# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=284

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 285

---

## [Capture All RAW traffic?](https://discuss.elastic.co/t/capture-all-raw-traffic/215937)

<div class="topic-metadata">

**Author:** [@Matt\_Vasquez](https://discuss.elastic.co/u/Matt_Vasquez)\
**Replies:** 0\
**Last updated:** [January 21, 2020, 6:23pm UTC](https://discuss.elastic.co/t/capture-all-raw-traffic/215937 "2020-01-21T18:23:27Z")

</div>

Is there a way for packetbeat to capture all raw packet data? I don't want to decode or specify protocols, just want all the raw packets as I would expect in wireshark..

---

## [Is there a way to specify the NIC for output?](https://discuss.elastic.co/t/is-there-a-way-to-specify-the-nic-for-output/215913)

<div class="topic-metadata">

**Author:** [@austin0918](https://discuss.elastic.co/u/austin0918)\
**Replies:** 2\
**Last updated:** [January 21, 2020, 4:32pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-specify-the-nic-for-output/215913 "2020-01-21T16:32:14Z")

</div>

Hi There, I have two NICs on a Linux server. Is there a way to specify which NIC to use by Filebeat for logstash output?

---

## [Generating metricbeat index pattern](https://discuss.elastic.co/t/generating-metricbeat-index-pattern/214682)

<div class="topic-metadata">

**Author:** [@mladen](https://discuss.elastic.co/u/mladen)\
**Replies:** 2\
**Last updated:** [January 21, 2020, 1:59pm UTC](https://discuss.elastic.co/t/generating-metricbeat-index-pattern/214682 "2020-01-21T13:59:08Z")

</div>

Hello, following beats developer guide I mange to install go. My goal is to change default metricbeat index pattern. I clone git repo, run make command & make update. Command make update created fields.yml file. I add m…

---

## [Metricbeat Http Module mapping error (Can't merge a non object mapping \[http.json\_namespace.classes\] with an object mapping \[http.json\_namespace.classes\] )](https://discuss.elastic.co/t/metricbeat-http-module-mapping-error-cant-merge-a-non-object-mapping-http-json-namespace-classes-with-an-object-mapping-http-json-namespace-classes/215322)

<div class="topic-metadata">

**Author:** [@fnkbz](https://discuss.elastic.co/u/fnkbz)\
**Replies:** 2\
**Last updated:** [January 21, 2020, 12:53pm UTC](https://discuss.elastic.co/t/metricbeat-http-module-mapping-error-cant-merge-a-non-object-mapping-http-json-namespace-classes-with-an-object-mapping-http-json-namespace-classes/215322 "2020-01-21T12:53:21Z")

</div>

I am running elasticsearch 7.5, kibana 7.5 and Metricbeat 7.5. I have enabled metricbeat's http module to get data from a spring boot app. Here is my metricbeat.yml http module snippet #---------------------------------…

---

## [Functionbeat kinesis filter\_pattern and elastic id](https://discuss.elastic.co/t/functionbeat-kinesis-filter-pattern-and-elastic-id/215867)

<div class="topic-metadata">

**Author:** [@nmesmeric](https://discuss.elastic.co/u/nmesmeric)\
**Replies:** 0\
**Last updated:** [January 21, 2020, 11:10am UTC](https://discuss.elastic.co/t/functionbeat-kinesis-filter-pattern-and-elastic-id/215867 "2020-01-21T11:10:11Z")

</div>

Hey, I have set up functionbeat to send events from Amazon Kinesis to our Elasticsearch cluster. I have two issues that i wondered if anyone could assist with. I have added a string as a filter\_pattern, however it d…

---

## [Time Zone in CEF FB Module](https://discuss.elastic.co/t/time-zone-in-cef-fb-module/215188)

<div class="topic-metadata">

**Author:** [@culprit](https://discuss.elastic.co/u/culprit)\
**Replies:** 13\
**Last updated:** [January 21, 2020, 9:41am UTC](https://discuss.elastic.co/t/time-zone-in-cef-fb-module/215188 "2020-01-21T09:41:26Z")

</div>

I am new to all this, so bear with me if i use the wrong terminology. Working on getting Fortigate logs into ES. Currently the path the events take are: Fortgate -\> FortiAnalyzer (forwarded in CEF format) -\> FileBea…

