# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=267

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 268

---

## [Prevent from filebeat to logging to /var/messages](https://discuss.elastic.co/t/prevent-from-filebeat-to-logging-to-var-messages/223773)

<div class="topic-metadata">

**Author:** [@Burga](https://discuss.elastic.co/u/Burga)\
**Replies:** 2\
**Last updated:** [March 16, 2020, 9:41pm UTC](https://discuss.elastic.co/t/prevent-from-filebeat-to-logging-to-var-messages/223773 "2020-03-16T21:41:23Z")

</div>

Hi , is there any way to prevent from filebeat logging to /var/messages ? , it logging and sends to logstash every beat example /var/log/messages Mar 16 15:27:19 solrc-stg1 filebeat\[20876\]: 2020-03-16T15:27:19.680+…

---

## [Uptime error after upgrading from kibana 6 to 7](https://discuss.elastic.co/t/uptime-error-after-upgrading-from-kibana-6-to-7/223128)

<div class="topic-metadata">

**Author:** [@ethranes](https://discuss.elastic.co/u/ethranes)\
**Replies:** 2\
**Last updated:** [March 16, 2020, 8:00pm UTC](https://discuss.elastic.co/t/uptime-error-after-upgrading-from-kibana-6-to-7/223128 "2020-03-16T20:00:24Z")

</div>

Hi. I have setup a server that is pinging a few other servers to see if they're up or not, and then sending that data into kibana. It was working fine when I was on kibana 6. I'ver recently updated to kibana 7 and I get…

---

## [How to check service status of microservices in application](https://discuss.elastic.co/t/how-to-check-service-status-of-microservices-in-application/223597)

<div class="topic-metadata">

**Author:** [@vbala21712](https://discuss.elastic.co/u/vbala21712)\
**Replies:** 1\
**Last updated:** [March 16, 2020, 8:00pm UTC](https://discuss.elastic.co/t/how-to-check-service-status-of-microservices-in-application/223597 "2020-03-16T20:00:09Z")

</div>

HI All, I am new to ELK. I need to monitor the service status of microservices in application (systemctl status XXXXX). and the tcp ports are keep on changing every time restart service. Please let me know what needs …

---

## [Change ECS event.duration unit to milliseconds in Packetbeat](https://discuss.elastic.co/t/change-ecs-event-duration-unit-to-milliseconds-in-packetbeat/223589)

<div class="topic-metadata">

**Author:** [@pryesh001](https://discuss.elastic.co/u/pryesh001)\
**Replies:** 2\
**Last updated:** [March 16, 2020, 7:09pm UTC](https://discuss.elastic.co/t/change-ecs-event-duration-unit-to-milliseconds-in-packetbeat/223589 "2020-03-16T19:09:39Z")

</div>

Hi, I have a requirement to capture http average event duration in milliseconds and show it in a visualisation. As of now ECS event.duration captures duration in nanoseconds. Which is not very readable in a visualisati…

---

## [Filebeat 5.x pushing to Elasticsearch 6.8.x via Kafka topic](https://discuss.elastic.co/t/filebeat-5-x-pushing-to-elasticsearch-6-8-x-via-kafka-topic/221475)

<div class="topic-metadata">

**Author:** [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Replies:** 1\
**Last updated:** [March 16, 2020, 7:06pm UTC](https://discuss.elastic.co/t/filebeat-5-x-pushing-to-elasticsearch-6-8-x-via-kafka-topic/221475 "2020-03-16T19:06:02Z")

</div>

From the product compatibility matrix, Elasticsearch 6.8.x is compatible with Beats (say filebeats) version 5.6.x to 6.8.x. Will it work, if I'm using filebeats version 5.5.1 to push to Kafka topic and Logstash 6.8.x i…

---

## [Performance impact from large fields.yml?](https://discuss.elastic.co/t/performance-impact-from-large-fields-yml/223811)

<div class="topic-metadata">

**Author:** [@JD\_Kemsley](https://discuss.elastic.co/u/JD_Kemsley)\
**Replies:** 0\
**Last updated:** [March 16, 2020, 6:50pm UTC](https://discuss.elastic.co/t/performance-impact-from-large-fields-yml/223811 "2020-03-16T18:50:25Z")

