# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=280

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 281

---

## [Metricbeat 7.2.1 custom index name: missing field accessing 'output.elasticsearch.index'](https://discuss.elastic.co/t/metricbeat-7-2-1-custom-index-name-missing-field-accessing-output-elasticsearch-index/217548)

<div class="topic-metadata">

**Author:** [@brandnull](https://discuss.elastic.co/u/brandnull)\
**Replies:** 1\
**Last updated:** [February 3, 2020, 8:36am UTC](https://discuss.elastic.co/t/metricbeat-7-2-1-custom-index-name-missing-field-accessing-output-elasticsearch-index/217548 "2020-02-03T08:36:34Z")

</div>

Hello, I'm trying to set up Metricbeat in different instances, gathering metrics in a single Elasticsearch node. However, I want to set up a custom index pattern per instance. In In /etc/metricbeat/metricbeat.yml I hav…

---

## [Winlogbeat - two instances](https://discuss.elastic.co/t/winlogbeat-two-instances/217542)

<div class="topic-metadata">

**Author:** [@Rysiu](https://discuss.elastic.co/u/Rysiu)\
**Replies:** 0\
**Last updated:** [February 2, 2020, 5:01pm UTC](https://discuss.elastic.co/t/winlogbeat-two-instances/217542 "2020-02-02T17:01:51Z")

</div>

Hi, I have a quick question. Is there any problem with running two Winlogbeat instances (sending data to two different destinations)? Can we run two Winlogbeat instances with different configurations? The question ma…

---

## [Auditbeat template - no fielddata allowed?](https://discuss.elastic.co/t/auditbeat-template-no-fielddata-allowed/217501)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 0\
**Last updated:** [February 1, 2020, 5:59pm UTC](https://discuss.elastic.co/t/auditbeat-template-no-fielddata-allowed/217501 "2020-02-01T17:59:10Z")

</div>

Im using 7.5.2 across the board. I installed the auditbeat vis and dashboards but when I go to the 'logins' view I get a message Fielddata is disabled on text fields by default. Set fielddata=true on \[event.action\] in …

---

## [Previous version source code running locally](https://discuss.elastic.co/t/previous-version-source-code-running-locally/217453)

<div class="topic-metadata">

**Author:** [@Yiw](https://discuss.elastic.co/u/Yiw)\
**Replies:** 0\
**Last updated:** [January 31, 2020, 7:38pm UTC](https://discuss.elastic.co/t/previous-version-source-code-running-locally/217453 "2020-01-31T19:38:05Z")

</div>

Hi all, I can get previous version 's source code from github release history (beats-6.8.6.zip). However, it seems different from what I got if I just cloned it using command line. The source code of previous version do…

---

## [Filebeat issue##](https://discuss.elastic.co/t/filebeat-issue/217449)

<div class="topic-metadata">

**Author:** [@san3ncrypt3d](https://discuss.elastic.co/u/san3ncrypt3d)\
**Replies:** 0\
**Last updated:** [January 31, 2020, 6:40pm UTC](https://discuss.elastic.co/t/filebeat-issue/217449 "2020-01-31T18:40:54Z")

</div>

Hey guys, I am trying to ingest suricata log into ES and get the dashboard in kibana. When i run filebeat it gives me error: Exiting: 1 error: error loading config file: invalid config: yaml: line 10: did not find expe…

---

## [Is it necessary to have a ES Index Template specified in Filebeat?](https://discuss.elastic.co/t/is-it-necessary-to-have-a-es-index-template-specified-in-filebeat/217443)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 0\
**Last updated:** [January 31, 2020, 6:05pm UTC](https://discuss.elastic.co/t/is-it-necessary-to-have-a-es-index-template-specified-in-filebeat/217443 "2020-01-31T18:05:15Z")

</div>

Is it possible to have ES indexes created without an index template in Filebeat ? The reason I ask is that we have field mapping conflicts with our log data. For eg: "service" is defined as an object in default templa…

---

## [K8S Node level logging as non-root user?](https://discuss.elastic.co/t/k8s-node-level-logging-as-non-root-user/193603)

