# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=279

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 280

---

## [Trend Micro Apex one is blocking metricbeat](https://discuss.elastic.co/t/trend-micro-apex-one-is-blocking-metricbeat/217619)

<div class="topic-metadata">

**Author:** [@emilie](https://discuss.elastic.co/u/emilie)\
**Replies:** 1\
**Last updated:** [February 5, 2020, 3:53pm UTC](https://discuss.elastic.co/t/trend-micro-apex-one-is-blocking-metricbeat/217619 "2020-02-05T15:53:13Z")

</div>

Hello, When metricbeat is used on a Windows machine with Trend Micro Apex one and the modules metric metricbeat.modules: - module: system metricsets: \["process"\] period: 60s after a few seconds metricbeat i…

---

## [Missing network traffic from metricbeat on mac OS](https://discuss.elastic.co/t/missing-network-traffic-from-metricbeat-on-mac-os/217642)

<div class="topic-metadata">

**Author:** [@aviationfan](https://discuss.elastic.co/u/aviationfan)\
**Replies:** 1\
**Last updated:** [February 5, 2020, 3:28pm UTC](https://discuss.elastic.co/t/missing-network-traffic-from-metricbeat-on-mac-os/217642 "2020-02-05T15:28:37Z")

</div>

I am investigating an issue where one of my macs is reporting network traffic and the other is not. Both macs have High Sierra macOS 10.13.6 (17G11023). I include the build number because that changed last week when app…

---

## [Starting new filebeat agent and the time is incorrect on the UI](https://discuss.elastic.co/t/starting-new-filebeat-agent-and-the-time-is-incorrect-on-the-ui/218015)

<div class="topic-metadata">

**Author:** [@andras.vecsi](https://discuss.elastic.co/u/andras.vecsi)\
**Replies:** 0\
**Last updated:** [February 5, 2020, 3:23pm UTC](https://discuss.elastic.co/t/starting-new-filebeat-agent-and-the-time-is-incorrect-on-the-ui/218015 "2020-02-05T15:23:30Z")

</div>

Hello, What I see on the kibana UI The message in my logs are generated like this 2020-02-05 14:55:46.428 | DEBUG | http-nio-8089-exec-2 | CommonsRequestLoggingFilter:47 | Before request \[XXX\] The log was generated…

---

## [Configuring aws ec2 on metricbeat k8 deamonset throws errors](https://discuss.elastic.co/t/configuring-aws-ec2-on-metricbeat-k8-deamonset-throws-errors/216370)

<div class="topic-metadata">

**Author:** [@eyesmoker1](https://discuss.elastic.co/u/eyesmoker1)\
**Replies:** 5\
**Last updated:** [February 5, 2020, 2:03pm UTC](https://discuss.elastic.co/t/configuring-aws-ec2-on-metricbeat-k8-deamonset-throws-errors/216370 "2020-02-05T14:03:59Z")

</div>

Running es 7.5 and metricbeat 7.5 helm charts on k8s. Trying to get ec2 dashboard working on kibana but metricbeat throws following errors. Metricbeat code - module: aws period: 300s metricsets: …

---

## [Need help with importing Winlogbeat index template when using ILM and Logstash](https://discuss.elastic.co/t/need-help-with-importing-winlogbeat-index-template-when-using-ilm-and-logstash/217979)

<div class="topic-metadata">

**Author:** [@fdaa](https://discuss.elastic.co/u/fdaa)\
**Replies:** 0\
**Last updated:** [February 5, 2020, 11:38am UTC](https://discuss.elastic.co/t/need-help-with-importing-winlogbeat-index-template-when-using-ilm-and-logstash/217979 "2020-02-05T11:38:16Z")

</div>

How do I manually import the Winlogbeat index template when using ILM and Logstash with the following settings? I have tried every possible setting I can think of in my temporary winlogbeat.yml but can't get it to work. …

---

## [Error on UPTIME](https://discuss.elastic.co/t/error-on-uptime/217517)

<div class="topic-metadata">

**Author:** [@nikhilesh](https://discuss.elastic.co/u/nikhilesh)\
**Replies:** 3\
**Last updated:** [February 5, 2020, 10:35am UTC](https://discuss.elastic.co/t/error-on-uptime/217517 "2020-02-05T10:35:26Z")

