# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=292

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 293

---

## [Configuring Filebeat to use X-Pack security in Basic version](https://discuss.elastic.co/t/configuring-filebeat-to-use-x-pack-security-in-basic-version/211626)

<div class="topic-metadata">

**Author:** [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Replies:** 0\
**Last updated:** [December 12, 2019, 10:57am UTC](https://discuss.elastic.co/t/configuring-filebeat-to-use-x-pack-security-in-basic-version/211626 "2019-12-12T10:57:54Z")

</div>

Hi, I'm trying to configure Filebeat to use X-Pack security in the Basic (free) version of the Elasticstack. I'm following what's stated here: https://www.elastic.co/guide/en/beats/filebeat/current/securing-beats.html …

---

## [Monitoring filebeat with metricbeat](https://discuss.elastic.co/t/monitoring-filebeat-with-metricbeat/211565)

<div class="topic-metadata">

**Author:** [@prr](https://discuss.elastic.co/u/prr)\
**Replies:** 1\
**Last updated:** [December 12, 2019, 10:45am UTC](https://discuss.elastic.co/t/monitoring-filebeat-with-metricbeat/211565 "2019-12-12T10:45:10Z")

</div>

I'm trying to setup metricbeat to monitor filebeat stats. But when I tried the beats module for doing so in my metricbeat config, I'm getting this error: error message from metricbeat logs: Error fetching data for met…

---

## [Elasticsearch Module - Slowlog field mapping](https://discuss.elastic.co/t/elasticsearch-module-slowlog-field-mapping/211522)

<div class="topic-metadata">

**Author:** [@AndrewMcQ](https://discuss.elastic.co/u/AndrewMcQ)\
**Replies:** 1\
**Last updated:** [December 12, 2019, 10:35am UTC](https://discuss.elastic.co/t/elasticsearch-module-slowlog-field-mapping/211522 "2019-12-12T10:35:15Z")

</div>

Hi - While working on enabling the Elasticsearch module, specifically the slowlog fileset, I ran into a challenge when I went to use the data in the index to build visualizations. Some of the fields that get pulled out…

---

## [PacketBeat to capture all traffic except few port?](https://discuss.elastic.co/t/packetbeat-to-capture-all-traffic-except-few-port/211169)

<div class="topic-metadata">

**Author:** [@frenchy59](https://discuss.elastic.co/u/frenchy59)\
**Replies:** 3\
**Last updated:** [December 12, 2019, 10:30am UTC](https://discuss.elastic.co/t/packetbeat-to-capture-all-traffic-except-few-port/211169 "2019-12-12T10:30:46Z")

</div>

Hi All, Is it possible to configure PacketBeat to capture all the traffic the box is having. except few exception traffic. and then report in Kibana which box is not having any traffic. The goal is to find out which …

---

## [Sometimes beginning of log line is missing resulting in \_jsonparsefailed tag](https://discuss.elastic.co/t/sometimes-beginning-of-log-line-is-missing-resulting-in-jsonparsefailed-tag/209022)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 8\
**Last updated:** [December 12, 2019, 9:12am UTC](https://discuss.elastic.co/t/sometimes-beginning-of-log-line-is-missing-resulting-in-jsonparsefailed-tag/209022 "2019-12-12T09:12:13Z")

</div>

Hi, I am on elastic stack 7.4.2 and using following pipeline: log -\> filebeat -\> redis (TLS via stunnel) -\> logstash-\> elasticsearch In logstash I use pipeline to pipeline communication, so that different inputs the s…

---

## [Filebeat and Logstash logdata not passing](https://discuss.elastic.co/t/filebeat-and-logstash-logdata-not-passing/211459)

<div class="topic-metadata">

**Author:** [@katara](https://discuss.elastic.co/u/katara)\
**Replies:** 3\
**Last updated:** [December 12, 2019, 5:19am UTC](https://discuss.elastic.co/t/filebeat-and-logstash-logdata-not-passing/211459 "2019-12-12T05:19:03Z")

</div>

Hi I have 2 servers in which one has Logstash 7.2.0 and another has filbeat 7.2.0. The below is my logstash conf file: \> input { beats { port =\> 5044 ssl =\> false } } output { …

