# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=268

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 269

---

## [Filebeat - Base64 Decode - "key not found" - 7.6.1](https://discuss.elastic.co/t/filebeat-base64-decode-key-not-found-7-6-1/223229)

<div class="topic-metadata">

**Author:** [@bgeveritt](https://discuss.elastic.co/u/bgeveritt)\
**Replies:** 1\
**Last updated:** [March 12, 2020, 7:52am UTC](https://discuss.elastic.co/t/filebeat-base64-decode-key-not-found-7-6-1/223229 "2020-03-12T07:52:27Z")

</div>

I'm trying to use the "decode\_base64\_field" processor, and have created an extremely simple use case, but it's failing with the following error: failed to decode base64 fields in processor: could not fetch base64 value …

---

## [Metricbeat modules setup](https://discuss.elastic.co/t/metricbeat-modules-setup/223200)

<div class="topic-metadata">

**Author:** [@northmilo](https://discuss.elastic.co/u/northmilo)\
**Replies:** 7\
**Last updated:** [March 12, 2020, 7:50am UTC](https://discuss.elastic.co/t/metricbeat-modules-setup/223200 "2020-03-12T07:50:07Z")

</div>

Hi, Is there a specific restictions to run elasticsearch and system module at the same time on monitored system. Does one exlclude another? Thanks!

---

## [Filebeat fields error.message disable/remove from Table](https://discuss.elastic.co/t/filebeat-fields-error-message-disable-remove-from-table/223207)

<div class="topic-metadata">

**Author:** [@northmilo](https://discuss.elastic.co/u/northmilo)\
**Replies:** 1\
**Last updated:** [March 12, 2020, 7:44am UTC](https://discuss.elastic.co/t/filebeat-fields-error-message-disable-remove-from-table/223207 "2020-03-12T07:44:25Z")

</div>

Hi, I have modified filebeat index and index template by removeing error.message field but it is still visible in discovery table. Is there any thing else I should do remove this message. I dont use Logstash and dont kn…

---

## [How to set pipeline to ES Cloud in Filebeat](https://discuss.elastic.co/t/how-to-set-pipeline-to-es-cloud-in-filebeat/223001)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 2\
**Last updated:** [March 12, 2020, 6:34am UTC](https://discuss.elastic.co/t/how-to-set-pipeline-to-es-cloud-in-filebeat/223001 "2020-03-12T06:34:58Z")

</div>

Hi, I created a pipeline in my Elastic Cloud. When add a document in Kibana the pipeline is working. But when I put the pipeline (as in the documentation) in Filebeat.yml, nothing happens. Thanks, Herman

---

## [Unique Template per Index](https://discuss.elastic.co/t/unique-template-per-index/223215)

<div class="topic-metadata">

**Author:** [@cappy](https://discuss.elastic.co/u/cappy)\
**Replies:** 0\
**Last updated:** [March 11, 2020, 8:38pm UTC](https://discuss.elastic.co/t/unique-template-per-index/223215 "2020-03-11T20:38:02Z")

</div>

I know you can specify multiple indices, but is it possible to specify a unique Elasticsearch template per index in the Filebeat config file?

---

## [Harvest and send output once a specific period (days/weeks/months)](https://discuss.elastic.co/t/harvest-and-send-output-once-a-specific-period-days-weeks-months/223190)

<div class="topic-metadata">

**Author:** [@Ralyenz](https://discuss.elastic.co/u/Ralyenz)\
**Replies:** 1\
**Last updated:** [March 11, 2020, 8:22pm UTC](https://discuss.elastic.co/t/harvest-and-send-output-once-a-specific-period-days-weeks-months/223190 "2020-03-11T20:22:31Z")

</div>

Hello Experts, I am new to FileBeat and I'm trying to configure it to harvest files and send the output to Kibana once every two weeks. Is it possible with FileBeat or should it be configured on Kibana's side ? Thanks…

---

## [Suricata (3 of 4 shards failed)](https://discuss.elastic.co/t/suricata-3-of-4-shards-failed/223060)

<div class="topic-metadata">

**Author:** [@Lavardin](https://discuss.elastic.co/u/Lavardin)\
**Replies:** 0\
**Last updated:** [March 11, 2020, 7:09am UTC](https://discuss.elastic.co/t/suricata-3-of-4-shards-failed/223060 "2020-03-11T07:09:22Z")

