# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=294

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 295

---

## [MetricBeat HTTP module Return Code](https://discuss.elastic.co/t/metricbeat-http-module-return-code/209732)

<div class="topic-metadata">

**Author:** [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Replies:** 8\
**Last updated:** [December 5, 2019, 2:16pm UTC](https://discuss.elastic.co/t/metricbeat-http-module-return-code/209732 "2019-12-05T14:16:10Z")

</div>

Good morning, I want to call an API that will run a query, but only want to know the return code of the request, not the actual returned data. This is to monitor that the API is up and running. I have the following ht…

---

## [Filebeat truncates output data](https://discuss.elastic.co/t/filebeat-truncates-output-data/210645)

<div class="topic-metadata">

**Author:** [@gappa](https://discuss.elastic.co/u/gappa)\
**Replies:** 7\
**Last updated:** [December 5, 2019, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-truncates-output-data/210645 "2019-12-05T13:25:00Z")

</div>

I'm using Filebeat 7.4.2 in order to read files from a directory. Each file contains valid json data line by line. Each json row within the file is read from filebeat then sent to a logstash (v7.4.2) instance that will s…

---

## [How to make filebeat run inside the logstash container?](https://discuss.elastic.co/t/how-to-make-filebeat-run-inside-the-logstash-container/210709)

<div class="topic-metadata">

**Author:** [@111254](https://discuss.elastic.co/u/111254)\
**Replies:** 0\
**Last updated:** [December 5, 2019, 12:40pm UTC](https://discuss.elastic.co/t/how-to-make-filebeat-run-inside-the-logstash-container/210709 "2019-12-05T12:40:59Z")

</div>

Using filebeat, you need to collect logs from the Logstash. In this case, filebeat should be launched inside the logstash container at each of its (logstash containers) startups and collected logs from the Logstash. Th…

---

## [Zookeeper 5-10x audit-activity](https://discuss.elastic.co/t/zookeeper-5-10x-audit-activity/208223)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 2\
**Last updated:** [December 5, 2019, 12:42pm UTC](https://discuss.elastic.co/t/zookeeper-5-10x-audit-activity/208223 "2019-12-05T12:42:21Z")

</div>

Looking at the volume of traffic coming from auditbeat - seems that my 3 zookeeper nodes are creating 5-10x the amount of audit events of any other server. I've added this line which helped a fair bit: - drop\_event.when…

---

## [\[Metricbeat Docker\] Overview ECS is showing no data and error: \[esaggs\] \> "field" is a required parameter](https://discuss.elastic.co/t/metricbeat-docker-overview-ecs-is-showing-no-data-and-error-esaggs-field-is-a-required-parameter/206540)

<div class="topic-metadata">

**Author:** [@Simon\_Becker](https://discuss.elastic.co/u/Simon_Becker)\
**Replies:** 2\
**Last updated:** [December 5, 2019, 9:46am UTC](https://discuss.elastic.co/t/metricbeat-docker-overview-ecs-is-showing-no-data-and-error-esaggs-field-is-a-required-parameter/206540 "2019-12-05T09:46:31Z")

</div>

Hello, I am using Metricbeat in docker to monitor my systems Metrics as well as my docker metrics. Unfortunately, i get an error in Kibana showing this: My metricbeat config looks like this: metricbeat.autodisco…

---

## [How many cpu and memory is filebeat suppose to use? is there any benchmark about it?](https://discuss.elastic.co/t/how-many-cpu-and-memory-is-filebeat-suppose-to-use-is-there-any-benchmark-about-it/210667)

<div class="topic-metadata">

**Author:** [@biello](https://discuss.elastic.co/u/biello)\
**Replies:** 0\
**Last updated:** [December 5, 2019, 9:43am UTC](https://discuss.elastic.co/t/how-many-cpu-and-memory-is-filebeat-suppose-to-use-is-there-any-benchmark-about-it/210667 "2019-12-05T09:43:56Z")

</div>

I am using filebeat to collect json-format docker logs at the speed of 10MB/s. And I am wondering how many cpu usage is ok in my case. Can you share your throughput and accordingly cpu usage here? That will be very helpf…

---

## [How can i stop to generating monitoring index? its taking too much memory without any index creation](https://discuss.elastic.co/t/how-can-i-stop-to-generating-monitoring-index-its-taking-too-much-memory-without-any-index-creation/208710)

