# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=270

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 271

---

## [How to get kubernetes node labels with metricbeat?](https://discuss.elastic.co/t/how-to-get-kubernetes-node-labels-with-metricbeat/220667)

<div class="topic-metadata">

**Author:** [@Federico\_Bevione](https://discuss.elastic.co/u/Federico_Bevione)\
**Replies:** 6\
**Last updated:** [March 5, 2020, 11:46am UTC](https://discuss.elastic.co/t/how-to-get-kubernetes-node-labels-with-metricbeat/220667 "2020-03-05T11:46:19Z")

</div>

Hi there, I'm trying to enrich node, or state\_node metrics of kubernetes module with k8s node labels but without any luck. I'm using metricbeat 7.6.0. My configuration is the following for the daemonset metricbeat.mo…

---

## [How to see and store Filebeat and Elasticsearch processing time logs duration in separate fields in Kibana](https://discuss.elastic.co/t/how-to-see-and-store-filebeat-and-elasticsearch-processing-time-logs-duration-in-separate-fields-in-kibana/222152)

<div class="topic-metadata">

**Author:** [@TeodorCa](https://discuss.elastic.co/u/TeodorCa)\
**Replies:** 0\
**Last updated:** [March 4, 2020, 8:03pm UTC](https://discuss.elastic.co/t/how-to-see-and-store-filebeat-and-elasticsearch-processing-time-logs-duration-in-separate-fields-in-kibana/222152 "2020-03-04T20:03:25Z")

</div>

Hello guys, Being a newbie with ELK Suite I might be asking about something that is already answered even though I couldn't find an answer to my problem after a long search. So, my apologies on beforehand. Anyhow, I can…

---

## [error":"Content-Type header \[application/x-www-form-urlencoded\] is not supported"](https://discuss.elastic.co/t/error-content-type-header-application-x-www-form-urlencoded-is-not-supported/221569)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 3\
**Last updated:** [March 5, 2020, 10:02am UTC](https://discuss.elastic.co/t/error-content-type-header-application-x-www-form-urlencoded-is-not-supported/221569 "2020-03-05T10:02:19Z")

</div>

Hi I am running a 7.6.0 version of ELK on CentOS Linux release 7.7.1908 (Core). I have downloaded beats-dashboards-1.3.1.zip using wget https://download.elastic.co/beats/dashboards/beats-dashboards-1.3.1.zip cd /root/…

---

## [Metricbeat jolokia agent for tomcat application](https://discuss.elastic.co/t/metricbeat-jolokia-agent-for-tomcat-application/221852)

<div class="topic-metadata">

**Author:** [@seddikalaouiismaili](https://discuss.elastic.co/u/seddikalaouiismaili)\
**Replies:** 9\
**Last updated:** [March 5, 2020, 6:23am UTC](https://discuss.elastic.co/t/metricbeat-jolokia-agent-for-tomcat-application/221852 "2020-03-05T06:23:36Z")

</div>

Hello I'm contacting you about collecting metrics for a java tomcat application. We want to collect metrics for our application and we need to put it on the ELK stack for graphing !! here below many config : ==\> on m…

---

## [Windows containers logging](https://discuss.elastic.co/t/windows-containers-logging/221997)

<div class="topic-metadata">

**Author:** [@alek](https://discuss.elastic.co/u/alek)\
**Replies:** 2\
**Last updated:** [March 4, 2020, 7:24pm UTC](https://discuss.elastic.co/t/windows-containers-logging/221997 "2020-03-04T19:24:40Z")

</div>

Hi, We have recently started using GKE ( Google managed Kubernetes service ) windows nodes. For all the linux deployments, we have filebeat deployed as daemonset that sends all the application logs into our Elasticsear…

---

## [Third party libraries used by Filebeat](https://discuss.elastic.co/t/third-party-libraries-used-by-filebeat/222004)

<div class="topic-metadata">

**Author:** [@rpsowood](https://discuss.elastic.co/u/rpsowood)\
**Replies:** 1\
**Last updated:** [March 4, 2020, 5:50pm UTC](https://discuss.elastic.co/t/third-party-libraries-used-by-filebeat/222004 "2020-03-04T17:50:08Z")