</div>

I enabled the suricata module on filebeats, but when loading the dashboard I receive an error that its unable to load 3 of 4 shards. Also I noticed alerts are not displaying. This is my Suricata settings in pfsense T…

---

## [Logstash log is not properly parsed after spliting logstash pipelines](https://discuss.elastic.co/t/logstash-log-is-not-properly-parsed-after-spliting-logstash-pipelines/223097)

<div class="topic-metadata">

**Author:** [@MioOgbeni](https://discuss.elastic.co/u/MioOgbeni)\
**Replies:** 2\
**Last updated:** [March 11, 2020, 2:51pm UTC](https://discuss.elastic.co/t/logstash-log-is-not-properly-parsed-after-spliting-logstash-pipelines/223097 "2020-03-11T14:51:48Z")

</div>

Hi, can I ask you for help? I have a Filebeat which handles Logstash logging. When I used only one main pipeline in Logstash, the logs were parsed correctly and looked like this. SummaryPS: This parsing error in messag…

---

## [Filebeat field rename does not work](https://discuss.elastic.co/t/filebeat-field-rename-does-not-work/223084)

<div class="topic-metadata">

**Author:** [@poitschkka01](https://discuss.elastic.co/u/poitschkka01)\
**Replies:** 0\
**Last updated:** [March 11, 2020, 9:32am UTC](https://discuss.elastic.co/t/filebeat-field-rename-does-not-work/223084 "2020-03-11T09:32:26Z")

</div>

Hello, the file rename does not work inmy configuration. Any idea why? filebeat version is 7.6.0 or 7.6.1 (tested with both). The logs are shipped to graylog. # Set directory for additional inputs: filebeat.config.i…

---

## [CollectD in HP-UX server B.11.31 U ia64](https://discuss.elastic.co/t/collectd-in-hp-ux-server-b-11-31-u-ia64/220791)

<div class="topic-metadata">

**Author:** [@renu\_jessi](https://discuss.elastic.co/u/renu_jessi)\
**Replies:** 4\
**Last updated:** [March 11, 2020, 1:09pm UTC](https://discuss.elastic.co/t/collectd-in-hp-ux-server-b-11-31-u-ia64/220791 "2020-03-11T13:09:27Z")

</div>

Hi, I am working on CollectdD with logstash ,i need to install collectd in hp ux server,please help me with the installation process and list of dependencies i need to install. server details : HP-UX server B.11.31 …

---

## [ES + filebeat index lifecycle management issue](https://discuss.elastic.co/t/es-filebeat-index-lifecycle-management-issue/223127)

<div class="topic-metadata">

**Author:** [@bhkybbzl](https://discuss.elastic.co/u/bhkybbzl)\
**Replies:** 0\
**Last updated:** [March 11, 2020, 12:29pm UTC](https://discuss.elastic.co/t/es-filebeat-index-lifecycle-management-issue/223127 "2020-03-11T12:29:25Z")

</div>

Hi, I've got a confusing issue when using index lifecycle management feature in ES and filebeat. I'm collecting logs from various pods in K8S using filebeat, and sending them to Elasticsearch, I have a few requirements…

---

## [Metricbeat -\> Filebeat -\> Logstash](https://discuss.elastic.co/t/metricbeat-filebeat-logstash/223089)

<div class="topic-metadata">

**Author:** [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Replies:** 1\
**Last updated:** [March 11, 2020, 11:40am UTC](https://discuss.elastic.co/t/metricbeat-filebeat-logstash/223089 "2020-03-11T11:40:28Z")

</div>

I want to send Metric&winlogbeat data to Filebeat and from filebeat to logstash. Instead of creating the single filebeat index, i want separate index files for winlogbeat and metric and these indexes must pass through …

---

## [Two instance of Auditbeat](https://discuss.elastic.co/t/two-instance-of-auditbeat/223114)

<div class="topic-metadata">

**Author:** [@RajeshKumar](https://discuss.elastic.co/u/RajeshKumar)\
**Replies:** 0\
**Last updated:** [March 11, 2020, 11:38am UTC](https://discuss.elastic.co/t/two-instance-of-auditbeat/223114 "2020-03-11T11:38:59Z")