<div class="topic-metadata">

**Author:** [@Mitesh\_Shah1](https://discuss.elastic.co/u/Mitesh_Shah1)\
**Replies:** 4\
**Last updated:** [December 5, 2019, 5:38am UTC](https://discuss.elastic.co/t/how-can-i-stop-to-generating-monitoring-index-its-taking-too-much-memory-without-any-index-creation/208710 "2019-12-05T05:38:29Z")

</div>

Hi i m using Elasticsearch 7.4 i just install and setup Elasticsearch and configure network.host & discovery.seed\_hosts Parameter in /etc/elasticsearch/elasticsearch.yml file. Now, when i am seeing in kibana , it showi…

---

## [Using modules alongside "normal" log processing](https://discuss.elastic.co/t/using-modules-alongside-normal-log-processing/210458)

<div class="topic-metadata">

**Author:** [@amhulli](https://discuss.elastic.co/u/amhulli)\
**Replies:** 2\
**Last updated:** [December 5, 2019, 4:14am UTC](https://discuss.elastic.co/t/using-modules-alongside-normal-log-processing/210458 "2019-12-05T04:14:36Z")

</div>

Hi, I have only been working on ELK for a month or so. I have recently upgraded my ELK stack (to 7.4.2) which is configured to use filebeat to read and parse logs via logstash to elasticsearch in a centralised log serv…

---

## [No cpu/memory information from metricbeat docker module monitoring windows container](https://discuss.elastic.co/t/no-cpu-memory-information-from-metricbeat-docker-module-monitoring-windows-container/210596)

<div class="topic-metadata">

**Author:** [@hendrik.ruemmler](https://discuss.elastic.co/u/hendrik.ruemmler)\
**Replies:** 0\
**Last updated:** [December 4, 2019, 9:49pm UTC](https://discuss.elastic.co/t/no-cpu-memory-information-from-metricbeat-docker-module-monitoring-windows-container/210596 "2019-12-04T21:49:36Z")

</div>

Hello, I try to setup monitoring for windows based docker containers. I already read all I can find on the net and windows containers are not really supported. Tested with: Elasticsearch 7.4.2 MetricBeat 7.5 Dock…

---

## [Metricbeat aws cpu total pct missing](https://discuss.elastic.co/t/metricbeat-aws-cpu-total-pct-missing/209723)

<div class="topic-metadata">

**Author:** [@Vinicios\_Grein](https://discuss.elastic.co/u/Vinicios_Grein)\
**Replies:** 20\
**Last updated:** [December 4, 2019, 9:28pm UTC](https://discuss.elastic.co/t/metricbeat-aws-cpu-total-pct-missing/209723 "2019-12-04T21:28:50Z")

</div>

Hi, I've configurated aws metricbeat on kibana and have some machines on there, about 20. Only 3 of them don't register the field aws.ec2.cpu.total.pct, all the others yes. Are there some configuration on aws or on a …

---

## [Aws cloudwatch metricset is sampling data -- can it import data exactly?](https://discuss.elastic.co/t/aws-cloudwatch-metricset-is-sampling-data-can-it-import-data-exactly/210085)

<div class="topic-metadata">

**Author:** [@cmr.paul.wilkinson](https://discuss.elastic.co/u/cmr.paul.wilkinson)\
**Replies:** 2\
**Last updated:** [December 4, 2019, 9:17pm UTC](https://discuss.elastic.co/t/aws-cloudwatch-metricset-is-sampling-data-can-it-import-data-exactly/210085 "2019-12-04T21:17:46Z")

</div>

Hello, I would like to ship all my AWS CloudWatch metrics from one of my AWS accounts to Elasticsearch. I have installed Metricbeat 7.4.2 and configured the aws module’s “cloudwatch” metricset like so: - module: aws …

---

## [Field \[raw\_date\] not present as part of path \[\_temp\_.raw\_date\]](https://discuss.elastic.co/t/field-raw-date-not-present-as-part-of-path-temp-raw-date/210525)

<div class="topic-metadata">

**Author:** [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Replies:** 0\
**Last updated:** [December 4, 2019, 11:54am UTC](https://discuss.elastic.co/t/field-raw-date-not-present-as-part-of-path-temp-raw-date/210525 "2019-12-04T11:54:26Z")

