# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=262

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 263

---

## [Metricbeat CEPH module using ceph-restful api (nautilus release)](https://discuss.elastic.co/t/metricbeat-ceph-module-using-ceph-restful-api-nautilus-release/226224)

<div class="topic-metadata">

**Author:** [@eihkoh](https://discuss.elastic.co/u/eihkoh)\
**Replies:** 1\
**Last updated:** [April 3, 2020, 8:43am UTC](https://discuss.elastic.co/t/metricbeat-ceph-module-using-ceph-restful-api-nautilus-release/226224 "2020-04-03T08:43:10Z")

</div>

Hi, Somebody is using the Metricbeat Ceph module to collect some of Ceph statistics and sending it to ElasticSearch? This Topic is more or less the same as the previous one: 'https://discuss.elastic.co/t/metricbeat-cep…

---

## [Parse text to Json in Filebeat](https://discuss.elastic.co/t/parse-text-to-json-in-filebeat/226146)

<div class="topic-metadata">

**Author:** [@Bhanu1](https://discuss.elastic.co/u/Bhanu1)\
**Replies:** 3\
**Last updated:** [April 3, 2020, 8:40am UTC](https://discuss.elastic.co/t/parse-text-to-json-in-filebeat/226146 "2020-04-03T08:40:29Z")

</div>

Need help to parse rsyslog data to elastic search 2020-04-01T06:12:05+00:00 log-forwarder-rs6zr myrtfapp-685c9695fd-pppnk\_fe614c {"log":"2020-04-01T06:12:05.453Z\\u0009INFO\\u0009\[monitoring\]\\u0009log/log.go:144\\u0009Non-…

---

## [Could not locate that index-pattern-field (id: flow.locality)](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-flow-locality/225441)

<div class="topic-metadata">

**Author:** [@opoplawski](https://discuss.elastic.co/u/opoplawski)\
**Replies:** 3\
**Last updated:** [April 3, 2020, 8:12am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-flow-locality/225441 "2020-04-03T08:12:24Z")

</div>

I'm starting to use the Filebeat netflow module. I've imported the filebeat 7.6.1 template and dashboards, but one of the visualizations generates this error: Could not locate that index-pattern-field (id: flow.localit…

---

## [ELK setup on IBM MQ](https://discuss.elastic.co/t/elk-setup-on-ibm-mq/226163)

<div class="topic-metadata">

**Author:** [@Deena](https://discuss.elastic.co/u/Deena)\
**Replies:** 0\
**Last updated:** [April 2, 2020, 7:06am UTC](https://discuss.elastic.co/t/elk-setup-on-ibm-mq/226163 "2020-04-02T07:06:55Z")

</div>

We are in process of doing a POC for setting up ELK stack for gathering IBM MQ Log data and QMGR metrics data into ELK. While working with ELK we found beat modules for MQ LOG but not with QMGR metrics. Can we setup the…

---

## [Metricbeat-\>Elasticsearch fine; Metricbeat-\>Kafka-\>Logstash-\>ElasticSearch not](https://discuss.elastic.co/t/metricbeat-elasticsearch-fine-metricbeat-kafka-logstash-elasticsearch-not/226272)

<div class="topic-metadata">

**Author:** [@thom1](https://discuss.elastic.co/u/thom1)\
**Replies:** 4\
**Last updated:** [April 2, 2020, 7:48pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-fine-metricbeat-kafka-logstash-elasticsearch-not/226272 "2020-04-02T19:48:50Z")

</div>

Using version 7.6.2 of everything Elastic, and version 2.12-2.4.1 of Kafka When I install metricbeat on some test host, and sent those beats directly to Elasticsearch, the \[Metricbeat System\] ECS dashboard looks fine an…

---

## [Logstash or Beats](https://discuss.elastic.co/t/logstash-or-beats/226220)

<div class="topic-metadata">

**Author:** [@Michaelk1](https://discuss.elastic.co/u/Michaelk1)\
**Replies:** 3\
**Last updated:** [April 2, 2020, 6:02pm UTC](https://discuss.elastic.co/t/logstash-or-beats/226220 "2020-04-02T18:02:53Z")

</div>

I would like an experienced opinion on whether to use Logstash or Beats to ship logs to Elasticsearch for an enterprise network. What is the advantage of using either and of using both? I want to be able to ship windows…

