# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=296

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 297

---

## [Filebeat for logs that send once every couple days](https://discuss.elastic.co/t/filebeat-for-logs-that-send-once-every-couple-days/209370)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 3\
**Last updated:** [November 27, 2019, 2:08pm UTC](https://discuss.elastic.co/t/filebeat-for-logs-that-send-once-every-couple-days/209370 "2019-11-27T14:08:35Z")

</div>

Hi, I'm running into some issues with logs I'm shipping with filebeat to logstash. I'm not quite sure what the issue is, but the file with the logs only refreshes once a day or once every two days with one or two lines …

---

## [Windows protected event logging format](https://discuss.elastic.co/t/windows-protected-event-logging-format/209680)

<div class="topic-metadata">

**Author:** [@kinomakino](https://discuss.elastic.co/u/kinomakino)\
**Replies:** 0\
**Last updated:** [November 27, 2019, 12:41pm UTC](https://discuss.elastic.co/t/windows-protected-event-logging-format/209680 "2019-11-27T12:41:28Z")

</div>

First of all, thanks for the help. We are considering using PEL to protect Windows logs and we don't know very well how to do the decryption process to incorporate the logs into ELK using Logstash and winlogbeat. Thank…

---

## [Packetbeat can't decode PPPoE packet](https://discuss.elastic.co/t/packetbeat-cant-decode-pppoe-packet/209679)

<div class="topic-metadata">

**Author:** [@tlittirut](https://discuss.elastic.co/u/tlittirut)\
**Replies:** 0\
**Last updated:** [November 27, 2019, 12:39pm UTC](https://discuss.elastic.co/t/packetbeat-cant-decode-pppoe-packet/209679 "2019-11-27T12:39:03Z")

</div>

Hi ELK Community, I'm trying to setup a packetbeat for troubleshooting spam attacking. However, I could not find the packet that encapsulated with PPPoE header in kibana which shows only normal IP packets and Flows wit…

---

## [How to get Data to Kibana 7.4 Display (uptime-heartbeat 7.4) on centOS 7?](https://discuss.elastic.co/t/how-to-get-data-to-kibana-7-4-display-uptime-heartbeat-7-4-on-centos-7/207845)

<div class="topic-metadata">

**Author:** [@Nuttapon\_Sangjumpa](https://discuss.elastic.co/u/Nuttapon_Sangjumpa)\
**Replies:** 4\
**Last updated:** [November 27, 2019, 9:29am UTC](https://discuss.elastic.co/t/how-to-get-data-to-kibana-7-4-display-uptime-heartbeat-7-4-on-centos-7/207845 "2019-11-27T09:29:30Z")

</div>

Get Data from heartbeat but can't show uptime in below :slight\_smile:

---

## [Using Filebeat with AWS ES with ingest-geoip disabled](https://discuss.elastic.co/t/using-filebeat-with-aws-es-with-ingest-geoip-disabled/209546)

<div class="topic-metadata">

**Author:** [@chiemeleakoma](https://discuss.elastic.co/u/chiemeleakoma)\
**Replies:** 2\
**Last updated:** [November 27, 2019, 5:38am UTC](https://discuss.elastic.co/t/using-filebeat-with-aws-es-with-ingest-geoip-disabled/209546 "2019-11-27T05:38:24Z")

</div>

I have setup filebeat with basic config as a proof of concept. After starting the service, i couldnt see any logs ingested by ES, but filebeat error log shows: 2019-11-26T15:56:28.174Z ERROR pipeline/output.go:100 Faile…

---

## [I have two Machine, one has elastic, Logstash and kibana and other pc has filebeat, in one PC ELK stack is up and when i start filebeat to send log to logstasg it is not able to send](https://discuss.elastic.co/t/i-have-two-machine-one-has-elastic-logstash-and-kibana-and-other-pc-has-filebeat-in-one-pc-elk-stack-is-up-and-when-i-start-filebeat-to-send-log-to-logstasg-it-is-not-able-to-send/208805)