---

## [Input plugin: kafka, error: "abandoned subscription to k8s-pod-logs-kafka-topic/0 because consuming was taking too long"](https://discuss.elastic.co/t/input-plugin-kafka-error-abandoned-subscription-to-k8s-pod-logs-kafka-topic-0-because-consuming-was-taking-too-long/211259)

<div class="topic-metadata">

**Author:** [@111258](https://discuss.elastic.co/u/111258)\
**Replies:** 4\
**Last updated:** [December 12, 2019, 1:54am UTC](https://discuss.elastic.co/t/input-plugin-kafka-error-abandoned-subscription-to-k8s-pod-logs-kafka-topic-0-because-consuming-was-taking-too-long/211259 "2019-12-12T01:54:50Z")

</div>

filebeat: 7.4.2 ES:7.4.2 filebeat.yml: filebeat.inputs: - type: kafka hosts: - wn0-xxx.internal.chinacloudapp.cn:9092 - wn1-xxx.internal.chinacloudapp.cn:9092 - wn2-xxx.internal.chinacloudapp.cn:9092 t…

---

## [Custom indexes didn't create using winlogbeat-7.2.1 version](https://discuss.elastic.co/t/custom-indexes-didnt-create-using-winlogbeat-7-2-1-version/209496)

<div class="topic-metadata">

**Author:** [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Replies:** 4\
**Last updated:** [December 11, 2019, 4:32pm UTC](https://discuss.elastic.co/t/custom-indexes-didnt-create-using-winlogbeat-7-2-1-version/209496 "2019-12-11T16:32:49Z")

</div>

hi, custom indexes didn't creating using winlogbeat-7.2.1 version. Below my winlogbeat configuration that properly works in winlogbeat 6.8.1. ###################### wlb Configuration ########################## winlogb…

---

## [Metricbeat not working when elasticsearch is upgraded from 7.4.0 to 7.5.0](https://discuss.elastic.co/t/metricbeat-not-working-when-elasticsearch-is-upgraded-from-7-4-0-to-7-5-0/210443)

<div class="topic-metadata">

**Author:** [@sharmila.dev](https://discuss.elastic.co/u/sharmila.dev)\
**Replies:** 7\
**Last updated:** [December 11, 2019, 4:16pm UTC](https://discuss.elastic.co/t/metricbeat-not-working-when-elasticsearch-is-upgraded-from-7-4-0-to-7-5-0/210443 "2019-12-11T16:16:58Z")

</div>

Hi, Im unable to set up monitoring for elastic search using metricbeat. It was working with version 7.4.0 but broke when upgraded to 7.5.0. I was sending metrics using metricbeat to separate monitoring cluster. Metricbe…

---

## [Not receiving State\_\* metrics in Azure/Kubernetes](https://discuss.elastic.co/t/not-receiving-state-metrics-in-azure-kubernetes/210490)

<div class="topic-metadata">

**Author:** [@Christiaan](https://discuss.elastic.co/u/Christiaan)\
**Replies:** 1\
**Last updated:** [December 11, 2019, 10:36am UTC](https://discuss.elastic.co/t/not-receiving-state-metrics-in-azure-kubernetes/210490 "2019-12-11T10:36:24Z")

</div>

Hi all, I'm in the middle of setting up an ECK for a Kubernetes cluster on Azure, and I've hit a small snag on Metricbeat. Hoping someone can push me in the right direction. The setup I've got Elastic and related depl…

---

## [Filebeat can't read container logs](https://discuss.elastic.co/t/filebeat-cant-read-container-logs/211419)

<div class="topic-metadata">

**Author:** [@langzichai](https://discuss.elastic.co/u/langzichai)\
**Replies:** 2\
**Last updated:** [December 11, 2019, 10:15am UTC](https://discuss.elastic.co/t/filebeat-cant-read-container-logs/211419 "2019-12-11T10:15:33Z")

</div>

hi , I use this ymal create in namesplace defuld; created success, but can't find any logs by type: container. Any help!!!! https://raw.githubusercontent.com/elastic/beats/7.4/deploy/kubernetes/filebeat-kubernetes.yaml …

---

## [How to install Filebeat on Webshere WAS 9](https://discuss.elastic.co/t/how-to-install-filebeat-on-webshere-was-9/211326)

<div class="topic-metadata">

**Author:** [@rockitaki](https://discuss.elastic.co/u/rockitaki)\
**Replies:** 1\
**Last updated:** [December 11, 2019, 8:46am UTC](https://discuss.elastic.co/t/how-to-install-filebeat-on-webshere-was-9/211326 "2019-12-11T08:46:44Z")

</div>

I have an elk on the server1, and Websphere aplication server cluster, with log file on path //waserver/someDir/trace\_log. Need I set up filebeat on WAS(how?), or can I just configure logstash on remote file?

