# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=290

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 291

---

## [Filebeat 6.5.X - massive memory usage](https://discuss.elastic.co/t/filebeat-6-5-x-massive-memory-usage/212508)

<div class="topic-metadata">

**Author:** [@urvi](https://discuss.elastic.co/u/urvi)\
**Replies:** 1\
**Last updated:** [December 19, 2019, 5:51pm UTC](https://discuss.elastic.co/t/filebeat-6-5-x-massive-memory-usage/212508 "2019-12-19T17:51:04Z")

</div>

Hi team, I am using filebeat version 6.5.X. I have observed memory used by filebeat keep on increasing. memstat shows memory usage as below : "memstats":{"gc\_next":11992835024,"memory\_alloc":6185623680,"memory\_total":…

---

## [Filebeat to QRadar](https://discuss.elastic.co/t/filebeat-to-qradar/212535)

<div class="topic-metadata">

**Author:** [@KenRider](https://discuss.elastic.co/u/KenRider)\
**Replies:** 0\
**Last updated:** [December 19, 2019, 5:49pm UTC](https://discuss.elastic.co/t/filebeat-to-qradar/212535 "2019-12-19T17:49:26Z")

</div>

What is the easiest/best/recommended way to get Filebeat output to QRadar?

---

## [Filebeat+logstash syslog fields](https://discuss.elastic.co/t/filebeat-logstash-syslog-fields/210074)

<div class="topic-metadata">

**Author:** [@Willl](https://discuss.elastic.co/u/Willl)\
**Replies:** 0\
**Last updated:** [December 1, 2019, 6:09pm UTC](https://discuss.elastic.co/t/filebeat-logstash-syslog-fields/210074 "2019-12-01T18:09:44Z")

</div>

HI New here and new to ELK. We have a 7.4.2 setup in DEV/UAT to evaluate ELK with beats. We are using Logstash to accept all beats traffic and put Nginx in front of Kibana. For Filebeat, we get "No result found" for …

---

## [Importing metricbeat events from json-file to elastic using filebeat](https://discuss.elastic.co/t/importing-metricbeat-events-from-json-file-to-elastic-using-filebeat/212457)

<div class="topic-metadata">

**Author:** [@dimuskin](https://discuss.elastic.co/u/dimuskin)\
**Replies:** 3\
**Last updated:** [December 19, 2019, 3:47pm UTC](https://discuss.elastic.co/t/importing-metricbeat-events-from-json-file-to-elastic-using-filebeat/212457 "2019-12-19T15:47:17Z")

</div>

Hi, I have a case when metricbeat can't deliver messages directly to elastic, instead, it writes JSON-style events to a file and later filebeat deliver it to elastic. But unfortunately I can’t use "json.keys\_under\_root…

---

## [Apache fields are disable](https://discuss.elastic.co/t/apache-fields-are-disable/212349)

<div class="topic-metadata">

**Author:** [@Yacine\_Mourchid](https://discuss.elastic.co/u/Yacine_Mourchid)\
**Replies:** 4\
**Last updated:** [December 19, 2019, 3:39pm UTC](https://discuss.elastic.co/t/apache-fields-are-disable/212349 "2019-12-19T15:39:36Z")

</div>

Hello, When I want to see all fields of my index in Discovery, my apache's fields are disable (I can see them only if I uncheck "hide missing fields"). In visualization, I can choose these fields but no data appears. …

---

## [Could not get Windows Performance Counters since Metricbeats 7.3.0](https://discuss.elastic.co/t/could-not-get-windows-performance-counters-since-metricbeats-7-3-0/198676)

<div class="topic-metadata">

**Author:** [@jbeyer](https://discuss.elastic.co/u/jbeyer)\
**Replies:** 19\
**Last updated:** [December 19, 2019, 2:06pm UTC](https://discuss.elastic.co/t/could-not-get-windows-performance-counters-since-metricbeats-7-3-0/198676 "2019-12-19T14:06:41Z")

</div>

I use Metricbeats to send Windows Perfomance Counters, like processor time and private bytes to elasticsearch. Until Metricbeats version 7.2.0 it runs well, but the same configuration doesn't run in version 7.3.0 and 7.3…

