# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=282

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 283

---

## [Monitor kubernetes ingress resources with heartbeat](https://discuss.elastic.co/t/monitor-kubernetes-ingress-resources-with-heartbeat/216537)

<div class="topic-metadata">

**Author:** [@laurentiusoica](https://discuss.elastic.co/u/laurentiusoica)\
**Replies:** 2\
**Last updated:** [January 27, 2020, 3:39pm UTC](https://discuss.elastic.co/t/monitor-kubernetes-ingress-resources-with-heartbeat/216537 "2020-01-27T15:39:55Z")

</div>

Is there any way to configure heartbeat to automatically detect the ingress resources in a cluster and run a simple health-check against each of them ? Also, the heartbeat chart deploys a daemonset; is this really neede…

---

## [Heartbeat Kubernetes Autodiscover](https://discuss.elastic.co/t/heartbeat-kubernetes-autodiscover/214435)

<div class="topic-metadata">

**Author:** [@akrzos](https://discuss.elastic.co/u/akrzos)\
**Replies:** 2\
**Last updated:** [January 27, 2020, 3:11pm UTC](https://discuss.elastic.co/t/heartbeat-kubernetes-autodiscover/214435 "2020-01-27T15:11:14Z")

</div>

I am trying to have heartbeat deployed in kubernetes as a daemonset in which each heartbeat daemon icmp pings all other nodes in a cluster. I was planning on doing this with the kubernetes autodiscover provider however …

---

## [Heartbeat keeps failing after upgrade from 7.4.2 to 7.5.2](https://discuss.elastic.co/t/heartbeat-keeps-failing-after-upgrade-from-7-4-2-to-7-5-2/216572)

<div class="topic-metadata">

**Author:** [@Peter\_Steenbergen](https://discuss.elastic.co/u/Peter_Steenbergen)\
**Replies:** 3\
**Last updated:** [January 27, 2020, 1:47pm UTC](https://discuss.elastic.co/t/heartbeat-keeps-failing-after-upgrade-from-7-4-2-to-7-5-2/216572 "2020-01-27T13:47:08Z")

</div>

Heartbeat keeps failing after upgrade from 7.4.2 to 7.5.2. This is the stack trace of it. 2020-01-26T15:40:45.261Z INFO \[publisher\] pipeline/module.go:97 Beat name: beat001-fr 2020-01-26T15:40:45.262Z INFO instance/bea…

---

## [Filebeat multiline pattern is not working](https://discuss.elastic.co/t/filebeat-multiline-pattern-is-not-working/216647)

<div class="topic-metadata">

**Author:** [@emilio](https://discuss.elastic.co/u/emilio)\
**Replies:** 1\
**Last updated:** [January 27, 2020, 1:00pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-is-not-working/216647 "2020-01-27T13:00:36Z")

</div>

Dear all, I have created such multiline pattern for filebeat for following type of log. multiline.pattern: ^\[\[0-9\]\]{4}-\[\[0-9\]\]{2}-\[\[0-9\]\]{2} \[\[0-9\]\]{2}:\[\[0-9\]\]{2}:\[\[0-9\]\]{2},\[\[0-9\]\]{3} multiline.negate: true multilin…

---

## [Netflow protocol version 0 not supported](https://discuss.elastic.co/t/netflow-protocol-version-0-not-supported/214971)

<div class="topic-metadata">

**Author:** [@w33ha-zxc](https://discuss.elastic.co/u/w33ha-zxc)\
**Replies:** 2\
**Last updated:** [January 27, 2020, 12:51pm UTC](https://discuss.elastic.co/t/netflow-protocol-version-0-not-supported/214971 "2020-01-27T12:51:48Z")

</div>

Have been trying to ingest Netflow Data from a Fortigate Firewall through Filebeat, but upon running filebeat -e gets me to the following warning - netflow/input.go:240 Error parsing NetFlow packet of length 220 from…

---

## [How secure filebeat communication with logstash without SSL](https://discuss.elastic.co/t/how-secure-filebeat-communication-with-logstash-without-ssl/216535)

