# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=266

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 267

---

## [Manips to update the Discover board](https://discuss.elastic.co/t/manips-to-update-the-discover-board/223750)

<div class="topic-metadata">

**Author:** [@Cuju](https://discuss.elastic.co/u/Cuju)\
**Replies:** 18\
**Last updated:** [March 19, 2020, 2:51pm UTC](https://discuss.elastic.co/t/manips-to-update-the-discover-board/223750 "2020-03-19T14:51:11Z")

</div>

Good morning, Actually, I use grok pipeline in Elasticsearch but it doesn't seem that the modifications apply when I change something on my pipeline. What are the manipulations to do to see them ? Regards.

---

## [FileBeat Output](https://discuss.elastic.co/t/filebeat-output/224266)

<div class="topic-metadata">

**Author:** [@Richard\_Phillips\_Roy](https://discuss.elastic.co/u/Richard_Phillips_Roy)\
**Replies:** 0\
**Last updated:** [March 19, 2020, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-output/224266 "2020-03-19T12:56:49Z")

</div>

Hi, I got two questions I have an apache server running on AWS EC2 Ubuntu Server Instance, I installed filebeat on the instance, how do I set the output of the filebeat to send the logs files from EC2 to my computer ru…

---

## [Set proxy in heartbeat](https://discuss.elastic.co/t/set-proxy-in-heartbeat/224163)

<div class="topic-metadata">

**Author:** [@Robin020](https://discuss.elastic.co/u/Robin020)\
**Replies:** 3\
**Last updated:** [March 19, 2020, 1:34pm UTC](https://discuss.elastic.co/t/set-proxy-in-heartbeat/224163 "2020-03-19T13:34:08Z")

</div>

I am trying to use a proxy for monitoring an url. I found this option: proxy\_url: socks5://user:password@socks5-proxy:2233 I have a proxy without auth so this is the what I have created: proxy\_url : socks4://\<IP\>:\<P…

---

## [Filebeat harvesting a csv file failing](https://discuss.elastic.co/t/filebeat-harvesting-a-csv-file-failing/223936)

<div class="topic-metadata">

**Author:** [@ankitagarwal10k](https://discuss.elastic.co/u/ankitagarwal10k)\
**Replies:** 3\
**Last updated:** [March 19, 2020, 1:05pm UTC](https://discuss.elastic.co/t/filebeat-harvesting-a-csv-file-failing/223936 "2020-03-19T13:05:18Z")

</div>

When I try using a csv file, the harvesting fails. below is the log from Filebeat: Mar 17 19:03:26 issi01 filebeat\[3989\]: 2020-03-17T19:03:26.282+0530 INFO log/harvester.go:316 File was removed: /…

---

## [Make collect command throws an error](https://discuss.elastic.co/t/make-collect-command-throws-an-error/224185)

<div class="topic-metadata">

**Author:** [@Daniel\_Carmel](https://discuss.elastic.co/u/Daniel_Carmel)\
**Replies:** 1\
**Last updated:** [March 19, 2020, 12:01pm UTC](https://discuss.elastic.co/t/make-collect-command-throws-an-error/224185 "2020-03-19T12:01:28Z")

</div>

I am trying to run the make collect command after creating new metricset and get the following error: ~/go\_dev/src/github.com/elastic/beats/metricbeat$ make collect Makefile:84: warning: overriding recipe for target 'in…

---

## [Beats generate files under /tmp](https://discuss.elastic.co/t/beats-generate-files-under-tmp/224231)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 1\
**Last updated:** [March 19, 2020, 8:55am UTC](https://discuss.elastic.co/t/beats-generate-files-under-tmp/224231 "2020-03-19T08:55:42Z")

</div>

when installed and running auditbeat and filebeat \[7.6.1\] on Linux I find files like below under /tmp: lrwxrwxrwx. 1 root root 66 Mar 19 09:15 filebeat.INFO -\> filebeat.stws-guinea-pig.root.log.INFO.20200319-091516.38…

