# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=275

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 276

---

## [Metricbeat - Bulk send failure - 429 Too Many Requests](https://discuss.elastic.co/t/metricbeat-bulk-send-failure-429-too-many-requests/219839)

<div class="topic-metadata">

**Author:** [@Djaswan](https://discuss.elastic.co/u/Djaswan)\
**Replies:** 2\
**Last updated:** [February 19, 2020, 1:03pm UTC](https://discuss.elastic.co/t/metricbeat-bulk-send-failure-429-too-many-requests/219839 "2020-02-19T13:03:04Z")

</div>

Hi, We are running a metricbeat daemon set within two GKE environments, a test and production environment. Both metricbeats are sending data to the same elasticsearch monitoring cluster. De metricbeat from the test env…

---

## [How can I push lttng traces to elastic using filebeat (or otherwise)](https://discuss.elastic.co/t/how-can-i-push-lttng-traces-to-elastic-using-filebeat-or-otherwise/219922)

<div class="topic-metadata">

**Author:** [@bhaskarsinghal](https://discuss.elastic.co/u/bhaskarsinghal)\
**Replies:** 2\
**Last updated:** [February 19, 2020, 9:27am UTC](https://discuss.elastic.co/t/how-can-i-push-lttng-traces-to-elastic-using-filebeat-or-otherwise/219922 "2020-02-19T09:27:39Z")

</div>

Hello All, I want to view and query the lttng traces using ELK. What is the best way to do this? I don't see any corresponding input type in filebeat documentation. Any pointers? Regards, Bhaskar

---

## [How to send filebeat logs (BareMetal) to elasticsearch (AWS)](https://discuss.elastic.co/t/how-to-send-filebeat-logs-baremetal-to-elasticsearch-aws/219902)

<div class="topic-metadata">

**Author:** [@anbunithi\_R](https://discuss.elastic.co/u/anbunithi_R)\
**Replies:** 0\
**Last updated:** [February 19, 2020, 6:38am UTC](https://discuss.elastic.co/t/how-to-send-filebeat-logs-baremetal-to-elasticsearch-aws/219902 "2020-02-19T06:38:08Z")

</div>

I have my kubernetes cluster running o bare metal and am collecting logs using filebeat. Am already sending my fileabeat logs to elasticsearch (which is running locally ). Now i also want to send my filebeat logs to elas…

---

## [Winlogbeat and Windows Event Fowarder (WEF) Wrong Hostname](https://discuss.elastic.co/t/winlogbeat-and-windows-event-fowarder-wef-wrong-hostname/218808)

<div class="topic-metadata">

**Author:** [@SeekAndDestroy](https://discuss.elastic.co/u/SeekAndDestroy)\
**Replies:** 2\
**Last updated:** [February 18, 2020, 2:56pm UTC](https://discuss.elastic.co/t/winlogbeat-and-windows-event-fowarder-wef-wrong-hostname/218808 "2020-02-18T14:56:15Z")

</div>

Hi. Last year, I configured Windows Event Forwarding to send 6 Windows Domain Controllers their Security Logs to a centralized server. The server has WinlogBeat reading the forwarded events, and sending them to Elasticse…

---

## [Define custom fields on root level when using multiple config yml files](https://discuss.elastic.co/t/define-custom-fields-on-root-level-when-using-multiple-config-yml-files/219627)

<div class="topic-metadata">

**Author:** [@nxtra](https://discuss.elastic.co/u/nxtra)\
**Replies:** 1\
**Last updated:** [February 19, 2020, 2:26am UTC](https://discuss.elastic.co/t/define-custom-fields-on-root-level-when-using-multiple-config-yml-files/219627 "2020-02-19T02:26:19Z")

</div>

In my main filebeat.yml I have filebeat.config.inputs: enabled: true path: /usr/share/filebeat/configs/\*.yml So I can define multiple config files. Each config file specifies a custom field name to add. However thi…

---

## [Permissions for beats](https://discuss.elastic.co/t/permissions-for-beats/219437)

<div class="topic-metadata">

**Author:** [@David\_Fuge](https://discuss.elastic.co/u/David_Fuge)\
**Replies:** 13\
**Last updated:** [February 19, 2020, 1:27am UTC](https://discuss.elastic.co/t/permissions-for-beats/219437 "2020-02-19T01:27:25Z")

