# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=274

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 275

---

## [Http input on different pipeline breaks beats pipeline](https://discuss.elastic.co/t/http-input-on-different-pipeline-breaks-beats-pipeline/220416)

<div class="topic-metadata">

**Author:** [@dris](https://discuss.elastic.co/u/dris)\
**Replies:** 1\
**Last updated:** [February 21, 2020, 6:25pm UTC](https://discuss.elastic.co/t/http-input-on-different-pipeline-breaks-beats-pipeline/220416 "2020-02-21T18:25:37Z")

</div>

I have two pipelines for logstash: beats http When I only use beats, everything works fine, data comes in as it should. However, when I turn on the http pipeline, http starts fine, but beats throws this error: :excep…

---

## [FileBeat with CRI-O \[not docker\] container runtime environment on Kubernetes?](https://discuss.elastic.co/t/filebeat-with-cri-o-not-docker-container-runtime-environment-on-kubernetes/219055)

<div class="topic-metadata">

**Author:** [@vpuvvala](https://discuss.elastic.co/u/vpuvvala)\
**Replies:** 1\
**Last updated:** [February 21, 2020, 5:36pm UTC](https://discuss.elastic.co/t/filebeat-with-cri-o-not-docker-container-runtime-environment-on-kubernetes/219055 "2020-02-21T17:36:43Z")

</div>

Hello, I'm trying to deploy filebeat on Kubernetes that is configured with running CRI-O container runtime environment. Deploying the filebeat as in https://github.com/elastic/beats/blob/master/deploy/kubernetes/filebe…

---

## [Out of delivery of messages in kafka](https://discuss.elastic.co/t/out-of-delivery-of-messages-in-kafka/220347)

<div class="topic-metadata">

**Author:** [@Gaurang\_Patel](https://discuss.elastic.co/u/Gaurang_Patel)\
**Replies:** 2\
**Last updated:** [February 21, 2020, 5:30pm UTC](https://discuss.elastic.co/t/out-of-delivery-of-messages-in-kafka/220347 "2020-02-21T17:30:48Z")

</div>

I want to process logs of one system(which has rolling policy). To process logs, logs must be given in order. So to achieve this, I have deployed latest version of filebeat(filebeat-7.5.2-linux-x86\_64) and producing the …

---

## [Improving Cisco IOS Filebeats Module](https://discuss.elastic.co/t/improving-cisco-ios-filebeats-module/220418)

<div class="topic-metadata">

**Author:** [@james.tutton](https://discuss.elastic.co/u/james.tutton)\
**Replies:** 0\
**Last updated:** [February 21, 2020, 4:35pm UTC](https://discuss.elastic.co/t/improving-cisco-ios-filebeats-module/220418 "2020-02-21T16:35:33Z")

</div>

Hi All, Just wanted to drop a line out to the Community and devs to say I am currently working to extend the number of logs passed by the cisco ios filebeat module. Forked Version of module is here: So Far all chang…

---

## [Setting up Metricbeats](https://discuss.elastic.co/t/setting-up-metricbeats/220398)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 0\
**Last updated:** [February 21, 2020, 3:02pm UTC](https://discuss.elastic.co/t/setting-up-metricbeats/220398 "2020-02-21T15:02:54Z")

</div>

Metricbeats file output.elasticsearch: hosts: \["https://host:9200"\] username: "monitor" password: "" ssl.certificate\_authorities: \["/path"\] I am getting this error any ideas / alhost:9200/\_nodes/\_local/stats: EOF …

---

## [Filebeat fails to start when output is set to file](https://discuss.elastic.co/t/filebeat-fails-to-start-when-output-is-set-to-file/220328)

<div class="topic-metadata">

**Author:** [@ldv](https://discuss.elastic.co/u/ldv)\
**Replies:** 0\
**Last updated:** [February 21, 2020, 10:06am UTC](https://discuss.elastic.co/t/filebeat-fails-to-start-when-output-is-set-to-file/220328 "2020-02-21T10:06:19Z")

</div>

I am quite new to filebeat and the ELK stack. After succesfully building a Filebeat, Elastic and Kibana stack indexing apache access logfiles, I wanted to use Filebeat to send output to a file for testing purposes. Howev…

