# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=276

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 277

---

## [Metricbeat process, what regex filter to exclude processes](https://discuss.elastic.co/t/metricbeat-process-what-regex-filter-to-exclude-processes/218709)

<div class="topic-metadata">

**Author:** [@MagicNotElastic](https://discuss.elastic.co/u/MagicNotElastic)\
**Replies:** 1\
**Last updated:** [February 16, 2020, 2:44am UTC](https://discuss.elastic.co/t/metricbeat-process-what-regex-filter-to-exclude-processes/218709 "2020-02-16T02:44:51Z")

</div>

Hi, Simple question here. I'd wish to exclude some processes, what regex flavour should be used, I get errors when using this: module: system period: 10s metricsets: process processes: \['^((?!taskhostw|dllhost|sv…

---

## [Auditbeat not starting on Startup - Mac](https://discuss.elastic.co/t/auditbeat-not-starting-on-startup-mac/218802)

<div class="topic-metadata">

**Author:** [@Bill.S.Preston](https://discuss.elastic.co/u/Bill.S.Preston)\
**Replies:** 5\
**Last updated:** [February 16, 2020, 2:39am UTC](https://discuss.elastic.co/t/auditbeat-not-starting-on-startup-mac/218802 "2020-02-16T02:39:59Z")

</div>

I can't seem to get my auditbeat to start sending data to my ElastaCloud from my Mac. Every time I start it I need to execute the following commands and it won't log until that point ./auditbeat setup ./auditbeat -e A…

---

## [Error index management Filebeat to Logstash](https://discuss.elastic.co/t/error-index-management-filebeat-to-logstash/218849)

<div class="topic-metadata">

**Author:** [@vazel](https://discuss.elastic.co/u/vazel)\
**Replies:** 2\
**Last updated:** [February 15, 2020, 7:54pm UTC](https://discuss.elastic.co/t/error-index-management-filebeat-to-logstash/218849 "2020-02-15T19:54:17Z")

</div>

Hi, I have the following configuration: Filebeat 7.2.0 and Logstash 7.2.0. ERROR instance/beat.go:877 Exiting: Index management requested but the Elasticsearch output is not configured/enabled When I run the filebeat s…

---

## [Import Windows events stored as syslog in PCAPs](https://discuss.elastic.co/t/import-windows-events-stored-as-syslog-in-pcaps/219480)

<div class="topic-metadata">

**Author:** [@m4rkus](https://discuss.elastic.co/u/m4rkus)\
**Replies:** 0\
**Last updated:** [February 15, 2020, 2:29pm UTC](https://discuss.elastic.co/t/import-windows-events-stored-as-syslog-in-pcaps/219480 "2020-02-15T14:29:29Z")

</div>

Hi, I have PCAP files (hundreds of GB:s) with recorded syslog traffic (UDP/514) containing log events from Windows hosts. I would like to import and parse the data in an ELK stack. If possible, I would also like to pres…

---

## [Unable to import vsphere dashboards into kibana](https://discuss.elastic.co/t/unable-to-import-vsphere-dashboards-into-kibana/218877)

<div class="topic-metadata">

**Author:** [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Replies:** 1\
**Last updated:** [February 14, 2020, 9:30pm UTC](https://discuss.elastic.co/t/unable-to-import-vsphere-dashboards-into-kibana/218877 "2020-02-14T21:30:00Z")

</div>

Hello i am unable to import vsphere dashboards into kibana. after installing with yum i don't even see the files for it so i got it from github which has the vsphere files called metricbeat-vsphere-host.json metricbea…

---

## [Best Practices for Accounts Running Beats Services](https://discuss.elastic.co/t/best-practices-for-accounts-running-beats-services/219448)

<div class="topic-metadata">

**Author:** [@illopssec](https://discuss.elastic.co/u/illopssec)\
**Replies:** 0\
**Last updated:** [February 14, 2020, 9:11pm UTC](https://discuss.elastic.co/t/best-practices-for-accounts-running-beats-services/219448 "2020-02-14T21:11:57Z")

</div>

Hello all, Speaking strictly for the various Beats that are compatible with Windows, I was wondering what the best practices are for accounts running the various Beats services? For instance, has anyone tried doing a la…

