# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=265

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 266

---

## [Filebeats Kubernetes File close due to inactive of 5min](https://discuss.elastic.co/t/filebeats-kubernetes-file-close-due-to-inactive-of-5min/224855)

<div class="topic-metadata">

**Author:** [@ConorTier](https://discuss.elastic.co/u/ConorTier)\
**Replies:** 2\
**Last updated:** [March 25, 2020, 8:43am UTC](https://discuss.elastic.co/t/filebeats-kubernetes-file-close-due-to-inactive-of-5min/224855 "2020-03-25T08:43:20Z")

</div>

Hey, Here is the setup currently have half working - Kubernetes - Amazon K8 - with a instance of logstash and file beats running on two pods - no demon sets for filebeats as want to read files from a specific directory …

---

## [Filebeat duplicate log](https://discuss.elastic.co/t/filebeat-duplicate-log/224209)

<div class="topic-metadata">

**Author:** [@ZPerling](https://discuss.elastic.co/u/ZPerling)\
**Replies:** 4\
**Last updated:** [March 25, 2020, 8:41am UTC](https://discuss.elastic.co/t/filebeat-duplicate-log/224209 "2020-03-25T08:41:05Z")

</div>

So, my filebeat running in the kubernetes cluster as daemonsets. and filebeat config: logging.level: info path.home: "/usr/share/filebeat" path.config: "/usr/share/filebeat" path.data: "/usr/share/filebe…

---

## [Filebeat randomly missing input records](https://discuss.elastic.co/t/filebeat-randomly-missing-input-records/224428)

<div class="topic-metadata">

**Author:** [@Henk21](https://discuss.elastic.co/u/Henk21)\
**Replies:** 4\
**Last updated:** [March 24, 2020, 2:59pm UTC](https://discuss.elastic.co/t/filebeat-randomly-missing-input-records/224428 "2020-03-24T14:59:58Z")

</div>

We routinely (re-)load ISE events in elasticsearch using the following command: cat ${FILELIST} | sort -u \>\>iselog.log.reprocess We sort the input file as it is made of ISE log events over multiple lines, and in our cu…

---

## [Filebeat on kubernetes](https://discuss.elastic.co/t/filebeat-on-kubernetes/224525)

<div class="topic-metadata">

**Author:** [@ash2](https://discuss.elastic.co/u/ash2)\
**Replies:** 3\
**Last updated:** [March 24, 2020, 5:17pm UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes/224525 "2020-03-24T17:17:09Z")

</div>

HI, I am looking for proper steps which are needed to be done for running filebeat on Kubernetes. Please anyone can guide me through all the steps for the deployment of filebeat as container and configuring Kubernetes. …

---

## [Can I monitor apache inside a docker container?](https://discuss.elastic.co/t/can-i-monitor-apache-inside-a-docker-container/224859)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [March 24, 2020, 4:17pm UTC](https://discuss.elastic.co/t/can-i-monitor-apache-inside-a-docker-container/224859 "2020-03-24T16:17:50Z")

</div>

Hi, I have mySQL and apache inside containers, I was wandering if I can monitor them? if that is true, I just have to enable Apache and mySql modules, or do I need some other configurations?

---

## [General Question : Best method for handling JSON files](https://discuss.elastic.co/t/general-question-best-method-for-handling-json-files/224687)

<div class="topic-metadata">

**Author:** [@zebulyon](https://discuss.elastic.co/u/zebulyon)\
**Replies:** 3\
**Last updated:** [March 24, 2020, 3:36pm UTC](https://discuss.elastic.co/t/general-question-best-method-for-handling-json-files/224687 "2020-03-24T15:36:38Z")

</div>

Hello, So I have a collection of PCAP files and I want to upload their content to Kibana. Now I am fairly certain that I will need to use tshark to convert the files to JSON, which I have done. Though I have a question…

---

## [Winlogbeat won't start as a Service](https://discuss.elastic.co/t/winlogbeat-wont-start-as-a-service/224864)

<div class="topic-metadata">

**Author:** [@illopssec](https://discuss.elastic.co/u/illopssec)\
**Replies:** 0\
**Last updated:** [March 24, 2020, 2:38pm UTC](https://discuss.elastic.co/t/winlogbeat-wont-start-as-a-service/224864 "2020-03-24T14:38:41Z")

