# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=271

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 272

---

## [Can Auditbeat retrieve username for events on Windows](https://discuss.elastic.co/t/can-auditbeat-retrieve-username-for-events-on-windows/221712)

<div class="topic-metadata">

**Author:** [@ychapiteau](https://discuss.elastic.co/u/ychapiteau)\
**Replies:** 0\
**Last updated:** [March 2, 2020, 3:19pm UTC](https://discuss.elastic.co/t/can-auditbeat-retrieve-username-for-events-on-windows/221712 "2020-03-02T15:19:23Z")

</div>

I looking for a solution to retrieve the username for an Auditbeat event using the file integrity module on Windows. Is there a way to do it ? I've already tried to use processors (include\_fields)

---

## [Starting ELK-stack from docker-compose but nothing happen](https://discuss.elastic.co/t/starting-elk-stack-from-docker-compose-but-nothing-happen/221219)

<div class="topic-metadata">

**Author:** [@zebulyon](https://discuss.elastic.co/u/zebulyon)\
**Replies:** 15\
**Last updated:** [March 2, 2020, 10:48am UTC](https://discuss.elastic.co/t/starting-elk-stack-from-docker-compose-but-nothing-happen/221219 "2020-03-02T10:48:54Z")

</div>

Hello beginner with the ELK-stack here and apologize in advance regarding the long post , So I'm using a docker-compose file to start the entire elastic stack from the official docker images ver 7.6.0. Seemingly all of …

---

## [Sending metrics from a log to his respective logstash configuration](https://discuss.elastic.co/t/sending-metrics-from-a-log-to-his-respective-logstash-configuration/221477)

<div class="topic-metadata">

**Author:** [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Replies:** 1\
**Last updated:** [March 1, 2020, 11:34pm UTC](https://discuss.elastic.co/t/sending-metrics-from-a-log-to-his-respective-logstash-configuration/221477 "2020-03-01T23:34:45Z")

</div>

Hi, I have a log with mixed metrics: cpu, filesystem, ping, uptime, etc...How can I direct each metric from Filebeat to his respective configuration in logstash? I also can use powershell to separate the metrics in hi…

---

## [Filebeat cisco modue "Error starting the server address already in use"](https://discuss.elastic.co/t/filebeat-cisco-modue-error-starting-the-server-address-already-in-use/220217)

<div class="topic-metadata">

**Author:** [@hazem\_Alhamwi](https://discuss.elastic.co/u/hazem_Alhamwi)\
**Replies:** 18\
**Last updated:** [March 1, 2020, 5:38pm UTC](https://discuss.elastic.co/t/filebeat-cisco-modue-error-starting-the-server-address-already-in-use/220217 "2020-03-01T17:38:54Z")

</div>

i am trying to setup log server for network devices using ELK and filebeat with Ubuntu 18, but kibana doesn't display any output. when i run filebeat -e i get the following messages: 2020-02-20T14:53:10.891Z INFO…

---

## [Filebeat, ILM and multiple indices](https://discuss.elastic.co/t/filebeat-ilm-and-multiple-indices/219638)

<div class="topic-metadata">

**Author:** [@corbosman](https://discuss.elastic.co/u/corbosman)\
**Replies:** 6\
**Last updated:** [March 1, 2020, 11:19am UTC](https://discuss.elastic.co/t/filebeat-ilm-and-multiple-indices/219638 "2020-03-01T11:19:33Z")

</div>

Hi all, im having a bit of a hard time understanding the best config for our setup. We are running filebeat to ship several totally different types of logs to elastic that need their own template and index. But at the s…

---

## [Events from the future on WEC](https://discuss.elastic.co/t/events-from-the-future-on-wec/221495)

<div class="topic-metadata">

**Author:** [@artem.n](https://discuss.elastic.co/u/artem.n)\
**Replies:** 0\
**Last updated:** [February 28, 2020, 10:36pm UTC](https://discuss.elastic.co/t/events-from-the-future-on-wec/221495 "2020-02-28T22:36:33Z")

</div>

Winlogbeat 7.6 is installed on WEC. "ignore\_older: 72h" is set. If the events being forwarded have a date greater than the WEC server date and "ignore\_older" is set, then such events will be ignored. Events from the fut…