---

## [Filebeat Autogenerating Index Name When I Specified: sample-%](https://discuss.elastic.co/t/filebeat-autogenerating-index-name-when-i-specified-sample/219038)

<div class="topic-metadata">

**Author:** [@daz1761](https://discuss.elastic.co/u/daz1761)\
**Replies:** 3\
**Last updated:** [February 14, 2020, 7:46pm UTC](https://discuss.elastic.co/t/filebeat-autogenerating-index-name-when-i-specified-sample/219038 "2020-02-14T19:46:29Z")

</div>

I have specified the index in my filebeat.yml as sample-%{+YYY.MM.dd} but when I check my indices via /\_cat/indices?vmyindexlooks like a some form of autogenerated name like:filebeat-7.5.2-2020.02.12-000001\` # setup fil…

---

## [Exit filebeat on eof?](https://discuss.elastic.co/t/exit-filebeat-on-eof/219189)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [February 14, 2020, 7:15pm UTC](https://discuss.elastic.co/t/exit-filebeat-on-eof/219189 "2020-02-14T19:15:22Z")

</div>

Hi, I want to import a set of static logs, meaning they are not written anymore. Can I tell filebeat to exit after all harvesters are closed? I tried --once flag but I get the following error when starting filebeat: E…

---

## [File Beat: Silent Installation](https://discuss.elastic.co/t/file-beat-silent-installation/218943)

<div class="topic-metadata">

**Author:** [@RajeshKumar](https://discuss.elastic.co/u/RajeshKumar)\
**Replies:** 1\
**Last updated:** [February 14, 2020, 6:58pm UTC](https://discuss.elastic.co/t/file-beat-silent-installation/218943 "2020-02-14T18:58:01Z")

</div>

Hi, Is there a document for the procedure of silent installation/uninstallation of FileBeat?

---

## [Filebeat Module Problem](https://discuss.elastic.co/t/filebeat-module-problem/219042)

<div class="topic-metadata">

**Author:** [@weasel87](https://discuss.elastic.co/u/weasel87)\
**Replies:** 1\
**Last updated:** [February 14, 2020, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-module-problem/219042 "2020-02-14T18:52:02Z")

</div>

I want to send cisco firewall logs to my elastic statck so I was trying to setup the siem for Cisco. I already have filebeat installed, so the next step is to enable the cisco module. This is what doesn't work. root@ela…

---

## [Packetbeat do not support http 2.0 or grpc](https://discuss.elastic.co/t/packetbeat-do-not-support-http-2-0-or-grpc/219422)

<div class="topic-metadata">

**Author:** [@Muneeb\_Younsi](https://discuss.elastic.co/u/Muneeb_Younsi)\
**Replies:** 0\
**Last updated:** [February 14, 2020, 5:03pm UTC](https://discuss.elastic.co/t/packetbeat-do-not-support-http-2-0-or-grpc/219422 "2020-02-14T17:03:12Z")

</div>

Packetbeat do not even show the request header for http2.0 or grpc request. Is it not supported yet?

---

## [Filebeat shared or per application server](https://discuss.elastic.co/t/filebeat-shared-or-per-application-server/219412)

<div class="topic-metadata">

**Author:** [@areller](https://discuss.elastic.co/u/areller)\
**Replies:** 3\
**Last updated:** [February 14, 2020, 4:54pm UTC](https://discuss.elastic.co/t/filebeat-shared-or-per-application-server/219412 "2020-02-14T16:54:40Z")

</div>

We have a .NET Framework stack where each application instance is deployed on its own windows server. We want to move to ELK instead of just writing log files to a shared network drive. What would be the best solution …

---

## [Metricbeat RDS module does not read aws tags](https://discuss.elastic.co/t/metricbeat-rds-module-does-not-read-aws-tags/219356)

<div class="topic-metadata">

**Author:** [@Rahul12](https://discuss.elastic.co/u/Rahul12)\
**Replies:** 0\
**Last updated:** [February 14, 2020, 11:02am UTC](https://discuss.elastic.co/t/metricbeat-rds-module-does-not-read-aws-tags/219356 "2020-02-14T11:02:22Z")

</div>

Hi, We are using EC2 and rds metricset of aws module. In EC2 metricset we are able to get aws tags but in rds module tags details are not coming. Can you please let me know how we can include aws tags in rds module?