</div>

Hi All, Is it good to have two instances of Audit Beat in a single server? I have the same requirement where I want to share information to two different Logstash servers. Regards, Rajesh

---

## [How to measure Network map drive free space with metricbeat on Windows Server 2012 using ELK and Grafana](https://discuss.elastic.co/t/how-to-measure-network-map-drive-free-space-with-metricbeat-on-windows-server-2012-using-elk-and-grafana/223096)

<div class="topic-metadata">

**Author:** [@Ionut](https://discuss.elastic.co/u/Ionut)\
**Replies:** 0\
**Last updated:** [March 11, 2020, 10:08am UTC](https://discuss.elastic.co/t/how-to-measure-network-map-drive-free-space-with-metricbeat-on-windows-server-2012-using-elk-and-grafana/223096 "2020-03-11T10:08:38Z")

</div>

Hello, I have an issue with metricbeat. We run Windows Server 2012 on a TEST machine where we have a setup for elasticsearch, metricbeat, filebeat and Grafana. I need to monitor the disk space in Grafana for the DEV env…

---

## [Docker fields won't be added](https://discuss.elastic.co/t/docker-fields-wont-be-added/222984)

<div class="topic-metadata">

**Author:** [@ghost\_recon](https://discuss.elastic.co/u/ghost_recon)\
**Replies:** 2\
**Last updated:** [March 11, 2020, 9:45am UTC](https://discuss.elastic.co/t/docker-fields-wont-be-added/222984 "2020-03-11T09:45:40Z")

</div>

I'm trying to send docker logs to logstash via filebeat, but the docker fields that are supposed to be added by filebeat don't show up in logsatsh like the docker.container.name, docker.container.image etc ... my filebe…

---

## [Filebeat stop harvesting](https://discuss.elastic.co/t/filebeat-stop-harvesting/219553)

<div class="topic-metadata">

**Author:** [@Charles\_Yuliansen](https://discuss.elastic.co/u/Charles_Yuliansen)\
**Replies:** 5\
**Last updated:** [March 11, 2020, 8:53am UTC](https://discuss.elastic.co/t/filebeat-stop-harvesting/219553 "2020-03-11T08:53:48Z")

</div>

I've configuring filebeat, logstash, elasticsearch. it works pretty well. But for some reason filebeat will stop harvesting log file. The file will be generated everyday. I've try this for few times at it always happene…

---

## [When filebeat harvest logs to elasticsearch ,"Failed to perform any bulk index operations: 413 Request Entity Too Large:"](https://discuss.elastic.co/t/when-filebeat-harvest-logs-to-elasticsearch-failed-to-perform-any-bulk-index-operations-413-request-entity-too-large/223045)

<div class="topic-metadata">

**Author:** [@ELK\_2100](https://discuss.elastic.co/u/ELK_2100)\
**Replies:** 1\
**Last updated:** [March 11, 2020, 8:13am UTC](https://discuss.elastic.co/t/when-filebeat-harvest-logs-to-elasticsearch-failed-to-perform-any-bulk-index-operations-413-request-entity-too-large/223045 "2020-03-11T08:13:19Z")

</div>

2020-03-11T09:00:51.117+0800 INFO pipeline/output.go:105 Connection to backoff(elasticsearch(http://1.2.3.4:9300)) established 2020-03-11T09:00:51.344+0800 ERROR elasticsearch/client.go:343 Failed to perform any bulk in…

---

## [How to transform the log lines?](https://discuss.elastic.co/t/how-to-transform-the-log-lines/223062)

<div class="topic-metadata">

**Author:** [@deostroll](https://discuss.elastic.co/u/deostroll)\
**Replies:** 1\
**Last updated:** [March 11, 2020, 8:10am UTC](https://discuss.elastic.co/t/how-to-transform-the-log-lines/223062 "2020-03-11T08:10:26Z")

</div>

I understand file beat is an aggregated tail -f command. But does it allow us to transform log-lines to a format whereby we can run searches (or queries) on elasticsearch (or kibana)? Can file beat do such transformatio…

---

## [Processing fields with Filebeat via Kubernetes annotations](https://discuss.elastic.co/t/processing-fields-with-filebeat-via-kubernetes-annotations/222965)

