# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=283

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 284

---

## [Auditbeat test config fails when auditbeat already running](https://discuss.elastic.co/t/auditbeat-test-config-fails-when-auditbeat-already-running/216312)

<div class="topic-metadata">

**Author:** [@p\_ansell](https://discuss.elastic.co/u/p_ansell)\
**Replies:** 0\
**Last updated:** [January 23, 2020, 8:17pm UTC](https://discuss.elastic.co/t/auditbeat-test-config-fails-when-auditbeat-already-running/216312 "2020-01-23T20:17:53Z")

</div>

I want to use the auditbeat test config command to test out new configurations on the servers they need to be deployed to (automatically using ansible template validate, to avoid overwriting configurations with something…

---

## [New Module Fails System Pipeline Reload Test](https://discuss.elastic.co/t/new-module-fails-system-pipeline-reload-test/215793)

<div class="topic-metadata">

**Author:** [@seaseao](https://discuss.elastic.co/u/seaseao)\
**Replies:** 3\
**Last updated:** [January 23, 2020, 8:57pm UTC](https://discuss.elastic.co/t/new-module-fails-system-pipeline-reload-test/215793 "2020-01-23T20:57:17Z")

</div>

Hi Everyone, I'm working on creating a new module for Filebeat to capture Greenplum command logs. After creating a module and fileset and adding in a first pipeline, the test\_reload\_writes\_pipeline test fails with error…

---

## [Testing beat module test\_modules.Test freezes](https://discuss.elastic.co/t/testing-beat-module-test-modules-test-freezes/216138)

<div class="topic-metadata">

**Author:** [@Jim\_Ivey](https://discuss.elastic.co/u/Jim_Ivey)\
**Replies:** 3\
**Last updated:** [January 23, 2020, 8:16pm UTC](https://discuss.elastic.co/t/testing-beat-module-test-modules-test-freezes/216138 "2020-01-23T20:16:24Z")

</div>

I'm trying to develop a module for filebeat. Running make testsuite, the furthest it ever gets is testing my module, where it just freezes -- for hours. For example: test\_fileset\_file\_071\_postgresql (test\_modules.Test…

---

## [Parse json from selected pods only](https://discuss.elastic.co/t/parse-json-from-selected-pods-only/215969)

<div class="topic-metadata">

**Author:** [@igniti0n](https://discuss.elastic.co/u/igniti0n)\
**Replies:** 1\
**Last updated:** [January 23, 2020, 7:05pm UTC](https://discuss.elastic.co/t/parse-json-from-selected-pods-only/215969 "2020-01-23T19:05:53Z")

</div>

Hello! I'm having an issue getting any parsing rules to work within my filebeat deployments. We have multiple services that need separate parsing rules that end up in the "message" field. Ideally i would like to be able…

---

## [Keeping Track of changes to host configuration object in Metricbeat](https://discuss.elastic.co/t/keeping-track-of-changes-to-host-configuration-object-in-metricbeat/215394)

<div class="topic-metadata">

**Author:** [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Replies:** 4\
**Last updated:** [January 23, 2020, 6:56pm UTC](https://discuss.elastic.co/t/keeping-track-of-changes-to-host-configuration-object-in-metricbeat/215394 "2020-01-23T18:56:20Z")

</div>

Greetings! I'm trying to look at changes to the "host" field produced by metricbeat. I'd like to run a process every day to see if this "host" field for some specific system changed. A typical metricbeat record that c…

---

## [Using custom pipeline for existing filebeat module](https://discuss.elastic.co/t/using-custom-pipeline-for-existing-filebeat-module/213270)

<div class="topic-metadata">

**Author:** [@jsosic](https://discuss.elastic.co/u/jsosic)\
**Replies:** 2\
**Last updated:** [January 23, 2020, 6:50pm UTC](https://discuss.elastic.co/t/using-custom-pipeline-for-existing-filebeat-module/213270 "2020-01-23T18:50:39Z")

</div>

Hi guys. I use custom nginx log format, with some additional fields, so current pipeline in Filebeat 7.x nginx module fails with "grok parse failure". My platform is CentOS 7.x. Now, I'm thinking of what is the best w…