---

## [Manual activation of modules](https://discuss.elastic.co/t/manual-activation-of-modules/223382)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 3\
**Last updated:** [March 18, 2020, 2:33pm UTC](https://discuss.elastic.co/t/manual-activation-of-modules/223382 "2020-03-18T14:33:07Z")

</div>

I'm trying to understand howto manually pre-setup ingest pipelines for various wanted filebeat modules and configure modules to use such pipelines. Eg let's look at system module, this has two parts syslog + audit logs,…

---

## [Filebeat module cef syslog parse errors](https://discuss.elastic.co/t/filebeat-module-cef-syslog-parse-errors/220148)

<div class="topic-metadata">

**Author:** [@undelete](https://discuss.elastic.co/u/undelete)\
**Replies:** 12\
**Last updated:** [March 18, 2020, 11:53am UTC](https://discuss.elastic.co/t/filebeat-module-cef-syslog-parse-errors/220148 "2020-03-18T11:53:38Z")

</div>

Im using the cef module in filebeat to receive cef events from a ArcSight SmartConnector. The SmartConnector is configured for Port 5001 Protocol UDP and CEF Version 0.1. On the Filebeat side I receive on port 5001 and…

---

## [Retrieve daily logs](https://discuss.elastic.co/t/retrieve-daily-logs/223274)

<div class="topic-metadata">

**Author:** [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Replies:** 8\
**Last updated:** [March 18, 2020, 4:30pm UTC](https://discuss.elastic.co/t/retrieve-daily-logs/223274 "2020-03-18T16:30:36Z")

</div>

Hello, Is it possible to configure a file beat on a path whose name varies (current date)? paths: /opt/zimbra/log/access\_log.2020-03-12 I think so but not found how to do it: :slight\_smile: Regards,

---

## [Filebeat pushes old logs on restart even though registry is persisted and functional](https://discuss.elastic.co/t/filebeat-pushes-old-logs-on-restart-even-though-registry-is-persisted-and-functional/224143)

<div class="topic-metadata">

**Author:** [@abdulahjamak](https://discuss.elastic.co/u/abdulahjamak)\
**Replies:** 0\
**Last updated:** [March 18, 2020, 3:55pm UTC](https://discuss.elastic.co/t/filebeat-pushes-old-logs-on-restart-even-though-registry-is-persisted-and-functional/224143 "2020-03-18T15:55:53Z")

</div>

Hi, our Filebeat (7.6.1 currently, it was an older version but we've upgraded it to the newest one for testing purposes) is running as a sidecar container. We have the data folder persisted. The data/registry/filebeat/d…

---

## [Conflicts between object types: filebeat vs metricbeat](https://discuss.elastic.co/t/conflicts-between-object-types-filebeat-vs-metricbeat/224131)

<div class="topic-metadata">

**Author:** [@rout39574](https://discuss.elastic.co/u/rout39574)\
**Replies:** 0\
**Last updated:** [March 18, 2020, 2:35pm UTC](https://discuss.elastic.co/t/conflicts-between-object-types-filebeat-vs-metricbeat/224131 "2020-03-18T14:35:30Z")

</div>

In our kafka-mediated ELK environment, we find that filebeat templates direct that the kafka.partition data item be type long, and metricbeat templates direct that it be type Object. This generates conflicts downstream …

---

## [Metricbeat sql module Oracle driver](https://discuss.elastic.co/t/metricbeat-sql-module-oracle-driver/224130)

<div class="topic-metadata">

**Author:** [@quotendepp](https://discuss.elastic.co/u/quotendepp)\
**Replies:** 0\
**Last updated:** [March 18, 2020, 2:28pm UTC](https://discuss.elastic.co/t/metricbeat-sql-module-oracle-driver/224130 "2020-03-18T14:28:28Z")

</div>

Hi, in the sql module in metricbeat it's possible to configure a driver. I saw in the code of the oracle module that the godror driver is used there and I figured then it should also be possible to use that one in the s…

---

## [Netflow gaps between filebeat and elasticsearch](https://discuss.elastic.co/t/netflow-gaps-between-filebeat-and-elasticsearch/224105)

