# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=285

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 286

---

## [Filebeat to Kafka SSL (with jks)](https://discuss.elastic.co/t/filebeat-to-kafka-ssl-with-jks/213595)

<div class="topic-metadata">

**Author:** [@nisham](https://discuss.elastic.co/u/nisham)\
**Replies:** 1\
**Last updated:** [January 16, 2020, 6:57pm UTC](https://discuss.elastic.co/t/filebeat-to-kafka-ssl-with-jks/213595 "2020-01-16T18:57:10Z")

</div>

Hello, I have setup a Kafka server with SSL enabled using the jks file. I'm able to read and write from the Kafka topic using Logstash by providing the JKS files in the logstash config file. I need to write data from F…

---

## [Filebeats via docker refusing to decode JSON](https://discuss.elastic.co/t/filebeats-via-docker-refusing-to-decode-json/215261)

<div class="topic-metadata">

**Author:** [@spamoom](https://discuss.elastic.co/u/spamoom)\
**Replies:** 2\
**Last updated:** [January 16, 2020, 6:03pm UTC](https://discuss.elastic.co/t/filebeats-via-docker-refusing-to-decode-json/215261 "2020-01-16T18:03:16Z")

</div>

I'm trying to configure filebeats to decode JSON messages put onto the docker logs (I have this setup using standard filebeats using the same config and it works without issue). It appears that the co.elastic.logs/enable…

---

## [Connection marked as failed because the onConnect callback failed: resource 'filebeat-7.5.1' exists, but it is not an alias"](https://discuss.elastic.co/t/connection-marked-as-failed-because-the-onconnect-callback-failed-resource-filebeat-7-5-1-exists-but-it-is-not-an-alias/214253)

<div class="topic-metadata">

**Author:** [@Flaviu](https://discuss.elastic.co/u/Flaviu)\
**Replies:** 2\
**Last updated:** [January 16, 2020, 5:26pm UTC](https://discuss.elastic.co/t/connection-marked-as-failed-because-the-onconnect-callback-failed-resource-filebeat-7-5-1-exists-but-it-is-not-an-alias/214253 "2020-01-16T17:26:06Z")

</div>

Hello, I have just installed a new server with filebeat 7.5.1 and for some reason, after I restart the filebeat or the server I get this error: Connection marked as failed because the onConnect callback failed: resour…

---

## [geoIP enrichment stops ES from receiving data from packetbeat](https://discuss.elastic.co/t/geoip-enrichment-stops-es-from-receiving-data-from-packetbeat/214955)

<div class="topic-metadata">

**Author:** [@jsu](https://discuss.elastic.co/u/jsu)\
**Replies:** 4\
**Last updated:** [January 16, 2020, 3:01pm UTC](https://discuss.elastic.co/t/geoip-enrichment-stops-es-from-receiving-data-from-packetbeat/214955 "2020-01-16T15:01:34Z")

</div>

Hey there, I'm currently running Packetbeat on a linux box and it sends directly data to an Elasticsearch cluster. Everything runs perfectly fine, except when I want to add geoIP info following this documentation. Inde…

---

## [Nginx file\_format incorrect output](https://discuss.elastic.co/t/nginx-file-format-incorrect-output/215113)

<div class="topic-metadata">

**Author:** [@marbro15](https://discuss.elastic.co/u/marbro15)\
**Replies:** 8\
**Last updated:** [January 16, 2020, 12:59pm UTC](https://discuss.elastic.co/t/nginx-file-format-incorrect-output/215113 "2020-01-16T12:59:19Z")

</div>

Hello, I have a question about the nginx log\_format. Currently we have the problem, that the source.address in filebeat shows address and ip in one field. For example: "source": { "address": "www.domain.tld 123.123.…

---

## [Filebeat sends packets with 0 leangth](https://discuss.elastic.co/t/filebeat-sends-packets-with-0-leangth/215265)

<div class="topic-metadata">

**Author:** [@ruranga](https://discuss.elastic.co/u/ruranga)\
**Replies:** 0\
**Last updated:** [January 16, 2020, 8:15am UTC](https://discuss.elastic.co/t/filebeat-sends-packets-with-0-leangth/215265 "2020-01-16T08:15:47Z")