<div class="topic-metadata">

**Author:** [@SoniyaGupta](https://discuss.elastic.co/u/SoniyaGupta)\
**Replies:** 2\
**Last updated:** [November 27, 2019, 4:12am UTC](https://discuss.elastic.co/t/i-have-two-machine-one-has-elastic-logstash-and-kibana-and-other-pc-has-filebeat-in-one-pc-elk-stack-is-up-and-when-i-start-filebeat-to-send-log-to-logstasg-it-is-not-able-to-send/208805 "2019-11-27T04:12:57Z")

</div>

it is giving connection Error not able to connect to port. I tried doing telnet for port it did not work. can you please tell me how I can change port to 8080 for logstash and filebeat. Logstash config file input { b…

---

## [Filebeat deployment on private cloud](https://discuss.elastic.co/t/filebeat-deployment-on-private-cloud/209591)

<div class="topic-metadata">

**Author:** [@tomyui](https://discuss.elastic.co/u/tomyui)\
**Replies:** 0\
**Last updated:** [November 27, 2019, 1:29am UTC](https://discuss.elastic.co/t/filebeat-deployment-on-private-cloud/209591 "2019-11-27T01:29:33Z")

</div>

hi~ bros. 3 options of filebeat deployment on private cloud. option A.) installed on OS, 1 filebeat instance per OS host. option B.) installed as a pod service and use daemonset to config 1 filebeat POD service per …

---

## [Manage Fault Tolerance on Heartbeat](https://discuss.elastic.co/t/manage-fault-tolerance-on-heartbeat/205480)

<div class="topic-metadata">

**Author:** [@ea1987](https://discuss.elastic.co/u/ea1987)\
**Replies:** 7\
**Last updated:** [November 26, 2019, 8:44pm UTC](https://discuss.elastic.co/t/manage-fault-tolerance-on-heartbeat/205480 "2019-11-26T20:44:27Z")

</div>

Hi guys, how is that possible to manage FT with this beat? Here is a brief example: Host A: hearbeat\_instance\_1 -\> ping Host C Host B: hearbeat\_instance\_2 -\> ping Host C How can I manage both instances to not perfor…

---

## [Unable to Publish all Events from Packetbeat to Elasticsearch for bursts](https://discuss.elastic.co/t/unable-to-publish-all-events-from-packetbeat-to-elasticsearch-for-bursts/209186)

<div class="topic-metadata">

**Author:** [@dhughes](https://discuss.elastic.co/u/dhughes)\
**Replies:** 2\
**Last updated:** [November 26, 2019, 5:06pm UTC](https://discuss.elastic.co/t/unable-to-publish-all-events-from-packetbeat-to-elasticsearch-for-bursts/209186 "2019-11-26T17:06:32Z")

</div>

I've been characterizing a problem with Packetbeat, configured to directly output to Elasticsearch. I've got the YML configured to use the memory internal queue (not the file spool queue). The problem is, when I burst …

---

## [How to configure s3 input to scale?](https://discuss.elastic.co/t/how-to-configure-s3-input-to-scale/209360)

<div class="topic-metadata">

**Author:** [@Ronin](https://discuss.elastic.co/u/Ronin)\
**Replies:** 2\
**Last updated:** [November 26, 2019, 2:45pm UTC](https://discuss.elastic.co/t/how-to-configure-s3-input-to-scale/209360 "2019-11-26T14:45:40Z")

</div>

We have 3 filebeat instances running with a s3/sqs input. From what I can tell each instance will only pull 10 sqs messages at one time. We are not bottlenecked on cpu or ram, so what do I need to configure for it to pro…

---

## [Filebeat windows docker image](https://discuss.elastic.co/t/filebeat-windows-docker-image/209534)

<div class="topic-metadata">

**Author:** [@sahinguler](https://discuss.elastic.co/u/sahinguler)\
**Replies:** 0\
**Last updated:** [November 26, 2019, 2:40pm UTC](https://discuss.elastic.co/t/filebeat-windows-docker-image/209534 "2019-11-26T14:40:47Z")

</div>

Hi all, Do you have filebeat docker image for windows ?

