# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=269

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 270

---

## [Include\_lines not match with "^\\\\{"](https://discuss.elastic.co/t/include-lines-not-match-with/222850)

<div class="topic-metadata">

**Author:** [@bigpigeon](https://discuss.elastic.co/u/bigpigeon)\
**Replies:** 0\
**Last updated:** [March 10, 2020, 4:19am UTC](https://discuss.elastic.co/t/include-lines-not-match-with/222850 "2020-03-10T04:19:30Z")

</div>

hi: I have jsonp log file have below format, I want to filter it with include\_lines:\["^\\\\{"\] rule, but it cannot filter start with "{" line's log {"level":"info","ts":1583809821.8151295,"caller":"v3@v3.1.0/default.go:…

---

## [Manual CloudFormation Deployment of Functionbeat](https://discuss.elastic.co/t/manual-cloudformation-deployment-of-functionbeat/222791)

<div class="topic-metadata">

**Author:** [@misterhops](https://discuss.elastic.co/u/misterhops)\
**Replies:** 0\
**Last updated:** [March 9, 2020, 7:36pm UTC](https://discuss.elastic.co/t/manual-cloudformation-deployment-of-functionbeat/222791 "2020-03-09T19:36:21Z")

</div>

Hi, We have been testing Functionbeat within our environment and the most frustrating part of the deployment is not being able to find detailed documentation on how to perform this cleanly. The approach seems to be usin…

---

## [Export generates wrong default field, lot of "text" duplicities #16891](https://discuss.elastic.co/t/export-generates-wrong-default-field-lot-of-text-duplicities-16891/222622)

<div class="topic-metadata">

**Author:** [@vbohata](https://discuss.elastic.co/u/vbohata)\
**Replies:** 4\
**Last updated:** [March 9, 2020, 6:41pm UTC](https://discuss.elastic.co/t/export-generates-wrong-default-field-lot-of-text-duplicities-16891/222622 "2020-03-09T18:41:34Z")

</div>

I noticed a lot of versions of beats generate wrong index templates. For example in 7.6.1 using "./filebeat export template" I get this in default\_field section: ... "process.args", "text", "process.executable", "pr…

---

## [Metricbeat elasticsearch module can't monitor \[cluster\_stats,index,shard\] metricsets when xpack.monitoring.exporters is set](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-cant-monitor-cluster-stats-index-shard-metricsets-when-xpack-monitoring-exporters-is-set/222597)

<div class="topic-metadata">

**Author:** [@tetsuyasodo](https://discuss.elastic.co/u/tetsuyasodo)\
**Replies:** 2\
**Last updated:** [March 9, 2020, 4:36pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-cant-monitor-cluster-stats-index-shard-metricsets-when-xpack-monitoring-exporters-is-set/222597 "2020-03-09T16:36:33Z")

</div>

Hi, I'm using an ES6.8 3 nodes cluster(cluster A) and an ES6.8 1 node cluster(cluster B). The cluster B is used for monitoring the cluster A. I'm exporting the .monitoring index from cluster A to cluster B. The confi…

---

## [Metricbeat unhappy with K8s kube-state-metrics labels](https://discuss.elastic.co/t/metricbeat-unhappy-with-k8s-kube-state-metrics-labels/222756)

<div class="topic-metadata">

**Author:** [@jweite](https://discuss.elastic.co/u/jweite)\
**Replies:** 0\
**Last updated:** [March 9, 2020, 3:46pm UTC](https://discuss.elastic.co/t/metricbeat-unhappy-with-k8s-kube-state-metrics-labels/222756 "2020-03-09T15:46:24Z")

</div>

Hi all, I deployed metricbeat under Kubernetes and am getting warnings that I interpret to mean that Elasticsearch is unhappy with pod label attributes being sent for kube-state-metrics. More specifically, the "standard…

---

## [Docker network at kubernetes](https://discuss.elastic.co/t/docker-network-at-kubernetes/165203)

<div class="topic-metadata">

**Author:** [@hohooss](https://discuss.elastic.co/u/hohooss)\
**Replies:** 19\
**Last updated:** [March 9, 2020, 2:45pm UTC](https://discuss.elastic.co/t/docker-network-at-kubernetes/165203 "2020-03-09T14:45:30Z")