---

## [LimitNOFILE Parameter 65K for ElasticSearch . for RHEL](https://discuss.elastic.co/t/limitnofile-parameter-65k-for-elasticsearch-for-rhel/215837)

<div class="topic-metadata">

**Author:** [@kprasann](https://discuss.elastic.co/u/kprasann)\
**Replies:** 0\
**Last updated:** [January 21, 2020, 8:32am UTC](https://discuss.elastic.co/t/limitnofile-parameter-65k-for-elasticsearch-for-rhel/215837 "2020-01-21T08:32:14Z")

</div>

Hi, Is it ok to set 65k as LimitNOFile in RHEL as root user? If there are performance issues with 65K File handles, how can that be mitigated? Can the file handle processes be killed? Any monitoring tool that can be used…

---

## [Using Filebeat/Pibeat/Easybeat w/ Suricata on Raspberry Pi 3 for Bitnami ELK](https://discuss.elastic.co/t/using-filebeat-pibeat-easybeat-w-suricata-on-raspberry-pi-3-for-bitnami-elk/215819)

<div class="topic-metadata">

**Author:** [@gorgymorg](https://discuss.elastic.co/u/gorgymorg)\
**Replies:** 0\
**Last updated:** [January 21, 2020, 4:44am UTC](https://discuss.elastic.co/t/using-filebeat-pibeat-easybeat-w-suricata-on-raspberry-pi-3-for-bitnami-elk/215819 "2020-01-21T04:44:50Z")

</div>

Hi, I have been reading over forum posts and readmes for trying to use filebeat and offshoots to integrate logs from Suricata running on a Raspberry Pi and ship them to a Bitnami ELK VM I have running on my computer - I …

---

## [Filebeat + cisco module - listening on other than localhost](https://discuss.elastic.co/t/filebeat-cisco-module-listening-on-other-than-localhost/212944)

<div class="topic-metadata">

**Author:** [@coltrane35](https://discuss.elastic.co/u/coltrane35)\
**Replies:** 2\
**Last updated:** [January 20, 2020, 10:18pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-listening-on-other-than-localhost/212944 "2020-01-20T22:18:57Z")

</div>

Hello, i have installed filebeat and enable cisco module Cico module default configuration make filebeat listenning on localhost 127.0.0.1 I want it to listen on all interfaces 0.0.0.0. Below is what is written in ci…

---

## [Sysmon DNS Query missing Status codes](https://discuss.elastic.co/t/sysmon-dns-query-missing-status-codes/213396)

<div class="topic-metadata">

**Author:** [@Nicholas\_Penning](https://discuss.elastic.co/u/Nicholas_Penning)\
**Replies:** 3\
**Last updated:** [January 20, 2020, 6:44pm UTC](https://discuss.elastic.co/t/sysmon-dns-query-missing-status-codes/213396 "2020-01-20T18:44:05Z")

</div>

Hello, We are ingesting some SysMon (Version 10.41) DNS logs via WinLogbeat 7.4.0 and have found that some status codes are not either getting translated with the sysmon.js or are not in the list. I will focus on the ev…

---

## [SysMon DNS Logs - dns.answers - Types](https://discuss.elastic.co/t/sysmon-dns-logs-dns-answers-types/213471)

<div class="topic-metadata">

**Author:** [@Nicholas\_Penning](https://discuss.elastic.co/u/Nicholas_Penning)\
**Replies:** 2\
**Last updated:** [January 20, 2020, 6:17pm UTC](https://discuss.elastic.co/t/sysmon-dns-logs-dns-answers-types/213471 "2020-01-20T18:17:04Z")

</div>

Hello, We are currently leveraging SysMon DNS logs and would like to have the capability to search/aggregrate on the types from the dns.answers that WinLogBeat ships to Elastic. Currently, the dns.answers field contain…

---

## [Syslog filebeat input, how to get sender IP address?](https://discuss.elastic.co/t/syslog-filebeat-input-how-to-get-sender-ip-address/214809)

