# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=293

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 294

---

## [ERROR instance/beat.go:916 Exiting: Failed to import dashboard](https://discuss.elastic.co/t/error-instance-beat-go-916-exiting-failed-to-import-dashboard/210362)

<div class="topic-metadata">

**Author:** [@shiva13](https://discuss.elastic.co/u/shiva13)\
**Replies:** 2\
**Last updated:** [December 9, 2019, 5:28am UTC](https://discuss.elastic.co/t/error-instance-beat-go-916-exiting-failed-to-import-dashboard/210362 "2019-12-09T05:28:24Z")

</div>

Hi, I'm trying to integrate Windows server to ELK using metric beat. But while loading or setting up the kibana dashboards facing the below ERR. Please help me fix this. Thanks 2019-12-03T17:16:50.507+0530 ERROR i…

---

## [Logstash & Filebeat sending file/logs over](https://discuss.elastic.co/t/logstash-filebeat-sending-file-logs-over/210663)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 4\
**Last updated:** [December 9, 2019, 2:58am UTC](https://discuss.elastic.co/t/logstash-filebeat-sending-file-logs-over/210663 "2019-12-09T02:58:18Z")

</div>

Hi all, I have this setup. Elasticsearch was setup on Server A with filebeat. Next I have Server B setup with logstash. Is it correct that I send Nginx logs from Server B using "logstash" to server A? and Filebeat on se…

---

## [Using custom pipeline with filebeat module](https://discuss.elastic.co/t/using-custom-pipeline-with-filebeat-module/210016)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 4\
**Last updated:** [December 8, 2019, 6:16pm UTC](https://discuss.elastic.co/t/using-custom-pipeline-with-filebeat-module/210016 "2019-12-08T18:16:40Z")

</div>

I've read a hundred pages of docs/forum posts/random blogs and am just as confused as I was to begin with - I took a break from this project for a few months, but nothing magically changed :wink: Overall Scenario: The…

---

## [Winlogbeat as a service not working after upgrade](https://discuss.elastic.co/t/winlogbeat-as-a-service-not-working-after-upgrade/211015)

<div class="topic-metadata">

**Author:** [@jvedman](https://discuss.elastic.co/u/jvedman)\
**Replies:** 0\
**Last updated:** [December 8, 2019, 3:09pm UTC](https://discuss.elastic.co/t/winlogbeat-as-a-service-not-working-after-upgrade/211015 "2019-12-08T15:09:28Z")

</div>

After upgrading from winlogbeat 6.4 to 7.5, on a Windows 10 1909 system, it appears to start as a service (indicates it is running) but never starts sending logs. I can start wlb from the command line, and it does start …

---

## ["exclude\_lines" not working with docker input](https://discuss.elastic.co/t/exclude-lines-not-working-with-docker-input/208211)

<div class="topic-metadata">

**Author:** [@Gimpiron](https://discuss.elastic.co/u/Gimpiron)\
**Replies:** 7\
**Last updated:** [December 8, 2019, 12:59pm UTC](https://discuss.elastic.co/t/exclude-lines-not-working-with-docker-input/208211 "2019-12-08T12:59:36Z")

</div>

Greetings, My Filebeat logs are getting spammed and I find it impossible to exclude certain lines in my log (the reverse proxy ones). EDIT: Im pretty sure that my ignore configurations are not valid, as I tried to test…

---

## [No connection to Elasticsearch](https://discuss.elastic.co/t/no-connection-to-elasticsearch/210869)

<div class="topic-metadata">

**Author:** [@FNFlorian](https://discuss.elastic.co/u/FNFlorian)\
**Replies:** 4\
**Last updated:** [December 8, 2019, 10:39am UTC](https://discuss.elastic.co/t/no-connection-to-elasticsearch/210869 "2019-12-08T10:39:20Z")

</div>

Hi, I get the following error message in the logs of Winlogbeat that the connection is denied. I see the connection on the Elasticsearch server. Errormessage in winlogbeat log: "Unable to connect because the target co…

---

## [No metrics cpu, memory for kubernetes pods](https://discuss.elastic.co/t/no-metrics-cpu-memory-for-kubernetes-pods/207503)