</div>

After a vanilla install of metricbeat on an EC2 instance, I enabled the system module in metricbeat.yml. I did not modify fields.yml, and after turning on metricbeat, I now see a huge number of fields in my index patter…

---

## [Docker module diskio and external storage](https://discuss.elastic.co/t/docker-module-diskio-and-external-storage/223806)

<div class="topic-metadata">

**Author:** [@Archie\_J](https://discuss.elastic.co/u/Archie_J)\
**Replies:** 0\
**Last updated:** [March 16, 2020, 5:38pm UTC](https://discuss.elastic.co/t/docker-module-diskio-and-external-storage/223806 "2020-03-16T17:38:54Z")

</div>

We are are currently using metricbeat docker module to monitor basic metrics from our containers on one host machine, however we are protoyping scaling our system to work accross multiple machines, and we would like to b…

---

## [PostgresSQL Metricbeat module, possible issue with database connections](https://discuss.elastic.co/t/postgressql-metricbeat-module-possible-issue-with-database-connections/223794)

<div class="topic-metadata">

**Author:** [@mxp7064](https://discuss.elastic.co/u/mxp7064)\
**Replies:** 0\
**Last updated:** [March 16, 2020, 4:50pm UTC](https://discuss.elastic.co/t/postgressql-metricbeat-module-possible-issue-with-database-connections/223794 "2020-03-16T16:50:40Z")

</div>

Hi, I started using PostgresSQL Metricbeat module on Kubernetes. I installed the latest version of Metricbeat via helm (elastic/metricbeat chart). It runs 3 metricbeat pods which show no errors and I can see the metric…

---

## [Filebeat logs are too verbose](https://discuss.elastic.co/t/filebeat-logs-are-too-verbose/223603)

<div class="topic-metadata">

**Author:** [@karlsson](https://discuss.elastic.co/u/karlsson)\
**Replies:** 1\
**Last updated:** [March 16, 2020, 4:02pm UTC](https://discuss.elastic.co/t/filebeat-logs-are-too-verbose/223603 "2020-03-16T16:02:32Z")

</div>

Hi all. Is there a way to reduce the size of filebeat logs? I deployed filebeat to a Docker host, everything works as expected, all container logs are sent to Elasticsearch. However, after a few days, json log file in /v…

---

## [Failed to parse kubernetes.labels.statefulset](https://discuss.elastic.co/t/failed-to-parse-kubernetes-labels-statefulset/223703)

<div class="topic-metadata">

**Author:** [@glaenen](https://discuss.elastic.co/u/glaenen)\
**Replies:** 0\
**Last updated:** [March 16, 2020, 7:19am UTC](https://discuss.elastic.co/t/failed-to-parse-kubernetes-labels-statefulset/223703 "2020-03-16T07:19:38Z")

</div>

According to this Github issue : https://github.com/elastic/beats/issues/12638 This should be fixed , but I'm still seeing this issue on a 7.6.1 install on AWS EKS. See epicvinny's comment , same issue on GKE Any advi…

---

## [How to use processor in Filebeat hint-based auto-discover?](https://discuss.elastic.co/t/how-to-use-processor-in-filebeat-hint-based-auto-discover/223701)

<div class="topic-metadata">

**Author:** [@Jack\_Phan](https://discuss.elastic.co/u/Jack_Phan)\
**Replies:** 0\
**Last updated:** [March 16, 2020, 7:05am UTC](https://discuss.elastic.co/t/how-to-use-processor-in-filebeat-hint-based-auto-discover/223701 "2020-03-16T07:05:35Z")

</div>

I'm having a log file from my cron-service with the format like this: ISO\_time|job\_name|job\_status Example: 2020-03-16T06:30:02+00:00|clean\_up\_database|0 2020-03-16T06:30:03+00:00|random\_job|1 How can I parse th…

---

## [Cannot start filebeat 7.6](https://discuss.elastic.co/t/cannot-start-filebeat-7-6/223682)

<div class="topic-metadata">

**Author:** [@Ding\_Huiyang](https://discuss.elastic.co/u/Ding_Huiyang)\
**Replies:** 0\
**Last updated:** [March 16, 2020, 3:22am UTC](https://discuss.elastic.co/t/cannot-start-filebeat-7-6/223682 "2020-03-16T03:22:40Z")

