# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=273

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 274

---

## [Winlogbeat sends not all eventlogs](https://discuss.elastic.co/t/winlogbeat-sends-not-all-eventlogs/220584)

<div class="topic-metadata">

**Author:** [@Marcel\_Palme](https://discuss.elastic.co/u/Marcel_Palme)\
**Replies:** 1\
**Last updated:** [February 25, 2020, 6:04am UTC](https://discuss.elastic.co/t/winlogbeat-sends-not-all-eventlogs/220584 "2020-02-25T06:04:48Z")

</div>

Hi, since I upgrade to 7.6.0 (Kibana, Elasticsearch, Winlogbeat) I get from my Domaincontroller not all log's. I use the default config from Winlogbeat (winlogbeat.yml) I only change my elasticsearchhost i have no idea…

---

## [Using regex in dissect tokenizer](https://discuss.elastic.co/t/using-regex-in-dissect-tokenizer/220773)

<div class="topic-metadata">

**Author:** [@Zhenshi\_Zhou](https://discuss.elastic.co/u/Zhenshi_Zhou)\
**Replies:** 0\
**Last updated:** [February 25, 2020, 5:47am UTC](https://discuss.elastic.co/t/using-regex-in-dissect-tokenizer/220773 "2020-02-25T05:47:41Z")

</div>

Hi, I'm using tokenizer to specify each field in log file, comma as the seperator. However, for one field, it sometimes contains quotes. For instance, the line is like: other filed,hello,other field. Filebeat will deal…

---

## [Heartbeat 7.6 autodiscover](https://discuss.elastic.co/t/heartbeat-7-6-autodiscover/220687)

<div class="topic-metadata">

**Author:** [@akrzos](https://discuss.elastic.co/u/akrzos)\
**Replies:** 3\
**Last updated:** [February 25, 2020, 4:20am UTC](https://discuss.elastic.co/t/heartbeat-7-6-autodiscover/220687 "2020-02-25T04:20:01Z")

</div>

I am trying out Heartbeat 7.6 and still can't seem to get the autodiscover to discover nodes. The documentation is difficult to understand at best, can anyone help point me in the right direction? My config is: heartb…

---

## [GenerateCustomBeat](https://discuss.elastic.co/t/generatecustombeat/219059)

<div class="topic-metadata">

**Author:** [@DWbank](https://discuss.elastic.co/u/DWbank)\
**Replies:** 1\
**Last updated:** [February 25, 2020, 2:40am UTC](https://discuss.elastic.co/t/generatecustombeat/219059 "2020-02-25T02:40:00Z")

</div>

I have been trying to figure out how to set up dev environment for a few days now. The documentation is to say the least confusing. When I get to the point mage GenerateCustomBeat I get this error No .go files marked…

---

## [How are you getting Palo Alto VPN Authentication Failures for SAML based logins?](https://discuss.elastic.co/t/how-are-you-getting-palo-alto-vpn-authentication-failures-for-saml-based-logins/220721)

<div class="topic-metadata">

**Author:** [@dsdameron](https://discuss.elastic.co/u/dsdameron)\
**Replies:** 0\
**Last updated:** [February 24, 2020, 8:26pm UTC](https://discuss.elastic.co/t/how-are-you-getting-palo-alto-vpn-authentication-failures-for-saml-based-logins/220721 "2020-02-24T20:26:50Z")

</div>

Our org is using a Palo Alto Firewall/VPN and the Global Protect client. Our client's are using SAML based logins to authenticate to this VPN. We are pulling in Palo Alto's system log (which contains VPN authenticatio…

---

## [Data path already locked by another beat](https://discuss.elastic.co/t/data-path-already-locked-by-another-beat/219852)

<div class="topic-metadata">

**Author:** [@yodog](https://discuss.elastic.co/u/yodog)\
**Replies:** 5\
**Last updated:** [February 24, 2020, 7:09pm UTC](https://discuss.elastic.co/t/data-path-already-locked-by-another-beat/219852 "2020-02-24T19:09:00Z")

