# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=264

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 265

---

## [How to send windows events through winlogbeat to Humio?](https://discuss.elastic.co/t/how-to-send-windows-events-through-winlogbeat-to-humio/225439)

<div class="topic-metadata">

**Author:** [@romattos](https://discuss.elastic.co/u/romattos)\
**Replies:** 1\
**Last updated:** [March 29, 2020, 1:55pm UTC](https://discuss.elastic.co/t/how-to-send-windows-events-through-winlogbeat-to-humio/225439 "2020-03-29T13:55:30Z")

</div>

How to send windows events through winlogbeat to Humio? I get this error: Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: \[Error connection to Elasticsearch http://xxxxxxxxx

---

## [WinlogBeats template : Necessary to keep all fields?](https://discuss.elastic.co/t/winlogbeats-template-necessary-to-keep-all-fields/225479)

<div class="topic-metadata">

**Author:** [@Travis](https://discuss.elastic.co/u/Travis)\
**Replies:** 0\
**Last updated:** [March 28, 2020, 10:06am UTC](https://discuss.elastic.co/t/winlogbeats-template-necessary-to-keep-all-fields/225479 "2020-03-28T10:06:45Z")

</div>

Hello ! As I don't send Winlogbeats logs directly to Elasticsearch, I had to export and import the template. I noticed that the file is huge ! It contains almost four thousand lines. I noticed some fields related to …

---

## [System.diskio.iostat.await value bump too high](https://discuss.elastic.co/t/system-diskio-iostat-await-value-bump-too-high/224240)

<div class="topic-metadata">

**Author:** [@HenryDuong](https://discuss.elastic.co/u/HenryDuong)\
**Replies:** 5\
**Last updated:** [March 27, 2020, 8:27pm UTC](https://discuss.elastic.co/t/system-diskio-iostat-await-value-bump-too-high/224240 "2020-03-27T20:27:58Z")

</div>

Hi guys, I'm using the Metricbeat module version 7.2.0 to collect system KPI, but the system.diskio.iostat.await value is so wrong, it returns the value too large to be right. And I make sure the system has nothing wron…

---

## [Metricbeat module docker vs memory dataset](https://discuss.elastic.co/t/metricbeat-module-docker-vs-memory-dataset/224802)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 15\
**Last updated:** [March 27, 2020, 8:04pm UTC](https://discuss.elastic.co/t/metricbeat-module-docker-vs-memory-dataset/224802 "2020-03-27T20:04:08Z")

</div>

When I try to run metricbeat 7.6.1 on a CentOS 7 box with docker-engine-17.05.0.ce-1.el7.centos.x86\_64, I see these warning logged every time docker attempts to ship the memory metricset: 2020-03-24T11:14:00.316+0100\<ta…

---

## [How to measure megabytes transferred between Beats and Logstash over 5044 port](https://discuss.elastic.co/t/how-to-measure-megabytes-transferred-between-beats-and-logstash-over-5044-port/225431)

<div class="topic-metadata">

**Author:** [@saif3r](https://discuss.elastic.co/u/saif3r)\
**Replies:** 0\
**Last updated:** [March 27, 2020, 3:15pm UTC](https://discuss.elastic.co/t/how-to-measure-megabytes-transferred-between-beats-and-logstash-over-5044-port/225431 "2020-03-27T15:15:06Z")

</div>

Hello, I was asked to measure how much data we send from Beats to Logstash over 24h period. Are such statistics available somewhere in Beats or Logstash? I can't install anything on a computer where Beats is installed s…

---

## ["object mapping for \[host\] tried to parse field \[host\] as object, but found a concrete value" on filebeat/ingest](https://discuss.elastic.co/t/object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value-on-filebeat-ingest/224433)

<div class="topic-metadata">

**Author:** [@EldrosKandar](https://discuss.elastic.co/u/EldrosKandar)\
**Replies:** 3\
**Last updated:** [March 27, 2020, 3:13pm UTC](https://discuss.elastic.co/t/object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value-on-filebeat-ingest/224433 "2020-03-27T15:13:48Z")