---

## [Custom filebeat module make update error](https://discuss.elastic.co/t/custom-filebeat-module-make-update-error/219587)

<div class="topic-metadata">

**Author:** [@graimato](https://discuss.elastic.co/u/graimato)\
**Replies:** 3\
**Last updated:** [February 21, 2020, 9:06am UTC](https://discuss.elastic.co/t/custom-filebeat-module-make-update-error/219587 "2020-02-21T09:06:00Z")

</div>

Dear All If it is possible I need an help about creation of a custom module for filebeat. I Followed the instructions make create-module MODULE={module} make create-fileset MODULE={module} FILESET={fileset} make cre…

---

## [Filebeat 7.3.0 stops after few minutes working](https://discuss.elastic.co/t/filebeat-7-3-0-stops-after-few-minutes-working/220301)

<div class="topic-metadata">

**Author:** [@SrHades](https://discuss.elastic.co/u/SrHades)\
**Replies:** 0\
**Last updated:** [February 21, 2020, 7:25am UTC](https://discuss.elastic.co/t/filebeat-7-3-0-stops-after-few-minutes-working/220301 "2020-02-21T07:25:55Z")

</div>

Hello, We are managing 30+ servers with filebeat configured, but one of them just stops after few minutes. Any guess? The given error is: Error while initializing input: Can only start an input when all related states…

---

## [Unable to start FileBeat "sends log files to Logstash or directly to Elasticsearch"](https://discuss.elastic.co/t/unable-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/220297)

<div class="topic-metadata">

**Author:** [@DavidSanchezGracia](https://discuss.elastic.co/u/DavidSanchezGracia)\
**Replies:** 0\
**Last updated:** [February 21, 2020, 6:44am UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/220297 "2020-02-21T06:44:04Z")

</div>

Hi, and thanks in advance for your help, I am having the following issue when starting FIleBeat on mi Ubuntu18.04 machine: \`filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Lo…

---

## [Cannot see filebeat process logs](https://discuss.elastic.co/t/cannot-see-filebeat-process-logs/219364)

<div class="topic-metadata">

**Author:** [@samiujan](https://discuss.elastic.co/u/samiujan)\
**Replies:** 2\
**Last updated:** [February 21, 2020, 6:14am UTC](https://discuss.elastic.co/t/cannot-see-filebeat-process-logs/219364 "2020-02-21T06:14:38Z")

</div>

Hi I have installed filebeat 7.5 on a Ubuntu machine - even though I enabled logging, I don't see filebeat's own logs being written to file or even the file being created at /var/log/filebeat I added more info to the c…

---

## [AuditBeat Will Not Start](https://discuss.elastic.co/t/auditbeat-will-not-start/210005)

<div class="topic-metadata">

**Author:** [@nuffskillz](https://discuss.elastic.co/u/nuffskillz)\
**Replies:** 1\
**Last updated:** [February 20, 2020, 8:35pm UTC](https://discuss.elastic.co/t/auditbeat-will-not-start/210005 "2020-02-20T20:35:39Z")

</div>

Hi A fresh install of auditbeat will not start returning the following below. Exiting: 1 error: 1 error: system/socket dataset setup failed: unable to guess one or more required parameters: guess\_sk\_buff\_proto failed: …

---

## [How can I extract form the logged JSON message a field value that can be used as partition key to the JSON messages to a Kafka topic with filebeat?](https://discuss.elastic.co/t/how-can-i-extract-form-the-logged-json-message-a-field-value-that-can-be-used-as-partition-key-to-the-json-messages-to-a-kafka-topic-with-filebeat/220224)

<div class="topic-metadata">

**Author:** [@Avi\_Chalbani](https://discuss.elastic.co/u/Avi_Chalbani)\
**Replies:** 0\
**Last updated:** [February 20, 2020, 4:20pm UTC](https://discuss.elastic.co/t/how-can-i-extract-form-the-logged-json-message-a-field-value-that-can-be-used-as-partition-key-to-the-json-messages-to-a-kafka-topic-with-filebeat/220224 "2020-02-20T16:20:09Z")

</div>

How can I extract form the logged JSON message a field value that can be used as partition key to the JSON messages to a Kafka topic with filebeat? I have an event (JSON message) in file, that needs to be sent to Kafka …

