# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=287

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 288

---

## [Cannot see data from Metricbeat data in ELK](https://discuss.elastic.co/t/cannot-see-data-from-metricbeat-data-in-elk/214037)

<div class="topic-metadata">

**Author:** [@Henry\_Navarro](https://discuss.elastic.co/u/Henry_Navarro)\
**Replies:** 1\
**Last updated:** [January 8, 2020, 3:26pm UTC](https://discuss.elastic.co/t/cannot-see-data-from-metricbeat-data-in-elk/214037 "2020-01-08T15:26:32Z")

</div>

Hi everyone, I am having the I saw a similar question in this link. But I cannot understand the solution and the topic is currently closed. It seems metricbeat is working but I cannot see the data in ELK. I did what j…

---

## [Trouble debugging MetricBeat connection issues](https://discuss.elastic.co/t/trouble-debugging-metricbeat-connection-issues/212931)

<div class="topic-metadata">

**Author:** [@Christiaan](https://discuss.elastic.co/u/Christiaan)\
**Replies:** 2\
**Last updated:** [January 8, 2020, 12:52pm UTC](https://discuss.elastic.co/t/trouble-debugging-metricbeat-connection-issues/212931 "2020-01-08T12:52:51Z")

</div>

Hi all, I'm running an ECK on a Kubernetes cluster and am using FileBeat and MetricBeat to send monitoring information to Elastic. For the most part, things are running smoothly, except for the MetricBeat Deployment, w…

---

## [Sending Log4j logs(in XML format) to Elasticsearch using Filebeat](https://discuss.elastic.co/t/sending-log4j-logs-in-xml-format-to-elasticsearch-using-filebeat/214199)

<div class="topic-metadata">

**Author:** [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Replies:** 1\
**Last updated:** [January 8, 2020, 11:15am UTC](https://discuss.elastic.co/t/sending-log4j-logs-in-xml-format-to-elasticsearch-using-filebeat/214199 "2020-01-08T11:15:29Z")

</div>

Hello, I need to send log files generated using Log4j on client machines to Elasticsearch installed on a server. I'm using Filebeat, but not Logstash. Is there any other plugin, etc required, or can it just be done usi…

---

## [Filebeat to logstash: Failed to publish events caused by: read tcp 192.168.155.177:55376-\>47.102.46.68:5045:wsarecv:An existing connection was forcibly closed by the remote host](https://discuss.elastic.co/t/filebeat-to-logstash-failed-to-publish-events-caused-by-read-tcp-192-168-155-177-55376-47-102-46-68wsarecv-an-existing-connection-was-forcibly-closed-by-the-remote-host/213657)

<div class="topic-metadata">

**Author:** [@cheninnocent](https://discuss.elastic.co/u/cheninnocent)\
**Replies:** 6\
**Last updated:** [January 8, 2020, 8:03am UTC](https://discuss.elastic.co/t/filebeat-to-logstash-failed-to-publish-events-caused-by-read-tcp-192-168-155-177-55376-47-102-46-68wsarecv-an-existing-connection-was-forcibly-closed-by-the-remote-host/213657 "2020-01-08T08:03:29Z")

</div>

As I said above, the above bug appears on several computers, but is normal on others. Even logstash only have input and output. The above bug still appears on several computers.

---

## [Packet Beat error : You don't have permission to capture on that device](https://discuss.elastic.co/t/packet-beat-error-you-dont-have-permission-to-capture-on-that-device/213587)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 0\
**Last updated:** [January 2, 2020, 2:29pm UTC](https://discuss.elastic.co/t/packet-beat-error-you-dont-have-permission-to-capture-on-that-device/213587 "2020-01-02T14:29:52Z")

</div>

Hi, i'm using elastic stack of version 7.5.1 with x-pack installed and can't able to run packetbeat and i'm getting the following error : Please help me solve it. Exiting: Sniffer main loop failed: Error starting snif…

---

## [Bug with filebeat inlucde\_lines?](https://discuss.elastic.co/t/bug-with-filebeat-inlucde-lines/214138)

<div class="topic-metadata">

**Author:** [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Replies:** 1\
**Last updated:** [January 7, 2020, 10:13pm UTC](https://discuss.elastic.co/t/bug-with-filebeat-inlucde-lines/214138 "2020-01-07T22:13:45Z")