---

## [IIS access map issue/ geo.point fileds](https://discuss.elastic.co/t/iis-access-map-issue-geo-point-fileds/217965)

<div class="topic-metadata">

**Author:** [@nikhilesh](https://discuss.elastic.co/u/nikhilesh)\
**Replies:** 1\
**Last updated:** [February 14, 2020, 7:38am UTC](https://discuss.elastic.co/t/iis-access-map-issue-geo-point-fileds/217965 "2020-02-14T07:38:16Z")

</div>

Hi Team, when the instance is in Public subnet, i could see geo.point fields in filebeat logs. but now the instance is moved to private subnet. after the instances moved to private subnet, i could not see these file…

---

## [Question: what happens when Logstash is unavailable for long?](https://discuss.elastic.co/t/question-what-happens-when-logstash-is-unavailable-for-long/218759)

<div class="topic-metadata">

**Author:** [@Christos\_Gitsis](https://discuss.elastic.co/u/Christos_Gitsis)\
**Replies:** 1\
**Last updated:** [February 13, 2020, 10:03pm UTC](https://discuss.elastic.co/t/question-what-happens-when-logstash-is-unavailable-for-long/218759 "2020-02-13T22:03:29Z")

</div>

I have a pipeline FileBeat --\> Logstash --\> ElasticSearch. I want to know what FileBeat does in case it cannot access Logstash for a longer time period. The application being monitored logs to a file, the current file i…

---

## [Is there a way to run metricbeat on remote servers](https://discuss.elastic.co/t/is-there-a-way-to-run-metricbeat-on-remote-servers/219182)

<div class="topic-metadata">

**Author:** [@SathishPrakasam](https://discuss.elastic.co/u/SathishPrakasam)\
**Replies:** 1\
**Last updated:** [February 13, 2020, 3:11pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-run-metricbeat-on-remote-servers/219182 "2020-02-13T15:11:06Z")

</div>

Dear Elk team, We are using metricbeat to monitor our Microservices. It's really easy to configure and use. I love it and it's capability to provide detailed system monitoring. On looking at the easy of doing infrastruc…

---

## [Filebeat custom Module](https://discuss.elastic.co/t/filebeat-custom-module/219191)

<div class="topic-metadata">

**Author:** [@graimato](https://discuss.elastic.co/u/graimato)\
**Replies:** 0\
**Last updated:** [February 13, 2020, 11:37am UTC](https://discuss.elastic.co/t/filebeat-custom-module/219191 "2020-02-13T11:37:31Z")

</div>

Dear All I'm implementing a new module for filebeat. I followed the instructions I created fileset I created pipeline I created fields I added documentation but when I execute make update command I have an error E…

---

## [Filebeat read tcp i/o timeout which is causing duplicate event to get stored in elasticsearch](https://discuss.elastic.co/t/filebeat-read-tcp-i-o-timeout-which-is-causing-duplicate-event-to-get-stored-in-elasticsearch/218985)

<div class="topic-metadata">

**Author:** [@Nikhil\_Pillai](https://discuss.elastic.co/u/Nikhil_Pillai)\
**Replies:** 1\
**Last updated:** [February 13, 2020, 11:14am UTC](https://discuss.elastic.co/t/filebeat-read-tcp-i-o-timeout-which-is-causing-duplicate-event-to-get-stored-in-elasticsearch/218985 "2020-02-13T11:14:59Z")

</div>

I am sending data via filebeat \> logstash \> elasticsearch \> kibana. Due to timeout at filebeat it's sending duplicate events. filebeat.log 2020-02-07T18:40:08.968+0400 ERROR logstash/async.go:256 Failed to publi…

---

## [\[FunctionBeat\] Timestamp Issue when collecting logs from cloudwatch](https://discuss.elastic.co/t/functionbeat-timestamp-issue-when-collecting-logs-from-cloudwatch/219026)

<div class="topic-metadata">

**Author:** [@Ben\_Ismail\_Mohamed](https://discuss.elastic.co/u/Ben_Ismail_Mohamed)\
**Replies:** 0\
**Last updated:** [February 12, 2020, 3:24pm UTC](https://discuss.elastic.co/t/functionbeat-timestamp-issue-when-collecting-logs-from-cloudwatch/219026 "2020-02-12T15:24:41Z")