---

## [Metricbeat couchdb module not working](https://discuss.elastic.co/t/metricbeat-couchdb-module-not-working/219094)

<div class="topic-metadata">

**Author:** [@Allan\_Johns](https://discuss.elastic.co/u/Allan_Johns)\
**Replies:** 6\
**Last updated:** [February 20, 2020, 3:23pm UTC](https://discuss.elastic.co/t/metricbeat-couchdb-module-not-working/219094 "2020-02-20T15:23:29Z")

</div>

I'm using metricbeat-7.5.2 to monitor couchdb-2.3.1. I get the following error in the docs in elastic written by metricbeat: error in http fetch: HTTP error 404 in : 404 Object Not Found I cannot get any further info,…

---

## [Filebeat :- Failed to publish events caused by: client is not connected](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603)

<div class="topic-metadata">

**Author:** [@ragur](https://discuss.elastic.co/u/ragur)\
**Replies:** 8\
**Last updated:** [February 20, 2020, 3:20pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603 "2020-02-20T15:20:59Z")

</div>

Filebeat throws the following error message: Failed to publish events caused by: read tcp 127.0.0.1:53380-\>127.0.0.1:5044: i/o timeout 2020-02-03T15:45:46.987+0530 ERROR logstash/async.go:256 Failed to publish events c…

---

## [Journalbeat Error while reading event: failed to get realtime timestamp: 99](https://discuss.elastic.co/t/journalbeat-error-while-reading-event-failed-to-get-realtime-timestamp-99/220200)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 0\
**Last updated:** [February 20, 2020, 2:07pm UTC](https://discuss.elastic.co/t/journalbeat-error-while-reading-event-failed-to-get-realtime-timestamp-99/220200 "2020-02-20T14:07:54Z")

</div>

Hi, I'm using elastic stack of 7.1.1 version with x-pack installed and I cant able to run the journalbeat as im getting the following errors. Please help me solve it. 2020-02-20T19:32:44.980+0530 ERROR \[input\] input/…

---

## [Uptime UI (and Discover) not showing any data in Heartbeat](https://discuss.elastic.co/t/uptime-ui-and-discover-not-showing-any-data-in-heartbeat/218717)

<div class="topic-metadata">

**Author:** [@shalvah.deimos](https://discuss.elastic.co/u/shalvah.deimos)\
**Replies:** 3\
**Last updated:** [February 20, 2020, 1:53pm UTC](https://discuss.elastic.co/t/uptime-ui-and-discover-not-showing-any-data-in-heartbeat/218717 "2020-02-20T13:53:21Z")

</div>

What I've done: Set up a Docker container running Heartbeat and sending to a remote ES cluster Configured monitors What should be happening I should see my Heartbeat monitors in the Uptime UI What is happening Upti…

---

## [Make metricbeat put out the same data as "GET \_node/stats?"](https://discuss.elastic.co/t/make-metricbeat-put-out-the-same-data-as-get-node-stats/220176)

<div class="topic-metadata">

**Author:** [@Mattness](https://discuss.elastic.co/u/Mattness)\
**Replies:** 0\
**Last updated:** [February 20, 2020, 11:50am UTC](https://discuss.elastic.co/t/make-metricbeat-put-out-the-same-data-as-get-node-stats/220176 "2020-02-20T11:50:58Z")

</div>

Hello, I am trying to create a custom stack monitoring dashboard. Essentially I want to custom 'fake' the already existing stack monitoring. I added metricbeat with the modules "elasticsearch" & "elasticsearch-xpack" & …

---

## [Fileabeat Netflow](https://discuss.elastic.co/t/fileabeat-netflow/220029)

<div class="topic-metadata">

**Author:** [@Uzzi](https://discuss.elastic.co/u/Uzzi)\
**Replies:** 2\
**Last updated:** [February 20, 2020, 10:05am UTC](https://discuss.elastic.co/t/fileabeat-netflow/220029 "2020-02-20T10:05:44Z")

</div>

Hi, I'm tryng to enable nfow module on production. My filebeat.yml: filebeat.modules: module: wazuh alerts: enabled: true archives: enabled: false setup.template.json.enabled: true setup.template.json.path: '…