</div>

Hi, I'm sending logs to ELK server using filebeat running in the syslog server. I dont get any update in KIbana. Then I check the packets (using tcpdump) in the syslog server (where filebeat runs), all packets are with …

---

## [Incorrect filebeat nginx mappings with kubernetes deployment](https://discuss.elastic.co/t/incorrect-filebeat-nginx-mappings-with-kubernetes-deployment/215046)

<div class="topic-metadata">

**Author:** [@laurentiusoica](https://discuss.elastic.co/u/laurentiusoica)\
**Replies:** 1\
**Last updated:** [January 16, 2020, 6:50am UTC](https://discuss.elastic.co/t/incorrect-filebeat-nginx-mappings-with-kubernetes-deployment/215046 "2020-01-16T06:50:14Z")

</div>

While using the k8s manifest from here https://raw.githubusercontent.com/elastic/beats/7.5/deploy/kubernetes/filebeat-kubernetes.yaml The nginx module mappings looks like these: "nginx" : { "properties" :…

---

## [Filebeat cannot find registry file (/var/lib/filebeat/registry/filebeat)](https://discuss.elastic.co/t/filebeat-cannot-find-registry-file-var-lib-filebeat-registry-filebeat/214997)

<div class="topic-metadata">

**Author:** [@ntran](https://discuss.elastic.co/u/ntran)\
**Replies:** 5\
**Last updated:** [January 16, 2020, 6:36am UTC](https://discuss.elastic.co/t/filebeat-cannot-find-registry-file-var-lib-filebeat-registry-filebeat/214997 "2020-01-16T06:36:02Z")

</div>

Hi all, I am getting this error message when I run filebeat -e: Writing of registry returned error: rename /var/lib/filebeat/registry/filebeat/data.json.new /var/lib/filebeat/registry/filebeat/data.json: no such file o…

---

## [Account name not showing in windows event\_id 4732](https://discuss.elastic.co/t/account-name-not-showing-in-windows-event-id-4732/213177)

<div class="topic-metadata">

**Author:** [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Replies:** 5\
**Last updated:** [January 16, 2020, 3:56am UTC](https://discuss.elastic.co/t/account-name-not-showing-in-windows-event-id-4732/213177 "2020-01-16T03:56:42Z")

</div>

I am trying to track users added to Administrators group. But in the event viewer log shows local username and group, but in the event which i am receiving has only the SID. I check the Friendly View and XML View, both a…

---

## [Suricata logs to Filebeat to Kafka topics, by event-type](https://discuss.elastic.co/t/suricata-logs-to-filebeat-to-kafka-topics-by-event-type/215179)

<div class="topic-metadata">

**Author:** [@driekhof](https://discuss.elastic.co/u/driekhof)\
**Replies:** 2\
**Last updated:** [January 15, 2020, 11:01pm UTC](https://discuss.elastic.co/t/suricata-logs-to-filebeat-to-kafka-topics-by-event-type/215179 "2020-01-15T23:01:32Z")

</div>

Hello, new to Filebeat. I have a simplified case working: Suricata to Filebeat to Kafka if I hard code one kafka topic name in filebeat.yml. But I'd like to make Filebeat dynamically route events to different topics b…

---

## [Question regarding Customizing fields.yml](https://discuss.elastic.co/t/question-regarding-customizing-fields-yml/215176)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 1\
**Last updated:** [January 15, 2020, 10:03pm UTC](https://discuss.elastic.co/t/question-regarding-customizing-fields-yml/215176 "2020-01-15T22:03:17Z")

</div>

Hi there, Just wanted to know what the general guidelines/best practices are regarding fields.yml which is used for creating index template. The out-of-box fields.yml has hundreds of fields and we are not even using m…

---

## [Metricbeat on MySQL docker](https://discuss.elastic.co/t/metricbeat-on-mysql-docker/215045)

<div class="topic-metadata">

**Author:** [@Martin\_Kirouac](https://discuss.elastic.co/u/Martin_Kirouac)\
**Replies:** 5\
**Last updated:** [January 15, 2020, 8:25pm UTC](https://discuss.elastic.co/t/metricbeat-on-mysql-docker/215045 "2020-01-15T20:25:10Z")

</div>

Hi. As a learning experience, I am trying to install Metricbeat on the MySQL 5.7 docker official (debian flavor see Dockerfile below) image using the official ELK image (elasticsearch:7.5.1 and kibana:7.5.1). I am strugg…

