# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=263

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 264

---

## [Build Winlobeat deb file](https://discuss.elastic.co/t/build-winlobeat-deb-file/225734)

<div class="topic-metadata">

**Author:** [@micas](https://discuss.elastic.co/u/micas)\
**Replies:** 4\
**Last updated:** [March 31, 2020, 5:28pm UTC](https://discuss.elastic.co/t/build-winlobeat-deb-file/225734 "2020-03-31T17:28:56Z")

</div>

I know the request is odd but i want to distribute winlogbeat inside a docker container that runs debian. I plan then (through configs and volumes) to read from the host windows machine. Is there any way i can build a w…

---

## [Metricbeat password literal issue](https://discuss.elastic.co/t/metricbeat-password-literal-issue/225851)

<div class="topic-metadata">

**Author:** [@naveenbangalore](https://discuss.elastic.co/u/naveenbangalore)\
**Replies:** 3\
**Last updated:** [March 31, 2020, 4:56pm UTC](https://discuss.elastic.co/t/metricbeat-password-literal-issue/225851 "2020-03-31T16:56:28Z")

</div>

Hi, Not sure if this issue was already reported. Found an unusual behaviour with metricbeat. Typically when Xpack is enabled, username and password are added in the metricbeat.yml. When the password contains the litera…

---

## [Winlogbeat vs Filebeat](https://discuss.elastic.co/t/winlogbeat-vs-filebeat/225685)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 2\
**Last updated:** [March 31, 2020, 4:27pm UTC](https://discuss.elastic.co/t/winlogbeat-vs-filebeat/225685 "2020-03-31T16:27:54Z")

</div>

Hi, Filebeat and Winlogbeat seem to work similarly. Both beats seem to be able to process logs from Windows (in the case of Filebeats, it can also process logs from other OS). My questions would be: 1- Which beat is be…

---

## [Error "Panic in job" - Unable to monitor my service](https://discuss.elastic.co/t/error-panic-in-job-unable-to-monitor-my-service/225498)

<div class="topic-metadata">

**Author:** [@luok0](https://discuss.elastic.co/u/luok0)\
**Replies:** 6\
**Last updated:** [March 31, 2020, 3:30pm UTC](https://discuss.elastic.co/t/error-panic-in-job-unable-to-monitor-my-service/225498 "2020-03-31T15:30:15Z")

</div>

Got below error in heartbeat's debug log when tried to monitor one service while it works fine for other services: hearbeat.yml: // # Configure monitors heartbeat.monitors: - type: http # List or urls to query urls…

---

## [Trouble sending logs to Logstash from Filebeat - Pipeline error recieved](https://discuss.elastic.co/t/trouble-sending-logs-to-logstash-from-filebeat-pipeline-error-recieved/225566)

<div class="topic-metadata">

**Author:** [@13ill13urr](https://discuss.elastic.co/u/13ill13urr)\
**Replies:** 2\
**Last updated:** [March 31, 2020, 3:19pm UTC](https://discuss.elastic.co/t/trouble-sending-logs-to-logstash-from-filebeat-pipeline-error-recieved/225566 "2020-03-31T15:19:40Z")

</div>

Hi there, pretty new to the Elastic Stack and I keep getting an error when trying to set up Filebeats and Logstash to work together. Error: \< ''' Failed to execute action {:action=\>LogStash::PipelineAction::Create/pi…

---

## [Problem file beat](https://discuss.elastic.co/t/problem-file-beat/225889)

<div class="topic-metadata">

**Author:** [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Replies:** 0\
**Last updated:** [March 31, 2020, 2:38pm UTC](https://discuss.elastic.co/t/problem-file-beat/225889 "2020-03-31T14:38:19Z")

</div>

I have this problem when i run the logstsh \[monitoring\] log/log.go:145 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":130,"time":{"ms":6}},"total":{"ticks":860,"time": {…

---

## [Use user.name.keyword field in a kibana visualisation](https://discuss.elastic.co/t/use-user-name-keyword-field-in-a-kibana-visualisation/225638)