---

## [Filebeat haproxy module timezone issue](https://discuss.elastic.co/t/filebeat-haproxy-module-timezone-issue/220144)

<div class="topic-metadata">

**Author:** [@Henrik\_Magnusson](https://discuss.elastic.co/u/Henrik_Magnusson)\
**Replies:** 0\
**Last updated:** [February 20, 2020, 9:40am UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-timezone-issue/220144 "2020-02-20T09:40:53Z")

</div>

Hi! I have a problem when sending haproxy logs with the filebeat module for haproxy directly to elasticsearch. The issue is that my systems are using timezone CET, so the logs are written into haproxy.log using my …

---

## [Winlogbeat logs not getting pulled in kibana](https://discuss.elastic.co/t/winlogbeat-logs-not-getting-pulled-in-kibana/220138)

<div class="topic-metadata">

**Author:** [@Jithin\_varghese](https://discuss.elastic.co/u/Jithin_varghese)\
**Replies:** 0\
**Last updated:** [February 20, 2020, 9:18am UTC](https://discuss.elastic.co/t/winlogbeat-logs-not-getting-pulled-in-kibana/220138 "2020-02-20T09:18:39Z")

</div>

Hi, I am trying to setup ELK along with winlogbeat in a windows machine. Winlogbeat service is getting started properly, but no data is getting pulled to kibana Below is the error message I got when I opened winlogbeat…

---

## [Metricbeat AWS Module : dashboard not working and aws.sqs.messages.visible multiplied by 5](https://discuss.elastic.co/t/metricbeat-aws-module-dashboard-not-working-and-aws-sqs-messages-visible-multiplied-by-5/219749)

<div class="topic-metadata">

**Author:** [@glaenen](https://discuss.elastic.co/u/glaenen)\
**Replies:** 5\
**Last updated:** [February 20, 2020, 6:12am UTC](https://discuss.elastic.co/t/metricbeat-aws-module-dashboard-not-working-and-aws-sqs-messages-visible-multiplied-by-5/219749 "2020-02-20T06:12:29Z")

</div>

Hello, Using the example configuration for the AWS Metricset SQS from : https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-aws-sqs.html AWS data is retrieved and indexed, after that I have 2 …

---

## [Heartbeat Resource Usage](https://discuss.elastic.co/t/heartbeat-resource-usage/218168)

<div class="topic-metadata">

**Author:** [@myatrakos](https://discuss.elastic.co/u/myatrakos)\
**Replies:** 3\
**Last updated:** [February 20, 2020, 3:20am UTC](https://discuss.elastic.co/t/heartbeat-resource-usage/218168 "2020-02-20T03:20:45Z")

</div>

I have setup heartbeat-7.5.1-1 on a Centos 7 VM with 6 vCPUs and 4Gb of memory. This is the heartbeat.yml config I am using: heartbeat.config.monitors: path: ${path.config}/monitors.d/\*\*/\*.yml reload.en…

---

## [Filebeat vs batch](https://discuss.elastic.co/t/filebeat-vs-batch/220068)

<div class="topic-metadata">

**Author:** [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Replies:** 0\
**Last updated:** [February 20, 2020, 2:22am UTC](https://discuss.elastic.co/t/filebeat-vs-batch/220068 "2020-02-20T02:22:38Z")

</div>

Hi, before Filebeat consume some logs I have to decrypt them with a batch file, and I was thinking, while decrypting the logs I can use the windows brother of grep "{ $\_ -match "expression"}" to filter the logs I need. …

---

## [Filebeat - cannot change pipeline in nginx module](https://discuss.elastic.co/t/filebeat-cannot-change-pipeline-in-nginx-module/219360)

<div class="topic-metadata">

**Author:** [@Harm](https://discuss.elastic.co/u/Harm)\
**Replies:** 2\
**Last updated:** [February 19, 2020, 9:12pm UTC](https://discuss.elastic.co/t/filebeat-cannot-change-pipeline-in-nginx-module/219360 "2020-02-19T21:12:31Z")

</div>

Hi, For processing our nginx access logs, we'd like to use a custom pipeline. Therefore I've changed the configuration to: - module: nginx # Access logs access: enabled: true input: pipeline: filebeat…

