Hi there, I have an issue here with metricbeat. I found out that if I change the hostname of my debian nodes (hostnamectl set-hostname FQDN), or if i add or remove IP addresses, i always have to restart metricbeat in o…

---

## [Error creating runner from config: Can only start an input when all related states are finished](https://discuss.elastic.co/t/error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/226422)

<div class="topic-metadata">

**Author:** [@viveknagar](https://discuss.elastic.co/u/viveknagar)\
**Replies:** 0\
**Last updated:** [April 3, 2020, 3:08pm UTC](https://discuss.elastic.co/t/error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/226422 "2020-04-03T15:08:10Z")

</div>

Hello All, I am getting error "Error creating runner from config: Can only start an input when all related states are finished" ,while using autodiscover in fIlebeat 7.4.2 . Below is my configuration file "filebeat.yml…

---

## [Kibana Dashboard: I am using elastic cloud trial version and filebeat is running but failed to load fllebeat index pattern on kibana](https://discuss.elastic.co/t/kibana-dashboard-i-am-using-elastic-cloud-trial-version-and-filebeat-is-running-but-failed-to-load-fllebeat-index-pattern-on-kibana/226023)

<div class="topic-metadata">

**Author:** [@Manav\_Chopra](https://discuss.elastic.co/u/Manav_Chopra)\
**Replies:** 3\
**Last updated:** [April 3, 2020, 2:29pm UTC](https://discuss.elastic.co/t/kibana-dashboard-i-am-using-elastic-cloud-trial-version-and-filebeat-is-running-but-failed-to-load-fllebeat-index-pattern-on-kibana/226023 "2020-04-03T14:29:45Z")

</div>

I am working on windows system and working on elastic cloud: elasticsearch and kibana I have installed filebeat as well and configured properly . In console if i run filebeat -e, it is running but on kibana nothing is s…

---

## [Seeking clarification on how 'filebeat setup' works with rollover\_alias defined, etc](https://discuss.elastic.co/t/seeking-clarification-on-how-filebeat-setup-works-with-rollover-alias-defined-etc/226406)

<div class="topic-metadata">

**Author:** [@dsdameron](https://discuss.elastic.co/u/dsdameron)\
**Replies:** 0\
**Last updated:** [April 3, 2020, 1:19pm UTC](https://discuss.elastic.co/t/seeking-clarification-on-how-filebeat-setup-works-with-rollover-alias-defined-etc/226406 "2020-04-03T13:19:39Z")

</div>

I am configuring filebeat to send various module output to Elastic Search v7. We are using ILM. I am looking at the ILM settings here: Configure index lifecycle management - ES 7 and I am wondering if someone could clar…

---

## [Filebeat performance stall sometimes](https://discuss.elastic.co/t/filebeat-performance-stall-sometimes/222207)

<div class="topic-metadata">

**Author:** [@GhOsTMZ](https://discuss.elastic.co/u/GhOsTMZ)\
**Replies:** 16\
**Last updated:** [April 3, 2020, 10:04am UTC](https://discuss.elastic.co/t/filebeat-performance-stall-sometimes/222207 "2020-04-03T10:04:06Z")

</div>

Hello anyone! I have a some problems with a Filebeat. I collecting logs from a 2 files and send it to a Logstash. Events rate decreasing after a few hours of work. Events rate becomes normal after restart filebeat or co…

---

## [FileBeat not running](https://discuss.elastic.co/t/filebeat-not-running/226211)

<div class="topic-metadata">

**Author:** [@Vlad\_Piratov](https://discuss.elastic.co/u/Vlad_Piratov)\
**Replies:** 1\
**Last updated:** [April 3, 2020, 9:10am UTC](https://discuss.elastic.co/t/filebeat-not-running/226211 "2020-04-03T09:10:52Z")

</div>

Hi, I recently started working with this product on debian 8. I found the book for version 6.0.0, and set it (ELK). The problem is this: I can't run FileBeat to send syslog logstash logs (FileBeat -\> logstash -\> elastic …

---

## [ES K8s (AKS) auditlogs via filebeat](https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036)

<div class="topic-metadata">

**Author:** [@VishalBhalla](https://discuss.elastic.co/u/VishalBhalla)\
**Replies:** 5\
**Last updated:** [April 3, 2020, 8:54am UTC](https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036 "2020-04-03T08:54:46Z")

</div>

Hi all. I just wanted to confirm my thinking with what I'm trying to achieve. We currently have an version 7.6.2 ES stack running on kubernetes in Azure AKS. The ES audit logs are currently being sent to stdout (so ava…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=260)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=262)