</div>

Hello, I would like to have the network traffic of each container that runs on the Kubernetes cluster retrieved by the metricbeat. I have embed the following configuration (check bold) at the configmap yaml, but metricb…

---

## [Filebeat service doesn't send log](https://discuss.elastic.co/t/filebeat-service-doesnt-send-log/222430)

<div class="topic-metadata">

**Author:** [@Roms](https://discuss.elastic.co/u/Roms)\
**Replies:** 10\
**Last updated:** [March 9, 2020, 1:26pm UTC](https://discuss.elastic.co/t/filebeat-service-doesnt-send-log/222430 "2020-03-09T13:26:56Z")

</div>

Hello everyone, I'm configuring filebeat to read logs from an xml file. When I do tests with the exe I get the logs in logstasch/elasticsearch and I can work on it in Kibana but when I run Filebeat as a service I don't…

---

## [Can't "SETUP" Packet beat](https://discuss.elastic.co/t/cant-setup-packet-beat/222029)

<div class="topic-metadata">

**Author:** [@tbhaxor](https://discuss.elastic.co/u/tbhaxor)\
**Replies:** 5\
**Last updated:** [March 9, 2020, 12:57pm UTC](https://discuss.elastic.co/t/cant-setup-packet-beat/222029 "2020-03-09T12:57:24Z")

</div>

After running elasticsearch and kibana behind reverse proxy via nginx i am getting following error # packetbeat --path.config /etc/packetbeat/ setup Overwriting ILM policy is disabled. Set \`setup.ilm.overwrite:true\` for…

---

## [Filebeat input and source files](https://discuss.elastic.co/t/filebeat-input-and-source-files/220115)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 5\
**Last updated:** [March 9, 2020, 11:03am UTC](https://discuss.elastic.co/t/filebeat-input-and-source-files/220115 "2020-03-09T11:03:32Z")

</div>

Hi all, I have been trying to getting data from the local server and also from a remote server within the same network. But how can I make sure data are coming in? Is there a command to check which are the source files…

---

## [Harvester doesn't start when filebeat started as windows service](https://discuss.elastic.co/t/harvester-doesnt-start-when-filebeat-started-as-windows-service/222683)

<div class="topic-metadata">

**Author:** [@Gauthier\_Le\_Moulec](https://discuss.elastic.co/u/Gauthier_Le_Moulec)\
**Replies:** 2\
**Last updated:** [March 9, 2020, 10:44am UTC](https://discuss.elastic.co/t/harvester-doesnt-start-when-filebeat-started-as-windows-service/222683 "2020-03-09T10:44:09Z")

</div>

Hey, I'm using filebeat to connect to Logstash... (and I work on windows 10) I have no problem running filebeat from the shell launching the single command "filebeat -e" but when I try to launch it as a windows service …

---

## [Why i am getting "1 of 3 shards failed"](https://discuss.elastic.co/t/why-i-am-getting-1-of-3-shards-failed/222565)

<div class="topic-metadata">

**Author:** [@tbhaxor](https://discuss.elastic.co/u/tbhaxor)\
**Replies:** 2\
**Last updated:** [March 9, 2020, 9:29am UTC](https://discuss.elastic.co/t/why-i-am-getting-1-of-3-shards-failed/222565 "2020-03-09T09:29:37Z")

</div>

Why i am getting this error. RESPONSE { "took": 27, "timed\_out": false, "\_shards": { "total": 3, "successful": 2, "skipped": 0, "failed": 1, "failures": \[ { "shard": 0, …

---

## [Unable to get the cpu metrics while using metricbeats on kubernetes](https://discuss.elastic.co/t/unable-to-get-the-cpu-metrics-while-using-metricbeats-on-kubernetes/222215)

<div class="topic-metadata">

**Author:** [@Dinesh\_Senthil\_Kumar](https://discuss.elastic.co/u/Dinesh_Senthil_Kumar)\
**Replies:** 1\
**Last updated:** [March 7, 2020, 1:13pm UTC](https://discuss.elastic.co/t/unable-to-get-the-cpu-metrics-while-using-metricbeats-on-kubernetes/222215 "2020-03-07T13:13:28Z")

