# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=278

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 279

---

## [ELK - MetricBeat dataflow](https://discuss.elastic.co/t/elk-metricbeat-dataflow/218543)

<div class="topic-metadata">

**Author:** [@iniyan.g](https://discuss.elastic.co/u/iniyan.g)\
**Replies:** 0\
**Last updated:** [February 10, 2020, 8:38am UTC](https://discuss.elastic.co/t/elk-metricbeat-dataflow/218543 "2020-02-10T08:38:52Z")

</div>

Hi ELK Team We are currently working on to setup instance/VM level monitoring using beats. We have chosen Metricbeat for pushing VM data to logstash and to elasticsearch. As of now, we are evaluating this only for 2 cli…

---

## [Some metricbeat.mssql.performance Metrics Not Returning Values](https://discuss.elastic.co/t/some-metricbeat-mssql-performance-metrics-not-returning-values/218493)

<div class="topic-metadata">

**Author:** [@wtg-bko](https://discuss.elastic.co/u/wtg-bko)\
**Replies:** 0\
**Last updated:** [February 10, 2020, 12:48am UTC](https://discuss.elastic.co/t/some-metricbeat-mssql-performance-metrics-not-returning-values/218493 "2020-02-10T00:48:36Z")

</div>

Hi, I want to report a bug I discovered. Some of the metrics in metricbeat.mssql.performance module did not return any values for me and I tried to debug this but did not find any useful logs from metricbeat itself. I t…

---

## [Mapping definition for \[name\] has unsupported parameters: \[path : docker.container.image\]](https://discuss.elastic.co/t/mapping-definition-for-name-has-unsupported-parameters-path-docker-container-image/215904)

<div class="topic-metadata">

**Author:** [@realyn\_elastic](https://discuss.elastic.co/u/realyn_elastic)\
**Replies:** 2\
**Last updated:** [February 9, 2020, 3:15pm UTC](https://discuss.elastic.co/t/mapping-definition-for-name-has-unsupported-parameters-path-docker-container-image/215904 "2020-02-09T15:15:09Z")

</div>

Hello team, I am facing the following issue whenever I try to roll over the winlogbeat index. I checked my document, and couldn't find any field related to docker at all. I am using default template mapping that is bein…

---

## [Monitoring AWS EC2 using Metricbeat](https://discuss.elastic.co/t/monitoring-aws-ec2-using-metricbeat/218304)

<div class="topic-metadata">

**Author:** [@bsteele1832](https://discuss.elastic.co/u/bsteele1832)\
**Replies:** 2\
**Last updated:** [February 8, 2020, 1:38pm UTC](https://discuss.elastic.co/t/monitoring-aws-ec2-using-metricbeat/218304 "2020-02-08T13:38:17Z")

</div>

I can't get Metricbeat to collect data from AWS about my EC2 instances. I have done the following: Installed Metricbeat. Enables the AWS module. Configured the modules.d/aws.yml in a million differnt ways. Started Metr…

---

## [Filebeat debug message](https://discuss.elastic.co/t/filebeat-debug-message/218314)

<div class="topic-metadata">

**Author:** [@TimTim](https://discuss.elastic.co/u/TimTim)\
**Replies:** 2\
**Last updated:** [February 8, 2020, 10:00am UTC](https://discuss.elastic.co/t/filebeat-debug-message/218314 "2020-02-08T10:00:04Z")

</div>

Hi! i'm running Filebeat 7.5.1 at the moment and now we are implementing the Centralized Management. It's going good (17 servers so far converted), but my latest one is giving me a headache... I enrolled without a prob…

---

## [Missing events from Windows Event Collector (WEC)](https://discuss.elastic.co/t/missing-events-from-windows-event-collector-wec/218415)

<div class="topic-metadata">

**Author:** [@\_finack](https://discuss.elastic.co/u/_finack)\
**Replies:** 0\
**Last updated:** [February 7, 2020, 9:11pm UTC](https://discuss.elastic.co/t/missing-events-from-windows-event-collector-wec/218415 "2020-02-07T21:11:18Z")