<div class="topic-metadata">

**Author:** [@vitfsb](https://discuss.elastic.co/u/vitfsb)\
**Replies:** 2\
**Last updated:** [December 7, 2019, 10:25pm UTC](https://discuss.elastic.co/t/no-metrics-cpu-memory-for-kubernetes-pods/207503 "2019-12-07T22:25:28Z")

</div>

Hello, I am using: ELK 7.4.2 quay.io/coreos/kube-state-metrics:v1.8.0 Metricbeat 7.4.2 Metricbeat-kubernetes.yaml--- apiVersion: v1 kind: ConfigMap metadata: name: metricbeat-deployment-modules namespac…

---

## [Metricbeats on GKE not working as expected - Missing deployments, nodes, etc](https://discuss.elastic.co/t/metricbeats-on-gke-not-working-as-expected-missing-deployments-nodes-etc/204948)

<div class="topic-metadata">

**Author:** [@Henrique\_Marques\_Fer](https://discuss.elastic.co/u/Henrique_Marques_Fer)\
**Replies:** 7\
**Last updated:** [December 7, 2019, 10:24pm UTC](https://discuss.elastic.co/t/metricbeats-on-gke-not-working-as-expected-missing-deployments-nodes-etc/204948 "2019-12-07T22:24:30Z")

</div>

I followed everything as the tutorial is saying: https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-kubernetes.html But I still don't get my nodes and deployments status: I have kube-state-metrics ru…

---

## [Connection could be made because the target machine actively refused it](https://discuss.elastic.co/t/connection-could-be-made-because-the-target-machine-actively-refused-it/208151)

<div class="topic-metadata">

**Author:** [@Coder\_HK](https://discuss.elastic.co/u/Coder_HK)\
**Replies:** 3\
**Last updated:** [December 7, 2019, 7:51pm UTC](https://discuss.elastic.co/t/connection-could-be-made-because-the-target-machine-actively-refused-it/208151 "2019-12-07T19:51:56Z")

</div>

I am running windows 10 as my main OS and Ubuntu in Vm ware.. I have installed ELK on ubuntu and now I want to move Sysmon/winlogbeat logs to logstash but I am getting the error .. every thing is running .. E,L,K

---

## [Modsecurity on IIS and Winlogbeat PLEASE HELP! lol](https://discuss.elastic.co/t/modsecurity-on-iis-and-winlogbeat-please-help-lol/210586)

<div class="topic-metadata">

**Author:** [@SigmazGFX](https://discuss.elastic.co/u/SigmazGFX)\
**Replies:** 3\
**Last updated:** [December 6, 2019, 10:32pm UTC](https://discuss.elastic.co/t/modsecurity-on-iis-and-winlogbeat-please-help-lol/210586 "2019-12-06T22:32:00Z")

</div>

Hey Gang, I'm really hoping for some help on this one. Previously we have been struggling on getting our Sophos XG working as a WAF solution, this has proven to be a bit daunting due to the fact that Sophos has basicall…

---

## [Json format file not parsing](https://discuss.elastic.co/t/json-format-file-not-parsing/210318)

<div class="topic-metadata">

**Author:** [@atahanceylan](https://discuss.elastic.co/u/atahanceylan)\
**Replies:** 1\
**Last updated:** [December 3, 2019, 10:35am UTC](https://discuss.elastic.co/t/json-format-file-not-parsing/210318 "2019-12-03T10:35:48Z")

</div>

Even if my JSON file is valid it is not parsed into fields. Whole json object is placed in message. My ELK stack is running on docker. My filebeat yml is like this: filebeat.inputs: type: log enabled: true paths: /…

---

## [Filebeat, raw logs to JSON format to send to elasticsearch directly](https://discuss.elastic.co/t/filebeat-raw-logs-to-json-format-to-send-to-elasticsearch-directly/210089)

<div class="topic-metadata">

**Author:** [@ali\_khalil](https://discuss.elastic.co/u/ali_khalil)\
**Replies:** 1\
**Last updated:** [December 6, 2019, 5:43pm UTC](https://discuss.elastic.co/t/filebeat-raw-logs-to-json-format-to-send-to-elasticsearch-directly/210089 "2019-12-06T17:43:45Z")