</div>

Hello, I have been trying to use the include\_lines option in the filebeat.yml file to read a SQL Server log file. Note that I am not using the mssql module of FileBeat; I just have an input of type log and point it to …

---

## [Unable to view Analytics and API Logs : Is Filebeat running well?](https://discuss.elastic.co/t/unable-to-view-analytics-and-api-logs-is-filebeat-running-well/214075)

<div class="topic-metadata">

**Author:** [@The-Big-K](https://discuss.elastic.co/u/The-Big-K)\
**Replies:** 1\
**Last updated:** [January 7, 2020, 4:09pm UTC](https://discuss.elastic.co/t/unable-to-view-analytics-and-api-logs-is-filebeat-running-well/214075 "2020-01-07T16:09:05Z")

</div>

Very new to ES ecosystem and enjoying the learning process. I've got ES and App-Search (Self-Hosted) running on Ubuntu. The only problem now is that I cannot see API logs and Analytics in my app-search dashboard. Apparan…

---

## [Metricbeat don't collect kubernetes volume metrics anymore](https://discuss.elastic.co/t/metricbeat-dont-collect-kubernetes-volume-metrics-anymore/214094)

<div class="topic-metadata">

**Author:** [@Chaya56](https://discuss.elastic.co/u/Chaya56)\
**Replies:** 0\
**Last updated:** [January 7, 2020, 3:51pm UTC](https://discuss.elastic.co/t/metricbeat-dont-collect-kubernetes-volume-metrics-anymore/214094 "2020-01-07T15:51:34Z")

</div>

Hello, I'm currently using Metricbeat to collect data from kubernetes volumes. It's a managed kubernetes hosted by OVH. it was working great until they installed a new standalone version of their plugin: cinder.csi.ope…

---

## [Minikube not adding add\_kubernetes\_metadata](https://discuss.elastic.co/t/minikube-not-adding-add-kubernetes-metadata/214046)

<div class="topic-metadata">

**Author:** [@vaclav](https://discuss.elastic.co/u/vaclav)\
**Replies:** 0\
**Last updated:** [January 7, 2020, 12:15pm UTC](https://discuss.elastic.co/t/minikube-not-adding-add-kubernetes-metadata/214046 "2020-01-07T12:15:03Z")

</div>

Hello, I am trying to run auditbeat on minikube, but kubernetes metadata are not added to events. Do you please know what should be correct configuration ? here is my config: --- apiVersion: v1 kind: ConfigMap metada…

---

## [Monitiring elasticsearch cluster](https://discuss.elastic.co/t/monitiring-elasticsearch-cluster/213992)

<div class="topic-metadata">

**Author:** [@kiran\_kumar1](https://discuss.elastic.co/u/kiran_kumar1)\
**Replies:** 2\
**Last updated:** [January 7, 2020, 9:21am UTC](https://discuss.elastic.co/t/monitiring-elasticsearch-cluster/213992 "2020-01-07T09:21:09Z")

</div>

HI Team, Getting below issue while conncting from monitoring cluster to production cluster by using metricbeat. issue:more than one namespace configured accessing config,could you please suggest on this. Thank you Ki…

---

## [Issues pushing kubernetes ingress-nginx logs using filebeat deamonset pods](https://discuss.elastic.co/t/issues-pushing-kubernetes-ingress-nginx-logs-using-filebeat-deamonset-pods/206923)

<div class="topic-metadata">

**Author:** [@Siva\_Krishna](https://discuss.elastic.co/u/Siva_Krishna)\
**Replies:** 19\
**Last updated:** [January 7, 2020, 8:40am UTC](https://discuss.elastic.co/t/issues-pushing-kubernetes-ingress-nginx-logs-using-filebeat-deamonset-pods/206923 "2020-01-07T08:40:23Z")

</div>

Hello all, We're facing issues pushing kubernetes ingress-nginx logs using filebeat deamonset pods. using filebeat v6.2.4, 6.3.0, & 6.4.0. please let us know if this is the correct configs to push only ingress-nginx p…