</div>

after upgrading from 7.5.1 to 7.6.0 my filebeat breaks with error data path already locked by another beat i have two instances of filebeat running for a very long time, one reading a specific set of files and sending t…

---

## [Output Not Match Configuration in process.include\_top\_n.by\_memory](https://discuss.elastic.co/t/output-not-match-configuration-in-process-include-top-n-by-memory/220710)

<div class="topic-metadata">

**Author:** [@Yiw](https://discuss.elastic.co/u/Yiw)\
**Replies:** 0\
**Last updated:** [February 24, 2020, 6:41pm UTC](https://discuss.elastic.co/t/output-not-match-configuration-in-process-include-top-n-by-memory/220710 "2020-02-24T18:41:15Z")

</div>

Hi all, I was trying to get top 5 processes by memory and cpu. I configured the module.d etc, but the output is sometimes correct, sometimes only top 5 by cpu and top 4 by mem. It's so weird. Not sure is there anyone en…

---

## [Filebeat index pattern is not auto detected by Kibana](https://discuss.elastic.co/t/filebeat-index-pattern-is-not-auto-detected-by-kibana/219999)

<div class="topic-metadata">

**Author:** [@Deepa1](https://discuss.elastic.co/u/Deepa1)\
**Replies:** 3\
**Last updated:** [February 24, 2020, 4:30pm UTC](https://discuss.elastic.co/t/filebeat-index-pattern-is-not-auto-detected-by-kibana/219999 "2020-02-24T16:30:46Z")

</div>

Hi , I have installed the filebeat my server,but in kibana the Index pattern is not auto detected.

---

## [FileBeat Sends the same file content again and again to logstash](https://discuss.elastic.co/t/filebeat-sends-the-same-file-content-again-and-again-to-logstash/220681)

<div class="topic-metadata">

**Author:** [@yassine](https://discuss.elastic.co/u/yassine)\
**Replies:** 2\
**Last updated:** [February 24, 2020, 3:48pm UTC](https://discuss.elastic.co/t/filebeat-sends-the-same-file-content-again-and-again-to-logstash/220681 "2020-02-24T15:48:35Z")

</div>

Hi, I'm a beginner in filabeat. the filbeat resend the already sent data again to the same index. (every 10 s) How can I solve this problem, please? any suggestions plzzz? version filebeat: 7.5.2- myconf is fileb…

---

## [@timestamp date different from index name date](https://discuss.elastic.co/t/timestamp-date-different-from-index-name-date/219615)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 6\
**Last updated:** [February 24, 2020, 3:19pm UTC](https://discuss.elastic.co/t/timestamp-date-different-from-index-name-date/219615 "2020-02-24T15:19:00Z")

</div>

I am getting different dates in @timestamp field and \_index name field as shown in picture My filebeat.yml output as below Please help, Thanks

---

## [Understanding link between Heartbeat and Metrics](https://discuss.elastic.co/t/understanding-link-between-heartbeat-and-metrics/220454)

<div class="topic-metadata">

**Author:** [@sroseman](https://discuss.elastic.co/u/sroseman)\
**Replies:** 1\
**Last updated:** [February 24, 2020, 3:08pm UTC](https://discuss.elastic.co/t/understanding-link-between-heartbeat-and-metrics/220454 "2020-02-24T15:08:29Z")

</div>

We set up heartbeat on a separate box in order to ping our various websites. That data all shows within the Uptime tab in Kibana. However, when I click "Show host metrics" for a certain row, it doesn't show anything on t…

---

## [Parse custom logs in Elastic cloud](https://discuss.elastic.co/t/parse-custom-logs-in-elastic-cloud/219044)

<div class="topic-metadata">

**Author:** [@arkaitzgarro](https://discuss.elastic.co/u/arkaitzgarro)\
**Replies:** 1\
**Last updated:** [February 24, 2020, 2:46pm UTC](https://discuss.elastic.co/t/parse-custom-logs-in-elastic-cloud/219044 "2020-02-24T14:46:37Z")

</div>

I'm sending custom logs with filebeat to Elasticsearch, but I would like to be able to parse them and extract some information. I see the document on Kibana, but the message is the whole log entry: \[2020-02-12 16:26:23\]…

