# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=297

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 298

---

## [Configuring Filebeat from a docker-compose.yml](https://discuss.elastic.co/t/configuring-filebeat-from-a-docker-compose-yml/209082)

<div class="topic-metadata">

**Author:** [@dbwest](https://discuss.elastic.co/u/dbwest)\
**Replies:** 0\
**Last updated:** [November 22, 2019, 3:12pm UTC](https://discuss.elastic.co/t/configuring-filebeat-from-a-docker-compose-yml/209082 "2019-11-22T15:12:15Z")

</div>

I've noticed that there seems to be some Convention that maps nested config to environment variables along this pattern... setting foo.bar.batz maps to env var FOO\_BAR\_BATZ. How far does this extend and what percentage…

---

## [Filebeat netflow module multiple host](https://discuss.elastic.co/t/filebeat-netflow-module-multiple-host/209076)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 0\
**Last updated:** [November 22, 2019, 2:51pm UTC](https://discuss.elastic.co/t/filebeat-netflow-module-multiple-host/209076 "2019-11-22T14:51:24Z")

</div>

Hi everyone In my system i have a multiple network equipment that need to push log to elasticsearch I have install filebeat on a seperate server and enable netflow module to collect log. So can i ask how to type in mu…

---

## [Crosscompiled Metricbeat metrics not visible in Kibana](https://discuss.elastic.co/t/crosscompiled-metricbeat-metrics-not-visible-in-kibana/208927)

<div class="topic-metadata">

**Author:** [@Oliver\_Suzuki](https://discuss.elastic.co/u/Oliver_Suzuki)\
**Replies:** 2\
**Last updated:** [November 22, 2019, 2:04pm UTC](https://discuss.elastic.co/t/crosscompiled-metricbeat-metrics-not-visible-in-kibana/208927 "2019-11-22T14:04:14Z")

</div>

Hi! I have recently been trying to get the following setup to run: Kibana & Elasticsearch on a x86, dockerized (compose) in recent a virtual Debian Linux system. Metricbeat sits in am arm64-alpine container on the arm…

---

## [Kube-state-metrics over SSL](https://discuss.elastic.co/t/kube-state-metrics-over-ssl/208537)

<div class="topic-metadata">

**Author:** [@trumbaut](https://discuss.elastic.co/u/trumbaut)\
**Replies:** 1\
**Last updated:** [November 22, 2019, 1:12pm UTC](https://discuss.elastic.co/t/kube-state-metrics-over-ssl/208537 "2019-11-22T13:12:46Z")

</div>

We try to get data from the kube-state-metrics pod in OpenShift. This works fine if we start a standalone kube-state-metrics pod and expose it over an HTTP route: - module: kubernetes enabled: true metricsets: -…

---

## [Fail to ship data from Metribeat to Logstash](https://discuss.elastic.co/t/fail-to-ship-data-from-metribeat-to-logstash/208876)

<div class="topic-metadata">

**Author:** [@LuigiDelavega](https://discuss.elastic.co/u/LuigiDelavega)\
**Replies:** 5\
**Last updated:** [November 22, 2019, 10:39am UTC](https://discuss.elastic.co/t/fail-to-ship-data-from-metribeat-to-logstash/208876 "2019-11-22T10:39:53Z")

</div>

Hello, Im pretty new to the ELK stack and i need your help to identify where my problem come from, please. I installed ElasticSearch, Kibana and logstash and they are working well. I used with sample data to be more fa…

---

## [Filebeat at least once delivery and udp input](https://discuss.elastic.co/t/filebeat-at-least-once-delivery-and-udp-input/208774)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [November 22, 2019, 6:18am UTC](https://discuss.elastic.co/t/filebeat-at-least-once-delivery-and-udp-input/208774 "2019-11-22T06:18:35Z")

</div>

I'm wondering if and how Filebeat can guarantee at least once delivery with an udp input? If we would restart Filebeat, will Palo Alto logs send to it, get lost?