<div class="topic-metadata">

**Author:** [@eoli3n](https://discuss.elastic.co/u/eoli3n)\
**Replies:** 4\
**Last updated:** [March 31, 2020, 8:39am UTC](https://discuss.elastic.co/t/use-user-name-keyword-field-in-a-kibana-visualisation/225638 "2020-03-31T08:39:15Z")

</div>

Hi, I want to be able to unique.count on user.name field from filebeat-\* indexes with system auth module enabled. When i do this, i get a kibana error "\* of \* shards failed", and when i go to "response" tab, i can read …

---

## [How to set close\_removed and close\_timeout globally for all file inputs?](https://discuss.elastic.co/t/how-to-set-close-removed-and-close-timeout-globally-for-all-file-inputs/225817)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [March 31, 2020, 8:37am UTC](https://discuss.elastic.co/t/how-to-set-close-removed-and-close-timeout-globally-for-all-file-inputs/225817 "2020-03-31T08:37:47Z")

</div>

Hi, I found this old thread here: Are there any news? Is it possible to configure these parameters globally now? If not, I opened this feature request. If it is already possible, I will close this request or you ma…

---

## [Filebeat is putting whole JSON object into one field](https://discuss.elastic.co/t/filebeat-is-putting-whole-json-object-into-one-field/225815)

<div class="topic-metadata">

**Author:** [@Mattness](https://discuss.elastic.co/u/Mattness)\
**Replies:** 1\
**Last updated:** [March 31, 2020, 8:26am UTC](https://discuss.elastic.co/t/filebeat-is-putting-whole-json-object-into-one-field/225815 "2020-03-31T08:26:17Z")

</div>

Hello, I am using filebeat to route log data from my machine to Elasticsearch. The log-files contain multiple lines with every line being one JSON object literal. I want each line to become an event with as many field…

---

## [Deleting files after file beat processes them](https://discuss.elastic.co/t/deleting-files-after-file-beat-processes-them/225796)

<div class="topic-metadata">

**Author:** [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Replies:** 0\
**Last updated:** [March 31, 2020, 6:27am UTC](https://discuss.elastic.co/t/deleting-files-after-file-beat-processes-them/225796 "2020-03-31T06:27:41Z")

</div>

Hi, I would like to know if there is a way of deleting log files once filebeat has finished processing. We have files sent to an input folder, file beat then processes them. I would like to clear them down once it is d…

---

## [FunctionBeat: incorrect IAM Service Principal for Lambda in AWS China regions](https://discuss.elastic.co/t/functionbeat-incorrect-iam-service-principal-for-lambda-in-aws-china-regions/225775)

<div class="topic-metadata">

**Author:** [@henrysher](https://discuss.elastic.co/u/henrysher)\
**Replies:** 0\
**Last updated:** [March 31, 2020, 2:59am UTC](https://discuss.elastic.co/t/functionbeat-incorrect-iam-service-principal-for-lambda-in-aws-china-regions/225775 "2020-03-31T02:59:39Z")

</div>

Hello, I have tested FunctionBeat in AWS China region with those errors: 2020-03-31T12:13:10.748+0800 INFO \[aws\] aws/op\_cloudformation.go:97 Stack event received, ResourceType: AWS::IAM::Role, LogicalResourceId: fnbclo…

---

## [Filebeat with suricata cannot resolve timestamp from null](https://discuss.elastic.co/t/filebeat-with-suricata-cannot-resolve-timestamp-from-null/225518)

<div class="topic-metadata">

**Author:** [@mloebl](https://discuss.elastic.co/u/mloebl)\
**Replies:** 3\
**Last updated:** [March 31, 2020, 12:29am UTC](https://discuss.elastic.co/t/filebeat-with-suricata-cannot-resolve-timestamp-from-null/225518 "2020-03-31T00:29:47Z")

</div>

Currently using a pfSense running 2.4.x and a filebeat I built against 7.6.1 for FreeBSD. Whenever an alert comes in, I get: error.message:cannot resolve \[timestamp\] from null as part of path \[suricata.eve.timestamp\] H…