---

## [Filebeat not sending logs to elasticsearch when pipeline is configured in filebeat.yml](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elasticsearch-when-pipeline-is-configured-in-filebeat-yml/216049)

<div class="topic-metadata">

**Author:** [@ramkms6666](https://discuss.elastic.co/u/ramkms6666)\
**Replies:** 1\
**Last updated:** [January 23, 2020, 6:43pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elasticsearch-when-pipeline-is-configured-in-filebeat-yml/216049 "2020-01-23T18:43:39Z")

</div>

hi, I have scenario trying to upload product logs using Filebeat to Elasticsearch. I have created ingest pipeline for converting log date to event date. Below is the ingest pipeline processor, PUT \_ingest/pipeline/mylo…

---

## [Best way to attach delete index via ilm](https://discuss.elastic.co/t/best-way-to-attach-delete-index-via-ilm/216078)

<div class="topic-metadata">

**Author:** [@Jathin](https://discuss.elastic.co/u/Jathin)\
**Replies:** 2\
**Last updated:** [January 23, 2020, 6:40pm UTC](https://discuss.elastic.co/t/best-way-to-attach-delete-index-via-ilm/216078 "2020-01-23T18:40:03Z")

</div>

It seems each new filebeat version creates its own mapping template and ilm policy. i had to manually update ilm policy to add delete phase. but for each new version a new ilm policy is created with default sections (wit…

---

## [DNS lookup failure "elasticsearch":](https://discuss.elastic.co/t/dns-lookup-failure-elasticsearch/216140)

<div class="topic-metadata">

**Author:** [@Adib\_Rastegarnia](https://discuss.elastic.co/u/Adib_Rastegarnia)\
**Replies:** 3\
**Last updated:** [January 23, 2020, 4:57pm UTC](https://discuss.elastic.co/t/dns-lookup-failure-elasticsearch/216140 "2020-01-23T16:57:59Z")

</div>

I have elasticsearch and kibana running in local k8s cluster (using kind) and they are up and running. I deployed filebeat using image version 7.5.2 and it is up and running but I see some errors in its logs that it cann…

---

## [Filebeat is shipping old log lines](https://discuss.elastic.co/t/filebeat-is-shipping-old-log-lines/216242)

<div class="topic-metadata">

**Author:** [@kwisatz](https://discuss.elastic.co/u/kwisatz)\
**Replies:** 2\
**Last updated:** [January 23, 2020, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-is-shipping-old-log-lines/216242 "2020-01-23T16:53:22Z")

</div>

I've recently noticed that filebeat is shipping not only new lines in my logs, but apparently all the lines, all the time. E.g. I'm shipping nginx logs that are being created very ordinarily: access\_log /v…

---

## [Adding Field Data By Api Call](https://discuss.elastic.co/t/adding-field-data-by-api-call/216211)

<div class="topic-metadata">

**Author:** [@benedery](https://discuss.elastic.co/u/benedery)\
**Replies:** 1\
**Last updated:** [January 23, 2020, 4:01pm UTC](https://discuss.elastic.co/t/adding-field-data-by-api-call/216211 "2020-01-23T16:01:38Z")

</div>

Hey, im using elastic,kibana,logstash, metricbeat and i want to add to EVERY document i get from metricbeat, a field that will be set by making an api call from server and fetching data. from my searches, i see i can …

---

## [Yet another exclude\_lines thread](https://discuss.elastic.co/t/yet-another-exclude-lines-thread/216239)

<div class="topic-metadata">

**Author:** [@kwisatz](https://discuss.elastic.co/u/kwisatz)\
**Replies:** 1\
**Last updated:** [January 23, 2020, 3:54pm UTC](https://discuss.elastic.co/t/yet-another-exclude-lines-thread/216239 "2020-01-23T15:54:16Z")

</div>

I'm sorry to have to open yet another exclude\_lines thread, but having read all the available threads and checked all possibilities, I still can't get the exclude\_lines option to work. My config is: filebeat: prospec…

---

## [Monitor API in heartbeat](https://discuss.elastic.co/t/monitor-api-in-heartbeat/216006)

<div class="topic-metadata">

**Author:** [@ollebil](https://discuss.elastic.co/u/ollebil)\
**Replies:** 1\
**Last updated:** [January 23, 2020, 2:47pm UTC](https://discuss.elastic.co/t/monitor-api-in-heartbeat/216006 "2020-01-23T14:47:32Z")