---

## [Drop\_event.when.not.or: - not working, Please help](https://discuss.elastic.co/t/drop-event-when-not-or-not-working-please-help/214843)

<div class="topic-metadata">

**Author:** [@GuessMyName](https://discuss.elastic.co/u/GuessMyName)\
**Replies:** 1\
**Last updated:** [January 15, 2020, 7:03pm UTC](https://discuss.elastic.co/t/drop-event-when-not-or-not-working-please-help/214843 "2020-01-15T19:03:16Z")

</div>

Hi Guys, For some reason... Winlogbeat is grabbing all security logs not just the one listed below, any idea what I'm missing ?, Running 7.5.1 Thx! winlogbeat.event\_logs: name: Security processors: drop\_event.whe…

---

## [Filebeat 7.5.1 Missing a step for custom index names config?](https://discuss.elastic.co/t/filebeat-7-5-1-missing-a-step-for-custom-index-names-config/215044)

<div class="topic-metadata">

**Author:** [@cgutshall](https://discuss.elastic.co/u/cgutshall)\
**Replies:** 2\
**Last updated:** [January 15, 2020, 3:51pm UTC](https://discuss.elastic.co/t/filebeat-7-5-1-missing-a-step-for-custom-index-names-config/215044 "2020-01-15T15:51:32Z")

</div>

I have the following set it my filebeat.yml config file, which should allow me to see dev-\* index in kibana. However these are still showing as filebeat-\*. Is there something Im missing based on the docs and the referenc…

---

## [Memory issues (long running instances)](https://discuss.elastic.co/t/memory-issues-long-running-instances/215136)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 0\
**Last updated:** [January 15, 2020, 1:08pm UTC](https://discuss.elastic.co/t/memory-issues-long-running-instances/215136 "2020-01-15T13:08:48Z")

</div>

Hi, I've a lot of Filebeat instances (v7.2.1) running on separate containers and noticed that longer an instance is running, the more memory (RSS) it uses. While a restart helps and the memory usage drops (e.g., from 38…

---

## [Auditbeat only sending metrics, not events](https://discuss.elastic.co/t/auditbeat-only-sending-metrics-not-events/215121)

<div class="topic-metadata">

**Author:** [@blastic](https://discuss.elastic.co/u/blastic)\
**Replies:** 0\
**Last updated:** [January 15, 2020, 11:02am UTC](https://discuss.elastic.co/t/auditbeat-only-sending-metrics-not-events/215121 "2020-01-15T11:02:41Z")

</div>

Hello. I'm having the following problems: I'm having machines with Debian 9.11 that run auditd (for managing the audit-rules) and auditbeat (version 7.5.1, for shipping the events off to logstash). Even though the conf…

---

## [About the filebeat input](https://discuss.elastic.co/t/about-the-filebeat-input/215065)

<div class="topic-metadata">

**Author:** [@eunnam](https://discuss.elastic.co/u/eunnam)\
**Replies:** 0\
**Last updated:** [January 15, 2020, 2:36am UTC](https://discuss.elastic.co/t/about-the-filebeat-input/215065 "2020-01-15T02:36:55Z")

</div>

Hello i'm using filebeat in aws ec2 and filebeat input type is s3. filebeat.inputs: - type: s3 queue\_url: "aws sqs queue url" If aws sqs queue is received message of aws s3 create, filebeat get file of gz format usi…

---

## [\[bug report\]: filebeat can't finish ,if the log file isn’t ending with line terminator(like \\n)](https://discuss.elastic.co/t/bug-report-filebeat-cant-finish-if-the-log-file-isn-t-ending-with-line-terminator-like-n/214835)

<div class="topic-metadata">

**Author:** [@chenyahui](https://discuss.elastic.co/u/chenyahui)\
**Replies:** 4\
**Last updated:** [January 15, 2020, 2:17am UTC](https://discuss.elastic.co/t/bug-report-filebeat-cant-finish-if-the-log-file-isn-t-ending-with-line-terminator-like-n/214835 "2020-01-15T02:17:11Z")

</div>

if a log file isn’t ending with line terminator(like \\n), the last line can't be read by harvester. the harvester of the file will not finished filebeat version \[7.5\]