---

## [How to send an application (systemd service) logs to Logstash?](https://discuss.elastic.co/t/how-to-send-an-application-systemd-service-logs-to-logstash/211340)

<div class="topic-metadata">

**Author:** [@arblr](https://discuss.elastic.co/u/arblr)\
**Replies:** 1\
**Last updated:** [December 11, 2019, 8:39am UTC](https://discuss.elastic.co/t/how-to-send-an-application-systemd-service-logs-to-logstash/211340 "2019-12-11T08:39:37Z")

</div>

My application / service name 'appdb', running as systemd service. I can observe logs from this application using shall command 'journalctl -u appdb.service'. I want to send these logs to Logstash. I am using the followi…

---

## [Increase performance for a PubSub module in Filebeat](https://discuss.elastic.co/t/increase-performance-for-a-pubsub-module-in-filebeat/210466)

<div class="topic-metadata">

**Author:** [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Replies:** 4\
**Last updated:** [December 10, 2019, 10:09pm UTC](https://discuss.elastic.co/t/increase-performance-for-a-pubsub-module-in-filebeat/210466 "2019-12-10T22:09:57Z")

</div>

How to improve performance for the Google Cloud module on a filebeat? I'm using Google Cloud module running on a filebeat: https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-googlecloud.html, and my e…

---

## [Manually import modified dashboard json in kibana](https://discuss.elastic.co/t/manually-import-modified-dashboard-json-in-kibana/211276)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 1\
**Last updated:** [December 10, 2019, 10:05pm UTC](https://discuss.elastic.co/t/manually-import-modified-dashboard-json-in-kibana/211276 "2019-12-10T22:05:49Z")

</div>

Am trying to load a modified json from kibana/7/dashboard/Winlogbeat.json as our Kibana instances are firewalled off for beats clients. So I'll have to import a version manually from my desktop, only Kibana complains. W…

---

## [Kafka output dropping messages due to size, but doesn't increment the "failed" counter](https://discuss.elastic.co/t/kafka-output-dropping-messages-due-to-size-but-doesnt-increment-the-failed-counter/210081)

<div class="topic-metadata">

**Author:** [@imriz](https://discuss.elastic.co/u/imriz)\
**Replies:** 1\
**Last updated:** [December 10, 2019, 3:10pm UTC](https://discuss.elastic.co/t/kafka-output-dropping-messages-due-to-size-but-doesnt-increment-the-failed-counter/210081 "2019-12-10T15:10:15Z")

</div>

Not sure yet if this is a bug, or intentional behavior - I've noticed in my logs that sometimes Filebeat's Kafka output will drop messages due to size error from the brokerm, but won't increment the "failed" counter (ht…

---

## [Is it possible Mutual authentication between Logstash and Beats](https://discuss.elastic.co/t/is-it-possible-mutual-authentication-between-logstash-and-beats/211017)

<div class="topic-metadata">

**Author:** [@Fedele\_Mantuano](https://discuss.elastic.co/u/Fedele_Mantuano)\
**Replies:** 6\
**Last updated:** [December 10, 2019, 2:40pm UTC](https://discuss.elastic.co/t/is-it-possible-mutual-authentication-between-logstash-and-beats/211017 "2019-12-10T14:40:27Z")

</div>

Hi community, my question is very easy. Is it possible the Mutual authentication between Logstash and Beats. I can authenticate the server Logstash, but is there a way to authenticate the client? I'd like to have diffe…

---

## [Custom index pattern vs ILM](https://discuss.elastic.co/t/custom-index-pattern-vs-ilm/210979)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 4\
**Last updated:** [December 10, 2019, 10:39am UTC](https://discuss.elastic.co/t/custom-index-pattern-vs-ilm/210979 "2019-12-10T10:39:18Z")

</div>

Attempting to make winlogbeat run on a Windows box and wonder about this issues from the log: 2019-12-07T13:31:20.231+0100 INFO \[index-management\] idxmgmt/std.go:182 Set output.elasticsearch.index to 'winlogbeat-7.5.0' …