</div>

Hi, I had googled a lot and spent many hours but I am not able to find a satisfying answer. How can I parse the raw log strings to JSON. Here is sample logs: \[11/Nov/2019 18:39:15\] INFO \[services2.abc:123\] Company nam…

---

## [How to ship custom log files to elastic?](https://discuss.elastic.co/t/how-to-ship-custom-log-files-to-elastic/210348)

<div class="topic-metadata">

**Author:** [@tortillla](https://discuss.elastic.co/u/tortillla)\
**Replies:** 3\
**Last updated:** [December 6, 2019, 4:58pm UTC](https://discuss.elastic.co/t/how-to-ship-custom-log-files-to-elastic/210348 "2019-12-06T16:58:01Z")

</div>

I am trying to ship custom log files generated by my own application. The format of the log files follows syslog. I tried to find out how to ship custom log files (and not syslog or nginx, etc.), but didn't succeed. Any…

---

## [Creating shared volume between my rest application and Filebeat](https://discuss.elastic.co/t/creating-shared-volume-between-my-rest-application-and-filebeat/210661)

<div class="topic-metadata">

**Author:** [@Nehajain](https://discuss.elastic.co/u/Nehajain)\
**Replies:** 1\
**Last updated:** [December 6, 2019, 4:47pm UTC](https://discuss.elastic.co/t/creating-shared-volume-between-my-rest-application-and-filebeat/210661 "2019-12-06T16:47:11Z")

</div>

Hi, I have a java application running on Docker. It is writing logs that Filebeat would be reading. The Filebeat is also running on Docker. So what I understand is that we need to create a shared volume where Java appl…

---

## [Filebeats 7.5.0 issue with s3 input with gzip files](https://discuss.elastic.co/t/filebeats-7-5-0-issue-with-s3-input-with-gzip-files/210800)

<div class="topic-metadata">

**Author:** [@Ronin](https://discuss.elastic.co/u/Ronin)\
**Replies:** 1\
**Last updated:** [December 6, 2019, 4:41pm UTC](https://discuss.elastic.co/t/filebeats-7-5-0-issue-with-s3-input-with-gzip-files/210800 "2019-12-06T16:41:24Z")

</div>

I have verified that the following issue works under 7.4.2 correctly. If a file is a gzip file it can not be decombressed under 7.5.0. The following log messages are provided: ERROR \[s3\] s3/input.go:259 handleS3Objects…

---

## [CISCO IOS Module Catalyst Switches](https://discuss.elastic.co/t/cisco-ios-module-catalyst-switches/210918)

<div class="topic-metadata">

**Author:** [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Replies:** 0\
**Last updated:** [December 6, 2019, 4:29pm UTC](https://discuss.elastic.co/t/cisco-ios-module-catalyst-switches/210918 "2019-12-06T16:29:49Z")

</div>

Hi, I am using filebeat to collect syslog messages from cisco switches. Right now it looks like the ios dataset parses only access-list logs and parsing of switch logs is not yet implemented. Please let me know if th…

---

## [\[Jolokia module\] Get value from inner path (substructure)](https://discuss.elastic.co/t/jolokia-module-get-value-from-inner-path-substructure/210391)

<div class="topic-metadata">

**Author:** [@misocurdo](https://discuss.elastic.co/u/misocurdo)\
**Replies:** 5\
**Last updated:** [December 6, 2019, 4:09pm UTC](https://discuss.elastic.co/t/jolokia-module-get-value-from-inner-path-substructure/210391 "2019-12-06T16:09:03Z")

</div>

The Jolokia documentation (https://jolokia.org/reference/html/protocol.html#paths) shows that is possibile to retrieve value from "An inner path points to a certain substructure (plain value, array, hash) within a a comp…

---

## [OSQuery snapshot support needs to be merged](https://discuss.elastic.co/t/osquery-snapshot-support-needs-to-be-merged/210450)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 1\
**Last updated:** [December 6, 2019, 2:32pm UTC](https://discuss.elastic.co/t/osquery-snapshot-support-needs-to-be-merged/210450 "2019-12-06T14:32:33Z")

</div>

I just started trying to build a snapshot-compatible pipeline and discovered the work had already been done over a year ago but never merged. It is @Kent\_Brake 's change https://github.com/elastic/beats/pull/8611