---

## [Filebeat vs Winlogbeat](https://discuss.elastic.co/t/filebeat-vs-winlogbeat/225684)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 1\
**Last updated:** [March 30, 2020, 9:44pm UTC](https://discuss.elastic.co/t/filebeat-vs-winlogbeat/225684 "2020-03-30T21:44:12Z")

</div>

Hi there, Filebeat and Winlogbeat seem to work similarly. Both beats seem to be able to process logs from Windows (in the case of Filebeats, it can also process logs from other OS). My questions would be: 1- Which beat…

---

## [Insert elastic search](https://discuss.elastic.co/t/insert-elastic-search/225647)

<div class="topic-metadata">

**Author:** [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Replies:** 1\
**Last updated:** [March 30, 2020, 9:37pm UTC](https://discuss.elastic.co/t/insert-elastic-search/225647 "2020-03-30T21:37:13Z")

</div>

I need the file to be inserted in elastic search to be removed from the directory

---

## [How to interpret the auditd.data.a fields](https://discuss.elastic.co/t/how-to-interpret-the-auditd-data-a-fields/225725)

<div class="topic-metadata">

**Author:** [@kasra](https://discuss.elastic.co/u/kasra)\
**Replies:** 0\
**Last updated:** [March 30, 2020, 5:42pm UTC](https://discuss.elastic.co/t/how-to-interpret-the-auditd-data-a-fields/225725 "2020-03-30T17:42:13Z")

</div>

I am trying to decode the arguments of syscalls which I have in "execve" logs. As these a0 to a3 fields are supposed to be encoded in hexadecimal I've tried to decode them to find out the args of the process but couldn'…

---

## [How to add system.hostfs definition into the yml files](https://discuss.elastic.co/t/how-to-add-system-hostfs-definition-into-the-yml-files/225047)

<div class="topic-metadata">

**Author:** [@micas](https://discuss.elastic.co/u/micas)\
**Replies:** 1\
**Last updated:** [March 30, 2020, 4:59pm UTC](https://discuss.elastic.co/t/how-to-add-system-hostfs-definition-into-the-yml-files/225047 "2020-03-30T16:59:34Z")

</div>

According to https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-docker.html i need to pass on docker containers the "-e -system.hostfs=/hostfs" however is there any way that i can add that to either the …

---

## [Questions on system.diskio latency metrics](https://discuss.elastic.co/t/questions-on-system-diskio-latency-metrics/225459)

<div class="topic-metadata">

**Author:** [@jkarras](https://discuss.elastic.co/u/jkarras)\
**Replies:** 1\
**Last updated:** [March 30, 2020, 4:54pm UTC](https://discuss.elastic.co/t/questions-on-system-diskio-latency-metrics/225459 "2020-03-30T16:54:32Z")

</div>

Hello, I am trying to get a better understanding of the disk io metrics below. Included are the definitions for each per the Elastic documentation online. system.diskio.read.time - total number of milliseconds spent b…

---

## [Kibana Elasticsearch error](https://discuss.elastic.co/t/kibana-elasticsearch-error/225694)

<div class="topic-metadata">

**Author:** [@thywoe](https://discuss.elastic.co/u/thywoe)\
**Replies:** 0\
**Last updated:** [March 30, 2020, 2:20pm UTC](https://discuss.elastic.co/t/kibana-elasticsearch-error/225694 "2020-03-30T14:20:42Z")

</div>

Error: Request to Elasticsearch failed: {"error":{"root\_cause":\[{"type":"illegal\_argument\_exception","reason":"The length of \[message.keyword\] field of \[4Ne\_K3EB1QJ6ixoFhFAq\] doc of \[filebeat-7.6.1\] index has exceeded \[1…