---

## [Problem. Filebeat 7.4.0 excesive syslog size](https://discuss.elastic.co/t/problem-filebeat-7-4-0-excesive-syslog-size/208291)

<div class="topic-metadata">

**Author:** [@salva](https://discuss.elastic.co/u/salva)\
**Replies:** 20\
**Last updated:** [November 26, 2019, 9:35am UTC](https://discuss.elastic.co/t/problem-filebeat-7-4-0-excesive-syslog-size/208291 "2019-11-26T09:35:41Z")

</div>

Hi. I have a problem with Filebeats 7.4.0. It generates a very large syslog. If I don't stop the service, it would take up all the disk space. Attached configuration (filebeat.yml):

---

## [Not able to convert json string to json object with filebeat TCP input](https://discuss.elastic.co/t/not-able-to-convert-json-string-to-json-object-with-filebeat-tcp-input/208179)

<div class="topic-metadata">

**Author:** [@vaseem](https://discuss.elastic.co/u/vaseem)\
**Replies:** 3\
**Last updated:** [November 26, 2019, 6:37am UTC](https://discuss.elastic.co/t/not-able-to-convert-json-string-to-json-object-with-filebeat-tcp-input/208179 "2019-11-26T06:37:13Z")

</div>

Hi All, I am sending json string(For example {"key1": "value1", "key2":"value2"}) to filebeat-\>elasticsearch-\>kibana using TCP input in filebeat. However I am getting json string under message field on kibana/elasticsea…

---

## [Should deploy filebeat as POD service~~?](https://discuss.elastic.co/t/should-deploy-filebeat-as-pod-service/209267)

<div class="topic-metadata">

**Author:** [@tomyui](https://discuss.elastic.co/u/tomyui)\
**Replies:** 0\
**Last updated:** [November 25, 2019, 9:45am UTC](https://discuss.elastic.co/t/should-deploy-filebeat-as-pod-service/209267 "2019-11-25T09:45:06Z")

</div>

Hi everyone, my organization is use OpenShift with tomcat for hosting application services. I need to use filebeat to monitor server logs & application logs, send to logstash. I have read thru. the doc about deploying…

---

## [Adding geotagging to monitors in heartbeat](https://discuss.elastic.co/t/adding-geotagging-to-monitors-in-heartbeat/208972)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 2\
**Last updated:** [November 25, 2019, 6:17pm UTC](https://discuss.elastic.co/t/adding-geotagging-to-monitors-in-heartbeat/208972 "2019-11-25T18:17:53Z")

</div>

Hello, I am wondering if there is a possibility to add geoTagging to the monitors. For example. If I have a centralized elasticsearch from where I am running heartbeat and I am setting up a monitor for the services that…

---

## [HeartBeat Shows more than 1 line of the same instance](https://discuss.elastic.co/t/heartbeat-shows-more-than-1-line-of-the-same-instance/207949)

<div class="topic-metadata">

**Author:** [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Replies:** 1\
**Last updated:** [November 25, 2019, 6:00pm UTC](https://discuss.elastic.co/t/heartbeat-shows-more-than-1-line-of-the-same-instance/207949 "2019-11-25T18:00:23Z")

</div>

So every time i restart hearbeat then go check kibana i see that it re-indexes ES and Kibana again for some reason, like it would show 2 of each as up and running, but its not supposed to do that, there should be only on…

---

## [Cannot see all Heartbeat monitors I've set up in Kibana](https://discuss.elastic.co/t/cannot-see-all-heartbeat-monitors-ive-set-up-in-kibana/207346)

<div class="topic-metadata">

**Author:** [@kanpeki](https://discuss.elastic.co/u/kanpeki)\
**Replies:** 1\
**Last updated:** [November 25, 2019, 5:58pm UTC](https://discuss.elastic.co/t/cannot-see-all-heartbeat-monitors-ive-set-up-in-kibana/207346 "2019-11-25T17:58:01Z")

</div>

Hello. I'm trying to use heartbeat to monitor a SOAP service. I've written monitors for each method in the service (20 something), but I'm only getting output in Kibana for 9 of those. No errors in the Heartbeat log or a…

---

## [Filebeat logstash number of outgoing tcp connections](https://discuss.elastic.co/t/filebeat-logstash-number-of-outgoing-tcp-connections/209338)

<div class="topic-metadata">

**Author:** [@miksir](https://discuss.elastic.co/u/miksir)\
**Replies:** 0\
**Last updated:** [November 25, 2019, 3:37pm UTC](https://discuss.elastic.co/t/filebeat-logstash-number-of-outgoing-tcp-connections/209338 "2019-11-25T15:37:15Z")

