# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=299

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 300

---

## [Licence to include Filebeat in our commercial product?](https://discuss.elastic.co/t/licence-to-include-filebeat-in-our-commercial-product/207537)

<div class="topic-metadata">

**Author:** [@Vijay\_Daggumati](https://discuss.elastic.co/u/Vijay_Daggumati)\
**Replies:** 6\
**Last updated:** [November 15, 2019, 5:20pm UTC](https://discuss.elastic.co/t/licence-to-include-filebeat-in-our-commercial-product/207537 "2019-11-15T17:20:17Z")

</div>

Hi, I would like to know the details regarding usage of file beat in our commercial product. We have a piece of software which we sell to our clients. To be clear, we only run the software on client hardware. We don't …

---

## [Panw Schema Potential Bug in CSV Parse and Column Numbering](https://discuss.elastic.co/t/panw-schema-potential-bug-in-csv-parse-and-column-numbering/208099)

<div class="topic-metadata">

**Author:** [@davidhowell.tx](https://discuss.elastic.co/u/davidhowell.tx)\
**Replies:** 3\
**Last updated:** [November 15, 2019, 5:14pm UTC](https://discuss.elastic.co/t/panw-schema-potential-bug-in-csv-parse-and-column-numbering/208099 "2019-11-15T17:14:51Z")

</div>

I'm unable to determine if this bug is manifesting in actual Filebeat parses of PAN-OS logs as I'm not utilizing them. I'm using the Filebeat configuration to assist in creating my Logstash pipeline to map PAN-OS fields …

---

## [Filebeat No data has been received from this module yet](https://discuss.elastic.co/t/filebeat-no-data-has-been-received-from-this-module-yet/207705)

<div class="topic-metadata">

**Author:** [@yasharne](https://discuss.elastic.co/u/yasharne)\
**Replies:** 2\
**Last updated:** [November 15, 2019, 4:44pm UTC](https://discuss.elastic.co/t/filebeat-no-data-has-been-received-from-this-module-yet/207705 "2019-11-15T16:44:12Z")

</div>

I have a container for kibana on a network named emk and mapped port of 5601 and a container for filebeat on the emk and three redis containers on emk and logstach on emk. I can ping all hosts from each other. I tried t…

---

## [Filebeat ships logs to remote logstash](https://discuss.elastic.co/t/filebeat-ships-logs-to-remote-logstash/208091)

<div class="topic-metadata">

**Author:** [@Michalis\_Koutzos](https://discuss.elastic.co/u/Michalis_Koutzos)\
**Replies:** 2\
**Last updated:** [November 15, 2019, 3:03pm UTC](https://discuss.elastic.co/t/filebeat-ships-logs-to-remote-logstash/208091 "2019-11-15T15:03:26Z")

</div>

Is it possible filebeat ships logs to remote logstash in differnt network ?

---

## [Collecting postgres information from multiple machinesfrom one metricbeat instance](https://discuss.elastic.co/t/collecting-postgres-information-from-multiple-machinesfrom-one-metricbeat-instance/207864)

<div class="topic-metadata">

**Author:** [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Replies:** 2\
**Last updated:** [November 15, 2019, 3:23pm UTC](https://discuss.elastic.co/t/collecting-postgres-information-from-multiple-machinesfrom-one-metricbeat-instance/207864 "2019-11-15T15:23:16Z")

</div>

Hi All, Good evening. I am trying to use metricbeat to get information about PostgreSQL, for one machine I am getting the information on the dashboard. What I am aiming is to use the same metricbeat instance and postg…

---

## [Filbeat 7.4 Kafka Input with Kafka SSL Enabled](https://discuss.elastic.co/t/filbeat-7-4-kafka-input-with-kafka-ssl-enabled/207009)

<div class="topic-metadata">

**Author:** [@a\_pel73](https://discuss.elastic.co/u/a_pel73)\
**Replies:** 1\
**Last updated:** [November 15, 2019, 2:01pm UTC](https://discuss.elastic.co/t/filbeat-7-4-kafka-input-with-kafka-ssl-enabled/207009 "2019-11-15T14:01:26Z")