</div>

Hello We have a problem sending cloudwatch events to our Elasticsearch Cluster. The error is on the Timestamp Configuration set to the collecte date instead of the cloudwatch event timestamp. So with a large volume of d…

---

## [Connecting kafka and metricbeat dockers with elastic cloud](https://discuss.elastic.co/t/connecting-kafka-and-metricbeat-dockers-with-elastic-cloud/218956)

<div class="topic-metadata">

**Author:** [@Enrique\_Castilla](https://discuss.elastic.co/u/Enrique_Castilla)\
**Replies:** 1\
**Last updated:** [February 13, 2020, 9:45am UTC](https://discuss.elastic.co/t/connecting-kafka-and-metricbeat-dockers-with-elastic-cloud/218956 "2020-02-13T09:45:17Z")

</div>

I have this weird error where I am getting contradictory logs and no output for the Kafka module in metricbeat. I have a docker compose that consists of a ZK + Kafka cluster where the main broker is kafka-sscc-1:9092 an…

---

## [MongoDB stats not coming up](https://discuss.elastic.co/t/mongodb-stats-not-coming-up/219169)

<div class="topic-metadata">

**Author:** [@Himani\_Arora1](https://discuss.elastic.co/u/Himani_Arora1)\
**Replies:** 0\
**Last updated:** [February 13, 2020, 9:30am UTC](https://discuss.elastic.co/t/mongodb-stats-not-coming-up/219169 "2020-02-13T09:30:37Z")

</div>

I have been facing the problem in mongo metricbeat dashboard. The mongoDB stats for elasticsearch are not coming up fully. Mongo Version: 3.2 Metricbeat version: 6.8 Receiving the below error in /var/log/metricbeat E…

---

## [Fields.yml not used by winlogbeat](https://discuss.elastic.co/t/fields-yml-not-used-by-winlogbeat/219150)

<div class="topic-metadata">

**Author:** [@SKiD](https://discuss.elastic.co/u/SKiD)\
**Replies:** 0\
**Last updated:** [February 13, 2020, 7:59am UTC](https://discuss.elastic.co/t/fields-yml-not-used-by-winlogbeat/219150 "2020-02-13T07:59:35Z")

</div>

Hey, currently I do configurations on my ELK stack since I figured out, that Winlogbeat does not use the default fields.yml to produce results according to the ECS. The problem I have is, that doesn't matter how I confi…

---

## [Filebeat pod stopped, crashloopbackoff](https://discuss.elastic.co/t/filebeat-pod-stopped-crashloopbackoff/218456)

<div class="topic-metadata">

**Author:** [@izazahamed.babji](https://discuss.elastic.co/u/izazahamed.babji)\
**Replies:** 2\
**Last updated:** [February 13, 2020, 1:58am UTC](https://discuss.elastic.co/t/filebeat-pod-stopped-crashloopbackoff/218456 "2020-02-13T01:58:29Z")

</div>

kubectl logs filebeat-filebeat-bl6x6 -f 2020-02-09T00:55:31.955Z INFO instance/beat.go:610 Home path: \[/usr/share/filebeat\] Config path: \[/usr/share/filebeat\] Data path: \[/usr/share/filebeat/data\] Logs path: \[/usr/share/…

---

## [Failed to publish events caused by: read tcp](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-read-tcp/217410)

<div class="topic-metadata">

**Author:** [@daz1761](https://discuss.elastic.co/u/daz1761)\
**Replies:** 14\
**Last updated:** [February 12, 2020, 11:00pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-read-tcp/217410 "2020-02-12T23:00:35Z")

</div>

I am new to ELK, and I noticed these ERROR logs coming from the Filebeat Docker container: filebeat | 2020-01-31T14:27:27.422Z ERROR logstash/async.go:256 Failed to publish events caused by: read tcp 172…

---

## [Intermittent timeouts (Doesn't appear to stop service)](https://discuss.elastic.co/t/intermittent-timeouts-doesnt-appear-to-stop-service/218132)