</div>

Hello, I've downloaded, extracted, and renamed the latest Winlogbeat to the following folder: C:\\Program Files\\Elastic\\Beats\\Winlogbeat I've corrected the install-service-winlogbeat.ps1to reflect the correct data folde…

---

## [Using Filebeat on K8s - Trying to obtain App logs inside Pods](https://discuss.elastic.co/t/using-filebeat-on-k8s-trying-to-obtain-app-logs-inside-pods/224116)

<div class="topic-metadata">

**Author:** [@solijam](https://discuss.elastic.co/u/solijam)\
**Replies:** 1\
**Last updated:** [March 24, 2020, 2:27pm UTC](https://discuss.elastic.co/t/using-filebeat-on-k8s-trying-to-obtain-app-logs-inside-pods/224116 "2020-03-24T14:27:54Z")

</div>

Hello Team! We are using Filbeat on Kubernetes - OCP configuration. Currently we have success on obtaining logs through Filebeat, but these only show what you would find by navigating on OCP 4.X Web console... Pods \> "…

---

## [Filebeat holds file-handle during elastic downtime. -\> monitored system failed due to full disk](https://discuss.elastic.co/t/filebeat-holds-file-handle-during-elastic-downtime-monitored-system-failed-due-to-full-disk/224657)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 3\
**Last updated:** [March 24, 2020, 10:56am UTC](https://discuss.elastic.co/t/filebeat-holds-file-handle-during-elastic-downtime-monitored-system-failed-due-to-full-disk/224657 "2020-03-24T10:56:58Z")

</div>

Hi, in our dev system we encountered following issue: Our elastic-Stack was unavailable because the disk was full. So the indices / shards had been set to read only automatically by elasticsearch. As consequence redis …

---

## [Kafka Module pipeline is not working](https://discuss.elastic.co/t/kafka-module-pipeline-is-not-working/219351)

<div class="topic-metadata">

**Author:** [@maewonline](https://discuss.elastic.co/u/maewonline)\
**Replies:** 2\
**Last updated:** [February 25, 2020, 9:55am UTC](https://discuss.elastic.co/t/kafka-module-pipeline-is-not-working/219351 "2020-02-25T09:55:55Z")

</div>

I want to send Kafka logs to Elastic through Logstash. I have configured the filebeat.yml file and I'm able to see my logs in Kibana but without the Kafka exported fields that applied using Kafka module pipeline.json Fi…

---

## [Metricbeat mongodb no reachable servers error](https://discuss.elastic.co/t/metricbeat-mongodb-no-reachable-servers-error/224788)

<div class="topic-metadata">

**Author:** [@Adrian\_Birladeanu](https://discuss.elastic.co/u/Adrian_Birladeanu)\
**Replies:** 0\
**Last updated:** [March 24, 2020, 8:44am UTC](https://discuss.elastic.co/t/metricbeat-mongodb-no-reachable-servers-error/224788 "2020-03-24T08:44:31Z")

</div>

Hello. I have a MongoDB replica set with version 4.2.0 running in Kubernetes and I tried to add metricbeat monitoring to a secondary node (metricbeat version 7.6.1). Metricbeat successfully authenticates with a user tha…

---

## [Trying to read files from a Network Location](https://discuss.elastic.co/t/trying-to-read-files-from-a-network-location/224273)

<div class="topic-metadata">

**Author:** [@Jorge\_Herrera](https://discuss.elastic.co/u/Jorge_Herrera)\
**Replies:** 1\
**Last updated:** [March 23, 2020, 6:48pm UTC](https://discuss.elastic.co/t/trying-to-read-files-from-a-network-location/224273 "2020-03-23T18:48:30Z")

</div>

Hi, i need to read files that are in another server using filebeat, but im trying everything and does not work. I created a network location in my PC and also try to acces with the IP of the server. How can i do that ?…

---

## [Unrecognizable messages](https://discuss.elastic.co/t/unrecognizable-messages/224336)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 1\
**Last updated:** [March 23, 2020, 6:38pm UTC](https://discuss.elastic.co/t/unrecognizable-messages/224336 "2020-03-23T18:38:36Z")