</div>

HI Team, i am unable to get the data for system metrics like cpu, memory, network either at pod level or container level. i have an running kube-system-metrics, i am able to view data related to pod/container state, co…

---

## [Question regarding "where" log data is process](https://discuss.elastic.co/t/question-regarding-where-log-data-is-process/222380)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 2\
**Last updated:** [March 6, 2020, 7:13pm UTC](https://discuss.elastic.co/t/question-regarding-where-log-data-is-process/222380 "2020-03-06T19:13:32Z")

</div>

Hi Team, \[ Deployment: Filebeat as kube daemonset running on dozens of nodes directly sending data to ES(AWS ES) \]. ( ie no intermediate logstash involved ). I have Not configured or specified any pipelines in my fileb…

---

## [Spaces between every letter from .log files on Windows](https://discuss.elastic.co/t/spaces-between-every-letter-from-log-files-on-windows/221758)

<div class="topic-metadata">

**Author:** [@braynyac](https://discuss.elastic.co/u/braynyac)\
**Replies:** 3\
**Last updated:** [March 6, 2020, 4:42pm UTC](https://discuss.elastic.co/t/spaces-between-every-letter-from-log-files-on-windows/221758 "2020-03-06T16:42:14Z")

</div>

As the topic says, I have several .log files that are sending data from Filebeats to Logstash / Graylog. Within Graylog, all of the lines for these files have a space between every character, like this: Interestingly,…

---

## [Exclude log files with filename containing a particular string](https://discuss.elastic.co/t/exclude-log-files-with-filename-containing-a-particular-string/222476)

<div class="topic-metadata">

**Author:** [@AdamJade](https://discuss.elastic.co/u/AdamJade)\
**Replies:** 0\
**Last updated:** [March 6, 2020, 2:55pm UTC](https://discuss.elastic.co/t/exclude-log-files-with-filename-containing-a-particular-string/222476 "2020-03-06T14:55:05Z")

</div>

Hi there I'm trying to ingest log files from a directory but i want exclude files log files containing 'ALL' string in their name. I tried exclude\_files: \['^ALL'\] but file name like this FAg\_ALL\_ToutesLogsOrdreHistori…

---

## [Could not create connection to db](https://discuss.elastic.co/t/could-not-create-connection-to-db/219444)

<div class="topic-metadata">

**Author:** [@Jose\_Campos](https://discuss.elastic.co/u/Jose_Campos)\
**Replies:** 8\
**Last updated:** [March 6, 2020, 2:16pm UTC](https://discuss.elastic.co/t/could-not-create-connection-to-db/219444 "2020-03-06T14:16:14Z")

</div>

Hi there I was triying to connect to a DB MSSQL from metricbeat, but I have 2 errors. Can you help me? Greetings

---

## [Filebeat publish but nothing appears](https://discuss.elastic.co/t/filebeat-publish-but-nothing-appears/222472)

<div class="topic-metadata">

**Author:** [@toms130](https://discuss.elastic.co/u/toms130)\
**Replies:** 0\
**Last updated:** [March 6, 2020, 2:05pm UTC](https://discuss.elastic.co/t/filebeat-publish-but-nothing-appears/222472 "2020-03-06T14:05:39Z")

</div>

Hi all, I've strange behavior with some filebeat instances on a kubernetes cluster. I send logs to logsatash container from 4 nodes with 4 filebeat instances deployed as daemonset. For time to time, I have no more log…

---

## [Exiting: data path already locked by another beat](https://discuss.elastic.co/t/exiting-data-path-already-locked-by-another-beat/220854)

<div class="topic-metadata">

**Author:** [@artherdent](https://discuss.elastic.co/u/artherdent)\
**Replies:** 3\
**Last updated:** [March 6, 2020, 1:52pm UTC](https://discuss.elastic.co/t/exiting-data-path-already-locked-by-another-beat/220854 "2020-03-06T13:52:13Z")