</div>

I'm trying to monitor an API that is behind Azure API management using heartbeat, and I need to submit the API key. This works: "curl https://api.blabla.com/service/v1/product/apicall" -H "Ocp-Apim-Subscription-Key: 123…

---

## [Metricbeat 7.5.1 Kubernetes Daemonset 400 Bad Request](https://discuss.elastic.co/t/metricbeat-7-5-1-kubernetes-daemonset-400-bad-request/216099)

<div class="topic-metadata">

**Author:** [@diegomolina](https://discuss.elastic.co/u/diegomolina)\
**Replies:** 5\
**Last updated:** [January 23, 2020, 2:36pm UTC](https://discuss.elastic.co/t/metricbeat-7-5-1-kubernetes-daemonset-400-bad-request/216099 "2020-01-23T14:36:05Z")

</div>

Hello, new user here. I recently deployed ECK on my own server with kubeadm (currently I'm just testing, so I have only one master node where I also schedule pods), using the ECK operator pattern and the quickstart guide…

---

## [Arithmetic operations in metricbeat processors](https://discuss.elastic.co/t/arithmetic-operations-in-metricbeat-processors/216234)

<div class="topic-metadata">

**Author:** [@naveenbangalore](https://discuss.elastic.co/u/naveenbangalore)\
**Replies:** 1\
**Last updated:** [January 23, 2020, 12:45pm UTC](https://discuss.elastic.co/t/arithmetic-operations-in-metricbeat-processors/216234 "2020-01-23T12:45:16Z")

</div>

I am trying to add the below metricbeat processor in system.yml file for adding a custom field. It does not throw any error but does not compute and add the field as well. Is it possible to perform arithmetic operations…

---

## [Where to check compatibility between metricbeat-kibana-elasticsearch](https://discuss.elastic.co/t/where-to-check-compatibility-between-metricbeat-kibana-elasticsearch/216136)

<div class="topic-metadata">

**Author:** [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Replies:** 3\
**Last updated:** [January 23, 2020, 12:17pm UTC](https://discuss.elastic.co/t/where-to-check-compatibility-between-metricbeat-kibana-elasticsearch/216136 "2020-01-23T12:17:53Z")

</div>

Hi, I'm installing in one machine metricbeat 7.5 and in other machine i have ELK 7.2, when loading the metricbeat dashboards i get errors in metricbeat realing to error 400 bad request, however dashboards load but never…

---

## [Problem](https://discuss.elastic.co/t/problem/216190)

<div class="topic-metadata">

**Author:** [@alxfernando](https://discuss.elastic.co/u/alxfernando)\
**Replies:** 1\
**Last updated:** [January 23, 2020, 8:23am UTC](https://discuss.elastic.co/t/problem/216190 "2020-01-23T08:23:41Z")

</div>

Hi I have a doubt, I want to analyze some logs that are not formatted, plain text with timestamp and ip addresses, among many other data, I have used logstash to load the data to elastisearch, but I found that logstash …

---

## [Configure disk spool using filebeat](https://discuss.elastic.co/t/configure-disk-spool-using-filebeat/216161)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 1\
**Last updated:** [January 23, 2020, 3:20am UTC](https://discuss.elastic.co/t/configure-disk-spool-using-filebeat/216161 "2020-01-23T03:20:32Z")

</div>

Hi Is there a way to use configure disk spool using filebeat? If the remote host is down, messages are spooled to disk on the client host and sent when it is up again. For example as per the below settings in rsyslog \> …

---

## [Send AWS Metadata alongwith logs from filebeat to kafka](https://discuss.elastic.co/t/send-aws-metadata-alongwith-logs-from-filebeat-to-kafka/216022)

<div class="topic-metadata">

**Author:** [@krish0608](https://discuss.elastic.co/u/krish0608)\
**Replies:** 1\
**Last updated:** [January 22, 2020, 11:03pm UTC](https://discuss.elastic.co/t/send-aws-metadata-alongwith-logs-from-filebeat-to-kafka/216022 "2020-01-22T23:03:18Z")

</div>

Is there any way through which i can send Aws metadata like instance id,Region,AccountId etc. This is my use case can you please help me out.