</div>

Issue: I am missing at least some events that exist on the WEC in Elasticsearch. The Environment: I am testing Elastic Stack. At the moment, I have a single Ubuntu server running Logstash, Elasticsearch, and Kibana with…

---

## [General Search Not working on Field](https://discuss.elastic.co/t/general-search-not-working-on-field/216912)

<div class="topic-metadata">

**Author:** [@jeffreygatsby](https://discuss.elastic.co/u/jeffreygatsby)\
**Replies:** 3\
**Last updated:** [February 7, 2020, 6:14pm UTC](https://discuss.elastic.co/t/general-search-not-working-on-field/216912 "2020-02-07T18:14:08Z")

</div>

I'm using FunctionBeat to export ECS logs to Elastic Cloud. Here is my configuration: functionbeat.provider.aws.deploy\_bucket: "gatsby-deploy" functionbeat.provider.aws.functions: - name: ProdServiceLogs enabled:…

---

## [MISP Module Polling Interval](https://discuss.elastic.co/t/misp-module-polling-interval/217468)

<div class="topic-metadata">

**Author:** [@will-secops](https://discuss.elastic.co/u/will-secops)\
**Replies:** 9\
**Last updated:** [February 7, 2020, 4:25pm UTC](https://discuss.elastic.co/t/misp-module-polling-interval/217468 "2020-02-07T16:25:23Z")

</div>

I'm using the MISP module with Filebeat 7.5.0. With the default configuration, it will do a single query against the MISP instance, process everything it finds, and then do nothing until the Filebeat process is restarte…

---

## [Duplicate beat.uuids on different hosts](https://discuss.elastic.co/t/duplicate-beat-uuids-on-different-hosts/218184)

<div class="topic-metadata">

**Author:** [@rozling](https://discuss.elastic.co/u/rozling)\
**Replies:** 3\
**Last updated:** [February 7, 2020, 2:53pm UTC](https://discuss.elastic.co/t/duplicate-beat-uuids-on-different-hosts/218184 "2020-02-07T14:53:29Z")

</div>

Hi, I'll preface this by saying I have a ticket open with Elastic Support about this, but since it's a really weird one IMO, I thought'd I'd post here in case anyone else has seen it. Basically we're sending monitoring…

---

## [There is no data to display - Infrastructure tab](https://discuss.elastic.co/t/there-is-no-data-to-display-infrastructure-tab/217373)

<div class="topic-metadata">

**Author:** [@ch0k](https://discuss.elastic.co/u/ch0k)\
**Replies:** 13\
**Last updated:** [February 7, 2020, 2:53pm UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-infrastructure-tab/217373 "2020-02-07T14:53:16Z")

</div>

Hi, I can't display Hosts in the Infrastructure tab in Kibana. I checked the other threads on the forum but it still doesn't work. Can you please help me? Metricbeat is installed on multiple servers and they send data …

---

## [Filebeat module netflow - modify netflow @timestamp by the current time](https://discuss.elastic.co/t/filebeat-module-netflow-modify-netflow-timestamp-by-the-current-time/217165)

<div class="topic-metadata">

**Author:** [@Bruno1](https://discuss.elastic.co/u/Bruno1)\
**Replies:** 2\
**Last updated:** [February 7, 2020, 2:50pm UTC](https://discuss.elastic.co/t/filebeat-module-netflow-modify-netflow-timestamp-by-the-current-time/217165 "2020-02-07T14:50:24Z")

</div>

Hello, I have a problem, the netflow filebeat module keep the timestamp of inside the netflow packet. Here 1993-12-03..., but I want modify this value by the current time. For now I have: Blockquote { "@timestamp":…

---

## [Filebeat is running on two different systems with two different modules but no documents appear in filebeat indx](https://discuss.elastic.co/t/filebeat-is-running-on-two-different-systems-with-two-different-modules-but-no-documents-appear-in-filebeat-indx/218360)

<div class="topic-metadata">

**Author:** [@dsdameron](https://discuss.elastic.co/u/dsdameron)\
**Replies:** 1\
**Last updated:** [February 7, 2020, 2:20pm UTC](https://discuss.elastic.co/t/filebeat-is-running-on-two-different-systems-with-two-different-modules-but-no-documents-appear-in-filebeat-indx/218360 "2020-02-07T14:20:27Z")

