# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=298

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 299

---

## [Metricbeat Kafka Module “error in connect: EOF”](https://discuss.elastic.co/t/metricbeat-kafka-module-error-in-connect-eof/208512)

<div class="topic-metadata">

**Author:** [@BabuGanesh](https://discuss.elastic.co/u/BabuGanesh)\
**Replies:** 0\
**Last updated:** [November 19, 2019, 1:38pm UTC](https://discuss.elastic.co/t/metricbeat-kafka-module-error-in-connect-eof/208512 "2019-11-19T13:38:08Z")

</div>

Hi I'm facing error with Metricbeat kafka module (similar to https://discuss.elastic.co/t/metricbeat-kafka-module-error-in-connect-eof/193392) 2019-11-19T02:43:51.762-0800 INFO kafka/log.go:53 Connected to broker…

---

## [Does filebeat support RHCOS](https://discuss.elastic.co/t/does-filebeat-support-rhcos/208447)

<div class="topic-metadata">

**Author:** [@sumanyama](https://discuss.elastic.co/u/sumanyama)\
**Replies:** 1\
**Last updated:** [November 19, 2019, 1:13pm UTC](https://discuss.elastic.co/t/does-filebeat-support-rhcos/208447 "2019-11-19T13:13:06Z")

</div>

HI, WE ARE LOOKING AT INSTALLING FILEBEAT ON OCP4.2. ALL THE MACHINES(MASTERS AND WORKERS) ARE RUNNING REDHAT COREOS. DOES FILEBEAT SUPPORT RHCOS TO FORWARD LOGS TO AN EXTERNAL ELASTIC SEARCH? ANY REFERENCE DOCUMENT FOR…

---

## [Filebeat not sending log fields](https://discuss.elastic.co/t/filebeat-not-sending-log-fields/208493)

<div class="topic-metadata">

**Author:** [@abrejuin](https://discuss.elastic.co/u/abrejuin)\
**Replies:** 1\
**Last updated:** [November 19, 2019, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-log-fields/208493 "2019-11-19T13:09:16Z")

</div>

Hello, I am using Filebeat 5.6 and sending several log files to logstash. For each log files, I want to add fields but it does not work : those fields does not appear in Kibana. I have others fields at the the end of …

---

## [Perfmon panic when no matches to wildcard instance](https://discuss.elastic.co/t/perfmon-panic-when-no-matches-to-wildcard-instance/208505)

<div class="topic-metadata">

**Author:** [@repeltol](https://discuss.elastic.co/u/repeltol)\
**Replies:** 1\
**Last updated:** [November 19, 2019, 12:27pm UTC](https://discuss.elastic.co/t/perfmon-panic-when-no-matches-to-wildcard-instance/208505 "2019-11-19T12:27:28Z")

</div>

Metricbeat version: 7.4.2 Windows version: Windows Server 2019 Perfmon part of the metricbeat.yml: - metricsets: - perfmon module: windows perfmon.group\_measurements\_by\_instance: true perfmon.ignore\_…

---

## [Packet Beat not sending any data](https://discuss.elastic.co/t/packet-beat-not-sending-any-data/206868)

<div class="topic-metadata">

**Author:** [@Mhodge13](https://discuss.elastic.co/u/Mhodge13)\
**Replies:** 3\
**Last updated:** [November 19, 2019, 11:39am UTC](https://discuss.elastic.co/t/packet-beat-not-sending-any-data/206868 "2019-11-19T11:39:59Z")

</div>

Hi, Started noticing issues today with packet beat not sending any data to our elasticsearch SIEM. I started debug logging and found this constantly happening. 2019-11-06T16:15:10.000-0600 DEBUG \[flows\] flows/work…

---

## [Autodiscover and parsing json in a multiline log message](https://discuss.elastic.co/t/autodiscover-and-parsing-json-in-a-multiline-log-message/208474)

<div class="topic-metadata">

**Author:** [@RadwanNizam](https://discuss.elastic.co/u/RadwanNizam)\
**Replies:** 0\
**Last updated:** [November 19, 2019, 9:42am UTC](https://discuss.elastic.co/t/autodiscover-and-parsing-json-in-a-multiline-log-message/208474 "2019-11-19T09:42:29Z")