<div class="topic-metadata">

**Author:** [@Kupauw](https://discuss.elastic.co/u/Kupauw)\
**Replies:** 0\
**Last updated:** [March 18, 2020, 12:20pm UTC](https://discuss.elastic.co/t/netflow-gaps-between-filebeat-and-elasticsearch/224105 "2020-03-18T12:20:49Z")

</div>

Hi everyone, I have been struggeling with parsing netflow from my Cisco FTD (cluster mode) with around 12k events per second. Through filebeat -\> elasticsearch. (Using version 7.6.0 for filebeat/elastic) I have 2 serv…

---

## [Error fetching data for metricset windows.service: The data is invalid](https://discuss.elastic.co/t/error-fetching-data-for-metricset-windows-service-the-data-is-invalid/222079)

<div class="topic-metadata">

**Author:** [@adrianbumbas](https://discuss.elastic.co/u/adrianbumbas)\
**Replies:** 4\
**Last updated:** [March 18, 2020, 11:53am UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-windows-service-the-data-is-invalid/222079 "2020-03-18T11:53:29Z")

</div>

Hello I'm trying to get Windows metrics using Metricbeat 7.6.0 and all I get in the logs is this message: Error fetching data for metricset windows.service: The data is invalid. The user under which I'm running Metric…

---

## [Error in autodiscover provider settings - unexpected type \<nil\>](https://discuss.elastic.co/t/error-in-autodiscover-provider-settings-unexpected-type-nil/224082)

<div class="topic-metadata">

**Author:** [@Anto74](https://discuss.elastic.co/u/Anto74)\
**Replies:** 0\
**Last updated:** [March 18, 2020, 11:03am UTC](https://discuss.elastic.co/t/error-in-autodiscover-provider-settings-unexpected-type-nil/224082 "2020-03-18T11:03:42Z")

</div>

Hi, I'm deploying my filebeat to collect log in a specific namespace. My chart looks like the following: autodiscover: enabled: true namespace: ".RELEASE.NAMESPACE" logplane: kubelog json: enabled: true target: "…

---

## [Renaming and repackaging beats](https://discuss.elastic.co/t/renaming-and-repackaging-beats/223735)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 1\
**Last updated:** [March 18, 2020, 9:38am UTC](https://discuss.elastic.co/t/renaming-and-repackaging-beats/223735 "2020-03-18T09:38:00Z")

</div>

Am trying to repackaged renamed versions of eg. auditbeat and filebeat v.7.6.1 using the FPM utility. But I find that most properly rpmbuild adds in symlinks under /usr/lib/.build-id to the binaries in such pacakges and…

---

## [Update pipeline filebeat-6.5.1-nginx-access-default - Error](https://discuss.elastic.co/t/update-pipeline-filebeat-6-5-1-nginx-access-default-error/223973)

<div class="topic-metadata">

**Author:** [@ORich](https://discuss.elastic.co/u/ORich)\
**Replies:** 0\
**Last updated:** [March 17, 2020, 4:26pm UTC](https://discuss.elastic.co/t/update-pipeline-filebeat-6-5-1-nginx-access-default-error/223973 "2020-03-17T16:26:14Z")

</div>

Trying to update the default pipeline that parses access log files from nginx in order to manage upstream\_response time. This pipeline is installed by Filebeat Nginx module. As you can check, I added extra field at the …

---

## [Regarding I/O](https://discuss.elastic.co/t/regarding-i-o/224043)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 0\
**Last updated:** [March 18, 2020, 7:56am UTC](https://discuss.elastic.co/t/regarding-i-o/224043 "2020-03-18T07:56:59Z")

</div>

Hi, Can I ask, what is the goto beats collector for monitoring disk i/o utilisation? I'd like to monitor the responsiveness of the disk subsystem on our elasticsearch nodes. Thx D

---

## [MSSQL module not available on metricbeat oss](https://discuss.elastic.co/t/mssql-module-not-available-on-metricbeat-oss/223908)

<div class="topic-metadata">

**Author:** [@Venkat\_Raj](https://discuss.elastic.co/u/Venkat_Raj)\
**Replies:** 5\
**Last updated:** [March 18, 2020, 6:52am UTC](https://discuss.elastic.co/t/mssql-module-not-available-on-metricbeat-oss/223908 "2020-03-18T06:52:06Z")