---

## [Parse AWS CloudTrail and CloudWatch Logs in Logstash](https://discuss.elastic.co/t/parse-aws-cloudtrail-and-cloudwatch-logs-in-logstash/208419)

<div class="topic-metadata">

**Author:** [@A\_P](https://discuss.elastic.co/u/A_P)\
**Replies:** 2\
**Last updated:** [November 21, 2019, 10:13pm UTC](https://discuss.elastic.co/t/parse-aws-cloudtrail-and-cloudwatch-logs-in-logstash/208419 "2019-11-21T22:13:51Z")

</div>

By default, CloudTrail logs are aggregated per region and then redirected to an S3 bucket (compressed JSON files). Cloudtrail delivers log files to s3 bucket, approximately every 5 minutes. We can use the Logstash S3 inp…

---

## [Not able to start, remove the filebeat](https://discuss.elastic.co/t/not-able-to-start-remove-the-filebeat/208113)

<div class="topic-metadata">

**Author:** [@newafounder](https://discuss.elastic.co/u/newafounder)\
**Replies:** 2\
**Last updated:** [November 21, 2019, 9:47pm UTC](https://discuss.elastic.co/t/not-able-to-start-remove-the-filebeat/208113 "2019-11-21T21:47:25Z")

</div>

Hi, so i have ansible playbook install filebeat agent on a server. After installation, i went to check the service and it was working fine. But then i manually stopped the service and starting again, afterwards i have ge…

---

## [Filebeats on kubernetes - How to change log level on yaml](https://discuss.elastic.co/t/filebeats-on-kubernetes-how-to-change-log-level-on-yaml/208979)

<div class="topic-metadata">

**Author:** [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Replies:** 0\
**Last updated:** [November 21, 2019, 9:23pm UTC](https://discuss.elastic.co/t/filebeats-on-kubernetes-how-to-change-log-level-on-yaml/208979 "2019-11-21T21:23:00Z")

</div>

Hello Folks! I have a OKD Server and would like set "logging.level: warning" into filebeat-kubernetes.yaml file, since default is "info". Then deploy it ( kubectl create -f filebeat-kubernetes.yaml ). Any idea what ext…

---

## [Kibana not picking up the updated filebeat configuration](https://discuss.elastic.co/t/kibana-not-picking-up-the-updated-filebeat-configuration/208940)

<div class="topic-metadata">

**Author:** [@Nehajain](https://discuss.elastic.co/u/Nehajain)\
**Replies:** 0\
**Last updated:** [November 21, 2019, 4:50pm UTC](https://discuss.elastic.co/t/kibana-not-picking-up-the-updated-filebeat-configuration/208940 "2019-11-21T16:50:49Z")

</div>

Hi, When I started implementing ELK stack, Kibana was reading correctly from the file beat. Now I have changed the path to the log file. Restarted Filebeat. Restarted Kibana. But I don't see any change in the Kibana das…

---

## ["Error initializing Kubernetes metadata enricher"](https://discuss.elastic.co/t/error-initializing-kubernetes-metadata-enricher/208893)

<div class="topic-metadata">

**Author:** [@tkzv](https://discuss.elastic.co/u/tkzv)\
**Replies:** 0\
**Last updated:** [November 21, 2019, 1:40pm UTC](https://discuss.elastic.co/t/error-initializing-kubernetes-metadata-enricher/208893 "2019-11-21T13:40:29Z")

</div>

When I run Metricbeat as a service on a Windows node of a Kubernetes cluster, I get multiple errors in the log: ERROR util/kubernetes.go:106 Error initializing Kubernetes metadata enricher: unable to build kube config d…

---

## [Exiting: resource 'metricbeat-7.4.2' exists, but it is not an alias](https://discuss.elastic.co/t/exiting-resource-metricbeat-7-4-2-exists-but-it-is-not-an-alias/206685)

<div class="topic-metadata">

**Author:** [@kenbergquist](https://discuss.elastic.co/u/kenbergquist)\
**Replies:** 5\
**Last updated:** [November 21, 2019, 1:08pm UTC](https://discuss.elastic.co/t/exiting-resource-metricbeat-7-4-2-exists-but-it-is-not-an-alias/206685 "2019-11-21T13:08:52Z")

</div>

After upgrading from 6.8.2 to 7.4.2, when executing metricbeat setup, I receive the error Exiting: resource 'metricbeat-7.4.2' exists, but it is not an alias Visualizations and dashboards are of course largely broken…