</div>

Hi, i am new to Elasticstack and am trying to configure filebeat to send logs to logstash-7.6.0. When running ./filebeat -e -c filebeat.yml -d "publish" i am recieving Exiting: data path already locked by another bea…

---

## [Best Shipper for 1500+ servers](https://discuss.elastic.co/t/best-shipper-for-1500-servers/221514)

<div class="topic-metadata">

**Author:** [@Shubhangi](https://discuss.elastic.co/u/Shubhangi)\
**Replies:** 3\
**Last updated:** [March 6, 2020, 11:02am UTC](https://discuss.elastic.co/t/best-shipper-for-1500-servers/221514 "2020-03-06T11:02:12Z")

</div>

Hi, What do you suggest is the best shipper when we intend to ship data from 1500+ application servers? I've used filebeat for 100s of web servers now but it'll be a lot to put filebeat agent on 1500+ applications now. …

---

## [Auditbeat doesn't reconnect after Logstash restart](https://discuss.elastic.co/t/auditbeat-doesnt-reconnect-after-logstash-restart/221174)

<div class="topic-metadata">

**Author:** [@feroz](https://discuss.elastic.co/u/feroz)\
**Replies:** 1\
**Last updated:** [March 6, 2020, 10:11am UTC](https://discuss.elastic.co/t/auditbeat-doesnt-reconnect-after-logstash-restart/221174 "2020-03-06T10:11:45Z")

</div>

We're running a set of Auditbeat agents that forward logging to a Logstash instance. Whenever we restart the Logstash instance, some of our Auditbeat agents lose their connection and are unable to reconnect. Curiously, t…

---

## [Elasticsearch does not receive Filebeat data](https://discuss.elastic.co/t/elasticsearch-does-not-receive-filebeat-data/222342)

<div class="topic-metadata">

**Author:** [@Axl](https://discuss.elastic.co/u/Axl)\
**Replies:** 3\
**Last updated:** [March 6, 2020, 9:23am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-receive-filebeat-data/222342 "2020-03-06T09:23:43Z")

</div>

Hello, I am new to ELK and filebeat. I have configured filebeat to get its input from a given json log file, and output it to logstash. However, when I test with curl -XGET 'http://localhost:9200/filebeat-\*/\_search?pr…

---

## [Auditbeat vs testing ES output](https://discuss.elastic.co/t/auditbeat-vs-testing-es-output/221252)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 20\
**Last updated:** [March 6, 2020, 7:09am UTC](https://discuss.elastic.co/t/auditbeat-vs-testing-es-output/221252 "2020-03-06T07:09:44Z")

</div>

trying to test auditbeat connectivity to elastic, connectivity seems fine only service is unavailable. Wondering where I possible could see the RC, tried ingesting nodes' elasticsearch + audit logs, beat log, but nothin…

---

## [Default Metricbeat dashboard has no data](https://discuss.elastic.co/t/default-metricbeat-dashboard-has-no-data/222236)

<div class="topic-metadata">

**Author:** [@jskishor](https://discuss.elastic.co/u/jskishor)\
**Replies:** 4\
**Last updated:** [March 6, 2020, 7:05am UTC](https://discuss.elastic.co/t/default-metricbeat-dashboard-has-no-data/222236 "2020-03-06T07:05:18Z")

</div>

Hi There, I installed metricbeat 6.7 on my RHEL 7 machine and when I tried to open the default metricbeat dashboard on kibana, it doesn't show any data except the one below Parts of or the entire area chart might not b…

---

## [Pass multiple conditions as an array to drop\_event](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502)

<div class="topic-metadata">

**Author:** [@jibsonline](https://discuss.elastic.co/u/jibsonline)\
**Replies:** 8\
**Last updated:** [March 5, 2020, 4:50pm UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502 "2020-03-05T16:50:06Z")

</div>

Hi, I am trying to pass multiple values as an array to drop\_event This works processors: - drop\_event: when: contains: message: "Starting Session" But I have multipl…

