# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=272

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 273

---

## [Metricbeat Service can't Start Running](https://discuss.elastic.co/t/metricbeat-service-cant-start-running/219919)

<div class="topic-metadata">

**Author:** [@Faiq\_FK](https://discuss.elastic.co/u/Faiq_FK)\
**Replies:** 3\
**Last updated:** [February 27, 2020, 8:25am UTC](https://discuss.elastic.co/t/metricbeat-service-cant-start-running/219919 "2020-02-27T08:25:18Z")

</div>

Hello, im in a project that need to install kibana-elasticsearch-metricbeat now i already install all of that, but after i install metricbeat and configure the yml file i cant start the metricbeat serive. This is my Po…

---

## [\[Auditbeat 7.6 - 7.2\] Processor not working](https://discuss.elastic.co/t/auditbeat-7-6-7-2-processor-not-working/220982)

<div class="topic-metadata">

**Author:** [@tienbmaa](https://discuss.elastic.co/u/tienbmaa)\
**Replies:** 0\
**Last updated:** [February 26, 2020, 8:47am UTC](https://discuss.elastic.co/t/auditbeat-7-6-7-2-processor-not-working/220982 "2020-02-26T08:47:17Z")

</div>

Hi all, I have problem about auditbeat processor. I have entry log, I config processor drop\_event when user.name: "root" but system not woking (event not droped): Processor Config: processors: - drop\_event: when…

---

## [Logstash parsing broken after upgrading from filebeat 5.6 to 7.6. Appears to be an issue with logs not getting tagged correctly](https://discuss.elastic.co/t/logstash-parsing-broken-after-upgrading-from-filebeat-5-6-to-7-6-appears-to-be-an-issue-with-logs-not-getting-tagged-correctly/221119)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 1\
**Last updated:** [February 26, 2020, 10:51pm UTC](https://discuss.elastic.co/t/logstash-parsing-broken-after-upgrading-from-filebeat-5-6-to-7-6-appears-to-be-an-issue-with-logs-not-getting-tagged-correctly/221119 "2020-02-26T22:51:41Z")

</div>

We recently upgraded our ELK stack and I realized we were still using filebeats 5.6 on our servers for log shipping. I'm testing out upgrading to 7.6 on a dev server. The upgrade itself went fine and it is still shippi…

---

## [Ship Auditbeat logs directly to Elastic Cloud (MacOS)](https://discuss.elastic.co/t/ship-auditbeat-logs-directly-to-elastic-cloud-macos/220734)

<div class="topic-metadata">

**Author:** [@AaronWF](https://discuss.elastic.co/u/AaronWF)\
**Replies:** 1\
**Last updated:** [February 26, 2020, 9:57pm UTC](https://discuss.elastic.co/t/ship-auditbeat-logs-directly-to-elastic-cloud-macos/220734 "2020-02-26T21:57:30Z")

</div>

I have signed up for an Elastic Cloud trial and I am trying to ship them directly to my Cloud ID instance. However, I am not sure where the error is, I have been checking the logs and no logs appear when it fails to star…

---

## [Winlogbeat event.type has 0 records](https://discuss.elastic.co/t/winlogbeat-event-type-has-0-records/220920)

<div class="topic-metadata">

**Author:** [@SeekAndDestroy](https://discuss.elastic.co/u/SeekAndDestroy)\
**Replies:** 0\
**Last updated:** [February 25, 2020, 8:59pm UTC](https://discuss.elastic.co/t/winlogbeat-event-type-has-0-records/220920 "2020-02-25T20:59:02Z")

</div>

I'm trying to get familiar with the SIEM. When I look at "Authentications" in the Hosts section, it is empty. If I look at the request, it appears to be looking for event.type: "aggregations": { "eventActionGroup": { …

---

## [Metricbeat on Windows isn't aware of processor groups](https://discuss.elastic.co/t/metricbeat-on-windows-isnt-aware-of-processor-groups/221106)

<div class="topic-metadata">

**Author:** [@dannygoulder](https://discuss.elastic.co/u/dannygoulder)\
**Replies:** 0\
**Last updated:** [February 26, 2020, 8:11pm UTC](https://discuss.elastic.co/t/metricbeat-on-windows-isnt-aware-of-processor-groups/221106 "2020-02-26T20:11:57Z")