</div>

By creation of a new pipeline, the following error began to pop up on the filebeat side: {"type":"mapper\_parsing\_exception","reason":"object mapping for \[host\] tried to parse field \[host\] as object, but found a concrete…

---

## [Filebeat not reading log files](https://discuss.elastic.co/t/filebeat-not-reading-log-files/225284)

<div class="topic-metadata">

**Author:** [@Mastana\_Guru](https://discuss.elastic.co/u/Mastana_Guru)\
**Replies:** 3\
**Last updated:** [March 27, 2020, 2:58pm UTC](https://discuss.elastic.co/t/filebeat-not-reading-log-files/225284 "2020-03-27T14:58:14Z")

</div>

Hi, Filebeat is not processing any files from the input folders Setup : Filebeat -\> Logstash -\> Elasticsearch -\> Kibana (All are version 7.6.1) Filebeat docker running on mac, only one instance running. ELK running …

---

## [Timestamp processor - parsing milliseconds with comma](https://discuss.elastic.co/t/timestamp-processor-parsing-milliseconds-with-comma/225068)

<div class="topic-metadata">

**Author:** [@dcamozzato](https://discuss.elastic.co/u/dcamozzato)\
**Replies:** 2\
**Last updated:** [March 27, 2020, 2:24pm UTC](https://discuss.elastic.co/t/timestamp-processor-parsing-milliseconds-with-comma/225068 "2020-03-27T14:24:13Z")

</div>

Hi, I am trying to use Filebeat 7.5.1 to parse a timestamp with the following format: '2020-01-17 06:37:17,849' My layout is this: '2006-01-02 15:04:05,999' Unfortunately, the above does not work. According to Golang…

---

## [Logstash: A plugin had an unrecoverable error. Will restart this plugin](https://discuss.elastic.co/t/logstash-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/225318)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 2\
**Last updated:** [March 27, 2020, 11:30am UTC](https://discuss.elastic.co/t/logstash-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/225318 "2020-03-27T11:30:17Z")

</div>

When I start my logstash config file it show like this \[2020-03-26T21:24:52,293\]\[INFO \]\[logstash.javapipeline \]\[main\] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipel…

---

## [ERROR	instance/beat.go:933	Exiting: Error reading config file: required 'object', but found 'string' in field 'filebeat.inputs.1' (source:'filebeat.yml')](https://discuss.elastic.co/t/error-instance-beat-go-933-exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-1-source-filebeat-yml/225074)

<div class="topic-metadata">

**Author:** [@hemant\_472](https://discuss.elastic.co/u/hemant_472)\
**Replies:** 2\
**Last updated:** [March 27, 2020, 8:50am UTC](https://discuss.elastic.co/t/error-instance-beat-go-933-exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-1-source-filebeat-yml/225074 "2020-03-27T08:50:43Z")

</div>

Hi, i am getting this error and not able to access my log file \`''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' filebeat.inputs: Each - is an input. Most options can be set …

---

## [Unable to create custom index or Disable ILM](https://discuss.elastic.co/t/unable-to-create-custom-index-or-disable-ilm/224964)

<div class="topic-metadata">

**Author:** [@rehannali](https://discuss.elastic.co/u/rehannali)\
**Replies:** 2\
**Last updated:** [March 27, 2020, 5:36am UTC](https://discuss.elastic.co/t/unable-to-create-custom-index-or-disable-ilm/224964 "2020-03-27T05:36:08Z")

</div>

Hi, I'm unable to create custom index from filebeat. I tried to disbale ilm and tried almost everything but i'm unable to disable it. configuration###################### Filebeat Configuration Example ##################…

---

## [Fields](https://discuss.elastic.co/t/fields/224799)

<div class="topic-metadata">

**Author:** [@rockyu](https://discuss.elastic.co/u/rockyu)\
**Replies:** 13\
**Last updated:** [March 27, 2020, 2:27am UTC](https://discuss.elastic.co/t/fields/224799 "2020-03-27T02:27:29Z")