<div class="topic-metadata">

**Author:** [@nino](https://discuss.elastic.co/u/nino)\
**Replies:** 3\
**Last updated:** [January 27, 2020, 11:09am UTC](https://discuss.elastic.co/t/how-secure-filebeat-communication-with-logstash-without-ssl/216535 "2020-01-27T11:09:03Z")

</div>

Hello All, i would like to know in case not using SSL between Filebeat and Logstash how secure is the communication?. Is log/file data travelling encrypted by default? Best regards

---

## [Metricbeat Requests To Nginx Keep 'Waiting' State](https://discuss.elastic.co/t/metricbeat-requests-to-nginx-keep-waiting-state/216525)

<div class="topic-metadata">

**Author:** [@Razco](https://discuss.elastic.co/u/Razco)\
**Replies:** 1\
**Last updated:** [January 27, 2020, 10:35am UTC](https://discuss.elastic.co/t/metricbeat-requests-to-nginx-keep-waiting-state/216525 "2020-01-27T10:35:55Z")

</div>

Hey there guys ! I'm encountering a very odd situation with configuring Metricbeat Nginx module. My Metricbeat requests to the Nginx server stuck on Waiting state on the Nginx. I've set-up the stub status page : loca…

---

## [Unable to upload netflow data to Elasticsearch with filebeat netflow module](https://discuss.elastic.co/t/unable-to-upload-netflow-data-to-elasticsearch-with-filebeat-netflow-module/216290)

<div class="topic-metadata">

**Author:** [@GregoryBrown](https://discuss.elastic.co/u/GregoryBrown)\
**Replies:** 8\
**Last updated:** [January 27, 2020, 10:35am UTC](https://discuss.elastic.co/t/unable-to-upload-netflow-data-to-elasticsearch-with-filebeat-netflow-module/216290 "2020-01-27T10:35:42Z")

</div>

All, I am trying to upload data from filebeat directly to ES. I see I am able to connect to my ES instance and I am getting netflow data into filebeat but when I search my ES I don't see any new indices I created or da…

---

## [Filtering option for Elasticsearch datasource](https://discuss.elastic.co/t/filtering-option-for-elasticsearch-datasource/216194)

<div class="topic-metadata">

**Author:** [@karthick2020](https://discuss.elastic.co/u/karthick2020)\
**Replies:** 7\
**Last updated:** [January 27, 2020, 10:18am UTC](https://discuss.elastic.co/t/filtering-option-for-elasticsearch-datasource/216194 "2020-01-27T10:18:16Z")

</div>

Hi Team, For metricbeat agent, a new field is added via metricbeat.yml with below config fields: application: \[“exxS-e11”,“eBxxxxH-e11”,“exxS-e10”\] fields\_under\_root: true So in kibana, the app info is displayed as …

---

## [Order Offset Filebeat](https://discuss.elastic.co/t/order-offset-filebeat/216541)

<div class="topic-metadata">

**Author:** [@Alfonso\_Perez\_Parra](https://discuss.elastic.co/u/Alfonso_Perez_Parra)\
**Replies:** 1\
**Last updated:** [January 27, 2020, 10:12am UTC](https://discuss.elastic.co/t/order-offset-filebeat/216541 "2020-01-27T10:12:36Z")

</div>

Hello, you know how in filebeat I can order the logs that he collects for me by the offset and so I don't put them in disorder in Kibana that if he doesn't lose a little bit the order with which he collects them

---

## [Script Processor](https://discuss.elastic.co/t/script-processor/216552)

<div class="topic-metadata">

**Author:** [@Rithesh\_Subramanian](https://discuss.elastic.co/u/Rithesh_Subramanian)\
**Replies:** 1\
**Last updated:** [January 27, 2020, 10:08am UTC](https://discuss.elastic.co/t/script-processor/216552 "2020-01-27T10:08:25Z")

</div>

Hi, I am trying to add script processor after splitting the message with dissect processor. But i am not able to start the filebeat after adding the script processor. processors: - rename: fields: - fro…

---

## [Unable to start Auditbeat on LXC container](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-lxc-container/119913)

<div class="topic-metadata">

**Author:** [@Luq](https://discuss.elastic.co/u/Luq)\
**Replies:** 8\
**Last updated:** [January 27, 2020, 9:08am UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-lxc-container/119913 "2020-01-27T09:08:43Z")