---

## [State\_service metricset fails on headless services](https://discuss.elastic.co/t/state-service-metricset-fails-on-headless-services/226131)

<div class="topic-metadata">

**Author:** [@Anya\_Sabo](https://discuss.elastic.co/u/Anya_Sabo)\
**Replies:** 2\
**Last updated:** [April 2, 2020, 4:22pm UTC](https://discuss.elastic.co/t/state-service-metricset-fails-on-headless-services/226131 "2020-04-02T16:22:40Z")

</div>

I was going to open a github issue, but it told me to open a discuss thread first. I didn't see anything similar in discuss or in github for this topic. It is easy to reproduce using the kubernetes module and having ECK …

---

## [How to properly launch filebeat in container?](https://discuss.elastic.co/t/how-to-properly-launch-filebeat-in-container/225984)

<div class="topic-metadata">

**Author:** [@voipp](https://discuss.elastic.co/u/voipp)\
**Replies:** 3\
**Last updated:** [April 2, 2020, 3:21pm UTC](https://discuss.elastic.co/t/how-to-properly-launch-filebeat-in-container/225984 "2020-04-02T15:21:00Z")

</div>

Hello! I launched filebeat in container like advised in this link: www.elastic.co But filebeat doesn't send my logs to remote host. It seems the provided dockerfile is incorrect, entrypoint is absent. Is it? I modifi…

---

## [Cannot connect "packetbeat-7.6.1-1.x86\_64"\[oss version\] to AWS Managed ES \[v7.4.2\]](https://discuss.elastic.co/t/cannot-connect-packetbeat-7-6-1-1-x86-64-oss-version-to-aws-managed-es-v7-4-2/224553)

<div class="topic-metadata">

**Author:** [@Yessen](https://discuss.elastic.co/u/Yessen)\
**Replies:** 2\
**Last updated:** [April 2, 2020, 2:48pm UTC](https://discuss.elastic.co/t/cannot-connect-packetbeat-7-6-1-1-x86-64-oss-version-to-aws-managed-es-v7-4-2/224553 "2020-04-02T14:48:10Z")

</div>

output of curl from the box where packetbeat is installed : curl https://aws-es-domain-endpoint.com:443 { "name" : "99abf5c22ca3a14294d52af72a17df86", "cluster\_name" : "528130383285:test-infra-ek", "cluster\_uuid" …

---

## [Filebeat aws region error](https://discuss.elastic.co/t/filebeat-aws-region-error/225832)

<div class="topic-metadata">

**Author:** [@Samerd](https://discuss.elastic.co/u/Samerd)\
**Replies:** 3\
**Last updated:** [April 2, 2020, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-aws-region-error/225832 "2020-04-02T14:31:09Z")

</div>

hi im tring to enable aws elb to send logs for my ELb. this is my AWS module config: and i got this error message : ERROR instance/beat.go:933 Exiting: Fileset aws/regions is configured but doesn't ex…

---

## [AWS Cloudwatch - Cant collect s3 tags from AWS/S3 namespace](https://discuss.elastic.co/t/aws-cloudwatch-cant-collect-s3-tags-from-aws-s3-namespace/225930)

<div class="topic-metadata">

**Author:** [@Yotamloe](https://discuss.elastic.co/u/Yotamloe)\
**Replies:** 3\
**Last updated:** [April 2, 2020, 8:32am UTC](https://discuss.elastic.co/t/aws-cloudwatch-cant-collect-s3-tags-from-aws-s3-namespace/225930 "2020-04-02T08:32:28Z")

</div>

Hi, i'm using metricbeat 7.5.1. I'm trying to collect daily storage metrics and s3 bucket tags with the cloudwatch metricset, but its failing to collect tags. I have succeeded to describe the tags in my aws account with …

---

## [Filebeat CEF module can't parse event as syslog rfc3164](https://discuss.elastic.co/t/filebeat-cef-module-cant-parse-event-as-syslog-rfc3164/226116)

<div class="topic-metadata">

**Author:** [@WBakeberg](https://discuss.elastic.co/u/WBakeberg)\
**Replies:** 2\
**Last updated:** [April 2, 2020, 8:30am UTC](https://discuss.elastic.co/t/filebeat-cef-module-cant-parse-event-as-syslog-rfc3164/226116 "2020-04-02T08:30:08Z")