</div>

Hi All, I have downloaded the source code of metricbeat 7.6 and created a new metricbeat module. But I am not able to see the MSSQL module. The actual package downloaded from the elasticsearch community consists of th…

---

## [Error while connection to Elasticsearch (503, The server refuse to browse the page)](https://discuss.elastic.co/t/error-while-connection-to-elasticsearch-503-the-server-refuse-to-browse-the-page/223613)

<div class="topic-metadata">

**Author:** [@stk1](https://discuss.elastic.co/u/stk1)\
**Replies:** 2\
**Last updated:** [March 18, 2020, 6:43am UTC](https://discuss.elastic.co/t/error-while-connection-to-elasticsearch-503-the-server-refuse-to-browse-the-page/223613 "2020-03-18T06:43:38Z")

</div>

Hi, I am having trouble sending data from Heartbeat to Elasticsearch (both version 7.3). On the same server runs an instance of apm-server which makes no trouble, so I used the same configuration for elasticsearch givin…

---

## [Apply multiple pipelines on logs by configuring filebeat config file (.yml)](https://discuss.elastic.co/t/apply-multiple-pipelines-on-logs-by-configuring-filebeat-config-file-yml/223944)

<div class="topic-metadata">

**Author:** [@oula\_oula](https://discuss.elastic.co/u/oula_oula)\
**Replies:** 2\
**Last updated:** [March 17, 2020, 11:18pm UTC](https://discuss.elastic.co/t/apply-multiple-pipelines-on-logs-by-configuring-filebeat-config-file-yml/223944 "2020-03-17T23:18:01Z")

</div>

Hello world, I'm trying to apply ingest pipelines simultaneously on my logs before they get into Elasticsearch. My logs must go through a specific pipeline (A or B, configured in 'inputs' area) depending on where they …

---

## [Is there a way to monitor JVM without Jolokia](https://discuss.elastic.co/t/is-there-a-way-to-monitor-jvm-without-jolokia/223959)

<div class="topic-metadata">

**Author:** [@dzoni](https://discuss.elastic.co/u/dzoni)\
**Replies:** 1\
**Last updated:** [March 17, 2020, 8:57pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-jvm-without-jolokia/223959 "2020-03-17T20:57:28Z")

</div>

Hello there, can i Setup the metricbeats with any Parameters, in order to monitor my jmx metrics of a Java application without using jolokia? i'm running my applications with Karaf. thanks alot greetings

---

## [File beat on a path whose name varies (current date)](https://discuss.elastic.co/t/file-beat-on-a-path-whose-name-varies-current-date/223867)

<div class="topic-metadata">

**Author:** [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Replies:** 2\
**Last updated:** [March 17, 2020, 7:14pm UTC](https://discuss.elastic.co/t/file-beat-on-a-path-whose-name-varies-current-date/223867 "2020-03-17T19:14:17Z")

</div>

Hello, Is it possible to configure a file beat on a path whose name varies (current date)? paths: /opt/zimbra/log/access\_log.2020-03-12 I think so but not found how to do it: :slight\_smile: Regards,

---

## [Filebeat DNS resolution fail](https://discuss.elastic.co/t/filebeat-dns-resolution-fail/223970)

<div class="topic-metadata">

**Author:** [@Ondra](https://discuss.elastic.co/u/Ondra)\
**Replies:** 0\
**Last updated:** [March 17, 2020, 4:15pm UTC](https://discuss.elastic.co/t/filebeat-dns-resolution-fail/223970 "2020-03-17T16:15:23Z")

</div>

Hello, I have encountered similar issue as in this thread: https://discuss.elastic.co/t/dns-lookup-failure-elasticsearch/216140/3 Unfortunatelly the filebeat is not able to resolve elasticsearch name. 2020-03-17T16:01…

---

## [Unable to parse Filebeat using multiline pattern](https://discuss.elastic.co/t/unable-to-parse-filebeat-using-multiline-pattern/223951)