---

## [Custom Cloudwatch Metrics](https://discuss.elastic.co/t/custom-cloudwatch-metrics/221324)

<div class="topic-metadata">

**Author:** [@AddChickpeas](https://discuss.elastic.co/u/AddChickpeas)\
**Replies:** 12\
**Last updated:** [February 28, 2020, 9:55pm UTC](https://discuss.elastic.co/t/custom-cloudwatch-metrics/221324 "2020-02-28T21:55:07Z")

</div>

Hello, Using v7.6.0 I'm attempting to collect some custom metrics using metricbeat, but not having any luck. I have tried pretty much every combination of the below possible - module: aws period: 60s access\_key\_i…

---

## [Send clamav logs to elk](https://discuss.elastic.co/t/send-clamav-logs-to-elk/221483)

<div class="topic-metadata">

**Author:** [@tbhaxor](https://discuss.elastic.co/u/tbhaxor)\
**Replies:** 0\
**Last updated:** [February 28, 2020, 8:04pm UTC](https://discuss.elastic.co/t/send-clamav-logs-to-elk/221483 "2020-02-28T20:04:56Z")

</div>

Hi there, I would like to send the scan logs from file c:\\program files\\clamav\\clamd.logs to elasticsearch and assign new index name like clamav-scans-\* The scan logs for clean file looks like Sat Feb 29 01:23:41 2020…

---

## [Restore deleted dashboards](https://discuss.elastic.co/t/restore-deleted-dashboards/221289)

<div class="topic-metadata">

**Author:** [@tbhaxor](https://discuss.elastic.co/u/tbhaxor)\
**Replies:** 2\
**Last updated:** [February 28, 2020, 8:00pm UTC](https://discuss.elastic.co/t/restore-deleted-dashboards/221289 "2020-02-28T20:00:04Z")

</div>

I have intentionally deleted some built-in dashboard. How do i recover it?

---

## [Filebeat modules scope](https://discuss.elastic.co/t/filebeat-modules-scope/221472)

<div class="topic-metadata">

**Author:** [@Mariano\_D](https://discuss.elastic.co/u/Mariano_D)\
**Replies:** 0\
**Last updated:** [February 28, 2020, 5:38pm UTC](https://discuss.elastic.co/t/filebeat-modules-scope/221472 "2020-02-28T17:38:15Z")

</div>

Hello. I've been taking a look into modules as a way to relieve Logstash load or replace it if not needed. I Started testing nginx and loaded the module and dashboards, I'm surprised filebeat does not even parse the re…

---

## [BPF filter is empty](https://discuss.elastic.co/t/bpf-filter-is-empty/221457)

<div class="topic-metadata">

**Author:** [@christoph\_service\_se](https://discuss.elastic.co/u/christoph_service_se)\
**Replies:** 0\
**Last updated:** [February 28, 2020, 3:26pm UTC](https://discuss.elastic.co/t/bpf-filter-is-empty/221457 "2020-02-28T15:26:45Z")

</div>

Hi Guys, I try to set up packet beat up and runing on a windows 2012 r2 server. The problem is that the bpf filter is empty, no matter with port i define in packetbeat.protocols. Here are my config packetbeat.interfa…

---

## [PostgreSQL module cannot connect](https://discuss.elastic.co/t/postgresql-module-cannot-connect/220916)

<div class="topic-metadata">

**Author:** [@thealy](https://discuss.elastic.co/u/thealy)\
**Replies:** 8\
**Last updated:** [February 28, 2020, 2:45pm UTC](https://discuss.elastic.co/t/postgresql-module-cannot-connect/220916 "2020-02-28T14:45:45Z")

</div>

We are running metricbeat-7.6.0 on a RedHat 7 system. The basic Metricbeat app is running and connecting with ES. However, the postgresql module is not connecting to the local database. The password, shown here as "redac…

---

## [Get values from nested JSON](https://discuss.elastic.co/t/get-values-from-nested-json/221423)

<div class="topic-metadata">

**Author:** [@Sumgan](https://discuss.elastic.co/u/Sumgan)\
**Replies:** 0\
**Last updated:** [February 28, 2020, 12:06pm UTC](https://discuss.elastic.co/t/get-values-from-nested-json/221423 "2020-02-28T12:06:59Z")