---

## [Beat to monitor APIs](https://discuss.elastic.co/t/beat-to-monitor-apis/210902)

<div class="topic-metadata">

**Author:** [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Replies:** 0\
**Last updated:** [December 6, 2019, 2:16pm UTC](https://discuss.elastic.co/t/beat-to-monitor-apis/210902 "2019-12-06T14:16:55Z")

</div>

Good morning, I would like to monitor APIs responses and performance, using the ELK stack. At first thought, it seems that a BEAT would be the best choice. Is there a BEAT that you know can be used to send API request…

---

## [Binary files decoded to c++ structs transfered to elasticsearch while the library is continuously updated -How to do all of that the fastest way](https://discuss.elastic.co/t/binary-files-decoded-to-c-structs-transfered-to-elasticsearch-while-the-library-is-continuously-updated-how-to-do-all-of-that-the-fastest-way/210877)

<div class="topic-metadata">

**Author:** [@liron\_gofberg](https://discuss.elastic.co/u/liron_gofberg)\
**Replies:** 0\
**Last updated:** [December 6, 2019, 11:21am UTC](https://discuss.elastic.co/t/binary-files-decoded-to-c-structs-transfered-to-elasticsearch-while-the-library-is-continuously-updated-how-to-do-all-of-that-the-fastest-way/210877 "2019-12-06T11:21:07Z")

</div>

Hi, I am wondering if I can use filebeat or Logstash or something else for streaming data from binary files to elastic the way I mentioned in the heading. I need to know the fastest way to do that. Here is what I am t…

---

## [File\_integrity sharing violation?](https://discuss.elastic.co/t/file-integrity-sharing-violation/210867)

<div class="topic-metadata">

**Author:** [@devdevdev](https://discuss.elastic.co/u/devdevdev)\
**Replies:** 0\
**Last updated:** [December 6, 2019, 10:35am UTC](https://discuss.elastic.co/t/file-integrity-sharing-violation/210867 "2019-12-06T10:35:44Z")

</div>

An error occurs when opening an Outlook PDF file with Auditbeat running. When Auditbeat is stopped, the PDF file can be opened. The error "Cannot save" also occurs when saving Excel as PDF. Is the setting bad? This p…

---

## [Mage generateCustomBeat - This backport is for Python 2.7 only](https://discuss.elastic.co/t/mage-generatecustombeat-this-backport-is-for-python-2-7-only/210839)

<div class="topic-metadata">

**Author:** [@gdcrocx](https://discuss.elastic.co/u/gdcrocx)\
**Replies:** 0\
**Last updated:** [December 6, 2019, 7:18am UTC](https://discuss.elastic.co/t/mage-generatecustombeat-this-backport-is-for-python-2-7-only/210839 "2019-12-06T07:18:14Z")

</div>

I am trying to build a new beat for pushing PCAPs to the Elastic Stack. I am seeing issues when generating the beat as it is looking for functools32 in a python 3.6 environment. Should I change it to functools as we are…

---

## [Elasticstack integration with Istio service mesh](https://discuss.elastic.co/t/elasticstack-integration-with-istio-service-mesh/210833)

<div class="topic-metadata">

**Author:** [@surenraju](https://discuss.elastic.co/u/surenraju)\
**Replies:** 0\
**Last updated:** [December 6, 2019, 6:29am UTC](https://discuss.elastic.co/t/elasticstack-integration-with-istio-service-mesh/210833 "2019-12-06T06:29:47Z")

</div>

Is there any plan to provide integration with Istio to push traces, metrics etc to elastic stack? Datadog and Stackdriver provides integration with Istio by providing Mixer adapter.