<div class="topic-metadata">

**Author:** [@carlsoane](https://discuss.elastic.co/u/carlsoane)\
**Replies:** 3\
**Last updated:** [January 31, 2020, 5:20pm UTC](https://discuss.elastic.co/t/k8s-node-level-logging-as-non-root-user/193603 "2020-01-31T17:20:42Z")

</div>

I'm trying to perform node level logging in a kubernetes cluster using Filebeat. I've installed Filebeat as a daemonset and it is reading logs from /var/lib/docker/containers//\*.log successfully. My concern is that I am …

---

## [Set index in filebeat](https://discuss.elastic.co/t/set-index-in-filebeat/217377)

<div class="topic-metadata">

**Author:** [@rguptarg](https://discuss.elastic.co/u/rguptarg)\
**Replies:** 2\
**Last updated:** [January 31, 2020, 4:53pm UTC](https://discuss.elastic.co/t/set-index-in-filebeat/217377 "2020-01-31T16:53:35Z")

</div>

Hi, I am trying to configure Index name at filebeat end, but it's not working and even no error in logs Configuration:- output.elasticsearch: hosts: \["IP:9200"\] username: "elastic" password: "changeme" output.elas…

---

## [How does one send nginx module output to a specified index using filebeat with logstash output](https://discuss.elastic.co/t/how-does-one-send-nginx-module-output-to-a-specified-index-using-filebeat-with-logstash-output/217419)

<div class="topic-metadata">

**Author:** [@dbwest](https://discuss.elastic.co/u/dbwest)\
**Replies:** 0\
**Last updated:** [January 31, 2020, 4:13pm UTC](https://discuss.elastic.co/t/how-does-one-send-nginx-module-output-to-a-specified-index-using-filebeat-with-logstash-output/217419 "2020-01-31T16:13:18Z")

</div>

I have only seen configurations doing this that are outputting to ES. How do you specify the index to send nginx module filebeat logs to if you are sending to logstash from filebeat?

---

## [Trouble with configuring Filebeat as DaemonSet on k8s environment](https://discuss.elastic.co/t/trouble-with-configuring-filebeat-as-daemonset-on-k8s-environment/217031)

<div class="topic-metadata">

**Author:** [@cloudants\_wvestjens](https://discuss.elastic.co/u/cloudants_wvestjens)\
**Replies:** 7\
**Last updated:** [January 31, 2020, 3:34pm UTC](https://discuss.elastic.co/t/trouble-with-configuring-filebeat-as-daemonset-on-k8s-environment/217031 "2020-01-31T15:34:18Z")

</div>

Hello. I am trying to configure Filebeat as DaemonSet on our Kubernetes platform. It's sending through systemlogs as expected, including the event info. I am trying to get it to do the same for nginx, apache2 and even…

---

## [Any beats are able to sending K8S/GKE event](https://discuss.elastic.co/t/any-beats-are-able-to-sending-k8s-gke-event/217320)

<div class="topic-metadata">

**Author:** [@Vincent\_Ngai](https://discuss.elastic.co/u/Vincent_Ngai)\
**Replies:** 1\
**Last updated:** [January 31, 2020, 3:16pm UTC](https://discuss.elastic.co/t/any-beats-are-able-to-sending-k8s-gke-event/217320 "2020-01-31T15:16:11Z")

</div>

HI there May i know any one try sending GKE event (kubectl get event) to elasticsearch cluster by using one of the beats ??

---

## [Should I leave my files unzipped?](https://discuss.elastic.co/t/should-i-leave-my-files-unzipped/217399)

<div class="topic-metadata">

**Author:** [@ldv](https://discuss.elastic.co/u/ldv)\
**Replies:** 0\
**Last updated:** [January 31, 2020, 2:43pm UTC](https://discuss.elastic.co/t/should-i-leave-my-files-unzipped/217399 "2020-01-31T14:43:11Z")

</div>

Hi, I have an environment where I want to start picking up apache access log files with filebeat. Up to now we have zipped the apache logs after 2 weeks to safe space. Is that still possible? Can filebeat pickup gzipped…

---

## [Filebeat missing end of logs for k8s pods](https://discuss.elastic.co/t/filebeat-missing-end-of-logs-for-k8s-pods/217281)