</div>

ror: \[illegal\_argument\_exception\] Fielddata is disabled on text fields by default. Set fielddata=true on \[monitor.id\] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use…

---

## [Filebeat processors decode\_json\_fields with condition not working](https://discuss.elastic.co/t/filebeat-processors-decode-json-fields-with-condition-not-working/217903)

<div class="topic-metadata">

**Author:** [@Kunal\_Saha](https://discuss.elastic.co/u/Kunal_Saha)\
**Replies:** 0\
**Last updated:** [February 5, 2020, 5:18am UTC](https://discuss.elastic.co/t/filebeat-processors-decode-json-fields-with-condition-not-working/217903 "2020-02-05T05:18:57Z")

</div>

My log file has entries line below. {"name":"foo","hostname":"local","pid":21894,"level":30,"msg":"shail","time":"2017-11-03T17:02:28.001Z","v":0} {"name":"foo","hostname":"local","pid":21894,"level":30,"msg":"jitu","t…

---

## [Error.message HTTP error 403 in : 403 Forbidden event.dataset elasticsearch.enrich](https://discuss.elastic.co/t/error-message-http-error-403-in-403-forbidden-event-dataset-elasticsearch-enrich/216425)

<div class="topic-metadata">

**Author:** [@tennaen](https://discuss.elastic.co/u/tennaen)\
**Replies:** 5\
**Last updated:** [February 5, 2020, 7:30am UTC](https://discuss.elastic.co/t/error-message-http-error-403-in-403-forbidden-event-dataset-elasticsearch-enrich/216425 "2020-02-05T07:30:55Z")

</div>

I have this problem with metricbeat: error.message HTTP error 403 in : 403 Forbidden event.dataset elasticsearch.enrich This is my metricbeat.yml output.elasticsearch: # Array of hosts to connect to. hosts: \["my.…

---

## [Filebeat parsing issue](https://discuss.elastic.co/t/filebeat-parsing-issue/217914)

<div class="topic-metadata">

**Author:** [@Bubunia\_Patra](https://discuss.elastic.co/u/Bubunia_Patra)\
**Replies:** 0\
**Last updated:** [February 5, 2020, 6:47am UTC](https://discuss.elastic.co/t/filebeat-parsing-issue/217914 "2020-02-05T06:47:21Z")

</div>

Hi, I am trying to fix a issue in the filebeat configuration file where it adds newline to the parsed logs and forwards to graylog/ES. I want the log to be in single line rather than multiple line. Even if the file(acce…

---

## [Filebeat log path on Kubernetes](https://discuss.elastic.co/t/filebeat-log-path-on-kubernetes/217891)

<div class="topic-metadata">

**Author:** [@Matt\_Kirkevold](https://discuss.elastic.co/u/Matt_Kirkevold)\
**Replies:** 0\
**Last updated:** [February 4, 2020, 11:37pm UTC](https://discuss.elastic.co/t/filebeat-log-path-on-kubernetes/217891 "2020-02-04T23:37:44Z")

</div>

I am using the filebeat on kubernetes with autodiscover. In the default filebeat-config configmap the input path is /var/log/containers/\*${data.kubernetes.container.id}.log. In the Running Filebeat on Kubernetes docume…

---

## [VSphere Dashboards](https://discuss.elastic.co/t/vsphere-dashboards/217866)

<div class="topic-metadata">

**Author:** [@JValenzani](https://discuss.elastic.co/u/JValenzani)\
**Replies:** 0\
**Last updated:** [February 4, 2020, 7:40pm UTC](https://discuss.elastic.co/t/vsphere-dashboards/217866 "2020-02-04T19:40:07Z")

</div>

I couldn't found vsphere dashboards for MetricBeat 7.5.2. I've checked the repository and found 2 files: https://github.com/elastic/beats/tree/master/metricbeat/module/vsphere/\_meta/kibana/7/dashboard but i can't find th…

---

## [Missing value for server\_uptime in module apache](https://discuss.elastic.co/t/missing-value-for-server-uptime-in-module-apache/214237)

<div class="topic-metadata">

**Author:** [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Replies:** 2\
**Last updated:** [February 4, 2020, 7:16pm UTC](https://discuss.elastic.co/t/missing-value-for-server-uptime-in-module-apache/214237 "2020-02-04T19:16:37Z")