</div>

I have installed filebeats on Centos6 I have the filebeats reading the /var/log/\*.log files (just using the default filebeats.yml config) I have filebeats sending the events to logstash then to ES. All I see is messag…

---

## [Ssh login fail events on kibana through filebeat](https://discuss.elastic.co/t/ssh-login-fail-events-on-kibana-through-filebeat/224377)

<div class="topic-metadata">

**Author:** [@gkulkarni](https://discuss.elastic.co/u/gkulkarni)\
**Replies:** 1\
**Last updated:** [March 23, 2020, 5:55pm UTC](https://discuss.elastic.co/t/ssh-login-fail-events-on-kibana-through-filebeat/224377 "2020-03-23T17:55:44Z")

</div>

Hi, Can someone help how to get events for failed ssh login attempts on Kibana dashboard? I'm using linux as host with filebeat installed. Should i install logstash as well in the host? -Thaks

---

## [I cannot forward docker meta data on Kafka](https://discuss.elastic.co/t/i-cannot-forward-docker-meta-data-on-kafka/224441)

<div class="topic-metadata">

**Author:** [@omerhanci](https://discuss.elastic.co/u/omerhanci)\
**Replies:** 1\
**Last updated:** [March 23, 2020, 5:31pm UTC](https://discuss.elastic.co/t/i-cannot-forward-docker-meta-data-on-kafka/224441 "2020-03-23T17:31:37Z")

</div>

I am using elastic stack with Kafka which is sitting between logstash and filebeat. I used following configuration to add docker metadata to log. processors: - add\_docker\_metadata: host: "unix:///var/run…

---

## [How to add field for logs from specific file](https://discuss.elastic.co/t/how-to-add-field-for-logs-from-specific-file/224567)

<div class="topic-metadata">

**Author:** [@pedro.1234](https://discuss.elastic.co/u/pedro.1234)\
**Replies:** 1\
**Last updated:** [March 23, 2020, 5:23pm UTC](https://discuss.elastic.co/t/how-to-add-field-for-logs-from-specific-file/224567 "2020-03-23T17:23:51Z")

</div>

Hello, I'm fresh user of ELK, i would like to read logs from different files and use grok's filter only for certain log/file. My setup looks like this: firewall logs -\> rsyslog -\> file -\> filebeat -\> logstash -\> Elast…

---

## [Modify the message outpout](https://discuss.elastic.co/t/modify-the-message-outpout/224574)

<div class="topic-metadata">

**Author:** [@geoffreydjof](https://discuss.elastic.co/u/geoffreydjof)\
**Replies:** 1\
**Last updated:** [March 23, 2020, 5:15pm UTC](https://discuss.elastic.co/t/modify-the-message-outpout/224574 "2020-03-23T17:15:25Z")

</div>

Hi, I have installed Filebeat on my servers to collect json logs. It works great ! I have one question : I would like to know if it's possible to modify the content of a message ? Let me be more explicit : In Kiban, …

---

## [Credentials' variables blocking beats from running as services on Windows](https://discuss.elastic.co/t/credentials-variables-blocking-beats-from-running-as-services-on-windows/214943)

<div class="topic-metadata">

**Author:** [@jsu](https://discuss.elastic.co/u/jsu)\
**Replies:** 11\
**Last updated:** [March 23, 2020, 3:58pm UTC](https://discuss.elastic.co/t/credentials-variables-blocking-beats-from-running-as-services-on-windows/214943 "2020-03-23T15:58:06Z")

</div>

Hey there, So, the problem doesn't appear on linux boxes, but only windows ones : win server 2012 and win10. I had the (almost) exact same problem with Winlogbeat, Metricbeat and Filebeat. Following the documentation c…

---

## [\[WinLogBeats\] Missing events from ForwardedEvents channel](https://discuss.elastic.co/t/winlogbeats-missing-events-from-forwardedevents-channel/224296)

<div class="topic-metadata">

**Author:** [@Travis](https://discuss.elastic.co/u/Travis)\
**Replies:** 2\
**Last updated:** [March 23, 2020, 3:56pm UTC](https://discuss.elastic.co/t/winlogbeats-missing-events-from-forwardedevents-channel/224296 "2020-03-23T15:56:50Z")