</div>

Hi all, using Filebeat 7.5.0 and the cisco module. Every Document got the error.message field \[raw\_date\] not present as part of path \[\_temp\_.raw\_date\]. I have imported the pipelines and the mapping via the filebeat cl…

---

## [Configure filebeat docker metadata](https://discuss.elastic.co/t/configure-filebeat-docker-metadata/210477)

<div class="topic-metadata">

**Author:** [@duclm2609](https://discuss.elastic.co/u/duclm2609)\
**Replies:** 0\
**Last updated:** [December 4, 2019, 6:59am UTC](https://discuss.elastic.co/t/configure-filebeat-docker-metadata/210477 "2019-12-04T06:59:23Z")

</div>

Hi all, Here is my scenario: I have 2 container of the same application running on 2 different server. On each server, I also have a filebeat (running inside a container) to harvest log (which is located on mounted volu…

---

## [Filebeat default dashboard is not loading through logstash log injest](https://discuss.elastic.co/t/filebeat-default-dashboard-is-not-loading-through-logstash-log-injest/209388)

<div class="topic-metadata">

**Author:** [@Rmodi](https://discuss.elastic.co/u/Rmodi)\
**Replies:** 5\
**Last updated:** [December 3, 2019, 7:27pm UTC](https://discuss.elastic.co/t/filebeat-default-dashboard-is-not-loading-through-logstash-log-injest/209388 "2019-12-03T19:27:08Z")

</div>

Hi, First, I have injected my filebeat log to elsticsearch by logstash. It shows me the logs in kibana as well, manually I can even created a metric count for login attempts successfully. However, after then I enable t…

---

## [Winlogbeat ILM and logstash](https://discuss.elastic.co/t/winlogbeat-ilm-and-logstash/210404)

<div class="topic-metadata">

**Author:** [@tomrade](https://discuss.elastic.co/u/tomrade)\
**Replies:** 2\
**Last updated:** [December 3, 2019, 6:25pm UTC](https://discuss.elastic.co/t/winlogbeat-ilm-and-logstash/210404 "2019-12-03T18:25:07Z")

</div>

Hey everyone ive been having issues getting ILM to work with winlogbeat and logstash I don't have ES access for winlogbeat and I dont want to create a seperate windows vm (in my container lab) just to setup ILM First …

---

## [Metricbeat 7.3.0 add\_host\_metadata](https://discuss.elastic.co/t/metricbeat-7-3-0-add-host-metadata/210384)

<div class="topic-metadata">

**Author:** [@raged](https://discuss.elastic.co/u/raged)\
**Replies:** 3\
**Last updated:** [December 3, 2019, 4:35pm UTC](https://discuss.elastic.co/t/metricbeat-7-3-0-add-host-metadata/210384 "2019-12-03T16:35:27Z")

</div>

I am trying to implement a way to get host meta data pushed from my clients. I have followed this link, however I do not see any fields get added to the event. Here is my current metricbeat.yml configuration file: #==…

---

## [Filebeat 7.4.1 PODs of k8s daemonset constantly crash](https://discuss.elastic.co/t/filebeat-7-4-1-pods-of-k8s-daemonset-constantly-crash/205649)

<div class="topic-metadata">

**Author:** [@makoch](https://discuss.elastic.co/u/makoch)\
**Replies:** 6\
**Last updated:** [December 3, 2019, 1:08pm UTC](https://discuss.elastic.co/t/filebeat-7-4-1-pods-of-k8s-daemonset-constantly-crash/205649 "2019-12-03T13:08:15Z")

</div>

I'm trying to use filebeat in my k8s cluster to forward logs to a dedicated self-hosted elasticsearch instance. Following the documentation here ( https://www.elastic.co/guide/en/beats/filebeat/current/running-on-kubern…

---

## [Winlogbeat can't setup dashboard](https://discuss.elastic.co/t/winlogbeat-cant-setup-dashboard/210324)

<div class="topic-metadata">

**Author:** [@onelaseth](https://discuss.elastic.co/u/onelaseth)\
**Replies:** 0\
**Last updated:** [December 3, 2019, 10:17am UTC](https://discuss.elastic.co/t/winlogbeat-cant-setup-dashboard/210324 "2019-12-03T10:17:47Z")