---

## [What roles are needed for the PostgreSQL user for Metricbeat?](https://discuss.elastic.co/t/what-roles-are-needed-for-the-postgresql-user-for-metricbeat/208889)

<div class="topic-metadata">

**Author:** [@Radu\_Murzea](https://discuss.elastic.co/u/Radu_Murzea)\
**Replies:** 0\
**Last updated:** [November 21, 2019, 12:56pm UTC](https://discuss.elastic.co/t/what-roles-are-needed-for-the-postgresql-user-for-metricbeat/208889 "2019-11-21T12:56:18Z")

</div>

I plan to enable MetricBeat's PostgreSQL module in order to monitor my PostgreSQL instances. In the module's config file, there is the option to include a username+password combination, so that MetricBeat can connect to…

---

## [Filebeat not ingesting logs from s3](https://discuss.elastic.co/t/filebeat-not-ingesting-logs-from-s3/207734)

<div class="topic-metadata">

**Author:** [@ben.sharp](https://discuss.elastic.co/u/ben.sharp)\
**Replies:** 9\
**Last updated:** [November 21, 2019, 10:25am UTC](https://discuss.elastic.co/t/filebeat-not-ingesting-logs-from-s3/207734 "2019-11-21T10:25:53Z")

</div>

Hi there, I've configured my Filebeat following the guide for s3 input (found here), but when running, both the input worker and filebeat are starting then stopping almost immediately (all in less than a second). I'm n…

---

## [Metricbeat overview dashboard](https://discuss.elastic.co/t/metricbeat-overview-dashboard/208671)

<div class="topic-metadata">

**Author:** [@AstroSlazak](https://discuss.elastic.co/u/AstroSlazak)\
**Replies:** 2\
**Last updated:** [November 21, 2019, 9:42am UTC](https://discuss.elastic.co/t/metricbeat-overview-dashboard/208671 "2019-11-21T09:42:16Z")

</div>

Hi, Is any chance to get dashboard with visualization ? System Overview - https://demo.elastic.co/app/kibana#/dashboard/Metricbeat-system-overview-ecs Host Overview - https://demo.elastic.co/app/kibana#/dashboard/79ff…

---

## [Escape specialcharacters in grok](https://discuss.elastic.co/t/escape-specialcharacters-in-grok/207060)

<div class="topic-metadata">

**Author:** [@Tinkerbell](https://discuss.elastic.co/u/Tinkerbell)\
**Replies:** 2\
**Last updated:** [November 21, 2019, 6:45am UTC](https://discuss.elastic.co/t/escape-specialcharacters-in-grok/207060 "2019-11-21T06:45:19Z")

</div>

How do we escape special characters in grok pattern. The below fails on this text. Log Line : 2019-09-03 11:52:56.387 - \[INFO\] - from \[Class:xxx.yyy.CLASSNAME Method:METHOD\] in 29 - Invalid Key and Password 1234567XXX…

---

## [Best Practices for Filebeat](https://discuss.elastic.co/t/best-practices-for-filebeat/208704)

<div class="topic-metadata">

**Author:** [@akhil](https://discuss.elastic.co/u/akhil)\
**Replies:** 3\
**Last updated:** [November 21, 2019, 4:31am UTC](https://discuss.elastic.co/t/best-practices-for-filebeat/208704 "2019-11-21T04:31:23Z")

</div>

Dear Elastic Team, I want to know the best practices for Filebeat configuration. Actually, there is one Production server where I have to setup filebeat. I want to configure the filebeat in that way so that when I will …

---

## [Multiple outputs in the filebeats.yml to the logstash](https://discuss.elastic.co/t/multiple-outputs-in-the-filebeats-yml-to-the-logstash/208603)

<div class="topic-metadata">

**Author:** [@Thiago\_Paiva](https://discuss.elastic.co/u/Thiago_Paiva)\
**Replies:** 2\
**Last updated:** [November 20, 2019, 6:00pm UTC](https://discuss.elastic.co/t/multiple-outputs-in-the-filebeats-yml-to-the-logstash/208603 "2019-11-20T18:00:48Z")

</div>

Hello, I have the following setting in the filebeats.yml: Two conditions input for logs filebeat.inputs: - paths: - E: \\ log\_type1 \_ \*. Log fields\_under\_root: true fields: type: type1 - paths: - E: \\ …