<div class="topic-metadata">

**Author:** [@Matt\_Kirkevold](https://discuss.elastic.co/u/Matt_Kirkevold)\
**Replies:** 2\
**Last updated:** [January 31, 2020, 2:28pm UTC](https://discuss.elastic.co/t/filebeat-missing-end-of-logs-for-k8s-pods/217281 "2020-01-31T14:28:26Z")

</div>

I have noticed a curious issue where if my kubernetes pod terminates too fast filebeat does not capture the end of the associated log. Anyone have this issue and any workaround to ensure filebeats can capture all the lo…

---

## [Filebeat prospector configuration files aren't recognized with .yaml suffix](https://discuss.elastic.co/t/filebeat-prospector-configuration-files-arent-recognized-with-yaml-suffix/217259)

<div class="topic-metadata">

**Author:** [@PMDubuc](https://discuss.elastic.co/u/PMDubuc)\
**Replies:** 3\
**Last updated:** [January 31, 2020, 1:37pm UTC](https://discuss.elastic.co/t/filebeat-prospector-configuration-files-arent-recognized-with-yaml-suffix/217259 "2020-01-31T13:37:02Z")

</div>

Using Filebeat 5.6.14 we've noticed that it ignores prospector configuration files that are kept in a separate directory if they have the official ".yaml" name extension instead of ".yml". The shorter one is commonly us…

---

## [Metricbeat dashboard drilldown](https://discuss.elastic.co/t/metricbeat-dashboard-drilldown/217121)

<div class="topic-metadata">

**Author:** [@Satya\_bharathi](https://discuss.elastic.co/u/Satya_bharathi)\
**Replies:** 4\
**Last updated:** [January 31, 2020, 1:06pm UTC](https://discuss.elastic.co/t/metricbeat-dashboard-drilldown/217121 "2020-01-31T13:06:42Z")

</div>

Hi, I installed metricbeat in different hosts and can view the system metrics in default dashboards. Is there any possibilty for the metricbeat dashboards to drilldown further? So that, I can analyse the cause behind th…

---

## [Function: cloudwatch, could not deploy, error: bucket 'trial' already exist and you don't have permission to access it](https://discuss.elastic.co/t/function-cloudwatch-could-not-deploy-error-bucket-trial-already-exist-and-you-dont-have-permission-to-access-it/217364)

<div class="topic-metadata">

**Author:** [@Aatman\_Bos](https://discuss.elastic.co/u/Aatman_Bos)\
**Replies:** 0\
**Last updated:** [January 31, 2020, 11:53am UTC](https://discuss.elastic.co/t/function-cloudwatch-could-not-deploy-error-bucket-trial-already-exist-and-you-dont-have-permission-to-access-it/217364 "2020-01-31T11:53:19Z")

</div>

I setup the IAM policies required for function beat, I exported the necessary AWS secrets, and I am sure that my AWS user is allowed to create S3 buckets. { "AWSTemplateFormatVersion": "2010-09-09", "Resources": { …

---

## [MetricBeat Microsoft SQL Server Custom Port](https://discuss.elastic.co/t/metricbeat-microsoft-sql-server-custom-port/214121)

<div class="topic-metadata">

**Author:** [@Anji\_Reddy](https://discuss.elastic.co/u/Anji_Reddy)\
**Replies:** 2\
**Last updated:** [January 31, 2020, 10:38am UTC](https://discuss.elastic.co/t/metricbeat-microsoft-sql-server-custom-port/214121 "2020-01-31T10:38:01Z")

</div>

We are trying to configure Metricbeat for Microsoft SQL server with custom port 31433. How do we configured mssql.yml file like below. This does not work. module: mssql metricsets: - "transaction\_log" - "performance" …

---

## [Nested JSON parsing issues](https://discuss.elastic.co/t/nested-json-parsing-issues/216271)

<div class="topic-metadata">

**Author:** [@ipolyzois](https://discuss.elastic.co/u/ipolyzois)\
**Replies:** 8\
**Last updated:** [January 31, 2020, 9:19am UTC](https://discuss.elastic.co/t/nested-json-parsing-issues/216271 "2020-01-31T09:19:56Z")

</div>

Hi, I'm using filebeat and elasticsearch 7.5.2 and i am trying to stream specific lines from a local log file to ES. The lines i am interested in have the following format {"level":30,"time":1579750597224,"pid":32172,…