<div class="topic-metadata">

**Author:** [@emilie](https://discuss.elastic.co/u/emilie)\
**Replies:** 7\
**Last updated:** [January 20, 2020, 5:03pm UTC](https://discuss.elastic.co/t/syslog-filebeat-input-how-to-get-sender-ip-address/214809 "2020-01-20T17:03:06Z")

</div>

Hello, I'm using filebeat to send syslog input to a kafka server (it works wonderfully, thank you). But I'm wondering: how can I add the IP from the machine that is sending its syslog input in my logs? (I'm aware of p…

---

## [Not able to filter from filebeat](https://discuss.elastic.co/t/not-able-to-filter-from-filebeat/215770)

<div class="topic-metadata">

**Author:** [@surya1](https://discuss.elastic.co/u/surya1)\
**Replies:** 1\
**Last updated:** [January 20, 2020, 4:45pm UTC](https://discuss.elastic.co/t/not-able-to-filter-from-filebeat/215770 "2020-01-20T16:45:59Z")

</div>

Hi , I have a log a file that has 10-12 lines per paragraph and this same pattern repeats. From this log file I need to select only 4-5 lines . Tried to use include lines but in elastic search i am not getting these as…

---

## [Unable to insert log data using filebeat](https://discuss.elastic.co/t/unable-to-insert-log-data-using-filebeat/215458)

<div class="topic-metadata">

**Author:** [@NileshG](https://discuss.elastic.co/u/NileshG)\
**Replies:** 2\
**Last updated:** [January 20, 2020, 10:16am UTC](https://discuss.elastic.co/t/unable-to-insert-log-data-using-filebeat/215458 "2020-01-20T10:16:00Z")

</div>

Hi, I am trying to insert log data using filebeat in an ElascticSearch. The index is created but the data differ than the actual one. My Log is 2020-01-17T17:13:43.218+0530 INFO crawler/crawler.go:106 Loading and…

---

## [Need explanations with filebeats & ILM](https://discuss.elastic.co/t/need-explanations-with-filebeats-ilm/214629)

<div class="topic-metadata">

**Author:** [@smux](https://discuss.elastic.co/u/smux)\
**Replies:** 2\
**Last updated:** [January 20, 2020, 10:55am UTC](https://discuss.elastic.co/t/need-explanations-with-filebeats-ilm/214629 "2020-01-20T10:55:23Z")

</div>

Hi, I’m trying to understand few things before setting up my cluster. 1 - Why filebeat default output index is filebeat-%{\[agent.version\]}-%{+yyyy.MM.dd} now it’s recommanded to use the ILM ? Why letting filebeat creat…

---

## [File beat stops time to time in RHEL environment](https://discuss.elastic.co/t/file-beat-stops-time-to-time-in-rhel-environment/213855)

<div class="topic-metadata">

**Author:** [@ruranga](https://discuss.elastic.co/u/ruranga)\
**Replies:** 2\
**Last updated:** [January 20, 2020, 9:36am UTC](https://discuss.elastic.co/t/file-beat-stops-time-to-time-in-rhel-environment/213855 "2020-01-20T09:36:48Z")

</div>

Hi, I have installed filbeat in RHEL syslog server and sending the logs to ELK stack at another server, By the way filebeat in the syslog server getting stopped time to time. When I check the logs following found 2020-…

---

## [Filebeat docker installation connection refused](https://discuss.elastic.co/t/filebeat-docker-installation-connection-refused/215607)

<div class="topic-metadata">

**Author:** [@NZHawk](https://discuss.elastic.co/u/NZHawk)\
**Replies:** 1\
**Last updated:** [January 19, 2020, 3:53pm UTC](https://discuss.elastic.co/t/filebeat-docker-installation-connection-refused/215607 "2020-01-19T15:53:09Z")

</div>

So I've just embarked on the windy ELK road and as a training ground I thought I'd look into the ease of Docker deployments before I get under the hood and drill down on config specifics. I've installed an ELK docker sta…

---

## [Need help with filebeat settings to separate logs in logstash for grok parser](https://discuss.elastic.co/t/need-help-with-filebeat-settings-to-separate-logs-in-logstash-for-grok-parser/215157)

