# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=295

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 296

---

## [How to get monitoring data over Kafka?](https://discuss.elastic.co/t/how-to-get-monitoring-data-over-kafka/210131)

<div class="topic-metadata">

**Author:** [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Replies:** 0\
**Last updated:** [December 2, 2019, 7:58am UTC](https://discuss.elastic.co/t/how-to-get-monitoring-data-over-kafka/210131 "2019-12-02T07:58:37Z")

</div>

Hi all, in a DMZ, the beats are sending their data to a Kafka. Logstash is getting this data from the internal net out of Kafka. So the beats are not able to connect to elasticsearch itself. How do I get the beat's mon…

---

## [Packetbeat cannot capture redis command CONFIG GET](https://discuss.elastic.co/t/packetbeat-cannot-capture-redis-command-config-get/209917)

<div class="topic-metadata">

**Author:** [@mazhechao](https://discuss.elastic.co/u/mazhechao)\
**Replies:** 2\
**Last updated:** [December 1, 2019, 10:57am UTC](https://discuss.elastic.co/t/packetbeat-cannot-capture-redis-command-config-get/209917 "2019-12-01T10:57:30Z")

</div>

Packetbeat cannot capture redis command CONFIG GET \* This command is incorrectly handled as response. Packetbeat version 7.4.2 (amd64), libbeat 7.4.2 \[15075156388b44390301f070960fd8aeac1c9712 built 2019-10-28 19:33:55…

---

## [Winlogbeat proxy support](https://discuss.elastic.co/t/winlogbeat-proxy-support/206151)

<div class="topic-metadata">

**Author:** [@Ixus223](https://discuss.elastic.co/u/Ixus223)\
**Replies:** 4\
**Last updated:** [November 30, 2019, 9:04am UTC](https://discuss.elastic.co/t/winlogbeat-proxy-support/206151 "2019-11-30T09:04:12Z")

</div>

Hi, I 'm currently using latest version of winlogbeat 7.4.1 to send data to an ELK stack. It works well when computer has a direct connection to internet but it doesn't with a proxy. When i add proxy parameter in winl…

---

## [Unwanted truncating of multiline message](https://discuss.elastic.co/t/unwanted-truncating-of-multiline-message/206872)

<div class="topic-metadata">

**Author:** [@Bhozar](https://discuss.elastic.co/u/Bhozar)\
**Replies:** 9\
**Last updated:** [November 29, 2019, 10:15pm UTC](https://discuss.elastic.co/t/unwanted-truncating-of-multiline-message/206872 "2019-11-29T22:15:46Z")

</div>

I'm having an issue with an XML log file being ingested by Filebeat and some of the messages being passed onto Logstash with the opening tag truncated. There's no pattern to the failures that I can spot and works 95% of …

---

## [How to enable beats monitoring using the central management console](https://discuss.elastic.co/t/how-to-enable-beats-monitoring-using-the-central-management-console/209684)

<div class="topic-metadata">

**Author:** [@ankitsynX](https://discuss.elastic.co/u/ankitsynX)\
**Replies:** 2\
**Last updated:** [November 29, 2019, 5:48pm UTC](https://discuss.elastic.co/t/how-to-enable-beats-monitoring-using-the-central-management-console/209684 "2019-11-29T17:48:07Z")

</div>

Dear All, I am unable to find any relevant instructions on how to enable monitoring of beats that are enrolled in central management. I have tried adding the monitoring configuration in the output section of tags. But …

---

## [Filebeat module for modsecurity v3](https://discuss.elastic.co/t/filebeat-module-for-modsecurity-v3/209987)

<div class="topic-metadata">

**Author:** [@matthijs42](https://discuss.elastic.co/u/matthijs42)\
**Replies:** 0\
**Last updated:** [November 29, 2019, 4:09pm UTC](https://discuss.elastic.co/t/filebeat-module-for-modsecurity-v3/209987 "2019-11-29T16:09:10Z")

</div>

Hi, I'm trying to write a new filebeat module for modsecurity v3. I followed the tutorial on the website (https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html) but I am stuck on 'create…