---

## [Filebeat multiple path and configs](https://discuss.elastic.co/t/filebeat-multiple-path-and-configs/219230)

<div class="topic-metadata">

**Author:** [@toms130](https://discuss.elastic.co/u/toms130)\
**Replies:** 2\
**Last updated:** [February 24, 2020, 1:29pm UTC](https://discuss.elastic.co/t/filebeat-multiple-path-and-configs/219230 "2020-02-24T13:29:14Z")

</div>

Hi, I use filebeat for catching logs from kubernetes. Actual config is - type: container paths: - /var/log/containers/\*.log I want to use a multiline config for some of my logs (/var/log/containers/celery-\*.…

---

## [Adding custom field to output](https://discuss.elastic.co/t/adding-custom-field-to-output/220497)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 3\
**Last updated:** [February 24, 2020, 11:48am UTC](https://discuss.elastic.co/t/adding-custom-field-to-output/220497 "2020-02-24T11:48:28Z")

</div>

Im wondering if this is still accurate. Im attempting to add some fields to 'system.yml' (as a test) as follows: (note that indents are being lost) add\_fields: target: fields: name: myproject id: '574734885120952…

---

## [Not able to see live reloading in metricbeat dashboard](https://discuss.elastic.co/t/not-able-to-see-live-reloading-in-metricbeat-dashboard/220341)

<div class="topic-metadata">

**Author:** [@aman97](https://discuss.elastic.co/u/aman97)\
**Replies:** 2\
**Last updated:** [February 24, 2020, 11:41am UTC](https://discuss.elastic.co/t/not-able-to-see-live-reloading-in-metricbeat-dashboard/220341 "2020-02-24T11:41:27Z")

</div>

Hi, I am not able to see live reloading in a custom metricbeat dashboard. I configured my metricbeat.yml file as per metric beat documentation

---

## [Unable to GenerateCustomBeat with Git Bash on Windows](https://discuss.elastic.co/t/unable-to-generatecustombeat-with-git-bash-on-windows/215974)

<div class="topic-metadata">

**Author:** [@Mint-M](https://discuss.elastic.co/u/Mint-M)\
**Replies:** 3\
**Last updated:** [February 24, 2020, 11:23am UTC](https://discuss.elastic.co/t/unable-to-generatecustombeat-with-git-bash-on-windows/215974 "2020-02-24T11:23:29Z")

</div>

I have followed all steps of the official guide bellow to generate a custom beat. https://www.elastic.co/guide/en/beats/devguide/current/newbeat-generate.html#newbeat-generate It works on CentOS8 ,however I met a few p…

---

## [Metricbeat prometheus debug logging](https://discuss.elastic.co/t/metricbeat-prometheus-debug-logging/220387)

<div class="topic-metadata">

**Author:** [@chrmrn](https://discuss.elastic.co/u/chrmrn)\
**Replies:** 2\
**Last updated:** [February 24, 2020, 10:14am UTC](https://discuss.elastic.co/t/metricbeat-prometheus-debug-logging/220387 "2020-02-24T10:14:43Z")

</div>

I've gotten an autodiscover metricbeat for prometheus working (scraping a pod in k8s), but I keep getting the error: unable to decode response from prometheus endpoint: decoding of metric family failed: text format pars…

---

## [Enable dynamic index for metricbeat index](https://discuss.elastic.co/t/enable-dynamic-index-for-metricbeat-index/216802)

<div class="topic-metadata">

**Author:** [@kasim123](https://discuss.elastic.co/u/kasim123)\
**Replies:** 4\
**Last updated:** [February 24, 2020, 10:01am UTC](https://discuss.elastic.co/t/enable-dynamic-index-for-metricbeat-index/216802 "2020-02-24T10:01:47Z")

</div>

I have implemented EFK stack using helm chart and after few days I installed metric beat in kuberentes cluster, right now we are getting metric and it is visible in kibana UI. However, we noticed only one metricbeat inde…