</div>

I've read the documentation about accounts for beats and securing beats. However, I still dont understand how to properly limit the accounts used to authenticate my winlogbeat and metricbeats back to my cluster. I am ru…

---

## [Metricbeat 7.4.2-1limiting the data collection of EC-2 instances](https://discuss.elastic.co/t/metricbeat-7-4-2-1limiting-the-data-collection-of-ec-2-instances/219452)

<div class="topic-metadata">

**Author:** [@mylux](https://discuss.elastic.co/u/mylux)\
**Replies:** 1\
**Last updated:** [February 18, 2020, 9:46pm UTC](https://discuss.elastic.co/t/metricbeat-7-4-2-1limiting-the-data-collection-of-ec-2-instances/219452 "2020-02-18T21:46:10Z")

</div>

Hello everybody, I am having issues with Metricbeat using the aws module and ec2 metricset. I have started the service waited for something about 40 minutes and seen that only few instances had their data collected as …

---

## [Reading the logs from Remote server](https://discuss.elastic.co/t/reading-the-logs-from-remote-server/219840)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 3\
**Last updated:** [February 18, 2020, 6:23pm UTC](https://discuss.elastic.co/t/reading-the-logs-from-remote-server/219840 "2020-02-18T18:23:33Z")

</div>

Whether filebeat can read the logs from remote linux/Windows servers? Path field can be set to remote server folder path? So is it possible to have multiple instances of filesbeats installed on a single server and they …

---

## [How to start multiple instances of filebeat in same host (Windows Server)?](https://discuss.elastic.co/t/how-to-start-multiple-instances-of-filebeat-in-same-host-windows-server/219827)

<div class="topic-metadata">

**Author:** [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Replies:** 3\
**Last updated:** [February 18, 2020, 4:07pm UTC](https://discuss.elastic.co/t/how-to-start-multiple-instances-of-filebeat-in-same-host-windows-server/219827 "2020-02-18T16:07:06Z")

</div>

I have downloaded the filebeat-7.6.0-windows-x86\_64.zip file. Do I need to unzip the file in two different directories with a different name? Do I need to change the name of one of the executables (filebeat.exe, filebe…

---

## [Delete Old Log Files](https://discuss.elastic.co/t/delete-old-log-files/219803)

<div class="topic-metadata">

**Author:** [@areller](https://discuss.elastic.co/u/areller)\
**Replies:** 2\
**Last updated:** [February 18, 2020, 3:45pm UTC](https://discuss.elastic.co/t/delete-old-log-files/219803 "2020-02-18T15:45:04Z")

</div>

I'm using Filebeat on windows server. I write logs from my applications to the following path format: C:\\AppLogs\\{AppName}\\{yyyy}-{MM}-{dd}.txt I need to have the ability to delete old log files. I don't want my drive …

---

## [\[auditbeats\]\[beats\] File permissions for file output not working](https://discuss.elastic.co/t/auditbeats-beats-file-permissions-for-file-output-not-working/219661)

<div class="topic-metadata">

**Author:** [@tomrade](https://discuss.elastic.co/u/tomrade)\
**Replies:** 3\
**Last updated:** [February 18, 2020, 3:21pm UTC](https://discuss.elastic.co/t/auditbeats-beats-file-permissions-for-file-output-not-working/219661 "2020-02-18T15:21:12Z")

</div>

In the file output we can specify a permission string for the files. I use auditbeat and although I set the string to "0644". The created file is still "0600" when I "ls" this. file, ive not be able to change this ive t…

---

## [Filebeat creating multiple threads and consuming system resources](https://discuss.elastic.co/t/filebeat-creating-multiple-threads-and-consuming-system-resources/219484)

<div class="topic-metadata">

**Author:** [@Nadia11](https://discuss.elastic.co/u/Nadia11)\
**Replies:** 1\
**Last updated:** [February 18, 2020, 3:07pm UTC](https://discuss.elastic.co/t/filebeat-creating-multiple-threads-and-consuming-system-resources/219484 "2020-02-18T15:07:45Z")

</div>

I have enable the filebeat, it started with consuming systems resources and creating multiple threads. I installed filebeat on a lunix server and ‘yml’ configuration file is as below. Would you please look into the same…

---

## [How to import vsphere dashboards in Kibana](https://discuss.elastic.co/t/how-to-import-vsphere-dashboards-in-kibana/218793)