</div>

Hello ! I noticed that some logs are missing when I collect the channel "Forwarded Events" of my central log collector Here is my test. 1-Logs are well forwarded from my client (SRV-2012) to the central log collecto…

---

## [Filebeat docker on mac connecting to logstash deployed in Openshift](https://discuss.elastic.co/t/filebeat-docker-on-mac-connecting-to-logstash-deployed-in-openshift/224454)

<div class="topic-metadata">

**Author:** [@Mastana\_Guru](https://discuss.elastic.co/u/Mastana_Guru)\
**Replies:** 1\
**Last updated:** [March 23, 2020, 1:48pm UTC](https://discuss.elastic.co/t/filebeat-docker-on-mac-connecting-to-logstash-deployed-in-openshift/224454 "2020-03-23T13:48:39Z")

</div>

Hi all, I am newbie to elk and filebeat. I have deployed EK(version 7.6.1) operator and logstash(version 7.6.1) in openshift. This scenaio works fine when I upload logs file to logstash. Now I am want to use filebeat to…

---

## [Can't exclude particular files](https://discuss.elastic.co/t/cant-exclude-particular-files/224640)

<div class="topic-metadata">

**Author:** [@AdamJade](https://discuss.elastic.co/u/AdamJade)\
**Replies:** 1\
**Last updated:** [March 23, 2020, 10:56am UTC](https://discuss.elastic.co/t/cant-exclude-particular-files/224640 "2020-03-23T10:56:44Z")

</div>

Hi there, i'm not able to exclude files with names like: NAg\_ALL\_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\_TTT\_SSSSSS.Batch.exe.log 14a8002e-0c20-40f3-a7bc-2800985dc684NAg\_ALL\_DDDDDDDDDDDDDDDD\_EEEEE.TTTTTTT.exe.log with this …

---

## [\[WINLOGBEAT\] - Event :Delete folder or file](https://discuss.elastic.co/t/winlogbeat-event-delete-folder-or-file/224401)

<div class="topic-metadata">

**Author:** [@ekaduk](https://discuss.elastic.co/u/ekaduk)\
**Replies:** 3\
**Last updated:** [March 23, 2020, 10:06am UTC](https://discuss.elastic.co/t/winlogbeat-event-delete-folder-or-file/224401 "2020-03-23T10:06:13Z")

</div>

Hi, I'm a newbie user. I'd like to know if it could be possible to register a deletion of a file/folder in Windows, and then register it with winlogbeat. I've read the documentation about winlogbeat and I can't find so…

---

## [Filebeat Kibana (Attemp to add fields in Discover) - Discover Error fetching fields for index pattern filebeat-\* (ID: filebeat-\*)](https://discuss.elastic.co/t/filebeat-kibana-attemp-to-add-fields-in-discover-discover-error-fetching-fields-for-index-pattern-filebeat-id-filebeat/224577)

<div class="topic-metadata">

**Author:** [@bmclellan](https://discuss.elastic.co/u/bmclellan)\
**Replies:** 0\
**Last updated:** [March 22, 2020, 8:04pm UTC](https://discuss.elastic.co/t/filebeat-kibana-attemp-to-add-fields-in-discover-discover-error-fetching-fields-for-index-pattern-filebeat-id-filebeat/224577 "2020-03-22T20:04:51Z")

</div>

Hello, After the last update to ELK (I think it was like a single . release, I am seeing this error when I go to the discover section of Kibana and try to add in new fields. Error fetching fields for index pattern file…

---

## [Loading IDS logs via Elasticsearch and Filebeats issues](https://discuss.elastic.co/t/loading-ids-logs-via-elasticsearch-and-filebeats-issues/222194)

<div class="topic-metadata">

**Author:** [@gorgymorg](https://discuss.elastic.co/u/gorgymorg)\
**Replies:** 15\
**Last updated:** [March 22, 2020, 3:51pm UTC](https://discuss.elastic.co/t/loading-ids-logs-via-elasticsearch-and-filebeats-issues/222194 "2020-03-22T15:51:14Z")

