# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=286

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 287

---

## [Группировка по полям, значение которых одинаково, но неизвестно](https://discuss.elastic.co/t/topic/214824)

<div class="topic-metadata">

**Author:** [@castorlilasfroid](https://discuss.elastic.co/u/castorlilasfroid)\
**Replies:** 0\
**Last updated:** [January 13, 2020, 12:06pm UTC](https://discuss.elastic.co/t/topic/214824 "2020-01-13T12:06:54Z")

</div>

Добрый день. Использую ELK для просмотра логов Active Directory. В частности - событий авторизации 4624. Но, поскольку при 1 событии авторизации генерируется несколько событий 4624 с одним и тем же winlog.event\_data.Lo…

---

## [Filebeats ILM permission error](https://discuss.elastic.co/t/filebeats-ilm-permission-error/214617)

<div class="topic-metadata">

**Author:** [@trunet](https://discuss.elastic.co/u/trunet)\
**Replies:** 3\
**Last updated:** [January 13, 2020, 10:01am UTC](https://discuss.elastic.co/t/filebeats-ilm-permission-error/214617 "2020-01-13T10:01:30Z")

</div>

Hello, Just finished configuring elasticsearch, filebeat and kibana with SSL, xpack security and ILM. Issue is that after following https://www.elastic.co/guide/en/beats/filebeat/current/feature-roles.html and creating…

---

## [Error while forwarding logs from one machine to another machine](https://discuss.elastic.co/t/error-while-forwarding-logs-from-one-machine-to-another-machine/214734)

<div class="topic-metadata">

**Author:** [@xiaozhoz](https://discuss.elastic.co/u/xiaozhoz)\
**Replies:** 0\
**Last updated:** [January 12, 2020, 4:08pm UTC](https://discuss.elastic.co/t/error-while-forwarding-logs-from-one-machine-to-another-machine/214734 "2020-01-12T16:08:12Z")

</div>

Hi everyone, I want to send docker logs from machine B to machine A but get some errors. Any reply will be appreciated. :grinning: on machine A (IP: 52.80.xx.xx): I set up ELK framework through docker-elk sudo docker…

---

## [Config not working, Injecting all logs](https://discuss.elastic.co/t/config-not-working-injecting-all-logs/214714)

<div class="topic-metadata">

**Author:** [@GuessMyName](https://discuss.elastic.co/u/GuessMyName)\
**Replies:** 0\
**Last updated:** [January 11, 2020, 10:18pm UTC](https://discuss.elastic.co/t/config-not-working-injecting-all-logs/214714 "2020-01-11T22:18:01Z")

</div>

Hi Guys, For some reason... Winlogbeat is grabbing all security logs not just the one listed below, any idea what I'm missing ?, Running 7.5.1 Thx! winlogbeat.event\_logs: name: Security processors: drop\_event.whe…

---

## [Filebeat.autodiscover seems to cause terraform/kubernetes based deploy issues](https://discuss.elastic.co/t/filebeat-autodiscover-seems-to-cause-terraform-kubernetes-based-deploy-issues/214667)

<div class="topic-metadata">

**Author:** [@cgutshall](https://discuss.elastic.co/u/cgutshall)\
**Replies:** 0\
**Last updated:** [January 10, 2020, 9:02pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-seems-to-cause-terraform-kubernetes-based-deploy-issues/214667 "2020-01-10T21:02:12Z")

</div>

I wrote up a yml based deploy to handle added a filebeat pod to each node in our EKS Cluster. When deploying the following config the pods are up and running with logs getting sent to elasticsearch. However I went to …

---

## [Is there a way to merge data collected from APM and Packetbeat](https://discuss.elastic.co/t/is-there-a-way-to-merge-data-collected-from-apm-and-packetbeat/214656)

<div class="topic-metadata">

**Author:** [@Kartheek\_Mannepalli](https://discuss.elastic.co/u/Kartheek_Mannepalli)\
**Replies:** 0\
**Last updated:** [January 10, 2020, 7:32pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-merge-data-collected-from-apm-and-packetbeat/214656 "2020-01-10T19:32:15Z")