<div class="topic-metadata">

**Author:** [@vicmarbev](https://discuss.elastic.co/u/vicmarbev)\
**Replies:** 1\
**Last updated:** [March 11, 2020, 7:54am UTC](https://discuss.elastic.co/t/processing-fields-with-filebeat-via-kubernetes-annotations/222965 "2020-03-11T07:54:45Z")

</div>

Hi, we've been looking into bypassing logstash and send logs directly from filebeat to elasticsearch. As we have a kubernetes deployment, as seen in here we can add annotations to handle things like multiline, excluded …

---

## [HTTP Module doesn't work (for me)](https://discuss.elastic.co/t/http-module-doesnt-work-for-me/222736)

<div class="topic-metadata">

**Author:** [@DarioLV](https://discuss.elastic.co/u/DarioLV)\
**Replies:** 2\
**Last updated:** [March 10, 2020, 8:02pm UTC](https://discuss.elastic.co/t/http-module-doesnt-work-for-me/222736 "2020-03-10T20:02:43Z")

</div>

Hi all! Basically, I don't receive data from the http module (Haproxy and System Module are working). I paste the configuration of my http.yml file for the HTTP Module in Metricbeats. Can someone please lend a hand with…

---

## [Filebeat cannot connect Kafka TLS](https://discuss.elastic.co/t/filebeat-cannot-connect-kafka-tls/222985)

<div class="topic-metadata">

**Author:** [@worapojc](https://discuss.elastic.co/u/worapojc)\
**Replies:** 0\
**Last updated:** [March 10, 2020, 5:14pm UTC](https://discuss.elastic.co/t/filebeat-cannot-connect-kafka-tls/222985 "2020-03-10T17:14:16Z")

</div>

Dear Elastic team, Test Environment: Local zookeeper, Kafka and Filebeat in a machine (kafka0). Kafka version: 2.13-2.4.0 Filebeat version: 7.6 I tried to setup Filebeat to connect Kafka with TLS option. I tested th…

---

## [CPU usage gauge working for one host but not others in metricbeat dashboard. Infrastructure shows the correct value.. PLIS HELP](https://discuss.elastic.co/t/cpu-usage-gauge-working-for-one-host-but-not-others-in-metricbeat-dashboard-infrastructure-shows-the-correct-value-plis-help/222835)

<div class="topic-metadata">

**Author:** [@shayan.ahmad](https://discuss.elastic.co/u/shayan.ahmad)\
**Replies:** 2\
**Last updated:** [March 10, 2020, 2:29pm UTC](https://discuss.elastic.co/t/cpu-usage-gauge-working-for-one-host-but-not-others-in-metricbeat-dashboard-infrastructure-shows-the-correct-value-plis-help/222835 "2020-03-10T14:29:34Z")

</div>

Hello - I've installed metricbeat (7.6) on multiple servers, and shipping data directly to elasticsearch (port 9200). The metricbeat dashboards seem to be working for the most part but the CPU usage gauge is showing a n…

---

## [How to change disk usage folder?](https://discuss.elastic.co/t/how-to-change-disk-usage-folder/222368)

<div class="topic-metadata">

**Author:** [@snorlax](https://discuss.elastic.co/u/snorlax)\
**Replies:** 4\
**Last updated:** [March 10, 2020, 2:27pm UTC](https://discuss.elastic.co/t/how-to-change-disk-usage-folder/222368 "2020-03-10T14:27:01Z")

</div>

Hello everyone! I have a question about shows disk usage on kibana. This is my folder that I can see on kibana. However, how can I change folder? Thanks again!