</div>

Hi, I am trying to get winlogbeat to work on a windows server. My config is: ###################### Winlogbeat Configuration Example ######################## This file is an example configuration file highlighting on…

---

## [Filebeat startup errors and source issue](https://discuss.elastic.co/t/filebeat-startup-errors-and-source-issue/210240)

<div class="topic-metadata">

**Author:** [@Cdnvballer](https://discuss.elastic.co/u/Cdnvballer)\
**Replies:** 2\
**Last updated:** [December 3, 2019, 1:13am UTC](https://discuss.elastic.co/t/filebeat-startup-errors-and-source-issue/210240 "2019-12-03T01:13:15Z")

</div>

current state: elk 6.8.5 setup, which seems to be parsing and visualizing... however: /etc/filebeat/filebeat.yml has the following ; I only want filebeat to look at 1 logfile (/var/log/network): "- type: log - /var/…

---

## [Setting up multiple ILM policies on a filebeat with multiple indices as its output](https://discuss.elastic.co/t/setting-up-multiple-ilm-policies-on-a-filebeat-with-multiple-indices-as-its-output/210263)

<div class="topic-metadata">

**Author:** [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Replies:** 0\
**Last updated:** [December 3, 2019, 12:40am UTC](https://discuss.elastic.co/t/setting-up-multiple-ilm-policies-on-a-filebeat-with-multiple-indices-as-its-output/210263 "2019-12-03T00:40:48Z")

</div>

I've been trying to set up ILM policies on a filebeat which has a module enabled for additional data source to process. So, I'll need to apply two different policies to two different indexes on the same filebeat. ILM po…

---

## [Metric beat output to database](https://discuss.elastic.co/t/metric-beat-output-to-database/206611)

<div class="topic-metadata">

**Author:** [@Narinder\_Tiwari](https://discuss.elastic.co/u/Narinder_Tiwari)\
**Replies:** 1\
**Last updated:** [December 2, 2019, 11:07pm UTC](https://discuss.elastic.co/t/metric-beat-output-to-database/206611 "2019-12-02T23:07:53Z")

</div>

Hi, We are using the metric beats to load the the log file form server. Our requirement is to load the log data into the database ( i.e my sql , SQL Server ) . Once data is loaded to database, we will make some adjustme…

---

## [Metricbeat Windows Not Finding any file systems to report. "The system cannot find the file specified."](https://discuss.elastic.co/t/metricbeat-windows-not-finding-any-file-systems-to-report-the-system-cannot-find-the-file-specified/206316)

<div class="topic-metadata">

**Author:** [@sdf301](https://discuss.elastic.co/u/sdf301)\
**Replies:** 2\
**Last updated:** [December 2, 2019, 11:06pm UTC](https://discuss.elastic.co/t/metricbeat-windows-not-finding-any-file-systems-to-report-the-system-cannot-find-the-file-specified/206316 "2019-12-02T23:06:39Z")

</div>

I am trying to install it on a Windows system (Windows 10 Pro). I got the service to start running and it's even sending output over to Kibana. Unfortunately, it isn't finding any file systems to report on. E, L, K, & M…

---

## [System-network-in-bytes-dropped - timeframe](https://discuss.elastic.co/t/system-network-in-bytes-dropped-timeframe/209877)

<div class="topic-metadata">

**Author:** [@kafe](https://discuss.elastic.co/u/kafe)\
**Replies:** 1\
**Last updated:** [December 2, 2019, 11:05pm UTC](https://discuss.elastic.co/t/system-network-in-bytes-dropped-timeframe/209877 "2019-12-02T23:05:29Z")

</div>

Can you please give me an exact timeframe during which the system-network data was collected in this example? https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-system-network.html { "@timest…

---

## ["host.name" value ignored by metricbeat arbitrarily](https://discuss.elastic.co/t/host-name-value-ignored-by-metricbeat-arbitrarily/208675)

<div class="topic-metadata">

**Author:** [@Brinckerkoff](https://discuss.elastic.co/u/Brinckerkoff)\
**Replies:** 1\
**Last updated:** [December 2, 2019, 10:56pm UTC](https://discuss.elastic.co/t/host-name-value-ignored-by-metricbeat-arbitrarily/208675 "2019-12-02T22:56:35Z")

