# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=291

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 292

---

## [Inconsistent response code from heartbeat and curl command from same machine](https://discuss.elastic.co/t/inconsistent-response-code-from-heartbeat-and-curl-command-from-same-machine/211793)

<div class="topic-metadata">

**Author:** [@J\_Weeda](https://discuss.elastic.co/u/J_Weeda)\
**Replies:** 8\
**Last updated:** [December 16, 2019, 7:34pm UTC](https://discuss.elastic.co/t/inconsistent-response-code-from-heartbeat-and-curl-command-from-same-machine/211793 "2019-12-16T19:34:50Z")

</div>

Hi, I'm facing an issue where heartbeat 7.5 reports a different response code (500) value than cUrl (302) reports on the same target URL I believe the heartbeat can me mimicked through curl -Iv. Below the heartbeat conf…

---

## [Journalbeat Dashboards Fail](https://discuss.elastic.co/t/journalbeat-dashboards-fail/211542)

<div class="topic-metadata">

**Author:** [@alphaDev23](https://discuss.elastic.co/u/alphaDev23)\
**Replies:** 3\
**Last updated:** [December 16, 2019, 7:17pm UTC](https://discuss.elastic.co/t/journalbeat-dashboards-fail/211542 "2019-12-16T19:17:15Z")

</div>

Using journalbeat 7.4.2 and ELK 7.4.2. Enabled kibana dashboards in journalbeat.yml: setup.dashboards.enabled: true sudo journalbeat -c /etc/journalbeat/journalbeat.yml setup ILM policy and write alias loading not e…

---

## [Getting logs from elasticsearch that runs in a container](https://discuss.elastic.co/t/getting-logs-from-elasticsearch-that-runs-in-a-container/211818)

<div class="topic-metadata">

**Author:** [@jlim0930](https://discuss.elastic.co/u/jlim0930)\
**Replies:** 2\
**Last updated:** [December 16, 2019, 5:49pm UTC](https://discuss.elastic.co/t/getting-logs-from-elasticsearch-that-runs-in-a-container/211818 "2019-12-16T17:49:42Z")

</div>

We are running our elasticsearch in docker containers and have multiple elasticsearch containers. We have a seperate monitoring cluster setup and we were able to use metricbeats container to collect monitoring and send …

---

## [Filebeat nginx module does not work with AWS ES](https://discuss.elastic.co/t/filebeat-nginx-module-does-not-work-with-aws-es/210449)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 5\
**Last updated:** [December 16, 2019, 5:26pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module-does-not-work-with-aws-es/210449 "2019-12-16T17:26:22Z")

</div>

Filebeat nginx module does not work with AWS ES due to lack of support for ingest-geoip plugin in AWS ES. Is there any temporary workaround for this issue ? I don't need the geoip information for now. Also any update o…

---

## [Configure Heartbeat to check date in JSON response body](https://discuss.elastic.co/t/configure-heartbeat-to-check-date-in-json-response-body/211958)

<div class="topic-metadata">

**Author:** [@zuerisee](https://discuss.elastic.co/u/zuerisee)\
**Replies:** 3\
**Last updated:** [December 16, 2019, 3:53pm UTC](https://discuss.elastic.co/t/configure-heartbeat-to-check-date-in-json-response-body/211958 "2019-12-16T15:53:18Z")

</div>

Hello everybody, I was wondering if it's possible to use Heartbeat to parse and check a date within a JSON response body against the current date. In this case I'd like to check if date is older than 2 weeks. { "t…

---

## [How to tail\_files once in filebeat](https://discuss.elastic.co/t/how-to-tail-files-once-in-filebeat/212007)

<div class="topic-metadata">

**Author:** [@chenyahui](https://discuss.elastic.co/u/chenyahui)\
**Replies:** 1\
**Last updated:** [December 16, 2019, 1:35pm UTC](https://discuss.elastic.co/t/how-to-tail-files-once-in-filebeat/212007 "2019-12-16T13:35:51Z")