---

## [Filebeat creates wrong index name](https://discuss.elastic.co/t/filebeat-creates-wrong-index-name/212456)

<div class="topic-metadata">

**Author:** [@bsundsrud](https://discuss.elastic.co/u/bsundsrud)\
**Replies:** 3\
**Last updated:** [December 19, 2019, 11:19am UTC](https://discuss.elastic.co/t/filebeat-creates-wrong-index-name/212456 "2019-12-19T11:19:11Z")

</div>

I'm using filebeat and elasticsearch 7.5.0, installed via Elastic's helm charts. I'm trying to get ES and Filebeat set up in such a way that I can stand up a new cluster inside kubernetes and have everything Just Work. …

---

## [Filebeat CPU utilization metrics are not normalized by default](https://discuss.elastic.co/t/filebeat-cpu-utilization-metrics-are-not-normalized-by-default/210659)

<div class="topic-metadata">

**Author:** [@marko\_vranjkovic](https://discuss.elastic.co/u/marko_vranjkovic)\
**Replies:** 6\
**Last updated:** [December 19, 2019, 8:38am UTC](https://discuss.elastic.co/t/filebeat-cpu-utilization-metrics-are-not-normalized-by-default/210659 "2019-12-19T08:38:35Z")

</div>

Can someone confirm that by using all default settings Filebeat CPU utilization metrics in Kibana stack monitoring are not normalized, e.g. for 4 CPUs the CPU utilization goes from 0% to 400%. This question is just a fi…

---

## [Is the logs collected by winlogbeat legally valid as an evidence in court?](https://discuss.elastic.co/t/is-the-logs-collected-by-winlogbeat-legally-valid-as-an-evidence-in-court/212441)

<div class="topic-metadata">

**Author:** [@jawadak](https://discuss.elastic.co/u/jawadak)\
**Replies:** 2\
**Last updated:** [December 19, 2019, 7:21am UTC](https://discuss.elastic.co/t/is-the-logs-collected-by-winlogbeat-legally-valid-as-an-evidence-in-court/212441 "2019-12-19T07:21:03Z")

</div>

Hi, I have a query related to legal purpose. I am using winlogbeat to ship windows event logs to the elasticsearch. And winlogbeat process the logs and add extra fields to it and store it as docs in an index. So, If I…

---

## [Logstash output from filebeat. What is 'index' configuration option?](https://discuss.elastic.co/t/logstash-output-from-filebeat-what-is-index-configuration-option/212421)

<div class="topic-metadata">

**Author:** [@Anand9](https://discuss.elastic.co/u/Anand9)\
**Replies:** 1\
**Last updated:** [December 19, 2019, 2:20am UTC](https://discuss.elastic.co/t/logstash-output-from-filebeat-what-is-index-configuration-option/212421 "2019-12-19T02:20:46Z")

</div>

This is an excerpt taken from filebeat config for logstash output here I'm wondering what does index have to do with logstash. In my logstash configuration itslef, if I redirect logs to ElasticSearch I believe my logs…

---

## [Netflow module bi-directinal flows input](https://discuss.elastic.co/t/netflow-module-bi-directinal-flows-input/212420)

<div class="topic-metadata">

**Author:** [@fpr](https://discuss.elastic.co/u/fpr)\
**Replies:** 0\
**Last updated:** [December 19, 2019, 12:29am UTC](https://discuss.elastic.co/t/netflow-module-bi-directinal-flows-input/212420 "2019-12-19T00:29:16Z")

</div>

Hi, I want to collect bi-directional netflow generated by nprobe and suricata. But it seems with the netflow module the output is always converted to uni-directional flows. Is that expected, a bug or have i overlooked …

---

## [System/socket dataset setup failed](https://discuss.elastic.co/t/system-socket-dataset-setup-failed/210574)

<div class="topic-metadata">

**Author:** [@Willl](https://discuss.elastic.co/u/Willl)\
**Replies:** 2\
**Last updated:** [December 18, 2019, 6:22pm UTC](https://discuss.elastic.co/t/system-socket-dataset-setup-failed/210574 "2019-12-18T18:22:41Z")