</div>

On a Windows 2008R2 or 7 system (or later) with \>64 and \<=128 logical CPUs, Metricbeat only sees half the CPUs on the system. This is because of Processor Groups. Is there any plan for Metricbeat to support processor g…

---

## [Is there a metricset within metricbeat that provides numastats?](https://discuss.elastic.co/t/is-there-a-metricset-within-metricbeat-that-provides-numastats/221098)

<div class="topic-metadata">

**Author:** [@slmingol](https://discuss.elastic.co/u/slmingol)\
**Replies:** 0\
**Last updated:** [February 26, 2020, 7:35pm UTC](https://discuss.elastic.co/t/is-there-a-metricset-within-metricbeat-that-provides-numastats/221098 "2020-02-26T19:35:44Z")

</div>

Was curious if there's a metricset that provides per PID numastats or at the very least a top five offender PIDs which are unevenly spanning numa nodes within a system using metricbeat?

---

## [Metricbeat kafka module with jaas authentification](https://discuss.elastic.co/t/metricbeat-kafka-module-with-jaas-authentification/221050)

<div class="topic-metadata">

**Author:** [@Khaled\_Chaoued](https://discuss.elastic.co/u/Khaled_Chaoued)\
**Replies:** 2\
**Last updated:** [February 26, 2020, 2:57pm UTC](https://discuss.elastic.co/t/metricbeat-kafka-module-with-jaas-authentification/221050 "2020-02-26T14:57:21Z")

</div>

Hello all, I have active Metricbeat kafka Module and configurer file /module.d/kafka.yml and metricbeat.yml. but i want to add configuration to this file, to permit authentification using Jaas. It's possible to add ja…

---

## [Monitoring Cluster not showing data properly](https://discuss.elastic.co/t/monitoring-cluster-not-showing-data-properly/219566)

<div class="topic-metadata">

**Author:** [@Vipul\_Sharma](https://discuss.elastic.co/u/Vipul_Sharma)\
**Replies:** 4\
**Last updated:** [February 20, 2020, 6:53am UTC](https://discuss.elastic.co/t/monitoring-cluster-not-showing-data-properly/219566 "2020-02-20T06:53:12Z")

</div>

Hello everyone, I have installed metricBeat on all our production servers which collecting the data in other monitoring elasticsearch. Everything is working fine up to this point all the indexes are being created on mo…

---

## [Openshift 4 Compatibility](https://discuss.elastic.co/t/openshift-4-compatibility/220987)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [February 26, 2020, 10:51am UTC](https://discuss.elastic.co/t/openshift-4-compatibility/220987 "2020-02-26T10:51:46Z")

</div>

Hello, Can someone confirm Filebeat (and other Beats) work with Openshift 4? Grtz Willem

---

## [7.6.0 on Windows: Netflow and Syslog are not being captured by Filebeat](https://discuss.elastic.co/t/7-6-0-on-windows-netflow-and-syslog-are-not-being-captured-by-filebeat/219736)

<div class="topic-metadata">

**Author:** [@c1jt](https://discuss.elastic.co/u/c1jt)\
**Replies:** 5\
**Last updated:** [February 26, 2020, 10:14am UTC](https://discuss.elastic.co/t/7-6-0-on-windows-netflow-and-syslog-are-not-being-captured-by-filebeat/219736 "2020-02-26T10:14:21Z")

</div>

Hello! I'm looking for help on a small Docker-ised ELK instance, my filebeat inplementation isn't recognising any netflow packets from the firewalls. I have two firewalls passing Netflow v5 (Sophos XG) and v9 (Cisco ASA…

---

## [Filebeat module netflow doesn't exist](https://discuss.elastic.co/t/filebeat-module-netflow-doesnt-exist/220774)

<div class="topic-metadata">

**Author:** [@bunico](https://discuss.elastic.co/u/bunico)\
**Replies:** 4\
**Last updated:** [February 26, 2020, 9:42am UTC](https://discuss.elastic.co/t/filebeat-module-netflow-doesnt-exist/220774 "2020-02-26T09:42:53Z")