</div>

If a transaction took longer our goal is to find out which step caused the slowness. Thanks to APM and RUM we have a good view of DB and http requests in the timeline view but it does not show any network related informa…

---

## [Omit non-json lines in log files while still allowing json parsing](https://discuss.elastic.co/t/omit-non-json-lines-in-log-files-while-still-allowing-json-parsing/214319)

<div class="topic-metadata">

**Author:** [@Gregory\_Zimmers](https://discuss.elastic.co/u/Gregory_Zimmers)\
**Replies:** 2\
**Last updated:** [January 10, 2020, 7:16pm UTC](https://discuss.elastic.co/t/omit-non-json-lines-in-log-files-while-still-allowing-json-parsing/214319 "2020-01-10T19:16:32Z")

</div>

I've found that I'm only able to apply \['^{'\] this pattern to include\_lines when I omit json parsing from the yml. After reading the documentation, it implies the line\_filtering is done after parsing, so if that's the ca…

---

## [Multiple container in single filebeat.autodiscover](https://discuss.elastic.co/t/multiple-container-in-single-filebeat-autodiscover/214646)

<div class="topic-metadata">

**Author:** [@rguptarg](https://discuss.elastic.co/u/rguptarg)\
**Replies:** 0\
**Last updated:** [January 10, 2020, 5:52pm UTC](https://discuss.elastic.co/t/multiple-container-in-single-filebeat-autodiscover/214646 "2020-01-10T17:52:45Z")

</div>

HI, I have configured filebeat.autodiscover for docker container log analysis, I have 8 docker containers and I want to add few containers in filebeat, below code is working fine for one image , filebeat.autodiscover: …

---

## [Filebeat failed to start: Exiting: error loading config file: yaml: line 31: did not find expected key](https://discuss.elastic.co/t/filebeat-failed-to-start-exiting-error-loading-config-file-yaml-line-31-did-not-find-expected-key/214632)

<div class="topic-metadata">

**Author:** [@lucc](https://discuss.elastic.co/u/lucc)\
**Replies:** 0\
**Last updated:** [January 10, 2020, 4:21pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-start-exiting-error-loading-config-file-yaml-line-31-did-not-find-expected-key/214632 "2020-01-10T16:21:06Z")

</div>

hi, I have an issue to start filebeat...Error message is: failed to start: Exiting: error loading config file: yaml: line 31: did not find expected key filebeat version 7.5.1 (amd64), libbeat 7.5.1 yml file below Tha…

---

## [Exceptions in filebeat logs](https://discuss.elastic.co/t/exceptions-in-filebeat-logs/214589)

<div class="topic-metadata">

**Author:** [@emilio](https://discuss.elastic.co/u/emilio)\
**Replies:** 0\
**Last updated:** [January 10, 2020, 10:53am UTC](https://discuss.elastic.co/t/exceptions-in-filebeat-logs/214589 "2020-01-10T10:53:49Z")

</div>

Dear all, What is wrong with filebeat version 7.4.2 config? ######################## Filebeat Configuration ############################ #========================== Modules configuration ============================= …

---

## [Error in fetching the logs Filebeat 7.3.2](https://discuss.elastic.co/t/error-in-fetching-the-logs-filebeat-7-3-2/214168)

<div class="topic-metadata">

**Author:** [@Anwesha\_Pokra](https://discuss.elastic.co/u/Anwesha_Pokra)\
**Replies:** 4\
**Last updated:** [January 10, 2020, 10:13am UTC](https://discuss.elastic.co/t/error-in-fetching-the-logs-filebeat-7-3-2/214168 "2020-01-10T10:13:11Z")

</div>

Hi, I am trying to pass the pod logs to elasticsearch using filebeat, but logs are not appearing in the filebeat pod log. I am deploying the filebeat as kubernetes pod. kubernetes version - 1.12.7 docker version - 1.1…

