# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=277

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 278

---

## [Filebeat not using new pipeline](https://discuss.elastic.co/t/filebeat-not-using-new-pipeline/218223)

<div class="topic-metadata">

**Author:** [@ethranes](https://discuss.elastic.co/u/ethranes)\
**Replies:** 3\
**Last updated:** [February 12, 2020, 12:14pm UTC](https://discuss.elastic.co/t/filebeat-not-using-new-pipeline/218223 "2020-02-12T12:14:08Z")

</div>

Hi, I have created the following pipeline in the dev tools menu PUT \_ingest/pipeline/filebeat-ssologin { "processors": \[ { "dissect": { "field": "message", "pattern": "%{date} \[%{log.logger}\]…

---

## [Filter instances](https://discuss.elastic.co/t/filter-instances/214372)

<div class="topic-metadata">

**Author:** [@Samerd](https://discuss.elastic.co/u/Samerd)\
**Replies:** 2\
**Last updated:** [February 12, 2020, 12:06pm UTC](https://discuss.elastic.co/t/filter-instances/214372 "2020-02-12T12:06:48Z")

</div>

Hi, i want to monitor specific instance only called 'logz\_io': Can we use filter instances : i found this example , but it is not working : - module: aws period: 10s metricsets: - ec2 defau…

---

## [Metrics on specific region](https://discuss.elastic.co/t/metrics-on-specific-region/214371)

<div class="topic-metadata">

**Author:** [@Samerd](https://discuss.elastic.co/u/Samerd)\
**Replies:** 2\
**Last updated:** [February 12, 2020, 12:05pm UTC](https://discuss.elastic.co/t/metrics-on-specific-region/214371 "2020-02-12T12:05:00Z")

</div>

Hi , I'm trying to choose specific region to specify the instances which includes in the chosen region only . i used this section , but it doesn't work: - module: aws period: 10s metricsets: - ec2…

---

## [\[Feature request\] resolve service port numbers](https://discuss.elastic.co/t/feature-request-resolve-service-port-numbers/218949)

<div class="topic-metadata">

**Author:** [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Replies:** 0\
**Last updated:** [February 12, 2020, 10:55am UTC](https://discuss.elastic.co/t/feature-request-resolve-service-port-numbers/218949 "2020-02-12T10:55:46Z")

</div>

That would be great to have a processor for translating network port numbers to their names and descriptions based on IANA registry. The result could look like this: Thanks a lot!

---

## [Beats configuration help](https://discuss.elastic.co/t/beats-configuration-help/216081)

<div class="topic-metadata">

**Author:** [@Walter\_Hiranpat](https://discuss.elastic.co/u/Walter_Hiranpat)\
**Replies:** 5\
**Last updated:** [February 12, 2020, 10:38am UTC](https://discuss.elastic.co/t/beats-configuration-help/216081 "2020-02-12T10:38:24Z")

</div>

I have deploy an elastic stack mostly using just kibana and elasticsearch (3 master, 5 data, 5 ingest nodes) version 7.5 . I have about 20 application servers and that I installed the beats on each of these servers. It …

---

## [Winlogbeat and latest ECS + commandline](https://discuss.elastic.co/t/winlogbeat-and-latest-ecs-commandline/218935)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 0\
**Last updated:** [February 12, 2020, 9:51am UTC](https://discuss.elastic.co/t/winlogbeat-and-latest-ecs-commandline/218935 "2020-02-12T09:51:11Z")

</div>

Hi, Im on 7.5, i have checked 7.6 release notes and cannot see anything about updating winlogbeats to the latest ECS, it seems to be on 1.1 still, when will this be coming? Also command\_line is converted to process.arg…

---

## [\[Filebeat\] Cisco Security Intelligence Events - Connection-Started Events not Parsed properly](https://discuss.elastic.co/t/filebeat-cisco-security-intelligence-events-connection-started-events-not-parsed-properly/218908)

<div class="topic-metadata">

**Author:** [@Nicholas\_Penning](https://discuss.elastic.co/u/Nicholas_Penning)\
**Replies:** 1\
**Last updated:** [February 12, 2020, 6:53am UTC](https://discuss.elastic.co/t/filebeat-cisco-security-intelligence-events-connection-started-events-not-parsed-properly/218908 "2020-02-12T06:53:31Z")