</div>

Hi For compliance purposes, I need to declare which third party libraries are used by Filebeat (OSS version) in our application. I see in the NOTICE.txt file a lot (200+) third parties listed, but I think this is for th…

---

## [Index template and ilm conflict](https://discuss.elastic.co/t/index-template-and-ilm-conflict/221729)

<div class="topic-metadata">

**Author:** [@chersko](https://discuss.elastic.co/u/chersko)\
**Replies:** 6\
**Last updated:** [March 4, 2020, 4:47pm UTC](https://discuss.elastic.co/t/index-template-and-ilm-conflict/221729 "2020-03-04T16:47:40Z")

</div>

I have the following in my metricbeat.yml "template" setup.template.enabled: true setup.template.name: "metrics\_index\_template" setup.template.pattern: "metrics-\*" setup.template.fields: "fields.yml" setup.template…

---

## [Filebeat - seems to be not picking up when using the inputs.d directory](https://discuss.elastic.co/t/filebeat-seems-to-be-not-picking-up-when-using-the-inputs-d-directory/222058)

<div class="topic-metadata">

**Author:** [@Apollyon](https://discuss.elastic.co/u/Apollyon)\
**Replies:** 2\
**Last updated:** [March 4, 2020, 4:29pm UTC](https://discuss.elastic.co/t/filebeat-seems-to-be-not-picking-up-when-using-the-inputs-d-directory/222058 "2020-03-04T16:29:28Z")

</div>

Hello, When having a play around with Filebeat and the input capabilities of the agent. Below is the config from the filebeat.yml and an example of a yml that is in the inputs.d directory. filebeat.yml - Works when co…

---

## [Build 7.0 for arm64 failed](https://discuss.elastic.co/t/build-7-0-for-arm64-failed/222033)

<div class="topic-metadata">

**Author:** [@hsam](https://discuss.elastic.co/u/hsam)\
**Replies:** 1\
**Last updated:** [March 4, 2020, 3:44pm UTC](https://discuss.elastic.co/t/build-7-0-for-arm64-failed/222033 "2020-03-04T15:44:46Z")

</div>

I need a build for arm64 , no error during the build. Build command: GOOS=linux GOARCH=arm CGO\_ENABLED=1 go build Here the 2 last line of the build :"/usr/lib/go-1.10/pkg/tool/linux\_arm64/buildid -w $WORK/b291/pkg.a # …

---

## [Monitor eps without sending the data](https://discuss.elastic.co/t/monitor-eps-without-sending-the-data/221437)

<div class="topic-metadata">

**Author:** [@tristan1](https://discuss.elastic.co/u/tristan1)\
**Replies:** 4\
**Last updated:** [March 4, 2020, 3:15pm UTC](https://discuss.elastic.co/t/monitor-eps-without-sending-the-data/221437 "2020-03-04T15:15:08Z")

</div>

I'm currently monitoring the log rate with Metricbeat on a Centos system. Now I would like to monitor all emitted log rate without sending all data to Elastic. For example i have a connector installed which is sending d…

---

## [Does K8s autodiscover work for all namespaces?](https://discuss.elastic.co/t/does-k8s-autodiscover-work-for-all-namespaces/221874)

<div class="topic-metadata">

**Author:** [@ben.sharp](https://discuss.elastic.co/u/ben.sharp)\
**Replies:** 4\
**Last updated:** [March 4, 2020, 1:27pm UTC](https://discuss.elastic.co/t/does-k8s-autodiscover-work-for-all-namespaces/221874 "2020-03-04T13:27:41Z")

</div>

Hello, As the title says I was wondering whether hint-based autodiscover for K8s (following this documentation) searches through all namespaces by default? I have a metricbeat Daemonset running in the kube-system names…

---

## [System module: error when defining syslog.input.processors](https://discuss.elastic.co/t/system-module-error-when-defining-syslog-input-processors/221865)

<div class="topic-metadata">

**Author:** [@TatsuKishi](https://discuss.elastic.co/u/TatsuKishi)\
**Replies:** 3\
**Last updated:** [March 4, 2020, 11:28am UTC](https://discuss.elastic.co/t/system-module-error-when-defining-syslog-input-processors/221865 "2020-03-04T11:28:37Z")