</div>

Hi, I'm using metricbeat 7.5 with apache module and Apache/2.4.6 on CentOS 7. Everythings works fine except for the fact that in the dashboad in the graph Uptime \[Metricbeat Apache\] ECS the metric server\_uptime is alway…

---

## [Filebeat multiline filter with autodiscover](https://discuss.elastic.co/t/filebeat-multiline-filter-with-autodiscover/217432)

<div class="topic-metadata">

**Author:** [@ztasre](https://discuss.elastic.co/u/ztasre)\
**Replies:** 1\
**Last updated:** [February 4, 2020, 3:49pm UTC](https://discuss.elastic.co/t/filebeat-multiline-filter-with-autodiscover/217432 "2020-02-04T15:49:00Z")

</div>

Filebeat version: 7.5.2 I am trying to get my application running on Kubernetes with the ELK stack to do logging. The application is written in Java so I need to be able to able to ingest multiline stack traces as a sin…

---

## [Beats privileges documentation](https://discuss.elastic.co/t/beats-privileges-documentation/214190)

<div class="topic-metadata">

**Author:** [@jsu](https://discuss.elastic.co/u/jsu)\
**Replies:** 8\
**Last updated:** [February 4, 2020, 1:00pm UTC](https://discuss.elastic.co/t/beats-privileges-documentation/214190 "2020-02-04T13:00:11Z")

</div>

Hi there, I had a problem that I managed to resolve but it seems then that the documentation isn't completely accurate. Let me know if I should post this somewhere else. So, when configuring Beats agents to send data t…

---

## [Include lines in filebeat](https://discuss.elastic.co/t/include-lines-in-filebeat/217776)

<div class="topic-metadata">

**Author:** [@whoatemyjam](https://discuss.elastic.co/u/whoatemyjam)\
**Replies:** 0\
**Last updated:** [February 4, 2020, 11:07am UTC](https://discuss.elastic.co/t/include-lines-in-filebeat/217776 "2020-02-04T11:07:32Z")

</div>

in filebeat is there a way to send the messages that have "somekey": "somevalue" in it, to logstash and ignore all the rest of the messages tried include\_lines: \[' "somekey": "somevalue" '\] but that fails T…

---

## [Filebeat add field based on line content](https://discuss.elastic.co/t/filebeat-add-field-based-on-line-content/217741)

<div class="topic-metadata">

**Author:** [@Mohammad\_Mousavi](https://discuss.elastic.co/u/Mohammad_Mousavi)\
**Replies:** 0\
**Last updated:** [February 4, 2020, 8:25am UTC](https://discuss.elastic.co/t/filebeat-add-field-based-on-line-content/217741 "2020-02-04T08:25:31Z")

</div>

Hi. I have an access.log that holds multiple vod applications log. I wanna have different grok filter for each application log. I thought maybe I can add some field in filebeat to trigger groks in logstash based on them…

---

## [Cant find data/registry on Centos 7 with yum repository,](https://discuss.elastic.co/t/cant-find-data-registry-on-centos-7-with-yum-repository/217555)

<div class="topic-metadata">

**Author:** [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Replies:** 5\
**Last updated:** [February 4, 2020, 1:44am UTC](https://discuss.elastic.co/t/cant-find-data-registry-on-centos-7-with-yum-repository/217555 "2020-02-04T01:44:58Z")

</div>

Hi, Im am testing configurations for a log file, and I want to use it many times, until the desired result is achieved, the problem is that I can not find the data/registry folder where the already processed files are …

---

## [Multiline Pattern that starts with INFO|ERROR|WARN|DEBUG](https://discuss.elastic.co/t/multiline-pattern-that-starts-with-info-error-warn-debug/217698)

<div class="topic-metadata">

**Author:** [@dbwest](https://discuss.elastic.co/u/dbwest)\
**Replies:** 0\
**Last updated:** [February 3, 2020, 9:28pm UTC](https://discuss.elastic.co/t/multiline-pattern-that-starts-with-info-error-warn-debug/217698 "2020-02-03T21:28:47Z")

</div>

I want to match the following multiline log entry and others that start with INFO, WARN, or DEBUG ERROR 2020-02-03 11:24:25,803 \[\[stuff-1.0.0-FILLER-some-domain\].http.requester.HTTP\_Request\_configuration\_Something.01 So…