</div>

Hi, My use case is to grab data from Kafka topic using Filebeat. I'm trying to implement Filebeat with Kafka Inputs. Following the document here. However my Kafka is SSL enabled, is Filebeat currently not supported t…

---

## [Filebeat 6.8.1 Sporadically stops Sending Logs](https://discuss.elastic.co/t/filebeat-6-8-1-sporadically-stops-sending-logs/208064)

<div class="topic-metadata">

**Author:** [@ven67](https://discuss.elastic.co/u/ven67)\
**Replies:** 1\
**Last updated:** [November 15, 2019, 11:55am UTC](https://discuss.elastic.co/t/filebeat-6-8-1-sporadically-stops-sending-logs/208064 "2019-11-15T11:55:47Z")

</div>

We have four separate kubernetes clusters, two on-prem and two in AWS setup with filebeat to ship logs. For several months we have been troubleshooting an issue where sporadically our filebeat daemonsets will altogether …

---

## [Filebeat certificate issue while setting up Kibana dashboard](https://discuss.elastic.co/t/filebeat-certificate-issue-while-setting-up-kibana-dashboard/208056)

<div class="topic-metadata">

**Author:** [@agiorgi](https://discuss.elastic.co/u/agiorgi)\
**Replies:** 0\
**Last updated:** [November 15, 2019, 11:28am UTC](https://discuss.elastic.co/t/filebeat-certificate-issue-while-setting-up-kibana-dashboard/208056 "2019-11-15T11:28:49Z")

</div>

Hi there :slight\_smile: I'm trying to setup Filebeat default dashboards in Kibana, within my ELK lab. The whole stack is version 7.4.2. I have configured security in Elasticsearch and Kibana, using the elasticsearch-c…

---

## [Error connection Logstash](https://discuss.elastic.co/t/error-connection-logstash/206760)

<div class="topic-metadata">

**Author:** [@Jonny3](https://discuss.elastic.co/u/Jonny3)\
**Replies:** 2\
**Last updated:** [November 15, 2019, 11:12am UTC](https://discuss.elastic.co/t/error-connection-logstash/206760 "2019-11-15T11:12:24Z")

</div>

Hi everyone, I started a few weeks ago to work with ELK and Filebeat in a Docker system for an university project. I have working the ELK, Kibana detect everything, including Beats, now I'm configuring Filebeat to send t…

---

## [Eperimenting o365beat, issue with the processors](https://discuss.elastic.co/t/eperimenting-o365beat-issue-with-the-processors/208041)

<div class="topic-metadata">

**Author:** [@brogio](https://discuss.elastic.co/u/brogio)\
**Replies:** 2\
**Last updated:** [November 15, 2019, 10:39am UTC](https://discuss.elastic.co/t/eperimenting-o365beat-issue-with-the-processors/208041 "2019-11-15T10:39:22Z")

</div>

Hi, we are testing o365beat and we are experiencing some issues. The first of this issues is about the processors not working in o365beat . The configuration is fairly default: we are sending the events directly to ela…

---

## [How to prevent truncation of line?](https://discuss.elastic.co/t/how-to-prevent-truncation-of-line/207831)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 2\
**Last updated:** [November 15, 2019, 10:23am UTC](https://discuss.elastic.co/t/how-to-prevent-truncation-of-line/207831 "2019-11-15T10:23:45Z")

</div>

Hi, I have some events in elasticsearch where filebeat sets the log.flag to truncated. From release notes I would say, that the truncation limit is configurable. Add tag "truncated" to "log.flags" if incoming line is…

---

## [Metricbeat 7.4.2 stopped reading k8s metrics](https://discuss.elastic.co/t/metricbeat-7-4-2-stopped-reading-k8s-metrics/207799)

<div class="topic-metadata">

**Author:** [@michaelh](https://discuss.elastic.co/u/michaelh)\
**Replies:** 1\
**Last updated:** [November 15, 2019, 10:17am UTC](https://discuss.elastic.co/t/metricbeat-7-4-2-stopped-reading-k8s-metrics/207799 "2019-11-15T10:17:19Z")

</div>

Hey everyone. My metricbeat is running as DaemonSet and reading host and docker metrics, however no k8s metrics are coming through. I am running on minikube with k8s version 1.16.0 and this is my config: kubernetes.yml…