<div class="topic-metadata">

**Author:** [@Quentinotd](https://discuss.elastic.co/u/Quentinotd)\
**Replies:** 4\
**Last updated:** [February 18, 2020, 3:02pm UTC](https://discuss.elastic.co/t/how-to-import-vsphere-dashboards-in-kibana/218793 "2020-02-18T15:02:23Z")

</div>

Hello, I've been using metricbeat with an elk stack for couple days and i'm now trying to get dashboards for vsphere. I've read the doc on the wiki, and they mention that there are dashboards available for Vsphere modu…

---

## [Filebeat Kafka output compatibility](https://discuss.elastic.co/t/filebeat-kafka-output-compatibility/219688)

<div class="topic-metadata">

**Author:** [@111293](https://discuss.elastic.co/u/111293)\
**Replies:** 1\
**Last updated:** [February 18, 2020, 2:53pm UTC](https://discuss.elastic.co/t/filebeat-kafka-output-compatibility/219688 "2020-02-18T14:53:10Z")

</div>

I want to use Filebeat Kafka output. Kafka version that I will use is 2.3.1. But your docs said that "This output works with all Kafka versions in between 0.11 and 2.1.0. Older versions might work as well, but are not …

---

## [Filebeat index condition and naming reference](https://discuss.elastic.co/t/filebeat-index-condition-and-naming-reference/219790)

<div class="topic-metadata">

**Author:** [@SKiD](https://discuss.elastic.co/u/SKiD)\
**Replies:** 0\
**Last updated:** [February 18, 2020, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-index-condition-and-naming-reference/219790 "2020-02-18T13:09:20Z")

</div>

Hey, I'm setting up Filebeat for different modules, such as Apache and Nginx. I try to archive an different index name for different modules and file type. For example for Filebeat I wanna create a different index for …

---

## [Netflow and Filebeat - Error running harvester: listen udp 0.0.0.0:2055: bind: address already in use](https://discuss.elastic.co/t/netflow-and-filebeat-error-running-harvester-listen-udp-0-0-0-0-bind-address-already-in-use/219498)

<div class="topic-metadata">

**Author:** [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Replies:** 1\
**Last updated:** [February 18, 2020, 1:11pm UTC](https://discuss.elastic.co/t/netflow-and-filebeat-error-running-harvester-listen-udp-0-0-0-0-bind-address-already-in-use/219498 "2020-02-18T13:11:13Z")

</div>

I'm trying to configure the netflow module with Filebeat but getting an error about the local address already in use. In my config, if I change the netflow\_host to localhost instead of 0.0.0.0 then the error says 127.0.0…

---

## [X-Pack license basic deos not work / free security](https://discuss.elastic.co/t/x-pack-license-basic-deos-not-work-free-security/219757)

<div class="topic-metadata">

**Author:** [@juuuhuuu](https://discuss.elastic.co/u/juuuhuuu)\
**Replies:** 2\
**Last updated:** [February 18, 2020, 1:10pm UTC](https://discuss.elastic.co/t/x-pack-license-basic-deos-not-work-free-security/219757 "2020-02-18T13:10:08Z")

</div>

Hello :slight\_smile: I would like to have encrypted comunication between logstash and Filebeat. Im using basic license. Since last year is possible to use X-Pack security feature for free .. in my docker-compose …

---

## [Metricbeat apiserver metricset needs clusterrole when RBAC enabled in k8s 1.14](https://discuss.elastic.co/t/metricbeat-apiserver-metricset-needs-clusterrole-when-rbac-enabled-in-k8s-1-14/219770)

<div class="topic-metadata">

**Author:** [@Babadofar](https://discuss.elastic.co/u/Babadofar)\
**Replies:** 0\
**Last updated:** [February 18, 2020, 11:28am UTC](https://discuss.elastic.co/t/metricbeat-apiserver-metricset-needs-clusterrole-when-rbac-enabled-in-k8s-1-14/219770 "2020-02-18T11:28:04Z")

</div>

with RBAC enabled, the apiserver metricset throws errormessage indicating the user does not have permission. Adding the clusterroles as indicated here https://kubernetes.io/docs/concepts/cluster-administration/monitorin…

---

## [Multiline is not fetching desired result from filebeat to ES](https://discuss.elastic.co/t/multiline-is-not-fetching-desired-result-from-filebeat-to-es/218772)