---

## [UTC offset isnt honor by ingest processor?](https://discuss.elastic.co/t/utc-offset-isnt-honor-by-ingest-processor/220604)

<div class="topic-metadata">

**Author:** [@Martin\_Ostlund](https://discuss.elastic.co/u/Martin_Ostlund)\
**Replies:** 1\
**Last updated:** [February 24, 2020, 9:55am UTC](https://discuss.elastic.co/t/utc-offset-isnt-honor-by-ingest-processor/220604 "2020-02-24T09:55:10Z")

</div>

Hello, After upgrading the ELK stack to 7.6.0 (from elastic APT repos) my logs are displayed with incorrect @timestamp in Kibana. Im using the vanilla apache module that ships with filebeat. The Apache access logs are…

---

## [Can someone share the metricbeat config file to push metric beat data of multiple machine into 1 Elasticsearch instance while not using Elastic Cloud](https://discuss.elastic.co/t/can-someone-share-the-metricbeat-config-file-to-push-metric-beat-data-of-multiple-machine-into-1-elasticsearch-instance-while-not-using-elastic-cloud/220583)

<div class="topic-metadata">

**Author:** [@aman97](https://discuss.elastic.co/u/aman97)\
**Replies:** 2\
**Last updated:** [February 24, 2020, 9:39am UTC](https://discuss.elastic.co/t/can-someone-share-the-metricbeat-config-file-to-push-metric-beat-data-of-multiple-machine-into-1-elasticsearch-instance-while-not-using-elastic-cloud/220583 "2020-02-24T09:39:39Z")

</div>

Hi All, I want to config metricbeat file to push metric beat data of multiple machines into 1 Elasticsearch instance while not using Elastic Cloud. Can someone share the metricbeat config file for the same?

---

## [Beats Central Management Questions](https://discuss.elastic.co/t/beats-central-management-questions/204123)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 2\
**Last updated:** [February 24, 2020, 9:38am UTC](https://discuss.elastic.co/t/beats-central-management-questions/204123 "2020-02-24T09:38:47Z")

</div>

Easy questions that I have not been able to determine the answer to yet. Does Beats Central Management support other beats besides FileBeat and MetricBeat because those are my only two options when I click Enroll Beats…

---

## [Regarding community\_id](https://discuss.elastic.co/t/regarding-community-id/220573)

<div class="topic-metadata">

**Author:** [@Bhavani\_Ananth](https://discuss.elastic.co/u/Bhavani_Ananth)\
**Replies:** 0\
**Last updated:** [February 24, 2020, 5:19am UTC](https://discuss.elastic.co/t/regarding-community-id/220573 "2020-02-24T05:19:59Z")

</div>

Hello Team, It would be good if you could elaborate more on the community id in packetbeat. We have a use case wherein we need to establish vertical correlation amongst the CI elements - say NIC, Storage, Router, Switc…

---

## [Cannot load dashboard](https://discuss.elastic.co/t/cannot-load-dashboard/219915)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 3\
**Last updated:** [February 24, 2020, 2:53am UTC](https://discuss.elastic.co/t/cannot-load-dashboard/219915 "2020-02-24T02:53:23Z")

</div>

Hi I have ES installed and run on Server A, while Packetbeat is installed on Server B. Which port I need to open to allows connection between these servers ? Kibana port is opened, ES 9200 is opened. Error on Packetbe…

---

## [Filebeat: daemonset mounting /var/lib/kubelet/pods not seeing new pvc data](https://discuss.elastic.co/t/filebeat-daemonset-mounting-var-lib-kubelet-pods-not-seeing-new-pvc-data/220244)

<div class="topic-metadata">

**Author:** [@Patrick\_Lieberg](https://discuss.elastic.co/u/Patrick_Lieberg)\
**Replies:** 1\
**Last updated:** [February 23, 2020, 9:35pm UTC](https://discuss.elastic.co/t/filebeat-daemonset-mounting-var-lib-kubelet-pods-not-seeing-new-pvc-data/220244 "2020-02-23T21:35:49Z")