</div>

We have a filebeat with the panw module enabled collecting data from Palo Alto Firewalls.On a separate system, we have filebeat running with the system module enabled. The data is being received by elastic search but the…

---

## [Help with Processors in filebeat modules](https://discuss.elastic.co/t/help-with-processors-in-filebeat-modules/215711)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 8\
**Last updated:** [February 7, 2020, 12:50pm UTC](https://discuss.elastic.co/t/help-with-processors-in-filebeat-modules/215711 "2020-02-07T12:50:44Z")

</div>

Hi, I'm having a lot of issues trying to figure out how to filter out log lines before they are indexed. After failing using "exclude\_lines" for a couple of times, I quickly moved to the use of processors. The main cons…

---

## [Winlogbeat 7.5.2 no data in discovery?](https://discuss.elastic.co/t/winlogbeat-7-5-2-no-data-in-discovery/218177)

<div class="topic-metadata">

**Author:** [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Replies:** 2\
**Last updated:** [February 7, 2020, 9:53am UTC](https://discuss.elastic.co/t/winlogbeat-7-5-2-no-data-in-discovery/218177 "2020-02-07T09:53:39Z")

</div>

Hi All, I just set up winlogbeat on a domain controller to check for failed AD logins. I am wondering, that I have really many documents in my discovery, but all of them are "empty". On the other side, in SIEM I can se…

---

## [Single yml file for metricbeat](https://discuss.elastic.co/t/single-yml-file-for-metricbeat/218286)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 1\
**Last updated:** [February 7, 2020, 8:37am UTC](https://discuss.elastic.co/t/single-yml-file-for-metricbeat/218286 "2020-02-07T08:37:54Z")

</div>

Hello All , I tried to configure single metricbeat.yml for all the servers.PFB yml file and error . But i am able to directly access the path from Run . But when i run from cmd receiving the below error . Kindly help. \>…

---

## [Deploying a new filebeat module](https://discuss.elastic.co/t/deploying-a-new-filebeat-module/217085)

<div class="topic-metadata">

**Author:** [@Jim\_Ivey](https://discuss.elastic.co/u/Jim_Ivey)\
**Replies:** 4\
**Last updated:** [February 6, 2020, 9:41pm UTC](https://discuss.elastic.co/t/deploying-a-new-filebeat-module/217085 "2020-02-06T21:41:31Z")

</div>

Sorry for peppering the boards here with countless questions. You guys have been extremely helpful and I successfully created my module and it passed all tests. Thanks so much! Now, I'm trying to deploy my module to a…

---

## ['mage' is not recognized as an internal or external command](https://discuss.elastic.co/t/mage-is-not-recognized-as-an-internal-or-external-command/217082)

<div class="topic-metadata">

**Author:** [@Yiw](https://discuss.elastic.co/u/Yiw)\
**Replies:** 23\
**Last updated:** [February 6, 2020, 7:54pm UTC](https://discuss.elastic.co/t/mage-is-not-recognized-as-an-internal-or-external-command/217082 "2020-02-06T19:54:23Z")

</div>

Hi all, I am having an issue and hoping you have seen this previously. #Using Windows 10# I cloned the beats source code according to https://www.elastic.co/guide/en/beats/devguide/current/beats-contributing.html Whe…

---

## [How to separate a log line by line](https://discuss.elastic.co/t/how-to-separate-a-log-line-by-line/217232)

<div class="topic-metadata">

**Author:** [@Ben240489](https://discuss.elastic.co/u/Ben240489)\
**Replies:** 4\
**Last updated:** [February 6, 2020, 3:34pm UTC](https://discuss.elastic.co/t/how-to-separate-a-log-line-by-line/217232 "2020-02-06T15:34:28Z")

</div>

Hi, I'm pretty new here and I am experimenting with ELK. One thing I couldn't figure out until now is: How can I parse a log line by line with each line becoming its own event? For example, I have a log file which look…

---

## [How to add ssl certificate for MySQL connection for metricbeat](https://discuss.elastic.co/t/how-to-add-ssl-certificate-for-mysql-connection-for-metricbeat/217851)