---

## [Send filebeat logs through logstash to different indexes](https://discuss.elastic.co/t/send-filebeat-logs-through-logstash-to-different-indexes/214753)

<div class="topic-metadata">

**Author:** [@Immac](https://discuss.elastic.co/u/Immac)\
**Replies:** 4\
**Last updated:** [January 14, 2020, 5:47pm UTC](https://discuss.elastic.co/t/send-filebeat-logs-through-logstash-to-different-indexes/214753 "2020-01-14T17:47:21Z")

</div>

Hi Folks, Besides the standard modules( system, auditd etc), I have to send a custom logs from one server to elasticsearch. I am thinking of sending the logs to logstash first so that I can do some grok processing for …

---

## [Filebeat 7.5 - Suricata module and Elastic cloud ingest pipeline issue](https://discuss.elastic.co/t/filebeat-7-5-suricata-module-and-elastic-cloud-ingest-pipeline-issue/215017)

<div class="topic-metadata">

**Author:** [@flxdan](https://discuss.elastic.co/u/flxdan)\
**Replies:** 0\
**Last updated:** [January 14, 2020, 4:32pm UTC](https://discuss.elastic.co/t/filebeat-7-5-suricata-module-and-elastic-cloud-ingest-pipeline-issue/215017 "2020-01-14T16:32:33Z")

</div>

Running Ubuntu 18.04 running Suricata 5.0.1 - I've tried to use the filebeat (7.5.0 and 7.5.1) Suricata module on Elastic cloud but running setup on filebeat keeps giving me the following error: 2020-01-14T15:25:00.230Z…

---

## [URL category](https://discuss.elastic.co/t/url-category/214983)

<div class="topic-metadata">

**Author:** [@ely\_bainto](https://discuss.elastic.co/u/ely_bainto)\
**Replies:** 0\
**Last updated:** [January 14, 2020, 11:21am UTC](https://discuss.elastic.co/t/url-category/214983 "2020-01-14T11:21:55Z")

</div>

Is there any way to categorize url.domain? (e.g. sports, entertainment, etc.)

---

## [Cisco Module arbitrary parse error with nearly identical messages](https://discuss.elastic.co/t/cisco-module-arbitrary-parse-error-with-nearly-identical-messages/214884)

<div class="topic-metadata">

**Author:** [@arnau\_K](https://discuss.elastic.co/u/arnau_K)\
**Replies:** 2\
**Last updated:** [January 14, 2020, 8:51am UTC](https://discuss.elastic.co/t/cisco-module-arbitrary-parse-error-with-nearly-identical-messages/214884 "2020-01-14T08:51:24Z")

</div>

Hello, I want to use Filebeat to import directly into elasticsearch the logs from a cisco router, these logs were first stored via syslog in an Ubuntu 16.04 server. However, I get this error message in the field error.…

---

## [How to fetch all the fields in decode\_json\_fields instead of specifying all the fields inside](https://discuss.elastic.co/t/how-to-fetch-all-the-fields-in-decode-json-fields-instead-of-specifying-all-the-fields-inside/213447)

<div class="topic-metadata">

**Author:** [@Viswanath\_Lekshman](https://discuss.elastic.co/u/Viswanath_Lekshman)\
**Replies:** 3\
**Last updated:** [January 14, 2020, 8:05am UTC](https://discuss.elastic.co/t/how-to-fetch-all-the-fields-in-decode-json-fields-instead-of-specifying-all-the-fields-inside/213447 "2020-01-14T08:05:28Z")

</div>

When i'm using decode\_json\_fields in Filebeat. I'm unable to specify all fields in a json Below is my sample json {"message":{"name": "Viswanath","cancel":1,"description":"Hey"},"level":"info"} When i use the below co…

---

## [Winlogbeat service won't start - Server 2016](https://discuss.elastic.co/t/winlogbeat-service-wont-start-server-2016/211374)

<div class="topic-metadata">

**Author:** [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Replies:** 9\
**Last updated:** [January 2, 2020, 8:15pm UTC](https://discuss.elastic.co/t/winlogbeat-service-wont-start-server-2016/211374 "2020-01-02T20:15:22Z")

</div>

I'm trying to install winlogbeat on a Server 2016 host but the service won't start. I've tested the config file using: winlogbeat.exe test config and it comes back OK. I've tried running it in the foreground using winlog…