</div>

I want to install filebeat, and connect it to logz.io After following the set up for the filebeat.yml, my filebeat could not be started. I am getting error: ● filebeat.service - Filebeat sends log files to Logstash o…

---

## [Make command fails when trying to compile new metricset in metricbeat](https://discuss.elastic.co/t/make-command-fails-when-trying-to-compile-new-metricset-in-metricbeat/223418)

<div class="topic-metadata">

**Author:** [@Daniel\_Carmel](https://discuss.elastic.co/u/Daniel_Carmel)\
**Replies:** 4\
**Last updated:** [March 14, 2020, 2:22am UTC](https://discuss.elastic.co/t/make-command-fails-when-trying-to-compile-new-metricset-in-metricbeat/223418 "2020-03-14T02:22:52Z")

</div>

I installed all the dependencies for creating new metricset with metricbeat(include Bison\\Yacc). After running the "Make create-metricset" and "Make collect" successfully I tried to compile the beat with the "Make" comm…

---

## [Palo alto logs](https://discuss.elastic.co/t/palo-alto-logs/222511)

<div class="topic-metadata">

**Author:** [@david-vazquez](https://discuss.elastic.co/u/david-vazquez)\
**Replies:** 21\
**Last updated:** [March 13, 2020, 10:54pm UTC](https://discuss.elastic.co/t/palo-alto-logs/222511 "2020-03-13T22:54:27Z")

</div>

Hello everybody, Im trying to ingest data from PAN-OS Syslog Integration 8.1.10. I read I can use filebeat + pawn module. I read the https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-panw.html to…

---

## [Failed to parse /etc/system-release](https://discuss.elastic.co/t/failed-to-parse-etc-system-release/222977)

<div class="topic-metadata">

**Author:** [@Martijn](https://discuss.elastic.co/u/Martijn)\
**Replies:** 8\
**Last updated:** [March 13, 2020, 9:36pm UTC](https://discuss.elastic.co/t/failed-to-parse-etc-system-release/222977 "2020-03-13T21:36:29Z")

</div>

Hi all, I am having an issue with the Metricbeat system module on red hat 6. I am getting the following error: "Error fetching data for metricset system.memory: VMStat: failed to read self process information: 1 error:…

---

## [Invalid control character in URL?](https://discuss.elastic.co/t/invalid-control-character-in-url/222981)

<div class="topic-metadata">

**Author:** [@NogNeetMachinaal](https://discuss.elastic.co/u/NogNeetMachinaal)\
**Replies:** 5\
**Last updated:** [March 13, 2020, 7:26pm UTC](https://discuss.elastic.co/t/invalid-control-character-in-url/222981 "2020-03-13T19:26:40Z")

</div>

See also below: I have found lots of errors in the syslog. They are all coming from PacketBeats. But I have no clue what this means; let alone what to do with it. Any suggestions? Thanks - Will Mar 10 17:30:11 tank …

---

## [Winlogbeats not sending logs to elasticsearch](https://discuss.elastic.co/t/winlogbeats-not-sending-logs-to-elasticsearch/223504)

<div class="topic-metadata">

**Author:** [@yasin\_mohammed](https://discuss.elastic.co/u/yasin_mohammed)\
**Replies:** 0\
**Last updated:** [March 13, 2020, 12:19pm UTC](https://discuss.elastic.co/t/winlogbeats-not-sending-logs-to-elasticsearch/223504 "2020-03-13T12:19:32Z")

</div>

Hi... Winlogbeats is not able to read event from a win 2012 64 bit server. It was working fine and suddenly stopped. 2020-03-05T06:39:47.573-0500 WARN beater/eventlogger.go:108 EventLog\[Microsoft-Windows-Sysmon/Operati…

---

## [Exiting : data path locked by another beat](https://discuss.elastic.co/t/exiting-data-path-locked-by-another-beat/223344)

<div class="topic-metadata">

**Author:** [@cctk](https://discuss.elastic.co/u/cctk)\
**Replies:** 2\
**Last updated:** [March 13, 2020, 8:52am UTC](https://discuss.elastic.co/t/exiting-data-path-locked-by-another-beat/223344 "2020-03-13T08:52:26Z")

</div>

Hi , I have upgraded the beats to 7.6.1 and i am experiencing an issue when starting the beat. It keeps failing with a message that the data path is already locked by another beat, there is only one instance of the be…