</div>

I configured Filebeat autodiscovery in order to monitor Elasticsearch logs (both are running as Docker containers). The objective is to monitor any errors generated by Elasticsearch. The logs generated by Elasticsearch a…

---

## [Filebeat stop harvesting new logs](https://discuss.elastic.co/t/filebeat-stop-harvesting-new-logs/208416)

<div class="topic-metadata">

**Author:** [@wackwinds](https://discuss.elastic.co/u/wackwinds)\
**Replies:** 2\
**Last updated:** [November 19, 2019, 4:56am UTC](https://discuss.elastic.co/t/filebeat-stop-harvesting-new-logs/208416 "2019-11-19T04:56:12Z")

</div>

Hi all, I used filebeat to collect docker logs in k8s. After all environment prepared, filebeat send some logs to logstash, but a short time later it stopped sending any logs to logstash. Can someone help me with this pr…

---

## [Missing User-ID field on Netflow from Palo Alto](https://discuss.elastic.co/t/missing-user-id-field-on-netflow-from-palo-alto/208327)

<div class="topic-metadata">

**Author:** [@fpieressa](https://discuss.elastic.co/u/fpieressa)\
**Replies:** 2\
**Last updated:** [November 19, 2019, 1:57am UTC](https://discuss.elastic.co/t/missing-user-id-field-on-netflow-from-palo-alto/208327 "2019-11-19T01:57:44Z")

</div>

Hi team, we have configured a Palo Alto Firewall to send Netflow to a Filebeat. We are seeing all events right, except that the "User-ID" Netflow field (value 56702) its not shown. We have replaced the Filebeat with a …

---

## [No Central metricbeat data coming through](https://discuss.elastic.co/t/no-central-metricbeat-data-coming-through/207015)

<div class="topic-metadata">

**Author:** [@gytaco](https://discuss.elastic.co/u/gytaco)\
**Replies:** 3\
**Last updated:** [November 18, 2019, 11:47pm UTC](https://discuss.elastic.co/t/no-central-metricbeat-data-coming-through/207015 "2019-11-18T23:47:52Z")

</div>

I have a metricbeat enrolled and it's status is updating fine. I am using Elastic Cloud so it's not a license or security issue that I am aware of. I have tried both token and user/name password and both enroll successf…

---

## [Filebeat in Docker can't output to Kafka](https://discuss.elastic.co/t/filebeat-in-docker-cant-output-to-kafka/208395)

<div class="topic-metadata">

**Author:** [@Pepper\_Pam](https://discuss.elastic.co/u/Pepper_Pam)\
**Replies:** 0\
**Last updated:** [November 18, 2019, 10:24pm UTC](https://discuss.elastic.co/t/filebeat-in-docker-cant-output-to-kafka/208395 "2019-11-18T22:24:15Z")

</div>

I'm trying to use filebeat in Docker to read log files from local machine and output to Kafka. But it doesn't work properly, doesn't output any message to Kafka. And I tested Kafka on my local machine, it works well itse…

---

## [Prometheus module doesn't work with WildFly 18](https://discuss.elastic.co/t/prometheus-module-doesnt-work-with-wildfly-18/207559)

<div class="topic-metadata">

**Author:** [@rcd](https://discuss.elastic.co/u/rcd)\
**Replies:** 4\
**Last updated:** [November 18, 2019, 10:45pm UTC](https://discuss.elastic.co/t/prometheus-module-doesnt-work-with-wildfly-18/207559 "2019-11-18T22:45:04Z")

</div>

I'm trying to configure Metricbeat to pull statistics from WildFly 18's MicroProfile Metrics subsystem. Internally, that subsystem is implemented using smallrye-metrics. When Metricbeat polls WildFly, the Prometheus modu…

---

## [Autodiscover module config with regular container input](https://discuss.elastic.co/t/autodiscover-module-config-with-regular-container-input/208391)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 0\
**Last updated:** [November 18, 2019, 9:48pm UTC](https://discuss.elastic.co/t/autodiscover-module-config-with-regular-container-input/208391 "2019-11-18T21:48:28Z")

</div>

Hi (Using filebeat 7.4.2 in kubernetes/docker container env) I was wondering if someone can guide me regarding the best way to do the following: Using filebeat autodiscover with module templates for nginx and mongodb …