<div class="topic-metadata">

**Author:** [@T4iga](https://discuss.elastic.co/u/T4iga)\
**Replies:** 5\
**Last updated:** [January 19, 2020, 2:36am UTC](https://discuss.elastic.co/t/need-help-with-filebeat-settings-to-separate-logs-in-logstash-for-grok-parser/215157 "2020-01-19T02:36:13Z")

</div>

I have an environment with a log-server and a second server runnig an ELK stack. The log-server writes logs to multiple directories on disk. I use filebeat to send those logs to the ELK server. I wrote a grok parsers to…

---

## [Config template "processors" section shadows custom processors in custom beats](https://discuss.elastic.co/t/config-template-processors-section-shadows-custom-processors-in-custom-beats/215578)

<div class="topic-metadata">

**Author:** [@chris-counteractive](https://discuss.elastic.co/u/chris-counteractive)\
**Replies:** 0\
**Last updated:** [January 18, 2020, 10:30pm UTC](https://discuss.elastic.co/t/config-template-processors-section-shadows-custom-processors-in-custom-beats/215578 "2020-01-18T22:30:53Z")

</div>

When you build a custom beat, the build process creates your config file by concatenating your custom \_meta/beat.yml and libbeat's \_meta/config.yml.tmpl. When it does this, any custom processors you've defined in \_meta…

---

## [RPM names do not match their contents - recreating issue](https://discuss.elastic.co/t/rpm-names-do-not-match-their-contents-recreating-issue/203195)

<div class="topic-metadata">

**Author:** [@akshatsharma](https://discuss.elastic.co/u/akshatsharma)\
**Replies:** 10\
**Last updated:** [January 18, 2020, 4:30pm UTC](https://discuss.elastic.co/t/rpm-names-do-not-match-their-contents-recreating-issue/203195 "2020-01-18T16:30:04Z")

</div>

Creating new issue as the previous issue(RPM names do not match their contents) was closed. Do we have any update on this? Best Regards, Akshat

---

## [Metricbeat Autodiscover Redis Module No Data](https://discuss.elastic.co/t/metricbeat-autodiscover-redis-module-no-data/214670)

<div class="topic-metadata">

**Author:** [@pooch](https://discuss.elastic.co/u/pooch)\
**Replies:** 11\
**Last updated:** [January 17, 2020, 8:38pm UTC](https://discuss.elastic.co/t/metricbeat-autodiscover-redis-module-no-data/214670 "2020-01-17T20:38:38Z")

</div>

For some reason I cannot pick up redis data using autodiscover for metricbeat. Auto discover for nginx is working just fine. I am running out of troubleshooting ideas. k8s version 1.14.6 metricbeats conf snip metricbe…

---

## [Google Cloud Module - Extracted Fields](https://discuss.elastic.co/t/google-cloud-module-extracted-fields/215216)

<div class="topic-metadata">

**Author:** [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Replies:** 2\
**Last updated:** [January 17, 2020, 6:44pm UTC](https://discuss.elastic.co/t/google-cloud-module-extracted-fields/215216 "2020-01-17T18:44:22Z")

</div>

Is the insertId field omitted in filebeat by Google Cloud module while extracting fields? The GCP flow logs have the insertId field in the initial logs, but it doesn't seem to be translated/parsed by the filebeat module. …

---

## [Segmentation violation and other errors with Go 1.13.6 - Beats 7.5.1](https://discuss.elastic.co/t/segmentation-violation-and-other-errors-with-go-1-13-6-beats-7-5-1/215208)

<div class="topic-metadata">

**Author:** [@Rishi\_Misra](https://discuss.elastic.co/u/Rishi_Misra)\
**Replies:** 8\
**Last updated:** [January 17, 2020, 3:26pm UTC](https://discuss.elastic.co/t/segmentation-violation-and-other-errors-with-go-1-13-6-beats-7-5-1/215208 "2020-01-17T15:26:22Z")

</div>

Hi there, I am in the process of porting Beats on s390x architecture and noticed that there are multiple segmentation violation when running test cases (Most of the beats - for example Filebeat, Packetbeat, Heartbeat ha…

---

## [Filebeat does not work while using cloud.id and cloud.auth](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167)

<div class="topic-metadata">

**Author:** [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Replies:** 15\
**Last updated:** [January 17, 2020, 2:48pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167 "2020-01-17T14:48:04Z")