</div>

Hey, I'm trying to define a processor in the system module just for syslog to drop certain spammy, non-relevant events. But when I define a drop\_event I get an error about a processor having multiple actions: #011ERROR#…

---

## [Unable to get netflow sequence number](https://discuss.elastic.co/t/unable-to-get-netflow-sequence-number/222034)

<div class="topic-metadata">

**Author:** [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Replies:** 0\
**Last updated:** [March 4, 2020, 10:10am UTC](https://discuss.elastic.co/t/unable-to-get-netflow-sequence-number/222034 "2020-03-04T10:10:04Z")

</div>

Hi I am using filebeat to save netflow data in elasticsearch. But while going through the data I realized there is no netflow sequence number stored in the index. Although when I use old version of logstash I get the seq…

---

## [Exclude log lines with nginx filebeat module](https://discuss.elastic.co/t/exclude-log-lines-with-nginx-filebeat-module/222019)

<div class="topic-metadata">

**Author:** [@thomas\_vega](https://discuss.elastic.co/u/thomas_vega)\
**Replies:** 0\
**Last updated:** [March 4, 2020, 8:59am UTC](https://discuss.elastic.co/t/exclude-log-lines-with-nginx-filebeat-module/222019 "2020-03-04T08:59:03Z")

</div>

I am using the filebeat nginx module and want to exclude certain lines. Therefore I want to add a drop\_event processor to the module configuration. This fails with following error message: filebeat.modules: - module: ng…

---

## [Basic Authorization for http API check](https://discuss.elastic.co/t/basic-authorization-for-http-api-check/221534)

<div class="topic-metadata">

**Author:** [@IMagalashvili](https://discuss.elastic.co/u/IMagalashvili)\
**Replies:** 2\
**Last updated:** [March 4, 2020, 8:15am UTC](https://discuss.elastic.co/t/basic-authorization-for-http-api-check/221534 "2020-03-04T08:15:50Z")

</div>

Hello, I have API check URL with Basic Authorization: curl --location --request GET 'http://xxx.xxx.xxx.xxx:3000/status' --header 'Accept: application/json' --header 'Content-Type: application/json' --header 'Auth…

---

## [Include only error](https://discuss.elastic.co/t/include-only-error/221282)

<div class="topic-metadata">

**Author:** [@armani\_ani](https://discuss.elastic.co/u/armani_ani)\
**Replies:** 5\
**Last updated:** [March 4, 2020, 7:21am UTC](https://discuss.elastic.co/t/include-only-error/221282 "2020-03-04T07:21:25Z")

</div>

Hi , I am using filebeat 7.6 with the below filebeat config logging.level: error filebeat.inputs: type: syslog protocol.tcp.host: "localhost:5000" include\_lines: \['error'\] I would like for example to include only…

---

## [Autodiscover does not collect prometheus metrics](https://discuss.elastic.co/t/autodiscover-does-not-collect-prometheus-metrics/218450)

<div class="topic-metadata">

**Author:** [@Babadofar](https://discuss.elastic.co/u/Babadofar)\
**Replies:** 5\
**Last updated:** [March 4, 2020, 7:19am UTC](https://discuss.elastic.co/t/autodiscover-does-not-collect-prometheus-metrics/218450 "2020-03-04T07:19:16Z")

</div>

I have exposed prometheus formatted metrics on several pods, using the prometheus module and listing each service separately works well, but I can not get autodiscover working. Using debug logging for all modules, I can …

---

## [Drop\_event in 7.6.0](https://discuss.elastic.co/t/drop-event-in-7-6-0/221533)

<div class="topic-metadata">

**Author:** [@kikog20](https://discuss.elastic.co/u/kikog20)\
**Replies:** 1\
**Last updated:** [March 3, 2020, 7:01pm UTC](https://discuss.elastic.co/t/drop-event-in-7-6-0/221533 "2020-03-03T19:01:59Z")

</div>

Hello, I dont know why my processor is not working.This is my processor: processors: - drop\_event.when.not.or: - equals.winlog.event\_id: 4608 - equals.winlog.event\_id: 4609 - equals.winlog.event\_id: 4624 - equals…