---

## [Filebeat.yml: permission denied while runing in docker](https://discuss.elastic.co/t/filebeat-yml-permission-denied-while-runing-in-docker/208140)

<div class="topic-metadata">

**Author:** [@Pepper\_Pam](https://discuss.elastic.co/u/Pepper_Pam)\
**Replies:** 2\
**Last updated:** [November 18, 2019, 8:26pm UTC](https://discuss.elastic.co/t/filebeat-yml-permission-denied-while-runing-in-docker/208140 "2019-11-18T20:26:18Z")

</div>

I have the Dockerfile for filebeat as below: FROM docker.elastic.co/beats/filebeat:7.4.2 COPY filebeat.yml /usr/share/filebeat/filebeat.yml USER root RUN chown root:filebeat /usr/share/filebeat/filebeat.yml USER fi…

---

## [Heartbeat not running all monitors when scheduler limit is set](https://discuss.elastic.co/t/heartbeat-not-running-all-monitors-when-scheduler-limit-is-set/207792)

<div class="topic-metadata">

**Author:** [@bwright1558](https://discuss.elastic.co/u/bwright1558)\
**Replies:** 3\
**Last updated:** [November 18, 2019, 5:41pm UTC](https://discuss.elastic.co/t/heartbeat-not-running-all-monitors-when-scheduler-limit-is-set/207792 "2019-11-18T17:41:37Z")

</div>

I'm using Heartbeat version 7.4.2. I've got 40+ HTTP monitors configured for Heartbeat, all of which use the cron syntax for scheduling. I'm using '0 0 \*/2 \* \* \* \*', meaning every 2 hours. I also have the scheduler.limit…

---

## [How to write more than one multiline patterns for two different type of Logs](https://discuss.elastic.co/t/how-to-write-more-than-one-multiline-patterns-for-two-different-type-of-logs/207552)

<div class="topic-metadata">

**Author:** [@faiz](https://discuss.elastic.co/u/faiz)\
**Replies:** 2\
**Last updated:** [November 18, 2019, 5:15pm UTC](https://discuss.elastic.co/t/how-to-write-more-than-one-multiline-patterns-for-two-different-type-of-logs/207552 "2019-11-18T17:15:32Z")

</div>

HI, I need to ship logs of my tomcat alongs with my applications logs. My application logs and tomcat logs are of different time stamp, There fore I need to write more that one multiline patterns in the filebeat prospe…

---

## [Centos, how to install to run as unprivileged user?](https://discuss.elastic.co/t/centos-how-to-install-to-run-as-unprivileged-user/208335)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [November 18, 2019, 2:42pm UTC](https://discuss.elastic.co/t/centos-how-to-install-to-run-as-unprivileged-user/208335 "2019-11-18T14:42:17Z")

</div>

Hi, When I install filebeat via yum install ./filebeat-7.4.2-x86\_64.rpm the service is running as root. In the past I always edited /usr/lib/systemd/system/filebeat.service adding User=filebeat Group=filebeat in \[Se…

---

## [Getting metricbeat\_metricbeat as prefix for all custom fields](https://discuss.elastic.co/t/getting-metricbeat-metricbeat-as-prefix-for-all-custom-fields/208315)

<div class="topic-metadata">

**Author:** [@debasish283](https://discuss.elastic.co/u/debasish283)\
**Replies:** 0\
**Last updated:** [November 18, 2019, 1:37pm UTC](https://discuss.elastic.co/t/getting-metricbeat-metricbeat-as-prefix-for-all-custom-fields/208315 "2019-11-18T13:37:16Z")

</div>

Team, I am getting prefix of metricbeat\_metricbeat in all the custom fields can you please tell me how to fix this? My git url is https://github.com/lavish-jain/zabbixbeat Thanks in advance

---

## [Ingest IBM MQ logs to Elasticsearch using filebeat module](https://discuss.elastic.co/t/ingest-ibm-mq-logs-to-elasticsearch-using-filebeat-module/208152)

<div class="topic-metadata">

**Author:** [@mladen](https://discuss.elastic.co/u/mladen)\
**Replies:** 0\
**Last updated:** [November 16, 2019, 9:30am UTC](https://discuss.elastic.co/t/ingest-ibm-mq-logs-to-elasticsearch-using-filebeat-module/208152 "2019-11-16T09:30:07Z")