---

## [Recommendations for syslog ingestion?](https://discuss.elastic.co/t/recommendations-for-syslog-ingestion/223557)

<div class="topic-metadata">

**Author:** [@\_finack](https://discuss.elastic.co/u/_finack)\
**Replies:** 3\
**Last updated:** [March 30, 2020, 1:46pm UTC](https://discuss.elastic.co/t/recommendations-for-syslog-ingestion/223557 "2020-03-30T13:46:22Z")

</div>

We have many applications where we would like to ingest their log data into Elastic Stack; however, the log shipping mechanism is syslog (BSD, CEF, or RFC 5424). Our use case is SIEM & threat hunting. Here are options I…

---

## [Log file still harvesting after uninstalling Filebeat,metricbeat,heartbeat](https://discuss.elastic.co/t/log-file-still-harvesting-after-uninstalling-filebeat-metricbeat-heartbeat/225555)

<div class="topic-metadata">

**Author:** [@gilang\_bilbisri](https://discuss.elastic.co/u/gilang_bilbisri)\
**Replies:** 2\
**Last updated:** [March 30, 2020, 12:34pm UTC](https://discuss.elastic.co/t/log-file-still-harvesting-after-uninstalling-filebeat-metricbeat-heartbeat/225555 "2020-03-30T12:34:29Z")

</div>

Hi everyone. Im sorry for my broken english Today I've been uninstalling every app on my machine to remake everything i have done. i've already to Uninstalling -Elasticsearch -filebeat -metricbeat -heartbeat -Ki…

---

## [Need help configuring Filebeat Path](https://discuss.elastic.co/t/need-help-configuring-filebeat-path/225401)

<div class="topic-metadata">

**Author:** [@Mattness](https://discuss.elastic.co/u/Mattness)\
**Replies:** 2\
**Last updated:** [March 30, 2020, 11:30am UTC](https://discuss.elastic.co/t/need-help-configuring-filebeat-path/225401 "2020-03-30T11:30:30Z")

</div>

Hello everyone, I am trying to send some log data to Elasticsearch with Filebeat. All the log files are contained in subdirectories inside a directory. E.g. C:\\Users\\Me\\Desktop\\Storage\\2019-06-13\\11\*.log I want Fileb…

---

## [Filebeat Ansible Tags](https://discuss.elastic.co/t/filebeat-ansible-tags/225430)

<div class="topic-metadata">

**Author:** [@santos1204](https://discuss.elastic.co/u/santos1204)\
**Replies:** 2\
**Last updated:** [March 30, 2020, 10:39am UTC](https://discuss.elastic.co/t/filebeat-ansible-tags/225430 "2020-03-30T10:39:06Z")

</div>

Hi, I'm trying to pass tags using an ansible variable from each beats host, so that I can filter on those tags inside Kibana. I've tried several methods, but the tags don't seem to show. Whats the best way to achieve t…

---

## [Duplicated documents when log file is rotated while ELK is down](https://discuss.elastic.co/t/duplicated-documents-when-log-file-is-rotated-while-elk-is-down/225655)

<div class="topic-metadata">

**Author:** [@nahiko2000](https://discuss.elastic.co/u/nahiko2000)\
**Replies:** 0\
**Last updated:** [March 30, 2020, 10:26am UTC](https://discuss.elastic.co/t/duplicated-documents-when-log-file-is-rotated-while-elk-is-down/225655 "2020-03-30T10:26:05Z")

</div>

Hi! We have many servers with a Tomcat in each server, with several applications in each server, and we want to save the applications log files in Elastic, so in each server we also have a Filebeat. -Between Filebeat…

---

## [Filebeat -e -d "\*" errorr](https://discuss.elastic.co/t/filebeat-e-d-errorr/225626)

<div class="topic-metadata">

**Author:** [@thywoe](https://discuss.elastic.co/u/thywoe)\
**Replies:** 6\
**Last updated:** [March 30, 2020, 9:13am UTC](https://discuss.elastic.co/t/filebeat-e-d-errorr/225626 "2020-03-30T09:13:23Z")

</div>

I'm getting this "Exiting: data path already locked by another beat" anytime i execute this command 'sudo filebeat -e -d "\*" ' and i cannot see my logs on kibana. I need help.