<div class="topic-metadata">

**Author:** [@Darshan\_Kamat](https://discuss.elastic.co/u/Darshan_Kamat)\
**Replies:** 3\
**Last updated:** [February 18, 2020, 10:37am UTC](https://discuss.elastic.co/t/multiline-is-not-fetching-desired-result-from-filebeat-to-es/218772 "2020-02-18T10:37:26Z")

</div>

I am not getting desired result .I have sample logs like below .I have multiline setting multiline.pattern: '^\[0-9\]{4}' multiline.negate: true multiline.match: after 1.when i search for "2003787391047586" i want ent…

---

## [Difference seen in the total number sockets using SAR or SS utility and with the number shown by Metricbeats system.socket.summary.all.count](https://discuss.elastic.co/t/difference-seen-in-the-total-number-sockets-using-sar-or-ss-utility-and-with-the-number-shown-by-metricbeats-system-socket-summary-all-count/219755)

<div class="topic-metadata">

**Author:** [@mdshahidbec](https://discuss.elastic.co/u/mdshahidbec)\
**Replies:** 0\
**Last updated:** [February 18, 2020, 10:03am UTC](https://discuss.elastic.co/t/difference-seen-in-the-total-number-sockets-using-sar-or-ss-utility-and-with-the-number-shown-by-metricbeats-system-socket-summary-all-count/219755 "2020-02-18T10:03:18Z")

</div>

Hi, I am trying to get the total number of sockets using the metricbeat plugin, however there is huge difference between what is shown by "system.socket.summary.all.count" and the value derived from SAR or SS utility. C…

---

## [Filebeat PANW Module Not Working](https://discuss.elastic.co/t/filebeat-panw-module-not-working/219433)

<div class="topic-metadata">

**Author:** [@savethebyte](https://discuss.elastic.co/u/savethebyte)\
**Replies:** 0\
**Last updated:** [February 14, 2020, 6:29pm UTC](https://discuss.elastic.co/t/filebeat-panw-module-not-working/219433 "2020-02-14T18:29:51Z")

</div>

Hello, We configure the PANW module in filebeat and it is not forwarding syslogs to elasticsearch. I am seeing syslogs coming in on UDP 514 and also see filebeat listening on udp 514, but not forwarding logs properly. #…

---

## [Why filebeat provided dashboard filtered out error log on map](https://discuss.elastic.co/t/why-filebeat-provided-dashboard-filtered-out-error-log-on-map/219699)

<div class="topic-metadata">

**Author:** [@rogerwang](https://discuss.elastic.co/u/rogerwang)\
**Replies:** 0\
**Last updated:** [February 18, 2020, 4:39am UTC](https://discuss.elastic.co/t/why-filebeat-provided-dashboard-filtered-out-error-log-on-map/219699 "2020-02-18T04:39:18Z")

</div>

Please refer to the link for the problem history. since the title does not fit the questions in the end after I have digged further in the problem, maybe it is better to rephrase. I got filebeat to feed apache access …

---

## [For how long filebeat attempts sending logs to logstash while it is unreachable](https://discuss.elastic.co/t/for-how-long-filebeat-attempts-sending-logs-to-logstash-while-it-is-unreachable/216275)

<div class="topic-metadata">

**Author:** [@ehsank777](https://discuss.elastic.co/u/ehsank777)\
**Replies:** 3\
**Last updated:** [February 17, 2020, 10:19am UTC](https://discuss.elastic.co/t/for-how-long-filebeat-attempts-sending-logs-to-logstash-while-it-is-unreachable/216275 "2020-02-17T10:19:00Z")

</div>

I was wondering about filebeat to logstash output resiliency. For example, we are using a single instance of logstash with a Elasticsearch cluster, what would happen if Logstash is done for a day?