</div>

Hello, Recently I installed filebeat 7.4.2 and enabled IBM MQ module. After applying new configuration I didn’t get any data to elasticsearch. Inspecting logs, I found following line: Nov 15 16:07:30 \*\*\*\*\*\*\*\* filebeat\[…

---

## [Error loading config file: yaml: line 217: found unexpected end of stream](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-217-found-unexpected-end-of-stream/208165)

<div class="topic-metadata">

**Author:** [@vahagg1](https://discuss.elastic.co/u/vahagg1)\
**Replies:** 1\
**Last updated:** [November 18, 2019, 11:25am UTC](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-217-found-unexpected-end-of-stream/208165 "2019-11-18T11:25:50Z")

</div>

Hi get following error please help me

---

## [Software / application metering with Metricbeat](https://discuss.elastic.co/t/software-application-metering-with-metricbeat/208298)

<div class="topic-metadata">

**Author:** [@chesini](https://discuss.elastic.co/u/chesini)\
**Replies:** 0\
**Last updated:** [November 18, 2019, 11:19am UTC](https://discuss.elastic.co/t/software-application-metering-with-metricbeat/208298 "2019-11-18T11:19:37Z")

</div>

Is there a way to do software / application metering with Metricbeat ? Does Elastic support software / application metering ? Regards

---

## [Filebeat flag files as inactive after roll](https://discuss.elastic.co/t/filebeat-flag-files-as-inactive-after-roll/208268)

<div class="topic-metadata">

**Author:** [@Palyndrome](https://discuss.elastic.co/u/Palyndrome)\
**Replies:** 1\
**Last updated:** [November 18, 2019, 11:15am UTC](https://discuss.elastic.co/t/filebeat-flag-files-as-inactive-after-roll/208268 "2019-11-18T11:15:46Z")

</div>

Hello, We are facing an issue on our production server. We are logging into a file using Log4Net with a rolling file appender. Sometimes, when the file is rolling the file is flagged as inactive and nor more logs are s…

---

## [Failed to connect with Elastic n Kibana](https://discuss.elastic.co/t/failed-to-connect-with-elastic-n-kibana/208189)

<div class="topic-metadata">

**Author:** [@rmahi](https://discuss.elastic.co/u/rmahi)\
**Replies:** 1\
**Last updated:** [November 18, 2019, 11:15am UTC](https://discuss.elastic.co/t/failed-to-connect-with-elastic-n-kibana/208189 "2019-11-18T11:15:12Z")

</div>

H there i got this error problem, pls help me. t@icldbyLZ0NLxgKI opt\]# systemctl status filebeat -l â— filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/usr/lib/sy…

---

## [Equivalent of filebeat on redhat 4](https://discuss.elastic.co/t/equivalent-of-filebeat-on-redhat-4/208287)

<div class="topic-metadata">

**Author:** [@seddikalaouiismaili](https://discuss.elastic.co/u/seddikalaouiismaili)\
**Replies:** 0\
**Last updated:** [November 18, 2019, 10:29am UTC](https://discuss.elastic.co/t/equivalent-of-filebeat-on-redhat-4/208287 "2019-11-18T10:29:24Z")

</div>

hello I would like to ask you about filebeat, we have production's server that we can't update (OS 4) which is very old. The real problem is that we can't install filebeat on these machines. Is there a way to collect t…

---

## [Configure FileBeat to combine all logs without multiline pattern](https://discuss.elastic.co/t/configure-filebeat-to-combine-all-logs-without-multiline-pattern/207256)

<div class="topic-metadata">

**Author:** [@abhisekdg](https://discuss.elastic.co/u/abhisekdg)\
**Replies:** 2\
**Last updated:** [November 18, 2019, 6:49am UTC](https://discuss.elastic.co/t/configure-filebeat-to-combine-all-logs-without-multiline-pattern/207256 "2019-11-18T06:49:37Z")

</div>

I am using Filebeat 6.4.2, Logstash 6.3.1 and want to combine all logs files on the filebeat input path \</var/log/application.log\> . Logs don't have any specific pattern to start with or end with. filebeat.inputs: …