</div>

I am trying to enable netflow module on my VM but I can't seem to able to do so. I have installed the whole ELK stack with the latest versions available. Does anyone have any idea how can I enable this module or how c…

---

## [Filebeat MISP module: ECS mapping mistakenly removed?](https://discuss.elastic.co/t/filebeat-misp-module-ecs-mapping-mistakenly-removed/220589)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 3\
**Last updated:** [February 26, 2020, 9:32am UTC](https://discuss.elastic.co/t/filebeat-misp-module-ecs-mapping-mistakenly-removed/220589 "2020-02-26T09:32:26Z")

</div>

Hey people, In a commit from november, the ability to map domain indicators of compromise to url.domain / dns.question.name was removed from the MISP module. See line 59 in the old file: https://github.com/elastic/beats…

---

## [Receiving onFilteredOut error while starting filebeat](https://discuss.elastic.co/t/receiving-onfilteredout-error-while-starting-filebeat/220992)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 0\
**Last updated:** [February 26, 2020, 9:26am UTC](https://discuss.elastic.co/t/receiving-onfilteredout-error-while-starting-filebeat/220992 "2020-02-26T09:26:01Z")

</div>

Hello All , receiving below error after i start filebeat in the server and data is not getting processed to logstash. Anybody have idea on the same please ? Pipeline client receives callback 'onFilteredOut' for event: …

---

## [Duplicate logs with ingest pipeline](https://discuss.elastic.co/t/duplicate-logs-with-ingest-pipeline/220647)

<div class="topic-metadata">

**Author:** [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Replies:** 2\
**Last updated:** [February 26, 2020, 9:16am UTC](https://discuss.elastic.co/t/duplicate-logs-with-ingest-pipeline/220647 "2020-02-26T09:16:03Z")

</div>

I have a EFK cluster with version 6.8.2 and everything was running smoothly until I had a requirement to create specific type of index (project-large\_payload-$namespace) based on a field length. For this, I used script\_…

---

## [Helm chart w/autodiscover config issue](https://discuss.elastic.co/t/helm-chart-w-autodiscover-config-issue/220736)

<div class="topic-metadata">

**Author:** [@croederLGP](https://discuss.elastic.co/u/croederLGP)\
**Replies:** 1\
**Last updated:** [February 26, 2020, 9:09am UTC](https://discuss.elastic.co/t/helm-chart-w-autodiscover-config-issue/220736 "2020-02-26T09:09:36Z")

</div>

I have multiple K8s pods that I want to monitor with a filebeat daemon. I want to annotate some pods using "json\_logs: true" to have filebeat apply the json\_decode module to the message field before shipping the data to …

---

## [Issue with getting information on process](https://discuss.elastic.co/t/issue-with-getting-information-on-process/220559)

<div class="topic-metadata">

**Author:** [@Faten](https://discuss.elastic.co/u/Faten)\
**Replies:** 4\
**Last updated:** [February 26, 2020, 8:45am UTC](https://discuss.elastic.co/t/issue-with-getting-information-on-process/220559 "2020-02-26T08:45:50Z")

</div>

Hi, We are collecting data every 5 sec from the system and Postgres modules that include processes, every 1 min we will get an empty row of the process as the following: ''' :"2020-02-19T17: 28: 29.721Z","@metadata":…

---

## [Importing example dashboard](https://discuss.elastic.co/t/importing-example-dashboard/220917)

<div class="topic-metadata">

**Author:** [@vijay\_kaali](https://discuss.elastic.co/u/vijay_kaali)\
**Replies:** 3\
**Last updated:** [February 26, 2020, 8:39am UTC](https://discuss.elastic.co/t/importing-example-dashboard/220917 "2020-02-26T08:39:37Z")

</div>

i am using 6.5.2 elasticsearch and trying to import metric beat 6.2.4 sample dashboard kibana/6/dashboard/Metricbeat-system-overview.json but it throws "saved objects file format is invalid and cannot be imported" My …

---

## [Metricbeat Alerts](https://discuss.elastic.co/t/metricbeat-alerts/220959)

<div class="topic-metadata">

**Author:** [@michealCT](https://discuss.elastic.co/u/michealCT)\
**Replies:** 0\
**Last updated:** [February 26, 2020, 6:14am UTC](https://discuss.elastic.co/t/metricbeat-alerts/220959 "2020-02-26T06:14:43Z")

</div>

Hi I m not able to setup the proper alerting for CPU metric Please help me out.