---

## [Filebeat jenkins plugin?](https://discuss.elastic.co/t/filebeat-jenkins-plugin/223477)

<div class="topic-metadata">

**Author:** [@veerendranath\_lukka1](https://discuss.elastic.co/u/veerendranath_lukka1)\
**Replies:** 0\
**Last updated:** [March 13, 2020, 8:47am UTC](https://discuss.elastic.co/t/filebeat-jenkins-plugin/223477 "2020-03-13T08:47:19Z")

</div>

HI, Its possible to add jenkins module to Filebeate (Decoding 8mha to plain string) example :8mha:////4FwJdzRgKbBr9Y3WXlVjFRxPmJ4cUAuKncISlzIgXIQhAAAAox+LCAAAAAAAAP9tjTEOAiEURD9rLGwtPQSb2FgYK1tC4wmQRYQl/7PAult5Iq/mHSRu…

---

## [Indices have lifecycle errors](https://discuss.elastic.co/t/indices-have-lifecycle-errors/223434)

<div class="topic-metadata">

**Author:** [@dhimasjoe](https://discuss.elastic.co/u/dhimasjoe)\
**Replies:** 1\
**Last updated:** [March 13, 2020, 2:10am UTC](https://discuss.elastic.co/t/indices-have-lifecycle-errors/223434 "2020-03-13T02:10:21Z")

</div>

I set up ELK in centos server and use beats as a log colector. this is my network : centos 7 : instaled ELK with ip (ex: 192.168.1.10) windows server 2012 r2 : instaled Web server (iis server) with ip (192.168.2.10) …

---

## [Heartbeat monitors](https://discuss.elastic.co/t/heartbeat-monitors/223199)

<div class="topic-metadata">

**Author:** [@northmilo](https://discuss.elastic.co/u/northmilo)\
**Replies:** 2\
**Last updated:** [March 12, 2020, 7:32pm UTC](https://discuss.elastic.co/t/heartbeat-monitors/223199 "2020-03-12T19:32:40Z")

</div>

Hi, I am planning to monitor local network gateway. Can you advise how to configure monitor for this task? Thanks!

---

## [Winlogbeat can't connect to the ELK Stack server](https://discuss.elastic.co/t/winlogbeat-cant-connect-to-the-elk-stack-server/222939)

<div class="topic-metadata">

**Author:** [@aboutELK](https://discuss.elastic.co/u/aboutELK)\
**Replies:** 7\
**Last updated:** [March 12, 2020, 12:40pm UTC](https://discuss.elastic.co/t/winlogbeat-cant-connect-to-the-elk-stack-server/222939 "2020-03-12T12:40:10Z")

</div>

I created ELK Stack Server with Ubuntu 18.04 LTS and a Linux client with filebeat. Everything works fine together. I tried to install winlogbeat on my Windows PCs. But I can't get it working together. The error log fro…

---

## [Update log files with same document ID with filebeat (similar to PUT index/\_doc/\_id)](https://discuss.elastic.co/t/update-log-files-with-same-document-id-with-filebeat-similar-to-put-index-doc-id/223280)

<div class="topic-metadata">

**Author:** [@aksroh](https://discuss.elastic.co/u/aksroh)\
**Replies:** 1\
**Last updated:** [March 12, 2020, 11:36am UTC](https://discuss.elastic.co/t/update-log-files-with-same-document-id-with-filebeat-similar-to-put-index-doc-id/223280 "2020-03-12T11:36:52Z")

</div>

I am using Filebeat with Elasticsearch. I want to update log files with same Document IDs, which one can achieve with PUT request in Dev Tools (PUT /index/\_doc/\_id). How to achieve the same functionality with filebeat?

---

## [What is the technology behind filebeat](https://discuss.elastic.co/t/what-is-the-technology-behind-filebeat/223306)

<div class="topic-metadata">

**Author:** [@Amine\_Maalfi](https://discuss.elastic.co/u/Amine_Maalfi)\
**Replies:** 1\
**Last updated:** [March 12, 2020, 11:34am UTC](https://discuss.elastic.co/t/what-is-the-technology-behind-filebeat/223306 "2020-03-12T11:34:13Z")

</div>

i tried finding the answer on elastic site or github but i found nothing there. i need to know what language/communication protocol is filebeat based on.