</div>

Error while initializing input: missing field accessing 'filebeat.inputs.0.fields.host\_ip'

---

## [Filebeats ingesting filebeats logs](https://discuss.elastic.co/t/filebeats-ingesting-filebeats-logs/225272)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 2\
**Last updated:** [March 27, 2020, 1:53am UTC](https://discuss.elastic.co/t/filebeats-ingesting-filebeats-logs/225272 "2020-03-27T01:53:04Z")

</div>

At first I added /var/log/filebeat/filebeat as an input in the "inputs.d/filebeat.yml" folder. This created a circular logging issue; ie filebeat would write data to the filebeat log file then re-read that log event i…

---

## [Where can i download the latest beats with static link?](https://discuss.elastic.co/t/where-can-i-download-the-latest-beats-with-static-link/225184)

<div class="topic-metadata">

**Author:** [@David\_Gacias](https://discuss.elastic.co/u/David_Gacias)\
**Replies:** 1\
**Last updated:** [March 27, 2020, 12:52am UTC](https://discuss.elastic.co/t/where-can-i-download-the-latest-beats-with-static-link/225184 "2020-03-27T00:52:46Z")

</div>

For example, in the downloads page all the links point to a numbered version like: https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.6.1-amd64.deb I have already tried: https://artifacts.elastic.co/down…

---

## [Building for ppc64le](https://discuss.elastic.co/t/building-for-ppc64le/225290)

<div class="topic-metadata">

**Author:** [@eugeneswalker](https://discuss.elastic.co/u/eugeneswalker)\
**Replies:** 0\
**Last updated:** [March 26, 2020, 8:49pm UTC](https://discuss.elastic.co/t/building-for-ppc64le/225290 "2020-03-26T20:49:16Z")

</div>

I'm trying to build the deb package for Filebeat for ppc64le . I've followed the developer guide and setup a Go environment with Python 3.7, Mage, and Virtualenv on my system. When I navigate to beats/filebeat directory …

---

## [Grok for auditbeat log](https://discuss.elastic.co/t/grok-for-auditbeat-log/225213)

<div class="topic-metadata">

**Author:** [@Burga](https://discuss.elastic.co/u/Burga)\
**Replies:** 1\
**Last updated:** [March 26, 2020, 8:12pm UTC](https://discuss.elastic.co/t/grok-for-auditbeat-log/225213 "2020-03-26T20:12:17Z")

</div>

Hi , I'm trying to set grok for auditbeat pipeline but getting grokparsefailure maybe someone has a sample audit grok configuration ? thanks in advance.

---

## [Dropping events in Auditbeat](https://discuss.elastic.co/t/dropping-events-in-auditbeat/224483)

<div class="topic-metadata">

**Author:** [@AaronWF](https://discuss.elastic.co/u/AaronWF)\
**Replies:** 4\
**Last updated:** [March 26, 2020, 6:17pm UTC](https://discuss.elastic.co/t/dropping-events-in-auditbeat/224483 "2020-03-26T18:17:16Z")

</div>

I have Auditbeat shipping system processes directly to elastic cloud, I would like to drop the noisiest events such as Google Chrome + Renderer and 'System/Library/Frameworks' and their child processes. I have added thi…

---

## [SIEM not found](https://discuss.elastic.co/t/siem-not-found/225023)

<div class="topic-metadata">

**Author:** [@alireza\_MHZ](https://discuss.elastic.co/u/alireza_MHZ)\
**Replies:** 1\
**Last updated:** [March 26, 2020, 5:53pm UTC](https://discuss.elastic.co/t/siem-not-found/225023 "2020-03-26T17:53:35Z")

</div>

hi i have setup auditbeat and Data successfully received as the kibana said. but when i click on SIEM APP Application Not Found No application was found at this URL. Try going back or choosing an app from the menu. w…

---

## [Error: system/socket dataset setup failed](https://discuss.elastic.co/t/error-system-socket-dataset-setup-failed/222603)