---

## [No data has been received from Heartbeat yet](https://discuss.elastic.co/t/no-data-has-been-received-from-heartbeat-yet/220448)

<div class="topic-metadata">

**Author:** [@IMagalashvili](https://discuss.elastic.co/u/IMagalashvili)\
**Replies:** 2\
**Last updated:** [February 26, 2020, 5:58am UTC](https://discuss.elastic.co/t/no-data-has-been-received-from-heartbeat-yet/220448 "2020-02-26T05:58:33Z")

</div>

Hello, could you help me. Version 7.6.0, CentOS 7. Doesn't work Uptime Monitor. ~\]$ sudo heartbeat test config Config OK ~\]$ sudo heartbeat test output elasticsearch: http://host\_ip:9200... parse url... OK conne…

---

## [Harvester in loop while parsing JSON data](https://discuss.elastic.co/t/harvester-in-loop-while-parsing-json-data/220612)

<div class="topic-metadata">

**Author:** [@aksroh](https://discuss.elastic.co/u/aksroh)\
**Replies:** 6\
**Last updated:** [February 26, 2020, 4:34am UTC](https://discuss.elastic.co/t/harvester-in-loop-while-parsing-json-data/220612 "2020-02-26T04:34:30Z")

</div>

Trying to parse JSON data from file (single line JSON data), harvester is being started again and again after close\_inactive time. filebeat.yml: filebeat.inputs: - type: log enabled: true paths: - D:\\ELK\\Logs\\\*…

---

## [Compiling filebeat for ppc64 h/w using go complier - issues](https://discuss.elastic.co/t/compiling-filebeat-for-ppc64-h-w-using-go-complier-issues/219682)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 10\
**Last updated:** [February 25, 2020, 8:16pm UTC](https://discuss.elastic.co/t/compiling-filebeat-for-ppc64-h-w-using-go-complier-issues/219682 "2020-02-25T20:16:42Z")

</div>

Hi, I'm attempting to compile filebeat from source using go compiler v1.13.8 as per this document: https://www.elastic.co/guide/en/beats/devguide/7.x/beats-contributing.html However, when I run the make command - I see …

---

## [Trying to start filebeat from container](https://discuss.elastic.co/t/trying-to-start-filebeat-from-container/220664)

<div class="topic-metadata">

**Author:** [@zebulyon](https://discuss.elastic.co/u/zebulyon)\
**Replies:** 5\
**Last updated:** [February 25, 2020, 4:34pm UTC](https://discuss.elastic.co/t/trying-to-start-filebeat-from-container/220664 "2020-02-25T16:34:27Z")

</div>

Hello I am currently unable of properly starting my filebeat process from its container. My probelm is that when I try to run it filebeat will imidietly exit and give me this error response: Exiting: error loading conf…

---

## [Adding pid based matcher to add\_kubernetes\_metadata processor (PR)](https://discuss.elastic.co/t/adding-pid-based-matcher-to-add-kubernetes-metadata-processor-pr/220881)

<div class="topic-metadata">

**Author:** [@jtinkus](https://discuss.elastic.co/u/jtinkus)\
**Replies:** 0\
**Last updated:** [February 25, 2020, 3:29pm UTC](https://discuss.elastic.co/t/adding-pid-based-matcher-to-add-kubernetes-metadata-processor-pr/220881 "2020-02-25T15:29:11Z")

</div>

Hello! I'm adding new matcher for add\_kubernetes\_metadata processor. PR is here: Problem was that we had no data available in auditbeat events for matching event to right metadata from kubernetes with existing match…

---

## [Filbeat exlude or include only](https://discuss.elastic.co/t/filbeat-exlude-or-include-only/220878)

<div class="topic-metadata">

**Author:** [@armani\_ani](https://discuss.elastic.co/u/armani_ani)\
**Replies:** 0\
**Last updated:** [February 25, 2020, 3:12pm UTC](https://discuss.elastic.co/t/filbeat-exlude-or-include-only/220878 "2020-02-25T15:12:26Z")