</div>

Trying to parse by filebeat JSON-log like: { "Date": "2020-02-28T07:16:32.140133Z", "Level": "Trace", "Message": "SLOW QUEUE MSG \[{queue}\]: {message} - {elapsed}ms. Q: {prevQueueCount}/{curQueueCount}.", "EventProp…

---

## [Filebeat works but keeps generating ERROR Messages in Logs](https://discuss.elastic.co/t/filebeat-works-but-keeps-generating-error-messages-in-logs/221396)

<div class="topic-metadata">

**Author:** [@Lukas\_L](https://discuss.elastic.co/u/Lukas_L)\
**Replies:** 2\
**Last updated:** [February 28, 2020, 10:38am UTC](https://discuss.elastic.co/t/filebeat-works-but-keeps-generating-error-messages-in-logs/221396 "2020-02-28T10:38:05Z")

</div>

Hi there, I am running Filebeat (7.3.1) on multiple Systems and all of them are sending their data to Logstash (Elasticsearch) as desired. I can see the events in Kibana perfectly. But I realized that every Filebeat in…

---

## [Unable to enable / disable module on manjaro os](https://discuss.elastic.co/t/unable-to-enable-disable-module-on-manjaro-os/221290)

<div class="topic-metadata">

**Author:** [@tbhaxor](https://discuss.elastic.co/u/tbhaxor)\
**Replies:** 1\
**Last updated:** [February 28, 2020, 9:18am UTC](https://discuss.elastic.co/t/unable-to-enable-disable-module-on-manjaro-os/221290 "2020-02-28T09:18:32Z")

</div>

System Details OS Kernel-Version: Linux h3ll 5.4.18-1-MANJARO #1 SMP PREEMPT Thu Feb 6 11:41:30 UTC 2020 x86\_64 GNU/Linux Filebeat Version: filebeat version 7.5.2 (amd64), libbeat 7.5.2 \[7.5.2 built 2020-01-26 19:01:07…

---

## [How to filter in filebeat](https://discuss.elastic.co/t/how-to-filter-in-filebeat/221265)

<div class="topic-metadata">

**Author:** [@D\_Gupta](https://discuss.elastic.co/u/D_Gupta)\
**Replies:** 1\
**Last updated:** [February 28, 2020, 9:15am UTC](https://discuss.elastic.co/t/how-to-filter-in-filebeat/221265 "2020-02-28T09:15:59Z")

</div>

Hi, Below message I'm getting from filebeat (7.0.1). I want to filter it in different line. How we can do it in filebeat.yml file? any help will be appreciable. t log.flags multiline t message Audit…

---

## [Dose filebeat support rocketmq](https://discuss.elastic.co/t/dose-filebeat-support-rocketmq/221228)

<div class="topic-metadata">

**Author:** [@dushang2016](https://discuss.elastic.co/u/dushang2016)\
**Replies:** 3\
**Last updated:** [February 28, 2020, 9:10am UTC](https://discuss.elastic.co/t/dose-filebeat-support-rocketmq/221228 "2020-02-28T09:10:59Z")

</div>

I need use filebeat and rocketmq,but i didn't found the function of filebeat output to rocketmq.

---

## [Importing Apache logs with FIlebeats tutorial doesn't work](https://discuss.elastic.co/t/importing-apache-logs-with-filebeats-tutorial-doesnt-work/221065)

<div class="topic-metadata">

**Author:** [@lgo](https://discuss.elastic.co/u/lgo)\
**Replies:** 10\
**Last updated:** [February 28, 2020, 9:07am UTC](https://discuss.elastic.co/t/importing-apache-logs-with-filebeats-tutorial-doesnt-work/221065 "2020-02-28T09:07:08Z")

</div>

Hello I'm following this tutorial, where you ingest some Apache logs with FIlebeats into Elasticsearch to visualize them in Kibana. I follow all the steps and none fails, but when I have a look at the index pattern …

---

## [Is metricbeat compatible for latest rhel 5 patchset](https://discuss.elastic.co/t/is-metricbeat-compatible-for-latest-rhel-5-patchset/220988)

<div class="topic-metadata">

**Author:** [@vijay\_kaali](https://discuss.elastic.co/u/vijay_kaali)\
**Replies:** 4\
**Last updated:** [February 28, 2020, 4:59am UTC](https://discuss.elastic.co/t/is-metricbeat-compatible-for-latest-rhel-5-patchset/220988 "2020-02-28T04:59:20Z")