---

## [Wildcard directories](https://discuss.elastic.co/t/wildcard-directories/225544)

<div class="topic-metadata">

**Author:** [@mimimike](https://discuss.elastic.co/u/mimimike)\
**Replies:** 1\
**Last updated:** [March 30, 2020, 9:02am UTC](https://discuss.elastic.co/t/wildcard-directories/225544 "2020-03-30T09:02:22Z")

</div>

Hi, I want to process the logs of multiple directories with filebeat. This files are contained in a share folder. I do not understand why the path "\\\\share\\folder\\\*.log" works well and the path "\\\\share\\\*\\\*.log" works w…

---

## [Syntax error on Raspbian](https://discuss.elastic.co/t/syntax-error-on-raspbian/225508)

<div class="topic-metadata">

**Author:** [@Cereal](https://discuss.elastic.co/u/Cereal)\
**Replies:** 1\
**Last updated:** [March 30, 2020, 8:18am UTC](https://discuss.elastic.co/t/syntax-error-on-raspbian/225508 "2020-03-30T08:18:31Z")

</div>

I'm trying to install Metricbeat on Raspbian to track my Pi-hole. I followed the install instructions for linux on elastics website (https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-configuration.html)…

---

## [Functionbeat not finding default credentials](https://discuss.elastic.co/t/functionbeat-not-finding-default-credentials/222784)

<div class="topic-metadata">

**Author:** [@Patrice1](https://discuss.elastic.co/u/Patrice1)\
**Replies:** 5\
**Last updated:** [March 30, 2020, 1:13am UTC](https://discuss.elastic.co/t/functionbeat-not-finding-default-credentials/222784 "2020-03-30T01:13:24Z")

</div>

I followed the guide to connect cloudwatch logs to kibana. After adding in my credentials and configs, the beat is not able to deploy to S3. I have the IAM permissions described. I only get the following debugging logs: …

---

## [Winlogbeat export Dashboard with Xpack](https://discuss.elastic.co/t/winlogbeat-export-dashboard-with-xpack/225415)

<div class="topic-metadata">

**Author:** [@xennn](https://discuss.elastic.co/u/xennn)\
**Replies:** 1\
**Last updated:** [March 29, 2020, 11:55pm UTC](https://discuss.elastic.co/t/winlogbeat-export-dashboard-with-xpack/225415 "2020-03-29T23:55:56Z")

</div>

Hello, i want to export the Dashboards from winlogbeat and import the json to Kibana. I have a ELK Stack Setup and cant use the normal command from the documentation. The Stack is almost encrypted with ssl xpack. Kiba…

---

## [Metric beats mappings for optional data](https://discuss.elastic.co/t/metric-beats-mappings-for-optional-data/225588)

<div class="topic-metadata">

**Author:** [@wahaj](https://discuss.elastic.co/u/wahaj)\
**Replies:** 0\
**Last updated:** [March 29, 2020, 8:58pm UTC](https://discuss.elastic.co/t/metric-beats-mappings-for-optional-data/225588 "2020-03-29T20:58:36Z")

</div>

I am trying to write a mapping for a custom metric beat whose goal is to capture the number of network connections for a list of protocols. There will be certain hosts, where a certain protocol will not be supported, whi…

---

## [Filebeat config to read current log only](https://discuss.elastic.co/t/filebeat-config-to-read-current-log-only/225442)

<div class="topic-metadata">

**Author:** [@manikandanb87](https://discuss.elastic.co/u/manikandanb87)\
**Replies:** 1\
**Last updated:** [March 29, 2020, 2:01pm UTC](https://discuss.elastic.co/t/filebeat-config-to-read-current-log-only/225442 "2020-03-29T14:01:18Z")

</div>

Hi Team, I have file beat cofigured on one of my machine and it is configured to send the feed to logstash. The thing is, I want my files to be read depending on todays date. My log files are getting generated in the f…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=262)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=264)