</div>

Greetings! The Cisco FTD FileBeat module is awesome and works very well. However, I noticed a possible bug with the ingest pipeline or maybe it's something that I have misconfigured. Any of the events from the Cisco FT…

---

## [Combining ES pipelines: custom and module's ones](https://discuss.elastic.co/t/combining-es-pipelines-custom-and-modules-ones/218858)

<div class="topic-metadata">

**Author:** [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Replies:** 0\
**Last updated:** [February 11, 2020, 8:09pm UTC](https://discuss.elastic.co/t/combining-es-pipelines-custom-and-modules-ones/218858 "2020-02-11T20:09:13Z")

</div>

I'd like to use a custom pipeline for some logs and collect system events - everything by a single Filebeat instance. The question - is the following config "a good way" to do that? I had to configure index names and pip…

---

## [Beat output.logstash to reverse proxy](https://discuss.elastic.co/t/beat-output-logstash-to-reverse-proxy/218868)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [February 11, 2020, 9:55pm UTC](https://discuss.elastic.co/t/beat-output-logstash-to-reverse-proxy/218868 "2020-02-11T21:55:08Z")

</div>

My beats ingest for my logstash instance sits behind a reverse proxy, located at: logstash:443/beats When I use the following configuration in my filebeat.yml (or any \*beat.yml file): output.logstash.hosts: \["logstash:…

---

## [Filebeat If Statement Ingest Processor not Working](https://discuss.elastic.co/t/filebeat-if-statement-ingest-processor-not-working/218685)

<div class="topic-metadata">

**Author:** [@savethebyte](https://discuss.elastic.co/u/savethebyte)\
**Replies:** 2\
**Last updated:** [February 11, 2020, 4:05pm UTC](https://discuss.elastic.co/t/filebeat-if-statement-ingest-processor-not-working/218685 "2020-02-11T16:05:32Z")

</div>

Hello, I am trying to map an IP address to a hostname with an If statement on an ingest pipeline. These IPs are not in DNS and need to have a hostname associated to them for reporting. If I remove the "if" statement, …

---

## [Common MetricBeat issue - "The request for this panel failed The aggregations key is missing from the response, check your permissions for this request"](https://discuss.elastic.co/t/common-metricbeat-issue-the-request-for-this-panel-failed-the-aggregations-key-is-missing-from-the-response-check-your-permissions-for-this-request/218813)

<div class="topic-metadata">

**Author:** [@northy](https://discuss.elastic.co/u/northy)\
**Replies:** 0\
**Last updated:** [February 11, 2020, 4:02pm UTC](https://discuss.elastic.co/t/common-metricbeat-issue-the-request-for-this-panel-failed-the-aggregations-key-is-missing-from-the-response-check-your-permissions-for-this-request/218813 "2020-02-11T16:02:36Z")

</div>

Hi all, At the risk of being redundant, I have an issue i Kibana regarding the above error when I try to view visualisations in kibana. I've noticed this error on forums in many different forms, but as of yet I've been …

---

## [Parsing timestamp from log](https://discuss.elastic.co/t/parsing-timestamp-from-log/218804)

<div class="topic-metadata">

**Author:** [@carrot](https://discuss.elastic.co/u/carrot)\
**Replies:** 0\
**Last updated:** [February 11, 2020, 3:41pm UTC](https://discuss.elastic.co/t/parsing-timestamp-from-log/218804 "2020-02-11T15:41:05Z")

</div>

I'm trying to parse timestamp from our Traffic Server diags log with filebeat. \[Feb 11 15:31:05.152\] Server {0x2ae10580cd40} NOTE: ssl\_multicert.config done reloading! \[Feb 11 15:31:05.340\] Server {0x2ae10580cd40} NOTE…

---

## [Failed to publish events: write tcp write: broken pipe](https://discuss.elastic.co/t/failed-to-publish-events-write-tcp-write-broken-pipe/218799)