<div class="topic-metadata">

**Author:** [@runtman](https://discuss.elastic.co/u/runtman)\
**Replies:** 9\
**Last updated:** [February 12, 2020, 10:59pm UTC](https://discuss.elastic.co/t/intermittent-timeouts-doesnt-appear-to-stop-service/218132 "2020-02-12T22:59:02Z")

</div>

Hello, so we are starting a project where we are moving to ELK 7, with the Elasticsearch and Kibana being offered by elastic.co rather than self hosted. In our ELK6 install, I had a Nginx loadbalancer balancing our logs…

---

## [Custom log for Filebeat DaemonSet running on Kubernetes](https://discuss.elastic.co/t/custom-log-for-filebeat-daemonset-running-on-kubernetes/219031)

<div class="topic-metadata">

**Author:** [@AndresL](https://discuss.elastic.co/u/AndresL)\
**Replies:** 0\
**Last updated:** [February 12, 2020, 3:32pm UTC](https://discuss.elastic.co/t/custom-log-for-filebeat-daemonset-running-on-kubernetes/219031 "2020-02-12T15:32:00Z")

</div>

Hi, i deployed a filebeat daemon set And i would like to use a custom folder, like /var/mylogs I configure filebeat to read from "/var/mylogs" and create a volume. But it is not getting any data. This is the confi…

---

## [Metricbeat won't work with spaces](https://discuss.elastic.co/t/metricbeat-wont-work-with-spaces/219016)

<div class="topic-metadata">

**Author:** [@BorisM](https://discuss.elastic.co/u/BorisM)\
**Replies:** 0\
**Last updated:** [February 12, 2020, 2:50pm UTC](https://discuss.elastic.co/t/metricbeat-wont-work-with-spaces/219016 "2020-02-12T14:50:44Z")

</div>

Hello, we have ELK 7.5.1 setup and different clusters that we want to report into different Kibana spaces that we created for such purpose. We have configured various beats to report into their respective indexes and th…

---

## [How can I use filebeat to get docker container logs and daemon logs to forward to logstash](https://discuss.elastic.co/t/how-can-i-use-filebeat-to-get-docker-container-logs-and-daemon-logs-to-forward-to-logstash/219008)

<div class="topic-metadata">

**Author:** [@BIs1](https://discuss.elastic.co/u/BIs1)\
**Replies:** 0\
**Last updated:** [February 12, 2020, 2:14pm UTC](https://discuss.elastic.co/t/how-can-i-use-filebeat-to-get-docker-container-logs-and-daemon-logs-to-forward-to-logstash/219008 "2020-02-12T14:14:35Z")

</div>

Hi, I am trying to get logs from docker container which is running apache/nifi on centos box. How can I use filebeat to get those nifi logs and forward it to logstash? When I use command "docker logs d2c8975d5c26" I ca…

---

## [Filebeat tags not reflected in kibana](https://discuss.elastic.co/t/filebeat-tags-not-reflected-in-kibana/218383)

<div class="topic-metadata">

**Author:** [@Chop](https://discuss.elastic.co/u/Chop)\
**Replies:** 0\
**Last updated:** [February 7, 2020, 4:29pm UTC](https://discuss.elastic.co/t/filebeat-tags-not-reflected-in-kibana/218383 "2020-02-07T16:29:11Z")

</div>

hi, i have been working with kibana and forwarding logs with filebeat. right now i have a situation where 2 servers are getting a different tag than the one i supplied. Filebeat configuration: max\_procs: 1 filebeat.…

---

## [Minimize Packet loss with af\_packet](https://discuss.elastic.co/t/minimize-packet-loss-with-af-packet/218976)

<div class="topic-metadata">

**Author:** [@interestinelk](https://discuss.elastic.co/u/interestinelk)\
**Replies:** 0\
**Last updated:** [February 12, 2020, 12:40pm UTC](https://discuss.elastic.co/t/minimize-packet-loss-with-af-packet/218976 "2020-02-12T12:40:00Z")

</div>

I try to use Packetbeat for network monitoring. If I use Packetbeat with pcap, I get network traffic successfully but some packets dropped. When I check the logs I see "Fail to parse HTTP parameters" If I add af\_packe…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=275)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=277)