---

## [Filebeat Trigger Linux OOM](https://discuss.elastic.co/t/filebeat-trigger-linux-oom/207647)

<div class="topic-metadata">

**Author:** [@StruggleYang](https://discuss.elastic.co/u/StruggleYang)\
**Replies:** 1\
**Last updated:** [November 15, 2019, 10:03am UTC](https://discuss.elastic.co/t/filebeat-trigger-linux-oom/207647 "2019-11-15T10:03:01Z")

</div>

why rss 4839820kb this is kill before ,use go tool pprof http://localhost:6060/debug/pprof/heap get data

---

## [How to store log line in other field then message](https://discuss.elastic.co/t/how-to-store-log-line-in-other-field-then-message/208030)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [November 15, 2019, 9:54am UTC](https://discuss.elastic.co/t/how-to-store-log-line-in-other-field-then-message/208030 "2019-11-15T09:54:45Z")

</div>

Hi, I have json logs which I need to ship to redis and logstash via filebeat. For the case I have a field named message inside my json string, I was asking myself if it is possible to let filebeat use the field filebeat…

---

## [Filebeat data not being updated in Kibana](https://discuss.elastic.co/t/filebeat-data-not-being-updated-in-kibana/207358)

<div class="topic-metadata">

**Author:** [@kahn](https://discuss.elastic.co/u/kahn)\
**Replies:** 1\
**Last updated:** [November 15, 2019, 9:49am UTC](https://discuss.elastic.co/t/filebeat-data-not-being-updated-in-kibana/207358 "2019-11-15T09:49:33Z")

</div>

/var/log/\*.log is currently being fetched and rendered in Kibana, but after the initial timestamp for which the index was created, no changing of timestamps or refreshing seems to pull new data in. I am new to this stac…

---

## [Monitoring and analysis of mysql-slow.log](https://discuss.elastic.co/t/monitoring-and-analysis-of-mysql-slow-log/207071)

<div class="topic-metadata">

**Author:** [@Vladpov](https://discuss.elastic.co/u/Vladpov)\
**Replies:** 1\
**Last updated:** [November 15, 2019, 9:23am UTC](https://discuss.elastic.co/t/monitoring-and-analysis-of-mysql-slow-log/207071 "2019-11-15T09:23:54Z")

</div>

Hi guys, I'm trying to monitor logs from mysql database so I configured Filebeat to push logs from mysql-slow.log file to logstash and to elasticsearch afterwards. I wanted to use multiline codec in input part of logst…

---

## [How to add settings in filebeat default template?](https://discuss.elastic.co/t/how-to-add-settings-in-filebeat-default-template/207040)

<div class="topic-metadata">

**Author:** [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Replies:** 1\
**Last updated:** [November 15, 2019, 9:15am UTC](https://discuss.elastic.co/t/how-to-add-settings-in-filebeat-default-template/207040 "2019-11-15T09:15:08Z")

</div>

I am very happy with the default mapping which filebeat provides for the index it creates. The only thing I want to do is to add these two to the mappings: numeric\_detection: true date\_detection: true I tried with…

---

## [Cannot Transfer logs - Filebeat 7.4.0 to Redis Output](https://discuss.elastic.co/t/cannot-transfer-logs-filebeat-7-4-0-to-redis-output/207023)

<div class="topic-metadata">

**Author:** [@Kim\_Mendoza](https://discuss.elastic.co/u/Kim_Mendoza)\
**Replies:** 1\
**Last updated:** [November 15, 2019, 9:05am UTC](https://discuss.elastic.co/t/cannot-transfer-logs-filebeat-7-4-0-to-redis-output/207023 "2019-11-15T09:05:54Z")

</div>

Failed to RPUSH to redis list with: write tcp sourceip:port--\>destinationip:port: i/o timeout My config: output.redis: hosts: \["172.27.30.102:6379"\] key: "logstash" db: 0 timeout: 5 index: "logs"

---

## [Nagioscheckbeat 'metric' data combined with 'check'?](https://discuss.elastic.co/t/nagioscheckbeat-metric-data-combined-with-check/205370)