</div>

How to invoke tail\_files just once in filebeat? Whether or not the filebeat restart later. The usage scenario is that I don't want to deal the exist files，and I just want to process new data But if I only use tail\_file…

---

## [Collect Logstash monitoring data with Metricbeat - 6.2.4](https://discuss.elastic.co/t/collect-logstash-monitoring-data-with-metricbeat-6-2-4/211941)

<div class="topic-metadata">

**Author:** [@SNJY](https://discuss.elastic.co/u/SNJY)\
**Replies:** 1\
**Last updated:** [December 16, 2019, 12:49pm UTC](https://discuss.elastic.co/t/collect-logstash-monitoring-data-with-metricbeat-6-2-4/211941 "2019-12-16T12:49:45Z")

</div>

Hi, I am running Elasticsearch cluster on basic license of ES-6.2.4. To collect logstash monitoring data through metricbeat - 6.2.4 - I enabled metricbeat module of logstash in /etc/metricbeat/modules.d/logstash.yml an…

---

## [Drop\_fields not working on doc](https://discuss.elastic.co/t/drop-fields-not-working-on-doc/211545)

<div class="topic-metadata">

**Author:** [@brain](https://discuss.elastic.co/u/brain)\
**Replies:** 7\
**Last updated:** [December 16, 2019, 12:05pm UTC](https://discuss.elastic.co/t/drop-fields-not-working-on-doc/211545 "2019-12-16T12:05:14Z")

</div>

i'm trying to use drop\_fields on part of a document: "signatures": \[ { "markcount": 2, "families": \[\], "description": "The binary likely contains encrypted or compressed data indicative of a pack…

---

## [Using Filebeat with multiple indices and logstash](https://discuss.elastic.co/t/using-filebeat-with-multiple-indices-and-logstash/211490)

<div class="topic-metadata">

**Author:** [@JoeSmith](https://discuss.elastic.co/u/JoeSmith)\
**Replies:** 3\
**Last updated:** [December 16, 2019, 10:09am UTC](https://discuss.elastic.co/t/using-filebeat-with-multiple-indices-and-logstash/211490 "2019-12-16T10:09:39Z")

</div>

Hi everyone, i've got a logstash instance that has an beats input on 5044. Im now trying to send filebeat data to that instance (which is working fine on a single index). I'd like to have multiple indices depending on …

---

## [Filebeat, missing rows in elastic index](https://discuss.elastic.co/t/filebeat-missing-rows-in-elastic-index/211942)

<div class="topic-metadata">

**Author:** [@skowron-line](https://discuss.elastic.co/u/skowron-line)\
**Replies:** 0\
**Last updated:** [December 16, 2019, 6:00am UTC](https://discuss.elastic.co/t/filebeat-missing-rows-in-elastic-index/211942 "2019-12-16T06:00:05Z")

</div>

Hi I have filebeat (7.4) with config as follows filebeat: config: modules: path: /etc/filebeat/modules.d/\*.yml reload: enabled: false inputs: - enabled: true paths: - /var/www/ewysz…

---

## [Filebeat monitoring when it is down](https://discuss.elastic.co/t/filebeat-monitoring-when-it-is-down/211870)

<div class="topic-metadata">

**Author:** [@Sajal](https://discuss.elastic.co/u/Sajal)\
**Replies:** 0\
**Last updated:** [December 14, 2019, 12:35pm UTC](https://discuss.elastic.co/t/filebeat-monitoring-when-it-is-down/211870 "2019-12-14T12:35:04Z")

</div>

Hi All, How we can monitor if filebeat is down but server is up where it is installed ? Thanks Sajal

---

## [Filebeat: Error watching for docker events: context deadline exceeded](https://discuss.elastic.co/t/filebeat-error-watching-for-docker-events-context-deadline-exceeded/211113)

<div class="topic-metadata">

**Author:** [@speechkey](https://discuss.elastic.co/u/speechkey)\
**Replies:** 4\
**Last updated:** [December 13, 2019, 3:08pm UTC](https://discuss.elastic.co/t/filebeat-error-watching-for-docker-events-context-deadline-exceeded/211113 "2019-12-13T15:08:20Z")