---

## [AWS RDS Data Not Appearing in Dashboard but it shows in metricbeat index](https://discuss.elastic.co/t/aws-rds-data-not-appearing-in-dashboard-but-it-shows-in-metricbeat-index/222707)

<div class="topic-metadata">

**Author:** [@vinayborra](https://discuss.elastic.co/u/vinayborra)\
**Replies:** 5\
**Last updated:** [March 12, 2020, 11:31am UTC](https://discuss.elastic.co/t/aws-rds-data-not-appearing-in-dashboard-but-it-shows-in-metricbeat-index/222707 "2020-03-12T11:31:28Z")

</div>

After following this tutorial as per elasticsearch documentation we are unable to get analytics on the dashboard \[Metricbeat AWS\] RDS Overview But i can find data in metricbeat index, so please suggest a solution for…

---

## [Can't enable metric modules in version 7.6](https://discuss.elastic.co/t/cant-enable-metric-modules-in-version-7-6/222449)

<div class="topic-metadata">

**Author:** [@Detlef](https://discuss.elastic.co/u/Detlef)\
**Replies:** 6\
**Last updated:** [March 12, 2020, 11:13am UTC](https://discuss.elastic.co/t/cant-enable-metric-modules-in-version-7-6/222449 "2020-03-12T11:13:40Z")

</div>

Hi, I can't list/enable/disable modules for metricbeat with the given programs. The metricbeat version is at the current latest version of 7.6. The output I recieve looks like this on all systems: I have Ubuntu 18.0…

---

## [Filebeat not working when trying to add k8s metadata](https://discuss.elastic.co/t/filebeat-not-working-when-trying-to-add-k8s-metadata/223316)

<div class="topic-metadata">

**Author:** [@prasadasokan](https://discuss.elastic.co/u/prasadasokan)\
**Replies:** 0\
**Last updated:** [March 12, 2020, 11:02am UTC](https://discuss.elastic.co/t/filebeat-not-working-when-trying-to-add-k8s-metadata/223316 "2020-03-12T11:02:48Z")

</div>

When trying to deploy Filebeat as a Daemonset in k8s we are able to see logs from all the pods running on that particular host. But we would like to add the k8s metadata to filter based on the deployment name as each one…

---

## [Exclude Directorys in Filebeat](https://discuss.elastic.co/t/exclude-directorys-in-filebeat/223139)

<div class="topic-metadata">

**Author:** [@Neropointer](https://discuss.elastic.co/u/Neropointer)\
**Replies:** 4\
**Last updated:** [March 12, 2020, 10:05am UTC](https://discuss.elastic.co/t/exclude-directorys-in-filebeat/223139 "2020-03-12T10:05:42Z")

</div>

I need harvest all log files in an directory and the subdirectories and exclude the backup directories that are in the same location. e. g. /foo/bar/service1/.log /foo/bar/service1.backup/.log /foo/bar/service2/.log …

---

## [Installation and configuration deployment of beats in large scale](https://discuss.elastic.co/t/installation-and-configuration-deployment-of-beats-in-large-scale/220035)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 3\
**Last updated:** [March 12, 2020, 9:21am UTC](https://discuss.elastic.co/t/installation-and-configuration-deployment-of-beats-in-large-scale/220035 "2020-03-12T09:21:28Z")

</div>

What is the best practice to install and configuration deployment of beats when there is a huge amount of servers/VMs say around 500. Whether Ansible configuration management will suffice?

---

## [Multiline - multiple level of multiline in Filebeat](https://discuss.elastic.co/t/multiline-multiple-level-of-multiline-in-filebeat/222875)

<div class="topic-metadata">

**Author:** [@aviman](https://discuss.elastic.co/u/aviman)\
**Replies:** 4\
**Last updated:** [March 12, 2020, 8:04am UTC](https://discuss.elastic.co/t/multiline-multiple-level-of-multiline-in-filebeat/222875 "2020-03-12T08:04:14Z")

</div>

Hi, Can we use multiple level of multiline feature in Filebeat. Input --\> multiline (to join based on 1st pattern) --\> processor(drop lines based on condition) --\>multiline (to join based on 2pattern) Input : 0 STAR…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=266)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=268)