<div class="topic-metadata">

**Author:** [@safehouse](https://discuss.elastic.co/u/safehouse)\
**Replies:** 2\
**Last updated:** [November 15, 2019, 2:47am UTC](https://discuss.elastic.co/t/nagioscheckbeat-metric-data-combined-with-check/205370 "2019-11-15T02:47:20Z")

</div>

@PhaedrusTheGreek In this post we discussed how to successfully send nagioscheckbeat 'check' data to the nagios host, while sending the 'metric' data to Elasticsearch. I am trying to figure out how to send Nagios 'perfd…

---

## [Creating indexes and ILM based on Kubernetes namespace using hints-based autodiscover](https://discuss.elastic.co/t/creating-indexes-and-ilm-based-on-kubernetes-namespace-using-hints-based-autodiscover/207972)

<div class="topic-metadata">

**Author:** [@Michael\_Davis](https://discuss.elastic.co/u/Michael_Davis)\
**Replies:** 0\
**Last updated:** [November 14, 2019, 11:11pm UTC](https://discuss.elastic.co/t/creating-indexes-and-ilm-based-on-kubernetes-namespace-using-hints-based-autodiscover/207972 "2019-11-14T23:11:38Z")

</div>

Hi all, We're just getting started with Filebeat on Kubernetes and the Elastic Stack in general. I'm really impressed with the capabilities of Filebeat so far. The hints-based autodiscover feature is a big deal for us a…

---

## [Help with sending PHP-FPM logs with custom pipeline](https://discuss.elastic.co/t/help-with-sending-php-fpm-logs-with-custom-pipeline/207588)

<div class="topic-metadata">

**Author:** [@Slavik\_Fursov](https://discuss.elastic.co/u/Slavik_Fursov)\
**Replies:** 4\
**Last updated:** [November 14, 2019, 10:46pm UTC](https://discuss.elastic.co/t/help-with-sending-php-fpm-logs-with-custom-pipeline/207588 "2019-11-14T22:46:24Z")

</div>

I have Debian 9 server with Nginx+PHP. Installed Filebeat 7.4.2. I have PHP-FPM log, which has entries like this: slavik@deb96:/var/log/php$ sudo cat php7.0-fpm.log \[11-Nov-2019 23:02:37\] WARNING: \[pool www\] child 133…

---

## [Default encoding for filebeat](https://discuss.elastic.co/t/default-encoding-for-filebeat/207968)

<div class="topic-metadata">

**Author:** [@Karthik\_Ramachandran](https://discuss.elastic.co/u/Karthik_Ramachandran)\
**Replies:** 0\
**Last updated:** [November 14, 2019, 10:50pm UTC](https://discuss.elastic.co/t/default-encoding-for-filebeat/207968 "2019-11-14T22:50:54Z")

</div>

Dear All I'm trying to find the default encoding when we don't set anything specific in prospector. I was referring to the documentation "https://www.elastic.co/guide/en/beats/filebeat/6.8/filebeat-input-log.html", but …

---

## [Use filters to extract info from access logs](https://discuss.elastic.co/t/use-filters-to-extract-info-from-access-logs/207601)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 3\
**Last updated:** [November 14, 2019, 8:59pm UTC](https://discuss.elastic.co/t/use-filters-to-extract-info-from-access-logs/207601 "2019-11-14T20:59:00Z")

</div>

Hi, I want to know if its possible to have filters that will extract info such as Status Code, IP, website, time from an access log. And is it better to do this in Log or Discover board? Or should I configure this in …

---

## [AWS RDS Metricset whitelist by database name and/or tags](https://discuss.elastic.co/t/aws-rds-metricset-whitelist-by-database-name-and-or-tags/207796)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 2\
**Last updated:** [November 14, 2019, 8:53pm UTC](https://discuss.elastic.co/t/aws-rds-metricset-whitelist-by-database-name-and-or-tags/207796 "2019-11-14T20:53:34Z")

</div>

Hi, Is there the option to whitelist which databases metricbeat pulls metrics for? Looking at https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-aws-rds.html it's not clear if there are addit…

---

## [How to automatically shut down filebeat after shipping is done](https://discuss.elastic.co/t/how-to-automatically-shut-down-filebeat-after-shipping-is-done/207958)