---

## [Can't get logs from some pods](https://discuss.elastic.co/t/cant-get-logs-from-some-pods/214570)

<div class="topic-metadata">

**Author:** [@ilanssari](https://discuss.elastic.co/u/ilanssari)\
**Replies:** 0\
**Last updated:** [January 10, 2020, 9:10am UTC](https://discuss.elastic.co/t/cant-get-logs-from-some-pods/214570 "2020-01-10T09:10:06Z")

</div>

Hello dear community. I have an issue that i can't get logs of some pods on our Kubernetes cluster, here is how we collect logs : filebeat -\> logstash -\> elasticsearch filebeat is deployed on each node on the cluster …

---

## [Using the Vault to store the credentials/secrets of beats](https://discuss.elastic.co/t/using-the-vault-to-store-the-credentials-secrets-of-beats/214531)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 0\
**Last updated:** [January 10, 2020, 5:18am UTC](https://discuss.elastic.co/t/using-the-vault-to-store-the-credentials-secrets-of-beats/214531 "2020-01-10T05:18:27Z")

</div>

Would like to know whether the beats secrets can be stored in Vault. I know about the supported keystore approach, (https://www.elastic.co/guide/en/beats/filebeat/current/keystore.html), but would like to know whether b…

---

## [Docker logs are not coming](https://discuss.elastic.co/t/docker-logs-are-not-coming/214436)

<div class="topic-metadata">

**Author:** [@rguptarg](https://discuss.elastic.co/u/rguptarg)\
**Replies:** 2\
**Last updated:** [January 10, 2020, 5:16am UTC](https://discuss.elastic.co/t/docker-logs-are-not-coming/214436 "2020-01-10T05:16:16Z")

</div>

Hi Team, I am trying to configure Docker logs forwarding to ELK through filebeat. I have followed (https://www.elastic.co/blog/enrich-docker-logs-with-filebeat). I can see docker logs on kibana but without log message …

---

## [Kibana can not show all the filebeat](https://discuss.elastic.co/t/kibana-can-not-show-all-the-filebeat/214410)

<div class="topic-metadata">

**Author:** [@kael](https://discuss.elastic.co/u/kael)\
**Replies:** 2\
**Last updated:** [January 10, 2020, 3:22am UTC](https://discuss.elastic.co/t/kibana-can-not-show-all-the-filebeat/214410 "2020-01-10T03:22:24Z")

</div>

i start five filebeat instances use different yml on one host，and different name,and set xpack.monitoring.enabled: true,but in Kibana Monitoring,i just saw one filebeat instance,is this a bug? if not,how i can do?i use e…

---

## [Filebeat unable to parse date with timezone](https://discuss.elastic.co/t/filebeat-unable-to-parse-date-with-timezone/214498)

<div class="topic-metadata">

**Author:** [@harddaynight](https://discuss.elastic.co/u/harddaynight)\
**Replies:** 0\
**Last updated:** [January 9, 2020, 9:52pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-parse-date-with-timezone/214498 "2020-01-09T21:52:08Z")

</div>

Hello Elastic Team, Can you, please, help me to find out why my filebeat can't parse a date with timezone properly? Sample of data: {"date": "2020-01-07 05:00:00+03:00", some other JSON fields} The message I get in l…

---

## [About the Filebeat type: docker](https://discuss.elastic.co/t/about-the-filebeat-type-docker/213868)

<div class="topic-metadata">

**Author:** [@BoboZheng](https://discuss.elastic.co/u/BoboZheng)\
**Replies:** 1\
**Last updated:** [January 9, 2020, 8:17pm UTC](https://discuss.elastic.co/t/about-the-filebeat-type-docker/213868 "2020-01-09T20:17:19Z")

</div>

Hi, I have a question about filebeat.yml. I want to match the specified pod\_name, but processors.add\_kubernetes\_metadata only match namespace. this is my setting: metadata: name: filebeat-inputs namespace: elk data: …