---

## [Exclude part of kubernetes log](https://discuss.elastic.co/t/exclude-part-of-kubernetes-log/213348)

<div class="topic-metadata">

**Author:** [@markrity](https://discuss.elastic.co/u/markrity)\
**Replies:** 3\
**Last updated:** [January 6, 2020, 7:29pm UTC](https://discuss.elastic.co/t/exclude-part-of-kubernetes-log/213348 "2020-01-06T19:29:36Z")

</div>

I'm trying to make Filebeat to exclude part of the whole log that being sent to Logstash through filebeat config xml file. I have log like this: { "@timestamp" : "timestamp" , "name" : "general" , …

---

## [Can't get filebeats to produce any info from redis or postgres](https://discuss.elastic.co/t/cant-get-filebeats-to-produce-any-info-from-redis-or-postgres/213582)

<div class="topic-metadata">

**Author:** [@aleksas](https://discuss.elastic.co/u/aleksas)\
**Replies:** 1\
**Last updated:** [January 6, 2020, 12:43pm UTC](https://discuss.elastic.co/t/cant-get-filebeats-to-produce-any-info-from-redis-or-postgres/213582 "2020-01-06T12:43:39Z")

</div>

Using helm-charts to configure sandbox cluster monitoring. Managed to configure metribeats for redis and postgres, but struggling to do same with filebeats. kibana show almost (2) no documents in filebeat-\* index. Nei…

---

## [Auditbeat permission Error](https://discuss.elastic.co/t/auditbeat-permission-error/213318)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 3\
**Last updated:** [January 6, 2020, 12:14pm UTC](https://discuss.elastic.co/t/auditbeat-permission-error/213318 "2020-01-06T12:14:54Z")

</div>

Hi, i'm using elk stack 7.1.1 with x-pack installed and i'm trying to setup auditbeat but i am getting the following error: 2019-12-30T13:18:04.176+0530 ERROR instance/beat.go:802 Exiting: 1 error: 1 error: failed to cr…

---

## [Is it possible to include separate processor config files from sub dir](https://discuss.elastic.co/t/is-it-possible-to-include-separate-processor-config-files-from-sub-dir/213871)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 0\
**Last updated:** [January 6, 2020, 10:04am UTC](https://discuss.elastic.co/t/is-it-possible-to-include-separate-processor-config-files-from-sub-dir/213871 "2020-01-06T10:04:37Z")

</div>

Wondering if might be possible to define winlogbeat processors in separate YML files to be included by the main config file thus to ease maintenance through automation tools?

---

## [Pipeline - grok - truncating at "\\n" in \[multiline\] message from filebeat](https://discuss.elastic.co/t/pipeline-grok-truncating-at-n-in-multiline-message-from-filebeat/211800)

<div class="topic-metadata">

**Author:** [@nigel.piggott](https://discuss.elastic.co/u/nigel.piggott)\
**Replies:** 6\
**Last updated:** [January 6, 2020, 8:47am UTC](https://discuss.elastic.co/t/pipeline-grok-truncating-at-n-in-multiline-message-from-filebeat/211800 "2020-01-06T08:47:39Z")

</div>

Filebeat is configured to correctly process a mutline file Using the ingest pipeline the grok processor extracts fields from the "message" However it is truncating the message when the message contains the regex "\\n" …

---

## [Filebeat config to read logs using docker](https://discuss.elastic.co/t/filebeat-config-to-read-logs-using-docker/213672)

<div class="topic-metadata">

**Author:** [@Praveen\_V](https://discuss.elastic.co/u/Praveen_V)\
**Replies:** 2\
**Last updated:** [January 6, 2020, 6:50am UTC](https://discuss.elastic.co/t/filebeat-config-to-read-logs-using-docker/213672 "2020-01-06T06:50:18Z")

</div>

Am able to run the filebeat via docker , however the output says log is taken.. i dont see any data in elastic , any suggestions would be helpful. thanks Command User ocker run --rm --name filebeat --volume="/usr/sh…

---

## [Kubernetes: collecting allocate resource percentages for nodes](https://discuss.elastic.co/t/kubernetes-collecting-allocate-resource-percentages-for-nodes/213817)

<div class="topic-metadata">

**Author:** [@collinwright](https://discuss.elastic.co/u/collinwright)\
**Replies:** 0\
**Last updated:** [January 5, 2020, 6:28pm UTC](https://discuss.elastic.co/t/kubernetes-collecting-allocate-resource-percentages-for-nodes/213817 "2020-01-05T18:28:34Z")