---

## [Metricbeat - Add a custom field with existing value](https://discuss.elastic.co/t/metricbeat-add-a-custom-field-with-existing-value/213873)

<div class="topic-metadata">

**Author:** [@Sudharshan\_K\_S](https://discuss.elastic.co/u/Sudharshan_K_S)\
**Replies:** 2\
**Last updated:** [January 31, 2020, 8:15am UTC](https://discuss.elastic.co/t/metricbeat-add-a-custom-field-with-existing-value/213873 "2020-01-31T08:15:20Z")

</div>

How can i add a custom field whose value will be equal to an exiting field Eg processors: -add\_fields: fields: new\_field: host.name

---

## [Handling multiline log with a timestamp on each line](https://discuss.elastic.co/t/handling-multiline-log-with-a-timestamp-on-each-line/217248)

<div class="topic-metadata">

**Author:** [@ricky.kwan.ix](https://discuss.elastic.co/u/ricky.kwan.ix)\
**Replies:** 2\
**Last updated:** [January 30, 2020, 10:47pm UTC](https://discuss.elastic.co/t/handling-multiline-log-with-a-timestamp-on-each-line/217248 "2020-01-30T22:47:48Z")

</div>

Hi, I'm trying to combine multiple log lines into a single line, but the issue is that each line has a timestamp (among other things) on it. Jan 30 2020 16:52:16 GMT: INFO (info): (hist.c:240) histogram dump: {test}-w…

---

## [Can metric beat collect remotely from systems](https://discuss.elastic.co/t/can-metric-beat-collect-remotely-from-systems/214246)

<div class="topic-metadata">

**Author:** [@liorg2](https://discuss.elastic.co/u/liorg2)\
**Replies:** 1\
**Last updated:** [January 30, 2020, 8:23pm UTC](https://discuss.elastic.co/t/can-metric-beat-collect-remotely-from-systems/214246 "2020-01-30T20:23:45Z")

</div>

can metric beat collect remotely from systems? for example sql server metricbeat thanks

---

## [Elastic Cloud output on shared / non-trusted environments](https://discuss.elastic.co/t/elastic-cloud-output-on-shared-non-trusted-environments/215855)

<div class="topic-metadata">

**Author:** [@gerard1](https://discuss.elastic.co/u/gerard1)\
**Replies:** 4\
**Last updated:** [January 30, 2020, 3:40pm UTC](https://discuss.elastic.co/t/elastic-cloud-output-on-shared-non-trusted-environments/215855 "2020-01-30T15:40:17Z")

</div>

Imagine the following scenario: You want to deploy Filebeat using Elastic Cloud in some servers that are managed by a 3rd party company. Is there any way to do that without using the Elastic Cloud global credentials? …

---

## [Heartbeat config changes creates multiple runners/monitors](https://discuss.elastic.co/t/heartbeat-config-changes-creates-multiple-runners-monitors/216899)

<div class="topic-metadata">

**Author:** [@sastorsl](https://discuss.elastic.co/u/sastorsl)\
**Replies:** 4\
**Last updated:** [January 30, 2020, 3:38pm UTC](https://discuss.elastic.co/t/heartbeat-config-changes-creates-multiple-runners-monitors/216899 "2020-01-30T15:38:37Z")

</div>

Have setup heartbeat-7.5.2 on a RedHat Enterprise Linux 7.7 (RHEL7) server. Basic setup as of yet - pushing to two elasticsearch outputs. http checks - nothing fancy. heartbeat.config.monitors: path: ${path.config}/…

---

## [Multiple Filebeat processes running after install on Windows VM](https://discuss.elastic.co/t/multiple-filebeat-processes-running-after-install-on-windows-vm/217083)

<div class="topic-metadata">

**Author:** [@averagedude99](https://discuss.elastic.co/u/averagedude99)\
**Replies:** 2\
**Last updated:** [January 30, 2020, 2:53pm UTC](https://discuss.elastic.co/t/multiple-filebeat-processes-running-after-install-on-windows-vm/217083 "2020-01-30T14:53:27Z")