---

## [Text removal from logs with Filebeat or Logstash](https://discuss.elastic.co/t/text-removal-from-logs-with-filebeat-or-logstash/221893)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 2\
**Last updated:** [March 3, 2020, 2:19pm UTC](https://discuss.elastic.co/t/text-removal-from-logs-with-filebeat-or-logstash/221893 "2020-03-03T14:19:05Z")

</div>

I've been learning about regex/grok the last few days and I'm trying to put the pieces together on how to remove text from some logs that we're ingesting. I have an example line from the logs below and have been able to…

---

## [Multiline pattern not working in my filebeat configuration](https://discuss.elastic.co/t/multiline-pattern-not-working-in-my-filebeat-configuration/221588)

<div class="topic-metadata">

**Author:** [@sushil](https://discuss.elastic.co/u/sushil)\
**Replies:** 1\
**Last updated:** [March 3, 2020, 2:05pm UTC](https://discuss.elastic.co/t/multiline-pattern-not-working-in-my-filebeat-configuration/221588 "2020-03-03T14:05:04Z")

</div>

Hi , I am using below multiline option in my filebeat.yml file. multiline.pattern: '^\[\[:space:\]\]+(at|.{3})\\b|^Caused by:' multiline.negate: false multiline.match: afterPreformatted text but the logs are still printi…

---

## [MetricBeat tomcat module with HTTPS](https://discuss.elastic.co/t/metricbeat-tomcat-module-with-https/220313)

<div class="topic-metadata">

**Author:** [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Replies:** 6\
**Last updated:** [March 3, 2020, 1:26pm UTC](https://discuss.elastic.co/t/metricbeat-tomcat-module-with-https/220313 "2020-03-03T13:26:33Z")

</div>

Hi guys, I have just tried to get the BETA version of the tomcat module to work with our tomcat(8.0.x) which only allows HTTPS connections. My configuration of the module(MetricBeat 7.6.0) is this: - module: tomcat …

---

## [Can't setup kibana dashboards for Beats](https://discuss.elastic.co/t/cant-setup-kibana-dashboards-for-beats/221625)

<div class="topic-metadata">

**Author:** [@tbhaxor](https://discuss.elastic.co/u/tbhaxor)\
**Replies:** 2\
**Last updated:** [March 2, 2020, 12:59pm UTC](https://discuss.elastic.co/t/cant-setup-kibana-dashboards-for-beats/221625 "2020-03-02T12:59:05Z")

</div>

I want to send my data from beats to elasticsearch via logstash, also I want to configure the kibana dashboards for the same So, in beats config, I have only added hosts for kibana and logstash. After doing this I can't…

---

## [Unable to setup Metricbeat dashboards](https://discuss.elastic.co/t/unable-to-setup-metricbeat-dashboards/220852)

<div class="topic-metadata">

**Author:** [@tristan1](https://discuss.elastic.co/u/tristan1)\
**Replies:** 13\
**Last updated:** [March 3, 2020, 7:10am UTC](https://discuss.elastic.co/t/unable-to-setup-metricbeat-dashboards/220852 "2020-03-03T07:10:54Z")

</div>

Hi, I am unable to setup Metricbeat dashboards. I'm trying the following: metricbeat setup --dashboards And getting this error: Loading dashboards (Kibana must be running and reachable) Exiting: error connecting to …

---

## [Unexpectedly High Hourly Usage of CW:GMD-Metrics with AWS Module](https://discuss.elastic.co/t/unexpectedly-high-hourly-usage-of-cw-gmd-metrics-with-aws-module/221594)

<div class="topic-metadata">

**Author:** [@AddChickpeas](https://discuss.elastic.co/u/AddChickpeas)\
**Replies:** 3\
**Last updated:** [March 3, 2020, 8:25am UTC](https://discuss.elastic.co/t/unexpectedly-high-hourly-usage-of-cw-gmd-metrics-with-aws-module/221594 "2020-03-03T08:25:01Z")

</div>

Hello, I'm trying to make sense of the CW:GMD-Metrics usage from my usage report. It currently is indicating it is using 10k metrics every hour, but I have no idea where that number is coming from. Looks farther back in…