---

## [Headers are not being sent](https://discuss.elastic.co/t/headers-are-not-being-sent/216121)

<div class="topic-metadata">

**Author:** [@sudarshansr](https://discuss.elastic.co/u/sudarshansr)\
**Replies:** 1\
**Last updated:** [January 22, 2020, 8:55pm UTC](https://discuss.elastic.co/t/headers-are-not-being-sent/216121 "2020-01-22T20:55:00Z")

</div>

Hello, I have a http type heartbeat monitor with headers. However, it seems that the headers are note being sent. Below is the conf. from the yml file. What am i doing wrong? type: http # Analytics-NonProd monitor ty…

---

## [View apache extended status](https://discuss.elastic.co/t/view-apache-extended-status/212895)

<div class="topic-metadata">

**Author:** [@jamesbro](https://discuss.elastic.co/u/jamesbro)\
**Replies:** 5\
**Last updated:** [January 22, 2020, 8:30pm UTC](https://discuss.elastic.co/t/view-apache-extended-status/212895 "2020-01-22T20:30:33Z")

</div>

I am currently monitoring the Apache status page, however. the extended status is not viewable/searchable in Kibana. Is there a way to get the extended status info from the status page into elastic using the metricbeat …

---

## [ERROR: metricset jolokia.jmx: mbean properties must be in the form key=value](https://discuss.elastic.co/t/error-metricset-jolokia-jmx-mbean-properties-must-be-in-the-form-key-value/215778)

<div class="topic-metadata">

**Author:** [@vmoragar](https://discuss.elastic.co/u/vmoragar)\
**Replies:** 6\
**Last updated:** [January 22, 2020, 3:55pm UTC](https://discuss.elastic.co/t/error-metricset-jolokia-jmx-mbean-properties-must-be-in-the-form-key-value/215778 "2020-01-22T15:55:28Z")

</div>

Hi, I use metricbeat (jolokia) to get jmx information in Websphere. jmx.mappings: mbean: 'WebSphere:type=ThreadPool,name=WebContainer,\*' attributes: attr: maximumSize field: threadpool.maximumSize The error is: …

---

## [Very low index rate when using logtstash and / or kafka/redis](https://discuss.elastic.co/t/very-low-index-rate-when-using-logtstash-and-or-kafka-redis/215781)

<div class="topic-metadata">

**Author:** [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Replies:** 7\
**Last updated:** [January 22, 2020, 3:46pm UTC](https://discuss.elastic.co/t/very-low-index-rate-when-using-logtstash-and-or-kafka-redis/215781 "2020-01-22T15:46:54Z")

</div>

Hi all, Building a new cluster under 7.5.1. We are using the Filebeat Cisco Module to collect cisco asa logs. Firstly, we tried to store them in a Kafka Node and get them via Logstash into Elasticsearch. We saw very fas…

---

## [Yum install fails](https://discuss.elastic.co/t/yum-install-fails/215936)

<div class="topic-metadata">

**Author:** [@Jathin](https://discuss.elastic.co/u/Jathin)\
**Replies:** 7\
**Last updated:** [January 22, 2020, 2:23pm UTC](https://discuss.elastic.co/t/yum-install-fails/215936 "2020-01-22T14:23:14Z")

</div>

yum install filebeat-7.5.\* Loaded plugins: fastestmirror Loading mirror speeds from cached hostfile Resolving Dependencies --\> Running transaction check ---\> Package filebeat.x86\_64 0:7.5.1-1 will be updated ---\> Package…

---

## [Metricbeat Oracle module](https://discuss.elastic.co/t/metricbeat-oracle-module/215097)

<div class="topic-metadata">

**Author:** [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Replies:** 6\
**Last updated:** [January 22, 2020, 2:04pm UTC](https://discuss.elastic.co/t/metricbeat-oracle-module/215097 "2020-01-22T14:04:56Z")

</div>

Hi, I am trying to use the Metricbeat oracle module, but it seems that it requires the user to connect as a sysdba. Is there anyway for the sysdba requirement to be disabled? I executed all queries for the tablespaces …