</div>

Testing auditbeat-7.5.0-1-x86\_64 on SLES 12 SP4. When the socket dataset is enabled under module system, auditbeat restarts. I checked the release note which says ipv6.disable=1 is taken care of. Any suggestion? Blo…

---

## [Using Filebeat modules and logstash conf](https://discuss.elastic.co/t/using-filebeat-modules-and-logstash-conf/212373)

<div class="topic-metadata">

**Author:** [@admin\_berlin](https://discuss.elastic.co/u/admin_berlin)\
**Replies:** 0\
**Last updated:** [December 18, 2019, 4:46pm UTC](https://discuss.elastic.co/t/using-filebeat-modules-and-logstash-conf/212373 "2019-12-18T16:46:54Z")

</div>

Hi, i'am trying to use the apache ECS dashboards, but the panels only display "No results found". Heres my setup: Webserver (with Filebeat and apache module enabled) --\> Logstash (with multiple inputs and outputs ) --\> …

---

## [Getting Tomcat logs from Kubernetes pods](https://discuss.elastic.co/t/getting-tomcat-logs-from-kubernetes-pods/211880)

<div class="topic-metadata">

**Author:** [@KenRider](https://discuss.elastic.co/u/KenRider)\
**Replies:** 7\
**Last updated:** [December 18, 2019, 1:39pm UTC](https://discuss.elastic.co/t/getting-tomcat-logs-from-kubernetes-pods/211880 "2019-12-18T13:39:07Z")

</div>

What is the recommended way to get Tomcat logs from Kubernetes pods? I have Elasticsearch, Kibana, and Filebeat 7.5.0 helm charts installed and am getting sysout and syserr from the pods but I also need the logs from /us…

---

## [Filebeat to Logstash Basic Authentication](https://discuss.elastic.co/t/filebeat-to-logstash-basic-authentication/212320)

<div class="topic-metadata">

**Author:** [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Replies:** 1\
**Last updated:** [December 18, 2019, 12:49pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-basic-authentication/212320 "2019-12-18T12:49:25Z")

</div>

Hello, I'm using a typical setup with Filebeat agents running on different Windows clients and Logstash and Elasticsearch setup on a separate server (Windows). I'm using the latest version 7.5. I need to configure basi…

---

## [Field not comming in audit beat logs user.audit.name](https://discuss.elastic.co/t/field-not-comming-in-audit-beat-logs-user-audit-name/210465)

<div class="topic-metadata">

**Author:** [@akki2208](https://discuss.elastic.co/u/akki2208)\
**Replies:** 3\
**Last updated:** [December 18, 2019, 12:02pm UTC](https://discuss.elastic.co/t/field-not-comming-in-audit-beat-logs-user-audit-name/210465 "2019-12-18T12:02:02Z")

</div>

I am using audit beat version 7.4 in audit beat logs field user.audit.name is not coming. Can anyone explain what might be the cause of it?

---

## [Custom field name not showing in Filebeat](https://discuss.elastic.co/t/custom-field-name-not-showing-in-filebeat/212088)

<div class="topic-metadata">

**Author:** [@katara](https://discuss.elastic.co/u/katara)\
**Replies:** 3\
**Last updated:** [December 18, 2019, 9:57am UTC](https://discuss.elastic.co/t/custom-field-name-not-showing-in-filebeat/212088 "2019-12-18T09:57:53Z")

</div>

Below is how im trying to add a custom fiels name in my filebeat 7.2.0 filebeat.inputs: - type: log enabled: true paths: - D:\\Oasis\\Logs\\Admin\_Log\\\* - D:\\Oasis\\Logs\\ERA\_Log\\\* - D:\\OasisServices\\Logs\\\* …

---

## [Metricbeat issue](https://discuss.elastic.co/t/metricbeat-issue/212293)

<div class="topic-metadata">

**Author:** [@tanthiamhuat](https://discuss.elastic.co/u/tanthiamhuat)\
**Replies:** 0\
**Last updated:** [December 18, 2019, 9:36am UTC](https://discuss.elastic.co/t/metricbeat-issue/212293 "2019-12-18T09:36:46Z")