</div>

I'm interested in using Metricbeat to monitor the resources Kubernetes has allocated (but may not necessarily be using) on each node. These numbers can be seen, for example, by running "kubectl describe node": ... Alloc…

---

## [Filebeat is always read file from beginning](https://discuss.elastic.co/t/filebeat-is-always-read-file-from-beginning/213563)

<div class="topic-metadata">

**Author:** [@rguptarg](https://discuss.elastic.co/u/rguptarg)\
**Replies:** 1\
**Last updated:** [January 4, 2020, 12:11pm UTC](https://discuss.elastic.co/t/filebeat-is-always-read-file-from-beginning/213563 "2020-01-04T12:11:51Z")

</div>

HI Team, I am using filebeat-7.3.2-1.x86\_64 for application log reading. but all the time filebeat read log from starting, hence duplicate data is present in elastic please suggest what configuration required?

---

## [Setting host.hostname mapping to static](https://discuss.elastic.co/t/setting-host-hostname-mapping-to-static/213224)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 4\
**Last updated:** [January 3, 2020, 6:52pm UTC](https://discuss.elastic.co/t/setting-host-hostname-mapping-to-static/213224 "2020-01-03T18:52:35Z")

</div>

ECE 2.3 Metricbeat 7.0.0 & 7.5.0 I need some guidance on how to stop the dynamic templating for host.hostname of our metricbeats. We've got a third party product that can only read data from the host.hostname field i…

---

## [Problem with ansible-beats and processors config](https://discuss.elastic.co/t/problem-with-ansible-beats-and-processors-config/213690)

<div class="topic-metadata">

**Author:** [@blabu23](https://discuss.elastic.co/u/blabu23)\
**Replies:** 3\
**Last updated:** [January 3, 2020, 5:05pm UTC](https://discuss.elastic.co/t/problem-with-ansible-beats-and-processors-config/213690 "2020-01-03T17:05:59Z")

</div>

Hi there! I am trying to install/configure filebeat with the ansible role from elastic. My playbook looks like this: - hosts: filebeat\_hosts roles: - role: role-beats vars: use\_repository: true beats\_ve…

---

## [Can't parse event as syslog rfc3164](https://discuss.elastic.co/t/cant-parse-event-as-syslog-rfc3164/212182)

<div class="topic-metadata">

**Author:** [@vipin.suthar](https://discuss.elastic.co/u/vipin.suthar)\
**Replies:** 1\
**Last updated:** [January 3, 2020, 11:11am UTC](https://discuss.elastic.co/t/cant-parse-event-as-syslog-rfc3164/212182 "2020-01-03T11:11:06Z")

</div>

Hello, We are facing a known issue with syslog input of filebeat, And running our Elasticsearch cluster on CentOS Linux release 7.7.1908 (Core) VM environment. We are working with Cisco ASA and FTD firewall logs, But o…

---

## [How packetbeat determine source and destination in TCP flow?](https://discuss.elastic.co/t/how-packetbeat-determine-source-and-destination-in-tcp-flow/212313)

<div class="topic-metadata">

**Author:** [@jaypark81](https://discuss.elastic.co/u/jaypark81)\
**Replies:** 2\
**Last updated:** [January 3, 2020, 6:35am UTC](https://discuss.elastic.co/t/how-packetbeat-determine-source-and-destination-in-tcp-flow/212313 "2020-01-03T06:35:00Z")

</div>

Hi, I'm investigating network flows. And Packetbeat collect network traffic including forwarding. I found some flow's destination is port 80 for http. Otherwise, some flows source port is port 80. I'm very sure the p…

---

## [How to ignore bookmark(.winlogbeat.yml) when start the winlogbeat?](https://discuss.elastic.co/t/how-to-ignore-bookmark-winlogbeat-yml-when-start-the-winlogbeat/212787)

<div class="topic-metadata">

**Author:** [@e997cd7e8d9915436150](https://discuss.elastic.co/u/e997cd7e8d9915436150)\
**Replies:** 2\
**Last updated:** [January 3, 2020, 4:41am UTC](https://discuss.elastic.co/t/how-to-ignore-bookmark-winlogbeat-yml-when-start-the-winlogbeat/212787 "2020-01-03T04:41:34Z")