</div>

Hi, I've searched here but couldn't find a similar issue. I'm trying to run Auditbeat on CentOS 7 and it fails to start. Log only has this: "root@kibana1:~# cat /var/log/auditbeat/auditbeat 2018-02-15T06:23:21.005Z I…

---

## [Filebeat Is not Sending Logs to Logstash even Harvesting Successfull](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-even-harvesting-successfull/216579)

<div class="topic-metadata">

**Author:** [@mgnfcnt](https://discuss.elastic.co/u/mgnfcnt)\
**Replies:** 2\
**Last updated:** [January 27, 2020, 9:05am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-even-harvesting-successfull/216579 "2020-01-27T09:05:33Z")

</div>

I am trying to use ELK space to collect file logs. Everything is OK untill filebeat integration. I can send the logs over tcp to logstash and see in the kibana. But I couldn't achieved filebeat setup to send the logs. I…

---

## [Filebeat not shippping logs to logstash , failing to start harvester, CloseOnSignal](https://discuss.elastic.co/t/filebeat-not-shippping-logs-to-logstash-failing-to-start-harvester-closeonsignal/216569)

<div class="topic-metadata">

**Author:** [@shashankvc](https://discuss.elastic.co/u/shashankvc)\
**Replies:** 0\
**Last updated:** [January 26, 2020, 12:26pm UTC](https://discuss.elastic.co/t/filebeat-not-shippping-logs-to-logstash-failing-to-start-harvester-closeonsignal/216569 "2020-01-26T12:26:47Z")

</div>

Filebeat failed with the below error. goroutine 176153 \[runnable\]: github.com/elastic/beats/filebeat/channel.CloseOnSignal.func1(0x33b6780, 0xc0ad61d8f0, 0xc0d1a879e0) /go/src/github.com/elastic/beats/filebeat/channel…

---

## [How to use processors in filebeat HAproxy's module?](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256)

<div class="topic-metadata">

**Author:** [@aventrax](https://discuss.elastic.co/u/aventrax)\
**Replies:** 7\
**Last updated:** [January 26, 2020, 9:15am UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256 "2020-01-26T09:15:53Z")

</div>

Hello, I'm new with filebeat and I'm in trouble adding a processor to the haproxy module. To begin, just adding a tag would be enough, I tried with this config without much luck (Filebeat 7.1.1 on Debian stretch): /etc…

---

## [Create Index with filebeat](https://discuss.elastic.co/t/create-index-with-filebeat/211964)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 14\
**Last updated:** [January 25, 2020, 6:27am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964 "2020-01-25T06:27:01Z")

</div>

Hello , I want to create a index and push data directly to elasticsearch with filebeat but i am not able to create a index its showing me the error can someone help me out. Exiting: setup.template.name and setup.templa…

---

## [Logs Alarms - Notifications](https://discuss.elastic.co/t/logs-alarms-notifications/216485)

<div class="topic-metadata">

**Author:** [@zolthar-z](https://discuss.elastic.co/u/zolthar-z)\
**Replies:** 1\
**Last updated:** [January 25, 2020, 4:52am UTC](https://discuss.elastic.co/t/logs-alarms-notifications/216485 "2020-01-25T04:52:28Z")

</div>

Hi Currently I have the typical filebeat-\>logtash-\>elasticsearch set up, I received the logs without a problem but now I need to send an e-mail or message in slack y there are some keywords in the logs message or if the…

---

## [Failed to connect to backoff, Filebeat on Server B and ELK on local machine](https://discuss.elastic.co/t/failed-to-connect-to-backoff-filebeat-on-server-b-and-elk-on-local-machine/215970)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 2\
**Last updated:** [January 25, 2020, 1:35am UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-filebeat-on-server-b-and-elk-on-local-machine/215970 "2020-01-25T01:35:50Z")

</div>

Filebeat is running on server B which read logs and pushes to ELK logstash on local Machine A. I want to use filebeat to send real time log files from the server, and point it to my local machine where Elasticsearch, lo…

---

## [Filebeat-oss 7.5.2 not parsing string as json](https://discuss.elastic.co/t/filebeat-oss-7-5-2-not-parsing-string-as-json/216348)