---

## [Couldn't push logs to elasticsearch using filebeat](https://discuss.elastic.co/t/couldnt-push-logs-to-elasticsearch-using-filebeat/211165)

<div class="topic-metadata">

**Author:** [@bharath\_k](https://discuss.elastic.co/u/bharath_k)\
**Replies:** 1\
**Last updated:** [December 10, 2019, 9:14am UTC](https://discuss.elastic.co/t/couldnt-push-logs-to-elasticsearch-using-filebeat/211165 "2019-12-10T09:14:08Z")

</div>

Hi Folks, Iam running elasticsearch 6.7 as managed service in cloud. where in i want to push the logs from Kubernetes pods to elasticsearch using filebeat (6.8.5) configuration on https protocol but its giving response …

---

## [Metricbeat error](https://discuss.elastic.co/t/metricbeat-error/211080)

<div class="topic-metadata">

**Author:** [@suraj\_kumar3](https://discuss.elastic.co/u/suraj_kumar3)\
**Replies:** 1\
**Last updated:** [December 10, 2019, 8:49am UTC](https://discuss.elastic.co/t/metricbeat-error/211080 "2019-12-10T08:49:05Z")

</div>

error creating aws metricset: failed to retrieve aws credentials, please check AWS credential in config: EC2RoleRequestError: no EC2 instance role found

---

## [How to send evtx files to logstash via FIlebeat?](https://discuss.elastic.co/t/how-to-send-evtx-files-to-logstash-via-filebeat/211008)

<div class="topic-metadata">

**Author:** [@Coder\_HK](https://discuss.elastic.co/u/Coder_HK)\
**Replies:** 2\
**Last updated:** [December 9, 2019, 8:27pm UTC](https://discuss.elastic.co/t/how-to-send-evtx-files-to-logstash-via-filebeat/211008 "2019-12-09T20:27:45Z")

</div>

I have 300mb evtx file and I want to send this file to logstash (which is on another machine) using Filebeat. How can I do this ? NOTE: I am using winlogbeat to send windows logs to logstash and it's working fine. but …

---

## [Additional metrics around system.net\* such as segments retransmitted?](https://discuss.elastic.co/t/additional-metrics-around-system-net-such-as-segments-retransmitted/210965)

<div class="topic-metadata">

**Author:** [@slmingol](https://discuss.elastic.co/u/slmingol)\
**Replies:** 2\
**Last updated:** [December 9, 2019, 2:25pm UTC](https://discuss.elastic.co/t/additional-metrics-around-system-net-such-as-segments-retransmitted/210965 "2019-12-09T14:25:50Z")

</div>

I'm looking to try and use metricbeat to triage a performance problem and want to be able to add in segments retransmitted but do not see these as being a tracked metric by metricbeat. Am I missing something or are these…

---

## [Define custom field on launch](https://discuss.elastic.co/t/define-custom-field-on-launch/211085)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [December 9, 2019, 1:53pm UTC](https://discuss.elastic.co/t/define-custom-field-on-launch/211085 "2019-12-09T13:53:43Z")

</div>

Added two metadata fields under 'host' to our index template and preloaded this into our elastic cluster like this: "metadata": { "properties": { "id1": { "type": "long" }, "i…

---

## [Filebeat with MSSQL and utf-16le](https://discuss.elastic.co/t/filebeat-with-mssql-and-utf-16le/210944)

<div class="topic-metadata">

**Author:** [@Christian\_SANCHEZ](https://discuss.elastic.co/u/Christian_SANCHEZ)\
**Replies:** 2\
**Last updated:** [December 9, 2019, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-with-mssql-and-utf-16le/210944 "2019-12-09T13:50:23Z")

</div>

Hello I am using Stack 7.4.0 on Windows 10 trying to parse my MSSQL logs. When using the filebeat.input as below it works file. Lines are correctly decoded and multiline is correctly handled. filebeat.inputs: - type:…

---

## [Filebeat is not outputting logs to ElasticSearch, not even to Console](https://discuss.elastic.co/t/filebeat-is-not-outputting-logs-to-elasticsearch-not-even-to-console/210173)