---

## [Filebeat unable to harvest ISC Bind logs](https://discuss.elastic.co/t/filebeat-unable-to-harvest-isc-bind-logs/207189)

<div class="topic-metadata">

**Author:** [@pestevao](https://discuss.elastic.co/u/pestevao)\
**Replies:** 2\
**Last updated:** [November 20, 2019, 4:33pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-harvest-isc-bind-logs/207189 "2019-11-20T16:33:01Z")

</div>

Hi, I'm trying to use filebeat to ship ISC Bind logs - heavy writed and aroung 8Gb at the day end - to logstash, grok them and finally store it's in Elastic. In Filebeat config I have: type: log enabled: true paths…

---

## [Sending sysmon logs from Winlogbeat to Logstash](https://discuss.elastic.co/t/sending-sysmon-logs-from-winlogbeat-to-logstash/208177)

<div class="topic-metadata">

**Author:** [@Coder\_HK](https://discuss.elastic.co/u/Coder_HK)\
**Replies:** 4\
**Last updated:** [November 20, 2019, 1:49pm UTC](https://discuss.elastic.co/t/sending-sysmon-logs-from-winlogbeat-to-logstash/208177 "2019-11-20T13:49:13Z")

</div>

I have installed ELK on ubuntu in vmware and Windows 10 is my main OS. I want to send sysmon logs to logstash that's on ubuntu from my windows system through winlogsbeat please guide me step by step how to do it ..

---

## [Any plan to release Beats modules for Open Liberty?](https://discuss.elastic.co/t/any-plan-to-release-beats-modules-for-open-liberty/208585)

<div class="topic-metadata">

**Author:** [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Replies:** 1\
**Last updated:** [November 20, 2019, 7:11am UTC](https://discuss.elastic.co/t/any-plan-to-release-beats-modules-for-open-liberty/208585 "2019-11-20T07:11:45Z")

</div>

Is any plan to have Beats modules ( filebeat and metricbeat ) for Open Liberty ? Thanks, Mauricio

---

## [Using a Beat to run a command at an interval](https://discuss.elastic.co/t/using-a-beat-to-run-a-command-at-an-interval/208632)

<div class="topic-metadata">

**Author:** [@fledder](https://discuss.elastic.co/u/fledder)\
**Replies:** 1\
**Last updated:** [November 20, 2019, 7:07am UTC](https://discuss.elastic.co/t/using-a-beat-to-run-a-command-at-an-interval/208632 "2019-11-20T07:07:35Z")

</div>

Hi, I have a question that I can't seem to find an answer for in the documentation or on the forum. I have a piece of software that logs to its own proprietary log format that I would like to bring into Elasticsearch. Th…

---

## [Winlogbeat not getting updated in Kibana](https://discuss.elastic.co/t/winlogbeat-not-getting-updated-in-kibana/207797)

<div class="topic-metadata">

**Author:** [@Bharat05](https://discuss.elastic.co/u/Bharat05)\
**Replies:** 5\
**Last updated:** [November 20, 2019, 4:52am UTC](https://discuss.elastic.co/t/winlogbeat-not-getting-updated-in-kibana/207797 "2019-11-20T04:52:22Z")

</div>

I am doing a POC in Elastic Stack using version 6.5.2. I am facing an issue in Kibana as the data are not getting updated. The winlogbeat indices creation stopped after a October 23 and no new indices have been created…

---

## [Naming filebeat logs](https://discuss.elastic.co/t/naming-filebeat-logs/207042)

<div class="topic-metadata">

**Author:** [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Replies:** 2\
**Last updated:** [November 20, 2019, 1:08am UTC](https://discuss.elastic.co/t/naming-filebeat-logs/207042 "2019-11-20T01:08:54Z")

</div>

I think I was trying something ambitious. Creating separate logs logging.level: info logging.to\_files: true logging.files: - name: test1 when.contains: fields.log\_source: "test1" - name: test2 …

---

## [Ros Logs](https://discuss.elastic.co/t/ros-logs/207136)

<div class="topic-metadata">

**Author:** [@RayKishev](https://discuss.elastic.co/u/RayKishev)\
**Replies:** 2\
**Last updated:** [November 20, 2019, 12:20am UTC](https://discuss.elastic.co/t/ros-logs/207136 "2019-11-20T00:20:44Z")