---

## [Host Count Not Reflecting In Kibana Dashboard](https://discuss.elastic.co/t/host-count-not-reflecting-in-kibana-dashboard/209941)

<div class="topic-metadata">

**Author:** [@KamleshKushwahaaa](https://discuss.elastic.co/u/KamleshKushwahaaa)\
**Replies:** 0\
**Last updated:** [November 29, 2019, 8:39am UTC](https://discuss.elastic.co/t/host-count-not-reflecting-in-kibana-dashboard/209941 "2019-11-29T08:39:58Z")

</div>

Hi, We had added 50 desktop machines (Windows 7 Pro), to Kibana after installing winlogbeat service on all those machines, many times 33 to 40 machines reflects in Kibana dashboard (but not all 50 machines. Count gets i…

---

## [Howto filter logs for Facility and Priority](https://discuss.elastic.co/t/howto-filter-logs-for-facility-and-priority/209573)

<div class="topic-metadata">

**Author:** [@robur314](https://discuss.elastic.co/u/robur314)\
**Replies:** 1\
**Last updated:** [November 29, 2019, 1:31pm UTC](https://discuss.elastic.co/t/howto-filter-logs-for-facility-and-priority/209573 "2019-11-29T13:31:30Z")

</div>

Hi all, I'm evaluating filebeat version 7.4.2 with elasticsearch (same version) and the system module. How can I filter the the log messages for facility and priority fields? Can I tweak/configure the filebeat syste…

---

## [Packetbeat support for AMQP 1.0](https://discuss.elastic.co/t/packetbeat-support-for-amqp-1-0/209933)

<div class="topic-metadata">

**Author:** [@xfgeek](https://discuss.elastic.co/u/xfgeek)\
**Replies:** 0\
**Last updated:** [November 29, 2019, 7:22am UTC](https://discuss.elastic.co/t/packetbeat-support-for-amqp-1-0/209933 "2019-11-29T07:22:08Z")

</div>

Hi, Packetbeat currently supports 0.9.1 version of AMQP. Please can the support be added for 1.0 version of AMQP. Thanks, Vishnu.

---

## [Elastic SIEM integration with Palo Alto Network FIrewall](https://discuss.elastic.co/t/elastic-siem-integration-with-palo-alto-network-firewall/209929)

<div class="topic-metadata">

**Author:** [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Replies:** 0\
**Last updated:** [November 29, 2019, 6:54am UTC](https://discuss.elastic.co/t/elastic-siem-integration-with-palo-alto-network-firewall/209929 "2019-11-29T06:54:50Z")

</div>

Hi Team, We are integrating Palo Alto Firewall device with Elastic siem. For this we have enabled firewall data on 514 and receiving the same. We want to use the ECS mapping for auto population of SIEM dashboard At fil…

---

## [Unable to harvest /var/log/container for filebeat 6.7.0 version](https://discuss.elastic.co/t/unable-to-harvest-var-log-container-for-filebeat-6-7-0-version/209811)

<div class="topic-metadata">

**Author:** [@abhinav.bhagat](https://discuss.elastic.co/u/abhinav.bhagat)\
**Replies:** 1\
**Last updated:** [November 29, 2019, 4:26am UTC](https://discuss.elastic.co/t/unable-to-harvest-var-log-container-for-filebeat-6-7-0-version/209811 "2019-11-29T04:26:23Z")

</div>

Hello Team, I am facing similar issue like https://discuss.elastic.co/t/filebeat-and-kubernetes-excluding-log-files/117837/12 but for filebeat 6.7.0. I am installing it using helm chart. Earlier it was 7.0.1 which wa…

---

## [Fingerprint processor in filebeat and winlogbeat?](https://discuss.elastic.co/t/fingerprint-processor-in-filebeat-and-winlogbeat/209883)

<div class="topic-metadata">

**Author:** [@bjosve](https://discuss.elastic.co/u/bjosve)\
**Replies:** 1\
**Last updated:** [November 28, 2019, 4:05pm UTC](https://discuss.elastic.co/t/fingerprint-processor-in-filebeat-and-winlogbeat/209883 "2019-11-28T16:05:43Z")

</div>

Hi, Any idea in which version of filebeat and winlogbeat the fingerprint processor will be available? Is it anyway I can use it today? Thanks.