---

## [Date math expression for index pattern](https://discuss.elastic.co/t/date-math-expression-for-index-pattern/222406)

<div class="topic-metadata">

**Author:** [@karthick2020](https://discuss.elastic.co/u/karthick2020)\
**Replies:** 0\
**Last updated:** [March 6, 2020, 5:25am UTC](https://discuss.elastic.co/t/date-math-expression-for-index-pattern/222406 "2020-03-06T05:25:04Z")

</div>

Hi Team, Currently we have enabled weekly rollover for metricbeat, winlogbeat & logstash index. I have following 2 queries on ILM, From documentation, understood that Logstash uses Joda to format the index pattern fr…

---

## [Filebeat 7.6.0 - AWS VPC Flowlogs - Parser Exception](https://discuss.elastic.co/t/filebeat-7-6-0-aws-vpc-flowlogs-parser-exception/222371)

<div class="topic-metadata">

**Author:** [@prv](https://discuss.elastic.co/u/prv)\
**Replies:** 0\
**Last updated:** [March 5, 2020, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-7-6-0-aws-vpc-flowlogs-parser-exception/222371 "2020-03-05T21:06:12Z")

</div>

Tying to use the new S3 input to source VPC flow logs. I am getting the following error. Any help. This is from Kibana logs. \[2020-03-05T20:32:04,069\]\[DEBUG\]\[o.e.a.b.TransportShardBulkAction\] \[node-1\] \[filebeat-7.6.0…

---

## [Multi Cloud Environment (AWS, IBM. AZURE)](https://discuss.elastic.co/t/multi-cloud-environment-aws-ibm-azure/222270)

<div class="topic-metadata">

**Author:** [@Reginato](https://discuss.elastic.co/u/Reginato)\
**Replies:** 1\
**Last updated:** [March 5, 2020, 5:55pm UTC](https://discuss.elastic.co/t/multi-cloud-environment-aws-ibm-azure/222270 "2020-03-05T17:55:55Z")

</div>

Hi, I have a multi-cloud environment (DB is on Oracle Cloud, Application servers are on AWS and Active Directoy is on AZURE). The ELK Stack server is installed on the IBM Cloud. In this scenario is it possible for ELK S…

---

## [Kubernetes custom metrics API for Horizontal Pod Autoscaler](https://discuss.elastic.co/t/kubernetes-custom-metrics-api-for-horizontal-pod-autoscaler/221645)

<div class="topic-metadata">

**Author:** [@Babadofar](https://discuss.elastic.co/u/Babadofar)\
**Replies:** 1\
**Last updated:** [March 5, 2020, 5:03pm UTC](https://discuss.elastic.co/t/kubernetes-custom-metrics-api-for-horizontal-pod-autoscaler/221645 "2020-03-05T17:03:43Z")

</div>

Hi there. I'm curious if there is a way to use metricbeat as a source for scaling resources in Kubernetes using HPA, as described here https://learnk8s.io/autoscaling-apps-kubernetes The idea would be for instance to …

---

## [Auditbeat File Integrity appending random string to file.path](https://discuss.elastic.co/t/auditbeat-file-integrity-appending-random-string-to-file-path/222261)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [March 5, 2020, 4:42pm UTC](https://discuss.elastic.co/t/auditbeat-file-integrity-appending-random-string-to-file-path/222261 "2020-03-05T16:42:51Z")

</div>

Hello, Just noticed that Auditbeat 7.5.2 File Integrity module seems to sometimes append a weird string to the file.path values, for example: Is this a known issue? I'm not sure how to reproduce. Grtz Willem

---

## [How to query for running services matching a specific list of services](https://discuss.elastic.co/t/how-to-query-for-running-services-matching-a-specific-list-of-services/222304)

<div class="topic-metadata">

**Author:** [@benjamin.watson](https://discuss.elastic.co/u/benjamin.watson)\
**Replies:** 0\
**Last updated:** [March 5, 2020, 2:05pm UTC](https://discuss.elastic.co/t/how-to-query-for-running-services-matching-a-specific-list-of-services/222304 "2020-03-05T14:05:16Z")

</div>

This is a metricbeat query question. I've got metricbeat loaded on a bunch of Windows hosts and am collecting metrics nicely. I've got the stock Windows Service dashboard working as well. We want to use the collected …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=268)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=270)