---

## [\[ActiveMq Module\] Problem with ingest pipeline](https://discuss.elastic.co/t/activemq-module-problem-with-ingest-pipeline/216891)

<div class="topic-metadata">

**Author:** [@geoffreydjof](https://discuss.elastic.co/u/geoffreydjof)\
**Replies:** 3\
**Last updated:** [February 3, 2020, 7:30pm UTC](https://discuss.elastic.co/t/activemq-module-problem-with-ingest-pipeline/216891 "2020-02-03T19:30:10Z")

</div>

Hey ! Sorry for bothering you. I'm quite new in the use of Filebeat but I wanted it to run on a server where ActiveMq is installed. I then installed Filebeat (6.3.0 OSS) and get the ActiveMq module of Activemq. When I…

---

## [Harvester could not be started on new file](https://discuss.elastic.co/t/harvester-could-not-be-started-on-new-file/217678)

<div class="topic-metadata">

**Author:** [@krishna\_bhargav](https://discuss.elastic.co/u/krishna_bhargav)\
**Replies:** 0\
**Last updated:** [February 3, 2020, 6:58pm UTC](https://discuss.elastic.co/t/harvester-could-not-be-started-on-new-file/217678 "2020-02-03T18:58:59Z")

</div>

We have over 10 files (type = log entries ) being read from filebeat.yml. When we reduce the number of files, type = log entries to 5 or less it works. how to fix this issue to allow all 10 files being read from single …

---

## [Count of the number of a particular named process in Kibana dashboards](https://discuss.elastic.co/t/count-of-the-number-of-a-particular-named-process-in-kibana-dashboards/217631)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [February 3, 2020, 2:00pm UTC](https://discuss.elastic.co/t/count-of-the-number-of-a-particular-named-process-in-kibana-dashboards/217631 "2020-02-03T14:00:58Z")

</div>

We had a request come in from one of our users thats looking to add a column to the list of "Top 10 Processes" visualization. They are looking to see if we can display the count of the number of a particular named proce…

---

## [Setup json metricset in module http](https://discuss.elastic.co/t/setup-json-metricset-in-module-http/217652)

<div class="topic-metadata">

**Author:** [@coute](https://discuss.elastic.co/u/coute)\
**Replies:** 0\
**Last updated:** [February 3, 2020, 3:40pm UTC](https://discuss.elastic.co/t/setup-json-metricset-in-module-http/217652 "2020-02-03T15:40:09Z")

</div>

Hello, I use module http in metricbeat to get some values through an API. The API return a json looking like that : { "items" : \[ { "timeSeries" : \[ { "metadata" : { "metricName" : …

---

## [Running the Filebeat Container - Docker](https://discuss.elastic.co/t/running-the-filebeat-container-docker/217656)

<div class="topic-metadata">

**Author:** [@daz1761](https://discuss.elastic.co/u/daz1761)\
**Replies:** 0\
**Last updated:** [February 3, 2020, 3:46pm UTC](https://discuss.elastic.co/t/running-the-filebeat-container-docker/217656 "2020-02-03T15:46:21Z")

</div>

I am reading the docs with respect to spinning up a Filebeat container and I am confused with these two --volume mounts: --volume="/var/lib/docker/containers:/var/lib/docker/containers:ro" --volume="/var/run/docker.soc…

---

## [I can't see Zeek's http.log in Kibana but everything else (DNS, SSL, etc.) is fine](https://discuss.elastic.co/t/i-cant-see-zeeks-http-log-in-kibana-but-everything-else-dns-ssl-etc-is-fine/217474)

<div class="topic-metadata">

**Author:** [@Sylancer](https://discuss.elastic.co/u/Sylancer)\
**Replies:** 1\
**Last updated:** [February 3, 2020, 3:16pm UTC](https://discuss.elastic.co/t/i-cant-see-zeeks-http-log-in-kibana-but-everything-else-dns-ssl-etc-is-fine/217474 "2020-02-03T15:16:49Z")

</div>

Hi, I've got an ElasticStack set up as per these instructions: https://holdmybeersecurity.com/2019/05/01/back-in-the-saddle-install-setup-elastic-stack-7-0-on-ubuntu-18-04/ What I'm trying to do is get Zeek logs into th…