<div class="topic-metadata">

**Author:** [@ali\_khalil](https://discuss.elastic.co/u/ali_khalil)\
**Replies:** 2\
**Last updated:** [December 9, 2019, 1:06pm UTC](https://discuss.elastic.co/t/filebeat-is-not-outputting-logs-to-elasticsearch-not-even-to-console/210173 "2019-12-09T13:06:12Z")

</div>

@ElasticMaa @elastock @andrewkroh @steffens Here is my filebeat.yml: filebeat.inputs: - type: log paths: - "/home/ubuntu/log/test\_logs\_json" enabled: true json.keys\_under\_ro…

---

## [Json: cannot unmarshal string into Go value of type map\[string\]interface {}](https://discuss.elastic.co/t/json-cannot-unmarshal-string-into-go-value-of-type-map-string-interface/208660)

<div class="topic-metadata">

**Author:** [@sur1029](https://discuss.elastic.co/u/sur1029)\
**Replies:** 2\
**Last updated:** [December 9, 2019, 12:36pm UTC](https://discuss.elastic.co/t/json-cannot-unmarshal-string-into-go-value-of-type-map-string-interface/208660 "2019-12-09T12:36:21Z")

</div>

Hi, We are pushing json logs from application and have configured filebeat to push same logs to es. I am getting below error in logs: 2019/11/20 06:12:59.971200 json .go:32: ERR Error decoding JSON: json : cannot unma…

---

## [Is there a way to use the "Time Series" data type with output redis? (Metricbeat)](https://discuss.elastic.co/t/is-there-a-way-to-use-the-time-series-data-type-with-output-redis-metricbeat/211039)

<div class="topic-metadata">

**Author:** [@17earlgrey](https://discuss.elastic.co/u/17earlgrey)\
**Replies:** 1\
**Last updated:** [December 9, 2019, 11:19am UTC](https://discuss.elastic.co/t/is-there-a-way-to-use-the-time-series-data-type-with-output-redis-metricbeat/211039 "2019-12-09T11:19:29Z")

</div>

Currently, metricbeat is only possible with List Structure types (Output Redis). This method may not be immediately visible. Is there a way to output "Time Series” data type for visualization? It seems that there is a…

---

## [Filebeat on Kubernetes - How to get relevant kuberntes information into logs?](https://discuss.elastic.co/t/filebeat-on-kubernetes-how-to-get-relevant-kuberntes-information-into-logs/211019)

<div class="topic-metadata">

**Author:** [@Justin\_Seiser](https://discuss.elastic.co/u/Justin_Seiser)\
**Replies:** 1\
**Last updated:** [December 9, 2019, 10:04am UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes-how-to-get-relevant-kuberntes-information-into-logs/211019 "2019-12-09T10:04:33Z")

</div>

Im using filebeat, installed via helm, from the official helm chart. We are sending logs to ElasticCloud. My filebeat.yaml setup.dashboards.enabled: true logging.metrics: enabled: false filebeat.inputs: type: con…

---

## [Fail to use multiline input mode in filebeats](https://discuss.elastic.co/t/fail-to-use-multiline-input-mode-in-filebeats/211033)

<div class="topic-metadata">

**Author:** [@yevgen92](https://discuss.elastic.co/u/yevgen92)\
**Replies:** 1\
**Last updated:** [December 9, 2019, 9:24am UTC](https://discuss.elastic.co/t/fail-to-use-multiline-input-mode-in-filebeats/211033 "2019-12-09T09:24:09Z")

</div>

I try to send a multiline event to logstash from xml file via filebeats. I use 7.5.2 version for both programs, and Windows 10. My xml file is next: my logstash configuration file is: input { beats{ port =\> 5044 …

---

## [Close\_removed rotate not wroking properly issue](https://discuss.elastic.co/t/close-removed-rotate-not-wroking-properly-issue/211075)

<div class="topic-metadata">

**Author:** [@theseaofstarts](https://discuss.elastic.co/u/theseaofstarts)\
**Replies:** 0\
**Last updated:** [December 9, 2019, 9:12am UTC](https://discuss.elastic.co/t/close-removed-rotate-not-wroking-properly-issue/211075 "2019-12-09T09:12:22Z")

</div>

Hi: I encountered the issue when using filebeat 7.4.1 in kubernetes. I set the rotate number of docker logs with 5, and enable close\_removed, disable close\_moved. In this way, i want filebeat keep trace of the contain…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=291)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=293)