</div>

Hi folks, I have filebeat 7.5.0 with autodiscovery feature running in a docker container on a bunch of hosts. It logs every 30-60 min following error: { "stream": "stderr", "caller": "docker/watcher.go:303", "lev…

---

## [Different registry for different inputs](https://discuss.elastic.co/t/different-registry-for-different-inputs/210541)

<div class="topic-metadata">

**Author:** [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Replies:** 1\
**Last updated:** [December 13, 2019, 2:22pm UTC](https://discuss.elastic.co/t/different-registry-for-different-inputs/210541 "2019-12-13T14:22:44Z")

</div>

Is it possible in filebeat to have different registry fiiles for different inputs? It would be very usefull as when you add a new input and for instnace you decide to change something, deleting that registry will only c…

---

## [How does Filebeat Redis module work for Slow Logs?](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028)

<div class="topic-metadata">

**Author:** [@dandago](https://discuss.elastic.co/u/dandago)\
**Replies:** 10\
**Last updated:** [December 13, 2019, 1:48pm UTC](https://discuss.elastic.co/t/how-does-filebeat-redis-module-work-for-slow-logs/211028 "2019-12-13T13:48:26Z")

</div>

The configuration file of the Redis module for Filebeat seems to support normal logs (from the Redis server's log file) and slowlogs (from the API)... see: I can understand how the logs are picked up from the log file…

---

## [Metricbeat decode\_json\_fields not working for me](https://discuss.elastic.co/t/metricbeat-decode-json-fields-not-working-for-me/211632)

<div class="topic-metadata">

**Author:** [@Ivan\_Vazquez](https://discuss.elastic.co/u/Ivan_Vazquez)\
**Replies:** 3\
**Last updated:** [December 13, 2019, 8:47am UTC](https://discuss.elastic.co/t/metricbeat-decode-json-fields-not-working-for-me/211632 "2019-12-13T08:47:51Z")

</div>

Hi community, I am new using all ELK stack and I'm recollecting data from an API with metricbeat with the http module, receiving a similar response: { "@timestamp": "2019-12-12T10:56:42.880Z", "event": { …

---

## [Filebeat cutting events from tiem to time](https://discuss.elastic.co/t/filebeat-cutting-events-from-tiem-to-time/211795)

<div class="topic-metadata">

**Author:** [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Replies:** 0\
**Last updated:** [December 13, 2019, 1:11pm UTC](https://discuss.elastic.co/t/filebeat-cutting-events-from-tiem-to-time/211795 "2019-12-13T13:11:14Z")

</div>

Hi, I have filebeat 7.3.0-1, that reads files from one directory and sends information to logstash, it process it and writes to elasticsearch. I have a monitoring daemon that from time to time, gets a report from a dat…

---

## [Help: Metricbeat to elasticsearch using ipv6](https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373)

<div class="topic-metadata">

**Author:** [@briank5400](https://discuss.elastic.co/u/briank5400)\
**Replies:** 5\
**Last updated:** [December 13, 2019, 1:06pm UTC](https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373 "2019-12-13T13:06:48Z")

</div>

I have elasticsearch/Kibana setup on another host and configured basic authentication. now I am trying to configure metricbeat to send some data (over ipv6) but I cant seem to figure out why its failing to authenticate …

---

## [Filebeat slow to send logs to logstash](https://discuss.elastic.co/t/filebeat-slow-to-send-logs-to-logstash/211765)

<div class="topic-metadata">

**Author:** [@yberrada](https://discuss.elastic.co/u/yberrada)\
**Replies:** 2\
**Last updated:** [December 13, 2019, 10:00am UTC](https://discuss.elastic.co/t/filebeat-slow-to-send-logs-to-logstash/211765 "2019-12-13T10:00:22Z")