---

## [Custom Module Config](https://discuss.elastic.co/t/custom-module-config/214003)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [January 9, 2020, 6:17pm UTC](https://discuss.elastic.co/t/custom-module-config/214003 "2020-01-09T18:17:47Z")

</div>

Hi, Each filebeat module comes with a default prospector config. How are we meant to customise/extend it without editing the config files under /usr/share/filebeat/module? Thx D

---

## [Using auditd along with auditbeat](https://discuss.elastic.co/t/using-auditd-along-with-auditbeat/214342)

<div class="topic-metadata">

**Author:** [@akki2208](https://discuss.elastic.co/u/akki2208)\
**Replies:** 1\
**Last updated:** [January 9, 2020, 4:25pm UTC](https://discuss.elastic.co/t/using-auditd-along-with-auditbeat/214342 "2020-01-09T16:25:01Z")

</div>

I want to run audit beat along with auditd. is there any option? or can we write auditbeat logs in some file?

---

## [Filebeat for Greenplum: Module or Fileset?](https://discuss.elastic.co/t/filebeat-for-greenplum-module-or-fileset/214463)

<div class="topic-metadata">

**Author:** [@seaseao](https://discuss.elastic.co/u/seaseao)\
**Replies:** 0\
**Last updated:** [January 9, 2020, 4:20pm UTC](https://discuss.elastic.co/t/filebeat-for-greenplum-module-or-fileset/214463 "2020-01-09T16:20:59Z")

</div>

Hi Everyone, I am going to develop an extension of Filebeat to read Greenplum logs. I am debating whether I want to make it as a new module, or as new filesets of the Postgresql module. I would love to hear the opinions…

---

## [Winlogbeat don't collect some event](https://discuss.elastic.co/t/winlogbeat-dont-collect-some-event/213584)

<div class="topic-metadata">

**Author:** [@ghl1l0](https://discuss.elastic.co/u/ghl1l0)\
**Replies:** 3\
**Last updated:** [January 9, 2020, 3:55pm UTC](https://discuss.elastic.co/t/winlogbeat-dont-collect-some-event/213584 "2020-01-09T15:55:11Z")

</div>

I had install winlogbeat in windows 10 until now i received all log include secrutiy application ... except "Security Group Management" log

---

## [System module - packages error](https://discuss.elastic.co/t/system-module-packages-error/214448)

<div class="topic-metadata">

**Author:** [@samoz83](https://discuss.elastic.co/u/samoz83)\
**Replies:** 0\
**Last updated:** [January 9, 2020, 2:46pm UTC](https://discuss.elastic.co/t/system-module-packages-error/214448 "2020-01-09T14:46:37Z")

</div>

Seem to be getting the below error from the packages module on our 18.04 machines meaning we get no stats on packages installed etc. failed to get packages: error getting DEB packages: error converting 25G to int: strco…

---

## [Metricbeat - "Beats" under Stack Monitoring missing](https://discuss.elastic.co/t/metricbeat-beats-under-stack-monitoring-missing/214390)

<div class="topic-metadata">

**Author:** [@RoNo](https://discuss.elastic.co/u/RoNo)\
**Replies:** 0\
**Last updated:** [January 9, 2020, 9:31am UTC](https://discuss.elastic.co/t/metricbeat-beats-under-stack-monitoring-missing/214390 "2020-01-09T09:31:40Z")

</div>

Hello. I am trying to setup metricbeats in my ELKStack setup atm. And I am currently only trying to use the Beat's module to monitor my filebeat/auditbeat/journalbeat etc.. How ever after successfully deployed it I am…

---

## [How to setup Hyper V with winlogbeat](https://discuss.elastic.co/t/how-to-setup-hyper-v-with-winlogbeat/212807)

<div class="topic-metadata">

**Author:** [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)\
**Replies:** 2\
**Last updated:** [January 9, 2020, 9:19am UTC](https://discuss.elastic.co/t/how-to-setup-hyper-v-with-winlogbeat/212807 "2020-01-09T09:19:57Z")

</div>

Hey, I want to monitor hyper v events using winlogbeat. How to do that, can someone please help. Thanks, Tahseen.