</div>

installed 7.5.0 version of filebeat on windows VM. after a successful install, noticed that filebeat.exe was running in background when looking at running processes but I had not started service yet. i confirmed that th…

---

## [Filebeats Sending Data to the Wrong index (ignoring .yml config and using default index)](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708)

<div class="topic-metadata">

**Author:** [@guibarati](https://discuss.elastic.co/u/guibarati)\
**Replies:** 9\
**Last updated:** [January 30, 2020, 2:17pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708 "2020-01-30T14:17:39Z")

</div>

Hi, I'm testing a filebeats indexing of JSON content created with wireshark. I have the filebeat.yml configured as below, but the logs keep going to the default filebeats index, (filebeat-7.5.2-2020.01.27-000001). Can…

---

## [Beats pipelines automation](https://discuss.elastic.co/t/beats-pipelines-automation/217193)

<div class="topic-metadata">

**Author:** [@gborg](https://discuss.elastic.co/u/gborg)\
**Replies:** 0\
**Last updated:** [January 30, 2020, 1:19pm UTC](https://discuss.elastic.co/t/beats-pipelines-automation/217193 "2020-01-30T13:19:53Z")

</div>

Hello I have a lot of servers running beats that are collected into a "middle layer"(1) before they are shipped to elasticsearch and I am currently managing the pipelines by hand, installing filebeat, set up against ela…

---

## [MetricBeat not creating monitoring-es index](https://discuss.elastic.co/t/metricbeat-not-creating-monitoring-es-index/217120)

<div class="topic-metadata">

**Author:** [@Vipul\_Sharma](https://discuss.elastic.co/u/Vipul_Sharma)\
**Replies:** 3\
**Last updated:** [January 30, 2020, 10:59am UTC](https://discuss.elastic.co/t/metricbeat-not-creating-monitoring-es-index/217120 "2020-01-30T10:59:17Z")

</div>

I have installed metric beat and it is running successfully not errors in logs metricBeat.yml elasticsearch output output.elasticsearch: ##Array of hosts to connect to. hosts: \["10.216.204.70:9200", "10.216.204.73:92…

---

## [Filebeat duplicating events always (twice)](https://discuss.elastic.co/t/filebeat-duplicating-events-always-twice/216954)

<div class="topic-metadata">

**Author:** [@nino](https://discuss.elastic.co/u/nino)\
**Replies:** 3\
**Last updated:** [January 30, 2020, 9:45am UTC](https://discuss.elastic.co/t/filebeat-duplicating-events-always-twice/216954 "2020-01-30T09:45:19Z")

</div>

Hello All, two days with this issue without find out the solution. Enviroment: filebeat on Windows sending .txt files to logstash into another machine. One file, one event whole file (multiline) Problem filebeat alwa…

---

## [Filebeat failed to publish events: client is not connected](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-client-is-not-connected/215531)

<div class="topic-metadata">

**Author:** [@rnakam01](https://discuss.elastic.co/u/rnakam01)\
**Replies:** 2\
**Last updated:** [January 30, 2020, 2:34am UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-client-is-not-connected/215531 "2020-01-30T02:34:53Z")

</div>

executing sudo /opt/elkstack/filebeat/filebeat -e -c /opt/elkstack/filebeat/filebeat.yml -d "publish" Consistently get 2020-01-17T15:07:18.857-0800 ERROR logstash/async.go:256 Failed to publish events caused by: …

---

## [Matching multiple patterns in grok for a filebeat ingestion pipeline](https://discuss.elastic.co/t/matching-multiple-patterns-in-grok-for-a-filebeat-ingestion-pipeline/217059)

<div class="topic-metadata">

**Author:** [@Jim\_Ivey](https://discuss.elastic.co/u/Jim_Ivey)\
**Replies:** 2\
**Last updated:** [January 29, 2020, 11:12pm UTC](https://discuss.elastic.co/t/matching-multiple-patterns-in-grok-for-a-filebeat-ingestion-pipeline/217059 "2020-01-29T23:12:09Z")

</div>

In logstash's grok, there's a break\_on\_match field that allows grok to match multiple patterns. Am I correct in believing that no such thing exists for grok in filebeat module ingestion pipelines (e.g., .../filebeat/mod…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=279)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=281)