</div>

In loadbalance=true mode number of established tcp connections to each host = worker (so total worker \* hosts) But in loadbalance=false mode - always 1 connection to logstash with any number of workers. 7.4.2 still rep…

---

## [Detect user browser](https://discuss.elastic.co/t/detect-user-browser/209299)

<div class="topic-metadata">

**Author:** [@yasin](https://discuss.elastic.co/u/yasin)\
**Replies:** 1\
**Last updated:** [November 25, 2019, 1:39pm UTC](https://discuss.elastic.co/t/detect-user-browser/209299 "2019-11-25T13:39:21Z")

</div>

Dear Team, We want to have the following: Able to check which browser he is using when user is trying to login. How are we able to find this?

---

## [Drop\_fields or include\_fields dosn't worsk](https://discuss.elastic.co/t/drop-fields-or-include-fields-dosnt-worsk/209049)

<div class="topic-metadata">

**Author:** [@science162](https://discuss.elastic.co/u/science162)\
**Replies:** 3\
**Last updated:** [November 25, 2019, 10:47am UTC](https://discuss.elastic.co/t/drop-fields-or-include-fields-dosnt-worsk/209049 "2019-11-25T10:47:59Z")

</div>

hello, I want to suppress some fields I doesn't use from and event. Neither processor, Nor filters works I don't Know what is the matter I looked for other issue close from that but did'nt find solution. When I use Pr…

---

## [Windows metricbeat service stops at random](https://discuss.elastic.co/t/windows-metricbeat-service-stops-at-random/208452)

<div class="topic-metadata">

**Author:** [@pdeelman](https://discuss.elastic.co/u/pdeelman)\
**Replies:** 5\
**Last updated:** [November 25, 2019, 10:41am UTC](https://discuss.elastic.co/t/windows-metricbeat-service-stops-at-random/208452 "2019-11-25T10:41:26Z")

</div>

Hi, I'm currently deploying my beats for my new cluster and I have the following setup: Metricbeat \> logstash (port 5044) \> elastic. I'm using logstash because I want to introduce a Kafka pipeline, but that isn't impor…

---

## [\[SOLVED\] New installation gives error](https://discuss.elastic.co/t/solved-new-installation-gives-error/209220)

<div class="topic-metadata">

**Author:** [@ericv](https://discuss.elastic.co/u/ericv)\
**Replies:** 1\
**Last updated:** [November 25, 2019, 8:13am UTC](https://discuss.elastic.co/t/solved-new-installation-gives-error/209220 "2019-11-25T08:13:01Z")

</div>

Hi, I just installed heartbeat-elastic on a Linux node, already have filebeat, metricbeat and packagebeat running on my entire cluster. Heartbeat is throwing me, what I believe is an error, when I run 'heartbeat setup'…

---

## [Network Latency](https://discuss.elastic.co/t/network-latency/208923)

<div class="topic-metadata">

**Author:** [@Kernel\_Panic](https://discuss.elastic.co/u/Kernel_Panic)\
**Replies:** 1\
**Last updated:** [November 25, 2019, 12:37am UTC](https://discuss.elastic.co/t/network-latency/208923 "2019-11-25T00:37:00Z")

</div>

Hello I need to graph/measure network latency, which beat should I use? metricbeat? heartbeat? packetbeat? is there any dashboard already for that? any examples around here? Thank you very much!! really appreciated yo…

---

## [Filebeat with PubSub Output?](https://discuss.elastic.co/t/filebeat-with-pubsub-output/209163)

<div class="topic-metadata">

**Author:** [@brucearctor](https://discuss.elastic.co/u/brucearctor)\
**Replies:** 1\
**Last updated:** [November 24, 2019, 3:46pm UTC](https://discuss.elastic.co/t/filebeat-with-pubsub-output/209163 "2019-11-24T15:46:50Z")

</div>

Would like output of pubsub (instead of Kafka). Anyone working on this? Otherwise, I am willing to take a crack at it.