<div class="topic-metadata">

**Author:** [@bmclellan](https://discuss.elastic.co/u/bmclellan)\
**Replies:** 0\
**Last updated:** [March 17, 2020, 2:39pm UTC](https://discuss.elastic.co/t/unable-to-parse-filebeat-using-multiline-pattern/223951 "2020-03-17T14:39:57Z")

</div>

Hello, I am having issues trying to parse a multiline file due to the \\n characters being read in. I've spent forever trying to figure out how to break my fields out due to this. Would someone mind giving me a hand? My…

---

## [Process telemetry returned from procs.go in Packetbeat github](https://discuss.elastic.co/t/process-telemetry-returned-from-procs-go-in-packetbeat-github/222349)

<div class="topic-metadata">

**Author:** [@jostromsttora](https://discuss.elastic.co/u/jostromsttora)\
**Replies:** 2\
**Last updated:** [March 17, 2020, 12:14pm UTC](https://discuss.elastic.co/t/process-telemetry-returned-from-procs-go-in-packetbeat-github/222349 "2020-03-17T12:14:23Z")

</div>

Hi, I noticed in Packetbeats github repo from two days ago, a commit for procs.go that includes returning process telemetry. I've configured my packetsbeat v7.6.1 to send logs and visualized in Kibana. However, I don't…

---

## [How matching logs of today's date](https://discuss.elastic.co/t/how-matching-logs-of-todays-date/223910)

<div class="topic-metadata">

**Author:** [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Replies:** 0\
**Last updated:** [March 17, 2020, 11:11am UTC](https://discuss.elastic.co/t/how-matching-logs-of-todays-date/223910 "2020-03-17T11:11:36Z")

</div>

I have a question, file beat input-\> file-\> path . How matching logs of today's date. My directory / service / logs / contains many log files, these logs are cut by date. I just want to let filebeat to match today's …

---

## [Maximum troughput of packetbeat](https://discuss.elastic.co/t/maximum-troughput-of-packetbeat/223882)

<div class="topic-metadata">

**Author:** [@sutello](https://discuss.elastic.co/u/sutello)\
**Replies:** 0\
**Last updated:** [March 17, 2020, 8:52am UTC](https://discuss.elastic.co/t/maximum-troughput-of-packetbeat/223882 "2020-03-17T08:52:15Z")

</div>

We used packetbeat in a course from my university to discover the traffic which are made from PC-Pools. Now i'm interested to write my thesis about this stuff. I'm planning to capture the Uplink from the university. It…

---

## [How to upload Cisco log file, output from Rsyslog too Kibana](https://discuss.elastic.co/t/how-to-upload-cisco-log-file-output-from-rsyslog-too-kibana/223637)

<div class="topic-metadata">

**Author:** [@Elastic6](https://discuss.elastic.co/u/Elastic6)\
**Replies:** 0\
**Last updated:** [March 14, 2020, 9:34pm UTC](https://discuss.elastic.co/t/how-to-upload-cisco-log-file-output-from-rsyslog-too-kibana/223637 "2020-03-14T21:34:28Z")

</div>

Hello, I am using a Ubuntu VM to host the entire ELK stack, I am using Rsyslog to listen for Cisco IOS logs and have successfully managed to output these logs to a file. I am trying to upload the file too Kibana but it …

---

## [Filebeat doesn't providing event fields (event.name,event.module...) doesnt](https://discuss.elastic.co/t/filebeat-doesnt-providing-event-fields-event-name-event-module-doesnt/223825)

<div class="topic-metadata">

**Author:** [@Burga](https://discuss.elastic.co/u/Burga)\
**Replies:** 0\
**Last updated:** [March 16, 2020, 9:54pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-providing-event-fields-event-name-event-module-doesnt/223825 "2020-03-16T21:54:47Z")

</div>

HI , I'm using filebeat sending logs to the logstash but i can't see event fields like event.name,event.module example { "input" =\> { "type" =\> "log" }, "agent" =\> { "hostname" =\> "solrc-stg1", "id" =\> "69b413d…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=265)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=267)