<div class="topic-metadata">

**Author:** [@n1029676](https://discuss.elastic.co/u/n1029676)\
**Replies:** 2\
**Last updated:** [January 25, 2020, 1:06am UTC](https://discuss.elastic.co/t/filebeat-oss-7-5-2-not-parsing-string-as-json/216348 "2020-01-25T01:06:35Z")

</div>

I've put in about 6 hours trying to troubleshoot this whole deployment and keep running in circles. I have some containers running in Docker and I've deployed Filebeat-oss:7.5.2 to forward the docker logs. My containers…

---

## [How to configure filebeat to restart automatically when it stopped or strucked , when it is runningwith elastic beanstalk app](https://discuss.elastic.co/t/how-to-configure-filebeat-to-restart-automatically-when-it-stopped-or-strucked-when-it-is-runningwith-elastic-beanstalk-app/216491)

<div class="topic-metadata">

**Author:** [@souji](https://discuss.elastic.co/u/souji)\
**Replies:** 0\
**Last updated:** [January 24, 2020, 9:17pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-restart-automatically-when-it-stopped-or-strucked-when-it-is-runningwith-elastic-beanstalk-app/216491 "2020-01-24T21:17:03Z")

</div>

Hi, I am new to Filebeat. Right now I configured the filebeat in elasticbeanstalk app to collect the logs and sends to logstash. In unit testing I stopped the filebeat, but it didn't restart automatically. How can I ac…

---

## [Error Reading Netapp evtx file with winlogbeat](https://discuss.elastic.co/t/error-reading-netapp-evtx-file-with-winlogbeat/215780)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 1\
**Last updated:** [January 24, 2020, 8:42pm UTC](https://discuss.elastic.co/t/error-reading-netapp-evtx-file-with-winlogbeat/215780 "2020-01-24T20:42:59Z")

</div>

Hi, I'm trying to read evtx files from Netapp logs using the following https://www.elastic.co/guide/en/beats/winlogbeat/current/reading-from-evtx.html I'm able to read the events but when parsing the version field I g…

---

## [Type HTTP with Auth Digest](https://discuss.elastic.co/t/type-http-with-auth-digest/216482)

<div class="topic-metadata">

**Author:** [@holiveira](https://discuss.elastic.co/u/holiveira)\
**Replies:** 2\
**Last updated:** [January 24, 2020, 8:12pm UTC](https://discuss.elastic.co/t/type-http-with-auth-digest/216482 "2020-01-24T20:12:25Z")

</div>

Any way to monitor an http type that has digest authentication? I've tried using user policies and password, but without success.

---

## [Meaning of metricbeat system.cpu.total.pct](https://discuss.elastic.co/t/meaning-of-metricbeat-system-cpu-total-pct/216455)

<div class="topic-metadata">

**Author:** [@dantonag](https://discuss.elastic.co/u/dantonag)\
**Replies:** 1\
**Last updated:** [January 24, 2020, 6:33pm UTC](https://discuss.elastic.co/t/meaning-of-metricbeat-system-cpu-total-pct/216455 "2020-01-24T18:33:39Z")

</div>

Hello, we have, in our production environment, a machine with 56 cores (system.cpu.cores gives "56"). Exactly, which is the range system.cpu.total.pct will assume? 0-56? 0-100? Thanks Gabriele

---

## [Elasticsearch json logs with filebeat module and ingest pipeline](https://discuss.elastic.co/t/elasticsearch-json-logs-with-filebeat-module-and-ingest-pipeline/213376)

<div class="topic-metadata">

**Author:** [@jeffspahr](https://discuss.elastic.co/u/jeffspahr)\
**Replies:** 5\
**Last updated:** [January 24, 2020, 5:08pm UTC](https://discuss.elastic.co/t/elasticsearch-json-logs-with-filebeat-module-and-ingest-pipeline/213376 "2020-01-24T17:08:17Z")

</div>

Hello, Elasticsearch writes json logs by default in 7.x (thanks!). When configuring Filebeat's Elasticsearch module, I was thinking I could ignore the ingest pipeline part since it's already shipping structured logs, bu…