</div>

Hello, we have just recently started ingesting syslog logs with the CEF module of Filebeat. We are receiving the error message: 2020-04-01T14:02:47.863-0500 ERROR \[syslog\] syslog/input.go:243 can't parse event as syslog…

---

## [Error when starting metricbeat with v7.6.0](https://discuss.elastic.co/t/error-when-starting-metricbeat-with-v7-6-0/225965)

<div class="topic-metadata">

**Author:** [@integritytsui](https://discuss.elastic.co/u/integritytsui)\
**Replies:** 4\
**Last updated:** [April 2, 2020, 8:10am UTC](https://discuss.elastic.co/t/error-when-starting-metricbeat-with-v7-6-0/225965 "2020-04-02T08:10:56Z")

</div>

I see this error when trying to start metricbeat on win10 system: 2020-04-01T08:32:08.830+0800 ERROR instance/beat.go:933 Exiting: 8 errors: protocol not available; protocol not available; protocol not available…

---

## [Filebeat PANW Module Not Working (continued)](https://discuss.elastic.co/t/filebeat-panw-module-not-working-continued/223962)

<div class="topic-metadata">

**Author:** [@savethebyte](https://discuss.elastic.co/u/savethebyte)\
**Replies:** 2\
**Last updated:** [April 2, 2020, 3:10am UTC](https://discuss.elastic.co/t/filebeat-panw-module-not-working-continued/223962 "2020-04-02T03:10:33Z")

</div>

Continuing the discussion from Filebeat PANW Module Not Working: I have added true to /etc/filebeat/filebeat.yml with no change in behavior. filebeat.inputs: - type: log # Change to true to enable this input configur…

---

## [Packetbeat docker image 'help' and 'setup' subcommands fail without --cap-add=NET\_ADMIN](https://discuss.elastic.co/t/packetbeat-docker-image-help-and-setup-subcommands-fail-without-cap-add-net-admin/225314)

<div class="topic-metadata">

**Author:** [@wfhartford](https://discuss.elastic.co/u/wfhartford)\
**Replies:** 2\
**Last updated:** [April 1, 2020, 6:47pm UTC](https://discuss.elastic.co/t/packetbeat-docker-image-help-and-setup-subcommands-fail-without-cap-add-net-admin/225314 "2020-04-01T18:47:57Z")

</div>

The packetbeat docker image normally requires that the flag --cap-add=NET\_ADMIN be passed in order to capture packets. This is understandable and expected when packet capture is actually being performed, however the dock…

---

## [Metricbeat fields and dashboards - Only create fields and dashboard for configured module](https://discuss.elastic.co/t/metricbeat-fields-and-dashboards-only-create-fields-and-dashboard-for-configured-module/225907)

<div class="topic-metadata">

**Author:** [@ritchierich](https://discuss.elastic.co/u/ritchierich)\
**Replies:** 2\
**Last updated:** [April 1, 2020, 6:44pm UTC](https://discuss.elastic.co/t/metricbeat-fields-and-dashboards-only-create-fields-and-dashboard-for-configured-module/225907 "2020-04-01T18:44:57Z")

</div>

What's easiest way to not to generate fields and dashboards and only modules that are configure. For example, I do not use aerospike, but fields are create along with visualizations and dashboards. Cheers, Rich

---

## [Metricbeat + Kibana Dashboards \[esaggs\] \> "field" is a required parameter](https://discuss.elastic.co/t/metricbeat-kibana-dashboards-esaggs-field-is-a-required-parameter/225860)

<div class="topic-metadata">

**Author:** [@ffknob](https://discuss.elastic.co/u/ffknob)\
**Replies:** 5\
**Last updated:** [April 1, 2020, 5:41pm UTC](https://discuss.elastic.co/t/metricbeat-kibana-dashboards-esaggs-field-is-a-required-parameter/225860 "2020-04-01T17:41:03Z")

</div>

Hello, I've just deployed a cluster in the Elastic Cloud and configured a metricbeat agent to send metrics to that cluster. Here is my metricbeat.yml: name: "xyz.acme.co" tags: \["ACME", "acme.co"\] setup.ilm.check\_ex…

---

## [Problem with module elasticsearch of filebeat or ingest pipeline in 7.6.0, 7.6.2](https://discuss.elastic.co/t/problem-with-module-elasticsearch-of-filebeat-or-ingest-pipeline-in-7-6-0-7-6-2/226075)