</div>

Hello all, Logstash & Filebeat version: 5.5.1 I am new to the ELK stack. I have set up a elasticsearch cluster on k8s. In the begining filebeat was very slow to send logs to logstash ( took hours ) and the logs of fil…

---

## [Cannot reload "enabled" configuration](https://discuss.elastic.co/t/cannot-reload-enabled-configuration/211763)

<div class="topic-metadata">

**Author:** [@sewenew](https://discuss.elastic.co/u/sewenew)\
**Replies:** 2\
**Last updated:** [December 13, 2019, 10:49am UTC](https://discuss.elastic.co/t/cannot-reload-enabled-configuration/211763 "2019-12-13T10:49:21Z")

</div>

I want to reload input configuration with external configuration file. However, it seems that the enabled option cannot be reloaded. Is there any workaround? # filebeat.yml filebeat.config.inputs: enabled: true pat…

---

## ["reason":"'?' is not an IP string literal](https://discuss.elastic.co/t/reason-is-not-an-ip-string-literal/211750)

<div class="topic-metadata">

**Author:** [@RoNo](https://discuss.elastic.co/u/RoNo)\
**Replies:** 2\
**Last updated:** [December 13, 2019, 10:14am UTC](https://discuss.elastic.co/t/reason-is-not-an-ip-string-literal/211750 "2019-12-13T10:14:17Z")

</div>

Hello. I am running elkstack with Filebeat with module auditd and using the pipeline filebeat-7.3.0-auditd-log-pipeline a lot of my logs related to docker ends up in the DLQ with the following message. \`{"level":"WAR…

---

## [Help for space separate message](https://discuss.elastic.co/t/help-for-space-separate-message/211672)

<div class="topic-metadata">

**Author:** [@Patricio\_Campos](https://discuss.elastic.co/u/Patricio_Campos)\
**Replies:** 1\
**Last updated:** [December 13, 2019, 10:01am UTC](https://discuss.elastic.co/t/help-for-space-separate-message/211672 "2019-12-13T10:01:40Z")

</div>

Hello, am new in Elastic, am working with SIEM module. I receive a log from Fortinet Firewall through a Rsyslog Linux and filebeat receive and send to Elasticsearcg, all importants field come in one large field named Me…

---

## [Filebeat with IIS logs](https://discuss.elastic.co/t/filebeat-with-iis-logs/211756)

<div class="topic-metadata">

**Author:** [@Aleix\_Abrie\_Prat](https://discuss.elastic.co/u/Aleix_Abrie_Prat)\
**Replies:** 1\
**Last updated:** [December 13, 2019, 9:50am UTC](https://discuss.elastic.co/t/filebeat-with-iis-logs/211756 "2019-12-13T09:50:41Z")

</div>

Hi everyone, I have a doubt with the module for IIS logs. I configured the output of filebeat to connect directly with the elasticsearch and then I've have done the command ".\\filebeat.exe setup to make the index in ela…

---

## [Server health status](https://discuss.elastic.co/t/server-health-status/211445)

<div class="topic-metadata">

**Author:** [@aparnababu](https://discuss.elastic.co/u/aparnababu)\
**Replies:** 8\
**Last updated:** [December 13, 2019, 8:27am UTC](https://discuss.elastic.co/t/server-health-status/211445 "2019-12-13T08:27:42Z")

</div>

how to find the unique count of good and bad health server status based on the system.cpu.user.pct and system.memory.actual.used.pct. I tried using the filter option but am getting the wrong count of server health status…

---

## [Uptime monitoring of IP using heart beat](https://discuss.elastic.co/t/uptime-monitoring-of-ip-using-heart-beat/211225)

<div class="topic-metadata">

**Author:** [@Sagar\_Mandal](https://discuss.elastic.co/u/Sagar_Mandal)\
**Replies:** 2\
**Last updated:** [December 13, 2019, 4:29am UTC](https://discuss.elastic.co/t/uptime-monitoring-of-ip-using-heart-beat/211225 "2019-12-13T04:29:50Z")