---

## [Fetch system parameter from metricbeat index with NEST](https://discuss.elastic.co/t/fetch-system-parameter-from-metricbeat-index-with-nest/209798)

<div class="topic-metadata">

**Author:** [@arvindK\_sharma](https://discuss.elastic.co/u/arvindK_sharma)\
**Replies:** 2\
**Last updated:** [December 6, 2019, 5:03am UTC](https://discuss.elastic.co/t/fetch-system-parameter-from-metricbeat-index-with-nest/209798 "2019-12-06T05:03:51Z")

</div>

Hi Guys, I am newbie with ElasticStack and want to get the value of system parameters from Metricbeat in my .NET core project but not found any Article to get understand it. Kindly share any sample code or guide for tha…

---

## [No records being produced by metricbeat](https://discuss.elastic.co/t/no-records-being-produced-by-metricbeat/210798)

<div class="topic-metadata">

**Author:** [@IamaBase](https://discuss.elastic.co/u/IamaBase)\
**Replies:** 1\
**Last updated:** [December 6, 2019, 4:31am UTC](https://discuss.elastic.co/t/no-records-being-produced-by-metricbeat/210798 "2019-12-06T04:31:24Z")

</div>

Metricbeat is starting, appears to be running, and I see no errors in the logs. \[root@xxx metricbeat\]# metricbeat test config Config OK \[root@xxx metricbeat\]# metricbeat test modules \[root@xxx metricbeat\]# metricbeat mo…

---

## [Updating ILM / rollover aliases on existing {auditbeat, metricbeat, packetbeat ...} via API](https://discuss.elastic.co/t/updating-ilm-rollover-aliases-on-existing-auditbeat-metricbeat-packetbeat-via-api/210758)

<div class="topic-metadata">

**Author:** [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Replies:** 2\
**Last updated:** [December 5, 2019, 10:11pm UTC](https://discuss.elastic.co/t/updating-ilm-rollover-aliases-on-existing-auditbeat-metricbeat-packetbeat-via-api/210758 "2019-12-05T22:11:12Z")

</div>

Greetings. I'm interested in modifying the default ILM policy for all of my \*beat processes using the API. We need to prevent hard drives from filling up - especially after version updates. We do not want to do this o…

---

## [How to apply ILM to entire matching index pattern?](https://discuss.elastic.co/t/how-to-apply-ilm-to-entire-matching-index-pattern/210784)

<div class="topic-metadata">

**Author:** [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Replies:** 1\
**Last updated:** [December 5, 2019, 10:10pm UTC](https://discuss.elastic.co/t/how-to-apply-ilm-to-entire-matching-index-pattern/210784 "2019-12-05T22:10:04Z")

</div>

Hi. I'd like to apply the same Index Lifecycle Management policy to all indices with a certain pattern. Specifically I need to do this for all of our beats {metricbeat-, auditbeat-, etc.}. I need to perform this task …

---

## [Adding support for SNI to filebeat](https://discuss.elastic.co/t/adding-support-for-sni-to-filebeat/209108)

<div class="topic-metadata">

**Author:** [@rstr](https://discuss.elastic.co/u/rstr)\
**Replies:** 2\
**Last updated:** [December 5, 2019, 9:43pm UTC](https://discuss.elastic.co/t/adding-support-for-sni-to-filebeat/209108 "2019-12-05T21:43:51Z")

</div>

We would like to have filebeat use SNI when connecting to our server. We reach our server via the aaa.com domain, but it only has a TLS cert for bbb.com. We would like to tell filebeat to connect to the server using aaa.…

---

## [WInlogbeat - event\_data Default SD String:](https://discuss.elastic.co/t/winlogbeat-event-data-default-sd-string/210766)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [December 5, 2019, 6:30pm UTC](https://discuss.elastic.co/t/winlogbeat-event-data-default-sd-string/210766 "2019-12-05T18:30:57Z")

</div>

Winlogbeat 7.4.0 is occasionally producing this: "date\_partition": { "day": "05", "month": "12", "year": "2019" }, "@version": "1", "log": { "level": "information" }, "winlog": { "computer\_name": "Server2106.a…

---

## [\[SOLVED\] Filebeat creates only one index](https://discuss.elastic.co/t/solved-filebeat-creates-only-one-index/210651)

<div class="topic-metadata">

**Author:** [@sebiwi\_ultra](https://discuss.elastic.co/u/sebiwi_ultra)\
**Replies:** 1\
**Last updated:** [December 5, 2019, 4:37pm UTC](https://discuss.elastic.co/t/solved-filebeat-creates-only-one-index/210651 "2019-12-05T16:37:15Z")

</div>

Hello, I'm using the default Filebeat configuration on a Kubernetes cluster. This is my configuration: filebeat.autodiscover: providers: - type: kubernetes host: ${NODE\_NAME} hints…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=292)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=294)