</div>

is metricbeat.6.2.x compatible to latest rhel 2.6.18-437.el5 ? any link to get support/compatibility matrix for elastic 6.5.x

---

## [Manually loading index-patterns and dashboards into kibana after exporting from Beats](https://discuss.elastic.co/t/manually-loading-index-patterns-and-dashboards-into-kibana-after-exporting-from-beats/220942)

<div class="topic-metadata">

**Author:** [@johncollaros](https://discuss.elastic.co/u/johncollaros)\
**Replies:** 2\
**Last updated:** [February 27, 2020, 11:19pm UTC](https://discuss.elastic.co/t/manually-loading-index-patterns-and-dashboards-into-kibana-after-exporting-from-beats/220942 "2020-02-27T23:19:01Z")

</div>

Hi, Due to the way the network is structured, beats cannot directly connect to Elasticsearch and Kibana. Also, salt is being used to setup the elastic stack. It is trivial to upload the index templates to Elasticsearc…

---

## [ILM breaks the mapping for a filebeat module](https://discuss.elastic.co/t/ilm-breaks-the-mapping-for-a-filebeat-module/220047)

<div class="topic-metadata">

**Author:** [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Replies:** 1\
**Last updated:** [February 27, 2020, 9:58pm UTC](https://discuss.elastic.co/t/ilm-breaks-the-mapping-for-a-filebeat-module/220047 "2020-02-27T21:58:24Z")

</div>

I installed a filebeat with google cloud module (https://github.com/elastic/beats/tree/master/x-pack/filebeat/module/googlecloud) and everything works fine, data gets parsed, and it shows up in the SIEM app just fine (EC…

---

## [Can't load dashboards from Windows version of packetbeat to Kibana on Security Onion](https://discuss.elastic.co/t/cant-load-dashboards-from-windows-version-of-packetbeat-to-kibana-on-security-onion/220886)

<div class="topic-metadata">

**Author:** [@tedfs](https://discuss.elastic.co/u/tedfs)\
**Replies:** 3\
**Last updated:** [February 27, 2020, 3:44pm UTC](https://discuss.elastic.co/t/cant-load-dashboards-from-windows-version-of-packetbeat-to-kibana-on-security-onion/220886 "2020-02-27T15:44:03Z")

</div>

Seems like problems loading dashboards is a common theme with beats. I've looked over all the forum posts I can find and I feel like I've just gone down deeper and deeper rabbit holes and not found any solution to my pro…

---

## [K8s filebeat to logstash](https://discuss.elastic.co/t/k8s-filebeat-to-logstash/220923)

<div class="topic-metadata">

**Author:** [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Replies:** 2\
**Last updated:** [February 27, 2020, 1:50pm UTC](https://discuss.elastic.co/t/k8s-filebeat-to-logstash/220923 "2020-02-27T13:50:09Z")

</div>

By referring the file-beat yml, Link K8s sending logs to elastic search directly, Is it possible to send to log stash ? The main problem I can control the logs from logstash than in the elastic search. Also i can send t…

---

## [Metricbeat and RabbitMQ](https://discuss.elastic.co/t/metricbeat-and-rabbitmq/220812)

<div class="topic-metadata">

**Author:** [@tennaen](https://discuss.elastic.co/u/tennaen)\
**Replies:** 15\
**Last updated:** [February 27, 2020, 12:49pm UTC](https://discuss.elastic.co/t/metricbeat-and-rabbitmq/220812 "2020-02-27T12:49:19Z")

</div>

I've set up rabbitmq monitoring with Metricbeat. And this is what i have in logs: error in mapping: error applying schema: 22 errors: key mnesia\_disk\_tx\_countnot found; keymnesia\_ram\_tx\_countnot found; keygc\_bytes\_recla…

---

## [Metricbeat dosen\`t shows in kibana\\Infrastructure after deleting index metricbeat-7.3.1](https://discuss.elastic.co/t/metricbeat-dosen-t-shows-in-kibana-infrastructure-after-deleting-index-metricbeat-7-3-1/221056)

<div class="topic-metadata">

**Author:** [@kvaga](https://discuss.elastic.co/u/kvaga)\
**Replies:** 4\
**Last updated:** [February 27, 2020, 10:35am UTC](https://discuss.elastic.co/t/metricbeat-dosen-t-shows-in-kibana-infrastructure-after-deleting-index-metricbeat-7-3-1/221056 "2020-02-27T10:35:21Z")