</div>

I follow the instructions for installations: curl -L -O https://artifacts.elastic.co/downloads/beats/metricbeat/metricbeat-7.5.0-amd64.deb sudo dpkg -i metricbeat-7.5.0-amd64.deb Above 2 is OK Modify /etc/metricbeat/…

---

## [Metricbeat Docker Module docker.cpu.total.pct service or container?](https://discuss.elastic.co/t/metricbeat-docker-module-docker-cpu-total-pct-service-or-container/212223)

<div class="topic-metadata">

**Author:** [@georgezhou](https://discuss.elastic.co/u/georgezhou)\
**Replies:** 0\
**Last updated:** [December 17, 2019, 8:20pm UTC](https://discuss.elastic.co/t/metricbeat-docker-module-docker-cpu-total-pct-service-or-container/212223 "2019-12-17T20:20:22Z")

</div>

According to Metricbeat Docker module exported fields, docker.cpu.total.pct represents the Total CPU usage. For example, I am running elasticsearch as a docker service with 2 replicas, so docker.container.labels.com\_doc…

---

## [How to test filebeat can take log files and stdout to terminal?](https://discuss.elastic.co/t/how-to-test-filebeat-can-take-log-files-and-stdout-to-terminal/212047)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 2\
**Last updated:** [December 17, 2019, 5:59pm UTC](https://discuss.elastic.co/t/how-to-test-filebeat-can-take-log-files-and-stdout-to-terminal/212047 "2019-12-17T17:59:14Z")

</div>

This is my filebeat.yml and it is not harvesting the logs from the defined file path- filebeat.inputs: - type: log enabled: true paths: -/home/mehak/Documents/filebeat-7.4.0-linux-x86\_64/logs/log2.log fields…

---

## [Metricbeat AWS Module - Which metrics are pulled?](https://discuss.elastic.co/t/metricbeat-aws-module-which-metrics-are-pulled/212175)

<div class="topic-metadata">

**Author:** [@cesarlino](https://discuss.elastic.co/u/cesarlino)\
**Replies:** 2\
**Last updated:** [December 17, 2019, 5:46pm UTC](https://discuss.elastic.co/t/metricbeat-aws-module-which-metrics-are-pulled/212175 "2019-12-17T17:46:46Z")

</div>

Hi, We want to setup AWS module to collect only RDS and S3 metrics with the following frequency: RDS: every minute S3: once a day AWS charges by the number of metrics requested. It is not clear how many and which met…

---

## [Use packetbeat inside Rancher cluster](https://discuss.elastic.co/t/use-packetbeat-inside-rancher-cluster/208657)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 1\
**Last updated:** [December 17, 2019, 5:41pm UTC](https://discuss.elastic.co/t/use-packetbeat-inside-rancher-cluster/208657 "2019-12-17T17:41:23Z")

</div>

We are trying to use packetbeat (from official Docker image) inside a Rancher cluster. But the packetbeat is only capturing traffic between itself container and elasticsearch :confused: is there a special configuration? …

---

## [Filebeat cannot connect to Logstash using ssl. curl: (35) TCP connection reset by peer](https://discuss.elastic.co/t/filebeat-cannot-connect-to-logstash-using-ssl-curl-35-tcp-connection-reset-by-peer/212193)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 2\
**Last updated:** [December 17, 2019, 4:42pm UTC](https://discuss.elastic.co/t/filebeat-cannot-connect-to-logstash-using-ssl-curl-35-tcp-connection-reset-by-peer/212193 "2019-12-17T16:42:42Z")

</div>

Hi guys, i've set up security for ELK. Everythings works, except the communication between Filebeat and Logstash. Everything is version 7.4 filebeat.yml output.logstash: # The Logstash hosts hosts: \["ip-address:50…

---

## [Filebeat multiple ports](https://discuss.elastic.co/t/filebeat-multiple-ports/211762)

<div class="topic-metadata">

**Author:** [@katara](https://discuss.elastic.co/u/katara)\
**Replies:** 17\
**Last updated:** [December 17, 2019, 10:50am UTC](https://discuss.elastic.co/t/filebeat-multiple-ports/211762 "2019-12-17T10:50:02Z")