</div>

Hi everyone, I'm experiencing an unexpected behaviour from metricbeat in some hosts: despite specifying a "host.name" in the "name" field in the metricbeat.yml configuration file, the beat overwrites this value with the…

---

## [Unable to set host header using standard HTTP options](https://discuss.elastic.co/t/unable-to-set-host-header-using-standard-http-options/210212)

<div class="topic-metadata">

**Author:** [@robcrawford](https://discuss.elastic.co/u/robcrawford)\
**Replies:** 1\
**Last updated:** [December 2, 2019, 10:20pm UTC](https://discuss.elastic.co/t/unable-to-set-host-header-using-standard-http-options/210212 "2019-12-02T22:20:29Z")

</div>

Hello! I'm using the prometheus metricbeat module and i'm trying to set the "Host" HTTP header for my target server. I'm using the standard http options to modify the headers. Here's a snippet of my config: - module: …

---

## [Getting "failed to parse field \[response.body\] of type \[keyword\] in document..."](https://discuss.elastic.co/t/getting-failed-to-parse-field-response-body-of-type-keyword-in-document/210196)

<div class="topic-metadata">

**Author:** [@zhelezovas](https://discuss.elastic.co/u/zhelezovas)\
**Replies:** 0\
**Last updated:** [December 2, 2019, 2:16pm UTC](https://discuss.elastic.co/t/getting-failed-to-parse-field-response-body-of-type-keyword-in-document/210196 "2019-12-02T14:16:55Z")

</div>

Hello, I'm trying to parse json logs with filebeat processor. In general it works fine, but sometimes I get "failed to parse field \[response.body\] of type \[keyword\] in document..." error. This is my filebeat config file…

---

## [Error while initializing input: No paths were defined for input accessing](https://discuss.elastic.co/t/error-while-initializing-input-no-paths-were-defined-for-input-accessing/210166)

<div class="topic-metadata">

**Author:** [@Dutchess\_Nicole](https://discuss.elastic.co/u/Dutchess_Nicole)\
**Replies:** 1\
**Last updated:** [December 2, 2019, 2:11pm UTC](https://discuss.elastic.co/t/error-while-initializing-input-no-paths-were-defined-for-input-accessing/210166 "2019-12-02T14:11:30Z")

</div>

strange error with getting filebeat to work with the mysql module Hi, I've been trying to get a filebeat running in order to parse a mysql slow log. According to the tutorials online one simply has to configure the file…

---

## [Help with Winlogbeat yaml config](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041)

<div class="topic-metadata">

**Author:** [@xxstyler20xx](https://discuss.elastic.co/u/xxstyler20xx)\
**Replies:** 6\
**Last updated:** [December 2, 2019, 1:56pm UTC](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041 "2019-12-02T13:56:56Z")

</div>

Hello I'm new to this and I just can't find the rigt answer for my problem.. I'm stuck with my winlogbeat yaml conf. // event\_logs: name: Security event\_id: 4625, 4624 processors: drop\_fields: fields: \["message"\] …

---

## [Filebeat won't load input](https://discuss.elastic.co/t/filebeat-wont-load-input/210181)

<div class="topic-metadata">

**Author:** [@Sams](https://discuss.elastic.co/u/Sams)\
**Replies:** 0\
**Last updated:** [December 2, 2019, 12:34pm UTC](https://discuss.elastic.co/t/filebeat-wont-load-input/210181 "2019-12-02T12:34:09Z")

</div>

filebeat parse my input to logstash and logstash parse it to elastic. but filebeat loading inouts =0. this is my filebeat.yaml filebeat.config.modules: path: "${path.config}/modules.d/\*.yml" reload.enabled: true …

---

## [Future of Journalbeat](https://discuss.elastic.co/t/future-of-journalbeat/210176)

<div class="topic-metadata">

**Author:** [@hrak](https://discuss.elastic.co/u/hrak)\
**Replies:** 0\
**Last updated:** [December 2, 2019, 12:09pm UTC](https://discuss.elastic.co/t/future-of-journalbeat/210176 "2019-12-02T12:09:43Z")

</div>

Journalbeat is currently still marked as experimental/"this might disappear at some point". Is Journalbeat planned to be marked stable/official any time soon? I am currently at a point where i have to choose between usi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=293)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=295)