</div>

Quick question. How can I play one event log on repeat or loop? How to ignore bookmark when start the winlogbeat? And can i auto restart the winlogbeat when changed the winlogbeat.yml? Thanks.:slight\_smile:

---

## [Processor in cascade](https://discuss.elastic.co/t/processor-in-cascade/210971)

<div class="topic-metadata">

**Author:** [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Replies:** 1\
**Last updated:** [January 3, 2020, 3:36am UTC](https://discuss.elastic.co/t/processor-in-cascade/210971 "2020-01-03T03:36:33Z")

</div>

Hi all I think to use processor, I'd like to know if it possible to do this processors: - add\_filed: fields: name: "pippo","pluto","paperino" processors: - if: contains: name: "pluto" then: …

---

## [Winlog beat data issue](https://discuss.elastic.co/t/winlog-beat-data-issue/212385)

<div class="topic-metadata">

**Author:** [@mparp](https://discuss.elastic.co/u/mparp)\
**Replies:** 1\
**Last updated:** [January 3, 2020, 3:07am UTC](https://discuss.elastic.co/t/winlog-beat-data-issue/212385 "2020-01-03T03:07:14Z")

</div>

How many beats (winlog) I can connect after Trail License expired ? The problem is I dont see events from newly configured beats starting from moment when license has expired. Is my issue related to license or I am doi…

---

## [Which is more efficient, sequence or "or"?](https://discuss.elastic.co/t/which-is-more-efficient-sequence-or-or/213640)

<div class="topic-metadata">

**Author:** [@barely47](https://discuss.elastic.co/u/barely47)\
**Replies:** 0\
**Last updated:** [January 3, 2020, 1:02am UTC](https://discuss.elastic.co/t/which-is-more-efficient-sequence-or-or/213640 "2020-01-03T01:02:34Z")

</div>

\- drop\_event: when: or: \[{equals: {process.executable: /bin/date}}, {equals: {process.executable: /bin/df}}, {equals: {process.executable: /bin/dmesg}}\] or - drop\_event: equals: {process.executabl…

---

## [Kubernetes autodiscover not working](https://discuss.elastic.co/t/kubernetes-autodiscover-not-working/213630)

<div class="topic-metadata">

**Author:** [@kluvi](https://discuss.elastic.co/u/kluvi)\
**Replies:** 0\
**Last updated:** [January 2, 2020, 9:37pm UTC](https://discuss.elastic.co/t/kubernetes-autodiscover-not-working/213630 "2020-01-02T21:37:22Z")

</div>

Hi. I have one Pod with running Heartbeat in our K8s cluster and tried to setup autodiscovery, but without any success... kluvi@kluvi:~$ k log -f deployment/service-monitoring-heartbeat-autodiscover log is DEPRECATED a…

---

## [7.5.1 Filebeat container still creating "Standalone Cluster"](https://discuss.elastic.co/t/7-5-1-filebeat-container-still-creating-standalone-cluster/213366)

<div class="topic-metadata">

**Author:** [@daniel.onit](https://discuss.elastic.co/u/daniel.onit)\
**Replies:** 2\
**Last updated:** [January 2, 2020, 8:55pm UTC](https://discuss.elastic.co/t/7-5-1-filebeat-container-still-creating-standalone-cluster/213366 "2020-01-02T20:55:59Z")

</div>

I am automating deployment of a ELK stack on Docker, and having issues getting the Elasticsearch logs to appear in the Kibana monitoring. I was having an issue that using "monitoring." rules would create a "Standalone C…

---

## [Hostname split in Kibana](https://discuss.elastic.co/t/hostname-split-in-kibana/213628)

<div class="topic-metadata">

**Author:** [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Replies:** 0\
**Last updated:** [January 2, 2020, 9:18pm UTC](https://discuss.elastic.co/t/hostname-split-in-kibana/213628 "2020-01-02T21:18:05Z")

</div>

Hello, I installed MetricBeat 7.5.1 on a remote Linux host (relative to the ES host), turned on and configured the system module. When I look at the dashboard for the system, I see that the name of the host has been sp…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=286)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=288)