</div>

Hi All, i have try to use filebat to ship syslog from Linux server, i use log type . I want just to ship error content on /var/log/syslog and exlucde for exaample all line that content info . My config client on fileb…

---

## [Error unpacking config data: can not convert 'string' into 'object' accessing 'output.logstash' (source:'winlogbeat.yml') accessing 'output' (source:'winlogbeat.yml')](https://discuss.elastic.co/t/error-unpacking-config-data-can-not-convert-string-into-object-accessing-output-logstash-source-winlogbeat-yml-accessing-output-source-winlogbeat-yml/220862)

<div class="topic-metadata">

**Author:** [@rizwanjavaid](https://discuss.elastic.co/u/rizwanjavaid)\
**Replies:** 0\
**Last updated:** [February 25, 2020, 1:32pm UTC](https://discuss.elastic.co/t/error-unpacking-config-data-can-not-convert-string-into-object-accessing-output-logstash-source-winlogbeat-yml-accessing-output-source-winlogbeat-yml/220862 "2020-02-25T13:32:04Z")

</div>

Hi! I am trying to configure elasticsearch,logstash and kibana on Windows 10. When i am trying to run the windows service of winogbeat, I am facing the issue ###################### Winlogbeat Configuration Example #####…

---

## [DISKIO on Windows is not working](https://discuss.elastic.co/t/diskio-on-windows-is-not-working/220785)

<div class="topic-metadata">

**Author:** [@yaroslavmamrokha](https://discuss.elastic.co/u/yaroslavmamrokha)\
**Replies:** 3\
**Last updated:** [February 25, 2020, 12:23pm UTC](https://discuss.elastic.co/t/diskio-on-windows-is-not-working/220785 "2020-02-25T12:23:06Z")

</div>

Hi Everyone, I'm using metricbeats service on Windows, and during DISKIO task, it is constantly throwing error in ioCounter, when calling DeviceIoControl function in file(metricbeat/module/system/diskio/diskstat\_windows…

---

## [Cannot create custom filebeat index](https://discuss.elastic.co/t/cannot-create-custom-filebeat-index/220833)

<div class="topic-metadata">

**Author:** [@stefdami](https://discuss.elastic.co/u/stefdami)\
**Replies:** 0\
**Last updated:** [February 25, 2020, 10:58am UTC](https://discuss.elastic.co/t/cannot-create-custom-filebeat-index/220833 "2020-02-25T10:58:41Z")

</div>

Hello guys, I have a problem creating a new custom index for filebeat. When I used the default filebeat index it ran without issues and I could see it on kibana, but when I tried to create a new one although I had creat…

---

## [Metricbeat Docker Autodiscover Not Working - ELK](https://discuss.elastic.co/t/metricbeat-docker-autodiscover-not-working-elk/219477)

<div class="topic-metadata">

**Author:** [@daz1761](https://discuss.elastic.co/u/daz1761)\
**Replies:** 2\
**Last updated:** [February 25, 2020, 8:52am UTC](https://discuss.elastic.co/t/metricbeat-docker-autodiscover-not-working-elk/219477 "2020-02-25T08:52:25Z")

</div>

I have followed the autodiscover docs and my docker container is not being discovered by the service. In order for a container to be discovered, it needs to be labeled, so in order to check docker-compose labels were wo…

---

## [Kibana doesn't update properly once filebeat is stopped for sometime](https://discuss.elastic.co/t/kibana-doesnt-update-properly-once-filebeat-is-stopped-for-sometime/220705)

<div class="topic-metadata">

**Author:** [@Pradeep\_Sanjeewa](https://discuss.elastic.co/u/Pradeep_Sanjeewa)\
**Replies:** 0\
**Last updated:** [February 24, 2020, 5:34pm UTC](https://discuss.elastic.co/t/kibana-doesnt-update-properly-once-filebeat-is-stopped-for-sometime/220705 "2020-02-24T17:34:51Z")

</div>

Hi, In my ELK setup, when filebeat is stopped for sometime, Kibana starts updating from the timestamp where the filebeat is started. No data available(under Disvover tab) for the filebeat not functioning timeframe. Once…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=271)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=273)