---

## [Multiline codec with Timestamp in between log message](https://discuss.elastic.co/t/multiline-codec-with-timestamp-in-between-log-message/214691)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 4\
**Last updated:** [January 14, 2020, 7:16am UTC](https://discuss.elastic.co/t/multiline-codec-with-timestamp-in-between-log-message/214691 "2020-01-14T07:16:11Z")

</div>

Hi , My Sample looks as follows. ObjMgrBusCompLog Create 4 000010c25c361790:0 2020-01-11 05:58:14 Begin: construct BusComp "Employee" at 18d25dc8 ObjMgrBusCompLog Create 4 000010c25c361790:0 2020-01-11 05:58:1…

---

## [Wrong timestamp (NOT timezone issue) with System module](https://discuss.elastic.co/t/wrong-timestamp-not-timezone-issue-with-system-module/214092)

<div class="topic-metadata">

**Author:** [@thomas.whc](https://discuss.elastic.co/u/thomas.whc)\
**Replies:** 3\
**Last updated:** [January 13, 2020, 10:50pm UTC](https://discuss.elastic.co/t/wrong-timestamp-not-timezone-issue-with-system-module/214092 "2020-01-13T22:50:04Z")

</div>

Hi team and thank you for your work. I am very new to ES and I am trying to build a simple stack with 1 ES, 1 KB and 2 filebeats (launched with binaries) all v7.5. I am not using LogStash but the prepacked modules of Fi…

---

## [Metricbeat to collect metrics from Kerberised Kafka + SSLCa configuration](https://discuss.elastic.co/t/metricbeat-to-collect-metrics-from-kerberised-kafka-sslca-configuration/214491)

<div class="topic-metadata">

**Author:** [@lskaa](https://discuss.elastic.co/u/lskaa)\
**Replies:** 5\
**Last updated:** [January 13, 2020, 9:07pm UTC](https://discuss.elastic.co/t/metricbeat-to-collect-metrics-from-kerberised-kafka-sslca-configuration/214491 "2020-01-13T21:07:40Z")

</div>

Hi All, May I know if anyone has experience to configure Metricbeat to collect metrics from Kerberised Kafka? Here is my kafka.yml. I also add Read and Describe operations to my Kafka instances for a user stats. modu…

---

## [Filbeat with docker compose](https://discuss.elastic.co/t/filbeat-with-docker-compose/214728)

<div class="topic-metadata">

**Author:** [@Haritz\_Saiz](https://discuss.elastic.co/u/Haritz_Saiz)\
**Replies:** 1\
**Last updated:** [January 13, 2020, 6:38pm UTC](https://discuss.elastic.co/t/filbeat-with-docker-compose/214728 "2020-01-13T18:38:14Z")

</div>

Hello everyone I am trying to send the generated logs by cowrie to logstash: Here is my docker compose: version: '3' volumes: cowrie-etc: driver: local cowrie-var: driver: local services: cowrie: con…

---

## [Heartbeat indexing not UTC](https://discuss.elastic.co/t/heartbeat-indexing-not-utc/214706)

<div class="topic-metadata">

**Author:** [@richard\_N](https://discuss.elastic.co/u/richard_N)\
**Replies:** 1\
**Last updated:** [January 13, 2020, 6:18pm UTC](https://discuss.elastic.co/t/heartbeat-indexing-not-utc/214706 "2020-01-13T18:18:22Z")

</div>

Logstash indexes UTC, im +5hours UTC so at 8pm every night a new index is started for the next day. Im also using Grafana which is UTC, after 8 it's looking for the next day pattern but the problem is heartbeat isn't UTC…

---

## [Can i use IAM role as credentials?](https://discuss.elastic.co/t/can-i-use-iam-role-as-credentials/214369)

<div class="topic-metadata">

**Author:** [@Samerd](https://discuss.elastic.co/u/Samerd)\
**Replies:** 1\
**Last updated:** [January 13, 2020, 6:02pm UTC](https://discuss.elastic.co/t/can-i-use-iam-role-as-credentials/214369 "2020-01-13T18:02:34Z")

</div>

Hi , Can we use IAM role instead of AWS credentials (without Access key and Secret Key that we use in metricbeat config file and without AWS token) ? thanks

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=284)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=286)