<div class="topic-metadata">

**Author:** [@rowe](https://discuss.elastic.co/u/rowe)\
**Replies:** 10\
**Last updated:** [March 26, 2020, 5:30pm UTC](https://discuss.elastic.co/t/error-system-socket-dataset-setup-failed/222603 "2020-03-26T17:30:38Z")

</div>

Hi! I'm new at this and trying to get Auditbeat running on my Synology NAS (DS918+, x86\_64) but there are errors when I try to start it (with ./auditbeat -e). Can anyone tell me if there is something I can do to fix …

---

## [Atlas Mongodb cluster not working with metricbeat](https://discuss.elastic.co/t/atlas-mongodb-cluster-not-working-with-metricbeat/225177)

<div class="topic-metadata">

**Author:** [@Rohail1](https://discuss.elastic.co/u/Rohail1)\
**Replies:** 1\
**Last updated:** [March 26, 2020, 5:25pm UTC](https://discuss.elastic.co/t/atlas-mongodb-cluster-not-working-with-metricbeat/225177 "2020-03-26T17:25:12Z")

</div>

Hello, I am unable to connect my atlas cluster with metric. If I use self-hosted MongoDB URL it works fine but if I use atlas cluster it throws an error saying "no reachable servers"

---

## [Packetbeat loss data when monitor mysql](https://discuss.elastic.co/t/packetbeat-loss-data-when-monitor-mysql/225149)

<div class="topic-metadata">

**Author:** [@Romber\_Li](https://discuss.elastic.co/u/Romber_Li)\
**Replies:** 0\
**Last updated:** [March 26, 2020, 9:20am UTC](https://discuss.elastic.co/t/packetbeat-loss-data-when-monitor-mysql/225149 "2020-03-26T09:20:35Z")

</div>

I deployed packbeat on a mysql server to capture mysql traffic, and then send to the kafka, but I found that, QPS that was sent to kafka was much lower than I saw in monitoring system(I use Percona Monitoring and Manage…

---

## [OSS version of packetbeat trying xpack endpoint](https://discuss.elastic.co/t/oss-version-of-packetbeat-trying-xpack-endpoint/225106)

<div class="topic-metadata">

**Author:** [@shantanuo](https://discuss.elastic.co/u/shantanuo)\
**Replies:** 0\
**Last updated:** [March 26, 2020, 3:47am UTC](https://discuss.elastic.co/t/oss-version-of-packetbeat-trying-xpack-endpoint/225106 "2020-03-26T03:47:46Z")

</div>

Packetbeat version 6.8.5 was working fine. When I upgraded to 7.6.1 I got an error while connecting to AWS elasticsearch server. I am using OSS version and as promised it wasn't trying any \_xpack/ endpoints in the older …

---

## [Log files which sometimes contain no data](https://discuss.elastic.co/t/log-files-which-sometimes-contain-no-data/224937)

<div class="topic-metadata">

**Author:** [@stantanev](https://discuss.elastic.co/u/stantanev)\
**Replies:** 2\
**Last updated:** [March 25, 2020, 10:27pm UTC](https://discuss.elastic.co/t/log-files-which-sometimes-contain-no-data/224937 "2020-03-25T22:27:21Z")

</div>

hi everyone, how does filebeat handle the case where a different log file is received every hour from a cloud system and sometimes the received files have no data (0kb). ? Do these files with no data cause any issues fo…

---

## [Error when startingmetricbeat with v7.5.3](https://discuss.elastic.co/t/error-when-startingmetricbeat-with-v7-5-3/224491)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 21\
**Last updated:** [March 25, 2020, 8:38pm UTC](https://discuss.elastic.co/t/error-when-startingmetricbeat-with-v7-5-3/224491 "2020-03-25T20:38:36Z")

</div>

I see this error when trying to start metricbeat on ppc64le system: 2020-03-20T15:47:22.639-0500 ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch(http://elasticdev:9200)): Connection marked …