</div>

Hi, I have 2 servers where OASIS logs are getting monitored with filebeat. I want them to be saved in the same index. Should I port themm from different ports( Server 1 : 5044, server 2 : 5045)? Or can i use the same…

---

## [Error loading Vsphere Dashboards](https://discuss.elastic.co/t/error-loading-vsphere-dashboards/211925)

<div class="topic-metadata">

**Author:** [@richard\_N](https://discuss.elastic.co/u/richard_N)\
**Replies:** 9\
**Last updated:** [December 17, 2019, 10:18am UTC](https://discuss.elastic.co/t/error-loading-vsphere-dashboards/211925 "2019-12-17T10:18:40Z")

</div>

It won't let me load the vsphere dashboards in 7.5. The plugin works fine but get unsupported media type using API and UI just says sorry there was an error. Has anyone else been able to get this to load?

---

## [Metric beat service turns off automatically in windows sever](https://discuss.elastic.co/t/metric-beat-service-turns-off-automatically-in-windows-sever/211060)

<div class="topic-metadata">

**Author:** [@shiva13](https://discuss.elastic.co/u/shiva13)\
**Replies:** 6\
**Last updated:** [December 17, 2019, 8:48am UTC](https://discuss.elastic.co/t/metric-beat-service-turns-off-automatically-in-windows-sever/211060 "2019-12-17T08:48:45Z")

</div>

Hi, I have integrated my windows server using metric beat to ELK. But the services automatically goes to off mode every few minutes. Please help. Thanks, Shiva

---

## [How to add multiple metricbeat parameter to query](https://discuss.elastic.co/t/how-to-add-multiple-metricbeat-parameter-to-query/211634)

<div class="topic-metadata">

**Author:** [@arvindK\_sharma](https://discuss.elastic.co/u/arvindK_sharma)\
**Replies:** 6\
**Last updated:** [December 17, 2019, 8:23am UTC](https://discuss.elastic.co/t/how-to-add-multiple-metricbeat-parameter-to-query/211634 "2019-12-17T08:23:15Z")

</div>

Hi, I want to expose endpoint of Metricbeat system parameters (Same as KIBANA) with the help of NEST to create a page similar to KIBANA dashboard in my application. I want to fetch all the parameters like CPU, Memory, …

---

## [Heartbeat can't connect to endpoint with cert and key](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436)

<div class="topic-metadata">

**Author:** [@rdaimler](https://discuss.elastic.co/u/rdaimler)\
**Replies:** 8\
**Last updated:** [December 17, 2019, 1:56am UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436 "2019-12-17T01:56:03Z")

</div>

Hello, I'm trying to check an endpoint that requires a cert and key. I get a Client.Timeout exceeded while awaiting headers error. - type: http id: Bitbucket schedule: '@every 20s' urls: \["https://bark.tgyu.com/b…

---

## [Merging old Metricbeat data to save disk space](https://discuss.elastic.co/t/merging-old-metricbeat-data-to-save-disk-space/212068)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 0\
**Last updated:** [December 16, 2019, 10:26pm UTC](https://discuss.elastic.co/t/merging-old-metricbeat-data-to-save-disk-space/212068 "2019-12-16T22:26:22Z")

</div>

I'm in the middle of a long running project to choose the best monitoring toolset we can. Right now I'm testing ELKStack and Prometheus+Grafana. During my research I remember reading about the idea of merging old metric …

---

## [Mysql Module not retrieving data](https://discuss.elastic.co/t/mysql-module-not-retrieving-data/211859)

<div class="topic-metadata">

**Author:** [@JValenzani](https://discuss.elastic.co/u/JValenzani)\
**Replies:** 6\
**Last updated:** [December 16, 2019, 7:55pm UTC](https://discuss.elastic.co/t/mysql-module-not-retrieving-data/211859 "2019-12-16T19:55:03Z")

</div>

I have the exact same problem described in this topic (https://discuss.elastic.co/t/no-data-mysql-dashboard-version-mismatch/146480). I'm using metricbeat 7.4.2 (amd64) with CentOS 7 and Percona Server 5.7.22 The topic…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=289)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=291)