---

## [Check database availability](https://discuss.elastic.co/t/check-database-availability/213835)

<div class="topic-metadata">

**Author:** [@radd](https://discuss.elastic.co/u/radd)\
**Replies:** 6\
**Last updated:** [January 9, 2020, 8:00am UTC](https://discuss.elastic.co/t/check-database-availability/213835 "2020-01-09T08:00:46Z")

</div>

Hi, I am new in ELK and I have one question regarding monitoring oracle DB availability. Please advice me, because I wish, with your help and knowledge, to find the best solution. I have read that I can monitor for Or…

---

## [Date parser using ingest node](https://discuss.elastic.co/t/date-parser-using-ingest-node/214341)

<div class="topic-metadata">

**Author:** [@Praveen\_V](https://discuss.elastic.co/u/Praveen_V)\
**Replies:** 0\
**Last updated:** [January 9, 2020, 4:45am UTC](https://discuss.elastic.co/t/date-parser-using-ingest-node/214341 "2020-01-09T04:45:42Z")

</div>

Hi All - Am trying to chop a message and convert the string to Date using Ingest node , however able to get the date string from the message .. but the format is string in Elastic. Any help here would be much appreciate…

---

## [Create a new index everyday with filebeat](https://discuss.elastic.co/t/create-a-new-index-everyday-with-filebeat/214163)

<div class="topic-metadata">

**Author:** [@darshanky](https://discuss.elastic.co/u/darshanky)\
**Replies:** 2\
**Last updated:** [January 8, 2020, 11:44pm UTC](https://discuss.elastic.co/t/create-a-new-index-everyday-with-filebeat/214163 "2020-01-08T23:44:48Z")

</div>

Hello Folks, I am new to Elasticstack and trying to get my hear around. I have setup the single node elastic stack which runs the Kibana as well. I have a client that has file beat installed and sends logs to elasticse…

---

## [Filebeat logstash module not working with json processor](https://discuss.elastic.co/t/filebeat-logstash-module-not-working-with-json-processor/213728)

<div class="topic-metadata">

**Author:** [@lorenzopolidori](https://discuss.elastic.co/u/lorenzopolidori)\
**Replies:** 2\
**Last updated:** [January 8, 2020, 9:54pm UTC](https://discuss.elastic.co/t/filebeat-logstash-module-not-working-with-json-processor/213728 "2020-01-08T21:54:39Z")

</div>

Hi, I am trying to send logs with Filebeat 7.5.1 from an EC2 Ubuntu instance to cloud Elasticsearch. The log file is /var/log/logback/oauth-service.log, in the following logstash format: {"@timestamp":"2020-01-02T16:…

---

## [Scaling filebeat over containers](https://discuss.elastic.co/t/scaling-filebeat-over-containers/213772)

<div class="topic-metadata">

**Author:** [@fizem](https://discuss.elastic.co/u/fizem)\
**Replies:** 1\
**Last updated:** [January 8, 2020, 8:56pm UTC](https://discuss.elastic.co/t/scaling-filebeat-over-containers/213772 "2020-01-08T20:56:11Z")

</div>

Hi, I’m looking for the appropriate way to monitor applicative logs produced nginx, tomcat, springboot embedded in docker with filebeat and ELK. In the container strategy, a container should be use for only one purpose …

---

## [Filebeat log folder is not created anymore](https://discuss.elastic.co/t/filebeat-log-folder-is-not-created-anymore/214269)

<div class="topic-metadata">

**Author:** [@Flaviu](https://discuss.elastic.co/u/Flaviu)\
**Replies:** 1\
**Last updated:** [January 8, 2020, 4:43pm UTC](https://discuss.elastic.co/t/filebeat-log-folder-is-not-created-anymore/214269 "2020-01-08T16:43:26Z")

</div>

I have installed filebeat 7.5.1 on a new server, and I realized that the folder in which I want filebeat to save his own logs is not created anymore. This was working in the previous version. I am doing something wrong o…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=285)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=287)