---

## [Custom beat install information and help](https://discuss.elastic.co/t/custom-beat-install-information-and-help/215958)

<div class="topic-metadata">

**Author:** [@kenrowland](https://discuss.elastic.co/u/kenrowland)\
**Replies:** 1\
**Last updated:** [January 24, 2020, 4:37pm UTC](https://discuss.elastic.co/t/custom-beat-install-information-and-help/215958 "2020-01-24T16:37:47Z")

</div>

I am developing a beat for our cluster platform. I believe I am going to create a metricset and module. However, the documentation does not cover installation on the target system. Can someone please point me to where I …

---

## [Override host.name for remote modules](https://discuss.elastic.co/t/override-host-name-for-remote-modules/216421)

<div class="topic-metadata">

**Author:** [@decibel83](https://discuss.elastic.co/u/decibel83)\
**Replies:** 1\
**Last updated:** [January 24, 2020, 3:38pm UTC](https://discuss.elastic.co/t/override-host-name-for-remote-modules/216421 "2020-01-24T15:38:05Z")

</div>

I am configuring Metricbeat to fetch some stats from a remote HAProxy server. This way HAProxy metrics are sent to Elasticsearch with the host.name of the local Metricbeat server and not of the host.name from the remote…

---

## [Login dataset is not supported on windows](https://discuss.elastic.co/t/login-dataset-is-not-supported-on-windows/216428)

<div class="topic-metadata">

**Author:** [@WilGG](https://discuss.elastic.co/u/WilGG)\
**Replies:** 1\
**Last updated:** [January 24, 2020, 3:18pm UTC](https://discuss.elastic.co/t/login-dataset-is-not-supported-on-windows/216428 "2020-01-24T15:18:56Z")

</div>

Hi Everyone I'm trying to put together SIEM by elk I have my Elasticserach and Kibana running on a single Debian aws node. and I have multiple Windows VM's (Slaves) sending security event logs to Windows logs collector …

---

## [Sending out logs from Windows machine to logstash via another Windows machine](https://discuss.elastic.co/t/sending-out-logs-from-windows-machine-to-logstash-via-another-windows-machine/216434)

<div class="topic-metadata">

**Author:** [@saif3r](https://discuss.elastic.co/u/saif3r)\
**Replies:** 1\
**Last updated:** [January 24, 2020, 3:09pm UTC](https://discuss.elastic.co/t/sending-out-logs-from-windows-machine-to-logstash-via-another-windows-machine/216434 "2020-01-24T15:09:33Z")

</div>

Hello, I am currently working on a process where we want to feed machine logs to our Logstash server. The way our network is setup makes it impossible to feed logs directly from Machine PC's to Logstash as Machine PC 1…

---

## [How to filter only error logs using filebeat](https://discuss.elastic.co/t/how-to-filter-only-error-logs-using-filebeat/216385)

<div class="topic-metadata">

**Author:** [@Anindita\_Chavan](https://discuss.elastic.co/u/Anindita_Chavan)\
**Replies:** 3\
**Last updated:** [January 24, 2020, 10:20am UTC](https://discuss.elastic.co/t/how-to-filter-only-error-logs-using-filebeat/216385 "2020-01-24T10:20:05Z")

</div>

Hello, i have a log file that contains INFO,WARN and ERROR like : \[17:37:17.103\] \[ERROR\] \[...\] \[.....\] these are log4j logs. Using filebeat, I want to filter out only those logs with log level ERROR and send them to …

---

## [FIlebeat not feeding logs to logstash](https://discuss.elastic.co/t/filebeat-not-feeding-logs-to-logstash/216363)

<div class="topic-metadata">

**Author:** [@Charles\_Yuliansen](https://discuss.elastic.co/u/Charles_Yuliansen)\
**Replies:** 2\
**Last updated:** [January 24, 2020, 9:56am UTC](https://discuss.elastic.co/t/filebeat-not-feeding-logs-to-logstash/216363 "2020-01-24T09:56:26Z")

</div>

I currently trying to sending iis logs by filebeat to logstash. Everything were fine when i send asterisk log to logstash but now for somereason filebeat wont sending logs to logstash . here is my filebeat.yml filebeat…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=281)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=283)