</div>

ELK version 7.3.1 some time ago I\`m setup ELK version 7.3 (on one server) and metricbeats (metricbeat version 7.3.1 ) on a few othres servers, all work fine, and kibana\\Infrastructure shows CPU\\Memory and other metrics …

---

## [Getting the logs in filebeat log but not in kibana](https://discuss.elastic.co/t/getting-the-logs-in-filebeat-log-but-not-in-kibana/221177)

<div class="topic-metadata">

**Author:** [@HimanshiM](https://discuss.elastic.co/u/HimanshiM)\
**Replies:** 2\
**Last updated:** [February 27, 2020, 9:47am UTC](https://discuss.elastic.co/t/getting-the-logs-in-filebeat-log-but-not-in-kibana/221177 "2020-02-27T09:47:40Z")

</div>

Hi, Somedays back I was getting the logs in kibana. Then since two days the logs are getting into filebeat logs but I could not see them on Kibana although I have not made any changes in any file. Please help me as soo…

---

## [Filebeat 7.6.0 oss can't work with AWS Elasticsearch Service because it tries to access xpack](https://discuss.elastic.co/t/filebeat-7-6-0-oss-cant-work-with-aws-elasticsearch-service-because-it-tries-to-access-xpack/221189)

<div class="topic-metadata">

**Author:** [@Vlad\_Lukyanov](https://discuss.elastic.co/u/Vlad_Lukyanov)\
**Replies:** 0\
**Last updated:** [February 27, 2020, 9:21am UTC](https://discuss.elastic.co/t/filebeat-7-6-0-oss-cant-work-with-aws-elasticsearch-service-because-it-tries-to-access-xpack/221189 "2020-02-27T09:21:36Z")

</div>

Have AWS ES instance open to world AWS EC2 instance for testing FileBeat OSS 7.6.0 installed from OSS-7.x Debian repo on 'filebeat setup -e --template' Got 2020-02-27T09:06:00.826Z INFO elasticsearch/client.go:757 A…

---

## [Use a dynamic index name with ILM](https://discuss.elastic.co/t/use-a-dynamic-index-name-with-ilm/221187)

<div class="topic-metadata">

**Author:** [@lockhaty](https://discuss.elastic.co/u/lockhaty)\
**Replies:** 0\
**Last updated:** [February 27, 2020, 9:19am UTC](https://discuss.elastic.co/t/use-a-dynamic-index-name-with-ilm/221187 "2020-02-27T09:19:14Z")

</div>

I am trying to use Functionbeats for the first time and would like to know if it is possible to have the index name dynamically set based on the event payload? I have tried: setup.ilm.enabled: auto setup.ilm.rollover…

---

## [How to lowercase a field for creating index in filebeat?](https://discuss.elastic.co/t/how-to-lowercase-a-field-for-creating-index-in-filebeat/221146)

<div class="topic-metadata">

**Author:** [@aksroh](https://discuss.elastic.co/u/aksroh)\
**Replies:** 1\
**Last updated:** [February 27, 2020, 9:07am UTC](https://discuss.elastic.co/t/how-to-lowercase-a-field-for-creating-index-in-filebeat/221146 "2020-02-27T09:07:26Z")

</div>

I am using index template to create dynamic indices, setup.ilm.enabled: false setup.template.enabled: true setup.template.name: "testing" setup.template.pattern: "testing-\*" setup.template.overwrite: true output.elasti…

---

## [Metricbeat data differs greatly from Elasticsearch Endpoint](https://discuss.elastic.co/t/metricbeat-data-differs-greatly-from-elasticsearch-endpoint/220327)

<div class="topic-metadata">

**Author:** [@Mattness](https://discuss.elastic.co/u/Mattness)\
**Replies:** 2\
**Last updated:** [February 27, 2020, 8:27am UTC](https://discuss.elastic.co/t/metricbeat-data-differs-greatly-from-elasticsearch-endpoint/220327 "2020-02-27T08:27:36Z")

</div>

So I wanted to build some dashboards with metric data about my elasticsearch instance. From the endpoint Get /nodes/\_stats I get all the data I need. With the metricset "node\_stats" from the metricbeat module "elastics…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=270)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=272)