---

## [Metricbeat 7.5.1 monitors Windows Processes](https://discuss.elastic.co/t/metricbeat-7-5-1-monitors-windows-processes/215999)

<div class="topic-metadata">

**Author:** [@Marcel\_Palme](https://discuss.elastic.co/u/Marcel_Palme)\
**Replies:** 1\
**Last updated:** [January 22, 2020, 12:20pm UTC](https://discuss.elastic.co/t/metricbeat-7-5-1-monitors-windows-processes/215999 "2020-01-22T12:20:46Z")

</div>

Hi, now i want to monitor all windows processes on a Host. I configure system.yml als follow: Module: system module: system metricsets: process processes: '.\*' but i get not all Processes that i see unter the Task…

---

## [Actual memory usage on the SUSE 12 SP4 operating system is inaccurate](https://discuss.elastic.co/t/actual-memory-usage-on-the-suse-12-sp4-operating-system-is-inaccurate/214516)

<div class="topic-metadata">

**Author:** [@wangtanxu](https://discuss.elastic.co/u/wangtanxu)\
**Replies:** 1\
**Last updated:** [January 22, 2020, 9:15am UTC](https://discuss.elastic.co/t/actual-memory-usage-on-the-suse-12-sp4-operating-system-is-inaccurate/214516 "2020-01-22T09:15:38Z")

</div>

KiB Mem : 16260192 total, 195472 free, 15297300 used KiB Swap: 16257532 total, 8238932 free, 18600 used. 8257532 cache My actual memory usage is 15297300 / 16260192 = 0.94, right? but the value that metricbeat …

---

## [Could not load template: couldn't load template: couldn't load json. Error: 400 Bad Request](https://discuss.elastic.co/t/could-not-load-template-couldnt-load-template-couldnt-load-json-error-400-bad-request/215961)

<div class="topic-metadata">

**Author:** [@Bjen\_Shah](https://discuss.elastic.co/u/Bjen_Shah)\
**Replies:** 0\
**Last updated:** [January 21, 2020, 10:27pm UTC](https://discuss.elastic.co/t/could-not-load-template-couldnt-load-template-couldnt-load-json-error-400-bad-request/215961 "2020-01-21T22:27:41Z")

</div>

2020-01-17T09:49:26-06:00 INFO Connected to Elasticsearch version 7.5.0 2020-01-17T09:49:26-06:00 INFO Trying to load template for client: http://0.0.0.0:9200 2020-01-17T09:49:26-06:00 ERR Connecting error publishing eve…

---

## [Filebeat 7.4v does not pick up the index templates provided in filebeat.yml](https://discuss.elastic.co/t/filebeat-7-4v-does-not-pick-up-the-index-templates-provided-in-filebeat-yml/214982)

<div class="topic-metadata">

**Author:** [@Sherlock\_H](https://discuss.elastic.co/u/Sherlock_H)\
**Replies:** 3\
**Last updated:** [January 21, 2020, 8:06pm UTC](https://discuss.elastic.co/t/filebeat-7-4v-does-not-pick-up-the-index-templates-provided-in-filebeat-yml/214982 "2020-01-21T20:06:17Z")

</div>

Hi Team, I have recently upgraded filebeat to 7.4v . I have setup.ilm.enabled: true in filebeat.yml but it does not seem to pick up the index template that i have provided in filebeat.yml, and instead it uses the defau…

---

## [Auditbeat not is connecting to Elasticksearch](https://discuss.elastic.co/t/auditbeat-not-is-connecting-to-elasticksearch/215891)

<div class="topic-metadata">

**Author:** [@Adrian\_Martinez\_Doca](https://discuss.elastic.co/u/Adrian_Martinez_Doca)\
**Replies:** 2\
**Last updated:** [January 21, 2020, 6:39pm UTC](https://discuss.elastic.co/t/auditbeat-not-is-connecting-to-elasticksearch/215891 "2020-01-21T18:39:30Z")

</div>

Hi to all, i am configuring auditbeat in some servers, i could configure in one server correctly and i can see info in Kibana, but when i configure the other servers i have the same message error. auditbeat: 2020-01-21T…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=282)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=284)