---

## [AWS Cloudwatch Metricset not pulling every minute](https://discuss.elastic.co/t/aws-cloudwatch-metricset-not-pulling-every-minute/221558)

<div class="topic-metadata">

**Author:** [@AddChickpeas](https://discuss.elastic.co/u/AddChickpeas)\
**Replies:** 3\
**Last updated:** [March 3, 2020, 12:05am UTC](https://discuss.elastic.co/t/aws-cloudwatch-metricset-not-pulling-every-minute/221558 "2020-03-03T00:05:01Z")

</div>

Facing kind of a weird issue where metricbeat isn't pulling data from AWS every 60 seconds as defined in the config. It generally falls into this 3 minutes on/3 minutes off format. We're going to be setting up alerts on …

---

## [Message field - How become a valid field?](https://discuss.elastic.co/t/message-field-how-become-a-valid-field/220274)

<div class="topic-metadata">

**Author:** [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Replies:** 3\
**Last updated:** [March 2, 2020, 11:40pm UTC](https://discuss.elastic.co/t/message-field-how-become-a-valid-field/220274 "2020-03-02T23:40:27Z")

</div>

Hi Team! We have a custom App and are trying define some Log Pattern based on some custom messages. At our Demo App where we type and submit any kind of test message, Filebeat outputs to ES and message appears at messag…

---

## [Send Log data from multiple files with different indices without logstash](https://discuss.elastic.co/t/send-log-data-from-multiple-files-with-different-indices-without-logstash/221648)

<div class="topic-metadata">

**Author:** [@CLehmann](https://discuss.elastic.co/u/CLehmann)\
**Replies:** 8\
**Last updated:** [March 2, 2020, 7:05pm UTC](https://discuss.elastic.co/t/send-log-data-from-multiple-files-with-different-indices-without-logstash/221648 "2020-03-02T19:05:53Z")

</div>

My goal is to use filebeat to take multiple log files, and send them to elastic search without logstash. Here is my filebeat.yml: filebeat.inputs: - type: log enabled: true paths: - /usr/share/filebeat…

---

## [Filebeat causes error messages in logstash](https://discuss.elastic.co/t/filebeat-causes-error-messages-in-logstash/221720)

<div class="topic-metadata">

**Author:** [@stefan\_schumacher](https://discuss.elastic.co/u/stefan_schumacher)\
**Replies:** 1\
**Last updated:** [March 2, 2020, 6:31pm UTC](https://discuss.elastic.co/t/filebeat-causes-error-messages-in-logstash/221720 "2020-03-02T18:31:35Z")

</div>

Hello, In this thread Badger points out that my supposed problem with logstash is actually a problem with filebeats. Unfortunately he doesn't use filebeat and therefore can't help me with my problem. It's probably best …

---

## [Custom filebeat index - same index name but diferent template](https://discuss.elastic.co/t/custom-filebeat-index-same-index-name-but-diferent-template/221671)

<div class="topic-metadata">

**Author:** [@bueka.torao](https://discuss.elastic.co/u/bueka.torao)\
**Replies:** 5\
**Last updated:** [March 2, 2020, 5:20pm UTC](https://discuss.elastic.co/t/custom-filebeat-index-same-index-name-but-diferent-template/221671 "2020-03-02T17:20:34Z")

</div>

Hi guys, I am setting my filebeat.yml in order to send logs to Elasticsearch. I created a template in Elasticsearch, I named it: filebeat . See below the configuration. I set the filebeat.yml as you guys can see below. …

---

## [Filebeat "dynamic" field rename](https://discuss.elastic.co/t/filebeat-dynamic-field-rename/221651)

<div class="topic-metadata">

**Author:** [@Stanislav\_Lapshansky](https://discuss.elastic.co/u/Stanislav_Lapshansky)\
**Replies:** 3\
**Last updated:** [March 2, 2020, 5:04pm UTC](https://discuss.elastic.co/t/filebeat-dynamic-field-rename/221651 "2020-03-02T17:04:44Z")

</div>

I want to rename fields in filebeat according to variable value. I've tried this: filebeat.inputs: - type: docker #... processors: - rename: fields: - from: "json" to: "%{\['docker.co…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=269)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=271)