<div class="topic-metadata">

**Author:** [@krishna\_bhargav](https://discuss.elastic.co/u/krishna_bhargav)\
**Replies:** 0\
**Last updated:** [November 14, 2019, 8:33pm UTC](https://discuss.elastic.co/t/how-to-automatically-shut-down-filebeat-after-shipping-is-done/207958 "2019-11-14T20:33:31Z")

</div>

We start filebeats daily when the data load is extracted and we would like to shutdown the filebeats once the data is shipped completly or when the filehandlers are closed once shipping completes. Is there a property /se…

---

## [Elasticsearch Metricbeat Module not parsing hosts properly](https://discuss.elastic.co/t/elasticsearch-metricbeat-module-not-parsing-hosts-properly/205893)

<div class="topic-metadata">

**Author:** [@Rad\_Engel](https://discuss.elastic.co/u/Rad_Engel)\
**Replies:** 15\
**Last updated:** [November 14, 2019, 7:43pm UTC](https://discuss.elastic.co/t/elasticsearch-metricbeat-module-not-parsing-hosts-properly/205893 "2019-11-14T19:43:34Z")

</div>

I've enabled the X-Pack on Elasticsearch Module in Metricbeat 7.4.1. I have SSL set up for my Elasticsearch cluster (single node, Kibana, Losgstash, and other beats are fine) and am attempting to get Metricbeat to query…

---

## [Rasppbery(ARM) install filebeat](https://discuss.elastic.co/t/rasppbery-arm-install-filebeat/207525)

<div class="topic-metadata">

**Author:** [@111236](https://discuss.elastic.co/u/111236)\
**Replies:** 1\
**Last updated:** [November 14, 2019, 6:57pm UTC](https://discuss.elastic.co/t/rasppbery-arm-install-filebeat/207525 "2019-11-14T18:57:49Z")

</div>

i can't install filebeat on Rasppbery(ARM). I followed: https://www.elasticice.net/?p=92 How to install Filebeat on a ARM based SBC (eg. Raspberry Pi 3) http://www.programmersought.com/article/31601555670/ as a resu…

---

## [Best beats for crontab in linux](https://discuss.elastic.co/t/best-beats-for-crontab-in-linux/206005)

<div class="topic-metadata">

**Author:** [@Bharatsid](https://discuss.elastic.co/u/Bharatsid)\
**Replies:** 1\
**Last updated:** [November 14, 2019, 6:53pm UTC](https://discuss.elastic.co/t/best-beats-for-crontab-in-linux/206005 "2019-11-14T18:53:08Z")

</div>

I want alert monitoring for crontab in my application. So which beats are best to monitor for crontabs?

---

## [Configuring filebeats for persistentVolumes in a cluster with multiple nodes](https://discuss.elastic.co/t/configuring-filebeats-for-persistentvolumes-in-a-cluster-with-multiple-nodes/205934)

<div class="topic-metadata">

**Author:** [@JeffKet](https://discuss.elastic.co/u/JeffKet)\
**Replies:** 1\
**Last updated:** [November 14, 2019, 4:37pm UTC](https://discuss.elastic.co/t/configuring-filebeats-for-persistentvolumes-in-a-cluster-with-multiple-nodes/205934 "2019-11-14T16:37:24Z")

</div>

I have a cluster with 3 master and 8 worker nodes. I have deployed filebeats in pods on each of the worker nodes to gather container logs. What I also have done is create a pod that writes to a persistentVolumeClaim in a…

---

## [How does EKS get autheticarted with AWS in order to get the data](https://discuss.elastic.co/t/how-does-eks-get-autheticarted-with-aws-in-order-to-get-the-data/207841)

<div class="topic-metadata">

**Author:** [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Replies:** 4\
**Last updated:** [November 14, 2019, 3:12pm UTC](https://discuss.elastic.co/t/how-does-eks-get-autheticarted-with-aws-in-order-to-get-the-data/207841 "2019-11-14T15:12:37Z")

</div>

Hi All, My environment is elasticsearch/stable,now 7.4.2 amd64 metricbeat/stable,now 7.4.2 amd64 I was going through the docs aws fields | Metricbeat Reference \[7.4\] | Elastic I was not able to see the docs for h…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=298)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=300)