<div class="topic-metadata">

**Author:** [@Aurel\_Drejta](https://discuss.elastic.co/u/Aurel_Drejta)\
**Replies:** 5\
**Last updated:** [February 6, 2020, 1:09pm UTC](https://discuss.elastic.co/t/how-to-add-ssl-certificate-for-mysql-connection-for-metricbeat/217851 "2020-02-06T13:09:44Z")

</div>

Where can i add the SSL certificate to connect to MySQL server when i configure the MySQL module file (mysql.yaml)? Sorry if this is something obvious but i can't find it anywhere. https://www.elastic.co/guide/en/beats…

---

## [How to access Kibana APIs](https://discuss.elastic.co/t/how-to-access-kibana-apis/218171)

<div class="topic-metadata">

**Author:** [@SathishPrakasam](https://discuss.elastic.co/u/SathishPrakasam)\
**Replies:** 0\
**Last updated:** [February 6, 2020, 12:36pm UTC](https://discuss.elastic.co/t/how-to-access-kibana-apis/218171 "2020-02-06T12:36:11Z")

</div>

Hi Team, In metricbeat.yml we have a setting, Kibana Host Scheme and port can be left out and will be set to the default (http and 5601) In case you specify and additional path, the scheme is required: http://localhost…

---

## [Winlogbeat - ERROR checkpoint/checkpoint.go:199](https://discuss.elastic.co/t/winlogbeat-error-checkpoint-checkpoint-go-199/218086)

<div class="topic-metadata">

**Author:** [@Mickael1](https://discuss.elastic.co/u/Mickael1)\
**Replies:** 2\
**Last updated:** [February 6, 2020, 10:40am UTC](https://discuss.elastic.co/t/winlogbeat-error-checkpoint-checkpoint-go-199/218086 "2020-02-06T10:40:50Z")

</div>

Hi everyone, To explain you simply the architecture; we collect sources windows log through our Windows Log Collector and Collector Server forward logs to SOC team with a specify number of events ID with winlogbeat 6.8 …

---

## [Filebeat unable send MariaDB slowlogs data to kibana](https://discuss.elastic.co/t/filebeat-unable-send-mariadb-slowlogs-data-to-kibana/218130)

<div class="topic-metadata">

**Author:** [@Ritesh\_Pradhan](https://discuss.elastic.co/u/Ritesh_Pradhan)\
**Replies:** 0\
**Last updated:** [February 6, 2020, 9:30am UTC](https://discuss.elastic.co/t/filebeat-unable-send-mariadb-slowlogs-data-to-kibana/218130 "2020-02-06T09:30:38Z")

</div>

Dear Team, We are used Filebeat 6.4.2 version. Filebeat sending many logs to kibana like Tomcat, MariaDB error, Apache, etc, but If I add a path to MariaDB slowlog, after kibana is not loaded data and Filebeat through …

---

## [Beats from Source missing XPack Modules](https://discuss.elastic.co/t/beats-from-source-missing-xpack-modules/218090)

<div class="topic-metadata">

**Author:** [@brokenvhs](https://discuss.elastic.co/u/brokenvhs)\
**Replies:** 0\
**Last updated:** [February 6, 2020, 5:38am UTC](https://discuss.elastic.co/t/beats-from-source-missing-xpack-modules/218090 "2020-02-06T05:38:03Z")

</div>

I followed this user's post about building Beats from source for ARM But there's something missing, and I can't quite wrap my head around it (I think because I know zero about Go and mage). All of the modules that are…

---

## [Winlogbeat as a docker sibling/sidecar container](https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409)

<div class="topic-metadata">

**Author:** [@zhammer](https://discuss.elastic.co/u/zhammer)\
**Replies:** 5\
**Last updated:** [February 6, 2020, 4:47am UTC](https://discuss.elastic.co/t/winlogbeat-as-a-docker-sibling-sidecar-container/217409 "2020-02-06T04:47:38Z")

</div>

i'd like to ship winlogbeat as a sibling/sidecar container to an app container to ship an app's event logs, rather than as a windows service running within the app container. this would fit well with a current setup wher…