---

## [Auditbeat - module for Kubernetes](https://discuss.elastic.co/t/auditbeat-module-for-kubernetes/219361)

<div class="topic-metadata">

**Author:** [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Replies:** 2\
**Last updated:** [February 19, 2020, 7:17pm UTC](https://discuss.elastic.co/t/auditbeat-module-for-kubernetes/219361 "2020-02-19T19:17:10Z")

</div>

Hi team! As far as I understood, auditbeat does a great job over system module collecting OS audit data with fantastic dashboards. Is is possible we collect audit data for K8s ? Such as User and Authentication informat…

---

## [After upgraded to 7.6 filebeat doesn't work as expected with config from 7.5.x](https://discuss.elastic.co/t/after-upgraded-to-7-6-filebeat-doesnt-work-as-expected-with-config-from-7-5-x/220046)

<div class="topic-metadata">

**Author:** [@delphi](https://discuss.elastic.co/u/delphi)\
**Replies:** 0\
**Last updated:** [February 19, 2020, 6:39pm UTC](https://discuss.elastic.co/t/after-upgraded-to-7-6-filebeat-doesnt-work-as-expected-with-config-from-7-5-x/220046 "2020-02-19T18:39:57Z")

</div>

Hi there. I'm using Filebeat 7.5.2 to read pod/container logs of GKE (k8s) using official Elastic Helm Charts. After upgrading to 7.6.0 it doesn't read pod/container logs anymore. There isn't any error in Filebeat logs …

---

## [Filebeat client version that will support Kerberos](https://discuss.elastic.co/t/filebeat-client-version-that-will-support-kerberos/220009)

<div class="topic-metadata">

**Author:** [@truittrg](https://discuss.elastic.co/u/truittrg)\
**Replies:** 1\
**Last updated:** [February 19, 2020, 5:57pm UTC](https://discuss.elastic.co/t/filebeat-client-version-that-will-support-kerberos/220009 "2020-02-19T17:57:19Z")

</div>

Is there filebeat client version planned that will support Kerberos authentication to Kafka brokers?

---

## [Send nps log to elk](https://discuss.elastic.co/t/send-nps-log-to-elk/220013)

<div class="topic-metadata">

**Author:** [@Teil\_Francois](https://discuss.elastic.co/u/Teil_Francois)\
**Replies:** 0\
**Last updated:** [February 19, 2020, 4:00pm UTC](https://discuss.elastic.co/t/send-nps-log-to-elk/220013 "2020-02-19T16:00:40Z")

</div>

Hi guys, I want to send NPS log in my ELK server, but the nps logs are stocked in an SQL Server (windows) (in a DB file). Is that possible to send my log to my elk Server in this configuration ?

---

## [Filebeat & ingest pipelines](https://discuss.elastic.co/t/filebeat-ingest-pipelines/219515)

<div class="topic-metadata">

**Author:** [@StefanoM](https://discuss.elastic.co/u/StefanoM)\
**Replies:** 4\
**Last updated:** [February 19, 2020, 3:11pm UTC](https://discuss.elastic.co/t/filebeat-ingest-pipelines/219515 "2020-02-19T15:11:59Z")

</div>

Hi there, is it correct to say that you only need to load an ingest pipeline (e.g. filebeat setup --pipelines --modules system,nginx,mysql) when you are using elasticsearch ingest node as output? Or do also need to do t…

---

## [Beats - Define field type with add\_fields processor in \*beat.yml?](https://discuss.elastic.co/t/beats-define-field-type-with-add-fields-processor-in-beat-yml/219385)

<div class="topic-metadata">

**Author:** [@devbot](https://discuss.elastic.co/u/devbot)\
**Replies:** 1\
**Last updated:** [February 19, 2020, 2:10pm UTC](https://discuss.elastic.co/t/beats-define-field-type-with-add-fields-processor-in-beat-yml/219385 "2020-02-19T14:10:13Z")

</div>

Looking at this documentation on adding fields, I see that filebeat can add any custom field by name and value that will be appended to every documented pushed to Elasticsearch by Filebeat. This is defined in filebeat.y…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=273)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=275)