</div>

I would like to capture Ros logs which is under /home/.ros/logs path. Will i be able to get those logs to Elastic and Kibana thru Filebeat or Logstash? I tried to specify the path in Filebeat.yml, but i still don't see R…

---

## [Metricbeat and Nginx Ingress controller crashed our production Kibana](https://discuss.elastic.co/t/metricbeat-and-nginx-ingress-controller-crashed-our-production-kibana/208582)

<div class="topic-metadata">

**Author:** [@mpdonahue](https://discuss.elastic.co/u/mpdonahue)\
**Replies:** 0\
**Last updated:** [November 19, 2019, 8:51pm UTC](https://discuss.elastic.co/t/metricbeat-and-nginx-ingress-controller-crashed-our-production-kibana/208582 "2019-11-19T20:51:02Z")

</div>

Hi all, Trying to get Metricbeats to scrape our Nginx-Ingress, especially so that we can see the number and response codes of the HTTP requests coming in. Unfortunately, it just showed a bunch of obviously not real HTT…

---

## [Bug? Filebeat stops load balancing when volume is low](https://discuss.elastic.co/t/bug-filebeat-stops-load-balancing-when-volume-is-low/208567)

<div class="topic-metadata">

**Author:** [@jimcs](https://discuss.elastic.co/u/jimcs)\
**Replies:** 0\
**Last updated:** [November 19, 2019, 7:08pm UTC](https://discuss.elastic.co/t/bug-filebeat-stops-load-balancing-when-volume-is-low/208567 "2019-11-19T19:08:53Z")

</div>

The issue only occurs on our "slower" servers, i.e. those with low filebeat volume. All our servers are configured to loadbalance between 4 logstash servers. For our busy servers, this works fine - they maintain (and use…

---

## [Unable to ingest logs on remote Elasticsearch server](https://discuss.elastic.co/t/unable-to-ingest-logs-on-remote-elasticsearch-server/208554)

<div class="topic-metadata">

**Author:** [@twelsh37](https://discuss.elastic.co/u/twelsh37)\
**Replies:** 0\
**Last updated:** [November 19, 2019, 5:45pm UTC](https://discuss.elastic.co/t/unable-to-ingest-logs-on-remote-elasticsearch-server/208554 "2019-11-19T17:45:27Z")

</div>

Hi All, First time post so please be gentle. I am pretty new to ELK but not to Linux. I am running: Server A - Remote Server filebeat v 6.8.4 OS Ubuntu 18.04 Server B - ELK Server Elastic Search 6.8.4 OS Ubuntu…

---

## [Please help with creating new index for Filebeat](https://discuss.elastic.co/t/please-help-with-creating-new-index-for-filebeat/208561)

<div class="topic-metadata">

**Author:** [@RayKishev](https://discuss.elastic.co/u/RayKishev)\
**Replies:** 0\
**Last updated:** [November 19, 2019, 6:32pm UTC](https://discuss.elastic.co/t/please-help-with-creating-new-index-for-filebeat/208561 "2019-11-19T18:32:03Z")

</div>

Hello @Elastic Team, I'm trying to capture Cpu temp logs using Filebeat. Im running a script which captures CPU temp and stores logs in log file, then Filebeat is picking them up and sends to Kibana. I can only see the…

---

## [Specify ILM policy for Multiple Elasticsearch outputs](https://discuss.elastic.co/t/specify-ilm-policy-for-multiple-elasticsearch-outputs/208129)

<div class="topic-metadata">

**Author:** [@TonyLuc](https://discuss.elastic.co/u/TonyLuc)\
**Replies:** 4\
**Last updated:** [November 19, 2019, 5:36pm UTC](https://discuss.elastic.co/t/specify-ilm-policy-for-multiple-elasticsearch-outputs/208129 "2019-11-19T17:36:35Z")

</div>

Scenario I am using filebeat to collect logs from 2 different sources. It is going to 2 different indexes. Thus in the filebeat.yml the following are added to the Elasticsearch output: output.elasticsearch: hosts: \["…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=296)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=298)