<div class="topic-metadata">

**Author:** [@v.n](https://discuss.elastic.co/u/v.n)\
**Replies:** 1\
**Last updated:** [April 1, 2020, 4:37pm UTC](https://discuss.elastic.co/t/problem-with-module-elasticsearch-of-filebeat-or-ingest-pipeline-in-7-6-0-7-6-2/226075 "2020-04-01T16:37:52Z")

</div>

Hello! From the moment we have upgraded to 7.6.0 we have tons of info at /var/log/messages such as Apr 1 17:12:37 ct-ms-sr-vmdb06 elasticsearch: regular expression has redundant nested repeat operator \* /(?:(?:(?:(?\<T…

---

## [Weird behavior Kibana and Metricbeat dashboards](https://discuss.elastic.co/t/weird-behavior-kibana-and-metricbeat-dashboards/224934)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [April 1, 2020, 3:37pm UTC](https://discuss.elastic.co/t/weird-behavior-kibana-and-metricbeat-dashboards/224934 "2020-04-01T15:37:58Z")

</div>

Im having trouble to get the Metricbeat dashboards to work, testing configurations, this is the one that gives me best result but still are some problems. setup.dashboards.enabled: true setup.dashboards.directory: "/usr…

---

## [Filebeat no create object property alias](https://discuss.elastic.co/t/filebeat-no-create-object-property-alias/225388)

<div class="topic-metadata">

**Author:** [@josgut](https://discuss.elastic.co/u/josgut)\
**Replies:** 1\
**Last updated:** [April 1, 2020, 3:31pm UTC](https://discuss.elastic.co/t/filebeat-no-create-object-property-alias/225388 "2020-04-01T15:31:29Z")

</div>

Hello, i'm trying to configure filebeat and use kibana iis sample dashboard, but i can't because filebeat setup doesn't create mapped alias of geoip object, for example, i see iis geoip object index template void, becaus…

---

## [\[Urgent\] Elasticsearch fails to start](https://discuss.elastic.co/t/urgent-elasticsearch-fails-to-start/226044)

<div class="topic-metadata">

**Author:** [@The-Big-K](https://discuss.elastic.co/u/The-Big-K)\
**Replies:** 6\
**Last updated:** [April 1, 2020, 2:58pm UTC](https://discuss.elastic.co/t/urgent-elasticsearch-fails-to-start/226044 "2020-04-01T14:58:58Z")

</div>

I've the latest Elasticsearch (updated 30 minutes ago); and it's still throwing the following error:- regular expression has redundant nested repeat operator \* /\\\[(?\<TIMESTAMP\_ISO8601:elasticsearch.deprecation.timestamp\>…

---

## [What is a better option? Creating a Metric Set or Create a new beat](https://discuss.elastic.co/t/what-is-a-better-option-creating-a-metric-set-or-create-a-new-beat/225999)

<div class="topic-metadata">

**Author:** [@nabeel\_ahmed](https://discuss.elastic.co/u/nabeel_ahmed)\
**Replies:** 2\
**Last updated:** [April 1, 2020, 10:21am UTC](https://discuss.elastic.co/t/what-is-a-better-option-creating-a-metric-set-or-create-a-new-beat/225999 "2020-04-01T10:21:17Z")

</div>

Hi, The documentation regarding extending Metric beat is quite confusion. Both looks like the same: Extend Metricbeat directly Create your own Beat and use Metricbeat as a library The situation is, I want to get metr…

---

## [Filebeat\_logs](https://discuss.elastic.co/t/filebeat-logs/225917)

<div class="topic-metadata">

**Author:** [@Anuradha](https://discuss.elastic.co/u/Anuradha)\
**Replies:** 1\
**Last updated:** [April 1, 2020, 10:06am UTC](https://discuss.elastic.co/t/filebeat-logs/225917 "2020-04-01T10:06:28Z")

</div>

I am not able to get any logs in filebeat on kibana dashboard

---

## [HTTP-json module: processing json array](https://discuss.elastic.co/t/http-json-module-processing-json-array/225833)

<div class="topic-metadata">

**Author:** [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Replies:** 5\
**Last updated:** [April 1, 2020, 9:12am UTC](https://discuss.elastic.co/t/http-json-module-processing-json-array/225833 "2020-04-01T09:12:00Z")