</div>

Hello - I am trying to use cloud.id and cloud.auth in my file beat configuration file. But that seems not working. This Works perfectly without using cloud.id and cloud\_auth. output.elasticsearch: hosts: \["https://4d…

---

## [Heartbeat Kubernetes deployment manifests and icmp dashboards](https://discuss.elastic.co/t/heartbeat-kubernetes-deployment-manifests-and-icmp-dashboards/214847)

<div class="topic-metadata">

**Author:** [@akrzos](https://discuss.elastic.co/u/akrzos)\
**Replies:** 9\
**Last updated:** [January 17, 2020, 2:20pm UTC](https://discuss.elastic.co/t/heartbeat-kubernetes-deployment-manifests-and-icmp-dashboards/214847 "2020-01-17T14:20:59Z")

</div>

Is there a heartbeat kubernetes deployment manifest that is available? (I only see auditbeat/filebeat/metricbeat yamls) Ideally this would show heartbeat best practices and or possible deployments in kubernetes. Also a…

---

## [Filebeat Azure Module Issue](https://discuss.elastic.co/t/filebeat-azure-module-issue/215297)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 4\
**Last updated:** [January 17, 2020, 12:37pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-issue/215297 "2020-01-17T12:37:01Z")

</div>

Hello, We seem to have issues getting the Filebeat Azure module to connect to our configured Azure namespace. Filebeat version is 7.5.1. Filebeat logs: Jan 16 11:42:31 myserver filebeat\[26155\]: 2020-01-16T11:42:31.680…

---

## [Filebeat script](https://discuss.elastic.co/t/filebeat-script/215402)

<div class="topic-metadata">

**Author:** [@fang5826](https://discuss.elastic.co/u/fang5826)\
**Replies:** 1\
**Last updated:** [January 17, 2020, 8:33am UTC](https://discuss.elastic.co/t/filebeat-script/215402 "2020-01-17T08:33:54Z")

</div>

In filebeat's script, how to create a new event and make it take effect, just like new\_event\_block.call() in logstash's ruby plug-in

---

## [Filebeat kafka out plugin error when configuring multiple topics using regex](https://discuss.elastic.co/t/filebeat-kafka-out-plugin-error-when-configuring-multiple-topics-using-regex/215264)

<div class="topic-metadata">

**Author:** [@iamabug](https://discuss.elastic.co/u/iamabug)\
**Replies:** 2\
**Last updated:** [January 16, 2020, 10:11pm UTC](https://discuss.elastic.co/t/filebeat-kafka-out-plugin-error-when-configuring-multiple-topics-using-regex/215264 "2020-01-16T22:11:10Z")

</div>

I am trying to output file to different topic using regex, but the following config does not work: filebeat.inputs: - type: log enabled: true paths: - ~/1.log output.kafka: enabled: true hosts: \["loca…

---

## [Multiline message with repeated header](https://discuss.elastic.co/t/multiline-message-with-repeated-header/215324)

<div class="topic-metadata">

**Author:** [@widhalmt](https://discuss.elastic.co/u/widhalmt)\
**Replies:** 1\
**Last updated:** [January 16, 2020, 8:21pm UTC](https://discuss.elastic.co/t/multiline-message-with-repeated-header/215324 "2020-01-16T20:21:25Z")

</div>

Hi, I have a rather tricky situation. Multiline messages are sent through some transportation service which adds its own header. Due to policy (and technical) issues it's not possible to install Filebeat on the originat…

---

## [MetricBeat and Pipelines?](https://discuss.elastic.co/t/metricbeat-and-pipelines/215306)

<div class="topic-metadata">

**Author:** [@Vafa\_Ronaghi](https://discuss.elastic.co/u/Vafa_Ronaghi)\
**Replies:** 1\
**Last updated:** [January 16, 2020, 7:35pm UTC](https://discuss.elastic.co/t/metricbeat-and-pipelines/215306 "2020-01-16T19:35:57Z")

</div>

Is it possible to use multiple pipelines for Metricbeat like in Logstash ? I am triyng to collect metrics from multiple PostgreSQL IInstances on same Machine. Each Instance belongs to one Application. I dont want to …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=283)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=285)