---

## [Using Winlogbeat to populate a CMDB and Application Portfolio](https://discuss.elastic.co/t/using-winlogbeat-to-populate-a-cmdb-and-application-portfolio/217246)

<div class="topic-metadata">

**Author:** [@ShivaKanou](https://discuss.elastic.co/u/ShivaKanou)\
**Replies:** 1\
**Last updated:** [February 6, 2020, 3:42am UTC](https://discuss.elastic.co/t/using-winlogbeat-to-populate-a-cmdb-and-application-portfolio/217246 "2020-02-06T03:42:43Z")

</div>

Hi all, I have a demand here at where I work to create a CMDB and a Application Portfolio. At first we thought about acquiring ServiceNow's Discovery or Dynatrace, but we'd like to test with ELK's Winlogbeat or any othe…

---

## [Failed to import dashboard: Failed to load directory](https://discuss.elastic.co/t/failed-to-import-dashboard-failed-to-load-directory/215079)

<div class="topic-metadata">

**Author:** [@Minh\_Ti\_n\_Tr\_n](https://discuss.elastic.co/u/Minh_Ti_n_Tr_n)\
**Replies:** 1\
**Last updated:** [February 6, 2020, 2:28am UTC](https://discuss.elastic.co/t/failed-to-import-dashboard-failed-to-load-directory/215079 "2020-02-06T02:28:13Z")

</div>

I got problem when setup winlogbeat Preformatted textPS C:\\Program Files\\Winlogbeat\> .\\winlogbeat.exe setup Index setup finished. Loading dashboards (Kibana must be running and reachable) Exiting: Failed to import da…

---

## [Winlogbeat not picking up all Application Logs](https://discuss.elastic.co/t/winlogbeat-not-picking-up-all-application-logs/214978)

<div class="topic-metadata">

**Author:** [@ted1621](https://discuss.elastic.co/u/ted1621)\
**Replies:** 1\
**Last updated:** [February 6, 2020, 2:24am UTC](https://discuss.elastic.co/t/winlogbeat-not-picking-up-all-application-logs/214978 "2020-02-06T02:24:03Z")

</div>

Under the Windows Application Logs I have a subfolder called DigitalPersona. I need to ship those logs to Kibana. Right now my winlogbeat.yml is configured as such: winlogbeat.event\_logs: name: Application ignore\_o…

---

## [Filebeat isnt applying logstash's grok pattern from one location](https://discuss.elastic.co/t/filebeat-isnt-applying-logstashs-grok-pattern-from-one-location/218059)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 0\
**Last updated:** [February 5, 2020, 10:29pm UTC](https://discuss.elastic.co/t/filebeat-isnt-applying-logstashs-grok-pattern-from-one-location/218059 "2020-02-05T22:29:08Z")

</div>

I have a file which when passed through my local system applies grok pattern. But when sent from server it doesnt apply gropk pattern. The file has same content but from different location has different outcomes. Does fi…

---

## [Feature List for Beats OSS vs Xpack versions](https://discuss.elastic.co/t/feature-list-for-beats-oss-vs-xpack-versions/217427)

<div class="topic-metadata">

**Author:** [@vNoob](https://discuss.elastic.co/u/vNoob)\
**Replies:** 2\
**Last updated:** [February 5, 2020, 6:09pm UTC](https://discuss.elastic.co/t/feature-list-for-beats-oss-vs-xpack-versions/217427 "2020-02-05T18:09:07Z")

</div>

Is there any beats documentation regarding which features are in the oss version vs the Elastic version? Is it the different modules? I found this but it doesn't really say how the beats differ between the versions Tha…

---

## [In filebeat, can we add a new field based on existing field?](https://discuss.elastic.co/t/in-filebeat-can-we-add-a-new-field-based-on-existing-field/218033)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 0\
**Last updated:** [February 5, 2020, 5:16pm UTC](https://discuss.elastic.co/t/in-filebeat-can-we-add-a-new-field-based-on-existing-field/218033 "2020-02-05T17:16:00Z")

</div>

Using filebeat 7.4.1 in container env ( Kubertes/docker/ daemon-set ) Can we add a new field based on existing properties ( either direct assignment or concatenate 2 fields etc ). ? Prefer if such a setting is part …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=277)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=279)