</div>

I'm getting the following response from a web-server: { "items": \[ {"id": "0", "title": "title 1", "text": "some text"}, {"id": "1", "title": "title 2", "text": "some text"} \] } Is is possible: to drop it…

---

## [Cannot parse multiline log using Filebeat](https://discuss.elastic.co/t/cannot-parse-multiline-log-using-filebeat/225628)

<div class="topic-metadata">

**Author:** [@Bhanu1](https://discuss.elastic.co/u/Bhanu1)\
**Replies:** 6\
**Last updated:** [April 1, 2020, 5:52am UTC](https://discuss.elastic.co/t/cannot-parse-multiline-log-using-filebeat/225628 "2020-04-01T05:52:26Z")

</div>

Hi I am new to Filebeats , I need some help to parse logfiles with below pattern Please help 2020-03-27T14:00:05+00:00 log-forwarder-68kh5 kapacitor-7cf7f7bdd4-lb6cn\_monit {"log":"ts=2020-03-27T14:00:05.321Z lvl=info …

---

## [Filebeat TCP input with Nginx Module](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618)

<div class="topic-metadata">

**Author:** [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Replies:** 6\
**Last updated:** [April 1, 2020, 5:16am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-nginx-module/225618 "2020-04-01T05:16:18Z")

</div>

Hi , My setup: Elasticsearch & Kibana - 7.5.2 Filebeat - 7.5.x I have a Filebeat(NGINX-1) listen on TCP input to recieve Proxy logs from a remote NGINX server(NGINX-2) sending logs through Logstash TCP output. My qu…

---

## [Metricbeat Jolokia Module Not Capturing all data](https://discuss.elastic.co/t/metricbeat-jolokia-module-not-capturing-all-data/225333)

<div class="topic-metadata">

**Author:** [@jason\_0](https://discuss.elastic.co/u/jason_0)\
**Replies:** 3\
**Last updated:** [March 31, 2020, 10:30pm UTC](https://discuss.elastic.co/t/metricbeat-jolokia-module-not-capturing-all-data/225333 "2020-03-31T22:30:17Z")

</div>

I have a RedHat AMQ setup with some dummy data in it that I'm trying to capture with Metricbeat. I'm able to capture standard MBean attributes such as java.lang:type=Runtime's 'Uptime'. I'm also able to capture some AMQ …

---

## [Fixing Multiline Logs in Filebeat](https://discuss.elastic.co/t/fixing-multiline-logs-in-filebeat/224299)

<div class="topic-metadata">

**Author:** [@kevin5617](https://discuss.elastic.co/u/kevin5617)\
**Replies:** 3\
**Last updated:** [March 31, 2020, 9:09pm UTC](https://discuss.elastic.co/t/fixing-multiline-logs-in-filebeat/224299 "2020-03-31T21:09:45Z")

</div>

I know that filebeat has a multiline tool to handle multiline logs. However, the way my log structure is setup I do not think those solutions work exactly the same way. I am using the ELK stack with docker, and for fileb…

---

## [What does filebeat's multiline tool match](https://discuss.elastic.co/t/what-does-filebeats-multiline-tool-match/225720)

<div class="topic-metadata">

**Author:** [@kevin5617](https://discuss.elastic.co/u/kevin5617)\
**Replies:** 3\
**Last updated:** [March 31, 2020, 9:07pm UTC](https://discuss.elastic.co/t/what-does-filebeats-multiline-tool-match/225720 "2020-03-31T21:07:22Z")

</div>

I am using filebeat to read Docker logs and feed them to logstash. I have some logs that are being split into separate events. This happens with stack traces, or just any logs with a new line in them. Here is my filebea…

---

## [Filebeat pipping Suricatas eve.json issues](https://discuss.elastic.co/t/filebeat-pipping-suricatas-eve-json-issues/225890)

<div class="topic-metadata">

**Author:** [@eriknox](https://discuss.elastic.co/u/eriknox)\
**Replies:** 1\
**Last updated:** [March 31, 2020, 5:55pm UTC](https://discuss.elastic.co/t/filebeat-pipping-suricatas-eve-json-issues/225890 "2020-03-31T17:55:37Z")

</div>

Hello all, I have Elastic 7.6.1 up and running without the use of Logstash. My issue that I have is that I cannot get Filebeat to ingest Suricata. I have the module imported. Suricata is alerting and dropping the jso…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=261)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=263)