<div class="topic-metadata">

**Author:** [@juuuhuuu](https://discuss.elastic.co/u/juuuhuuu)\
**Replies:** 0\
**Last updated:** [February 11, 2020, 3:24pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-write-tcp-write-broken-pipe/218799 "2020-02-11T15:24:09Z")

</div>

Hi Team, Could you please give me some tips tricks ... what else shloud I try .. My filebeats.conf filebeat.inputs: type: log paths: /ttt/apache-daily-access.log scan\_frequency: 10s output.logstash: enabled: t…

---

## [Using METRICBEAT to monitor rds mysql databases](https://discuss.elastic.co/t/using-metricbeat-to-monitor-rds-mysql-databases/218789)

<div class="topic-metadata">

**Author:** [@robbrazil](https://discuss.elastic.co/u/robbrazil)\
**Replies:** 0\
**Last updated:** [February 11, 2020, 2:31pm UTC](https://discuss.elastic.co/t/using-metricbeat-to-monitor-rds-mysql-databases/218789 "2020-02-11T14:31:50Z")

</div>

I used metric beat on a proxysql server to monitor mysql on /etc/metricbeat/modules.d/mysql.yml I added successfully one HOST to this file but i need to monitor one master db and 4 replicas. How can i do that? Thanks

---

## [Filebeat, s3access & ECS](https://discuss.elastic.co/t/filebeat-s3access-ecs/218011)

<div class="topic-metadata">

**Author:** [@cosmo](https://discuss.elastic.co/u/cosmo)\
**Replies:** 1\
**Last updated:** [February 11, 2020, 2:22pm UTC](https://discuss.elastic.co/t/filebeat-s3access-ecs/218011 "2020-02-11T14:22:03Z")

</div>

Hello Looking to start migrating to ECS, for all the benefits listed on the blog Got nginx running through the filebeat modules, happy days (although the blog post suggests I should have event.original and message fiel…

---

## [No logs shipped from Kubernetes Filebeat](https://discuss.elastic.co/t/no-logs-shipped-from-kubernetes-filebeat/215899)

<div class="topic-metadata">

**Author:** [@jmgirven](https://discuss.elastic.co/u/jmgirven)\
**Replies:** 7\
**Last updated:** [February 11, 2020, 1:34pm UTC](https://discuss.elastic.co/t/no-logs-shipped-from-kubernetes-filebeat/215899 "2020-02-11T13:34:25Z")

</div>

I am running filebeats 7.5.1 on my kubernetes cluster as described in the section "Get started in minutes" "Hosted" "Kubernetes Logs" from here: https://www.elastic.co/what-is/kubernetes-monitoring With the exception t…

---

## [Redundant Elastic Cluster](https://discuss.elastic.co/t/redundant-elastic-cluster/218762)

<div class="topic-metadata">

**Author:** [@Neropointer](https://discuss.elastic.co/u/Neropointer)\
**Replies:** 1\
**Last updated:** [February 11, 2020, 12:40pm UTC](https://discuss.elastic.co/t/redundant-elastic-cluster/218762 "2020-02-11T12:40:42Z")

</div>

I created a cluster with two nodes on two servers. Each has kibana, elasticsearch, logstash and filebeat installed. The log files are being copied with a cronjob (Admin reasons) from the the servers i want to log to both…

---

## [Metricbeat failed with Certificate error](https://discuss.elastic.co/t/metricbeat-failed-with-certificate-error/218744)

<div class="topic-metadata">

**Author:** [@kasim123](https://discuss.elastic.co/u/kasim123)\
**Replies:** 0\
**Last updated:** [February 11, 2020, 9:32am UTC](https://discuss.elastic.co/t/metricbeat-failed-with-certificate-error/218744 "2020-02-11T09:32:40Z")

</div>

Hi Team, I have configure EFK with xpack enabled. I was able to configure kibana and fluent-bit with same ssl certificates. Now i am trying to configure metricbeat in my cluster. It failed to pass readiness probe ch…

---

## [Auditd module is not working in auditbeat daemonset configuration](https://discuss.elastic.co/t/auditd-module-is-not-working-in-auditbeat-daemonset-configuration/218712)