</div>

I currently have Suricata running on an Ubuntu VM on computer 1 and am attempting to ship logs to an ELK stack on a VM on computer 2. My goal is to have Suricata logs in /var/logs on computer 1 VM shipped via filebeat ve…

---

## [Pfsense Firewall Logs via Filebeat](https://discuss.elastic.co/t/pfsense-firewall-logs-via-filebeat/224492)

<div class="topic-metadata">

**Author:** [@ctdlegion](https://discuss.elastic.co/u/ctdlegion)\
**Replies:** 0\
**Last updated:** [March 20, 2020, 9:14pm UTC](https://discuss.elastic.co/t/pfsense-firewall-logs-via-filebeat/224492 "2020-03-20T21:14:58Z")

</div>

We have a new Elastic Cloud deployment where we are collecting Sysmon and Windows logs from a server in a remote data center. We have that Windows server setup with Filebeat listening for inbound syslog so that we can a…

---

## [Filebeat on centos8?](https://discuss.elastic.co/t/filebeat-on-centos8/224252)

<div class="topic-metadata">

**Author:** [@Ludovic9](https://discuss.elastic.co/u/Ludovic9)\
**Replies:** 6\
**Last updated:** [March 20, 2020, 5:20pm UTC](https://discuss.elastic.co/t/filebeat-on-centos8/224252 "2020-03-20T17:20:48Z")

</div>

Hello, I'm trying to start filebeat on centos 8 server. My elk server is on 6.8.3 version. Here my test : filebeat 7.6.1 installed by rpm the config file is OK filebeat starts correctly but I don't see any log in e…

---

## [Jolokia autodiscovery](https://discuss.elastic.co/t/jolokia-autodiscovery/219622)

<div class="topic-metadata">

**Author:** [@Milan\_Todorovic](https://discuss.elastic.co/u/Milan_Todorovic)\
**Replies:** 12\
**Last updated:** [March 20, 2020, 11:37am UTC](https://discuss.elastic.co/t/jolokia-autodiscovery/219622 "2020-03-20T11:37:27Z")

</div>

Hi, I am currently in use of ELK cluster based on version 7.3.1 under Kubernetes environment. I also use Jolokia module inside metricbeat in order to gather many metrics. I wander does anyone can help me regarding Jolok…

---

## [Does filebeat support sFlow?](https://discuss.elastic.co/t/does-filebeat-support-sflow/222842)

<div class="topic-metadata">

**Author:** [@Jasonoh](https://discuss.elastic.co/u/Jasonoh)\
**Replies:** 1\
**Last updated:** [March 19, 2020, 9:36pm UTC](https://discuss.elastic.co/t/does-filebeat-support-sflow/222842 "2020-03-19T21:36:15Z")

</div>

Hi All, Just curious, does filebeat support sFlow data? it seems errored out when filebeat try to parse. Thank you

---

## [Heartbeat TLS ServerName not being set correctly](https://discuss.elastic.co/t/heartbeat-tls-servername-not-being-set-correctly/224280)

<div class="topic-metadata">

**Author:** [@michael.russell](https://discuss.elastic.co/u/michael.russell)\
**Replies:** 1\
**Last updated:** [March 19, 2020, 5:36pm UTC](https://discuss.elastic.co/t/heartbeat-tls-servername-not-being-set-correctly/224280 "2020-03-19T17:36:20Z")

</div>

When trying to monitor an SSL enabled endpoint it seems like Heartbeat is setting the ServerName to the IP address instead of the hostname. For setups where the certificate is only signed with the domain (and not all IP …

---

## [Winlogbeat 7.5.2 duplicate events](https://discuss.elastic.co/t/winlogbeat-7-5-2-duplicate-events/220371)

<div class="topic-metadata">

**Author:** [@knrdv](https://discuss.elastic.co/u/knrdv)\
**Replies:** 3\
**Last updated:** [March 19, 2020, 3:35pm UTC](https://discuss.elastic.co/t/winlogbeat-7-5-2-duplicate-events/220371 "2020-03-19T15:35:42Z")

</div>

Issue: One event from one Windows host shows like multiple identical events in Kibana. Events shown in Kibana differentiate only by the "\_id" field with everything else being identical. What could be the problem? Veriso…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=264)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=266)