</div>

Hi Team, I want to use heartbeat to do uptime monitoring of my servers in my network. I just need to know where in heartbeat.yml I need to make changes. for example, replacing type: http to type: IP and what else do …

---

## [Possible regression in Heartbeat 7.5.0](https://discuss.elastic.co/t/possible-regression-in-heartbeat-7-5-0/210423)

<div class="topic-metadata">

**Author:** [@bwright1558](https://discuss.elastic.co/u/bwright1558)\
**Replies:** 3\
**Last updated:** [December 12, 2019, 9:33pm UTC](https://discuss.elastic.co/t/possible-regression-in-heartbeat-7-5-0/210423 "2019-12-12T21:33:50Z")

</div>

I'm running Heartbeat using the official Heartbeat docker image. Ever since updating from 7.4.2 to 7.5.0, none of my HTTP monitors appear to be getting run. I have around 300 monitors configured with their schedule set t…

---

## [Exiting: 1 error: error making http request:](https://discuss.elastic.co/t/exiting-1-error-error-making-http-request/211669)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 1\
**Last updated:** [December 12, 2019, 8:10pm UTC](https://discuss.elastic.co/t/exiting-1-error-error-making-http-request/211669 "2019-12-12T20:10:30Z")

</div>

I am setting up metricbeat on a node with Kibana and Elasticsearch (coordinator role) I have setup the kibana portion and it injected the dashboards but at the end of the run it still fails with Exiting: 1 error: error…

---

## [Metricbeat Active Directory (AD) performance metrics (perfmon) yaml build](https://discuss.elastic.co/t/metricbeat-active-directory-ad-performance-metrics-perfmon-yaml-build/209687)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 9\
**Last updated:** [December 12, 2019, 5:45pm UTC](https://discuss.elastic.co/t/metricbeat-active-directory-ad-performance-metrics-perfmon-yaml-build/209687 "2019-12-12T17:45:04Z")

</div>

I'm looking for a little guidance on how to build out the windows.yml module in Metricbeat. If this is being built out correctly we may need 3-4 lines to ship the Active Directroy perfmon out. The issue that I'm having…

---

## [Auditbeat won't start on deb 8\_11](https://discuss.elastic.co/t/auditbeat-wont-start-on-deb-8-11/210712)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 1\
**Last updated:** [December 12, 2019, 9:59am UTC](https://discuss.elastic.co/t/auditbeat-wont-start-on-deb-8-11/210712 "2019-12-12T09:59:44Z")

</div>

Attempts to start auditbeat on this system give these errors: instance/beat.go:916 Exiting: 1 error: 1 error: system/socket dataset setup failed: unable to guess one or more required parameters: guess\_sk\_buff\_pr…

---

## [Metricbeat Failed to connect EOF](https://discuss.elastic.co/t/metricbeat-failed-to-connect-eof/210939)

<div class="topic-metadata">

**Author:** [@elkuser2](https://discuss.elastic.co/u/elkuser2)\
**Replies:** 8\
**Last updated:** [December 12, 2019, 2:51pm UTC](https://discuss.elastic.co/t/metricbeat-failed-to-connect-eof/210939 "2019-12-12T14:51:47Z")

</div>

I am trying to run metricbeat, but no data is showing up in the GUI and I keep getting the following error in the metricbeat logs: 2019-12-06T20:48:49.394Z ERROR pipeline/output.go:100 Failed to connect to bac…

---

## [Yaml: line 159: did not find expected key](https://discuss.elastic.co/t/yaml-line-159-did-not-find-expected-key/211516)

<div class="topic-metadata">

**Author:** [@uek1967](https://discuss.elastic.co/u/uek1967)\
**Replies:** 3\
**Last updated:** [December 12, 2019, 11:32am UTC](https://discuss.elastic.co/t/yaml-line-159-did-not-find-expected-key/211516 "2019-12-12T11:32:24Z")

</div>

Hi folks, I need you help solving the problem with filebeat as described above: ./filebeat test config -e gives out the following error: Exiting: error loading config file: yaml: line 159: did not find expected key W…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=290)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=292)