<div class="topic-metadata">

**Author:** [@Rimamartur](https://discuss.elastic.co/u/Rimamartur)\
**Replies:** 0\
**Last updated:** [February 11, 2020, 6:13am UTC](https://discuss.elastic.co/t/auditd-module-is-not-working-in-auditbeat-daemonset-configuration/218712 "2020-02-11T06:13:00Z")

</div>

auditd module is not working in auditbeat daemonset configuration. The Auditbeat pods go in crashbackloop state

---

## [Memprofile shows memory usage way below expected](https://discuss.elastic.co/t/memprofile-shows-memory-usage-way-below-expected/218672)

<div class="topic-metadata">

**Author:** [@carlsoane](https://discuss.elastic.co/u/carlsoane)\
**Replies:** 0\
**Last updated:** [February 10, 2020, 9:09pm UTC](https://discuss.elastic.co/t/memprofile-shows-memory-usage-way-below-expected/218672 "2020-02-10T21:09:54Z")

</div>

I have a series of filebeats running in a kubernetes environment that are being repeatedly OOMKilled. I have my filebeat pods configured to run with memory requests of 250m and limits of 500m. I run the filebeats with --…

---

## [Tracebeat - root privileges](https://discuss.elastic.co/t/tracebeat-root-privileges/218667)

<div class="topic-metadata">

**Author:** [@Rysiu](https://discuss.elastic.co/u/Rysiu)\
**Replies:** 1\
**Last updated:** [February 10, 2020, 8:42pm UTC](https://discuss.elastic.co/t/tracebeat-root-privileges/218667 "2020-02-10T20:42:31Z")

</div>

Hi, I have a question about tracebeat. Tracebeat available at the address: The problem is probably classic. Can I run tracebeat somehow without root privileges? Is there any possibility?

---

## [Filebeat not reporting in](https://discuss.elastic.co/t/filebeat-not-reporting-in/218488)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 1\
**Last updated:** [February 10, 2020, 8:12pm UTC](https://discuss.elastic.co/t/filebeat-not-reporting-in/218488 "2020-02-10T20:12:35Z")

</div>

I am trying to get filebeat to report in to Kibana. It shows that the service is running on the host, but when i do a status on filebeat, I get lines like this: 2020-02-09T23:23:59.136Z ERROR pipeline/out…

---

## [How to push logs to elasticsearch in filebeat?](https://discuss.elastic.co/t/how-to-push-logs-to-elasticsearch-in-filebeat/218501)

<div class="topic-metadata">

**Author:** [@111289](https://discuss.elastic.co/u/111289)\
**Replies:** 1\
**Last updated:** [February 10, 2020, 7:59pm UTC](https://discuss.elastic.co/t/how-to-push-logs-to-elasticsearch-in-filebeat/218501 "2020-02-10T19:59:57Z")

</div>

hear is my filebeat.yml filebeat.inputs: - type: log enabled: true paths: - ../typescript/rate-limit-test/logs/\*.log json.message\_key: "message" json.keys\_under\_root: true json.overwrite\_keys: true scan\_…

---

## [I want know how to configure filebeat, Logstash and Elastic search](https://discuss.elastic.co/t/i-want-know-how-to-configure-filebeat-logstash-and-elastic-search/218515)

<div class="topic-metadata">

**Author:** [@chandrasekhar.panchi](https://discuss.elastic.co/u/chandrasekhar.panchi)\
**Replies:** 1\
**Last updated:** [February 10, 2020, 7:49pm UTC](https://discuss.elastic.co/t/i-want-know-how-to-configure-filebeat-logstash-and-elastic-search/218515 "2020-02-10T19:49:49Z")

</div>

Hi All, I want to know how to do the below requirement, File beats should be installed in Linux nodes where the logs resides, and Elastic search and Log stash should be installed in Windows Master, where logs are fetch…

---

## [Filebeat modules 7.5 vs. 8.0](https://discuss.elastic.co/t/filebeat-modules-7-5-vs-8-0/218658)

<div class="topic-metadata">

**Author:** [@Jim\_Ivey](https://discuss.elastic.co/u/Jim_Ivey)\
**Replies:** 0\
**Last updated:** [February 10, 2020, 7:01pm UTC](https://discuss.elastic.co/t/filebeat-modules-7-5-vs-8-0/218658 "2020-02-10T19:01:37Z")