---

## [Filebeat: invalid argument. Continuing](https://discuss.elastic.co/t/filebeat-invalid-argument-continuing/217641)

<div class="topic-metadata">

**Author:** [@miBogi](https://discuss.elastic.co/u/miBogi)\
**Replies:** 0\
**Last updated:** [February 3, 2020, 2:56pm UTC](https://discuss.elastic.co/t/filebeat-invalid-argument-continuing/217641 "2020-02-03T14:56:01Z")

</div>

Hi to All, at the startup of docker container i recieve the following error: ERROR registrar/registrar.go:374 Writing of registry returned error: sync /usr/share/filebeat/data/registry/filebeat: invalid argument…

---

## [Auditbeat's process module produces error in Kibana for field \[process.created\]](https://discuss.elastic.co/t/auditbeats-process-module-produces-error-in-kibana-for-field-process-created/217594)

<div class="topic-metadata">

**Author:** [@tterranigma](https://discuss.elastic.co/u/tterranigma)\
**Replies:** 0\
**Last updated:** [February 3, 2020, 9:59am UTC](https://discuss.elastic.co/t/auditbeats-process-module-produces-error-in-kibana-for-field-process-created/217594 "2020-02-03T09:59:11Z")

</div>

I am using auditbeat 7.5.2 (I also tried with autibeat 7.5.1). Auditbeat sends data to logstash and logstash to elasticsearch. This is how the beats input in logstash is configured: input { if 1 == 1 { beats { id =\> '…

---

## [Invalid character 'x' in string escape code; pipeline/output.go:92 Failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/invalid-character-x-in-string-escape-code-pipeline-output-go-92-failed-to-publish-events-temporary-bulk-send-failure/217608)

<div class="topic-metadata">

**Author:** [@adeel109](https://discuss.elastic.co/u/adeel109)\
**Replies:** 0\
**Last updated:** [February 3, 2020, 10:54am UTC](https://discuss.elastic.co/t/invalid-character-x-in-string-escape-code-pipeline-output-go-92-failed-to-publish-events-temporary-bulk-send-failure/217608 "2020-02-03T10:54:59Z")

</div>

Hi All, I am getting below error when starting filebeat: 2020-02-03T10:31:21.416Z ERROR reader/json.go:32 Error decoding JSON: invalid character 'x' in string escape code 2020-02-03T10:31:22.467Z INFO elasticsearch/c…

---

## [Index lifecycle error and Index name error](https://discuss.elastic.co/t/index-lifecycle-error-and-index-name-error/217613)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 0\
**Last updated:** [February 3, 2020, 11:12am UTC](https://discuss.elastic.co/t/index-lifecycle-error-and-index-name-error/217613 "2020-02-03T11:12:52Z")

</div>

Hello, I was trying to change the index name you see in 'index management'. And even though I was successful, I now have an 'Index lifecycle' error. This is how my code looks like: setup.template.name: "filebeat-%{\[agen…

---

## [Convert type of custom fields added via metricbeat processors](https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352)

<div class="topic-metadata">

**Author:** [@naveenbangalore](https://discuss.elastic.co/u/naveenbangalore)\
**Replies:** 5\
**Last updated:** [February 3, 2020, 11:08am UTC](https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352 "2020-02-03T11:08:10Z")

</div>

I have added the following processor in system.yml module of metricbeat. These custom fields flow to elastisearch as objects, but I am looking to pass them as strings. I tried using the "convert" processor without any …

---

## [Only Error and Warning message capture in docker input](https://discuss.elastic.co/t/only-error-and-warning-message-capture-in-docker-input/217590)

<div class="topic-metadata">

**Author:** [@rguptarg](https://discuss.elastic.co/u/rguptarg)\
**Replies:** 0\
**Last updated:** [February 3, 2020, 9:48am UTC](https://discuss.elastic.co/t/only-error-and-warning-message-capture-in-docker-input/217590 "2020-02-03T09:48:10Z")

</div>

Hi All, I am using filebeat (filebeat-7.3.2-1.x86\_64) for Doctor log analysis, now I want to capture only Error and Warning message. I have tried "include\_lines: \['^ERR', '^WARN'\]" option but it's not working. can you s…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=278)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=280)