---

## [Filebeat Haproxy TCP log grok expressions do not match](https://discuss.elastic.co/t/filebeat-haproxy-tcp-log-grok-expressions-do-not-match/221055)

<div class="topic-metadata">

**Author:** [@Jacob-N](https://discuss.elastic.co/u/Jacob-N)\
**Replies:** 1\
**Last updated:** [March 10, 2020, 1:02pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-tcp-log-grok-expressions-do-not-match/221055 "2020-03-10T13:02:01Z")

</div>

I am sending logs from haproxy to a filebeat via Syslog. Filebeat is able to parse an HTTP log but not a TCP log. filebeat version 7.6.0 (amd64), libbeat 7.6.0 \[6a23e8f8f30f5001ba344e4e54d8d9cb82cb107c built 2020-02-05 …

---

## [Metricbeat kubernetes fails to collect](https://discuss.elastic.co/t/metricbeat-kubernetes-fails-to-collect/217414)

<div class="topic-metadata">

**Author:** [@Babadofar](https://discuss.elastic.co/u/Babadofar)\
**Replies:** 8\
**Last updated:** [March 10, 2020, 12:08pm UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-fails-to-collect/217414 "2020-03-10T12:08:55Z")

</div>

Using the latest elastic helm chart 7.5.2 on EKS kubernetes, I get these errors from metricbeat trying to fetch from kubernetes.volume 2020-01-31T15:32:52.119Z INFO module/wrapper.go:252 Error fetching data for metric…

---

## [Send metricbeat data to Elastic search for every 3 minutes](https://discuss.elastic.co/t/send-metricbeat-data-to-elastic-search-for-every-3-minutes/222919)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 0\
**Last updated:** [March 10, 2020, 11:15am UTC](https://discuss.elastic.co/t/send-metricbeat-data-to-elastic-search-for-every-3-minutes/222919 "2020-03-10T11:15:44Z")

</div>

Hello All , I am trying to change the period of sending the data from metricbeat to elasticsearch to 3 minutes but it seems not working. Can any one please help me what i am missing here.My Metricbeat.yml is pasted her…

---

## [Filebeat debug logging are not written](https://discuss.elastic.co/t/filebeat-debug-logging-are-not-written/222734)

<div class="topic-metadata">

**Author:** [@Axl](https://discuss.elastic.co/u/Axl)\
**Replies:** 7\
**Last updated:** [March 10, 2020, 10:44am UTC](https://discuss.elastic.co/t/filebeat-debug-logging-are-not-written/222734 "2020-03-10T10:44:23Z")

</div>

Hi, I configured filebeat to write debug logs to /var/log/filebeat directory, but I haven't got anything in there... This is my configuration file: logging.level: debug logging.to\_files: true logging.files: path: /…

---

## [Auditbeat: Can we access node/host process from the Kubernetes pod?](https://discuss.elastic.co/t/auditbeat-can-we-access-node-host-process-from-the-kubernetes-pod/222767)

<div class="topic-metadata">

**Author:** [@rajat\_badjatya](https://discuss.elastic.co/u/rajat_badjatya)\
**Replies:** 0\
**Last updated:** [March 9, 2020, 4:43pm UTC](https://discuss.elastic.co/t/auditbeat-can-we-access-node-host-process-from-the-kubernetes-pod/222767 "2020-03-09T16:43:25Z")

</div>

Is there a way to access the underlying host/node's process from Kubernetes pod in the same way as we access the host/node's filesystem by using hostPath volume mount? PS: I am trying to monitor the node process with …

---

## [Can Filebeat ship the below type of log files? Or WInlogbeat?](https://discuss.elastic.co/t/can-filebeat-ship-the-below-type-of-log-files-or-winlogbeat/222779)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 1\
**Last updated:** [March 10, 2020, 8:33am UTC](https://discuss.elastic.co/t/can-filebeat-ship-the-below-type-of-log-files-or-winlogbeat/222779 "2020-03-10T08:33:36Z")

</div>

I read that Winlogbeat is a Windows specific log-shipper but I have installed FIlebeat to ship log files from server to linux system with ELK. Can filebeat actually ship these log type files properly? Or is Winlogbeat be…

---

## [Problem with @timestamp time in indexes](https://discuss.elastic.co/t/problem-with-timestamp-time-in-indexes/222280)

<div class="topic-metadata">

**Author:** [@Vinnyard](https://discuss.elastic.co/u/Vinnyard)\
**Replies:** 21\
**Last updated:** [March 10, 2020, 6:46am UTC](https://discuss.elastic.co/t/problem-with-timestamp-time-in-indexes/222280 "2020-03-10T06:46:37Z")

</div>

Hello, we have filebeat sending messages directly to elasticsearch index. And we found such problem, @timestamp in kibana view ( when we search) is different from timestamp we have in file on server( which use filebeat)…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=267)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=269)