</div>

I'm trying to develop a filebeat module for an Ubuntu 14.04 system running filebeat 7.5.0. I'll soon be developing for an Ubuntu 18 environment, but I'm stuck with 14 for now. I can't actually develop on the Ubuntu 14 …

---

## [Heartbeat list of host help](https://discuss.elastic.co/t/heartbeat-list-of-host-help/217415)

<div class="topic-metadata">

**Author:** [@delatucci](https://discuss.elastic.co/u/delatucci)\
**Replies:** 8\
**Last updated:** [February 10, 2020, 5:41pm UTC](https://discuss.elastic.co/t/heartbeat-list-of-host-help/217415 "2020-02-10T17:41:16Z")

</div>

Hi all, I am trying to configure an icmp.yml file to ping a list of hosts on my network. I got it to ping the host that part is working, how do I add name: to the list of host. type: icmp enabled: true schedule: '@…

---

## [How to use installed existing certificates in Windows servers to secure communication with logstash/elasticsearch?](https://discuss.elastic.co/t/how-to-use-installed-existing-certificates-in-windows-servers-to-secure-communication-with-logstash-elasticsearch/218643)

<div class="topic-metadata">

**Author:** [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Replies:** 0\
**Last updated:** [February 10, 2020, 4:52pm UTC](https://discuss.elastic.co/t/how-to-use-installed-existing-certificates-in-windows-servers-to-secure-communication-with-logstash-elasticsearch/218643 "2020-02-10T16:52:31Z")

</div>

Instead of placing the certs and keys in Winlogbeats folder, what is the yml config to use installed certificates in Windows server?

---

## [Sudden logstash-filebeat i/o timeout errors](https://discuss.elastic.co/t/sudden-logstash-filebeat-i-o-timeout-errors/218625)

<div class="topic-metadata">

**Author:** [@cbontempi](https://discuss.elastic.co/u/cbontempi)\
**Replies:** 0\
**Last updated:** [February 10, 2020, 3:32pm UTC](https://discuss.elastic.co/t/sudden-logstash-filebeat-i-o-timeout-errors/218625 "2020-02-10T15:32:12Z")

</div>

I have been running a logstash (docker) and filebeat (Windows 10) combination for about 5 months, and recently I've started seeing some "i/o timeout" errors on the filebeat side. One particular site (of a total of 10 si…

---

## [Under Infrastructure Change Host name to IP address](https://discuss.elastic.co/t/under-infrastructure-change-host-name-to-ip-address/218578)

<div class="topic-metadata">

**Author:** [@Harshil\_Narielwala](https://discuss.elastic.co/u/Harshil_Narielwala)\
**Replies:** 0\
**Last updated:** [February 10, 2020, 11:58am UTC](https://discuss.elastic.co/t/under-infrastructure-change-host-name-to-ip-address/218578 "2020-02-10T11:58:00Z")

</div>

Hi, IN ELK 7.2.1 version under infrastructure I want to change the Name have hostname to the public IP address of the host Kindly let me know what's the solution

---

## [Metricbeat add\_kubernetes\_metadata on prometheus module does not add kubernetes metadata](https://discuss.elastic.co/t/metricbeat-add-kubernetes-metadata-on-prometheus-module-does-not-add-kubernetes-metadata/218547)

<div class="topic-metadata">

**Author:** [@Babadofar](https://discuss.elastic.co/u/Babadofar)\
**Replies:** 0\
**Last updated:** [February 10, 2020, 9:11am UTC](https://discuss.elastic.co/t/metricbeat-add-kubernetes-metadata-on-prometheus-module-does-not-add-kubernetes-metadata/218547 "2020-02-10T09:11:24Z")

</div>

Hi there. I'm using the prometheus module to collect Spring Boot actuator metrics from. The metrics are coming in to elasticsearch fine, but the kubernetes metadata is not added to the events. I suspect this may have to…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=276)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=278)