---

## [Part of geo\_point field do not show on the world map](https://discuss.elastic.co/t/part-of-geo-point-field-do-not-show-on-the-world-map/219307)

<div class="topic-metadata">

**Author:** [@rogerwang](https://discuss.elastic.co/u/rogerwang)\
**Replies:** 4\
**Last updated:** [February 17, 2020, 9:24am UTC](https://discuss.elastic.co/t/part-of-geo-point-field-do-not-show-on-the-world-map/219307 "2020-02-17T09:24:44Z")

</div>

Hello, I got filebeat to feed apache access and error log to elasticsearch. It is awesome and the filebeat provided dashboard is great as well. However, when I filtered and show only data from the error log, the map wi…

---

## [Winlogbeat can't send events to Elasticsearch](https://discuss.elastic.co/t/winlogbeat-cant-send-events-to-elasticsearch/218940)

<div class="topic-metadata">

**Author:** [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Replies:** 1\
**Last updated:** [February 17, 2020, 8:59am UTC](https://discuss.elastic.co/t/winlogbeat-cant-send-events-to-elasticsearch/218940 "2020-02-17T08:59:22Z")

</div>

Hello. We have near 2300 EPS comming on each WEC Windows collector and near 350 EPS that winlogbeat ship to Logstash or Elasticsearch (i test both). I try a lot of things on winlogbeat side, but nothing happen. Then i i…

---

## [Limit of total fields ... has been exceeded](https://discuss.elastic.co/t/limit-of-total-fields-has-been-exceeded/216812)

<div class="topic-metadata">

**Author:** [@upietz](https://discuss.elastic.co/u/upietz)\
**Replies:** 2\
**Last updated:** [February 17, 2020, 7:49am UTC](https://discuss.elastic.co/t/limit-of-total-fields-has-been-exceeded/216812 "2020-02-17T07:49:46Z")

</div>

Hi there, using winlogbeat-7.5.0-windows-x86\_64 on different Windows OS (2012R2,2016,10,...) we're regularly hitting the es (7.4.1) field limitation for our daily indices ("logstash-winlogbeat-%{+YYYY.MM}"). Logstash do…

---

## [Filebeat doesn't harvest](https://discuss.elastic.co/t/filebeat-doesnt-harvest/219218)

<div class="topic-metadata">

**Author:** [@Noureddine\_Brahmi](https://discuss.elastic.co/u/Noureddine_Brahmi)\
**Replies:** 2\
**Last updated:** [February 17, 2020, 7:30am UTC](https://discuss.elastic.co/t/filebeat-doesnt-harvest/219218 "2020-02-17T07:30:04Z")

</div>

Hello, I've been facing a probem since a while now. My filebeat plugin does not harvest the fields that i ask him to harvest in my conf file. I'm using filebeat 7.6.0 My conf: filebeat.inputs: - type: log paths: …

---

## [Metricbeat kubernetes module doesn't report container memory](https://discuss.elastic.co/t/metricbeat-kubernetes-module-doesnt-report-container-memory/219381)

<div class="topic-metadata">

**Author:** [@smiklos](https://discuss.elastic.co/u/smiklos)\
**Replies:** 1\
**Last updated:** [February 17, 2020, 7:24am UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-module-doesnt-report-container-memory/219381 "2020-02-17T07:24:14Z")

</div>

Hi, Starting from k8s version 1.14, the kubelet /stats/summary endpoint doesn't return memory info per container but rather per pod only. Looks like metricbeat doesn't handle that and therefor the pre-generated dashboar…

---

## [Filebeat Logstash CSV filter best practices](https://discuss.elastic.co/t/filebeat-logstash-csv-filter-best-practices/218473)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 2\
**Last updated:** [February 16, 2020, 9:09am UTC](https://discuss.elastic.co/t/filebeat-logstash-csv-filter-best-practices/218473 "2020-02-16T09:09:03Z")

</div>

Hello @filebeatuser; I use filebeat to ship messages to Logstash, which parses the messages and ingest them into the Elasticseach cluster. Each message/logline corresponds logically to a tab-separated row in a csv file…

---

## [Metricbeat chart does not load dashboards](https://discuss.elastic.co/t/metricbeat-chart-does-not-load-dashboards/218624)

<div class="topic-metadata">

**Author:** [@Dimitris\_S](https://discuss.elastic.co/u/Dimitris_S)\
**Replies:** 1\
**Last updated:** [February 16, 2020, 8:48am UTC](https://discuss.elastic.co/t/metricbeat-chart-does-not-load-dashboards/218624 "2020-02-16T08:48:25Z")

</div>

Describe the bug I'm not able to load the metricbeat dashboards in Kibana Version of Helm and Kubernetes: $ helm version Client: &version.Version{SemVer:"v2.16.1", GitCommit:"bbdfe5e7803a12bbdf97e94cd847859890cf4050",…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=274)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=276)