---

## [Non timeseries beat indexes](https://discuss.elastic.co/t/non-timeseries-beat-indexes/209725)

<div class="topic-metadata">

**Author:** [@Blake\_Wills](https://discuss.elastic.co/u/Blake_Wills)\
**Replies:** 1\
**Last updated:** [November 28, 2019, 4:04pm UTC](https://discuss.elastic.co/t/non-timeseries-beat-indexes/209725 "2019-11-28T16:04:04Z")

</div>

Is it possible to setup beats (auditbeat / metricbeat / winlogbeat) to not use timeseries indexes? I've orderridden the index name in the respective config files but the template (via \[beat\].exe setup - manual loading) …

---

## [Unable to send logs from filebeat to elastic output](https://discuss.elastic.co/t/unable-to-send-logs-from-filebeat-to-elastic-output/209553)

<div class="topic-metadata">

**Author:** [@prasad\_elk](https://discuss.elastic.co/u/prasad_elk)\
**Replies:** 1\
**Last updated:** [November 28, 2019, 3:19pm UTC](https://discuss.elastic.co/t/unable-to-send-logs-from-filebeat-to-elastic-output/209553 "2019-11-28T15:19:10Z")

</div>

Hi Team, we have production environment where we are getting below error while filebeat is sending logs to Elastic output, so kindly help us in getting resolve this issue. 2019-11-26T08:59:14.977Z ERROR elasti…

---

## [Filebeat setup encounters bad json, but doesn't tell me what the problem is?](https://discuss.elastic.co/t/filebeat-setup-encounters-bad-json-but-doesnt-tell-me-what-the-problem-is/209119)

<div class="topic-metadata">

**Author:** [@krainboltgreene](https://discuss.elastic.co/u/krainboltgreene)\
**Replies:** 2\
**Last updated:** [November 28, 2019, 3:14pm UTC](https://discuss.elastic.co/t/filebeat-setup-encounters-bad-json-but-doesnt-tell-me-what-the-problem-is/209119 "2019-11-28T15:14:25Z")

</div>

---

## [Understand Filebeat in Docker](https://discuss.elastic.co/t/understand-filebeat-in-docker/209323)

<div class="topic-metadata">

**Author:** [@iamoric](https://discuss.elastic.co/u/iamoric)\
**Replies:** 2\
**Last updated:** [November 28, 2019, 3:12pm UTC](https://discuss.elastic.co/t/understand-filebeat-in-docker/209323 "2019-11-28T15:12:44Z")

</div>

Hi, I would like to run Filebeat in Docker with mouting volume. I followed the documentation (https://www.elastic.co/guide/en/beats/filebeat/7.4/running-on-docker.html#\_volume\_mounted\_configuration) and it works fine, …

---

## [Beat can receiver data from kibana or not?](https://discuss.elastic.co/t/beat-can-receiver-data-from-kibana-or-not/209264)

<div class="topic-metadata">

**Author:** [@Fent](https://discuss.elastic.co/u/Fent)\
**Replies:** 1\
**Last updated:** [November 28, 2019, 3:12pm UTC](https://discuss.elastic.co/t/beat-can-receiver-data-from-kibana-or-not/209264 "2019-11-28T15:12:20Z")

</div>

I want to add some button on kibana to send command to beat(like filebeat) ,to control the beat to start to collect log or stop collect , I want to know if there have some API to handle communication between kibana a…

---

## [Error decoding JSON: invalid character '\\x00' looking for beginning of value](https://discuss.elastic.co/t/error-decoding-json-invalid-character-x00-looking-for-beginning-of-value/209571)

<div class="topic-metadata">

**Author:** [@gstrickl](https://discuss.elastic.co/u/gstrickl)\
**Replies:** 1\
**Last updated:** [November 28, 2019, 3:08pm UTC](https://discuss.elastic.co/t/error-decoding-json-invalid-character-x00-looking-for-beginning-of-value/209571 "2019-11-28T15:08:35Z")