---

## [Haproxy module does not honour ssl.verification\_mode: 'none'](https://discuss.elastic.co/t/haproxy-module-does-not-honour-ssl-verification-mode-none/206906)

<div class="topic-metadata">

**Author:** [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Replies:** 3\
**Last updated:** [November 18, 2019, 5:09am UTC](https://discuss.elastic.co/t/haproxy-module-does-not-honour-ssl-verification-mode-none/206906 "2019-11-18T05:09:38Z")

</div>

Our hosting provider runs haproxy for us and we have access to the stats interface. We have been using a custom script to extract stats, but since metricbeat has a haproxy module, it would be nice to use that instead. T…

---

## [Filebeat overwriting log.level and log.logger](https://discuss.elastic.co/t/filebeat-overwriting-log-level-and-log-logger/207548)

<div class="topic-metadata">

**Author:** [@Heatzone87](https://discuss.elastic.co/u/Heatzone87)\
**Replies:** 4\
**Last updated:** [November 17, 2019, 8:29pm UTC](https://discuss.elastic.co/t/filebeat-overwriting-log-level-and-log-logger/207548 "2019-11-17T20:29:50Z")

</div>

I have my application logger below: {"@timestamp":"2019-11-12T16:05:05.407636Z","log":{"level":"INFO","logger":"audit"} However when i run Filebeat in debug mode i notice that my keys are gone and replace with the file…

---

## [Observed a panic: "invalid memory address or nil pointer dereference"](https://discuss.elastic.co/t/observed-a-panic-invalid-memory-address-or-nil-pointer-dereference/206465)

<div class="topic-metadata">

**Author:** [@1robroos](https://discuss.elastic.co/u/1robroos)\
**Replies:** 4\
**Last updated:** [November 16, 2019, 4:20pm UTC](https://discuss.elastic.co/t/observed-a-panic-invalid-memory-address-or-nil-pointer-dereference/206465 "2019-11-16T16:20:00Z")

</div>

Hello Looks like I have the same issues as written in closed issue 14320: https://github.com/elastic/beats/issues/14320 So I am using: ( as directed in https://www.elastic.co/guide/en/beats/metricbeat/current/running-o…

---

## [Is it mandatory to give value of session\_token: '\<session\_token\>' to reaad AWS values](https://discuss.elastic.co/t/is-it-mandatory-to-give-value-of-session-token-session-token-to-reaad-aws-values/207920)

<div class="topic-metadata">

**Author:** [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Replies:** 2\
**Last updated:** [November 16, 2019, 11:59am UTC](https://discuss.elastic.co/t/is-it-mandatory-to-give-value-of-session-token-session-token-to-reaad-aws-values/207920 "2019-11-16T11:59:17Z")

</div>

Hi All, Trying to see how I can read the AWS monitoring values from the link "https://www.elastic.co/guide/en/beats/metricbeat/7.4/metricbeat-module-aws.html" , thanks @Kaiyan\_Sheng for sharing the docs with me I coul…

---

## [When filebeat has little work to do, it stops loadbalancing correctly](https://discuss.elastic.co/t/when-filebeat-has-little-work-to-do-it-stops-loadbalancing-correctly/208123)

<div class="topic-metadata">

**Author:** [@jimcs](https://discuss.elastic.co/u/jimcs)\
**Replies:** 0\
**Last updated:** [November 15, 2019, 6:27pm UTC](https://discuss.elastic.co/t/when-filebeat-has-little-work-to-do-it-stops-loadbalancing-correctly/208123 "2019-11-15T18:27:40Z")

</div>

We have 4 logstash instances running with the following configuration on all our servers: output.logstash: enabled: true hosts: \["logstash1:5046", "logstash2:5046", "logstash3:5046", "logstash4:5046"\] loadbalance…

---

## [Eb extension - filebeat - windows](https://discuss.elastic.co/t/eb-extension-filebeat-windows/208122)

<div class="topic-metadata">

**Author:** [@Sagi\_Tiger](https://discuss.elastic.co/u/Sagi_Tiger)\
**Replies:** 0\
**Last updated:** [November 15, 2019, 6:24pm UTC](https://discuss.elastic.co/t/eb-extension-filebeat-windows/208122 "2019-11-15T18:24:50Z")

</div>

Does anyone have an .eb extension config to install filebeat on a windows machine?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=297)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=299)