---

## [Kubernetes Filebeat (7.4.2) Chart (7.4.1) + autodiscover results in Error creating runner from config](https://discuss.elastic.co/t/kubernetes-filebeat-7-4-2-chart-7-4-1-autodiscover-results-in-error-creating-runner-from-config/209174)

<div class="topic-metadata">

**Author:** [@Alexei\_Smirnov](https://discuss.elastic.co/u/Alexei_Smirnov)\
**Replies:** 0\
**Last updated:** [November 24, 2019, 10:38am UTC](https://discuss.elastic.co/t/kubernetes-filebeat-7-4-2-chart-7-4-1-autodiscover-results-in-error-creating-runner-from-config/209174 "2019-11-24T10:38:08Z")

</div>

I've been trying to setup FILEBEAT in our kubernetes clusters. Tried using filebeat chart from elastic helm repo, it is currently at 7.4.1 and also tried to upgrade to image 7.4.2 to same result. We are using filebeat.a…

---

## [Silent failure to process AWS elb metrics](https://discuss.elastic.co/t/silent-failure-to-process-aws-elb-metrics/208073)

<div class="topic-metadata">

**Author:** [@mesiasc](https://discuss.elastic.co/u/mesiasc)\
**Replies:** 3\
**Last updated:** [November 23, 2019, 3:28pm UTC](https://discuss.elastic.co/t/silent-failure-to-process-aws-elb-metrics/208073 "2019-11-23T15:28:09Z")

</div>

I have not managed to see any load balancer metrics. I have a load balancer as part of an ECE deployment and can see the LB is working. Also it has metrics visible in the AWS console both for the LB itself and under clo…

---

## [RDS module only getting metrics of one instance](https://discuss.elastic.co/t/rds-module-only-getting-metrics-of-one-instance/208938)

<div class="topic-metadata">

**Author:** [@miguel.d](https://discuss.elastic.co/u/miguel.d)\
**Replies:** 4\
**Last updated:** [November 22, 2019, 4:59pm UTC](https://discuss.elastic.co/t/rds-module-only-getting-metrics-of-one-instance/208938 "2019-11-22T16:59:18Z")

</div>

Hello! We tried the rds module with basic settings - module: aws period: 60s metricsets: - rds access\_key\_id: 'accesskey' secret\_access\_key: 'secretkey' It is able to pull all the db\_instance properly but …

---

## [Kibana/ES not showing kube pod metrics](https://discuss.elastic.co/t/kibana-es-not-showing-kube-pod-metrics/208913)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 4\
**Last updated:** [November 22, 2019, 4:31pm UTC](https://discuss.elastic.co/t/kibana-es-not-showing-kube-pod-metrics/208913 "2019-11-22T16:31:49Z")

</div>

I have ES-Beats-Kibana setup running in Kubernetes. In Kibana under Infrastructure App on Host Tab I can see all metrics (CPU, Memory, Load, In/Out Traffic & Log Rate) for all Kubernetes nodes. But On Kubernetes Tab, I …

---

## [Fields/tag set custom fields in filebeat, but logstash gives error](https://discuss.elastic.co/t/fields-tag-set-custom-fields-in-filebeat-but-logstash-gives-error/209086)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 0\
**Last updated:** [November 22, 2019, 4:01pm UTC](https://discuss.elastic.co/t/fields-tag-set-custom-fields-in-filebeat-but-logstash-gives-error/209086 "2019-11-22T16:01:22Z")

</div>

What is the right way for version 7.4 to add feilds in filebeat and then connect it with logstash.conf file so each log file has its own index created in ES? Below is logstash.conf input { beats { port =\> 5044 …

---

## [Filebeat .log configuring](https://discuss.elastic.co/t/filebeat-log-configuring/209068)

<div class="topic-metadata">

**Author:** [@111245](https://discuss.elastic.co/u/111245)\
**Replies:** 0\
**Last updated:** [November 22, 2019, 1:44pm UTC](https://discuss.elastic.co/t/filebeat-log-configuring/209068 "2019-11-22T13:44:36Z")

</div>

Hello! Could someone help? I'm setting up filebeat. The task is to send logs from the path /root/slk/log/\*.log Configured such filebeat.yml: filebeat.inputs: - type: log ﾠ enabled: true ﾠ paths: ﾠﾠ - …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=295)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=297)