</div>

Hello, I am new to elastic filebeat and need some assistance with an error. We wrote a powershell script to pull down Office 365 audit logs and write them out to CSV files. These records also include a field that cont…

---

## [Filebeat not parsing json correctly](https://discuss.elastic.co/t/filebeat-not-parsing-json-correctly/209863)

<div class="topic-metadata">

**Author:** [@Sreekanth\_Ragi](https://discuss.elastic.co/u/Sreekanth_Ragi)\
**Replies:** 0\
**Last updated:** [November 28, 2019, 1:18pm UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-correctly/209863 "2019-11-28T13:18:31Z")

</div>

Team, I have multiline message that is a json, I have tried parsing it using the multi line filter, though the below filter parses it all correctly except for the closing '}'. Any ideas on what I'm doing wrong. I know o…

---

## [Add custom fields in Metricbeat](https://discuss.elastic.co/t/add-custom-fields-in-metricbeat/209285)

<div class="topic-metadata">

**Author:** [@SunilSMenon](https://discuss.elastic.co/u/SunilSMenon)\
**Replies:** 3\
**Last updated:** [November 28, 2019, 11:01am UTC](https://discuss.elastic.co/t/add-custom-fields-in-metricbeat/209285 "2019-11-28T11:01:30Z")

</div>

Hi, Can anyone help me to know how to add custom fields in Metricbeat. Requirement : While configuring Metricbeat for one server I want to add the Server Owner & Server Environment for that server. So that in Kibana we…

---

## [ELK on Windows Server 2016 with Filebeat on Windows 10 client - problems](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667)

<div class="topic-metadata">

**Author:** [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Replies:** 6\
**Last updated:** [November 28, 2019, 10:33am UTC](https://discuss.elastic.co/t/elk-on-windows-server-2016-with-filebeat-on-windows-10-client-problems/209667 "2019-11-28T10:33:09Z")

</div>

Hello, I've setup ELK 7.4.2 on Windows Server 2016, with some of these references: http://robwillis.info/2019/05/installing-elk-7-elasticsearch-logstash-and-kibana-windows-server-2016/ and I've setup Filebeat on…

---

## [Cannot index event publisher.Event ... Can't get text on a START\_OBJECT](https://discuss.elastic.co/t/cannot-index-event-publisher-event-cant-get-text-on-a-start-object/207859)

<div class="topic-metadata">

**Author:** [@tkzv](https://discuss.elastic.co/u/tkzv)\
**Replies:** 3\
**Last updated:** [November 27, 2019, 4:11pm UTC](https://discuss.elastic.co/t/cannot-index-event-publisher-event-cant-get-text-on-a-start-object/207859 "2019-11-27T16:11:00Z")

</div>

I'm trying to collect data from Kubernetes cluster using Metricbeat and Kube-state-metrics. My configuration is the same as https://raw.githubusercontent.com/elastic/beats/7.3/deploy/kubernetes/metricbeat-kubernetes.yaml …

---

## [How to use the timestamp of the original logs in winlogbets?](https://discuss.elastic.co/t/how-to-use-the-timestamp-of-the-original-logs-in-winlogbets/209645)

<div class="topic-metadata">

**Author:** [@jogoinar10](https://discuss.elastic.co/u/jogoinar10)\
**Replies:** 2\
**Last updated:** [November 28, 2019, 3:42am UTC](https://discuss.elastic.co/t/how-to-use-the-timestamp-of-the-original-logs-in-winlogbets/209645 "2019-11-28T03:42:37Z")

</div>

I'm using winlogbeat to transfer data logs from event viewer. However, I have a problem with the timestamp. I'm not sure if it carry over the timestamp from the original log. Or is it overwriting during the indexing of d…

---

## [Filebeat to match IIS logs timestamp](https://discuss.elastic.co/t/filebeat-to-match-iis-logs-timestamp/209565)

<div class="topic-metadata">

**Author:** [@alexserd](https://discuss.elastic.co/u/alexserd)\
**Replies:** 2\
**Last updated:** [November 27, 2019, 6:27pm UTC](https://discuss.elastic.co/t/filebeat-to-match-iis-logs-timestamp/209565 "2019-11-27T18:27:21Z")