</div>

We have a filebeat daemonset in our kubernetes cluster and we have mount the /var/lib/kubelet/pods hostpath from the host node so we can collect log data stored on pvc's. When a new application pod comes online and a n…

---

## [Filebeat docker help with creating the container](https://discuss.elastic.co/t/filebeat-docker-help-with-creating-the-container/219760)

<div class="topic-metadata">

**Author:** [@zebulyon](https://discuss.elastic.co/u/zebulyon)\
**Replies:** 5\
**Last updated:** [February 23, 2020, 5:20pm UTC](https://discuss.elastic.co/t/filebeat-docker-help-with-creating-the-container/219760 "2020-02-23T17:20:35Z")

</div>

Hello, complete beginner with the ELK-stack here so this might be really trivial. I'm using the docker image docker.elastic.co/beats/filebeat:7.6.0 as well as the other corresponding images of the ELK-stack all of versi…

---

## [Metricbeat stops logstash monitoring](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146)

<div class="topic-metadata">

**Author:** [@tennaen](https://discuss.elastic.co/u/tennaen)\
**Replies:** 6\
**Last updated:** [February 23, 2020, 4:08am UTC](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146 "2020-02-23T04:08:15Z")

</div>

I have running metricbeat, to monitor my ELK. It works great for Kibana and Elasticsearch, but when it comes to Logstash, it stops showing status. Starts working only after metricbeat restart. Logstash version: 7.5.2 M…

---

## [Append values to array with filebeat processors](https://discuss.elastic.co/t/append-values-to-array-with-filebeat-processors/220452)

<div class="topic-metadata">

**Author:** [@rout39574](https://discuss.elastic.co/u/rout39574)\
**Replies:** 1\
**Last updated:** [February 21, 2020, 11:00pm UTC](https://discuss.elastic.co/t/append-values-to-array-with-filebeat-processors/220452 "2020-02-21T23:00:16Z")

</div>

I would like to incrementally set multivalue fields in a succession of processor statements. What I want to do is analogous to a series of add\_tags processors with various conditions; but I don't want to pollute the '…

---

## [Apache module](https://discuss.elastic.co/t/apache-module/220455)

<div class="topic-metadata">

**Author:** [@sroseman](https://discuss.elastic.co/u/sroseman)\
**Replies:** 1\
**Last updated:** [February 21, 2020, 10:49pm UTC](https://discuss.elastic.co/t/apache-module/220455 "2020-02-21T22:49:45Z")

</div>

I've enabled the apache module, but in metricbeat -e, I see the following error. //Error fetching data for metricset apache.status: error fetching data: error making http request: Get http://localhost:8080/server-status…

---

## [How to delete .monitoring-es-7-mb-\* indices automatically after period of time?](https://discuss.elastic.co/t/how-to-delete-monitoring-es-7-mb-indices-automatically-after-period-of-time/220194)

<div class="topic-metadata">

**Author:** [@elk51211](https://discuss.elastic.co/u/elk51211)\
**Replies:** 1\
**Last updated:** [February 21, 2020, 10:46pm UTC](https://discuss.elastic.co/t/how-to-delete-monitoring-es-7-mb-indices-automatically-after-period-of-time/220194 "2020-02-21T22:46:10Z")

</div>

How to delete .monitoring-es-7-mb-\* indices automatically after period of time? Is there a way to assign a index lifecycle policy to the monitoring in the metricbeat.yaml file?

---

## [Can we have : an agent which publish system metrics from 2 servers](https://discuss.elastic.co/t/can-we-have-an-agent-which-publish-system-metrics-from-2-servers/219147)

<div class="topic-metadata">

**Author:** [@Samerd](https://discuss.elastic.co/u/Samerd)\
**Replies:** 1\
**Last updated:** [February 21, 2020, 7:35pm UTC](https://discuss.elastic.co/t/can-we-have-an-agent-which-publish-system-metrics-from-2-servers/219147 "2020-02-21T19:35:56Z")

</div>

Hi, is there a way to make an agent to send metrics for another 2 servers (system metrics)- the 2 servers send the metrics to the agent , and the agent will publish the metrics .

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=272)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=274)