---

## [Using Modules and Custom logs](https://discuss.elastic.co/t/using-modules-and-custom-logs/224186)

<div class="topic-metadata">

**Author:** [@bmclellan](https://discuss.elastic.co/u/bmclellan)\
**Replies:** 4\
**Last updated:** [March 25, 2020, 5:46pm UTC](https://discuss.elastic.co/t/using-modules-and-custom-logs/224186 "2020-03-25T17:46:35Z")

</div>

Hello, Is it possible to use the modules that come with filebeat and create your own custom logs as well? I attempted to follow the file structure of the 'iis' module and create my own, but it doesn't seem to be proces…

---

## [Filebeat 7.5.1 logging.files.path is not working](https://discuss.elastic.co/t/filebeat-7-5-1-logging-files-path-is-not-working/224750)

<div class="topic-metadata">

**Author:** [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Replies:** 10\
**Last updated:** [March 25, 2020, 5:46pm UTC](https://discuss.elastic.co/t/filebeat-7-5-1-logging-files-path-is-not-working/224750 "2020-03-25T17:46:24Z")

</div>

I have put the following in my filebeats for 7.5.1 but everything is being logged to syslog still. any idea on why? logging.level: info logging.to\_syslog: false logging.to\_files: true logging.files: path: /var/log/…

---

## [Running filebeat as ECS daemon](https://discuss.elastic.co/t/running-filebeat-as-ecs-daemon/224958)

<div class="topic-metadata">

**Author:** [@Alexander\_Popov](https://discuss.elastic.co/u/Alexander_Popov)\
**Replies:** 2\
**Last updated:** [March 25, 2020, 2:49pm UTC](https://discuss.elastic.co/t/running-filebeat-as-ecs-daemon/224958 "2020-03-25T14:49:44Z")

</div>

I want to run filebeat as AWS ECS daemon My plan is to attach volume in filebeat daemon as /var/log/app and same volumes in all app containers. Each container will write logs in /var/log/app/$container\_id folder q…

---

## [How filebeat chooses module paths based on OS when running inside docker](https://discuss.elastic.co/t/how-filebeat-chooses-module-paths-based-on-os-when-running-inside-docker/224921)

<div class="topic-metadata">

**Author:** [@micas](https://discuss.elastic.co/u/micas)\
**Replies:** 2\
**Last updated:** [March 25, 2020, 12:46pm UTC](https://discuss.elastic.co/t/how-filebeat-chooses-module-paths-based-on-os-when-running-inside-docker/224921 "2020-03-25T12:46:02Z")

</div>

I have filebeat running on a docker container, on the documentation it says that when activating a module, if i leave the paths as default it will choose the path based on the OS. Obviously i want to capture the log fil…

---

## [Packetbeat: Postgres Module No Data](https://discuss.elastic.co/t/packetbeat-postgres-module-no-data/224983)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 0\
**Last updated:** [March 25, 2020, 12:24pm UTC](https://discuss.elastic.co/t/packetbeat-postgres-module-no-data/224983 "2020-03-25T12:24:36Z")

</div>

Hi, I'm trying to test packetbeat (6.8.7) for tracking postgres transactions. I have flow, dns and pgsql modules enabled. I have the index template loaded and am seeing data in kibana for types flow and dns. However, I…

---

## [Elasticsearch ingest pipelines not configured](https://discuss.elastic.co/t/elasticsearch-ingest-pipelines-not-configured/224878)

<div class="topic-metadata">

**Author:** [@A\_B](https://discuss.elastic.co/u/A_B)\
**Replies:** 3\
**Last updated:** [March 25, 2020, 12:23pm UTC](https://discuss.elastic.co/t/elasticsearch-ingest-pipelines-not-configured/224878 "2020-03-25T12:23:58Z")

</div>

Hello all, not entirely sure if this should be classified as Filebeat, Elasticsearch or Kibana but as I'm executing a Filebeat command, I will start here. I'm trying to setup Elasticsearch ingest pipelines per this doc…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=263)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=265)