</div>

Currently @timestamp is showing as a time when logs get ingested. We need to match it with timestamp from IIS logs. Here is our ingest default.json from filebeat { "description": "Pipeline for parsing IIS access logs. …

---

## [When or how often does setup need to be done?](https://discuss.elastic.co/t/when-or-how-often-does-setup-need-to-be-done/209743)

<div class="topic-metadata">

**Author:** [@joberly](https://discuss.elastic.co/u/joberly)\
**Replies:** 0\
**Last updated:** [November 27, 2019, 6:10pm UTC](https://discuss.elastic.co/t/when-or-how-often-does-setup-need-to-be-done/209743 "2019-11-27T18:10:23Z")

</div>

In reference to setup of any of the Beats, but specifically Filebeat (e.g. filebeat setup -e, see https://www.elastic.co/guide/en/beats/filebeat/7.4/load-kibana-dashboards.html), how often should setup be run? Is this on…

---

## [Querying Service Status](https://discuss.elastic.co/t/querying-service-status/209733)

<div class="topic-metadata">

**Author:** [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Replies:** 0\
**Last updated:** [November 27, 2019, 5:08pm UTC](https://discuss.elastic.co/t/querying-service-status/209733 "2019-11-27T17:08:50Z")

</div>

Hello, I want to monitor that a service is up and running, using the HTTP module of MetricBeat, using the hostname and port for that service. It finds the host IP, but I keep getting the following error: error making …

---

## [Monitor APIs using MetricsBeat](https://discuss.elastic.co/t/monitor-apis-using-metricsbeat/209386)

<div class="topic-metadata">

**Author:** [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Replies:** 3\
**Last updated:** [November 27, 2019, 4:54pm UTC](https://discuss.elastic.co/t/monitor-apis-using-metricsbeat/209386 "2019-11-27T16:54:23Z")

</div>

Hello, I would like to monitor an API call from ES and Kibana. The HTTP module in MetricBeat seems like the most logical choice. I have installed it, and I see that it is writing to ES. However, I am having issues co…

---

## [Unexpected state reading file(cannot allocate memory)](https://discuss.elastic.co/t/unexpected-state-reading-file-cannot-allocate-memory/209446)

<div class="topic-metadata">

**Author:** [@msunilreddy](https://discuss.elastic.co/u/msunilreddy)\
**Replies:** 2\
**Last updated:** [November 27, 2019, 3:59pm UTC](https://discuss.elastic.co/t/unexpected-state-reading-file-cannot-allocate-memory/209446 "2019-11-27T15:59:58Z")

</div>

Hi, I am getting below error when I start filebeat. It was working fine from past one month. Suddenly my filebeat container exited with OOM killed error. I am using filebeat 6.7.2 version. 2019-11-25T22:05:42.769-0…

---

## [Mapping Conflict between modules](https://discuss.elastic.co/t/mapping-conflict-between-modules/209707)

<div class="topic-metadata">

**Author:** [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Replies:** 0\
**Last updated:** [November 27, 2019, 2:49pm UTC](https://discuss.elastic.co/t/mapping-conflict-between-modules/209707 "2019-11-27T14:49:52Z")

</div>

Hi all, I am just testing Elastic Stack 7.4.2 with SIEM. I am using Filebeat module system and cisco. When using "filebeat-\*" as index pattern, kibana tells me, that there is a mapping conflict. The conflicting field …

---

## [Filebeat, ship logs raw](https://discuss.elastic.co/t/filebeat-ship-logs-raw/209536)

<div class="topic-metadata">

**Author:** [@gborg](https://discuss.elastic.co/u/gborg)\
**Replies:** 1\
**Last updated:** [November 27, 2019, 2:09pm UTC](https://discuss.elastic.co/t/filebeat-ship-logs-raw/209536 "2019-11-27T14:09:34Z")

</div>

Hello, I am wondering if there is an option to have filebeat only send the data it collects, not all the fields it adds itself like agent, ecs, etc My problem is that due to filebeat setting host.name, it overwrites my …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=294)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=296)
